Risk control rule dynamic updating method and system based on online learning
By using online learning methods to dynamically update risk control rules, and utilizing real-time transaction data and historical experience data to form an labeled online learning sample set, risk control rule parameters are adjusted in batches. This solves the problems of flexibility and targeting in traditional risk control rule update methods, and enables timely response and efficient optimization of risk control rules.
Patent Information
- Application Number
- CN202511829078.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-05
- Publication Date
- 2026-02-17
AI Technical Summary
Traditional risk control rule update methods cannot respond to real-time changes in the trading environment in a timely manner, lack flexibility and pertinence, and are difficult to optimize risk control rule parameters quickly and accurately, resulting in an inability to effectively identify newly emerging risks.
By acquiring the current set of initial risk control rules and real-time transaction data, a subset of transaction data that did not hit the rules is formed. This subset is then associated with transaction data that have similar characteristics in the historical risk control results database to label the actual risk status. This forms an labeled online learning sample set. The risk control rule parameters are then adjusted in batches using an incremental update method based on online learning to verify effectiveness and deployment.
It enables dynamic updates of risk control rules, allowing for timely responses to changes in the trading environment and rapid adjustments to risk control rule parameters. This improves the accuracy and reliability of the risk control system, ensures the scientific validity and effectiveness of the risk control rules, continuously enhances risk control performance, and prevents various risks.
Smart Images

Figure CN121542277A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of risk control technology, and more specifically, to a method and system for dynamically updating risk control rules based on online learning. Background Technology
[0002] In numerous fields such as financial transactions and e-commerce, risk control rules play a crucial role in ensuring business security and preventing risks. Traditional methods for updating risk control rules typically employ a periodic, batch update model, where professionals conduct a comprehensive review and adjustment of the rules based on historical data and experience at regular intervals. However, this approach has significant limitations.
[0003] On the one hand, regular batch updates cannot respond promptly to changes in the real-time trading environment. As market dynamics, user behavior patterns, and fraud methods continue to evolve, new risk characteristics emerge rapidly. Traditional update methods, due to their long intervals, struggle to capture these changes in a timely manner, causing risk control rules to fail to effectively identify newly emerging risks for a period of time, thus potentially leading to business losses.
[0004] On the other hand, traditional update methods lack flexibility and specificity in sample selection and rule adjustment. They are often based on fixed historical data samples for analysis, making it difficult to dynamically select more representative samples according to real-time trading conditions. Furthermore, the rule adjustment process is relatively complex, making it difficult to quickly and accurately optimize risk control rule parameters to adapt to constantly changing trading scenarios. Summary of the Invention
[0005] In view of this, the purpose of this application is to provide a method and system for dynamically updating risk control rules based on online learning.
[0006] According to a first aspect of this application, a method for dynamically updating risk control rules based on online learning is provided, the method comprising: Obtain the currently effective initial risk control rule set and real-time transaction data sequence. Based on the initial risk control rule set, perform risk assessment on each transaction in the real-time transaction data sequence to obtain the initial risk assessment result and the subset of transaction data that did not hit the rules for each transaction. The initial risk control rule set contains multiple rule entries for determining transaction risk, and the real-time transaction data sequence contains detailed information of multiple transactions generated in chronological order. Online learning samples are selected from the subset of transaction data that did not hit the rules and the historical risk control result database. The subset of transaction data that did not hit the rules is associated with transaction data with similar characteristics in the historical risk control result database. The actual risk status of each associated transaction is marked to form an labeled online learning sample set. The historical risk control result database stores the risk judgment results of past transactions and the actual risk status of subsequent verification. Based on the labeled online learning sample set, the risk control rule parameters are iterated. The incremental update method of online learning is adopted. The samples in the labeled online learning sample set are input into the rule parameter adjustment process in batches according to the time sequence. The judgment threshold and feature weight of the corresponding risk control rule item are adjusted according to the labeling results of each batch of samples, and the iterated risk control rule parameter set is generated. The effectiveness of the risk control rules corresponding to the iterative risk control rule parameter set is verified. The risk control rules corresponding to the iterative risk control rule parameter set are applied to the newly collected verification transaction data sequence. The verification risk judgment result under the risk control rule is compared with the actual risk status subsequently fed back by the verification transaction data sequence. The conformity rate of the risk control rule judgment is calculated to obtain the rule effectiveness verification result. Based on the rule validity verification results, the iterative risk control rules are deployed. If the rule validity verification results meet the preset rule application standards, the risk control rules corresponding to the iterative risk control rule parameter set are updated to the currently effective risk control rule set, replacing the original initial risk control rule set. At the same time, the labeled online learning samples and rule parameter adjustment records during this iteration process are stored in the online learning history database.
[0007] According to a second aspect of this application, a risk control rule dynamic update system based on online learning is provided. The risk control rule dynamic update system based on online learning includes a machine-readable storage medium and a processor. The machine-readable storage medium stores machine-executable instructions. When the processor executes the machine-executable instructions, the risk control rule dynamic update system based on online learning implements the aforementioned risk control rule dynamic update method based on online learning.
[0008] According to a third aspect of this application, a computer-readable storage medium is provided, wherein computer-executable instructions are stored therein, and when the computer-executable instructions are executed, the aforementioned method for dynamically updating risk control rules based on online learning is implemented.
[0009] Based on any of the above aspects, the technical effect of this application is as follows: By acquiring the currently effective initial risk control rule set and real-time transaction data sequences, and performing risk assessment based on the initial rules, the system can quickly identify transaction data that has not met the rules. Online learning samples are then selected from the subset of transaction data that has not met the rules and from the historical risk control result database to form an labeled online learning sample set. This fully utilizes real-time transaction data and historical experience data, ensuring the representativeness and comprehensiveness of the samples. Employing an incremental update approach for online learning, the system iterates rule parameters by inputting samples in batches according to time sequence. This allows for real-time response to changes in the trading environment, quickly adjusting the judgment thresholds and feature weights of risk control rule entries, enabling the risk control rules to adapt to new risk characteristics in a timely manner. The effectiveness of the iterated risk control rules is verified by comparing the verification risk judgment results with the actual risk status and calculating the conformity rate, ensuring that the updated rules have high accuracy and reliability. Based on the verification results, the iterated risk control rules are deployed, achieving dynamic updates and optimization of the risk control rules. This continuously improves the performance of the risk control system, effectively prevents various risks, and ensures the stable operation of the business. Simultaneously, the labeled online learning samples and rule parameter adjustment records are stored in the online learning history database, further enhancing the scientific nature of the risk control rule updates. Attached Figure Description
[0010] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings used in the embodiments will be briefly described below. It should be understood that the following drawings only show some embodiments of this application and should not be regarded as a limitation of the scope. For those skilled in the art, other related drawings can be obtained based on the drawings without creative effort.
[0011] Figure 1 A flowchart illustrating the method for dynamically updating risk control rules based on online learning provided in an embodiment of this application is shown. Figure 2 This illustration shows a component structure diagram of a system for dynamically updating risk control rules based on online learning, provided in an embodiment of this application, for implementing the above-described method for dynamically updating risk control rules based on online learning. Detailed Implementation
[0012] The embodiments of this application are described below with reference to the accompanying drawings. It should be understood that the embodiments described below with reference to the accompanying drawings are exemplary descriptions for explaining the technical solutions of the embodiments of this application, and do not constitute a limitation on the technical solutions of the embodiments of this application.
[0013] Those skilled in the art will understand that, unless otherwise stated, the singular forms “a,” “an,” “the,” and “the” used herein may also include the plural forms. It should be further understood that the terms “comprising” and “including” as used in embodiments of this application mean that the corresponding feature can be implemented as the presented feature, information, data, step, operation, element, and / or component, but do not exclude implementation as other features, information, data, step, operation, element, component, and / or combinations thereof supported by the art. It should be understood that when an element is said to be “connected” or “coupled” to another element, the element may be directly connected or coupled to the other element, or it may mean that the element and the other element are connected through an intermediate element. Furthermore, “connected” or “coupled” as used herein may include wireless connection or wireless coupling, and the term “and / or” as used herein indicates at least one of the items defined by the term; for example, “A and / or B” may be implemented as “A,” or as “B,” or as “A and B.”
[0014] To make the objectives, technical solutions, and advantages of this application clearer, the embodiments of this application will be described in further detail below with reference to the accompanying drawings. The technical solutions of the embodiments of this application and the technical effects produced by the technical solutions of this application will be explained below through the description of several exemplary embodiments. It should be noted that the following embodiments can be referenced, borrowed from, or combined with each other, and the same terms, similar features, and similar implementation steps in different embodiments will not be described again.
[0015] Figure 1 This document illustrates a flowchart of a method and system for dynamically updating risk control rules based on online learning, provided in an embodiment of this application. It should be understood that in other embodiments, the order of some steps in the method for dynamically updating risk control rules based on online learning in this embodiment can be shared according to actual needs, or some steps can be omitted or maintained. The detailed steps of this method for dynamically updating risk control rules based on online learning include: Step S110: Obtain the currently effective initial risk control rule set and real-time transaction data sequence. Based on the initial risk control rule set, perform risk assessment on each transaction in the real-time transaction data sequence to obtain the initial risk assessment result and the subset of transaction data that did not hit the rules for each transaction. The initial risk control rule set contains multiple rule entries for determining transaction risk, and the real-time transaction data sequence contains detailed information of multiple transactions generated in chronological order.
[0016] In this embodiment, step S110 is specifically applied to the real-time transaction risk control scenario of an internet finance platform. This internet finance platform processes a large number of user-to-user fund transfers and payments daily. To ensure transaction security, it needs to conduct real-time risk assessments on each transaction through risk control rules. The initial risk control rule set is a set of rules pre-set and currently in use by the platform, while the real-time transaction data sequence is all transaction data recorded by the platform in chronological order of transaction occurrence within a recent period.
[0017] Step S111: Retrieve the initial set of risk control rules that are currently in effect from the risk control rule management system. Each rule entry contains risk assessment characteristics, characteristic assessment conditions, and risk level mapping relationships. Record the unique identifier and current application version of each rule entry.
[0018] In the aforementioned internet finance platform scenario, the risk control rule management system is a system specifically designed for storing, managing, and maintaining various risk control rules. The rule entries in the initial risk control rule set are formulated based on factors such as the platform's historical risk events and industry risk characteristics. For example, the risk assessment characteristics of a rule entry might include "single transaction amount," "transaction frequency of the initiating account in the past month," and "counterparty account location." The assessment criteria might include "a single transaction amount exceeding five times the account's average single transaction amount in the past three months," "the initiating account's transaction frequency in the past month exceeding three times the average transaction frequency of similar accounts on the platform," and "the counterparty account location being a risk warning area." The risk level mapping relationship assigns a "high-risk," "medium-risk," or "low-risk" level to transactions that meet these criteria. Each rule entry has a unique identifier, such as "R-2023-001," and also records the current application version, such as "V1.2," to facilitate rule tracking and management.
[0019] Step S112: Obtain a real-time transaction data sequence arranged in chronological order from the transaction processing system. The detailed information of each transaction includes transaction participant information, transaction amount information, transaction channel information, transaction time information, and transaction operation record.
[0020] The transaction processing system is the core system of an internet finance platform for handling actual transactions, and the real-time transaction data sequence originates from this system. Detailed information for each transaction forms the basis for risk assessment. This includes information on the transaction participants such as the initiator's account identifier, account type (e.g., individual user, corporate user), account registration time, and real-name authentication status; transaction amount information such as the specific amount and currency; transaction channel information such as whether the transaction was initiated via a mobile app, webpage, or third-party payment interface; transaction time information such as the specific time the transaction was initiated (accurate to the second), the time the transaction request arrived in the system, and the start and end times of transaction processing; and transaction operation records such as key steps taken during the transaction, including whether secondary verification was performed, whether the transaction password was changed, and whether the bound device was changed. All of this information is arranged chronologically to form a continuous real-time transaction data sequence.
[0021] Step S113: Extract detailed information of each transaction in the real-time transaction data sequence one by one, match the detailed information of each transaction with each rule entry in the initial risk control rule set, and check whether the detailed information of the transaction meets the feature judgment conditions of the rule entry.
[0022] After obtaining the real-time transaction data sequence and the initial risk control rule set, each transaction needs to be risk-assessed individually. For each transaction in the real-time transaction data sequence, the feature information related to each rule entry in the initial risk control rule set is first extracted from the transaction's detailed information. For example, if the feature assessment conditions of a rule entry involve "single transaction amount" and "transaction frequency of the initiating account in the past month," then the transaction amount and the transaction frequency data of the initiating account in the past month are extracted from the current transaction's detailed information. Then, these extracted feature information are compared with the feature assessment conditions of the rule entry to check whether the conditions are met. This process requires traversing all rule entries in the initial risk control rule set and performing the above matching check on each rule entry.
[0023] Step S114: If the details of any transaction meet the feature judgment conditions of a certain rule entry, then the unique identifier of the rule entry and the corresponding risk level are used as the initial risk judgment result of the transaction; if the details of any transaction do not meet the feature judgment conditions of any rule entry, then the details of the transaction are classified into the subset of transaction data that do not match the rule.
[0024] When the detailed information of a transaction meets the characteristic criteria of a certain rule entry, it indicates that the transaction carries a certain risk. In this case, the unique identifier of the rule entry (e.g., "R-2023-001") and the risk level determined according to the risk level mapping relationship (e.g., "high risk") are recorded as the initial risk assessment result for the transaction. If the detailed information of a transaction, after being matched against all rule entries in the initial risk control rule set, does not meet the characteristic criteria of any rule entry, it is considered that the transaction has not yet been identified as risky by the existing rules. The detailed information of this transaction is then stored separately and categorized into the subset of transaction data that did not match any rules. For example, a transaction with a small amount, where both the initiating and counterparty accounts are long-term, normal trading accounts, and the trading channel and time are normal, does not meet the criteria of any rule entry and will be included in this subset.
[0025] Step S115: Record the rule entry identifier and judgment time corresponding to the initial risk assessment result of each transaction. Sort the subset of transaction data that did not hit the rule according to the transaction time order, and mark the collection time and unique identifier of each transaction that did not hit the rule to form a structured subset of transaction data that did not hit the rule.
[0026] For the initial risk assessment result of each transaction, in addition to recording the rule entry identifier and risk level, the time of the assessment also needs to be recorded for subsequent auditing and traceability of the assessment process. The subset of transaction data that did not hit the rule needs to be structured. First, it should be sorted according to the order of transaction occurrence, which clearly reflects the time distribution of transactions that were not hit by the rule. Simultaneously, each transaction that did not hit the rule should be labeled with the time it was collected from that subset and its unique identifier (e.g., transaction serial number "T-20231012-00001"). The structured subset of transaction data that did not hit the rule can be stored in a database table. The table fields include the unique transaction identifier, transaction participant information, transaction amount information, transaction time information, and collection time, etc., to facilitate efficient querying and processing in subsequent steps.
[0027] Step S120: Select online learning samples from the subset of transaction data that did not hit the rules and the historical risk control result database. Associate the subset of transaction data that did not hit the rules with transaction data with similar characteristics in the historical risk control result database, and label the actual risk status of each associated transaction to form a labeled online learning sample set. The historical risk control result database stores the risk judgment results of past transactions and the actual risk status of subsequent verification.
[0028] In the context of internet finance platforms, the subset of transaction data that fails to meet the rules may contain potentially risky transactions that were not identified by the current initial risk control rules. The historical risk control results database stores information about all past transactions on the platform, including the initial risk assessment results at the time of the transaction and the actual risk status determined after a period of verification (such as whether fraud, theft, or other risk events occurred). By associating the subset of transaction data that fails to meet the rules with transaction data with similar characteristics in the historical risk control results database, the actual risk status of historical transactions can be used to label transactions that fail to meet the rules, thus forming a sample set for online learning.
[0029] Step S121: Extract detailed transaction information, initial risk assessment results, actual risk status and verification time of past transactions from the historical risk control result database. The actual risk status is determined based on whether a risk event occurs after the transaction.
[0030] The historical risk control results database is a long-term accumulated database containing a large amount of complete information on past transactions. When extracting data, it is necessary to obtain detailed transaction information for each past transaction. This information is similar in structure to the detailed transaction information in the real-time transaction data sequence, including transaction participants, amount, channel, time, and operation records. The initial risk assessment result is the result determined by the risk control rules at the time the transaction occurred. The actual risk status verified subsequently is determined based on the actual situation within a certain period after the transaction. For example, if a transaction is reported as fraudulent within three days of its occurrence, then the actual risk status of the transaction is "high risk"; if no abnormalities occur within one month of the transaction, the actual risk status is "normal". The verification time is the time when the actual risk status is determined.
[0031] Step S122: Extract features from the detailed information of each transaction in the subset of transaction data that did not hit the rule, and extract features of the same dimension from the detailed information of past transactions in the historical risk control result database to obtain a feature set of past transactions. Compare the features of the transactions that did not hit the rule with the feature set of past transactions, select past transactions with similar features as related transactions, and establish a correspondence between transactions that did not hit the rule and related transactions. The extracted features include transaction amount features, transaction channel features, historical behavior features of transaction participants, and transaction operation features.
[0032] For each transaction in the subset of transaction data that did not hit the rules, feature extraction is required. Similarly, for each past transaction in the historical risk control results database, feature extraction in the same dimensions is also necessary to ensure feature comparability. Extracted transaction amount features may include the relative size of the transaction amount (e.g., comparison with the account's historical transaction amounts) and the range of the amount; transaction channel features may include the type of channel and the historical probability of risk occurrence for that channel; historical behavior features of transaction participants may include the participant's trading habits (e.g., transaction time period, transaction amount range), historical default records, and account activity; transaction operation features may include the operation duration during the transaction process, the completeness of the operation steps, and whether commonly used devices were used. The extracted features of the transactions that did not hit the rules are compared with each feature in the feature set of past transactions to identify those past transactions that are similar across all feature dimensions. These are then considered related transactions, and a correspondence is established between the transactions that did not hit the rules and these related transactions.
[0033] Step S1221: For each transaction in the subset of transaction data that did not hit the rule, extract the range of the transaction amount and the difference between the transaction amount and the historical average transaction amount of the transaction participant as transaction amount features.
[0034] In internet finance platforms, transaction amount is a crucial indicator for measuring transaction risk. For a specific transaction within a subset of transaction data that does not meet the rules, the first step is to determine the range to which its transaction amount falls. For example, the platform can categorize transaction amounts into ranges such as "0-1000 yuan," "1001-5000 yuan," "5001-10000 yuan," and "above 10000 yuan," determining its range based on the specific amount of the transaction. Then, the difference between this transaction amount and the historical average transaction amount of the transaction participant (such as the account initiating the transaction) is calculated. The historical average transaction amount can be the average single transaction amount of the account over the past month, three months, or six months. The difference feature can be the ratio of this transaction amount to the historical average transaction amount, or the percentage of the difference to the historical average transaction amount. Transaction amount features extracted through these methods can more comprehensively reflect the degree of anomaly in this transaction amount.
[0035] Step S1222: For transaction channel information, extract the channel type used in the transaction, the historical risk frequency of the channel, and the geographical distribution characteristics of the channel as transaction channel features.
[0036] Different transaction channels may have different risk levels. The type of channel used is a basic characteristic, such as mobile apps, web pages, and third-party payment interfaces. The historical risk frequency of a channel refers to the proportion of risk events that occurred in transactions initiated through that channel over a past period. For example, a third-party payment interface might have had risk events occurring in 0.5% of its total transactions over the past six months. The geographical distribution characteristics of a channel refer to the geographical distribution of its users and the channel's risk performance in different regions. For example, a channel might have a significantly higher risk incidence rate in region A than in other regions. These characteristics collectively constitute the characteristics of a transaction channel and are used to assess the risks associated with that channel.
[0037] Step S1223: Based on the historical behavioral characteristics of the trading participants, extract information such as the frequency of transactions, the distribution of transaction time periods, the distribution of counterparty types, and whether there are historical risk records in the recent period of the trading participants, and integrate them into the historical behavioral characteristics of the trading participants.
[0038] A participant's historical behavioral patterns can reflect their risk profile. Recent transaction frequency can be the number of transactions made by the participant within the past week or month; excessively high or low frequency may indicate anomalies. Transaction time distribution refers to the typical time of day during which the participant trades. For example, if a user typically trades between 9:00 AM and 6:00 PM on weekdays, a transaction initiated at 2:00 AM might be unusual. Counterparty type distribution indicates whether the participant's counterparties are primarily individual users, corporate users, or other types of accounts; different types of counterparties have different risk levels. The existence of historical risk records indicates whether the participant's account has experienced any risk events in the past, such as fraudulent transactions or theft. A history of such events may indicate a relatively higher risk in the current transaction. Integrating this information forms the participant's historical behavioral characteristics.
[0039] Step S1224: Based on the transaction operation characteristics, extract information such as the device type initiating the transaction, the continuous duration of the operation, the completeness of the operation steps, and whether there is an abnormal operation sequence to form transaction operation characteristics.
[0040] The characteristics of a transaction operation can also reflect the risk of the transaction. The type of device initiating the transaction includes mobile phones, computers, tablets, etc., and the unique identifier of the device (such as the device serial number). If the device initiating the transaction is not a device frequently used by the account, there may be a risk. The continuous duration of the operation refers to the time elapsed from the start of the transaction to its submission. An excessively short or long operation time may indicate an anomaly. The completeness of the operation steps refers to whether all necessary steps were completed during the transaction, such as whether SMS verification codes were used and whether transaction information was verified. Incomplete steps may indicate an anomaly in the transaction. The presence of an abnormal operation sequence refers to whether the operation steps in the transaction process follow a normal logical order. For example, a normal transaction process is "select transaction type - enter amount - enter password - submit transaction." If an abnormal sequence such as "enter password - select transaction type - enter amount - submit transaction" occurs, there may be a risk. The above information collectively constitutes the characteristics of a transaction operation.
[0041] Step S1225: Extract features from the detailed transaction information of each past transaction in the historical risk control result database to obtain the transaction amount features, transaction channel features, historical behavior features of transaction participants, and transaction operation features of each past transaction. Integrate the features of all past transactions to form a feature set of past transactions.
[0042] Similar to the feature extraction method for the subset of transaction data that did not hit the rules, for each past transaction in the historical risk control result database, the transaction amount feature, transaction channel feature, historical behavior feature of transaction participants, and transaction operation feature are extracted according to the methods described in steps S1221 to S1224 above. Integrating all these past transaction features forms a large feature set of past transactions. Each element in this feature set is a feature vector of a past transaction, containing information about that transaction across various feature dimensions.
[0043] Step S1226: Set similarity comparison weights for each feature dimension. The weights for transaction amount features and historical behavior features of transaction participants are set as first-class weights, and the weights for transaction channel features and transaction operation features are set as second-class weights. The first-class weight value is greater than the second-class weight value. For each feature dimension of the transaction that did not hit the rule, perform a similarity assessment with the corresponding feature dimension of the past transaction. If the information overlap of two transactions in any feature dimension reaches a preset ratio, then that dimension is judged as similar. Calculate the comprehensive similarity score between the transaction that did not hit the rule and each past transaction by combining the similarity assessment results of each feature dimension and the corresponding weights.
[0044] When comparing the similarity of transactions that did not meet the rules with past transactions, different feature dimensions may have varying degrees of impact on transaction similarity. Therefore, it is necessary to set similarity comparison weights for each feature dimension. Based on the risk characteristics and historical experience of internet finance platforms, transaction amount characteristics and the historical behavior characteristics of transaction participants usually have a greater impact on transaction risk. Therefore, the weights of these two feature dimensions are set as the first type of weight. The impact of transaction channel characteristics and transaction operation characteristics is relatively small, so they are set as the second type of weight, and the value of the first type of weight is greater than that of the second type of weight. For example, the first type of weight can be set to 0.4, and the second type of weight can be set to 0.1 (this is only an illustration of the weight ratio, not specific values).
[0045] When assessing the similarity between each feature dimension of a transaction that did not meet the rules and its corresponding feature dimensions in past transactions, for the transaction amount feature dimension, the overlap is calculated by comparing the range of transaction amounts and the differences from the historical average transaction amount. For the transaction channel feature dimension, the overlap is compared by comparing channel type, historical risk frequency, and geographical distribution. For the historical behavior feature dimension of transaction participants, the overlap is compared by comparing transaction frequency, transaction time distribution, counterparty type distribution, and historical risk records. For the transaction operation feature dimension, the overlap is compared by comparing device type, continuous operation duration, step completeness, and operation sequence. If the overlap of information in a certain feature dimension between two transactions reaches a preset proportion (e.g., 70%), then that dimension is considered similar.
[0046] The overall similarity score is calculated by combining the similarity assessment results of each feature dimension and their corresponding weights. For example, if a transaction that did not match the rule is similar to a past transaction in the transaction amount feature dimension (weight 0.4) and the historical behavior feature dimension of the transaction participants (weight 0.4), but not similar in the other two dimensions (weight 0.1), then the overall similarity score is 0.4 + 0.4 = 0.8 (this is only an illustration of the calculation method and not a specific numerical value).
[0047] For example, in step S1226-1: Based on the degree of influence of each feature dimension in historical risk control data on risk judgment, similarity comparison weights are set for transaction amount features, transaction channel features, historical behavior features of transaction participants, and transaction operation features, respectively. The weights of transaction amount features and historical behavior features of transaction participants are set as first-class weights, and the weights of transaction channel features and transaction operation features are set as second-class weights. The value of the first-class weight is greater than the value of the second-class weight.
[0048] Historical risk control data contains a wealth of correlation information between risk events and various feature dimensions. Analyzing this data allows us to determine the degree of influence each feature dimension has on risk assessment. For example, analysis reveals that abnormal transaction amounts and abnormal historical behavior of transaction participants are the main factors leading to risk events; therefore, these two feature dimensions are assigned higher weights (Type I). While transaction channels and transaction operation characteristics also have an impact, it is relatively smaller, and they are assigned secondary weights. When setting weights, it is necessary to ensure that the Type I weight value is greater than the Type II weight value to reflect the difference in importance between different feature dimensions.
[0049] Step S1226-2: For the transaction amount feature dimension, compare the transaction amount range of the non-match rule transaction with the past transaction and the difference features with the historical average transaction amount, calculate the information overlap of the two in this dimension. If the overlap reaches the preset ratio, it is determined that the transaction amount feature dimension is similar.
[0050] Specifically, regarding the transaction amount range, if the amount of the non-matching transaction falls within the "5001-10000 yuan" range, and the amount of past transactions also falls within this range, then they overlap in the range. Regarding the difference characteristics from the historical average transaction amount, if the difference characteristic of the non-matching transaction is "greater than three times the historical average transaction amount," and the difference characteristic of past transactions is also "greater than three times the historical average transaction amount," then they overlap in this aspect. The overlap of the range and the difference characteristics is considered to calculate the information overlap degree. If the information overlap degree reaches a preset proportion (e.g., 70%), then the transaction amount characteristic dimension is determined to be similar.
[0051] Step S1226-3: For the transaction channel feature dimension, compare the channel type, historical risk occurrence frequency, and geographical distribution characteristics of the transactions that did not hit the rules with those of past transactions, calculate the information overlap, and if the overlap reaches a preset ratio, determine that the transaction channel feature dimension is similar.
[0052] The same channel type is a basic condition for overlap. Regarding the frequency of historical risk occurrence, if the historical risk occurrence frequency of channels that did not hit the rules is 0.5%, and the historical risk occurrence frequency of channels that had previous transactions is between 0.4% and 0.6%, then they are considered to overlap in this characteristic. In terms of geographical distribution, if channels that did not hit the rules are mainly distributed in regions A, B, and C, and channels that had previous transactions are also mainly distributed in these regions, then they overlap in geographical distribution. The degree of overlap in these aspects is calculated, and if a preset proportion is reached, that dimension is considered similar.
[0053] Step S1226-4: For the historical behavioral characteristics dimension of the transaction participants, compare the transaction frequency, transaction time distribution, counterparty type distribution and historical risk records of the transactions that did not hit the rules with those of the past transactions, calculate the information overlap, and if the overlap reaches the preset ratio, determine that the historical behavioral characteristics dimension of the transaction participants is similar.
[0054] Regarding transaction frequency, if a participant who did not meet the rules has traded 50 times in the past month, and a participant who has traded in the past month has traded 45-55 times, then they are considered to have overlapped. In terms of transaction time distribution, if both primarily trade between 9:00 and 18:00 on weekdays, they are considered to have overlapped. The distribution of counterparty types and historical risk records are also compared in a similar way to calculate the degree of information overlap; if a preset ratio is reached, they are considered similar.
[0055] Step S1226-5: For the transaction operation feature dimension, compare the device type, operation duration, step completeness and operation sequence of the non-match rule transaction with the past transaction, calculate the information overlap. If the overlap reaches the preset ratio, it is determined that the transaction operation feature dimension is similar.
[0056] Similar device type is an important point of overlap. Regarding the duration of continuous operations, if the continuous operation duration of a transaction that did not match the rule is 3 minutes, and the continuous operation duration of a past transaction is 2.5-3.5 minutes, then it is considered overlapping. The completeness of steps and the operation sequence are also compared accordingly, and the degree of information overlap is calculated; if a preset ratio is reached, similarity is determined.
[0057] Step S1226-6: For each similar feature dimension, its corresponding weight value is included in the calculation of the comprehensive similarity score; for dissimilar feature dimensions, the weight value of that feature dimension is not included; the comprehensive similarity score is the sum of the weight values of all similar feature dimensions. If the transaction that did not hit the rule is similar to the past transaction in all feature dimensions, then the comprehensive similarity score is the sum of the weight values of each dimension; if only some feature dimensions are similar, then it is the sum of the weight values of the similar dimensions.
[0058] For example, if a transaction that does not match the rules is similar to a past transaction in the dimensions of transaction amount (weight 0.4) and the historical behavior of the transaction participants (weight 0.4), but not in the other two dimensions, then the overall similarity score is 0.4 + 0.4 = 0.8. If all four dimensions are similar, then the overall similarity score is 0.4 + 0.1 + 0.4 + 0.1 = 1.0 (this is just an illustration of the calculation method).
[0059] Step S1226-7: Record the comprehensive similarity score of each past transaction and the transaction that did not hit the rule, and sort the past transactions in descending order of comprehensive similarity score; if multiple past transactions have the same comprehensive similarity score and are all higher than the preset threshold, then further compare the verification time of the past transactions, and select the past transaction with the most recent verification time as the associated transaction.
[0060] After calculating the overall similarity score between each past transaction and the transaction that did not hit the rule, the past transactions are sorted from highest to lowest score. A preset threshold for the overall similarity score is used, such as 0.6 (illustrative value), and past transactions with scores higher than this threshold are selected as candidate related transactions. If multiple candidate related transactions have the same overall similarity score and are all higher than the threshold, their verification times are compared. The more recent the verification time of a past transaction, the greater its actual risk status is as a reference value for the current transaction that did not hit the rule. Therefore, the past transaction with the most recent verification time is selected as the related transaction first.
[0061] Step S1227: Select past transactions with a comprehensive similarity score higher than the similarity score threshold as related transactions of the transactions that did not match the rule. If there are multiple past transactions with a comprehensive similarity score higher than the similarity score threshold, select the preset number of past transactions with the highest comprehensive similarity score as related transactions.
[0062] The similarity score threshold is set based on the platform's risk control needs and historical experience, and is used to filter out past transactions that are sufficiently similar to the transaction that did not hit the rule. For example, if the similarity score threshold is set to 0.6 (illustrative value), when the overall similarity score of a past transaction is higher than 0.6, it is considered a related transaction to the transaction that did not hit the rule. If multiple past transactions have overall similarity scores higher than this threshold, to ensure the reasonableness of the quality and quantity of related transactions, a preset number (e.g., 3) of past transactions with the highest overall similarity scores are selected as related transactions. This avoids too many related transactions from causing confusion in the labeling results, while ensuring that the selected related transactions have the highest reference value.
[0063] Step S1228: Create a list of related transactions for each transaction that does not match the rule, record the transaction identifier, comprehensive similarity score and feature similarity dimension of the related transactions, and form a correspondence between transactions that do not match the rule and related transactions.
[0064] For each transaction that does not match the rule, the selected related transactions are compiled into a list of related transactions. The list records the transaction identifier of each related transaction (e.g., "T-20230901-00015"), the overall similarity score between the related transaction and the transaction that did not match the rule, and the similarity across different feature dimensions (e.g., transaction amount, historical behavior of transaction participants, etc.). This list establishes a correspondence between transactions that do not match the rule and related transactions.
[0065] Step S123: Mark the actual risk status of related transactions onto the corresponding unmatched rule transactions. If any unmatched rule transaction has multiple related transactions, select the actual risk status of the related transaction with the most recent verification time as the marking result of the unmatched rule transaction.
[0066] The actual risk status of related-party transactions is determined through subsequent verification and has high reliability. Labeling the actual risk status of a related-party transaction with the corresponding transaction that did not meet the rule requirement assigns a reference risk status label to that transaction. When a transaction that did not meet the rule requirement has multiple related-party transactions, the actual risk status of these transactions may be the same or different. Since related-party transactions with more recent verification times are closer to the current transaction in terms of transaction characteristics and risk environment, the actual risk status of the related-party transaction with the most recent verification time is selected as the labeling result for that transaction. For example, if a transaction that did not meet the rule requirement has three related-party transactions, verified one month ago, half a month ago, and one week ago respectively, and the related-party transaction verified one week ago had an actual risk status of "high risk," then that transaction would be labeled as "high risk."
[0067] Step S124: Filter out the non-hit rule transactions that have been marked with actual risk status, retain transaction data with complete transaction characteristics and clear marking results, and merge the filtered marked transaction data with some data marked as risky transactions and normal transactions in the historical risk control result database in a recent period to form a marked online learning sample set. The marked online learning sample set is arranged in the order of marking time.
[0068] Transactions that missed the rule and have been labeled with their actual risk status may have incomplete transaction features (e.g., missing key features) or unclear labeling results (e.g., inconsistent actual risk statuses across multiple related transactions, making it impossible to determine which is more accurate). Such transaction data is unsuitable as online learning samples and needs to be screened, retaining only those with complete transaction features and clear labeling results. Simultaneously, to enrich the diversity and representativeness of the online learning sample set, it is also necessary to select data from the historical risk control results database that was labeled as risky or normal transactions within a recent period (e.g., the last three months). The screened transaction data that missed the rule and these historical transaction data are then merged to form a labeled online learning sample set. To reflect the temporal characteristics of the samples, this online learning sample set is arranged in chronological order of labeling time, which can be the time when the transaction missed the rule and was labeled or the verification time of a historical transaction.
[0069] Step S130: Based on the labeled online learning sample set, perform risk control rule parameter iteration. Using the incremental update method of online learning, input the samples in the labeled online learning sample set into the rule parameter adjustment process in batches according to the time sequence. Adjust the judgment threshold and feature weight of the corresponding risk control rule item according to the labeling results of each batch of samples, and generate the iterated risk control rule parameter set.
[0070] In internet finance platform scenarios, labeled online learning sample sets contain a large number of transaction samples with actual risk status labels. By incrementally updating these samples through online learning and inputting them into the rule parameter adjustment process in batches according to time sequence, risk control rules can be dynamically adjusted based on the latest risk characteristics. Each batch of samples reflects the transaction risk characteristics within a certain time period. Adjusting the judgment thresholds and feature weights of risk control rule entries based on the labeling results of these samples allows the rules to more accurately identify newly emerging risk patterns and improve the effectiveness of risk control rules.
[0071] Step S131: Divide the labeled online learning sample set into multiple batches of incremental samples in chronological order. Each batch of incremental samples contains a preset number of labeled transaction data generated in consecutive time periods.
[0072] The labeled online learning sample set is arranged chronologically. To enable incremental updates, it needs to be divided into multiple batches of incremental samples. During partitioning, a predetermined number of consecutive labeled transaction data points are used as a batch of incremental samples, arranged chronologically. The predetermined number can be determined based on factors such as the platform's transaction volume and the rate of risk change; for example, every 1000 consecutive labeled transaction data points could be used as a batch of incremental samples. This partitioning ensures that each batch of samples is representative, reflecting the risk characteristics within that time period, and facilitates the gradual adjustment of rule parameters.
[0073] Step S132: Set a parameter adjustment counter for each rule entry in the initial risk control rule set. The initial counter value is zero. The counter value is used to record the number of incremental sample batches that have participated in parameter adjustment for that rule entry.
[0074] The parameter adjustment counter tracks the number of times each rule entry has participated in parameter adjustments. The initial counter value is zero, indicating that the rule entry has not yet participated in any batch of parameter adjustments. The counter value increments by 1 after a rule entry has undergone parameter adjustments based on a batch of incremental samples. The counter value provides insight into the history of rule entry parameter adjustments; for example, rule entries with high counter values may warrant consideration of whether they are overly sensitive or have other issues.
[0075] Step S133: Take the first batch of incremental samples to input the rule parameter adjustment process. For each risk control rule item, select samples with features related to the rule item from the first batch of incremental samples, that is, samples whose features are consistent with the judgment features of the rule item; analyze the labeling results of the selected samples. If the sample is labeled as risky and the sample is not judged as risky by the original rule item, then reduce the judgment threshold of the corresponding feature of the rule item; if the sample is labeled as normal and the sample is misjudged as risky by the original rule item, then increase the judgment threshold of the corresponding feature of the rule item; adjust the feature weight according to the degree of deviation between the sample labeling results and the rule judgment results. The degree of deviation is determined based on the relative difference between the sample feature and the original rule judgment threshold. The larger the relative difference, the greater the degree of deviation, and the greater the adjustment of the corresponding feature weight. If any feature is a key influencing factor in multiple deviation samples, then increase the weight of the feature.
[0076] The first batch of incremental samples are the earliest samples in the labeled online learning sample set, representing earlier risk characteristics. These are then input into the rule parameter adjustment process to adjust the parameters of each rule entry in the initial risk control rule set.
[0077] Step S1331: Select the first batch of incremental samples from the divided batches of incremental samples, and read the labeled information and extracted transaction features of each transaction in the batch of samples.
[0078] From multiple batches of incremental samples divided in chronological order, the first batch of incremental samples is selected. The labeled information of each transaction in this batch of samples is read, namely the actual risk status label (such as "high risk" or "normal"), as well as the previously extracted transaction characteristics such as transaction amount characteristics, transaction channel characteristics, historical behavior characteristics of transaction participants, and transaction operation characteristics. The above information is the basic data for adjusting the rule parameters.
[0079] Step S1332: For the first risk control rule entry in the initial risk control rule set, extract the judgment feature of the rule entry. The judgment feature is the core feature of the rule used to determine risk.
[0080] Each rule in the initial risk control rule set has its specific judgment characteristics. For example, the judgment characteristics of the first rule might be "the ratio of transaction amount to the average single transaction amount of the account over the past three months" and "the transaction frequency of the account initiating the transaction over the past month." These are the core characteristics used by this rule to determine transaction risk. These judgment characteristics are extracted in order to filter relevant samples from the incremental samples.
[0081] Step S1333: Iterate through each transaction in the first batch of incremental samples and check whether the characteristics of the transaction contain features consistent with the characteristics determined by the rule entry. If they do, then filter the transaction sample as a sample related to the features corresponding to the rule entry.
[0082] For each transaction in the first batch of incremental samples, check whether its transaction characteristics contain features consistent with the judgment characteristics of the current rule entry. For example, if the judgment characteristics of the current rule entry are "the ratio of transaction amount to the average single transaction amount of the account in the past three months" and "the transaction frequency of the account initiating the transaction in the past month", then check whether each transaction extracts these two features. If a transaction contains these two features, then it is selected as a sample related to the features corresponding to that rule entry.
[0083] Step S1334: Classify the selected feature-related samples according to the labeling results into samples labeled as risky and samples labeled as normal.
[0084] The selected feature-related samples are categorized according to their actual risk status in the labeled information: one category is samples labeled as risky, and the other is samples labeled as normal. This categorization facilitates the analysis of how the rule entries determine the risk status of samples in different risk states.
[0085] Step S1335: First, process the samples marked as risky. Check whether each sample of this type is judged as risky by the original rule entry. If it is not judged as risky, lower the judgment threshold of the corresponding judgment feature of the rule entry so that subsequent similar samples can be judged as risky by the rule entry.
[0086] The original rule entries refer to the rule entries in the initial risk control rule set. For samples marked as risky but not classified as risky by the original rule entries, it indicates that the judgment threshold of the original rule entries may be too high, leading to missed judgments. In this case, it is necessary to lower the judgment threshold of the corresponding judgment feature of that rule entry. For example, the judgment threshold for "the ratio of transaction amount to the average single transaction amount of the account in the past three months" in the original rule entry is "greater than 5". A sample marked as risky has a ratio of 4.5, which does not meet the threshold and is therefore not classified as risky. In this case, the judgment threshold can be lowered, such as to "greater than 4", so that subsequent samples with similar ratios can be classified as risky.
[0087] Step S1336: Reprocess the samples marked as normal, check whether each sample of this type was misjudged as risk by the original rule entry. If it was misjudged, increase the judgment threshold of the corresponding judgment feature of the rule entry to reduce misjudgment.
[0088] For samples marked as normal but judged as risky by the original rule, it indicates that the judgment threshold of the original rule may be too low, leading to misjudgment. In this case, it is necessary to increase the judgment threshold of the corresponding judgment feature of the rule. For example, the judgment threshold for "trading frequency of the account initiating the transaction in the past month" in the original rule is "greater than 30 times". A sample marked as normal has 35 times, and is judged as risky, but the account is actually a normal high-frequency trading account. In this case, the judgment threshold can be increased to "greater than 40 times" to reduce misjudgments of normal transactions.
[0089] Step S1337: Calculate the degree of deviation for each deviation sample. The degree of deviation is determined based on the difference between the sample features and the original rule's judgment threshold. The greater the difference, the greater the degree of deviation.
[0090] Biased samples include samples labeled as risky but not classified as risky, and samples labeled as normal but misclassified as risky. For samples labeled as risky but not classified, the degree of bias is the difference between the sample's feature value and the original rule's judgment threshold. For example, if the sample's feature value is 4.5 and the original threshold is 5, the difference is 0.5 (this is for illustrative purposes only, not a specific value). For samples labeled as normal but misclassified, the degree of bias is the difference between the original rule's judgment threshold and the sample's feature value. For example, if the sample's feature value is 35 and the original threshold is 30, the difference is 5 (illustrative value). The larger the difference, the more severe the bias in the rule's judgment of that sample, and the greater the degree of bias.
[0091] Step S1338: Determine the adjustment range of feature weights based on the degree of deviation. The greater the degree of deviation, the greater the adjustment range of the corresponding judgment feature weights. If any feature is a key factor causing judgment deviation in multiple deviation samples, that is, the deviation of multiple deviation samples mainly stems from the mismatch between the feature and the rule judgment conditions, then increase the weight of the feature in the rule judgment.
[0092] The greater the degree of deviation, the more unreasonable the setting of the judgment feature in the current rule entry is, and the more significantly its weight needs to be adjusted. For example, if a judgment feature causes judgment deviation in multiple biased samples, and the degree of deviation is large, then its weight needs to be significantly increased or decreased. If a feature is a key factor causing judgment deviation in multiple biased samples, meaning that the deviation in these biased samples is mainly due to the feature not matching the rule judgment conditions, it indicates that the importance of this feature in risk judgment is underestimated. Therefore, the weight of this feature in the rule judgment needs to be increased, so that the rule pays more attention to the performance of this feature when making judgments.
[0093] Step S1339: After completing the parameter adjustment of the first rule entry, process the other rule entries in the initial risk control rule set according to the same process until all rule entries have completed the parameter adjustment based on the first batch of incremental samples.
[0094] After adjusting the judgment threshold and feature weights of the first rule entry based on the first batch of incremental samples, the same process from steps S1332 to S1338 is followed to process all other rule entries in the initial risk control rule set, such as the second and third rule entries, to ensure that the parameters of each rule entry can be adjusted based on the first batch of incremental samples.
[0095] Step S13310: Record the parameter adjustment details of each rule entry in the first batch of incremental samples, including the direction of the adjustment judgment threshold change, the adjustment magnitude, the feature weight change, and the corresponding number of deviation samples.
[0096] Record in detail the parameter adjustments for each rule entry in the first batch of incremental samples. For the judgment threshold, record whether it is increased or decreased (direction of change) and the magnitude of the adjustment (e.g., from 5 to 4); for the feature weight, record whether it is increased or decreased and the changes; at the same time, record the number of biased samples involved in this adjustment.
[0097] Step S134: After completing the rule parameter adjustment for the first batch of incremental samples, increment the parameter adjustment counter value of the corresponding rule entry by 1, and then repeat the above operations of screening samples, adjusting the judgment threshold and feature weights for the second batch of incremental samples.
[0098] After the first batch of incremental samples is processed, the parameter adjustment counter value of each rule entry involved in the adjustment is incremented by 1; for example, the counter value of a certain rule entry changes from 0 to 1. Then, the second batch of incremental samples is taken, and the same steps S1331 to S13310 as the first batch of incremental samples are followed to adjust the sample screening, judgment threshold, and feature weights. By processing incremental samples in batches in this way, the rule parameters can gradually adapt to the risk characteristics of different time periods.
[0099] Step S135: During the parameter adjustment process of each batch of incremental samples, refer to the adjustment records of previous batches of the rule entry. If the rule judgment deviation shows a downward trend after multiple consecutive batches of adjustments, reduce the adjustment range of subsequent batches; if the deviation shows an upward trend, re-evaluate the rationality of feature selection and adjust the feature weight allocation method.
[0100] When processing each batch of incremental samples, it is necessary to refer to the parameter adjustment records of previous batches for the rule entries. By analyzing the changing trend of rule judgment deviation after adjustments in previous batches (such as changes in false negative rate and false positive rate), the adjustment strategy for the current batch can be adjusted. If the rule judgment deviation shows a downward trend after several consecutive batches of adjustments, it indicates that the current adjustment direction is correct. To avoid over-adjustment, the adjustment range of subsequent batches can be reduced. If the deviation shows an upward trend, it may indicate that the feature selection is unreasonable or the feature weight allocation is inappropriate. In this case, it is necessary to re-evaluate whether the judgment features of the rule entries are appropriate, whether features need to be added or replaced, and adjust the feature weight allocation method.
[0101] Step S136: After all batches of incremental samples have completed parameter adjustment, collect the adjusted judgment threshold and feature weight of each risk control rule item, integrate them to form the iterative risk control rule parameter set, and record the parameter adjustment process of each rule item and the degree of influence of each batch of incremental samples.
[0102] After all batches of incremental samples in the labeled online learning sample set have been processed, the judgment threshold and feature weights of each risk control rule entry have been adjusted. These adjusted parameters are collected and integrated to form the iterative risk control rule parameter set. Simultaneously, the complete parameter adjustment process for each rule entry is recorded in detail, including the impact of each batch of incremental samples on the parameters (e.g., how much the threshold was adjusted and how much the weights changed due to a particular batch of samples), to facilitate subsequent analysis and optimization of the rule iteration process.
[0103] Step S140: Verify the validity of the risk control rules corresponding to the iterative risk control rule parameter set, apply the risk control rules corresponding to the iterative risk control rule parameter set to the newly collected verification transaction data sequence, compare the verification risk judgment result under the risk control rule with the actual risk status subsequently fed back by the verification transaction data sequence, calculate the compliance rate of the risk control rule judgment, and obtain the rule validity verification result.
[0104] In the context of internet finance platforms, the effectiveness of risk control rules corresponding to the iterated set of risk control rules needs to be verified through actual transaction data. The newly collected verification transaction data sequence consists of transaction data that occurred on the platform after the rule parameters were iterated. This data was not involved in the previous sample selection and parameter adjustment process, and can objectively reflect the actual performance of the iterated rules. By comparing the rule judgment results with the actual risk status after the transaction and statistically analyzing indicators such as the compliance rate, the effectiveness of the rules can be evaluated.
[0105] Step S141: Collect a new verification transaction data sequence from the transaction processing system. The time range of the verification transaction data sequence is later than that of the real-time transaction data sequence, and it contains multiple transaction data with different characteristics. The verification transaction data sequence has not participated in the previous online learning sample screening and rule parameter iteration process.
[0106] The transaction processing system continuously generates new transaction data, and the verification transaction data sequence is collected from this new data. Its time frame must be later than the real-time transaction data sequence previously used to screen online learning samples to ensure data freshness and independence. The verification transaction data sequence should include multiple transactions with different characteristics, such as different transaction amounts, different transaction channels, different transaction participants, and different transaction operation behaviors. This is necessary to comprehensively verify the ability of the iterated risk control rules to judge various transaction situations. Furthermore, this transaction data must absolutely not have participated in the previous online learning sample screening and rule parameter iteration process to avoid bias in the verification results.
[0107] Step S142: Load the risk control rules corresponding to the iterative risk control rule parameter set into the rule verification process, input each transaction data in the verification transaction data sequence into the risk control rule, perform risk judgment operation, and obtain the verification risk judgment result corresponding to each transaction. The verification risk judgment result includes the risk level and the triggering rule entry identifier.
[0108] The rule verification process is a dedicated module for testing and verifying the effectiveness of risk control rules. The process loads the risk control rules corresponding to the iterated set of risk control rule parameters into this module, and then inputs each transaction data from the verification transaction data sequence one by one. For each transaction data, the risk control rule performs a risk assessment operation based on detailed information such as transaction participant information, transaction amount information, transaction channel information, transaction time information, and transaction operation records, combined with the judgment characteristics of the rule entries, the adjusted judgment threshold, and feature weights. The final output of the verified risk assessment result includes not only the risk level of the transaction (e.g., "high risk," "medium risk," "low risk," "normal"), but also an identifier of which rule entries were triggered, for subsequent analysis of rule triggering.
[0109] Step S143: Record the verification risk assessment result and assessment time for each verification transaction, and continuously track the subsequent actual transaction status of each verification transaction to observe whether any risk events occur and determine the actual risk status of each verification transaction.
[0110] After obtaining the verification risk assessment result for each verified transaction, it is necessary to record the assessment result and the time of the assessment for comparison with the subsequent actual risk status. Simultaneously, each verified transaction should be continuously tracked. The tracking period can be determined based on the platform's risk event incubation period, such as one month. During the tracking period, observe whether any risk events occur, such as the transaction initiator complaining of account theft, illegal transfer of transaction funds, or the transaction being identified as fraudulent by regulatory agencies. Based on the occurrence of these risk events, determine the actual risk status of each verified transaction. If a risk event occurs, the actual risk status is classified as "high risk" or the corresponding level; if no risk event occurs, it is classified as "normal."
[0111] Step S1431: Assign a unique verification identifier to each verification transaction in the verification transaction data sequence, record the verification risk judgment result of each transaction, including the determined risk level, the triggered rule entry identifier and the judgment time, and store it in the verification result record table.
[0112] A unique verification identifier can be a unique string or number used to distinguish different verification transactions. The verification result record table is a dedicated database table or file for storing information related to verification transactions. Each record corresponds to one verification transaction and includes fields such as verification identifier, determined risk level, triggered rule entry identifier, and determination time. This allows for systematic management of verification transaction determination results, facilitating subsequent querying and analysis.
[0113] Step S1432: Set a tracking period and continuously monitor the subsequent transaction status of each verification transaction within the tracking period, including whether the transaction is revoked by the initiator, whether there is an abnormal flow of funds, whether a risk complaint is received, and whether it is marked as a risky transaction by the regulatory system.
[0114] The tracking period needs to be set based on the actual situation of the internet finance platform, taking into account the average occurrence time of risk events. During the tracking period, the subsequent transaction status of each verified transaction is continuously monitored through multiple channels, including the platform's transaction monitoring system, customer service system, and regulatory interfaces. A transaction being cancelled by the initiator may indicate that the user discovers an anomaly; abnormal fund flows may occur, such as funds being transferred multiple times to several unfamiliar accounts within a short period; receiving a risk complaint means that a user has complained to the platform about a problem with the transaction; and being marked as a risky transaction by the regulatory system is an assessment of the risk by external regulatory agencies. All of these are important bases for determining whether a transaction poses a risk.
[0115] Step S1433: Based on the transaction status monitored during the tracking period, determine the actual risk status of each verification transaction. If any of the above-mentioned risk-related statuses occur, the actual risk status is determined to be risky; if no risk-related statuses occur during the tracking period and the transaction is settled normally, the actual risk status is determined to be normal.
[0116] After the tracking period ends, the monitoring results of each verified transaction are analyzed. If, during the tracking period, the transaction experiences any of the following risk-related states: transaction cancellation, abnormal fund transfer, receipt of risk complaints, or being marked as a risky transaction by the regulatory system, its actual risk status is determined to be "risk". If no risk-related state occurs during the tracking period, and the transaction has been successfully settled and funds have been successfully received, then the actual risk status of the transaction is determined to be "normal".
[0117] Step S1434: Record the actual risk status of each verification transaction in the verification result record table and store it in association with the verification risk judgment result of the transaction.
[0118] The actual risk status of each verified transaction is added to the verification result record table and associated with the verification identifier of the transaction, so that the verification risk assessment result and the actual risk status of each transaction can be matched one by one, which facilitates subsequent comparative analysis.
[0119] Step S144: Compare the verification risk assessment result of each verification transaction with the actual risk status. If the risk level in the verification risk assessment result is consistent with the actual risk status, the rule assessment result of the transaction is determined to be compliant; otherwise, it is determined to be non-compliant. Calculate the proportion of the number of transactions with compliant rule assessment results to the total number of verification transactions to obtain the compliance rate of the rule assessment.
[0120] For each transaction in the verification result record table, the risk level in its verification risk assessment result is compared with the actual risk status. For example, if the verification risk assessment result is "high risk" and the actual risk status is also "risk," it is judged as compliant; if the verification risk assessment result is "normal" and the actual risk status is "risk," it is judged as ineligible. The number of compliant transactions and the total number of verified transactions are counted. The compliance rate of the rule judgment is obtained by dividing the number of compliant transactions by the total number of verified transactions. The higher the compliance rate, the higher the accuracy of the rule judgment after iteration.
[0121] Step S1441: Compare the verification risk assessment result and the actual risk status of each transaction in the verification result record table one by one. If the risk level in the verification risk assessment result is risk and the actual risk status is risk, or the risk level in the verification risk assessment result is normal and the actual risk status is normal, then the rule assessment result of the transaction is determined to be compliant.
[0122] During the comparison process, the judgment is strictly based on the correspondence between risk level and actual risk status. Only when the risk level in the verification risk assessment result is completely consistent with the actual risk status is it judged as compliant. For example, "high risk" corresponds to actual "risk", and "normal" corresponds to actual "normal".
[0123] Step S1442: If the risk level in the verification risk assessment result is risky but the actual risk status is normal, or the risk level in the verification risk assessment result is normal but the actual risk status is risky, then the rule assessment result for this transaction is determined to be non-compliant.
[0124] Both of these situations indicate a deviation in the rule judgment; the former is a misjudgment, and the latter is an omission, both of which are judged as non-compliance.
[0125] Step S1443: Count the number of transactions that are deemed compliant in the verification result record table, and at the same time count the total number of verified transactions in the verification transaction data sequence; the compliance rate of the rule judgment is determined by the ratio of the number of compliant transactions to the total number of verified transactions.
[0126] By querying and statistically analyzing the verification result record table, the number of transactions that meet the criteria and the total number of verified transactions are obtained. The formula for calculating the compliance rate is the number of transactions that meet the criteria divided by the total number of verified transactions (this is only a textual description of the calculation method, not a formula).
[0127] Step S145: Analyze the transaction data that does not meet the judgment criteria, distinguish between missed judgments and false judgments of the rule entries, and calculate the missed judgment rate and false judgment rate respectively. Missed judgment refers to a risky transaction that was actually a risky transaction but was not judged as risky, and false judgment refers to a normal transaction that was judged as risky.
[0128] Transaction data that does not meet the criteria is an important resource for analyzing rule-related issues. A missed judgment occurs when a transaction is actually at risk, but the verification result indicates it is normal; a false judgment occurs when a transaction is actually normal, but the verification result indicates it is at risk. By analyzing each transaction that does not meet the criteria, we can determine whether each transaction was missed or falsely judged. Then, we can separately calculate the proportion of missed judgment transactions to the total number of verified transactions (missed judgment rate) and the proportion of falsely judged transactions to the total number of verified transactions (false judgment rate). The missed judgment rate and false judgment rate reflect the rule's deficiencies from different perspectives.
[0129] Step S146: Integrate the compliance rate, false negative rate and false positive rate of the rule judgment to form the rule validity verification result. The rule validity verification result also includes the feature analysis of transactions that do not meet the judgment, that is, in which features do the transactions that do not meet the judgment deviate from the rule judgment conditions.
[0130] The rule validity verification result is a comprehensive evaluation report of the performance of the iterated risk control rules, including three key indicators: compliance rate, false negative rate, and false positive rate. Furthermore, it is necessary to conduct feature analysis on transactions that do not meet the criteria, identifying which feature dimensions deviate from the rule's judgment conditions. For example, a false negative transaction might have a "ratio of transaction amount to historical average transaction amount" of 4.8, while the adjusted rule threshold is 5, resulting in it not being classified as risk, indicating a deviation in the transaction amount feature dimension.
[0131] Step S150: Deploy the iterated risk control rules according to the rule validity verification results. If the rule validity verification results meet the preset rule application standards, update the risk control rules corresponding to the iterated risk control rule parameter set to the currently effective risk control rule set, replacing the original initial risk control rule set. At the same time, store the labeled online learning samples and rule parameter adjustment records in this iteration process to the online learning history database.
[0132] In the context of internet finance platforms, the validity verification results of rules determine whether the iterated risk control rules can be officially put into use. The preset rule application standards are a set of indicator requirements formulated by the platform based on its own risk tolerance and business objectives. If the iterated rules meet these standards, they can be updated to the currently effective rules to improve the platform's risk control capabilities; otherwise, further optimization is required. Simultaneously, relevant data from the iteration process is stored to facilitate subsequent auditing and rule optimization.
[0133] Step S151: Obtain the preset rule application standard, which includes the minimum compliance rate requirement, the maximum limit of the missed judgment rate, and the maximum limit of the false judgment rate for rule judgment. Only when the compliance rate in the rule validity verification result reaches the minimum compliance rate requirement, and the missed judgment rate and false judgment rate are both lower than the corresponding maximum limits, is it determined that the rule application standard is met.
[0134] The pre-defined application standards for the rules are determined before the rule validity verification process. The minimum compliance rate requirement is the lowest percentage of accurate judgments that the rule must achieve; the maximum false negative rate is the largest allowed percentage of false negatives, which may lead to risk losses; the maximum false positive rate is the largest allowed percentage of false positives, which may affect user experience and normal transactions. Only when all three indicators in the rule validity verification results meet the requirements can the iterated rule be considered to be ready for application.
[0135] Step S152: Compare the compliance rate, false negative rate and false positive rate in the rule validity verification results with the corresponding indicators in the rule application standard to check whether all indicator requirements are met.
[0136] The compliance rate in the rule validity verification results is compared with the minimum compliance rate requirement in the rule application standard to see if it meets or exceeds the requirement; the false negative rate is compared with the maximum false negative rate limit to see if it is lower than or equal to the requirement; and the false positive rate is compared with the maximum false positive rate limit to see if it is lower than or equal to the requirement. Only when all three indicators meet the conditions is the rule application standard deemed to be met.
[0137] Step S153: If all the indicator requirements are met, the risk control rules corresponding to the iterated risk control rule parameter set are determined to have the application conditions. The adjusted judgment threshold and feature weight of each rule entry are read from the iterated risk control rule parameter set to generate new risk control rule entries.
[0138] When the rule validity verification results meet all the indicator requirements, it indicates that the risk control rules corresponding to the iterated risk control rule parameter set can effectively identify transaction risks. At this point, the adjusted judgment threshold and feature weight of each rule entry are read from the iterated parameter set, and combined with other information such as the risk judgment characteristics, feature judgment conditions, and risk level mapping relationship of the rule entry, a new and complete risk control rule entry is generated.
[0139] Step S154: Integrate the new risk control rule entries to form a new set of currently effective risk control rules. Replace the original initial set of risk control rules with the new set of currently effective risk control rules through the rule update interface of the risk control rule management system. Set the effective time of the new set of currently effective risk control rules to the current time.
[0140] The newly generated risk control rule entries are integrated according to a certain structure to form a new set of currently effective risk control rules. Then, through the rule update interface provided by the risk control rule management system, the original initial set of risk control rules in the system is replaced with this new set. At the same time, the effective time of the new rule set is set to the current time to ensure that the new rules can immediately begin to assess the risk of newly occurring transactions.
[0141] Step S155: If the rule application standard is not met, analyze the reasons why the rule validity verification results do not meet the indicator requirements. If the false negative rate is greater than the corresponding threshold, return to the online learning sample screening step to supplement and screen more samples containing false negative features. If the false negative rate is greater than the corresponding threshold, return to the rule parameter iteration step to readjust the judgment threshold and feature weight of the corresponding rule item.
[0142] If the rule validity verification results do not meet the rule application standards, the specific reasons need to be analyzed. If the false negative rate is too high, it indicates that the online learning sample set may lack sufficient samples with false negative characteristics, causing the rule to fail to effectively identify such risky transactions. In this case, it is necessary to return to step S120 (online learning sample screening step) to supplement and screen more samples containing false negative characteristics (such as the feature dimensions that caused false negatives analyzed earlier). If the false positive rate is too high, it indicates that there may be a problem with the rule parameter adjustment. It is necessary to return to step S130 (rule parameter iteration step) to readjust the judgment threshold and feature weights of the corresponding rule entries.
[0143] Step S156: Collect all labeled online learning samples during this iteration, including the selected non-matching rule transaction samples, related historical transaction samples, and merged incremental samples, and classify and organize them according to time order and labeling results.
[0144] The labeled online learning samples generated during this iteration are valuable data assets that need to be comprehensively collected. These samples include non-hit rule transaction samples selected from real-time transaction data, historical transaction samples linked from the historical risk control result database, and incremental samples formed by merging. After collection, they are classified and organized according to time order (such as labeling time or transaction occurrence time) and labeling results (risk status, normal status) to facilitate subsequent querying and analysis.
[0145] Step S157: Collect parameter adjustment records for each risk control rule item during this iteration, including the adjustment range of each batch of incremental samples, the basis for adjustment, the comparison of parameters before and after adjustment, and the feedback on the effect after adjustment.
[0146] The parameter adjustment record for each risk control rule entry details the rule iteration process. The adjustment range includes the change in the judgment threshold and feature weights for each adjustment; the adjustment basis refers to which batch of samples and which biased samples were used for the adjustment; the parameter comparison before and after the adjustment shows the changes in parameters; the feedback on the effect of the adjustment can be the improvement in the judgment bias of samples after each batch of adjustments.
[0147] Step S158: Store the organized and labeled online learning samples and parameter adjustment records in the online learning history database. At the same time, record the initiation time, effective time, number of sample batches participating in the iteration, and final rule validity verification results of this rule update to form a rule update archive.
[0148] The online learning history database is a specialized database used to store data related to the rule iteration process. The organized, labeled online learning samples and parameter adjustment records are stored in this database. Simultaneously, it records information such as the initiation time of this rule update (the time when rule iteration begins), the effective time (if the rule is applied), the number of sample batches participating in the iteration, and the final rule validity verification result. This information collectively constitutes the rule update archive. Figure 2 This embodiment illustrates a risk control rule dynamic update system 100 based on online learning, comprising a processor 1001, a memory 1003, and program code stored in the memory 1003. The processor 1001 executes the program code to implement the steps of the risk control rule dynamic update method based on online learning. The processor 1001 and the memory 1003 are connected, for example, via a bus 1002. Optionally, the risk control rule dynamic update system 100 may further include a transceiver 1004, which can be used for data interaction between this risk control rule dynamic update system and other risk control rule dynamic update systems based on online learning, such as sending and / or receiving data. It should be noted that in actual scheduling, the transceiver 1004 is not limited to one, and the structure of this risk control rule dynamic update system 100 based on online learning does not constitute a limitation on the embodiments of this application.
[0149] The memory 1003 is used to store program code for executing the embodiments of this application, and its execution is controlled by the processor 1001. The processor 1001 is used to execute the program code stored in the memory 1003 to implement the steps shown in the foregoing method embodiments.
[0150] This application provides a computer-readable storage medium storing program code, which, when executed by a processor, can implement the steps and corresponding content of the aforementioned method embodiments.
[0151] It should be understood that although arrows indicate various operation steps in the flowcharts of the embodiments of this application, the order in which these steps are implemented is not limited to the order indicated by the arrows. Unless explicitly stated herein, in some implementation scenarios of the embodiments of this application, the implementation steps in each flowchart may be executed in other orders based on requirements. Furthermore, some or all steps in each flowchart may include multiple sub-steps or multiple stages depending on the actual implementation scenario. Some or all of these sub-steps or stages may be executed at the same time, and each sub-step or stage may also be executed at different times. In scenarios where execution times differ, the execution order of these sub-steps or stages can be flexibly configured based on requirements, and the embodiments of this application do not limit this.
[0152] The above description is only an optional implementation method for some implementation scenarios of this application. It should be noted that for those skilled in the art, other similar implementation methods based on the technical concept of this application, without departing from the technical concept of this application, also fall within the protection scope of the embodiments of this application.
Claims
1. A method for dynamically updating risk control rules based on online learning, characterized in that, The method includes: Obtain the currently effective initial risk control rule set and real-time transaction data sequence. Based on the initial risk control rule set, perform risk assessment on each transaction in the real-time transaction data sequence to obtain the initial risk assessment result and the subset of transaction data that did not hit the rules for each transaction. The initial risk control rule set contains multiple rule entries for determining transaction risk, and the real-time transaction data sequence contains detailed information of multiple transactions generated in chronological order. Online learning samples are selected from the subset of transaction data that did not hit the rules and the historical risk control result database. The subset of transaction data that did not hit the rules is associated with transaction data with similar characteristics in the historical risk control result database. The actual risk status of each associated transaction is marked to form an labeled online learning sample set. The historical risk control result database stores the risk judgment results of past transactions and the actual risk status of subsequent verification. Based on the labeled online learning sample set, the risk control rule parameters are iterated. The incremental update method of online learning is adopted. The samples in the labeled online learning sample set are input into the rule parameter adjustment process in batches according to the time sequence. The judgment threshold and feature weight of the corresponding risk control rule item are adjusted according to the labeling results of each batch of samples, and the iterated risk control rule parameter set is generated. The effectiveness of the risk control rules corresponding to the iterative risk control rule parameter set is verified. The risk control rules corresponding to the iterative risk control rule parameter set are applied to the newly collected verification transaction data sequence. The verification risk judgment result under the risk control rule is compared with the actual risk status subsequently fed back by the verification transaction data sequence. The conformity rate of the risk control rule judgment is calculated to obtain the rule effectiveness verification result. Based on the rule validity verification results, the iterative risk control rules are deployed. If the rule validity verification results meet the preset rule application standards, the risk control rules corresponding to the iterative risk control rule parameter set are updated to the currently effective risk control rule set, replacing the original initial risk control rule set. At the same time, the labeled online learning samples and rule parameter adjustment records during this iteration process are stored in the online learning history database.
2. The method for dynamically updating risk control rules based on online learning according to claim 1, characterized in that, The process of obtaining the currently effective initial risk control rule set and real-time transaction data sequence, and performing risk assessment on each transaction in the real-time transaction data sequence based on the initial risk control rule set to obtain the initial risk assessment result and a subset of transaction data that did not hit the rules for each transaction includes: Retrieve the initial set of risk control rules that are currently in effect from the risk control rule management system. Each rule entry contains risk assessment characteristics, characteristic assessment conditions, and risk level mapping relationships. Record the unique identifier and current application version of each rule entry. The system retrieves real-time transaction data sequences arranged in chronological order from the transaction processing system. Detailed information for each transaction includes information on the transaction participants, transaction amount, transaction channel, transaction time, and transaction operation records. Detailed information of each transaction in the real-time transaction data sequence is extracted one by one. The detailed information of each transaction is matched with each rule entry in the initial risk control rule set to check whether the detailed information of the transaction meets the feature judgment conditions of the rule entry. If the details of any transaction meet the feature determination conditions of a certain rule entry, then the unique identifier of that rule entry and the corresponding risk level are used as the initial risk determination result of that transaction; if the details of any transaction do not meet the feature determination conditions of any rule entry, then the details of that transaction are classified into the subset of transaction data that do not match the rule. Record the rule entry identifier and judgment time corresponding to the initial risk assessment result of each transaction. Sort the subset of transaction data that did not hit the rule according to the transaction time order, and mark the collection time and unique identifier of each transaction that did not hit the rule, forming a structured subset of transaction data that did not hit the rule.
3. The method for dynamically updating risk control rules based on online learning according to claim 1, characterized in that, The process involves selecting online learning samples from the subset of transaction data that did not meet the rules and the historical risk control result database, associating the subset of transaction data that did not meet the rules with transaction data with similar characteristics in the historical risk control result database, and labeling the actual risk status of each associated transaction to form a labeled online learning sample set, including: Extract detailed transaction information, initial risk assessment results, actual risk status and verification time of past transactions from the historical risk control results database. The actual risk status is determined based on whether a risk event occurs after the transaction. Feature extraction is performed on the detailed information of each transaction in the subset of transaction data that did not hit the rule, and feature extraction is performed on the detailed information of past transactions in the historical risk control result database in the same dimension to obtain the feature set of past transactions. The feature set of past transactions is compared with the feature set of past transactions, and past transactions with similar features are selected as related transactions to establish the correspondence between transactions that did not hit the rule and related transactions. The extracted features include transaction amount features, transaction channel features, historical behavior features of transaction participants, and transaction operation features. The actual risk status of related transactions is marked onto the corresponding unmatched rule transactions. If any unmatched rule transaction has multiple related transactions, the actual risk status of the related transaction with the most recent verification time is selected as the marking result of the unmatched rule transaction. Transactions that did not hit the rules and whose actual risk status was marked were screened, and transaction data with complete transaction characteristics and clear marking results were retained. The screened marked transaction data was then merged with some data marked as risky and normal transactions in the historical risk control result database in a recent period to form a marked online learning sample set. The marked online learning sample set was arranged in order of marking time.
4. The method for dynamically updating risk control rules based on online learning according to claim 1, characterized in that, The risk control rule parameter iteration is performed based on the labeled online learning sample set. An incremental update method using online learning is employed. Samples from the labeled online learning sample set are input into the rule parameter adjustment process in batches according to time sequence. The judgment threshold and feature weights of the corresponding risk control rule entries are adjusted based on the labeling results of each batch of samples, generating an iterated risk control rule parameter set, including: The labeled online learning sample set is divided into multiple batches of incremental samples in chronological order. Each batch of incremental samples contains a preset number of labeled transaction data generated in consecutive time periods. Set a parameter adjustment counter for each rule entry in the initial risk control rule set. The initial counter value is zero. The counter value is used to record the number of incremental sample batches that have participated in parameter adjustment for that rule entry. The process involves taking the first batch of incremental samples and adjusting the rule parameters. For each risk control rule, samples with features consistent with the rule's judgment features are selected from the first batch of incremental samples. The labeling results of the selected samples are analyzed. If a sample is labeled as risky and was not judged as risky by the original rule, the judgment threshold of the corresponding feature is lowered. If a sample is labeled as normal and was misjudged as risky by the original rule, the judgment threshold of the corresponding feature is raised. The feature weights are adjusted based on the degree of deviation between the sample labeling results and the rule judgment results. The degree of deviation is determined by the relative difference between the sample feature and the original rule judgment threshold. The larger the relative difference, the greater the degree of deviation, and the greater the adjustment of the corresponding feature weight. If any feature is a key influencing factor in multiple deviation samples, the weight of that feature is increased. After adjusting the rule parameters for the first batch of incremental samples, increment the parameter adjustment counter value of the corresponding rule entry by 1, and then repeat the above operations of screening samples, adjusting the judgment threshold and feature weights for the second batch of incremental samples. During the parameter adjustment process for each batch of incremental samples, refer to the adjustment records of previous batches for this rule entry. If the rule judgment deviation shows a downward trend after multiple consecutive batches of adjustments, then reduce the adjustment range of subsequent batches; if the deviation shows an upward trend, then re-evaluate the rationality of feature selection and adjust the feature weight allocation method. After all batches of incremental samples have completed parameter adjustments, the adjusted judgment threshold and feature weights of each risk control rule entry are collected and integrated to form an iterative risk control rule parameter set. At the same time, the parameter adjustment process of each rule entry and the degree of influence of each batch of incremental samples are recorded.
5. The method for dynamically updating risk control rules based on online learning according to claim 1, characterized in that, The validity verification of the risk control rules corresponding to the iterative risk control rule parameter set is performed by applying the risk control rules corresponding to the iterative risk control rule parameter set to the newly collected verification transaction data sequence, comparing the verification risk judgment result under the risk control rule with the actual risk status subsequently fed back by the verification transaction data sequence, and statistically calculating the conformity rate of the risk control rule judgment to obtain the rule validity verification result, including: New verification transaction data sequences are collected from the transaction processing system. The time range of the verification transaction data sequences is later than that of the real-time transaction data sequences, and they contain multiple transaction data with different characteristics. The verification transaction data sequences have not participated in the previous online learning sample screening and rule parameter iteration process. The risk control rules corresponding to the iterative risk control rule parameter set are loaded into the rule verification process. Each transaction data in the verification transaction data sequence is input into the risk control rule one by one, and the risk judgment operation is performed to obtain the verification risk judgment result corresponding to each transaction. The verification risk judgment result includes the risk level and the triggering rule entry identifier. Record the verification risk assessment result and assessment time for each verification transaction, and continuously track the subsequent actual transaction status of each verification transaction to observe whether any risk events occur and determine the actual risk status of each verification transaction. Compare the verification risk assessment result of each verification transaction with the actual risk status. If the risk level in the verification risk assessment result is consistent with the actual risk status, the rule assessment result of the transaction is determined to be compliant; otherwise, it is determined to be non-compliant. Calculate the proportion of transactions with compliant rule assessment results out of the total number of verification transactions to obtain the rule assessment compliance rate. Analyze transaction data that does not meet the criteria, distinguish between missed and incorrect judgments of rule entries, and calculate the missed judgment rate and incorrect judgment rate separately. Missed judgment refers to transactions that are actually risky but are not judged as risky, while incorrect judgment refers to transactions that are actually normal but are judged as risky. The compliance rate, false negative rate, and false positive rate of the rule judgment are integrated to form the rule validity verification result. The rule validity verification result also includes the feature analysis of transactions that do not meet the judgment, that is, in which features do the transactions that do not meet the judgment deviate from the rule judgment conditions.
6. The method for dynamically updating risk control rules based on online learning according to claim 3, characterized in that, The process involves extracting features from the detailed information of each transaction in the subset of transaction data that did not meet the rule, and extracting features of the same dimension from the detailed information of past transactions in the historical risk control result database to obtain a feature set of past transactions. A similarity comparison is then performed between the features of the transactions that did not meet the rule and the feature set of past transactions. Past transactions with similar features are selected as related transactions to establish a correspondence between transactions that did not meet the rule and related transactions. This includes: For each transaction in the subset of transaction data that did not hit the rule, the range of the transaction amount and the difference between the transaction amount and the historical average transaction amount of the transaction participant are extracted as transaction amount features. For transaction channel information, extract the channel type used in the transaction, the frequency of historical risk occurrence of the channel, and the geographical distribution characteristics of the channel as transaction channel features; Based on the historical behavioral characteristics of trading participants, information such as the frequency of transactions, the distribution of transaction time periods, the distribution of counterparty types, and the existence of historical risk records in recent periods are extracted and integrated into the historical behavioral characteristics of trading participants. Based on the characteristics of transaction operations, information such as the type of device initiating the transaction, the duration of the operation, the completeness of the operation steps, and whether there are abnormal operation sequences are extracted to form transaction operation characteristics; Feature extraction is performed on the detailed transaction information of each past transaction in the historical risk control results database to obtain the transaction amount feature, transaction channel feature, historical behavior feature of transaction participants, and transaction operation feature of each past transaction. The features of all past transactions are integrated to form the feature set of past transactions. A similarity comparison weight is assigned to each feature dimension. The weights for transaction amount and historical behavior of transaction participants are set as the first type of weight, while the weights for transaction channel and transaction operation are set as the second type of weight. The first type of weight is greater than the second type of weight. A similarity assessment is performed on each feature dimension of the transaction that did not meet the rule and the corresponding feature dimension of the past transaction. If the information overlap of two transactions in any feature dimension reaches a preset ratio, then that dimension is judged to be similar. The comprehensive similarity score between the transaction that did not meet the rule and each past transaction is calculated by combining the similarity assessment results of each feature dimension and the corresponding weight. Past transactions with a comprehensive similarity score higher than the similarity score threshold are selected as related transactions of transactions that did not meet the rules. If multiple past transactions have a comprehensive similarity score higher than the similarity score threshold, then the preset number of past transactions with the highest comprehensive similarity score are selected as related transactions. For each transaction that does not match the rules, a list of related transactions is created, recording the transaction identifier, comprehensive similarity score, and feature similarity dimension of the related transactions, thus forming a correspondence between transactions that do not match the rules and related transactions.
7. The method for dynamically updating risk control rules based on online learning according to claim 4, characterized in that, The process of adjusting the input rule parameters of the first batch of incremental samples involves selecting samples with features related to the rule entry from the first batch of incremental samples for each risk control rule entry, i.e., samples whose features are consistent with the judgment features of the rule entry; analyzing the labeling results of the selected samples, if the sample is labeled as risky and the sample is not judged as risky by the original rule entry, then the judgment threshold of the feature corresponding to the rule entry is reduced. If a sample is labeled as normal but is misjudged as risk by the original rule, the judgment threshold for the corresponding feature of that rule is increased. Feature weights are adjusted based on the degree of deviation between the sample labeling result and the rule judgment result. The degree of deviation is determined by the relative difference between the sample feature and the original rule judgment threshold; the larger the relative difference, the greater the degree of deviation, and the greater the adjustment of the corresponding feature weight. If any feature is a key influencing factor in multiple biased samples, the weight of that feature is increased. Feature weights include: Select the first batch of incremental samples from the divided batches of incremental samples, and read the labeled information and extracted transaction features of each transaction in this batch of samples; For the first risk control rule entry in the initial risk control rule set, the judgment feature of the rule entry is extracted. The judgment feature is the core feature of the rule used to determine risk. Iterate through each transaction in the first batch of incremental samples and check whether the characteristics of the transaction contain features that are consistent with the characteristics determined by the rule entry. If they are, then filter the transaction sample as a sample related to the feature corresponding to the rule entry. The selected feature-related samples are classified according to the labeling results into samples labeled as risky and samples labeled as normal. First, process the samples marked as risky. Check whether each sample of this type is judged as risky by the original rule entry. If it is not judged as risky, lower the judgment threshold of the corresponding judgment feature of the rule entry so that subsequent similar samples can be judged as risky by the rule entry. Then process the samples marked as normal and check whether each sample of this type was misjudged as risk by the original rule entry. If it was misjudged, increase the judgment threshold of the corresponding judgment feature of the rule entry to reduce the misjudgment. The degree of deviation for each deviation sample is calculated. The degree of deviation is determined based on the difference between the sample features and the original rule's judgment threshold. The greater the difference, the greater the degree of deviation. The adjustment range of feature weights is determined based on the degree of deviation. The greater the degree of deviation, the greater the adjustment range of the corresponding judgment feature weight. If any feature is the key factor causing the judgment deviation in multiple deviation samples, that is, the deviation of multiple deviation samples is mainly due to the mismatch between the feature and the rule judgment conditions, then the weight of the feature in the rule judgment is increased. After completing the parameter adjustment of the first rule entry, process the other rule entries in the initial risk control rule set according to the same process until all rule entries have completed the parameter adjustment based on the first batch of incremental samples; Record the parameter adjustment details for each rule entry in the first batch of incremental samples, including the direction of the adjustment judgment threshold, the adjustment magnitude, the change in feature weights, and the corresponding number of biased samples.
8. The method for dynamically updating risk control rules based on online learning according to claim 5, characterized in that, The system records the verification risk assessment result and assessment time for each verification transaction, continuously tracks the subsequent actual transaction status of each verification transaction, observes whether risk events occur, and determines the actual risk status of each verification transaction. The verification risk assessment result for each verification transaction is compared with the actual risk status. If the risk level in the verification risk assessment result matches the actual risk status, the transaction is deemed compliant; otherwise, it is deemed non-compliant. The compliance rate of the rule assessment is calculated as the proportion of compliant transactions out of the total number of verification transactions, including: Assign a unique verification identifier to each verification transaction in the verification transaction data sequence, record the verification risk assessment result of each transaction, including the assessed risk level, the triggered rule entry identifier, and the assessment time, and store it in the verification result record table; Set a tracking period and continuously monitor the subsequent transaction status of each verified transaction within the tracking period, including whether the transaction is revoked by the initiator, whether there is an abnormal flow of funds, whether a risk complaint is received, and whether it is marked as a risky transaction by the regulatory system. Based on the transaction status monitored during the tracking period, the actual risk status of each verification transaction is determined. If any of the above-mentioned risk-related statuses occur, the actual risk status is determined to be risky; if no risk-related statuses occur during the tracking period and the transaction is settled normally, the actual risk status is determined to be normal. The actual risk status of each verified transaction is recorded in the verification result record table and stored in association with the verification risk assessment result of the transaction; Compare the verification risk assessment result of each transaction with the actual risk status in the verification result record table one by one. If the risk level in the verification risk assessment result is risk and the actual risk status is risk, or the risk level in the verification risk assessment result is normal and the actual risk status is normal, then the rule assessment result of the transaction is determined to be compliant. If the risk level in the verification risk assessment result is "risk" but the actual risk status is "normal", or if the risk level in the verification risk assessment result is "normal" but the actual risk status is "risk", then the rule assessment result for this transaction is deemed non-compliant. The number of transactions deemed compliant is recorded in the statistical verification results record table, and the total number of verified transactions in the verification transaction data sequence is also counted. The compliance rate of the rule determination is determined by the ratio of the number of compliant transactions to the total number of verified transactions. The determined compliance rate is compared with the preset compliance rate benchmark. If the compliance rate is higher than the benchmark, it is preliminarily determined that the iterated risk control rules are effective. If the compliance rate is lower than the benchmark, the reasons for the non-compliance judgment need to be further analyzed to provide direction for possible subsequent rule adjustments.
9. The method for dynamically updating risk control rules based on online learning according to claim 1, characterized in that, The process involves deploying iterated risk control rules based on the rule validity verification results. If the rule validity verification results meet preset rule application standards, the risk control rules corresponding to the iterated risk control rule parameter set are updated to the currently effective risk control rule set, replacing the original initial risk control rule set. Simultaneously, the labeled online learning samples and rule parameter adjustment records from this iteration process are stored in the online learning history database, including: Obtain the preset rule application standard, which includes the minimum compliance rate requirement, the maximum limit of the false negative rate, and the maximum limit of the false positive rate for rule judgment. Only when the compliance rate in the rule validity verification result reaches the minimum compliance rate requirement, and the false negative rate and the false positive rate are both lower than the corresponding maximum limits, is it determined that the rule application standard is met. The compliance rate, false negative rate, and false positive rate in the rule validity verification results are compared with the corresponding indicators in the rule application standard to check whether all indicator requirements are met. If all the indicator requirements are met, the risk control rules corresponding to the iterated risk control rule parameter set are determined to be applicable. The adjusted judgment threshold and feature weight of each rule entry are read from the iterated risk control rule parameter set to generate new risk control rule entries. The new risk control rule entries are integrated to form a new set of currently effective risk control rules. The original initial set of risk control rules is replaced with the new set of currently effective risk control rules through the rule update interface of the risk control rule management system. The effective time of the new set of currently effective risk control rules is set to the current time. If the rule application standard is not met, analyze the reasons why the rule validity verification results do not meet the indicator requirements. If the false negative rate is greater than the corresponding threshold, return to the online learning sample screening step to supplement and screen more samples containing false negative features. If the false negative rate is greater than the corresponding threshold, return to the rule parameter iteration step to readjust the judgment threshold and feature weight of the corresponding rule item. All labeled online learning samples were collected during this iteration, including the selected non-matching rule transaction samples, related historical transaction samples, and merged incremental samples, and sorted and organized according to time order and labeling results; Collect parameter adjustment records for each risk control rule item during this iteration, including the adjustment range, adjustment basis, parameter comparison before and after adjustment, and feedback on the effect after adjustment for each batch of incremental samples; The organized and labeled online learning samples and parameter adjustment records are stored in the online learning history database. At the same time, the initiation time, effective time, number of sample batches participating in the iteration, and final rule validity verification results of this rule update are recorded to form a rule update archive.
10. A risk control rule dynamic update system based on online learning, characterized in that, The method includes a processor and a computer-readable storage medium storing machine-executable instructions, which, when executed by the processor, implement the online learning-based risk control rule dynamic update method as described in any one of claims 1-9.