Visit service anti-fraud detection method and device

By combining image detection and semantic detection channels to process communication record screenshots, and combining check-in trajectory curvature and device characteristics, multi-dimensional fraud indicators are generated, solving the problem that existing technologies cannot effectively identify fraudulent business visits by salespersons, and achieving more efficient fraud detection.

CN121660809APending Publication Date: 2026-03-13CHINA LIFE INSURANCE CO LTD SHANGHAI DATA CENT
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-20
Publication Date
2026-03-13

AI Technical Summary

Technical Problem

Existing technologies are unable to effectively identify fraudulent activities by insurance industry sales agents during business visits, especially in verifying the authenticity of screenshots from communication software and the effectiveness of communication between sales agents and customers.

Method used

A method combining image detection and semantic detection is used to process communication record screenshots and determine the forgery score of communication records. By combining the curvature of the check-in trajectory, device characteristics and customer behavior characteristics, multi-dimensional fraud indicators are generated. By integrating multi-source data for correlation analysis, the authenticity of the visit business is verified.

Benefits of technology

It improves the ability to identify advanced forgery behaviors, enhances the accuracy and comprehensiveness of fraud detection in business visits, and reduces the fraud false alarm rate.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121660809A_ABST
    Figure CN121660809A_ABST
Patent Text Reader

Abstract

The invention provides a visit service anti-fraud detection method and device. The method comprises the following steps: obtaining service visit data of a target salesman; processing a communication record screenshot of the communication application based on detection of an image detection channel and a semantic detection channel, and determining a communication record forgery score of the communication record screenshot; determining a sign-in track curvature of the target salesman based on a sign-in place in the visit sign-in data; determining an equipment fraud score based on equipment characteristics in the visit sign-in data; target salesman behavior characteristics and customer behavior characteristics in the business visit data are extracted, the target salesman behavior characteristics and the customer behavior characteristics are aligned, and a customer behavior response value is generated; and taking the communication record forgery score, the sign-in track curvature, the equipment fraud score and the customer behavior response value as fraud indexes, and determining a fraud detection result of the visit service of the target salesman, so that fraud risk assessment is more comprehensive and effective.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of data processing, and more specifically, to a method and apparatus for anti-fraud detection in visitor services. Background Technology

[0002] Currently, the insurance industry primarily relies on GPS location tracking and OCR comparison of chat logs from communication software to verify the authenticity of sales visits. The mainstream approach can be summarized as "single-source location tracking + rule matching": mobile terminals use GPS to collect the salesperson's real-time location and timestamp, which is then uploaded to a cloud server via 4G / 5G networks. The server performs spatiotemporal matching of this trajectory with the customer's location or IP address; if a threshold is met, a "valid visit" result is generated, triggering a reward. At the data level, visit records from the business system, screenshots and chat logs from communication software on social media platforms, and call records from mobile carriers are stored and analyzed independently.

[0003] Therefore, it is impossible to effectively identify fraudulent activities related to visitation services. Summary of the Invention

[0004] In view of this, the purpose of this application is to provide a method and apparatus for anti-fraud detection of visit business, which improves the accuracy of identifying fraudulent behavior in visit business.

[0005] This application provides an embodiment of a visitor business anti-fraud detection method, the method comprising: Obtain business visit data from target marketers; the business visit data includes: visit check-in data from business applications, screenshots of communication records from communication applications, and evaluation records; Based on the image detection channel and semantic detection channel, the communication record screenshots of the communication application are processed to determine the communication record forgery score of the communication record screenshots; Based on the check-in locations in the visit check-in data, the curvature of the target salesperson's check-in trajectory is determined; the curvature of the check-in trajectory represents the degree of bending of the GPS check-in trajectory. Based on the device characteristics in the visit check-in data, and combined with the trained device risk assessment model, the device fraud score is determined. Extract the target salesperson behavior characteristics and customer behavior characteristics from the business visit data, align the target salesperson behavior characteristics and customer behavior characteristics, and generate a customer behavior response value; the customer behavior response value is used to characterize the matching degree between customer behavior and salesperson visit behavior; The fraud detection results of the target salesperson's visit business are determined by using the communication record forgery score, check-in trajectory curvature, device fraud score, and customer behavior response value as fraud indicators.

[0006] In some embodiments, the visitor service anti-fraud detection method, the step of processing the communication record screenshots of the communication application based on image detection channels and semantic detection channels, and determining the communication record forgery score of the communication record screenshots, includes: Based on the image detection channel, the tampering area features in the communication record screenshot of the communication application are extracted, and the image forgery probability of the communication record screenshot is determined based on the extracted tampering area features; Text is extracted from the communication record screenshots based on the semantic detection channel; target fields related to the visit are extracted from the visit check-in data and evaluation records to form a visit summary; Perform semantic consistency verification on the text in the communication record screenshot and the visit summary to obtain the semantic consistency probability; Based on the image forgery probability and semantic consistency probability, the communication record forgery score of the communication record screenshot is determined.

[0007] In some embodiments, the visitor service anti-fraud detection method, the step of extracting tampered area features from the communication record screenshot of the communication application based on the image detection channel, and determining the image forgery probability of the communication record screenshot based on the extracted tampered area features, includes: The communication record screenshots of the aforementioned communication application are preprocessed to generate compressed images; The pixel-level residual between the original communication record screenshot and the compressed image is calculated to initially locate the tamper-sensitive areas in the image, thus obtaining the preprocessed communication record screenshot; the weight of the tamper-sensitive areas in the preprocessed communication record screenshot is greater than the weight of the normal areas; The pre-processed communication record screenshots are processed by a pre-trained image processing model to obtain a heatmap of the tamper-sensitive area, and the image forgery probability of the communication record screenshots is output.

[0008] In some embodiments, the visit business anti-fraud detection method, wherein performing semantic consistency verification on the text in the communication record screenshot and the visit summary to obtain the semantic consistency probability includes: Identify the text in the screenshot of the communication record and the target entity in the visit summary; Count the number of target entities that match the text in the screenshot of the communication record and the visit summary; Based on the number of matched target entities and the total number of target entities, the semantic consistency probability is calculated.

[0009] In some embodiments, the visit business anti-fraud detection method, wherein determining the curvature of the target salesperson's check-in trajectory based on the check-in locations in the visit check-in data includes: Based on the check-in timestamps corresponding to the check-in locations in the visit check-in data, the check-in locations are connected in chronological order to form the GPS check-in trajectory of the target marketer; The GPS check-in trajectory is treated as a planar curve, and the curvature of the check-in trajectory is calculated.

[0010] In some embodiments, the visit business anti-fraud detection method, the step of determining the device fraud score based on device characteristics in the visit check-in data and in conjunction with a trained device risk assessment model, includes: The device features in the visit check-in data are input into the trained device risk assessment model. The device risk assessment model processes the device features and outputs a device fraud score. The device characteristics are multi-dimensional device fingerprints collected by the business application when the terminal starts up, including device ID, model, MAC, IMEI, system patch level, root status, proxy marker, VPN marker, and sensor deviation.

[0011] In some embodiments, the visit business anti-fraud detection method involves extracting target salesperson behavior features and customer behavior features from the business visit data, aligning the target salesperson behavior features and customer behavior features, and generating a customer behavior response value. This includes: extracting target salesperson behavior features and customer behavior features from the business visit data; the target salesperson behavior features include a check-in timestamp, a check-in location, and a first customer identifier provided by the target salesperson; the customer behavior features include the customer location, a customer response timestamp, and a second customer identifier extracted from the customer's response information. If the time difference between the check-in timestamp and the customer response timestamp is less than a preset duration, the distance difference between the check-in location and the customer's location is less than a preset distance threshold, and the first customer identifier and the second customer identifier are the same, then it is marked as a pairing event; Based on the time difference between the check-in timestamp and the customer response timestamp, the distance between the check-in location and the customer's location, and the consistency judgment result of the first customer identifier and the second customer identifier, a customer behavior response value is generated.

[0012] In some embodiments, the fraud detection method for visitation services, wherein the step of using the communication record forgery score, check-in trajectory curvature, device fraud score, and customer behavior response value as fraud indicators to determine the fraud detection result of the target salesperson's visitation service includes: Based on the pre-set weights corresponding to the fraud indicators, the fraud indicators are weighted and summed to determine the final risk score; The warning level in the fraud detection results is determined based on the final risk score; different warning levels correspond to different score ranges.

[0013] In some embodiments, the fraud detection method for visitation services, wherein the step of using the communication record forgery score, check-in trajectory curvature, device fraud score, and customer behavior response value as fraud indicators to determine the fraud detection result of the target salesperson's visitation service includes: Determine whether the communication record forgery score, check-in trajectory curvature, device fraud score, and customer behavior response value, which are used as fraud indicators, are abnormal. If multiple fraud indicators are abnormal, the correlation analysis results in the fraud detection results are determined to be abnormal.

[0014] In some embodiments, a visit business anti-fraud detection device is also provided, the device comprising: The acquisition module is used to acquire business visit data of target marketers; the business visit data includes: visit check-in data of business applications, screenshots of communication records and evaluation records of communication applications; the visit check-in data includes check-in location, check-in timestamp, stay duration, visit purpose, visit method, visit content and device characteristics; The first determining module is used to process the communication record screenshots of the communication application based on the image detection channel and the semantic detection channel, and determine the communication record forgery score of the communication record screenshots; The second determining module is used to determine the curvature of the target salesperson's check-in trajectory based on the check-in locations in the visit check-in data; the curvature of the check-in trajectory represents the degree of curvature of the GPS check-in trajectory; The third determination module is used to determine the equipment fraud score based on the equipment characteristics in the visit check-in data and in combination with the trained equipment risk assessment model. The generation module is used to extract the target salesperson behavior characteristics and customer behavior characteristics from the business visit data, align the target salesperson behavior characteristics and customer behavior characteristics, and generate a customer behavior response value; the customer behavior response value is used to characterize the matching degree between customer behavior and salesperson visit behavior; The fourth determination module is used to determine the fraud detection results of the target salesperson's visit business by using the communication record forgery score, check-in trajectory curvature, device fraud score, and customer behavior response value as fraud indicators.

[0015] This application provides a method and apparatus for anti-fraud detection of business visits. The method acquires business visit data of a target salesperson. The business visit data includes: visit check-in data of a business application, screenshots of communication records from a communication application, and evaluation records. The method processes the screenshots of communication records from the communication application based on image detection and semantic detection channels to determine the communication record forgery score of the screenshots. Based on the check-in locations in the visit check-in data, the method determines the curvature of the target salesperson's check-in trajectory. The curvature of the check-in trajectory represents GPS data. The curvature of the sign-in trajectory; based on the device characteristics in the visit sign-in data, combined with the trained device risk assessment model, the device fraud score is determined; the target salesperson behavior characteristics and customer behavior characteristics are extracted from the business visit data, and the target salesperson behavior characteristics and customer behavior characteristics are aligned to generate a customer behavior response value; the customer behavior response value is used to characterize the matching degree between customer behavior and salesperson visit behavior; the communication record forgery score, sign-in trajectory curvature, device fraud score, and customer behavior response value are used as fraud indicators to determine the fraud detection result of the target salesperson's visit business; by integrating the visit sign-in data of the business application, the communication record screenshots and evaluation records of the communication application, the multi-source data is correlated and analyzed to effectively verify whether the communication is real; the communication record screenshots are processed by a dual-channel "image detection + semantic detection" approach, which can identify tampering traces at the image level and improve the ability to identify advanced forgery behavior by verifying the logical consistency of the communication content at the semantic level; at the same time, by combining the sign-in trajectory curvature, device risk assessment, and the matching degree between salesperson and customer behavior, a multi-dimensional fraud indicator is constructed to make the fraud risk assessment more comprehensive and effective. Attached Figure Description

[0016] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings used in the embodiments will be briefly introduced below. It should be understood that the following drawings only show some embodiments of this application and should not be regarded as a limitation of the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.

[0017] Figure 1 A flowchart of the visit business anti-fraud detection method described in an embodiment of this application is shown; Figure 2 A flowchart illustrating the method for determining the communication record forgery score of the communication record screenshot according to an embodiment of this application is shown; Figure 3 A flowchart illustrating the method for determining the curvature of a target marketer's check-in trajectory as described in an embodiment of this application is shown. Figure 4 A flowchart of the method for generating customer behavior response values ​​according to an embodiment of this application is shown; Figure 5 A schematic diagram of the anti-fraud detection device for visitor services described in an embodiment of this application is shown. Detailed Implementation

[0018] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. It should be understood that the accompanying drawings in this application are for illustrative and descriptive purposes only and are not intended to limit the scope of protection of this application. Furthermore, it should be understood that the schematic drawings are not drawn to scale. The flowcharts used in this application illustrate operations implemented according to some embodiments of this application. It should be understood that the operations in the flowcharts may not be implemented in sequence, and steps without logical contextual relationships may be reversed or implemented simultaneously. In addition, those skilled in the art, guided by the content of this application, may add one or more other operations to the flowcharts, or remove one or more operations from the flowcharts.

[0019] Furthermore, the described embodiments are merely some, not all, of the embodiments of this application. The components of the embodiments of this application described and illustrated herein can typically be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of this application provided in the accompanying drawings is not intended to limit the scope of the claimed application, but merely to illustrate selected embodiments of the application. All other embodiments obtained by those skilled in the art based on the embodiments of this application without inventive effort are within the scope of protection of this application.

[0020] It should be noted that the term "comprising" will be used in the embodiments of this application to indicate the presence of the features declared thereafter, but does not exclude the addition of other features.

[0021] Currently, the insurance industry primarily relies on GPS location tracking and OCR comparison of chat logs from communication software to verify the authenticity of sales visits. The mainstream approach can be summarized as "single-source location tracking + rule matching": mobile terminals use GPS to collect the salesperson's real-time location and timestamp, which is then uploaded to a cloud server via 4G / 5G networks. The server performs spatiotemporal matching of this trajectory with the customer's location or IP address; if a threshold is met, a "valid visit" result is generated, triggering a reward. At the data level, visit records from the business system, screenshots and chat logs from communication software on social media platforms, and call records from mobile carriers are stored and analyzed independently.

[0022] As a result, existing technologies cannot effectively identify fraudulent activities in business visits, such as simply forging location check-in records within the business system without verifying whether genuine and effective communication has taken place between the business visitor and the customer on WeChat; or the screenshots of communication software showing signs of AI synthesis or high-precision Photoshop manipulation, etc.

[0023] Based on this, this application provides a method and apparatus for anti-fraud detection of business visits. The method acquires business visit data of a target salesperson. The business visit data includes: visit check-in data of a business application, screenshots of communication records from a communication application, and evaluation records. The method processes the screenshots of communication records from the communication application based on image detection and semantic detection channels to determine the communication record forgery score of the screenshots. Based on the check-in locations in the visit check-in data, the method determines the check-in trajectory curvature of the target salesperson. The check-in trajectory curvature represents GPS data. The curvature of the sign-in trajectory; based on the device characteristics in the visit sign-in data, combined with the trained device risk assessment model, the device fraud score is determined; the target salesperson behavior characteristics and customer behavior characteristics are extracted from the business visit data, and the target salesperson behavior characteristics and customer behavior characteristics are aligned to generate a customer behavior response value; the customer behavior response value is used to characterize the matching degree between customer behavior and salesperson visit behavior; the communication record forgery score, sign-in trajectory curvature, device fraud score, and customer behavior response value are used as fraud indicators to determine the fraud detection result of the target salesperson's visit business; by integrating the visit sign-in data of the business application, the communication record screenshots and evaluation records of the communication application, the multi-source data is correlated and analyzed to effectively verify whether the communication is real; the communication record screenshots are processed by a dual-channel "image detection + semantic detection" approach, which can identify tampering traces at the image level and improve the ability to identify advanced forgery behavior by verifying the logical consistency of the communication content at the semantic level; at the same time, by combining the sign-in trajectory curvature, device risk assessment, and the matching degree between salesperson and customer behavior, a multi-dimensional fraud indicator is constructed to make the fraud risk assessment more comprehensive and effective.

[0024] Please refer to Figure 1 , Figure 1 A flowchart of the visitor business anti-fraud detection method described in an embodiment of this application is shown; as follows: Figure 1 As shown, the method includes the following steps S101-S106: S101. Obtain business visit data of target marketers; the business visit data includes: visit check-in data of business applications, screenshots of communication records of communication applications, and evaluation records; S102. Based on the image detection channel and semantic detection channel, process the communication record screenshot of the communication application to determine the communication record forgery score of the communication record screenshot; S103. Based on the check-in locations in the visit check-in data, determine the curvature of the target salesperson's check-in trajectory; the curvature of the check-in trajectory represents the degree of bending of the GPS check-in trajectory; S104. Based on the device characteristics in the visit check-in data, and combined with the trained device risk assessment model, determine the device fraud score. S105. Extract the target salesperson behavior characteristics and customer behavior characteristics from the business visit data, align the target salesperson behavior characteristics and customer behavior characteristics, and generate a customer behavior response value; the customer behavior response value is used to characterize the matching degree between customer behavior and salesperson visit behavior; S106. The communication record forgery score, check-in trajectory curvature, device fraud score, and customer behavior response value are used as fraud indicators to determine the fraud detection results of the target salesperson's visit business.

[0025] In step S101, business visit data of the target marketers is obtained; the business visit data includes: visit check-in data of business applications, screenshots of communication records of communication applications, and evaluation records.

[0026] In some embodiments, the visit check-in data of the business application is data in the "business application (e.g., visit check-in application)" deployed by the enterprise, which is visit information actively registered by the salesperson.

[0027] The visit check-in data includes check-in location (GPS coordinates), check-in timestamp, stay duration (time difference between check-in and departure), visit purpose (e.g., recommending product A), visit method (e.g., face-to-face meeting), visit content (brief record of communication content summary), and equipment characteristics.

[0028] The device characteristics include the device model of the terminal used by the marketer (such as "Huawei Mate 60 Pro"), device ID (IMEI / unique device identifier), device operating status (such as system patch level, root status, proxy / VPN enabled flag), etc.

[0029] Screenshots of communication records from communication applications, including the screenshot time and the text content within the screenshot (the dialogue text between the customer and the salesperson), etc.

[0030] Evaluation records for communication applications include customer feedback data submitted via the application after communicating with the salesperson, reflecting their evaluation of the visit; this includes the customer's OpenID (such as nickname).

[0031] In step S102, the communication record screenshot of the communication application is processed based on the image detection channel and the semantic detection channel to determine the communication record forgery score of the communication record screenshot.

[0032] Please refer to Figure 2The step of processing the communication record screenshots of the communication application based on the image detection channel and the semantic detection channel, and determining the communication record forgery score of the communication record screenshots, includes the following steps S201-S204: S201. Extract tampered area features from the communication record screenshot of the communication application based on the image detection channel, and determine the image forgery probability of the communication record screenshot based on the extracted tampered area features; S202. Extract the text from the communication record screenshot based on the semantic detection channel; extract target fields related to the visit from the visit check-in data and evaluation records to form a visit summary; S203. Perform semantic consistency verification on the text in the communication record screenshot and the visit summary to obtain the semantic consistency probability; S204. Based on the image forgery probability and semantic consistency probability, determine the communication record forgery score of the communication record screenshot.

[0033] By processing communication record screenshots through a dual-path approach of "image detection channel + semantic detection channel," it captures pixel-level tampering traces (such as AI synthesis and local anomalies in high-precision Photoshop) at the image level, and verifies the logical consistency between the text and the visited business at the semantic level. This breaks through the limitations of traditional single OCR or image detection, which can only identify low-level tampering. It significantly improves the recognition accuracy of advanced forgery scenarios such as "images are compliant but text is fake" and "texts are similar in form but semantically contradictory," and greatly reduces the fraud false detection rate.

[0034] In some embodiments, the step of extracting tampered region features from a screenshot of a communication record of the communication application based on an image detection channel, and determining the image forgery probability of the communication record screenshot based on the extracted tampered region features, includes: The communication record screenshots of the aforementioned communication application are preprocessed to generate compressed images; The pixel-level residual between the original communication record screenshot and the compressed image is calculated to initially locate the tamper-sensitive areas in the image, thus obtaining the preprocessed communication record screenshot; the weight of the tamper-sensitive areas in the preprocessed communication record screenshot is greater than the weight of the normal areas; The pre-processed communication record screenshots are processed by a pre-trained image processing model to obtain a heatmap of the tamper-sensitive area, and the image forgery probability of the communication record screenshots is output.

[0035] In other words, the image detection channel first locates the tampered sensitive areas through pixel-level residuals and assigns them higher weights. Then, the pre-processed image is input into the model to avoid wasting computing power on normal areas while highlighting tampering features. Combined with the heatmap and forgery probability output by the pre-trained image processing model, a progressive detection from coarse localization to fine judgment is achieved, which not only improves inference efficiency but also enhances robustness to subtle tampering (such as local text replacement and background synthesis).

[0036] In some embodiments, the step of performing semantic consistency verification on the text in the communication record screenshot and the visit summary to obtain the semantic consistency probability includes: Identify the text in the screenshot of the communication record and the target entity in the visit summary; Count the number of target entities that match the text in the screenshot of the communication record and the visit summary; Based on the number of matched target entities and the total number of target entities, the semantic consistency probability is calculated.

[0037] In other words, the semantic detection channel extracts target fields from visit check-in data and evaluation records to form a visit summary, and then calculates the semantic consistency probability with "target entity matching" as the core. This anchors text verification to key business information such as "product name, visit time, and location," avoiding misjudgments caused by irrelevant text differences (such as different colloquial expressions), ensuring that semantic verification is strongly correlated with visit business, and improving the business adaptability of forgery scores.

[0038] In this way, the forgery score is determined by combining the probability of image forgery and the probability of semantic consistency, rather than judging "true / false" from a single dimension. This can reflect the risk contribution of different dimensions (such as the intuitive risk of image tampering and the logical risk of semantic contradiction) and output a quantifiable level of risk.

[0039] In some embodiments, the specific implementation of the image detection channel is as follows.

[0040] The image detection channel uses Swin-Transformer + ELA high-frequency residuals to output the forgery probability P. img .

[0041] The communication record screenshots of the communication application are preprocessed to generate compressed images: Specifically, the images are first normalized, the communication record screenshots are uniformly scaled to a fixed resolution (such as 512×512), and converted to RGB three-channel format.

[0042] Then, the image is processed by ELA (Error Level Analysis) to perform JPEG compression (quality=95%) to generate a compressed version; the pixel-level residual (high-frequency noise) between the original image and the compressed image is calculated to highlight the tampered area (such as PS traces), and the tampered area is used first for feature extraction.

[0043] Feature extraction is performed using the Swing-Transformer.

[0044] The Swin-Transformer model architecture is as follows: it uses a pre-trained Swin-Transformer-Base (input size 512×512, window size = 8).

[0045] The key steps for feature extraction using Swin-Transformer are as follows: Local window attention: Divide the image into 8×8 non-overlapping windows and extract local texture features (such as edge anomalies and color level breaks).

[0046] Hierarchical feature fusion: Global contextual information (such as background consistency) is gradually aggregated through downsampling of 4 stages.

[0047] Output feature map: A heat map of the tamper-sensitive area is obtained (size 64×64, number of channels = 1024).

[0048] Forgery probability calculation: Input the feature map into a fully connected layer + Sigmoid, and output the image forgery probability P. img ∈ [0,1].

[0049] In some embodiments, the threshold for determining the probability of image forgery is as follows: P img ≥ 0.7 → Determined as forgery (high confidence level).

[0050] 0.3 <P img <0.7 → Further verification is needed in conjunction with semantic channels.

[0051] In some embodiments, the sample set used for training the image detection channel is subjected to data augmentation processing. Specifically, during training, tampered data (such as random text replacement and background synthesis) is synthesized to simulate a real forgery scenario.

[0052] In some embodiments, the Swin-Transformer loss function Focal Loss (γ=2) addresses the imbalance between positive and negative samples.

[0053] In some embodiments, the specific implementation of the semantic detection channel is as follows.

[0054] The semantic detection channel calculates the semantic consistency probability P based on BERT-CRF. sem .

[0055] First, the chat text is extracted by using OCR to obtain the text content from the WeChat chat screenshots and sorting it by timestamp. Then, the visit summary is structured, and fields such as "Purpose of Visit" and "Product Name" of the corresponding visit record are extracted from the business system.

[0056] Then, BERT semantic encoding is used to semantically encode the chat text and visit summary, and global semantic features are extracted.

[0057] Specifically, the BERT-Base-Chinese model is used, and the input format is concatenated text: for example, such as [CLS] chat text: the customer said "I need to know about product A"; [SEP] visit summary: product B was recommended [SEP].

[0058] The output of the BERT-Base-Chinese model is represented as the embedding vector (768 dimensions) of the [CLS] tag as a global semantic feature.

[0059] In some embodiments, CRF consistency verification is performed on the text in the communication record screenshot and the visit summary, starting with entity alignment: The CRF layer is used to identify key entities (such as product name, time, and location) in the chat text and visit summary. These key entities are the target entities.

[0060] Example rule: If "Product A" is mentioned in the chat but does not appear in the summary, it is marked as contradictory.

[0061] Based on the number of matched target entities and the total number of target entities, the semantic consistency probability is calculated. Specifically, the consistency score S is defined as the number of matched entities / the total number of entities.

[0062] The semantic consistency probability obtained from the transformation is: ; For example, when k=10 and S=0.8, P sem ≈0.95, k represents the semantic sensitivity coefficient; S represents the consistency score. Represents the probability of semantic consistency.

[0063] ∈[0,1], the closer the value is to 1, the higher the semantic consistency between the two (the chat content matches the business logic of the visit, and the suspicion of screenshot forgery is low); the closer the value is to 0, the more significant the semantic contradiction (such as the chat mentioning "product A" and the visit summary recording "product B", and the suspicion of screenshot forgery is high).

[0064] During the training process in the semantic detection channel, adversarial sample processing is performed. Specifically, synonym substitution noise (such as “Product A” → “Insurance Plan A”) is injected into the OCR text to enhance robustness.

[0065] In some embodiments, the semantic sensitivity coefficient k is determined based on the business type (e.g., life insurance k=15, auto insurance k=8).

[0066] In step S103, the curvature of the target salesperson's check-in trajectory is determined based on the check-in location in the visit check-in data; the curvature of the check-in trajectory represents the degree of curvature of the GPS check-in trajectory.

[0067] In some embodiments, please refer to Figure 3 The determination of the curvature of the target salesperson's check-in trajectory based on the check-in locations in the visit check-in data includes the following steps S301-S302: S301. Based on the check-in timestamps corresponding to the check-in locations in the visit check-in data, connect each check-in location in chronological order to form the GPS check-in trajectory of the target marketer; S302. Treat the GPS check-in trajectory as a plane curve and calculate the curvature of the check-in trajectory of the plane curve.

[0068] Here, the check-in timestamp t0, the dwell time Δt, and the curvature κ of the check-in trajectory are used to calculate the check-in trajectory. "Check-in trajectory curvature" refers to treating the GPS trajectory left by salespeople during the check-in process as a planar curve, and using the mathematical concept of curvature κ to quantify "how curved" this curve is. κ = 0: The trajectory is almost a straight line with no curves; The larger κ is, the sharper the trajectory turns (e.g., circling, back and forth); The sign of κ (positive / negative) indicates whether to bend to the left or to the right; In this application embodiment, it is treated as an anti-fraud feature or a preparatory anti-fraud indicator; if a marketer claims to be "visiting on normal walking," but the trajectory curvature suddenly becomes very large (obvious circling or shaking in place), it may be cheating by using virtual positioning or simulated trajectory.

[0069] Based on the curvature of the check-in trajectory, the curvature value is used to quantify the "abnormal curvature" of the trajectory. The curvature of the trajectory of a normal offline visit is usually small (the movement path is smooth), while virtual location fraud (such as using software to forge multiple locations) often shows "severe curvature of the trajectory in a short period of time" (sudden increase in curvature). Therefore, curvature can be used as a key feature to determine whether "check-in data is a real movement trajectory", thereby breaking through the limitations of traditional "single location verification" and identifying virtual location fraud through the curvature features of continuous trajectories, thus improving the accuracy of anti-fraud detection.

[0070] In step S104, the equipment fraud score is determined based on the equipment characteristics in the visit check-in data and the trained equipment risk assessment model.

[0071] In some embodiments, determining the device fraud score based on device characteristics in the visit check-in data and in conjunction with a trained device risk assessment model includes: The device features in the visit check-in data are input into the trained device risk assessment model. The device risk assessment model processes the device features and outputs a device fraud score. The device characteristics are multi-dimensional device fingerprints collected by the business application when the terminal starts up, including device ID, model, MAC, IMEI, system patch level, root status, proxy marker, VPN marker, and sensor deviation.

[0072] In some embodiments, the multi-dimensional device fingerprint collected by the business application when the terminal starts up is uploaded to the "device fingerprint database" in the cloud.

[0073] The device risk assessment model uses historical abnormal device samples to train a lightweight GBDT model, outputting a continuous score of 0–1: 0: Completely trustworthy (normal terminal, no tampering records); 1: High-risk gray market (rooted, device modification tools, historical fraudulent devices); In use, the anti-fraud engine uses this score as the "device" score. risk "Directly substitute the score into the real-time risk scoring formula; the higher the score, the greater the weight of the anomaly."

[0074] Traditional anti-fraud methods rely solely on location tracking and chat logs, neglecting the "cheating tools themselves"—for example, marketers using rooted phones to install fake location software and forge attendance records, which is difficult to detect with traditional methods. However, by using device fingerprinting and risk models, the characteristics of "modified devices" (such as root status and sensor deviations) can be directly identified. Even if the location and chat logs are very convincingly forged, as long as the device is "abnormal," it will be assigned a high-risk score, thus blocking fraudulent activities such as "using cheating devices to forge visits" at the source.

[0075] In step S105, the target salesperson behavior characteristics and customer behavior characteristics are extracted from the business visit data, the target salesperson behavior characteristics and customer behavior characteristics are aligned, and a customer behavior response value is generated.

[0076] In some embodiments, please refer to Figure 4The step of extracting target salesperson behavior features and customer behavior features from the business visit data, aligning the target salesperson behavior features and customer behavior features, and generating customer behavior response values ​​includes the following steps S401-S403: S401, extracting target salesperson behavior features and customer behavior features from the business visit data; the target salesperson behavior features include check-in timestamp, check-in location, and a first customer identifier provided by the target salesperson; the customer behavior features include customer location, customer response timestamp, and a second customer identifier extracted from the customer's response information; S402. If the time difference between the check-in timestamp and the customer response timestamp is less than a preset duration, the distance difference between the check-in location and the customer location is less than a preset distance threshold, and the first customer identifier and the second customer identifier are the same, then it is marked as a pairing event. S403. Based on the time difference between the check-in timestamp and the customer response timestamp, the distance between the check-in location and the customer's location, and the consistency judgment result of the first customer identifier and the second customer identifier, generate a customer behavior response value.

[0077] Here, aligning the behavioral characteristics of the target marketer with those of the customer is crucial for determining whether the marketer's claimed visit behavior (e.g., "visiting customer A in community A at 9:00 AM") truly corresponds to the customer's actual behavior (e.g., "customer A reported receiving the visit in community A at 9:10 AM"). Ultimately, the "customer behavior response value" quantifies the closeness of this association, providing a key basis for anti-fraud by verifying whether the behaviors of both parties are consistent. The essence of this process is "spatiotemporal matching + identity verification".

[0078] Specifically, in this embodiment of the application, the behavioral characteristics of target marketers and customer behavioral characteristics are aligned and cross-validated through three dimensions.

[0079] Time alignment: The difference between the salesperson's check-in time (e.g., 9:00) and the customer's response time (e.g., 9:05) must be less than the preset time (e.g., 15 minutes) to avoid time discrepancies such as "salesperson check-in at midnight, customer only responds at noon" (which may be a fake visit). Spatial alignment: The distance between the salesperson's check-in location (GPS coordinates of Community A) and the customer's location (location when the customer submits feedback) must be less than a preset threshold (e.g., 500 meters) to avoid spatial contradictions such as "the salesperson checks in in the east of the city and the customer gives feedback in the west of the city"; Identity alignment: The customer identifier provided by the marketer (such as customer A's ID) must be consistent with the identifier in the customer response information (customer A's OpenID) to avoid identity fraud such as "the marketer visits customer A but uses customer B's feedback to fill in the gaps".

[0080] When all three conditions are met, it is marked as a "paired event" (highly correlated behavior). Then, based on the specific differences (time difference, distance difference) and identity consistency results, the customer behavior response value is calculated (e.g., the smaller the time difference, the closer the distance, and the more consistent the identity, the closer the response value is to 1).

[0081] Time alignment means that the time difference between the check-in timestamp and the customer response timestamp is less than a preset duration; spatial alignment means that the distance difference between the check-in location and the customer's location is less than a preset distance threshold; identity alignment means that the first customer identifier and the second customer identifier are consistent.

[0082] Specifically, if |δt| ≤ preset distance threshold (e.g., 15 min) and |δl| ≤ preset distance threshold (e.g., 1000 meters) and the OpenID is consistent, it is marked as a "pairing event". The higher the degree of fit, the smaller the customer behavior response value.

[0083] Here, δt represents the time difference between the check-in timestamp and the customer response timestamp, and δl represents the distance difference between the check-in location and the customer's location.

[0084] Define customer behavior response value R cust = 1 – (α·|δt| + β·|δl| + γ·Δ openid ); where; δt: time difference (min), δl: distance difference (m), Δ openid : 0 or 1, 1 for consistency, 0 for inconsistency; α represents the time weight coefficient; β represents the distance weight coefficient; γ represents the identity weight coefficient; for example, α = 1 / 15, β = 1 / 1000, γ = 1. Result R cust ∈ [0,1], the smaller the value, the less closely it fits and the more human intervention is needed.

[0085] In step S106, the communication record forgery score, check-in trajectory curvature, device fraud score, and customer behavior response value are used as fraud indicators to determine the fraud detection results of the target salesperson's visit business.

[0086] In some embodiments, the step of using the communication record forgery score, check-in trajectory curvature, device fraud score, and customer behavior response value as fraud indicators to determine the fraud detection result of the target salesperson's visit business includes: Based on the pre-set weights corresponding to the fraud indicators, the fraud indicators are weighted and summed to determine the final risk score; The warning level in the fraud detection results is determined based on the final risk score; different warning levels correspond to different score ranges.

[0087] In some embodiments, the step of using the communication record forgery score, check-in trajectory curvature, device fraud score, and customer behavior response value as fraud indicators to determine the fraud detection result of the target salesperson's visit business includes: Determine whether the communication record forgery score, check-in trajectory curvature, device fraud score, and customer behavior response value, which are used as fraud indicators, are abnormal. If multiple fraud indicators are abnormal, the correlation analysis results in the fraud detection results are determined to be abnormal.

[0088] In some embodiments, communication record forgery scores, check-in trajectory curvature, device fraud scores, and customer behavior response values ​​are used as fraud indicators and mapped to rows and columns of a matrix to form a multidimensional association table. For example, please refer to Table 1 below: Table 1

[0089] In some embodiments, each cell stores a binary state (0 / 1) or a probability value (0–1), and a threshold is used to determine whether the fraud indicator is abnormal.

[0090] In some embodiments, the final risk score (Risk) is calculated by summing all fraud indicators in the matrix and combining them with their weights. Score : Risk Score = Σ(cell value × weight) / total weight; For example: Risk Score = 0.3·F forgery + 0.3·|κ| + 0.2·device risk +0.2 R cust Where κ is the trajectory curvature, device risk R is the score for device fraud. cust F represents the customer behavior response value. forgery To falsify scores for communication records.

[0091] In some embodiments, the final risk score is converted to a range of 0-100 and a three-level early warning mechanism is implemented: 0-30 points: green alert, normal passage; 30-70 points: orange alert, push manual review work order (including evidence package); 70-100 points: red interception, record risk control log.

[0092] In some embodiments, the final risk score can be determined by weighting and summing only the abnormal fraud indicators based on the pre-defined weights corresponding to the fraud indicators. In some embodiments, correlation analysis is also performed based on multiple fraud indicators to locate fraud patterns through matrix row and column correlation. For example, if both "spatiotemporal matching" and "semantic consistency" are abnormal, it is determined to be a forged visit.

[0093] In this embodiment, the two dimensions of "quantitative scoring" and "qualitative correlation" complement each other, jointly improving the accuracy and interpretability of anti-fraud judgment.

[0094] Weighted summation is used to determine the warning level and quantify risk scoring. In scenarios where the risk level of visited business needs to be "quantitatively ranked", such as when processing salesperson visit data in batches, high-risk business can be quickly screened out by risk score for priority verification, thereby improving anti-fraud efficiency.

[0095] Multi-indicator anomaly detection correlation analysis is performed, and an independent anomaly threshold is set for each fraud indicator (e.g., communication record forgery score > 0.7 is abnormal, trajectory curvature > 0.5 is abnormal, device fraud score > 0.6 is abnormal, and customer behavior response value < 0.3 is abnormal). Each indicator is judged to be abnormal. If two or more indicators are abnormal at the same time (e.g., "high forgery score + high device risk" or "abnormal trajectory curvature + low customer response value"), it is judged as "correlation anomaly" (i.e., multi-dimensional cross-validation all points to fraud, and the risk credibility is higher).

[0096] For example, a slightly high equipment fraud score for a certain business (single anomaly) may be a misjudgment, but "high equipment risk + abnormal trajectory curvature + low customer response value" (multiple anomalies) can almost certainly indicate fraud, thus avoiding misjudgments due to fluctuations in a single indicator.

[0097] The synergy of these two approaches combines quantitative and qualitative methods, enhancing the reliability and usability of anti-fraud measures.

[0098] Based on the same inventive concept, this application also provides a visit business anti-fraud detection device corresponding to the visit business anti-fraud detection method. Since the principle of the device in this application is similar to the visit business anti-fraud detection method described above in this application, the implementation of the device can refer to the implementation of the method, and the repeated parts will not be described again.

[0099] Please refer to Figure 5 , Figure 5 This application shows a schematic diagram of the anti-fraud detection device for visitor services according to an embodiment of the present application. The device includes: The acquisition module 501 is used to acquire business visit data of the target marketers; the business visit data includes: visit check-in data of business applications, screenshots of communication records and evaluation records of communication applications; the visit check-in data includes check-in location, check-in timestamp, stay duration, visit purpose, visit method, visit content and device characteristics; The first determining module 502 is used to process the communication record screenshot of the communication application based on the image detection channel and the semantic detection channel, and determine the communication record forgery score of the communication record screenshot; The second determining module 503 is used to determine the curvature of the target salesperson's check-in trajectory based on the check-in location in the visit check-in data; the curvature of the check-in trajectory represents the degree of curvature of the GPS check-in trajectory; The third determining module 504 is used to determine the equipment fraud score based on the equipment characteristics in the visit check-in data and in combination with the trained equipment risk assessment model. The generation module 505 is used to extract the target salesperson behavior characteristics and customer behavior characteristics from the business visit data, align the target salesperson behavior characteristics and customer behavior characteristics, and generate a customer behavior response value; the customer behavior response value is used to characterize the matching degree between customer behavior and salesperson visit behavior; The fourth determining module 506 is used to determine the fraud detection results of the target salesperson's visit business by using the communication record forgery score, check-in trajectory curvature, device fraud score, and customer behavior response value as fraud indicators.

[0100] In some embodiments, in the visitor service anti-fraud detection device, the first determining module, when processing the communication record screenshot of the communication application based on the image detection channel and the semantic detection channel, and determining the communication record forgery score of the communication record screenshot, is specifically used for: Based on the image detection channel, the tampering area features in the communication record screenshot of the communication application are extracted, and the image forgery probability of the communication record screenshot is determined based on the extracted tampering area features; Text is extracted from the communication record screenshots based on the semantic detection channel; target fields related to the visit are extracted from the visit check-in data and evaluation records to form a visit summary; Perform semantic consistency verification on the text in the communication record screenshot and the visit summary to obtain the semantic consistency probability; Based on the image forgery probability and semantic consistency probability, the communication record forgery score of the communication record screenshot is determined.

[0101] In some embodiments, in the visitor service anti-fraud detection device, the first determining module, when extracting tampered area features from a screenshot of a communication record of the communication application based on an image detection channel, and determining the image forgery probability of the communication record screenshot based on the extracted tampered area features, is specifically used for: The communication record screenshots of the aforementioned communication application are preprocessed to generate compressed images; The pixel-level residual between the original communication record screenshot and the compressed image is calculated to initially locate the tamper-sensitive areas in the image, thus obtaining the preprocessed communication record screenshot; the weight of the tamper-sensitive areas in the preprocessed communication record screenshot is greater than the weight of the normal areas; The pre-processed communication record screenshots are processed by a pre-trained image processing model to obtain a heatmap of the tamper-sensitive area, and the image forgery probability of the communication record screenshots is output.

[0102] In some embodiments, in the visitor service anti-fraud detection device, the first determining module, when performing semantic consistency verification on the text in the communication record screenshot and the visit summary to obtain the semantic consistency probability, is specifically used for: Identify the text in the screenshot of the communication record and the target entity in the visit summary; Count the number of target entities that match the text in the screenshot of the communication record and the visit summary; Based on the number of matched target entities and the total number of target entities, the semantic consistency probability is calculated.

[0103] In some embodiments, in the visit business anti-fraud detection device, the second determining module, when determining the curvature of the target salesperson's check-in trajectory based on the check-in location in the visit check-in data, is specifically used for: Based on the check-in timestamps corresponding to the check-in locations in the visit check-in data, the check-in locations are connected in chronological order to form the GPS check-in trajectory of the target marketer; The GPS check-in trajectory is treated as a planar curve, and the curvature of the check-in trajectory is calculated.

[0104] In some embodiments, in the visit business anti-fraud detection device, the third determining module, when determining the device fraud score based on the device characteristics in the visit check-in data and in conjunction with the trained device risk assessment model, is specifically used for: The device features in the visit check-in data are input into the trained device risk assessment model. The device risk assessment model processes the device features and outputs a device fraud score. The device characteristics are multi-dimensional device fingerprints collected by the business application when the terminal starts up, including device ID, model, MAC, IMEI, system patch level, root status, proxy marker, VPN marker, and sensor deviation.

[0105] In some embodiments, in the visit business anti-fraud detection device, the generation module, when extracting the target salesperson behavior features and customer behavior features from the business visit data, aligning the target salesperson behavior features and customer behavior features, and generating customer behavior response values, is specifically used to: extract the target salesperson behavior features and customer behavior features from the business visit data; the target salesperson behavior features include a check-in timestamp, a check-in location, and a first customer identifier provided by the target salesperson; the customer behavior features include the customer location, a customer response timestamp, and a second customer identifier extracted from the customer's response information; If the time difference between the check-in timestamp and the customer response timestamp is less than a preset duration, the distance difference between the check-in location and the customer's location is less than a preset distance threshold, and the first customer identifier and the second customer identifier are the same, then it is marked as a pairing event; Based on the time difference between the check-in timestamp and the customer response timestamp, the distance between the check-in location and the customer's location, and the consistency judgment result of the first customer identifier and the second customer identifier, a customer behavior response value is generated.

[0106] In some embodiments, in the visit business anti-fraud detection device, the fourth determining module, when using the communication record forgery score, check-in trajectory curvature, device fraud score, and customer behavior response value as fraud indicators to determine the fraud detection result of the target salesperson's visit business, is specifically used for: Based on the pre-set weights corresponding to the fraud indicators, the fraud indicators are weighted and summed to determine the final risk score; The warning level in the fraud detection results is determined based on the final risk score; different warning levels correspond to different score ranges.

[0107] In some embodiments, in the visit business anti-fraud detection device, the fourth determining module, when using the communication record forgery score, check-in trajectory curvature, device fraud score, and customer behavior response value as fraud indicators to determine the fraud detection result of the target salesperson's visit business, is specifically used for: Determine whether the communication record forgery score, check-in trajectory curvature, device fraud score, and customer behavior response value, which are used as fraud indicators, are abnormal. If multiple fraud indicators are abnormal, the correlation analysis results in the fraud detection results are determined to be abnormal. Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the systems and devices described above can be referred to the corresponding processes in the method embodiments, and will not be repeated here. In the several embodiments provided in this application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. The device embodiments described above are merely illustrative. For example, the division of modules is only a logical functional division; in actual implementation, there may be other division methods. Furthermore, multiple modules or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed mutual coupling or direct coupling or communication connection can be through some communication interfaces; the indirect coupling or communication connection of devices or modules can be electrical, mechanical, or other forms.

[0108] The modules described as separate components may or may not be physically separate. The components shown as modules may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0109] In addition, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.

[0110] If the aforementioned functions are implemented as software functional units and sold or used as independent products, they can be stored in a processor-executable, non-volatile, computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, a platform server, or a network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, ROM, RAM, magnetic disks, or optical disks.

[0111] The above are merely specific embodiments of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A method for detecting fraud in business visits, characterized in that, The method includes: Obtain business visit data from target marketers; the business visit data includes: visit check-in data from business applications, screenshots of communication records from communication applications, and evaluation records; Based on the image detection channel and semantic detection channel, the communication record screenshots of the communication application are processed to determine the communication record forgery score of the communication record screenshots; Based on the check-in locations in the visit check-in data, the curvature of the target salesperson's check-in trajectory is determined; the curvature of the check-in trajectory represents the degree of bending of the GPS check-in trajectory. Based on the device characteristics in the visit check-in data, and combined with the trained device risk assessment model, the device fraud score is determined. Extract the target salesperson behavior characteristics and customer behavior characteristics from the business visit data, align the target salesperson behavior characteristics and customer behavior characteristics, and generate a customer behavior response value; the customer behavior response value is used to characterize the matching degree between customer behavior and salesperson visit behavior; The fraud detection results of the target salesperson's visit business are determined by using the communication record forgery score, check-in trajectory curvature, device fraud score, and customer behavior response value as fraud indicators.

2. The anti-fraud detection method for visitation business according to claim 1, characterized in that, The process of processing communication record screenshots of the communication application based on image detection channels and semantic detection channels, and determining the communication record forgery score of the communication record screenshots, includes: Based on the image detection channel, the tampering area features in the communication record screenshot of the communication application are extracted, and the image forgery probability of the communication record screenshot is determined based on the extracted tampering area features; Text is extracted from the communication record screenshots based on the semantic detection channel; target fields related to the visit are extracted from the visit check-in data and evaluation records to form a visit summary; Perform semantic consistency verification on the text in the communication record screenshot and the visit summary to obtain the semantic consistency probability; Based on the image forgery probability and semantic consistency probability, the communication record forgery score of the communication record screenshot is determined.

3. The visit business anti-fraud detection method according to claim 2, characterized in that, The step of extracting tampered region features from the communication record screenshot of the communication application based on the image detection channel, and determining the image forgery probability of the communication record screenshot based on the extracted tampered region features, includes: The communication record screenshots of the aforementioned communication application are preprocessed to generate compressed images; The pixel-level residual between the original communication record screenshot and the compressed image is calculated to initially locate the tamper-sensitive areas in the image, thus obtaining the preprocessed communication record screenshot; the weight of the tamper-sensitive areas in the preprocessed communication record screenshot is greater than the weight of the normal areas; The pre-processed communication record screenshots are processed by a pre-trained image processing model to obtain a heatmap of the tamper-sensitive area, and the image forgery probability of the communication record screenshots is output.

4. The visit business anti-fraud detection method according to claim 2, characterized in that, The step of performing semantic consistency verification on the text in the communication record screenshot and the visit summary to obtain the semantic consistency probability includes: Identify the text in the screenshot of the communication record and the target entity in the visit summary; Count the number of target entities that match the text in the screenshot of the communication record and the visit summary; Based on the number of matched target entities and the total number of target entities, the semantic consistency probability is calculated.

5. The anti-fraud detection method for visitation business according to claim 1, characterized in that, The step of determining the curvature of the target marketer's check-in trajectory based on the check-in locations in the visit check-in data includes: Based on the check-in timestamps corresponding to the check-in locations in the visit check-in data, the check-in locations are connected in chronological order to form the GPS check-in trajectory of the target marketer; The GPS check-in trajectory is treated as a planar curve, and the curvature of the check-in trajectory is calculated.

6. The anti-fraud detection method for visitation business according to claim 1, characterized in that, The process of determining the device fraud score based on device characteristics in the visit check-in data and in conjunction with the trained device risk assessment model includes: The device features in the visit check-in data are input into the trained device risk assessment model. The device risk assessment model processes the device features and outputs a device fraud score. The device characteristics are multi-dimensional device fingerprints collected by the business application when the terminal starts up, including device ID, model, MAC, IMEI, system patch level, root status, proxy marker, VPN marker, and sensor deviation.

7. The anti-fraud detection method for visitation business according to claim 1, characterized in that, Extracting target salesperson behavior features and customer behavior features from the business visit data, aligning the target salesperson behavior features and customer behavior features, and generating customer behavior response values ​​includes: extracting target salesperson behavior features and customer behavior features from the business visit data; the target salesperson behavior features include check-in timestamp, check-in location, and a first customer identifier provided by the target salesperson; the customer behavior features include customer location, customer response timestamp, and a second customer identifier extracted from the customer's response information; If the time difference between the check-in timestamp and the customer response timestamp is less than a preset duration, the distance difference between the check-in location and the customer's location is less than a preset distance threshold, and the first customer identifier and the second customer identifier are the same, then it is marked as a pairing event; Based on the time difference between the check-in timestamp and the customer response timestamp, the distance between the check-in location and the customer's location, and the consistency judgment result of the first customer identifier and the second customer identifier, a customer behavior response value is generated.

8. The anti-fraud detection method for visitation business according to claim 1, characterized in that, The method of using the communication record forgery score, check-in trajectory curvature, device fraud score, and customer behavior response value as fraud indicators to determine the fraud detection results of the target salesperson's visit business includes: Based on the pre-set weights corresponding to the fraud indicators, the fraud indicators are weighted and summed to determine the final risk score; The warning level in the fraud detection results is determined based on the final risk score; different warning levels correspond to different score ranges.

9. The visit business anti-fraud detection method according to claim 1 or 8, characterized in that, The method of using the communication record forgery score, check-in trajectory curvature, device fraud score, and customer behavior response value as fraud indicators to determine the fraud detection results of the target salesperson's visit business includes: Determine whether the communication record forgery score, check-in trajectory curvature, device fraud score, and customer behavior response value, which are used as fraud indicators, are abnormal. If multiple fraud indicators are abnormal, the correlation analysis results in the fraud detection results are determined to be abnormal.

10. A visitor fraud detection device, characterized in that, The device includes: The acquisition module is used to acquire business visit data of target marketers; the business visit data includes: visit check-in data of business applications, screenshots of communication records and evaluation records of communication applications; the visit check-in data includes check-in location, check-in timestamp, stay duration, visit purpose, visit method, visit content and device characteristics; The first determining module is used to process the communication record screenshots of the communication application based on the image detection channel and the semantic detection channel, and determine the communication record forgery score of the communication record screenshots; The second determining module is used to determine the curvature of the target salesperson's check-in trajectory based on the check-in locations in the visit check-in data; the curvature of the check-in trajectory represents the degree of curvature of the GPS check-in trajectory; The third determination module is used to determine the equipment fraud score based on the equipment characteristics in the visit check-in data and in combination with the trained equipment risk assessment model. The generation module is used to extract the target salesperson behavior characteristics and customer behavior characteristics from the business visit data, align the target salesperson behavior characteristics and customer behavior characteristics, and generate a customer behavior response value; the customer behavior response value is used to characterize the matching degree between customer behavior and salesperson visit behavior; The fourth determination module is used to determine the fraud detection results of the target salesperson's visit business by using the communication record forgery score, check-in trajectory curvature, device fraud score, and customer behavior response value as fraud indicators.