Terminal device control method and device based on flow conversion linkage, equipment and medium

By constructing user device association graphs and flow relationship graphs, abnormal flow linkage behaviors of terminal devices are identified, solving the problems of small identification range and low accuracy in existing technologies, and achieving more efficient traffic interception and improved server security.

CN120994504BActive Publication Date: 2026-03-03中信证券股份有限公司
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-10-21
Publication Date
2026-03-03

AI Technical Summary

Technical Problem

Existing technologies for identifying and controlling abnormal flow behavior of terminal devices suffer from problems such as small identification range, low accuracy, high server load, and high security risks, making it difficult to accurately identify individual abnormal behaviors and group abnormal linkage behaviors.

Method used

By acquiring user multi-source login association information and value object flow information, a user device association graph is constructed and divided, flow relationships are mined, a user value object flow graph is generated, abnormal flow linkage is identified, and monitoring, early warning and flow interception control are performed.

Benefits of technology

It improves the accuracy of terminal device traffic interception and early warning, reduces server load, enhances server security, reduces missed detections and false detections, and improves the scope and speed of flow linkage identification.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120994504B_ABST
    Figure CN120994504B_ABST
Patent Text Reader

Abstract

Embodiments of the present disclosure disclose a terminal device control method and device based on flow conversion linkage, an equipment and a medium. A specific implementation of the method includes: obtaining a user multi-source login association information set and a user value object flow conversion information set; constructing a knowledge graph for the user multi-source login association information set to obtain a user device association graph; dividing the user device association graph to obtain a user login association subgraph set; mining flow conversion relationship for the user value object flow conversion information set to obtain a flow conversion relationship information set; generating a user value object flow conversion graph; identifying abnormal flow conversion linkage for the user value object flow conversion graph to obtain a flow conversion linkage abnormal association graph set; monitoring and warning processing a terminal device set, and flow conversion interception control for the terminal device set. The implementation can improve the accuracy of the server's flow interception and warning for the terminal device, reduce the load of the server, and improve the security of the server.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments disclosed herein relate to the field of computer technology, and specifically to terminal device control methods, apparatus, devices, and media based on flow linkage. Background Technology

[0002] Identifying the flow and linkage of value objects can involve identifying abnormal behavior in groups of multiple users, and then monitoring, issuing warnings, and blocking traffic on terminal devices exhibiting abnormal behavior. Currently, the common approach to controlling the flow and linkage of value objects is to use machine learning algorithms to identify anomalies in the flow behavior of individual users related to value objects, obtain abnormal user information, then identify similar behaviors in user sets associated with the abnormal user information to obtain abnormal user groups, and finally block traffic on the terminal devices corresponding to the abnormal user groups.

[0003] However, in practice, it has been found that when using the above methods to control the flow and linkage of value-related data, the following technical problems often arise: the detected flow behavior for identifying the flow behavior of a single user's value object is relatively simple; the scope of the flow group identified by identifying flow linkage with users associated with abnormal users is small, making it difficult to accurately identify both individual abnormal behavior and group abnormal linkage behavior; furthermore, the number of flow behavior indicators selected by machine learning algorithms is limited, making it difficult to effectively, accurately, and comprehensively identify flow linkage behavior, increasing the possibility of missed detections and false detections, resulting in low accuracy in abnormal behavior identification; the server's accuracy in intercepting and controlling the flow of data on terminal devices is poor; the server handles a large number of flow requests, resulting in poor server load reduction and increased server security risks.

[0004] The information disclosed in this background section is only intended to enhance the understanding of the background of the present disclosure concept, and therefore may contain information that does not constitute prior art known to those skilled in the art. Summary of the Invention

[0005] The summary portion of this disclosure is intended to provide a brief overview of the concepts, which will be described in detail in the detailed description portion. This summary portion is not intended to identify key or essential features of the claimed technical solutions, nor is it intended to limit the scope of the claimed technical solutions.

[0006] Some embodiments of this disclosure propose terminal device control methods, apparatuses, devices, and media based on flow linkage to solve one or more of the technical problems mentioned in the background section above.

[0007] In a first aspect, some embodiments of this disclosure provide a terminal device control method based on flow linkage, including: acquiring a user multi-source login association information set and a user value object flow information set; constructing a knowledge graph on the aforementioned user multi-source login association information set to obtain a user device association graph; dividing the aforementioned user device association graph to obtain a user login association sub-graph set; mining flow relationships on the aforementioned user value object flow information set to obtain a flow relationship information set; generating a user value object flow graph based on the aforementioned user value object flow information set and the aforementioned flow relationship information set; identifying abnormal flow linkage on the aforementioned user value object flow graph based on the aforementioned user login association sub-graph set to obtain a flow linkage abnormal association graph set; sending the aforementioned flow linkage abnormal association graph set to a flow alarm device to control the aforementioned flow alarm device to monitor and warn of the value object flow information of the terminal device set corresponding to the aforementioned flow linkage abnormal association graph set, and in response to determining that the aforementioned flow alarm device has issued a warning message, performing flow interception control on the aforementioned terminal device set.

[0008] Secondly, some embodiments of this disclosure provide a terminal device control apparatus based on flow linkage, including: an acquisition unit configured to acquire a user multi-source login association information set and a user value object flow information set; a knowledge graph construction unit configured to construct a knowledge graph on the aforementioned user multi-source login association information set to obtain a user device association graph; a graph partitioning unit configured to partition the aforementioned user device association graph to obtain a user login association sub-graphet; a flow relationship mining unit configured to mine flow relationships on the aforementioned user value object flow information set to obtain a flow relationship information set; and a generation unit configured to generate information based on the aforementioned user value object flow information set. The value object flow information set and the aforementioned flow relationship information set are used to generate a user value object flow graph. The abnormal flow linkage identification unit is configured to identify abnormal flow linkages in the aforementioned user value object flow graph based on the aforementioned user login association sub-graph set, and obtain a flow linkage abnormal association graph set. The flow interception control unit is configured to send the aforementioned flow linkage abnormal association graph set to the flow alarm device to control the aforementioned flow alarm device to monitor and warn about the value object flow information of the terminal device set corresponding to the aforementioned flow linkage abnormal association graph set, and to perform flow interception control on the aforementioned terminal device set in response to determining that the aforementioned flow alarm device has issued a warning message.

[0009] Thirdly, some embodiments of this disclosure provide an electronic device, including: one or more processors; and a storage device having one or more programs stored thereon, such that when the one or more programs are executed by the one or more processors, the one or more processors implement the method as described in any implementation of the first aspect.

[0010] Fourthly, some embodiments of this disclosure provide a computer-readable medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements the method as described in any implementation of the first aspect.

[0011] The above embodiments of this disclosure have the following beneficial effects: The terminal device control method based on flow linkage in some embodiments of this disclosure can improve the accuracy of server traffic interception and early warning for terminal devices, reduce server load, and improve server security. Specifically, the reason why the related terminal devices bear a large number of flow requests, the effect of reducing terminal device load is poor, and the security risk of terminal devices is increased is that: the flow behavior detected by identifying the value object flow behavior of a single user is relatively simple; the scope of the flow group identified by flow linkage identification through users associated with abnormal users is small, making it difficult to accurately identify both single abnormal behavior and group abnormal linkage behavior; and the number of flow behavior indicators selected by machine learning algorithms is small, making it difficult to effectively, accurately and comprehensively identify flow linkage behavior, increasing the possibility of missed detection and false detection, resulting in low accuracy of abnormal behavior identification, poor precision of server flow interception and control of terminal devices, and a large number of flow requests on the server, resulting in poor effect of reducing server load and increasing server security risk. Based on this, the terminal device control method based on flow linkage in some embodiments of this disclosure can first obtain the user multi-source login association information set and the user value object flow information set. Here, the user multi-source login association information set and the user value object flow information set facilitate the subsequent construction of user device association graphs and user value object flow graphs. Secondly, a knowledge graph is constructed from the aforementioned user multi-source login association information set to obtain the user device association graph. Here, strong potential associations between users, excluding value object flow and explicit social relationships (e.g., relatives, friends), can be effectively identified through login devices and personal information, achieving efficient association between users and increasing the scope and comprehensiveness of identification. Thirdly, the aforementioned user device association graph is partitioned to obtain the user login association sub-graphet. Here, separating multiple users with strong associations from the graph reduces useless data on users and devices without association with the user, thereby reducing the data volume of the user login association sub-graphet and facilitating faster identification of subsequent abnormal flow linkages. Next, flow relationship mining is performed on the aforementioned user value object flow information set to obtain a flow relationship information set. Here, flow relationship mining can uncover potential flow relationships, improving the comprehensiveness of the flow relationship information set. Subsequently, based on the aforementioned user value object flow information set and flow relationship information set, a user value object flow graph is generated. This improves the accuracy and comprehensiveness of the user value object flow graph, as each user value object node and flow edge in the graph includes a wealth of attribute information. Then, based on the aforementioned user login association sub-graphet, abnormal flow linkage identification is performed on the aforementioned user value object flow graph, resulting in an abnormal flow linkage association graphet.Here, the combined use of the user login association sub-graph and the user value object flow graph complement each other. The user login association sub-graph can accurately define the identification scope, discover strongly related groups based on device and information sharing, and reduce the amount and complexity of computational data. The user value object flow graph accurately identifies flow behavior, improving the comprehensiveness and accuracy of the flow linkage anomaly association graph and reducing the occurrence of missed and false detections. Finally, the above-mentioned flow linkage anomaly association graph is sent to the flow alarm device to control the flow alarm device to monitor and warn of the value object flow information of the terminal device set corresponding to the flow linkage anomaly association graph, and to intercept and control the flow of the terminal device set in response to the warning information issued by the flow alarm device. Here, the accuracy and high quality of the flow linkage anomaly association graph can improve the real-time and accuracy of monitoring and warning, thereby improving the accuracy of flow interception and control of terminal devices, effectively reducing the server's flow volume and load, and improving server security. Therefore, this terminal device control method based on flow linkage can effectively associate potential user association information through terminal devices and information sharing by using the user login association graph. After graph division, combined with the user value object flow graph, the accuracy and speed of abnormal flow linkage identification can be improved, thereby improving the accuracy of early warning and interception of abnormal terminal devices, reducing server load and improving server security. Attached Figure Description

[0012] The above and other features, advantages, and aspects of the embodiments of this disclosure will become more apparent from the accompanying drawings and the following detailed description. Throughout the drawings, the same or similar reference numerals denote the same or similar elements. It should be understood that the drawings are schematic, and elements are not necessarily drawn to scale.

[0013] Figure 1 This is a flowchart of some embodiments of the terminal device control method based on abnormal flow linkage identification according to the present disclosure;

[0014] Figure 2 This is a schematic diagram of the user equipment association map in some embodiments of the terminal equipment control method based on abnormal flow linkage identification according to this disclosure;

[0015] Figure 3 This is a schematic diagram of the user value object flow map in some embodiments of the terminal device control method based on abnormal flow linkage identification according to this disclosure;

[0016] Figure 4 This is a schematic diagram of the structure of some embodiments of the terminal device control device based on abnormal flow linkage identification according to the present disclosure;

[0017] Figure 5This is a schematic diagram of the structure of an electronic device suitable for implementing some embodiments of the present disclosure. Detailed Implementation

[0018] Embodiments of this disclosure will now be described in more detail with reference to the accompanying drawings. While some embodiments of this disclosure are shown in the drawings, it should be understood that this disclosure can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided to provide a more thorough and complete understanding of this disclosure. It should be understood that the accompanying drawings and embodiments of this disclosure are for illustrative purposes only and are not intended to limit the scope of protection of this disclosure.

[0019] It should also be noted that, for ease of description, only the parts relevant to the invention are shown in the accompanying drawings. Unless otherwise specified, the embodiments and features described in this disclosure can be combined with each other.

[0020] It should be noted that the concepts of "first" and "second" mentioned in this disclosure are used only to distinguish different devices, modules or units, and are not used to limit the order of functions performed by these devices, modules or units or their interdependencies.

[0021] It should be noted that the terms "a" and "a plurality of" used in this disclosure are illustrative rather than restrictive, and those skilled in the art should understand that, unless otherwise expressly indicated in the context, they should be understood as "one or more".

[0022] The names of messages or information exchanged between multiple devices in the embodiments of this disclosure are for illustrative purposes only and are not intended to limit the scope of such messages or information.

[0023] This disclosure will now be described in detail with reference to the accompanying drawings and embodiments.

[0024] Figure 1 A flowchart 100 is shown, illustrating some embodiments of a terminal device control method based on abnormal flow linkage identification according to this disclosure. This terminal device control method based on abnormal flow linkage identification includes the following steps:

[0025] Step 101: Obtain the user multi-source login association information set and the user value object transfer information set.

[0026] In some embodiments, the executing entity (e.g., an electronic device) of the aforementioned terminal device control method based on abnormal flow linkage identification can acquire user multi-source login association information set and user value object flow information set via wired or wireless connection. The aforementioned user multi-source login association information set can be an information set from different data sources related to user information and user login terminal device value object flow operation information. User login terminal devices can include, but are not limited to, at least one of the following: mobile phone, personal computer, desktop computer. For example, the aforementioned user multi-source login association information set can include, but is not limited to, at least one of the following: a multi-type user information database set, and a login information set on a value object flow terminal device set (user transaction terminal device set). The aforementioned multi-type user information database set can be a database storing different types of user information. The aforementioned multi-type user information database set can include: ECIF (Enterprise Customer Information Facility), personal customer information database, institutional customer information database, and product customer information database. The aforementioned personal customer information database can be a database that stores customer information based on the individual customer's document type and corresponding document number for account opening (opening securities accounts and fund accounts). The aforementioned institutional customer information database can be a database that stores company-related information based on the company's business license and unified social credit code. The aforementioned product customer information database can be a database that stores the identification information of users corresponding to the product, based on the product's name. The user value object circulation information (securities transaction information, securities target attribute information) in the aforementioned user value object circulation information set can be both user information and user value object circulation information.

[0027] Step 102: Construct a knowledge graph from the user's multi-source login association information set to obtain the user device association graph.

[0028] In some embodiments, the aforementioned executing entity may construct a knowledge graph from the aforementioned user multi-source login association information set to obtain a user device association graph. This user device association graph may be a knowledge graph with multiple connected components, used to describe the association between user information and the terminal login device used by the user. Nodes in the aforementioned user device association graph may include: user nodes, user personal information, and device nodes. The aforementioned user personal information and device nodes may be nodes composed of information from the terminal device used by the user and user personal information stored on the terminal device. For example, the aforementioned user personal information and device nodes may include, but are not limited to, at least one of the following: user terminal (e.g., mobile phone, computer), user information stored on the user terminal (e.g., registered mobile phone number), universally unique identifier (UUID) of the terminal device, IMEI (International Mobile Equipment Identity) of the terminal device, MAC (Media Access Control Address) address of the terminal device, and MAC_HD (Macintosh HD, the default startup disk of macOS). Edges in the aforementioned user device association graph may be connecting edges used to describe the association between user nodes, user personal information, and device nodes. The aforementioned knowledge graph construction can be performed using a bottom-up knowledge graph construction method. For example... Figure 2 As shown, Figure 2 It displays a user device association graph consisting of user nodes, user personal information, and device nodes.

[0029] In some optional implementations of certain embodiments, the above-mentioned knowledge graph construction of the user multi-source login association information set to obtain the user device association graph may include the following steps:

[0030] The first step is to fuse the user multi-source information set included in the aforementioned user multi-source login association information set to obtain user login association fused information. The aforementioned user multi-source information set can be user-related information from different data sources. The aforementioned user login association fused information can be obtained by fusing data from the aforementioned user multi-source information set, using user identification information representing user identity as the fusion basis. The aforementioned user identification information may include, but is not limited to, at least one of the following: information on document type and corresponding document number.

[0031] The second step involves performing fuzzy identification of value object users on the aforementioned user login association and fusion information to obtain a fuzzy value object user information set. This fuzzy value object user information set can be obtained by modifying user information from the product customer information database that has the same user ID type, user ID number, and value object name to represent the same user. In practice, the executing entity can first preprocess the aforementioned user login association and fusion information to obtain preprocessed user login association and fusion information. Secondly, using a fuzzy matching algorithm, fuzzy matching is performed on the set of value object names included in the preprocessed user login association and fusion information to obtain an object fuzzy matching name information set. For example, the object fuzzy matching name information may be named differently in different customer information sets. In user multi-source information A of the user multi-source information set, it may be named "xxx Growth Fund 2025," and in user multi-source information B of the user multi-source information set, it may be named "xxx Growth 2025 Fund." Through the fuzzy matching algorithm, "xxx Growth Fund 2025" and "xxx Growth 2025 Fund" are identified as the same value object name, thus obtaining the object fuzzy matching name information set. Then, based on the user ID type and user ID code, fuzzy matching is performed on the user information set included in the preprocessed user login association fusion information to obtain the user fuzzy matching information set. Finally, fuzzy matching is performed on the object fuzzy matching name information set and the above user fuzzy matching information set to determine the successfully matched user information as the same user information, which is then used as the fuzzy value object user information set.

[0032] The third step involves disambiguating the aforementioned user login association and fusion information to obtain a user identity disambiguation information set. This disambiguation information set identifies user information with the same meaning but different usernames as belonging to the same user. In practice, the executing entity can use the user ID type information and the corresponding user ID number in the user information to perform user identity disambiguation processing on the aforementioned user login association and fusion information, thus identifying user information with the same user ID type and the same user ID number as belonging to the same user.

[0033] The fourth step is to determine the aforementioned set of fuzzy value object user information and the aforementioned set of user identity disambiguation information as a user entity information set. The user entity information in the aforementioned user entity information set can be information representing users with the same user attribute information. The aforementioned user attribute information may include, but is not limited to, at least one of the following: user name, user identity information, user document type information, and user document number corresponding to the user document type information.

[0034] The fifth step involves extracting user device information from the value object order information set included in the aforementioned multi-source login association information set to obtain a user device entity information set. The value object order information in this set can include information about devices used by the user during the value object transfer process (user transaction process) and the user's pre-registered contact information. The user device entities in this set can include device information for the user's terminal device used for login to transfer value objects and user login information. For example, the user device entity information set may include, but is not limited to, at least one of the following: hard drive, registered mobile phone number, user email address, and IDFV (IdentifierForVendor, the vendor identifier of the terminal device). In practice, the executing entity can first perform data cleaning on the aforementioned value object order information set using a Greenplum distributed database to obtain a cleaned value object order information set. This cleaned value object order information set may include, but is not limited to, at least one of the following: value object transfer information (transaction flow information), value attribute value transfer information (fund flow), and user information. Then, the device flow information set stored in the terminal device set corresponding to the above-mentioned cleaned value object order information set is pre-parsed to obtain the user device entity information set.

[0035] Step 6: Determine the aforementioned user equipment entity information set and the user equipment association relationship information set. The user equipment association relationship information in the aforementioned user equipment association relationship information set can be information describing the associations between user equipment entity information and user entity information, and between user entity information and other user entity information. The aforementioned user equipment association relationship information set can include: device usage relationship information and user association relationship information. The aforementioned device usage relationship information can represent the relationship information of a user's use of a terminal device or their personal information. Different users can be indirectly associated through the same personal information and devices from the same source. The aforementioned user association relationships can represent direct relationships between users that are not based on personal information, and indirect relationships established through terminal devices. For example, the aforementioned user association relationships can include, but are not limited to, at least one of the following: second contact person, legal representative, or agent.

[0036] Step 7: Generate a user equipment association graph based on the above user entity information set, the above user equipment entity information set, and the above user equipment association relationship information set.

[0037] As an example, the aforementioned execution entity can first construct triples from the aforementioned user entity information set, user device entity information set, and user device association relationship information set to obtain a user device triple set. Then, the user device triple set is input into a graph database to obtain a user device association graph. The graph database can be an existing graph database. For example, the graph database could be the Noe4j graph database.

[0038] Step 103: Divide the user device association graph to obtain the user login association sub-graph set.

[0039] In some embodiments, the aforementioned executing entity may partition the aforementioned user device association graph to obtain a user login association sub-graph set. The user login association sub-graph set may be the largest connected graph of the aforementioned user device association graph, composed of user nodes belonging to the same community, user personal information and device nodes, corresponding association relationships and usage relationships.

[0040] In some optional implementations of certain embodiments, the above-mentioned graph partitioning of the user equipment association graph to obtain the user login association sub-graphet may include the following steps:

[0041] The first step is to determine the degree set of user device nodes in the aforementioned user device association graph. The degree of each user device node in this degree set represents the importance of a user node or user information and device node, i.e., the number of connections to other nodes.

[0042] The second step is to determine the user device node access sequence based on the aforementioned user device node degree set. This user device node access sequence can be obtained by sorting the user device node sets included in the aforementioned user device association graph in descending order of the user device node degrees included in the aforementioned user device node degree set. Each user device node can be a node set composed of user nodes, user personal information, and device nodes.

[0043] The third step, based on the user equipment node access sequence, is to perform the following subgraph determination steps:

[0044] Sub-step 1, based on the initial user equipment node, performs the following access graph generation steps:

[0045] The first sub-step involves determining, based on the aforementioned user equipment association graph, user equipment nodes following the starting user equipment node as user equipment depth nodes. The starting user equipment node is the node located at the initial position in the node access sequence. The user equipment depth nodes can be user equipment nodes located after the starting user equipment node that have not been visited. This determination can be made using the connecting edges in the aforementioned user equipment association graph.

[0046] The second sub-step involves adding the user equipment depth node and the starting user equipment node to a preset data stack to obtain a node access stack. This preset data stack can be a pre-defined stack data structure used to store the user equipment depth node and the starting user equipment node.

[0047] The third sub-step, in response to determining that the node access stack satisfies the node depth access condition, generates a node access graph based on the starting user equipment node and the user equipment depth nodes. The node depth access condition can be a condition where, in the reverse order of their addition to the node access stack, none of the user equipment nodes included in the stack have been subsequently unvisited. The node access graph can be a graph composed of multiple user equipment nodes from the starting user equipment node to the aforementioned user equipment depth nodes. This generation can be performed using a depth-first search algorithm.

[0048] Sub-step 2: In response to the determination that the node access stack does not meet the node depth access conditions, the user equipment depth node is determined as the starting user equipment node, and the generation step is executed again.

[0049] Sub-step 3: In response to the determination that the node unaccessed sequence is empty, the obtained node access graphs are determined as user login associated subgraph sets, wherein the above-mentioned node unaccessed sequence is the user device node access sequence after removing the corresponding access sequences of each node access graph.

[0050] Fourth, in response to the determination that the node unvisited sequence is not empty, the node unvisited sequence is determined as the user equipment node access sequence, and the above determination steps are performed again.

[0051] Furthermore, in the process of adopting technical solutions to address the technical problems mentioned in the background, the following technical issues often arise: Because the user device association graph contains a large number of different types of connection edges and user device nodes, and these are constantly changing, it is difficult to accurately partition the user device association graph. This results in low user association in the partitioned user login association subgraph, with some useless and erroneous nodes and edges, reducing the accuracy and partitioning speed of the user login association subgraph, increasing server load, and reducing server security. A conventional solution to these technical problems is to use a streaming graph partitioning method to partition the user device association graph, obtaining a user login association subgraph set. However, this conventional solution still has the following problems: Because the streaming graph partitioning method treats all user device nodes and connection edges with the same importance, it cannot accurately distinguish the importance of different nodes and edges. Furthermore, when processing partitions with large amounts of connection edges and user device node data, it is necessary to obtain the subgraph structure information in advance, resulting in low partitioning efficiency and speed, an imbalance between partitioning efficiency and quality, and low quality of the user login association subgraph. Considering the shortcomings of the aforementioned conventional solutions, and taking into account the advantages and current state of our company's abnormal behavior recognition technology, we have decided to adopt the following solution:

[0052] In some optional implementations of certain embodiments, the above-mentioned graph partitioning of the user equipment association graph to obtain the user login association sub-graphet may include the following steps:

[0053] The first step is to perform time-slicing processing on the aforementioned user equipment association graph to obtain a sequence of associated time-series slice graphs. The associated time-series slice graphs in this sequence can be user equipment association graphs formed from user multi-source login association information sets within one day. The time slicing can be performed with a one-day division period. These time slices can capture the structural changes of the user equipment association graph over time.

[0054] The second step involves using a heterogeneous graph attention model for user equipment to perform node semantic attention aggregation on each associated temporal slice in the aforementioned sequence of associated temporal slices, generating a node adjacency relationship fusion feature vector group, resulting in a sequence of node adjacency relationship fusion feature vector groups. The aforementioned heterogeneous graph attention model for user equipment can be a deep neural network that performs node-level and semantic-level attention feature aggregation on the associated temporal slices in the input sequence of associated temporal slices to output node adjacency relationship fusion feature vectors. For example, the aforementioned heterogeneous graph attention model can be a heterogeneous graph attention network. The aforementioned node-level attention can be an attention network used to aggregate adjacent nodes with the same type of connection relationship. The aforementioned semantic-level attention can be an attention network used to aggregate adjacent nodes with different types of connection relationships.

[0055] The third step involves performing time-aware embedding processing on the aforementioned node adjacency relationship fusion feature vector sequence to obtain a node temporal embedding feature vector sequence. The node temporal embedding feature vectors in this sequence can be feature vectors that fuse node-level, semantic-level, and temporal feature information. In practice, the executing entity can use a dynamic graph self-attention network to perform time-aware embedding processing on the aforementioned node adjacency relationship fusion feature vector sequence to obtain the node temporal embedding feature vector sequence.

[0056] The fourth step involves performing streaming community partitioning on the aforementioned user equipment association graph based on the sequence of node temporal embedding feature vectors, resulting in an initial association community set. The initial association communities in this set can be communities where the user equipment nodes have relatively similar embedding similarities in their node temporal embedding feature vectors and denser connections, while the communities themselves are relatively sparse.

[0057] As an example, the aforementioned execution entity can first traverse the user equipment nodes included in the aforementioned user equipment association graph according to the order in which the user equipment nodes appear, obtaining a sequence of user equipment nodes to be partitioned. Then, it creates communities for the user equipment nodes located at the initial position in the sequence of user equipment nodes to be partitioned, obtaining an initial node community. Next, it sequentially determines the output node device for each user equipment node in the sequence of user equipment nodes to be partitioned after removing the initial position, obtaining a set of node communities. This determination can be achieved by first determining the mean cosine similarity between the current user equipment node to be partitioned and all user equipment nodes in a node community that has a connection and has already been partitioned. If the mean is greater than or equal to a preset embedding similarity threshold, the current user equipment node to be partitioned is assigned to a node community with a connection; otherwise, a new node community is created. The preset embedding similarity threshold can be a pre-set minimum value for determining if nodes belong to the same node community. For example, the preset embedding similarity threshold could be 0.7. Finally, the initial node community and the set of node communities are determined as the initial association community set.

[0058] The fifth step involves performing community partitioning mapping on the initial associated community set to obtain a mapped associated community set. The mapped associated communities in this set can be communities that have been merged or divided from the initial associated communities to achieve load balancing in the mapped partitions. In practice, the executing entity can first sort the initial associated community set by community volume from largest to smallest to obtain an initial associated community sequence. The community volume can be the sum of the degrees of each user device node included in the initial associated community. Then, the community module degree increment groups that are mapped sequentially to each preset community partition in the preset community partition set from the initial associated community sequence are determined to obtain a community module degree increment group set. The community module degree increment can be a numerical measure of the quality of the initial associated community, expressed as the difference between the number of connected edges in the user device association graph and the number of edges in an initial associated community. The community module degree increment can also be the difference between the ratio of the sum of normalized weights of the connected edges in the initial associated community to the sum of normalized weights in the user device association graph, and the ratio of the total degree of user device nodes included in the initial associated community to the total degree of the user device association graph. Finally, using a greedy algorithm, the initial associated community set is partitioned and mapped based on the incremental grouping of community modularity to obtain the mapped associated community set.

[0059] Step 6: Perform community-aware partitioning on the overloaded edge set and cut edge set included in the above-mentioned mapping-related community set to obtain the mapping-optimized related community set, which serves as the user login related sub-graph set. Here, overloaded edges in the overloaded edge set can be edges exceeding the load corresponding to the preset community partition set. Cut edges in the cut edge set can be edges between mapping-related communities included in the mapping-related community set. The mapping-optimized related community set can be a community set obtained by allocating the overloaded edge set and cut edge set to the above-mentioned mapping-related community set. In practice, the execution entity can perform the following perceptual partitioning steps for each edge in the overloaded edge set and cut edge set: First, determine the mapping-related communities where the two user device nodes associated with the edge belong, obtaining the first mapping-related community and the second mapping-related community. Second, determine the normalized edge weight values ​​of the edges connecting the two associated user device nodes, respectively, as the first and second related edge weight values. Third, determine the first and second replication factor values ​​for the edge belonging to the first and second mapping-related communities, respectively. The first replication factor score can be the sum of 2, the difference between the first association edge weight value and the ratio of the first association edge weight value to the sum of the first and second association edge weight values, and 0, if the first user device node is in the first mapping association community and the second user device node is in the second mapping association community. The 0 value is due to the second user device node not being in the first mapping association community. Next, the first semantic association value and the second semantic association value for edges belonging to the first and second mapping association communities are determined. The first semantic association value can be the product of the node temporal embedding feature vector of the first user device node, the cosine similarity value of the average node temporal embedding feature vector of the node temporal embedding feature vector set included in the first mapping association community, and the normalized weight value of the edge. Then, the sum of the first replication factor value and the first semantic association value is determined as the first edge allocation value, and the sum of the second replication factor value and the second semantic association value is determined as the second edge allocation value. Finally, the larger value between the first and second edge allocation values ​​is determined as the target edge allocation value, and the edge is assigned to the mapping association community where the target edge allocation value is located. If the load of the mapping association community where the target edge allocation value is located exceeds the preset community load, the edge is divided into community-aware partitions using the DBH (Dynamic Balance Hierarchy) edge partitioning method to obtain the mapping optimized association community set, which serves as the user login association subgraph.

[0060] Step 7: Based on the user login associated sub-graphet, determine the abnormal flow linkage associated graphet, and perform flow interception control on the terminal devices corresponding to the abnormal flow linkage associated graphet. The specific implementation method for this step can be found in steps 104-107, and will not be repeated here.

[0061] The above technical solution and its related content, as an inventive point of this disclosure, solve the technical problem mentioned in the background: "Because the user equipment association graph contains a large number of different types of connection edges and user equipment nodes, and is constantly changing, it is difficult to accurately divide the user equipment association graph. This results in low user association in the divided user login association subgraph, with some useless and incorrect nodes and edges, reducing the accuracy and division speed of the user login association subgraph, increasing the load on terminal devices, and reducing security." The factors that reduce the accuracy and division speed of the user login association subgraph, increase the server load, and reduce server security are often as follows: Because the user equipment association graph contains a large number of different types of connection edges and user equipment nodes, and is constantly changing, it is difficult to accurately divide the user equipment association graph. This results in low user association in the divided user login association subgraph, with some useless and incorrect nodes and edges, reducing the accuracy and division speed of the user login association subgraph, increasing the server load, and reducing server security. If these factors are solved, the accuracy and division speed of the user login association subgraph can be improved, the load on terminal devices can be reduced, and security can be improved. To achieve this effect, this disclosure first performs time-slicing processing on the user device association graph and embeds the association time-series slice graph sequence at the node, semantic, and temporal levels. This allows for real-time capture of the graph's structural changes over time and precise weighting of heterogeneous edges and nodes in the user device association graph, improving the comprehensiveness and accuracy of node temporal embedding feature vectors and avoiding semantic fragmentation of subgraphs during subsequent partitioning. Secondly, streaming community partitioning is performed based on the node temporal embedding feature vector sequence. Single-pass partitioning reduces memory consumption and provides global graph structure guidance for subsequent community partitioning mapping, avoiding semantic fragmentation caused by partitioning. Then, community partitioning mapping is performed on the initial association community set. This preserves community integrity, ensures load balancing of the mapped association community set, and reduces the number of splitting edges by wired allocation of edges within the same community, thus reducing the amount of data required for subsequent community-aware partitioning. Next, community-aware partitioning is performed on the overloaded edge set and the cut edge set to obtain a mapping-optimized association community set. By determining only the mapping association community where the user device nodes associated with the edges belong, the computational load can be reduced, and the processing speed of community-aware partitioning can be improved. Furthermore, by combining the replication factor value and semantic association value for perception, the quality and speed of perception partitioning can be balanced. Finally, the abnormal flow linkage association graph set is determined, and flow interception control is performed on the terminal devices corresponding to the abnormal flow linkage association graph set. This can improve the accuracy of flow interception for terminal devices, enhance server security, and effectively reduce server load.

[0062] Step 104: Min the flow relationship of the user value object flow information set to obtain the flow relationship information set.

[0063] In some embodiments, the executing entity can perform flow relationship mining on the user value object flow information set to obtain a flow relationship information set. The user value object flow information in the flow relationship information set can be information extracted and mined from the user value object flow information set, representing the connection relationship between user information and user value objects. The flow relationship information may include, but is not limited to, at least one of the following: flow frequency, flow attribute value (transaction amount), flow attribute value change information, value object flow unit price information (transaction price), flow days, and value object storage flow status information (securities holding status information). In practice, the executing entity can first use an association rule mining algorithm to perform flow relationship mining on the user value object flow information set to obtain a flow mining relationship information set. The association rule mining algorithm can be the Apriori algorithm. Then, at least one flow mining relationship information that satisfies the flow relationship constraint condition is selected from the flow mining relationship information set. The flow relationship constraint condition can be that the flow buy or sell attribute value (transaction amount) is greater than or equal to a preset flow attribute threshold. The aforementioned preset flow attribute threshold can be a pre-defined minimum value for the flow attribute. Then, using the Pearson correlation coefficient algorithm, the set of relational correlation values ​​for at least one flow mining relationship is determined. Finally, multiple flow mining relationships with corresponding relational correlation values ​​less than or equal to the preset correlation threshold are selected from the at least one flow mining relationship to obtain a set of flow relationship information. The aforementioned preset correlation threshold can be a pre-defined maximum value representing any two flow mining relationship information.

[0064] Step 105: Generate a user value object flow graph based on the user value object flow information set and flow relationship information set.

[0065] In some embodiments, the aforementioned executing entity can generate a user value object circulation graph based on the aforementioned user value object circulation information set and the aforementioned circulation relationship information set. The aforementioned user value object circulation graph can be a knowledge graph describing the connection relationships between user information and value objects. Nodes in the aforementioned user value object circulation graph can include user nodes and value object nodes. Connecting edges in the aforementioned user value object circulation graph can include, but are not limited to, at least one of the following: minimum successful inflow count (minimum number of buy transactions per day) within a preset time range, maximum successful inflow count (maximum number of buy transactions per day) within a preset time range, percentage of minimum successful inflow count, circulation buy, circulation sell, circulation attribute value (transaction amount), circulation days, and value object storage (securities holdings). The aforementioned preset time range can be a pre-defined time range for value object circulation. For example, the aforementioned preset time range can be 20 days. Figure 3 As shown, Figure 3 The graph shows the flow of user value objects, consisting of user nodes and value object nodes.

[0066] As an example, the aforementioned execution entity can first use a named entity recognition model to perform entity recognition on the aforementioned user value object flow information set, obtaining a user entity node information set and a value object entity node information set. The named entity recognition model can be a deep neural network used to identify the user entities and user value entities included in the aforementioned user value object flow information set. For example, the named entity recognition model can be a model composed of a Bidirectional Long Short-Term Memory (BiLSTM) and a Conditional Random Field (CRF) connected in series. Then, a set of flow triples is generated for the user entity node information set, the value object entity node information set, and the aforementioned flow relationship information set. Finally, the flow triples are input into a graph database to obtain a user value object flow graph.

[0067] In some optional implementations of certain embodiments, generating a user value object flow graph based on the user value object flow information set and the flow relationship information set may include the following steps:

[0068] The first step is to preprocess the aforementioned user value object flow information set to obtain a preprocessed user value object flow information set. This preprocessing may include, but is not limited to, at least one of the following: data cleaning, format conversion, missing value handling, outlier detection, and standardization and normalization.

[0069] The second step involves filtering the preprocessed user value object circulation information set to obtain the target value object circulation information set. Specifically, the target value object circulation information in this set is selected from the preprocessed user value object circulation information set, based on the user and value object information that has been circulating for the most recent 20 days, and where the transaction amount (buy or sell attribute value) of the connection edge between the user and value object information is greater than or equal to a preset circulation attribute threshold. This preset circulation attribute threshold can be a pre-defined minimum value for the circulation attribute.

[0070] The third step involves constructing user profiles based on the aforementioned target value object circulation information set, resulting in a user circulation indicator information set. This set of user circulation indicator information can describe a user's style (user trading style) and personal preferences regarding the circulation of value objects. This user circulation indicator information set may include, but is not limited to, at least one of the following: user basic attribute values ​​(net assets), value object circulation sector information (preferred listed sector), user preference information regarding value objects (preferred industry), preference information for circulating value objects (circulating share preference), value object attribute value selection preference information (securities price preference), and value object selection ability information (stock selection ability information).

[0071] The fourth step involves extracting value object indicators from the aforementioned target value object circulation information set to obtain a value object indicator information set. The value object indicator information in this set can be information used to describe the value object. This value object indicator information set may include, but is not limited to, at least one of the following: value object derived indicator information, value object market attribute value (securities market capitalization), value object circulation and transaction attribute value (securities transaction amount), value object conversion frequency (securities turnover rate), value object price-to-earnings ratio, value object price-to-book ratio, and value object suspension status information. The aforementioned value object derived indicator information can be indicator information derived from the value object's own attribute value (price). For example, the aforementioned value object derived indicator information may include, but is not limited to, at least one of the following: the difference in the absolute value of the value object's own attribute value's rise and fall, the maximum and minimum values ​​of the value object's own attribute value within one year, and the correlation between the current value object's own attribute value and its historical maximum or minimum point.

[0072] The fifth step involves constructing triples from the aforementioned user flow indicator information set, value object indicator information set, and flow relationship information set to obtain a flow triplet set. The flow triples in this set can be data structures that represent the relationships between user flow indicator information, value object indicator information, and flow relationship information in triple form. For example, the flow triplet could be <user preference information, flow attribute value, value object type>.

[0073] Step 6: Input the aforementioned flow triplet set into the preset graph database to obtain the user value object flow graph. The preset graph database can be an existing database used to store graph data structures. For example, the preset graph database can be a Neo4j database.

[0074] Step 106: Based on the user login associated sub-graphet, perform abnormal flow linkage identification on the user value object flow graph to obtain the abnormal flow linkage associated graphet.

[0075] In some embodiments, the aforementioned execution entity can identify abnormal flow linkages in the aforementioned user value object flow graph based on the aforementioned user login association subgraph set, thereby obtaining an abnormal flow linkage association graph set. Specifically, the abnormal flow linkage association graph in the aforementioned abnormal flow linkage association graph set can be a subgraph where the value object flow relationships between various user nodes included in the user login association subgraph exhibit convergent transaction abnormal behavior. Alternatively, the aforementioned abnormal flow linkage association graph can be an association graph that only includes user nodes.

[0076] In some optional implementations of certain embodiments, the above-mentioned identification of abnormal flow linkages in the user value object flow graph based on the user login association sub-graph set to obtain an abnormal flow linkage association graph set may include the following steps:

[0077] The first step involves extracting features from the user value object node set and flow edge set included in the aforementioned user value object flow graph, resulting in a flow node feature vector set and a flow edge feature vector set. The user value object nodes in the aforementioned user value object node set can be either user nodes or value object nodes. The flow node feature vectors in the aforementioned flow node feature vector set can represent the attribute information of the user value object node set in the form of feature vectors. The flow edge feature vectors in the aforementioned flow edge feature vector set can represent the association strength and frequency between two connected user value object nodes in the form of feature vectors. In practice, the executing entity can first standardize the numerical data included in the aforementioned user value object node set and the aforementioned flow edge set to obtain a first flow node feature vector set and a first flow edge feature vector set. Then, it can perform one-hot encoding on the categorical data included in the aforementioned user value object node set and the aforementioned flow edge set to obtain a second flow node feature vector set and a second flow edge feature vector set. Finally, the feature vector sets of the first flow node, the first flow edge, the second flow node, and the second flow edge are concatenated to obtain the feature vector sets of the flow node and the flow edge.

[0078] The second step involves performing the following association graph generation steps based on the user value object graph recognition layer included in the user value object graph recognition model:

[0079] Sub-step 1: Determine the set of neighboring node feature vectors for the feature vector set of the flowing node. The user value object graph recognition model includes a multi-layer user value object graph recognition layer. This model can be a graph deep neural network model that aggregates the input flowing edge feature vector set into the flowing node feature vector set according to depth and superimposes its own flowing node feature vector set according to the importance of each node. The user value object graph recognition layer can be a graph deep neural network layer that embeds importance into the input flowing node feature vector set and the flowing edge feature vector set. The neighboring node feature vector set in the neighboring node feature vector set can be the feature vector set of the set of neighboring user value object nodes that have a one-hop connection with the user value object node. The user value object graph recognition model is trained through the following steps: First, generate a positive sample set and a negative sample set for model training. The positive sample set can be 1000 randomly selected user nodes, with user nodes having the same type of flowing edge as each user node selected as the positive sample set. The aforementioned negative sample set can be 50 user nodes randomly selected as negative samples for each user node. The training quantity for positive samples can be 1000, and the training quantity for negative samples can be 50,000. When training the user value object graph recognition model with positive samples, transition edges need to be removed to prevent data leakage. The second step involves training the model using a mini-batch method on the aforementioned training positive and negative sample sets. In this mini-batch method, each batch includes a graph consisting of one training positive sample and one negative sample. The target node set included in each training positive and negative sample is the inner target node set, and the first-order and second-order adjacency nodes of the target node set constitute a heterogeneous batch. The training parameters for the user value object graph recognition model can include: a period of 10, 1024 sample pairs per batch, a learning rate of 0.001, and a loss function that is the dot product between the sample pairs consisting of the training positive and negative samples.

[0080] Sub-step 2 involves inputting the flow edge feature vector set into the edge encoder of the user value object graph recognition layer to obtain the edge-encoded feature vector set. The user value object graph recognition layer further includes a relationship-aware attention mechanism and a graph structure fusion layer. The edge encoder can be a deep neural network that performs a high-dimensional representation mapping on the input flow edge feature vector set and embeds depth information. For example, the edge encoder can be a multilayer perceptron. The edge-encoded feature vectors in the edge-encoded feature vector set can be high-dimensional representations that include both depth and attribute information of the flow edges.

[0081] Sub-step 3 involves concatenating the edge-encoded feature vector set and the adjacency embedding feature vector set, followed by a linear transformation to obtain a concatenated transformed feature vector set. The concatenated transformed feature vectors in this set can be feature vectors obtained by linearly transforming the feature information of adjacent user value object nodes and adjacent flow edges. This linear transformation can be performed through a linear layer.

[0082] Sub-step 4 involves using a relationship-aware attention mechanism to generate a set of relational attention weights based on the concatenated transformation feature vector set and the transition node feature vector set. The relational attention weights in this set characterize the importance of each adjacent user value object node to the user value object node. This relationship-aware attention mechanism can be used to determine the different levels of importance of each adjacent user value object node to the user value object node. For example, it could be a neural network consisting of a feedforward network, a LeakyReLU activation function, and a Softmax activation function connected in series. In practice, the execution entity can first concatenate the concatenated transformation feature vector set and the transition node feature vector set to obtain a concatenated node feature vector set. Then, this concatenated node feature vector set is input into the relationship-aware attention mechanism and normalized to obtain the relational attention weight set.

[0083] Sub-step 5 involves fusing the attention weight set of association relationships and the concatenation transformation feature vector set through a graph structure fusion layer to obtain a node fusion feature vector set. This graph structure fusion layer can be a deep neural network model that fuses the input attention weight set of association relationships and the concatenation transformation feature vector set based on graph structures and adjacent nodes. For example, this graph structure fusion layer could be a graph convolutional network. The node fusion feature vectors in the node fusion feature vector set can be feature vectors of adjacent user value object nodes with different degrees of fusion influence and feature vectors of adjacent flow edges. These node fusion feature vectors can represent the information about the flow of user information to value object information. In practice, the execution entity can first perform a weighted summation of each attention weight in the attention weight set of association relationships and the corresponding concatenation transformation feature vector set in the concatenation variable feature vector set, and then accumulate the sums to obtain an attention weight fusion feature vector set. Then, this attention weight fusion feature vector set is input to the graph structure fusion layer to obtain the node fusion feature vector set.

[0084] Sub-step 6: In response to determining that the value object graph recognition layer satisfies the model layer constraints, a flow linkage anomaly association graph set is generated based on the node fusion feature vector set and the aforementioned user login association sub-graph set. The aforementioned model layer constraints may include the value object graph recognition layer being the last recognition layer in the aforementioned user value object graph recognition model.

[0085] Optionally, the above method may further include the following steps:

[0086] The first step is to determine that the above value object graph identification layer does not meet the model layer constraints, and then identify the value object graph identification layer that follows the value object graph identification layer as the value object graph identification layer.

[0087] The second step is to fuse the node feature vector set and determine it as the flow node feature vector set.

[0088] The third step involves identifying the node fusion feature vectors that have a target association relationship with each node fusion feature vector in the node fusion feature vector set as adjacent node feature vectors, thus obtaining an adjacent node feature vector set. This is then used to execute the aforementioned association graph generation step again. The target association relationship can be a one-hop connection between the user value object node corresponding to the node fusion feature vector and this connection.

[0089] In some optional implementations of certain embodiments, generating the flow linkage anomaly association graph based on the node fusion feature vector set and the user login association subgraph set may include the following steps:

[0090] The first step is to select node fusion feature vectors that represent user nodes from the above set of node fusion feature vectors to obtain the user node fusion feature vector set.

[0091] The second step is to perform the following anomaly graph generation steps for each user node fusion feature vector in the above user node fusion feature vector set:

[0092] Sub-step 1 involves determining the user node similarity between the user node fusion feature vector and each node fusion feature vector in the aforementioned node fusion feature vector set, thus obtaining a user node similarity group. The aforementioned user node similarity characterizes the degree of similarity between two corresponding user nodes in their behavior regarding the flow of value object information. This determination can be performed using the cosine similarity formula.

[0093] Sub-step 2 involves filtering the user node fusion feature vector set based on the aforementioned user node similarity group to obtain a filtered user node fusion feature vector set. This filtered user node fusion feature vector set can be either empty or non-empty. For example, the executing entity can first filter user node fusion feature vectors with a similarity greater than or equal to a preset similarity threshold from the aforementioned user node fusion feature vector set, using these as target user node fusion feature vectors to obtain the target user node fusion feature vector set. The preset similarity threshold can be a pre-defined minimum value used to determine whether there is similar value object flow behavior between user nodes corresponding to the user node fusion feature vectors. For example, the preset similarity threshold could be 0.8. Then, the top 20 target user node fusion feature vector sets, sorted by user node similarity from high to low, are selected from the target user node fusion feature vector set to obtain the filtered user node fusion feature vector set.

[0094] Sub-step 3: Determine the set of user nodes that simultaneously exist in the user node fusion feature vector set after the above filtering and the user node set included in the user login association sub-graph set, and obtain the target user node set.

[0095] Sub-step 4 involves determining the percentage of user nodes in the target user node set and the user node set included in the user login association subgraph. This percentage represents the ratio of user nodes exhibiting similar value object transfer behaviors to the total number of user nodes included in the user login association subgraph. In practice, the executing entity can determine the ratio of the number of target user nodes in the target user node set to the number of user nodes in the user node set included in the user login association subgraph as the percentage of user nodes.

[0096] Sub-step 5: In response to determining that the proportion of user nodes is greater than or equal to a preset node proportion threshold, a flow linkage anomaly correlation diagram is generated based on the aforementioned target user node set. The preset node proportion threshold can be a pre-defined critical value used to determine abnormal flow linkages. For example, the preset node proportion threshold could be 0.4.

[0097] As an example, the aforementioned executing entity can first filter out at least one target user node from the target user node set that meets a preset flow attribute value condition. This preset flow attribute value condition can be that the flow attribute value (transaction amount) of value object information between target user nodes is greater than or equal to a preset flow attribute threshold. This preset flow attribute threshold can be a pre-set maximum value for the attribute. Then, a subgraph including the at least one target user node is selected from the aforementioned user value object flow graph as a flow linkage anomaly association graph.

[0098] Furthermore, in the process of adopting technical solutions to address the technical problems mentioned in the background, the following technical issues often arise: Because the flow of value objects is dynamic, it is difficult to accurately describe the flow in time sequence, and it is also difficult to detect short-term abnormal user interaction flow behaviors, leading to missed detections. This results in low accuracy in identifying abnormal flow linkages, increases the server's flow request load, and reduces server security. A conventional solution to these technical problems is to analyze the dynamic changes in flow behavior multiple times using static graphs, and to identify anomalies by determining if the proportion of node similarity in the user value object flow graph within the corresponding user login association subgraph exceeds a preset threshold, thus obtaining an abnormal flow linkage association graph. However, this conventional solution still has the following problems: multiple analyses of static graphs result in repeated anomaly identification due to duplicate content, leading to low anomaly identification speed; fixed thresholds for anomaly identification easily lead to high false negative and high false positive rates; additionally, node similarity calculation only measures node features and does not consider the impact of heterogeneous relationships, resulting in low anomaly identification accuracy, high server flow request load, and low server security. Considering the shortcomings of the aforementioned conventional solutions, and taking into account the advantages and current state of abnormal behavior recognition technology possessed by the inventor's company, we have decided to adopt the following solution:

[0099] In some optional implementations of certain embodiments, the above-mentioned identification of abnormal flow linkages in the user value object flow graph based on the user login association sub-graph set to obtain an abnormal flow linkage association graph set may include the following steps:

[0100] The first step involves performing heterogeneous graph completion and fusion processing on the aforementioned user login association subgraph and the aforementioned user value object flow graph to obtain a heterogeneous user flow graph set. Specifically, the heterogeneous user flow graph in this set can be a graph fusion process where user nodes, value object nodes, and corresponding flow edges from the user value object flow graph are added to the user login association subgraph. In practice, the execution entity can first perform graph fusion on the corresponding subgraphs in the aforementioned user login association subgraph and the aforementioned user value object flow graph according to user nodes, obtaining a fused graph set. Then, graph disambiguation is performed on the fused graph set to obtain a disambiguated fused graph set. Finally, meta-path-based relation completion processing is performed on the disambiguated fused graph set to obtain the heterogeneous user flow graph set.

[0101] The second step involves performing temporal edge embedding on the aforementioned heterogeneous user flow graph set to obtain a temporal heterogeneous user flow graph set. This user flow temporal heterogeneous graph set can be a heterogeneous graph with temporal information embedded on a daily construction period. In practice, the execution entity can utilize ST-GCN (Spatio-Temporal Convolutional Networks) to perform temporal edge embedding on the aforementioned heterogeneous user flow graph set to obtain the user flow temporal heterogeneous graph set.

[0102] The third step involves performing meta-path fusion on the aforementioned heterogeneous user flow time-series graph to obtain a node path fusion feature vector set. The node path fusion feature vectors in this set represent the dynamic weights of the heterogeneous connection edges determined by the meta-path and the multi-dimensional attribute information of the heterogeneous nodes. In practice, the execution entity can utilize RGAT (Relation-based Graph Attention) to perform meta-path fusion on the aforementioned heterogeneous user flow time-series graph to obtain the node path fusion feature vector set.

[0103] The fourth step involves determining the cosine similarity set, adjacency distance similarity set, and global similarity set for each user node in the aforementioned heterogeneous user flow graph. The cosine similarity set can describe the local similarity between nodes with associated relationships, emphasizing explicit associations. The adjacency distance similarity set can describe the similarity of the node's neighbor structure, emphasizing contextual associations; that is, two base nodes are similar if they have similar neighbors. The global similarity set can describe the global similarity of multi-hop paths (greater than or equal to 3) or subgraph structures to capture non-linear relationships. The adjacency distance similarity can be obtained using the LINE (Large-scale Information Network Embedding) second-order loss algorithm. The global similarity can be obtained using the tensor decomposition formula.

[0104] Fifth, based on the aforementioned cosine similarity set, adjacency distance similarity set, and global similarity set, preliminary flow linkage identification is performed on the aforementioned user value object flow graph to obtain a preliminary flow linkage graph set. The preliminary flow linkage graph in the aforementioned preliminary flow linkage graph set can be a graph obtained by sampling the aforementioned user value object flow graph using an influence-oriented subgraph to retain high-weight adjacent nodes of core nodes.

[0105] As an example, the aforementioned execution entity can first perform dynamic weighted summation on the aforementioned cosine similarity set, the aforementioned adjacency distance similarity set, and the aforementioned global similarity set to obtain a multi-level similarity set of nodes. Then, using the PageRank algorithm, based on the aforementioned multi-level similarity set of nodes, a core node set is selected from the aforementioned user value object flow graph. Finally, using the eigenvector centrality algorithm, the adjacency subgraph of the aforementioned core node set is determined, resulting in a preliminary flow linkage graph set.

[0106] Step 6: Perform counterfactual verification on the causal graph set corresponding to the initial flow and linkage graph set to obtain a counterfactual verification result information set. The counterfactual verification result information in this set can characterize whether causal relationships exist in the causal graph. The causal graphs in this set can be those in the initial flow and linkage graph where causal relationships exist.

[0107] Step 7: Based on the counterfactual verification result information set mentioned above, request flow interception control is performed on the terminal device set of each user included in the above-mentioned abnormal flow association graph.

[0108] As an example, the aforementioned executing entity can first perform generative flow linkage identification on at least one initial flow linkage graph that fails verification in the aforementioned counterfactual verification result information set, obtaining a generative anomaly subgraph set. The generative anomaly subgraph in the generative anomaly subgraph set can be an initial flow linkage graph with user convergence linkage anomalies. The aforementioned generative flow linkage identification can be performed through anomaly identification via a generative adversarial network. Then, the aforementioned generative anomaly subgraph set and the at least one initial flow linkage graph that passes verification are determined as a flow linkage anomaly association graph set, and request flow interception control is performed on the terminal device set of each user included in the aforementioned flow linkage anomaly association graph set.

[0109] The above-described technical solution and its related content, as an inventive point of this disclosure, solve the technical problem mentioned in the background: "Because the circulation behavior of value objects is dynamically changing, it is difficult to accurately describe the circulation behavior in a timely manner, and it is difficult to detect short-term abnormal user-interaction circulation behavior, resulting in missed detections, leading to low accuracy in identifying abnormal circulation linkages, increasing the server's circulation request load, and reducing server security." The factors that lead to low accuracy in identifying abnormal circulation linkages, increased server circulation request load, and reduced server security are often as follows: Because the circulation behavior of value objects is dynamically changing, it is difficult to accurately describe the circulation behavior in a timely manner, and it is difficult to detect short-term abnormal user-interaction circulation behavior, resulting in missed detections, low accuracy in identifying abnormal circulation linkages, increased server circulation request load, and reduced server security. If these factors are resolved, the effect of improving the accuracy of identifying abnormal circulation linkages, reducing the server's circulation request load, and improving server security can be achieved. To achieve this effect, this disclosure first fuses the user login association subgraph set and the user value object flow graph, then performs temporal embedding and meta-path fusion. This allows for the fusion of more dimensional attribute information from each node and edge, as well as the capture of multi-scale temporal information, to accurately describe the incremental dynamic changes in flow behavior and reduce the computational overhead of anomaly identification for duplicate content. Meta-path fusion can assign weights according to meta-paths to accurately reflect the heterogeneity of the heterogeneous graph. Second, it determines the cosine similarity set, adjacency distance similarity set, and global similarity set, and performs weighted summation to dynamically integrate multi-dimensional information, facilitating the subsequent discovery of potential hidden flow linkage user groups. Then, it performs preliminary flow linkage identification through multi-level node similarity sets. Influence-guided subgraph sampling can reduce the subgraph size and decrease the computational resource consumption for subsequent anomaly identification. Subsequently, after counterfactual verification of the causal graph, generative flow linkage identification is performed. By analyzing the causal relationships in the initial flow linkage graph, falsely related transactions can be filtered out, true causal relationships can be retained, and the accuracy of identifying user group linkage anomalies can be improved. Counterfactual verification and generative anomaly identification can further improve the determination of causal relationships, reduce the false alarm rate of anomalies, and improve the accuracy of identifying abnormal flow linkages. Finally, request flow interception control is performed on the terminal device sets of each user included in the flow linkage anomaly association graph, which can effectively reduce the server's flow request load and improve server security.

[0110] Step 107: Send the flow linkage anomaly association set to the flow alarm device to control the flow alarm device to monitor and warn the flow information of the value objects of the terminal device set corresponding to the flow linkage anomaly association set, and in response to the determination that the flow alarm device has issued a warning message, perform flow interception control on the terminal device set.

[0111] In some embodiments, the executing entity may send the aforementioned flow linkage anomaly association graph to a flow alarm device to control the flow alarm device to monitor and issue early warnings for the flow information of the value objects of the terminal device set corresponding to the aforementioned flow linkage anomaly association graph, and to perform flow interception control on the aforementioned terminal device set in response to determining that the flow alarm device has issued an early warning message. The aforementioned flow alarm device may be a terminal device used to issue an abnormal alarm for identified behaviors involving convergent transactions. The aforementioned flow interception control may include, but is not limited to, at least one of the following: discarding the flow request of the terminal device, initiating a form to prohibit task submission for the flow operation of the value object corresponding to the terminal device, and modifying the device type of the terminal device in the server to an abnormal device.

[0112] Further reference Figure 4 As an implementation of the methods shown in the above figures, this disclosure provides some embodiments of a terminal device control device based on flow linkage. These device embodiments are similar to... Figure 1 Corresponding to the method embodiments shown, this terminal device control device based on flow linkage can be specifically applied to various electronic devices.

[0113] like Figure 4 As shown, a terminal device control device 400 based on flow linkage includes: an acquisition unit 401, a knowledge graph construction unit 402, a graph partitioning unit 403, a flow relationship mining unit 404, a generation unit 405, an abnormal flow linkage identification unit 406, and a flow interception control unit 407. The acquisition unit 401 is configured to acquire a user multi-source login association information set and a user value object flow information set. The knowledge graph construction unit 402 is configured to construct a knowledge graph from the aforementioned user multi-source login association information set to obtain a user device association graph. The graph partitioning unit 403 is configured to partition the aforementioned user device association graph to obtain a user login association sub-graphet. The flow relationship mining unit 404 is configured to mine flow relationships from the aforementioned user value object flow information set to obtain a flow relationship information set. The generation unit 405 is configured to generate a user value object flow graph based on the aforementioned user value object flow information set and the aforementioned flow relationship information set. The abnormal flow linkage identification unit 406 is configured to identify abnormal flow linkages in the user value object flow graph based on the aforementioned user login association sub-graph set, thereby obtaining an abnormal flow linkage association graph set. The flow interception control unit 407 is configured to: send the aforementioned abnormal flow linkage association graph set to the flow alarm device to control the flow alarm device to monitor and issue early warnings for the value object flow information of the terminal device set corresponding to the aforementioned abnormal flow linkage association graph set; and, in response to determining that the flow alarm device has issued an early warning message, to perform flow interception control on the aforementioned terminal device set.

[0114] It is understandable that the units described in the terminal equipment control device 400 based on flow linkage are related to the reference Figure 1 The steps in the described method correspond to each other. Therefore, the operations, features, and beneficial effects described above for the method also apply to the terminal equipment control device 400 based on flow linkage and the units contained therein, and will not be repeated here.

[0115] The following is for reference. Figure 5 It shows a schematic diagram of the structure of an electronic device (e.g., an electronic device) 500 suitable for implementing some embodiments of the present disclosure. Figure 5 The electronic device shown is merely an example and should not be construed as limiting the functionality and scope of the embodiments of this disclosure.

[0116] like Figure 5 As shown, electronic device 500 may include a processing unit (e.g., a central processing unit, a graphics processing unit, etc.) 501, which can perform various appropriate actions and processes according to a program stored in read-only memory (ROM) 502 or a program loaded from storage device 508 into random access memory (RAM) 503. RAM 503 also stores various programs and data required for the operation of electronic device 500. Processing unit 501, ROM 502, and RAM 503 are interconnected via bus 504. Input / output (I / O) interface 505 is also connected to bus 504.

[0117] Typically, the following devices can be connected to I / O interface 505: input devices 506 including, for example, touchscreens, touchpads, keyboards, mice, cameras, microphones, accelerometers, gyroscopes, etc.; output devices 507 including, for example, liquid crystal displays (LCDs), speakers, vibrators, etc.; storage devices 508 including, for example, magnetic tapes, hard disks, etc.; and communication devices 509. Communication device 509 allows electronic device 500 to communicate wirelessly or wiredly with other devices to exchange data. Although Figure 5 An electronic device 500 with various devices is shown; however, it should be understood that it is not required to implement or possess all of the devices shown. More or fewer devices may be implemented or possessed alternatively. Figure 5 Each box shown can represent a device or multiple devices as needed.

[0118] In particular, according to some embodiments of this disclosure, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, some embodiments of this disclosure include a computer program product comprising a computer program carried on a computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via communication device 509, or installed from storage device 508, or installed from ROM 502. When the computer program is executed by processing device 501, it performs the functions defined in the methods of some embodiments of this disclosure.

[0119] It should be noted that, in some embodiments of this disclosure, the computer-readable medium described above may be a computer-readable signal medium or a computer-readable storage medium, or any combination thereof. A computer-readable storage medium may be, for example,—but not limited to—an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of a computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof. In some embodiments of this disclosure, a computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. In some embodiments of this disclosure, a computer-readable signal medium may include a data signal propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such propagated data signals may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A computer-readable signal medium can be any computer-readable medium other than a computer-readable storage medium, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted using any suitable medium, including but not limited to: wires, optical fibers, RF (radio frequency), etc., or any suitable combination thereof.

[0120] In some implementations, clients and servers can communicate using any currently known or future-developed network protocol such as HTTP (Hypertext Transfer Protocol) and can interconnect with digital data communication (e.g., communication networks) of any form or medium. Examples of communication networks include local area networks (“LANs”), wide area networks (“WANs”), the Internet (e.g., the Internet of Things), and peer-to-peer networks (e.g., ad hoc peer-to-peer networks), as well as any currently known or future-developed networks.

[0121] The aforementioned computer-readable medium may be included in the aforementioned electronic device; or it may exist independently and not assembled into the electronic device. The aforementioned computer-readable medium carries one or more programs. When the aforementioned one or more programs are executed by the electronic device, the electronic device causes the following actions: It acquires a set of user multi-source login association information and a set of user value object flow information; it constructs a knowledge graph from the aforementioned user multi-source login association information to obtain a user device association graph; it partitions the aforementioned user device association graph to obtain a user login association sub-graphet; it mines the flow relationships from the aforementioned user value object flow information to obtain a flow relationship information set; it generates a user value object flow graph based on the aforementioned user value object flow information and the aforementioned flow relationship information set; it identifies abnormal flow linkages in the aforementioned user value object flow graph based on the aforementioned user login association sub-graphet, obtaining a flow linkage abnormal association graph set; and it sends the aforementioned flow linkage abnormal association graph set to a flow alarm device to control the flow alarm device to monitor and issue early warnings for the value object flow information of the terminal device set corresponding to the aforementioned flow linkage abnormal association graph set, and in response to determining that the flow alarm device has issued an early warning message, it performs flow interception control on the aforementioned terminal device set.

[0122] Computer program code for performing operations of some embodiments of this disclosure can be written in one or more programming languages ​​or a combination thereof, including object-oriented programming languages ​​such as Java, Smalltalk, and C++, and conventional procedural programming languages ​​such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a local area network (LAN) or a wide area network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).

[0123] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this disclosure. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.

[0124] The units described in some embodiments of this disclosure can be implemented in software or hardware. The described units can also be housed in a processor; for example, a processor may be described as including an acquisition unit, a knowledge graph construction unit, a graph partitioning unit, a flow relationship mining unit, a generation unit, an abnormal flow linkage identification unit, and a flow interception control unit. The names of these units do not necessarily limit the unit itself; for example, the acquisition unit may also be described as "a unit that acquires a set of user multi-source login association information and a set of user value object flow information."

[0125] The functions described above in this document can be performed at least in part by one or more hardware logic components. For example, exemplary types of hardware logic components that can be used, without limitation, include: field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), system-on-a-chip (SoCs), complex programmable logic devices (CPLDs), and so on.

[0126] The above description is merely a selection of preferred embodiments of this disclosure and an explanation of the technical principles employed. Those skilled in the art should understand that the scope of the invention involved in the embodiments of this disclosure is not limited to technical solutions formed by specific combinations of the above-described technical features, but should also cover other technical solutions formed by arbitrary combinations of the above-described technical features or their equivalents without departing from the above-described inventive concept. For example, technical solutions formed by substituting the above-described features with (but not limited to) technical features with similar functions disclosed in the embodiments of this disclosure.

Claims

1. A terminal device control method based on abnormal flow linkage identification, comprising: obtaining a user multi-source login association information set and a user value object flow information set; constructing a knowledge graph for the user multi-source login association information set to obtain a user device association graph; dividing the user device association graph to obtain a user login association subgraph set; mining flow relationship for the user value object flow information set to obtain a flow relationship information set; generating a user value object flow graph based on the user value object flow information set and the flow relationship information set, including: preprocessing the user value object flow information set to obtain a preprocessed user value object flow information set; filtering the preprocessed user value object flow information set to obtain a target value object flow information set; constructing a user portrait for the target value object flow information set to obtain a user flow indicator information set; extracting value object indicators from the target value object flow information set to obtain a value object indicator information set; constructing triplets from the user flow indicator information set, the value object indicator information set, and the flow relationship information set to obtain a flow triplet set; and inputting the flow triplet set into a pre-set graph database to obtain a user value object flow graph; identifying abnormal flow linkage for the user value object flow graph based on the user login association subgraph set to obtain a flow linkage abnormal association graph set, including: extracting features from a user value object node set and a flow edge set included in the user value object flow graph to obtain a flow node feature vector set and a flow edge feature vector set; based on a user value object graph identification layer included in a user value object graph identification model, performing the following association graph generation steps: determining adjacent node feature vector groups of the flow node feature vector set, wherein the user value object graph identification model includes multiple layers of user value object graph identification layers; inputting the flow edge feature vector set into an edge encoder included in the user value object graph identification layer to obtain edge encoding feature vector sets, wherein the user value object graph identification layer further includes a relationship-aware attention mechanism and a graph structure fusion layer; performing linear transformation on the edge encoding feature vector sets and the adjacent node feature vector groups after feature splicing to obtain spliced and transformed feature vector groups; generating an association relationship attention weight set based on the spliced and transformed feature vector groups and the flow node feature vector set using the relationship-aware attention mechanism; performing feature fusion on the association relationship attention weight set and the spliced and transformed feature vector groups through the graph structure fusion layer to obtain node fusion feature vector sets; in response to determining that the value object graph identification layer satisfies a model layer constraint condition, generating the flow linkage abnormal association graph set based on the node fusion feature vector sets and the user login association subgraph set. The flow linkage exception association graph set is sent to a flow linkage alarm device to control the flow linkage alarm device to monitor and warn the value object flow linkage information of a terminal device set corresponding to the flow linkage exception association graph set, and to control the flow linkage of the terminal device set in response to determining that the flow linkage alarm device sends a warning message.

2. The method of claim 1, wherein, The knowledge graph construction on the user multi-source login association information set obtains a user device association graph, including: Data fusion is performed on the user multi-source information set included in the user multi-source login association information set to obtain user login association fusion information; Fuzzy value object user information set is obtained by performing value object user fuzzy identification on the user login association fusion information; User identity disambiguation information set is obtained by performing user identity disambiguation processing on the user login association fusion information; The fuzzy value object user information set and the user identity disambiguation information set are determined as user entity information set; User device entity information set is obtained by performing user device information extraction on the value object order information set included in the user multi-source login association information set; User device association relationship information set of the user device entity information set and the user entity information set is determined; The user device association graph is generated according to the user entity information set, the user device entity information set, and the user device association relationship information set.

3. The method of claim 1, wherein, The graph division on the user device association graph obtains a user login association subgraph set, including: User device node degree set of the user device association graph is determined; User device node access sequence is determined according to the user device node degree set; Based on the user device node access sequence, the following subgraph determination steps are executed: Based on the starting user device node, the following access graph generation steps are executed: According to the user device association graph, the user device node located after the starting user device node is determined as a user device depth node, wherein the starting user device node is the node located at the initial position in the node access sequence; The user device depth node and the starting user device node are added to a preset data stack to obtain a node access stack; In response to determining that the node access stack satisfies the node depth access condition, a node access graph is generated according to the starting user device node and the user device depth node; In response to determining that the node access stack does not satisfy the node depth access condition, the user device depth node is determined as the starting user device node to execute the generation step again; In response to determining that the node unvisited sequence is empty, the obtained each node access graph is determined as the user login association subgraph set, wherein the node unvisited sequence is the user device node access sequence after removing each access sequence corresponding to each node access graph; In response to determining that the node unvisited sequence is not empty, the node unvisited sequence is determined as the user device node access sequence to execute the determination step again.

4. The method of claim 1, wherein, The method further includes: In response to determining that the value object graph identification layer does not satisfy the model layer constraint condition, the value object graph identification layer located after the value object graph identification layer is determined as the value object graph identification layer; The node fusion feature vector set is determined as a flow transfer node feature vector set; Each node fusion feature vector in the node fusion feature vector set is determined as a neighbor node feature vector, and a neighbor node feature vector set is obtained, so as to execute the association graph generation step again.

5. The method of claim 1, wherein, The user node fusion feature vector set is obtained by screening the node fusion feature vector set to represent a user node; For each user node fusion feature vector in the user node fusion feature vector set, the following abnormal association graph generation step is executed: The user node similarity between the user node fusion feature vector and each node fusion feature vector in the node fusion feature vector set is determined to obtain a user node similarity group; The user node fusion feature vector set is screened according to the user node similarity group to obtain a screened user node fusion feature vector set; A target user node set is obtained by determining a user node set that exists in both the user node set corresponding to the screened user node fusion feature vector set and the user node set included in the user login association subgraph set; A user node proportion value is determined by determining the proportion of the target user node set in the user node set included in the user login association subgraph set; In response to determining that the user node proportion value is greater than or equal to a preset node proportion threshold, an abnormal flow transfer linkage association graph is generated according to the target user node set.

6. A terminal device control apparatus based on abnormal flow transfer linkage identification, comprising: An acquisition unit configured to acquire a user multi-source login association information set and a user value object flow transfer information set; A knowledge graph construction unit configured to construct a user device association graph based on the user multi-source login association information set; A graph division unit configured to divide the user device association graph to obtain a user login association subgraph set; A flow transfer relationship mining unit configured to mine flow transfer relationship information from the user value object flow transfer information set; A generation unit configured to generate a user value object flow transfer graph based on the user value object flow transfer information set and the flow transfer relationship information set, including: preprocessing the user value object flow transfer information set to obtain a preprocessed user value object flow transfer information set; screening the preprocessed user value object flow transfer information set to obtain a target value object flow transfer information set; constructing a user portrait based on the target value object flow transfer information set to obtain a user flow transfer indicator information set; extracting a value object indicator from the target value object flow transfer information set to obtain a value object indicator information set; constructing a triple based on the user flow transfer indicator information set, the value object indicator information set, and the flow transfer relationship information set to obtain a flow transfer triple set; and inputting the flow transfer triple set into a preset graph database to obtain a user value object flow transfer graph. ​ The abnormal flow linkage identification unit is configured to perform abnormal flow linkage identification on the user value object flow graph according to the user login association subgraph set, to obtain a flow linkage abnormal association graph set, including: performing feature extraction on the user value object node set and the flow edge set included in the user value object flow graph, to obtain a flow node feature vector set and a flow edge feature vector set; based on a user value object graph identification layer included in a user value object graph identification model, performing the following association graph generation steps: determining an adjacent node feature vector group set of the flow node feature vector set, wherein the user value object graph identification model includes multiple layers of user value object graph identification layers; inputting the flow edge feature vector set to an edge encoder included in the user value object graph identification layer to obtain an edge encoding feature vector set, wherein the user value object graph identification layer further includes a relationship perception attention mechanism and a graph structure fusion layer; performing feature splicing on the edge encoding feature vector set and the adjacent node feature vector group set, and then performing linear transformation to obtain a spliced and transformed feature vector group set; generating an association relationship attention weight set according to the spliced and transformed feature vector group set and the flow node feature vector set by using the relationship perception attention mechanism; performing feature fusion on the association relationship attention weight set and the spliced and transformed feature vector group set by the graph structure fusion layer, to obtain a node fusion feature vector set; in response to determining that the value object graph identification layer satisfies a model layer constraint condition, generating the flow linkage abnormal association graph set according to the node fusion feature vector set and the user login association subgraph set; The flow interception control unit is configured to send the flow linkage abnormal association graph set to a flow alarm device, to control the flow alarm device to perform monitoring and early warning processing on value object flow information of a terminal device set corresponding to the flow linkage abnormal association graph set, and in response to determining that the flow alarm device sends an early warning information, to perform flow interception control on the terminal device set. 7.An electronic device, comprising: one or more processors; a storage device having stored thereon one or more programs, when the one or more programs are executed by the one or more processors, the one or more processors implement the method according to any one of claims 1-5.

8. A computer readable medium having stored thereon a computer program, wherein, The computer program is executed by the processor to implement the method according to any one of claims 1-5.

Citation Information

Patent Citations

  • Value object information sending method, device and equipment and computer readable medium

    CN116662672A

  • Information interception method and system based on abnormal traffic identification

    CN116684182A