Risk point mining method and device, electronic equipment and storage medium
By extracting and structuring risk events from pre-built data sources, and combining them with related information retrieval and judgment rules, the problem of risk point mining relying on experience in existing technologies has been solved. This enables accurate differentiation and updating of risk points, improving the accuracy and efficiency of risk point mining.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- PING AN TECH (SHENZHEN) CO LTD
- Filing Date
- 2026-03-04
- Publication Date
- 2026-06-02
AI Technical Summary
Existing risk point discovery methods rely on user experience, resulting in insufficient accuracy and a tendency to misidentify old risk points as new ones.
By extracting risk events from pre-built data sources, extracting structured information and retrieving related information, determining new and old risk points based on the structured information of risk events, and updating risk points.
It improves the systematicness and coherence of risk point mining, reduces duplicate mining and omissions, and enhances the accuracy and efficiency of new risk point identification.
Smart Images

Figure CN122132888A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of data processing technology, applicable to the financial and medical fields, and particularly to a risk point mining method and apparatus, electronic device and storage medium. Background Technology
[0002] Risk point mining is used to identify new risks that are not recorded in existing risk management systems. For example, in the financial sector, risk point mining of massive amounts of transaction data can uncover unrecorded risks such as new fraudulent transaction patterns. Similarly, in the medical field, risk point mining of patient medical records can reveal new drug interaction risks and other risks not included in the existing medical safety management system.
[0003] Currently, risk point discovery methods typically involve manually collecting risk events from data sources and judging whether a risk event is a new, unrecorded risk event based on the user's experience. However, this method heavily relies on user experience. If the user lacks sufficient experience, they may mistakenly store old risk points as new ones. Therefore, improving the accuracy of risk point discovery has become a pressing technical problem. Summary of the Invention
[0004] The main objective of this application is to provide a risk point discovery method, apparatus, electronic device, and storage medium, which aims to improve the accuracy of risk point discovery.
[0005] To achieve the above objectives, a first aspect of this application proposes a risk point mining method, the method comprising: Risk events are extracted from the pre-built data source to obtain risk event objects; Structured information is extracted from the risk event object to obtain the risk event structured information; Based on the structured information of the risk events, related information retrieval is performed to obtain risk-related information; Based on the risk association information, the risk event object is judged as a new or old risk point to obtain new or old risk point judgment information, wherein the new or old risk point judgment information includes new risk point judgment information; Based on the new risk point determination information and the risk event object, the risk point is updated.
[0006] In some embodiments, the step of retrieving related information based on the structured information of the risk event to obtain risk-related information includes: Based on the structured information of the risk events, a relational database query is performed to obtain the relevant risk items in the database; Semantic features are extracted from the structured information of the risk events to obtain risk semantic features; Based on the aforementioned risk semantic features, a feature similarity search is performed on the preset risk event knowledge base to obtain information on similar risk cases; The risk association information is obtained by summarizing the relevant risk items in the database and the information on similar risk cases.
[0007] In some embodiments, the step of performing feature similarity retrieval on a preset risk event knowledge base based on the risk semantic features to obtain information on similar risk cases includes: The risk event knowledge base is subjected to risk event semantic feature extraction to obtain the knowledge base semantic features; The similarity between the risk semantic features and the knowledge base semantic features is calculated to obtain the feature similarity. Based on the feature similarity, information is extracted from the risk event knowledge base to obtain information on similar risk cases.
[0008] In some embodiments, the step of extracting structured information from the risk event object to obtain structured risk event information includes: The risk event objects are identified by risk type to obtain risk event categories; Based on the risk event category, fields are extracted from the risk event object to obtain key information about the risk event; The key information of the risk event is processed in a structured manner to obtain the structured information of the risk event.
[0009] In some embodiments, the step of determining whether a risk event object is a new or old risk point based on the risk association information to obtain risk point newness / oldness determination information includes: Based on the aforementioned risk event categories, judgment rules are selected to obtain the target judgment rules; Based on the target determination rule, feature extraction is performed on the risk association information to obtain relevant information features; Based on the relevant information features, risk points are determined for the risk event objects to obtain information on whether the risk points are old or new.
[0010] In some embodiments, the step of extracting risk events from a pre-built data source to obtain risk event objects includes: The data source is monitored to obtain data change information; The risk event object is obtained by generating an object from the data change information.
[0011] In some embodiments, updating the risk point based on the new risk point determination information and the risk event object includes: Based on the new risk point determination information, a draft is generated for the risk event object to obtain a risk point draft; The draft risk points are evaluated to obtain draft evaluation information, which includes draft approval information. Based on the information obtained from the draft approval, the draft risk points are stored to obtain new risk point mining information.
[0012] To achieve the above objectives, a second aspect of this application provides a risk point detection device, the device comprising: The event extraction module is used to extract risk events from pre-built data sources to obtain risk event objects; The information extraction module is used to extract structured information from the risk event object to obtain structured information about the risk event; The information retrieval module is used to retrieve related information based on the structured information of the risk event to obtain risk-related information; The risk assessment module is used to determine the old and new risk points of the risk event object based on the risk association information, and obtain the old and new risk point assessment information, wherein the old and new risk point assessment information includes new risk point assessment information. The risk point update module is used to update risk points based on the new risk point determination information and the risk event object.
[0013] To achieve the above objectives, a third aspect of this application provides an electronic device, which includes a memory and a processor. The memory stores a computer program, and the processor executes the computer program to implement the method described in the first aspect.
[0014] To achieve the above objectives, a fourth aspect of the present application provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the method described in the first aspect.
[0015] The risk point mining method, apparatus, electronic device, and storage medium proposed in this application extract risk event objects from a pre-constructed data source, achieving initial capture and transformation of risk data. Then, the risk event objects are structurally extracted to form standardized risk event structured information, providing a standardized foundation for subsequent data processing. Based on this structured information, a correlation information retrieval is conducted to obtain comprehensive risk correlation information, providing sufficient data support for risk point determination. Subsequently, based on the risk correlation information, the old and new risk points of the risk event objects are determined, accurately distinguishing between existing and new risks. Finally, based on the new risk point determination information, risk points are updated, forming a complete technical process from risk data capture, processing, and analysis to the identification of new risks. This not only effectively improves the systematicness and coherence of risk point mining, ensuring the orderly progression of the entire risk mining process, but also reduces redundant mining and risk omissions through standardized processing and accurate determination, improving the accuracy and efficiency of new risk point identification, and ensuring the comprehensiveness and timeliness of risk point mining work. Attached Figure Description
[0016] Figure 1 This is a flowchart of the risk point mining method provided in the embodiments of this application; Figure 2 yes Figure 1 The flowchart of step S101 in the text; Figure 3 yes Figure 1 The flowchart of step S102 in the document; Figure 4 yes Figure 1 The flowchart of step S103 in the process; Figure 5 yes Figure 4 The flowchart of step S403 in the process; Figure 6 yes Figure 1 The flowchart of step S104 in the process; Figure 7 yes Figure 1 The flowchart of step S105 in the process; Figure 8 This is a schematic diagram of the risk point discovery device provided in the embodiments of this application; Figure 9 This is a schematic diagram of the hardware structure of the electronic device provided in the embodiments of this application. Detailed Implementation
[0017] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.
[0018] It should be noted that although functional modules are divided in the device schematic diagram and a logical order is shown in the flowchart, in some cases, the steps shown or described may be performed in a different order than the module division in the device or the order in the flowchart. The terms "first," "second," etc., in the specification, claims, and the aforementioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence.
[0019] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application belongs. The terminology used herein is for the purpose of describing embodiments of this application only and is not intended to limit this application.
[0020] First, let's analyze some of the terms used in this application: Large Language Models: Large language models refer to general-purpose language models with basic natural language understanding and logical reasoning capabilities. These models are not optimized for cloud resource matching scenarios and require further fine-tuning using domain-specific sample data to enable them to learn cloud resource matching logic. For example, in the financial field, a pre-built large language model could be a general-purpose model with financial text understanding capabilities, able to parse financial terms such as cross-border payments and transaction delays, but it lacks the matching logic between transaction processing volume and CPU core count. In the medical field, a pre-built large language model could be a general-purpose model with medical text understanding capabilities, able to recognize medical terms such as electronic medical records and image analysis, but it lacks the matching logic between image processing volume and GPU configuration.
[0021] Artificial Intelligence (AI) is a technological field that integrates multiple disciplines such as computer science, psychology, philosophy, and cognitive science. AI aims to develop systems and machines capable of performing tasks that typically require human intelligence. These tasks include, but are not limited to, language understanding, learning, reasoning, perception, pattern recognition, problem-solving, and planning. AI systems simulate human cognitive functions through algorithms and statistical models, enabling computers to recognize language and images, understand natural language, and even make complex decisions and predictions.
[0022] Risk point mining is used to identify new risks that are not recorded in existing risk management systems. For example, in the financial sector, risk point mining of massive amounts of transaction data can uncover unrecorded risks such as new fraudulent transaction patterns. Similarly, in the medical field, risk point mining of patient medical records can reveal new drug interaction risks and other risks not included in the existing medical safety management system.
[0023] Currently, risk point discovery methods typically involve manually collecting risk events from data sources and judging whether a risk event is a new, unrecorded risk event based on the user's experience. However, this method heavily relies on user experience. If the user lacks sufficient experience, they may mistakenly store old risk points as new ones. Therefore, improving the accuracy of risk point discovery has become a pressing technical problem.
[0024] Based on this, embodiments of this application provide a risk point mining method and apparatus, electronic device and storage medium, aiming to improve the accuracy of risk point mining.
[0025] The risk point mining method, apparatus, electronic device, and storage medium provided in this application are specifically described through the following embodiments. First, the risk point mining method in this application is described.
[0026] The embodiments of this application can acquire and process relevant data based on artificial intelligence technology. Artificial intelligence (AI) refers to the theories, methods, technologies, and application systems that use digital computers or machines controlled by digital computers to simulate, extend, and expand human intelligence, perceive the environment, acquire knowledge, and use that knowledge to obtain optimal results.
[0027] Foundational technologies for artificial intelligence generally include sensors, dedicated AI chips, cloud computing, distributed storage, big data processing, operating / interactive systems, and mechatronics. AI software technologies mainly encompass computer vision, robotics, biometrics, speech processing, natural language processing, and machine learning / deep learning.
[0028] The risk point mining method provided in this application relates to the field of data processing technology and is applicable to the financial and medical fields. The risk point mining method provided in this application can be applied to a terminal, a server, or software running on either a terminal or a server. In some embodiments, the terminal can be a smartphone, tablet, laptop, desktop computer, etc.; the server can be configured as an independent physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms; the software can be an application implementing the risk point mining method, but is not limited to the above forms.
[0029] This application can be used in a wide variety of general-purpose or special-purpose computer system environments or configurations. Examples include: personal computers, server computers, handheld or portable devices, tablet devices, multiprocessor systems, microprocessor-based systems, set-top boxes, programmable consumer electronics, network PCs, minicomputers, mainframe computers, and distributed computing environments including any of the above systems or devices. This application can be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc., that perform specific tasks or implement specific abstract data types. This application can also be practiced in distributed computing environments where tasks are performed by remote processing devices connected via a communication network. In distributed computing environments, program modules can reside in local and remote computer storage media, including storage devices.
[0030] It should be noted that in all specific embodiments of this application, when processing data related to user identity or characteristics, such as user information, user behavior data, user historical data, and user location information, user permission or consent is obtained first. Furthermore, the collection, use, and processing of this data comply with relevant laws, regulations, and standards. In addition, when embodiments of this application require access to sensitive personal information of users, separate permission or consent from the user is obtained through pop-ups or redirection to confirmation pages. Only after obtaining the user's separate permission or consent is the necessary user-related data required for the proper functioning of these embodiments acquired.
[0031] Figure 1 This is an optional flowchart of the risk point mining method provided in the embodiments of this application. This method can be used in a risk point mining system. Figure 1 The method may include, but is not limited to, steps S101 to S105.
[0032] Step S101: Extract risk events from the pre-built data source to obtain risk event objects; Step S102: Extract structured information from the risk event object to obtain structured information about the risk event; Step S103: Based on the structured information of the risk event, perform a related information retrieval to obtain risk-related information; Step S104: Based on the risk association information, determine the old and new risk points of the risk event objects to obtain the old and new risk point determination information, wherein the old and new risk point determination information includes the new risk point determination information. Step S105: Update the risk points based on the new risk point determination information and the risk event objects.
[0033] Steps S101 to S105, as illustrated in this embodiment, extract risk events from a pre-constructed data source to obtain risk event objects. This enables the capture and transformation of risky data from the data source. The risk event objects are then structurally extracted to form standardized risk event structured information, providing a standardized foundation for data processing. Based on this structured information, related information retrieval is performed to obtain comprehensive risk association information, providing sufficient data support for risk point determination. Subsequently, based on the risk association information, the newness of the risk event objects is determined, resulting in risk point newness determination information. This enables accurate differentiation between existing and new risks. Finally, if the risk point newness determination information indicates a new risk point, risk point updates can be completed based on this new information. This not only improves the systematicness and coherence of risk point mining, ensuring the orderly progression of the entire risk mining process, but also reduces redundant mining and risk omissions through standardized processing and accurate determination, improving the accuracy and efficiency of new risk point identification and ensuring the comprehensiveness and timeliness of risk point mining.
[0034] In step S101 of some embodiments, the data source refers to a carrier that can provide various types of raw data related to risk. In the financial field, the data source can be data such as transaction records, credit application materials, account change records, and compliance filing documents stored in bank transaction systems, credit approval platforms, anti-fraud monitoring systems, and customer information management systems. In the medical field, the data source can be data such as patient medical records, drug circulation records, diagnosis and treatment operation data, and medical insurance reimbursement data stored in hospital electronic medical record systems, drug management systems, diagnostic and treatment equipment data platforms, and medical insurance settlement systems.
[0035] A risk event object refers to an independent data unit that carries core data related to risk. In the financial field, a risk event object can be a data set containing core information such as the trading entity, transaction amount, transaction time, and transaction channel of an abnormal transaction. In the medical field, a risk event object can be a data set containing key information such as patient information, drug name, drug dosage, prescribing physician, and medication time involved in medication errors.
[0036] This application embodiment can capture data change information by monitoring a pre-built data source, extract key content from the data source based on the change information, and finally encapsulate the extracted key content to generate a risk event object.
[0037] For details, please refer to Figure 2 In some embodiments, step S101 may include, but is not limited to, steps S201 to S202: Step S201: Monitor the data source to obtain data change information; Step S202: Generate an object from the data change information to obtain a risk event object.
[0038] In step S201 of some embodiments, data change information refers to data content that has been added, modified, or deleted in the data source captured by data monitoring. In the financial field, data change information may be abnormal transfer records of customer accounts or supplementary modifications to credit application materials; in the medical field, data change information may be newly added symptom descriptions in patient medical records or adjustment information of drug usage records.
[0039] This application embodiment can continuously monitor a specified data source based on pre-set monitoring rules and frequencies through data interface integration or data synchronization technology. This allows for real-time capture of changes in data, such as additions, modifications, and deletions. Furthermore, these changes are initially recorded to form data change information. For example, in the financial sector, by connecting to a bank's transaction system, real-time monitoring of customer account transfers, consumption, deposits, and withdrawals can be achieved. When a single-day transfer amount exceeds a preset threshold, the relevant changes to that transaction are recorded, forming data change information. In the medical field, by connecting to a hospital's electronic medical record system, continuous monitoring of patient medical record updates can be achieved. When a doctor adds information about a patient's allergy history, this new record is captured, providing data change information.
[0040] In step S202 of some embodiments, for the captured data change information, key content related to risk identification can be further extracted from the data source according to pre-set risk-related field filtering rules, thereby eliminating redundant and irrelevant data in the data source and forming structured core change information. For example, in the financial field, the pre-set risk-related field filtering rules can be for abnormal transfer data change information, extracting key fields such as the transaction subject account, transaction counterparty, transaction amount, transaction time, and transaction channel from the bank transaction system; in the medical field, the pre-set risk-related field filtering rules can be for drug usage adjustment data change information, extracting core content such as patient ID, drug name, dosage before and after adjustment, prescribing physician, and adjustment time from the drug management system. Furthermore, the extracted core change information can be standardized and organized according to preset data formats and encapsulation specifications to construct an independent data unit containing risk-related key information, i.e., a risk event object, which can ensure that the risk event object can fully carry the basic data required for risk analysis.
[0041] Steps S201 to S202, as illustrated in this embodiment, involve continuous data monitoring of the data source to ensure timely capture of various data changes, laying the foundation for risk event extraction. Based on the captured data change information, core changes are accurately extracted, and irrelevant redundant data is eliminated, ensuring the effectiveness of data analysis. Finally, the core changes are encapsulated into standardized risk event objects, providing standardized data support for structured extraction and risk assessment of risk event objects. This not only improves the timeliness and accuracy of risk event extraction but also reduces the difficulty of subsequent data processing through standardization, effectively minimizing risk omissions and interference from invalid data.
[0042] In step S102 of some embodiments, risk event structured information refers to risk event-related data with a unified format and standardized fields. In the financial field, risk event structured information can be abnormal credit application data organized according to preset field specifications. This risk event structured information usually includes standardized information such as applicant qualifications, application amount, repayment ability assessment indicators, and suspected violations. In the medical field, risk event structured information can be medical device malfunction-related data organized according to a unified field format. This risk event structured information usually includes standardized information such as device model, usage time, malfunction manifestations, and patient information involved.
[0043] This application embodiment can identify the risk type of a risk event object to determine its category, then determine the information to be extracted based on the category, extract the information to obtain key information, and finally perform structured processing on the key information to obtain structured risk event information with uniform format and standardized fields.
[0044] For details, please refer to Figure 3 In some embodiments, step S102 may include, but is not limited to, steps S301 to S303: Step S301: Identify the risk type of the risk event object to obtain the risk event category; Step S302: Based on the risk event category, extract fields from the risk event object to obtain key information about the risk event; Step S303: The key information of the risk event is processed in a structured manner to obtain the structured information of the risk event.
[0045] In step S301 of some embodiments, the risk event category refers to the classification result of the risk attributes of the risk event object. For example, in the financial field, the risk event category may be fraudulent transaction risk, overdue repayment risk, etc.; in the medical field, the risk event category may be adverse drug reaction risk, surgical procedure compliance risk, etc.
[0046] This application embodiment can pre-define a risk type classification system. Then, by analyzing the core data features of a risk event object and comparing them with the typical features of various risks in the risk type classification system, the risk category to which the risk event object belongs can be determined. For example, in the financial field, by comparing the features of a risk event object containing information such as large anonymous transfers and counterparties being accounts in high-risk areas with various risks in the pre-define risk type classification system, it can be determined that it belongs to the fraud transaction risk category. In the medical field, by matching the features of a risk event object containing records of severe allergic reactions after a patient uses a certain drug with various risks in the pre-define risk type classification system, it can be classified as the adverse drug reaction risk category.
[0047] In step S302 of some embodiments, key information about risk events refers to data content that can reflect the core characteristics of risk events and is of great significance to risk analysis and judgment, such as transaction amount, transaction subject, credit application qualifications, etc. in the financial field, and drug name, dosage, diagnosis and treatment operation steps, etc. in the medical field.
[0048] This application embodiment can pre-define a list of key information fields based on different risk event categories. Then, based on the obtained risk event categories, it can selectively filter and extract core data related to the risk analysis of that risk event category from the risk event objects, i.e., key information about the risk event. For example, in the financial field, for risk event objects in the overdue repayment risk category, the list of key information fields could include borrower's name, loan amount, repayment period, and number of overdue days; in the medical field, for risk event objects in the surgical procedure compliance risk category, the list of key information fields could include core content such as surgery name, surgeon, surgery time, and procedure records.
[0049] In step S303 of some embodiments, the aforementioned key information on risk events can be organized, classified, and formatted according to a pre-defined standardized data format and field specifications. This transforms the scattered key information on risk events into standardized data with a clear structure, standardized fields, and ease of subsequent retrieval and analysis. For example, in the financial field, standardized data format and field specifications can be used to organize the extracted key information on overdue repayment risks according to a structural framework of "borrower information, loan details, and overdue status," unifying the field format and data type. In the medical field, standardized data format and field specifications can be used to standardize the key information on surgical operation compliance risks according to a structure of "basic surgical information, operating procedures, and physician qualifications," forming standardized structured information on risk events.
[0050] Steps S301 to S303, as illustrated in this embodiment, identify the risk type of the risk event object, providing a clear direction for extracting key information about the risk event object and avoiding blindness in the extraction process. Then, based on the determined risk event category, key information about the risk event is extracted in a targeted manner, ensuring the relevance and effectiveness of the key information about the risk event and the risk analysis. Finally, the key information about the risk event is structured to form standardized data, providing standardized data support for the retrieval of related information and the determination of new and old risk points. This reduces the data analysis difficulty of risk point mining and effectively reduces the risk judgment bias caused by inconsistent data formats and missing core information, ensuring the accuracy and consistency of risk point mining.
[0051] In step S103 of some embodiments, risk-related information refers to various supporting data that are related to the current risk event object and are obtained through association information retrieval. In the financial field, risk-related information may be the processing results of similar illegal transactions in the past, the corresponding regulatory policy requirements, the credit rating information of the account involved, etc. In the medical field, risk-related information may be the rectification measures for similar medical errors, the relevant medical quality control standards, the revision records of the instructions for the drug involved, etc.
[0052] This application embodiment can obtain relevant risk items from a relational database based on structured information of risk events, then extract the risk semantic features of the structured information and perform feature similarity retrieval on a preset risk event knowledge base to obtain information on similar risk cases, and finally summarize the above two types of information to obtain risk association information.
[0053] For details, please refer to Figure 4 In some embodiments, step S103 may include, but is not limited to, steps S401 to S404: Step S401: Based on the structured information of the risk event, perform a relational database query to obtain the relevant risk items in the database; Step S402: Extract semantic features from the structured information of risk events to obtain risk semantic features; Step S403: Based on risk semantic features, perform feature similarity retrieval on the preset risk event knowledge base to obtain information on similar risk cases; Step S404: Summarize the relevant risk items and similar risk case information in the database to obtain risk association information.
[0054] In step S401 of some embodiments, the database-related risk item refers to existing risk record data that is associated with the structured information of the current risk event. For example, in the financial field, the database-related risk item may be a historical overdue repayment record related to the current irregular credit application; in the medical field, the database-related risk item may be a past medical error record related to the current abnormal diagnosis and treatment operation.
[0055] This application embodiment can construct a targeted database query statement based on key fields contained in the structured information of risk events, such as transaction entity ID in the financial field and diagnosis and treatment operation code in the medical field. Then, the database query statement is used to connect to a relational database that stores existing risk records and execute the query operation. This can filter out historical risk records that are related to the current risk event structured information and form related risk items in the database.
[0056] In step S402 of some embodiments, risk semantic features refer to a set of semantic elements that can characterize the core meaning and key attributes of a risk event. In the financial field, risk semantic features can be a set of semantic elements that characterize the anonymity of the subject and the large amount of money involved in fraudulent transactions. In the medical field, risk semantic features can be a set of semantic elements that characterize the drug category and symptom correlation of adverse drug reactions.
[0057] This application embodiment can employ natural language processing technology, combined with preset semantic feature extraction rules, to parse the content of each field in the structured information of risk events, thereby extracting semantic elements that reflect the core attributes and essential characteristics of the risk events. Furthermore, these semantic elements can be integrated to form risk semantic features. For example, in the financial field, for abnormal transaction structured information containing information such as anonymous transaction entities, single transaction amount of 500,000 yuan, and counterparty being an overseas account, semantic elements such as entity anonymity, large amount, and cross-border transaction can be extracted and integrated into risk semantic features. In the medical field, for medication error structured information containing information such as drug A, dosage exceeding the normal range by 2 times, and patient experiencing rash symptoms, semantic elements such as drug type A, dosage exceeding the standard, and correlation between symptoms and rash can be extracted to form risk semantic features.
[0058] In step S403 of some embodiments, the preset risk event knowledge base refers to a pre-built data set that stores knowledge and cases related to various risk events. In the financial field, the preset risk event knowledge base may be a database that stores various financial fraud cases and experience in handling compliance risk events; in the medical field, the preset risk event knowledge base may be a database that stores various medical risk cases and knowledge of diagnosis and treatment guidelines.
[0059] Similar risk case information refers to historical risk case data that has a high degree of semantic similarity to the current risk event.
[0060] This application embodiment can obtain knowledge base semantic features by extracting semantic features from a preset risk event knowledge base, then calculate the similarity between the knowledge base semantic features and the risk semantic features of the current risk event, and finally extract information from the risk event knowledge base based on the similarity to obtain information on similar risk cases.
[0061] For details, please refer to Figure 5 In some embodiments, step S403 may include, but is not limited to, steps S501 to S503: Step S501: Extract semantic features of risk events from the risk event knowledge base to obtain the semantic features of the knowledge base; Step S502: Calculate the similarity between the risk semantic features and the knowledge base semantic features to obtain the feature similarity. Step S503: Based on feature similarity, extract information from the risk event knowledge base to obtain information on similar risk cases.
[0062] In step S501 of some embodiments, the semantic features of the knowledge base refer to the set of semantic elements extracted from the cases or knowledge content in the risk event knowledge base, which can characterize the core meaning and key attributes of the cases or knowledge content in the knowledge base. For example, in the financial field, the semantic features of the knowledge base can be a set of semantic elements such as transaction patterns, subject characteristics, and risk levels of historical fraud cases; in the medical field, the semantic features of the knowledge base can be a set of semantic elements such as drug type, symptom manifestations, and applicable population of past adverse drug reaction cases.
[0063] This application embodiment can extract semantic elements that can characterize the core attributes of each risk case and knowledge entry stored in the risk event knowledge base by performing text parsing and element extraction. For example, risk types and transaction characteristics in the financial field, risk causes and symptom manifestations in the medical field, etc., and integrate these semantic elements in a unified format to form the knowledge base semantic features corresponding to each knowledge base content.
[0064] In step S502 of some embodiments, feature similarity refers to the quantitative result of the degree of similarity between risk semantic features and knowledge base semantic features calculated by a similarity algorithm.
[0065] This application embodiment can use semantic similarity calculation algorithms such as cosine similarity and Euclidean distance to quantify the risk semantic features of the current risk event with each semantic feature in the knowledge base semantic feature library to obtain the similarity value between the two, i.e. feature similarity. It should be noted that the higher the feature similarity, the more the core features of the two match.
[0066] In step S503 of some embodiments, a similarity threshold can be preset, for example, 0.8. Then, cases with feature similarity higher than the similarity threshold are selected from the semantic feature library of the knowledge base. The core information of these cases (such as case handling process and penalty results in the financial field; response measures and rectification plans in the medical field) is extracted and organized in a unified format to form similar risk case information. In the financial field, the core information may be case handling process and penalty results, and in the medical field, it may be response measures and rectification plans.
[0067] Steps S501 to S503 as illustrated in this embodiment of the application extract semantic features from the risk event knowledge base to construct a standardized comparison benchmark, providing a unified and accurate reference for similarity calculation. Then, a quantitative algorithm is used to calculate the similarity between the risk semantic features and the knowledge base semantic features, ensuring the objectivity and accuracy of the similarity judgment. Finally, similar risk cases are screened based on a preset threshold, ensuring the relevance and effectiveness of the extracted cases. It also provides high-quality similar cases to support the aggregation of risk association information, further enhancing the reliability of risk analysis and judgment, and ensuring the precise advancement of the entire risk point mining process.
[0068] In step S404 of some embodiments, pre-defined data integration rules can be used to classify, organize, and merge key information such as the time of risk occurrence and the handling result in the relevant risk items in the database with the core content such as the time of risk occurrence and the handling result in similar risk cases, forming comprehensive data with a clear structure and complete content, i.e., risk association information. For example, three illegal transfer records of a certain entity in the database can be integrated with three similar cross-border fraud cases according to the structure of "historical risk records - similar cases", and after deduplication, risk association information can be formed.
[0069] Steps S401 to S404, as illustrated in this embodiment, involve querying a relational database based on structured information of risk events to obtain existing risk records directly related to the current risk event. This provides basic data support for risk analysis. Further extraction of semantic features of the risk event and similarity retrieval of knowledge base features supplements information on similar historical risk cases, enriching the dimensions and depth of the supporting data. Finally, summarizing relevant risk items and similar risk case information from the database forms comprehensive risk association information. This not only ensures the comprehensiveness and relevance of risk association information, avoiding information bias caused by a single data source, but also provides sufficient and effective data support for determining new and old risk points, reducing judgment bias caused by insufficient information and improving the accuracy and reliability of risk point mining.
[0070] In step S104 of some embodiments, the risk point newness determination information refers to conclusive information indicating whether the risk point corresponding to the current risk event object is an existing risk or a new risk.
[0071] New risk point determination information refers to specific information in the old and new risk point determination information that indicates that the risk point corresponding to the current risk event object is a new risk that has not been recorded.
[0072] This application embodiment can select the corresponding target determination rule based on the risk event category, then extract relevant information features from the risk association information according to the rule, and finally, determine the newness or oldness of the risk point based on these relevant information features, thereby obtaining the newness or oldness determination information of the risk point.
[0073] For details, please refer to Figure 6 In some embodiments, step S104 may include, but is not limited to, steps S601 to S603: Step S601: Based on the risk event category, select the judgment rule to obtain the target judgment rule; Step S602: Based on the target determination rules, feature extraction is performed on the risk association information to obtain relevant information features; Step S603: Based on relevant information features, risk points are determined for risk event objects to obtain information on whether the risk points are old or new.
[0074] In step S601 of some embodiments, the target determination rule refers to the new and old determination criteria of risk points that are specifically adapted to the current risk event category. For example, in the financial field, the target determination rule may be "if the overlap of core features is greater than or equal to 80%, it is determined to be an old risk point"; in the medical field, the target determination rule may be "if the drug ingredients conflict and the applicable symptoms are consistent, it is determined to be an old risk point".
[0075] This application embodiment can pre-construct a judgment rule library categorized by risk event type. Each category corresponds to a set of judgment rules adapted to its risk characteristics. Once the current risk event category is determined, all rules corresponding to that risk event category can be retrieved from the judgment rule library. These rules are then filtered based on the needs of the current risk analysis scenario. Ultimately, a uniquely suitable judgment criterion can be determined as the target judgment rule. For example, if the risk event category is cross-border illegal capital flow risk, the "fund transfer frequency judgment rule" and "counterparty risk level judgment rule" for that category can be retrieved from the judgment rule library. Combined with the analyzed "large amount of funds rapidly entering and exiting" scenario, the combined judgment rule of "fund transfer frequency and counterparty risk level" can be selected as the target judgment rule.
[0076] In step S602 of some embodiments, the relevant information features refer to the core features extracted from risk-related information that play a key role in determining the newness or oldness of risk points. For example, in the financial field, the relevant information features may be the type of falsification of application materials and the characteristics of fund flow in historical credit fraud cases; in the medical field, the relevant information features may be the type of component conflict and adverse reaction manifestations in past drug incompatibilities.
[0077] This application embodiment can use the key judgment dimensions defined in the aforementioned target judgment rules as a guide to perform targeted analysis of historical risk records, similar cases, and other content in risk-related information, extracting core features directly related to the judgment dimensions. Furthermore, irrelevant and redundant information in the core features can be removed to form structured relevant information features. For example, when the target judgment rule is "the type of forgery in credit application materials and the authenticity of repayment ability proof," features such as the types of forged materials (false income certificates, forged asset certificates, etc.) and the verification results of repayment ability proof can be extracted from the risk-related information.
[0078] In step S603 of some embodiments, the core features of the current risk event object can be compared one by one with the extracted relevant information features, and a comprehensive evaluation can be performed based on quantitative standards such as the feature overlap threshold set by the above-mentioned target judgment rule. It should be noted that if the risk event object meets the judgment condition of "old risk point", it is judged as an existing risk; if the risk event object does not meet the judgment condition of "old risk point", and the core features of the risk event object are significantly different from the above-mentioned relevant information features, it is judged as a new risk. Furthermore, based on the above judgment results, clear risk point old / new judgment information can be output. For example, the core features of the current credit application are "fake bank statements and forged property certificates", and the features of the historical old risk points in the relevant information features are "fake income certificates and forged vehicle certificates". According to the target judgment rule "core forgery type overlap ≥ 60% is old risk", the overlap is calculated to be 50%, and it is judged as a new risk point. New risk point judgment information can be output.
[0079] Steps S601 to S603 of this embodiment provide precise directional basis for determining the new and old risk points by selecting appropriate target judgment rules based on risk event categories, avoiding judgment bias caused by general rules. Then, key relevant information features are extracted from risk-related information based on the target judgment rules, which can ensure the pertinence and effectiveness of the judgment basis. Finally, the new and old risk points are determined based on feature comparison, realizing the accurate implementation of decisions. This not only improves the pertinence and accuracy of the determination of new and old risk points and effectively distinguishes between existing risks and new risks, but also provides reliable decision support for risk point updates, reduces risk management loopholes or duplicate management caused by judgment errors, and improves the scientificity and efficiency of risk point mining.
[0080] In step S105 of some embodiments, if the risk point new / old determination information is new risk point determination information, a risk point draft can be generated based on the risk event object. Further, the risk point draft is evaluated, and when the risk point draft is evaluated and passed, the evaluation result containing the draft pass information can be obtained. Finally, the risk point draft is stored based on the draft pass information, and the new risk point mining can be completed.
[0081] For details, please refer to Figure 7 In some embodiments, step S105 may include, but is not limited to, steps S701 to S703: Step S701: Based on the new risk point determination information, generate a draft of the risk event object to obtain the risk point draft; Step S702: Evaluate the draft risk points to obtain draft evaluation information, including draft approval information; Step S703: Based on the draft approval information, store the draft risk points to obtain new risk point mining information.
[0082] In step S701 of some embodiments, the risk point draft refers to a preliminary document constructed in a pre-set format that contains new core risk information and control recommendations. For example, in a credit fraud scenario, the risk point draft may be a preliminary plan that includes new credit fraud risk characteristics, judgment criteria, and prevention and control measures; in a drug interaction discovery scenario, the risk point draft may be a preliminary document that includes new drug interaction risk manifestations, identification methods, and response plans.
[0083] In this embodiment of the application, new risk point determination information can be used as risk point update signal. When the risk point update signal is received, key data in the risk event object can be extracted, and combined with the preset risk point draft template and the management experience of similar risks, a preliminary document containing core elements such as new risk name, description, characteristics, judgment criteria, and prevention and control measures can be constructed, namely risk point draft.
[0084] In step S702 of some embodiments, the draft evaluation information refers to conclusive information reflecting the quality and feasibility of the draft at risk points. The draft evaluation information can be judgments such as "passed", "needs modification before passing", or "rejected".
[0085] The information that the draft has been approved refers to specific information in the draft assessment information that indicates the risk points of the draft meet the requirements and can be formally implemented.
[0086] This application embodiment can train an automated evaluation model based on the review information of historical drafts by experts in relevant fields. The automated evaluation model can review the draft from dimensions such as whether the core elements of the draft are complete, whether the risk characteristics match the judgment criteria, and whether the countermeasures are feasible. Furthermore, the automated evaluation model can also give evaluation conclusions such as "passed", "passed after modification", and "rejected" based on the review results, thereby forming draft evaluation information.
[0087] In step S703 of some embodiments, new risk point mining information refers to standardized new risk data that can be used for subsequent risk management.
[0088] In this embodiment of the application, after obtaining the draft approval information, the core information such as risk characteristics, judgment criteria, and prevention and control measures in the risk point draft can be standardized according to the preset data format and storage specifications to eliminate redundant content. Then, the standardized core information of the risk point draft is stored in the corresponding database or knowledge base to form structured, searchable, and reusable standardized new risk data, namely, new risk point mining information.
[0089] In the embodiments of this application, steps S701 to S703, upon obtaining new risk point determination information, can generate a draft risk point based on the risk event object, thereby achieving the standardized and structured presentation of the core information of the risk event object. Furthermore, the quality and feasibility of the draft risk point are strictly controlled through draft evaluation, ensuring the accuracy and effectiveness of the implemented new risk information. Finally, based on the standardized storage of the draft information to form new risk point mining information, the formal implementation of the new risk can be completed. This not only ensures the standardization and reliability of the implementation of new risk points and avoids incomplete or unreasonable risk information from entering the management system, but also achieves the standardized accumulation of new risk information, providing high-quality data support for risk monitoring and prevention, effectively improving the integrity and dynamic evolution capability of the risk management system, and ensuring the closed-loop implementation of the entire risk point mining process.
[0090] This application extracts risk event objects from a pre-constructed data source, enabling the capture and transformation of risky data. The risk event objects are then structurally extracted to form standardized risk event structured information, providing a standardized foundation for data processing. Based on this structured information, a correlation retrieval is performed to obtain comprehensive risk correlation information, providing sufficient data support for risk point identification. Subsequently, based on the risk correlation information, the age of the risk event objects is determined, resulting in a risk point age determination, enabling accurate differentiation between existing and new risks. Finally, if the risk point age determination information indicates a new risk point, the risk point can be updated based on this new information. This not only improves the systematicness and coherence of risk point mining, ensuring the orderly progression of the entire risk mining process, but also reduces redundant mining and risk omissions through standardized processing and accurate determination, improving the accuracy and efficiency of new risk point identification, and guaranteeing the comprehensiveness and timeliness of risk point mining.
[0091] Please see Figure 8 This application also provides a risk point discovery device, which can implement the above-described risk point discovery method. The device includes: The event extraction module 801 is used to extract risk events from a pre-built data source to obtain risk event objects; The information extraction module 802 is used to extract structured information from risk event objects to obtain structured information about risk events. The information retrieval module 803 is used to retrieve related information based on the structured information of risk events to obtain risk-related information; The risk assessment module 804 is used to determine the old and new risk points of risk event objects based on risk association information, and obtain the old and new risk point assessment information, which includes the new risk point assessment information. The risk point update module 805 is used to update risk points based on new risk point determination information and risk event objects.
[0092] The specific implementation of this risk point discovery device is basically the same as the specific implementation of the risk point discovery method described above, and will not be repeated here.
[0093] This application also provides an electronic device, which includes a memory and a processor. The memory stores a computer program, and the processor executes the computer program to implement the aforementioned risk point detection method. This electronic device can be any smart terminal, including tablet computers, in-vehicle computers, etc.
[0094] Please see Figure 9 , Figure 9 The hardware structure of an electronic device according to another embodiment is illustrated. The electronic device includes: The processor 901 can be implemented using a general-purpose CPU (Central Processing Unit), microprocessor, application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of this application. The memory 902 can be implemented as a read-only memory (ROM), static storage device, dynamic storage device, or random access memory (RAM). The memory 902 can store the operating system and other applications. When the technical solutions provided in the embodiments of this specification are implemented through software or firmware, the relevant program code is stored in the memory 902 and is called and executed by the processor 901 using the risk point mining method of the embodiments of this application. The input / output interface 903 is used to implement information input and output; The communication interface 904 is used to enable communication and interaction between this device and other devices. Communication can be achieved through wired means (such as USB, Ethernet cable, etc.) or wireless means (such as mobile network, WIFI, Bluetooth, etc.). Bus 905 transmits information between various components of the device (e.g., processor 901, memory 902, input / output interface 903, and communication interface 904); The processor 901, memory 902, input / output interface 903, and communication interface 904 are connected to each other within the device via bus 905.
[0095] This application also provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the aforementioned risk point discovery method.
[0096] Memory, as a non-transitory computer-readable storage medium, can be used to store non-transitory software programs and non-transitory computer-executable programs. Furthermore, memory may include high-speed random access memory, and may also include non-transitory memory, such as at least one disk storage device, flash memory device, or other non-transitory solid-state storage device. In some embodiments, memory may optionally include memory remotely located relative to the processor, and these remote memories can be connected to the processor via a network. Examples of such networks include, but are not limited to, the Internet, intranets, local area networks, mobile communication networks, and combinations thereof.
[0097] The risk point mining method, risk point mining device, electronic device, and storage medium provided in this application embodiment extract risk events from a pre-constructed data source to obtain risk event objects; extract structured information from the risk event objects to obtain structured information of the risk events; retrieve related information based on the structured information of the risk events to obtain risk association information; determine whether the risk event objects are new or old risk points based on the risk association information to obtain risk point new / old determination information, wherein the risk point new / old determination information includes new risk point determination information; and update the risk points based on the new risk point determination information and the risk event objects.
[0098] The embodiments described in this application are for the purpose of more clearly illustrating the technical solutions of the embodiments of this application, and do not constitute a limitation on the technical solutions provided by the embodiments of this application. As those skilled in the art will know, with the evolution of technology and the emergence of new application scenarios, the technical solutions provided by the embodiments of this application are also applicable to similar technical problems.
[0099] Those skilled in the art will understand that the technical solutions shown in the figures do not constitute a limitation on the embodiments of this application, and may include more or fewer steps than shown, or combine certain steps, or different steps.
[0100] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs.
[0101] Those skilled in the art will understand that all or some of the steps in the methods disclosed above, as well as the functional modules / units in the systems and devices, can be implemented as software, firmware, hardware, or suitable combinations thereof.
[0102] The terms “first,” “second,” “third,” “fourth,” etc. (if present) in the specification and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms “comprising” and “having,” and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0103] It should be understood that in this application, "at least one (item)" means one or more, and "more than" means two or more. "And / or" is used to describe the relationship between related objects, indicating that three relationships can exist. For example, "A and / or B" can represent three cases: only A exists, only B exists, and both A and B exist simultaneously, where A and B can be singular or plural. The character " / " generally indicates that the preceding and following related objects are in an "or" relationship. "At least one (item) of the following" or similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one (item) of a, b, or c can represent: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, and c can be single or multiple.
[0104] In the several embodiments provided in this application, it should be understood that the disclosed apparatus and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of the units described above is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. The coupling or direct coupling or communication connection between the shown or discussed units may be through some interfaces, or indirect coupling or communication connection between the apparatus or units, and may be electrical, mechanical, or other forms.
[0105] The units described above as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0106] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0107] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes multiple instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this application. The aforementioned storage medium includes various media capable of storing programs, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0108] The preferred embodiments of the present application have been described above with reference to the accompanying drawings, but this does not limit the scope of the claims of the present application. Any modifications, equivalent substitutions, and improvements made by those skilled in the art without departing from the scope and substance of the embodiments of the present application shall be within the scope of the claims of the present application.
Claims
1. A risk point discovery method, characterized in that, The method includes: Risk events are extracted from the pre-built data source to obtain risk event objects; Structured information is extracted from the risk event object to obtain the risk event structured information; Based on the structured information of the risk events, related information retrieval is performed to obtain risk-related information; Based on the risk association information, the risk event object is judged as a new or old risk point to obtain new or old risk point judgment information, wherein the new or old risk point judgment information includes new risk point judgment information; Based on the new risk point determination information and the risk event object, the risk point is updated.
2. The method according to claim 1, characterized in that, The process of retrieving related information based on the structured information of the risk event to obtain risk-related information includes: Based on the structured information of the risk events, a relational database query is performed to obtain the relevant risk items in the database; Semantic features are extracted from the structured information of the risk events to obtain risk semantic features; Based on the aforementioned risk semantic features, a feature similarity search is performed on the preset risk event knowledge base to obtain information on similar risk cases; The risk association information is obtained by summarizing the relevant risk items in the database and the information on similar risk cases.
3. The method according to claim 2, characterized in that, Based on the aforementioned risk semantic features, a feature similarity search is performed on a pre-defined risk event knowledge base to obtain information on similar risk cases, including: The risk event knowledge base is subjected to risk event semantic feature extraction to obtain the knowledge base semantic features; The similarity between the risk semantic features and the knowledge base semantic features is calculated to obtain the feature similarity. Based on the feature similarity, information is extracted from the risk event knowledge base to obtain information on similar risk cases.
4. The method according to claim 1, characterized in that, The step of extracting structured information from the risk event object to obtain structured information about the risk event includes: The risk event objects are identified by risk type to obtain risk event categories; Based on the risk event category, fields are extracted from the risk event object to obtain key information about the risk event; The key information of the risk event is processed in a structured manner to obtain the structured information of the risk event.
5. The method according to claim 4, characterized in that, The step of determining whether a risk event object is a new or old risk point based on the risk association information, and obtaining new or old risk point determination information, includes: Based on the aforementioned risk event categories, judgment rules are selected to obtain the target judgment rules; Based on the target determination rule, feature extraction is performed on the risk association information to obtain relevant information features; Based on the relevant information features, risk points are determined for the risk event objects to obtain information on whether the risk points are old or new.
6. The method according to any one of claims 1-5, characterized in that, The step of extracting risk events from a pre-built data source to obtain risk event objects includes: The data source is monitored to obtain data change information; The risk event object is obtained by generating an object from the data change information.
7. The method according to any one of claims 1-5, characterized in that, The step of updating risk points based on the new risk point determination information and the risk event object includes: Based on the new risk point determination information, a draft is generated for the risk event object to obtain a risk point draft; The draft risk points are evaluated to obtain draft evaluation information, which includes draft approval information. Based on the information obtained from the draft approval, the draft risk points are stored to obtain new risk point mining information.
8. A risk point detection device, characterized in that, The device includes: The event extraction module is used to extract risk events from pre-built data sources to obtain risk event objects; The information extraction module is used to extract structured information from the risk event object to obtain structured information about the risk event; The information retrieval module is used to retrieve related information based on the structured information of the risk event to obtain risk-related information; The risk assessment module is used to determine the old and new risk points of the risk event object based on the risk association information, and obtain the old and new risk point assessment information, wherein the old and new risk point assessment information includes new risk point assessment information. The risk assessment module is used to update risk points based on the new risk point assessment information and the risk event object.
9. An electronic device, characterized in that, The electronic device includes a memory and a processor, the memory storing a computer program, and the processor executing the computer program to implement the risk point mining method according to any one of claims 1 to 7.
10. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by the processor, it implements the risk point mining method according to any one of claims 1 to 7.