Fraud risk grading and grading early warning method based on user portraits

By using a user profile-based fraud risk assessment method that combines user historical data and information characteristics, fraud risks are classified and warned, solving the problem of inconsistent results caused by a single perspective in existing technologies, and realizing personalized fraud risk identification and warning.

CN121531366AActive Publication Date: 2026-02-13NANJING BOSHENGYU NETWORK TECH CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202610056447.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-01-16
Publication Date
2026-02-13
Estimated Expiration
2046-01-16

AI Technical Summary

Technical Problem

Existing fraud risk assessment methods typically take only a single perspective and fail to consider the differences in anti-fraud awareness among different users, resulting in assessment results that do not match reality.

Method used

The fraud risk level classification and early warning method based on user profiles analyzes the historical network data of communication network users to extract fraud identification features and elimination schemes. Combined with user information features, a network test space is formed to classify and warn of fraud risks.

Benefits of technology

It enables targeted fraud risk identification and tiered early warning based on users' anti-fraud capabilities, ensuring that the warning results match the actual situation and avoiding false alarms.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121531366A_ABST
    Figure CN121531366A_ABST
Patent Text Reader

Abstract

The invention discloses a fraud risk grading and grading early warning method based on a user portrait, and relates to the technical field of anti-fraud, and the method comprises the steps: obtaining at least one communication network user accessing a communication network; analyzing and summarizing to obtain at least one fraud mode of the communication network user, obtaining a fraud identification feature, and obtaining at least one fraud elimination scheme corresponding to the fraud mode; basic information is obtained; obtaining an effective part; analyzing to obtain a mastering coefficient of the communication network user on the fraud elimination scheme, and comprehensively analyzing to obtain a fraud coefficient of the communication data to be detected on the communication network user; and carrying out grading and early warning on the to-be-detected communication data. By obtaining the fraud identification features, forming the fraud elimination scheme, obtaining at least one effective part, forming the mastering coefficient and forming the fraud coefficient, fraud risk analysis can be performed from two aspects of users and fraud at the same time, so that targeted fraud risk identification can be performed for each user.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of anti-fraud technology, specifically to a method for classifying and issuing early warnings of fraud risk levels based on user profiles. Background Technology

[0002] Fraud primarily originates from communications and can include telecommunications fraud, online fraud, etc. It mainly involves contacting users via phone calls or chat to lure them into being scammed. Fraud risk classification is a systematic assessment process typically used by financial institutions, payment platforms, communication service providers, or anti-fraud centers to identify, warn against, and intercept fraudulent activities of varying severity.

[0003] Existing fraud risk assessments are usually conducted from a single perspective, namely, from the perspective of fraud. It is assumed that different users have the same ability to identify fraud. However, in reality, different people have different awareness of fraud prevention. Therefore, using only a single perspective to conduct fraud risk assessment can easily lead to assessment results that do not match reality. Summary of the Invention

[0004] To address the aforementioned technical issues, this technical solution provides a method for classifying and issuing early warnings of fraud risk levels based on user profiles. The solution resolves the problems mentioned in the background section.

[0005] To achieve the above objectives, the technical solution adopted by the present invention is as follows: Fraud risk level classification and graded early warning methods based on user profiles include: Identify at least one user of a communication network that has access to the communication network, such as the Internet, telephone, or mobile phone. Based on historical network data of communication network users, at least one fraud pattern of communication network users is analyzed and summarized. Feature extraction is performed on the fraud pattern to obtain fraud identification features. Based on big data, at least one fraud elimination solution corresponding to the fraud pattern is obtained. Feature extraction is performed on the information of communication network users to obtain at least one basic piece of information; At least one network test space shall be constructed, and at least one piece of basic information shall be stored in the network test space; The communication data to be tested, received by the user of the communication network, is transmitted to the network test space. Based on the fraud mode, feature extraction is performed on the communication data to be tested to obtain at least one valid part. Based on basic information, the understanding coefficient of communication network users regarding fraud elimination schemes is obtained through analysis. Based on the understanding coefficient, the fraud coefficient of the communication data to be detected on communication network users is obtained through comprehensive analysis. Based on the fraud coefficient, the communication data to be detected is classified and an early warning is issued.

[0006] Preferably, the analysis and summarization of at least one fraud pattern of communication network users includes the following steps: In historical network data, at least one fraudulent incident is obtained, and the fraudulent incidents are deduplicated and clustered to obtain at least one fraudulent pattern.

[0007] Preferably, the step of extracting features from the fraud pattern to obtain fraud identification features includes the following steps: Identify historical communication data that resulted in economic losses for communication network users under fraudulent patterns, and segment the historical communication data into at least one basic data block. Based on at least one data basic block, at least one data basic block combination is formed. The data basic block combination is composed of several of the at least one data basic block. The at least one data basic block combination includes all combinations of at least one data basic block. If the combination of basic data blocks causes economic loss, then the combination of basic data blocks is used as the target combination of basic data blocks; otherwise, no action is taken. In the target data basic block combination, at least one target data basic block combination is selected as the feature data basic block combination. The feature data basic block combination satisfies that: each target data basic block combination can be formed by splicing together at least one feature data basic block combination. The basic blocks of feature data are combined as fraud identification features for fraud patterns.

[0008] Preferably, obtaining at least one fraud elimination solution corresponding to the fraud pattern based on big data includes the following steps: Obtain the information text of the fraudulent pattern as the first text, and obtain the information text other than the fraudulent pattern as the second text; The part of the second text that overlaps with the first text is taken as the third text, and the part of the first text that is not the third text is taken as the target part. Based on semantic recognition, the target part is divided into at least one independent word group. Based on semantic recognition, adjacent independent word groups are merged until the merged result is a complete sentence. The result of merging independent word groups is taken as at least one fraud identification feature in the information text of the fraud pattern. Fraud identification features are sequentially decomposed into at least one word, and at least one synonym of the word is obtained based on a Chinese database; The words in the fraud identification features are replaced with synonyms of the words, and each replacement result is used as an approximate fraud identification feature. Based on big data, strategies for eliminating similar fraud identification features are obtained. The elimination strategies for at least one similar fraud identification feature corresponding to the fraud identification feature in the fraud pattern are summarized as fraud elimination schemes corresponding to the fraud pattern.

[0009] Preferably, the step of extracting features from the information of communication network users to obtain at least one basic piece of information includes the following steps: The system acquires chat logs of communication network users on the Internet, extracts the reply information of communication network users from the chat logs, and divides the reply information into at least one basic piece of information based on semantic recognition. The basic piece of information is a complete sentence.

[0010] Preferably, the process of setting up at least one network test space includes the following steps: Generate at least one storage space to store at least one piece of basic information separately, and aggregate the at least one storage space storing the basic information to obtain the network test space.

[0011] Preferably, the step of extracting features from the communication data to be detected to obtain at least one effective portion includes the following steps: The communication data to be detected is evenly divided into at least one local block. If the local block appears in the approximate fraud identification feature, the local block is taken as the target local block and the target local block is matched to the fraudulent pattern corresponding to the approximate fraud identification feature. If there is no local block between two target local blocks, then the two target local blocks are regarded as adjacent target local blocks, and the adjacent target local blocks are spliced ​​together to obtain at least one suspected feature. The maximum value of the overlap ratio between the suspected feature and at least one approximate fraud identification feature is used as the verification value of the suspected feature. If the verification value of the suspected feature is greater than the preset value, the suspected feature is considered as a valid part.

[0012] The preset values ​​are obtained as follows: At least one fraud history event is obtained in advance. The overlapping part between the similar fraud identification features and the fraud history event is taken as the preset part. The proportion of the preset part to the similar fraud identification features is taken as the estimated proportion. The maximum value of at least one estimated proportion generated by a single historical fraud event is used as the baseline proportion, and the minimum value of the baseline proportion is used as the preset value.

[0013] Preferably, the analysis to obtain the knowledge coefficient of communication network users regarding the fraud elimination solution includes the following steps: The basic information is evenly divided into at least one word. Based on the Chinese database, synonyms of the words are obtained. The words in the basic information are replaced with the synonyms of the words. Each replacement method forms basic approximate information of the basic information.

[0014] The basic approximate information is summarized to obtain the overall basic information. The part of the overall basic information that overlaps with the fraud elimination plan is used as the reference part. The proportion of the reference part to the fraud elimination plan is used as the communication network user's mastery coefficient of the fraud elimination plan.

[0015] Preferably, the comprehensive analysis to obtain the fraud coefficient of the communication data to be detected for communication network users includes the following steps: The approximate fraud identification feature with the smallest difference from the effective part is taken as the target approximate fraud identification feature, and the fraud identification feature that generates the target approximate fraud identification feature is taken as the target fraud pattern. The number of approximate fraud identification features generated by the fraud identification features in the target fraud pattern is taken as the feature value of the target fraud pattern, and the number of approximate fraud identification features generated by the fraud identification features in the target fraud pattern is taken as the overall value of the target fraud pattern. The feature value of the target fraud pattern is divided by the total value of the target fraud pattern to obtain the feature coefficient of the target fraud pattern. The fraud elimination plan corresponding to the target fraud pattern is taken as the target fraud elimination plan. The fraud value of the target fraud elimination plan is obtained by subtracting the communication network user's mastery coefficient of the target fraud elimination plan from 1. The fraud coefficient is obtained by multiplying the fraud value of the target fraud elimination scheme with the characteristic coefficient of the corresponding target fraud pattern and summing them.

[0016] Preferably, the classification and early warning of the communication data to be detected includes the following steps: Obtain at least one historical communication data point, use the minimum and maximum values ​​of the fraud coefficient of the communication network user based on the historical communication data as endpoints to form an early warning interval, and evenly divide the early warning interval into at least one local interval. The local intervals are numbered from smallest to largest according to the value of the midpoint of the local interval. If the fraud coefficient belongs to a local interval, the local interval number is used as the risk level to match the communication data to be detected, and an early warning is issued.

[0017] Compared with the prior art, the beneficial effects of the present invention are as follows: By obtaining fraud identification features, formulating fraud elimination plans, obtaining at least one effective component, forming a mastery coefficient, and forming a fraud coefficient, fraud risk can be analyzed simultaneously from both the user and fraud perspectives. This allows for the identification of the success probability of fraud based on the specific circumstances of the fraud and the user's anti-fraud capabilities. Consequently, targeted fraud risk identification can be performed for each user, with corresponding level classifications and warnings, ensuring that the warning results match the actual situation and avoiding false alarms. Attached Figure Description

[0018] Figure 1 This is a flowchart illustrating the fraud risk level classification and graded early warning method based on user profiles of the present invention.

[0019] Figure 2 This is a schematic diagram illustrating the process of extracting features from a fraud pattern to obtain fraud identification features according to the present invention.

[0020] Figure 3 This is a flowchart illustrating the process of obtaining at least one fraud elimination solution corresponding to a fraud pattern based on big data, according to the present invention.

[0021] Figure 4 This is a schematic diagram of the process of extracting features from the communication data to be detected according to the present invention to obtain at least one effective part;

[0022] Figure 5 This is a flowchart illustrating the process of obtaining the knowledge coefficient of communication network users regarding fraud elimination solutions in the analysis of this invention.

[0023] Figure 6 This is a flowchart illustrating the process of obtaining the fraud coefficient of the communication data to be detected for communication network users through comprehensive analysis, as described in this invention.

[0024] Figure 7 This is a schematic diagram illustrating the process of classifying and issuing early warnings for the communication data to be detected according to the present invention. Detailed Implementation

[0025] The following description is intended to disclose the invention and enable those skilled in the art to implement it. The preferred embodiments described below are merely examples, and other obvious variations will occur to those skilled in the art.

[0026] Reference Figure 1 As shown, the fraud risk level classification and graded early warning method based on user profiles includes: Identify at least one user of a communication network that has access to the communication network, such as the Internet, telephone, or mobile phone. Based on historical network data of communication network users, at least one fraud pattern of communication network users is analyzed and summarized. Feature extraction is performed on the fraud pattern to obtain fraud identification features. Based on big data, at least one fraud elimination solution corresponding to the fraud pattern is obtained. Feature extraction is performed on the information of communication network users to obtain at least one basic piece of information; At least one network test space shall be constructed, and at least one piece of basic information shall be stored in the network test space; The communication data to be tested, received by the user of the communication network, is transmitted to the network test space. Based on the fraud mode, feature extraction is performed on the communication data to be tested to obtain at least one valid part. Based on basic information, the understanding coefficient of communication network users regarding fraud elimination schemes is obtained through analysis. Based on the understanding coefficient, the fraud coefficient of the communication data to be detected on communication network users is obtained through comprehensive analysis. Based on the fraud coefficient, the communication data to be detected is classified and an early warning is issued.

[0027] It is easy to see that different groups of people have different abilities to identify fraud. Therefore, for the same fraud, the risk of fraud may be low for user A, but high for user B. Therefore, when identifying fraud risk, it is necessary to identify different people differently. Only in this way can the same standard be used for classification and warning in the future. To this end, a series of steps are set up to handle this.

[0028] Analyzing and summarizing at least one pattern of fraud against communication network users includes the following steps: In historical network data, at least one fraudulent incident is obtained, and the fraudulent incidents are deduplicated and clustered to obtain at least one fraudulent pattern.

[0029] Reference Figure 2 As shown, the steps to extract features from the fraud pattern and obtain fraud identification features include: Identify historical communication data that resulted in economic losses for communication network users under fraudulent patterns, and segment the historical communication data into at least one basic data block. Based on at least one data basic block, at least one data basic block combination is formed. The data basic block combination is composed of several of the at least one data basic block. The at least one data basic block combination includes all combinations of at least one data basic block. If the combination of basic data blocks causes economic loss, then the combination of basic data blocks is used as the target combination of basic data blocks; otherwise, no action is taken. In the target data basic block combination, at least one target data basic block combination is selected as the feature data basic block combination. The feature data basic block combination satisfies that: each target data basic block combination can be formed by splicing together at least one feature data basic block combination. The basic blocks of feature data are combined as fraud identification features for fraud patterns.

[0030] Fraud identification features are used to identify fraud patterns. Fraud patterns are generated by fraudulent events, and therefore correspond to the text recording the fraud events. Fraud identification features can be extracted from this text. Based on the fraud identification features, it can be determined whether a fraud pattern has appeared or the degree to which it has appeared, and then the probability of success of the fraud under this fraud pattern can be estimated.

[0031] Reference Figure 3 As shown, based on big data, obtaining at least one fraud elimination solution corresponding to a fraud pattern includes the following steps: Obtain the information text of the fraudulent pattern as the first text, and obtain the information text other than the fraudulent pattern as the second text; The part of the second text that overlaps with the first text is taken as the third text, and the part of the first text that is not the third text is taken as the target part. Based on semantic recognition, the target part is divided into at least one independent word group. Based on semantic recognition, adjacent independent word groups are merged until the merged result is a complete sentence. The result of merging independent word groups is taken as at least one fraud identification feature in the information text of the fraud pattern. Fraud identification features are sequentially decomposed into at least one word, and at least one synonym of the word is obtained based on a Chinese database; The words in the fraud identification features are replaced with synonyms of the words, and each replacement result is used as an approximate fraud identification feature. Based on big data, strategies for eliminating similar fraud identification features are obtained. The elimination strategies for at least one similar fraud identification feature corresponding to the fraud identification feature in the fraud pattern are summarized as fraud elimination schemes corresponding to the fraud pattern.

[0032] The fraud pattern is determined by the fraud identification features. However, in the actual identification process, a completely precise method cannot be used. A fuzzy approximation method is required because text can be expressed in multiple ways, and the same meaning can be expressed in multiple ways. Therefore, by using synonym replacement, at least one approximate fraud identification feature corresponding to the fraud identification feature can be generated. Since the elimination strategy for approximate fraud identification features can be obtained from big data, because each fraud method is known and its elimination method is known, a fraud elimination scheme corresponding to the fraud pattern can be formed by summarizing these schemes.

[0033] Extracting features from information of communication network users to obtain at least one basic piece of information includes the following steps: The system acquires chat logs of communication network users on the Internet, extracts the reply information of communication network users from the chat logs, and divides the reply information into at least one basic piece of information based on semantic recognition. The basic piece of information is a complete sentence.

[0034] The main purpose of basic information is to assess the user's cognitive abilities in the future, and then determine the risk of being scammed in various fraud scenarios.

[0035] Setting up at least one network test space involves the following steps: Generate at least one storage space to store at least one piece of basic information separately, and aggregate the at least one storage space storing the basic information to obtain the network test space.

[0036] The network testing space is primarily used for evaluating fraud; all fraud is identified here.

[0037] Reference Figure 4 As shown, feature extraction of the communication data to be detected to obtain at least one effective portion includes the following steps: The communication data to be detected is evenly divided into at least one local block. If the local block appears in the approximate fraud identification feature, the local block is taken as the target local block and the target local block is matched to the fraudulent pattern corresponding to the approximate fraud identification feature.

[0038] If there is no local block between two target local blocks, then the two target local blocks are regarded as adjacent target local blocks, and the adjacent target local blocks are spliced ​​together to obtain at least one suspected feature.

[0039] The maximum value of the overlap ratio between the suspected feature and at least one approximate fraud identification feature is used as the verification value of the suspected feature. If the verification value of the suspected feature is greater than the preset value, the suspected feature is considered as a valid part.

[0040] The preset values ​​are obtained as follows: At least one fraud history event is obtained in advance. The overlapping part between the similar fraud identification features and the fraud history event is taken as the preset part. The proportion of the preset part to the similar fraud identification features is taken as the estimated proportion. The maximum value of at least one estimated proportion generated by a single historical fraud event is used as the baseline proportion, and the minimum value of the baseline proportion is used as the preset value.

[0041] Here, the maximum value of the overlap ratio between the suspected feature and at least one approximate fraud identification feature is used as the verification value of the suspected feature. This means that there is an overlap ratio between the suspected feature and the approximate fraud identification feature, and there are different overlap ratios between the suspected feature and each approximate fraud identification feature. The maximum value of these overlap ratios is used as the verification value of the suspected feature.

[0042] When identifying the effective part, fuzzy identification is also used. That is, it is not necessary for the two to be completely identical before the suspected feature is considered as the effective part. As long as they are similar enough, it means that they can produce the same effect as the similar fraud identification features. Therefore, they can be considered as the effective part.

[0043] Fraudulent historical events themselves necessarily contain features that have the same effect as a certain similar fraud identification feature, which are denoted as reference features. Therefore, the estimated ratio is the approximate ratio of the reference feature to the closest similar fraud identification feature. However, this value will fluctuate in different fraudulent historical events. Therefore, we take its minimum value as the preset value. Using the preset value for approximate judgment can meet almost all identification needs.

[0044] Reference Figure 5 As shown, the analysis of the communication network users' understanding of the fraud elimination solution includes the following steps: The basic information is evenly divided into at least one word. Based on the Chinese database, synonyms of the words are obtained. The words in the basic information are replaced with the synonyms of the words. Each replacement method forms basic approximate information of the basic information. The basic approximate information is summarized to obtain the overall basic information. The part of the overall basic information that overlaps with the fraud elimination plan is used as the reference part. The proportion of the reference part to the fraud elimination plan is used as the communication network user's mastery coefficient of the fraud elimination plan.

[0045] The probability of a telecommunications network user being scammed is mainly determined by their ability to identify scams. Therefore, based on their chat history, general basic information is generated, and by comparing the general basic information with the scam elimination plan, the degree to which the telecommunications network user understands the scam elimination plan can be determined.

[0046] Reference Figure 6 As shown, the comprehensive analysis to obtain the fraud coefficient of the communication data to be detected for communication network users includes the following steps: The approximate fraud identification feature with the smallest difference from the effective part is taken as the target approximate fraud identification feature, and the fraud identification feature that generates the target approximate fraud identification feature is taken as the target fraud pattern. The number of approximate fraud identification features generated by the fraud identification features in the target fraud pattern is taken as the feature value of the target fraud pattern, and the number of approximate fraud identification features generated by the fraud identification features in the target fraud pattern is taken as the overall value of the target fraud pattern. The feature value of the target fraud pattern is divided by the total value of the target fraud pattern to obtain the feature coefficient of the target fraud pattern. The fraud elimination plan corresponding to the target fraud pattern is taken as the target fraud elimination plan. The fraud value of the target fraud elimination plan is obtained by subtracting the communication network user's mastery coefficient of the target fraud elimination plan from 1. The fraud coefficient is obtained by multiplying the fraud value of the target fraud elimination scheme with the characteristic coefficient of the corresponding target fraud pattern and summing them.

[0047] The mastery coefficient of a communication network user regarding a target fraud elimination solution is the proportion of the communication network user's mastery of the content in the target fraud elimination solution. Therefore, the fraud value of a target fraud elimination solution is the proportion of the communication network user's lack of mastery of the content in the target fraud elimination solution. Thus, the risk of being defrauded is the sum of the fraud values ​​of the target fraud elimination solutions corresponding to the target fraud patterns appearing in the communication data to be detected. However, it should be noted that the fewer fraud features appear in the target fraud pattern, the less sufficiency the solution has, and therefore the lower the success rate of its implementation. Therefore, this needs to be taken into consideration when summing. Thus, the fraud value of the target fraud elimination solution is multiplied by the feature coefficient of the corresponding target fraud pattern and then summed to obtain the fraud coefficient.

[0048] Reference Figure 7 As shown, the classification and early warning of the communication data to be detected includes the following steps: Obtain at least one historical communication data point, use the minimum and maximum values ​​of the fraud coefficient of the communication network user based on the historical communication data as endpoints to form an early warning interval, and evenly divide the early warning interval into at least one local interval. The local intervals are numbered from smallest to largest according to the value of the midpoint of the local interval. If the fraud coefficient belongs to a local interval, the local interval number is used as the risk level to match the communication data to be detected, and an early warning is issued.

[0049] Because this method is used to obtain fraud coefficients multiple times in advance, a series of historical data can be generated, which in turn forms a warning interval. The warning interval can be divided in a regular manner to perform classification and warning.

[0050] Furthermore, this solution also proposes a storage medium on which a computer-readable program is stored. When the computer-readable program is invoked, it runs the aforementioned method for classifying and classifying fraud risk levels based on user profiles.

[0051] It is understandable that the storage medium can be a magnetic medium, such as a floppy disk, hard disk, or magnetic tape; an optical medium, such as a DVD; or a semiconductor medium, such as a solid-state drive (SSD).

[0052] In summary, the advantages of this invention are as follows: by obtaining fraud identification features, forming a fraud elimination scheme, obtaining at least one effective component, forming a mastery coefficient, and forming a fraud coefficient, it is possible to analyze fraud risk from both the user and fraud perspectives simultaneously. This allows for the identification of the success probability of fraud based on the specific circumstances of the fraud and the user's anti-fraud capabilities. Consequently, targeted fraud risk identification can be performed for each user, with corresponding level classifications and warnings, ensuring that the warning results match the actual situation and avoiding false alarms.

[0053] The foregoing has shown and described the basic principles, main features, and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited to the above embodiments. The embodiments and descriptions in the specification are merely principles of the invention. Various changes and modifications can be made to the invention without departing from its spirit and scope, and all such changes and modifications fall within the scope of the claimed invention. The scope of protection claimed by the appended claims and their equivalents is defined.

Claims

1. A method for classifying and tiered early warning of fraud risk levels based on user profiles, characterized in that, include: Identify at least one user of a communication network that has access to the communication network, such as the Internet, telephone, or mobile phone. Based on historical network data of communication network users, at least one fraud pattern of communication network users is analyzed and summarized. Feature extraction is performed on the fraud pattern to obtain fraud identification features. Based on big data, at least one fraud elimination solution corresponding to the fraud pattern is obtained. Feature extraction is performed on the information of communication network users to obtain at least one basic piece of information; At least one network test space shall be constructed, and at least one piece of basic information shall be stored in the network test space; The communication data to be tested, received by the user of the communication network, is transmitted to the network test space. Based on the fraud mode, feature extraction is performed on the communication data to be tested to obtain at least one valid part. Based on basic information, the understanding coefficient of communication network users regarding fraud elimination schemes is obtained through analysis. Based on the understanding coefficient, the fraud coefficient of the communication data to be detected on communication network users is obtained through comprehensive analysis. Based on the fraud coefficient, the communication data to be detected is classified and an early warning is issued.

2. The method for classifying and grading fraud risk levels based on user profiles as described in claim 1, characterized in that, The analysis and summarization of at least one fraud pattern for communication network users includes the following steps: In historical network data, at least one fraudulent incident is obtained, and the fraudulent incidents are deduplicated and clustered to obtain at least one fraudulent pattern.

3. The method for classifying and issuing early warnings of fraud risk levels based on user profiles according to claim 2, characterized in that, The process of extracting features from the fraud pattern to obtain fraud identification features includes the following steps: Identify historical communication data that resulted in economic losses for communication network users under fraudulent patterns, and segment the historical communication data into at least one basic data block. Based on at least one data basic block, at least one data basic block combination is formed. The data basic block combination is composed of several of the at least one data basic block. The at least one data basic block combination includes all combinations of at least one data basic block. If the combination of basic data blocks causes economic loss, then the combination of basic data blocks is used as the target combination of basic data blocks; otherwise, no action is taken. In the target data basic block combination, at least one target data basic block combination is selected as the feature data basic block combination. The feature data basic block combination satisfies that: each target data basic block combination can be formed by splicing together at least one feature data basic block combination. The basic blocks of feature data are combined as fraud identification features for fraud patterns.

4. The method for classifying and issuing early warnings of fraud risk levels based on user profiles according to claim 3, characterized in that, The method of obtaining at least one fraud elimination solution corresponding to a fraud pattern based on big data includes the following steps: Obtain the information text of the fraudulent pattern as the first text, and obtain the information text other than the fraudulent pattern as the second text; The part of the second text that overlaps with the first text is taken as the third text, and the part of the first text that is not the third text is taken as the target part. Based on semantic recognition, the target part is divided into at least one independent word group. Based on semantic recognition, adjacent independent word groups are merged until the merged result is a complete sentence. The result of merging independent word groups is taken as at least one fraud identification feature in the information text of the fraud pattern. Fraud identification features are sequentially decomposed into at least one word, and at least one synonym of the word is obtained based on a Chinese database; The words in the fraud identification features are replaced with synonyms of the words, and each replacement result is used as an approximate fraud identification feature. Based on big data, strategies for eliminating similar fraud identification features are obtained. The elimination strategies for at least one similar fraud identification feature corresponding to the fraud identification feature in the fraud pattern are summarized as fraud elimination schemes corresponding to the fraud pattern.

5. The method for classifying and grading fraud risk levels based on user profiles as described in claim 4, characterized in that, The step of extracting features from the information of communication network users to obtain at least one basic piece of information includes the following steps: The system acquires chat logs of communication network users on the Internet, extracts the reply information of communication network users from the chat logs, and divides the reply information into at least one basic piece of information based on semantic recognition. The basic piece of information is a complete sentence.

6. The method for classifying and grading fraud risk levels based on user profiles as described in claim 5, characterized in that, The process of setting up at least one network test space includes the following steps: Generate at least one storage space to store at least one piece of basic information separately, and aggregate the at least one storage space storing the basic information to obtain the network test space.

7. The method for classifying and grading fraud risk levels based on user profiles as described in claim 6, characterized in that, The process of extracting features from the communication data to be detected to obtain at least one effective portion includes the following steps: The communication data to be detected is evenly divided into at least one local block. If the local block appears in the approximate fraud identification feature, the local block is taken as the target local block and the target local block is matched to the fraudulent pattern corresponding to the approximate fraud identification feature. If there is no local block between two target local blocks, then the two target local blocks are regarded as adjacent target local blocks, and the adjacent target local blocks are spliced ​​together to obtain at least one suspected feature. The maximum value of the overlap ratio between the suspected feature and at least one approximate fraud identification feature is used as the verification value of the suspected feature. If the verification value of the suspected feature is greater than the preset value, the suspected feature is considered as a valid part. The preset values ​​are obtained as follows: At least one fraud history event is obtained in advance. The overlapping part between the similar fraud identification features and the fraud history event is taken as the preset part. The proportion of the preset part to the similar fraud identification features is taken as the estimated proportion. The maximum value of at least one estimated proportion generated by a single historical fraud event is used as the baseline proportion, and the minimum value of the baseline proportion is used as the preset value.

8. The method for classifying and grading fraud risk levels based on user profiles as described in claim 7, characterized in that, The analysis to obtain the communication network users' understanding of fraud prevention solutions includes the following steps: The basic information is evenly divided into at least one word. Based on the Chinese database, synonyms of the words are obtained. The words in the basic information are replaced with the synonyms of the words. Each replacement method forms basic approximate information of the basic information. The basic approximate information is summarized to obtain the overall basic information. The part of the overall basic information that overlaps with the fraud elimination plan is used as the reference part. The proportion of the reference part to the fraud elimination plan is used as the communication network user's mastery coefficient of the fraud elimination plan.

9. The method for classifying and grading fraud risk levels based on user profiles as described in claim 8, characterized in that, The comprehensive analysis to obtain the fraud coefficient of the communication data to be detected for communication network users includes the following steps: The approximate fraud identification feature with the smallest difference from the effective part is taken as the target approximate fraud identification feature, and the fraud identification feature that generates the target approximate fraud identification feature is taken as the target fraud pattern. The number of approximate fraud identification features generated by the fraud identification features in the target fraud pattern is taken as the feature value of the target fraud pattern, and the number of approximate fraud identification features generated by the fraud identification features in the target fraud pattern is taken as the overall value of the target fraud pattern. The feature value of the target fraud pattern is divided by the total value of the target fraud pattern to obtain the feature coefficient of the target fraud pattern. The fraud elimination plan corresponding to the target fraud pattern is taken as the target fraud elimination plan. The fraud value of the target fraud elimination plan is obtained by subtracting the communication network user's mastery coefficient of the target fraud elimination plan from 1. The fraud coefficient is obtained by multiplying the fraud value of the target fraud elimination scheme with the characteristic coefficient of the corresponding target fraud pattern and summing them.

10. The method for classifying and grading fraud risk levels based on user profiles as described in claim 9, characterized in that, The process of classifying and issuing early warnings for the communication data to be detected includes the following steps: Obtain at least one historical communication data point, use the minimum and maximum values ​​of the fraud coefficient of the communication network user based on the historical communication data as endpoints to form an early warning interval, and evenly divide the early warning interval into at least one local interval. The local intervals are numbered from smallest to largest according to the value of the midpoint of the local interval. If the fraud coefficient belongs to a local interval, the local interval number is used as the risk level to match the communication data to be detected, and an early warning is issued.

Citation Information

Patent Citations

  • Network finance anti-fraud method and device, electronic equipment and medium

    CN118096353A

  • Fraud identification method and device, electronic equipment and storage medium

    CN118674465A

  • Anti-fraud joint defense early warning method and system

    CN119476950A

  • Telecommunication fraud risk identification method based on bank card transfer scene

    CN121258517A

  • KR20250150195A