Risk management and control method, device, equipment and medium
By generating dynamic risk assessment benchmarks and multi-dimensional evaluation feature sets, the problems of scenario adaptability and real-time performance in marketing activities in existing technologies are solved, enabling real-time risk identification and interception in marketing activities, and improving the accuracy and adaptability of risk identification.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-22
- Publication Date
- 2026-04-07
AI Technical Summary
Existing fraud detection technologies suffer from poor scenario adaptability, high implementation thresholds, and insufficient real-time performance in marketing campaigns. They are difficult to adapt to diverse marketing scenarios and cannot achieve real-time behavior judgment and interception, leading to increased operating costs and resource loss.
Based on historical negative behavior data of the target user group and real-time operational environment data, a dynamic risk assessment benchmark is generated. A structured time series model is used for dynamic fitting, a multi-dimensional assessment feature set is extracted, a comprehensive risk index is calculated, and corresponding handling operations are performed according to the level of abnormality.
It enables automatic and precise adjustment of risk assessment standards, improves the accuracy of risk identification and environmental adaptability, can intercept abnormal behavior in real time, reduces the harm to normal users, and lowers operating costs.
Smart Images

Figure CN121810291A_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to the field of big data technology, and specifically to a risk management method, apparatus, equipment, medium, and program product. Background Technology
[0002] With the increasing frequency of online business activities, various marketing and promotional activities have become important means for merchants to attract users and increase sales. However, these activities have also given rise to various fraudulent participation behaviors, leading to wasted marketing resources and increased operating costs, and may even disrupt normal market order. To address this issue, existing technologies have proposed a variety of fraud identification and risk management solutions, such as methods based on rule engines, machine learning models, or community network analysis, to identify abnormal users and prevent malicious transactions.
[0003] While existing technologies can identify negative behavior to some extent, they still have several significant limitations when applied to marketing campaigns. First, most existing solutions are designed for conventional transaction environments, relying on typical features such as order amount and transaction fees for behavior determination. This makes them difficult to adapt to special marketing mechanisms like fee-free periods, leading to decreased accuracy due to the lack of corresponding transaction features. Second, some methods depend on complex multi-rule combinations and large-scale historical data. Deployment costs are high and implementation is difficult when data accumulation is insufficient or the campaign scale is small, limiting their applicability in small to medium-sized scenarios. Furthermore, existing technologies primarily focus on offline data analysis and post-event identification, failing to achieve real-time behavior judgment and interception during user participation. This reliance on post-event handling increases operational costs and makes it difficult to effectively and promptly prevent resource loss.
[0004] Therefore, existing fraud detection technologies have significant limitations in terms of scenario adaptability, implementation threshold, and real-time performance. There is an urgent need for a risk management solution that can be applied to diverse marketing scenarios, balance efficiency and cost, and has real-time interception capabilities. Summary of the Invention
[0005] In view of the above problems, this disclosure provides risk management methods, devices, equipment, media and procedures to improve the efficiency of monitoring abnormal activities in marketing campaigns.
[0006] According to a first aspect of this disclosure, a risk management method is provided, the method comprising: generating a dynamic risk assessment benchmark based on historical negative behavior data of a target user group and real-time operational environment data within a corresponding time window, wherein the dynamic risk assessment benchmark is obtained by dynamically fitting the statistical distribution of historical negative behavior data using a structured time series model with real-time business environment data as a covariate; acquiring negative behavior data of the target user within an activity period, extracting a multi-dimensional assessment feature set from the negative behavior data, wherein the multi-dimensional assessment feature set includes at least frequency characteristics, negative pattern characteristics, and associated risk characteristics of the user's negative behavior; calculating and fusing the dynamic deviation of the target user's various characteristics under the multi-dimensional assessment feature set based on the dynamic risk assessment benchmark, generating a comprehensive risk index for the target user; determining the abnormality level of the target user based on the comprehensive risk index, and performing a handling operation corresponding to the abnormality level.
[0007] In the embodiments of this disclosure, generating a dynamic risk assessment benchmark based on historical negative behavior data of the target user group and real-time operational environment data within the corresponding time window includes: inputting the historical operational environment data of the target user group as a covariate into the structured time series model, and training the model using the historical negative behavior data of the target user group as the target variable; inputting real-time business environment data into the trained structured time series model, and outputting the posterior prediction probability distribution of each negative behavior indicator within a future preset time period; and confirming the dynamic risk assessment benchmark based on the posterior prediction probability distribution.
[0008] In embodiments of this disclosure, the method further includes: setting a warning threshold lower than the dynamic risk assessment benchmark; and triggering a warning operation to remind the target user when the target user's comprehensive risk index exceeds the warning threshold but does not exceed the dynamic risk assessment benchmark.
[0009] In embodiments of this disclosure, the step of acquiring negative behavior data of a target user during an activity period and extracting a multi-dimensional evaluation feature set from the negative behavior data includes: acquiring negative behavior data of the target user during the activity period, which includes timestamps, behavior types, resource identifiers, and user identifiers; based on the negative behavior data, statistically analyzing the frequency of occurrence of various negative behaviors within a preset time window to generate the frequency features; based on the user behavior sequences in the negative behavior data, quantifying the negative behavior of the target user into the negative pattern features; and based on the user relationships implicit in the negative behavior data, constructing a risk association network and quantifying the risk transmission influence of the target user on users with associated relationships through graph computing indicators to generate the associated risk features.
[0010] In the embodiments of this disclosure, the step of calculating and fusing the dynamic deviation of the target user's various features under the multidimensional evaluation feature set based on the dynamic risk judgment benchmark to generate the target user's comprehensive risk index includes: calculating the extreme probability of each feature of the target user in the corresponding posterior prediction probability distribution based on the posterior prediction probability distribution in the dynamic risk judgment benchmark, as the dynamic deviation; and performing a weighted summation of the dynamic deviations of the frequency feature, negative pattern feature, and associated risk feature to generate the comprehensive risk index.
[0011] In embodiments of this disclosure, determining the anomaly level of the target user based on the comprehensive risk index and executing a handling operation corresponding to the anomaly level includes: determining a basic anomaly level based on the grading interval of the comprehensive risk index; correcting the basic anomaly level based on the risk index change trend of the target user within a preset observation period to obtain the anomaly level; and invoking and executing the corresponding handling operation based on the multi-level mapping relationship between the anomaly level and the handling operation, wherein the intensity of the handling operation is highly positively correlated with the anomaly level.
[0012] In embodiments of this disclosure, the step of correcting the basic anomaly level based on the risk index change trend of the target user within a preset observation period to obtain the anomaly level includes: calculating the rate of change of the comprehensive risk index of the target user within the preset observation period; comparing the rate of change with preset positive trend thresholds and negative trend thresholds, wherein the positive trend thresholds and negative trend thresholds are determined based on the risk index change range predicted by the structured time series model; if the rate of change is greater than the positive trend threshold, it is determined to be a risk acceleration trend, and the basic anomaly level is corrected upward by at least one level; if the rate of change is less than the negative trend threshold, it is determined to be a risk mitigation trend, and the basic anomaly level is corrected downward by at least one level.
[0013] In embodiments of this disclosure, the method further includes: initiating an observation period for the target user to whom the disposal operation is performed; if the comprehensive risk index of the target user continues to decline to the grading range corresponding to a lower abnormality level during the observation period, automatically reducing its abnormality level and the corresponding disposal intensity.
[0014] The second aspect of this disclosure provides a risk management device, comprising: a benchmark generation module, configured to generate a dynamic risk assessment benchmark based on historical negative behavior data of a target user group and real-time operational environment data within a corresponding time window, wherein the dynamic risk assessment benchmark is obtained by dynamically fitting the statistical distribution of historical negative behavior data using a structured time series model with real-time business environment data as a covariate; a feature extraction module, configured to acquire negative behavior data of the target user within an activity period and extract a multi-dimensional evaluation feature set from the negative behavior data, wherein the multi-dimensional evaluation feature set includes at least frequency features, negative pattern features, and associated risk features of the user's negative behavior; a risk evaluation module, configured to calculate and fuse the dynamic deviation of various features of the target user under the multi-dimensional evaluation feature set based on the dynamic risk assessment benchmark, and generate a comprehensive risk index for the target user; and a risk handling module, configured to determine the abnormality level of the target user based on the comprehensive risk index and execute handling operations corresponding to the abnormality level.
[0015] A third aspect of this disclosure provides an electronic device comprising: one or more processors; and a memory for storing one or more computer programs, wherein the one or more processors execute the one or more computer programs to implement the steps of the method described above.
[0016] A fourth aspect of this disclosure also provides a computer-readable storage medium having a computer program or instructions stored thereon, which, when executed by a processor, implement the steps of the above-described method.
[0017] The fifth aspect of this disclosure also provides a computer program product, including a computer program or instructions that, when executed by a processor, implement the steps of the above-described method.
[0018] According to the risk management method provided in this disclosure, real-time business environment data is input as a covariate into a structured time series model to generate a dynamic risk assessment benchmark closely linked to the current operational status. This achieves the technical effect that the risk assessment standard can be automatically and accurately adjusted according to fluctuations in the business environment, thereby solving the technical problem that traditional fixed thresholds are prone to misjudging normal users during peak activity periods and missing risk behaviors during off-peak periods, thus significantly improving the accuracy and environmental adaptability of risk identification. The method also systematically extracts assessment feature sets in three dimensions—frequency, pattern, and associated risks—from user negative behavior data, constructing a three-dimensional risk profile to achieve a multi-dimensional and penetrating assessment of user risk, thereby effectively discovering some complex and hidden abnormal behaviors. Attached Figure Description
[0019] The foregoing contents, as well as other objects, features, and advantages of this disclosure, will become clearer from the following description of embodiments with reference to the accompanying drawings, in which:
[0020] Figure 1 This diagram illustrates an application scenario of the risk management method and apparatus according to embodiments of the present disclosure.
[0021] Figure 2 A flowchart illustrating a risk management method according to an embodiment of the present disclosure is shown schematically.
[0022] Figure 3 A schematic diagram illustrating the structure of a risk management device according to an embodiment of the present disclosure is shown; and
[0023] Figure 4 A block diagram of an electronic device suitable for implementing a risk management method according to an embodiment of the present disclosure is shown schematically. Detailed Implementation
[0024] The embodiments of the present disclosure will now be described with reference to the accompanying drawings. However, it should be understood that these descriptions are exemplary only and are not intended to limit the scope of the disclosure. In the following detailed description, numerous specific details are set forth to provide a thorough understanding of the embodiments of the present disclosure for ease of explanation. However, it will be apparent that one or more embodiments may be practiced without these specific details. Furthermore, descriptions of well-known structures and techniques are omitted in the following description to avoid unnecessarily obscuring the concepts of the present disclosure.
[0025] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit this disclosure. The terms “comprising,” “including,” etc., as used herein indicate the presence of the stated features, steps, operations, and / or components, but do not exclude the presence or addition of one or more other features, steps, operations, or components.
[0026] All terms used herein (including technical and scientific terms) have the meanings commonly understood by those skilled in the art, unless otherwise defined. It should be noted that the terms used herein are to be interpreted in a manner consistent with the context of this specification, and not in an idealized or overly rigid way.
[0027] When using expressions such as "at least one of A, B and C", they should generally be interpreted in accordance with the meaning that is commonly understood by those skilled in the art (e.g., "a system having at least one of A, B and C" should include, but is not limited to, a system having A alone, a system having B alone, a system having C alone, a system having A and B, a system having A and C, a system having B and C, and / or a system having A, B and C, etc.).
[0028] It should be noted that the risk management methods and devices provided in this disclosure can be used in the financial sector to prevent abnormal orders during marketing campaigns, and can also be used in any sector other than the financial sector.
[0029] It should be noted that in the embodiments of this application, certain software, components, models and other existing solutions in the industry may be mentioned. These should be regarded as exemplary and are only intended to illustrate the feasibility of implementing the technical solution of this application. However, it does not mean that the applicant has used or necessarily used the solution.
[0030] In the technical solution disclosed herein, the user information (including but not limited to user personal information, user image information, user device information, such as location information) and data (including but not limited to data used for analysis, stored data, and displayed data) involved are all information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, storage, use, processing, transmission, provision, disclosure, and application of related data all comply with relevant laws, regulations, and standards, and necessary measures have been taken to ensure that they do not violate public order and good morals. Corresponding operation entry points are provided for users to choose to authorize or refuse.
[0031] This disclosure provides a risk management method, which includes: generating a dynamic risk assessment benchmark based on historical negative behavior data of a target user group and real-time operational environment data within a corresponding time window; the dynamic risk assessment benchmark is obtained by dynamically fitting the statistical distribution of historical negative behavior data using a structured time series model with real-time business environment data as a covariate; acquiring negative behavior data of the target user within an activity period, extracting a multi-dimensional assessment feature set from the negative behavior data, the multi-dimensional assessment feature set including at least the frequency characteristics, negative pattern characteristics, and associated risk characteristics of the user's negative behavior; calculating and fusing the dynamic deviation of various characteristics of the target user under the multi-dimensional assessment feature set based on the dynamic risk assessment benchmark to generate a comprehensive risk index for the target user; determining the abnormality level of the target user based on the comprehensive risk index, and performing handling operations corresponding to the abnormality level.
[0032] Figure 1 The diagram illustrates an application scenario of the risk management method according to an embodiment of the present disclosure.
[0033] like Figure 1 As shown, application scenario 100 according to this embodiment may include the control of negative behavior in marketing activities in the financial sector. Network 104 serves as a medium for providing a communication link between the first terminal device 101, the second terminal device 102, the third terminal device 103, and the server 105. Network 104 may include various connection types, such as wired or wireless communication links, or fiber optic cables, etc.
[0034] Users can use the first terminal device 101, the second terminal device 102, and the third terminal device 103 to interact with the server 105 via the network 104 to receive or send messages, etc. Various communication client applications can be installed on the first terminal device 101, the second terminal device 102, and the third terminal device 103, such as shopping applications, web browser applications, search applications, instant messaging tools, email clients, social media platform software, etc. (for example only).
[0035] The first terminal device 101, the second terminal device 102, and the third terminal device 103 can be various electronic devices with displays and support web browsing, including but not limited to smartphones, tablets, laptops, and desktop computers.
[0036] Server 105 can be a server that provides various services, such as a backend management server that supports websites browsed by users using the first terminal device 101, the second terminal device 102, and the third terminal device 103 (this is just an example). The backend management server can analyze and process data such as received user requests, and feed back the processing results (such as web pages, information, or data obtained or generated according to user requests) to the terminal devices.
[0037] It should be noted that the risk management method provided in this embodiment can generally be executed by server 105. Correspondingly, the risk management device provided in this embodiment can generally be located in server 105. The risk management method provided in this embodiment can also be executed by a server or server cluster that is different from server 105 and capable of communicating with the first terminal device 101, the second terminal device 102, the third terminal device 103, and / or server 105. Correspondingly, the risk management device provided in this embodiment can also be located in a server or server cluster that is different from server 105 and capable of communicating with the first terminal device 101, the second terminal device 102, the third terminal device 103, and / or server 105.
[0038] It should be understood that Figure 1 The number of terminal devices, networks, and servers shown is merely illustrative. Depending on implementation needs, any number of terminal devices, networks, and servers can be included.
[0039] The following will be based on Figure 1 The described scene, through Figure 2 The risk management method of the disclosed embodiments is described in detail.
[0040] Figure 2 A flowchart illustrating a risk management method according to an embodiment of this disclosure is shown schematically.
[0041] like Figure 2 As shown, the risk management method of this embodiment includes operations S210 to S240, and the transaction processing method can be executed sequentially.
[0042] When operating S210, a dynamic risk assessment benchmark is generated based on the historical negative behavior data of the target user group and the real-time operating environment data within the corresponding time window.
[0043] In embodiments of this disclosure, user consent or authorization may be obtained before acquiring user historical information. For example, a request to acquire user information may be sent to the user before operation S210. If the user consents or authorizes the acquisition of user information, operation S210 is performed.
[0044] During marketing campaigns, some users may engage in negative behaviors to obtain rewards at a low cost, such as abnormal refunds or returns. To address this, behavioral thresholds derived from profiling the target user group can serve as a means of identifying negative user behavior. The target user group comprises all active users with relevant transaction history related to a specific product, platform, or marketing campaign. For example, all users on an e-commerce app who have made purchases and requested refunds within the past year. By analyzing the historical data of this large group, the distribution patterns of negative behaviors within the target user group can be determined, allowing for the identification of negative behavioral characteristics and the establishment of risk assessment benchmarks.
[0045] In real-world operations, user behavior patterns change with fluctuations in promotional activity, discounts, inventory, and user preferences. For example, during peak periods, user participation is higher, leading to more transactions and refunds; conversely, during off-peak periods, user engagement is lower, resulting in less malicious activity. Therefore, relying solely on the frequency of negative user behavior to determine malicious intent is often inaccurate.
[0046] In this embodiment, a dynamic risk assessment benchmark is generated based on historical negative behavior data of the target user group and real-time operational environment data within the corresponding time window. This dynamic risk assessment benchmark is obtained by dynamically fitting the statistical distribution of historical negative behavior data using a structured time series model, with real-time business environment data as a covariate. The dynamic risk assessment benchmark automatically adjusts with the current operational environment, raising the threshold when the environment is hot to avoid false alarms and lowering the threshold when the environment is cold to increase vigilance. This makes the assessment results more consistent with actual business conditions and significantly reduces the false alarm rate.
[0047] In operation S220, acquire negative behavior data of target users during the activity period, and extract multidimensional evaluation feature sets from the negative behavior data.
[0048] In this embodiment, the system acquires full behavioral data of the target user during the activity period through event tracking logs and a business database. This raw data records the timestamp, behavior type (e.g., click, claim, order), involved resources (e.g., coupon ID), and device session identifier for each key user operation. From this behavioral data, the system extracts and constructs a multi-dimensional assessment feature set consisting of three core dimensions to comprehensively characterize user risk. The multi-dimensional assessment feature set includes at least the frequency characteristics, negative pattern characteristics, and associated risk characteristics of user negative behavior. The frequency characteristics represent the cumulative scale and density of user negative behavior over time; the negative pattern characteristics represent the abnormal regularity and strategy in the user's behavioral sequence that violates normal human operating habits or business logic; and the associated risk characteristics, from a network relationship perspective, represent the target user's association with other users through devices, social networks, or financial links, and the potential for risk diffusion or influence within high-risk communities. By systematically extracting frequency, pattern, and association features from the original behavioral data—a process that moves from the surface to the core and from the individual to the network—this method constructs a user risk profile that is far richer than a single indicator, providing a solid and multidimensional data foundation for subsequent accurate and intelligent risk assessment.
[0049] In operation S230, based on the dynamic risk assessment benchmark, the dynamic deviation of various features of the target user under the multi-dimensional assessment feature set is calculated and integrated to generate the comprehensive risk index of the target user.
[0050] In this embodiment, the user's multi-dimensional measured feature values are positioned and measured within a dynamic risk assessment benchmark defined by the current environment to quantify the degree of deviation of the user's negative behavior from the normal benchmark. After obtaining the dynamic deviation of each dimension, the system synthesizes them into a comprehensive risk index through a preset weighted fusion function. The fusion process acknowledges that different features contribute differently to the overall risk assessment. For example, associated risk features may have a higher weight because they can reveal group dynamics. These weights can be determined based on historical data verification or expert experience.
[0051] This step transforms multidimensional and heterogeneous risk signals into a single, objective, and rankable comprehensive risk index. This not only solves the problem of multi-indicator decision-making but also ensures that risk assessment is always based on the current environment, achieving accurate, adaptive, and automated intelligent risk control core judgments.
[0052] In operation S240, the anomaly level of the target user is determined based on the comprehensive risk index, and the corresponding handling operation is executed.
[0053] Matching a user's comprehensive risk index with a defined anomaly level range allows the comprehensive risk index to be assigned a risk level with business significance, providing a basis for decision-making in subsequent precise handling.
[0054] In this embodiment, a multi-level classification system is established to precisely refine the severity of users' negative behaviors. Through this classification, the system can distinguish between potential risks and confirmed malicious behavior, enabling the implementation of differentiated handling strategies tailored to the level of risk. This effectively combats malicious behavior while minimizing collateral damage to legitimate users.
[0055] In this embodiment, the system pre-defines a dynamic mapping relationship between anomaly levels and handling actions to ensure that the handling intensity is commensurate with the risk level. For example, for a primary anomaly level, the system increases the frequency of data collection and log recording of the user's behavior in the background, focusing on monitoring the user, and adds gentle, suggestive text to the user interface, such as "Your account has an abnormal behavior risk; please participate in activities in a regulated manner," aiming to guide the user to stop the abnormal behavior through psychological deterrence. For a high-level anomaly level, the system can restrict the user's eligibility to participate in high-value sub-activities or receive high-value rewards, or temporarily delay the distribution of rewards already obtained by the user, reserving time for manual review or system observation. According to this method, once an anomaly level is determined, the corresponding handling action is automatically and immediately triggered by the system without manual intervention, thereby achieving "in-process interception" and minimizing resource loss.
[0056] In this embodiment, the handling operation is not static; the intensity of the handling can be dynamically adjusted based on the user's subsequent behavior. If the user's behavior returns to normal, the system can automatically lift or reduce the handling.
[0057] According to the risk management method provided in this disclosure, by using real-time operational environment data as a covariate input into a structured time series model, a risk judgment benchmark that dynamically links with the environment is generated. This enables the threshold to adaptively adjust with business fluctuations, solving the problem of false positives during peak periods and false negatives during off-peak periods caused by fixed thresholds, and significantly improving the accuracy and environmental adaptability of risk identification. Simultaneously, by systematically extracting a three-dimensional feature set of frequency, pattern, and associated risks from behavioral data, a three-dimensional risk profile of users is constructed, enabling multi-dimensional, penetrating assessment of complex and concealed abnormal behaviors, greatly expanding the depth and breadth of risk identification coverage.
[0058] The risk management method provided in this disclosure will be described in detail below with reference to specific embodiments.
[0059] In operation S210, dynamic risk assessment benchmarks can be generated based on historical negative behavior data of the target user group and real-time operational environment data within the corresponding time window, which may include operations S211~S2123.
[0060] In operation S211, the historical operating environment data of the target user group is used as a covariate input into the structured time series model, and the historical negative behavior data of the target user group is used as the target variable for model training.
[0061] In this disclosed embodiment, when a user uses the application for the first time, they are clearly informed through the "User Privacy Agreement" and the "Activity Participation Instructions" that their historical and activity-period transaction data will be used to assess the integrity of their participation in the activity to ensure fairness. The user's check of the "agree" box constitutes authorization.
[0062] In this embodiment, the system first inputs historical operational environment data as covariates into a structured time series model, and uses historical negative behavior data as the target variable for model training. This process essentially allows the model to learn and quantify the dynamic conditional dependencies between environmental factors and group behavior indicators from aligned time series data. During training, the model simultaneously decomposes the inherent trends and seasonal cycles of the behavioral data and separates the regression effects explained by environmental variables, ultimately forming a set of model parameters that can accurately describe the "reasonable fluctuation range of negative behavior under different environmental conditions."
[0063] In operation S212, real-time business environment data is input into the trained structured time series model, and the posterior prediction probability distribution of each negative behavior indicator within a preset future time period is output.
[0064] In this embodiment, the currently collected real-time business environment data, such as the current activity page views and coupon real-time consumption rate, is input into the model trained by operation S211. The model then performs conditional probability calculations based on the dynamic "environment-behavior" dependency it has learned internally. Its core output is not a single predicted value, but rather the posterior predicted probability distribution of various negative behavior indicators over a preset future time period.
[0065] The probability distribution output by the model fully depicts the expected fluctuation range and uncertainty of each negative behavior indicator under the current specific operating conditions. For example, it not only gives "under the current high traffic, the expected number of abnormal orders per user per day is about 5", but also provides a complete statistical description such as "there is a 95% probability that this number will fall between 3 and 8 times". This probability distribution then becomes the direct and scientific basis for generating dynamic risk assessment benchmarks (such as taking its 95th percentile as the risk line), enabling risk standards to reflect and adapt to the ever-changing business environment in real time and accurately.
[0066] In operation S213, the dynamic risk assessment benchmark is confirmed based on the posterior predicted probability distribution.
[0067] In this embodiment of the disclosure, a high quantile of the posterior prediction probability distribution is selected as a benchmark based on the business party's requirements for the stringency of risk control. For example, if the risk control strategy is set to "only classify the 5% of users with the most abnormal behavior as high risk", the system will calculate the 95th percentile of the posterior prediction distribution and determine this value as the dynamic risk judgment benchmark in the current environment.
[0068] The key technological value of this step lies in achieving the decoupling and flexible configuration of strategy and computation. Business requirements (such as "controlling the most abnormal 5%)" are abstracted into a quantile selection instruction for a probability distribution, while the model is responsible for providing the precise shape of that distribution. This allows the same intelligent model to dynamically generate judgment criteria of varying stringency based on different business stages or risk preferences. For example, a higher quantile, such as 97%, can be used during major marketing campaigns to encourage participation and reduce false positives; while a slightly lower quantile, such as 90%, can be used during normal periods to strengthen control. By transforming statistical inference results into clear decision boundaries, this operation ultimately completes the closed-loop generation of dynamic risk judgment benchmarks, providing a scientific and flexible standard for subsequent real-time risk comparison and handling.
[0069] In this embodiment, a warning threshold lower than the dynamic risk assessment benchmark can also be set. When the target user's overall risk index exceeds the warning threshold but does not exceed the dynamic risk assessment benchmark, a warning operation is triggered to remind the target user. This warning threshold, together with the dynamic benchmark, constitutes a two-level risk range for warning and assessment.
[0070] Once the system calculates the target user's comprehensive risk index, it compares it with two thresholds: if the index exceeds the warning threshold but has not yet reached the dynamic risk assessment benchmark, the user is determined to have entered the "risk concern zone." At this point, the system will not implement strong restrictive measures, but will trigger preset warning operations, such as displaying a risk warning on the user interface, sending a reminder message, or requiring lightweight secondary verification. This design enables early and gentle intervention in risk management.
[0071] In operation S220, negative behavior data of the target user during the activity period is obtained, and multi-dimensional evaluation feature set is extracted from the negative behavior data, including operations S221 to S224.
[0072] In operation S221, negative behavior data of the target user during the activity period is obtained, including timestamps, behavior types, resource identifiers, and user identifiers.
[0073] In this embodiment of the disclosure, the system first extracts the original behavioral data of the target user during the activity period from the log data points and business database, filters out data with abnormal behaviors such as concentrated order placement, concentrated refunds or negative reviews, and cleans and parses it into structured behavioral data in a unified format.
[0074] In operation S222, based on negative behavior data, the frequency of occurrence of various negative behaviors within a preset time window is statistically analyzed to generate frequency characteristics.
[0075] In this embodiment of the disclosure, the system counts and statistically analyzes various negative behaviors in real time within a preset sliding time window, such as the past hour or the cumulative total for the day, based on the aforementioned structured data, and calculates the number of times or rate of occurrence per unit time.
[0076] In operation S223, based on the user behavior sequence in the negative behavior data, the negative behavior of the target user is quantified into negative pattern features.
[0077] In this embodiment, the system performs in-depth analysis of user behavior sequences. First, discrete behaviors are sorted by time to form a continuous behavioral trajectory. Then, sequence pattern analysis algorithms (such as Hidden Markov Models and sequence anomaly detection models) are applied to model and evaluate this trajectory. This operation is not a simple counting process, but rather a quantification of abnormal regularities in the behavioral sequence that violate human operating habits or normal business logic. For example, it detects the existence of machine-like precise operation intervals, fixed cyclical paths, or abnormal context combinations, thereby transforming difficult-to-discover strategic and programmatic cheating patterns into computable pattern feature values.
[0078] In operation S224, a risk association network is constructed based on the user relationships implied in the negative behavior data, and the risk transmission influence of the target user on users with related relationships is quantified by graph calculation indicators to generate association risk characteristics.
[0079] In this embodiment, user relationships (such as shared devices, IP address clusters, social connections, and financial links) are mined from behavioral data, and a risk association network graph is constructed based on this graph. Nodes represent users, and edges represent association strength. Subsequently, the system uses graph computation algorithms (such as calculating node degree centrality, eigenvector centrality, or performing community discovery) to quantify the topological importance of target users within the network and their potential influence as risk hubs. The associated risk features generated by this operation can effectively reveal group-based and contagious risks that isolated individual behavioral analysis cannot detect, achieving a dimensional upgrade in risk identification from a "point" to a "surface" approach.
[0080] By executing the three feature extraction operations S222, S223, and S224 in parallel, the system systematically transforms the original behavioral flow into three complementary and progressively deeper feature dimensions: frequency, pattern, and associated risk. Together, these features construct a three-dimensional and comprehensive user risk profile, laying a solid data foundation for subsequent accurate and intelligent risk assessment.
[0081] In operation S230, based on the dynamic risk assessment benchmark, the dynamic deviation of various features of the target user under the multi-dimensional assessment feature set is calculated and integrated to generate the comprehensive risk index of the target user, including operations S231~S232.
[0082] In operation S231, based on the posterior predicted probability distribution in the dynamic risk judgment benchmark, the extreme probability of each feature of the target user in the corresponding posterior predicted probability distribution is calculated as the dynamic deviation.
[0083] In this embodiment, the dynamic risk assessment benchmark provides a posterior predicted probability distribution for each feature dimension under corresponding environmental conditions. This distribution defines the expected fluctuation range of the feature under normal circumstances. For each feature among frequency, negative pattern, and associated risk, the system statistically locates the user's actual feature value within its corresponding posterior predicted probability distribution. Specifically, it calculates the extreme probability, i.e., the probability that the actual value appears at the extreme tail of the distribution. Technically, this is typically achieved by calculating the cumulative distribution function value of the value in the distribution and converting it into a one-sided P-value. The generated dynamic deviation is a standardized probability value.
[0084] In operation S232, the dynamic deviations of frequency characteristics, negative pattern characteristics, and associated risk characteristics are weighted and summed to generate a comprehensive risk index.
[0085] In this embodiment, a preset fusion weight is assigned to frequency, negative patterns, and associated risk characteristics. These weights reflect the relative importance of different dimensions in the overall risk assessment. For example, associated risk characteristics are often given higher weights due to their ability to reveal group dynamics. The comprehensive risk index is typically calculated by weighted summation after applying a negative logarithmic transformation to the dynamic deviations of each dimension.
[0086] In operation S240, the anomaly level of the target user is determined based on the comprehensive risk index, and the corresponding handling operations are performed, including operations S241 to S243.
[0087] In operation S241, the corresponding basic anomaly level is determined based on the classification range of the comprehensive risk index.
[0088] In this embodiment, the calculated comprehensive risk index is compared with a series of preset, static grading threshold intervals. Each interval corresponds to a basic anomaly level, such as "low risk," "medium risk," and "high risk." This grading process is a preliminary judgment based on a snapshot, providing the user with an initial, easily understood label for their risk status.
[0089] In operation S242, the basic anomaly level is adjusted based on the risk index change trend of the target user within the preset observation period to obtain the anomaly level.
[0090] Introducing a risk level adjustment based on the trend of risk index changes within a preset observation period allows the system to consider not only "how dangerous the user is at this moment" but also "how the user's level of danger is changing" when making decisions. By incorporating the evolution of risk into the decision factors, the system can dynamically calibrate the initial level: for users whose risk continues to escalate, even if their current index has not reached a higher threshold, the level should be raised to prevent potential problems; for users whose risk has significantly mitigated, even if their historical index is high, the level should be lowered to reflect fairness. This makes the final risk assessment and handling more forward-looking, adaptable, and accurate.
[0091] Operation S242 includes operations S2421 to S2424.
[0092] In operation S2421, the rate of change of the comprehensive risk index of the target user during the preset observation period is calculated.
[0093] For example, if the preset observation period is the past 30 minutes, the system obtains a series of the user's comprehensive risk index during this period. By calculating the linear regression slope or the average change per unit time of this time series, the system derives a quantified rate of change. A positive value indicates that the risk index is rising, and a negative value indicates that it is falling.
[0094] In operation S2422, the rate of change is compared with preset positive trend thresholds and negative trend thresholds, which are determined based on the range of risk index changes predicted by the structured time series model.
[0095] In this embodiment of the disclosure, the system invokes the aforementioned structured time series model. This model can not only predict the level value of the risk index, but also predict its normal fluctuation range within a given observation period, i.e., the "risk index change range". The system sets the upper limit of this predicted range as a positive trend threshold and the lower limit as a negative trend threshold.
[0096] In operation S2423, if the rate of change is greater than the positive trend threshold, it is determined to be an accelerating risk situation, and the basic anomaly level is revised upward by at least one level.
[0097] If the calculated rate of change is greater than the dynamically generated positive trend threshold, it indicates that the user's risk is rising significantly faster than normal fluctuations that can be explained in the current environment. The system determines this as an "accelerated risk situation" and adjusts the basic anomaly level upward by at least one level, for example, from "medium risk" to "high risk".
[0098] In operation S2424, if the rate of change is less than the negative trend threshold, it is determined to be a risk mitigation situation, and the basic anomaly level is revised down by at least one level.
[0099] If the rate of change is less than the dynamically generated negative trend threshold, it indicates that the user's risk improvement speed significantly exceeds normal expectations. The system determines this as a "risk mitigation situation" and lowers the basic anomaly level by at least one level, for example, from "medium risk" to "low risk" or "under observation".
[0100] If the rate of change is between the two thresholds, the risk status is determined to be fluctuating within the normal range, and the original basic abnormal level is maintained.
[0101] In operation S243, based on the multi-level mapping relationship between exception level and handling operation, the corresponding handling operation is called and executed. The intensity of the handling operation is positively correlated with the exception level.
[0102] In this embodiment, the system maintains a pre-defined multi-level mapping table between anomaly levels and corresponding handling operations. This is a well-defined strategy configuration, where each anomaly level precisely corresponds to a set of pre-defined, progressive handling operation packages. Once the final risk level is determined, the system automatically queries this mapping table, calls and executes the complete handling operation package matching that level. Low-risk levels may trigger only lightweight monitoring and alerting operations, such as displaying a mild risk warning on the user interface or slightly increasing the frequency of collecting user behavior logs, aiming to observe and warn with minimal interference. Medium-risk levels will execute function restriction and delay operations, such as temporarily restricting the user's participation in specific high-value activities, such as flash sales or lotteries, or delaying the distribution of already obtained rewards, controlling potential losses while leaving room for observation and callback of user behavior. High-risk levels will initiate strong intervention and blocking operations, such as immediately suspending the user's eligibility to participate in all activities, freezing related assets and rights in their account, and automatically generating a case for manual review, to achieve rapid risk isolation and control.
[0103] In some embodiments of this disclosure, after operation S243 performs the action on the target user, an observation period, such as 24 hours or 3 days, can be initiated for the target user. This observation period can be used to monitor whether the action measures effectively guide user behavior and whether the user's own risk status has substantially improved. If the target user's overall risk index continues to decline to a lower abnormality level range during the observation period, for example, from a high-risk range to a medium-risk range, then its abnormality level and the corresponding action intensity are automatically reduced. This mechanism provides users with a clear path to mitigate penalties by correcting their behavior, reflecting the fairness of control.
[0104] Based on the aforementioned risk management methods, this disclosure also provides a risk management device. The following will be combined with... Figure 3 The device is described in detail.
[0105] Figure 3 A schematic block diagram of a risk management device according to an embodiment of the present disclosure is shown.
[0106] like Figure 3 As shown, the risk management device 300 in this embodiment includes a baseline generation module 310, a feature extraction module 320, a risk assessment module 330, and a risk handling module 340.
[0107] The benchmark generation module 310 is used to generate a dynamic risk assessment benchmark based on historical negative behavior data of the target user group and real-time operational environment data within the corresponding time window. The dynamic risk assessment benchmark is obtained by dynamically fitting the statistical distribution of historical negative behavior data using a structured time series model, with real-time business environment data as a covariate. In one embodiment, the benchmark generation module 310 can be used to perform the operation S210 described above, which will not be repeated here.
[0108] The feature extraction module 320 is used to acquire the target user's behavioral data during the activity period and extract a multi-dimensional evaluation feature set from the behavioral data. The multi-dimensional evaluation feature set includes at least the frequency features of user behavior, negative pattern features, and associated risk features. In one embodiment, the feature extraction module 320 can be used to perform the operation S220 described above, which will not be repeated here.
[0109] The risk assessment module 330 is used to calculate and integrate the dynamic deviation of various characteristics of the target user under the multi-dimensional assessment feature set based on the dynamic risk judgment benchmark, and generate a comprehensive risk index for the target user. In one embodiment, the risk assessment module 330 can be used to perform the operation S230 described above, which will not be repeated here.
[0110] The risk handling module 340 is used to determine the anomaly level of a target user based on a comprehensive risk index and execute handling operations corresponding to the anomaly level. In one embodiment, the risk handling module 340 can be used to execute the operation S240 described above, which will not be repeated here.
[0111] According to embodiments of this disclosure, any multiple modules among the benchmark generation module 310, feature extraction module 320, risk assessment module 330, and risk handling module 340 can be combined into one module, or any one of these modules can be split into multiple modules. Alternatively, at least some of the functions of one or more of these modules can be combined with at least some of the functions of other modules and implemented in one module. According to embodiments of this disclosure, at least one of the benchmark generation module 310, feature extraction module 320, risk assessment module 330, and risk handling module 340 can be at least partially implemented as hardware circuitry, such as a field-programmable gate array (FPGA), a programmable logic array (PLA), a system-on-a-chip, a system-on-a-substrate, a system-on-package, an application-specific integrated circuit (ASIC), or implemented in hardware or firmware by any other reasonable means of integrating or packaging the circuitry, or implemented in software, hardware, or firmware, or in any suitable combination of any of these three implementation methods. Alternatively, at least one of the benchmark generation module 310, feature extraction module 320, risk assessment module 330, and risk management module 340 may be implemented at least partially as a computer program module, which can perform corresponding functions when the computer program module is run.
[0112] Figure 4 A block diagram of an electronic device suitable for implementing a risk management method according to an embodiment of the present disclosure is shown schematically.
[0113] like Figure 4 As shown, an electronic device 400 according to an embodiment of the present disclosure includes a processor 401, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 402 or a program loaded from a storage portion 408 into a random access memory (RAM) 403. The processor 401 may include, for example, a general-purpose microprocessor (e.g., a CPU), an instruction set processor and / or an associated chipset and / or a special-purpose microprocessor (e.g., an application-specific integrated circuit (ASIC)), etc. The processor 401 may also include onboard memory for caching purposes. The processor 401 may include a single processing unit or multiple processing units for performing different actions of the method flow according to an embodiment of the present disclosure.
[0114] RAM 403 stores various programs and data required for the operation of electronic device 400. Processor 401, ROM 402, and RAM 403 are interconnected via bus 404. Processor 401 performs various operations of the method flow according to embodiments of the present disclosure by executing programs in ROM 402 and / or RAM 403. It should be noted that programs may also be stored in one or more memories other than ROM 402 and RAM 403. Processor 401 may also perform various operations of the method flow according to embodiments of the present disclosure by executing programs stored in one or more memories.
[0115] According to embodiments of this disclosure, the electronic device 400 may further include an input / output (I / O) interface 405, which is also connected to a bus 404. The electronic device 400 may also include one or more of the following components connected to the input / output (I / O) interface 405: an input section 406 including a keyboard, mouse, etc.; an output section 407 including a cathode ray tube (CRT), liquid crystal display (LCD), etc., and a speaker, etc.; a storage section 408 including a hard disk, etc.; and a communication section 409 including a network interface card such as a LAN card, modem, etc. The communication section 409 performs communication processing via a network such as the Internet. A drive 410 is also connected to the input / output (I / O) interface 405 as needed. A removable medium 411, such as a disk, optical disk, magneto-optical disk, semiconductor memory, etc., is installed on the drive 410 as needed so that computer programs read from it can be installed into the storage section 408 as needed.
[0116] This disclosure also provides a computer-readable storage medium, which may be included in the device / apparatus / system described in the above embodiments; or it may exist independently and not assembled into the device / apparatus / system. The computer-readable storage medium carries one or more programs that, when executed, implement the method according to the embodiments of this disclosure.
[0117] According to embodiments of this disclosure, the computer-readable storage medium may be a non-volatile computer-readable storage medium, such as including, but not limited to: portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof. In this disclosure, the computer-readable storage medium may be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. For example, according to embodiments of this disclosure, the computer-readable storage medium may include ROM 402 and / or RAM 403 and / or one or more memories other than ROM 402 and RAM 403 described above.
[0118] Embodiments of this disclosure also include a computer program product comprising a computer program containing program code for performing the methods shown in the flowchart. When the computer program product is run on a computer system, the program code is used to enable the computer system to implement the risk management methods provided in the embodiments of this disclosure.
[0119] When the computer program is executed by the processor 401, it performs the functions defined in the system / apparatus of this disclosure embodiments. According to embodiments of this disclosure, the systems, apparatuses, modules, units, etc., described above can be implemented by computer program modules.
[0120] In one embodiment, the computer program may rely on a tangible storage medium such as an optical storage device or a magnetic storage device. In another embodiment, the computer program may also be transmitted and distributed in the form of signals over a network medium, and downloaded and installed via communication section 409, and / or installed from removable medium 411. The program code contained in the computer program can be transmitted using any suitable network medium, including but not limited to: wireless, wired, etc., or any suitable combination thereof.
[0121] In such an embodiment, the computer program can be downloaded and installed from a network via communication section 409, and / or installed from removable medium 411. When the computer program is executed by processor 401, it performs the functions defined in the system of this disclosure embodiment. According to embodiments of this disclosure, the systems, devices, apparatuses, modules, units, etc., described above can be implemented by computer program modules.
[0122] According to embodiments of this disclosure, program code for executing the computer programs provided in embodiments of this disclosure can be written in any combination of one or more programming languages. Specifically, these computational programs can be implemented using high-level procedural and / or object-oriented programming languages, and / or assembly / machine languages. Programming languages include, but are not limited to, languages such as Java, C++, Python, "C", or similar programming languages. The program code can execute entirely on a user's computing device, partially on a user's device, partially on a remote computing device, or entirely on a remote computing device or server. In cases involving remote computing devices, the remote computing device can be connected to the user's computing device via any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computing device (e.g., via the Internet using an Internet service provider).
[0123] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this disclosure. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram or flowchart, and combinations of blocks in a block diagram or flowchart, may be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.
[0124] Those skilled in the art will understand that the features described in the various embodiments of this disclosure can be combined and / or combined in various ways, even if such combinations or combinations are not explicitly described in this disclosure. In particular, the features described in the various embodiments of this disclosure can be combined and / or combined in various ways without departing from the spirit and teachings of this disclosure. All such combinations and / or combinations fall within the scope of this disclosure.
[0125] The embodiments of this disclosure have been described above. However, these embodiments are for illustrative purposes only and are not intended to limit the scope of this disclosure. Although various embodiments have been described above, this does not mean that the measures in the various embodiments cannot be used advantageously in combination. Various substitutions and modifications can be made by those skilled in the art without departing from the scope of this disclosure, and all such substitutions and modifications should fall within the scope of this disclosure.
Claims
1. A risk management method, characterized in that, The method includes: Based on historical negative behavior data of the target user group and real-time operational environment data within the corresponding time window, a dynamic risk assessment benchmark is generated. The dynamic risk assessment benchmark is obtained by using real-time business environment data as a covariate and dynamically fitting the statistical distribution of historical negative behavior data using a structured time series model. Acquire negative behavior data of target users during the activity period, and extract a multi-dimensional evaluation feature set from the negative behavior data. The multi-dimensional evaluation feature set includes at least the frequency characteristics, negative pattern characteristics, and associated risk characteristics of user negative behavior. Based on the dynamic risk assessment benchmark, the dynamic deviation of the target user under the multi-dimensional assessment feature set is calculated and integrated to generate the comprehensive risk index of the target user; Based on the comprehensive risk index, the anomaly level of the target user is determined, and the corresponding handling operation is performed.
2. The method according to claim 1, characterized in that, The dynamic risk assessment benchmark generated based on historical negative behavior data of the target user group and real-time operational environment data within the corresponding time window includes: The historical operating environment data of the target user group is used as a covariate and input into the structured time series model, while the historical negative behavior data of the target user group is used as the target variable for model training. The real-time business environment data is input into the trained structured time series model, and the posterior prediction probability distribution of each negative behavior indicator within a preset future time period is output. Based on the aforementioned posterior predicted probability distribution, a dynamic risk assessment benchmark is established.
3. The method according to claim 2, characterized in that, The method further includes: Set a warning threshold that is lower than the dynamic risk assessment benchmark; When the target user's overall risk index exceeds the warning threshold but does not exceed the dynamic risk assessment benchmark, a warning operation is triggered to remind the target user.
4. The method according to claim 1, characterized in that, The step of acquiring negative behavior data of target users during the activity period and extracting a multi-dimensional evaluation feature set from the negative behavior data includes: Obtain negative behavior data of the target user during the activity period, including timestamps, behavior types, resource identifiers, and user identifiers. Based on the negative behavior data, the frequency of occurrence of various negative behaviors within a preset time window is statistically analyzed to generate the frequency characteristics; Based on the user behavior sequence in the negative behavior data, the negative behavior of the target user is quantified into the negative pattern features; Based on the user relationships implied in the negative behavior data, a risk association network is constructed, and the risk transmission influence of the target user on users with related relationships is quantified by graph computing indicators to generate the associated risk characteristics.
5. The method according to claim 1, characterized in that, The process of calculating and fusing the dynamic deviation of the target user's various features under the multi-dimensional assessment feature set based on the dynamic risk assessment benchmark to generate the target user's comprehensive risk index includes: Based on the posterior prediction probability distribution in the dynamic risk judgment benchmark, the extreme probabilities of each feature of the target user in the corresponding posterior prediction probability distribution are calculated as the dynamic deviation. The dynamic deviations of the frequency characteristics, negative pattern characteristics, and associated risk characteristics are weighted and summed to generate the comprehensive risk index.
6. The method according to claim 1, characterized in that, The step of determining the anomaly level of the target user based on the comprehensive risk index and performing the corresponding handling operation includes: Based on the classification range in which the comprehensive risk index is located, the corresponding basic anomaly level is determined; Based on the risk index change trend of the target user during the preset observation period, the basic anomaly level is corrected to obtain the anomaly level; Based on the multi-level mapping relationship between the anomaly level and the handling operation, the corresponding handling operation is invoked and executed, and the intensity of the handling operation is positively correlated with the height of the anomaly level.
7. The method according to claim 6, characterized in that, The step of correcting the basic anomaly level based on the risk index change trend of the target user within a preset observation period to obtain the anomaly level includes: Calculate the rate of change of the comprehensive risk index of the target user during the preset observation period; The rate of change is compared with preset positive trend thresholds and negative trend thresholds, which are determined based on the range of risk index changes predicted by the structured time series model. If the rate of change is greater than the positive trend threshold, it is determined to be an accelerating risk situation, and the basic anomaly level is revised upward by at least one level. If the rate of change is less than the negative trend threshold, it is determined to be a risk mitigation situation, and the basic anomaly level is adjusted down by at least one level.
8. The method according to claim 6, characterized in that, The method further includes: An observation period will be initiated for the target users to whom the action is taken. If the target user's overall risk index continues to decline to the lower abnormality level range during the observation period, its abnormality level and corresponding handling intensity will be automatically reduced.
9. A risk management device, characterized in that, The device includes: The benchmark generation module is used to generate a dynamic risk assessment benchmark based on the historical negative behavior data of the target user group and the real-time operating environment data within the corresponding time window. The dynamic risk assessment benchmark is obtained by using real-time business environment data as a covariate and dynamically fitting the statistical distribution of historical negative behavior data using a structured time series model. The feature extraction module is used to acquire negative behavior data of target users during the activity period, and extract a multi-dimensional evaluation feature set from the negative behavior data. The multi-dimensional evaluation feature set includes at least the frequency feature, negative pattern feature, and associated risk feature of the user's negative behavior. The risk assessment module is used to calculate and integrate the dynamic deviation of the target user under the multi-dimensional assessment feature set based on the dynamic risk judgment benchmark, and generate the comprehensive risk index of the target user. The risk handling module is used to determine the anomaly level of the target user based on the comprehensive risk index and to perform handling operations corresponding to the anomaly level.
10. An electronic device, comprising: One or more processors; Memory, used to store one or more computer programs. The characteristic feature is that the one or more processors execute the one or more computer programs to implement the steps of the method according to any one of claims 1 to 8.
11. A computer-readable storage medium having a computer program or instructions stored thereon, characterized in that, When the computer program or instructions are executed by a processor, they implement the steps of the method according to any one of claims 1 to 8.
12. A computer program product, comprising a computer program or instructions, characterized in that, When the computer program or instructions are executed by a processor, they implement the steps of the method according to any one of claims 1 to 8.