Risk prediction method based on mobile terminal equipment
By acquiring multi-source data from mobile terminal devices, dividing dynamic and static feature sets, and establishing a risk prediction model with a two-way feature coupling mechanism, the problem of the inability to integrate multi-source data in traditional methods is solved, and more accurate risk prediction and timely risk warning are achieved.
Patent Information
- Application Number
- CN202511584382.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-31
- Publication Date
- 2025-12-02
- Estimated Expiration
- 2045-10-31
AI Technical Summary
Traditional mobile terminal risk prediction methods cannot fully integrate multi-source data such as user operation behavior sequences, device status change records, and environmental parameter change trajectories, making it difficult to adapt to the complex and ever-changing risk situations in mobile terminal usage scenarios, resulting in inaccurate risk prediction.
By acquiring historical behavior data of mobile terminal devices, dynamic input feature sets and static interference feature sets are divided, and a dynamic risk prediction model with a two-way feature coupling mechanism is established. Combined with a sliding time window and interference feature fluctuation spectrum, a real-time risk warning signal is generated.
It enables comprehensive analysis of multi-dimensional data from mobile terminal devices, improving the accuracy and reliability of risk prediction. It can promptly capture dynamic changes in devices and the environment, providing more targeted and timely risk alerts.
Smart Images

Figure CN121052829A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of data security technology, specifically a risk prediction method based on mobile terminal devices. Background Technology
[0002] In today's digital age, mobile devices such as smartphones and tablets have become indispensable tools in people's lives. Their penetration rate is extremely high, with almost everyone owning one or even multiple devices. With the help of mobile devices, people can conveniently conduct various online activities, covering many areas such as social communication, online shopping, mobile payment, online office work, and entertainment. For example, people can stay in touch with family and friends anytime, anywhere through social software such as WeChat and QQ; shop on e-commerce platforms such as Taobao and JD.com, selecting global goods without leaving home; easily complete daily consumption and online transfers using convenient online payment methods such as Alipay and WeChat Pay; conduct remote work and online meetings through various office software such as DingTalk and Tencent Meeting, breaking the limitations of time and space; and enrich their leisure time by watching videos and playing games on platforms such as Douyin and iQiyi.
[0003] While these online activities bring convenience, they also come with numerous risks. Take online payments as an example: when users make payments, they may encounter malware attacks. Malware may hide in seemingly legitimate applications, stealing users' payment account information, passwords, verification codes, and other critical information during the payment process, leading to the theft of funds. Some criminals may also send phishing links or impersonate bank customer service representatives to trick users into clicking links and entering payment information, thereby defrauding them of money. Mobile devices themselves may also be at risk of attack. Hackers may exploit vulnerabilities in the device's system to infiltrate it and obtain various types of data stored on the device, such as contact information, photos, and documents, causing data leaks and posing a serious threat to users' privacy and financial security.
[0004] Faced with these risks, traditional risk prediction methods have revealed numerous shortcomings. In terms of data utilization, traditional methods often only analyze single types of data, failing to fully integrate multi-source data such as user operation behavior sequences, device status change records, and environmental parameter change trajectories. For example, they may only focus on user payment behavior data, ignoring the impact of factors such as the device's network environment and system status on payment risk. Regarding model construction, traditional models are mostly static, making it difficult to adapt to the complex and ever-changing risk situations in mobile terminal usage scenarios. Mobile terminal usage scenarios are constantly changing; users may perform various operations in different locations and network environments, and risk factors change accordingly. Traditional models cannot capture these dynamic changes in a timely manner and make accurate risk predictions.
[0005] With the increasing prevalence of mobile devices in people's lives and work, their security needs are growing daily. However, the limitations of traditional risk prediction methods make them insufficient to meet the current complex security situation. Therefore, there is an urgent need for a new risk prediction method that can fully utilize multi-source data, comprehensively analyze mobile device usage, and construct a dynamic risk prediction model to adapt to constantly changing risk scenarios and effectively protect the security of users' various online activities on mobile devices. The risk prediction method based on mobile terminal devices proposed in this invention arises from this background. Summary of the Invention
[0006] The purpose of this invention is to provide a risk prediction method based on mobile terminal devices to solve the problems mentioned in the background art.
[0007] To achieve the above objectives, the present invention provides a risk prediction method based on mobile terminal devices, the method comprising: Acquire a set of historical behavior data of a mobile terminal device, wherein the set of historical behavior data includes user operation behavior sequences, device status change records, and environmental parameter change trajectories; Based on the historical behavior data set, the dynamic input feature set and the static interference feature set are divided. The dynamic input feature set consists of the real-time updated user operation behavior sequence, while the static interference feature set is generated by fusing device status change records and environmental parameter change trajectories. A dynamic risk prediction model is established, using the dynamic input feature set as the model input layer and the static interference feature set as the model hidden layer adjustment parameters. The risk probability value is output through a two-way feature coupling mechanism. A sliding time window is used to segment the static interference feature set, extract the fluctuation period and frequency distribution of the interference features within each time window, and generate an interference feature fluctuation map. Based on the interference characteristic fluctuation spectrum matching the interference characteristic state at the current time point, and combined with the risk probability value output by the dynamic risk prediction model, a real-time risk warning signal is generated.
[0008] Preferably, the acquisition of the historical behavior data set of the mobile terminal device specifically includes: Extract user operation behavior sequences from the device's local logs. These sequences include application startup time, screen touch trajectories, and network request frequency. Collect device hardware status change records, including battery temperature fluctuation curve, CPU load peak and memory usage change range; The trajectory of environmental parameter changes is obtained through a sensor interface. The trajectory of environmental parameter changes includes geographical location offset, ambient light intensity gradient and surrounding wireless signal strength matrix.
[0009] Preferably, the step of dividing the dynamic input feature set and the static interference feature set according to the historical behavior data set includes: The user operation behavior sequence is timestamped and the operation behavior segments corresponding to abnormal timestamps are removed. The continuous operation behavior segments are merged into a dynamic input feature set. The records of changes in device hardware status are superimposed with the trajectory of changes in environmental parameters over time. The mean-variance ratio of the superimposed features is calculated, and features with a variance ratio lower than the threshold are selected to form a static interference feature set.
[0010] Preferably, the establishment of the dynamic risk prediction model includes: Construct a neural network architecture that includes an input layer, a hidden layer, and an output layer. The number of nodes in the input layer is consistent with the dimension of the dynamic input feature set, while the number of nodes in the hidden layer is dynamically adjusted by the dimension of the static perturbation feature set. An interference feature attenuation factor is embedded in the hidden layer, and the weight of the interference feature attenuation factor is adaptively updated according to the fluctuation period of the static interference feature set. The risk probability value is calculated through the output layer. The risk probability value is the result of a nonlinear combination of the input layer features and the hidden layer adjustment parameters.
[0011] Preferably, the step of segmenting the static interference feature set using a sliding time window includes: Set a fixed-length time window and slide along the time axis with a preset step size to extract a subset of static interference features; For each subset, a frequency domain transformation is performed, and the period corresponding to the peak value of the frequency domain energy distribution is extracted as the interference feature fluctuation period; Count the frequency of feature values exceeding the historical mean within each subset, generate a frequency distribution histogram, and mark it as the frequency distribution pattern of interference features.
[0012] Preferably, the generation of the interference feature fluctuation spectrum includes: The fluctuation period and frequency distribution of the interference characteristics are spliced together in the order of time windows to form a two-dimensional fluctuation time series matrix. The two-dimensional fluctuation time series matrix is normalized to eliminate the dimensional differences between different feature dimensions; A heatmap is plotted based on the normalization results. The horizontal axis of the heatmap represents the time window number, the vertical axis represents the type of interference feature, and the color level represents the intensity of the fluctuation.
[0013] Preferably, the step of matching the interference feature state at the current time point based on the interference feature fluctuation map includes: Obtain the time window number to which the current time point belongs, and extract the wave intensity vector corresponding to the number from the interference feature wave map; Calculate the cosine similarity between the wave intensity vector and the historical window vector, and select the historical window with the highest similarity as the matching result; Mark the interference feature state corresponding to the matching result as the current interference feature state.
[0014] Preferably, the step of generating a real-time risk warning signal by combining the risk probability value output by the dynamic risk prediction model includes: Input the current state of the interference features into the hidden layer of the dynamic risk prediction model to update the hidden layer adjustment parameters; The risk probability value is recalculated based on the updated model parameters, and an early warning signal is triggered when the risk probability value exceeds the dynamic threshold. The dynamic threshold is determined by the moving average of historical risk probability values and the fluctuation intensity of the current disturbance characteristic state.
[0015] Preferably, the process for determining the dynamic threshold includes: Take the risk probability value sequence of the most recent N time windows and calculate its exponentially weighted moving average as the benchmark threshold; The baseline threshold is adjusted according to the fluctuation intensity of the current interference characteristic state. For every preset unit increase in fluctuation intensity, the baseline threshold is reduced by a fixed proportion. The adjusted baseline threshold is used as the dynamic threshold at the current time point.
[0016] Preferably, the processing after triggering the warning signal includes: Record snapshots of the dynamic input feature set and static interference feature set at the moment the warning signal is triggered; The snapshot data is matched with the historical early warning case library by feature matching, and the historical case number with the highest matching degree is output. The corresponding handling strategy is retrieved based on the historical case number and loaded into the execution queue of the mobile terminal device.
[0017] Compared with the prior art, the beneficial effects of the present invention are: This method comprehensively utilizes historical behavioral data sets, encompassing user operation behavior sequences, device status change records, and environmental parameter change trajectories. Unlike traditional methods that rely on only a single type of data, this multi-source data fusion provides a more comprehensive and multi-dimensional reflection of the mobile terminal device's usage status and surrounding environment. Taking mobile payment as an example, traditional methods may only focus on the payment operation itself, while this method not only analyzes the steps and frequency of user operation behavior sequences but also combines device status change records such as battery level and network connection status during payment, as well as environmental parameter changes such as geographical location and surrounding network signal strength, to comprehensively assess the risks during the payment process. By analyzing this multi-dimensional data, more potential risk factors can be uncovered, significantly improving the accuracy of risk prediction and more accurately identifying potential security threats.
[0018] The dynamic risk prediction model constructed in this invention is innovative. It effectively fuses dynamic input feature sets and static interference feature sets through a bidirectional feature coupling mechanism. The dynamic input feature set consists of real-time updated user operation behavior sequences, which can promptly reflect the latest operational dynamics of users. The static interference feature set is generated by fusing device state change records and environmental parameter change trajectories, reflecting the impact of the relatively stable state of equipment and environment on risk. In traditional models, it is often difficult to fully consider the interrelationships between these dynamic and static factors, resulting in limitations in risk prediction. However, the bidirectional feature coupling mechanism of this model allows dynamic and static features to complement and influence each other. When users perform sensitive information transmission operations in different network environments, the model can simultaneously explore the intrinsic correlations between risk factors based on changes in user operation behavior sequences and factors such as the stability and security of the network environment (a part of the static interference feature set), thereby making more accurate risk predictions and greatly improving the accuracy and reliability of predictions.
[0019] A sliding time window is used to segment the static interference feature set, and the fluctuation period and frequency distribution of the interference features within each time window are extracted to generate an interference feature fluctuation map. This process enables dynamic analysis of interference features, allowing real-time capture of changes in device status and environmental parameters. When abnormal fluctuations occur in device power consumption or frequent changes in network signal strength, the interference feature fluctuation map can promptly reflect these changes. Based on this map, the interference feature status at the current time point is matched, and combined with the risk probability value output by the dynamic risk prediction model, a real-time risk warning signal can be generated quickly and accurately. Compared with traditional risk warning methods, this method no longer simply issues warnings based on preset fixed rules, but rather provides users with more targeted and timely risk alerts based on real-time dynamic changes in devices and the environment, as well as the risk probability derived from comprehensive analysis. This allows users to take appropriate preventative measures as soon as a risk occurs, effectively reducing the losses caused by the risk. Attached Figure Description
[0020] Figure 1 This is a schematic diagram illustrating the working principle of the risk prediction method based on mobile terminal devices described in this invention. Figure 2 A flowchart for obtaining a collection of historical behavior data from mobile terminal devices; Figure 3 A flowchart for establishing a dynamic risk prediction model. Detailed Implementation
[0021] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0022] Please see Figure 1This invention provides a risk prediction method based on mobile terminal devices. The method integrates user behavior data, device status, and environmental parameters to achieve accurate risk warnings. The historical behavior data set of the mobile terminal device is the fundamental data source for the method, containing user operation behavior sequences, device status change records, and environmental parameter change trajectories. The division between dynamic input feature sets and static interference feature sets is based on data update frequency and impact degree. The dynamic input feature set consists of real-time changing user operation behavior sequences, while the static interference feature set is generated by fusing relatively stable device status change records and environmental parameter change trajectories. The dynamic risk prediction model is designed with a two-way feature coupling mechanism. The dynamic input feature set serves as the model input layer, transmitting real-time behavior patterns, while the static interference feature set serves as the model hidden layer, adjusting parameters and introducing external interference factors. The sliding time window is applied to the static interference feature set; the sliding process extracts a subset of features and analyzes fluctuation patterns. The generation of the interference feature fluctuation spectrum depends on the periodicity and frequency analysis within the time window, and the spectrum visually presents the historical change patterns of the interference features. The interference feature status matching operation at the current time point is implemented based on the similarity calculation of the fluctuation spectrum. The matching result is combined with the risk probability value output by the model to trigger a warning signal.
[0023] Example 1: See Figure 2 The historical behavior data set of mobile terminal devices forms the data foundation of the entire risk prediction method. The completeness and accuracy of the historical behavior data set directly affect the reliability of subsequent feature engineering and model prediction. The data acquisition process begins with a systematic scan and analysis of the device's local logs. The device's local logs serve as a raw data warehouse recording user interactions with the device, containing event records arranged in chronological order. User operation behavior sequences are extracted from these log entries. The extraction logic for user operation behavior sequences focuses on identifying user interaction events with clear start and end points, such as an application usage session starting from when the application icon is clicked to launch and ending when the user switches to another application or locks the screen. Application launch duration records the duration of each application from launch to exit. Screen touch trajectory captures the user's continuous operations on the touchscreen. The screen touch trajectory is stored in the form of time-series coordinate points, including press, move, and release events. Network request frequency counts the number of data communications initiated to the server within a specific time interval. Network request frequency is categorized according to different network protocol ports and application processes.
[0024] The collection of device hardware status change records relies on the underlying hardware monitoring interfaces provided by the mobile terminal operating system. These interfaces read and record the operating parameters of key hardware components at a fixed sampling frequency. Battery temperature fluctuation curves are continuously measured by the device's built-in thermistor. Each data point in the battery temperature fluctuation curve includes a timestamp and the corresponding Celsius temperature value. CPU load peaks are obtained by reading the system load file, recording the maximum percentage of the processor in an active state per unit time. Memory usage change ranges are defined by monitoring changes in available memory, recording the minimum and maximum memory usage over a period of time. Obtaining environmental parameter change trajectories requires accessing various integrated sensor hardware within the device. Sensor interfaces periodically read data according to a preset sampling rate. Geographic location offset is derived from GPS receiver or network base station positioning data, calculating the straight-line distance between two consecutive positioning points. Ambient light intensity gradients are measured by a light sensor, calculating the rate of change of ambient light intensity per unit time. The surrounding wireless signal strength matrix is obtained by scanning visible access points through the wireless network adapter, recording the service set identifier and corresponding signal strength indication value for each access point.
[0025] The historical behavior data set is stored using a time-series database structure. Each data record is accompanied by a high-precision timestamp derived from the device's system clock, ensuring a unified time base for all data sources. The preprocessing stage of the user operation behavior sequence includes a data cleaning step, designed to remove invalid or erroneous records, such as duplicate events caused by system failures, ghost clicks with unusually short durations, and network request packets that are clearly outside the reasonable range. The coordinate sequence of screen touch trajectories undergoes smoothing filtering to eliminate coordinate point jitter caused by finger tremors or sensor noise. Data points recorded for device hardware state changes may experience sampling loss due to system resource contention; these missing data points are filled using linear interpolation algorithms to maintain the continuity of the time series. Sensor readings for environmental parameter change trajectories are susceptible to transient interference; for example, geographic location data may jump due to signal obstruction, and ambient light intensity may abruptly change due to brief obstructions. These outliers are identified and corrected using a sliding window statistical method, replacing significantly deviated peak values with the median of the data within the window.
[0026] The process of dividing historical behavior data sets into dynamic input feature sets and static interference feature sets is performed at the back end of the data preprocessing pipeline. The division is based on the update frequency of feature values and their potential impact patterns on risk events. User operation behavior sequences undergo timestamp alignment, using millisecond-level precision of the system clock as a benchmark. Timestamps from all data sources are synchronized and corrected, taking into account minor clock drift that may exist between different data acquisition modules. Operation behavior segments corresponding to abnormal timestamps are identified and removed. Criteria for judging abnormal timestamps include timestamps significantly ahead of or behind system time, timestamp sequences exhibiting non-monotonic increase (i.e., later events have smaller timestamps), and time intervals between adjacent events exceeding the upper limit of normal human interaction reaction time (e.g., set to 30 seconds). Continuous operation behavior segments are merged into a dynamic input feature set. The merging logic for continuous operation behavior segments is based on a time interval threshold between events. Multiple discrete operation events with time intervals less than a set threshold (e.g., 2 seconds) are aggregated into a meaningful user session segment. This dynamic input feature set characterizes the user's real-time, high-frequency changing interaction intentions and behavioral habits.
[0027] Device status change records and environmental parameter change trajectories are overlaid and fused along the time dimension. This overlay operation aligns data streams from different physical sources on the time axis, forming a multi-dimensional composite feature vector. Each valid time point corresponds to a feature vector, and each dimension of the vector represents a device status or environmental parameter reading. The mean-variance ratio of the overlaid features is calculated within a sliding time window, with the window size set large enough to capture short-term fluctuations in the features. For each feature dimension within the window, its arithmetic mean and variance are calculated, and then the variance is divided by the mean to obtain the variance ratio for that feature. Features with variance ratios below a preset threshold are selected to form a static interference feature set. The threshold is chosen based on statistical analysis of historical data distribution, such as using the median or a certain percentile of all feature variance ratios as the dividing line. Features with low variance ratios indicate that their values are relatively stable and change slowly over time, typically corresponding to the basic operating state of the device or a relatively constant environmental background. Although these static interference feature sets do not directly reflect the user's immediate intent, they serve as contextual information and play an important modulating role in risk probability. The partitioning results of the dynamic input feature set and the static interference feature set are persistently stored in the form of a feature index table. The feature index table records the name of each feature variable, the type of the set it belongs to, the latest data update timestamp, and the statistics used for partitioning. This partitioning process is periodic; as new data continues to flow in, the feature index table is updated regularly to ensure that the partitioning of the feature set can adapt to long-term drift that may occur in the data distribution.
[0028] Example 2: See Figure 3The dynamic risk prediction model is built upon a customized neural network architecture. This architecture needs to handle two different types of data streams: dynamic input feature sets and static interference feature sets. The neural network architecture includes an input layer, hidden layers, and an output layer. The number of nodes in the input layer is strictly consistent with the dimension of the dynamic input feature set. Each input layer node receives real-time values for a specific feature dimension from the dynamic input feature set. The number of nodes in the hidden layer is dynamically adjusted by the dimension of the static interference feature set. This adjustment mechanism is implemented through a mapping function, which converts the vector length of the static interference feature set into the number of nodes required for the hidden layer. The activation function of the hidden layer is a nonlinear function with saturation characteristics to prevent gradient explosion. An interference feature decay factor is embedded in the hidden layer. This decay factor is introduced to quantify the timeliness of the impact of the static interference feature set on the current risk prediction. The weight update process of the interference feature decay factor is synchronized with the fluctuation period of the static interference feature set. A longer fluctuation period indicates a slower change in the interference feature, and its weight on the current moment is correspondingly reduced. The weight calculation uses an exponential decay function, with the decay coefficient inversely proportional to the fluctuation period. The output layer calculates the risk probability value. This calculation involves matrix multiplication of the input layer feature vector with the hidden layer parameters modulated by a decay factor. The result is mapped to a zero-to-one probability space via a logistic function. A bidirectional feature coupling mechanism is implemented during the model's forward propagation. The values of the static disturbance feature set are not used as direct input features but rather as adjustment parameters to modulate the biases of the hidden layer neurons. This allows the same set of dynamic input features to produce different risk probability outputs under different static disturbance backgrounds.
[0029] The model training phase utilizes labeled historical risk event data, including a large number of normal behavior samples and known risk behavior samples. The training process employs an error backpropagation algorithm, with the loss function defined as the cross-entropy between the predicted risk probability value and the true label. Model parameters are initialized using random numbers following a Gaussian distribution, and the number of training iterations is determined based on an early stopping strategy on the validation set. The trained dynamic risk prediction model is capable of handling the combined influence of dynamic input feature sets and static interference feature sets; during the model inference phase, only a single forward propagation calculation is needed to output the risk probability value. The operation of segmenting the static interference feature set using a sliding time window is fundamental to analyzing the temporal patterns of interference features. Setting a fixed-length time window requires consideration of data acquisition frequency and feature change rate; a window length that is too short cannot capture the complete fluctuation cycle, while a window length that is too long will introduce excessive historical noise. The window length is set to cover hundreds of data sampling points, sufficient to include multiple typical fluctuation cycles. A preset step size is used to slide and truncate a subset of static interference features along the time axis. The step size is set smaller than the window length to generate overlapping window sequences, ensuring smooth transitions between consecutive windows and avoiding abrupt changes. The static interference feature subset captured by each window is a two-dimensional matrix, where the rows of the matrix correspond to time points and the columns correspond to different dimensions of the static interference features.
[0030] For each subset, a frequency domain transformation is performed. The Fast Fourier Transform (FFT) algorithm converts the time-domain feature sequence to a frequency-domain representation. The FFT decomposes the time series into sinusoidal components of different frequencies, and the output is a complex sequence whose magnitude represents the energy of each frequency component. The period corresponding to the peak of the frequency domain energy distribution is used as the fluctuation period of the interference feature. A peak detection algorithm scans the frequency domain energy spectrum to find local maxima, and converts the frequency components corresponding to these maxima into time periods. The frequency of feature values exceeding the historical mean within each subset is counted. The historical mean is calculated based on the entire training dataset and represents the long-term average level of the feature. The frequency counting process iterates through each time point in the window, counting the number of times the feature value exceeds the historical mean. A frequency distribution histogram is generated and marked as the frequency distribution pattern of the interference feature. The horizontal axis of the histogram divides the frequency into several equally wide intervals, and the vertical axis records the number of feature dimensions appearing in each interval. The frequency distribution pattern is extracted from the morphological features of the histogram, such as unimodal, bimodal, or uniform distribution patterns, each corresponding to different interference feature behavior characteristics.
[0031] All feature subsets captured by the sliding time window constitute a time-series sample library, which stores the analysis results of each window in chronological order. The window sliding process is continuous; as new data points enter the system, the oldest data points are removed from the window, maintaining the timeliness of the data within the window. The analysis results of each window include the fluctuation period and frequency distribution patterns of the interference features. These intermediate results are stored in a data structure for subsequent map generation. Window parameters such as length and step size can be adjusted according to the actual application scenario; different parameter settings will affect the granularity of fluctuation pattern analysis. The sliding window mechanism enables the system to continuously track the evolution trend of the static interference feature set, providing a data foundation for real-time state matching.
[0032] Example 3: The generation process of the interference feature fluctuation map begins with the integration of the sliding time window analysis results. The fluctuation period and frequency distribution patterns of the interference features are spliced together according to the time window order. The splicing operation combines the fluctuation period value and frequency distribution value corresponding to each time window into a feature vector. The dimension of the feature vector is equal to the number of static interference feature types analyzed. The construction of the two-dimensional fluctuation time series matrix uses the time window number as the row index and the interference feature type as the column index. Each element in the matrix is filled with the fluctuation intensity quantification value corresponding to the window and feature type. The fluctuation intensity quantification value is obtained by comprehensively calculating the significance of the fluctuation period and the deviation of the frequency distribution. The calculation process involves the fusion of multiple indicators of the feature sequence within the window.
[0033] Normalization is applied to two-dimensional fluctuation time series matrices to eliminate dimensional differences. The normalization process uses a minimum-maximum scaling method to linearly transform each element value in the matrix to the [0,1] interval. For any element value in the matrix... Its normalized value Calculated using the following formula:
[0034] in: This represents the original fluctuation intensity value of the j-th type of disturbance feature in the i-th time window. This represents the minimum value of the characteristic fluctuation intensity of the j-th type of disturbance across all time windows. This represents the maximum value of the characteristic fluctuation intensity of the j-th type of disturbance across all time windows. This represents the normalized fluctuation intensity value. The normalized two-dimensional fluctuation time series matrix eliminates the bias caused by the different original numerical ranges of different feature types, making the fluctuation intensity between different features comparable.
[0035] A heatmap is generated based on the normalization results. The horizontal axis of the heatmap labels the consecutive time window numbers, and the vertical axis lists the names of all static interference feature types. The heatmap uses a gradient color mapping from cool to warm tones, with low fluctuation intensity values mapped to blue and high fluctuation intensity values mapped to red. Each pixel block in the heatmap corresponds to a specific time window and the normalized fluctuation intensity value of a specific interference feature. The color depth intuitively reflects the activity change pattern of the interference feature at historical time points. The generated interference feature fluctuation map is stored in image file format, while the corresponding normalized matrix data is retained for subsequent numerical calculations. The update mechanism of the interference feature fluctuation map is synchronized with the sliding time window. Whenever a new time window is analyzed, the map is appended with the latest data points and re-rendered.
[0036] The process of matching the state of interference features at the current time point relies on querying and calculating the similarity of the interference feature fluctuation map. The time window number to which the current time point belongs is obtained. The calculation of the time window number is based on the arithmetic operation of the current system timestamp and the sliding window parameters. The numbering rule is to divide the current timestamp by the window step size and take the integer part; the result is the window number to which the current time point falls. The corresponding fluctuation intensity vector is extracted from the interference feature fluctuation map. The fluctuation intensity vector is a multi-dimensional vector, and its components represent the normalized fluctuation intensity of various interference features within the current time window. The cosine similarity between the fluctuation intensity vector and the historical window vector is calculated. The historical window vector refers to the sequence of fluctuation intensity vectors corresponding to all historical time windows earlier than the current window in the interference feature fluctuation map.
[0037] Cosine similarity measures the similarity of two vectors in direction, with a value ranging from -1 to 1. A value closer to 1 indicates that the two vectors are more aligned in direction. For the current wave intensity vector... and a certain historical fluctuation intensity vector cosine similarity The data is calculated using the vector dot product and modulus. The historical window with the highest similarity is selected as the matching result. The matching result is a specific historical time window number, and the interference feature fluctuation pattern of this window is most similar to that of the current window. The interference feature state corresponding to the matching result is marked as the current interference feature state. The current interference feature state contains complete state information such as the interference feature fluctuation cycle and frequency distribution pattern extracted from the matched historical window. After the state matching process is completed, the current interference feature state is encapsulated into a data structure, ready to be input into the hidden layer of the dynamic risk prediction model. The historical record of the matching operation is saved to track the long-term trend of the matching pattern and evaluate the effectiveness of the matching algorithm. The entire matching process is designed to find the interference feature background most similar to the current situation from historical data, thereby providing more accurate contextual information for risk prediction. The maintenance of the interference feature fluctuation map includes regularly archiving historical data and controlling the data size of the map to ensure that query efficiency does not decrease over time. The performance optimization of the matching algorithm can be achieved by building an index structure for the fluctuation vector, such as using a spatial partitioning tree to accelerate the nearest neighbor search process. The accuracy of the current interference characteristics can be indirectly assessed by comparing its predictive performance with the actual occurrence of risk events.
[0038] Example 4: The risk probability value output by the dynamic risk prediction model is combined with the current interference feature state to generate a real-time risk warning signal. The current interference feature state is input into the hidden layer of the dynamic risk prediction model. The hidden layer adjustment parameters are updated according to the fluctuation period and frequency distribution data contained in the current interference feature state. The update operation modifies the bias weights of the hidden layer neurons, and the adjustment magnitude of the bias weights is proportional to the fluctuation intensity of the current interference feature state. The risk probability value is recalculated based on the updated model parameters. The recalculation process performs a complete forward propagation. The value of the dynamic input feature set is passed through the input layer, processed by the adjusted hidden layer, and finally generates a new risk probability value in the output layer. When the risk probability value exceeds the dynamic threshold, a warning signal is triggered. The triggering condition of the warning signal is a Boolean logic judgment that compares the real-time calculated risk probability value with the value of the dynamic threshold. The dynamic threshold is jointly determined by the moving average of historical risk probability values and the fluctuation intensity of the current interference feature state. The adaptive mechanism of the dynamic threshold enables the warning system to maintain stable performance under different interference backgrounds.
[0039] The dynamic threshold determination process includes historical data statistics and real-time parameter adjustment. The risk probability value sequence of the most recent N time windows is taken. The value of the number of time windows N affects the threshold's response speed to recent trends; a smaller N value makes the threshold more sensitive to changes in risk probability. The risk probability value sequence is retrieved from the model output log in chronological order. The sequence data contains all risk probability values output by the model within N consecutive complete time windows. Its exponentially weighted moving average is calculated as the baseline threshold. The exponentially weighted moving average calculation assigns higher weight to recent data, and the weight decay factor λ controls the decay rate of historical data. The baseline threshold represents the average level of risk probability within the recent window and is the basic value for dynamic threshold calculation. The baseline threshold is adjusted according to the fluctuation intensity of the current disturbance feature state. The fluctuation intensity is directly read from the current disturbance feature state data and is a normalized scalar value. For every preset unit increase in fluctuation intensity, the baseline threshold is correspondingly reduced by a fixed proportion. The preset unit is set to 0.1, and the fixed proportion is set to 5% of the baseline threshold. The adjusted baseline threshold serves as the dynamic threshold for the current time point and is immediately used for subsequent risk probability comparison and judgment after the dynamic threshold calculation is completed. For specific parameter configurations in the dynamic threshold adjustment process, please refer to Table 1.
[0040] Table 1: Dynamic Threshold Adjustment Parameter Configuration Parameter name Parameter symbol Value Parameter Description Number of time windows N 20 Number of consecutive time windows used to calculate the baseline threshold Weight decay factor λ 0.3 The weighting coefficient of recent data in the calculation of exponentially weighted moving average Unit of fluctuation intensity ΔI 0.1 Basic adjustment unit of fluctuation intensity Threshold reduction ratio η 5% The percentage decrease in the benchmark threshold for each unit increase in fluctuation intensity Minimum threshold lower limit <![CDATA[T min ]]> 0.2 The minimum value that can be set for dynamic thresholds The processing flow after a warning signal is triggered includes signal generation and transmission. The content structure of the warning signal includes signal type, trigger timestamp, risk level assessment, and a summary of associated features. Signal types distinguish between instantaneous and continuous warnings; instantaneous warnings address single threshold exceedance events, while continuous warnings address threshold exceedances across multiple consecutive time windows. Risk level assessment is based on the magnitude of the risk probability value exceeding the dynamic threshold; the greater the exceedance, the higher the risk level. The summary of associated features records key feature values from the dynamic input feature set and static interference feature set when the warning is triggered; these feature values aid in subsequent analysis of the cause of the warning. The warning signal is transmitted to the user interface layer and decision module via a message queue mechanism on the mobile terminal device. The message queue ensures the reliability and order of signal transmission. After receiving the warning signal, the user interface layer presents visual or auditory alerts to the user according to a preset display strategy. The decision module may trigger automatic protective measures, such as temporarily restricting certain sensitive operations.
[0041] The generation frequency of real-time risk warning signals is consistent with the calculation cycle of the dynamic risk prediction model. A complete risk assessment and warning check process is executed after each time window. Historical warning data is persistently stored, with a storage format containing complete contextual information for subsequent auditing and analysis. The false alarm filtering mechanism for warning signals is implemented by comparing the warning status of consecutive time windows; isolated single threshold exceedances may be marked as an observation state instead of immediately triggering an active warning. The sensitivity of the warning system can be calibrated by adjusting the parameters in the dynamic threshold calculation to adapt to different application scenarios and security requirements. Warning response time is a key performance indicator; the entire processing flow from data acquisition to warning signal generation must be completed within a specified time delay to ensure real-time risk identification and response. Warning signal validity management ensures that expired warning statuses are promptly cleared, preventing the system from being in an unnecessary state of alert for extended periods. The warning feedback mechanism allows users to evaluate the accuracy of warnings; this evaluation data is used to optimize the dynamic threshold algorithm and model parameters.
[0042] Example 5: Snapshot recording of dynamic input feature sets and static interference feature sets is initiated immediately upon triggering the warning signal. The dynamic input feature set snapshot captures the instantaneous state of all active user operation sequences at the current time, including but not limited to a list of running applications, the coordinate sequence of the current screen touch trajectory, and the network request types and target addresses within the last minute. The static interference feature set snapshot records real-time readings of device hardware state changes and environmental parameter changes, such as the current battery temperature, the instantaneous load percentage of each CPU core, available memory capacity, GPS positioning coordinates, ambient light sensor values, and a list of all scanned Wi-Fi signal strengths. Snapshot data is stored in a structured binary format. Each snapshot file contains a fixed-length header containing the timestamp of snapshot generation, the mobile terminal device's unique identifier, the snapshot version number, and a data checksum. The body of the snapshot file stores various feature values in a predetermined field order. Numerical features use a fixed-point number format to save storage space, while categorical features are compressed using dictionary encoding.
[0043] The historical early warning case library is a pre-built database of risk events. Each record in the library contains complete feature snapshot data, risk event tags, handling strategy codes, and handling result feedback. The library is built by collecting historical security event data; each case represents a confirmed risk scenario and its corresponding response. Case data comes from multiple sources, including verified threat events reported by mobile devices, attack test data simulated in security labs, and anonymized records of security events encountered by real users. Snapshot data is matched against the historical early warning case library using a feature matching algorithm. The matching algorithm combines all feature values from the current snapshot into a high-dimensional feature vector, while also representing each case in the historical early warning case library as a feature vector of the same dimension. The feature matching process calculates the Euclidean distance between the current snapshot feature vector and the feature vector of each historical case; a smaller distance value indicates a higher similarity between the two feature vectors. The historical case number with the highest matching degree is output. The matching degree is obtained by converting the reciprocal of the distance value, and the conversion formula ensures that the matching degree value is between zero and one. During the matching degree calculation process, different feature dimensions are weighted. The weighting coefficients are dynamically adjusted according to the importance of the features in historical risk identification. Important features are given higher weights to improve matching accuracy.
[0044] Historical case numbers retrieve corresponding handling strategies, which are stored in a strategy library as executable scripts. The strategy library employs versioning, with each strategy corresponding to a unique strategy identifier and version number. The content of the handling strategies is designed based on risk type and severity, including but not limited to process termination commands, network connection blocking rules, enhanced user authentication requirements, system setting modification commands, and security scan trigger conditions. The handling strategies are loaded into the execution queue of the mobile terminal device. The execution queue is a priority task scheduling system, with high-risk handling strategies executed first. The execution queue management module monitors the strategy execution status, recording execution logs for successfully executed strategies and initiating retry mechanisms or degradation schemes for failed strategies. During strategy execution, an interaction channel with the user is maintained; significant handling actions require user confirmation before execution to avoid a decline in user experience due to excessive automation. A specific example is as follows: Suppose a mobile terminal device triggers an alert signal at 10:05:23 AM. At this time, a dynamic input feature set snapshot records that the user is frequently switching between banking and social applications, the screen touch trajectory exhibits an abnormally rapid swiping pattern, and the network request frequency is significantly higher than usual, with target addresses involving multiple overseas IPs. A snapshot of the static interference feature set shows that the device's battery temperature is at a high level of 45 degrees Celsius, the CPU load consistently exceeds 80%, the available memory space is less than 100MB, the device is located in an area with unusual activity, and the surrounding Wi-Fi signal strength fluctuates drastically. The system immediately combines these snapshot data into a feature vector and calculates its similarity with 500 known risk cases in the historical warning case library. After processing by the matching algorithm, it is found that the current features have a similarity of 0.93 with case number CASE-2023-0478, which records a similar phishing attack that occurred last year. The system automatically retrieves the handling strategy associated with case number CASE-2023-0478, which includes immediately terminating suspicious network connections, forcibly enabling two-factor authentication, and popping up a security warning window to inform the user of the current risk. These handling strategies are loaded into a high-priority position in the execution queue and begin sequential execution within 200 milliseconds. During execution, the system continuously monitors the effect of the strategy execution. If it detects that the user's normal operation is excessively blocked, it automatically adjusts the strategy strength or requests manual intervention.
[0045] The processing flow after an early warning signal is triggered includes a complete closed-loop management mechanism, with detailed operation logs generated at each stage. These logs record the snapshot data storage path, input and output parameters for feature matching calculations, loading time of the handling strategy, and execution result status codes. Log data is used for subsequent analysis of the accuracy and timeliness of early warning processing, supporting continuous system optimization. The case library update mechanism allows the inclusion of newly confirmed risk events and their handling experience, ensuring the system can cope with new threats. The dynamic loading mechanism for handling strategies supports remote updates, allowing security teams to deploy new protection strategies promptly without requiring terminal application version upgrades. The entire processing flow is designed with mobile terminal device resource constraints in mind. Snapshot data uses differential compression technology to reduce storage consumption, feature matching algorithms optimize computational complexity to control energy consumption, and a timeout interrupt mechanism is introduced to prevent resource deadlock during strategy execution. In multi-terminal collaborative scenarios, the early warning processing results of a single device can be securely shared with other devices under the same user account, forming a joint prevention and control security protection system.
[0046] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus.
[0047] Although embodiments of the invention have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the appended claims and their equivalents.
Claims
1. A risk prediction method based on mobile terminal devices, characterized in that, Includes the following steps: Acquire a set of historical behavior data of a mobile terminal device, wherein the set of historical behavior data includes user operation behavior sequences, device status change records, and environmental parameter change trajectories; Based on the historical behavior data set, the dynamic input feature set and the static interference feature set are divided. The dynamic input feature set consists of the real-time updated user operation behavior sequence, while the static interference feature set is generated by fusing device status change records and environmental parameter change trajectories. A dynamic risk prediction model is established, using the dynamic input feature set as the model input layer and the static interference feature set as the model hidden layer adjustment parameters. The risk probability value is output through a two-way feature coupling mechanism. A sliding time window is used to segment the static interference feature set, extract the fluctuation period and frequency distribution of the interference features within each time window, and generate an interference feature fluctuation map. Based on the interference characteristic fluctuation spectrum matching the interference characteristic state at the current time point, and combined with the risk probability value output by the dynamic risk prediction model, a real-time risk warning signal is generated.
2. The risk prediction method based on mobile terminal devices according to claim 1, characterized in that, The acquisition of the historical behavior data set of the mobile terminal device specifically includes: Extract user operation behavior sequences from the device's local logs. These sequences include application startup time, screen touch trajectories, and network request frequency. Collect device hardware status change records, including battery temperature fluctuation curve, CPU load peak and memory usage change range; The trajectory of environmental parameter changes is obtained through a sensor interface. The trajectory of environmental parameter changes includes geographical location offset, ambient light intensity gradient and surrounding wireless signal strength matrix.
3. The risk prediction method based on mobile terminal devices according to claim 2, characterized in that, The process of dividing the dynamic input feature set and the static interference feature set based on the historical behavior data set includes: The user operation behavior sequence is timestamped and the operation behavior segments corresponding to abnormal timestamps are removed. The continuous operation behavior segments are merged into a dynamic input feature set. The records of changes in device hardware status are superimposed with the trajectory of changes in environmental parameters over time. The mean-variance ratio of the superimposed features is calculated, and features with a variance ratio lower than the threshold are selected to form a static interference feature set.
4. The risk prediction method based on mobile terminal devices according to claim 3, characterized in that, The establishment of the dynamic risk prediction model includes: Construct a neural network architecture that includes an input layer, a hidden layer, and an output layer. The number of nodes in the input layer is consistent with the dimension of the dynamic input feature set, while the number of nodes in the hidden layer is dynamically adjusted by the dimension of the static perturbation feature set. An interference feature attenuation factor is embedded in the hidden layer, and the weight of the interference feature attenuation factor is adaptively updated according to the fluctuation period of the static interference feature set. The risk probability value is calculated through the output layer. The risk probability value is the result of a nonlinear combination of the input layer features and the hidden layer adjustment parameters.
5. The risk prediction method based on mobile terminal devices according to claim 4, characterized in that, The step of segmenting and truncating the static interference feature set using a sliding time window includes: Set a fixed-length time window and slide along the time axis with a preset step size to extract a subset of static interference features; For each subset, a frequency domain transformation is performed, and the period corresponding to the peak value of the frequency domain energy distribution is extracted as the interference feature fluctuation period; Count the frequency of feature values exceeding the historical mean within each subset, generate a frequency distribution histogram, and mark it as the frequency distribution pattern of interference features.
6. The risk prediction method based on mobile terminal devices according to claim 5, characterized in that, The generated interference feature fluctuation spectrum includes: The fluctuation period and frequency distribution of the interference characteristics are spliced together in the order of time windows to form a two-dimensional fluctuation time series matrix. The two-dimensional fluctuation time series matrix is normalized to eliminate the dimensional differences between different feature dimensions; A heatmap is plotted based on the normalization results. The horizontal axis of the heatmap represents the time window number, the vertical axis represents the type of interference feature, and the color level represents the intensity of the fluctuation.
7. The risk prediction method based on mobile terminal devices according to claim 6, characterized in that, The interference feature state at the current time point is matched based on the interference feature fluctuation map, including: Obtain the time window number to which the current time point belongs, and extract the wave intensity vector corresponding to the number from the interference feature wave map; Calculate the cosine similarity between the wave intensity vector and the historical window vector, and select the historical window with the highest similarity as the matching result; Mark the interference feature state corresponding to the matching result as the current interference feature state.
8. The risk prediction method based on mobile terminal devices according to claim 7, characterized in that, The process of generating a real-time risk warning signal by combining the risk probability value output by the dynamic risk prediction model includes: Input the current state of the interference features into the hidden layer of the dynamic risk prediction model to update the hidden layer adjustment parameters; The risk probability value is recalculated based on the updated model parameters, and an early warning signal is triggered when the risk probability value exceeds the dynamic threshold. The dynamic threshold is determined by the moving average of historical risk probability values and the fluctuation intensity of the current disturbance characteristic state.
9. The risk prediction method based on mobile terminal devices according to claim 8, characterized in that, The process for determining the dynamic threshold includes: Take the risk probability value sequence of the most recent N time windows and calculate its exponentially weighted moving average as the benchmark threshold; The baseline threshold is adjusted according to the fluctuation intensity of the current interference characteristic state. For every preset unit increase in fluctuation intensity, the baseline threshold is reduced by a fixed proportion. The adjusted baseline threshold is used as the dynamic threshold at the current time point.
10. The risk prediction method based on mobile terminal devices according to claim 9, characterized in that, The processing after triggering the warning signal includes: Record snapshots of the dynamic input feature set and static interference feature set at the moment the warning signal is triggered; The snapshot data is matched with the historical early warning case library by feature matching, and the historical case number with the highest matching degree is output. The corresponding handling strategy is retrieved based on the historical case number and loaded into the execution queue of the mobile terminal device.
Citation Information
Patent Citations
Risk prediction method and device, electronic equipment and computer readable storage medium
CN114676927A
Risk account prediction method and device and electronic equipment
CN115049484A
Account risk prediction method and system based on machine learning
CN120450708A
General field risk early warning method, system and equipment based on data processing and medium
CN120707269A
Method and system for monitoring operation state of automatic control platform
CN120856587A
Cited By
Card swiping early warning method and system for intelligent terminal transaction environment
CN122155823A
A card swiping early warning method and system for an intelligent terminal transaction environment
CN122155823B