Fraud risk level classification and grading early warning method based on user portrait

By using a user profile-based fraud risk assessment method, combined with big data and semantic recognition technology, fraud risk assessments are conducted based on the anti-fraud awareness of different users. This solves the problem of inconsistent assessment results in existing technologies and enables personalized fraud risk identification and early warning.

CN121531366BActive Publication Date: 2026-03-27NANJING BOSHENGYU NETWORK TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2026-01-16
Publication Date
2026-03-27

AI Technical Summary

Technical Problem

Existing fraud risk assessments are usually conducted from a single perspective, failing to consider the differences in anti-fraud awareness among different users, resulting in assessment results that do not match reality.

Method used

Based on user profiles, fraud identification features and elimination schemes are extracted by analyzing historical network data of communication network users. Combined with user information features, fraud risk is classified and early warning is issued. Big data and semantic recognition technologies are used for fuzzy matching and evaluation.

Benefits of technology

It enables personalized fraud risk identification and early warning based on users' anti-fraud capabilities, improving the accuracy of assessment results and avoiding false alarms.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121531366B_ABST
    Figure CN121531366B_ABST
Patent Text Reader

Abstract

The application discloses a fraud risk level division and graded early warning method based on user portrait, relates to the technical field of anti-fraud, and comprises the following steps: obtaining at least one communication network user accessing a communication network; analyzing and summarizing at least one fraud mode of the communication network user to obtain fraud identification features, obtaining at least one fraud elimination scheme corresponding to the fraud mode; obtaining basic information; obtaining an effective part; analyzing to obtain a mastering coefficient of the communication network user to the fraud elimination scheme, comprehensively analyzing to obtain a fraud coefficient of the to-be-detected communication data to the communication network user; and grading and early warning the to-be-detected communication data. The fraud risk can be analyzed from the two aspects of the user and fraud by obtaining the fraud identification features, forming the fraud elimination scheme, obtaining at least one effective part, forming the mastering coefficient and forming the fraud coefficient, so that the fraud risk of each user can be identified.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of anti-fraud, in particular to a fraud risk level division and grading early warning method based on user portrait. BACKGROUND

[0002] Fraud is mainly generated by communication, which can be telecom fraud, network fraud, etc. It mainly induces users to be defrauded by talking or chatting with them. Fraud risk level division is a systematic evaluation process, which is usually used by financial institutions, payment platforms, communication service providers or anti-fraud centers to identify, warn and intercept frauds of different severity.

[0003] Existing fraud risk assessment is usually only from a single perspective, that is, from the perspective of fraud analysis. For different users, it is assumed that their ability to identify fraud is consistent, but in reality, people's anti-fraud awareness is different. Therefore, only using a single perspective to evaluate fraud risk may result in an evaluation result that does not match the actual situation. SUMMARY

[0004] To solve the above technical problems, the fraud risk level division and grading early warning method based on user portrait is provided, which solves the problems in the background technology.

[0005] To achieve the above purpose, the technical scheme adopted by the present application is:

[0006] The fraud risk level division and grading early warning method based on user portrait comprises:

[0007] At least one communication network user accessing the communication network is obtained, and the communication network is the Internet, telephone and mobile phone;

[0008] Based on the historical network data of the communication network user, at least one fraud mode of the communication network user is analyzed and summarized, the fraud recognition features are extracted from the fraud mode, at least one fraud elimination scheme corresponding to the fraud mode is obtained based on big data;

[0009] The information of the communication network user is extracted to obtain at least one basic information;

[0010] At least one network test space is built to store at least one basic information in the network test space;

[0011] The communication data to be detected received by the communication network user is transmitted to the network test space, and the communication data to be detected is extracted based on the fraud mode to obtain at least one effective part;

[0012] Based on the basic information, a grasping coefficient of the communication network user to the fraud elimination scheme is analyzed, and a fraud coefficient of the to-be-detected communication data to the communication network user is comprehensively analyzed according to the grasping coefficient;

[0013] Based on the fraud coefficient, the to-be-detected communication data is graded and warned.

[0014] Preferably, the analysis and summarization to obtain at least one fraud mode of the communication network user comprises the following steps:

[0015] In the historical network data, at least one fraud event is obtained, and the fraud events are de-duplicated and clustered to obtain at least one fraud mode.

[0016] Preferably, the feature extraction of the fraud mode to obtain the fraud identification feature comprises the following steps:

[0017] The historical communication data of the communication network user in the historical network data in the fraud mode is identified, and the historical communication data is divided into at least one data basic block.

[0018] Based on the at least one data basic block, at least one data basic block combination is formed, the data basic block combination is composed of a plurality of data basic blocks in the at least one data basic block, and the at least one data basic block combination contains all combination conditions of the at least one data basic block.

[0019] It is detected whether the data basic block combination causes economic loss, if yes, the data basic block combination is taken as a target data basic block combination, and if not, no processing is performed.

[0020] In the target data basic block combination, at least one target data basic block combination is selected as a feature data basic block combination, and the feature data basic block combination satisfies that the target data basic block combination can be composed by splicing the at least one feature data basic block combination.

[0021] The feature data basic block combination is taken as the fraud identification feature of the fraud mode.

[0022] Preferably, the at least one fraud elimination scheme corresponding to the fraud mode is obtained based on big data, and the at least one fraud elimination scheme comprises the following steps:

[0023] An information text of the fraud mode is obtained as a first text, and an information text other than the fraud mode is obtained as a second text.

[0024] The part of the second text coinciding with the first text is taken as a third text, and the part of the first text other than the third text is taken as a target part, the target part is divided into at least one independent word group based on semantic recognition.

[0025] merging adjacent independent phrases until the merged results are complete sentences, and taking the merged results of the independent phrases as at least one fraud recognition feature existing in the information text of the fraud pattern;

[0026] decomposing the fraud recognition feature into at least one word in sequence, and obtaining at least one synonym of the word based on a Chinese database;

[0027] replacing the word in the fraud recognition feature with the synonym of the word, and taking each replacement result as an approximate fraud recognition feature;

[0028] obtaining an elimination strategy of the approximate fraud recognition feature based on big data, and taking the elimination strategies of at least one approximate fraud recognition feature corresponding to the fraud recognition feature in the fraud pattern as a fraud elimination scheme corresponding to the fraud pattern.

[0029] Preferably, the feature extraction on the information of the communication network user includes the following steps:

[0030] obtaining chat records of the communication network user on the Internet, extracting reply information of the communication network user in the chat records, and dividing the reply information into at least one basic information based on semantic recognition, the basic information being a complete sentence.

[0031] Preferably, the building of the network test space includes the following steps:

[0032] generating at least one storage space to respectively store at least one basic information, and taking the at least one storage space storing the basic information as the network test space.

[0033] Preferably, the feature extraction on the to-be-detected communication data includes the following steps:

[0034] uniformly segmenting the to-be-detected communication data into at least one local block, taking the local block as a target local block if the local block appears in the approximate fraud recognition feature, and matching the target local block to the fraud pattern corresponding to the approximate fraud recognition feature;

[0035] taking two target local blocks as adjacent target local blocks if there is no local block between the two target local blocks, and splicing the adjacent target local blocks to obtain at least one suspected feature;

[0036] taking the maximum value of the coincidence ratio of the suspected feature and the at least one approximate fraud recognition feature as a verification value of the suspected feature, and taking the suspected feature as an effective part if the verification value of the suspected feature is greater than a preset value;

[0037] The preset value is obtained as follows:

[0038] acquiring at least one fraud history event in advance, taking the coincident part of the approximate fraud identification feature and the fraud history event as a preset part, taking the proportion of the preset part in the approximate fraud identification feature as a preset proportion;

[0039] taking the maximum value of at least one preset proportion generated by a single fraud history event as a benchmark proportion, and taking the minimum value of the benchmark proportion as a preset value.

[0040] Preferably, the analysis of the communication network user's mastery coefficient of the fraud elimination scheme comprises the following steps:

[0041] uniformly segmenting the basic information into at least one word, acquiring the synonym of the word based on a Chinese database, replacing the word in the basic information with the synonym of the word, and forming the basic approximate information of the basic information in each replacement mode;

[0042] summarizing the basic approximate information to obtain the overall basic information, taking the coincident part of the overall basic information and the fraud elimination scheme as a reference part, and taking the proportion of the reference part in the fraud elimination scheme as the communication network user's mastery coefficient of the fraud elimination scheme.

[0043] Preferably, the comprehensive analysis of the fraud coefficient of the communication data to be detected to the communication network user comprises the following steps:

[0044] taking the approximate fraud identification feature with the minimum distance from the effective part as a target approximate fraud identification feature, and taking the fraud identification feature in the target approximate fraud identification feature as a target fraud identification feature;

[0045] taking the number of the target approximate fraud identification features generated by the fraud identification features in the target fraud identification mode as a feature value of the target fraud identification mode, and taking the number of the approximate fraud identification features generated by the fraud identification features in the target fraud identification mode as a total value of the target fraud identification mode;

[0046] dividing the feature value of the target fraud identification mode by the total value of the target fraud identification mode to obtain a feature coefficient of the target fraud identification mode;

[0047] taking the fraud elimination scheme corresponding to the target fraud identification mode as a target fraud elimination scheme, and taking 1 minus the communication network user's mastery coefficient of the target fraud elimination scheme as a fraud value of the target fraud elimination scheme;

[0048] multiplying the fraud value of the target fraud elimination scheme and the feature coefficient of the corresponding target fraud identification mode and accumulating to obtain a fraud coefficient.

[0049] Preferably, the grading and early warning of the communication data to be detected comprises the following steps:

[0050] At least one historical communication data is obtained, the minimum and maximum values of the fraud coefficient of the communication network user are used as the end points of the historical communication data, a warning interval is formed, and the warning interval is evenly divided into at least one local interval;

[0051] The local intervals are numbered from small to large according to the numerical values of the midpoints of the local intervals, and if the fraud coefficient belongs to a local interval, the number of the local interval is matched to the risk level of the communication data to be detected, and an early warning is issued.

[0052] Compared with the prior art, the present application has the beneficial effects that:

[0053] By obtaining the fraud recognition feature, forming the fraud elimination scheme, obtaining at least one effective part, forming the mastery coefficient, and forming the fraud coefficient, the fraud risk can be analyzed from the user and the fraud at the same time, the success probability of the fraud can be identified according to the fraud situation and the anti-fraud ability of the user, the fraud risk of each user can be identified and graded and warned accordingly, and the result of the early warning can be consistent with the actual situation, avoiding false positives. BRIEF DESCRIPTION OF DRAWINGS

[0054] Figure 1 It is a flowchart of the fraud risk grading and early warning method based on user portrait of the present application;

[0055] Figure 2 It is a flowchart of the feature extraction of the fraud pattern to obtain the fraud recognition feature of the present application;

[0056] Figure 3 It is a flowchart of obtaining at least one fraud elimination scheme corresponding to the fraud pattern based on big data of the present application;

[0057] Figure 4 It is a flowchart of the feature extraction of the communication data to be detected to obtain at least one effective part of the present application;

[0058] Figure 5 It is a flowchart of the analysis to obtain the mastery coefficient of the communication network user to the fraud elimination scheme of the present application;

[0059] Figure 6 It is a flowchart of the comprehensive analysis to obtain the fraud coefficient of the communication network user to the communication data to be detected of the present application;

[0060] Figure 7 It is a flowchart of the grading and early warning of the communication data to be detected of the present application. DETAILED DESCRIPTION

[0061] The following description is presented to enable any person skilled in the art to practice the application as claimed. The preferred embodiments disclosed herein are only examples of the many possible variations of the present application.

[0062] Referring to Figure 1 As shown, the user portrait-based fraud risk level classification and early warning method includes:

[0063] At least one communication network user accessing a communication network is obtained, and the communication network is the Internet, telephone, and mobile phone.

[0064] Based on the historical network data of the communication network user, at least one fraud mode of the communication network user is analyzed and summarized, the fraud mode is feature extracted to obtain fraud identification features, and based on big data, at least one fraud elimination scheme corresponding to the fraud mode is obtained.

[0065] The information of the communication network user is feature extracted to obtain at least one basic information.

[0066] At least one network test space is built, and at least one basic information is stored in the network test space.

[0067] The communication data to be detected received by the communication network user is transmitted to the network test space, and based on the fraud mode, the communication data to be detected is feature extracted to obtain at least one effective part.

[0068] Based on the basic information, the communication network user's mastery coefficient of the fraud elimination scheme is analyzed to obtain, and according to the mastery coefficient, the fraud coefficient of the communication data to be detected to the communication network user is comprehensively analyzed.

[0069] Based on the fraud coefficient, the communication data to be detected is classified and warned.

[0070] As can be easily known, different people have different abilities to identify fraud, so for the same fraud, it may have a smaller fraud risk for user A, but a larger fraud risk for user B, therefore, when identifying fraud risk, different people need to be identified differently, and thus the same standard can be used for classification and warning in the subsequent use. For this purpose, a series of steps are set up to handle it.

[0071] The at least one fraud mode of the communication network user is analyzed and summarized, including the following steps:

[0072] In the historical network data, at least one fraud event is obtained, and the fraud event is de-duplicated and clustered to obtain at least one fraud mode.

[0073] Referring toFigure 2 As shown, the feature extraction is performed on the fraud mode to obtain the fraud recognition features, which includes the following steps:

[0074] The historical communication data of the communication network user in the fraud mode is identified, and the historical communication data is divided into at least one data basic block;

[0075] Based on the at least one data basic block, at least one data basic block combination is formed, the data basic block combination is composed of several data basic blocks in the at least one data basic block, and the at least one data basic block combination contains all combination conditions of the at least one data basic block;

[0076] It is detected whether the data basic block combination causes economic loss. If yes, the data basic block combination is taken as a target data basic block combination, and if no, no processing is performed;

[0077] In the target data basic block combination, at least one target data basic block combination is selected as a feature data basic block combination, and the feature data basic block combination satisfies that the target data basic block combination can be composed by splicing the at least one feature data basic block combination;

[0078] The feature data basic block combination is taken as the fraud recognition feature of the fraud mode.

[0079] The fraud recognition feature is used for identifying the fraud mode. The fraud mode is caused by the fraud event, and therefore, it corresponds to the text recording the fraud event. Therefore, the fraud recognition feature can be extracted in the text. Thus, it can be judged whether the fraud mode appears or the degree of appearance according to the fraud recognition feature, and further, the possibility of the fraud success of the fraud mode can be estimated.

[0080] Referring to Figure 3 As shown, based on big data, at least one fraud elimination scheme corresponding to the fraud mode is obtained, which includes the following steps:

[0081] An information text of the fraud mode is obtained as a first text, and an information text other than the fraud mode is obtained as a second text;

[0082] The part of the second text coinciding with the first text is taken as a third text, and the part of the first text other than the third text is taken as a target part. Based on semantic recognition, the target part is divided into at least one independent word group;

[0083] Based on semantic recognition, adjacent independent word groups are merged until the merged results are all complete sentences. The merged results of the independent word groups are taken as at least one fraud recognition feature existing in the information text of the fraud mode;

[0084] The fraud identification feature is sequentially decomposed into at least one word, at least one synonym of the word is obtained based on a Chinese database, and the synonym of the word is replaced in the fraud identification feature, and each replacement result is taken as an approximate fraud identification feature;

[0085] The synonym of the word is replaced in the fraud identification feature, and each replacement result is taken as an approximate fraud identification feature.

[0086] Based on big data, the elimination strategy of the approximate fraud identification feature is obtained, the elimination strategy of at least one approximate fraud identification feature corresponding to the fraud identification feature in the fraud mode is summarized as the fraud elimination scheme corresponding to the fraud mode.

[0087] The fraud mode is determined by the fraud identification feature, but in the actual identification process, it cannot be identified in a completely accurate manner, and needs to be identified in a fuzzy approximate manner, because the expression of the text has multiple ways, and the same meaning can be expressed in multiple ways. Therefore, at least one approximate fraud identification feature corresponding to the fraud identification feature is generated by the synonym replacement method, and because the elimination strategy of the approximate fraud identification feature can be obtained through big data, because each fraud method is known, its elimination method is known, therefore, it can be summarized to form the fraud elimination scheme corresponding to the fraud mode.

[0088] The information of the communication network user is extracted to obtain at least one basic information, including the following steps:

[0089] Obtain the chat record of the communication network user in the Internet, extract the reply information of the communication network user in the chat record, and divide the reply information into at least one basic information based on semantic recognition. The basic information is a complete sentence.

[0090] The function of the basic information is mainly to evaluate the cognitive ability of the user in the subsequent process, and then judge the risk of being cheated in various fraud cases.

[0091] At least one network test space is built, including the following steps:

[0092] At least one storage space is generated to store at least one basic information respectively, and at least one storage space storing the basic information is summarized to obtain a network test space.

[0093] The network test space is mainly used for evaluating fraud, that is, all frauds are identified in this space.

[0094] Referring to Figure 4 The feature of the communication data to be detected is extracted to obtain at least one effective part, including the following steps:

[0095] The communication data to be detected is evenly divided into at least one local block, if the local block appears in the approximate fraud identification feature, the local block is taken as a target local block, and the target local block is matched to the fraud mode corresponding to the approximate fraud identification feature;

[0096] If there is no local block between the two target local blocks, the two target local blocks are taken as adjacent target local blocks, and the adjacent target local blocks are spliced to obtain at least one suspected feature;

[0097] The maximum value of the overlap ratio of the suspected feature and the at least one approximate fraud identification feature is taken as a verification value of the suspected feature, and if the verification value of the suspected feature is greater than a preset value, the suspected feature is taken as an effective part;

[0098] The preset value is obtained as follows:

[0099] At least one fraud historical event is obtained in advance, the overlapping part of the approximate fraud identification feature and the fraud historical event is taken as a preset part, and the proportion of the preset part to the approximate fraud identification feature is taken as an estimated proportion;

[0100] The maximum value of the at least one estimated proportion generated by a single fraud historical event is taken as a reference proportion, and the minimum value of the reference proportion is taken as the preset value.

[0101] Here, the maximum value of the overlap ratio of the suspected feature and the at least one approximate fraud identification feature is taken as the verification value of the suspected feature, which means that there is an overlap ratio between the suspected feature and the approximate fraud identification feature, and there is a different overlap ratio between each approximate fraud identification feature. The maximum value of these overlap ratios is taken as the verification value of the suspected feature;

[0102] In the effective part identification, fuzzy identification is also used, that is, the suspected feature is not required to be completely consistent with the approximate fraud identification feature, but only needs to be similar enough to be taken as an effective part, which can produce the same effect as the approximate fraud identification feature.

[0103] The fraud historical event itself necessarily contains a feature with the same effect as a certain approximate fraud identification feature, which is referred to as a reference feature. Therefore, the estimated proportion obtained is the approximate proportion of the reference feature and the closest approximate fraud identification feature. However, the value will fluctuate in different fraud historical events. Therefore, the minimum value is taken as the preset value, and the approximate judgment using the preset value can meet almost all identification requirements.

[0104] Referring to Figure 5 As shown in the figure, the analysis of the communication network user's mastery coefficient of the fraud elimination scheme includes the following steps:

[0105] Divide the basic information into at least one word, obtain the synonyms of the word based on the Chinese database, replace the word in the basic information with the synonyms of the word, and each replacement forms basic approximate information of the basic information;

[0106] Summarize the basic approximate information to obtain overall basic information, and the overlapping part of the overall basic information and the fraud elimination scheme is taken as a reference part, and the proportion of the reference part in the fraud elimination scheme is taken as a master coefficient of the communication network user to the fraud elimination scheme.

[0107] The probability of being cheated of the communication network user is mainly determined by the ability to identify fraud, therefore, the overall basic information is generated according to the chat record, and the degree of master of the communication network user to the fraud elimination scheme is judged through the overlapping part of the overall basic information and the fraud elimination scheme.

[0108] Referring to Figure 6 As shown in the figure, the comprehensive analysis of the fraud coefficient of the communication data to be detected to the communication network user includes the following steps:

[0109] The approximate fraud identification feature with the smallest distance from the effective part is taken as the target approximate fraud identification feature, and the fraud identification feature in the target fraud identification feature is taken as the target fraud identification feature.

[0110] The number of target approximate fraud identification features generated by the fraud identification features in the target fraud identification mode is taken as the feature value of the target fraud identification mode, and the number of approximate fraud identification features generated by the fraud identification features in the target fraud identification mode is taken as the overall value of the target fraud identification mode.

[0111] The feature value of the target fraud identification mode is divided by the overall value of the target fraud identification mode to obtain the feature coefficient of the target fraud identification mode.

[0112] The fraud elimination scheme corresponding to the target fraud identification mode is taken as the target fraud elimination scheme, and the fraud value of the target fraud elimination scheme is obtained by subtracting the master coefficient of the communication network user to the target fraud elimination scheme from 1.

[0113] The fraud value of the target fraud elimination scheme is multiplied by the feature coefficient of the corresponding target fraud identification mode and accumulated to obtain the fraud coefficient.

[0114] The grasping coefficient of the target fraud elimination scheme by the communication network user is the proportion of the grasping of the content in the target fraud elimination scheme by the communication network user, therefore, the fraud value of the target fraud elimination scheme is the proportion of the ungrasping of the content in the target fraud elimination scheme by the communication network user, and the risk of being fraud is the superposition of the fraud value of the target fraud elimination scheme corresponding to the target fraud mode in the to-be-detected communication data, but it needs to be noted that the less the fraud features in the target fraud mode, the smaller the sufficiency of the scheme, and therefore, the smaller the implementation success, and therefore, when superimposing, it needs to be taken into account, and therefore, the fraud value of the target fraud elimination scheme is multiplied by the feature coefficient of the corresponding target fraud mode and accumulated to obtain the fraud coefficient.

[0115] Referring to Figure 7 As shown in the figure, the grading and early warning of the to-be-detected communication data includes the following steps:

[0116] At least one historical communication data is acquired, the minimum value and the maximum value of the fraud coefficient of the communication network user are used as end points by using the historical communication data to form a warning interval, and the warning interval is uniformly divided into at least one local interval;

[0117] The local intervals are numbered from small to large according to the numerical value of the midpoint of the local interval, and if the fraud coefficient belongs to the local interval, the number of the local interval is matched as a risk level to the to-be-detected communication data, and a warning is issued.

[0118] Because the method is used to acquire the fraud coefficient multiple times in advance, a series of historical data can be formed, and then the warning interval is formed, and the warning interval is regularly divided, so that the grading and early warning can be performed.

[0119] Furthermore, the present scheme also proposes a storage medium having a computer readable program stored thereon, and the computer readable program runs the above-mentioned fraud risk level division and grading early warning method based on user portrait when being called.

[0120] It can be understood that the storage medium can be a magnetic medium, for example, a floppy disk, a hard disk, a magnetic tape, an optical medium such as a DVD, or a semiconductor medium such as a solid state disk (SSD) and the like.

[0121] In summary, the advantages of the present application are that by obtaining fraud identification features, forming fraud elimination schemes, obtaining at least one effective part, forming grasping coefficients and forming fraud coefficients, the fraud risk can be analyzed from the perspectives of users and frauds at the same time, the success probability of fraud can be identified according to the fraud situation and the anti-fraud ability of the user, thereby the fraud risk of each user can be identified and graded and warned correspondingly, so that the result of the warning can be consistent with the actual situation, and false positives can be avoided.

[0122] The foregoing is considered as illustrative only of the principles of the application. Further, since numerous modifications and changes will readily occur to those skilled in the art, it is not desired to limit the application to the exact construction and practice described. Accordingly, all such variations and modifications are intended to be included within the scope of the application as defined in the following claims, along with the full scope of equivalents to which such claims are entitled.

Claims

1. A method for classifying and issuing early warnings of fraud risk levels based on user profiles, characterized in that, include: Identify at least one user of a communication network that has access to the communication network, such as the Internet, telephone, or mobile phone. Based on historical network data of communication network users, at least one fraud pattern of communication network users is analyzed and summarized. Feature extraction is performed on the fraud pattern to obtain fraud identification features. Based on big data, at least one fraud elimination solution corresponding to the fraud pattern is obtained. Feature extraction is performed on the information of communication network users to obtain at least one basic piece of information; At least one network test space shall be constructed, and at least one piece of basic information shall be stored in the network test space; The communication data to be tested, received by the user of the communication network, is transmitted to the network test space. Based on the fraud mode, feature extraction is performed on the communication data to be tested to obtain at least one valid part. Based on basic information, the understanding coefficient of communication network users regarding fraud elimination schemes is obtained through analysis. Based on the understanding coefficient, the fraud coefficient of the communication data to be detected on communication network users is obtained through comprehensive analysis. Based on the fraud coefficient, the communication data to be detected is classified and given early warnings. The comprehensive analysis to obtain the fraud coefficient of the communication data to be detected for communication network users includes the following steps: The approximate fraud identification feature with the smallest difference from the effective part is taken as the target approximate fraud identification feature, and the fraud identification feature that generates the target approximate fraud identification feature is taken as the target fraud pattern. The number of approximate fraud identification features generated by the fraud identification features in the target fraud pattern is taken as the feature value of the target fraud pattern, and the number of approximate fraud identification features generated by the fraud identification features in the target fraud pattern is taken as the overall value of the target fraud pattern. The feature value of the target fraud pattern is divided by the total value of the target fraud pattern to obtain the feature coefficient of the target fraud pattern. The fraud elimination plan corresponding to the target fraud pattern is taken as the target fraud elimination plan. The fraud value of the target fraud elimination plan is obtained by subtracting the communication network user's mastery coefficient of the target fraud elimination plan from 1. The fraud coefficient is obtained by multiplying the fraud value of the target fraud elimination scheme with the characteristic coefficient of the corresponding target fraud pattern and summing them.

2. The method for classifying and grading fraud risk levels based on user profiles as described in claim 1, characterized in that, The analysis and summarization of at least one fraud pattern for communication network users includes the following steps: In historical network data, at least one fraud event is obtained, and the fraud event is deduplicated and clustered to obtain at least one fraud pattern.

3. The method for classifying and grading fraud risk levels based on user profiles as described in claim 2, characterized in that, The process of extracting features from the fraud pattern to obtain fraud identification features includes the following steps: Identify historical communication data that resulted in economic losses for communication network users under fraudulent patterns, and segment the historical communication data into at least one basic data block. Based on at least one data basic block, at least one data basic block combination is formed. The data basic block combination is composed of several of the at least one data basic block. The at least one data basic block combination includes all combinations of at least one data basic block. If the combination of basic data blocks causes economic loss, then the combination of basic data blocks is used as the target combination of basic data blocks; otherwise, no action is taken. In the target data basic block combination, at least one target data basic block combination is selected as the feature data basic block combination. The feature data basic block combination satisfies that: each target data basic block combination can be formed by splicing together at least one feature data basic block combination. The basic blocks of feature data are combined as fraud identification features for fraud patterns.

4. The method for classifying and issuing early warnings of fraud risk levels based on user profiles according to claim 3, characterized in that, The method of obtaining at least one fraud elimination solution corresponding to a fraud pattern based on big data includes the following steps: Obtain the information text of the fraudulent pattern as the first text, and obtain the information text other than the fraudulent pattern as the second text; The part of the second text that overlaps with the first text is taken as the third text, and the part of the first text that is not the third text is taken as the target part. Based on semantic recognition, the target part is divided into at least one independent word group. Based on semantic recognition, adjacent independent word groups are merged until the merged result is a complete sentence. The result of merging independent word groups is taken as at least one fraud identification feature in the information text of the fraud pattern. Fraud identification features are sequentially decomposed into at least one word, and at least one synonym of the word is obtained based on a Chinese database; The words in the fraud identification features are replaced with synonyms of the words, and each replacement result is used as an approximate fraud identification feature. Based on big data, strategies for eliminating similar fraud identification features are obtained. The elimination strategies for at least one similar fraud identification feature corresponding to the fraud identification feature in the fraud pattern are summarized as fraud elimination schemes corresponding to the fraud pattern.

5. The method for classifying and grading fraud risk levels based on user profiles as described in claim 4, characterized in that, The step of extracting features from the information of communication network users to obtain at least one basic piece of information includes the following steps: The system acquires chat logs of communication network users on the Internet, extracts the reply information of communication network users from the chat logs, and divides the reply information into at least one basic piece of information based on semantic recognition. The basic piece of information is a complete sentence.

6. The method for classifying and grading fraud risk levels based on user profiles as described in claim 5, characterized in that, The process of setting up at least one network test space includes the following steps: Generate at least one storage space to store at least one piece of basic information separately, and aggregate the at least one storage space storing the basic information to obtain the network test space.

7. The method for classifying and grading fraud risk levels based on user profiles as described in claim 6, characterized in that, The process of extracting features from the communication data to be detected to obtain at least one effective portion includes the following steps: The communication data to be detected is evenly divided into at least one local block. If the local block appears in the approximate fraud identification feature, the local block is taken as the target local block and the target local block is matched to the fraudulent pattern corresponding to the approximate fraud identification feature. If there is no local block between two target local blocks, then the two target local blocks are regarded as adjacent target local blocks, and the adjacent target local blocks are spliced ​​together to obtain at least one suspected feature. The maximum value of the overlap ratio between the suspected feature and at least one approximate fraud identification feature is used as the verification value of the suspected feature. If the verification value of the suspected feature is greater than the preset value, the suspected feature is considered as a valid part. The preset values ​​are obtained as follows: At least one fraud history event is obtained in advance. The overlapping part between the similar fraud identification features and the fraud history event is taken as the preset part. The proportion of the preset part to the similar fraud identification features is taken as the estimated proportion. The maximum value of at least one estimated proportion generated by a single historical fraud event is used as the baseline proportion, and the minimum value of the baseline proportion is used as the preset value.

8. The method for classifying and grading fraud risk levels based on user profiles as described in claim 7, characterized in that, The analysis to obtain the communication network users' understanding of fraud prevention solutions includes the following steps: The basic information is evenly divided into at least one word. Based on the Chinese database, synonyms of the words are obtained. The words in the basic information are replaced with the synonyms of the words. Each replacement method forms basic approximate information of the basic information. The basic approximate information is summarized to obtain the overall basic information. The part of the overall basic information that overlaps with the fraud elimination plan is used as the reference part. The proportion of the reference part to the fraud elimination plan is used as the communication network user's mastery coefficient of the fraud elimination plan.

9. The method for classifying and grading fraud risk levels based on user profiles as described in claim 8, characterized in that, The process of classifying and issuing early warnings for the communication data to be detected includes the following steps: Obtain at least one historical communication data point, use the minimum and maximum values ​​of the fraud coefficient of the communication network user based on the historical communication data as endpoints to form an early warning interval, and evenly divide the early warning interval into at least one local interval. The local intervals are numbered from smallest to largest according to the value of the midpoint of the local interval. If the fraud coefficient belongs to a local interval, the local interval number is used as the risk level to match the communication data to be detected, and an early warning is issued.

Citation Information

Patent Citations

  • Network finance anti-fraud method and device, electronic equipment and medium

    CN118096353A

  • Telecommunication fraud risk identification method based on bank card transfer scene

    CN121258517A