IoT-based methods, systems, devices, and storage media for preventing tampering of e-commerce transaction data.

By collecting multi-dimensional transaction data and calculating device health values ​​in the IoT e-commerce platform, performing digital signature verification and anomaly filtering, and using a cross-modal intelligent mapping model to generate dynamic verification thresholds, the problem of insufficient accuracy and comprehensiveness of the IoT e-commerce platform transaction data anti-tampering scheme is solved, and high reliability of transaction data is guaranteed.

CN121603217BActive Publication Date: 2026-04-21SHENZHEN GLOBALBRANDS TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
SHENZHEN GLOBALBRANDS TECH CO LTD
Filing Date
2026-01-29
Publication Date
2026-04-21

AI Technical Summary

Technical Problem

Existing anti-tampering solutions for transaction data in IoT e-commerce platforms suffer from several problems, including a lack of data source credibility assessment, a lack of targeted anti-tampering logic in the cross-modal data fusion process, and fixed verification thresholds that cannot adapt to complex scenarios. These issues result in insufficient accuracy and comprehensiveness in anti-tampering measures.

Method used

Multidimensional transaction data is collected synchronously by IoT devices, device health values ​​are calculated and integrated into standardized data packets, digital signature legality verification and abnormal data filtering are performed, multidimensional data association is performed using a pre-trained cross-modal intelligent mapping model, and dynamic verification thresholds are generated by combining real-time scene features to perform dual verification of numerical consistency and semantic relevance.

Benefits of technology

It achieves end-to-end, multi-dimensional, and dynamically adaptable anti-tampering of transaction data, improves the accuracy and comprehensiveness of transaction data identification in the e-commerce platform, ensures the authenticity and security of transaction data, and adapts to diverse e-commerce transaction scenarios with different product types, transaction times, and environmental conditions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121603217B_ABST
    Figure CN121603217B_ABST
Patent Text Reader

Abstract

This invention relates to the fields of Internet of Things (IoT) and data security technology, specifically providing a method, system, device, and storage medium for preventing tampering of transaction data in an IoT-based e-commerce platform. The method includes: synchronously collecting multi-dimensional transaction data and calculating device health values ​​via IoT devices when a transaction is triggered, and integrating this data into standardized data packets according to rules; performing digital signature verification, abnormal data filtering, and low-confidence data marking on the standardized data packets to obtain compliant data packets; associating multi-dimensional data through a cross-modal intelligent mapping model, calculating the credibility weight of the fused data, and outputting a fused feature vector; extracting real-time scene features, and integrating basic product thresholds and scene correction values ​​using a physical law knowledge base to generate a dynamic verification threshold; and performing dual verification of numerical consistency and semantic relevance on the fused feature vector based on the dynamic verification threshold to intercept suspected tampered transactions. This solution effectively ensures the authenticity and security of transaction data in an IoT-based e-commerce platform.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the fields of Internet of Things (IoT) and data security technology, specifically to a method, system, device, and storage medium for preventing tampering of transaction data in an online marketplace based on the Internet of Things. Background Technology

[0002] With the deep integration of IoT technology and e-commerce, IoT e-commerce platforms have rapidly gained popularity due to their convenient and intelligent transaction models. Transaction data serves as the core basis for e-commerce operations, fund settlement, and user rights protection; its authenticity and security directly determine the credibility of transactions. However, the collection of transaction data in IoT e-commerce platforms relies on various types of IoT devices (such as RFID readers, image acquisition devices, and weight sensors). Data transmission and processing involve multiple links, making them susceptible to security risks such as data distortion caused by device malfunctions, malicious tampering, and cross-dimensional data time sequence misalignment. Once transaction data is tampered with, it can lead to transaction disputes, economic losses, and even a crisis of reputation for the e-commerce platform. Therefore, preventing transaction data tampering has become a key technical requirement for the operation of IoT e-commerce platforms.

[0003] Existing anti-tampering solutions for transaction data mostly employ a single verification mechanism, such as verifying data transmission integrity solely through digital signatures or performing anomaly checks on single-dimensional data based on fixed thresholds. However, such solutions have significant technical flaws: First, the reliability assessment of the data source is lacking, failing to consider the impact of IoT device operating status (such as response latency and packet loss rate) and the reliability of historical data collection on current transaction data. This makes it difficult to identify data collected by abnormal or low-reliability devices, thus creating potential tampering risks at the source. Second, the cross-modal data fusion process lacks targeted anti-tampering logic, often employing indiscriminate feature fusion methods without effectively suppressing features suspected of tampering. This results in tampering features such as semantic contradictions and temporal discrepancies being included in the fused data, reducing the authenticity of the data fusion. Third, the verification thresholds are mostly fixed, failing to adapt to the differentiated needs of different product attributes (such as perishable fresh produce versus ordinary goods), transaction scenarios (such as promotional bulk transactions versus regular retail), and environmental conditions (such as temperature and humidity changes), leading to a high rate of missed and false positives during the verification process.

[0004] The shortcomings of the existing technologies mentioned above result in insufficient accuracy, comprehensiveness, and scenario adaptability of transaction data anti-tampering in IoT e-commerce, failing to meet the high reliability requirements in complex transaction environments. Therefore, there is an urgent need for a full-link, multi-dimensional, and dynamically adaptable transaction data anti-tampering technology solution to address the deficiencies of the existing technologies. Summary of the Invention

[0005] To overcome the shortcomings of existing technologies, this invention provides a method, system, device, and storage medium for preventing tampering of e-commerce transaction data based on the Internet of Things, thereby solving the problems in existing technologies.

[0006] One embodiment of the present invention provides a method for preventing tampering of e-commerce transaction data based on the Internet of Things, comprising the following steps:

[0007] When a transaction is triggered, multi-dimensional transaction data is collected synchronously through IoT devices and the device health value of the IoT devices is calculated. The multi-dimensional transaction data and device health value are integrated according to the preset data trustworthiness encapsulation rules to obtain a standardized data packet with digital signature and trustworthiness label.

[0008] The standardized data packets are subjected to digital signature verification, abnormal data filtering, and low-confidence data marking to obtain compliant data packets.

[0009] Based on a pre-trained cross-modal intelligent mapping model, multi-dimensional data association is performed on compliant data packets to obtain fused data; combined with device health values ​​and preset data weights, the credibility weight of the fused data is calculated and the fused feature vector is output.

[0010] Based on the fused feature vector, real-time scene features are extracted, a pre-built physical law knowledge base is called, and the real-time scene features are used as input to calculate and integrate the basic threshold of the product and the scene correction value to obtain the dynamic verification threshold.

[0011] The fused feature vector is subjected to dual verification of numerical consistency and semantic relevance based on the dynamic verification threshold. If either verification fails, it is marked as suspected tampering and the transaction is intercepted.

[0012] This application also relates to an IoT-based system for preventing tampering with transaction data in online marketplaces, comprising:

[0013] The data processing module is used to synchronously collect multi-dimensional transaction data through IoT devices and calculate the device health value of IoT devices when a transaction is triggered. It integrates the multi-dimensional transaction data and device health value according to preset data trustworthiness encapsulation rules to obtain a standardized data packet with digital signature and trustworthiness label.

[0014] The data filtering module is used to perform digital signature verification, abnormal data filtering, and low-confidence data marking on the standardized data packets to obtain compliant data packets.

[0015] The first calculation module is used to perform multi-dimensional data association on compliant data packets based on a pre-trained cross-modal intelligent mapping model to obtain fused data; and to calculate the credibility weight of the fused data and output the fused feature vector by combining the device health value and the preset data weight.

[0016] The second calculation module is used to extract real-time scene features based on the fused feature vector, call the pre-built physical law knowledge base, and calculate and integrate the basic threshold of the commodity and the scene correction value with the real-time scene features as input to obtain the dynamic verification threshold.

[0017] The verification module is used to perform dual verification of numerical consistency and semantic relevance on the fused feature vector based on the dynamic verification threshold. If either verification fails, it is marked as suspected tampering and the transaction is intercepted.

[0018] This application also relates to a computer device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the steps of the above-described method for preventing tampering of transaction data in an online marketplace based on the Internet of Things.

[0019] This application also relates to a computer-readable storage medium storing a computer program that, when executed by a processor, implements the steps of the above-described method for preventing tampering of transaction data in an online marketplace based on the Internet of Things.

[0020] The above embodiments provide a method, system, device, and storage medium for preventing tampering of e-commerce transaction data based on the Internet of Things, which have the following beneficial effects:

[0021] This solution synchronously collects multi-dimensional transaction data and calculates device health values ​​by linking IoT devices when a transaction is triggered. It then uses digital signatures and trustworthiness tags to encapsulate the data source with trustworthiness. High-trustworthiness data is further refined through multi-level compliance screening, including digital signature verification, anomaly filtering, and risk level labeling. Relying on a pre-trained, tamper-proof, customized cross-modal intelligent mapping model, it accurately correlates multi-dimensional data and generates fused data and tamper risk confidence through risk-differentiated weighted preprocessing, semantic-temporal dual consistency verification, and attention mechanism fusion. Furthermore, it dynamically calculates trustworthiness weights based on device health values ​​and risk label level coefficients in a scenario-based manner. Simultaneously, it extracts multi-dimensional real-time scene features based on the fused feature vector and integrates basic thresholds for goods from a physical law knowledge base. The system generates dynamically adaptable thresholds based on scene correction values, and ultimately intercepts suspected tampered transactions through dual verification of numerical consistency and semantic relevance. This forms a closed-loop anti-tampering mechanism encompassing "source credibility, process precision, dynamic thresholds, and comprehensive verification," effectively addressing issues such as the lack of source credibility assessment, susceptibility to tampering features in data fusion, fixed verification thresholds that cannot adapt to complex scenarios, and high rates of missed and false positives in traditional transaction data anti-tampering solutions. It significantly improves the accuracy and comprehensiveness of anti-tampering identification in e-commerce transaction data, ensuring the authenticity and security of transaction data. It adapts to diverse e-commerce transaction scenarios with different product types, transaction times, and environmental conditions, reducing transaction disputes and economic losses caused by data tampering, and providing strong technical support for the credible operation of IoT e-commerce transactions. Attached Figure Description

[0022] Figure 1A flowchart illustrating an IoT-based method for preventing tampering with transaction data in an online marketplace, provided as an embodiment of the present invention.

[0023] Figure 2 This is a schematic block diagram of a computer device provided in an embodiment of the present invention. Detailed Implementation

[0024] The technical solutions in the embodiments of the present invention will now be clearly and completely described in conjunction with the accompanying drawings.

[0025] Reference Figure 1 One embodiment of the present invention provides a method for preventing tampering of e-commerce transaction data based on the Internet of Things, comprising the following steps:

[0026] S10. When a transaction is triggered, multi-dimensional transaction data is collected synchronously through IoT devices and the device health value of the IoT devices is calculated. Multi-dimensional transaction data and device health value are integrated according to preset data trustworthiness encapsulation rules to obtain a standardized data packet with digital signature and trustworthiness label.

[0027] S20. Perform digital signature validity verification, abnormal data filtering, and low-confidence data marking on the standardized data packets to obtain compliant data packets;

[0028] S30. Based on the pre-trained cross-modal intelligent mapping model, multi-dimensional data association is performed on compliant data packets to obtain fused data; combined with device health values ​​and preset data weights, the credibility weight of the fused data is calculated and the fused feature vector is output.

[0029] S40. Based on the fused feature vector, extract real-time scene features, call the pre-built physical law knowledge base, use the real-time scene features as input, calculate and integrate the basic threshold of the commodity and the scene correction value to obtain the dynamic verification threshold.

[0030] S50. Based on the dynamic verification threshold, the fused feature vector is subjected to dual verification of numerical consistency and semantic relevance. If either verification fails, it is marked as suspected tampering and the transaction is intercepted.

[0031] In this embodiment, as described in step S10 above, the IoT devices include, but are not limited to, RFID readers, image acquisition devices, weight sensors, and temperature sensors. When transactions such as product settlement and order submission occur in the IoT mall, the system automatically triggers various IoT devices deployed in the transaction scenario to synchronously collect data. These devices synchronously collect multi-dimensional transaction data that can comprehensively characterize product attributes and transaction status. The multi-dimensional transaction data can cover characteristic data such as product category, origin, and batch collected by RFID readers, product appearance image feature data acquired by image acquisition devices, and corresponding physical feature data collected by weight sensors, temperature sensors, and other devices. At the same time, the system acquires relevant indicators such as the operating parameters and data acquisition quality of the IoT devices during this data collection process, and calculates the device health value used to evaluate the credibility of the data collected by the device. The preset data credibility encapsulation rules are structured integration and credibility identification rules based on the IoT mall data security management specifications, specifically including three aspects: First, the data structure integration rules require that the data be integrated according to the "device identification- The system organizes data in a fixed field order of "collection timestamp - multidimensional transaction data - device health value" to form a unified data body to be packaged. Secondly, it uses a digital signature generation rule, employing an asymmetric encryption algorithm and encrypting the hash digest of the data body using the e-commerce server's private key to generate a unique digital signature. Thirdly, it uses a trustworthiness label assignment rule, mapping the device health value's score range to corresponding label levels, with a positive correlation between label levels and health values. Once the multidimensional transaction data collection and IoT device health value calculation are complete, the system structurally integrates the collected multidimensional transaction data and the calculated device health value according to preset data trustworthiness packaging rules. A unique digital signature is generated for the integrated data, used to verify whether the data has been tampered with during transmission and storage. Simultaneously, a trustworthiness label associated with indicators such as device health value is assigned to the integrated data, ultimately forming a standardized data package containing multidimensional transaction data, device health value, digital signature, and trustworthiness label. This data package serves as the source data for all subsequent data processing and verification stages.

[0032] As described in step S20 above, the core objective is to perform multi-level screening and purification on the standardized data packets generated in step S10 to ensure that the data entering subsequent processing stages has high credibility and validity. The specific process is as follows: First, digital signature legality verification is performed. The system uses the asymmetric encryption algorithm corresponding to the data packet generation and decrypts the digital signature in the data packet using the e-commerce server's public key. The hash digest obtained after decryption is compared with the real-time hash calculation result of the data packet body to verify whether the data maintains integrity and source legality during transmission and storage. Then, abnormal data filtering is performed. Based on the preset abnormal data judgment rules, the multi-dimensional transaction data in the data packet is verified, and data that violates objective physical rules is filtered out. Data that violates rules, does not conform to normal transaction logic, or is invalid due to missing core data dimensions or serious mismatches in cross-dimensional data time series is temporarily retained and the missing information is recorded for data that is missing non-core data dimensions but does not affect the overall validity. Finally, low-confidence data is marked. Combining the confidence label of the data packet and the health value of the associated IoT device, and referring to the preset risk level classification standard, the risk level of the data packets after signature verification and anomaly filtering is assessed and marked as risk data of different confidence levels. Finally, the data packets that pass signature verification, have no key anomalies, and whose confidence level meets the preset standard are summarized and screened out. These are the compliant data packets, which will be used as input data for subsequent cross-modal data fusion processing.

[0033] As described in step S30 above, the cross-modal intelligent mapping model is a customized model trained with anti-tampering guidance. It has the dual capabilities of processing multi-source heterogeneous data and identifying implicit tampering risks. It can extract features, align dimensions, and semantically associate transaction data of different dimensions, such as RFID product features, image features, and physical sensor features, in compliant data packets. This eliminates information fragmentation caused by data heterogeneity and outputs fused data that can comprehensively represent the core information of commodity transactions. Simultaneously, it generates the tampering risk confidence level of the fused data. Based on the fused data and tampering risk confidence level output by the cross-modal intelligent mapping model, combined with the Io associated with the compliant data packet, The reliability of the fused data is quantitatively assessed by combining the device health value, risk labeling level coefficient, and preset scenario-based data weighting rules. The preset data weights will dynamically adjust the proportion of each core evaluation factor according to the needs of the transaction scenario. The reliability weight of the fused data is obtained through weighted calculation. This weight directly reflects the reliability level of the fused data from the source of collection to the fusion result. The fused data and the corresponding reliability weights are structured and integrated to output a fused feature vector containing comprehensive transaction characteristics and reliability quantitative indicators. This vector will serve as the core input data for the dynamic verification threshold calculation in step S40 and the dual verification in step S50.

[0034] As described in step S40 above, by combining scenario adaptation and physical laws as dual constraints, the limitations of traditional fixed thresholds are overcome, and dynamic verification thresholds that fit real-time transaction scenarios are generated, providing a judgment standard for subsequent risk assessment. From the fused feature vector output in step S30, real-time scenario features including product category, transaction scenario type, device operating status, and credible quantitative indicators are extracted to ensure that the feature dimensions cover the three core dimensions of product attributes, scenario environment, and data credibility. A pre-built physical law knowledge base is invoked (this knowledge base covers constraint rules that conform to actual business logic and physical laws, such as reasonable range of product weight, price range threshold, logistics timeliness constraints, and data transmission stability standards). This knowledge base is based on historical compliant transaction data, industry standards, and physical common sense. The system is designed to match scenario-based rules. It takes extracted real-time scenario features as input, matches the corresponding product's base threshold (a pre-defined range based on historical compliance data and physical laws) from the knowledge base, and then calculates a scenario correction value based on real-time scenario dynamic factors (such as promotional activities, device load, environmental interference, and data credibility weight). A pre-defined integration algorithm (such as base threshold ± scenario correction value, base threshold × scenario correction coefficient, etc.) is used to weight and integrate the two values ​​to obtain a dynamic verification threshold. This dynamic verification threshold has scenario adaptability and reasonable constraints, accurately matching the risk assessment needs of different transaction scenarios. It provides a dynamically adjusted judgment basis for the dual verification in step S50, avoiding misjudgment or omission of fixed thresholds in complex scenarios.

[0035] As described in step S50 above, based on the dynamic verification threshold generated in step S40 and the fused feature vector output in step S30, a comprehensive investigation of data tampering risks is conducted from two dimensions: quantitative indicators and logical correlations, to ensure the authenticity and compliance of transaction data. Specifically:

[0036] For numerical consistency verification, the actual values ​​of quantifiable core transaction indicators (such as product weight, transaction price, inventory quantity, data transmission latency, etc.) in the fused feature vector are compared with the dynamic verification thresholds output by S40. The verification logic is as follows: if the actual value of the quantifiable indicator is within a reasonable range of the dynamic verification threshold (e.g., the actual weight of mineral water is 502g, and the dynamic threshold is [492g-508g]), then the numerical consistency verification is deemed to have passed; if the actual value exceeds the threshold range (e.g., the actual selling price of clothing is 380 yuan, and the dynamic threshold is [238.8 yuan-358.8 yuan]), then the numerical consistency verification is directly deemed to have failed, triggering a suspected tampering flag.

[0037] For semantic relevance verification: the focus is on the inherent logical consistency of semantic features in each dimension of the fused feature vector (echoing the core idea of ​​semantic consistency verification in S322 and covering implicit logical conflicts after fusion). The verification objects include three types of relationships: semantic matching of product attributes, adaptation of transaction scenarios to product attributes, and fit between data sources and semantic features. Specifically: ① Semantic matching of product attributes: For example, the "fresh strawberry" labeled with RFID features needs to be consistent with the appearance and weight features of red berries extracted from the image, corresponding to the specification of 200g / box, to avoid contradictions between category codes and physical characteristics; ② Adaptation of transaction scenarios to product attributes: For example, the cold chain transportation scenario needs to match the product attribute "requires refrigeration" to avoid logical conflicts between room temperature products labeled as cold chain transportation; ③ Fit between data sources and semantic features: If the weight features of products collected by high-risk equipment (confidence weight 0.2) have semantic contradictions with the appearance features collected by risk-free equipment (e.g., weight labeled as 1kg but image shows small packaging), it is mainly judged as semantic relevance anomaly. The verification process uses a pre-defined semantic association rule base (integrating product attribute logic and transaction scenario specifications) to perform rule matching. If there is no logical conflict, the semantic association verification is deemed to have passed; if any contradiction exists, it is deemed to have failed.

[0038] Based on the verification results of numerical consistency and semantic relevance, a "one-vote veto system" is adopted to determine the compliance of transaction data: both verifications must pass simultaneously to confirm that the data is free from tampering risks and allow the transaction to proceed normally; if either verification fails (e.g., numerical values ​​exceed thresholds, semantic logic contradictions), the transaction is immediately marked as a "suspected data tampering transaction," triggering a transaction interception mechanism (e.g., suspending the payment process, locking the order), and generating a tampering risk report (listing the failed steps, abnormal indicators, and related thresholds), providing a basis for subsequent manual review and risk tracing. This dual verification mechanism focuses on the inherent logical consistency of semantic features in each dimension of the fused feature vector, and combines dynamic thresholds to achieve scenario-based adaptation of quantitative indicators, effectively avoiding missed judgments (e.g., tampered data with no semantic contradictions but abnormal numerical values) or misjudgments (e.g., implicit tampering with compliant numerical values ​​but conflicting semantic logic) caused by single-dimensional verification, ultimately achieving comprehensive and precise prevention and control of transaction data tampering risks.

[0039] In one embodiment, step S10, the calculation of the device health value of the IoT device, specifically includes the following steps:

[0040] S11. When a transaction is triggered, the operating parameters of the IoT device during the multi-dimensional transaction data collection window are obtained. The operating parameters are judged to be qualified according to the preset parameter threshold, and the device operating status score is calculated. The collection window starts from the time the collection command is issued and ends when the IoT device completes the collection of multi-dimensional transaction data and transmits it to the data integration and packaging stage. The operating parameters include at least the concurrent collection response time and the data transmission packet loss rate.

[0041] S12. Verify the data dimension integrity of the multidimensional transaction data and the temporal matching of cross-dimensional data, and calculate the data collection quality score based on the verification results.

[0042] S13. Retrieve the anti-tampering verification results corresponding to the historical data collected by the IoT device, calculate the suspected tampering rate of the historical data, and calculate the historical verification correlation score based on the suspected tampering rate.

[0043] S14. Based on the current transaction scenario, set the dynamic weight ratio of the device operation status score, data collection quality score, and historical verification correlation score. Calculate the device health value by comprehensively weighting the three scores based on the dynamic weight ratio. Among them, the weight ratio of improving the data collection quality score is given in commodity transaction scenarios that are sensitive to data collection quality, and the weight ratio of improving the device operation status score is given during peak transaction periods.

[0044] In this embodiment, as described in step S11 above, the core is based on the operational status evaluation score of the IoT device during this data collection process. Specifically, when a transaction is triggered, the system synchronously starts timing the data collection window. The time range of this window is from the moment the data collection command is issued until the IoT device completes the multi-dimensional transaction data collection and successfully transmits it to the data integration and encapsulation stage. During the window, the system obtains the key operating parameters of the IoT device in real time. The operating parameters include at least the concurrent data collection response time (i.e., the time interval from when the device receives the data collection command to when it starts returning data) and the data transmission packet loss rate (i.e., the proportion of lost data frames in the total number of data frames during transmission). Then, the system retrieves the preset parameter threshold (this threshold is set based on the device's factory standards and the mall's operational requirements; for example, the preset threshold for the concurrent data collection response time of the RFID reader is ≤500ms, and the data transmission packet loss rate is ≤500ms). The packet loss rate is preset to a threshold of ≤1%. The real-time acquired operating parameters are compared one by one with the preset parameter thresholds of the corresponding devices to determine whether each parameter is qualified. Then, according to the pre-designed scoring rules (each operating parameter has a full score of 10 points. Taking RFID readers as an example: concurrent acquisition response time ≤500ms gets 10 points, 500ms < time ≤600ms (1.2 times the threshold) is deducted linearly, and time >600ms gets 0 points; data transmission packet loss rate ≤1% gets 10 points, 1% < packet loss rate ≤1.5% is deducted linearly, and packet loss rate >1.5% gets 0 points), the score of each parameter is calculated. Since concurrent acquisition response time and data transmission packet loss rate are the core operating indicators, each accounts for 50% of the weight. Finally, the average value is calculated by "concurrent acquisition response time score × 50% + data transmission packet loss rate score × 50%", which is the device operating status score.

[0045] As described in step S12 above, its core is based on the quality assessment score of the collected data. Specifically, the system performs dual quality checks on the multi-dimensional transaction data collected in step S10. The first check is the integrity of the data dimensions. Data dimensions include core data dimensions and non-core data dimensions. Core data dimensions are key dimensions to ensure the validity of transactions and must include at least RFID product category and product weight characteristics. Non-core data dimensions include auxiliary characteristics such as temperature and humidity. The system checks whether the core dimensions are complete and without missing data, and records the missing data of non-core dimensions. The second check is the cross-dimensional data time sequence matching. The system extracts the timestamps of each dimension's data collection, calculates the maximum timestamp deviation between data collected by different devices such as RFID readers, image acquisition devices, and weight sensors, and determines whether the deviation is within the preset time sequence matching threshold. Within the specified range, such as a preset time-series matching threshold of ≤200ms, the data is ensured to be synchronously collected within the same transaction scenario. Based on the dual verification results, the data collection quality score is calculated according to the pre-designed scoring rules. The data collection quality score has a maximum of 10 points, of which data dimension integrity verification accounts for 60% of the weight, and cross-dimensional time-series matching verification accounts for 40% of the weight. If the core dimension is complete and there are no missing non-core dimensions, the dimension integrity score is 6 points. If only one non-core dimension is missing, 1 point is deducted. If one core dimension is missing, the dimension integrity score is 0 points. If the maximum timestamp deviation is ≤200ms, the time-series matching score is 4 points. If the deviation is within 200-300ms (allowing for slight deviations), 1 point is deducted linearly. If the deviation is >300ms, the time-series matching score is 0 points. Finally, the scores of the two verifications are summed according to their weights to obtain the data collection quality score.

[0046] As described in step S13 above, its core is to evaluate the historical data collection performance of the device based on the historical data collection performance. Specifically, the system retrieves all historical data collection records of the device within a fixed period (such as the last 30 days) through the unique identifier of the IoT device, as well as the final verification results of the corresponding historical data in the subsequent anti-tampering verification process (including judgments such as normal or suspected tampering). Based on the above historical verification results, the suspected tampering rate of the device is calculated, that is, the proportion of the number of data entries marked as suspected tampering in the historical data collection to the total number of data entries collected in the period. For example, the historical verification correlation score is 10 points, which is calculated using a reverse scoring rule linked to the suspected tampering rate. The preset risk ratio is 5%. If the suspected tampering rate is 0%, 10 points are obtained. If the suspected tampering rate is >5%, 0 points are obtained directly. If the suspected tampering rate is between 0% and 5%, the score is calculated according to a linear reverse ratio (for example, when the suspected tampering rate is 2.5%, the score = 10 points - (2.5% / 5%) × 10 points = 5 points). The final calculated score is the historical verification correlation score.

[0047] As described in step S14 above, the core is to obtain the final device health value by dynamically weighting and integrating three scores. Specifically, the system first automatically identifies the type characteristics of the current transaction scenario through the scenario recognition module, and then sets differentiated dynamic weight ratios for the device operation status score, data collection quality score, and historical verification correlation score according to the preset scenario-weight mapping rules. The total weight of the three scores is 100%. Among them, for transaction scenarios that are sensitive to data collection quality, such as fresh produce and high-value luxury goods, the weight ratio of the data collection quality score is increased, such as setting the weight of the data collection quality score to 50%, the weight of the device operation status score to 30%, and the weight of the historical verification correlation score to 20%, to ensure the priority of core data quality assessment. For peak transaction periods such as holiday promotions and peak store traffic, the weight ratio of the device operation status score is increased, such as setting the weight of the device operation status score to 100%. The weighting is 50% for data acquisition quality score, 30% for historical verification and correlation score, and 20% for historical verification and correlation score, with a focus on the operational stability of the device under high load. For routine transaction scenarios such as daily retail, a balanced weighting is adopted, such as 34%, 33%, and 33% for each of the three scores. After the weights are set, the system multiplies the three scores calculated in steps S11 to S13 by their corresponding weights, and then sums the products. The final sum is the device health value of the IoT device for this data acquisition, with a score range of 0-10 (a full score represents that the device's operating status, data acquisition quality, and historical performance are all at the best level). For example, in a fresh food transaction scenario, an RFID reader has a device operating status score of 9, a data acquisition quality score of 10, and a historical verification and correlation score of 8. Its device health value = 9 × 30% + 10 × 50% + 8 × 20% = 9.3 points.

[0048] In one embodiment, step S20 specifically includes the following steps:

[0049] S21. Perform digital signature validity verification on the standardized data packet. If the verification fails, the data packet is directly removed. If the verification passes, adjust the verification result level based on the device health value associated with the standardized data packet. When the device health value is lower than the preset health threshold, mark the verification result as pending review.

[0050] S22. For standardized data packets that have passed the digital signature legality verification or are marked as pending review, filter out abnormal data that violates objective physical laws and does not have the validity of transaction data, as well as invalid data with mismatched time series across dimensions; among them, when core data dimensions are missing, the standardized data packets are directly removed, and when non-core data dimensions are missing, the standardized data packets are retained and marked as missing dimensions.

[0051] S23. Based on the preset trustworthiness label threshold, mark the filtered standardized data packets as low-trustworthiness data: when the trustworthiness label of the standardized data packet is lower than the preset trustworthiness label threshold and the associated device health value does not reach the preset security level, it is marked as high-risk low-trustworthiness data; when only the trustworthiness label is lower than the preset trustworthiness label threshold or only the device health value does not reach the preset security level, it is marked as low-risk low-trustworthiness data; after filtering and marking, compliant data packets are obtained.

[0052] In this embodiment, as described in step S21 above, the core is to complete the verification of the digital signature of the standardized data packet and dynamically adjust the verification result level. The system uses the same asymmetric encryption algorithm (such as SHA-256+RSA algorithm) as when the standardized data packet was generated in step S10, calls the public key of the e-commerce server to decrypt the unique digital signature attached to the data packet, and obtains the corresponding hash digest; at the same time, it performs real-time hash calculation on the main content of the data packet (including multi-dimensional transaction data, device health values ​​and other core information) to generate a real-time hash digest; and compares the decrypted hash digest with the real-time calculated hash digest. The system performs a consistency comparison of the hash digests. If the two do not match, the digital signature validity verification fails, and the standardized data packet is directly removed without proceeding to any subsequent processing. If the two match completely, the digital signature validity verification passes. At this point, the system retrieves the IoT device health value associated with the data packet and compares it with the preset device health threshold (set based on the mall's data security requirements, such as a threshold of 6 points out of 10). If the device health value is below 6 points, the verification result is marked as pending review. If the device health value reaches or exceeds 6 points, the verification result level is maintained.

[0053] As described in step S22 above, its core is to complete the filtering of abnormal and invalid data. The processing objects are the standardized data packets that have passed the digital signature legality verification or are marked as pending review in step S21. The system verifies the multi-dimensional transaction data in the data packet item by item according to the preset abnormal data judgment rules. First, it filters out data that violates objective physical laws, such as negative weight values, or product categories that do not match the image features at all, which are abnormal data that do not have the validity of transaction data. Then, it verifies the temporal matching of cross-dimensional data and removes invalid data whose timestamp deviations of the data collected by each device exceed the preset threshold. In the data dimension integrity verification stage, if the data packet is missing core data dimensions such as RFID product category and product weight, the standardized data packet is directly removed. If only non-core data dimensions such as temperature and humidity are missing, the standardized data packet is retained, and the missing dimension information is clearly marked in the extended fields of the data packet.

[0054] As described in step S23 above, its core is to complete the low-reliability data risk level labeling and compliant data packet screening. The system retrieves the preset reliability label threshold and device health value security level standard, where the reliability label threshold is set to ≥0.7 and the device health value security level standard is set to ≥6 points (forming a one-to-one mapping relationship with the reliability label threshold). The standardized data packets filtered in step S22 are compared with the dual thresholds of the reliability label threshold and the device health value security level standard. When the reliability label of the data packet is lower than the preset reliability label threshold and the health value of its associated IoT device does not reach the preset security level, the data packet is marked as "high risk, low reliability". The system assigns risk levels to data packets. When a data packet's credibility tag is below a preset threshold, or its device health value fails to meet a preset security level, the data packet is marked as "low-risk, low-credibility data." When a data packet's credibility tag is greater than or equal to 0.7 and its device health value is greater than or equal to 6, the data packet is marked as "no-risk." After completing the risk level marking, the system filters out data packets that have passed digital signature verification (including data packets marked as "pending review" but passed the S22 filter), have no abnormal or invalid data, and have not been marked as "high-risk, low-credibility data," ultimately obtaining compliant data packets that meet the requirements of subsequent data fusion processing.

[0055] In one embodiment, step S30, the construction and training of the cross-modal intelligent mapping model, specifically includes the following steps:

[0056] S311. Construct a tamper-proof training dataset, which includes a positive sample set and a negative sample set. The positive sample set is untampered multidimensional transaction data, which includes at least RFID product feature data, product image feature data and weight feature data. The negative sample set is multidimensional transaction data containing tampering traces, which includes at least semantically contradictory samples, temporally disjointed samples and samples collected by high-risk devices.

[0057] S312. Construct a model architecture that includes an input layer, an anti-tampering weighted preprocessing layer, a semantic-temporal consistency verification layer, a cross-modal fusion layer, and an output layer connected in sequence. The anti-tampering weighted preprocessing layer has a built-in risk level-health value weighted factor mapping module, and the semantic-temporal consistency verification layer has a built-in product core information semantic matching rule base and temporal verification module.

[0058] S313. Design a composite loss function, which includes fusion accuracy loss and tampering feature penalty loss. The tampering feature penalty loss calculates a penalty value for three categories of sample features with preset weights: semantically contradictory sample features, temporally disjointed sample features, and high-risk device-collected sample features.

[0059] S314. Input the training dataset into the constructed model architecture, and iterate the training until the model converges with the goal of minimizing the composite loss function. During the training process, monitor the accuracy of the model in recognizing the tampered features of the negative sample set in real time. Stop training when the accuracy reaches the preset threshold to obtain the cross-modal intelligent mapping model.

[0060] In this embodiment, as described in step S311 above, a tamper-proof-oriented training dataset is constructed. This training dataset is designed to improve the model's ability to identify tampering behavior in transaction data and enhance its tamper-proof capabilities during data fusion. The constructed training dataset includes two categories: a positive sample set and a negative sample set. The positive sample set consists of pre-collected multi-dimensional transaction data without any tampering traces, including but not limited to RFID product category, origin, batch, and other product characteristic data; product appearance image characteristic data; and weight characteristic data collected by weight sensors. All types of data meet the requirements of semantic consistency and temporal synchronization. The negative sample set covers clearly defined... The multidimensional transaction data with tampering traces consists of a sample set containing at least three specific types of samples: first, semantically contradictory samples (i.e., product information represented by data from different dimensions conflicts with each other, such as the product category of RFID tags being inconsistent with the product category corresponding to image features); second, temporally disjointed samples (i.e., the timestamp deviation of cross-dimensional data exceeds the preset reasonable range and does not meet the requirements for synchronous collection); and third, samples collected by high-risk devices (i.e., transaction data collected by IoT devices with health values ​​lower than the preset security level). By combining the positive sample set and the negative sample set in a preset ratio (e.g., a 7:3 ratio), a training dataset covering various normal and abnormal scenarios is formed.

[0061] As described in step S312 above, its core is to build a customized cross-modal intelligent mapping model architecture adapted to the requirements of anti-tampering data fusion. This architecture integrates rule verification and deep learning fusion algorithms, specifically including an input layer, an anti-tampering weighted preprocessing layer, a semantic-temporal consistency verification layer, a cross-modal fusion layer, and an output layer connected in sequence. The input layer adopts a data tensor reshaping and normalization algorithm to receive multi-dimensional heterogeneous transaction data such as RFID product features, image features, and weight sensing features. Through normalization, data of different dimensions are mapped to the [0,1] region. The data is then restructured into a tensor format that can be processed by deep learning models, completing the data format standardization process. The tamper-proof weighted preprocessing layer incorporates a risk level-health value weighting factor mapping module. This module assigns differentiated weighting factors to data of different dimensions based on the health value and risk level of the associated IoT devices using a linear weighting formula. This enhances the feature weights of high-confidence data (high health value, low risk level) and weakens the interference from low-confidence data. The semantic-temporal consistency verification layer integrates a dual verification algorithm of rule base matching and lightweight feature similarity calculation. The system incorporates a built-in semantic matching rule base for core product information and a time-series verification module. The semantic matching rule base includes rules for the correspondence between product category and appearance features, weight and specifications, etc. It also utilizes lightweight convolutional neural networks (such as MobileNet) to extract semantic features from product images, and then compares the consistency between RFID category features and image semantic features using cosine similarity calculation. The time-series verification module employs an absolute value calculation algorithm for timestamp deviation to check the synchronization of timestamps across dimensions, eliminating data with deviations exceeding a preset threshold. The cross-modal fusion layer uses a cross-modal multi-head attention mechanism combined with a feature concatenation algorithm. It focuses on high-confidence, highly correlated data features through attention weight allocation, and then concatenates the attention-weighted features of each modality with the original features to achieve deep fusion of multimodal data, addressing the technical challenge of directly fusing heterogeneous data. The output layer uses a fully connected layer (FC layer) dimension mapping algorithm to map the deeply fused high-dimensional features to a preset low-dimensional feature space, outputting the integrated unified dimension fusion features, providing a standardized feature carrier for subsequent confidence weight calculations.

[0062] As described in step S313 above, its core is to design a composite loss function that balances fusion accuracy and anti-tampering detection capabilities. Through differentiated loss weights and targeted penalty mechanisms, it simultaneously enhances the model's data fusion effect and sensitivity to tampering feature detection. Specifically, the composite loss function consists of a fusion accuracy loss (… ) and tampering feature penalty loss ( The two parts are weighted according to preset weights, and the overall expression is: ;in, This is the weighting coefficient for the fusion accuracy loss (preset to 0.4, emphasizing the priority of anti-tampering identification). Among them, the fusion accuracy loss ( The loss function, calculated using the mean squared error (MSE), specifically measures the numerical deviation between the fused features output by the model and the true fused feature labels. This adapts to the quantitative evaluation needs of low-dimensional feature vectors after cross-modal fusion, ensuring the integrity and accuracy of the fused data; the feature tampering penalty loss... To address three types of tampering features in the negative sample set—semantic inconsistencies, temporal discrepancies, and samples collected from high-risk devices—a differentiated penalty logic is designed: First, the penalty weights for the three types of samples are preset to a ratio of 3:3:4 (samples collected from high-risk devices are given a higher penalty weight due to their higher tampering risk). Then, the penalty value for each type of sample is calculated using the cross-entropy loss function: tampering features that the model fails to identify (predicted probability below a preset threshold of 0.5) are given the full penalty value; tampering features that are accurately identified (predicted probability ≥ 0.5) are penalized with decreasing penalty values ​​based on the identification confidence level; and tampering samples that are misclassified as normal features are subject to an additional penalty coefficient. Through this triple mechanism of basic penalty + confidence adjustment + misclassification, the model is guided to focus on learning the differentiated performance of various tampering features, improving its sensitivity to identifying covert tampering behaviors. Finally, the composite loss function is obtained by summing the two parts of the loss according to preset weights, ensuring that the model optimizes fusion accuracy without weakening its core anti-tampering capabilities.

[0063] As described in step S314 above, its core is to complete the iterative training and convergence determination of the cross-modal intelligent mapping model. The training dataset constructed in step S311 is divided into a training set and a validation set according to a preset ratio of 8:2, and input into the model architecture constructed in step S312. With minimizing the composite loss function as the training objective, the Adam gradient descent algorithm is used for iterative training. During the training process, the accuracy of the model in identifying tampered features on the negative sample set on the validation set is monitored in real time. At the same time, the composite loss value of each iteration is recorded. When the composite loss value tends to be stable and there is no significant decrease for 10 consecutive rounds, and the accuracy of tampered feature identification reaches a preset threshold (such as 95%), the model training is determined to be converged, and iterative training is stopped. Finally, a cross-modal intelligent mapping model with multi-dimensional data association and fusion capabilities and tampered feature identification capabilities is obtained. This model can be directly used for the compliant data packet fusion processing in step S30.

[0064] In one embodiment, step S30 involves performing multi-dimensional data association on compliant data packets based on a pre-trained cross-modal intelligent mapping model to obtain fused data, specifically including the following steps:

[0065] S321. Input the compliance data package into the input layer of the cross-modal intelligent mapping model. Based on the risk label level of the compliance data package and the associated device health value, call the mapping module of the anti-tampering weighted preprocessing layer to match the differential weighting factor, and extract features and perform weighted processing on the data of each dimension of the compliance data package to output the weighted feature set; where the higher the risk level and the lower the device health value, the smaller the differential weighting factor of the corresponding dimension data.

[0066] S322. Input the weighted feature set into the semantic-temporal consistency verification layer. Verify the semantic consistency and temporal consistency of each dimension of the product features through the product core information semantic matching rule base and the temporal verification module. Perform multi-dimensional data association only on features that pass both semantic consistency and temporal consistency verification. Eliminate suspected tampered features that have semantic contradictions or temporal discrepancies, and output the associated feature set.

[0067] S323. Input the associated feature set into the cross-modal fusion layer, use the attention mechanism to assign weights to the features of each dimension and perform data fusion to obtain fused data and output it through the output layer; wherein, the output layer calculates the tampering risk confidence of the fused data synchronously based on the semantic consistency verification result and the time sequence consistency verification result and outputs it.

[0068] In this embodiment, as described in step S321 above, the compliant data packet filtered in step S20 is input into the input layer of the cross-modal intelligent mapping model. The model automatically associates the risk label level of the data packet with the risk label level as marked in S23: no risk, low risk and low confidence, and high risk and low confidence; and the corresponding IoT device health value (the calculation result of step S14). The risk level-health value weighting factor mapping module of the anti-tampering weighted preprocessing layer is called, and according to the rule that "the higher the risk level and the lower the device health value, the smaller the differential weighting factor of the corresponding dimension data", the exclusive weighting factor of each dimension data (RFID product features, image features, weight features, etc.) is matched. For example, no risk + device health value of 8 points (out of 10) matches a weighting factor of 0.9, low risk and low confidence + device health value of 5 points matches a weighting factor of 0.5, and high risk and low confidence + The equipment health value of 4 points is matched with a weighting factor of 0.2. At the same time, through the feature extraction submodule built into the model, core features are extracted from each dimension of the compliant data package (such as extracting structured features such as product category code and production batch from RFID data, extracting visual features such as product outline and color from image data, and extracting normalized numerical features from weight data). The extracted original features are then weighted with the corresponding differential weighting factor to finally output a weighted feature set that strengthens high-confidence features and weakens low-confidence features. For example, a risk-free data weighted feature set containing weighted product category code features (weight 0.9), product outline visual features (weight 0.9), and normalized weight features (weight 0.9) or a low-risk data weighted feature set containing product category code features (weight 0.5), image visual features (weight 0.5), and weight features (weight 0.5).

[0069] As described in step S322 above, the weighted feature set output in step S321 is input into the semantic-temporal consistency verification layer. This layer calls the built-in semantic matching rule library of product core information (including the corresponding relationship rules of product category-appearance features, weight-specifications, etc.) and compares the semantic consistency of features in different dimensions by calculating cosine similarity. At the same time, the temporal verification module is started, and the absolute value calculation algorithm of timestamp deviation is used to check the synchronization of the collection time of features in each dimension. Only features that pass the semantic consistency verification (similarity ≥ preset threshold 0.8) and the temporal consistency verification (deviation ≤ preset threshold 200ms) are retained. Suspicious features that have semantic contradictions or temporal discrepancies are directly removed. Then, through the feature association algorithm, the features of each dimension that have passed the double verification are semantically bound according to the product core information to form a structured associated feature set and output it.

[0070] As described in step S323 above, the associated feature set output in step S322 is input into the cross-modal fusion layer. This layer adopts a cross-modal multi-head attention mechanism to dynamically assign weights to the importance of associated features in each dimension, focusing on core features with high relevance and high credibility. Then, the attention-weighted features are concatenated and fused with the original associated features to generate fused data that has both completeness and relevance. Finally, the fused data is output through the output layer. At the same time, based on the semantic consistency verification results and time sequence consistency verification results mentioned above, the output layer calculates and outputs the tampering risk confidence of the fused data (with a value range of 0-1, the closer to 1, the lower the tampering risk) using a probabilistic statistical algorithm, based on the feature weighting coefficients. The core reason for calculating and outputting this tampering risk confidence is that although the cross-modal fusion process is based on compliant data packages, features of different dimensions may be affected by hidden factors during the concatenation and fusion process. Sexual association conflicts create new tampering risk points, while previous steps only marked the risks of the original data packets without quantifying the risks of the merged data. The effects are reflected in three aspects: First, it provides accurate quantitative basis for the subsequent calculation of the credibility weight of the merged data in step S30, so that the weight allocation no longer relies solely on the health value and risk level of the original devices, but combines the actual risk characteristics of the merged data, improving the scientific nature and accuracy of credibility assessment; second, it improves the closed-loop nature of the entire anti-tampering technology system, realizing full-process control from risk marking of the original data packets to risk quantification of the merged data, preventing the fusion process from becoming a vulnerability in anti-tampering; third, it provides clear risk decision-making references for subsequent data applications. If the confidence level is lower than a preset threshold (e.g., 0.7), it can automatically trigger manual review or data isolation mechanisms, further ensuring the security and reliability of IoT mall transaction data.

[0071] In one embodiment, step S30, the calculation method for the credibility weight of the fused data, specifically includes the following steps:

[0072] S331. Determine the core factors for weight calculation. The core factors include tamper risk confidence, equipment health value and risk labeling level coefficient. The risk labeling level coefficient is set according to high risk and low confidence, low risk and low confidence and no risk.

[0073] S332. Normalize the core factors, wherein the tampering risk confidence is normalized in reverse, and the higher the confidence, the lower the normalized value. The equipment health value is normalized according to the ratio of the actual score to the full score.

[0074] S333. Set the scenario-based weight ratio of each core factor according to the current trading scenario, and perform a weighted summation of the normalized core factors according to the scenario-based weight ratio to obtain the credibility weight of the fused data.

[0075] In this embodiment, as described in step S331 above, a triple assessment system of "post-fusion risk + device basic credibility + original data risk" is constructed to achieve a full-link, multi-dimensional, and comprehensive assessment of the credibility of fused data. This avoids the one-sidedness caused by single-factor assessment and ensures that the credibility weight can truly reflect the credibility level of the data throughout the entire process from the data collection source (device health value), the original state (risk label level), to the fusion result (confidence level of tampering risk). This provides scientific and reliable quantitative support for subsequent dynamic verification threshold setting and risk decision-making. Specifically, the core factors for weight calculation include three key indicators. The first factor is the tampering risk confidence level output in step S323 (values ​​range from 0 to 1, with a lower tampering risk as the value approaches 1), which directly reflects the real-time risk status of the fused data. The second factor is the IoT device health value calculated in step S14 (values ​​range from 0 to 10, with a perfect score representing the optimal device status), which reflects the basic credibility of the data collection source. The third factor is the risk labeling level coefficient, which is set with specific values ​​according to the risk labeling level in step S23: a coefficient of 0.3 for high risk and low credibility, a coefficient of 0.6 for low risk and low credibility, and a coefficient of 1.0 for no risk. The coefficient quantifies the basic risk level of the original data packet.

[0076] As described in step S332 above, by eliminating the dimensional differences between different factors, the additive nature of each indicator is ensured. This includes normalizing the three core factors separately and mapping them uniformly to the [0,1] interval. Specifically, the tampering risk confidence level is processed using reverse normalization, because this indicator is positively correlated with confidence (higher confidence level means higher confidence). Reverse normalization ensures that "high confidence corresponds to a low normalized value," maintaining consistency with the evaluation logic of other factors. This is specifically achieved through the formula... Perform calculations. The original tampering risk confidence level is set as follows: for example, a confidence level of 0.9 corresponds to a normalized value of 0.1, and a confidence level of 0.6 corresponds to a normalized value of 0.4. The equipment health value is directly normalized according to the ratio of "actual score / full score". For example, a health value of 8 points (full score of 10 points) corresponds to a normalized value of 0.8, and a health value of 5 points corresponds to a normalized value of 0.5. The risk labeling level coefficient is already in the range of [0,1] and does not require additional processing. The set value (0.3 / 0.6 / 1.0) is directly used as the normalization result.

[0077] As described in step S333 above, by dynamically allocating factor weights based on scenario requirements, the credibility is accurately quantified. According to different transaction scenarios in the IoT e-commerce platform, the preset scenario-based data weight allocation rules differentiate the weight percentages of three core factors: the normalized confidence value of tampering risk, the normalized value of device health, and the risk labeling level coefficient, ensuring that the weight allocation aligns with the scenario's risk focus. For example, in the fresh produce transaction scenario (sensitive to food safety risks caused by data tampering), the weight percentages are: 40% for the normalized confidence value of tampering risk, 30% for the normalized value of device health, and 30% for the risk labeling level coefficient. In the peak holiday transaction scenario (where high device load easily generates abnormal data), the weight percentages are: 30% for the normalized confidence value of tampering risk, 40% for the normalized value of device health, and 30% for the risk labeling level coefficient. A balanced weighting of 3:3:4 is set for the regular retail scenario. Then, the credibility weights are calculated using a weighted summation formula.

[0078]

[0079] in, The scenario-based weighting of each factor is given. , These are the original IoT device health value calculated in step S14 and the risk labeling level coefficient set in step S331, respectively. All are normalized factor values, and the final output credibility weight ranges from 0 to 1. The closer to 1, the higher the overall credibility level of the fused data, providing a quantitative basis for risk decisions in subsequent data applications.

[0080] In one embodiment, step S40 specifically includes the following steps:

[0081] S41. Extract real-time scene features based on fused feature vectors, wherein the real-time scene features include at least product attribute features, environmental perception features, and transaction scene features;

[0082] S42. Call the pre-built physical law knowledge base, which includes a commodity basic threshold library and a scene correction rule library. Input the real-time scene features into the physical law knowledge base and match them to obtain the commodity basic threshold corresponding to the commodity attribute features, as well as the scene correction rules and scene correction values ​​corresponding to the environmental perception features and transaction scene features.

[0083] S43. Based on the scenario correction rules, the basic threshold of the product and the scenario correction value are weighted and calculated to obtain the dynamic verification threshold.

[0084] In this embodiment, as described in step S41 above, based on the fused feature vector output in step S30, real-time scene features are extracted using feature filtering and dimension extraction algorithms (such as feature filtering algorithms based on variance thresholds, mutual information feature selection algorithms, principal component analysis (PCA) dimensionality reduction algorithms, etc.) to ensure that the feature dimensions fully cover the key influencing factors of the entire transaction process. The extracted real-time scene features include at least three types of core features: First, product attribute features (based on the extraction of core product information from the fused feature vector, such as product category, specifications, standard weight, preset price range, and other structured features, which are directly related to the RFID product features and weight features in step S321); Second, environmental perception features (related to environmental data collected by IoT devices and device operating status, such as the current load rate of the device, temperature and humidity of the collection environment, data transmission signal strength, etc., echoing the device health value assessment dimension in step S14); Third, transaction scene features (representing the scene attributes of the current transaction, such as transaction time (weekdays / holidays), scene type (regular retail / fresh food zone / promotional activities), transaction flow (peak / off-peak) etc.), and finally outputting a structured set of real-time scene features.

[0085] As described in step S42 above, a pre-built physical law knowledge base is invoked. This knowledge base is constructed by integrating historical compliant transaction data, industry commodity standards, physical common sense, and equipment operation specifications, and supports dynamic updates. The commodity basic threshold library stores the benchmark judgment ranges corresponding to different commodity attributes, such as the standard weight threshold [495g-505g] for a certain brand of 500ml mineral water and the reasonable price range threshold [199 yuan-299 yuan] for a certain category of clothing, corresponding one-to-one with commodity attribute characteristics. The scenario correction rule library contains the mapping relationship between environment, transaction scenario, and correction logic, such as "Equipment load rate > 80% → increased data deviation risk → weight threshold..." Rules such as "Value correction value +3g" and "Promotional activity scenario → reasonable price fluctuation → price range correction coefficient 1.2" are used. Through feature keyword matching algorithms (such as TF-IDF weighted matching algorithm), the real-time scene features extracted in step S41 are matched with the rules / thresholds in the knowledge base, and the basic threshold of the product corresponding to the product attribute features (such as [495g-505g]) and the scene correction rules (such as "weight threshold correction value +3g" and "price range correction coefficient 1.2") and scene correction values ​​(such as +3g ​​and 1.2) corresponding to environmental perception features (such as device load rate 85%) and transaction scene features (such as promotional scene) are output.

[0086] As described in step S43 above, the scenario correction rule matched in step S42 is used as the calculation basis. The weighted calculation logic corresponding to the rule is adopted to integrate the basic threshold of the product and the scenario correction value. If the correction rule is a "threshold offset type" (such as weight or quantity threshold), it is calculated according to "dynamic verification threshold = basic threshold of product ± scenario correction value". For example, the standard weight threshold of mineral water [495g-505g] + the high load correction value of equipment + 3g, resulting in a dynamic verification threshold [492g-508g]. If the correction rule is a "coefficient scaling type" (such as price or timeliness threshold), it is calculated according to "dynamic verification threshold = basic threshold of product × scenario correction coefficient". For example, the price range of clothing [199 yuan-299 yuan] × the promotional scenario correction coefficient 1.2, resulting in a dynamic verification threshold [238.8 yuan-358.8 yuan]. Finally, a dynamic verification threshold adapted to the real-time transaction scenario is output. This threshold will serve as the core judgment standard for the dual verification in step S50 to ensure the scenario adaptability and accuracy of risk judgment.

[0087] In one embodiment, an IoT-based e-commerce transaction data anti-tampering system is provided, which corresponds to the IoT-based e-commerce transaction data anti-tampering method described in the above embodiments. The IoT-based e-commerce transaction data anti-tampering system includes:

[0088] The data processing module is used to synchronously collect multi-dimensional transaction data through IoT devices and calculate the device health value of IoT devices when a transaction is triggered. It integrates the multi-dimensional transaction data and device health value according to preset data trustworthiness encapsulation rules to obtain a standardized data packet with digital signature and trustworthiness label.

[0089] The data filtering module is used to perform digital signature verification, abnormal data filtering, and low-confidence data marking on the standardized data packets to obtain compliant data packets.

[0090] The first calculation module is used to perform multi-dimensional data association on compliant data packets based on a pre-trained cross-modal intelligent mapping model to obtain fused data; and to calculate the credibility weight of the fused data and output the fused feature vector by combining the device health value and the preset data weight.

[0091] The second calculation module is used to extract real-time scene features based on the fused feature vector, call the pre-built physical law knowledge base, and calculate and integrate the basic threshold of the commodity and the scene correction value with the real-time scene features as input to obtain the dynamic verification threshold.

[0092] The verification module is used to perform dual verification of numerical consistency and semantic relevance on the fused feature vector based on the dynamic verification threshold. If either verification fails, it is marked as suspected tampering and the transaction is intercepted.

[0093] For specific limitations regarding the IoT-based e-commerce transaction data anti-tampering system, please refer to the limitations of the IoT-based e-commerce transaction data anti-tampering method described above, which will not be repeated here. The various modules in the aforementioned IoT-based e-commerce transaction data anti-tampering system can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in or independent of the processor in a computer device, or stored in the memory of a computer device as software, so that the processor can call and execute the corresponding operations of each module.

[0094] In one embodiment, a computer device is provided, which may be a server, and its internal structure diagram may be as follows. Figure 2 As shown, the computer device includes a processor, memory, network interface, and database connected via a system bus. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system, computer programs, and database. The internal memory provides the environment for the operation of the operating system and computer programs stored in the non-volatile storage media. The database is used for data storage, data processing, and data analysis. The network interface is used for communication with external terminals via a network connection. When the computer program is executed by the processor, it implements a method for preventing tampering of transaction data in an online marketplace based on the Internet of Things (IoT).

[0095] In one embodiment, a computer device is provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements a method for preventing tampering of e-commerce transaction data based on the Internet of Things.

[0096] In one embodiment, a computer-readable storage medium is provided having a computer program stored thereon, which, when executed by a processor, implements a method for preventing tampering of e-commerce transaction data based on the Internet of Things.

[0097] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium. When executed, the computer program can include the processes of the embodiments of the above methods. Any references to memory, storage, databases, or other media used in the embodiments provided in this application can include non-volatile and / or volatile memory. Non-volatile memory may include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory may include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in a variety of forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), dual data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), RAMbus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM), etc.

[0098] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the above-described division of functional units and modules is used as an example. In practical applications, the above functions can be assigned to different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above.

[0099] The above-described embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application, and should all be included within the protection scope of this application.

Claims

1. A method for preventing tampering of e-commerce transaction data based on the Internet of Things, characterized in that, Includes the following steps: When a transaction is triggered, multi-dimensional transaction data is collected synchronously through IoT devices and the device health value of the IoT devices is calculated. The multi-dimensional transaction data and device health value are integrated according to the preset data trustworthiness encapsulation rules to obtain a standardized data packet with digital signature and trustworthiness label. The standardized data packets are subjected to digital signature verification, abnormal data filtering, and low-confidence data marking to obtain compliant data packets. Based on a pre-trained cross-modal intelligent mapping model, multi-dimensional data association is performed on compliant data packets to obtain fused data; combined with device health values ​​and preset data weights, the credibility weight of the fused data is calculated and the fused feature vector is output. Based on the fused feature vector, real-time scene features are extracted. A pre-built physical law knowledge base is invoked. Using the real-time scene features as input, the basic threshold for the product and the scene correction value are calculated and integrated to obtain the dynamic verification threshold. Specifically, the steps are as follows: Real-time scene features are extracted based on fused feature vectors, and the real-time scene features include at least product attribute features, environmental perception features, and transaction scene features. The pre-built physical law knowledge base is invoked. The physical law knowledge base includes a commodity basic threshold library and a scene correction rule library. Real-time scene features are input into the physical law knowledge base to match and obtain the commodity basic threshold corresponding to the commodity attribute features, as well as the scene correction rules and scene correction values ​​corresponding to the environmental perception features and transaction scene features. Based on the scenario correction rules, the basic threshold of the product and the scenario correction value are weighted and calculated to obtain the dynamic verification threshold; The fused feature vector is subjected to dual verification of numerical consistency and semantic relevance based on the dynamic verification threshold. If either verification fails, it is marked as suspected tampering and the transaction is intercepted.

2. The method for preventing tampering of e-commerce transaction data based on the Internet of Things as described in claim 1, characterized in that, The calculation of the device health value of the IoT device specifically includes the following steps: When a transaction is triggered, the operating parameters of the IoT device during the multi-dimensional transaction data collection window are obtained. The operating parameters are judged to be qualified according to the preset parameter threshold, and the device operating status score is calculated. The collection window period starts from the time the collection command is issued and ends when the IoT device completes the collection of this multi-dimensional transaction data and transmits it to the data integration and packaging stage. The operating parameters include at least the concurrent collection response time and the data transmission packet loss rate. Verify the data dimension integrity of the multidimensional transaction data and the temporal matching of cross-dimensional data, and calculate the data collection quality score based on the verification results; Retrieve the anti-tampering verification results corresponding to the historical data collected by IoT devices, calculate the suspected tampering rate of the historical data, and calculate the historical verification correlation score based on the suspected tampering rate. Based on the current transaction scenario, dynamic weighting ratios are set for the device operation status score, data collection quality score, and historical verification correlation score. The three scores are then comprehensively weighted and calculated based on these dynamic weighting ratios to obtain the device health value. Among these weighting ratios, the weighting ratio for improving the data collection quality score is increased in commodity transaction scenarios that are sensitive to data collection quality, while the weighting ratio for improving the device operation status score is increased during peak transaction periods.

3. The method for preventing tampering of e-commerce transaction data based on the Internet of Things as described in claim 1, characterized in that, The steps of verifying the digital signature validity of the standardized data packets, filtering abnormal data, and marking low-confidence data to obtain compliant data packets specifically include the following steps: The standardized data packets are digitally signed for legality verification. If the verification fails, the data packets are directly removed. If the verification passes, the verification result level is adjusted based on the device health value associated with the standardized data packets. When the device health value is lower than a preset health threshold, the verification result is marked as pending review. For standardized data packets that have passed the digital signature validity verification or are marked as pending review, filter out abnormal data that violates objective physical laws and lacks the validity of transaction data, as well as invalid data with mismatched time series across dimensions; among them, standardized data packets are directly removed when core data dimensions are missing, while standardized data packets are retained and marked as missing dimensions when non-core data dimensions are missing. Based on a preset trustworthiness label threshold, the filtered standardized data packets are marked as low-trustworthiness data: when the trustworthiness label of a standardized data packet is lower than the preset trustworthiness label threshold and the associated device health value does not reach the preset security level, it is marked as high-risk low-trustworthiness data; when only the trustworthiness label is lower than the preset trustworthiness label threshold or only the device health value does not reach the preset security level, it is marked as low-risk low-trustworthiness data; after filtering and marking, compliant data packets are obtained.

4. The method for preventing tampering of e-commerce transaction data based on the Internet of Things as described in claim 1, characterized in that, The construction and training of the cross-modal intelligent mapping model specifically includes the following steps: Construct a tamper-proof training dataset, which includes a positive sample set and a negative sample set. The positive sample set consists of untampered multidimensional transaction data, which includes at least RFID product feature data, product image feature data, and weight feature data. The negative sample set consists of multidimensional transaction data containing tampering traces, which includes at least semantically contradictory samples, temporally disjointed samples, and samples collected by high-risk devices. The model architecture consists of an input layer, a tamper-proof weighted preprocessing layer, a semantic-temporal consistency verification layer, a cross-modal fusion layer, and an output layer connected in sequence. The tamper-proof weighted preprocessing layer has a built-in risk level-health value weighted factor mapping module, and the semantic-temporal consistency verification layer has a built-in semantic matching rule base and temporal verification module for product core information. Design a composite loss function, which includes fusion accuracy loss and tampering feature penalty loss. The tampering feature penalty loss calculates a penalty value for three categories of sample features: semantically contradictory sample features, temporally disjointed sample features, and sample features collected by high-risk devices, according to a preset weight. The training dataset is input into the constructed model architecture, and the model is iteratively trained with the goal of minimizing the composite loss function until the model converges. During the training process, the accuracy of the model in identifying tampered features of the negative sample set is monitored in real time. When the accuracy reaches a preset threshold, the training is stopped, and a cross-modal intelligent mapping model is obtained.

5. The method for preventing tampering of e-commerce transaction data based on the Internet of Things as described in claim 4, characterized in that, The step of performing multi-dimensional data association on compliant data packets to obtain fused data based on the pre-trained cross-modal intelligent mapping model specifically includes the following steps: The compliance data package is input into the input layer of the cross-modal intelligent mapping model. Based on the risk label level of the compliance data package and the associated device health value, the mapping module of the anti-tampering weighted preprocessing layer is called to match the differential weighting factor. Features are extracted and weighted for each dimension of the compliance data package, and a weighted feature set is output. The higher the risk level and the lower the device health value, the smaller the differential weighting factor of the corresponding dimension data. The weighted feature set is input into the semantic-temporal consistency verification layer. The semantic consistency and temporal consistency of the product features in each dimension are verified by the semantic matching rule base of the product core information and the temporal verification module. Multi-dimensional data association is performed only on features that pass both semantic consistency and temporal consistency verification. Suspicious tampered features with semantic contradictions or temporal discrepancies are removed, and the associated feature set is output. The associated feature set is input into the cross-modal fusion layer. The attention mechanism is used to assign weights to the features of each dimension and perform data fusion to obtain fused data, which is then output through the output layer. The output layer calculates the tampering risk confidence of the fused data synchronously based on the semantic consistency verification result and the time sequence consistency verification result, and outputs it.

6. The method for preventing tampering of e-commerce transaction data based on the Internet of Things as described in claim 5, characterized in that, The calculation method for the credibility weight of the fused data specifically includes the following steps: The core factors for weight calculation are determined, including the tamper risk confidence level, equipment health value, and risk labeling level coefficient. The risk labeling level coefficient is set according to high risk and low confidence level, low risk and low confidence level, and no risk level. The core factors are normalized, wherein the tampering risk confidence is reversed and normalized, with higher confidence being lower normalized values. The equipment health value is normalized according to the ratio of the actual score to the full score. Based on the current trading scenario, the scenario-based weight ratio of each core factor is set, and the normalized core factors are weighted and summed according to the scenario-based weight ratio to obtain the credibility weight of the fused data.

7. An IoT-based system for preventing tampering with transaction data in an online marketplace, used to implement the steps of the IoT-based method for preventing tampering with transaction data in an online marketplace as described in any one of claims 1-6, characterized in that, include: The data processing module is used to synchronously collect multi-dimensional transaction data through IoT devices and calculate the device health value of IoT devices when a transaction is triggered. It integrates the multi-dimensional transaction data and device health value according to preset data trustworthiness encapsulation rules to obtain a standardized data packet with digital signature and trustworthiness label. The data filtering module is used to perform digital signature verification, abnormal data filtering, and low-confidence data marking on the standardized data packets to obtain compliant data packets. The first calculation module is used to perform multi-dimensional data association on compliant data packets based on a pre-trained cross-modal intelligent mapping model to obtain fused data; and to calculate the credibility weight of the fused data and output the fused feature vector by combining the device health value and the preset data weight. The second calculation module is used to extract real-time scene features based on the fused feature vector, call the pre-built physical law knowledge base, and calculate and integrate the basic threshold of the commodity and the scene correction value with the real-time scene features as input to obtain the dynamic verification threshold. The verification module is used to perform dual verification of numerical consistency and semantic relevance on the fused feature vector based on the dynamic verification threshold. If either verification fails, it is marked as suspected tampering and the transaction is intercepted.

8. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the steps of the method for preventing tampering of e-commerce transaction data based on the Internet of Things as described in any one of claims 1-6.

9. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by the processor, it implements the steps of the method for preventing tampering of e-commerce transaction data based on the Internet of Things as described in any one of claims 1-6.

Citation Information

Patent Citations

  • Electronic commerce transaction verification system based on block chain

    CN119963200A

  • Multi-source data fusion method and system based on cloud computing

    CN119989267A