Risk data identification method, device and equipment

By acquiring risk information and creating risk identification prompt templates, and using risk identification models to identify suspicious business data, the problem of insufficient accuracy in risk data identification in existing technologies is solved, enabling accurate identification of potentially risky documents and enhancing network security.

CN122293369APending Publication Date: 2026-06-26ALIPAY (HANGZHOU) INFORMATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
ALIPAY (HANGZHOU) INFORMATION TECH CO LTD
Filing Date
2026-03-13
Publication Date
2026-06-26

AI Technical Summary

Technical Problem

Existing technologies are not accurate enough in identifying the risks of network service data and are difficult to effectively identify potentially risky documents.

Method used

By acquiring risk information, we can determine the suspected risk type of suspicious business data, create risk identification prompt word templates, and use risk identification models to identify whether suspicious business data is risky business data corresponding to risky objects.

Benefits of technology

It improves the accuracy of risk identification for suspicious business data, can accurately identify potentially risky documents, and enhances cybersecurity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122293369A_ABST
    Figure CN122293369A_ABST
Patent Text Reader

Abstract

This specification provides a risk data identification method, apparatus, and device. The risk data identification method includes: first, acquiring risk information, determining suspicious business data based on the risk information, and determining the suspected risk type of the suspicious business data. The risk information includes object feature data of the risk object, and the suspicious business data is associated with the object feature data. Second, based on the risk information, suspected risk type, and suspicious business data, creating a risk identification prompt word template corresponding to the suspicious business data. The risk identification prompt word template is used to represent the target risk identification strategy for the suspicious business data and the identification reference information required for the target risk identification strategy. Next, acquiring identification reference information, generating risk identification prompt words corresponding to the suspicious business data based on the identification reference information and the risk identification prompt word template. Finally, identifying whether the suspicious business data is risk business data corresponding to the risk object based on the risk identification prompt words.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This document relates to the field of data processing technology, and in particular to a method, apparatus and equipment for risk data identification. Background Technology

[0002] With increasing awareness of cybersecurity, identifying whether business data on the network is risky is a necessary measure to ensure network security. For example, identifying whether user-uploaded business files are risky files that could potentially be used to attack the network. As business data becomes more diverse and complex, higher demands are placed on the accuracy of business data risk identification. Summary of the Invention

[0003] The purpose of the embodiments in this specification is to provide a risk data identification method, apparatus, and device that can improve the accuracy of risk identification of business data.

[0004] To achieve the above technical solution, the embodiments in this specification are implemented as follows: This specification provides one or more embodiments of a risk data identification method, comprising: acquiring risk information; determining suspicious business data based on the risk information; and determining a suspected risk type of the suspicious business data. The risk information includes object feature data of a risk object. The suspicious business data is associated with the object feature data. Based on the risk information, the suspected risk type, and the suspicious business data, a risk identification prompt word template corresponding to the suspicious business data is created. The risk identification prompt word template is used to represent a target risk identification strategy for the suspicious business data and identification reference information required for the target risk identification strategy. The identification reference information is acquired, and based on the identification reference information and the risk identification prompt word template, a risk identification prompt word corresponding to the suspicious business data is generated. Using a risk identification model, based on the risk identification prompt word, it is identified whether the suspicious business data is risk business data corresponding to the risk object.

[0005] This specification provides one or more embodiments of a risk data identification device, comprising: an information determination unit, which acquires risk information, determines suspicious business data based on the risk information, and determines the suspected risk type of the suspicious business data. The risk information includes object feature data of a risk object. The suspicious business data is associated with the object feature data. A template creation unit, which creates a risk identification prompt word template corresponding to the suspicious business data based on the risk information, the suspected risk type, and the suspicious business data. The risk identification prompt word template is used to represent a target risk identification strategy for the suspicious business data and identification reference information required for the target risk identification strategy. A prompt word generation unit, which acquires the identification reference information and generates a risk identification prompt word corresponding to the suspicious business data based on the identification reference information and the risk identification prompt word template. A risk identification unit, which, through a risk identification model, identifies whether the suspicious business data is risk business data corresponding to the risk object based on the risk identification prompt word.

[0006] This specification provides one or more embodiments of a risk data identification device, including: a processor; and a memory configured to store computer-executable instructions, which, when executed, cause the processor to: acquire risk information; determine suspicious business data based on the risk information; and determine a suspected risk type of the suspicious business data. The risk information includes object feature data of a risk object. The suspicious business data is associated with the object feature data. Based on the risk information, the suspected risk type, and the suspicious business data, a risk identification prompt word template corresponding to the suspicious business data is created. The risk identification prompt word template represents a target risk identification strategy for the suspicious business data and identification reference information required for the target risk identification strategy. The identification reference information is acquired, and a risk identification prompt word corresponding to the suspicious business data is generated based on the identification reference information and the risk identification prompt word template. Using a risk identification model, the suspicious business data is identified as risk business data corresponding to the risk object based on the risk identification prompt word.

[0007] This specification provides one or more embodiments of a computer-readable storage medium for storing computer-executable instructions, which, when executed, perform the following process: acquiring risk information, determining suspicious business data based on the risk information, and determining the suspected risk type of the suspicious business data. The risk information includes object feature data of a risk object. The suspicious business data is associated with the object feature data. Based on the risk information, the suspected risk type, and the suspicious business data, a risk identification prompt word template corresponding to the suspicious business data is created. The risk identification prompt word template represents a target risk identification strategy for the suspicious business data and identification reference information required for the target risk identification strategy. The identification reference information is acquired, and based on the identification reference information and the risk identification prompt word template, a risk identification prompt word corresponding to the suspicious business data is generated. Using a risk identification model, based on the risk identification prompt word, it is identified whether the suspicious business data is risky business data corresponding to the risk object.

[0008] This specification also provides a computer program product in one or more embodiments, including a computer program that, when executed by a processor, implements the following process: acquiring risk information, determining suspicious business data based on the risk information, and determining the suspected risk type of the suspicious business data. The risk information includes object feature data of a risk object. The suspicious business data is associated with the object feature data. Based on the risk information, the suspected risk type, and the suspicious business data, a risk identification prompt word template corresponding to the suspicious business data is created. The risk identification prompt word template is used to represent a target risk identification strategy for the suspicious business data and identification reference information required for the target risk identification strategy. The identification reference information is acquired, and based on the identification reference information and the risk identification prompt word template, a risk identification prompt word corresponding to the suspicious business data is generated. Using a risk identification model, based on the risk identification prompt word, it is identified whether the suspicious business data is risk business data corresponding to the risk object. Attached Figure Description

[0009] To more clearly illustrate the technical solutions in one or more embodiments of this specification or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this specification. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort. Figure 1 A flowchart illustrating a risk data identification method provided in one or more embodiments of this specification; Figure 2A flowchart illustrating another risk data identification method provided in one or more embodiments of this specification; Figure 3 A flowchart illustrating yet another risk data identification method provided in one or more embodiments of this specification; Figure 4 A schematic diagram of the structure of a risk data identification device provided for one or more embodiments of this specification; Figure 5 This is a schematic diagram of the structure of a risk data identification device provided for one or more embodiments of this specification. Detailed Implementation

[0010] To enable those skilled in the art to better understand the technical solutions in one or more embodiments of this specification, the technical solutions in one or more embodiments of this specification will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this specification, and not all of the embodiments. Based on one or more embodiments of this specification, all other embodiments obtained by those skilled in the art without creative effort should fall within the protection scope of this document.

[0011] This specification provides one or more embodiments of a risk data identification mechanism that can acquire risk information, including object feature data of a risk object. From massive amounts of business data, it identifies suspicious business data associated with the object feature data and determines the suspected risk type of the suspicious business data. Then, based on the risk information, suspected risk type, and suspicious business data, it creates a risk identification prompt word template corresponding to the suspicious business data. It obtains identification reference information required for the target risk identification strategy from the risk identification prompt word template. Based on the identification reference information and the risk identification prompt word template, it generates a risk identification prompt word corresponding to the suspicious business data. Based on this risk identification prompt word, it identifies whether the suspicious business data is risky business data corresponding to the risk object. Since the risk identification prompt word can be generated based on currently identified suspicious business data, the suspected risk type of the suspicious business data, and the risk information, this risk identification prompt word is a personalized prompt word corresponding to the suspicious business data. Based on this prompt word, more accurate and targeted risk identification can be performed on suspicious business data, improving the accuracy of risk identification for suspicious business data.

[0012] Figure 1This is a flowchart illustrating a risk data identification method provided in one or more embodiments of this specification. The execution subject of this method can be a terminal device or a server. The terminal device can be a mobile terminal device such as a mobile phone or tablet computer, a computer device such as a laptop or desktop computer, or an Internet of Things (IoT) device (specifically, a smartwatch, in-vehicle device, etc.). The server can be a single independent server or a server cluster composed of multiple servers. The server can be a backend server for financial services or online shopping services, or a backend server for an application. This embodiment uses a server as the execution subject for detailed explanation. For the case where the execution subject is a terminal device, please refer to the following section on server-side processing, which will not be repeated here. Figure 1 As shown, the method may specifically include the following steps: Step S102: Obtain risk information, determine suspicious business data based on the risk information, and determine the suspected risk type of the suspicious business data; the risk information includes the object characteristic data of the risk object; the suspicious business data is associated with the object characteristic data; Step S104: Based on risk information, suspected risk types, and suspicious business data, create a risk identification prompt template corresponding to the suspicious business data; the risk identification prompt template is used to represent the target risk identification strategy for the suspicious business data and the identification reference information required for the target risk identification strategy. Step S106: Obtain identification reference information, and generate risk identification prompts corresponding to suspicious business data based on the identification reference information and risk identification prompt template; Step S108: Using the risk identification model, identify whether the suspicious business data is the risky business data corresponding to the risk object based on the risk identification prompt words.

[0013] In step S102 above, risk information is obtained. Risk information includes the object characteristic data of the risk objects. In one form, the risk information is a list recording the object characteristic data of the risk objects. In one example, the risk objects include pre-determined risk users, and the object characteristic data includes the risk user's user ID (identity), user work experience, user education experience, etc. In another example, the risk objects include pre-determined risk addresses, and the object characteristic data includes the address information of the risk addresses, etc. In yet another example, the risk objects include pre-determined risk entities, and the object characteristic data includes the entity identifier of the risk entity, etc. Entities include, but are not limited to, enterprises, institutions, and other groups. In yet another example, the risk objects include pre-determined risk regions, and the object characteristic data includes the region identifier of the risk region, etc.

[0014] In step S102 above, suspicious business data is determined based on risk information. This suspicious business data is associated with the object characteristic data of the risk object in the risk information. A large amount of business data is stored in the database; this data can be online or offline. If a piece of business data is associated with the object characteristic data of a risk object, then that business data may be the risk business data corresponding to that risk object. For example, if a piece of business data is similar to the user ID of a risky user, then that business data may represent that risky user; that business data may be the ID of that risky user; and that business data may be risky business data. Similarly, if a piece of business data is similar to the address information of a risky address, then that business data may represent that risky address; that business data may be the address information of that risky address; and that business data may be risky business data. Likewise, if a piece of business data is similar to the entity identifier of a risky entity, then that business data may represent that risky entity; that business data may be the entity identifier of that risky entity; and that business data may be risky business data. For example, if a piece of business data resembles the region identifier of a risky region, then that business data may represent that risky region, may be the region identifier of that risky region, and may be risky business data. Furthermore, if the physical address represented by a piece of business data may be a physical address within a risky region, then that business data is suspicious. Similarly, if the IP (Internet Protocol) address represented by a piece of business data may be an IP address within a risky region, then that business data is suspicious.

[0015] For business data that may be considered risky, it can be identified as suspicious business data. Steps S104-S108 are then used to determine whether the suspicious business data corresponds to a risky object. For example, if a piece of business data is similar to a user ID of a risky user, then the business data is suspicious. If steps S104-S108 determine that the business data is risky, then the business data represents a risky user, and the business data is the user ID of that risky user. Similarly, if a piece of business data is similar to the address information of a risky address, then the business data is suspicious. If steps S104-S108 determine that the business data is risky, then the business data represents a risky address, and the business data is the address information of that risky address. For example, if a certain business data is similar to the entity identifier of a risk entity, then the business data is suspicious business data. If the business data is determined to be risky business data through the process of steps S104-S108, then it means that the business data is used to represent a risk entity and the business data is the entity identifier of the risk entity.

[0016] In some cases, as mentioned above, if the physical address represented by a certain business data might be a physical address within a risky area, then the business data is considered suspicious. If, through steps S104-S108, it is determined that the physical address represented by the business data is indeed a physical address within a risky area, then the business data is considered risky business data. Similarly, if the IP address represented by a certain business data might be an IP address within a risky area, then the business data is considered suspicious. If, through steps S104-S108, it is determined that the IP address represented by the business data is indeed an IP address within a risky area, then the business data is considered risky business data.

[0017] In some embodiments, identifying suspicious business data based on risk information includes: Determine the degree of correlation between business data and the object characteristic data of risk objects in risk information. If the degree of correlation is greater than the correlation threshold, the business data is determined to be suspicious business data.

[0018] In one scenario, the aforementioned correlation can include similarity. For example, a risky object includes a risky user, and object feature data includes the risky user's user ID, which is 001. A certain business data entry is "0010". The similarity between this business data entry "0010" and the risky user's user ID "001" is determined to be 0.9, which is greater than the similarity threshold of 0.5. Therefore, this business data entry "0010" is determined to be suspicious business data; it may represent a risky user, and it may be the risky user's user ID.

[0019] For example, a risk object includes a risk address, and the object feature data includes the address information of the risk address, which is located in District A, City A, Province A. A certain business data is "District A1, City A, Province A". The similarity between this business data "District A1, City A, Province A" and the address information of the risk address "District A, City A, Province A" is determined to be 0.95, which is greater than the similarity threshold of 0.5. Therefore, the business data "District A1, City A, Province A" is determined to be suspicious business data. This business data "District A1, City A, Province A" may represent a risk address, and this business data "District A1, City A, Province A" may be the address information of a risk address.

[0020] For example, a risk object includes a risk entity, and the object's characteristic data includes the entity identifier of the risk entity, which is AAA. If a certain business data point is "AAA1", the similarity between this business data point "AAA1" and the entity identifier "AAA" of the risk entity is determined to be 0.85, which is greater than the similarity threshold of 0.5. Therefore, this business data point "AAA1" is determined to be suspicious business data; it may represent the risk entity, and it may be the entity identifier of the risk entity.

[0021] For example, a risk object includes a risky region, and the object's feature data includes the region identifier of the risky region, which is BBB. A certain business data point is "BBB1". The similarity between this business data point "BBB1" and the region identifier "BBB" of the risky region is determined to be 0.85, which is greater than the similarity threshold of 0.5. Therefore, this business data point "BBB1" is determined to be suspicious business data; it may represent a risky region, and it may be the region identifier of a risky region.

[0022] Furthermore, as mentioned earlier, if the address represented by a certain business data may be a physical address within a risk area, then the probability that the physical address represented by the business data is located in that risk area is determined, and the correlation degree includes this probability. If the probability is greater than a threshold, then the business data is determined to be suspicious business data. Similarly, if the IP (Internet Protocol) address represented by a certain business data may be an IP address within a risk area, then the probability that the IP address represented by the business data is located in that risk area is determined, and the correlation degree includes this probability. If the probability is greater than a threshold, then the business data is determined to be suspicious business data.

[0023] As can be seen, this embodiment can achieve the effect of accurately identifying suspicious business data based on the degree of correlation between business data and the object feature data of risk objects in risk information.

[0024] In some embodiments, identifying suspicious business data based on risk information includes: Determine the object category of the risk object, and parse the business data according to the object category to obtain the information represented by the business data based on the object category; If the correlation between the information represented by the object category in the business data and the object feature data is greater than the correlation threshold, then the business data is identified as suspicious business data.

[0025] In this embodiment, firstly, the object category of the risk object is determined. Risk objects include, but are not limited to, risky users, risky entities, risky addresses, and risky regions, as mentioned above. Object categories include, but are not limited to, individuals, entities, addresses, and regions. Then, the business data is parsed based on the object category to obtain the information represented by the business data based on the object category. Next, it is determined whether the correlation between the information represented by the business data based on the object category and the object feature data is greater than a correlation threshold. If it is greater, the business data is identified as suspicious business data.

[0026] In one scenario, the aforementioned correlation may include similarity. In one example, the risk object includes a risky address, and the object feature data includes the physical address information of the risky address. The object category for determining the risky object includes address categories. The business data includes the obtained IP address. Based on the object category, the IP address is parsed to obtain the physical address information represented by the IP address. It is then determined whether the similarity between this physical address information and the physical address information of the risky address is greater than a similarity threshold. If it is greater, the IP address is identified as suspicious business data. In this case, the IP address may represent a risky address, or it may be the IP address of a risky address.

[0027] In another example, the risk object includes a risk address, and the object feature data includes the physical address information of the risk address. The object category for determining the risk object includes address type. Business data includes the obtained latitude and longitude information. Based on the object category, the latitude and longitude information is parsed to obtain the physical address information represented by the latitude and longitude information. It is then determined whether the similarity between this physical address information and the physical address information of the risk address is greater than a similarity threshold. If it is greater, the latitude and longitude information is identified as suspicious business data. In this case, the latitude and longitude information may represent a risk address, or it may be the latitude and longitude information of a risk address.

[0028] As can be seen, this embodiment takes into account the object category of the risk object, and can parse the business data based on the object category to obtain the information represented by the business data based on the object category. When the correlation between the information represented by the business data based on the object category and the object feature data is greater than the correlation threshold, the business data is identified as suspicious business data. This effectively solves the problem that the business data and the object feature data have the same meaning but different expression methods. For example, the address can be represented by province, city, district or by IP or latitude and longitude, which improves the accuracy of identifying suspicious business data.

[0029] In step S102 above, the suspected risk type of the suspicious business data is also determined. Suspected risk types include, but are not limited to, at least one of the following: personal, entity, address, region, IP, and latitude / longitude. Among these, entities include, but are not limited to, organizations such as enterprises and institutions.

[0030] In some embodiments, determining the suspected risk type of suspicious business data includes: Determine the object category of the risk object, and determine the business content represented by the suspicious business data; Based on the above object categories and business content, select the suspected risk type of suspicious business data from each preset category.

[0031] In this embodiment, firstly, the object category of the risk object is determined. Risk objects include, but are not limited to, the aforementioned risk users, risk entities, risk addresses, and risk regions. Object categories include, but are not limited to, individuals, entities, addresses, and regions. Then, the business content represented by the suspicious business data is determined.

[0032] Based on the business type of the suspicious business data, the business content represented by the suspicious business data can be determined, thereby avoiding misjudgment of the business content caused by the same business data being used to represent different content in different businesses. For example, if the suspicious business data is an IP address, when the business type of the suspicious business data is a purchase-related business, the business content represented by the IP address may be the address of the user's device; when the business type of the suspicious business data is a registration-related business, the business content represented by the IP address may be the login IP.

[0033] Next, based on the aforementioned object categories and business content, suspected risk types of suspicious business data are selected from various preset categories. Multiple preset categories are stored, including at least one of the following: personal, entity, address, region, IP, and latitude / longitude. The category among the preset categories that matches the aforementioned object categories and business content can be used as the suspected risk type of the suspicious business data.

[0034] For example, if the object category is "personal" and the suspicious business data is "0001", where "0001" represents the buyer ID and the business content is "buyer ID", and the "personal" in each preset category matches the object category and business content, then the suspected risk type is "personal".

[0035] For example, if the object category is "Entity Class" and the suspicious business data is "AA1", where "AA1" represents the purchasing company identifier and the business content is "purchasing the company identifier", and the "Entity Class" in each preset category matches the object category and business content, then the suspected risk type is Entity Class.

[0036] For example, if the object category is "address type" and the suspicious business data is "ABC", where "ABC" represents the login IP and the business content is "login IP", and the "IP type" in each preset category matches the object category and business content, then the suspected risk type is IP type.

[0037] For example, if the object category is "address", the suspicious business data is "xxxx", where "xxxx" represents the latitude and longitude information of the login location, and the business content is "latitude and longitude information of the login location", and the "latitude and longitude" category in each preset category matches the object category and business content, then the suspected risk type is latitude and longitude.

[0038] For example, if the object category is "address", the suspicious business data is "yyyy", where "yyyy" represents the delivery address and the business content is "delivery address", and the "address" category in each preset category matches the object category and business content, then the suspected risk type is address.

[0039] For example, if the object category is "regional category", the suspicious business data is "zzzz", and "zzzz" represents the delivery address, which may be located in a risky area, and the business content is "delivery address", then the suspected risk type is the address category if the "address category" in each preset category matches the object category and business content.

[0040] For example, if the object category is "regional category", the suspicious business data is "cccc", and "cccc" represents the login IP, the login IP may be located in a risky region, and the business content is "login IP", then the suspected risk type is the address category if the "IP category" in each preset category matches the object category and business content.

[0041] In some examples, the process of determining the object category of risky objects and the business content represented by suspicious business data can be performed using a Large Language Model (LLM). Based on the object category and business content, the suspected risk type of the suspicious business data is selected from various preset categories. This Large Language Model can also be called a category determination model.

[0042] As can be seen, the embodiments of this specification can take into account the business content represented by the suspicious business data in the business and the object category of the risk object, and select the suspected risk type of the suspicious business data from each preset category, so that the suspected risk type matches the object category of the risk object and the business content represented by the suspicious business data, thereby improving the accuracy of determining the suspected risk type.

[0043] In some examples, risk information data can also be input into a large language model. This model then performs the aforementioned process of "identifying suspicious business data based on risk information and determining the suspected risk type of the suspicious business data" for each business data item stored in the database. The suspicious business data resides within the various business data items stored in the database.

[0044] In step S104 above, a risk identification prompt template is created based on the risk information, the suspected risk type of the suspicious business data, and the suspicious business data itself. The risk identification prompt template represents the target risk identification strategy for the suspicious business data and the identification reference information required by the target risk identification strategy. Specifically, the target risk identification strategy is used to identify whether the suspicious business data corresponds to a risky object; for example, it identifies whether the ID in the suspicious business data is the user ID of the risky user recorded in the risk information, and whether the address in the suspicious business data is an address within the risky region recorded in the risk information. The identification reference information is the necessary information required by the target risk identification strategy to identify risks in the suspicious business data.

[0045] In some embodiments, a risk identification prompt template corresponding to suspicious business data is created based on risk information, suspected risk types, and suspicious business data, including: Based on the suspected risk type, obtain the initial risk identification strategy corresponding to the suspicious business data; the initial risk identification strategy is used to represent the risk identification strategy for the suspected risk type. Based on the risk information, the initial risk identification strategy is adjusted to obtain the target risk identification strategy. Based on the suspicious business data and the target risk identification strategy, identification reference information is determined. Generate supplementary prompts corresponding to the identification reference information, and perform data fusion based on the target risk identification strategy and the supplementary prompts to obtain risk identification prompt word templates.

[0046] In this embodiment, pre-defined risk identification strategies are provided for each suspected risk type. A large language model can be used to semantically understand the manual review experience corresponding to each suspected risk type to obtain the corresponding risk identification strategy. The manual review experience is used to verify whether the suspicious business data corresponding to each suspected risk type is indeed risky business data; therefore, the risk identification strategy for each suspected risk type is used to identify whether the suspicious business data corresponding to each suspected risk type is indeed risky business data.

[0047] First, obtain the risk identification strategies corresponding to each suspected risk type. Then, query the risk identification strategies corresponding to the suspected risk types of the suspicious business data in step S102. Use these risk identification strategies as the initial risk identification strategies for the suspicious business data in step S102. The initial risk identification strategy represents the risk identification strategy for the suspected risk types of the suspicious business data in step S102.

[0048] Then, based on the risk information, the initial risk identification strategy is adjusted to obtain the target risk identification strategy. Based on the suspicious business data and the target risk identification strategy, identification reference information is determined. Identification refers to the necessary information required by the target risk identification strategy to identify risks in suspicious business data.

[0049] Finally, supplementary prompts corresponding to the identification reference information are generated. Based on the target risk identification strategy and the supplementary prompts, data fusion is performed to obtain a risk identification prompt template. For example, the target risk identification strategy and the supplementary prompts are fused to obtain the risk identification prompt template. The risk identification prompt template includes both the target risk identification strategy and the supplementary prompts.

[0050] As can be seen, this embodiment allows for the acquisition of a risk identification strategy set for the suspected risk type of suspicious business data as an initial risk identification strategy. Based on risk information, the initial risk identification strategy is adjusted to obtain a target risk identification strategy. This allows the target risk identification strategy to not only consider the suspected risk type of suspicious business data but also to be personalized based on risk information. Based on the suspicious business data and the target risk identification strategy, identification reference information is determined, and supplementary prompts corresponding to the identification reference information are incorporated into the risk identification prompt word template. This enables the risk identification prompt word template to supplement the identification reference information, achieving the effect of accurately identifying suspicious business data based on the identification reference information.

[0051] In some embodiments, based on the suspected risk type, an initial risk identification strategy corresponding to the suspicious business data is obtained, including: The system acquires various risk identification sub-strategies set by the expert agent for suspected risk types; each risk identification sub-strategy has a corresponding risk identification dimension; and the risk identification sub-strategy is used to identify suspected risk types based on the risk identification dimension. An initial risk identification strategy is generated based on each risk identification sub-strategy; the initial risk identification strategy includes each risk identification sub-strategy.

[0052] In this embodiment, the expert agent sets multiple risk identification sub-strategies for each suspected risk type. Each risk identification sub-strategy corresponds to a risk identification dimension. The risk identification sub-strategy is used to identify the suspected risk type based on the risk identification dimension, and to identify whether the suspicious business data corresponding to the suspected risk type is risky business data. For example, suspected risk types include, but are not limited to, at least one of the following: personal, entity, address, region, IP, and latitude / longitude. For personal types, risk identification dimensions can be set to include: education experience dimension and work experience dimension. Based on these two dimensions, it can be identified whether the user represented by the suspicious business data is a risky user. For entity types, risk identification dimensions can be set to include: company name dimension and company business category dimension. Based on these two dimensions, it can be identified whether the company represented by the suspicious business data is a risky entity. For address types, risk identification dimensions can be set to include: address information dimension and the category of shops near the address dimension. Based on these two dimensions, it can be identified whether the address represented by the suspicious business data is a risky address, or whether the address represented by the suspicious business data is located in a risky area. Therefore, the expert agent obtains the various risk identification sub-strategies set by the expert agent for the suspected risk types of the suspicious business data in step S102, and uses each risk identification sub-strategy as the initial risk identification strategy corresponding to the suspicious business data in step S102. In various embodiments of this specification, the expert agent can also be referred to as an agent.

[0053] As can be seen, this embodiment can accurately obtain the various risk identification sub-strategies set by the expert intelligent agent for the suspected risk type corresponding to the suspicious risk data, and accurately generate the initial risk identification strategy based on each risk identification sub-strategy.

[0054] In some embodiments, the initial risk identification strategy is adjusted based on risk information to obtain a target risk identification strategy, including: Based on the object characteristic data in the risk information, the risk identification parameters required for the initial risk identification strategy are adjusted, and the adjusted risk identification parameters are matched with the object characteristic data; the target risk identification strategy includes the adjusted initial risk identification strategy.

[0055] Each risk identification sub-strategy in the initial risk identification strategy includes at least one risk identification parameter. For example, for individuals, the risk identification dimensions include: education experience dimension and work experience dimension. Therefore, the risk identification sub-strategy corresponding to the education experience dimension must include at least the education experience parameter, and the risk identification sub-strategy corresponding to the work experience dimension must include at least the work experience parameter. Similarly, for entities, the risk identification dimensions include: company name dimension and company business category dimension. Therefore, the risk identification sub-strategy corresponding to the company name dimension must include at least the company name parameter, and the risk identification sub-strategy corresponding to the company business category dimension must include at least the company business category parameter.

[0056] Therefore, the various risk identification parameters required for the initial risk identification strategy are determined. Based on the object feature data in the risk information, these parameters are adjusted to match the object feature data. The target risk identification strategy includes the adjusted initial risk identification strategy. In one scenario, considering that the object feature data in the risk information might not include a certain risk identification parameter in the initial risk identification strategy, this parameter can be removed from the required parameters, thus avoiding the identification of suspicious business data based on non-existent object feature data. In another scenario, considering that the required parameters may not include a certain object feature data from the risk information, a risk identification parameter corresponding to that object feature data can be added to the required parameters, enabling comprehensive identification of suspicious business data based on the object feature data.

[0057] In one example, the risk object's characteristic data includes education level. Since education level is not among the risk identification parameters required by the initial risk identification strategy, it can be added to the initial risk identification strategy's required risk identification parameters. In another example, the risk object's characteristic data does not include work unit. Since work unit exists among the risk identification parameters required by the initial risk identification strategy, the work unit parameter can be removed from the initial risk identification strategy's required risk identification parameters.

[0058] The initial risk identification strategy, after parameter adjustment, can be used as the target risk identification strategy. Therefore, based on the above process, the risk identification parameters required for the initial risk identification strategy can be adjusted according to the object feature data in the risk information, so that the adjusted risk identification parameters match the object feature data. Matching can be understood as the adjusted risk identification parameters and the object feature data representing the same information items, thereby achieving the effect of combining the object feature data of the risk object to generate a targeted target risk identification strategy.

[0059] In some embodiments, identification reference information is determined based on suspicious business data and a target risk identification strategy, including: The suspicious business data is compared with the information missing from the risk identification parameters required by the target risk identification strategy, and the identification reference information is determined based on the missing information.

[0060] Based on the above process, a target risk identification strategy can be generated, which includes various adjusted risk identification parameters. In this step, information missing from the suspicious business data compared to the risk identification parameters required by the target risk identification strategy is identified as reference information. For example, suspicious business data may include a user ID and the user's registration duration, but not the user's workplace. However, the risk identification parameters required by the target risk identification strategy include workplace, and the user characteristics of risky users also include workplace. It is necessary to compare whether the workplace of the user corresponding to the suspicious business data matches that of the risky user to determine whether the user represented by the suspicious business data is a risky user, and thus whether the suspicious business data is risky business data corresponding to a risky user. Therefore, the workplace of the user corresponding to the suspicious business data is identified as reference information.

[0061] For example, suspicious business data includes address information but does not include the surrounding merchant categories. However, the risk identification parameters required by the target risk identification strategy include the surrounding merchant categories of the address information. The address characteristics of the risk address include the surrounding merchant categories of the risk address. It is necessary to compare the surrounding merchant categories of the address information corresponding to the suspicious business data with the surrounding merchant categories of the risk address to determine whether the address represented by the suspicious business data is a risk address, and then determine whether the suspicious business data is the risk business data corresponding to the risk address. Therefore, the surrounding merchant categories of the address information corresponding to the suspicious business data are determined as identification reference information.

[0062] For example, suspicious business data may include street information but not the geographic area information corresponding to that street. However, the risk identification parameters required by the target risk identification strategy include the geographic area information corresponding to the street information. The regional characteristics of the risk area include the geographic area information of each geographic area within the risk area. It is necessary to compare the geographic area information corresponding to the street information in the suspicious business data with the geographic area information of each geographic area within the risk area to determine whether the street information represented by the suspicious business data is located within the risk area. In this way, it can be determined whether the suspicious business data is the risk business data corresponding to the risk area. Therefore, the geographic area information corresponding to the street information in the suspicious business data is determined as the identification reference information.

[0063] Therefore, through the above process, it is possible to compare the information missing from the suspicious business data compared to the risk identification parameters required by the target risk identification strategy, and determine the identification reference information based on the missing information, so that subsequent identification reference information can accurately identify whether the suspicious business data is the risk business data corresponding to the risk object.

[0064] In some embodiments, the target risk identification strategy can represent the identification target, identification process, and identification rules for suspicious business data. The identification target includes identifying whether the suspicious business data corresponds to a risky business data object. The identification process includes the various risk identification sub-strategies described above, each of which includes multiple risk identification parameters. The identification rules include determining that the suspicious business data is risky business data after each risk identification parameter meets its corresponding condition. In one example, each risk identification sub-strategy sequentially identifies whether the educational and professional experience of the user represented by the suspicious business data matches that of a risky user, and determines whether the user represented by the suspicious business data is a risky user based on the identification results, thereby determining whether the suspicious business data corresponds to a risky user. In this example, the suspicious business data may include a user ID.

[0065] After obtaining the risk identification prompt template, in step S106 above, identification reference information is obtained. This reference information can be compared with the object characteristic data of the risk object to determine whether the suspicious business data corresponds to the risk object. Based on the identification reference information and the risk identification prompt template, risk identification prompts corresponding to the suspicious business data are generated. For example, identification reference information is obtained based on the supplementary prompt information mentioned above, and then filled into the risk identification prompt template to obtain the risk identification prompts corresponding to the suspicious business data. When obtaining identification reference information, it can be obtained from the following aspects: obtaining identification reference information from user registration information, and retrieving identification reference information from external websites, such as retrieving a specific address or IP address.

[0066] In some embodiments, the identification reference information includes at least one sub-data, each sub-data having a corresponding data modality; based on the identification reference information and the risk identification prompt word template, risk identification prompt words corresponding to suspicious business data are generated, including: Extract the data content of the sub-data based on its data modality; The data content of the sub-data is validated; the validation includes timeliness and / or authenticity verification. The risk identification prompts are obtained by filling the risk identification prompt template with the verified data content.

[0067] First, based on the data modality of the sub-data, the data content of the sub-data is extracted. For example, for text-modal sub-data, the data content is extracted using a large language model to obtain structured data content. For image-modal sub-data, the data content is extracted using a visual processing model such as a Vision-Language Model (VLM). Then, the data content of the sub-data is validated, including timeliness and / or authenticity verification. In one scenario, timeliness verification is performed; in another, authenticity verification is performed; and in yet another, both timeliness and authenticity verification are performed. If the timeliness and / or authenticity verification of a sub-data fails, that sub-data is deleted, and only those that pass are retained. Finally, the risk identification prompt word template is populated based on the validated data content to obtain the risk identification prompt words. Alternatively, after obtaining the sub-data, it can be cleaned first, followed by content extraction and validation.

[0068] As can be seen, this embodiment can process identification reference information of different modalities, and fill the risk identification prompt word template based on the identification reference information of various modalities to obtain risk identification prompt words.

[0069] After obtaining the risk identification prompt, in step S108 above, the risk identification model identifies whether the suspicious business data corresponds to the risky object based on the risk identification prompt. The risk identification prompt can be input into the risk identification model, which can be a large language model. The risk identification model identifies whether the suspicious business data corresponds to the risky object based on the risk identification prompt. The risk identification model can logically verify the identification target, identification process, and identification rules for suspicious business data represented by the target risk identification strategy. For example, it verifies whether the identification target, identification process, and identification rules are logically consistent and free from contradictions. If the verification passes, the model identifies whether the suspicious business data corresponds to the risky object based on the risk identification prompt; if the verification fails, it prompts the user to modify the risk identification prompt.

[0070] Of course, an intelligent agent can also be used to identify whether suspicious business data corresponds to risky business data based on risk identification prompts. Whether to use a risk identification model or an intelligent agent for risk identification can be chosen based on actual needs.

[0071] An example of a risk identification prompt could be: "Please identify whether the suspicious business data 'User ID001' represents a risky user, based on three dimensions: User ID, Educational Background, and Professional Experience." Here, the risky user's User ID is "0010," the suspicious business data is "User ID001," and the risky user's educational and professional experience is as follows: xxxxx. The educational and professional experience of the user represented by "User ID001" is as follows: yyyyyy. In this example, the risky user's User ID, educational and professional experience can be obtained from the object feature data of the risky object, while the educational and professional experience of the user represented by "User ID001" can be identification reference information obtained from the system. The risk identification model can output identification results and reasoning chains, thus making the identification results fully interpretable.

[0072] The aforementioned risk data identification method can be applied to both online and offline scenarios. In online scenarios, risk information can be acquired, and based on this information, suspicious business data can be identified from various online business data sets. The suspected risk type of the suspicious business data can also be determined. Based on the risk information, suspected risk type, and suspicious business data, a risk identification prompt word template corresponding to the suspicious business data is created. Identification reference information is obtained, and based on the identification reference information and the risk identification prompt word template, risk identification prompt words corresponding to the suspicious business data are generated. Using a risk identification model, the risk identification prompt words are used to identify whether the suspicious business data corresponds to a risky object. In offline scenarios, risk information can be acquired, and based on this information, suspicious business data can be identified from various offline business data sets. The suspected risk type of the suspicious business data can also be determined. Based on the risk information, suspected risk type, and suspicious business data, a risk identification prompt word template corresponding to the suspicious business data is created. Identification reference information is obtained, and based on the identification reference information and the risk identification prompt word template, risk identification prompt words corresponding to the suspicious business data are generated. Using a risk identification model, the risk identification prompt words are used to identify whether the suspicious business data corresponds to a risky object.

[0073] The above process is described below with specific examples.

[0074] Example 1: Obtain a list of risky user IDs, identify similar user IDs in business data as suspicious business data, and determine the suspected risk type as personal. Create a risk identification prompt template based on the risky user ID list, suspected risk type, and similar user IDs. The template's identification reference information includes the work experience and educational background of the users corresponding to the similar user IDs. The template's target risk identification strategy includes the identification process and rules for determining whether the user represented by the similar user ID is a risky user. Obtain the identification reference information, generate risk identification prompts based on the identification reference information and the risk identification prompt template, and use the risk identification model to determine whether the work experience and educational background of the users corresponding to the similar user IDs match those of the risky users, thereby determining whether the user corresponding to the similar user ID is a risky user, and further identifying whether the similar user ID is risky business data. The work experience and educational background of risky users can be obtained from risk information.

[0075] Example 2: Obtain the address information of risky addresses, identify IPs with similar addresses in the business data as suspicious business data, and determine the suspected risk type as IP class. Create a risk identification prompt word template based on the risky address information, suspected risk type, and the aforementioned IPs. The template's identification reference information includes the specific address corresponding to the aforementioned IPs. The template's target risk identification strategy includes the identification process and rules for identifying whether the specific address corresponding to the IP is a risky address. Obtain identification reference information, generate risk identification prompt words based on the identification reference information and the risk identification prompt word template, and use the risk identification model to determine whether the specific address corresponding to the aforementioned IP matches the address information of the risky address, thereby determining whether the specific address corresponding to the IP is a risky address, and further identifying whether the IP is risky business data.

[0076] Example 3: Obtain the regional information of the risk area, identify address data in the business data that may be located in the risk area as suspicious business data, and determine the suspected risk type as address type. Create a risk identification prompt word template based on the address information of the risk address, the suspected risk type, and the above suspicious business data. The identification reference information of this template includes merchant information near the above suspicious business data. The target risk identification strategy of this template includes the identification process and identification rules for identifying whether the address represented by the suspicious business data is located in the risk area. Obtain the identification reference information, generate risk identification prompt words based on the identification reference information and the risk identification prompt word template, and use the risk identification model to determine whether the merchant information near the above suspicious business data matches the regional information of the risk area, thereby determining whether the address represented by the suspicious business data is located in the risk area, and further identifying whether the IP is the risky business data corresponding to the risk area.

[0077] Furthermore, in some embodiments, the above method flow further includes: Identify the business elements associated with suspicious business data; business elements include business processes and / or user accounts. If the suspicious business data is the risky business data corresponding to the risky object, then risk control shall be carried out on that business element; If the suspicious business data is not the risky business data corresponding to the risky object, then the business element is allowed to proceed.

[0078] First, identify the business elements associated with the suspicious business data. In one scenario, the business element includes a business process; in another, it includes a user account; and in yet another, it includes both a business process and a user account. As mentioned above, suspicious business data can be identified in both online and offline business data.

[0079] When suspicious business data is identified in online business data, this suspicious business data may have associated business processes. For example, suspicious business data may include shipping address information, and the associated business process may include a purchase transaction. Similarly, suspicious business data may have associated user accounts. For example, suspicious business data may include a user ID, and the associated user account may include the user account corresponding to that user ID. Finally, suspicious business data may have associated business processes and user accounts. For example, suspicious business data may include the IP address of a purchasing user, the associated business process may include a purchase transaction, and the associated user account may include the purchasing user's account.

[0080] When suspicious business data is identified in offline business data, the suspicious business data may have associated user accounts. For example, suspicious business data may include user login IPs, and associated user accounts may include the login user accounts corresponding to those user login IPs.

[0081] If the suspicious business data is determined to be risky business data corresponding to a risky object, then risk control measures are implemented on the business element, such as rejecting the aforementioned business process and / or implementing risk control on the user account. If the suspicious business data is determined not to be risky business data corresponding to a risky object, then the aforementioned business element is allowed, such as permitting the aforementioned business process and / or maintaining the user account in a normal state.

[0082] Therefore, the embodiments in this specification can not only identify risky business data, but also perform risk control on the business processes and / or user accounts corresponding to the risky business data, thereby improving the security of network data.

[0083] Figure 2A flowchart illustrating another risk data identification method provided in one or more embodiments of this specification, such as... Figure 2 As shown, the method includes: Step S202: Obtain risk information, determine suspicious business data based on the risk information, and determine the suspected risk type of the suspicious business data; the risk information includes the object characteristic data of the risk object; the suspicious business data is associated with the object characteristic data; Step S204: Based on risk information, suspected risk types, and suspicious business data, create a risk identification prompt template corresponding to the suspicious business data; the risk identification prompt template is used to represent the target risk identification strategy for the suspicious business data and the identification reference information required for the target risk identification strategy. Step S206: Obtain identification reference information, and generate risk identification prompts corresponding to suspicious business data based on the identification reference information and the risk identification prompt template; Step S208: Using the risk identification model, identify whether the suspicious business data is the risky business data corresponding to the risk object based on the risk identification prompt words; Step S210: If the suspicious business data is risky business data, then risk control is carried out on the business elements associated with the suspicious business data. Step S212: If the suspicious business data is not risky business data, then the business elements associated with the suspicious business data are allowed to proceed.

[0084] about Figure 2 For a detailed explanation of the process, please refer to the above description, which will not be repeated here.

[0085] As described above, the target risk identification strategy is generated based on the initial risk identification strategy corresponding to the suspicious business data. The initial risk identification strategy is set by the expert agent for the suspected risk type. Based on this, the above process also includes: The risk identification results for determining whether suspicious business data is risky business data are reviewed, and the review results are obtained. Based on the review results, the initial risk identification strategy and / or expert agent will be adjusted.

[0086] In this embodiment, the risk identification results regarding whether suspicious business data constitutes risky business data can also be reviewed, for example, through manual review to obtain the review results. Based on the review results, the initial risk identification strategy can be adjusted, or the expert agent can be adjusted, or both the initial risk identification strategy and the expert agent can be adjusted.

[0087] For example, if the review result indicates that the risk identification result is inaccurate because it fails to verify whether the friend relationships of the users represented by the suspicious business data are consistent with those of the risky users, then the initial risk identification strategy can be adjusted based on this reason. The adjusted initial risk identification strategy adds a sub-strategy to verify whether the friend relationships of the users represented by the suspicious business data are consistent with those of the risky users. Alternatively, the expert agent can be adjusted so that it considers the consistency between the friend relationships of the users represented by the suspicious business data and those of the risky users when generating the initial risk identification strategy. In this example, the suspicious business data may include user IDs.

[0088] Therefore, this embodiment can also review the risk identification results of whether suspicious business data is risky business data, obtain the review results, and adjust the initial risk identification strategy and / or expert agent based on the review results, thereby improving the accuracy of the initial risk identification strategy and / or expert agent.

[0089] Figure 3 A flowchart illustrating yet another risk data identification method provided in one or more embodiments of this specification, such as... Figure 3 As shown, the method includes: Step S302: Obtain risk information, determine suspicious business data based on the risk information, and determine the suspected risk type of the suspicious business data; the risk information includes the object characteristic data of the risk object; the suspicious business data is associated with the object characteristic data; Step S304: Based on risk information, suspected risk types, and suspicious business data, create a risk identification prompt template corresponding to the suspicious business data; the risk identification prompt template is used to represent the target risk identification strategy for the suspicious business data and the identification reference information required for the target risk identification strategy; the target risk identification strategy is generated based on the initial risk identification strategy corresponding to the suspicious business data; the initial risk identification strategy is set by the expert agent for the suspected risk type; Step S306: Obtain identification reference information, and generate risk identification prompts corresponding to suspicious business data based on the identification reference information and the risk identification prompt template; Step S308: Using the risk identification model, identify whether the suspicious business data is the risky business data corresponding to the risk object based on the risk identification prompt words; Step S310: Review the risk identification results of whether the suspicious business data is risky business data, obtain the review results, and adjust the initial risk identification strategy and / or expert agent based on the review results.

[0090] about Figure 3 For a detailed explanation of the process, please refer to the above description, which will not be repeated here.

[0091] This specification provides one or more embodiments of a risk data identification mechanism that can acquire risk information, including object feature data of a risk object. From massive amounts of business data, it identifies suspicious business data associated with the object feature data and determines the suspected risk type of the suspicious business data. Then, based on the risk information, suspected risk type, and suspicious business data, it creates a risk identification prompt word template corresponding to the suspicious business data. It obtains identification reference information required for the target risk identification strategy from the risk identification prompt word template. Based on the identification reference information and the risk identification prompt word template, it generates a risk identification prompt word corresponding to the suspicious business data. Based on this risk identification prompt word, it identifies whether the suspicious business data is risky business data corresponding to the risk object. Since the risk identification prompt word can be generated based on currently identified suspicious business data, the suspected risk type of the suspicious business data, and the risk information, this risk identification prompt word is a personalized prompt word corresponding to the suspicious business data. Based on this prompt word, more accurate and targeted risk identification can be performed on suspicious business data, improving the accuracy of risk identification for suspicious business data.

[0092] Furthermore, the aforementioned risk data identification mechanism can acquire multimodal identification reference information and perform content extraction and verification on this information, achieving automated acquisition and organization of identification reference information. Additionally, this mechanism uses a risk identification model to determine whether suspicious business data corresponds to the risky business data of the risky object. The risk identification model can output a reasoning chain, making the identification results highly interpretable. Moreover, this risk data identification mechanism does not rely on a large number of existing manually reviewed cases and is applicable to risk data identification in various scenarios.

[0093] It should be noted that the various implementation methods of the risk data identification method provided above can be executed independently or combined to form new implementation methods as needed for actual execution or deployment. At the same time, each specific execution step in each implementation method can be executed independently or in combination as needed. Any one or more features in the specific execution steps of each implementation method can also be deleted as needed for actual execution or deployment. In addition, any specific execution step and / or any one or more features in one implementation method can be added to another implementation method to form a new implementation method. Alternatively, any specific execution step and / or any one or more features in one implementation method can be used to replace any specific execution step and / or any one or more features in another implementation method to form a new implementation method.

[0094] Figure 4A schematic diagram of the structure of a risk data identification device provided in one or more embodiments of this specification, such as... Figure 4 As shown, the device includes: Information determination unit 41 acquires risk information, determines suspicious business data based on the risk information, and determines the suspected risk type of the suspicious business data; the risk information includes object feature data of the risk object; the suspicious business data is associated with the object feature data; The template creation unit 42 creates a risk identification prompt word template corresponding to the suspicious business data based on the risk information, the suspected risk type, and the suspicious business data. The risk identification prompt word template is used to represent the target risk identification strategy for the suspicious business data and the identification reference information required for the target risk identification strategy. The prompt word generation unit 43 obtains the identification reference information and generates risk identification prompt words corresponding to the suspicious business data based on the identification reference information and the risk identification prompt word template. The risk identification unit 44 identifies, through the risk identification model, whether the suspicious business data is the risky business data corresponding to the risk object based on the risk identification prompt words.

[0095] Optionally, the information determination unit 41 determines the object category of the risk object, parses the business data according to the object category, and obtains the information represented by the business data based on the object category; if the correlation between the information represented by the business data based on the object category and the object feature data is greater than the correlation threshold, then the business data is determined as the suspicious business data.

[0096] Optionally, the information determination unit 41 determines the object category of the risk object and the business content represented by the suspicious business data; and selects the suspected risk type of the suspicious business data from various preset categories according to the object category and the business content.

[0097] Optionally, the template creation unit 42 obtains an initial risk identification strategy corresponding to the suspected risk type based on the suspected risk type; the initial risk identification strategy represents a risk identification strategy for the suspected risk type; the initial risk identification strategy is adjusted based on the risk information to obtain the target risk identification strategy; the identification reference information is determined based on the suspected business data and the target risk identification strategy; supplementary prompt information corresponding to the identification reference information is generated; and data fusion is performed based on the target risk identification strategy and the supplementary prompt information to obtain the risk identification prompt word template.

[0098] Optionally, the template creation unit 42 obtains various risk identification sub-strategies set by the expert agent for the suspected risk type; the risk identification sub-strategy has a corresponding risk identification dimension; the risk identification sub-strategy is used to identify the suspected risk type based on the risk identification dimension; the initial risk identification strategy is generated according to each of the risk identification sub-strategies; the initial risk identification strategy includes each of the risk identification sub-strategies.

[0099] Optionally, the template creation unit 42 adjusts the risk identification parameters required for the initial risk identification strategy based on the object feature data in the risk information, and the adjusted risk identification parameters match the object feature data; the target risk identification strategy includes the adjusted initial risk identification strategy.

[0100] Optionally, the template creation unit 42 compares the suspicious business data with the information missing from the risk identification parameters required by the target risk identification strategy, and determines the identification reference information based on the missing information.

[0101] Optionally, the identification reference information includes at least one sub-data, each of which has a corresponding data modality; the prompt word generation unit 43 extracts the data content of the sub-data according to the data modality of the sub-data; verifies the data content of the sub-data; the verification includes timeliness verification and / or authenticity verification; and fills the risk identification prompt word template based on the verified data content to obtain the risk identification prompt word.

[0102] Optionally, it also includes a risk control unit to determine the business elements associated with the suspicious business data; the business elements include business processes and / or user accounts; if the suspicious business data is the risky business data, then risk control is performed on the business elements; if the suspicious business data is not the risky business data, then the business elements are allowed to proceed.

[0103] Optionally, the target risk identification strategy is generated based on the initial risk identification strategy corresponding to the suspicious business data; the initial risk identification strategy is set by an expert agent for the suspected risk type; it also includes a review unit to review whether the suspicious business data is the risky business data and obtain a review result; and adjust the initial risk identification strategy and / or the expert agent according to the review result.

[0104] For ease of description, the above devices are described by dividing them into various modules or units based on their functions. Of course, when implementing one or more of these specifications, the functions of each module or unit can be implemented in the same or different software and / or hardware, or a module that performs the same function can be implemented by a combination of multiple sub-modules or sub-units, etc. The device embodiments described above are merely illustrative. For example, the division of units is only a logical functional division; in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed.

[0105] Since the apparatus embodiment corresponds to the method embodiment, the description is relatively simple. Figure 4 For a more detailed description of the apparatus, please refer to the description of embodiments of the risk data identification method, which will not be repeated here.

[0106] Corresponding to the risk data identification method described above, based on the same technical concept, one or more embodiments of this specification also provide a risk data identification device, which is used to perform the risk data identification method provided above. Figure 5 This is a schematic diagram of the structure of a risk data identification device provided for one or more embodiments of this specification.

[0107] like Figure 5 As shown, device 500 mainly consists of a communication interface 502, a user interface 504, a processor 506, and a data storage 508. These components are interconnected and communicate with each other via a system bus, network, or other connection mechanism 810. The communication interface 502 enables device 500 to communicate with other devices, access networks, and transmission networks via analog or digital modulation. For example, the communication interface 502 may include a chipset and antenna for wireless communication with a radio access network or access point. Furthermore, the communication interface 502 can be a wired interface such as Ethernet, Token Ring, or a USB port, or a wireless interface such as Wi-Fi, Bluetooth, Global Positioning System (GPS), or a wide-area wireless interface (e.g., WiMAX or LTE). Of course, the communication interface 502 can also support other forms of physical layer interfaces and standard or proprietary communication protocols. The communication interface 502 may also include multiple physical communication interfaces, such as Wi-Fi, Bluetooth, and wide-area wireless interfaces.

[0108] User interface 504 includes receiving user input and providing output to the user. Therefore, user interface 504 may include input components such as a keypad, keyboard, touch-sensitive or presence-sensitive panel, computer mouse, trackball, joystick, microphone, still camera, and video camera, and output components such as a display screen (which may be combined with a touch-sensitive panel), CRT, LCD, LED, display using DLP technology, printer, and other similar devices known or developed in the future. User interface 504 may also generate auditory output via speakers, speaker jacks, audio output ports, audio output devices, headphones, and other similar devices known or developed in the future. In some embodiments, user interface 504 may include software, circuitry, or other forms of logic capable of transmitting and receiving data from external user input / output devices. Additionally or alternatively, device 500 may support remote access from other devices via communication interface 502 or another physical interface (not shown). User interface 504 may be configured to receive user input, the position and movement of which may be indicated by indicators or cursors described herein. User interface 504 may also be configured as a display device for rendering or displaying text fragments.

[0109] Processor 506 may include one or more general-purpose processors and / or special-purpose processors. Data storage 508 may include one or more volatile and / or non-volatile storage components and may be integrated wholly or partially with processor 506. Data storage 508 may include removable and non-removable components.

[0110] Processor 506 is capable of executing program instructions 818 (e.g., compiled or uncompiled program logic and / or machine code) stored in data storage 508 to perform the various functions described herein. Data storage 508 may contain a non-transitory computer-readable medium on which program instructions are stored, which, when executed by device 500, enable device 500 to perform any methods, processes, or functions disclosed in this specification and / or the accompanying drawings. Execution of program instructions 818 by processor 506 may result in processor 506 using data 812. For example, program instructions 818 may include an operating system 822 (e.g., an operating system kernel, device drivers, and / or other modules) installed on device 500 and one or more application programs 820 (e.g., a browser, social application, or game application).

[0111] Similarly, data 812 may contain operating system data 816 and application data 814. Operating system data 816 is primarily accessible to the operating system 822, while application data 814 is primarily accessible to one or more applications 820. Application data 814 may reside in a file system visible or hidden from the user of device 500. Applications 820 may communicate with the operating system 822 through one or more application programming interfaces (APIs). These APIs facilitate applications 820 in reading and / or writing application data 814, transmitting or receiving information via communication interface 502, receiving or displaying information on user interface 504, etc. In some terms, application 820 may be simply referred to as an "app". Furthermore, application 820 may be downloaded to device 500 through one or more online app stores or app markets. However, applications may also be installed on device 500 in other ways, such as through a web browser or a physical interface on device 500 (e.g., a USB port).

[0112] In one specific embodiment, risk data identification includes a memory and one or more programs, wherein one or more programs are stored in the memory, and one or more programs may include one or more modules, and each module may include a series of computer-executable instructions for the risk data identification device, and is configured to be executed by one or more processors. The one or more programs include computer-executable instructions for performing the following: Obtain risk information, determine suspicious business data based on the risk information, and determine the suspected risk type of the suspicious business data; the risk information includes object feature data of the risk object; the suspicious business data is associated with the object feature data; Based on the risk information, the suspected risk type, and the suspicious business data, a risk identification prompt word template corresponding to the suspicious business data is created; the risk identification prompt word template is used to represent the target risk identification strategy for the suspicious business data and the identification reference information required for the target risk identification strategy. Obtain the identification reference information, and generate risk identification prompts corresponding to the suspicious business data based on the identification reference information and the risk identification prompt template; The risk identification model identifies whether the suspicious business data is the risky business data corresponding to the risk object based on the risk identification prompt words.

[0113] Since the device embodiment corresponds to the method embodiment, the description is relatively simple. For more information about the device, please refer to the description of the embodiment of the risk data identification method, which will not be repeated here.

[0114] Corresponding to the risk data identification method described above, and based on the same technical concept, one or more embodiments of this specification also provide a computer-readable storage medium.

[0115] The computer-readable storage medium provided in this embodiment is used to store computer-executable instructions, which, when executed, implement the following process: Obtain risk information, determine suspicious business data based on the risk information, and determine the suspected risk type of the suspicious business data; the risk information includes object feature data of the risk object; the suspicious business data is associated with the object feature data; Based on the risk information, the suspected risk type, and the suspicious business data, a risk identification prompt word template corresponding to the suspicious business data is created; the risk identification prompt word template is used to represent the target risk identification strategy for the suspicious business data and the identification reference information required for the target risk identification strategy. Obtain the identification reference information, and generate risk identification prompts corresponding to the suspicious business data based on the identification reference information and the risk identification prompt template; The risk identification model identifies whether the suspicious business data is the risky business data corresponding to the risk object based on the risk identification prompt words.

[0116] It should be noted that the embodiments of a computer-readable storage medium described in this specification and the embodiments of a risk data identification method described in this specification are based on the same inventive concept. Therefore, the specific implementation of this embodiment can be referred to the implementation of the corresponding method described above, and the repeated parts will not be described again.

[0117] Corresponding to the other risk data identification method described above, based on the same technical concept, one or more embodiments of this specification also provide another computer program product.

[0118] In some embodiments, a computer program product is provided, including a computer program that, when executed by a processor, performs the following steps: Obtain risk information, determine suspicious business data based on the risk information, and determine the suspected risk type of the suspicious business data; the risk information includes object feature data of the risk object; the suspicious business data is associated with the object feature data; Based on the risk information, the suspected risk type, and the suspicious business data, a risk identification prompt word template corresponding to the suspicious business data is created; the risk identification prompt word template is used to represent the target risk identification strategy for the suspicious business data and the identification reference information required for the target risk identification strategy. Obtain the identification reference information, and generate risk identification prompts corresponding to the suspicious business data based on the identification reference information and the risk identification prompt template; The risk identification model identifies whether the suspicious business data is the risky business data corresponding to the risk object based on the risk identification prompt words.

[0119] It should be noted that the embodiment of a computer program product in this specification and the embodiment of a risk data identification method in this specification are based on the same inventive concept. Therefore, the specific implementation of this embodiment can be referred to the implementation of the corresponding method described above, and the repeated parts will not be described again.

[0120] The various embodiments in this specification are described in a progressive manner. The same or similar parts between the various embodiments can be referred to each other. Each embodiment focuses on describing the differences from other embodiments. For example, the device embodiment, equipment embodiment and computer-readable storage medium embodiment are all similar to the method embodiment, so the description is relatively simple. When reading the relevant content of the device embodiment, equipment embodiment and computer-readable storage medium embodiment, please refer to the description of the method embodiment.

[0121] While one or more embodiments of this specification provide method steps as described in the embodiments or flowcharts, it is understood that the order of steps listed in the embodiments or flowcharts is merely one possible execution order among many steps, and does not represent the only execution order. Therefore, when the claims involve method steps, any changes or adjustments to the order of such steps, or the parallelism between steps, are also within the scope of protection of the claims. This specification uses specific terms to describe embodiments of this specification. For example, "an embodiment," "one embodiment," and / or "some embodiments" refer to a particular feature, structure, or characteristic related to at least one embodiment of this specification. Therefore, it should be emphasized and noted that "an embodiment," "one embodiment," or "an alternative embodiment" mentioned twice or more in different locations in this specification do not necessarily refer to the same embodiment. Furthermore, without contradiction, those skilled in the art can combine and integrate the different embodiments or examples described in this specification, as well as the features of different embodiments or examples.

[0122] The foregoing has described specific embodiments of this specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims may be performed in a different order than that shown in the embodiments and may still achieve the desired result. Furthermore, the processes depicted in the drawings do not necessarily require the specific or sequential order shown to achieve the desired result. In some embodiments, multitasking and parallel processing are possible or may be advantageous.

[0123] In the 1930s, improvements to a technology could be clearly distinguished as either hardware improvements (e.g., improvements to the circuit structure of diodes, transistors, switches, etc.) or software improvements (improvements to the methodology). However, with technological advancements, many improvements to the methodology today can be considered direct improvements to the hardware circuit structure. Designers almost always obtain the corresponding hardware circuit structure by programming the improved methodology into the hardware circuit. Therefore, it cannot be said that an improvement to the methodology cannot be implemented using hardware physical modules. For example, a Programmable Logic Device (PLD) (such as a Field Programmable Gate Array (FPGA)) is such an integrated circuit whose logic function is determined by the user programming the device. Designers can program and "integrate" a digital system onto a PLD themselves, without needing chip manufacturers to design and manufacture dedicated integrated circuit chips. Furthermore, nowadays, instead of manually manufacturing integrated circuit chips, this programming is mostly implemented using "logic compiler" software. Similar to the software compiler used in program development, the original code before compilation must also be written in a specific programming language, called a Hardware Description Language (HDL). There are many HDLs, such as ABEL (Advanced Boolean Expression Language), AHDL (Altera Hardware Description Language), Confluence, CUPL (Cornell University Programming Language), HDCal, JHDL (Java Hardware Description Language), Lava, Lola, MyHDL, PALASM, and RHDL (Ruby Hardware Description Language). Currently, the most commonly used are VHDL (Very-High-Speed ​​Integrated Circuit Hardware Description Language) and Verilog. Those skilled in the art should also understand that by simply performing some logic programming on the method flow using one of these hardware description languages ​​and programming it into an integrated circuit, the hardware circuit implementing the logical method flow can be easily obtained.

[0124] The controller can be implemented in any suitable manner. For example, it can take the form of a microprocessor or processor and a computer-readable medium storing computer-readable program code (e.g., software or firmware) executable by the (micro)processor, logic gates, switches, application-specific integrated circuits (ASICs), programmable logic controllers, and embedded microcontrollers. Examples of controllers include, but are not limited to, the following microcontrollers: ARC 625D, Atmel AT91SAM, Microchip PIC18F26K20, and Silicon Labs C8051F320. A memory controller can also be implemented as part of the control logic of the memory. Those skilled in the art will also recognize that, in addition to implementing the controller in purely computer-readable program code form, the same functionality can be achieved by logically programming the method steps to make the controller take the form of logic gates, switches, application-specific integrated circuits, programmable logic controllers, and embedded microcontrollers. Therefore, such a controller can be considered a hardware component, and the means included therein for implementing various functions can also be considered as structures within the hardware component. Alternatively, the means for implementing various functions can be considered as both software modules implementing the method and structures within the hardware component.

[0125] The systems, devices, modules, or units described in the above embodiments can be implemented using a graphics processing unit (GPU) combined with large models and / or intelligent agents. The GPU provides parallel computing acceleration and hardware support for the large models and / or intelligent agents to complete the relevant processing and operation of this embodiment.

[0126] The systems, devices, modules, or units described in the above embodiments can be implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer. Specifically, a computer can be, for example, a personal computer, laptop computer, cellular phone, camera phone, smartphone, personal digital assistant, media player, navigation device, email device, game console, tablet computer, wearable device, or any combination of these devices.

[0127] For ease of description, the above apparatus is described by dividing it into various functional units. Of course, when implementing the embodiments of this specification, the functions of each unit can be implemented in one or more software and / or hardware.

[0128] Those skilled in the art will understand that one or more embodiments of this specification can be provided as a method, system, or computer program product. Therefore, one or more embodiments of this specification may take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this specification may take the form of a computer program product embodied on one or more computer-readable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0129] This specification is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this specification. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0130] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0131] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0132] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.

[0133] Memory may include non-persistent storage in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of computer-readable media.

[0134] Computer-readable media include both permanent and non-permanent, removable and non-removable media that can store information using any method or technology. Information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer-readable storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, disk storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.

[0135] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitation, an element defined by the phrase "comprising at least one…" does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0136] It should also be noted that the terms "one," "an," and "the" do not specifically refer to the singular; they can also include the plural. Ordinal numbers such as "first," "second," etc., do not necessarily indicate order; often they are used to distinguish objects. For example, "first server" and "second server" usually refer to two servers. To differentiate between these two servers, they are described as "first server" and "second server." Of course, sometimes these two servers may be the same server. Unless explicitly stated, "receiving and sending data" does not necessarily mean direct receipt and transmission; it can be indirect. For example, A receiving data sent by B can be understood as A directly receiving data sent by B, or it can be understood as A indirectly receiving data sent by B through other entities such as C. Similarly, B sending data to A can be understood as B sending data directly to A, or it can be understood as B indirectly sending data to A through other entities such as C. Here, C can be one entity, or it can be two or more entities.

[0137] Unless explicitly stated otherwise, the relationships between structures can be direct or indirect. For example, when describing "A is connected to B," unless it is explicitly stated that A and B are directly connected, it should be understood that A can be directly connected to B or indirectly connected to B. Similarly, when describing "A is above B," unless it is explicitly stated that A is directly above B (AB is adjacent and A is above B), it should be understood that A can be directly above B or indirectly above B (AB is separated by other elements, and A is above B). And so on.

[0138] One or more embodiments of this specification can be described in the general context of computer-executable instructions, such as program modules, that are executed by a computer. Generally, program modules include routines, programs, objects, components, data structures, etc., that perform a particular task or implement a particular abstract data type. One or more embodiments of this specification can also be practiced in distributed computing environments where tasks are performed by remote processing devices connected via a communication network. In distributed computing environments, program modules can reside in local and remote computer storage media, including storage devices.

[0139] The above description is merely an embodiment of this document and is not intended to limit the scope of this document. Various modifications and variations can be made to this document by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this document should be included within the scope of the claims of this document.

Claims

1. A risk data identification method, comprising: Obtain risk information, identify suspicious business data based on the risk information, and determine the suspected risk type of the suspicious business data; The risk information includes object characteristic data of the risk object; the suspicious business data is associated with the object characteristic data; Based on the risk information, the suspected risk type, and the suspicious business data, create a risk identification prompt word template corresponding to the suspicious business data; The risk identification prompt template is used to represent the target risk identification strategy for the suspicious business data and the identification reference information required for the target risk identification strategy; Obtain the identification reference information, and generate risk identification prompts corresponding to the suspicious business data based on the identification reference information and the risk identification prompt template; The risk identification model identifies whether the suspicious business data is the risky business data corresponding to the risk object based on the risk identification prompt words.

2. The method according to claim 1, wherein determining suspicious business data based on the risk information includes: The object category of the risk object is determined, and the business data is parsed according to the object category to obtain the information represented by the business data based on the object category; If the degree of correlation between the information represented by the object category and the object feature data is greater than the correlation threshold, then the business data is identified as the suspicious business data.

3. The method according to claim 1, wherein determining the suspected risk type of the suspicious business data includes: Determine the object category of the risk object, and determine the business content represented by the suspicious business data; Based on the object category and the business content, select the suspected risk type of the suspicious business data from each preset category.

4. The method according to claim 1, wherein creating a risk identification prompt word template corresponding to the suspicious business data based on the risk information, the suspected risk type, and the suspicious business data includes: Based on the suspected risk type, obtain the initial risk identification strategy corresponding to the suspicious business data; The initial risk identification strategy is used to represent the risk identification strategy for the suspected risk type; Based on the risk information, the initial risk identification strategy is adjusted to obtain the target risk identification strategy. Based on the suspicious business data and the target risk identification strategy, the identification reference information is determined. Supplementary prompt information corresponding to the identification reference information is generated, and data fusion is performed based on the target risk identification strategy and the supplementary prompt information to obtain the risk identification prompt word template.

5. The method according to claim 4, wherein obtaining the initial risk identification strategy corresponding to the suspicious business data based on the suspected risk type includes: Obtain the various risk identification sub-strategies set by the expert intelligent agent for the suspected risk type; The risk identification sub-strategy has a corresponding risk identification dimension; The risk identification sub-strategy is used to identify the suspected risk type based on the risk identification dimension; The initial risk identification strategy is generated based on each of the aforementioned risk identification sub-strategies; The initial risk identification strategy includes each of the aforementioned risk identification sub-strategies.

6. The method according to claim 4, wherein adjusting the initial risk identification strategy based on the risk information to obtain the target risk identification strategy comprises: Based on the object feature data in the risk information, the risk identification parameters required for the initial risk identification strategy are adjusted, and the adjusted risk identification parameters match the object feature data; the target risk identification strategy includes the adjusted initial risk identification strategy.

7. The method according to claim 4, wherein determining the identification reference information based on the suspicious business data and the target risk identification strategy includes: The identification reference information is determined based on the missing information in the suspicious business data compared to the risk identification parameters required by the target risk identification strategy.

8. The method according to claim 1, wherein the identification reference information includes at least one sub-data, and each sub-data has a corresponding data modality; The step of generating risk identification prompts corresponding to the suspicious business data based on the identification reference information and the risk identification prompt template includes: Based on the data modality of the sub-data, extract the data content of the sub-data; The data content of the sub-data is verified; the verification includes timeliness verification and / or authenticity verification. The risk identification prompt word template is filled with the verified data content to obtain the risk identification prompt word.

9. The method according to claim 1, further comprising: Identify the business elements associated with the suspicious business data; the business elements include business processes and / or user accounts. If the suspicious business data is the risky business data, then risk control shall be applied to the business element. If the suspicious business data is not the risky business data, then the business element is allowed to proceed.

10. The method according to claim 1, wherein the target risk identification strategy is generated based on the initial risk identification strategy corresponding to the suspicious business data; The initial risk identification strategy is set by an expert agent for the suspected risk type; Also includes: The risk identification results of whether the suspicious business data is the risky business data are reviewed to obtain the review results; Based on the review results, the initial risk identification strategy and / or the expert agent are adjusted.

11. A risk data identification device, comprising: The information determination unit acquires risk information, determines suspicious business data based on the risk information, and determines the suspected risk type of the suspicious business data. The risk information includes object characteristic data of the risk object; the suspicious business data is associated with the object characteristic data; The template creation unit creates a risk identification prompt word template corresponding to the suspicious business data based on the risk information, the suspected risk type, and the suspicious business data. The risk identification prompt template is used to represent the target risk identification strategy for the suspicious business data and the identification reference information required for the target risk identification strategy; The prompt word generation unit obtains the identification reference information and generates risk identification prompt words corresponding to the suspicious business data based on the identification reference information and the risk identification prompt word template. The risk identification unit, through a risk identification model, identifies whether the suspicious business data is the risky business data corresponding to the risk object based on the risk identification prompt words.

12. A risk data identification device, comprising: processor; And, a memory configured to store computer-executable instructions, which, when executed, cause the processor to: Obtain risk information, determine suspicious business data based on the risk information, and determine the suspected risk type of the suspicious business data; the risk information includes object feature data of the risk object; the suspicious business data is associated with the object feature data; Based on the risk information, the suspected risk type, and the suspicious business data, create a risk identification prompt word template corresponding to the suspicious business data; The risk identification prompt template is used to represent the target risk identification strategy for the suspicious business data and the identification reference information required for the target risk identification strategy; Obtain the identification reference information, and generate risk identification prompts corresponding to the suspicious business data based on the identification reference information and the risk identification prompt template; The risk identification model identifies whether the suspicious business data is the risky business data corresponding to the risk object based on the risk identification prompt words.