Fraud behavior identification method, device and equipment, medium and product
By constructing an anti-fraud knowledge graph to analyze dialogue data, identify fraud state nodes, and predict transition probabilities, the real-time and accuracy issues of fraud behavior identification in existing technologies are solved, achieving the effect of timely intervention and blocking of transactions.
Patent Information
- Application Number
- CN202511397958.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-28
- Publication Date
- 2026-01-09
Smart Images

Figure CN121309060A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of communication security, in particular to a fraud behavior identification method, device, equipment, medium and product. BACKGROUND
[0002] Current anti-fraud technologies mainly rely on keyword matching, black list library, behavior rule engine or simple classification model, and lack the modeling ability of dynamic evolution path of fraud behavior. The existing solutions mainly include two categories: one is the knowledge extraction and graph construction around the fraud case, which improves the visualization and classification ability of fraud patterns; the second is the relationship reasoning based on the graph, which is used to identify potential fraud associated accounts or speech patterns. But the existing technologies have significant defects: 1) unable to identify the fraud stage in real time and predict the next action; 2) unstructured disassembly of user psychological state and fraud induction node, resulting in intervention lag or strategy mismatch; 3) mostly offline analysis, which cannot meet the needs of dynamic fraud behavior identification and intervention. SUMMARY
[0003] The fraud behavior identification method, device, equipment, medium and product provided by the embodiments of the present application realize the rapid and dynamic identification of the current fraud stage, and predict the strategy that the fraudster may take next, so as to intervene in time, block the transaction or remind the user.
[0004] In a first aspect, the present embodiment provides a fraud behavior identification method, which comprises:
[0005] analyzing the current conversation data to determine a current fraud state node corresponding to the current conversation data;
[0006] determining a current fraud probability that the user is successfully defrauded according to a target fraud behavior state chain associated with the current fraud state node in a pre-constructed anti-fraud knowledge graph, wherein the anti-fraud knowledge graph takes a plurality of fraud state nodes as nodes and takes behavior features corresponding to the fraud state nodes as edges, and each fraud state node contains a transition probability from the fraud state node to a next fraud state node;
[0007] if the current fraud probability is greater than a preset fraud probability threshold, it is determined that there is a fraud behavior, and the user is warned of fraud.
[0008] In a second aspect, the present embodiment provides a fraud behavior identification device, which comprises:
[0009] a node determination module configured to analyze the current conversation data to determine a current fraud state node corresponding to the current conversation data;
[0010] The probability determination module is used to determine the current fraud probability of a user being successfully defrauded based on the target fraud behavior state chain associated with the current fraud state node in the pre-constructed anti-fraud knowledge graph. The anti-fraud knowledge graph uses multiple fraud state nodes as nodes and the behavioral features corresponding to the fraud state nodes as edges. Each fraud state node contains the transition probability of itself jumping to the next fraud state node.
[0011] The early warning module is used to determine that fraudulent behavior exists and to issue a fraud warning to the user if the current fraud probability is greater than a preset fraud probability threshold.
[0012] Thirdly, this embodiment provides an electronic device, including:
[0013] At least one processor; and
[0014] A memory communicatively connected to the at least one processor; wherein,
[0015] The memory stores a computer program that can be executed by the at least one processor, which enables the at least one processor to perform the fraud detection method according to any embodiment of the present invention.
[0016] Fourthly, this embodiment provides a computer-readable storage medium storing computer instructions that cause a processor to execute and implement the fraud behavior identification method as described in any embodiment of the present invention.
[0017] Fifthly, embodiments of the present invention also provide a computer program product, the computer program product including a computer program, which, when executed by a processor, implements the fraud behavior identification method as described in any embodiment of the present invention.
[0018] This invention provides a method, apparatus, device, medium, and product for identifying fraudulent behavior. The method includes: first, parsing current dialogue data to determine the current fraud state node corresponding to the current dialogue data; then, determining the current fraud probability of a user being successfully defrauded based on the target fraud behavior state chain associated with the current fraud state node in a pre-constructed anti-fraud knowledge graph. The anti-fraud knowledge graph uses multiple fraud state nodes as nodes and the corresponding behavioral features as edges. Each fraud state node includes its own transition probability to the next fraud state node; finally, if the current fraud probability is greater than a preset fraud probability threshold, fraudulent behavior is determined, and a fraud warning is issued to the user. This technical solution utilizes a knowledge graph to achieve structured modeling of the entire fraud behavior evolution path and locates the fraud state node in real-time dialogue. Combined with the constructed anti-fraud knowledge graph, it assists frontline anti-fraud personnel or systems in dynamically identifying fraud behavior stages and predicting the next fraudulent action during calls or text interactions, thereby timely intervention, blocking transactions, or alerting users, improving the accuracy and efficiency of fraud identification.
[0019] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of the present invention, nor is it intended to limit the scope of the invention. Other features of the invention will become readily apparent from the following description. Attached Figure Description
[0020] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0021] Figure 1 This is a flowchart illustrating a fraud behavior identification method provided in Embodiment 1 of the present invention;
[0022] Figure 2 This is an example diagram of loading some fraud status nodes and behavioral characteristics into an anti-fraud knowledge graph provided in Embodiment 1 of the present invention;
[0023] Figure 3 This is a flowchart illustrating another fraud behavior identification method provided in Embodiment 2 of the present invention;
[0024] Figure 4 This is a schematic diagram of a fraud behavior identification device provided in Embodiment 3 of the present invention;
[0025] Figure 5 This is a schematic diagram of the structure of an electronic device provided in Embodiment 4 of the present invention. Detailed Implementation
[0026] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.
[0027] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0028] It is understood that before using the technical solutions disclosed in the various embodiments of the present invention, users should be informed of the types, scope of use, and usage scenarios of the personal information involved in the present invention and their authorization should be obtained in accordance with relevant laws and regulations through appropriate means.
[0029] For example, upon receiving a user's active request, a prompt message is sent to the user to explicitly inform them that the requested operation will require the acquisition and use of the user's personal information. This allows the user to independently choose whether to provide personal information to the software or hardware, such as the electronic device, application program, server, or storage medium executing the operation of this invention, based on the prompt message.
[0030] As an optional but non-limiting implementation, in response to a user's active request, sending a prompt message to the user can be done via a pop-up window, where the prompt message can be presented in text format. Furthermore, the pop-up window can also include a selection control allowing the user to choose "agree" or "disagree" to provide personal information to the electronic device.
[0031] It is understood that the above notification and user authorization process is merely illustrative and does not constitute a limitation on the implementation of the present invention. Other methods that comply with relevant laws and regulations may also be applied to the implementation of the present invention.
[0032] Analysis of existing anti-fraud technologies reveals that current methods fail to meet the needs of dynamic fraud identification and intervention: 1) Most methods focus on the static collection of fraud knowledge or case clustering, lacking modeling of the "stage evolution path" of fraudulent behavior. This makes it impossible to determine the current stage and predict the next action in real-time during the dialogue between the user and the fraudster. 2) Existing methods do not structurally break down the "user's psychological state" or the "fraudster's inducement state" during the fraud process, such as key nodes like "establishing trust → creating panic → inducing transfers → cutting off contact," leading to delayed intervention or mismatched strategies. 3) Current anti-fraud systems mostly rely on offline analysis or post-event tracing, lacking the ability to combine real-time dialogue content and dynamically calculate the probability of behavioral shifts, making it difficult to achieve precise intervention during fraud. Therefore, a method is needed to address these issues.
[0033] Example 1
[0034] Figure 1 This is a flowchart illustrating a fraud behavior identification method provided in Embodiment 1 of the present invention. This method is applicable to situations where fraud behavior needs to be identified. The method can be executed by a fraud behavior identification device, which can be implemented in hardware and / or software and is generally integrated into an electronic device.
[0035] like Figure 1 As shown, the fraud identification method provided in this embodiment can specifically include the following steps:
[0036] S101. Analyze the current dialogue data to determine the current fraud status node corresponding to the current dialogue data.
[0037] Specifically, the current dialogue data can be understood as the real-time dialogue data between the user and the fraudster at the current moment. Fraud status nodes can be understood as the status nodes in the process of a fraudulent event. For example, by analyzing the dialogue data of various fraud events, fraud status nodes can be identified as including impersonating someone to start the conversation, creating panic, inducing isolation, requesting money transfers, cutting off contact, user hesitation, user refusal, and successful fraud. Each fraud status node corresponds to leading phrases or textual characteristics.
[0038] In this embodiment, after acquiring the current dialogue data, the data can be parsed, segmented, and then the user's current state node can be extracted and recorded as the current fraud state node. This embodiment does not specifically limit the parsing method of the current dialogue data; for example, a general large model can be used to analyze and extract the current fraud state node, or a trained model can be used to extract the current fraud state node from the current dialogue data. For example, the current fraud state node is represented as... .
[0039] It should be noted that if the current dialogue data is analyzed and it is determined that it does not contain any fraud status nodes, it means that there is no fraudulent activity at present, and there is no need to issue a fraud warning to the user.
[0040] S102. Based on the target fraud behavior state chain associated with the current fraud state node in the pre-constructed anti-fraud knowledge graph, determine the current fraud probability that the user has been successfully defrauded.
[0041] In the anti-fraud knowledge graph, multiple fraud state nodes are used as nodes, and the behavioral features corresponding to the fraud state nodes are used as edges. Each fraud state node contains the transition probability of itself jumping to the next fraud state node.
[0042] In this embodiment, a knowledge graph, denoted as the anti-fraud knowledge graph, is pre-constructed, containing all potential fraud state nodes and the leading phrases or behavioral characteristics between fraud state nodes during the evolution of fraudulent behavior. Each fraud state node related to a fraud event is used as a node, and the corresponding behavioral characteristics of the fraud state nodes are used as edges to construct the anti-fraud knowledge graph. The above steps are equivalent to building the framework of the anti-fraud knowledge graph. The following steps will populate the anti-fraud knowledge graph with specific data. Historical fraud sample data is collected and parsed to construct fraud behavior state chains corresponding to the historical fraud sample data. Specifically, a fraud behavior state chain can be understood as a path connecting the fraud state nodes contained in a fraud event according to the order in which the nodes occurred. Each fraud behavior state chain is loaded into the anti-fraud knowledge graph, and the transition probability of each fraud state node jumping to the next fraud state node is determined. Each transition probability is added to the corresponding fraud state node in the anti-fraud knowledge graph to obtain the updated anti-fraud knowledge graph.
[0043] In this embodiment, the node position of the current fraud state node in the anti-fraud knowledge graph is determined. Based on the outgoing edges of the current fraud state node, the associated fraud behavior state chains are determined and denoted as target fraud behavior state chains. Each fraud state node in the anti-fraud knowledge graph is associated with a corresponding jump probability from the current fraud state node to the next fraud state node. For each target fraud behavior state chain, the jump frequency of the current fraud state node and each subsequent fraud state node is obtained. Then, for each target fraud behavior state chain, the probability of the entire chain is calculated as the probability that the user is successfully defrauded by the target fraud behavior state chain. The fraud probabilities corresponding to each target fraud behavior state chain are added together, and the sum is the probability that the user is successfully defrauded, denoted as the current fraud probability.
[0044] S103. If the current fraud probability is greater than the preset fraud probability threshold, then it is determined that there is fraudulent behavior, and a fraud warning is issued to the user.
[0045] In this embodiment, the fraud probability threshold can be set based on actual experience or according to warning requirements. A lower threshold can be set when warning requirements are high, and a higher threshold can be set when warning requirements are low. If the current fraud probability is greater than the preset threshold, fraud is confirmed, and a fraud warning is issued to the user. If the current fraud probability is less than or equal to the preset threshold, the probability of successful fraud is low, and no fraud warning is needed. Since the user's status changes frequently in practice, the latest user status is used to determine if fraud has occurred.
[0046] The above technical solution uses knowledge graphs to achieve structured modeling of the evolution path of all fraudulent behaviors and locates the state node of fraud from real-time dialogue. Combined with the constructed anti-fraud knowledge graph, it assists front-line anti-fraud personnel or systems in dynamically identifying the stage of fraudulent behavior and predicting the next fraudulent action during calls or text interactions, thereby intervening in time, blocking transactions or reminding users, and improving the accuracy of fraud identification and response efficiency.
[0047] As an optional embodiment of the present invention, based on the above embodiments, the steps for constructing the anti-fraud knowledge graph can be optimized, including:
[0048] a1) Construct an anti-fraud knowledge graph by taking each fraud status node related to the fraud event as a node and the behavioral features corresponding to the fraud status node as edges.
[0049] In this embodiment, based on various fraud events, all potential fraud state nodes and the leading phrases or behavioral characteristics between fraud state nodes are determined during the evolution of fraud behavior. Each fraud state node related to a fraud event is used as a node, and the corresponding behavioral characteristics of the fraud state node are used as edges to construct a graph, which is denoted as an anti-fraud knowledge graph. For example, Table 1 is a sample table of the original data of the anti-fraud knowledge graph provided in Embodiment 1 of the present invention. As shown in Table 1, the data sample is anonymized. Fraud state nodes include impersonating XX to start a conversation, creating panic, inducing isolation, etc., and each fraud state node has a corresponding leading phrase or behavioral characteristic.
[0050] Table 1
[0051]
[0052] Continuing from the example above, the table above shows some potential fraud status nodes and inducement phrases or behavioral characteristics. These potential fraud status nodes and behavioral characteristics can be obtained through analysis and currently cover mainstream fraud types such as impersonation, fake order rebates, fake investments, and impersonation of customer service. Among them, there are 187 status nodes for impersonation and 926 inducement phrases; there are 215 status nodes for fake order rebates and 1103 phrases. Other fraud types can be expanded according to specific scenarios. For example, a fraud event can be analyzed as a typical path chain: "Impersonating XX to start" → "Creating panic" → "Inducing isolation" → "Requesting transfers" → "Scam successful".
[0053] It is understandable that the constructed anti-fraud knowledge graph contains one type of node, "fraud status node," and one type of edge, "leading language / behavioral characteristics," which are collectively referred to as behavioral characteristics in this embodiment. For ease of understanding, after loading the example data in Table 1 into the anti-fraud knowledge graph, the overall graph structure is as follows: Figure 2 As shown, Figure 2 This is an example diagram of a fraud knowledge graph containing partial fraud state nodes and behavioral characteristics, provided in Embodiment 1 of the present invention. Figure 2 As shown, the fraud status nodes include: impersonating XX to start, creating panic, inducing isolation, requesting money transfer, cutting off contact, user hesitation, and successful fraud. Each fraud status node corresponds to a behavioral characteristic. For example, the behavioral characteristic corresponding to the fraud status node of creating panic is "This is XX, you are suspected of money laundering and need to cooperate with the investigation."
[0054] b1) Collect historical fraud sample data, parse the historical fraud sample data, and construct the fraud behavior state chain corresponding to the historical fraud sample data.
[0055] The above steps essentially establish the framework of an anti-fraud knowledge graph. The following steps will populate this knowledge graph with specific data. A fraud behavior state chain can be understood as a path connecting the fraud state nodes of a fraud event in chronological order, including the starting state node, intermediate state nodes, ending state node, and behavioral characteristics. First, a large amount of fraud data from historical periods is collected. This data can be either audio or text data; there are no specific restrictions. All this data is converted to text data as historical fraud sample data. Then, this historical fraud sample data is parsed, extracting the fraud state nodes and corresponding fraud behavior characteristics of each fraud event. These fraud state nodes and their corresponding behavioral characteristics are then arranged in chronological order to form the fraud behavior state chain of the fraud event.
[0056] For example, a historical fraud sample data, namely the text transcribed from the conversation during the fraud process, is shown below: Sample data number 001, data content is:
[0057] Scammers: Hello, this is the XX Anti-Fraud Center. Our system has detected that your bank cards are suspected of money laundering…
[0058] User: Huh? That can't be right, I've never done that before…
[0059] Fraudster: Case number X-2025-0087, transferred to XX, if not handled within 24 hours, a nationwide arrest warrant will be issued…
[0060] User: What should I do then?
[0061] Scammers: Add XX QQ now, and he will guide you through the process. Remember, this is a state secret; you must not tell anyone…
[0062] User: Okay, I'll add...
[0063] Scammers: First, download the "Security Protection" APP, enter your bank card number and verification code, and the system will freeze your funds for review...
[0064] As a specific implementation, the step of parsing the historical fraud sample data and constructing the fraud behavior state chain corresponding to the historical fraud sample data includes:
[0065] b11) Construct the extracted state chain prompt words.
[0066] In this embodiment, prompt words are constructed for extracting fraudulent state nodes and behavioral features from dialogue data, and these prompt words are denoted as extraction state chain prompt words. For example, the constructed extraction state chain prompt words are as follows:
[0067] You are a fraud conversation analysis tool. Please extract the fraud behavior state stream according to the following rules:
[0068] 1) The extracted entity state names must strictly originate from the specified entity state library to ensure the accuracy and consistency of the state names.
[0069] 2) The output format is a table. The table must contain two columns: "Status Node" and "Corresponding User Dialogue Text Segment", clearly showing the correspondence between each status node and the corresponding text segment.
[0070] 3) User dialogue text needs to be segmented reasonably to ensure that each segment accurately corresponds to a state node, avoiding ambiguous segmentation or mismatched state nodes.
[0071] b12) Input the extracted state chain prompt words and the historical fraud sample data into the large model for processing, so that the large model can extract each fraud state node contained in each fraud event and the behavioral features corresponding to each fraud state node from the historical fraud sample data.
[0072] In this embodiment, a general large model is used to extract fraud state nodes and fraud behavior features. For example, mainstream large model APIs can be directly called to extract user states from the fully aggregated transcribed text library. The state library is the collection of all user states in Table 1. Due to its large scale and involvement of some business-sensitive content, it will not be elaborated here. The main advantage of using a large model is that it can segment the dialogue text between fraudsters and users through the model's understanding capabilities, automatically associate and identify user states, and construct user state chains. For example, Table 2 is an example table of data results parsed by the large model provided in Embodiment 1 of this invention. As shown in Table 2, a certain historical fraud sample data is parsed, the dialogue is segmented, and then the customer state is extracted based on the segmented dialogue to obtain fraud state nodes. The specific contents are shown in the following table, which will not be elaborated here.
[0073] Table 2
[0074]
[0075] b13) For each fraud incident, the fraud state nodes included in the fraud incident and the behavioral characteristics corresponding to each fraud state are arranged in the order of occurrence of the nodes to form the fraud behavior state chain of the fraud incident.
[0076] In this embodiment, after parsing the historical fraud sample data of each fraud event, the fraud state nodes contained in the fraud event and the behavioral characteristics corresponding to each fraud state are obtained. According to the order in which the nodes occur, a fraud behavior state chain of the fraud event is formed.
[0077] Taking Table 2 as an example, the state chain of the model output is "Impersonating XX to start → Creating panic → Inducing isolation → Requesting transfer". After parsing the full set of historical fraud sample data, each text will generate a similar state chain as described above.
[0078] The above technical solution specifies the steps for determining the state chain of fraudulent behavior. By leveraging the understanding capabilities of large models, it segments the dialogue text between fraudsters and users, automatically identifies the user's state, and constructs the state chain of fraudulent behavior, providing basic data for the construction of a fraud knowledge graph.
[0079] c1) Load each of the fraud behavior state chains into the anti-fraud knowledge graph and determine the transition probability of each fraud state node jumping to the next fraud state node.
[0080] In this embodiment, historical fraudulent call recordings or chat texts need to be parsed using a large model to extract the fraudulent behavior state flow and calculate the transition frequency between states. After loading all fraudulent behavior state chains into the anti-fraud knowledge graph, the actual jump frequencies between different state chains are obtained. With the jump frequencies between different state nodes, the higher the jump frequency, the stronger the connection between the two state nodes. For example, the jump frequency from "creating panic" to "inducing isolation" is 4 times. The purpose of this step is to quantify the transition probability of the entire state chain based on these jump frequencies, providing data support for real-time fraud identification. The calculation of transition probability is essentially a path analysis process, which enables the system to predict the probability of a user being "successfully defrauded" from their current state, assisting relevant departments in making optimal handling decisions.
[0081] As a specific implementation, the step of loading each fraud behavior state chain into the anti-fraud knowledge graph and determining the transition probability of each fraud state node jumping to the next fraud state node can be optimized, including:
[0082] c11) Load the state chains of each fraudulent behavior into the anti-fraud knowledge graph.
[0083] In this embodiment, the entire fraud behavior state chain is loaded into the anti-fraud knowledge graph. This is equivalent to adding the jump data between different fraud state nodes to the fraud state nodes of the anti-fraud knowledge graph.
[0084] c12) For each fraud state node, determine the first jump frequency for the fraud state node to jump to any next fraud state node.
[0085] In this embodiment, a probabilistic model is constructed. A Markov chain model is used to quantify the transition probabilities between state nodes. This model assumes that state transitions are memoryless (i.e., the next state depends only on the current state), and is suitable for stochastic processes of user state changes. The probability calculation formula is:
[0086] ,in, Indicates from the state node Transfer to state node The probability, From the state node Transfer to state node Jump frequency, It is a state node The sum of jump frequencies of all outgoing edges.
[0087] This formula is used to construct a transition probability matrix, where each element represents the probability value between each pair of fraudulent state nodes.
[0088] Referring to the above probability model, for each fraud state node, the jump frequency from the fraud state node to any next fraud state node is determined and denoted as the first jump frequency. For example, the "induced isolation → request for transfer" occurred 85 times.
[0089] c13) Determine the second jump frequency for the fraud state node to jump to all the next fraud state nodes.
[0090] Continuing with the above probability model, the sum of the jump frequencies of all outgoing edges of the fraudulent state node is denoted as the second jump frequency. Continuing with the example above, the total number of outgoing edges for "induced isolation" is 100.
[0091] c14) The first jump frequency is divided by the second jump frequency to obtain the transition probability of the fraud state node jumping to any next fraud state node.
[0092] Continuing with the above probability model, we divide the first jump frequency by the second jump frequency to obtain the transition probability of a fraudulent state node jumping to any next fraudulent state node. For example, if "induced isolation → request for transfer" occurs 85 times, and the total number of outgoing edges for "induced isolation" is 100, then the transition probability is 0.85, and P(induced isolation → request for transfer) = 85 / 100 = 0.85.
[0093] The above technical solution specifies the steps for determining the transition probability between fraud status nodes, providing basic data for whether to issue a fraud warning later.
[0094] d1) Add each of the aforementioned transition probabilities to the fraud status node corresponding to the anti-fraud knowledge graph to obtain the updated anti-fraud knowledge graph.
[0095] In this embodiment, the calculated transition probabilities are stored in a graph database and integrated with the constructed anti-fraud knowledge graph. Specifically, a "probability" field can be added to the edge attributes for later use. Simultaneously, a visual probability heatmap can be generated based on the frequency data, facilitating information security managers to monitor high-frequency paths.
[0096] The above technical solution constructs a simplified anti-fraud knowledge graph using "fraud state nodes - inducement behavior edges". It uses the knowledge graph to achieve structured modeling of the evolution path of all fraud behaviors and provides a basis for the identification of fraud behaviors through the construction of the anti-fraud knowledge graph.
[0097] As an optional embodiment of the present invention, the method can be further optimized based on the above embodiments by including:
[0098] The system receives an update operation on the anti-fraud knowledge graph and updates the anti-fraud knowledge graph. The update operation includes adding, deleting, or modifying fraud status nodes or behavioral features corresponding to fraudulent status nodes in the anti-fraud knowledge graph.
[0099] In this embodiment, the anti-fraud knowledge graph can also be maintained. In practical applications, fraudulent tactics and behavioral patterns continuously evolve, requiring dynamic updates to the anti-fraud knowledge graph. For example, the add, delete, and modify statements of the graph database are encapsulated as an Application Programming Interface (API). Frontline personnel can submit graph update requests at the anti-fraud workbench or the front end of the early warning system. A semantic similarity model is used to compare newly added state nodes with existing nodes; modifications with high similarity trigger alarms. After review by the anti-fraud center, the API is called to complete the graph update.
[0100] In this embodiment, updating the anti-fraud knowledge graph includes adding, deleting, or modifying fraud status nodes in the anti-fraud knowledge graph, or adding, deleting, or modifying the behavioral characteristics corresponding to a certain fraud status node. These operations are referred to as updating the anti-fraud knowledge graph. When an update to the anti-fraud knowledge graph is required, the user can perform an update operation. This execution entity receives the update operation and updates the anti-fraud knowledge graph based on the parsing results of the update operation. For example, the update operation type is adding a status node, with the initial status node being impersonating bank customer service, the script or behavioral characteristic being "Your account is abnormal, you need to click the link to reset your password," and the ending node status being inducing clicks; whether to cover is yes. Or, the update operation type is deleting a status node, with the initial status node being creating panic, the script or behavioral characteristic being "—," and the ending status being inducing transfers; whether to cover is no. Or, the operation type is updating a status node, with the initial status node being requesting transfers, the script or behavioral characteristic being "Please scan the QR code with WeChat to transfer money to a safe account," and the ending status being successful fraud; whether to cover is yes.
[0101] The above technical solution supports dynamic updates of the graph, adapting to the rapid changes in fraudulent rhetoric and providing more accurate support for the identification of fraudulent activities.
[0102] Example 2
[0103] Figure 3 This is a flowchart illustrating another fraud behavior identification method provided in Embodiment 2 of the present invention. This embodiment is a further optimization of the above embodiment. In this embodiment, the limitation optimizations are made to "parse the current dialogue data and determine the current fraud state node corresponding to the current dialogue data" and "determine the current fraud probability of the user being successfully defrauded based on the target fraud behavior state chain in the pre-constructed anti-fraud knowledge graph of the current fraud state node".
[0104] like Figure 3 As shown in the figure, this embodiment 2 provides a method for identifying fraudulent behavior, which specifically includes the following steps:
[0105] S201. Input the pre-constructed extraction state chain prompts and the current dialogue data into the large model for processing, so that the large model can extract the current fraud state node corresponding to the current dialogue data from the current dialogue data.
[0106] The extracted state chain cue words used in this step are the same as those used in the anti-fraud knowledge graph construction process, and will not be repeated here. The pre-constructed extracted state chain cue words and the current dialogue data are input into the large model for processing. The dialogue text is parsed via API calls to allow the large model to extract the current fraud state node corresponding to the current dialogue data, denoted as the current fraud state node. For example, the current fraud state node is represented as... .
[0107] S202. Based on the node position of the current fraud state node in the anti-fraud knowledge graph, determine the target fraud behavior state chain associated with the current fraud state node.
[0108] In this embodiment, the node position of the current fraud state node in the anti-fraud knowledge graph is determined, and based on the outgoing edges of the current fraud state node, the fraud behavior state chains associated with the current fraud state node are determined and denoted as the target fraud behavior state chain.
[0109] S203. For each of the target fraud behavior state chains, determine the probability that the user has been successfully defrauded by the target fraud behavior state chain.
[0110] In this embodiment, for each target fraud behavior state chain, the probability of the entire chain is calculated as the probability that the user is successfully defrauded by the target fraud behavior state chain. For example, for the path from the user's initial state (such as "impersonating XX to start") to the target product state (such as "fraud successful"), the transition probability of the entire chain is calculated to quantify the possibility that the user is defrauded.
[0111] As a specific implementation, the step of determining the probability of a user being successfully defrauded by the target fraud behavior state chain for each of the target fraud behavior state chains can be optimized, including:
[0112] a2) For each of the target fraud behavior state chains, obtain the current fraud state node and the transition probability of each subsequent fraud state node.
[0113] In this embodiment, for each target fraud behavior state chain, the subsequent fraud state node connected to the current fraud state node is recorded as the subsequent fraud state node. Each fraud state node in the anti-fraud knowledge graph is associated with a corresponding transition probability from the current fraud state node to the next fraud state node. This step is used to obtain the transition probabilities of the current fraud state node and each subsequent fraud state node. The sequence of the target fraud behavior state chain can be represented as follows: That is, the known user's current fraud status node is Follow the navigation map The user has reached the status node. ,in This is a node representing the user's status as having been scammed (i.e., the scam was successful).
[0114] b2) Multiply the transition probabilities to obtain the probability that the user was successfully defrauded by the target fraud behavior state chain.
[0115] In this embodiment, the transition probabilities are multiplied together, and the product is used as the probability that the user has been successfully scammed by the target fraud behavior state chain. Specifically, the path probability product method is used: , among which, among which It is a sequence of state nodes along a path. To improve efficiency, dynamic programming algorithms, such as Dijkstra's algorithm, are introduced for real-time calculation in a graph with hundreds of millions of nodes. For example, the probability of a path "impersonating XX to start → creating panic → inducing isolation → successful fraud" is the product of the transition probabilities of each segment.
[0116] The above technical solution specifies the steps for determining the probability of a user being successfully defrauded by the target fraud behavior state chain, and quantifies the likelihood of a user being defrauded.
[0117] S204. Add up the fraud probabilities corresponding to each of the target fraud behavior state chains to obtain the current fraud probability that the user has been successfully defrauded.
[0118] Specifically, the fraud probabilities corresponding to the state chain of each target fraud behavior are added together, and the sum is taken as the probability that the user is successfully defrauded, which is recorded as the current fraud probability.
[0119] S205. If the current fraud probability is greater than a preset fraud probability threshold, then fraudulent behavior is determined to exist, and a fraud warning is issued to the user.
[0120] The aforementioned technical solution details the steps for parsing current dialogue data to determine the current fraud state node corresponding to that data, and for determining the probability of a user being successfully scammed. It leverages the semantic understanding capabilities of a large-scale model to achieve "dynamic stage identification" of fraudulent behavior, overcoming the limitations of static matching in traditional keyword or rule engines. By utilizing knowledge graphs to achieve structured modeling of the evolution path of all fraudulent behaviors, and leveraging the semantic understanding capabilities of the large-scale model, it locates the current state node of the fraud in real-time dialogue. Finally, by constructing a fraud state transition probability model, it can quantitatively assess the current risk of fraud success. This provides a basis for frontline anti-fraud personnel or systems to accurately intervene during fraud, significantly improving the success rate of fraud prevention and fraud identification.
[0121] Example 3
[0122] Figure 4This is a schematic diagram of a fraud behavior identification device provided in Embodiment 3 of the present invention. This device is applicable to situations requiring the identification of fraudulent behavior. The fraud behavior identification device can be implemented in hardware and / or software and is generally integrated into an electronic device. Figure 4 As shown, the device includes: a node determination module 31, a probability determination module 32, and an early warning module 33, wherein,
[0123] The node determination module 31 is used to parse the current dialogue data and determine the current fraud status node corresponding to the current dialogue data;
[0124] The probability determination module 32 is used to determine the current fraud probability of a user being successfully defrauded based on the target fraud behavior state chain associated with the current fraud state node in the pre-constructed anti-fraud knowledge graph. The anti-fraud knowledge graph uses multiple fraud state nodes as nodes and the behavioral features corresponding to the fraud state nodes as edges. Each fraud state node contains the transition probability of itself jumping to the next fraud state node.
[0125] The early warning module 33 is used to determine that there is fraudulent behavior and issue a fraud warning to the user if the current fraud probability is greater than a preset fraud probability threshold.
[0126] The above technical solution uses knowledge graphs to achieve structured modeling of the evolution path of all fraudulent behaviors and locates the state node of fraud from real-time dialogue. Combined with the constructed anti-fraud knowledge graph, it is used to assist front-line anti-fraud personnel or systems in dynamically identifying the stage of fraudulent behavior and predicting the next fraudulent action during calls or text interactions, thereby intervening in time, blocking transactions or reminding users, and improving the accuracy of fraud identification and response efficiency.
[0127] Optionally, the device further includes a map construction module, which may specifically include:
[0128] The graph construction unit is used to construct an anti-fraud knowledge graph by taking each fraud state node related to the fraud event as a node and the behavioral features corresponding to the fraud state node as edges.
[0129] A state chain construction unit is used to collect historical fraud sample data, parse the historical fraud sample data, and construct the fraud behavior state chain corresponding to the historical fraud sample data.
[0130] The probability determination unit is used to load each fraud behavior state chain into the anti-fraud knowledge graph and determine the transition probability of each fraud state node jumping to the next fraud state node.
[0131] The graph determination unit is used to add each of the transition probabilities to the fraud status node corresponding to the anti-fraud knowledge graph to obtain the updated anti-fraud knowledge graph.
[0132] Optionally, the state chain building unit can be specifically used for:
[0133] Construct and extract state chain cue words;
[0134] The extracted state chain prompts and the historical fraud sample data are input into a large model for processing, so that the large model can extract each fraud state node contained in each fraud event and the behavioral features corresponding to each fraud state node from the historical fraud sample data.
[0135] For each fraud incident, the fraud state nodes included in the fraud incident and the behavioral characteristics corresponding to each fraud state are arranged in the order in which the nodes occur to form the fraud behavior state chain of the fraud incident.
[0136] Optionally, the probability determination unit can be specifically used for:
[0137] The state chains of each fraudulent behavior are loaded into the anti-fraud knowledge graph;
[0138] For each fraud state node, a first jump frequency is determined for the fraud state node to jump to any next fraud state node;
[0139] Determine the second jump frequency for the fraud state node to jump to all the next fraud state nodes;
[0140] The first jump frequency is divided by the second jump frequency to obtain the transition probability of the fraud state node jumping to any next fraud state node.
[0141] Optionally, the node determination module 31 is used for:
[0142] The pre-constructed extraction state chain prompts and the current dialogue data are input into a large model for processing, so that the large model can extract the current fraud state node corresponding to the current dialogue data from the current dialogue data.
[0143] Optionally, the probability determination module 32 is specifically used for:
[0144] Based on the node position of the current fraud state node in the anti-fraud knowledge graph, the target fraud behavior state chain associated with the current fraud state node is determined;
[0145] For each of the target fraud behavior state chains, determine the probability that the user is successfully defrauded by the target fraud behavior state chain;
[0146] The fraud probabilities corresponding to each of the target fraud behavior state chains are added together to obtain the current fraud probability that the user has been successfully defrauded.
[0147] Optionally, the probability determination module 32 is used to perform the step of determining the probability that the user has been successfully defrauded by the target fraud behavior state chain for each of the target fraud behavior state chains, including:
[0148] For each of the target fraud behavior state chains, obtain the current fraud state node and the transition probability of each subsequent fraud state node;
[0149] Multiply the transition probabilities to obtain the probability that the user was successfully defrauded by the target fraud behavior state chain.
[0150] Optionally, the device also includes a map updating module, specifically used for:
[0151] The system receives an update operation on the anti-fraud knowledge graph and updates the anti-fraud knowledge graph. The update operation includes adding, deleting, or modifying fraud status nodes or behavioral features corresponding to fraudulent status nodes in the anti-fraud knowledge graph.
[0152] The fraud behavior identification device provided in the embodiments of the present invention can execute the fraud behavior identification method provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the execution method.
[0153] Example 4
[0154] Figure 5 This is a schematic diagram of an electronic device provided in Embodiment 4 of the present invention. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices (such as helmets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the invention described and / or claimed herein.
[0155] like Figure 5As shown, the electronic device 40 includes at least one processor 41 and a memory, such as a read-only memory (ROM) 42 or a random access memory (RAM) 43, communicatively connected to the at least one processor 41. The memory stores computer programs executable by the at least one processor. The processor 41 can perform various appropriate actions and processes based on the computer program stored in the ROM 42 or loaded from storage unit 48 into the RAM 43. The RAM 43 may also store various programs and data required for the operation of the electronic device 40. The processor 41, ROM 42, and RAM 43 are interconnected via a bus 44. An input / output (I / O) interface 45 is also connected to the bus 44.
[0156] Multiple components in electronic device 40 are connected to I / O interface 45, including: input unit 46, such as keyboard, mouse, etc.; output unit 47, such as various types of monitors, speakers, etc.; storage unit 48, such as disk, optical disk, etc.; and communication unit 49, such as network card, modem, wireless transceiver, etc. Communication unit 49 allows electronic device 40 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.
[0157] Processor 41 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of processor 41 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. Processor 41 performs the various methods and processes described above, such as fraud behavior detection methods.
[0158] In some embodiments, the fraud detection method may be implemented as a computer program tangibly contained in a computer-readable storage medium, such as storage unit 48. In some embodiments, part or all of the computer program may be loaded and / or installed on electronic device 40 via ROM 42 and / or communication unit 49. When the computer program is loaded into RAM 43 and executed by processor 41, one or more steps of the fraud detection method described above may be performed. Alternatively, in other embodiments, processor 41 may be configured to perform the fraud detection method by any other suitable means (e.g., by means of firmware).
[0159] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), payload-programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.
[0160] Computer programs used to implement the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when executed by the processor, the computer programs cause the functions / operations specified in the flowcharts and / or block diagrams to be performed. The computer programs may be executed entirely on a machine, partially on a machine, or as a standalone software package, partially on a machine and partially on a remote machine, or entirely on a remote machine or server.
[0161] In the context of this invention, a computer-readable storage medium can be a tangible medium that may contain or store a computer program for use by or in conjunction with an instruction execution system, apparatus, or device. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination thereof. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.
[0162] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).
[0163] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or middleware components (e.g., application servers), or frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., communication networks). Examples of communication networks include local area networks (LANs), wide area networks (WANs), blockchain networks, and the Internet.
[0164] A computing system can include clients and servers. Clients and servers are generally located far apart and typically interact through communication networks. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or cloud host, which is a hosting product within the cloud computing service system to address the shortcomings of traditional physical hosts and VPS services, such as high management difficulty and weak business scalability.
[0165] This invention also provides a computer program product, including a computer program that, when executed by a processor, implements the fraud behavior identification method provided in any embodiment of this invention.
[0166] In implementing the computer program product, computer program code for performing the operations of this invention can be written in one or more programming languages or a combination thereof. These programming languages include, but are not limited to, object-oriented programming languages—such as Java, Smalltalk, and C++—as well as conventional procedural programming languages—such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a local area network (LAN) or a wide area network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).
[0167] It should be understood that the various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps described in this invention can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution of this invention can be achieved, and this is not limited herein.
[0168] The specific embodiments described above do not constitute a limitation on the scope of protection of this invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this invention should be included within the scope of protection of this invention.
Claims
1. A method for identifying fraudulent activities, characterized in that, include: The current dialogue data is parsed to determine the current fraud status node corresponding to the current dialogue data. Based on the target fraud behavior state chain associated with the current fraud state node in the pre-constructed anti-fraud knowledge graph, the current fraud probability of the user being successfully defrauded is determined. In the anti-fraud knowledge graph, multiple fraud state nodes are used as nodes, and the behavioral features corresponding to the fraud state nodes are used as edges. Each fraud state node contains the transition probability of itself jumping to the next fraud state node. If the current fraud probability is greater than a preset fraud probability threshold, then fraudulent activity is determined to exist, and a fraud warning is issued to the user.
2. The method according to claim 1, characterized in that, The steps for constructing the anti-fraud knowledge graph include: A knowledge graph for anti-fraud is constructed by taking each fraud status node related to a fraud event as a node and the corresponding behavioral features of the fraud status node as edges. Collect historical fraud sample data, parse the historical fraud sample data, and construct the fraud behavior state chain corresponding to the historical fraud sample data; The state chains of each fraud behavior are loaded into the anti-fraud knowledge graph to determine the transition probability of each fraud state node to the next fraud state node. Each of the aforementioned transition probabilities is added to the fraud status node corresponding to the anti-fraud knowledge graph to obtain the updated anti-fraud knowledge graph.
3. The method according to claim 2, characterized in that, The step of parsing the historical fraud sample data and constructing the fraud behavior state chain corresponding to the historical fraud sample data includes: Construct and extract state chain cue words; The extracted state chain prompts and the historical fraud sample data are input into a large model for processing, so that the large model can extract each fraud state node contained in each fraud event and the behavioral features corresponding to each fraud state node from the historical fraud sample data. For each fraud incident, the fraud state nodes included in the fraud incident and the behavioral characteristics corresponding to each fraud state are arranged in the order in which the nodes occur to form the fraud behavior state chain of the fraud incident.
4. The method according to claim 2, characterized in that, The step of loading each of the fraud behavior state chains into the anti-fraud knowledge graph and determining the transition probability of each fraud state node jumping to the next fraud state node includes: The state chains of each fraudulent behavior are loaded into the anti-fraud knowledge graph; For each fraud state node, a first transition frequency is determined for the fraud state node to jump to any next fraud state node; Determine the second transition frequency for the fraud state node to jump to all the next fraud state nodes; The first transition frequency is divided by the second transition frequency to obtain the transition probability of the fraud state node jumping to any next fraud state node.
5. The method according to claim 1, characterized in that, The step of parsing the current dialogue data to determine the current fraud status node corresponding to the current dialogue data includes: The pre-constructed extraction state chain prompts and the current dialogue data are input into a large model for processing, so that the large model can extract the current fraud state node corresponding to the current dialogue data from the current dialogue data.
6. The method according to claim 1, characterized in that, The step of determining the current fraud probability of a user being successfully defrauded based on the target fraud behavior state chain associated with the current fraud state node in the pre-constructed anti-fraud knowledge graph includes: Based on the node position of the current fraud state node in the anti-fraud knowledge graph, the target fraud behavior state chain associated with the current fraud state node is determined; For each of the target fraud behavior state chains, determine the probability that the user is successfully defrauded by the target fraud behavior state chain; The fraud probabilities corresponding to each of the target fraud behavior state chains are added together to obtain the current fraud probability that the user has been successfully defrauded.
7. The method according to claim 6, characterized in that, For each of the target fraud behavior state chains, determining the probability that the user has been successfully defrauded by the target fraud behavior state chain includes: For each of the target fraud behavior state chains, obtain the current fraud state node and the transition probability of each subsequent fraud state node; Multiply the transition probabilities to obtain the probability that the user was successfully defrauded by the target fraud behavior state chain.
8. The method according to claim 1, characterized in that, Also includes: The system receives an update operation on the anti-fraud knowledge graph and updates the anti-fraud knowledge graph. The update operation includes adding, deleting, or modifying fraud status nodes or behavioral features corresponding to fraud status nodes in the anti-fraud knowledge graph.
9. A fraud detection device, characterized in that, include: The node determination module is used to parse the current dialogue data and determine the current fraud status node corresponding to the current dialogue data; The probability determination module is used to determine the current fraud probability of a user being successfully defrauded based on the target fraud behavior state chain associated with the current fraud state node in the pre-constructed anti-fraud knowledge graph. The anti-fraud knowledge graph uses multiple fraud state nodes as nodes and the behavioral features corresponding to the fraud state nodes as edges. Each fraud state node contains the transition probability of itself jumping to the next fraud state node. The early warning module is used to determine that fraudulent behavior exists and to issue a fraud warning to the user if the current fraud probability is greater than a preset fraud probability threshold.
10. An electronic device, characterized in that, include: At least one processor; as well as A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that can be executed by the at least one processor, the computer program being executed by the at least one processor to enable the at least one processor to perform the fraud detection method as described in any one of claims 1-8.
11. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions that cause a processor to execute the fraud detection method as described in any one of claims 1-8.
12. A computer program product, characterized in that, The computer program product includes a computer program that, when executed by a processor, implements the fraud detection method as described in any one of claims 1-8.