Business processing method, electronic equipment, storage medium and program product

By deploying a user profile reasoning model and homomorphic encryption technology locally, combined with a business decision engine, the balance between real-time user profiling and privacy protection in existing technologies is solved, achieving accurate user profiling and secure business processing.

CN121786376APending Publication Date: 2026-04-03INDUSTRIAL AND COMMERCIAL BANK OF CHINA
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-22
Publication Date
2026-04-03

AI Technical Summary

Technical Problem

Existing user profiling-based business processing methods struggle to strike a balance between real-time performance and user privacy protection, resulting in insufficient accuracy of user profiles and a high risk of privacy breaches.

Method used

By acquiring the historical and real-time characteristics of target users, risk profiles are created using a locally deployed profiling inference model. The risk profile tag values ​​are then homomorphically encrypted, and the encrypted data is used for risk assessment and decision-making in conjunction with a business decision engine. This ensures user privacy while improving profile accuracy.

Benefits of technology

It enables the real-time acquisition of accurate user profiles while protecting user privacy, thereby reducing business processing risks, improving response speed and user profile accuracy, and minimizing the risk of privacy leaks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121786376A_ABST
    Figure CN121786376A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a service processing method, electronic equipment, a storage medium and a program product, and relates to the technical field of federated learning, and the method comprises the steps: obtaining historical features and real-time features of a target user in response to a service processing request initiated by the target user; inputting the historical features and the real-time features of the target user into a locally-deployed portrait reasoning model, and performing risk portraying on the target user by using the locally-deployed portrait reasoning model to obtain a risk portrait label value of the target user; performing homomorphic encryption on the risk portrait label value of the target user to obtain an encrypted portrait label value; performing risk assessment on the service processing request by using a service decision engine based on the encrypted portrait label value and the encrypted label threshold to obtain a risk assessment decision result; and executing the business processing request based on the risk assessment decision result. According to the method, the accurate user portrait can be obtained in real time on the premise of protecting the privacy of the user, and the business processing risk is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present invention relate to the field of federated learning technology, and in particular to a business processing method, electronic device, storage medium and program product. Background Technology

[0002] Based on banks' requirements for precise risk control and personalized services, user profiling is crucial. Using these profiles to assess risk and identify needs during business transactions improves decision-making efficiency, enhances user experience, and ensures business security. However, existing user-profiling-based business processing methods suffer from insufficient real-time performance and struggle to strike a balance between protecting user privacy and ensuring the accuracy of user profiles. Summary of the Invention

[0003] This invention provides a business processing method, electronic device, storage medium, and program product, which can obtain accurate user profiles in real time while protecting user privacy, thereby reducing business processing risks.

[0004] In a first aspect, the business processing method provided in the embodiments of the present invention includes:

[0005] In response to business processing requests initiated by target users, obtain the historical and real-time characteristics of the target users;

[0006] The historical and real-time characteristics of the target user are input into the locally deployed profile reasoning model to create a risk profile of the target user and obtain the risk profile label value of the target user.

[0007] Homomorphically encrypt the risk profile tag values ​​of the target users to obtain encrypted profile tag values;

[0008] The business decision engine is used to perform risk assessment on business processing requests based on encrypted profile tag values ​​and encrypted tag thresholds to obtain risk assessment decision results. The encrypted tag threshold is obtained by homomorphically encrypting the original tag threshold.

[0009] Business processing requests are executed based on the risk assessment decision results.

[0010] Secondly, the business processing apparatus provided in the embodiments of the present invention includes:

[0011] The acquisition module is used to respond to business processing requests initiated by target users and acquire the historical and real-time characteristics of the target users;

[0012] The profiling module is used to input the historical and real-time characteristics of the target user into the locally deployed profiling inference model, so as to use the locally deployed profiling inference model to create a risk profile of the target user and obtain the risk profile label value of the target user.

[0013] The encryption module is used to perform homomorphic encryption on the risk profile tag value of the target user to obtain the encrypted profile tag value.

[0014] The assessment module is used to perform risk assessment on business processing requests based on encrypted profile tag values ​​and encrypted tag thresholds using the business decision engine, and obtain risk assessment decision results. The encrypted tag threshold is obtained by homomorphically encrypting the original tag threshold.

[0015] The execution module is used to execute business processing requests based on the risk assessment decision results.

[0016] Thirdly, the electronic device provided in the embodiments of the present invention includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the program, it implements the business processing method as described in any embodiment of the present invention.

[0017] Fourthly, the computer-readable storage medium provided in the embodiments of the present invention stores a computer program thereon, which, when executed by a processor, implements the business processing method as described in any embodiment of the present invention.

[0018] Fifthly, the computer program product provided in the embodiments of the present invention includes a computer program, which, when executed by a processor, implements the business processing method as described in any embodiment of the present invention.

[0019] In this embodiment of the invention, by acquiring the historical and real-time characteristics of the target user, comprehensive data support is provided for subsequent risk profiling of the target user; risk profiling based on the historical and real-time characteristics of the target user can comprehensively consider historical and real-time behaviors to dynamically adjust the risk assessment results and improve the accuracy of user profiling; using a locally deployed profiling inference model for risk profiling can reduce network transmission latency and thus improve response speed, while reducing the risk of user privacy leakage; homomorphic encryption of the risk profiling tag value of the target user can ensure that sensitive user data is calculated in an encrypted state, thereby protecting user privacy. Attached Figure Description

[0020] To more clearly illustrate the technical solution of the present invention, the accompanying drawings used in the embodiments will be briefly introduced below. It should be understood that the following drawings only show some embodiments of the present invention and should not be regarded as a limitation on the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.

[0021] Figure 1 This is a flowchart illustrating a business processing method provided in an embodiment of the present invention;

[0022] Figure 2 This is another schematic diagram of the business processing method provided in the embodiments of the present invention;

[0023] Figure 3 This is an interactive schematic diagram of the portrait reasoning model training method provided in an embodiment of the present invention;

[0024] Figure 4 This is a schematic diagram of a business processing device provided in an embodiment of the present invention;

[0025] Figure 5 This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present invention. Detailed Implementation

[0026] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.

[0027] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0028] Figure 1 This is a flowchart illustrating a business processing method provided in an embodiment of the present invention. The business processing method provided in this embodiment is applicable to scenarios where a business processing system is instructed to process transactions for users. This business processing method can be executed by a business processing device provided in this embodiment, which can be implemented using software and / or hardware. In a specific embodiment, the device can be integrated into an electronic device, which can be a smart terminal in a bank branch, such as a smart teller machine. A business processing system can be installed in the electronic device. The following embodiment uses the integration of the business processing device into an electronic device as an example for illustration. See also... Figure 1 The business processing method in this embodiment may include the following steps:

[0029] Step 101: In response to the business processing request initiated by the target user, obtain the target user's historical and real-time characteristics.

[0030] The target user refers to the user who initiates a business processing request at the current business processing terminal. The target user is the object served by the business processing system. The business processing system is integrated on the business processing terminal, which is the executing entity of the business processing method in this embodiment. For example, the business processing terminal can be a smart terminal in a bank branch. A business processing request refers to a specific business operation request initiated by the target user to the business processing terminal. A business processing request typically includes the business type, request parameters, and related data. For example, a business processing request may include a loan application of 100,000 yuan, a transfer transaction of 10,000 yuan, and account opening, etc.

[0031] Historical features are data characterizing the historical behavioral characteristics of a target user within a business processing system. They reflect a user's long-term behavioral patterns and risk propensity. Examples include user personal information, historical transaction frequency, historical risk event records, average transaction amount, number of past complaints, and historical login devices. Historical features can be persisted in the business processing terminal and retrieved in real-time upon receiving a business request from the target user. Real-time features are data characterizing the behavioral characteristics of the target user during the current business processing session. This business processing session begins in response to a business processing request initiated by the target user. Examples include the duration of the current operation, the interface click flow of the current operation, and changes in geographical location.

[0032] In this embodiment, by acquiring the historical and real-time characteristics of the target user, comprehensive data support is provided for the subsequent risk profiling of the target user.

[0033] Step 102: Input the historical and real-time characteristics of the target user into the locally deployed profile reasoning model to create a risk profile of the target user and obtain the risk profile label value of the target user.

[0034] A profile reasoning model refers to a computational model used to analyze the historical and real-time characteristics of a target user and output a risk label value. For example, a profile reasoning model can be a rule engine that infers the risk profile of a target user based on predefined rules in the business logic; or it can be a machine learning model that trains the profile reasoning model using historical data from the business processing system to learn the mapping relationship between the user's historical and real-time characteristics and the risk profile label value.

[0035] Risk profile label values ​​refer to the quantifiable risk ratings output by the profile inference model, assessing the potential risk a target user poses to the business processing system. For example, a risk profile label value can be a single risk score, with higher values ​​indicating a greater potential risk to the business system; or it can be a vector or tuple of quantified risk scores, with each dimension corresponding to a type of risk, such as identity theft risk, credit risk, or compliance risk, where higher values ​​indicate a greater risk in that specific area.

[0036] In this embodiment, by creating a risk profile based on the target user's historical and real-time characteristics, the risk assessment results can be dynamically adjusted by comprehensively considering historical and real-time behaviors, thereby improving the accuracy of the user profile. By creating a risk profile using a locally deployed profile inference model, network transmission latency can be reduced, thereby improving response speed and reducing the risk of user privacy leakage.

[0037] Step 103: Homomorphically encrypt the risk profile tag value of the target user to obtain the encrypted profile tag value.

[0038] Homomorphic encryption is a cryptographic technique that allows computations to be performed on ciphertext data to obtain ciphertext computation results, ensuring that the decrypted ciphertext computation result is consistent with the computation result obtained directly on the plaintext data. Encrypted profile tag values ​​refer to the ciphertext data obtained after homomorphically encrypting risk profile tag values.

[0039] For example, assuming the risk profile label value is s=70, the public key and the corresponding private key generated by the business processing terminal are used to encrypt s using the homomorphic encryption algorithm E(.) and the private key to obtain the encrypted profile label value E(s)=1855.

[0040] In this embodiment, by homomorphically encrypting the risk profile tag value of the target user, it is possible to ensure that the user's sensitive data is calculated in an encrypted state, thereby protecting the user's privacy.

[0041] Step 104: Use the business decision engine to perform risk assessment on business processing requests based on encrypted profile tag values ​​and encrypted tag thresholds to obtain risk assessment decision results. The encrypted tag threshold is obtained by homomorphically encrypting the original tag threshold.

[0042] The original label threshold refers to the threshold value of the profile label predefined according to business logic. The original label threshold can be used to classify the risk level of the profile label value, and then obtain the corresponding risk assessment decision result based on the business decision engine. The encrypted label threshold refers to the ciphertext threshold obtained after performing a specific homomorphic encryption operation on the original label threshold. A specific homomorphic encryption operation refers to an encryption operation performed using the same homomorphic encryption algorithm and key as the one used to encrypt the profile label value. Continuing the previous example, the business processing terminal sends the public key and the encrypted profile label value E(s) = 1855 to the business processing engine, causing the business processing engine to use the public key and the same E(.) algorithm to encrypt the original label threshold t = 80, resulting in the encrypted label threshold E(t) = 2000.

[0043] A business decision engine can be understood as a rule engine that analyzes and makes decisions based on encrypted profile tag values ​​and encrypted tag thresholds according to predefined business logic. Specifically, the business decision engine can execute decision logic equivalent to that on encrypted data, ensuring that the risk assessment decision result obtained based on encrypted profile tag values ​​and encrypted tag thresholds is consistent with the risk assessment decision result obtained based on risk profile tag values ​​and original tag thresholds. The risk assessment decision result refers to the action measures taken against the target user, calculated by the business decision engine based on the target user's encrypted profile tag values ​​and encrypted tag thresholds. For example, the risk assessment decision result may include "approve the business processing request," "reject the business processing request," "require manual review," or "trigger secondary verification," etc.

[0044] Continuing the previous example, the business decision engine supports a homomorphic comparison protocol, ensuring that the comparison operation between the encrypted profile tag value E(s) and the encrypted tag threshold E(t) satisfies (E(s)@E(t)) = (s@t), where @ can be any comparison operator, such as >, <, etc. The business rule engine executes the decision logic in ciphertext, determining whether E(s) > E(t) is true, and outputs the encrypted risk decision result Cs = 1500. The business processing terminal uses its private key to decrypt the ciphertext operation result to obtain the plaintext operation result Ds = 10. Based on the predefined business logic that Ds > 0 is equivalent to s > t being true, the risk decision result corresponding to s > t is "Approve business processing request".

[0045] Step 105: Execute the business processing request based on the risk assessment decision results.

[0046] Executing a business processing request can be understood as performing final processing on the target user's business processing request based on the risk assessment decision. For example, when the risk assessment decision is "approve the business processing request," the user's business processing request is executed automatically; when the risk assessment decision is "require manual review," a message is sent to the salesperson's terminal requesting manual review.

[0047] In this embodiment, by acquiring the historical and real-time characteristics of the target user, comprehensive data support is provided for subsequent risk profiling of the target user; risk profiling based on the historical and real-time characteristics of the target user can comprehensively consider historical and real-time behaviors to dynamically adjust the risk assessment results and improve the accuracy of user profiling; using a locally deployed profiling inference model for risk profiling can reduce network transmission latency and thus improve response speed, while reducing the risk of user privacy leakage; homomorphic encryption of the risk profiling tag value of the target user can ensure that sensitive user data is calculated in an encrypted state, thereby protecting user privacy.

[0048] The following is combined with Figure 2 The business processing method provided in the embodiments of the present invention will be further explained. Figure 2 This is another schematic flowchart of the business processing method provided in this embodiment of the invention. (See attached diagram.) Figure 2 The business processing method in this embodiment may include:

[0049] Step 201: In response to the business processing request initiated by the target user, obtain the target user's historical and real-time characteristics.

[0050] Step 202: Input the historical and real-time features of the target user into the locally deployed profile inference model, wherein the profile inference model includes an attention unit and an inference unit.

[0051] An attention unit refers to a computational unit in a profiling inference model that assigns weights to historical and real-time features in relation to the computational results. For example, an attention unit can be a neural network built on an attention mechanism, which can take historical and real-time features as input and output weight coefficients. An inference unit refers to a computational unit in a profiling inference model that generates the final risk profile label value.

[0052] Step 203: Use attention units to assign a first weight to the historical features of the target user and a second weight to the real-time features of the target user; wherein the second weight is greater than the first weight.

[0053] The first weight, calculated using the attention unit, measures the relative importance of the target user's historical characteristics in this risk profile. The second weight, also calculated using the attention unit, measures the relative importance of the target user's real-time characteristics in this risk profile. Specifically, because real-time characteristics better reflect abnormal behavior during the user's current business process, they receive higher attention, making the second weight greater than the first weight.

[0054] In this embodiment, by using attention units to assign a first weight to the historical features of the target user and a second weight to the real-time features of the target user, the second weight is greater than the first weight. This enables adaptive allocation of the importance of different features and prioritizes real-time features that reflect the user's latest behavior, thereby improving the accuracy and timeliness of user profiles.

[0055] Step 204: Using the inference unit, a risk profile of the target user is created based on the target user's historical characteristics, first weight, real-time characteristics, and second weight, and the risk profile label value of the target user is obtained.

[0056] For example, the inference unit can first perform weighted fusion of historical feature vectors with the first weight, then perform weighted fusion of real-time feature vectors with the second weight, and then concatenate or add the weighted fused feature vectors before inputting them into a multilayer perceptron, and finally output a quantified risk profile label value.

[0057] Step 205: Homomorphically encrypt the risk profile tag value of the target user to obtain the encrypted profile tag value.

[0058] Step 206: Use the business decision engine to determine whether the encrypted profile tag value exceeds the encrypted tag threshold.

[0059] Specifically, the business decision engine receives the encrypted profile tag value sent by the business processing terminal and ensures that the encrypted tag threshold and the encrypted profile tag value are in a homomorphic encrypted state. The business rule engine can then perform a comparison in the ciphertext space to determine whether the encrypted profile tag value exceeds the encrypted tag threshold.

[0060] For example, suppose the encrypted profile label value is E(75) and the encrypted label threshold is E(60). The business decision engine executes a homomorphic comparison protocol, performs operations on the ciphertext, and determines that E(75) > E(60) is true, that is, the encrypted profile label value exceeds the encrypted label threshold.

[0061] In this embodiment, by determining whether the encrypted profile tag value exceeds the encrypted tag threshold, the profile tag value and the tag threshold remain encrypted throughout the entire decision-making process, effectively preventing the leakage of user privacy.

[0062] Step 207: If the encrypted profile tag value exceeds the encrypted tag threshold, determine that the risk assessment decision requires manual review.

[0063] Specifically, if the encrypted profile tag value exceeds the encrypted tag threshold, it indicates that the overall risk of the target user's behavioral characteristics has exceeded the preset automated processing security boundary of the business processing system. Therefore, it is necessary to suspend the automated business processing process and introduce review by business personnel for further judgment.

[0064] In this embodiment, by introducing manual review when the encrypted profile tag value exceeds the encrypted tag threshold, business requests from high-risk target users can be temporarily blocked, preventing threats to the security and compliance of the business processing system.

[0065] Step 208: If the encrypted profile tag value does not exceed the encrypted tag threshold, determine that the risk assessment decision result is that no manual review is required.

[0066] Specifically, if the encrypted profile tag value exceeds the encrypted tag threshold, it indicates that the overall risk of the target user's behavioral characteristics is within the safe range that the business processing system considers to be in. Therefore, the business processing terminal can automatically execute the business processing process without manual review.

[0067] In this embodiment, by eliminating manual review when the encrypted profile tag value does not exceed the encrypted tag threshold, the processing efficiency of security target user business requests can be accelerated.

[0068] Step 209: If the risk assessment decision indicates that manual review is required, notify the manual review end to conduct a manual review of the target user, obtain the manual review result from the manual review end, and execute the business processing request if the manual review result is approved.

[0069] The manual review terminal can be understood as the operating terminal used by business processing system administrators. For example, business system administrators could be risk management specialists, business operations personnel, etc. The manual review terminal can communicate bidirectionally with the business processing terminal to receive review tasks, query relevant data required for review, interact with the business processing terminal for additional verification, and ultimately obtain the manual review result. The manual review terminal can also be designed with a multi-level architecture.

[0070] The manual review result refers to the final judgment of the business processing system administrator on the current business processing request. For example, the manual review result may be "approved," "failed," or "requires supplementary materials for review again." If the manual review result is "approved," the business processing request is executed.

[0071] In this embodiment, by introducing manual review and executing business processing requests upon successful review, the professional knowledge and experience of business system administrators can be fully utilized, thereby further improving the accuracy of risk control in the business processing system.

[0072] Step 210: If the risk assessment decision result indicates that no manual review is required, directly execute the business processing request.

[0073] Specifically, if the risk assessment decision does not require manual review, the business processing terminal will automatically execute the business processing flow.

[0074] Optionally, the locally deployed profile inference model is obtained through the following method:

[0075] (1) Use local training data to train the portrait reasoning model issued by the central server to obtain the local model gradient.

[0076] In a distributed network, the central server is the core service node responsible for distributing the initial user profile inference model to the business processing terminals. For example, the central server can be a physical server, a cloud server instance, etc., distributing the pre-trained user profile inference model to the business processing terminals once a month. In this embodiment, the user profile inference model is a data-driven computational model with the function of calculating user profile risk values. The user profile inference model is typically a lightweight deep learning model to meet the needs of real-time computation on business processing terminals with limited computing and storage resources. For example, the user profile inference model can be a knowledge distillation and compression deep learning model.

[0077] Local training data refers to a private dataset stored locally on a single business processing system terminal, used to train the profile inference model distributed by the central server. Local training data can be obtained by collecting and processing recently processed business data from that terminal. For example, local training data may include historical and real-time feature data of users from several business processing sessions, as well as profile risk value labels corresponding to that business processing session, determined by an expert system or historical review results. Local model gradient refers to the model gradient calculated by the profile inference model during model training using local training data.

[0078] In this embodiment, the profile reasoning model issued by the central server is trained using local training data, which avoids the transmission of local training data and can prevent the leakage of user privacy information in the training data.

[0079] Optionally, the local model gradient can be obtained by training the image inference model distributed by the central server using local training data, including:

[0080] (a) Use local training data to train the portrait reasoning model issued by the central server to obtain the gradient of the original model.

[0081] The raw model gradient can be understood as the unprocessed gradient calculated by the profiling inference model during its training using local training data. The raw model gradient may contain sensitive information sufficient to infer parts of the raw training data.

[0082] (b) Gaussian noise is added to the original model gradient using a differential privacy encryptor to obtain the local model gradient.

[0083] A differential privacy encryptor can be understood as an algorithmic module that implements a differential privacy protection mechanism, used to add Gaussian noise to the original model gradient. This ensures that the output is statistically indistinguishable from the existence of a specific training data record in the input dataset. For example, the differential privacy encryptor can generate random numbers conforming to a Gaussian distribution and add them as Gaussian noise to the original model gradient based on a preset noise scale parameter. In this step, the local model gradient refers to the model gradient that satisfies the definition of differential privacy, obtained after adding Gaussian noise to the original model gradient using the differential privacy encryptor.

[0084] In this embodiment, by using a differential privacy encryptor to add Gaussian noise to the gradient of the original model, the possibility of leaking local training data through local gradients is eliminated, further protecting user privacy.

[0085] Optionally, after step (1), the method further includes calculating local gradient weights based on the freshness and quantity of the local training data.

[0086] Local training data is an indicator of the timeliness of local training data. Generally, the fresher the training data, the better it reflects user behavior patterns in the current business environment, and the more representative the trained model will be. For example, the freshness of local training data can be calculated based on the average lifespan of the training data, or the difference between the timestamp of the most recent training data and the current time. The quantity of training data refers to the total number of samples used for this local model training. Generally, the larger the quantity of training data, the better it reflects common user behavior patterns, and the more representative the trained model will be. Local gradient weights can be understood as coefficients that quantify the importance and reliability of the gradients of the local model trained by the business processing terminal based on local training data. Local gradient weights are directly proportional to the freshness and quantity of local training data.

[0087] For example, the local gradient weight of the i-th service processing terminal can be calculated using the following formula: . in the formula Represents the local gradient weight of the i-th service processing terminal. This represents the freshness of the local data on the i-th terminal. The number of local training data for the i-th service processing terminal is represented by the number of data points. It can smooth the data and prevent the local gradient weights from becoming too large due to an extremely large amount of local training data or extremely high freshness.

[0088] In this embodiment, by calculating the local gradient weight based on the freshness and quantity of local training data, the importance of the local model gradient of the business processing terminal with higher training data quality is increased.

[0089] (2) The local model gradient is reported to the edge aggregation node through the federated learning coordinator so that the edge aggregation node can aggregate the local model gradient reported by the business processing terminal within its coverage area to obtain the global gradient.

[0090] A federated learning coordinator refers to a software component or service in a distributed system used to coordinate data transmission between business processing terminals and edge aggregation nodes. An edge aggregation node refers to a computing node deployed on a business processing terminal within a distributed system, used to aggregate the local model gradients reported by the business processing terminals within its coverage area. For example, when the coverage area of ​​an edge aggregation node is divided by geographical region, the edge aggregation node could be a server deployed in a provincial branch data center, covering all business processing terminals within the province according to the geographical region. Aggregation processing can be understood as the edge aggregation node using a preset aggregation algorithm to aggregate the local gradients uploaded by each business processing terminal to generate a model optimization direction that represents the distribution characteristics of all training data within its coverage area. The aggregation algorithm used is not limited. For example, it could be a federated averaging algorithm, a safe averaging algorithm, etc. The global gradient refers to the model gradient obtained by aggregating the local gradients of all business processing terminals participating in this aggregation process.

[0091] In this embodiment, by introducing edge aggregation nodes for gradient aggregation processing in the intermediate layer, direct communication between the central server and the business processing terminal is avoided, thereby reducing network bandwidth pressure and the computing bottleneck of the central node.

[0092] Optionally, step (2) includes: reporting the local model gradient and local gradient weights to the edge aggregation nodes through the federated learning coordinator, so that the edge aggregation nodes can aggregate the local model gradients reported by the service processing terminals within their respective coverage areas according to the local gradient weights reported by the service processing terminals within their respective coverage areas, and obtain the global gradient.

[0093] Specifically, the service processing terminal simultaneously reports its local gradient weights and local model gradients to the edge aggregation node. This allows the edge aggregation node to perform a weighted average of the local model gradients reported by the service processing terminal. Optionally, the freshness and quantity of local training data can also be reported, allowing the edge aggregation node to determine the local gradient weights for each service processing terminal. For example, global gradients... The calculation formula is as follows: ,in The aggregate weight represents the i-th service processing terminal. The denominator represents the local model gradient uploaded by the i-th service processing terminal. It is used to sum all aggregate weights, which serves as a normalization function to ensure the stability of the aggregate gradient's data scale.

[0094] In this embodiment, by aggregating the local model gradients reported by the service processing terminals within their respective coverage areas based on local gradient weights, the importance of the model gradients obtained from high-quality training data in the aggregation process can be enhanced, thereby accelerating model convergence and improving its final performance.

[0095] (3) Receive incremental model parameters from the central server through edge aggregation nodes. The incremental model parameters are determined by the central server based on the global gradient reported by each edge aggregation node, adjusting the portrait inference model deployed in the central server, and based on the difference in model parameters of the portrait inference model before and after adjustment.

[0096] Incremental model parameters refer to the amount of change in model parameters after a round of aggregation and update of the profile inference model deployed on it by the central server, based on the global gradient reported by each edge aggregation node. For example, if the initial profile inference model parameters sent by the central server to the business processing terminal are... After the central server aggregates the global gradients from each edge node, it uses the gradient descent algorithm to calculate the updated model parameters. Then the incremental model parameters are ,and .

[0097] In this embodiment, by distributing incremental model parameters, the communication overhead of the business processing terminal is saved, and the collaborative evolution of the reasoning capabilities of the profile reasoning model deployed on each business processing terminal is realized.

[0098] (4) Update the portrait reasoning model issued by the central server based on the incremental model parameters to obtain the locally deployed portrait reasoning model.

[0099] Continuing with the previous example, if the parameters of the profile inference model currently deployed on the business processing terminal are... Received Afterwards, an update operation is performed, and the parameters of the locally deployed profile inference model are obtained. ,but .

[0100] In this embodiment, by acquiring the historical and real-time characteristics of the target user, comprehensive data support is provided for subsequent risk profiling of the target user. An attention unit is used to assign a first weight to the target user's historical characteristics and a second weight to the target user's real-time characteristics, making the second weight greater than the first weight. This allows for adaptive allocation of the importance of different features, with a focus on real-time features reflecting the user's latest behavior, thereby improving the accuracy and timeliness of the user profile. Homomorphic encryption of the risk profile label values ​​of the target user ensures that sensitive user data is calculated in an encrypted state, thus protecting user privacy. Determining whether the encrypted profile label value exceeds the encrypted label threshold ensures that the profile label value and the label threshold remain encrypted throughout the decision-making process, effectively preventing user privacy leakage. Introducing manual review when the encrypted profile label value exceeds the encrypted label threshold can temporarily block business requests from high-risk target users, preventing threats to the security and compliance of the business processing system. Exempting manual review when the encrypted profile label value does not exceed the encrypted label threshold can accelerate the processing efficiency of business requests from secure target users. Introducing manual review and executing business processing requests only after approval can fully leverage… Leveraging the expertise and experience of business system administrators further enhances the accuracy of risk control in business processing systems. Using local training data to train the profiling inference model distributed by the central server avoids the transmission of local training data, preventing the leakage of user privacy information within the training data. A differential privacy encryptor adds Gaussian noise to the original model gradients, eliminating the possibility of leaking local training data through local gradients and further protecting user privacy. Local gradient weights are calculated based on the freshness and quantity of local training data, increasing the importance of local model gradients from business processing terminals with higher-quality training data. Edge aggregation nodes are introduced for gradient aggregation in the intermediate layer, avoiding direct communication between the central server and business processing terminals, reducing network bandwidth pressure and the computational bottleneck of the central node. Aggregating local model gradients reported by business processing terminals within their respective coverage areas based on local gradient weights emphasizes the importance of model gradients obtained from high-quality training data, accelerating model convergence and improving final performance. Distributing incremental model parameters saves communication overhead for business processing terminals, enabling the collaborative evolution of the profiling inference model's inference capabilities deployed on various business processing terminals.

[0101] For example, Figure 3 This is an interactive schematic diagram of the portrait reasoning model training method provided in this embodiment of the invention. (See attached diagram) Figure 3First, the central server trains an initial profile inference model and distributes it to all business processing terminals in the distributed system. The terminals receive and deploy the model. Then, each business processing terminal trains its own profile inference model using local training data, obtaining local model gradients and calculating local gradient weights based on the freshness and quantity of the local training data. Next, the business processing terminal reports its local gradient weights and local model gradients to the federated learning coordinator, which then forwards the local gradient weights and gradients of the business processing models within the coverage area of ​​each edge aggregation node to the corresponding edge aggregation node. The edge aggregation nodes then aggregate the received local model gradients, weighting and summing them using their local gradient weights to obtain the global gradient. The central server then summarizes the global gradients reported by each edge aggregation node, adjusts the profile inference models deployed on them based on these global gradients, obtaining an updated profile inference model, and calculates the difference in model parameters before and after the adjustment to determine the incremental model parameters. Finally, the incremental model parameters are distributed to each business processing terminal. Upon receiving the incremental model parameters, each business processing terminal adjusts its locally deployed profile inference model, completing this round of profile inference model updates.

[0102] Figure 4 This is a schematic diagram of a business processing device provided in an embodiment of the present invention, such as... Figure 4 As shown, the device includes:

[0103] The acquisition module 401 is used to acquire the historical and real-time characteristics of the target user in response to the business processing request initiated by the target user.

[0104] The profiling module 402 is used to input the historical and real-time characteristics of the target user into the locally deployed profiling inference model, so as to use the locally deployed profiling inference model to create a risk profile of the target user and obtain the risk profile label value of the target user.

[0105] Encryption module 403 is used to perform homomorphic encryption on the risk profile tag value of the target user to obtain the encrypted profile tag value;

[0106] The assessment module 404 is used to perform risk assessment on business processing requests based on encrypted profile tag values ​​and encrypted tag thresholds using the business decision engine, and obtain risk assessment decision results. The encrypted tag threshold is obtained by homomorphically encrypting the original tag threshold.

[0107] Execution module 405 is used to execute business processing requests based on the risk assessment decision results.

[0108] In one embodiment, the risk assessment decision result includes whether manual review is required or not. The assessment module 404 uses the business decision engine to perform a risk assessment on the business processing request based on the encrypted profile tag value and the encrypted tag threshold, and obtains the risk assessment decision result, including:

[0109] Use the business decision engine to determine whether the encrypted profile tag value exceeds the encrypted tag threshold;

[0110] If the encrypted profile tag value exceeds the encrypted tag threshold, the risk assessment decision will be determined to require manual review.

[0111] If the encrypted profile tag value does not exceed the encrypted tag threshold, the risk assessment decision is determined to be that no manual review is required.

[0112] In one embodiment, the execution module 405 executes a business processing request based on the risk assessment decision result, including:

[0113] If the risk assessment decision indicates that manual review is required, notify the manual review team to conduct a manual review of the target user, obtain the manual review result from the manual review team, and execute the business processing request if the manual review result is approved.

[0114] If the risk assessment decision indicates that no manual review is required, the business processing request will be executed directly.

[0115] In one embodiment, the profiling inference model includes an attention unit and an inference unit. The profiling module 402 inputs the historical and real-time features of the target user into the locally deployed profiling inference model to perform risk profiling on the target user and obtain the risk profile label value of the target user, including:

[0116] Input the target user's historical and real-time characteristics into the locally deployed profile reasoning model;

[0117] Attention units are used to assign a first weight to the target user's historical features and a second weight to the target user's real-time features; wherein the second weight is greater than the first weight.

[0118] The inference unit is used to create a risk profile of the target user based on the target user's historical characteristics, first weight, real-time characteristics and second weight, and obtain the risk profile label value of the target user.

[0119] In one embodiment, the device further includes an inference model acquisition module for acquiring a locally deployed profile inference model, and the inference model training module includes:

[0120] The training submodule is used to train the portrait reasoning model distributed by the central server using local training data to obtain the local model gradient.

[0121] The reporting submodule is used to report the local model gradient to the edge aggregation node through the federated learning coordinator, so that the edge aggregation node can aggregate the local model gradient reported by the business processing terminal within its coverage area to obtain the global gradient.

[0122] The receiving submodule is used to receive incremental model parameters sent by the central server through the edge aggregation nodes. The incremental model parameters are determined by the central server based on the global gradient reported by each edge aggregation node, adjusting the portrait inference model deployed in the central server, and according to the difference in model parameters of the portrait inference model before and after the adjustment.

[0123] The update submodule is used to update the profile inference model issued by the central server based on the incremental model parameters, so as to obtain the locally deployed profile inference model.

[0124] In one embodiment, the training submodule trains the profile inference model distributed by the central server using local training data to obtain the local model gradient, including:

[0125] The image inference model distributed by the central server is trained using local training data to obtain the gradient of the original model;

[0126] A differential privacy encryptor is used to add Gaussian noise to the original model gradient to obtain the local model gradient.

[0127] In one embodiment, the reporting submodule is further configured to, after training the profile inference model distributed by the central server using local training data and obtaining the local model gradient:

[0128] Calculate local gradient weights based on the freshness and quantity of local training data;

[0129] The local model gradient and local gradient weights are reported to the edge aggregation nodes through the federated learning coordinator, so that the edge aggregation nodes can aggregate the local model gradients reported by the service processing terminals within their respective coverage areas according to the local gradient weights reported by the service processing terminals within their respective coverage areas, and obtain the global gradient.

[0130] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the above-described division of functional modules is merely an example. In practical applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above. The specific working process of the functional modules described above can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.

[0131] The apparatus of this invention provides comprehensive data support for subsequent risk profiling of target users by acquiring their historical and real-time characteristics. Risk profiling based on these characteristics allows for dynamic adjustment of risk assessment results, considering both historical and real-time behavior, thus improving the accuracy of user profiling. Utilizing a locally deployed profiling inference model reduces network transmission latency, thereby increasing response speed and mitigating the risk of user privacy leakage. Homomorphic encryption of the risk profile tag values ​​ensures that sensitive user data is calculated in an encrypted state, thereby protecting user privacy.

[0132] The following is for reference. Figure 5 It shows a schematic diagram of the structure of a computer system 500 suitable for implementing an electronic device according to embodiments of the present invention. Figure 5 The electronic device shown is merely an example and should not be construed as limiting the functionality and scope of use of the embodiments of the present invention.

[0133] like Figure 5 As shown, the computer system 500 includes a central processing unit (CPU) 501, which can perform various appropriate actions and processes based on programs stored in read-only memory (ROM) 502 or programs loaded from storage section 508 into random access memory (RAM) 503. The RAM 503 also stores various programs and data required for the operation of the computer system 500. The CPU 501, ROM 502, and RAM 503 are interconnected via a bus 504. An input / output (I / O) interface 505 is also connected to the bus 504.

[0134] The following components are connected to I / O interface 505: input section 506 including keyboard, mouse, etc.; output section 507 including cathode ray tube, liquid crystal display, etc., and speakers, etc.; storage section 508 including hard disk, etc.; and communication section 509 including network interface card, such as modem, etc. Communication section 509 performs communication processing via a network such as the Internet. Drive 510 is also connected to I / O interface 505 as needed. Removable media 511, such as disk, optical disk, magneto-optical disk, semiconductor memory, etc., are installed on drive 510 as needed so that computer programs read from them can be installed into storage section 508 as needed.

[0135] In particular, according to the embodiments disclosed in this invention, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments disclosed in this invention include a computer program product comprising a computer program carried on a computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via communication section 509, and / or installed from removable medium 511. When the computer program is executed by central processing unit (CPU) 501, it performs the functions defined above in the system of this invention.

[0136] It should be noted that the computer-readable medium shown in this invention can be a computer-readable signal medium or a computer-readable storage medium, or any combination thereof. A computer-readable storage medium can be, for example,—but not limited to—an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of a computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, a random access memory, a read-only memory, an erasable programmable read-only memory, an optical fiber, a portable compact disk read-only memory, an optical storage device, a magnetic storage device, or any suitable combination thereof. In this invention, a computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. In this invention, a computer-readable signal medium can include a data signal propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such propagated data signals can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. Computer-readable signal media can also be any computer-readable medium other than computer-readable storage media, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted using any suitable medium, including but not limited to: wireless, wire, optical fiber, etc., or any suitable combination thereof.

[0137] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present invention. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram or flowchart, and combinations of blocks in a block diagram or flowchart, may be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.

[0138] The modules and / or units described in the embodiments of this invention can be implemented in software or hardware. The described modules and / or units can also be housed in a processor; for example, a processor can be described as including an acquisition module, an image processing module, an encryption module, an evaluation module, and an execution module. The names of these modules do not necessarily limit the functionality of the module itself.

[0139] In another aspect, the present invention also provides a computer-readable medium, which may be included in the device described in the above embodiments; or it may exist independently and not assembled into the device. The computer-readable medium carries one or more programs, which, when executed by the device, cause the device to include:

[0140] In response to a business processing request initiated by a target user, the system obtains the target user's historical and real-time characteristics. These characteristics are then input into a locally deployed profiling inference model to create a risk profile of the target user, resulting in a risk profile tag value. This risk profile tag value is then homomorphically encrypted to obtain an encrypted profile tag value. A business decision engine is used to perform a risk assessment on the business processing request based on the encrypted profile tag value and an encrypted tag threshold, yielding a risk assessment decision result. The encrypted tag threshold is obtained by homomorphically encrypting the original tag threshold. Finally, the business processing request is executed based on the risk assessment decision result.

[0141] The technical solution of this invention provides comprehensive data support for subsequent risk profiling of target users by acquiring their historical and real-time characteristics. Risk profiling based on these characteristics allows for dynamic adjustment of risk assessment results, considering both historical and real-time behavior, thus improving the accuracy of user profiling. Utilizing a locally deployed profiling inference model reduces network transmission latency, thereby improving response speed and mitigating the risk of user privacy leakage. Homomorphic encryption of the risk profile tag values ​​ensures that sensitive user data is calculated in an encrypted state, thereby protecting user privacy.

[0142] This invention also provides a computer program product, including a computer program that, when executed by a processor, implements the business processing method provided in any embodiment of this invention.

[0143] In the implementation of a computer program product, computer program code for performing the operations of this invention can be written in one or more programming languages ​​or a combination thereof. Programming languages ​​include object-oriented programming languages ​​as well as conventional procedural programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including local area networks (LANs) or wide area networks (WANs), or it can be connected to an external computer (e.g., via the Internet using an Internet service provider).

[0144] It should be understood that the various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps described in this invention can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution of this invention can be achieved, and this is not limited herein.

[0145] It should be noted that the collection, use, storage, sharing, and transfer of user personal information involved in the technical solution of this invention all comply with the provisions of relevant laws and regulations, and require notification to the user and obtaining the user's consent or authorization. Where applicable, user personal information has undergone de-identification and / or anonymization and / or encryption technical processing. In addition, a corresponding operation entry is provided for the user to choose to agree to or reject the automated decision result; if the user chooses to reject, the process proceeds to the expert decision-making process.

[0146] The specific embodiments described above do not constitute a limitation on the scope of protection of this invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can occur depending on design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this invention should be included within the scope of protection of this invention.

Claims

1. A business processing method, characterized in that, include: In response to business processing requests initiated by target users, obtain the historical and real-time characteristics of the target users; The historical and real-time characteristics of the target user are input into the locally deployed profile reasoning model to create a risk profile of the target user and obtain the risk profile label value of the target user. Homomorphically encrypt the risk profile tag values ​​of the target users to obtain encrypted profile tag values; The business decision engine is used to perform risk assessment on business processing requests based on encrypted profile tag values ​​and encrypted tag thresholds to obtain risk assessment decision results. The encrypted tag threshold is obtained by homomorphically encrypting the original tag threshold. Business processing requests are executed based on the risk assessment decision results.

2. The method according to claim 1, characterized in that, Risk assessment decision results include whether manual review is required or not. The business decision engine uses encrypted profile tag values ​​and encrypted tag thresholds to perform risk assessments on business processing requests, resulting in risk assessment decision results, including: Use the business decision engine to determine whether the encrypted profile tag value exceeds the encrypted tag threshold; If the encrypted profile tag value exceeds the encrypted tag threshold, the risk assessment decision will be determined to require manual review. If the encrypted profile tag value does not exceed the encrypted tag threshold, the risk assessment decision is determined to be that no manual review is required.

3. The method according to claim 2, characterized in that, Execute business processing requests based on risk assessment decisions, including: If the risk assessment decision indicates that manual review is required, notify the manual review team to conduct a manual review of the target user, obtain the manual review result from the manual review team, and execute the business processing request if the manual review result is approved. If the risk assessment decision indicates that no manual review is required, the business processing request will be executed directly.

4. The method according to claim 1, characterized in that, The profile inference model includes an attention unit and an inference unit. It inputs the target user's historical and real-time characteristics into a locally deployed profile inference model to create a risk profile of the target user, obtaining the target user's risk profile label value, including: Input the target user's historical and real-time characteristics into the locally deployed profile reasoning model; Attention units are used to assign a first weight to the target user's historical features and a second weight to the target user's real-time features; wherein the second weight is greater than the first weight. The inference unit is used to create a risk profile of the target user based on the target user's historical characteristics, first weight, real-time characteristics and second weight, and obtain the risk profile label value of the target user.

5. The method according to claim 1, characterized in that, The locally deployed profile inference model is obtained through the following method: The local model gradient is obtained by training the image inference model distributed by the central server using local training data. The local model gradient is reported to the edge aggregation node through the federated learning coordinator, so that the edge aggregation node can aggregate the local model gradients reported by the business processing terminals within its coverage area to obtain the global gradient. The incremental model parameters are received by the edge aggregation nodes from the central server. The incremental model parameters are determined by the central server based on the global gradient reported by each edge aggregation node, adjusting the portrait inference model deployed in the central server, and according to the difference in model parameters of the portrait inference model before and after the adjustment. The profile reasoning model issued by the central server is updated based on the incremental model parameters to obtain the locally deployed profile reasoning model.

6. The method according to claim 5, characterized in that, The local model gradient is obtained by training the image inference model distributed by the central server using local training data, including: The image inference model distributed by the central server is trained using local training data to obtain the gradient of the original model; A differential privacy encryptor is used to add Gaussian noise to the original model gradient to obtain the local model gradient.

7. The method according to claim 5, characterized in that, After training the image inference model distributed by the central server using local training data and obtaining the local model gradient, the process also includes: Calculate local gradient weights based on the freshness and quantity of local training data; The local model gradients are reported to the edge aggregation nodes through the federated learning coordinator, so that the edge aggregation nodes can aggregate the local model gradients reported by the business processing terminals within their respective coverage areas to obtain the global gradient, including: The local model gradient and local gradient weights are reported to the edge aggregation nodes through the federated learning coordinator, so that the edge aggregation nodes can aggregate the local model gradients reported by the service processing terminals within their respective coverage areas according to the local gradient weights reported by the service processing terminals within their respective coverage areas, and obtain the global gradient.

8. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the business processing method as described in any one of claims 1 to 7.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by the processor, it implements the business processing method as described in any one of claims 1 to 7.

10. A computer program product, characterized in that, The computer program product includes a computer program that, when executed by a processor, implements the business processing method as described in any one of claims 1 to 7.