Group identification method and device, program product and electronic equipment

By constructing a directed graph and performing cluster analysis, abnormal group accounts are identified, solving the problem that existing technologies cannot adapt to complex and ever-changing social risk control scenarios, and achieving accurate identification and control of violations.

CN121743903APending Publication Date: 2026-03-27HANGZHOU NETEASE CLOUD MUSIC TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-09-25
Publication Date
2026-03-27

AI Technical Summary

Technical Problem

In existing technologies, methods for identifying violations based on internet social platforms are not applicable to complex and ever-changing social risk control scenarios, and cannot effectively identify groups that use multiple accounts to commit violations.

Method used

By identifying user device account switching data, a directed graph is constructed and cluster analysis is performed to identify abnormal group accounts. The group relationship is dynamically updated using the user device account switching relationship. Combined with the LOUVAIN clustering algorithm and node and edge weight analysis, abnormal group accounts are identified.

Benefits of technology

It enables precise identification and control of groups engaging in illegal activities, improves the convenience and adaptability of account management, and can adapt to complex and ever-changing social risk control scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121743903A_ABST
    Figure CN121743903A_ABST
Patent Text Reader

Abstract

The invention discloses a group identification method and device, a computer program product and electronic equipment, and relates to the technical field of computers. The method comprises the following steps: determining account switching data corresponding to one or more pieces of user equipment; the account switching data comprises an account switching relationship corresponding to a historical use account of the user equipment; according to the account switching data corresponding to each piece of user equipment, constructing a directed graph taking a historical use account as a node; and performing clustering analysis on the directed graph to obtain a clustering analysis result, and determining an abnormal group account from the historical use accounts based on the clustering analysis result. According to the method and the device, the group relationship is clustered based on the account switching relationship of the user equipment, the group relationship can be updated in real time along with the dynamically changing user account switching behavior, and the method and the device can be well suitable for complex and changeable social risk control scenes.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of this disclosure relate to the field of computer technology, and more specifically, to group identification methods, group identification devices, computer program products, and electronic devices. Background Technology

[0002] This section is intended to provide background or context for embodiments of the invention as set forth in the claims. The description herein is not an admission that it is prior art simply because it is included in this section.

[0003] With the development of internet social products, illegal activities on these platforms have gradually come to light. Individuals involved in these illegal activities typically use multiple accounts, phone numbers, and ID cards to evade common detection methods. Accurate identification of these groups is an effective way to combat them.

[0004] In related technologies, group relationships are usually built through static data of product registration and login. These relationships are relatively fixed and cannot be applied to complex and ever-changing social risk control scenarios.

[0005] It should be noted that the information disclosed in the background section above is only used to enhance the understanding of the background of this disclosure, and therefore may include information that does not constitute prior art known to those skilled in the art. Summary of the Invention

[0006] This disclosure provides a group identification method, group identification device, computer program product, and electronic device, thereby at least partially solving the problem that related technologies cannot be applied to complex and ever-changing social risk control scenarios.

[0007] Other features and advantages of this disclosure will become apparent from the following detailed description, or may be learned in part from practice of this disclosure.

[0008] According to a first aspect of this disclosure, a group identification method is provided, the method comprising: determining account switching data corresponding to one or more user devices; the account switching data including account switching relationships corresponding to historically used accounts of the user devices; constructing a directed graph with the historically used accounts as nodes based on the account switching data corresponding to each user device; performing cluster analysis on the directed graph to obtain cluster analysis results, and identifying abnormal group accounts from the historically used accounts based on the cluster analysis results.

[0009] In one exemplary embodiment of this disclosure, determining the account switching data corresponding to one or more user devices includes: collecting user behavior data to determine the account usage data corresponding to one or more user devices; and determining the account switching data corresponding to each user device based on the account usage data corresponding to each user device.

[0010] In an exemplary embodiment of this disclosure, the step of constructing a directed graph with the historical user accounts as nodes based on the account switching data corresponding to each user device includes: connecting the nodes corresponding to each historical user account according to the account switching relationship corresponding to each historical user account to form multiple directed edges to obtain a directed graph with the historical user accounts as nodes; wherein, the directed edge corresponds to the account switching device, and the account switching device is the user device that switches from one historical user account connected to the directed edge to another historical user account connected to the directed edge.

[0011] In an exemplary embodiment of this disclosure, the step of performing cluster analysis on the directed graph to obtain cluster analysis results includes: determining the weight of the node corresponding to each of the historical user accounts and / or the weight of each of the directed edges; and performing cluster analysis on the directed graph based on the weight of the node corresponding to each of the historical user accounts and / or the weight of each of the directed edges to obtain cluster analysis results.

[0012] In one exemplary embodiment of this disclosure, determining the weight of the node corresponding to each of the historical accounts and / or the weight of each of the directed edges includes: determining the weight of the node corresponding to each of the historical accounts based on the first duration data and the second duration data corresponding to each of the historical accounts; wherein the first duration data is the time elapsed since the account switching time, and the second duration data is the account activity duration.

[0013] In one exemplary embodiment of this disclosure, determining the weight of the node corresponding to each of the historical accounts and / or the weight of each of the directed edges includes: determining the weight of each directed edge based on the usage duration of the two historical accounts connected to each directed edge on the account switching device and the risk coefficient corresponding to the account switching device.

[0014] In one exemplary embodiment of this disclosure, determining abnormal group accounts from the historical usage accounts based on the clustering analysis results includes: dividing the historical usage accounts into multiple groups based on the clustering analysis results; determining a group containing known illegal industry accounts from the multiple groups; and identifying the historical usage accounts in the group containing known illegal industry accounts as abnormal group accounts.

[0015] According to a second aspect of this disclosure, a group identification device is disclosed, the device comprising: a switching data determination module, configured to determine account switching data corresponding to one or more user devices; the account switching data including account switching relationships corresponding to historically used accounts of the user devices; a directed graph construction module, configured to construct a directed graph with the historically used accounts as nodes based on the account switching data corresponding to each user device; and a group account identification module, configured to perform cluster analysis on the directed graph to obtain cluster analysis results, and determine abnormal group accounts from the historically used accounts based on the cluster analysis results.

[0016] According to a third aspect of the present disclosure, a computer program product is disclosed, including a computer program that, when executed by a processor, implements the crowd identification method of the first aspect and its possible implementations.

[0017] According to a fourth aspect of the present disclosure, an electronic device is disclosed, comprising: a processor; and a memory for storing executable instructions of the processor; wherein the processor is configured to execute the crowd identification method of the first aspect and its possible implementations by executing the executable instructions.

[0018] The technical solution disclosed herein has the following beneficial effects:

[0019] In the aforementioned group identification process, account switching data corresponding to one or more user devices is determined. This account switching data includes account switching relationships corresponding to historical accounts used by the user devices. Based on the account switching data corresponding to each user device, a directed graph is constructed with the historical accounts used as nodes. Cluster analysis is performed on the directed graph to obtain cluster analysis results, and abnormal group accounts are identified from the historical accounts used based on these results. On one hand, this disclosure clusters group relationships based on user device account switching relationships. These group relationships can be updated in real time following dynamically changing user account switching behavior, exhibiting strong resistance to illegal activities and being well-suited for complex and ever-changing social risk control scenarios. On the other hand, this disclosure identifies abnormal group accounts from historical accounts based on cluster analysis results, which facilitates targeted management of abnormal group accounts and improves the convenience of account management.

[0020] It should be understood that the above general description and the following detailed description are merely exemplary and do not limit this disclosure. Attached Figure Description

[0021] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this disclosure and, together with the description, serve to explain the principles of this disclosure. It is obvious that the drawings described below are merely some embodiments of this disclosure, and those skilled in the art can obtain other drawings based on these drawings without any inventive effort.

[0022] Figure 1 A flowchart illustrating a group identification method in this exemplary embodiment is shown.

[0023] Figure 2 This illustration shows a flowchart of a process for determining account switching data corresponding to one or more user devices in this exemplary embodiment.

[0024] Figure 3 This exemplary embodiment illustrates a directed graph with historically used accounts as nodes;

[0025] Figure 4A This illustration shows an architecture diagram for controlling illegal industries in this exemplary embodiment;

[0026] Figure 4B This illustration shows an architecture diagram of a group identification method in this exemplary embodiment;

[0027] Figure 5 This illustration shows a flowchart of an abnormal group account identification method in this exemplary embodiment;

[0028] Figure 6 This diagram illustrates a structural block diagram of a group identification device according to this exemplary embodiment;

[0029] Figure 7 An electronic device for implementing the above-described crowd identification method is shown in this exemplary embodiment.

[0030] In the accompanying drawings, the same or corresponding reference numerals indicate the same or corresponding parts. Detailed Implementation

[0031] The principles and spirit of this disclosure will now be described with reference to several exemplary embodiments. It should be understood that these embodiments are given merely to enable those skilled in the art to better understand and implement this disclosure, and are not intended to limit the scope of this disclosure in any way. Rather, these embodiments are provided to make this disclosure more thorough and complete, and to fully convey the scope of this disclosure to those skilled in the art.

[0032] Those skilled in the art will recognize that embodiments of this disclosure can be implemented as an apparatus, device, method, or computer program product. Therefore, this disclosure can be specifically implemented in the following forms: entirely hardware, entirely software (including firmware, resident software, microcode, etc.), or a combination of hardware and software.

[0033] According to embodiments of this disclosure, a group identification method, a group identification device, a computer program product, and an electronic device are proposed.

[0034] The number of any elements in the accompanying drawings is for illustrative purposes only and not as a limitation, and any naming is for distinction only and has no limiting meaning.

[0035] The principles and spirit of this disclosure will be explained in detail below with reference to several representative embodiments. Invention Overview

[0037] In the related technologies disclosed herein, group relationships are constructed through static data from product registration and login. These relationships are relatively fixed and cannot be applied to complex and ever-changing social risk control scenarios.

[0038] To address the aforementioned issues, this disclosure proposes a group identification method. Based on the account switching relationships of user devices, group relationships are clustered. These group relationships can be updated in real time following the dynamically changing user account switching behavior, exhibiting strong resistance against illegal industries and being well-suited for complex and ever-changing social risk control scenarios. Furthermore, by identifying abnormal group accounts from historically used accounts based on the clustering analysis results, it is beneficial to conduct targeted management of abnormal group accounts, thereby improving the convenience of account management.

[0039] Application Scenarios Overview

[0040] It should be noted that the following application scenarios are shown only to facilitate understanding of the spirit and principles of this disclosure, and the implementation of this disclosure is not limited in any way. Rather, the implementation of this disclosure can be applied to any applicable scenario. For example, it can be applied to social risk control scenarios such as fraudulent inducement behavior, traffic redirection behavior, fraudulent transactions, and multi-level marketing campaigns.

[0041] Exemplary methods

[0042] The following section, in conjunction with the application scenarios described above, provides reference... Figure 1 This describes a group identification method according to exemplary embodiments of the present disclosure.

[0043] Please see Figure 1 , Figure 1 The diagram shown is a flowchart illustrating a group identification method according to an exemplary embodiment of this disclosure. Figure 1As shown, this group identification method may include:

[0044] Step S110: Determine account switching data corresponding to one or more user devices; the account switching data includes the account switching relationship corresponding to the user device's historical accounts.

[0045] Step S120: Based on the account switching data corresponding to each user device, construct a directed graph with historically used accounts as nodes;

[0046] Step S130: Perform cluster analysis on the directed graph to obtain the cluster analysis results, and identify abnormal group accounts from the historical user accounts based on the cluster analysis results.

[0047] Implementation Figure 1 The group identification method shown clusters group relationships based on the account switching relationship of user devices. The group relationships can be updated in real time with the dynamic changes in user account switching behavior, which has strong countermeasures against illegal industries and can be well applied to complex and ever-changing social risk control scenarios. Based on the cluster analysis results, abnormal group accounts are identified from historical accounts, which is conducive to targeted control of abnormal group accounts and can improve the convenience of account management.

[0048] These steps are described in detail below.

[0049] In step S110, account switching data corresponding to one or more user devices is determined; the account switching data includes the account switching relationship corresponding to the user device's historical accounts.

[0050] The user equipment can be a mobile phone, tablet computer, personal computer, smart wearable device, game console, or other terminal device, and this disclosure does not impose specific limitations on it.

[0051] The account switching data includes the account switching relationships corresponding to the user device's historically used accounts. Optionally, historically used accounts may include accounts that the user device has logged into and then logged out of, as well as accounts that are currently logged into.

[0052] For example, user behavior data can be acquired, and account switching data corresponding to one or more user devices can be determined from the user behavior data.

[0053] In one alternative implementation, such as Figure 2 As shown, the above-mentioned determination of account switching data corresponding to one or more user devices can be achieved through the following steps:

[0054] Step S210: Collect user behavior data and determine the account usage data corresponding to one or more user devices;

[0055] Step S220: Determine the account switching data corresponding to each user device based on the account usage data corresponding to each user device.

[0056] Figure 2 The steps shown identify user device account switching behavior over time to facilitate dynamic detection of user behavior and improve the real-time performance and accuracy of group identification.

[0057] User behavior data may include, but is not limited to, login, registration, and playback behavior data. This behavior data may include information that can uniquely identify the device and user, such as device identifiers and account identifiers. For example, the device identifier can be generated using unique information such as the device's MAC (Media Access Control Address) address to ensure global uniqueness.

[0058] Optionally, user behavior data can be collected through event tracking. When collecting user behavior data, user actions can be recorded over a timeline. It's important to note that the user behavior data collected here is not user-generated content; it's a platform-wide capability and will not record private information such as user messages.

[0059] After collecting user behavior data, account usage data for one or more user devices can be extracted from the user behavior data. This allows for the determination of account switching data for each user device based on the account usage data. Account usage data may include, but is not limited to, account identifiers, login times, and other information. Optionally, the account switching relationships corresponding to historically used accounts on a user device can be determined based on the login times of those accounts.

[0060] Optionally, user behavior data can be collected periodically or in real time, such as collecting data once a day. Furthermore, based on the latest collected user behavior data, the account usage data corresponding to each user device can be updated, and in response to the update operation of the account usage data corresponding to each user device, the account switching data corresponding to each user device can be updated, in order to dynamically maintain group relationships and enhance the ability to combat illegal activities.

[0061] In step S120, a directed graph with historically used accounts as nodes is constructed based on the account switching data corresponding to each user device.

[0062] A directed graph is a graph consisting of a set of nodes and a set of directed edges, which can represent the relationships between nodes.

[0063] In one optional implementation, the above-mentioned construction of a directed graph with historically used accounts as nodes based on the account switching data corresponding to each user device can be achieved through the following steps: according to the account switching relationship corresponding to each historically used account, the nodes corresponding to each historically used account are connected to form multiple directed edges to obtain a directed graph with historically used accounts as nodes; wherein, the directed edge corresponds to the account switching device, and the account switching device is the user device that switches from one historically used account connected to another historically used account connected to the directed edge.

[0064] For example, such as Figure 3 As shown, a directed graph with historically used accounts as nodes is provided. The historically used accounts of user device A include account 1, account 2, and account 3. User device A acts as an account switching device, and the corresponding account switching relationships are: switching from account 1 to account 2, and switching from account 2 to account 3.

[0065] Optionally, the constructed directed graph can be stored in a graph database. Graph databases use vertices and edges as basic storage units, enabling efficient storage and retrieval of graph data. These databases may include, but are not limited to, GraphDB, Neo4j, and NEBULA. In practical applications, a suitable graph database can be selected to store the directed graph according to specific needs; this disclosure does not impose any specific limitations on this.

[0066] By constructing a directed graph with historically used accounts as nodes and devices used to switch accounts as edges, it is possible to perform clustering based on account switching relationships to identify groups.

[0067] In step S130, cluster analysis is performed on the directed graph to obtain the cluster analysis results, and abnormal group accounts are identified from the historical user accounts based on the cluster analysis results.

[0068] Among them, the cluster analysis results can be account segmentation results, and accounts that are grouped together can be identified as a group.

[0069] Optionally, this disclosure may employ the LOUVAIN clustering algorithm to perform clustering analysis on the directed graph, obtaining clustering results suitable for complex social scenarios. LOUVAIN clustering is a modularity-based community detection algorithm designed to maximize the modularity of the entire community network.

[0070] It should be noted that in practical applications, other clustering algorithms, such as LPA (label propagation algorithm) and HANP, may also be used in this disclosure, and this disclosure does not impose specific limitations on them.

[0071] In one optional implementation, the above-mentioned cluster analysis of the directed graph to obtain the cluster analysis results can be achieved through the following steps: determining the weight of the node corresponding to each historical user account and / or the weight of each directed edge; performing cluster analysis on the directed graph based on the weight of the node corresponding to each historical user account and / or the weight of each directed edge to obtain the cluster analysis results.

[0072] Optionally, the weight of the node corresponding to each historical account can be determined through the following steps: Based on the first duration data and the second duration data corresponding to each historical account, determine the weight of the node corresponding to each historical account; wherein, the first duration data is the time from the time of account switching to the current time, and the second duration data is the account's active duration.

[0073] Optionally, the first duration data can be negatively correlated with the node weight value, and the second duration data can be positively correlated with the node weight value. For example, this can be achieved by calculating... Determine the node weights. Where ΔQ1 represents the node weight value; T x This is the first duration data; T y The second duration data; α is the node weight control parameter, which can be set by the developers based on experience, and this disclosure does not impose specific limitations on it. Wherein, the second duration data T... y It can be represented by the monthly active days metric.

[0074] In the above steps, the node weights are derived from the account switching time and activity time, and this time data provides data support for cluster analysis.

[0075] Optionally, the weight of each directed edge can be determined by the following steps: based on the usage duration of the two historical accounts connected to each directed edge on the account switching device and the risk coefficient corresponding to the account switching device, determine the weight of each directed edge.

[0076] Optionally, the usage duration of a historical account on devices with account switching can be positively correlated with the weight of the corresponding directed edge. For example, this can be achieved by calculating ΔQ2 = βU. a U b Determine the edge weights. Here, ΔQ2 represents the node weight value; U a This indicates the duration of account A's usage across different devices; U b This represents the duration of account b's use on the corresponding account switching device; β is the edge weight control parameter, i.e., the risk coefficient corresponding to the account switching device, which can be set by the developers based on experience, and this disclosure does not impose specific limitations on it.

[0077] Optionally, different beta values ​​can be assigned to different accounts when switching devices. For example, when the account is switched to a registered or trusted device, the switching behavior is considered low-risk and a smaller beta value can be set; when the account is switched to a non-registered or non-trusted device, the switching behavior is considered high-risk and a larger beta value can be set.

[0078] In the above steps, the weight of the directed edge is positively correlated with the usage duration of the corresponding account before and after the device switching. This duration data provides data support for cluster analysis.

[0079] Optionally, when updating a directed graph, the weights of the nodes in the directed graph and / or the weights of each directed edge can be updated simultaneously to ensure the real-time nature of the data.

[0080] In one optional implementation, the above-mentioned identification of abnormal group accounts from historical usage accounts based on cluster analysis results can be achieved through the following steps: dividing historical usage accounts into multiple groups based on cluster analysis results; identifying groups containing known illegal industry accounts from the multiple groups; and identifying historical usage accounts in the groups containing known illegal industry accounts as abnormal group accounts.

[0081] For example, after dividing the historical usage accounts corresponding to one or more user devices into multiple groups, it can be determined whether the groups contain known illegal industry accounts, and the accounts in the groups containing known illegal industry accounts can be regarded as abnormal group accounts.

[0082] For example, the ratio between the number of known illegal industry accounts in the group and the total number of accounts in the corresponding group can also be determined; if the ratio for the group exceeds a preset ratio, the accounts in the group can be regarded as abnormal group accounts.

[0083] By using known accounts involved in illegal activities, abnormal group accounts can be identified, which facilitates the management of these accounts. For example, they can be blacklisted or restricted from switching devices, and their previously used or currently used devices can be subject to certain restrictions.

[0084] Optionally, the indicators involved in the group identification process can be integrated with other risk control indicators to achieve control over illegal industries.

[0085] For example, such as Figure 4AThe diagram illustrates an architecture for managing illegal industries, comprising a graph database layer, a group storage layer, and a risk control application layer. The graph database layer stores underlying data and generates group data, including but not limited to behavioral flow data, switching flow data, and graph data. The group storage layer stores the final results of group clustering, such as group identification information, for business risk control purposes, including but not limited to user device identifiers and the number of user devices within the group, and user account identifiers and the number of user accounts within the group. The risk control application layer identifies illegal industries and performs risk control, utilizing group information and other business indicators to achieve management of illegal industries.

[0086] For example, such as Figure 4B As shown, an architecture diagram for group identification is provided. It can extract behavior streams from user behavior, cleanse switching records from the behavior streams to obtain switching streams, and further construct a directed graph based on the switching streams. Through cluster analysis, groups are identified. User behavior can include actions such as login, registration, and playback. The behavior streams and switching streams can record the mapping relationship between user account identifiers and user device identifiers. The directed graph can be stored using a graph database.

[0087] like Figure 5 As shown, a flowchart for identifying abnormal group accounts is provided, which may include the following steps:

[0088] Step S501: Collect user behavior data and determine the account usage data corresponding to one or more user devices;

[0089] Step S502: Determine the account switching data for each user device based on the account usage data for each user device; the account switching data includes the account switching relationships corresponding to the historical accounts used by the user device.

[0090] Step S503: Based on the account switching relationship corresponding to each historical account, connect the nodes corresponding to each historical account to form multiple directed edges, so as to obtain a directed graph with historical accounts as nodes.

[0091] Step S504: Determine the weight of the node corresponding to each historical user account and / or the weight of each directed edge.

[0092] Step S505: Based on the weight of the node corresponding to each historical user account and / or the weight of each directed edge, perform cluster analysis on the directed graph to obtain the cluster analysis results, so as to divide the historical user accounts into multiple groups.

[0093] Step S506: Identify groups from multiple groups that contain known accounts involved in illegal activities, and designate historically used accounts from these groups as abnormal group accounts.

[0094] Implementing the embodiments of this disclosure, based on the account switching relationship of user devices, clusters group relationships. The group relationships can be updated in real time with the dynamically changing user account switching behavior, which has strong countermeasures against illegal industries and can be well applied to complex and ever-changing social risk control scenarios. Based on the cluster analysis results, abnormal group accounts are identified from historically used accounts, which is conducive to targeted control of abnormal group accounts and can improve the convenience of account management.

[0095] Exemplary device

[0096] After introducing the methods of exemplary embodiments of this disclosure, the following references are made. Figure 6 A group identification device according to an exemplary embodiment of the present disclosure will be described.

[0097] Please see Figure 6 , Figure 6 The diagram shown is a structural block diagram of a group identification device according to an exemplary embodiment of the present disclosure. Figure 6 As shown, a group identification device 600 according to an example embodiment of this disclosure includes: a switching data determination module 610, a directed graph construction module 620, and a group account identification module 630, wherein:

[0098] The handover data determination module 610 is used to determine account handover data corresponding to one or more user devices; the account handover data includes the account handover relationship corresponding to the historical accounts used by the user devices.

[0099] The directed graph construction module 620 is used to construct a directed graph with historically used accounts as nodes based on the account switching data corresponding to each user device.

[0100] The group account identification module 630 is used to perform cluster analysis on a directed graph, obtain cluster analysis results, and identify abnormal group accounts from historical accounts based on the cluster analysis results.

[0101] In an optional implementation, based on the aforementioned scheme, the switching data determination module 610 can be configured to: collect user behavior data, determine account usage data corresponding to one or more user devices; and determine account switching data corresponding to each user device based on the account usage data corresponding to each user device.

[0102] In an optional implementation, based on the aforementioned scheme, the directed graph construction module 620 can be configured to: connect the nodes corresponding to each historical user account according to the account switching relationship corresponding to each historical user account to form multiple directed edges, so as to obtain a directed graph with historical user accounts as nodes; wherein, the directed edge corresponds to the account switching device, and the account switching device is the user device that switches from one historical user account connected to the directed edge to another historical user account connected to the directed edge.

[0103] In an optional implementation, based on the aforementioned scheme, the group account identification module 630 further includes: a weight determination module, used to determine the weight of the node corresponding to each historical user account and / or the weight of each directed edge; and a clustering analysis module, used to perform clustering analysis on the directed graph based on the weight of the node corresponding to each historical user account and / or the weight of each directed edge, to obtain the clustering analysis result.

[0104] In an optional implementation, based on the aforementioned scheme, the weight determination module can be configured to: determine the weight of the node corresponding to each historical user account based on the first duration data and the second duration data corresponding to each historical user account; wherein, the first duration data is the duration from the account switching time to the current duration, and the second duration data is the account activity duration.

[0105] In an optional implementation, based on the aforementioned scheme, the weight determination module can be configured to: determine the weight of each directed edge based on the usage duration of the two historical accounts connected to each directed edge on the account switching device and the risk coefficient corresponding to the account switching device.

[0106] In an optional implementation, based on the aforementioned scheme, the group account identification module 630 can be configured to determine abnormal group accounts from historical accounts based on cluster analysis results, and to divide historical accounts into multiple groups based on cluster analysis results; determine the group containing known illegal industry accounts from the multiple groups; and identify historical accounts in the group containing known illegal industry accounts as abnormal group accounts.

[0107] Implementing the embodiments of this disclosure, based on the account switching relationship of user devices, clusters group relationships. The group relationships can be updated in real time with the dynamically changing user account switching behavior, which has strong countermeasures against illegal industries and can be well applied to complex and ever-changing social risk control scenarios. Based on the cluster analysis results, abnormal group accounts are identified from historically used accounts, which is conducive to targeted control of abnormal group accounts and can improve the convenience of account management.

[0108] It should be noted that although several modules or units of the group identification device have been mentioned in the detailed description above, this division is not mandatory. In fact, according to embodiments of this disclosure, the features and functions of two or more modules or units described above can be embodied in one module or unit. Conversely, the features and functions of one module or unit described above can be further divided and embodied by multiple modules or units.

[0109] Exemplary program product

[0110] Having introduced the apparatus of the exemplary embodiments of this disclosure, the program product of the exemplary embodiments of this disclosure will now be described.

[0111] Exemplary embodiments of this disclosure also provide a computer program product. The computer program product includes a computer program that, when executed by a processor, implements the aforementioned group identification method.

[0112] In one embodiment, the computer program product can be a tangible product containing a computer program, such as a computer-readable storage medium storing the computer program. The readable storage medium can be a storage medium based on electrical, magnetic, optical, electromagnetic, infrared, or other signals, including but not limited to: random access memory (RAM), read-only memory (ROM), magnetic tape, floppy disk, flash memory, hard disk drive (HDD), solid-state drive (SSD), etc. For example, the computer program product can be implemented as a non-volatile storage medium storing the computer program, such as read-only memory, NAND flash memory, etc.

[0113] In one implementation, the computer program product can be an intangible product containing a computer program. For example, the computer program product can be implemented as a virtual digital product, such as an executable file, installation package, or other digital file storing the computer program.

[0114] Computer program code can be written in one or more programming languages. Examples of programming languages ​​include C, Java, and C++. Program code can execute entirely on the user's computing device, partially on the user's computing device, or as a standalone software package. It can also execute partially on the user's computing device and partially on a remote computing device, or entirely on a remote computing device or server. In cases involving remote computing devices, the remote computing device can be connected to the user's computing device via any type of network, such as a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computing device (e.g., via an internet connection provided by a mobile network operator).

[0115] Computer programs can be carried or transmitted via signals such as electricity, magnetism, light, electromagnetic radiation, and infrared rays. Electronic devices can convert signals carrying computer programs into digital signals, thereby running the computer programs. When a computer program runs on an electronic device, its code causes the electronic device to execute (more specifically, the processor of the electronic device to execute) the method steps of various exemplary embodiments of this disclosure. Exemplarily, this may include the following steps:

[0116] Determine account switching data for one or more user devices; the account switching data includes the account switching relationships corresponding to the user devices' historical accounts.

[0117] Based on the account switching data corresponding to each user device, a directed graph is constructed with historically used accounts as nodes;

[0118] Cluster analysis is performed on the directed graph to obtain the cluster analysis results, and abnormal group accounts are identified from the historical accounts based on the cluster analysis results.

[0119] In one alternative implementation, based on the aforementioned scheme, determining the account switching data corresponding to one or more user devices can be achieved through the following steps: collecting user behavior data to determine the account usage data corresponding to one or more user devices; and determining the account switching data corresponding to each user device based on the account usage data corresponding to each user device.

[0120] In an optional implementation, based on the aforementioned scheme, a directed graph with historically used accounts as nodes is constructed according to the account switching data corresponding to each user device. This can be achieved through the following steps: according to the account switching relationship corresponding to each historically used account, the nodes corresponding to each historically used account are connected to form multiple directed edges to obtain a directed graph with historically used accounts as nodes; wherein, the directed edge corresponds to the account switching device, and the account switching device is the user device that switches from one historically used account connected to another historically used account connected to the directed edge.

[0121] In one optional implementation, based on the aforementioned scheme, cluster analysis is performed on the directed graph to obtain the cluster analysis results. This can be achieved through the following steps: determining the weight of the node corresponding to each historical user account and / or the weight of each directed edge; performing cluster analysis on the directed graph based on the weight of the node corresponding to each historical user account and / or the weight of each directed edge to obtain the cluster analysis results.

[0122] In one optional implementation, based on the aforementioned scheme, the weight of the node corresponding to each historical user account and / or the weight of each directed edge can be determined through the following steps: the weight of the node corresponding to each historical user account is determined according to the first duration data and the second duration data corresponding to each historical user account; wherein, the first duration data is the duration from the time of account switching to the current duration, and the second duration data is the duration of account activity.

[0123] In an optional implementation, based on the aforementioned scheme, the weight of the node corresponding to each historical user account and / or the weight of each directed edge can be determined by the following steps: determining the weight of each directed edge based on the usage duration of the two historical user accounts connected to each directed edge on the account switching device and the risk coefficient corresponding to the account switching device.

[0124] In an optional implementation, based on the aforementioned scheme, identifying abnormal group accounts from historical usage accounts based on cluster analysis results can be achieved through the following steps: dividing historical usage accounts into multiple groups based on cluster analysis results; identifying groups containing known illegal industry accounts from the multiple groups; in an optional implementation, based on the aforementioned scheme, historical usage accounts in the group containing known illegal industry accounts are identified as abnormal group accounts.

[0125] Implementing the embodiments of this disclosure, based on the account switching relationship of user devices, clusters group relationships. The group relationships can be updated in real time with the dynamically changing user account switching behavior, which has strong countermeasures against illegal industries and can be well applied to complex and ever-changing social risk control scenarios. Based on the cluster analysis results, abnormal group accounts are identified from historically used accounts, which is conducive to targeted control of abnormal group accounts and can improve the convenience of account management.

[0126] Exemplary electronic devices

[0127] Having introduced the group identification methods, apparatus, and program products of exemplary embodiments of the present disclosure, we will now introduce an electronic device according to another exemplary embodiment of the present disclosure.

[0128] An exemplary embodiment of this disclosure also provides an electronic device capable of implementing the above-described group identification method. The electronic device may include a processor and a memory. The memory stores executable instructions of the processor, such as program code. The processor executes the executable instructions to perform the method of this exemplary embodiment. Furthermore, the electronic device may also include a display for displaying a graphical user interface.

[0129] The following is for reference. Figure 7 The electronic device is illustrated by way of a general-purpose computing device. It should be understood that... Figure 7The electronic device 700 shown is merely an example and should not be construed as limiting the functionality and scope of use of the embodiments disclosed herein.

[0130] like Figure 7 As shown, the electronic device 700 may include: a processor 710, a memory 720, a bus 730, an I / O (input / output) interface 740, a network adapter 750, and a display 760.

[0131] The memory 720 may include volatile memory, such as RAM 721 and cache unit 722, and may also include non-volatile memory, such as ROM 723. The memory 720 may also include one or more program modules 724, including but not limited to: an operating system, one or more application programs, other program modules, and program data. Each or some combination of these examples may include an implementation of a network environment. For example, program module 724 may include the modules described above.

[0132] The processor 710 may include one or more processing units, such as an AP (Application Processor), a modem processor, a GPU (Graphics Processing Unit), an ISP (Image Signal Processor), a controller, an encoder, a decoder, a DSP (Digital Signal Processor), a baseband processor, and / or an NPU (Neural-Network Processing Unit).

[0133] The processor 710 can be used to execute executable instructions stored in the memory 720, such as performing any one or more method steps in this exemplary embodiment.

[0134] For example, processor 710 may perform the following steps:

[0135] Determine account switching data for one or more user devices; the account switching data includes the account switching relationships corresponding to the user devices' historical accounts.

[0136] Based on the account switching data corresponding to each user device, a directed graph is constructed with historically used accounts as nodes;

[0137] Cluster analysis is performed on the directed graph to obtain the cluster analysis results, and abnormal group accounts are identified from the historical accounts based on the cluster analysis results.

[0138] In one alternative implementation, based on the aforementioned scheme, determining the account switching data corresponding to one or more user devices can be achieved through the following steps: collecting user behavior data to determine the account usage data corresponding to one or more user devices; and determining the account switching data corresponding to each user device based on the account usage data corresponding to each user device.

[0139] In an optional implementation, based on the aforementioned scheme, a directed graph with historically used accounts as nodes is constructed according to the account switching data corresponding to each user device. This can be achieved through the following steps: according to the account switching relationship corresponding to each historically used account, the nodes corresponding to each historically used account are connected to form multiple directed edges to obtain a directed graph with historically used accounts as nodes; wherein, the directed edge corresponds to the account switching device, and the account switching device is the user device that switches from one historically used account connected to another historically used account connected to the directed edge.

[0140] In one optional implementation, based on the aforementioned scheme, cluster analysis is performed on the directed graph to obtain the cluster analysis results. This can be achieved through the following steps: determining the weight of the node corresponding to each historical user account and / or the weight of each directed edge; performing cluster analysis on the directed graph based on the weight of the node corresponding to each historical user account and / or the weight of each directed edge to obtain the cluster analysis results.

[0141] In one optional implementation, based on the aforementioned scheme, the weight of the node corresponding to each historical user account and / or the weight of each directed edge can be determined through the following steps: the weight of the node corresponding to each historical user account is determined according to the first duration data and the second duration data corresponding to each historical user account; wherein, the first duration data is the duration from the time of account switching to the current duration, and the second duration data is the duration of account activity.

[0142] In an optional implementation, based on the aforementioned scheme, the weight of the node corresponding to each historical user account and / or the weight of each directed edge can be determined by the following steps: determining the weight of each directed edge based on the usage duration of the two historical user accounts connected to each directed edge on the account switching device and the risk coefficient corresponding to the account switching device.

[0143] In an optional implementation, based on the aforementioned scheme, identifying abnormal group accounts from historical usage accounts based on cluster analysis results can be achieved through the following steps: dividing historical usage accounts into multiple groups based on cluster analysis results; identifying groups containing known illegal industry accounts from the multiple groups; in an optional implementation, based on the aforementioned scheme, historical usage accounts in the group containing known illegal industry accounts are identified as abnormal group accounts.

[0144] Implementing the embodiments of this disclosure, based on the account switching relationship of user devices, clusters group relationships. The group relationships can be updated in real time with the dynamically changing user account switching behavior, which has strong countermeasures against illegal industries and can be well applied to complex and ever-changing social risk control scenarios. Based on the cluster analysis results, abnormal group accounts are identified from historically used accounts, which is conducive to targeted control of abnormal group accounts and can improve the convenience of account management.

[0145] Bus 730 is used to connect different components of electronic device 700 and may include data bus, address bus and control bus.

[0146] Electronic device 700 can communicate with one or more external devices 800 (such as keyboard, mouse, external controller, etc.) through I / O interface 740.

[0147] Electronic device 700 can communicate with one or more networks via network adapter 750. For example, network adapter 750 can provide mobile communication solutions such as 3G / 4G / 5G, or wireless communication solutions such as wireless LAN, Bluetooth, and near-field communication. Network adapter 750 can communicate with other modules of electronic device 700 via bus 730.

[0148] Electronic device 700 can display a graphical user interface, etc., via display 760.

[0149] although Figure 7 As not shown in the diagram, other hardware and / or software modules may also be configured in the electronic device 700, including but not limited to: a display, microcode, device driver, redundant processor, external disk drive array, RAID (Redundant Arrays of Independent Disks) system, tape drive, and data backup storage system.

[0150] It should be noted that although several modules or units for the device used to perform actions have been mentioned in the detailed description above, this division is not mandatory. In fact, according to exemplary embodiments of this disclosure, the features and functions of two or more modules or units described above can be embodied in one module or unit. Conversely, the features and functions of one module or unit described above can be further divided and embodied by multiple modules or units.

[0151] Those skilled in the art will understand that various aspects of this disclosure can be implemented as systems, methods, or program products. Therefore, various aspects of this disclosure can be embodied in entirely hardware implementations, entirely software implementations (including firmware, microcode, etc.), or implementations combining hardware and software aspects, collectively referred to herein as “circuit,” “module,” or “system.” Other embodiments of this disclosure will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of this disclosure that follow the general principles of this disclosure and include common knowledge or customary techniques in the art not disclosed herein. The specification and embodiments are to be considered exemplary only, and the true scope and spirit of this disclosure are indicated by the claims.

[0152] It should be understood that this disclosure is not limited to the precise structures described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of this disclosure is defined only by the appended claims.

Claims

1. A group identification method, characterized in that, The method includes: Determine account switching data corresponding to one or more user devices; the account switching data includes the account switching relationships corresponding to the historical accounts used by the user devices. Based on the account switching data corresponding to each user device, a directed graph is constructed with the historically used accounts as nodes; Cluster analysis is performed on the directed graph to obtain cluster analysis results, and abnormal group accounts are identified from the historical usage accounts based on the cluster analysis results.

2. The method according to claim 1, characterized in that, The process of determining account switching data corresponding to one or more user devices includes: Collect user behavior data to determine the account usage data corresponding to one or more user devices; Based on the account usage data corresponding to each user device, determine the account switching data corresponding to each user device.

3. The method according to claim 1, characterized in that, The step of constructing a directed graph with the historically used accounts as nodes based on the account switching data corresponding to each user device includes: Based on the account switching relationship corresponding to each of the historical accounts, the nodes corresponding to each of the historical accounts are connected to form multiple directed edges to obtain a directed graph with the historical accounts as nodes; wherein, the directed edge corresponds to the account switching device, and the account switching device is the user device that switches from one of the historical accounts connected to the directed edge to another connected historical account.

4. The method according to claim 3, characterized in that, The clustering analysis of the directed graph to obtain the clustering analysis results includes: Determine the weight of the node corresponding to each of the historical accounts and / or the weight of each of the directed edges; Based on the weights of the nodes corresponding to each historical user account and / or the weights of each directed edge, cluster analysis is performed on the directed graph to obtain the cluster analysis results.

5. The method according to claim 4, characterized in that, Determining the weight of the node corresponding to each of the historical user accounts and / or the weight of each of the directed edges includes: The weight of the node corresponding to each historical user account is determined based on the first duration data and the second duration data corresponding to each historical user account. The first duration data is the time elapsed since the account was switched, and the second duration data is the account's active duration.

6. The method according to claim 4, characterized in that, Determining the weight of the node corresponding to each of the historical user accounts and / or the weight of each of the directed edges includes: The weight of each directed edge is determined based on the usage duration of the two historical accounts connected to each directed edge on the account switching device and the risk coefficient corresponding to the account switching device.

7. The method according to claim 1, characterized in that, The process of identifying anomalous accounts from the historical usage accounts based on the clustering analysis results includes: Based on the clustering analysis results, the historical accounts were divided into multiple groups; Identify groups from the multiple groups that contain known accounts involved in illegal activities; Historically used accounts within the group that includes known accounts involved in illegal activities are classified as abnormal group accounts.

8. A group identification device, characterized in that, The device includes: The account switching data determination module is used to determine account switching data corresponding to one or more user devices; the account switching data includes the account switching relationship corresponding to the historical accounts used by the user device. A directed graph construction module is used to construct a directed graph with the historically used accounts as nodes based on the account switching data corresponding to each user device. The group account identification module is used to perform cluster analysis on the directed graph, obtain the cluster analysis results, and identify abnormal group accounts from the historical accounts based on the cluster analysis results.

9. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the method described in any one of claims 1 to 7.

10. An electronic device, characterized in that, include: processor; as well as Memory for storing the executable instructions of the processor; The processor is configured to execute the method of any one of claims 1 to 7 by executing the executable instructions.