User account control releasing method and device, equipment, medium and program product
By using a combination model and a large language model, the problems of low efficiency and high misjudgment rate in user account decontrol are solved, and efficient integration of multi-source heterogeneous data and accurate decision-making are achieved, thereby improving the processing efficiency and accuracy of user account decontrol.
Patent Information
- Application Number
- CN202511682066.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-17
- Publication Date
- 2026-02-10
AI Technical Summary
Existing technologies are inefficient and have a high false positive rate in user account decontrolling, making it difficult to effectively integrate multi-source heterogeneous data, especially lacking semantic analysis capabilities for complex text materials.
The combined model employs a combination of machine learning and deep learning models. It processes multi-source heterogeneous data, uses a large language model to generate the basis for lifting control measures, and combines a risk list with manual review to make accurate decisions.
It improved the efficiency of user account deregulation, reduced the false positive rate, achieved a balance between risk control and user experience, and enhanced the accuracy and compliance of data analysis.
Smart Images

Figure CN121502476A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of artificial intelligence, and relates to application of a large model in a financial technology scene, in particular to a user account control method and device, equipment, medium and program product. BACKGROUND
[0002] Currently, control of a user account is mainly through manual review, a traditional rule engine and a machine learning model. For the manual review mode, account history records, transaction flow and customer submitted materials are reviewed by human, which is time-consuming and easily affected by subjective factors; the traditional rule engine lacks semantic analysis capability for complex text materials (such as customer complaint statements); and the traditional machine learning model is difficult to integrate unstructured text data (such as customer service dialogue records).
[0003] Therefore, in the face of more and more complex multi-source heterogeneous data associated with an account, only using a single method to control a user account inevitably causes low processing efficiency and high misjudgment rate. SUMMARY
[0004] In view of the above problems, the present application provides a user account control method, device, equipment, medium and program product, which can improve the processing efficiency of user account control and reduce the misjudgment rate.
[0005] According to a first aspect of the present application, a user account control method is provided, comprising: in response to receiving a control request for a user account, obtaining multi-source heterogeneous data associated with the user account under the condition that the user authorizes to obtain the multi-source heterogeneous data; under the condition that the user account is not on a preset risk list, processing the multi-source heterogeneous data by using a combined model to obtain a risk level of the user account, wherein the combined model is composed of a machine learning model and a deep learning model; and under the condition that the risk level is lower than a preset risk level range, controlling the user account.
[0006] According to an embodiment of the present application, the multi-source heterogeneous data includes static feature data and time series feature data; processing the multi-source heterogeneous data by using the combined model to obtain the risk level of the user account comprises: inputting the static feature data into the machine learning model to obtain a first risk score of the static feature data; inputting the time series feature data into the deep learning model to obtain a second risk score of the time series feature data; and weighting and fusing the first risk score and the second risk score to obtain the risk level of the user account.
[0007] According to an embodiment of the present application, the first risk score and the second risk score are weighted and fused, including: determining the weight of the first risk score and the second risk score according to the performance score of the machine learning model and the performance score of the deep learning model; wherein the performance score is determined by a plurality of preset performance indicators of each model.
[0008] According to an embodiment of the present application, further comprising: rejecting the unblocking request in the case that the risk level is higher than the preset risk level range.
[0009] According to an embodiment of the present application, further comprising: rejecting the unblocking request in the case that the user account is determined to be on the risk list.
[0010] According to an embodiment of the present application, further comprising: in the case that the risk level is within the risk level range, processing the unblocking request and the multi-source heterogeneous data using a large language model to obtain unblocking basis for the user account; generating an operation prompt window according to the unblocking basis, for prompting to input an unblocking result for the unblocking request; and in response to receiving the unblocking result input for the operation prompt window, processing the unblocking request according to the unblocking result.
[0011] According to an embodiment of the present application, further comprising: analyzing the multi-source heterogeneous data and the risk level using a large language model to generate a risk trend report of the user account.
[0012] The second aspect of the present application provides a user account unblocking device, comprising: a data acquisition module, configured to acquire multi-source heterogeneous data associated with a user account in the case that the user authorizes the acquisition of the multi-source heterogeneous data in response to receiving an unblocking request for the user account; a risk level determination module, configured to determine a risk level of the user account by processing the multi-source heterogeneous data using a combined model in the case that the user account is not on a preset risk list, wherein the combined model is composed of a machine learning model and a deep learning model; and an account unblocking module, configured to unblock the user account in the case that the risk level is lower than a preset risk level range.
[0013] The third aspect of the present application provides an electronic device, comprising: one or more processors; a memory for storing one or more computer programs, wherein the one or more processors execute the one or more computer programs to implement the steps of the above method.
[0014] The fourth aspect of the present application further provides a computer readable storage medium having a computer program or instructions stored thereon, wherein the computer program or instructions are executed by a processor to implement the steps of the above method.
[0015] The fifth aspect of the present application also provides a computer program product comprising computer programs or instructions, which, when executed by a processor, implement the steps of the above method. BRIEF DESCRIPTION OF DRAWINGS
[0016] The above and other objects, features and advantages of the present application will become more apparent from the following description when taken in conjunction with the accompanying drawings, in which:
[0017] Figure 1 An application scenario diagram of a user account control method, device, equipment, medium and program product according to an embodiment of the present application is schematically shown;
[0018] Figure 2 A flowchart of a user account control method according to an embodiment of the present application is schematically shown;
[0019] Figure 3 A flowchart of inputting multi-source heterogeneous data into a combined model according to an embodiment of the present application is schematically shown;
[0020] Figure 4 A structural block diagram of a user account control device according to an embodiment of the present application is schematically shown;
[0021] Figure 5 A block diagram of an electronic device suitable for implementing a user account control method according to an embodiment of the present application is schematically shown. DETAILED DESCRIPTION
[0022] Hereinafter, embodiments of the present application will be described with reference to the accompanying drawings. It is to be understood, however, that the description is merely exemplary and is intended to provide a thorough understanding of the present application. The following description, given together with the accompanying drawings, is intended to provide a thorough understanding of the present application. However, it is apparent that one or more embodiments can be implemented without the specific details, as is apparent to those skilled in the art.
[0023] The terms used herein are merely used to describe specific embodiments, and are not intended to limit the present application. The terms "include", "comprise" and the like used herein indicate the presence of the described features, steps, operations and / or components, but do not exclude the presence or addition of one or more other features, steps, operations or components.
[0024] All terms used herein, including technical and scientific terms, have meanings commonly understood by one of ordinary skill in the art, unless otherwise defined. It should be noted that the terms used herein should be interpreted in the context of the present specification, and should not be interpreted in an idealized or overly formal manner.
[0025] When using expressions such as "at least one of A, B and C", they should generally be interpreted in accordance with the meaning that is commonly understood by those skilled in the art (e.g., "a system having at least one of A, B and C" should include, but is not limited to, a system having A alone, a system having B alone, a system having C alone, a system having A and B, a system having A and C, a system having B and C, and / or a system having A, B and C, etc.).
[0026] In the technical solution of this application, the user information (including but not limited to user personal information, user image information, user device information, such as location information) and data (including but not limited to data used for analysis, stored data, and displayed data) involved are all information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, storage, use, processing, transmission, provision, disclosure, and application of related data all comply with relevant laws, regulations, and standards, take necessary confidentiality measures, do not violate public order and good morals, and provide corresponding operation entry points for users to choose to authorize or refuse.
[0027] In scenarios involving automated decision-making using personal information, the methods, apparatus, devices, media, and program products provided in this application all offer users corresponding entry points for choosing to agree to or reject the automated decision-making results; if the user chooses to reject, the process proceeds to expert decision-making. Here, "automated decision-making" refers to the activity of automatically analyzing and evaluating an individual's behavioral habits, interests, or economic, health, and credit status through computer programs, and then making a decision. Here, "expert decision-making" refers to the activity of making decisions by personnel who specialize in a particular field, possess specialized experience, knowledge, and skills, and have reached a certain level of professional expertise.
[0028] Figure 1 The illustration schematically depicts an application scenario of a user account unlocking method, apparatus, device, medium, and program product according to embodiments of this application.
[0029] like Figure 1 As shown, application scenario 100 according to this embodiment may include a first terminal device 101, a second terminal device 102, a third terminal device 103, a network 104, and a server 105. The network 104 serves as a medium for providing a communication link between the first terminal device 101, the second terminal device 102, the third terminal device 103, and the server 105. The network 104 may include various connection types, such as wired or wireless communication links, or fiber optic cables, etc.
[0030] Users can use the first terminal device 101, the second terminal device 102, and the third terminal device 103 to interact with the server 105 via the network 104 to receive or send messages, etc. Various communication client applications can be installed on the first terminal device 101, the second terminal device 102, and the third terminal device 103, such as shopping applications, web browser applications, search applications, instant messaging tools, email clients, social media platform software, etc. (for example only).
[0031] The first terminal device 101, the second terminal device 102, and the third terminal device 103 can be various electronic devices with displays and support web browsing, including but not limited to smartphones, tablets, laptops, and desktop computers.
[0032] Server 105 can be a server that provides various services, such as a backend management server that supports websites browsed by users using the first terminal device 101, the second terminal device 102, and the third terminal device 103 (this is just an example). The backend management server can analyze and process data such as received user requests, and feed back the processing results (such as web pages, information, or data obtained or generated according to user requests) to the terminal devices.
[0033] It should be noted that the user account deactivation method provided in this application embodiment can generally be executed by server 105. Correspondingly, the data storage device provided in this application embodiment can generally be located in server 105. The user account deactivation method provided in this application embodiment can be executed by a server or server cluster that is different from server 105 and capable of communicating with the first terminal device 101, the second terminal device 102, the third terminal device 103, and / or server 105. Correspondingly, the data storage device provided in this application embodiment can also be located in a server or server cluster that is different from server 105 and capable of communicating with the first terminal device 101, the second terminal device 102, the third terminal device 103, and / or server 105.
[0034] It should be understood that Figure 1 The number of terminal devices, networks, and servers shown is merely illustrative. Depending on implementation needs, any number of terminal devices, networks, and servers can be included.
[0035] The following will be based on Figure 1 The described scene, through Figure 2 and Figure 3 The method for unlocking user accounts according to embodiments of this application will be described in detail.
[0036] Figure 2 A flowchart illustrating a method for unlocking a user account according to an embodiment of this application is shown.
[0037] like Figure 2 As shown, the user account decontrol method in this embodiment includes operations S210 to S230.
[0038] In operation S210, a request to release control of a user account is received, and with the user's authorization to obtain multi-source heterogeneous data, the multi-source heterogeneous data associated with the user account is obtained.
[0039] For example, multi-source heterogeneous data includes static feature data and time-series feature data. Static feature data includes basic user identity data, basic account attribute data, and fixed user qualification data. Basic user identity data may include, for example, user name, ID number, gender, date of birth, registered address, and contact number—inherent information verified through real-name authentication. Basic account attribute data may include, for example, account type, bank branch, account opening date, account location, account level, type and validity period of the identification document submitted at the time of account opening, etc. Fixed user qualification data may include, for example, user occupation, proof of income, asset proof submitted at the time of account opening, and associated fixed accounts, etc.
[0040] The time-series characteristic data includes transaction flow time-series data, account operation time-series logs, customer service interaction time-series records, and account status dynamic change records. Transaction flow time-series data can be, for example, the timestamp of each account transaction, transaction amount, counterparty account, transaction type, transaction location, transaction remarks, etc., forming a sequence of data in chronological order of transaction occurrence. Account operation time-series logs can be, for example, records sorted by operation time, such as account login time, login device, login IP address, login location, account password modification time, transfer limit adjustment time, and bound device change time. Customer service interaction time-series records can be, for example, time-series interaction information such as the time of each conversation between the user and bank customer service, the conversation channel, a summary of the conversation content, and the time and content of the customer service's remarks on the account. Account status dynamic change records can be, for example, the time point of account unfreezing, the trigger time and reason for temporary account freezing, and the time of dynamic adjustment of account transaction permissions, etc., which change over time.
[0041] For example, a user account release request carries the following information: (1) User account identification information, which is used to uniquely identify the account to be released and is the basis of the release request; (2) Release initiator information, which is used to confirm the legitimacy of the request initiator and includes the identity information of the entity initiating the release; (3) Explanation of the reason for the release application, such as the appeal text; and a statement authorizing the bank to obtain multi-source heterogeneous data, which is used to authorize the bank to obtain user account information for release risk assessment.
[0042] For example, the acquisition of multi-source heterogeneous data associated with user accounts includes the following methods: (1) User active submission, through form filling (such as registration information) and file upload (such as avatar, ID card), to obtain structured (name, mobile phone number), semi-structured (personal profile) and unstructured (image) data; (2) Platform internal collection to obtain various types of business and behavioral data; (3) Third-party docking to obtain associated third-party structured / semi-structured data; (4) Terminal device collection, through applying for location, sensor permissions or Bluetooth docking (such as smartwatches), to obtain device information, health data, etc.; (5) Public platform acquisition, relying on government APIs and academic reports to obtain official structured data. These methods cover multiple types of heterogeneous data, laying the foundation for user data profiling and subsequent account decontrol analysis. The acquisition of the above data has been authorized by the user in advance and complies with data laws and regulations.
[0043] In operation S220, if it is determined that the user account is not on the preset risk list, the combined model is used to process the multi-source heterogeneous data to obtain the risk level of the user account; the combined model is composed of a machine learning model and a deep learning model.
[0044] In this embodiment of the application, if it is determined that the user account is on the risk list, the request to remove control is rejected.
[0045] For example, the pre-defined risk list consists of two sets of high-risk accounts: a third-party warning list, provided by an external authoritative institution, which includes individuals with high-risk characteristics and their corresponding bank accounts, accounts with illegal or irregular activities, or "high-risk transaction entity accounts" jointly marked by multiple banks. It also includes an internal bank high-risk list, generated by the bank based on its own risk control data, including accounts with a history of high-risk behavior, such as those that have triggered multiple abnormal transaction rules (e.g., more than 5 large transfers in a single day with counterparties in high-risk areas), accounts manually identified as suspected of violations and whose risks have not been resolved, and accounts with questionable account opening information that cannot be corrected.
[0046] For example, expert rule models can be used to determine whether a user account is on a pre-defined risk list. Essentially, an expert rule model is a set of pre-defined rules built upon the knowledge and experience of domain experts. These rules include whether the user account's account number / ID number completely matches an account number / ID number on the risk list, and whether the user account's associated mobile phone number / bank card number has appeared on the risk list.
[0047] Upon receiving a request to lift control restrictions, the system will first call the expert rule model to compare the key identifiers of the account to be lifted (such as account number, ID number, and associated mobile phone number) with the information in the preset risk list. If the comparison is successful, the account will be directly determined to be on the risk list, and the request to lift control restrictions will be rejected. If the comparison fails, the system will proceed to the risk assessment stage of the subsequent combined model.
[0048] In this embodiment of the application, the method of rejecting the de-control request is also included if the risk level is higher than a preset risk level range.
[0049] For example, if the risk level is higher than the preset risk level range, it means that the user account is at high risk, and the request to unblock the account can be rejected directly to avoid problems such as financial loss and compliance risks caused by unblocking the user account.
[0050] For example, the risk threshold for lifting user account control (including high-risk threshold and low-risk threshold) is initially anchored based on risk control compliance requirements, business risk tolerance and historical risk case data, and then calibrated by combining the performance indicators such as accuracy and recall of the combined model.
[0051] For example, the high-risk threshold and low-risk threshold are quantitative risk level demarcation points set by banks based on risk control and compliance requirements, business risk tolerance, and historical demarcation case data. They are used to divide the risk level output by the combined model into three intervals: "low risk, medium risk, and high risk," and thus correspond to different demarcation and handling strategies.
[0052] Low risk threshold (denoted as T1): If the risk level is "below T1", it means that the account risk is extremely low and meets the conditions for automatic de-control.
[0053] High-risk threshold (denoted as T2, and T2 > T1): If the risk level is "higher than T2", it means that the account risk is extremely high and the account will be directly rejected for deregulation.
[0054] Between the two thresholds (T1≤risk level≤T2): If the risk level is in the "medium risk range", further manual intervention is required for judgment.
[0055] In operation S230, if the risk level is lower than the preset risk level range, the user account is released from control.
[0056] The user account decontrolling method provided in this application, by acquiring multi-source heterogeneous data after user authorization, breaks through the limitations of traditional single-dimensional data. It comprehensively covers the risk characteristics required for account decontrolling and provides sufficient multi-dimensional data for subsequent combined model evaluation, laying the foundation for accurate decision-making in account decontrolling. By intercepting high-risk accounts in advance through a risk list, it solves the problem of untimely handling of known high-risk accounts in existing technologies; simultaneously, it eliminates the need for such accounts to enter subsequent combined model evaluation or manual review, reducing computational resource consumption and labor costs, directly improving the overall efficiency of the decontrolling process. It utilizes a combined model of machine learning and deep learning to process data, combining the advantages of both models to improve the accuracy of risk level assessment; by first excluding accounts on the risk list to reduce invalid processing, and then automatically decontrolling accounts once the risk level meets the standard, it reduces manual intervention, improving decontrolling efficiency and reducing the false judgment rate, achieving a balance between risk control and user experience in user account decontrolling.
[0057] Figure 3 The flowchart illustrating the input of multi-source heterogeneous data into a combined model according to an embodiment of this application is shown schematically.
[0058] like Figure 3 As shown, in some embodiments, the above operation S220 uses a combined model to process multi-source heterogeneous data to obtain the risk level of the user account, and may further include operations S221 to S223.
[0059] In operation S221, static feature data is input into the machine learning model to obtain the first risk score of the static feature data.
[0060] For example, machine learning models include, but are not limited to, gradient boosting decision trees and random forests, which are suitable for processing static feature data (such as user ID information, account type, etc.). Machine learning models can accurately mine risk associations in static data such as user identity information, account type, and account opening qualifications, and the output first risk score can clearly trace which static features affect the risk level.
[0061] The core advantages of machine learning are high processing efficiency, strong interpretability, and adaptability to low-dimensional structured data. It can clearly trace which static features lead to high or low risk scores, meeting the compliance and traceability requirements of bank risk control.
[0062] In operation S222, the time series feature data is input into the deep learning model to obtain the second risk score of the time series feature data.
[0063] For example, deep learning models include, but are not limited to, long short-term memory networks, gated recurrent units, and other models capable of handling temporal features.
[0064] By capturing dynamic patterns in data over time (such as the time sequence of transactions and changes in login location), it outputs a quantitative score (i.e., a second risk score) of the risk of dynamic account behavior. Its core advantage is that it can uncover implicit correlations in high-dimensional time-series data and capture time dependencies, and can discover dynamic anomaly patterns that are difficult to identify by traditional machine learning (such as the combined risk of "large-amount transfers at night + logins from different locations").
[0065] In operation S223, the first risk score and the second risk score are weighted and merged to obtain the risk level of the user account.
[0066] In this embodiment of the application, the first risk score and the second risk score are weighted and fused, including: determining the weights of the first risk score and the second risk score based on the performance scores of the machine learning model and the deep learning model; wherein, the performance score is determined by a combination of multiple preset performance indicators of each model.
[0067] For example, the first and second risk scores obtained from both models are both in the range of 0 to 100.
[0068] For example, several quantitative performance metrics are set for machine learning models (processing static data) and deep learning models (processing time-series data) to reflect the reliability of the model's risk assessment, including accuracy, recall, and false positive rate. Accuracy represents the proportion of accounts the model classifies as low-risk that are actually risk-free; recall represents the proportion of high-risk accounts the model successfully identifies; and false positive rate represents the proportion of normal accounts that the model misclassifies as high-risk. All three metrics are presented in the same format as percentages.
[0069] By summing and averaging the performance metrics of each model, a single model performance metric is obtained, resulting in a single performance score. This performance score is the ratio of the single model's performance metric to the sum of the performance metrics of the two models. Weights are then assigned based on these performance scores. The weights of the machine learning model and the deep learning model are positively correlated with their performance scores.
[0070] Finally, a weighted fusion is performed to obtain a comprehensive risk score, which is the sum of the risk scores of the machine learning model and the deep learning model multiplied by their respective model weights.
[0071] Based on the weights of the aforementioned machine learning and deep learning models, the weights are dynamically adjusted according to the real-time performance of the models. When the machine learning model's evaluation of static data is more reliable (high performance score), the first risk score is given a higher weight to avoid the static risk being underestimated. When the deep learning model's mining of time series data is more accurate, the weight of the second risk score is increased to ensure that dynamic anomalies in the data are not missed. Ultimately, the comprehensive risk level can both leverage the model's strengths and balance static and dynamic risks, providing a more realistic quantitative basis for risk mitigation decisions.
[0072] By inputting static feature data and time-series feature data into the machine learning model and deep learning model respectively, the capability mismatch caused by a single model processing all data is avoided, fully leveraging the respective advantages of the machine learning model and the deep learning model. Simultaneously, by weightedly fusing the first risk score obtained from the machine learning model and the second risk score obtained from the deep learning model, the errors of a single model are avoided, allowing for a more accurate judgment on account release.
[0073] In this embodiment of the application, the method further includes: when the risk level is within the risk level range, processing the decontrol request and multi-source heterogeneous data using a large language model to obtain the decontrol basis for the user account; generating an operation prompt window based on the decontrol basis to prompt the input of the decontrol result for the decontrol request; and processing the decontrol request based on the decontrol result in response to receiving the decontrol result input in the operation prompt window.
[0074] When the risk level falls within a preset range, it means that the account deregulation process requires manual review and cannot be fully automated. In this case, a large language model can be used to process the deregulation request and multi-source heterogeneous data to generate deregulation criteria for reviewers to refer to.
[0075] For example, the basis for deregulation includes a compliance analysis report on multi-source heterogeneous data.
[0076] Specifically, the compliance analysis report clarifies whether the multi-source heterogeneous data of user accounts meets the basic compliance requirements of bank risk control. For example, it may be whether the user's identity information (ID number, registered address, etc.) is consistent, whether there are any abnormalities in the basic attributes of the account (account type, branch of account opening, account opening date, etc.), and whether the user's fixed qualifications (occupation, income certificate, etc.) are complete and true.
[0077] For example, the reviewer could be an account risk review specialist in the bank's risk control department, or a staff member responsible for handling the deregulation process.
[0078] For example, the bank server generates an operation prompt window based on the decontrol criteria provided by the big language model and displays it to the reviewers. The reviewers verify the authenticity of the data and determine whether the risk is abnormal by combining the decontrol criteria generated by the big language model. Finally, they process the decontrol request based on the decontrol criteria. This processing method may be to agree to decontrol, refuse decontrol, or request supplementary materials.
[0079] By using large language models, fragmented, multi-source, heterogeneous data (such as transaction records and user complaint texts) can be transformed into structured evidence, avoiding manual information sifting by reviewers and reducing decision-making time. This also enhances the accuracy of judgments; large language models can capture implicit relationships within multi-source, heterogeneous data, compensating for omissions in complex data correlations by manual review and reducing the false judgment rate.
[0080] In some embodiments, the method further includes: using a large language model to analyze multi-source heterogeneous data and risk levels to generate a risk trend report for user accounts.
[0081] For example, when the risk level is within a preset range, relying solely on the current risk level and the criteria for deregulation is insufficient to support long-term judgments regarding the deregulation of user accounts. Large language models can uncover the implicit correlations between multi-source heterogeneous data and the causal relationship between these correlations and the risk levels of user accounts, thereby predicting future risk changes based on historical patterns. Finally, the analysis results are transformed into risk trend reports to assist relevant personnel in making decisions.
[0082] Based on the above-mentioned method for unlocking user accounts, this application also provides a device for unlocking user accounts, which will be described below in conjunction with... Figure 4 The device is described in detail.
[0083] Figure 4 A schematic block diagram of a user account unlocking device according to an embodiment of this application is shown.
[0084] like Figure 4 As shown, the user account decontrol device 400 in this embodiment includes a data acquisition module 410, a risk level determination module 420, and an account decontrol module 430.
[0085] The data acquisition module 410 is used to respond to a request to unlock a user account, and, with the user's authorization to acquire multi-source heterogeneous data, acquire the multi-source heterogeneous data associated with the user account. In one embodiment, the data acquisition module 410 can be used to execute S210 described above, which will not be repeated here.
[0086] The risk level determination module 420 is used to process multi-source heterogeneous data using a combined model to obtain the risk level of the user account when it is determined that the user account is not on a preset risk list. The combined model is composed of a machine learning model and a deep learning model. In one embodiment, the risk level determination module S420 can be used to execute S220 as described above, which will not be repeated here.
[0087] The account de-control module S430 is used to de-control a user account when the risk level is lower than a preset risk level range. In one embodiment, the account de-control module S430 can be used to execute S230 described above, which will not be repeated here.
[0088] According to embodiments of this application, any multiple modules among the data acquisition module 410, risk level determination module 420, and account decontrol module 430 can be combined into one module, or any one of these modules can be split into multiple modules. Alternatively, at least some of the functions of one or more of these modules can be combined with at least some of the functions of other modules and implemented in one module. According to embodiments of this application, at least one of the data acquisition module 410, risk level determination module 420, and account decontrol module 430 can be at least partially implemented as hardware circuitry, such as field-programmable gate arrays (FPGAs), programmable logic arrays (PLAs), systems-on-a-chip, systems-on-a-substrate, systems-on-package, application-specific integrated circuits (ASICs), or any other reasonable means of integrating or packaging circuitry, or implemented in software, hardware, or firmware, or in any appropriate combination of any of these three implementation methods. Alternatively, at least one of the data acquisition module 410, risk level determination module 420, and account decontrol module 430 can be at least partially implemented as a computer program module, which can perform corresponding functions when the computer program module is run.
[0089] Figure 5 A block diagram schematically illustrates an electronic device suitable for implementing a user account deregulation method according to an embodiment of this application.
[0090] like Figure 5As shown, an electronic device 500 according to an embodiment of this application includes a processor 501, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 502 or a program loaded from a storage portion 508 into a random access memory (RAM) 503. The processor 501 may include, for example, a general-purpose microprocessor (e.g., a CPU), an instruction set processor and / or an associated chipset and / or a special-purpose microprocessor (e.g., an application-specific integrated circuit (ASIC)), etc. The processor 501 may also include onboard memory for caching purposes. The processor 501 may include a single processing unit or multiple processing units for performing different actions of the method flow according to an embodiment of this application.
[0091] RAM 503 stores various programs and data required for the operation of electronic device 500. Processor 501, ROM 502, and RAM 503 are interconnected via bus 504. Processor 501 executes various operations of the method flow according to embodiments of this application by executing programs in ROM 502 and / or RAM 503. It should be noted that the programs may also be stored in one or more memories other than ROM 502 and RAM 503. Processor 501 may also execute various operations of the method flow according to embodiments of this application by executing programs stored in said one or more memories.
[0092] According to embodiments of this application, the electronic device 500 may further include an input / output (I / O) interface 505, which is also connected to a bus 504. The electronic device 500 may also include one or more of the following components connected to the input / output (I / O) interface 505: an input section 506 including a keyboard, mouse, etc.; an output section 507 including a cathode ray tube (CRT), liquid crystal display (LCD), etc., and a speaker, etc.; a storage section 508 including a hard disk, etc.; and a communication section 509 including a network interface card such as a LAN card, modem, etc. The communication section 509 performs communication processing via a network such as the Internet. A drive 510 is also connected to the input / output (I / O) interface 505 as needed. A removable medium 511, such as a disk, optical disk, magneto-optical disk, semiconductor memory, etc., is installed on the drive 510 as needed so that computer programs read from it can be installed into the storage section 508 as needed.
[0093] This application also provides a computer-readable storage medium, which may be included in the device / apparatus / system described in the above embodiments; or it may exist independently and not assembled into the device / apparatus / system. The computer-readable storage medium carries one or more programs, which, when executed, implement the method according to the embodiments of this application.
[0094] According to embodiments of this application, the computer-readable storage medium can be a non-volatile computer-readable storage medium, such as including but not limited to: portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof. In this application, the computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. For example, according to embodiments of this application, the computer-readable storage medium may include ROM 502 and / or RAM 503 and / or one or more memories other than ROM 502 and RAM 503 described above.
[0095] Embodiments of this application also include a computer program product comprising a computer program containing program code for performing the methods shown in the flowchart. When the computer program product is run on a computer system, the program code is used to enable the computer system to implement the user account unlocking method provided in the embodiments of this application.
[0096] When the computer program is executed by the processor 501, it performs the functions defined in the system / apparatus of this application embodiment. According to the embodiments of this application, the systems, apparatuses, modules, units, etc., described above can be implemented by computer program modules.
[0097] In one embodiment, the computer program may rely on a tangible storage medium such as an optical storage device or a magnetic storage device. In another embodiment, the computer program may also be transmitted and distributed in the form of signals over a network medium, and may be downloaded and installed via the communication section 509, and / or installed from a removable medium 511. The program code contained in the computer program can be transmitted using any suitable network medium, including but not limited to: wireless, wired, etc., or any suitable combination thereof.
[0098] In such an embodiment, the computer program can be downloaded and installed from a network via communication section 509, and / or installed from removable medium 511. When the computer program is executed by processor 501, it performs the functions defined in the system of this application embodiment. According to embodiments of this application, the systems, devices, apparatuses, modules, units, etc., described above can be implemented by computer program modules.
[0099] According to embodiments of this application, program code for executing the computer programs provided in the embodiments of this application can be written in any combination of one or more programming languages. Specifically, these computational programs can be implemented using high-level procedural and / or object-oriented programming languages, and / or assembly / machine languages. Programming languages include, but are not limited to, languages such as Java, C++, Python, "C", or similar programming languages. The program code can be executed entirely on the user's computing device, partially on the user's device, partially on a remote computing device, or entirely on a remote computing device or server. In cases involving remote computing devices, the remote computing device can be connected to the user's computing device via any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computing device (e.g., via the Internet using an Internet service provider).
[0100] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this application. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram or flowchart, and combinations of blocks in a block diagram or flowchart, may be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.
[0101] Those skilled in the art will understand that the features described in the various embodiments of this application can be combined and / or combined in various ways, even if such combinations or combinations are not explicitly described in this application. In particular, the features described in the various embodiments of this application can be combined and / or combined in various ways without departing from the spirit and teachings of this application. All such combinations and / or combinations fall within the scope of this application.
Claims
1. A method for unlocking a user account, characterized in that, The method includes: In response to receiving a request to unlock a user account, and with the user's authorization to obtain multi-source heterogeneous data, the multi-source heterogeneous data associated with the user account is obtained. If it is determined that the user account is not on the preset risk list, the multi-source heterogeneous data is processed using a combined model to obtain the risk level of the user account. The combined model is composed of a machine learning model and a deep learning model. If the risk level is lower than the preset risk level range, the user account will be deactivated.
2. The method according to claim 1, characterized in that, The multi-source heterogeneous data includes static feature data and time-series feature data; The risk level of the user account is obtained by processing the multi-source heterogeneous data using a combined model, including: The static feature data is input into the machine learning model to obtain a first risk score for the static feature data; The time-series feature data is input into the deep learning model to obtain a second risk score for the time-series feature data. The risk level of the user account is obtained by weighting and fusing the first risk score and the second risk score.
3. The method according to claim 2, characterized in that, The first risk score and the second risk score are weighted and fused, including: The weights of the first risk score and the second risk score are determined based on the performance scores of the machine learning model and the deep learning model; wherein the performance score is determined by a combination of multiple preset performance indicators for each model.
4. The method according to claim 1, characterized in that, The method further includes: If the risk level is higher than the preset risk level range, the request to de-escalate is rejected.
5. The method according to claim 1, characterized in that, The method further includes: If the user account is identified as being on the risk list, the request to lift the control order is rejected.
6. The method according to claim 1, characterized in that, The method further includes: When the risk level is within the specified risk level range, the large language model is used to process the release request and the multi-source heterogeneous data to obtain the release basis for the user account. An operation prompt window is generated based on the decontrol criteria to prompt the user to input the decontrol result for the decontrol request; In response to receiving the decontrol result input in the operation prompt window, the decontrol request is processed according to the decontrol result.
7. The method according to claim 1, characterized in that, The method further includes: The risk trend report for the user account is generated by analyzing the multi-source heterogeneous data and the risk level using a large language model.
8. A device for unlocking user accounts, characterized in that, The device includes: The data acquisition module is used to respond to a request to unlock a user account, and, with the user's authorization to acquire multi-source heterogeneous data, acquire multi-source heterogeneous data associated with the user account. The risk level determination module is used to process the multi-source heterogeneous data using a combined model to obtain the risk level of the user account when it is determined that the user account is not on a preset risk list. The combined model is composed of a machine learning model and a deep learning model. The account decontrol module is used to decontrol the user account when the risk level is lower than a preset risk level range.
9. An electronic device, comprising: One or more processors; Memory, used to store one or more computer programs. The characteristic feature is that the one or more processors execute the one or more computer programs to implement the steps of the method according to any one of claims 1 to 7.
10. A computer-readable storage medium having a computer program or instructions stored thereon, characterized in that, When the computer program or instructions are executed by a processor, they implement the steps of the method according to any one of claims 1 to 7.
11. A computer program product, comprising a computer program or instructions, characterized in that, When the computer program or instructions are executed by a processor, they implement the steps of the method according to any one of claims 1 to 7.