Risk identification method and device, equipment, storage medium and program product
By classifying, labeling, and scoring ATM transaction data, and combining real-time stream processing and supervised learning, structured feature vectors are generated. This solves the problems of high misjudgment rate and insufficient flexibility in risk identification in ATM business, and achieves accurate risk identification and intervention.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-25
- Publication Date
- 2026-03-13
AI Technical Summary
In existing technologies, risk identification for offline cash withdrawal services such as ATMs relies on transaction amount or frequency, which has a high false positive rate. Furthermore, manual due diligence is inefficient, costly, and lacks flexibility, making it difficult to cope with complex risk scenarios.
By classifying and labeling transaction data to generate structured feature vectors, calculating risk scores, and triggering corresponding risk response strategies based on the scores, the system utilizes a real-time stream processing framework and sliding window mechanism for real-time updates. Combined with supervised learning algorithms and scenario parameters, the scoring parameter table is adjusted to identify abnormal transaction behaviors.
It improved the accuracy and flexibility of risk identification, reduced the false judgment rate, achieved precise identification and intervention, and reduced losses caused by sudden abnormal transactions.
Smart Images

Figure CN121660690A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of financial technology, and in particular to a risk identification method, apparatus, device, storage medium, and program product. Background Technology
[0002] With the widespread adoption of mobile payments and e-banking, offline cash withdrawal services such as Automated Teller Machines (ATMs) still play an important role in financial scenarios, especially for large cash withdrawals.
[0003] Among related technologies, identifying risks caused by abnormal transaction behavior relies on transaction amount or frequency, or on manual due diligence, which has problems such as a high rate of misjudgment. Summary of the Invention
[0004] This application provides a risk identification method, apparatus, device, storage medium, and program product to improve the accuracy of risk identification.
[0005] In a first aspect, this application provides a risk identification method, comprising: classifying and labeling transaction data according to preset rules to generate a structured feature vector, wherein the structured feature vector includes multiple features such as: transaction time, transaction amount, transaction location, transaction frequency, and transaction channel; calculating a risk score based on the structured feature vector; and triggering a corresponding risk response strategy based on the risk score.
[0006] In one possible embodiment, calculating a risk score based on a structured feature vector includes: assigning initial score values to multiple features of the structured feature vector according to a scoring parameter table determined based on historical transaction data; and weighting and summing the initial score values with the feature label values of the structured feature vector to generate a risk score.
[0007] In one possible embodiment, before assigning initial scores to multiple features of a structured feature vector according to a scoring parameter table, the risk identification method further includes: updating the scoring parameter table using a supervised learning algorithm based on the structured feature vectors of historical transaction data; and / or updating the scoring parameter table according to the frequency of occurrence of novel risk patterns.
[0008] In one possible embodiment, before assigning initial score values to multiple features of the structured feature vector according to the scoring parameter table, the risk identification method further includes: adjusting and updating the scoring parameter table according to scenario parameters, including: the distribution of transaction frequency characteristics in different time periods.
[0009] In one possible embodiment, after calculating the risk score, the risk identification method further includes: finding behavioral baseline data for the same account based on transaction data, wherein the behavioral baseline data is obtained by analyzing the transaction behavior patterns of the historical transaction data of the same account; comparing the transaction data with the behavioral baseline data to generate a transaction difference score; and adjusting and updating the risk score based on the transaction difference score.
[0010] In one possible embodiment, after classifying and labeling transaction data according to preset rules, the risk identification method further includes: updating the structured feature vector through a real-time stream processing framework; the update includes: updating the feature label values of the structured feature vector of continuous transaction data in real time based on a sliding window mechanism.
[0011] In one possible embodiment, triggering a corresponding risk response strategy based on a risk score includes: matching a risk response strategy based on the score range of the risk score, wherein the risk response strategy includes at least one of the following: log recording, SMS reminder, intelligent outbound calling, manual outbound calling, and manual review.
[0012] In one possible embodiment, after matching the risk response strategy according to the score range of the risk score, the risk identification method further includes: adjusting and updating the risk response strategy according to the customer authentication result and the strength of the risk response strategy, wherein the customer authentication result includes at least one of the following: face recognition pass rate, SMS verification code verification result.
[0013] Secondly, this application provides a risk identification device, comprising: a structured feature vector generation module, used to classify and label transaction data according to preset rules to generate a structured feature vector, wherein the structured feature vector includes multiple features including: transaction time, transaction amount, transaction location, transaction frequency, and transaction channel; a risk score calculation module, used to calculate a risk score based on the structured feature vector; and a risk response module, used to trigger a corresponding risk response strategy based on the risk score.
[0014] Thirdly, this application provides an electronic device, including: a processor and a memory communicatively connected to the processor; the memory stores computer-executable instructions; the processor executes the computer-executable instructions stored in the memory to implement the method as described in any of the first aspects.
[0015] Fourthly, this application provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, are used to implement the method as described in any of the first aspects.
[0016] Fifthly, this application provides a computer program product, including a computer program that, when executed by a processor, implements the method of any one of the first aspects.
[0017] In this embodiment, by classifying and labeling transaction data, the generated structured feature vectors can map multiple features of the transaction data and quantify the degree of anomaly of each feature, thus comprehensively reflecting the risk of the transaction data. Risk scores calculated using structured feature vectors are more accurate and can reduce the risk misjudgment rate. By triggering corresponding risk response strategies based on the risk scores, accurate risk identification and intervention can be achieved, reducing losses caused by risks. Attached Figure Description
[0018] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.
[0019] Figure 1 A schematic diagram illustrating a scenario in which the risk identification method of this application is applied;
[0020] Figure 2 This is a flowchart of the risk identification method according to an embodiment of this application;
[0021] Figure 3 This is a flowchart of a risk identification method according to another embodiment of this application;
[0022] Figure 4 This is a schematic diagram of the risk identification device provided in the embodiments of this application;
[0023] Figure 5 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application.
[0024] The accompanying drawings illustrate specific embodiments of this application, which will be described in more detail below. These drawings and descriptions are not intended to limit the scope of the concept in any way, but rather to illustrate the concept of this application to those skilled in the art through reference to particular embodiments. Detailed Implementation
[0025] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.
[0026] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, storage, use, processing, transmission, provision, disclosure, and application of the relevant data all comply with the relevant laws, regulations, and standards of the relevant countries and regions, have taken necessary confidentiality measures, do not violate public order and good morals, and provide corresponding operation access points for users to choose to authorize or refuse.
[0027] Furthermore, the technical solution involved in this application, which involves big data analysis of user information (including but not limited to personal biometrics, identity data, consumption data, asset data, electronic terminal operation data, etc.) and the use of artificial intelligence technology for automated decision-making, and makes decisions that have a significant impact on personal rights based on the results of automated decision-making, provides users with corresponding operation entry points for users to choose to agree to or reject the results of automated decision-making; if the user chooses to reject, the process will proceed to the expert decision-making process.
[0028] It should be noted that the risk identification methods, devices, equipment, storage media, and program products provided in this application can be used in the field of financial technology, or in any field other than financial technology. The application fields of the risk identification methods, devices, equipment, storage media, and program products in this application are not limited.
[0029] Figure 1 This is a schematic diagram illustrating a scenario where the risk identification method of this application is applied. For example... Figure 1 As shown, in a financial scenario, customer 1 carries smart card 2 and inserts it into an automated teller machine (ATM) 3 to perform a transaction, generating transaction data. The transaction data is then sent from the ATM to the financial institution's server 4. Server 4 can receive the transaction data and execute the risk identification method of this embodiment.
[0030] In related technology 1, facial recognition technology is used for liveness detection (such as requiring customers to blink or nod), combined with multiple verifications such as phone numbers and passwords, to reduce the risk of identity theft. However, this type of solution can only verify the authenticity of the customer's identity and cannot identify abnormal features of the transaction data itself, and it is not suitable for identifying risks other than identity theft.
[0031] In related technology 2, risk identification is conducted through manual due diligence, such as having customer service personnel or branch employees inquire about the customer's transaction purpose. This method suffers from problems such as low efficiency, high cost, and susceptibility to subjective judgment.
[0032] In related technology 3, fixed rules (such as daily withdrawal limits) are used for risk identification. For example, when a single withdrawal reaches the daily limit, a risk warning SMS is sent to the customer. This method lacks flexibility, struggles to handle complex risk scenarios, and suffers from low accuracy in risk identification.
[0033] The risk identification methods, apparatus, devices, storage media, and program products provided in this application are intended to at least solve one of the above-mentioned technical problems in the related art.
[0034] The technical solution of this application and how the technical solution of this application solves the above-mentioned technical problems are described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments. The embodiments of this application will now be described with reference to the accompanying drawings.
[0035] Figure 2 This is a flowchart illustrating a risk identification method according to an embodiment of this application. The risk identification method of this application embodiment can be executed by an electronic device, specifically by a server.
[0036] like Figure 2 As shown, the risk identification method of this application embodiment includes steps S110 to S130.
[0037] S110. Classify and label the transaction data according to preset rules to generate structured feature vectors.
[0038] The structured feature vector contains several of the following features: transaction time, transaction amount, transaction location, transaction frequency, and transaction channel.
[0039] Transaction data refers to the original transaction information. The following will use ATM cash withdrawal as an example to illustrate this. Transaction data includes transaction time, transaction amount, transaction location, etc.
[0040] Classification and labeling refers to mapping transaction data into binary labels (0 or 1) according to preset rules, which is used to quantify the degree of feature anomalies.
[0041] For example, regarding transaction time: if a single transaction occurs within the first time range (e.g., 24:00-4:00), the first label TXN_TIME, indicating whether the single transaction time is abnormal, is set to 1; if multiple transactions occur within the first time range, the second label TXN_TIME_N, indicating whether the multiple transaction times are abnormal, is set to 1.
[0042] Regarding transaction amounts: If the amount of a single transaction reaches the daily limit, the third tag TXN_AMT, which indicates whether the single transaction amount is abnormal, will be set to 1; if the balance after the transaction is greater than the preset balance threshold, the fourth tag TXN_BALANCE, which indicates whether the balance after the transaction is abnormal, will be set to 1.
[0043] Regarding transaction locations: If multiple transactions occur at different financial outlets within a second time frame (e.g., one day), the fifth label TXN_BRANCHCODE, indicating whether the transaction outlet is abnormal, will be set to 1; if multiple transactions occur at locations outside a preset geographical range within a third time frame (e.g., one day), the sixth label TXN_ZONE, indicating whether the transaction geographical location is abnormal, will be set to 1.
[0044] Regarding trading frequency: If there are multiple consecutive trades on the same day, the seventh label TXN_NUM, indicating whether the number of trades on that day is abnormal, is set to 1; if there are consecutive trades over multiple days, the eighth label TXN_DAY, indicating whether the number of trades over multiple days is abnormal, is set to 1; if consecutive trades over multiple days all reach the daily limit, the ninth label TXN_MAX_DAY, indicating whether the trading volume over multiple days is abnormal, is set to 1.
[0045] Regarding transaction channels: If a customer makes multiple offline cash transactions through an ATM, but is between 20 and 30 years old (customers in this age group tend to prefer online transactions), then the tenth label, TRADING_CHANNEL, indicating whether the transaction channel is abnormal, should be set to 1.
[0046] Among the aforementioned features, the values of the first to tenth labels can be understood as the label values of the feature tags, with 1 indicating anomaly and 0 indicating normality. A structured feature vector refers to a data structure that integrates the feature label values of multiple features into a unified format. For example, the integrated values of the first to tenth labels form a structured feature vector.
[0047] S120. Calculate the risk score based on the structured feature vector.
[0048] Risk score refers to a numerical value that quantifies the risk of trading data.
[0049] S130. Trigger the corresponding risk response strategy based on the risk score.
[0050] Risk response strategies refer to intervention measures based on risk scores.
[0051] In this embodiment, by classifying and labeling transaction data, the generated structured feature vectors can map multiple features of the transaction data and quantify the degree of anomaly of each feature, thus comprehensively reflecting the risk of the transaction data. Risk scores calculated using structured feature vectors are more accurate and can reduce the risk misjudgment rate. By triggering corresponding risk response strategies based on the risk scores, accurate risk identification and intervention can be achieved, reducing losses caused by risks.
[0052] Figure 3 This is a flowchart illustrating a risk identification method according to another embodiment of this application. Figure 3 As shown, in one possible embodiment, after classifying and labeling the transaction data according to preset rules in step S110, the risk identification method further includes step S111.
[0053] S111. The structured feature vector is updated using a real-time stream processing framework.
[0054] Real-time stream processing framework: A computing framework that supports real-time data processing.
[0055] The update includes: real-time calculation of feature label values for continuous transaction data based on a sliding window mechanism and updating the structured feature vector.
[0056] The sliding window mechanism refers to calculating feature label values using a fixed time window (e.g., 1 hour). Specifically, based on the sliding window, transaction data is acquired immediately when a transaction occurs, and feature label values are calculated based on this transaction data, rather than batch processing historical transaction data.
[0057] Some abnormal transactions are sudden, multiple transactions within a short period. To address this, this embodiment employs a combination of a real-time stream processing framework and a sliding window mechanism to handle sudden abnormal transactions and improve the lag in risk identification. For example, related technologies may miss new risk behaviors (such as sudden high-frequency cross-regional cash withdrawals) due to delayed analysis. However, this embodiment uses a real-time stream processing framework to capture transaction data instantly and calculate feature label values in real time to extract and update structured feature vectors, thereby identifying potential risks earlier. This reduces the risk of financial loss caused by sudden abnormal transaction behavior while avoiding unintended disruptions to normal transactions.
[0058] like Figure 3 As shown, in one possible embodiment, step S120, which calculates the risk score based on the structured feature vector, includes steps S121 to S122.
[0059] S121. Assign initial score values to multiple features of the structured feature vector according to the scoring parameter table.
[0060] The scoring parameter table is determined based on historical transaction data. For example, analysis of historical transaction data may reveal that among the various features of the structured feature vector, transaction amount, transaction frequency, and transaction location contribute more to risk identification, thus allowing for setting higher initial scores for these three factors.
[0061] S122. The initial score value is weighted and summed with the corresponding feature label value of the structured feature vector to generate a risk score.
[0062] Weighted summation refers to multiplying each feature label value of the structured feature vector by its corresponding initial score value and then summing the results to generate a risk score.
[0063] For example, in the structured feature vector, the feature label value indicating abnormal trading time is 1, and the initial score for trading time is 10 points; the feature label value indicating abnormal trading location is 1, and the initial score for abnormal trading location is 20 points. By weighted summation, the risk score can be determined to be 30 points.
[0064] Following the example above, regarding transaction time: if a single transaction occurs within a certain time range (e.g., 24:00-4:00), the first label TXN_TIME, indicating whether the single transaction time is abnormal, is set to 1; if multiple transactions occur within the same time range, the second label TXN_TIME_N, indicating whether the multiple transactions are abnormal, is set to 1. That is, transaction time includes both single and multiple transaction times, and the initial scores for both single and multiple transaction times are still preset using the scoring parameter table. In this case, the feature label values for both single and multiple transaction times are multiplied by their respective initial scores and then summed.
[0065] The weighted summation method for transaction amount, transaction location, transaction frequency, and transaction channel is similar to that for transaction time, and will not be repeated here.
[0066] In this embodiment, a scoring parameter table determined from historical transaction data is used as the basis for assigning initial scoring values to multiple features of the structured feature vector. This allows for accurate assignment of initial scoring values based on historical experience reflected in the historical transaction data. By weighted summing of the initial scoring values and the corresponding feature label values of the structured feature vector, the generated risk score comprehensively considers the impact of each feature on risk identification, making risk assessment more accurate. In other words, this embodiment offers higher accuracy in risk identification.
[0067] In the above embodiments, the scoring parameter table determined by historical transaction data is used as the basis for assigning initial scoring values to multiple features of the structured feature vector, and the initial scoring values can be accurately assigned based on the historical experience reflected in the historical transaction data.
[0068] like Figure 3 As shown, in one possible embodiment, the scoring parameter table may support adjustment and updating, for example.
[0069] Specifically, before assigning initial score values to multiple features of the structured feature vector according to the scoring parameter table in step S120, the risk assessment method further includes: updating the scoring parameter table using a supervised learning algorithm based on the structured feature vector of historical transaction data; and / or updating the scoring parameter table according to the frequency of occurrence of new risk patterns.
[0070] Supervised learning algorithms are machine learning algorithms that learn a rating parameter table using training data and labels. Specifically, they learn the initial rating value corresponding to each feature in the rating parameter table. Examples of supervised learning algorithms include logistic regression models and decision tree models. Supervised learning algorithms can uncover implicit relationships between features in a structured feature vector. Updating the rating parameter table using supervised learning algorithms results in a more accurate risk identification system.
[0071] For example, a server collects historical transaction data, extracts structured feature vectors from the historical transaction data, adds an initial score value label to each feature of the structured feature vector, and inputs the structured feature vector with the initial score value label as training samples into a supervised learning algorithm. The supervised learning algorithm outputs the predicted initial score value. The parameters of the supervised learning algorithm are adjusted based on the difference between the predicted initial score value and the initial score value of the training sample, until the difference between the predicted initial score value and the initial score value of the training sample converges. At this point, the supervised learning algorithm is trained, and the initial score value for each feature can be obtained through this supervised learning algorithm, i.e., a score parameter table. This score parameter table is used to update the original score parameter table, which allows for accurate assignment of initial score values based on historical experience such as the implicit correlations between the features of the structured feature vector learned by the supervised learning algorithm.
[0072] New risk patterns refer to risk characteristics that are not prominent in historical transaction data but appear frequently now. For example, a new type of risk pattern is "high-frequency, small-amount interbank cash withdrawals," which was not marked as a risk in historical transaction data but appears frequently now.
[0073] In this embodiment, the scoring parameter table is dynamically optimized through supervised learning algorithms or novel risk pattern analysis, which enhances the flexibility of risk assessment and its adaptability to new risk patterns. For example, by training a logistic regression model using historical transaction data and discovering a strong correlation between "abnormal transaction frequency" and risk, the scoring parameter table can be adjusted so that the initial score for transaction frequency is increased from 20 to 30. Furthermore, when a new risk pattern (such as high-frequency, small-amount interbank cash withdrawals) emerges, the server can adjust the scoring parameter table according to its frequency of occurrence, increasing the initial score for the relevant features and ensuring that the scoring parameter table aligns with the actual risk pattern.
[0074] Unlike the above-mentioned adjustment of the scoring parameter table based on supervised learning algorithms or novel risk patterns, in another possible embodiment, before assigning initial score values to multiple features of the structured feature vector according to the scoring parameter table in step S120, the risk assessment method further includes: adjusting and updating the scoring parameter table according to the scenario parameters.
[0075] The scenario parameters include: the distribution of transaction frequency characteristics in different time periods.
[0076] For example, trading frequency increases during holidays; in this case, the scoring parameter table can be adjusted to lower the initial score for trading frequency and avoid misjudgment of risk. Trading frequency decreases on weekdays; in this case, the scoring parameter table can be adjusted to lower the initial score for trading frequency and avoid misjudgment of risk.
[0077] In this embodiment, the scoring parameter table, driven by scenario parameters, can be adjusted to adaptively identify different transaction patterns. For example, in high-risk scenarios, the scoring parameter table can be adjusted to increase the initial score value of the corresponding feature, thereby improving the sensitivity of risk identification. Conversely, in low-risk scenarios, the initial score value of the corresponding feature can be decreased to reduce false risk assessments. This reduces the false risk assessment rate and ensures accurate risk identification in different scenarios.
[0078] It should be noted that when adjusting multiple scoring parameter tables—supervised learning algorithms, novel risk models, and scenario parameters—the priority order for adjusting these tables can be set in descending order: supervised learning algorithms, novel risk models, and scenario parameters. This priority is only an example; business personnel can adjust this priority according to actual needs.
[0079] like Figure 3 As shown, in one possible embodiment, after calculating the risk score in step S120, the risk assessment method further includes steps S141 to S143.
[0080] S141. Based on transaction data, find the baseline data of the behavior of the same account.
[0081] Behavioral baseline data is obtained by analyzing the trading behavior patterns of historical transaction data of the same account.
[0082] Specifically, the server can analyze multiple historical transaction data sets for the same account using clustering algorithms (such as K-means) to establish behavioral baseline data as the basis for subsequent determination of transaction difference scores. For example, the historical transaction preferences of a 20-year-old customer might be high-frequency online payments and low-frequency offline cash withdrawals. Based on this, behavioral baseline data can be established.
[0083] S142. Compare and process the transaction data with the behavioral baseline data to generate a transaction difference score.
[0084] For example, features such as transaction frequency and transaction amount can be extracted from transaction data and behavioral baseline data, feature similarity can be calculated based on these features, and then a transaction difference score can be generated based on the feature similarity.
[0085] Transaction discrepancy scores indicate the degree of difference between transaction data and behavioral baseline data. For example, a 20-year-old customer's behavioral baseline data shows frequent online payments and infrequent offline cash withdrawals. If the transaction data indicates that this customer makes infrequent online payments and frequent offline cash withdrawals, then there is a significant transaction discrepancy between the two.
[0086] S143. Adjust and update the risk score based on the transaction difference score.
[0087] For example, a mapping relationship between the trading difference score and the adjustment range of the risk score can be pre-established. The adjustment range of the risk score can be determined based on the trading difference score and this mapping relationship, and the risk score can be adjusted and updated based on this adjustment range.
[0088] In this embodiment, comparing transaction data with baseline behavioral data for the same account can alleviate the problem of insufficient identification of account borrowing or theft. By comparing the deviation between the customer's baseline behavioral data and the current transaction data, a transaction difference score is used to accurately assess the degree of difference between the baseline behavioral data and the transaction data, thereby accurately identifying risks. For example, when an account is used for abnormal transactions due to account borrowing, its transaction pattern may not match the historical behavior reflected in the account holder's baseline behavioral data. In this embodiment, by comparing the deviation between the customer's baseline behavioral data and the current transaction data, a transaction difference score is used to accurately assess the degree of difference between the baseline behavioral data and the transaction data. This allows for personalized and accurate identification of such anomalies for individual accounts, improving the accuracy of risk identification.
[0089] like Figure 3 As shown, in one possible embodiment, step S130, which triggers the corresponding risk response strategy based on the risk score, includes: matching the risk response strategy based on the score range of the risk score.
[0090] Risk response strategies include at least one of the following: logging, SMS alerts, intelligent outbound calling, manual outbound calling, and manual review.
[0091] Taking risk response strategies including log recording, SMS alerts, intelligent outbound calling, manual outbound calling, and manual review as an example, multiple scoring intervals can be pre-set, each corresponding to one of the aforementioned risk response strategies. Based on the numerical value of the scoring interval, the corresponding risk response strategy corresponds to the intervention intensity of the scoring interval, and multiple scoring intervals can form a tiered progressive mechanism.
[0092] The following will illustrate this with specific examples:
[0093] The scoring interval 1 is [0, 30), and the risk response strategy corresponding to scoring interval 1 is log recording. For example, if there are log records for 3 consecutive days, 30 points will be added to the current risk score, and the current risk score will be updated using the risk score with the added 30 points to trigger the risk response strategy corresponding to scoring interval 2.
[0094] The scoring interval 2 is [30, 60), and the risk response strategy corresponding to scoring interval 2 is SMS alerts. For example, if SMS alerts are received for 3 consecutive days, 30 points will be added to the current risk score, and the current risk score will be updated using the risk score with the added 30 points to trigger the risk response strategy corresponding to scoring interval 3.
[0095] The scoring range 3 is [60, 90), and the risk response strategy corresponding to scoring range 3 is intelligent outbound calling. For example, if intelligent outbound calling occurs for 3 consecutive days, 30 points will be added to the current risk score, and the current risk score will be updated using the risk score with the added 30 points to trigger the risk response strategy corresponding to scoring range 4.
[0096] The scoring range 4 is [90, 120), and the risk response strategy corresponding to scoring range 4 is manual outbound calling. For example, if manual outbound calling occurs for 3 consecutive days, 30 points will be added to the current risk score, and the current risk score will be updated using the risk score with the added 30 points to trigger the risk response strategy corresponding to scoring range 5.
[0097] The scoring range 5 is [120, +∞), and the risk response strategy corresponding to the scoring range 5 is manual review.
[0098] In this embodiment, by triggering a tiered risk response strategy based on the risk score range, risks can be precisely intervened in and intervention resources can be reasonably allocated to cope with scenarios with limited intervention resources and improve risk response efficiency.
[0099] The above embodiments match risk response strategies with risk intervals corresponding to risk scores. In one possible embodiment, after matching risk response strategies with risk intervals corresponding to risk scores, the risk identification method may further include: adjusting and updating risk response strategies based on customer identity verification results and the strength of risk response strategies to improve the accuracy of risk intervention.
[0100] Customer authentication results include at least one of the following: facial recognition pass rate, SMS verification code verification result.
[0101] Customer identity verification results refer to the results of confirming a customer's identity through biometrics (such as facial recognition) or verification methods (such as SMS verification codes).
[0102] Taking the aforementioned risk response strategies, including log recording, SMS alerts, intelligent outbound calling, manual outbound calling, and manual review, as an example, the risk response strategies can be arranged in ascending order of intensity as follows: log recording, SMS alerts, intelligent outbound calling, manual outbound calling, and manual review.
[0103] For example, if the current risk score is 40, corresponding to a score range of [30, 60), the risk response strategy for this range is SMS alerts. If the customer authentication result indicates successful authentication, it suggests a high probability that the current transaction is normal; therefore, the strength of the risk response strategy can be reduced, i.e., the risk response strategy can be adjusted and updated to a weaker log recording. If the customer authentication result indicates unsuccessful authentication, it suggests a high probability that the current transaction is risky; therefore, the strength of the risk response strategy can be increased, i.e., the risk response strategy can be adjusted to a stronger intelligent outbound calling strategy.
[0104] It should be noted that, regarding the lower boundary of log recording strength, if the customer authentication result indicates that the customer authentication has passed, the strength of the risk response strategy can be reduced, for example, by deleting the log record. Regarding the upper boundary of manual review strength, if the customer authentication result indicates that the customer authentication has failed, the strength of the risk response strategy can be increased, for example, by increasing the number of prompts for manual review.
[0105] In this embodiment, a risk score is determined by combining the structured feature vectors of the transaction data itself, and a corresponding risk response strategy is matched based on the risk score. Furthermore, considering the real-world scenario where customers may have genuine transaction needs similar to the risk, customer identity verification is introduced. For example, by combining transaction data and identity verification, it is determined whether the strength of the current risk response strategy needs adjustment, thus achieving accurate and dynamic risk intervention.
[0106] Figure 4 This is a schematic diagram of the risk identification device according to an embodiment of this application. Figure 4As shown, the risk identification device provided in this application embodiment includes: a structured feature vector generation module 210, a risk score calculation module 220, and a risk response module 230.
[0107] The structured feature vector generation module 210 is used to classify and label transaction data according to preset rules and generate structured feature vectors. The structured feature vectors contain multiple features including: transaction time, transaction amount, transaction location, transaction frequency, and transaction channel.
[0108] The risk scoring calculation module 220 is used to calculate the risk score based on the structured feature vector.
[0109] The risk response module 230 is used to trigger the corresponding risk response strategy based on the risk score.
[0110] In one possible embodiment, the risk score calculation module includes: an initial score value determination submodule, used to assign initial score values to multiple features of a structured feature vector according to a score parameter table, wherein the score parameter table is determined based on historical transaction data; and a weighted summation submodule, used to perform a weighted summation of the initial score values and the feature label values of the structured feature vector to generate a risk score.
[0111] In one possible embodiment, the risk identification device further includes: a first updating submodule for the scoring parameter table, used to update the scoring parameter table using a supervised learning algorithm with structured feature vectors of historical transaction data; and / or, a second updating submodule for the scoring parameter table, used to update the scoring parameter table according to the frequency of occurrence of new risk patterns.
[0112] In one possible embodiment, the risk identification device further includes: a third update submodule for the scoring parameter table, used to adjust and update the scoring parameter table according to scenario parameters, including: the distribution of transaction frequency characteristics in different time periods.
[0113] In one possible embodiment, the risk identification device further includes: a behavior baseline data lookup module, used to look up behavior baseline data for the same account based on transaction data, wherein the behavior baseline data is obtained by analyzing the transaction behavior patterns of historical transaction data of the same account; a comparison processing module, used to compare the transaction data with the behavior baseline data to generate a transaction difference score; and a risk score update module, used to adjust and update the risk score according to the transaction difference score.
[0114] In one possible embodiment, the risk identification device further includes: a real-time update module for updating the structured feature vector through a real-time stream processing framework; the real-time update module includes a real-time update submodule for updating the feature label values of the structured feature vector of continuous transaction data in real time based on a sliding window mechanism.
[0115] In one possible embodiment, the risk response module includes a risk response submodule, which is used to match a risk response strategy according to the scoring range of the risk score. The risk response strategy includes at least one of the following: log recording, SMS reminder, intelligent outbound calling, manual outbound calling, and manual review.
[0116] In one possible embodiment, the risk identification device further includes a risk response strategy update module, used to adjust and update the risk response strategy based on the customer authentication result and the strength of the risk response strategy, wherein the customer authentication result includes at least one of the following: face recognition pass rate, SMS verification code verification result.
[0117] Figure 5 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Figure 5 As shown, this application embodiment provides an electronic device including a processor 301 and a memory 302. Optionally, the device further includes a communication component 303. The processor 301, memory 302, and communication component 303 are connected via a bus 304.
[0118] In the specific implementation process, the memory 302 stores code, and the processor 301 runs the code stored in the memory 302 to execute the method of the above method embodiment.
[0119] The specific implementation process of processor 301 can be found in the above method embodiments, and its implementation principle and technical effect are similar. It will not be repeated here.
[0120] In the above Figure 5 In the illustrated embodiments, it should be understood that the processor 301 can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), etc. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the method disclosed in this invention can be directly implemented by a hardware processor, or implemented by a combination of hardware and software modules within the processor.
[0121] The memory 302 may include high-speed RAM memory, and may also include non-volatile memory (NVM), such as at least one disk storage.
[0122] Bus 304 can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. Bus 304 can be divided into address bus, data bus, control bus, etc. For ease of illustration, the bus 304 in the accompanying drawings of this application is not limited to only one bus or one type of bus.
[0123] This application provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, are used to implement the methods described in the above-described method embodiments.
[0124] The aforementioned computer-readable storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk. The readable storage medium can be any available medium accessible to a general-purpose or special-purpose computer.
[0125] An exemplary readable storage medium is coupled to a processor, enabling the processor to read information from and write information to the readable storage medium. Of course, the readable storage medium can also be a component of the processor. The processor and the readable storage medium can reside in an Application Specific Integrated Circuit (ASIC). Alternatively, the processor and the readable storage medium can exist as discrete components in the device.
[0126] This application provides a computer program product, including a computer program that, when executed by a processor, implements the methods provided in any of the embodiments described above.
[0127] It should be noted that, for the sake of simplicity, the foregoing method embodiments are all described as a series of actions. However, those skilled in the art should understand that this application is not limited to the described order of actions, as some steps may be performed in other orders or simultaneously according to this application. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are all optional embodiments, and the actions and modules involved are not necessarily essential to this application.
[0128] It should be further noted that although the steps in the flowchart are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowchart may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these sub-steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the sub-steps or stages of other steps.
[0129] It should be understood that the above-described device embodiments are merely illustrative, and the device of this application can also be implemented in other ways. For example, the division of units / modules in the above embodiments is only a logical functional division, and there may be other division methods in actual implementation. For example, multiple units, modules, or components may be combined, or integrated into another system, or some features may be ignored or not executed.
[0130] Furthermore, unless otherwise specified, the functional units / modules in the various embodiments of this application can be integrated into one unit / module, or each unit / module can exist physically separately, or two or more units / modules can be integrated together. The integrated units / modules described above can be implemented in hardware or as software program modules.
[0131] When integrated units / modules are implemented in hardware, the hardware can be digital circuits, analog circuits, etc. The physical implementation of the hardware structure includes, but is not limited to, transistors, memristors, etc. Unless otherwise specified, the processor can be any suitable hardware processor, such as a CPU, GPU, FPGA, DSP, and ASIC, etc. Unless otherwise specified, the storage unit can be any suitable magnetic or magneto-optical storage medium, such as Resistive Random Access Memory (RRAM), Dynamic Random Access Memory (DRAM), Static Random Access Memory (SRAM), Enhanced Dynamic Random Access Memory (EDRAM), High-Bandwidth Memory (HBM), Hybrid Memory Cube (HMC), etc.
[0132] If the integrated unit / module is implemented as a software program module and sold or used as an independent financial product, it can be stored in a computer-readable storage device (CMD). Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software financial product. This computer software financial product is stored in a memory and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this application. The aforementioned memory includes various media capable of storing program code, such as a USB flash drive, read-only memory (ROM), random access memory (RAM), portable hard drive, magnetic disk, or optical disk.
[0133] In the above embodiments, the descriptions of each embodiment have their own emphasis. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments. The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as the combination of these technical features does not contradict each other, it should be considered within the scope of this specification.
[0134] Other embodiments of this application will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of this application that follow the general principles of this application and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of this application are indicated by the following claims.
[0135] It should be understood that this application is not limited to the precise structure described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of this application is limited only by the appended claims.
Claims
1. A risk identification method, characterized in that, include: The transaction data is classified and labeled according to preset rules to generate a structured feature vector. The structured feature vector includes multiple features such as transaction time, transaction amount, transaction location, transaction frequency, and transaction channel. Calculate the risk score based on the structured feature vector; The risk response strategy is triggered based on the risk score.
2. The method according to claim 1, characterized in that, The calculation of the risk score based on the structured feature vector includes: Initial score values are assigned to multiple features of the structured feature vector according to a scoring parameter table, which is determined based on historical transaction data. The risk score is generated by weighting and summing the initial score value with the feature label value of the structured feature vector.
3. The method according to claim 2, characterized in that, Before assigning initial score values to multiple features of the structured feature vector according to the scoring parameter table, the method further includes: The scoring parameter table is updated using structured feature vectors from historical transaction data and a supervised learning algorithm; and / or, The scoring parameter table is updated based on the frequency of occurrence of new risk patterns.
4. The method according to claim 2, characterized in that, Before assigning initial score values to multiple features of the structured feature vector according to the scoring parameter table, the method further includes: The scoring parameter table is adjusted and updated based on the scenario parameters, which include the distribution of transaction frequency characteristics over different time periods.
5. The method according to any one of claims 1-4, characterized in that, After calculating the risk score, the method further includes: Based on the transaction data, find the behavioral baseline data of the same account. The behavioral baseline data is obtained by analyzing the transaction behavior patterns of the historical transaction data of the same account. The transaction data is compared with the behavioral baseline data to generate a transaction difference score; The risk score is adjusted and updated based on the transaction difference score.
6. The method according to any one of claims 1-4, characterized in that, After classifying and tagging the transaction data according to preset rules, the method further includes: The structured feature vector is updated using a real-time stream processing framework; The update includes: updating the feature label values of the structured feature vector of continuous transaction data in real time based on a sliding window mechanism.
7. The method according to any one of claims 1-4, characterized in that, The risk response strategy triggered based on the risk score includes: Risk response strategies are matched based on the scoring range of the risk score, and the risk response strategies include at least one of the following: log recording, SMS reminders, intelligent outbound calling, manual outbound calling, and manual review.
8. The method according to any one of claims 1-4, characterized in that, After matching a risk response strategy based on the risk score range, the method further includes: Based on the customer authentication results and the strength of the risk response strategy, the risk response strategy is adjusted and updated. The customer authentication results include at least one of the following: facial recognition pass rate and SMS verification code verification results.
9. A risk identification device, characterized in that, The device includes: The structured feature vector generation module is used to classify and label transaction data according to preset rules and generate structured feature vectors. The structured feature vectors include multiple features such as transaction time, transaction amount, transaction location, transaction frequency, and transaction channel. The risk scoring calculation module is used to calculate the risk score based on the structured feature vector. The risk response module is used to trigger the corresponding risk response strategy based on the risk score.
10. An electronic device, characterized in that, include: A processor, and a memory communicatively connected to the processor; The memory stores computer-executed instructions; The processor executes computer execution instructions stored in the memory to implement the method as described in any one of claims 1 to 8.
11. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the method as described in any one of claims 1 to 8.
12. A computer program product, characterized in that, Includes a computer program that, when executed by a processor, implements the method of any one of claims 1 to 8.