Risk control rule optimization method and device
By analyzing fraud risk complaint forms and optimizing risk control rules through rule analysis models, the problems of low efficiency and insufficient accuracy in risk control rule optimization have been solved, resulting in more efficient and accurate interception of fraudulent behavior.
Patent Information
- Application Number
- CN202511474658.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-15
- Publication Date
- 2026-02-24
AI Technical Summary
In existing technologies, risk control rule optimization is inefficient and inaccurate, making it difficult to effectively cover increasingly complex fraudulent activities.
By obtaining fraud risk complaint forms, we analyze the mapping relationship between fraud targets and risk characteristics, optimize risk control rules using a pre-trained rule analysis model, obtain optimization strategies for target risk control rules, and update the original risk control rules.
It improves the efficiency and accuracy of risk control rule optimization, enabling better interception of fraudulent activities, dynamic adjustment of risk level scores, and flexible response to complex fraud patterns.
Smart Images

Figure CN121563189A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of data risk control technology, and more specifically, to a method and apparatus for optimizing risk control rules. Background Technology
[0002] With the continuous development of internet finance, fraudulent activities committed online are increasing and becoming more complex and sophisticated, causing significant economic losses and reputational risks to various internet platforms. Current fraud risk management primarily relies on pre-established risk control rules to intercept potential fraudulent activities, followed by manual analysis.
[0003] In traditional fraud risk management, after risk control rules are formulated, the risk control strategy is usually optimized and improved manually. However, manual optimization of risk control rules is inefficient and inaccurate, making it difficult to accurately cover the increasing number of fraudulent activities.
[0004] Therefore, there is an urgent need for a technical solution that can efficiently and accurately optimize risk control rules. Summary of the Invention
[0005] This invention provides a risk control rule optimization method and apparatus, which can effectively improve the efficiency and accuracy of risk control rule optimization.
[0006] According to a first aspect of this application, a risk control rule optimization method is provided, the method comprising: Obtain a fraud risk complaint form, and based on the fraud risk complaint form, obtain the fraud target and risk characteristics, as well as the mapping relationship between the risk characteristics and the fraud target; The number of fraud targets mapped by the risk feature is determined according to the mapping relationship, and the target feature is obtained from the risk feature according to the number of fraud targets mapped by the risk feature. Obtain the rule matching degree between the pre-constructed original risk control rules and the target feature, and obtain the target risk control rule from the original risk control rules based on the rule matching degree; The original risk control rule, the target feature, the rule matching degree, and the target risk control rule are processed using a pre-trained rule analysis model to obtain the optimization strategy of the target risk control rule; The target risk control rule is optimized using the optimization strategy, and the original risk control rule is updated based on the optimized target risk control rule.
[0007] Optionally, obtaining the fraud risk complaint form includes: Obtain candidate risk complaint forms related to fraud; The candidate risk complaint forms are divided into business risk complaint forms for different business operations; The evaluation indicators for the business are obtained based on the business risk complaint form, and the risk level score for the business is obtained based on the evaluation indicators. Businesses whose risk level scores exceed a preset risk level score threshold are classified as high-risk businesses, and the business risk complaint forms for these high-risk businesses are classified as fraud risk complaint forms.
[0008] Optionally, the step of obtaining the evaluation indicators of the business based on the business risk complaint form, and obtaining the risk level score of the business based on the evaluation indicators, includes: Based on a preset time period, extract several evaluation indicators of the business in the current time period from the business risk complaint form, and extract several evaluation indicators of the business in historical time periods. Based on the evaluation indicators for the current time period and historical time periods, obtain the month-on-month growth rate of each evaluation indicator for the current time period; The risk level score of the business is obtained by weighting the various evaluation indicators for the current time period and the month-on-month growth rate of each evaluation indicator for the current time period.
[0009] Optionally, obtaining the target feature from the risk features based on the number of fraud targets mapped by the risk features includes: If the ratio of the number of fraud targets mapped by the risk feature to the total number of fraud targets exceeds a preset threshold, then the risk feature is used as the target feature.
[0010] Optionally, obtaining the rule matching degree between the pre-constructed original risk control rules and the target features includes: Obtain several risk control conditions contained in the original risk control rules; the risk control conditions are used to determine whether the fraud risk complaint form meets the original risk control rules; Each risk control condition in the original risk control rule is matched with each of the target features using text matching. The ratio of the number of risk control conditions that match the target feature to the total number of risk control conditions in the original risk control rules is used as the rule matching degree.
[0011] Optionally, obtaining the rule matching degree between the pre-constructed original risk control rules and the target features includes: Obtain several risk control conditions contained in the original risk control rules; the risk control conditions are used to determine whether the fraud risk complaint form meets the original risk control rules; Each risk control condition in the original risk control rule is matched with each of the target features using text matching. The ratio of the number of target features that match the risk control conditions to the total number of risk control conditions in the original risk control rules is used as the first matching degree. The semantic similarity between the original risk control rule and the set of all target features is obtained as the second matching degree; The first matching degree and the second matching degree are weighted to obtain the rule matching degree.
[0012] Optionally, obtaining candidate risk complaint forms related to fraud includes: Obtain the payment complaint form and its semantic vector; The semantic vector is processed by a pre-trained fraud classification model to obtain the fraud risk score of the payment complaint form; If the fraud risk score exceeds a preset risk threshold, the payment complaint is determined to be a candidate risk complaint.
[0013] Optionally, the evaluation indicators include several basic indicators and moving averages of each basic indicator; wherein, the moving average is obtained based on the basic indicators in the current time period and the basic indicators in several recent historical time periods, and the recent historical time periods are the time periods that are closest to the current time period in time.
[0014] Optionally, the step of processing the original risk control rule, the target feature, the rule matching degree, and the target risk control rule using a pre-trained rule analysis model to obtain an optimization strategy for the target risk control rule includes: Construct semantic guidance instructions, which are used to guide the rule analysis model to output the optimization strategy of the target risk control rule as required; The original risk control rule, the target feature, the rule matching degree, the target risk control rule, and the semantic guidance instruction are input into the rule analysis model for processing to obtain the optimization strategy of the target risk control rule.
[0015] According to a second aspect of this application, a risk control rule optimization device is provided, the device comprising: The complaint acquisition module is used to acquire fraud risk complaint forms, and based on the fraud risk complaint forms, acquire the fraud targets and risk characteristics, as well as the mapping relationship between the risk characteristics and the fraud targets; The target feature acquisition module is used to determine the number of fraud targets mapped by the risk feature according to the mapping relationship, and to acquire the target feature from the risk feature according to the number of fraud targets mapped by the risk feature; The target rule acquisition module is used to acquire the rule matching degree between the pre-constructed original risk control rules and the target features, and to acquire the target risk control rule from the original risk control rules based on the rule matching degree; The optimization strategy acquisition module is used to process the original risk control rule, the target feature, the rule matching degree and the target risk control rule using a pre-trained rule analysis model to obtain the optimization strategy of the target risk control rule; The rule update module is used to optimize the target risk control rule using the optimization strategy, and update the original risk control rule according to the optimized target risk control rule.
[0016] According to a third aspect of this application, an electronic device is provided, comprising: Memory, used to store one or more computer programs; A processor, when the one or more computer programs are executed by the processor, implements the risk control rule optimization method described in the first aspect above.
[0017] According to a fourth aspect of this application, a computer-readable storage medium is provided, the computer-readable storage medium storing computer instructions for causing a processor to execute and implement the risk control rule optimization method described in the first aspect above.
[0018] Based on any of the above aspects, the risk control rule optimization method, device, electronic device and computer storage medium provided in this application embodiment can extract common or similar features among fraud targets as target features by utilizing the mapping relationship between fraud targets and risk features in fraud risk complaint forms. In this way, the target features can be used to more accurately match the pre-built original risk control rules and verify the interception capability of the original risk control rules. Meanwhile, by inputting the matched target risk control rules, the original risk control rules, target features, and the rule matching degree of the target risk control rules into a pre-trained rule analysis model, the logical analysis capabilities of the rule analysis model are used to verify the interception capability of the original risk control rules and provide specific optimization strategies. Compared with the manual analysis and optimization of the interception capability of the original risk control rules, using the rule analysis model can effectively improve the efficiency of the analysis. Furthermore, the rule analysis model can better uncover the potential correlations between target features, target risk control rules, and the original risk control rules, thereby providing more accurate optimization strategies and improving the accuracy of risk control rule optimization. Attached Figure Description
[0019] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0020] Figure 1 This is an illustrative application scenario diagram of the risk control rule optimization method provided in this embodiment.
[0021] Figure 2 This is a flowchart illustrating the steps of the risk control rule optimization method provided in this embodiment.
[0022] Figure 3 This is a flowchart illustrating the steps involved in obtaining a fraud risk complaint form as provided in this embodiment.
[0023] Figure 4 This is a flowchart illustrating the steps involved in obtaining candidate risk complaint forms as provided in this embodiment.
[0024] Figure 5 This is a schematic diagram illustrating the steps involved in obtaining a risk level score as provided in this embodiment.
[0025] Figure 6 This is a flowchart illustrating one method for obtaining rule matching degree provided in this embodiment.
[0026] Figure 7 This is a flowchart illustrating another method for obtaining rule matching degree provided in this embodiment.
[0027] Figure 8 This is a schematic diagram of the functional modules of the risk control rule optimization device provided in this embodiment.
[0028] Figure 9 This is a schematic diagram of the structure of the electronic device provided in this embodiment. Detailed Implementation
[0029] The accompanying drawings are for illustrative purposes only and should not be construed as limiting the scope of this application. To better illustrate the following embodiments, some components in the drawings may be omitted, enlarged, or reduced, and do not represent the actual dimensions of the product; it is understandable to those skilled in the art that some well-known structures and their descriptions may be omitted in the drawings.
[0030] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present application, and not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative effort should fall within the scope of protection of the present application.
[0031] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0032] With the continuous development of internet finance, financial fraud committed through the internet is increasing, and these fraudulent activities are becoming increasingly complex and sophisticated, causing huge economic losses and reputational risks to various internet platforms that provide financial services.
[0033] Current fraud risk management primarily relies on pre-established risk control rules to intercept potentially fraudulent activities, followed by manual analysis. These risk control rules can be understood as a combination of several risk control restrictions. When these restrictions are met, the corresponding fraudulent activity is intercepted, preventing user losses. For example, a risk control rule could be "restrict overseas QR code transactions," meaning the restrictions could be "overseas" and "QR code transaction." When both restrictions are met, the activity is intercepted.
[0034] In traditional fraud risk management, corresponding risk control rules are pre-established and subsequently optimized and updated. This optimization is typically done manually, involving periodic analysis of transaction data to identify vulnerabilities in the rules and subsequent updates. This manual approach to rule optimization is inefficient and inaccurate, making it difficult to precisely cover increasingly complex fraudulent activities.
[0035] This embodiment provides a technical solution that can solve the above problems. The specific implementation of this application will be described in detail below with reference to the accompanying drawings.
[0036] An exemplary diagram illustrating an application scenario of a risk control rule optimization method provided in this application embodiment is shown below. Figure 1 As shown, the application scenario includes at least a server 100 and a terminal 200 that can communicate with the server 100.
[0037] Understandably, the server 100 can be an independent electronic device or a cluster of multiple electronic devices; the terminal 200 can be a smartphone terminal, personal computer, tablet computer, vehicle terminal, etc., but is not limited to these.
[0038] In one feasible approach, server 100 and terminal 200 may respectively execute the risk control rule optimization method provided in the embodiments of this application, or, optionally, the risk control rule optimization method provided in the embodiments of this application may be partially executed in server 100 and partially executed in terminal 200.
[0039] like Figure 2 As shown in the figure, this embodiment provides a risk control rule optimization method, which may include the following steps: S1: Obtain a fraud risk complaint form, and based on the fraud risk complaint form, obtain the fraud target and risk characteristics, as well as the mapping relationship between the risk characteristics and the fraud target; In this embodiment, the fraud risk complaint form can be obtained from payment complaint forms related to finance. These payment complaint forms refer to complaint texts submitted to the platform by users after completing payments due to objections regarding the payment amount, deduction time, payee identity, transaction authenticity, duplicate deductions, failure to receive services or goods, or doubts about the payment recipient, such as merchant qualifications or account information. Therefore, these payment complaint forms can be analyzed to extract the fraud risk complaint form.
[0040] In one implementation, such as Figure 3 As shown, obtaining a fraud risk complaint form may include: S11: Obtain a candidate risk complaint form related to fraud; As mentioned above, the candidate risk complaint form can be obtained from the payment complaint form, then... Figure 4 As shown, step S11 may include the following sub-steps: S111: Obtain the payment complaint form and its semantic vector; In this embodiment, all payment complaint forms submitted by users can be collected periodically, such as collecting payment complaint forms submitted by users daily. After collecting the payment complaint forms, the text content of the payment complaint forms is converted into semantic vectors. By converting the payment complaint forms into corresponding semantic vectors, the model can be better used to perform semantic analysis on the semantic vectors to determine whether the payment complaint forms are related to fraudulent activities.
[0041] S112: Process the semantic vector using a pre-trained fraud classification model to obtain the fraud risk score of the payment complaint form; In one implementation, the fraud classification model can employ a classification model with intent recognition capabilities. The semantic recognition of the semantic vector using the fraud classification model can be expressed as follows: In the formula, P represents the fraud risk score, content represents the payment complaint form, BERT(content) represents the semantic vector of the payment complaint form, and W1 and b1 are the hyperparameters obtained by pre-training the fraud classification model.
[0042] S113: If the fraud risk score exceeds the preset risk threshold, the payment complaint is determined to be a candidate risk complaint.
[0043] In this embodiment, the candidate risk complaint forms refer to payment complaint forms related to fraudulent activities. However, fraudulent activities can be divided into those with more severe impact and those with less severe impact. It is understood that although all fraudulent activities need to be processed and restricted, those with more severe impact need to be prioritized to avoid greater losses. Therefore, after obtaining the candidate risk complaint forms, it is necessary to further extract the candidate risk complaint forms with the greatest impact as the fraud risk complaint forms.
[0044] S12: Divide the candidate risk complaint forms into business risk complaint forms for different business operations; Understandably, fraud perpetrators will target specific business operations with different fraudulent activities, resulting in them typically focusing their fraudulent activities on only certain business areas within a given timeframe. Therefore, this embodiment categorizes candidate risk complaint forms according to business areas. Based on these categorized risk complaint forms, it can better utilize data relationships within the same business area to accurately identify fraudulent activities with significant impact.
[0045] S13: Obtain the evaluation indicators of the business based on the business risk complaint form, and obtain the risk level score of the business based on the evaluation indicators; In this embodiment, as Figure 5 As shown, step S13 may include the following sub-steps: S131: Based on a preset time period, extract several evaluation indicators of the business in the current time period from the business risk complaint form, and extract several evaluation indicators of the business in historical time periods. S132: Based on the evaluation indicators of the current time period and historical time periods, obtain the month-on-month growth rate of each evaluation indicator in the current time period; S133: The risk level score of the business is obtained by weighting the various evaluation indicators in the current time period and the month-on-month growth rate of the various evaluation indicators in the current time period.
[0046] Understandably, by using evaluation metrics for the current period, we can better determine the extent of fraudulent activity in a given business within a specific timeframe, thus effectively filtering out businesses with recent fraudulent activity. Furthermore, by analyzing the month-on-month growth rates of various evaluation metrics within the current period, we can better identify fraudulent activities with an expanding impact, thereby more accurately screening out high-risk businesses.
[0047] In a preferred embodiment, the evaluation indicators include several basic indicators and a moving average of each basic indicator; in this embodiment, the several basic indicators may include the amount of complaints, the number of complaint forms, and the number of complaint targets; the moving average can be obtained based on the basic indicators in the current time period and the basic indicators in several recent historical time periods, wherein the recent historical time period is the time period that is closest to the current time period in time.
[0048] For example, taking the complaint amount as an example, if the time period is set to one day, the moving average can be the sum of the complaint amount on the current day and the complaint amount of the previous 6 days, divided by the sum of the number of days, 7.
[0049] In one optional implementation, the month-on-month growth rate of the moving average of the basic indicator can be calculated by taking the current time period and several recent historical time periods as the current time period, obtaining the number of time periods included in the current time range as the period number, taking the period number of the closest period to the current time period as the recent historical time period, and calculating the month-on-month growth rate of the moving average of the basic indicator by taking the moving average of the basic indicator in the current time period and the moving average of the basic indicator in the recent historical time period.
[0050] By calculating the month-on-month growth rate of the moving average of the basic indicators, the risk level score calculation can focus more on the risk of fraudulent activities in the medium and long term, avoiding the situation where the corresponding business remains in a high-risk state in the short term, resulting in a constant month-on-month growth rate. It can dynamically obtain the risk level score of the business, and thus obtain the fraud risk complaint form.
[0051] S14: The business whose risk level score exceeds the preset risk level score threshold is identified as a high-risk business, and the business risk complaint form of the high-risk business is identified as the fraud risk complaint form.
[0052] By setting a risk level scoring threshold to identify high-risk businesses, the evaluation criteria for high-risk businesses can be dynamically adjusted by changing the risk level scoring threshold, thereby enabling the flexible extraction of fraud risk complaint forms.
[0053] In this embodiment, after obtaining the fraud risk complaint form, it is also necessary to obtain the fraud target and risk characteristics of the fraud risk complaint form.
[0054] In this embodiment, the target of fraud can be understood as a user who commits fraudulent behavior, which can be obtained through the complaint targets of the fraud risk complaint forms. The target of fraud can be an individual or a group that commits fraudulent behavior. When the target of fraud is a group, the complaint targets of related fraud risk complaint forms can be identified by analyzing the relationships between the fraud risk complaint forms.
[0055] In this embodiment, the risk characteristics can be understood as specific behavioral patterns of fraudulent behavior; in a preferred embodiment, the risk characteristics can be represented in a structured manner as follows: In this context, feature_name represents the feature name of the risk feature, feature_operator represents the operator of the risk feature, and feature_value represents the value of the operator. For example, for the risk feature "QR code payment method", where feature_name can be the payment method, feature_operator can be "=", and feature_value can be QR code payment, then the corresponding risk feature can be represented as "Payment method = QR code payment".
[0056] By obtaining the fraud targets and risk characteristics of the fraud risk complaint form, it is possible to extract common or similar characteristics among the fraud targets from the risk characteristics. Furthermore, it is possible to use these common or similar characteristics to verify that the pre-constructed original risk rules can effectively intercept various fraudulent behaviors of the fraud targets.
[0057] It is understood that, in this embodiment, since the risk characteristics and the fraud targets can be obtained from the fraud risk complaint form, the mapping relationship between the risk characteristics and the fraud targets can be obtained through the fraud risk complaint forms corresponding to the risk characteristics and the fraud targets.
[0058] S2: Determine the number of fraud targets mapped by the risk feature according to the mapping relationship, and obtain the target feature from the risk feature according to the number of fraud targets mapped by the risk feature; In this embodiment, the step S2, which involves obtaining the target feature from the risk features based on the number of fraudulent targets mapped by the risk features, may include the following sub-steps: If the ratio of the number of fraud targets mapped by the risk feature to the total number of fraud targets exceeds a preset threshold, then the risk feature is used as the target feature.
[0059] Understandably, if the ratio of the number of fraudulent targets mapped by a risk feature to the total number of fraudulent targets is large, it indicates that the risk feature appears in most fraudulent targets, and the risk feature represents a common feature of this group of fraudulent targets. Therefore, by setting the quantity threshold, shared features present in the vast majority of fraudulent targets can be identified as the target feature. Simultaneously, the target feature can be used to effectively verify the pre-constructed original risk rules, verifying whether the original risk rules can effectively cover the fraudulent behavior of the vast majority of fraudulent targets.
[0060] In an optional implementation, the step of obtaining the target feature from the risk features based on the number of fraud targets mapped by the risk features can be expressed as: In the formula, T(X) represents the number of fraud targets mapped by risk feature X, and D represents the total number of fraud targets; Support(X) represents the ratio of the number of targets mapped by the risk feature to the total number of fraud targets, denoted as the support degree of risk feature X; if the support degree of risk feature X exceeds a preset quantity threshold, then risk feature X is taken as the target feature.
[0061] S3: Obtain the rule matching degree between the pre-built original risk control rules and the target feature, and obtain the target risk control rule from the original risk control rules according to the rule matching degree; In one implementation, step S3 involves obtaining the rule matching degree between the pre-built original risk control rules and the target features, such as... Figure 6 As shown, it may include: A1: Obtain several risk control conditions contained in the original risk control rules; A2: Perform text matching between each risk control condition in the original risk control rule and each of the target features; A3: The ratio of the number of risk control conditions that match the target feature to the total number of risk control conditions in the original risk control rules is taken as the rule matching degree.
[0062] In this embodiment, the risk control conditions can be used to determine whether the fraud risk complaint or the payment complaint meets the original risk control rules; it is understood that the original risk control rules can be represented by several risk control conditions. For example, the original risk control rule for "ordering via overseas IP (Internet Protocol Address) QR code scanning" can be represented as follows: In the form of IP country For the country where the IP is located, PAY method This indicates the payment method. QrCode (Quick Response Code) represents QR code payment, which can be understood as, when PAY... method QR code payment and IP country For the United States, this can be a risk control condition for the original risk control rules; similarly, PAY... method QR code payment and IP country This can also be a risk control condition for the original risk control rules in the UK.
[0063] Specifically, by performing text matching between the risk control conditions and the target features, the target features that match the original risk control rules can be obtained directly and accurately. Understandably, in this embodiment, if the risk control condition matches the target feature in text, it means that the fraudulent behavior corresponding to the target feature will be intercepted by the original risk control rule. Therefore, the ratio of the number of risk control conditions matching the target feature to the total number of risk control conditions can be used as the rule matching degree to measure the interception capability of the original risk control rule for the corresponding target feature. The target risk control rule with the highest interception capability for the target feature can be selected from the original risk control rules, and then the interception capability can be further improved by optimizing the target risk control rule.
[0064] In another implementation, step S3 involves obtaining the rule matching degree between the pre-built original risk control rules and the target features, such as... Figure 7 As shown, it may include: B1: Obtain several risk control conditions contained in the original risk control rules; B2: Perform text matching between each risk control condition in the original risk control rule and each of the target features; B3: The ratio of the number of target features that match the risk control conditions to the total number of risk control conditions in the original risk control rules is taken as the first matching degree; B4: Obtain the semantic similarity between the original risk control rule and the set of all target features as the second matching degree; B5: Weight the first matching degree and the second matching degree to obtain the rule matching degree.
[0065] In this embodiment, based on obtaining a first matching degree by matching the text with the risk control conditions and target features, the semantic similarity between the original risk control rule and the set of all target features is further obtained as a second matching degree. The first matching degree and the second matching degree are weighted to obtain the rule matching degree, thereby adapting to the original risk control rule and using similarity to intercept fraudulent behavior, thereby improving the interception capability of the original risk control rule.
[0066] S4: Use a pre-trained rule analysis model to process the original risk control rule, the target feature, the rule matching degree, and the target risk control rule to obtain the optimization strategy of the target risk control rule; In this embodiment, step S4 may include the following steps: A semantic guidance instruction is constructed to guide the rule analysis model to output the optimization strategy of the target risk control rule as required; the original risk control rule, the target feature, the rule matching degree, the target risk control rule and the semantic guidance instruction are input into the rule analysis model for processing to obtain the optimization strategy of the target risk control rule.
[0067] In this embodiment, the rule analysis model can be constructed based on a language analysis model with logical analysis capabilities; wherein, the original risk control rules input to the rule analysis model can be a set of all original risk control rules, and the target features input to the rule analysis model can be a set of all target features. In one implementation, the rule matching degree input to the rule analysis model can be the rule matching degree corresponding to the target risk control rule; in some implementations, the rule matching degree input to the rule analysis model can be a set of each target feature and the original risk control rule.
[0068] By utilizing the semantic guidance instructions, the rule analysis model is guided to analyze the relationship between the original risk control rules, the target features, the rule matching degree, and the target risk control rules, thereby quickly and effectively obtaining the optimization strategy for the target risk control rules.
[0069] S5: Optimize the target risk control rule using the optimization strategy, and update the original risk control rule according to the optimized target risk control rule.
[0070] In this embodiment, after optimizing the target risk control rule, the optimized target risk control rule updates the original risk control rule, so that the optimized target risk control rule can be used as the original risk control rule to intercept fraudulent behavior.
[0071] like Figure 8 As shown in the illustration, this application also provides a risk control rule optimization device. Optionally, the risk control rule optimization device may include: The complaint acquisition module 11 is used to acquire fraud risk complaint forms, and based on the fraud risk complaint forms, acquire the fraud target and risk characteristics, as well as the mapping relationship between the risk characteristics and the fraud target; In this embodiment, the complaint acquisition module 11 can be used to perform... Figure 2 For a detailed description of the complaint acquisition module 11 shown in step S1, please refer to the description of step S1.
[0072] The target feature acquisition module 12 is used to determine the number of fraud targets mapped by the risk feature according to the mapping relationship, and to acquire the target feature from the risk feature according to the number of fraud targets mapped by the risk feature; In this embodiment, the target feature acquisition module 12 can be used to perform... Figure 2 For a detailed description of the target feature acquisition module 12 shown in step S2, please refer to the description of step S2.
[0073] The target rule acquisition module 13 is used to acquire the rule matching degree between the pre-constructed original risk control rules and the target features, and to acquire the target risk control rule from the original risk control rules according to the rule matching degree; In this embodiment, the target rule acquisition module 13 can be used to execute... Figure 2 For a detailed description of the target rule acquisition module 13 shown in step S3, please refer to the description of step S3.
[0074] The optimization strategy acquisition module 14 is used to process the original risk control rule, the target feature, the rule matching degree and the target risk control rule using a pre-trained rule analysis model to obtain the optimization strategy of the target risk control rule; In this embodiment, the optimization strategy acquisition module 14 can be used to execute... Figure 2 For a detailed description of the optimization strategy acquisition module 14 shown in step S4, please refer to the description of step S4.
[0075] The rule update module 15 is used to optimize the target risk control rule using the optimization strategy, and update the original risk control rule according to the optimized target risk control rule.
[0076] In this embodiment, the rule update module 15 can be used to execute... Figure 2 For a detailed description of the rule update module 15, see step S5 shown below. For a detailed description of step S5, please refer to the description of step S5.
[0077] It is understood that the above-described device embodiments and method embodiments can correspond to each other, and similar descriptions of the device embodiments can be referred to the method embodiments. To avoid repetition, further details are omitted here. The risk control rule optimization device provided in this application can execute a risk control rule optimization method provided in any embodiment of this application, and has the corresponding functional modules and beneficial effects of executing the method. The functional modules of the risk control rule optimization device can be implemented in hardware, in software instructions, or in a combination of hardware and software modules.
[0078] Specifically, the steps of the method embodiments of this application can be completed by integrated logic circuits in the processor hardware and / or instructions in software form. The steps of the risk control rule optimization method in the embodiments of this application can be directly implemented by a hardware encoding processor, or by a combination of hardware and software modules in the encoding processor. Optionally, the software module can be located in random access memory, and storage media such as read-only memory, programmable read-only memory, flash memory, electrically erasable programmable memory, and registers are all acceptable. The storage medium is located in the memory, and the processor reads the information in the memory and, in conjunction with its hardware, completes the steps in the above method embodiments.
[0079] This application provides an electronic device with the following structure: Figure 9 As shown. The electronic device can be as described in this embodiment. Figure 1 The server 100 or terminal 200 shown.
[0080] The electronic device includes a memory 21, a processor 22, a communication module 23, and an input / output interface 24, etc. Optionally, the memory 21, the processor 22, the communication module 23, and the input / output interface 24 can be connected and communicate with each other through a bus 25.
[0081] The memory 21 is used to store one or more computer programs and to transfer the code of the computer programs to the processor 22; when the one or more computer programs are executed by the processor 22, the risk control rule optimization method in this application embodiment is implemented.
[0082] Optionally, the electronic device can be connected to a network via communication module 23 to communicate with other devices, such as terminals or servers, to achieve data interaction. The electronic device can be various forms of digital computers, exemplarily such as desktop computers, servers, workbenches, mainframes, or other types of computers. The electronic device can also be various forms of mobile terminals, exemplarily such as smartphones, tablets, wearable devices (such as helmets, glasses, watches, etc.), and other similar mobile terminals.
[0083] Optionally, the electronic device can connect to required input / output devices, such as a keyboard or display device, via the input / output interface 24. The electronic device itself may have a display device, and other display devices can also be connected externally via the input / output interface 24. Optionally, a storage device, such as a hard disk, can also be connected via the input / output interface 24 to store data from the electronic device, read data from the storage device, or store data from the storage device in the memory 21. It is understood that the input / output interface 24 can be a wired interface or a wireless interface. Depending on the actual application scenario, the device connected to the input / output interface 24 can be a component of the electronic device or an external device connected to the electronic device when needed.
[0084] Optionally, the memory 21 may be a volatile memory and / or a non-volatile memory. The volatile memory may be a random access memory, etc., and the non-volatile memory may be a read-only memory, a programmable read-only memory, an erasable programmable read-only memory, an electrically erasable programmable read-only memory, or a flash memory, etc.
[0085] Optionally, the computer program stored in the processor 22 can be divided into one or more modules, which are stored in the memory 21 and executed by the processor 22 to perform the method provided in this embodiment. The one or more modules can be a series of computer program instruction segments capable of performing specific functions, which describe the execution process of the computer program in the electronic device.
[0086] Optionally, the processor 22 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the processor 22 include, but are not limited to, a central processing unit, a graphics processing unit, a digital signal processor, various special-purpose artificial intelligence computing chips, various processors running machine learning model algorithms, and can also be any suitable controller, microcontroller, processor, etc. The processor 22 executes the various methods and processes of this embodiment, exemplarily, such as a risk control rule optimization method according to an embodiment of this application.
[0087] Optionally, the bus 25 may include a path for transmitting information. Depending on its function, the bus 25 may be divided into an address bus, a data bus, a control bus, etc.
[0088] In an optional implementation, this application embodiment also provides a computer storage medium storing a computer program thereon. When the computer program is executed by a computer, it enables the computer to perform the methods described in the above-described method embodiments. Part or all of the computer program can be loaded and / or installed on the memory 21 of an electronic device. When the computer program is executed by the processor 22, one or more steps of a risk control rule optimization method according to an embodiment of this application can be performed.
[0089] Optionally, the computer-readable storage medium may be a random access memory, a read-only memory, a programmable read-only memory, an erasable programmable read-only memory, an electrically erasable programmable read-only memory, etc.
[0090] Obviously, the above embodiments of this application are merely examples for clearly illustrating the technical solution of this application, and are not intended to limit the specific implementation of this application. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the claims of this application should be included within the protection scope of the claims of this application.
Claims
1. A risk control rule optimization method, characterized in that, The method includes: Obtain a fraud risk complaint form, and based on the fraud risk complaint form, obtain the fraud target and risk characteristics, as well as the mapping relationship between the risk characteristics and the fraud target; The number of fraud targets mapped by the risk feature is determined according to the mapping relationship, and the target feature is obtained from the risk feature according to the number of fraud targets mapped by the risk feature. Obtain the rule matching degree between the pre-constructed original risk control rules and the target feature, and obtain the target risk control rule from the original risk control rules based on the rule matching degree; The original risk control rule, the target feature, the rule matching degree, and the target risk control rule are processed using a pre-trained rule analysis model to obtain the optimization strategy of the target risk control rule; The target risk control rule is optimized using the optimization strategy, and the original risk control rule is updated based on the optimized target risk control rule.
2. The risk control rule optimization method according to claim 1, characterized in that, The process of obtaining a fraud risk complaint form includes: Obtain candidate risk complaint forms related to fraud; The candidate risk complaint forms are divided into business risk complaint forms for different business operations; The evaluation indicators for the business are obtained based on the business risk complaint form, and the risk level score for the business is obtained based on the evaluation indicators. Businesses whose risk level scores exceed a preset risk level score threshold are classified as high-risk businesses, and the business risk complaint forms for these high-risk businesses are classified as fraud risk complaint forms.
3. The risk control rule optimization method according to claim 2, characterized in that, The step of obtaining the evaluation indicators for the business based on the business risk complaint form, and obtaining the risk level score for the business based on the evaluation indicators, includes: Based on a preset time period, extract several evaluation indicators of the business in the current time period from the business risk complaint form, and extract several evaluation indicators of the business in historical time periods. Based on the evaluation indicators for the current time period and historical time periods, obtain the month-on-month growth rate of each evaluation indicator for the current time period; The risk level score of the business is obtained by weighting the various evaluation indicators for the current time period and the month-on-month growth rate of each evaluation indicator for the current time period.
4. The risk control rule optimization method according to claim 1, characterized in that, The step of obtaining the target feature from the risk features based on the number of fraud targets mapped by the risk features includes: If the ratio of the number of fraud targets mapped by the risk feature to the total number of fraud targets exceeds a preset threshold, then the risk feature is used as the target feature.
5. The risk control rule optimization method according to claim 1, characterized in that, The step of obtaining the rule matching degree between the pre-constructed original risk control rules and the target features includes: Obtain several risk control conditions contained in the original risk control rules; the risk control conditions are used to determine whether the fraud risk complaint form meets the original risk control rules; Each risk control condition in the original risk control rule is matched with each of the target features using text matching. The ratio of the number of risk control conditions that match the target feature to the total number of risk control conditions in the original risk control rules is used as the rule matching degree.
6. The risk control rule optimization method according to claim 1, characterized in that, The step of obtaining the rule matching degree between the pre-constructed original risk control rules and the target features includes: Obtain several risk control conditions contained in the original risk control rules; the risk control conditions are used to determine whether the fraud risk complaint form meets the original risk control rules; Each risk control condition in the original risk control rule is matched with each of the target features using text matching. The ratio of the number of target features that match the risk control conditions to the total number of risk control conditions in the original risk control rules is used as the first matching degree. The semantic similarity between the original risk control rule and the set of all target features is obtained as the second matching degree; The first matching degree and the second matching degree are weighted to obtain the rule matching degree.
7. The risk control rule optimization method according to claim 2, characterized in that, The acquisition of candidate risk complaint forms related to fraud includes: Obtain the payment complaint form and its semantic vector; The semantic vector is processed by a pre-trained fraud classification model to obtain the fraud risk score of the payment complaint form; If the fraud risk score exceeds a preset risk threshold, the payment complaint is determined to be a candidate risk complaint.
8. The risk control rule optimization method according to claim 2 or 3, characterized in that, The evaluation indicators include several basic indicators and moving averages of each basic indicator; wherein, the moving averages are obtained by comparing the basic indicators in the current time period with the basic indicators in several recent historical time periods, and the recent historical time periods are the time periods that are closest to the current time period in time.
9. The risk control rule optimization method according to any one of claims 1-7, characterized in that, The step of processing the original risk control rules, the target features, the rule matching degree, and the target risk control rules using a pre-trained rule analysis model to obtain an optimization strategy for the target risk control rules includes: Construct semantic guidance instructions, which are used to guide the rule analysis model to output the optimization strategy of the target risk control rule as required; The original risk control rule, the target feature, the rule matching degree, the target risk control rule, and the semantic guidance instruction are input into the rule analysis model for processing to obtain the optimization strategy of the target risk control rule.
10. A risk control rule optimization device, characterized in that, The device includes: The complaint acquisition module is used to acquire fraud risk complaint forms, and based on the fraud risk complaint forms, acquire the fraud targets and risk characteristics, as well as the mapping relationship between the risk characteristics and the fraud targets; The target feature acquisition module is used to determine the number of fraud targets mapped by the risk feature according to the mapping relationship, and to acquire the target feature from the risk feature according to the number of fraud targets mapped by the risk feature; The target rule acquisition module is used to acquire the rule matching degree between the pre-constructed original risk control rules and the target features, and to acquire the target risk control rule from the original risk control rules based on the rule matching degree; The optimization strategy acquisition module is used to process the original risk control rule, the target feature, the rule matching degree and the target risk control rule using a pre-trained rule analysis model to obtain the optimization strategy of the target risk control rule; The rule update module is used to optimize the target risk control rule using the optimization strategy, and update the original risk control rule according to the optimized target risk control rule.