Information processing method and device, electronic equipment, storage medium and program product

By categorizing metadata into three types—basic, environmental, and risk—and generating derived information and adjusting weighting coefficients, the problems of fragmented adaptation, insufficient data collection rate, and excessive risk control in mobile payments are solved, achieving more accurate risk assessment and higher security.

CN121997318APending Publication Date: 2026-05-08CHINA UNIONPAY
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
CHINA UNIONPAY
Filing Date
2025-12-25
Publication Date
2026-05-08

AI Technical Summary

Technical Problem

Existing technologies in mobile payments suffer from fragmented adaptation, insufficient data collection, excessive risk control, and a lack of prevention and control, resulting in inconsistent and ineffective risk prevention and control methods.

Method used

Meta-information is categorized into three types: basic, environmental, and risk. Derivative information is generated to characterize abnormal behavior patterns. Weight coefficients are adjusted using regression algorithms and weighted processing is performed to generate risk characteristics. Risk assessment is then conducted by integrating multi-dimensional information.

Benefits of technology

It resolves the risk blind spots caused by permission denial, improves the accuracy and security of risk detection, reduces the false positive rate, improves user experience, and increases the difficulty and cost of attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121997318A_ABST
    Figure CN121997318A_ABST
Patent Text Reader

Abstract

According to the information processing method and device, the electronic equipment, the storage medium and the program product, bottom layer data can be classified into three categories, bottom layer fragmentation differences are isolated, an upper layer model does not need to concern the specific source of the data, a large number of adaptive codes do not need to be written for each situation, and maintenance and unification are facilitated. Afterwards, by generating derivative information, information missing is converted into features of risk assessment, and the problem of risk blind areas caused by permission rejection is solved. Subsequently, based on a dynamic weight adjustment mechanism of real-time state information, the model can distinguish abnormity and maliciousness, misjudgment caused by model stiffness is reduced, and while safety is guaranteed, the experience of legal users is greatly improved. And finally, through multi-dimensional information fusion, an attacker needs to perfectly simulate normal equipment in all dimensions at the same time, so that the attack cost and difficulty are greatly improved, and a security breakthrough caused by single feature deficiency or improper processing is effectively blocked.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of information security technology, and in particular to an information processing method, apparatus, electronic device, storage medium, and program product. Background Technology

[0002] With the widespread adoption of mobile payments, users are making payments and transferring money more frequently using their smartphones, which in turn increases the risks involved.

[0003] Currently, the main method of risk prevention and control is to collect basic information, environmental information, and risk labels of the mobile device (mobile terminal) where the APP is located through a single mobile application (APP), and to judge the risk situation based on this information and incorporate it into the reference factors for the APP's comprehensive risk decision-making.

[0004] However, this risk control method has certain limitations, such as fragmented adaptation, insufficient data collection rate, excessive risk control, and lack of prevention and control. Summary of the Invention

[0005] This application provides information processing methods, apparatus, electronic devices, storage media, and program products to address issues such as fragmented adaptation, insufficient data collection rate, excessive risk control, and lack of prevention and control.

[0006] In a first aspect, embodiments of this application provide an information processing method, including:

[0007] Obtain the metadata of the target device, which includes basic information, environmental information, and risk information;

[0008] The metadata is processed to generate at least one type of derived information, which is used to characterize the abnormal behavior patterns implied in the metadata.

[0009] Based on the status information of the target device, adjust the weight coefficient corresponding to at least one type of derived information;

[0010] Based on the adjusted weighting coefficients, the meta-information and the derived information are weighted to obtain the risk characteristics of the target device, which are used to characterize the risk probability of the target device.

[0011] In one possible implementation, the derived information includes at least one of the following:

[0012] Uncollected information, which is used to characterize information that was not collected due to permission denial, but whose absence itself carries risks;

[0013] Abnormal change information, which is used to characterize information that should remain fixed but has undergone abnormal changes;

[0014] Abnormal static information, which is used to characterize information that should change over time but remains static.

[0015] In one possible implementation, the processing of the metadata to generate at least one type of derived information includes at least one of the following:

[0016] Based on the metadata, at least one key information collection permission is determined; according to the authorization response result of the key information collection permission, the uncollected information is generated.

[0017] Based on the selected stable term in the metadata, the current value of the selected stable term is compared with the dynamic baseline to determine the abnormal change information caused by abnormal information changes;

[0018] Based on the selected dynamic item in the metadata and the context conditions under which the selected dynamic item should change; and according to the state of the selected dynamic item during the time period in which the context conditions are met, determine the abnormal static information generated due to abnormal information staticity.

[0019] In one possible implementation, adjusting the weight coefficients corresponding to at least one type of derived information based on the state information of the target device includes:

[0020] The state information of the target device is input into the regression algorithm, which is used to adjust the weight coefficients corresponding to at least one type of derived information based on the state information of the target device, and output the adjusted weight coefficients.

[0021] In one possible implementation, the regression algorithm includes the Cox regression algorithm.

[0022] In one possible implementation, the meta-information and the derived information are weighted based on adjusted weighting coefficients to obtain the risk characteristics of the target device, including:

[0023] The metadata and the derived information are quantized to obtain the quantization results of the metadata and the derived information.

[0024] Based on the adjusted weighting coefficients and the quantification results of the meta-information and the derived information, a weighted processing is performed to obtain the risk characteristics of the target device.

[0025] In one possible implementation, the weighted processing based on the adjusted weight coefficients and the quantization results of the meta-information and the derived information to obtain the risk characteristics of the target device includes:

[0026] Based on the quantification results of the risk information and the derived information, and the corresponding weighting coefficients, a first weighting value is determined;

[0027] Based on the quantization results of the meta-information and the derived information, and the corresponding weighting coefficients, a second weighting value is determined;

[0028] The risk characteristics are determined based on the first weighted value and the second weighted value.

[0029] In one possible implementation, the method further includes:

[0030] Output a risk contribution factor label, which is used to indicate one or more specific risk information items that contribute the most to the risk characteristic.

[0031] In one possible implementation, the method further includes:

[0032] When the risk characteristics of the target device indicate that the probability of risk of the target device is greater than a preset threshold, the risk clue of the target device is sent to the backend server corresponding to the first application, so that the backend server uploads the risk clue to the risk clue sharing platform; the risk clue includes at least one of the identifier of the target device and the risk account identifier associated with the target device.

[0033] The risk clues in the risk clue sharing platform are used to instruct the backend servers of other applications to perform risk control based on the risk clues.

[0034] In one possible implementation, the number of target devices is multiple; the method further includes:

[0035] Based on the risk characteristics of multiple target devices and associated clustering elements, the multiple target devices are clustered to identify other risky devices;

[0036] The clustering elements include at least one of the following: equipment environmental spatial information, counterparty information, risk score contribution factors, and equipment activity time series information.

[0037] In one possible implementation, clustering multiple target devices based on their risk characteristics and associated clustering elements to identify other risky devices includes:

[0038] Based on the risk characteristics, risk contribution factors, and at least one clustering element, construct a feature triplet to characterize each of the target devices;

[0039] Based on the feature triplet, a community detection algorithm is used to divide the multiple target devices into communities to obtain an initial community set.

[0040] Based on a preset quality function, the initial community set is iteratively optimized until the preset optimization conditions are met, resulting in an optimized community division. Among these, devices within the same community are more likely to be identified as belonging to the same risk group than devices in different communities.

[0041] Secondly, embodiments of this application provide an information processing apparatus, including:

[0042] The acquisition module is used to acquire metadata of the target device, including basic information, environmental information and risk information;

[0043] The first processing module is used to process the metadata to generate at least one type of derived information, wherein the derived information is used to characterize the abnormal behavior patterns implied in the metadata.

[0044] The second processing module is used to adjust the weight coefficients corresponding to at least one type of derived information based on the status information of the target device.

[0045] The third processing module is used to perform weighted processing on the meta-information and the derived information based on the adjusted weight coefficients to obtain the risk characteristics of the target device, and the risk characteristics are used to characterize the risk probability of the target device.

[0046] Thirdly, embodiments of this application provide an electronic device, including: a memory and a processor;

[0047] The memory stores computer-executed instructions;

[0048] The processor executes computer execution instructions stored in the memory, causing the processor to perform the first aspect and / or various possible implementations of the first aspect as described above.

[0049] Fourthly, embodiments of this application provide a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, are used to implement the first aspect and / or various possible implementations of the first aspect.

[0050] Fifthly, embodiments of this application provide a computer program product, including a computer program that, when executed by a processor, implements the first aspect and / or various possible implementations of the first aspect.

[0051] The information processing method, apparatus, electronic device, storage medium, and program product provided in this application acquire metadata of the target device. This metadata includes basic information, environmental information, and risk information. All underlying data can be categorized into these three types, isolating fragmented differences and eliminating the need for custom code for each situation. The metadata is then processed to generate at least one type of derived information. This derived information characterizes abnormal behavior patterns implicit in the metadata. By generating derived information, missing information is transformed into risk assessment features, addressing the risk blind spot problem caused by permission denial. Subsequently, based on the target device's status information, the weight coefficients corresponding to at least one type of derived information are adjusted. A dynamic weight adjustment mechanism based on real-time status information enables the model to distinguish between abnormal and malicious activity, reducing misjudgments caused by model rigidity and significantly improving the experience for legitimate users while ensuring security. Finally, based on the adjusted weight coefficients, the metadata and derived information are weighted to obtain the risk characteristics of the target device. Through multi-dimensional information fusion, attackers must perfectly simulate a normal device across all dimensions, greatly increasing the cost and difficulty of attacks and effectively blocking security breaches caused by missing or improperly processed single features. Attached Figure Description

[0052] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.

[0053] Figure 1 Flowchart of the information processing method provided in this application Figure 1 ;

[0054] Figure 2 A schematic diagram of the information processing method provided in this application;

[0055] Figure 3 Flowchart of the information processing method provided in this application Figure 2 ;

[0056] Figure 4 A schematic diagram of the information processing method provided in this application;

[0057] Figure 5 A flowchart illustrating the information processing method provided in this application;

[0058] Figure 6 A schematic diagram of the information processing method provided in this application;

[0059] Figure 7 A schematic diagram of the information processing apparatus provided in this application;

[0060] Figure 8 A schematic diagram of the structure of the electronic device provided in this application.

[0061] The accompanying drawings illustrate specific embodiments of this application, which will be described in more detail below. These drawings and descriptions are not intended to limit the scope of the concept in any way, but rather to illustrate the concept of this application to those skilled in the art through reference to particular embodiments. Detailed Implementation

[0062] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.

[0063] With the widespread adoption of mobile payments, users are making payments and transferring money via smartphones more frequently, which also increases the risks involved. For example, user devices may be remotely controlled, or the device environment may be tampered with by malware or vulnerabilities, bypassing the risk control mechanisms of individual mobile payment apps, leading to resource theft, fraudulent transactions, and other problems.

[0064] Currently, the main method of risk prevention and control is to collect basic information, environmental information, and risk labels of the mobile device (mobile terminal) where the APP is located through a single mobile application (APP), and to judge the risk situation based on this information and incorporate it into the reference factors for the APP's comprehensive risk decision-making.

[0065] The basic information includes the mobile terminal's operating system, brand, and model; the environmental information includes IP address, GPS location, and a list of apps installed on the device; and the risk tags can include root access, jailbreaking, and running multiple instances of software.

[0066] However, existing technologies have the following limitations:

[0067] (1) Fragmentation adaptation problem

[0068] Each mobile terminal manufacturer provides fragmented differences in its ability to identify device status. For example, there are at least four types of operating systems, including Android, Google, HarmonyOS, and iOS. The processing logic of different versions of each type of operating system is also different, which means that risk models need to write a lot of adaptation code for each situation, making them difficult to maintain and unify.

[0069] (2) Insufficient collection rate

[0070] Some device information (such as contacts and system permissions) requires user authorization, resulting in insufficient data collection.

[0071] (3) Over-risk control and conflict experience

[0072] In an effort to reduce the time of risk, some apps set the device risk scoring threshold too low, leading to misjudgments and impacting user experience.

[0073] (4) Lack of risk prevention and control

[0074] A single app's mishandling of certain operating systems or the absence of some key device elements can be used as a breakthrough point.

[0075] To address this, this application proposes an information processing method that categorizes underlying data into three unified categories (basic, environment, and risk), regardless of whether the data originates from Android, iOS, or HarmonyOS. This isolates the fragmented differences at the underlying level, eliminating the need for upper-layer models to concern themselves with the specific data source. This avoids the need to write extensive adaptation code for each scenario, facilitating maintenance and standardization. By generating derived information, missing information is transformed into features for risk assessment, resolving the risk blind spot caused by permission denial. A dynamic weight adjustment mechanism based on real-time status information enables the model to distinguish between anomalies and malicious intent, reducing misjudgments caused by model rigidity and significantly improving the experience for legitimate users while ensuring security. Through multi-dimensional information fusion, attackers are required to perfectly simulate normal devices across all dimensions, greatly increasing the cost and difficulty of attacks and effectively blocking security vulnerabilities caused by missing or improperly processed single features.

[0076] The technical solution of this application and how the technical solution of this application solves the above-mentioned technical problems are described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments. The embodiments of this application will now be described with reference to the accompanying drawings.

[0077] Figure 1 Flowchart of the information processing method provided in this application Figure 1 ,like Figure 1 As shown, using an electronic device as the execution subject, the method includes:

[0078] S101. Obtain the metadata of the target device, which includes basic information, environmental information and risk information.

[0079] The target device can be any mobile terminal, such as a mobile phone or tablet. The metadata of the target device refers to a comprehensive data set of its basic attributes, operating status, and potential risk characteristics. Meta-information can include basic information, environmental information, and risk information.

[0080] Basic information refers to the inherent hardware and core software attributes of a device that typically remain unchanged during its normal usage cycle. Basic information may include the device brand, model, and hardware specifications.

[0081] Device brand refers to the manufacturer or brand identity of a mobile terminal; device model refers to a specific device model defined by the manufacturer to distinguish product lines with different hardware configurations under the same brand; hardware parameters refer to characteristic values ​​describing the physical hardware specifications of the device, including but not limited to the model and number of cores of the central processing unit (CPU), the capacity of random access memory (RAM), the capacity of read-only memory (ROM), the screen resolution and size, the sensor type, and the International Mobile Equipment Identity (IMEI).

[0082] Sensor types can include gyroscopes, accelerometers, proximity sensors, and light sensors. The International Mobile Equipment Identity (IMEI) is a digital identifier used to uniquely identify cellular network devices. The Media Access Control (MAC) address is a unique identifier for the network interface.

[0083] Environmental information refers to dynamic information reflecting the current operating status, resource status, and external environment of a device. Environmental information may include device power-on time, battery level, CPU and memory usage, storage space, and temperature. It may also include geographical and network environment information, such as IP (Internet Protocol), GPS (Global Positioning System), network connection type, and Wi-Fi status.

[0084] Power-on time refers to the length of time the device has been running continuously since its last startup; battery power refers to the percentage of the device's current remaining power; CPU utilization refers to the percentage of the central processing unit's activity level within a specific time interval; memory usage refers to the percentage or specific capacity of currently used running memory relative to the total memory; device storage space refers to the used and remaining capacity of the device's internal storage; device temperature refers to the current temperature value of key components of the device (such as the battery and CPU) read by sensors.

[0085] An IP address is the logical address assigned to a device in the current network connection, which can be used to infer its approximate geographical location and network service provider; GPS positioning refers to the latitude and longitude coordinates of the device obtained through the Global Positioning System, representing its precise geographical location; network connection type refers to the way the device is currently accessing the Internet, such as Wi-Fi, cellular network (4G / 5G), etc.; Wi-Fi status indicates whether the device's Wi-Fi function is enabled, as well as the Service Set Identifier (SSID) or Basic Service Set Identifier (BSSID) of the currently connected Wi-Fi network.

[0086] Risk information refers to feature tags that are directly identified through system interfaces, security scans, or behavioral analysis, clearly indicating that a device may be in an insecure or malicious state. Risk information can be obtained through technical interfaces provided by device manufacturers, marking potential risk characteristics of the device, which may include characteristics of compromised system integrity, abnormal application environment, abuse of privacy and security permissions, and abnormal device status.

[0087] System integrity breaches include debug mode, root / jailbreak, and tampering or abnormal call patterns of system function values. Debug mode refers to the device's operating system having enabled developer debugging options, allowing for low-level code analysis and modification. Root / jailbreak means the device has obtained the highest system privileges, breaking through the operating system's security sandbox restrictions, allowing arbitrary modification of system files and installation of unauthorized applications. Tampering or abnormal call patterns of system function values ​​indicate that the return values ​​of critical system application programming interfaces (APIs) have been modified by hooks or injection techniques, or that their call sequences, frequencies, or parameters do not conform to normal application behavior patterns.

[0088] Abnormal application environment characteristics include multiple instances and the installation of unauthorized apps. Multiple instances refer to running multiple independent instances of the same application on the same device through unofficial means; the installation of unauthorized apps refers to the installation of applications from unofficial app stores (sideloading) or applications that have been marked as malicious or risky by security software.

[0089] Characteristics of privacy and security permission abuse include enabling screen sharing, hijacking the camera / microphone, accessing contacts, and enabling accessibility permissions. Enabling screen sharing means the device is currently sharing its screen content with an external device or application, potentially leading to the leakage of sensitive information. Hijacking the camera / microphone means an unknown or background application is detected accessing and potentially using the camera or microphone without the user's explicit consent or foreground prompt. Accessing contacts means an application is reading the device's contact information in the background, even when the user did not actively initiate contact requests. Enabling accessibility permissions means the device has enabled high-level "accessibility services" for specific applications. While these services are intended to assist people with disabilities, they are often abused by malware to simulate user clicks, steal screen content, or even install other applications.

[0090] Abnormal device status characteristics include no SIM card installed, emulator / virtual environment, etc. No SIM card installed means that a SIM card cannot be detected in a device that should normally have a SIM card installed, which may indicate that the device is a test device, a virtual device, or a device specifically used for Wi-Fi fraud; emulator / virtual environment means that the device is detected to be running in a software-simulated virtual environment, rather than real physical hardware.

[0091] For example, the device's metadata is collected by integrating a device anomaly detection component into the APP and sent to the electronic device.

[0092] In this embodiment, regardless of whether the underlying data comes from Android, iOS, or HarmonyOS, it can be categorized into three unified categories (basic, environment, and risk), which isolates the fragmented differences at the underlying level. This eliminates the need for the upper-level model to care about the specific source of the data, thereby avoiding the need to write a large amount of adaptation code for each situation, which facilitates maintenance and unification.

[0093] S102. Process the metadata to generate at least one type of derived information, which is used to characterize the abnormal behavior patterns implied in the metadata.

[0094] Derivative information refers to information obtained through secondary processing and analysis of metadata. Its value lies not in the content of the information itself, but in its representation of potential abnormal behavior patterns of the device.

[0095] In this embodiment of the application, by generating derived information, the event of failed data collection is transformed into a feature with risk implications. For example, denial of authorization is no longer merely a blank in the data, but is interpreted as a behavioral signal that may have hidden intentions.

[0096] By leveraging derived information, deeper-level abnormal behavioral patterns can be discovered that traditional static tags cannot capture. For example, even if seemingly normal basic device information is fabricated using technical means, it is difficult to completely simulate the dynamic behavior of real devices during operation (such as sensor data streams and natural fluctuations in the network environment). By analyzing these behavioral patterns, disguised devices attempting to bypass traditional detection methods can be identified, improving detection accuracy.

[0097] Optionally, the derived information includes at least one of the following: uncollected information, abnormal change information, and abnormal static information. Uncollected information is used to characterize information that was not collected due to permission denial, but whose absence itself carries risks; abnormal change information is used to characterize information that should have remained fixed but has undergone abnormal changes; abnormal static information is used to characterize information that should have changed over time but has remained static.

[0098] For example, uncollected information may include refusing authorization to turn on GPS to conceal geographical location, or refusing authorization for the device to collect and install apps to disguise the app's existence. In normal user interactions, users typically agree to apps obtaining necessary device information in order to obtain services (such as payment, navigation, etc.). However, fraudsters may intentionally refuse authorization to collect certain key information in order to conceal their true intentions or traces of their crimes.

[0099] For example, normal users usually don't mind sharing a rough location to obtain local services, and denying authorization may be intended to hide the fact that they are using virtual location software; or, denying authorization to read the application list is intended to hide malware, modification tools, virtual environment software, or a large number of fraudulent applications installed on the device.

[0100] For example, abnormal change information may include a single device being associated with multiple mobile phone brands for a short period of time, or frequent changes in IP / GPS within a short period of time. A real physical device typically has some hardware attributes (such as brand, model, and manufacturer) that remain unchanged for a short period. If the system detects frequent changes in these information, it indicates an abnormal device environment.

[0101] For example, if a single device is associated with multiple mobile phone brands in a short period of time, it may be using device modification software or a device farm that can tamper with device reports to carry out automated mass fraud attempts; another example is that if the IP address / GPS location changes frequently and drastically in a short period of time, which is physically impossible (such as moving between two distant locations within 1 minute), it indicates the use of proxy IP, VPN (Virtual Private Network), or virtual location software.

[0102] For example, abnormal static information could include a battery that remains at 100% (which could indicate charging or being remotely controlled), or a device's gyroscope remaining in the same position. In real-world user devices, some sensor data and status data are typically dynamic. For example, the battery depletes, the phone moves causing changes in gyroscope data, and the screen orientation changes. A continuously unchanging state violates the laws of physics and human behavior.

[0103] A battery that remains at 100% is highly likely to be connected to a charger and may be under automated script control (such as a group control system) for activities like order boosting or cash grabbing. It could also be a cloud phone or emulator, where the battery status is virtual. A device with consistently unchanged gyroscope / accelerometer data indicates that it may be stationary and unattended, or it may simply be a sensorless simulator. This is a strong signal for identifying device farms and emulators.

[0104] Therefore, uncollected information, abnormally changing information, and abnormally static information can be used as risk factors.

[0105] For example, the collected raw metadata is subjected to time-series analysis, contextual correlation, and intent inference to generate derived information representing abnormal behavior patterns.

[0106] Optionally, based on metadata, at least one key information collection permission is determined; based on the authorization response result of the key information collection permission, uncollected information is generated. By analyzing the metadata of data or tasks to determine key information collection permissions, the privacy risks and data redundancy caused by traditional one-size-fits-all broad authorization are avoided. Moreover, users are no longer faced with general and broad permission requests, but rather specific permission requests that are highly relevant to the current scenario and have clear reasons, reducing user doubts and authorization fatigue, and increasing users' willingness and likelihood of authorization.

[0107] For example, the current business scenario is identified, which may include, but is not limited to, financial payment, social relationship addition, content publishing, real-name authentication, and personalized recommendation initialization. Then, contextual metadata related to the business scenario is obtained. This metadata may include the scenario itself, as well as user device type, application version, network access point, etc. Using the business scenario and / or related metadata as query conditions, a pre-configured key permission mapping table is accessed. This table stores the identifiers of one or more information collection permissions necessary to complete the core functions or meet compliance requirements of different business scenarios. Subsequently, the permission identifier matching the current conditions is extracted from the key permission mapping table and identified as the key information collection permission.

[0108] Optionally, based on the selected stable items in the metadata, the current value of the selected stable items is compared with the dynamic baseline to determine the abnormal change information caused by abnormal changes in information. This solves the problem of whether the obtained data is reliable and whether it contains hidden risks. It can also identify risks hidden under authorization, thereby more accurately identifying high-risk behaviors such as fraud, cheating, and account theft.

[0109] For example, a time-series data stream is established for selected metadata items (such as device brand, device model, IP address, and GPS city code) for continuous monitoring; a dynamic baseline is established for each device (or device group). The baseline can be an individual historical baseline or a group statistical baseline. The individual historical baseline refers to the mode or stable value of the information item of the device over a period of time (such as 24 hours), while the group statistical baseline refers to the common value or change pattern of the information item of the same type of device (such as the same brand and model).

[0110] Then, the current information value is compared with the baseline value in real time. If the frequency of the current information value differs significantly from the frequency of the baseline value, or the amplitude differs significantly, such as exceeding a preset threshold, it is judged as an abnormal change and abnormal change information is generated.

[0111] Optionally, based on the selected dynamic item in the metadata and the context conditions under which the selected dynamic item should change, abnormal static information generated due to abnormal information staticity is determined according to the state of the selected dynamic item during the time period that meets the context conditions. Cheating scripts can easily forge a reasonable device ID or IP address, but it is extremely difficult to continuously and realistically simulate all the natural dynamics of a real physical device; simulating natural battery degradation, generating continuous gyroscope data streams that conform to handheld movement patterns, and randomly simulating the force and trajectory of screen touches all require extremely high cost and complexity. This solution can significantly reduce the possibility of forgery and improve device security.

[0112] For example, identify information items that are expected to change under natural use, such as battery level, screen brightness, gyroscope / accelerometer readings, available memory, device temperature, etc. Establish contextual conditions for these information items to change, for example, when the device is not connected to power, the battery level is expected to decrease over time due to discharge; when the device is in motion (based on an initial assessment using accelerometer readings), the gyroscope data is expected to change.

[0113] During the period when the context conditions for change are met, the information value is continuously monitored. If the information value remains constant (or fluctuates less than a very small threshold) for a duration exceeding a preset threshold, it is judged as abnormal stillness and abnormal stillness information is generated.

[0114] It's important to note that abnormal change information and abnormal static information can construct a dual verification dimension of dynamic and static data. Abnormal change detection targets stable items (which should remain relatively unchanged), preventing them from changing unnaturally (such as sudden device ID mutations or location jumps), primarily combating identity forgery, account theft, and script simulation. Abnormal static detection targets dynamic items (which should change naturally), preventing them from changing unnaturally (such as a constantly full battery or no sensor data), primarily combating automated scripts, virtual machines, cloud phones, and device farms. The combination of these two methods constitutes a three-dimensional, cross-validation system for data authenticity, capable of identifying more complex and covert cheating methods.

[0115] S103. Adjust the weight coefficients corresponding to at least one type of derived information based on the status information of the target device.

[0116] Status information refers to the sum of all dynamic contexts related to the device's risk situation at the time of assessment. It includes not only specific data such as currently collected environmental information, risk information, and derived information, but also business scenarios (such as login, transactions), physical contexts (such as whether it is charging or moving), and possible related risk intelligence (such as the risk records of the same device in other apps) inferred from this data.

[0117] Static and rigid scoring thresholds and weights cannot distinguish between normal noise and real risks, leading to misjudgments and impacting user experience. In this embodiment, weights are adjusted based on real-time status information, addressing the problem of static and rigid scoring thresholds and weights failing to differentiate between normal noise and real risks, thus reducing misjudgments and improving user experience.

[0118] For example, if a device's battery is consistently at 100%, the weight of this information is reduced in the context of being connected to a charger to avoid false alarms; while in the context of not charging, its weight is increased to indicate the risk of remote control, thus achieving accurate risk purification and effectively reducing false alarms.

[0119] Optionally, the state information of the target device can be input into a regression algorithm. This algorithm adjusts the weights corresponding to at least one type of derived information based on the target device's state information and outputs the adjusted weight coefficients. State information is complex and multidimensional, including continuous variables (battery percentage, CPU temperature) and discrete variables (business scenario type), as well as numerical data (sensor readings) and categorical data (network type). Traditional rule systems struggle to effectively handle such high-dimensional, heterogeneous inputs. One of the core capabilities of regression algorithms is to automatically learn a set of optimal weight coefficients through training to quantify the contribution of each input feature to the output target, thereby achieving automated and optimized mapping from complex state perception to clear decision instructions.

[0120] For example, a regression algorithm might discover that, at 2 AM and when using a specific proxy IP, historically abnormal static information (such as no sensor data) has a very high correlation with the final fraud, while abnormal change information (such as device ID changes) has a moderate correlation. Therefore, the decision weight of abnormal static information in this state is automatically increased, while the weight of abnormal change information is decreased.

[0121] In one possible implementation, the regression algorithm is the Cox regression algorithm, which typically refers to the Cox Proportional Hazards Model. The core of this model is to construct the relationship between the hazard function and covariates, without pre-setting the specific distribution of survival time (such as exponential or normal distributions), only assuming that the covariates' influence on the hazard is exponential. This characteristic allows it to adapt to various survival scenarios, avoiding analytical bias caused by discrepancies between the assumed distribution and actual data. The Cox model, through a partial likelihood function, relies solely on the order of events rather than specific times to complete parameter estimation, directly and efficiently processing such incomplete data, fully utilizing all observational information in the study, and avoiding data waste.

[0122] In practical applications, the Cox regression algorithm can assign different weight values ​​to each category of equipment elements, including basic, environmental, and risk categories, forming a vector matrix. W. Among them, risk-related equipment elements have the highest weighting values, while basic equipment elements have the lowest weighting values.

[0123] In other examples, other regression algorithms that can implement weight adjustments, or other algorithms, may also be used.

[0124] For example, real-time sensing devices provide real-time status information, including current environmental information, risk information, uncollected information, abnormal change information, and abnormal static information, as well as inferred business scenarios. Then, based on a preset adjustment strategy, dynamic weighting is performed in conjunction with the device's real-time status information.

[0125] For example, regarding uncollected information: if location information is refused in a large-amount transfer scenario, the weight coefficient of the uncollected information is increased; if contact access is refused in a news reading scenario, the weight coefficient of the uncollected information is decreased or remains unchanged. Regarding abnormal change information: if an IP address jumps from one location to another very distant location within one minute, the weight coefficient of the abnormal change information is increased based on the magnitude of this extreme change.

[0126] For abnormal inactivity information: if the battery level remains at 100% for 24 hours and the device is not being charged, the weighting factor for abnormal inactivity will be increased in conjunction with this strong abnormal signal; if the device is connected to a charger, the weighting factor for abnormal inactivity information will be decreased.

[0127] For example, during algorithm initialization, the three types of derived information are ranked by basic risk weights based on business experience. For instance, uncollected information has the highest weight coefficient because denying authorization is a proactive and clearly intentional high-risk behavior, directly indicating the user's adversarial intent, resulting in a very high risk confidence level. The weight coefficients for abnormal change information and abnormal static information are the same, but lower than those for uncollected information. Abnormal change and abnormal static information indicate an abnormal device environment, but this abnormality could be due to malicious tampering or special circumstances (such as frequent travel causing IP changes). Therefore, further quantitative analysis is needed to confirm their risk level, thereby dynamically adjusting their final weights.

[0128] For abnormal change information: within the time window T, count the number of changes C of specific information (such as device brand) and the number of contradictory information dimensions D (for example, the brand has changed, but the model has not; or the brand, model and resolution are inconsistent).

[0129] The weighting coefficient adjustment formula is W_V_final = W_V_base + ×C + β × D; W_V_base is the base weight for abnormal change information; α and β are adjustment coefficients. The more frequent the changes (the larger C is) and the more contradictory points there are (the larger D is), the higher the final weight W_V_final will be.

[0130] For abnormal static information: monitor the duration L of a specific dynamic parameter (such as battery level, gyroscope reading) remaining unchanged, and the deviation Δ of its value from the natural state (e.g., the abnormality of a battery level that is constant at 100% is higher than the abnormality of a battery level that is constant at 50%).

[0131] The weighting coefficient adjustment formula is W_S_final = W_S_base + γ × L + δ × Δ; where W_S_base is the base weight of the abnormal static information; γ and δ are adjustment coefficients. The longer the constant time (the larger L is), the more unnatural the value (the larger Δ is), and the higher the final weight W_S_final will be. For example, if gyroscope data remains unchanged for 2 consecutive hours, its risk weight will increase linearly or exponentially with time.

[0132] For information not collected: a key score I' is preset for different types of information (such as GPS, app list, contacts). If authorization for a certain piece of information is denied, a weight related to the key score of that information is directly assigned to it.

[0133] The weighting formula is W_U = θ × I`, where θ is an adjustment coefficient. For example, the weight increase from denying GPS access (high I` value) is far greater than denying access to unimportant sensors.

[0134] S104. Based on the adjusted weighting coefficients, the meta-information and derived information are weighted to obtain the risk characteristics of the target equipment. The risk characteristics are used to characterize the risk probability of the target equipment.

[0135] Risk characteristics are used to characterize the risk probability of a target device. This probability value directly and comprehensively represents the likelihood that the target device is suspected of fraud or malicious behavior at the current moment.

[0136] For example, the metadata and its corresponding weight coefficients are weighted to obtain the corresponding weight value, and the derived information and its corresponding weight coefficients are also weighted to obtain the corresponding weight value. The two weight values ​​are then added together to obtain the corresponding risk characteristic.

[0137] Optionally, the metadata and derived information are quantified to obtain quantified results. Meta-information includes basic information, environmental information, and risk information, thus yielding quantified results for basic information, environmental information, and risk information. Derived information includes at least one of uncollected information, abnormal change information, and abnormal static information. Accordingly, the quantified results of derived information may include quantified results for uncollected information, abnormal change information, and / or abnormal static information.

[0138] Then, based on the adjusted weighting coefficients and the quantification results of meta-information and derived information, weighted processing is performed to obtain the risk characteristics of the target equipment. The collected multi-source, heterogeneous raw equipment status data is transformed into unified numerical feature values ​​that can be mathematically calculated, according to their business meaning, providing standardized input for subsequent dynamic weighting and risk scoring calculations.

[0139] For example, the quantification of basic information can employ categorical coding, establishing a dictionary mapping for each attribute and mapping the category string to a unique integer ID or vector. For instance, device brand = Apple, when querying the preset mapping table, is quantized as B_1 = 1; operating system version = iOS 15.4 can be quantized as the major version number B_2 = 15.

[0140] Environmental information can be quantified directly using numerical values. For example, battery level = 80%, directly quantified as E_1 = 0.8; CPU utilization = 45%, quantified as E_2 = 0.45; network type = WiFi, quantified as E_3 = 1 (e.g., 1 = WiFi, 2 = 4G, 3 = 5G).

[0141] Risk information (R) can be quantified using binary risk labels, mostly Boolean values, directly indicating whether the risk exists. For example, ROOT status = true is quantified as R_1 = 1.0; camera hijacking = false is quantified as R_2 = 0.0; accessibility permission enabled = true is quantified as R_3 = 1.0.

[0142] The quantification of uncollected information can be achieved using a missing indicator. A feature is created for each collectable key item, with 0 representing successful collection and 1 representing rejection or missing information. For example, a denied request for GPS permission is quantified as U_1=1.0; a successful acquisition of the list of installed apps is quantified as U_2=0.0.

[0143] The quantification of abnormal change information can employ inconsistency detection and intensity quantification. By comparing the current value with the device's historical baseline value or the current value, the intensity of the change is calculated. For example, if the brand of the device collected this time is inconsistent with the most frequently occurring brand of the device in the past, it is quantified as V_1=1.0; if the IP address in this request is not from the same country as the IP address in the previous request, it is quantified as V_2=1.0; if they are from the same country but different cities, it can be quantified as 0.5.

[0144] The quantification of abnormal static information can be performed by quantifying the intensity of no change in a specific context, which needs to be determined in conjunction with the context in which the change should occur (such as the device being moved or the user being operated). For example, if the variance of the gyroscope readings is close to 0 within 10 seconds, the static anomaly can be calculated as 1 - (actual variance / expected minimum variance). If the expected minimum variance is 0.5 and the actual variance is 0.01, then S_1 = 1 - (0.01 / 0.5) = 0.98.

[0145] For example, risk characteristics are determined based on the quantification results of risk information, the quantification results of derived information, and the corresponding weighting coefficients. For instance, the quantification results of risk information and their corresponding weighting coefficients are multiplied together, and the quantification results of derived information and their corresponding weighting coefficients are multiplied together. Then, the two multiplication results are added together to obtain the risk characteristics.

[0146] Optionally, a first weighted value is determined based on the quantification results of risk information and derived information, as well as the corresponding weighting coefficients. The quantification results of risk information and their corresponding weighting coefficients are multiplied together, and the quantification results of derived information and their corresponding weighting coefficients are also multiplied together. The two multiplication results are then added together to obtain the first weighted value.

[0147] Simultaneously, based on the quantization results of the metadata and derived information, and their corresponding weighting coefficients, a second weighting value is determined. The quantization result of the metadata is multiplied by its corresponding weighting coefficient, and the derived information is multiplied by its corresponding weighting coefficient. The two multiplication results are then added together to obtain the second weighting value.

[0148] Subsequently, the risk characteristics are determined based on the first weighted value and the second weighted value. Specifically, the risk characteristics are determined based on the ratio of the first weighted value and the second weighted value.

[0149] Different devices can collect vastly different amounts of information; a new or clean device may collect less information, while an older or more complex device may collect more. If only the numerator is summed, the device with more information will naturally score higher, affecting accuracy. By using a second weighting value as a normalization factor, the bias caused by the difference in information volume is automatically eliminated, improving accuracy.

[0150] For example, the device's metadata and derived information can both include multiple categories. The i-th type of basic information on the Nth device (target device) is marked as... The corresponding weighting coefficient is The dynamic information record of the i-th class is as follows: The corresponding weighting coefficient is The risk information for the i-th category is recorded as follows: The corresponding weighting coefficient is The i-th type of uncollected information is recorded as follows: The corresponding weighting coefficient is The i-th type of abnormal change information is recorded as follows: The corresponding weighting coefficient is The i-th type of abnormal static information is recorded as follows: The corresponding weighting coefficient is . The quantization results are marked as , The quantization results are marked as , The quantization results are marked as , The quantization results are marked as , The quantization results are marked as , The quantization results are marked as .

[0151] Then, based on the quantification results and weight coefficients of various types of information, the weighting function for each type of information is determined. The weighting function is an intermediate metric that characterizes the contribution of a certain type of information to the overall risk of the equipment, obtained by linearly combining the quantified values ​​of its internal sub-features with dynamically adjusted weight coefficients and then mapping it through the exponential function exp() at a specific time t for a certain type of equipment information (such as basic information B, risk information R, etc.).

[0152] Specifically, A weighting function representing the basic information of the equipment at time t;

[0153] A weighting function representing the device's environmental information at time t;

[0154] The weighting function represents the risk information of the equipment at time t;

[0155] The weighting function represents the time t when the device did not collect data but may indicate a risk.

[0156] A weighting function representing information about the device at time t that should have been fixed but has changed;

[0157] The weighting function represents the information that the device should change at time t but remains fixed.

[0158] Accordingly, risk characteristics can be determined based on weighting functions for various types of information.

[0159] remember Let HR be the risk score of the nth device at time t, where HR>1 indicates that the element was not collected but the characteristic is risky; HR<1 or HR=0 indicates that the element was not collected but the risk is low or the impact of not collecting can be ignored.

[0160]

[0161] Based on this, risk characteristics can be determined, which are represented by risk scores, such as... Figure 2 As shown.

[0162] Optionally, while determining the risk characteristics, risk contribution factor markers can also be output. These risk contribution factor markers are used to indicate one or more specific risk information items that contribute the most to the risk characteristics.

[0163] While outputting scores, the system analyzes the contribution of various information items to risk characteristics. Specific information items whose contribution exceeds a certain threshold (such as abnormal IP jumps, denied GPS authorization, and root detection) are output as high-risk contribution factors, which greatly enhances the interpretability of risk decisions and makes it easier for operations personnel to understand the source of risks and take targeted measures.

[0164] For example, if the collected risk information includes "camera hijacking," it is sufficient to indicate that the device poses an extremely high risk and requires special labeling. Let the risk assessment result for the Nth device be: The specific high-risk contributing factor element is marked in <>.

[0165] For example, the contribution ratio of each item in the scoring formula is calculated, and the information items with a ratio exceeding the threshold are used as contribution factors; when using a machine learning model, the contribution value of each input feature is calculated using a model interpretation tool, and the top K features with the largest contribution values ​​are selected as contribution factors; the equipment information is matched with a predefined key risk rule base, and the risk factors corresponding to the matched rules are used as mandatory labeling contribution factors.

[0166] The information processing method provided in this application can categorize underlying data into three unified categories (basic, environment, and risk), regardless of whether the data originates from Android, iOS, or HarmonyOS. This isolates the fragmented differences at the underlying level, eliminating the need for upper-layer models to concern themselves with the specific source of the data. This avoids the need to write extensive adaptation code for each scenario, facilitating maintenance and consistency. By generating derived information, missing information is transformed into features for risk assessment, resolving the risk blind spot problem caused by permission denial. A dynamic weight adjustment mechanism based on real-time status information enables the model to distinguish between anomalies and malicious intent, reducing misjudgments caused by model rigidity. This significantly improves the experience for legitimate users while ensuring security. Through multi-dimensional information fusion, attackers are required to perfectly simulate normal devices across all dimensions, greatly increasing the cost and difficulty of attacks and effectively blocking security breaches caused by missing or improperly processed single features.

[0167] Figure 3 Flowchart of the information processing method provided in this application Figure 2 ,like Figure 3 As shown, in this embodiment... Figure 1 Based on the embodiments, the method further includes:

[0168] S105. When the risk probability of the target device, as indicated by the risk characteristics of the target device, is greater than a preset threshold, the risk clues of the target device are sent to the backend server corresponding to the first application, so that the backend server corresponding to the first application uploads the risk clues of the target device to the risk clue sharing platform.

[0169] Among them, risk clues include at least one of the identifier of the target device and the risk account identifier associated with the target device; risk clues in the risk clue sharing platform are used to instruct the backend servers of other applications to perform risk control based on risk clues.

[0170] For example, the target device may refer to the device where the first application is located. If the first application has a better ability to detect risks in the device environment than the second application, the first application will upload the risk clues to the risk clue sharing platform.

[0171] For example, risk clues include the identifier of the target device, that is, risk device sharing is realized. Risk device sharing is applicable to sharing risk clues between apps that have the same data collection device ID standard.

[0172] For example, APP1 has a better ability to detect device environmental risks than APP2. This is mainly because APP1 uploads information about devices with high risk scores to the risk clue sharing backend. Then, APP2 subscribes to abnormal device information through the risk clue sharing backend. APP2 can combine APP1's strength in device risk identification with its strength in other dimensions of risk characteristic discrimination to implement precise risk control on user accounts accessing APP2. Figure 4 As shown, APP2 sensed through the risk clue sharing backend that the current account Usr2 was accessing the high-risk device d1. The main risk factors were that the device camera was hijacked and the CPU value remained unchanged. There was sufficient reason to implement risk control on Usr2.

[0173] For example, risk clues include risk account identifiers associated with the target device, that is, risk account sharing is realized. Risk account sharing is applicable to sharing clues between apps that have different data collection device ID standards but the same user account system.

[0174] For example, if APP1 has a strong ability to detect device environment risks and user accounts accessing risky devices are suspected of being linked to other devices, APP1 will upload the account information to the risk clue sharing backend. Then, APP3 subscribes to the list of abnormal devices through the risk clue sharing backend. APP3 combines APP1's expertise in device risk identification with its expertise in other dimensions of risk feature judgment to implement precise risk control on user accounts accessing APP3. Figure 4 As shown, APP3 can detect through the risk clue sharing backend that the current account Usr1 has accessed other high-risk devices, and has sufficient evidence to implement risk control on Usr1.

[0175] The information processing method provided in this application represents a paradigm shift from single-point defense to ecosystem-wide collaborative defense, solving the problems of data silos and capability silos in traditional risk control. Through a shared platform, the app can gain access to the risk perspectives of other apps, forming a global view and achieving capability aggregation.

[0176] Figure 5 Flowchart of the information processing method provided in this application Figure 3 ,like Figure 5 As shown, in this embodiment... Figure 1 Based on the embodiments, the method further includes:

[0177] S106. Based on the risk characteristics of multiple target devices and the associated clustering elements, cluster the multiple target devices to identify other risky devices.

[0178] The clustering elements include at least one of the following: equipment environment spatial information (space-sp), counterparty information (opponent-op), risk score contribution factor (factor-fr), and equipment activity time series (time sreries-ts).

[0179] Device environmental spatial information refers to the location or environmental identification information of a target device in physical or cyberspace, which may include IP, GPS, etc. The clustering significance of this information is that devices sharing the same or adjacent environmental spatial information may be controlled by the same physical entity (such as being located in the same device farm) or operating under the operation of the same regional fraud group.

[0180] Counterparty information refers to the identification information of another entity directly related to business transactions occurring on the target device. This information clusters together the frequent transactions or interactions between different devices and the same few counterparties, serving as a core clue for identifying fraudulent schemes such as group collusion or fund transfers. Counterparties can include transfer partners, merchants, etc.

[0181] Risk scoring contribution factors refer to the specific risk sub-items or abnormal characteristics with the highest contribution during the calculation of a device's comprehensive risk score. These can include factors such as a hijacked camera or an unchanging gyroscope display. The significance of this clustering information is that devices sharing the same high-risk contribution factors are likely to have used the same cheating tools, hacking software, or attack methods.

[0182] Device activity time sequence information refers to the temporal distribution and pattern characteristics of risky behaviors or business activities generated by target devices. The significance of this information clustering lies in the high similarity or synchronicity of activity time sequences, which is strong evidence for determining whether devices are controlled by automated scripts or group control software. This is key to identifying machine behavior and distinguishing it from manual operation.

[0183] It should be noted that risky devices located in close proximity are more likely to be from organized groups; fraud gangs often concentrate on transferring funds to the same bank cards or merchants; fraud gangs modifying devices will leave similar risk characteristics; risky devices have a short usage cycle, but are often concentrated within a certain period of time.

[0184] Optionally, feature triples are constructed to characterize each target device based on risk characteristics, risk contribution factors, and at least one clustering element; based on the feature triples, a community detection algorithm is used to divide multiple target devices into communities to obtain an initial community set; based on a preset quality function, the initial community set is iteratively optimized until the preset optimization conditions are met to obtain the optimized community division result; wherein, devices in the same community are more likely to be identified as belonging to the same risk group than devices in different communities.

[0185] By introducing risk contribution factors, we can discover device groups using the same cheating methods, enabling precise strikes against tool-based black market activities. Through clustering elements, we can uncover hidden business connections and identify seemingly independent but actually coordinated distributed fraud networks. By linking these elements from multiple dimensions, attackers are required to perfectly simulate normal devices in all dimensions simultaneously, greatly increasing the cost and difficulty of attacks, thereby effectively blocking security breaches caused by the lack of or improper handling of a single feature.

[0186] For example, community detection algorithms include the Leiden algorithm, which is a graph algorithm for community detection. Its core objective is to partition a complex network into subsets of nodes (i.e., communities) that are tightly connected internally and sparsely connected externally.

[0187] The Leiden algorithm is executed in three iterative phases, which are repeated until the community structure is stable:

[0188] The local move phase traverses each node in the network, attempting to move it to the community of an adjacent node and calculating the change in modularity after the move. The move operation is only performed if the modularity increases.

[0189] The community aggregation phase treats each community obtained in the previous phase as a supernode, constructing a new aggregation network. The edge weights between supernodes are equal to the sum of the edge weights between different community nodes in the original network.

[0190] The refinement stage involves reassigning community tags to each original node based on the aggregated network, further improving the precision of community segmentation and increasing the accuracy of risk assessment by the team.

[0191] For example, community detection algorithms may also include other algorithms, such as those similar to the Leiden algorithm.

[0192] For example, clustering multiple target devices based on their risk characteristics and associated clustering elements includes the following steps:

[0193] (1) Calculate the risk assessment result binary for each piece of equipment. Then, label the binary tuple and the four clustering elements to form a triple. The four clustering elements can be represented in key-value format, or left empty if there are no values. A triple is represented in the following format: .

[0194] (2) According to the Leiden algorithm, node movement is performed to obtain the first stage of community division. Risky devices assigned to the same community are more likely to be connected to the same fraud gang. For example Figure 6As shown in i and ii.

[0195] (3) Carry out community re-division and optimization work.

[0196] r represents the current density of the community. ;

[0197] Nd represents the number of risky devices in the current community; a quality function is introduced. Calculate the quality score for each community.

[0198] 1. The priority of the four clustering elements can be dynamically adjusted according to the risk situation, with the default priority being sp>op>ts>fr. As shown in steps iii and iv of the figure, the Q value of community a is lower than that of community b. At the same time, devices 2 and 3 in community a and device 1 in community b have the same sp (geographical location). Therefore, devices 2 and 3 in community a and device 1 in community b are refined into new sub-communities. Similarly, devices 4 and 5 in community c are refined into new sub-communities.

[0199] 2. Repeat these steps until the density of each community reaches the preset threshold.

[0200] The information processing method provided in this embodiment no longer uses single-point data as input, but rather a batch of pre-calculated risk characteristics of devices and their related elements (such as geographical location, trading counterparties, etc.). This marks a shift in analysis from individual diagnosis to group profiling. The method employs clustering, an unsupervised learning approach, to discover hidden, unknown correlation patterns within the device group, rather than verifying known rules. Then, through the identified risk device groups, it identifies unlabeled but similarly patterned related devices. This achieves a paradigm shift in risk control from rule-driven, ex-post response to data-driven, proactive discovery.

[0201] Figure 7 A schematic diagram of the information processing apparatus provided in this application is shown below. Figure 7 As shown, the information processing device 10 provided in this embodiment includes:

[0202] The acquisition module 11 is used to acquire metadata of the target device, including basic information, environmental information and risk information;

[0203] The first processing module 12 is used to process the metadata and generate at least one type of derived information, which is used to characterize the abnormal behavior patterns hidden in the metadata.

[0204] The second processing module 13 is used to adjust the weight coefficients corresponding to at least one type of derived information based on the status information of the target device.

[0205] The third processing module 14 is used to perform weighted processing on the meta-information and derived information based on the adjusted weight coefficients to obtain the risk characteristics of the target device. The risk characteristics are used to characterize the risk probability of the target device.

[0206] In one possible implementation, the derived information includes at least one of the following:

[0207] Uncollected information is used to characterize information that was not collected due to permission denial, but whose absence itself carries risks.

[0208] Abnormal change information is used to characterize information that should remain fixed but has undergone abnormal changes.

[0209] Abnormal static information is used to characterize information that should change over time but remains static.

[0210] In one possible implementation, the first processing module 12 is specifically used to determine at least one key information collection permission based on metadata; and to generate uncollected information based on the authorization response result of the key information collection permission.

[0211] Based on the selected stable terms in the metadata, the current value of the selected stable terms is compared with the dynamic baseline to determine the abnormal change information caused by abnormal changes in information.

[0212] Based on the selected dynamic item in the metadata, and the context conditions under which the selected dynamic item should change; based on the state of the selected dynamic item during the time period that meets the context conditions, determine the abnormal static information generated due to abnormal information static.

[0213] In one possible implementation, the second processing module 13 is specifically used to input the state information of the target device into the regression algorithm. The regression algorithm is used to adjust the weight coefficients corresponding to at least one type of derived information based on the state information of the target device, and output the adjusted weight coefficients.

[0214] In one possible implementation, the regression algorithm includes the Cox regression algorithm.

[0215] In one possible implementation, the third processing module 14 is specifically used to perform quantization processing on the metadata and derived information to obtain the quantization results of the metadata and derived information.

[0216] Based on the adjusted weighting coefficients and the quantification results of the meta-information and derived information, a weighted processing is performed to obtain the risk characteristics of the target equipment.

[0217] In one possible implementation, the third processing module 14 is specifically used to determine the first weighted value based on the quantification results of risk information and derived information, and the corresponding weighting coefficients.

[0218] The second weighting value is determined based on the quantification results of the meta-information and derived information, as well as the corresponding weighting coefficients.

[0219] Risk characteristics are determined based on the first weighted value and the second weighted value.

[0220] In one possible implementation, the third processing module 14 is further configured to output a risk contribution factor marker, which indicates one or more specific risk information items that contribute the most to the risk characteristics.

[0221] In one possible implementation, a fourth processing module 15 is further included, which is used to send the risk clue of the target device to the backend server corresponding to the first application when the risk characteristics of the target device indicate that the risk probability of the target device is greater than a preset threshold, so that the backend server uploads the risk clue to the risk clue sharing platform; the risk clue includes at least one of the identifier of the target device and the risk account identifier associated with the target device.

[0222] Risk clues in the risk clue sharing platform are used to instruct the backend servers of other applications to perform risk control based on the risk clues.

[0223] In one possible implementation, there are multiple target devices; the fourth processing module 15 is also used to cluster the multiple target devices based on their risk characteristics and associated clustering elements to identify other risky devices.

[0224] Clustering elements include at least one of the following: equipment environmental spatial information, counterparty information, risk score contribution factors, and equipment activity time series information.

[0225] In one possible implementation, the fourth processing module 15 is specifically used to construct a feature triplet to characterize each target device based on risk characteristics, risk contribution factors and at least one clustering element.

[0226] Based on feature triples, a community detection algorithm is used to divide multiple target devices into communities to obtain an initial community set.

[0227] Based on a preset quality function, the initial community set is iteratively optimized until the preset optimization conditions are met, resulting in an optimized community division. Among these, devices within the same community are more likely to be identified as belonging to the same risk group than devices in different communities.

[0228] The information processing device provided in this embodiment can execute the method provided in the above method embodiment. Its implementation principle and technical effect are similar, and will not be described in detail here.

[0229] Figure 8A schematic diagram of the structure of the electronic device provided in this application. Figure 8 As shown, the electronic device 50 provided in this embodiment includes at least one processor 501 and a memory 502. Optionally, the electronic device 50 further includes a communication component 503. The processor 501, memory 502, and communication component 503 are connected via a bus.

[0230] In a specific implementation, at least one processor 501 executes computer execution instructions stored in memory 502, causing at least one processor 501 to perform the above-described method.

[0231] The specific implementation process of processor 501 can be found in the above method embodiments, and its implementation principle and technical effect are similar. It will not be repeated here.

[0232] In the above embodiments, it should be understood that the processor can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), etc. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the method disclosed in this invention can be directly implemented by a hardware processor, or implemented by a combination of hardware and software modules within the processor.

[0233] The memory may include random access memory (RAM) and may also include non-volatile memory (NVM), such as at least one disk storage device.

[0234] The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. Buses can be categorized as address buses, data buses, control buses, etc. For ease of illustration, the buses shown in the accompanying drawings are not limited to a single bus or a single type of bus.

[0235] This application also provides a computer program product, including a computer program that, when executed by a processor, implements the above-described method.

[0236] This application also provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, implement the above-described method.

[0237] The aforementioned readable storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk. The readable storage medium can be any available medium accessible to a general-purpose or special-purpose computer.

[0238] An exemplary readable storage medium is coupled to a processor, enabling the processor to read information from and write information to the readable storage medium. Of course, the readable storage medium can also be a component of the processor. The processor and the readable storage medium can reside in an Application Specific Integrated Circuit (ASIC). Alternatively, the processor and the readable storage medium can exist as discrete components in the device.

[0239] The division of units is merely a logical functional division; in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be indirect coupling or communication connection through some interfaces, devices, or units, and may be electrical, mechanical, or other forms.

[0240] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0241] In addition, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.

[0242] If a function is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this invention, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0243] Those skilled in the art will understand that all or part of the steps of the above-described method embodiments can be implemented by hardware related to program instructions. The aforementioned program can be stored in a computer-readable storage medium. When executed, the program performs the steps of the above-described method embodiments; and the aforementioned storage medium includes various media capable of storing program code, such as ROM, RAM, magnetic disks, or optical disks.

[0244] Finally, it should be noted that other embodiments of the invention will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This invention is intended to cover any variations, uses, or adaptations of the invention that follow the general principles of the invention and include common knowledge or customary techniques in the art not disclosed herein, and is not limited to the precise structures described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of the invention is limited only by the appended claims.

Claims

1. An information processing method, characterized in that, include: Obtain the metadata of the target device, which includes basic information, environmental information, and risk information; The metadata is processed to generate at least one type of derived information, which is used to characterize the abnormal behavior patterns implied in the metadata. Based on the status information of the target device, adjust the weight coefficient corresponding to at least one type of derived information; Based on the adjusted weighting coefficients, the meta-information and the derived information are weighted to obtain the risk characteristics of the target device, which are used to characterize the risk probability of the target device.

2. The method according to claim 1, characterized in that, The derived information includes at least one of the following: Uncollected information, which is used to characterize information that was not collected due to permission denial, but whose absence itself carries risks; Abnormal change information, which is used to characterize information that should remain fixed but has undergone abnormal changes; Abnormal static information, which is used to characterize information that should change over time but remains static.

3. The method according to claim 2, characterized in that, The processing of the metadata generates at least one type of derived information, including at least one of the following: Based on the metadata, at least one key information collection permission is determined; according to the authorization response result of the key information collection permission, the uncollected information is generated. Based on the selected stable term in the metadata, the current value of the selected stable term is compared with the dynamic baseline to determine the abnormal change information caused by abnormal information changes; Based on the selected dynamic item in the metadata and the context conditions under which the selected dynamic item should change; and according to the state of the selected dynamic item during the time period in which the context conditions are met, determine the abnormal static information generated due to abnormal information staticity.

4. The method according to claim 1, characterized in that, The step of adjusting the weight coefficients corresponding to at least one type of derived information based on the state information of the target device includes: The state information of the target device is input into the regression algorithm, which is used to adjust the weight coefficients corresponding to at least one type of derived information based on the state information of the target device, and output the adjusted weight coefficients.

5. The method according to claim 4, characterized in that, The regression algorithm includes the Cox regression algorithm.

6. The method according to claim 1, characterized in that, Based on the adjusted weighting coefficients, the metadata and the derived information are weighted to obtain the risk characteristics of the target device, including: The metadata and the derived information are quantized to obtain the quantization results of the metadata and the derived information. Based on the adjusted weighting coefficients and the quantification results of the meta-information and the derived information, a weighted processing is performed to obtain the risk characteristics of the target device.

7. The method according to claim 6, characterized in that, The risk characteristics of the target device are obtained by weighting the adjusted weight coefficients and the quantification results of the meta-information and the derived information, including: Based on the quantification results of the risk information and the derived information, and the corresponding weighting coefficients, a first weighting value is determined; Based on the quantization results of the meta-information and the derived information, and the corresponding weighting coefficients, a second weighting value is determined; The risk characteristics are determined based on the first weighted value and the second weighted value.

8. The method according to any one of claims 1-7, characterized in that, The method further includes: Output a risk contribution factor label, which is used to indicate one or more specific risk information items that contribute the most to the risk characteristic.

9. The method according to any one of claims 1-7, characterized in that, The method further includes: When the risk characteristics of the target device indicate that the probability of risk of the target device is greater than a preset threshold, the risk clue of the target device is sent to the backend server corresponding to the first application, so that the backend server uploads the risk clue to the risk clue sharing platform; the risk clue includes at least one of the identifier of the target device and the risk account identifier associated with the target device. The risk clues in the risk clue sharing platform are used to instruct the backend servers of other applications to perform risk control based on the risk clues.

10. The method according to any one of claims 1-7, characterized in that, The number of target devices is multiple; the method further includes: Based on the risk characteristics of multiple target devices and associated clustering elements, the multiple target devices are clustered to identify other risky devices; The clustering elements include at least one of the following: equipment environmental spatial information, counterparty information, risk score contribution factors, and equipment activity time series information.

11. The method according to claim 10, characterized in that, The method of clustering multiple target devices based on their risk characteristics and associated clustering elements to identify other risky devices includes: Based on the risk characteristics, risk contribution factors, and at least one clustering element, construct a feature triplet to characterize each of the target devices; Based on the feature triplet, a community detection algorithm is used to divide the multiple target devices into communities to obtain an initial community set. Based on a preset quality function, the initial community set is iteratively optimized until the preset optimization conditions are met, resulting in an optimized community division. Among these, devices within the same community are more likely to be identified as belonging to the same risk group than devices in different communities.

12. An information processing device, characterized in that, include: The acquisition module is used to acquire metadata of the target device, including basic information, environmental information and risk information; The first processing module is used to process the metadata to generate at least one type of derived information, wherein the derived information is used to characterize the abnormal behavior patterns implied in the metadata. The second processing module is used to adjust the weight coefficients corresponding to at least one type of derived information based on the status information of the target device. The third processing module is used to perform weighted processing on the meta-information and the derived information based on the adjusted weight coefficients to obtain the risk characteristics of the target device, and the risk characteristics are used to characterize the risk probability of the target device.

13. An electronic device, characterized in that, include: Memory, processor; The memory stores computer-executed instructions; The processor executes computer execution instructions stored in the memory, causing the processor to perform the method as described in any one of claims 1-11.

14. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the method as described in any one of claims 1-11.

15. A computer program product, characterized in that, Includes a computer program that, when executed by a processor, implements the method described in any one of claims 1-11.