Data anomaly processing method and apparatus
By structurally transforming and detecting anomalies in user service data, and combining this with rule mapping and compilation from a rule engine, the problem of handling user service data anomalies has been solved, achieving efficient and personalized data anomaly management.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- QIANTANG CREDIT INFORMATION CO LTD
- Filing Date
- 2026-04-13
- Publication Date
- 2026-07-21
AI Technical Summary
With the diversified development of internet services, user service data management faces pressure in detecting and handling data anomalies, and existing technologies are insufficient to effectively identify and process abnormal service data.
After submitting an access authorization request through the data access application and performing a structured transformation, the data detection component is used to detect service data anomalies, generate abnormal service data and parameters, and combine them with the rule engine to perform rule mapping and compilation, generate anomaly handling rules, and perform matching and interaction.
It enables accurate identification and personalized processing of user service data, improves the accuracy and efficiency of anomaly handling, and ensures data security and comprehensive management.
Smart Images

Figure CN122432900A_ABST
Abstract
Description
Technical Field
[0001] This document relates to the field of data processing technology, and in particular to a data anomaly handling method and apparatus. Background Technology
[0002] With the continuous development of internet technology, online services provided by the internet have emerged. Online services provide a convenient means of providing services to users. As users use online services more frequently, user data on various online services is also accumulating. In this process, the diversification of user needs for online services has also put pressure and challenges on online service providers in managing user data. Summary of the Invention
[0003] This specification provides one or more embodiments of a data anomaly handling method, comprising: performing a structured transformation on user service data based on an access authorization request submitted by a user through a data access application to obtain structured data; inputting the structured data into a data detection component for service data anomaly detection to obtain abnormal service data and data anomaly parameters, and synchronizing them to a rule engine; using the rule engine to perform rule mapping and rule compilation for data anomaly handling based on the abnormal service data and the data anomaly parameters to obtain anomaly handling rules; performing anomaly handling matching on the structured data based on the anomaly handling rules, and performing data anomaly handling interaction based on the matching results.
[0004] This specification provides one or more embodiments of a data anomaly handling apparatus, comprising: a data conversion module configured to perform a structured conversion on user service data based on an access authorization request submitted by a user through a data access application to obtain structured data; a data detection module configured to input the structured data into a data detection component for service data anomaly detection, obtain abnormal service data and data anomaly parameters, and synchronize them to a rule engine; a rule processing module configured to perform rule mapping and rule compilation for data anomaly handling based on the abnormal service data and the data anomaly parameters through the rule engine to obtain anomaly handling rules; and an anomaly handling module configured to perform anomaly handling matching on the structured data based on the anomaly handling rules, and perform data anomaly handling interaction based on the matching results.
[0005] This specification provides one or more embodiments of a data anomaly processing device, including: a processor; and a memory configured to store computer-executable instructions, which, when executed, cause the processor to: perform a structured transformation on user service data based on an access authorization request submitted by a user through a data access application to obtain structured data; input the structured data into a data detection component for service data anomaly detection, obtaining abnormal service data and data anomaly parameters, and synchronizing them to a rule engine; perform rule mapping and rule compilation for data anomaly processing based on the abnormal service data and the data anomaly parameters through the rule engine to obtain anomaly processing rules; perform anomaly processing matching on the structured data based on the anomaly processing rules, and perform data anomaly processing interaction based on the matching results.
[0006] This specification provides one or more embodiments of a computer-readable storage medium for storing computer-executable instructions, which, when executed, perform the following steps: Based on an access authorization request submitted by a user through a data access application, perform a structured transformation on the user's service data to obtain structured data. Input the structured data into a data detection component for service data anomaly detection, obtain abnormal service data and data anomaly parameters, and synchronize them to a rule engine. Through the rule engine, perform rule mapping and rule compilation based on the abnormal service data and the data anomaly parameters to obtain anomaly handling rules. Perform anomaly handling matching on the structured data based on the anomaly handling rules, and perform data anomaly handling interaction based on the matching results. Attached Figure Description
[0007] To more clearly illustrate the technical solutions in one or more embodiments of this specification or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this specification. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort. Figure 1 A schematic diagram illustrating the implementation environment of a data anomaly handling method provided in one or more embodiments of this specification; Figure 2 A flowchart illustrating a data anomaly handling method provided in one or more embodiments of this specification; Figure 3 A flowchart illustrating a data anomaly handling method for an accounting scenario provided in one or more embodiments of this specification; Figure 4 A schematic diagram of an embodiment of a data anomaly processing device provided in one or more embodiments of this specification; Figure 5 This is a schematic diagram of the structure of a data anomaly processing device provided for one or more embodiments of this specification. Detailed Implementation
[0008] To enable those skilled in the art to better understand the technical solutions in one or more embodiments of this specification, the technical solutions in one or more embodiments of this specification will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this specification, and not all of the embodiments. Based on one or more embodiments of this specification, all other embodiments obtained by those skilled in the art without creative effort should fall within the protection scope of this document.
[0009] The data anomaly handling methods provided in one or more embodiments of this specification are applicable to the implementation environment of data anomaly handling. (Refer to...) Figure 1 The implementation environment includes at least: Server 101; in addition, it may also include data access application 102; The server 101 can be deployed with a data detection component 101-1 and a rule engine 101-2. The server 101 is used to perform structured transformation on the user's service data to obtain structured data. The data detection component 101-1 performs service data anomaly detection on the structured data and synchronizes the obtained abnormal service data and data anomaly parameters to the rule engine 101-2. The rule engine 101-2 combines the abnormal service data and data anomaly parameters to perform rule mapping and rule compilation for data anomaly handling to obtain anomaly handling rules. According to the anomaly handling rules, anomaly handling matching is performed on the structured data, and data anomaly handling interaction is performed based on the matching results. Data access application 102 can be used by users to submit access authorization requests and send the access authorization requests to the server. In this implementation environment, server 101 performs structured transformation on user service data based on access authorization requests submitted by data access application 102 to obtain structured data. The data detection component 101-1 performs service data anomaly detection on the structured data and synchronizes the obtained abnormal service data and data anomaly parameters to rule engine 101-2. Rule engine 101-2 combines the abnormal service data and data anomaly parameters to perform rule mapping and rule compilation for data anomaly handling, thereby obtaining anomaly handling rules. Anomaly handling matching is performed on the structured data according to the anomaly handling rules, and data anomaly handling interaction is performed based on the matching results, thereby realizing data anomaly handling for user service data.
[0010] One or more embodiments of a data anomaly handling method provided in this specification are as follows: Reference Figure 2 The data anomaly handling method provided in this embodiment can be applied to the server or the client, and specifically includes steps S202 to S208.
[0011] Step S202: Based on the access authorization request submitted by the user through the data access application, perform a structured transformation on the user's service data to obtain structured data.
[0012] The data access application described in this embodiment refers to an application program or subroutine that performs data access. The subroutine can be a mini-program. The data access application can be an application program or subroutine in any field. Specifically, the data access application can be an exception handling application that performs data exception handling for users. The access authorization request can be a request from the user to authorize access to service data.
[0013] The service data may include personal consumption service data, household billing data, salary data, and / or resource return data. For example, personal consumption service data includes user service or consumption data in e-commerce systems, catering systems, tourism systems, transportation systems, and / or resource management systems; household billing data includes user education expenditure data in the dimension of children's education and / or payment expenditure data in the dimension of public fees; and resource return data includes user return data for borrowed resources. Optionally, the service data includes user billing data in the billing system, which may specifically include user resource expenditure data and / or resource inflow data in the billing system, or user resource expenditure data and / or resource inflow data in the user's personal account or family group account in the billing system, such as user resource expenditure data and resource inflow data in the resource accumulation system.
[0014] In practice, based on the access authorization request submitted by the user through the data access application, the user's service data is transformed into structured data. Specifically, the user's service data can be obtained based on the access authorization request submitted by the user through the data access application, and then the user's service data can be transformed into structured data.
[0015] In the specific execution process, in order to improve the comprehensiveness and completeness of subsequent service data anomaly detection and ensure the data security of user service data, in an optional implementation method provided in this embodiment, the user's service data includes the user's multi-source heterogeneous accounting data obtained from the data source system by calling the multi-source data interface and / or the accounting-related materials uploaded by the user for the multi-source heterogeneous accounting data; the specific service data can be obtained in the following ways: By calling the multi-source data interface, the user's multi-source heterogeneous accounting data is obtained from the data source system; Obtain accounting-related materials uploaded by users for multi-source heterogeneous accounting data; Optional, the accounting-related materials include: user resource data for resource services, user service data for medical services, and / or user payment records for payment services.
[0016] Among them, multi-source data interfaces can be data acquisition interfaces corresponding to data source systems; data source systems may include e-commerce systems, catering systems, tourism systems, transportation systems, resource management systems, education systems, public payment systems, medical systems and / or resource systems; multi-source heterogeneous accounting data refers to accounting data with multiple dimensions and / or multiple different data structures. Specifically, multi-source heterogeneous accounting data may include personal consumption data obtained from e-commerce systems, catering systems, tourism systems, transportation systems and / or resource management systems, education expenditure data obtained from education systems, payment expenditure data obtained from public payment systems and / or resource borrowing data and / or resource return data obtained from resource systems.
[0017] Furthermore, the data source system can also be an accounting system, meaning it can retrieve user transaction data, or it can retrieve user resource expenditure data and / or resource inflow data across multiple dimensions, such as expenditure amounts and / or resource inflow amounts. User service data in medical services may include medical visit data or medical expenditure data; user payment records in payment services may include payment expenditure data; and user resource data in resource services may include resource borrowing data and / or resource return data. Accounting-related materials can be accounting-related images and / or accounting-related documents.
[0018] Specifically, after obtaining the user's multi-source heterogeneous accounting data from the data source system, the user may have supporting materials for the multi-source heterogeneous accounting data. Therefore, the accounting-related materials uploaded by the user for the multi-source heterogeneous accounting data can be obtained. The accounting-related materials can be used to prove the authenticity and rationality of the multi-source heterogeneous accounting data.
[0019] In addition, service data can also be obtained through the following methods: By calling the multi-source data interface, the user's multi-source heterogeneous service data is obtained from the data source system; Obtain data association materials related to user uploads of data from multi-source heterogeneous services; Optionally, multi-source heterogeneous service data includes: user resource data in resource services, user service data in medical services, and / or user payment records in payment services.
[0020] Among them, data-related materials may include supporting materials for proving the authenticity of multi-source heterogeneous service data, such as medical treatment materials for proving the authenticity of user service data in medical services, and payment vouchers for proving the authenticity of user payment records in payment services.
[0021] Based on this, in order to improve the organization of user service data and facilitate subsequent anomaly detection, the user service data can be transformed into structured data. In one optional implementation of this embodiment, the following operations are performed during the process of transforming the user service data into structured data: Multi-source heterogeneous accounting data is transformed into structured data to obtain multi-source structured data; The accounting data is identified and extracted from the accounting materials to obtain related accounting data, and then the related accounting data is mapped with multi-source structured data to obtain structured accounting data.
[0022] Specifically, in the process of transforming multi-source heterogeneous accounting data into multi-source structured data, heterogeneous accounting values can be extracted from the multi-source heterogeneous accounting data according to the multi-source heterogeneous accounting fields and populated into the multi-source heterogeneous accounting fields to obtain multi-source structured data; in the process of identifying and extracting accounting data from accounting-related materials to obtain related accounting data, the accounting-related materials can be classified, and accounting data can be identified and extracted from the accounting-related materials according to the identification method corresponding to the material category to obtain related accounting data; in the process of mapping related accounting data with multi-source structured data, target multi-source structured data can be matched in the multi-source structured data based on the related accounting data, and the related accounting data and target multi-source structured data can be fused to obtain structured accounting data.
[0023] For example, multi-source structured data includes structured salary data, structured education expenditure data, structured medical diagnosis data, and structured payment data. Based on related accounting data, target multi-source structured data is matched in the multi-source structured data, and the related accounting data and target multi-source structured data are fused to obtain structured accounting data.
[0024] The above-described implementation method of transforming user service data into structured data can also be replaced by transforming multi-source heterogeneous data into structured service data; performing data identification and extraction on data-related materials to obtain related data; and mapping the related data with structured service data to obtain structured data.
[0025] Step S204: Input the structured data into the data detection component to perform service data anomaly detection, obtain abnormal service data and data anomaly parameters, and synchronize them to the rule engine.
[0026] The above-mentioned process involves transforming the user's service data into structured data based on the access authorization request submitted by the user through the data access application. In this step, the structured data is input into the data detection component to detect service data anomalies, obtain abnormal service data and data anomaly parameters, and synchronize them to the rule engine. This service data anomaly detection helps users accurately identify abnormal service data, which helps to ensure the security of users' service data.
[0027] The abnormal service data described in this embodiment can be service data or service tags indicating abnormal situations. Optionally, in addition to the user's accounting data in the billing system, the abnormal service data may include service data or service tags where the resource flow value exceeds the range of resource flow parameters recorded in the accounting processing agreement. For example, abnormal service data may include service data or service tags where the expenditure amount for each period exceeds the planned limit recorded in the expenditure management agreement, service data or service tags where the resource inflow amount for each period does not reach the planned resource accumulation amount recorded in the resource accumulation agreement, and / or service data or service tags where the actual repayment amount for each period does not reach the amount due recorded in the repayment agreement. The period can be a time period, such as a month, week, and / or day.
[0028] In addition, abnormal service data may also include service data or service tags whose resource flow values are not within the range of resource flow parameters recorded in the billing agreement; for example, if a user's medical expenditure amount in the medical service service data exceeds the planned limit recorded in the billing agreement, it represents abnormal service data with a disease abnormal tag, and the data abnormal parameter is the amount of medical expenditure in the user's medical service service data; as another example, if a user's transportation expenditure amount in the transportation service or transportation system service data exceeds the planned limit recorded in the expenditure management agreement, it represents abnormal service data with a travel abnormal tag or a large expenditure abnormal tag, and the data abnormal parameters include the transportation duration, transportation amount, and / or transportation location in the transportation service or transportation system service data.
[0029] The data detection component refers to a detection component for detecting service data anomalies; optionally, the data detection component includes a pre-trained data anomaly detection model; in one optional implementation of this embodiment, service data anomaly detection is implemented in the following way: The structured data is aligned temporally, and features are extracted from the temporal structured data to obtain a temporal feature set; The temporal feature set is input into a multi-label classification network for multi-label classification processing to obtain multiple abnormal service data and the data anomaly parameters of each abnormal service data.
[0030] The time series feature set can be a collection of one or more time series features, and the time series feature set can be a sequence of time series features; the structured data can be structured time series data, such as a user's account transaction records or disease recovery progress within a time period. In addition, structured time series data can also include other types of time series data.
[0031] Specifically, temporal alignment of structured data can be achieved by sorting the structured data according to time order to obtain temporal structured data; or, after sorting the structured data according to time order, temporal data completion can be performed on the initial temporal structured data obtained by sorting to obtain temporal structured data; in the process of inputting the temporal feature set into a multi-label classification network for multi-label classification processing to obtain multiple abnormal service data and data anomaly parameters of each abnormal service data, the temporal feature set can be input into the temporal convolution module in the multi-label classification network for temporal feature encoding, and the obtained encoded feature set can be input into the multi-label classification prediction module to predict the user probability of multiple abnormal service labels, to obtain the predicted probability of users for multiple abnormal service labels, and the abnormal service labels with predicted probabilities greater than the probability threshold among the multiple abnormal service labels can be regarded as multiple abnormal service data, and the predicted probabilities can be used as data anomaly parameters of multiple abnormal service data; in the process of extracting features from temporal structured data to obtain a temporal feature set, the temporal structured data can be input into a feature extraction model for feature extraction to obtain a temporal feature set.
[0032] For example, the feature extraction model is LSTM (Long Short-Term Memory) - Autoencoder.
[0033] In the specific execution process, the feature extraction model can be obtained by training the model to be trained based on temporal structured data samples. The model training can be unsupervised training. Specifically, the temporal structured data of the current time point in the temporal structured data samples is input into the feature extraction network of the model to be trained. Based on the temporal features of the previous time point, the temporal structured data is extracted to obtain the temporal features of the current time point. The temporal features of the current time point are input into the decoder for decoding processing to obtain the predicted temporal data of the current time point. The loss is calculated based on the temporal structured data of the current time point and the predicted temporal data. Based on the calculated loss, the parameters of the model to be trained are adjusted to obtain the feature extraction model.
[0034] For example, the loss function of the model to be trained is:
[0035]
[0036] in, Represents the temporal characteristics of the previous time point. The temporal characteristics representing the current point in time, Time-series structured data representing the current point in time. This represents the predicted time series data at the current time point, where T represents the t-th time point. This represents a loss.
[0037] Furthermore, in an optional implementation of this embodiment, during the process of temporal alignment of structured data and feature extraction of temporal structured data to obtain a temporal feature set, the following operations are performed: Temporal features are obtained by extracting temporal features from structured service data within structured data. Feature standardization is performed on associated data in structured data to obtain associated data features, and cross-modal feature fusion is performed between time series features and associated data features to obtain a time series feature set.
[0038] Among them, structured service data can be structured expenditure data and / or structured resource inflow data, such as structured medical expenditure data and structured payment data; related data can be user attribute data, such as the user's occupation and / or the type of disease the user suffers from.
[0039] Specifically, in the process of standardizing the features of related data in structured data to obtain related data features, the related data can be normalized to a preset numerical range to obtain related data features; alternatively, the following operations can be performed: calculate the user's resource inflow decline ratio based on the user's resource inflow data as the related data feature of the resource inflow data; calculate the user's medical expenditure ratio based on the user's medical expenditure data as the related data feature of the medical expenditure data; calculate the user's payment continuity index based on the user's public payment data as the related data feature of the public payment data; and / or calculate the user's remaining resource data based on the user's resource inflow and resource outflow data as the related data feature.
[0040] In the process of calculating the percentage decrease in user resource inflow based on user resource inflow data, the percentage decrease in resource inflow can be calculated based on user resource inflow data and average resource inflow data. For example, the percentage decrease in resource inflows is:
[0041] in, The proportion of the decrease in the inflow of resources Represents average resource inflow data. This represents data on resource inflows.
[0042] In the process of calculating the proportion of a user's medical expenditure based on the user's medical expenditure data, the proportion of medical expenditure can be calculated based on the user's total medical expenditure data and resource inflow data. For example, the percentage of medical expenditure is:
[0043] in, Represents the proportion of medical expenditure. This represents the user's total medical expenditure data.
[0044] In the process of calculating the user's payment continuity index as public payment data based on the user's public payment data, the payment continuity index can be calculated based on the number of time periods during which the user has not made continuous payments and the total number of time periods. For example, the continuous payment indicator is:
[0045] in, Represents continuous contribution indicators, This represents the number of periods during which a user has not made continuous payments. This represents the total number of time periods; a time period can be a payment period, such as a month or a week.
[0046] It should be noted that the above-mentioned operation of using the structured data input data detection component to perform service data anomaly detection, obtain abnormal service data and data anomaly parameters, and synchronize them to the rule engine can be replaced by using the structured data input data detection component to perform service data anomaly detection, obtain abnormal service data and / or data anomaly parameters, and synchronize them to the rule engine; or it can be replaced by using the structured data input data detection component to perform service data anomaly detection, obtain abnormal service data and / or data anomaly parameters, and combining it with other processing steps provided in this embodiment to form a new implementation method.
[0047] Step S206: Obtain exception handling rules by performing rule mapping and rule compilation for data exception handling based on the exception service data and the data exception parameters through the rule engine.
[0048] The above-mentioned structured data input data detection component performs service data anomaly detection, obtains abnormal service data and data anomaly parameters, and synchronizes them to the rule engine. In this step, the rule engine combines the abnormal service data and data anomaly parameters to perform rule mapping and rule compilation for data anomaly handling, thereby obtaining anomaly handling rules. This enables the generation of personalized anomaly handling rules for different users, which helps to improve the accuracy and effectiveness of subsequent anomaly handling.
[0049] The exception handling rules described in this embodiment refer to the rules for matching exceptions in structured data. For example, exception handling rules include reducing the expenditure of the target service, the reduction ratio of the expenditure of the target service, increasing the resource inflow of the target service, and / or increasing the resource inflow ratio of the target service; for example, reducing the user's expenditure on the food delivery service and increasing the resource inflow ratio of the user in the resource accumulation service or the resource accumulation system.
[0050] In specific implementation, to improve the flexibility and targeting of subsequent anomaly handling for structured data, in an optional implementation method provided in this embodiment, the following operations are performed during the process of obtaining anomaly handling rules through rule mapping and rule compilation based on anomaly service data and data anomaly parameters: The initial parameter set is obtained by mapping the abnormal service data and data abnormal parameters to the preset parameter set for data abnormal handling. The initial parameter set is validated to obtain the target parameter set, and the target parameter set is then compiled into rules to obtain exception handling rules.
[0051] The preset parameter set refers to a pre-generated set of parameters for data anomaly handling. The preset parameter set can be a set of one or more preset parameters. The preset parameter set can be obtained by calculating on a continuous parameter space. For example, multiple expenditure reduction ratios can be constructed based on expenditure ranges of at least one dimension, and multiple salary increase ratios can be constructed based on salary ranges of at least one dimension. The dimension here can be any dimension, such as food delivery, education, medical care, and / or transportation.
[0052] Specifically, in the process of mapping abnormal service data and data anomaly parameters to a preset parameter set for data anomaly handling to obtain an initial parameter set, the abnormal service data and / or data anomaly parameters can be matched with the preset parameter set to obtain the initial parameter set. In the process of validating the initial parameter set to obtain the target parameter set, it can be verified whether the initial parameters in the initial parameter set are within the preset parameter range of the corresponding dimension. For example, if the initial parameter is the education expenditure reduction ratio in the education dimension, and the education dimension has a corresponding preset expenditure reduction range, it can be verified whether the education expenditure reduction ratio in the education dimension is within the preset expenditure reduction range of the education dimension. Alternatively, it can be verified whether the initial parameter is greater than a preset parameter threshold. In the process of compiling rules for the target parameter set to obtain anomaly handling rules, the target parameter set can be compiled based on the target compilation language to obtain the anomaly handling rules. For example, the target compilation language is a DSL (Domain-Specific Language).
[0053] Based on this, in practical application scenarios, users may have multiple abnormal service data. Exception handling for a single abnormal service data point may affect other abnormal service data. Therefore, to improve the balance of exception handling among multiple abnormal service data points, in an optional implementation of this embodiment, the following operations are also performed during the process of mapping and compiling rules for data exception handling based on abnormal service data and data exception parameters to obtain exception handling rules: The anomaly handling rules are input into the correlation detection data model for correlation detection. If the detection fails, the parameters of the anomaly handling rules are corrected.
[0054] Among them, an association detection data model can be constructed based on the anomaly handling constraint information of multiple abnormal service data; for example, the anomaly handling constraint information for the disease anomaly label is that the expenditure reduction ratio is greater than x1 yuan, the anomaly handling constraint information for the large expenditure anomaly label is that the expenditure reduction ratio is greater than x2 yuan, the expenditure reduction duration for both the disease anomaly label and the large expenditure anomaly label is x3, and the total expenditure reduction ratio is less than x4 yuan. An association detection data model can be constructed based on the anomaly handling constraint information.
[0055] Specifically, during the process of correlation detection of exception handling rules, exception handling rules can be correlated and adapted with exception handling constraint information of multiple exception service data. If there are rule clauses in the exception handling rules that are not compatible, the parameters of the rule clauses can be adjusted.
[0056] It should be noted that the above-mentioned operation of obtaining exception handling rules by performing rule mapping and rule compilation based on exception service data and data exception parameters through the rule engine can be replaced by performing rule mapping and rule compilation based on exception service data and / or data exception parameters to obtain exception handling rules; or it can be replaced by performing rule mapping and rule compilation based on exception service data and / or data exception parameters through the rule engine to obtain exception handling rules, and combining it with other processing steps provided in this embodiment to form a new implementation method.
[0057] Step S208: Perform anomaly handling matching on the structured data based on the anomaly handling rules, and perform data anomaly handling interaction based on the matching results.
[0058] In this step, anomaly handling matching is performed on structured data based on anomaly handling rules, and data anomaly handling interaction is performed based on the matching results. This improves the efficiency of subsequent data anomaly handling interaction and reduces computing resource costs through anomaly handling matching.
[0059] In practical applications, user-generated anomaly handling rules may be extensive. To avoid reducing the efficiency of data anomaly handling by directly interacting with the data based on these rules, this embodiment provides an optional implementation. During the process of matching structured data based on anomaly handling rules and interacting with the data based on the matching results, the anomaly matching results obtained from the rule matching process are interpreted, and an anomaly handling strategy is generated based on the interpreted anomaly data. Specifically, the following operations can be performed: Based on anomaly handling rules, rule matching processing is performed on structured data to obtain anomaly matching results, and then interpretation processing is performed to obtain anomaly interpretation data. Anomaly handling prompts are generated based on anomaly interpretation data and input into a large language model to generate anomaly handling strategies, thus obtaining the anomaly handling strategy.
[0060] Among them, the exception handling prompt words can be prompt words generated based on the exception interpretation data and / or the task fields generated by the exception handling strategy; the exception handling strategy can be a strategy to reduce expenses or a strategy to increase salaries or income, such as a reduction ratio for reducing expenses or an increase ratio for increasing income.
[0061] Specifically, in the process of performing rule matching processing on structured data based on anomaly handling rules to obtain anomaly matching results, the anomaly handling rules can be matched with the structured data to obtain the anomaly handling rules or matching anomaly handling rule clauses that match the structured data. Since the anomaly handling rules can be obtained by compiling the target parameter set based on the target compilation language, in order to improve the readability of the matched anomaly handling rules or matching anomaly handling rule clauses, the matched anomaly handling rules or matching anomaly handling rule clauses can be interpreted to obtain anomaly interpretation data.
[0062] Based on this, to ensure the security of data anomaly handling interactions, in one optional implementation of this embodiment, the following operations are performed during the process of anomaly handling matching of structured data based on anomaly handling rules and data anomaly handling interactions based on the matching results: Update the accounting protocol corresponding to abnormal service data based on the exception handling strategy; The updated accounting agreement was signed, and the agreement was then stored as evidence.
[0063] One method for processing agreement notarization is to upload the signed accounting agreement to the blockchain for notarization.
[0064] Specifically, during the process of updating the accounting agreement corresponding to abnormal service data based on the data anomaly handling strategy, the terms of the accounting agreement corresponding to the abnormal service data can be updated based on the data anomaly handling strategy; for example, increasing the monthly expenditure limit recorded in the accounting agreement; during the process of signing the updated accounting agreement, the updated terms in the updated accounting agreement can be extracted by summarizing and hashing to obtain the hash operation result, and the agreement can be signed based on the hash operation result.
[0065] In practical applications, after data anomaly handling interactions, user behavior may exceed the accounting processing parameters of the accounting processing protocol. To better regulate user behavior, ensure it complies with the accounting processing protocol, and assist users in better accounting management, this embodiment provides an optional implementation that further performs the following operations: Check whether the resource parameters carried in the resource request submitted by the user exceed the accounting parameters of the accounting protocol; If so, freeze or restrict the user's resource permissions, or generate and push notifications for the resource request's accounting requirements; otherwise, no action is required.
[0066] The resource parameters can be the amount of resource expenditure and / or the amount of resource transfer; the accounting parameters include the resource expenditure limit and / or the cumulative amount of resources; by detecting the resource parameters, protective locking is performed so that when deviations occur or risks increase, the user's resource permissions can be frozen or restricted, which can help users better manage their accounts.
[0067] It should be noted that the user data obtained in this manual, such as user service data, multi-source heterogeneous accounting data, and accounting-related materials, are authorized by the user and do not involve user privacy.
[0068] It should be added that each optional implementation method and each feasible execution method in steps S202 to S208 provided in this embodiment can be executed independently as needed, or they can be combined and referenced with each other. At the same time, each specific execution step in each optional implementation method or each feasible execution method can also be executed independently or combined as needed. The execution conditions of "if" or "under what circumstances" involved in each step or operation can be directly deleted, and subsequent operations can be executed. The limitation of "with" involved in each step or operation can also be deleted. This embodiment does not make specific limitations in this regard.
[0069] It should also be added that, depending on the actual application scenario, step S202 and any of the subsequent steps S204 to S208 can be deleted, or any feature in any step can be deleted. For example, "accessing the application through data" in step S202 can be deleted, and the execution order of steps S202 to S208 can also be arbitrary.
[0070] The following description uses the application of a data anomaly handling method provided in this embodiment in an accounting scenario as an example to further illustrate the data anomaly handling method provided in this embodiment. (See also...) Figure 3 The data anomaly handling method applied to accounting scenarios includes the following steps.
[0071] Step S302: Based on the access authorization request submitted by the user through the data access application, obtain the user's multi-source heterogeneous accounting data from the accounting system by calling the multi-source data interface.
[0072] Step S304: Obtain the accounting-related materials uploaded by the user for multi-source heterogeneous accounting data, and perform structured transformation on the multi-source heterogeneous accounting data to obtain multi-source structured data.
[0073] Step S306: Identify and extract accounting data from the accounting-related materials to obtain related accounting data, and map the related accounting data with multi-source structured data to obtain structured accounting data.
[0074] Step S308: Input the structured accounting data into the data detection component to detect service data anomalies, obtain abnormal service data and data anomaly parameters, and synchronize them to the rule engine.
[0075] Step S310: The rule engine maps the abnormal accounting data and data anomaly parameters to the preset parameter set for data anomaly processing to obtain the initial parameter set.
[0076] Step S312: The initial parameter set is validated by the rule engine to obtain the target parameter set, and the target parameter set is compiled into rules to obtain exception handling rules.
[0077] Step S314: Perform rule matching processing on the structured accounting data based on the exception handling rules to obtain the exception matching results and perform interpretation processing to obtain exception interpretation data.
[0078] Step S316: Generate exception handling prompt words based on exception interpretation data and input them into the large language model to generate exception handling strategies, thereby obtaining exception handling strategies.
[0079] It should be noted that any one or more of steps S302 to S316 can be replaced by the corresponding technical means provided in steps S202 to S208 as needed for implementation and deployment. Any one or more of steps S302 to S316 can also be combined into a new implementation method as needed for implementation and deployment. Furthermore, any one or more of steps S302 to S316 can also be combined with one or more of the steps provided in steps S202 to S208 to form a new implementation method, or combined with one or more of the optional implementation methods provided in steps S202 to S208 to form a new implementation method, as needed for actual deployment. These will not be elaborated on here.
[0080] The following is an embodiment of a data anomaly handling device provided in this specification: In the above embodiments, a data anomaly processing method is provided, and correspondingly, a data anomaly processing device is also provided, which will be described below with reference to the accompanying drawings.
[0081] Reference Figure 4 The diagram illustrates an embodiment of a data anomaly processing device provided in this embodiment.
[0082] Since the apparatus embodiments correspond to the method embodiments, the descriptions are relatively simple. For relevant parts, please refer to the corresponding descriptions of the method embodiments provided above. The apparatus embodiments described below are merely illustrative.
[0083] This embodiment provides a data anomaly processing device, including: The data conversion module 402 is configured to perform structured conversion on the user's service data to obtain structured data based on the access authorization request submitted by the user through the data access application. The data detection module 404 is configured to input the structured data into the data detection component to perform service data anomaly detection, obtain abnormal service data and data anomaly parameters, and synchronize them to the rule engine; The rule processing module 406 is configured to obtain exception processing rules by performing rule mapping and rule compilation for data exception processing based on the exception service data and the data exception parameters through the rule engine; The exception handling module 408 is configured to perform exception handling matching on the structured data based on the exception handling rules, and to perform data exception handling interaction based on the matching results.
[0084] For ease of description, the above devices are described by dividing them into various modules or units based on their functions. Of course, when implementing one or more of these specifications, the functions of each module or unit can be implemented in the same or different software and / or hardware, or a module that performs the same function can be implemented by a combination of multiple sub-modules or sub-units, etc. The device embodiments described above are merely illustrative. For example, the division of units is only a logical functional division; in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed.
[0085] This specification provides an example of a data anomaly processing device as follows: Corresponding to the data anomaly handling method described above, based on the same technical concept, one or more embodiments of this specification also provide a data anomaly handling device, which is used to execute the data anomaly handling method provided above. Figure 5 This is a schematic diagram of the structure of a data anomaly processing device provided for one or more embodiments of this specification.
[0086] This embodiment provides a data anomaly processing device, comprising: like Figure 5As shown, device 500 mainly consists of a communication interface 502, a user interface 504, a processor 506, and a data storage 508. These components are interconnected and communicate with each other via a system bus, network, or other connection mechanism 510. The communication interface 502 enables device 500 to communicate with other devices, access networks, and transmission networks via analog or digital modulation. For example, the communication interface 502 may include a chipset and antenna for wireless communication with a radio access network or access point. Furthermore, the communication interface 502 can be a wired interface such as Ethernet, Token Ring, or a USB port, or a wireless interface such as Wi-Fi, Bluetooth, Global Positioning System (GPS), or a wide-area wireless interface (e.g., WiMAX or LTE). Of course, the communication interface 502 can also support other forms of physical layer interfaces and standard or proprietary communication protocols. The communication interface 502 may also include multiple physical communication interfaces, such as Wi-Fi, Bluetooth, and wide-area wireless interfaces. The user interface 504 includes receiving user input and providing output to the user. Therefore, user interface 504 may include input components such as a keypad, keyboard, touch-sensitive or presence-sensitive panel, computer mouse, trackball, joystick, microphone, still camera, and video camera, and output components such as a display screen (which may be combined with a touch-sensitive panel), CRT, LCD, LED, display using DLP technology, printer, and other similar devices known or developed in the future. User interface 504 may also generate auditory output via speakers, speaker jacks, audio output ports, audio output devices, headphones, and other similar devices known or developed in the future. In some embodiments, user interface 504 may include software, circuitry, or other forms of logic capable of transmitting and receiving data to and from external user input / output devices. Additionally or alternatively, device 500 may support remote access from other devices via communication interface 502 or another physical interface (not shown). User interface 504 may be configured to receive user input, the position and movement of which may be indicated by indicators or cursors described herein. User interface 504 may also be configured as a display device for rendering or displaying text fragments.
[0087] Processor 506 may include one or more general-purpose processors and / or special-purpose processors. Data storage 508 may include one or more volatile and / or non-volatile storage components and may be integrated wholly or partially with processor 506. Data storage 508 may include removable and non-removable components.
[0088] Processor 506 is capable of executing program instructions 518 (e.g., compiled or uncompiled program logic and / or machine code) stored in data storage 508 to perform the various functions described herein. Data storage 508 may contain a non-transitory computer-readable medium on which program instructions are stored, which, when executed by device 500, enable device 500 to perform any methods, processes, or functions disclosed in this specification and / or the accompanying drawings. Execution of program instructions 518 by processor 506 may result in processor 506 using data 512. For example, program instructions 518 may include an operating system 522 (e.g., an operating system kernel, device drivers, and / or other modules) installed on device 500 and one or more application programs 520 (e.g., a browser, social application, or game application). Similarly, data 512 may include operating system data 516 and application data 514. Operating system data 516 is primarily accessible to operating system 522, while application data 514 is primarily accessible to one or more application programs 520. Application data 514 may reside in a file system visible or hidden from the user of device 500. Application 520 can communicate with operating system 522 through one or more application programming interfaces (APIs). These APIs facilitate application 520 in reading and / or writing application data 514, transmitting or receiving information via communication interface 502, and receiving or displaying information on user interface 504. In some terms, application 520 may be simply referred to as "app". Furthermore, application 520 can be downloaded to device 500 through one or more online app stores or app markets. However, applications can also be installed on device 500 in other ways, such as through a web browser or a physical interface on device 500 (e.g., a USB port).
[0089] In one specific embodiment, the data anomaly processing device includes a memory and one or more programs, wherein the one or more programs are stored in the memory, and the one or more programs may include one or more modules, and each module may include a series of computer-executable instructions for the data anomaly processing device, and is configured to be executed by one or more processors. The one or more programs include computer-executable instructions for performing the following: Based on the access authorization request submitted by the user through the data access application, the user's service data is transformed into structured data. The structured data is input into the data detection component to detect service data anomalies, obtain abnormal service data and data anomaly parameters, and synchronize them to the rule engine; The rule engine performs rule mapping and rule compilation for data anomaly handling based on the abnormal service data and the data anomaly parameters to obtain anomaly handling rules. The structured data is matched for anomaly handling based on the anomaly handling rules, and the data anomaly handling interaction is performed based on the matching results.
[0090] This specification provides an embodiment of a computer-readable storage medium as follows: Corresponding to the data anomaly handling method described above, based on the same technical concept, one or more embodiments of this specification also provide a computer-readable storage medium.
[0091] The computer-readable storage medium provided in this embodiment is used to store computer-executable instructions, which, when executed, perform the following steps: Based on the access authorization request submitted by the user through the data access application, the user's service data is transformed into structured data. The structured data is input into the data detection component to detect service data anomalies, obtain abnormal service data and data anomaly parameters, and synchronize them to the rule engine; The rule engine performs rule mapping and rule compilation for data anomaly handling based on the abnormal service data and the data anomaly parameters to obtain anomaly handling rules. The structured data is matched for anomaly handling based on the anomaly handling rules, and the data anomaly handling interaction is performed based on the matching results.
[0092] It should be noted that the embodiments of a computer-readable storage medium described in this specification and the embodiments of a data anomaly handling method described in this specification are based on the same inventive concept. Therefore, the specific implementation of this embodiment can be referred to the implementation of the corresponding method described above, and the repeated parts will not be described again.
[0093] This specification provides an example of a computer program product as follows: Corresponding to the data anomaly handling method described above, based on the same technical concept, one or more embodiments of this specification also provide a computer program product.
[0094] A computer program product includes a computer program / instructions that, when executed by a processor, perform the following steps: Based on the access authorization request submitted by the user through the data access application, the user's service data is transformed into structured data. The structured data is input into the data detection component to detect service data anomalies, obtain abnormal service data and data anomaly parameters, and synchronize them to the rule engine; The rule engine performs rule mapping and rule compilation for data anomaly handling based on the abnormal service data and the data anomaly parameters to obtain anomaly handling rules. The structured data is matched for anomaly handling based on the anomaly handling rules, and the data anomaly handling interaction is performed based on the matching results.
[0095] It should be noted that the embodiments of a computer program product described in this specification and the embodiments of a data anomaly handling method described in this specification are based on the same inventive concept. Therefore, the specific implementation of this embodiment can be referred to the implementation of the corresponding method described above, and the repeated parts will not be described again.
[0096] The various embodiments in this specification are described in a progressive manner. The same or similar parts between the various embodiments can be referred to each other. Each embodiment focuses on describing the differences from other embodiments. For example, the device embodiment, equipment embodiment and computer-readable storage medium embodiment are all similar to the method embodiment, so the description is relatively simple. When reading the relevant content of the device embodiment, equipment embodiment and computer-readable storage medium embodiment, please refer to the description of the method embodiment.
[0097] Although one or more embodiments of this specification provide method steps as described in the embodiments or flowcharts, it is understood that the order of steps listed in the embodiments or flowcharts is only one of many possible execution orders and does not represent the only execution order. Therefore, when the claims involve method steps, any changes or adjustments to the order of such steps, or the parallelism between steps, are also within the scope of protection of the claims.
[0098] This specification uses specific terms to describe embodiments thereof. Terms such as "an embodiment," "one embodiment," and / or "some embodiments" refer to a particular feature, structure, or characteristic associated with at least one embodiment of this specification. Therefore, it should be emphasized and noted that references to "an embodiment," "one embodiment," or "an alternative embodiment" in different locations throughout this specification do not necessarily refer to the same embodiment. Furthermore, those skilled in the art can combine and integrate the different embodiments or examples described herein, as well as the features of those different embodiments or examples, without contradiction.
[0099] The foregoing has described specific embodiments of this specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims may be performed in a different order than that shown in the embodiments and may still achieve the desired result. Furthermore, the processes depicted in the drawings do not necessarily require the specific or sequential order shown to achieve the desired result. In some embodiments, multitasking and parallel processing are possible or may be advantageous.
[0100] In the 1930s, improvements to a technology could be clearly distinguished as either hardware improvements (e.g., improvements to the circuit structure of diodes, transistors, switches, etc.) or software improvements (improvements to the methodology). However, with technological advancements, many improvements to the methodology today can be considered direct improvements to the hardware circuit structure. Designers almost always obtain the corresponding hardware circuit structure by programming the improved methodology into the hardware circuit. Therefore, it cannot be said that an improvement to the methodology cannot be implemented using hardware physical modules. For example, a Programmable Logic Device (PLD) (such as a Field Programmable Gate Array (FPGA)) is such an integrated circuit whose logic function is determined by the user programming the device. Designers can program and "integrate" a digital system onto a PLD themselves, without needing chip manufacturers to design and manufacture dedicated integrated circuit chips. Furthermore, nowadays, instead of manually manufacturing integrated circuit chips, this programming is mostly implemented using "logic compiler" software. Similar to the software compiler used in program development, the original code before compilation must also be written in a specific programming language, called a Hardware Description Language (HDL). There are many HDLs, such as ABEL (Advanced Boolean Expression Language), AHDL (Altera Hardware Description Language), Confluence, CUPL (Cornell University Programming Language), HDCal, JHDL (Java Hardware Description Language), Lava, Lola, MyHDL, PALASM, and RHDL (Ruby Hardware Description Language). Currently, the most commonly used are VHDL (Very-High-Speed Integrated Circuit Hardware Description Language) and Verilog. Those skilled in the art should also understand that by simply performing some logic programming on the method flow using one of these hardware description languages and programming it into an integrated circuit, the hardware circuit implementing the logical method flow can be easily obtained.
[0101] The controller can be implemented in any suitable manner. For example, it can take the form of a microprocessor or processor and a computer-readable medium storing computer-readable program code (e.g., software or firmware) executable by the (micro)processor, logic gates, switches, application-specific integrated circuits (ASICs), programmable logic controllers, and embedded microcontrollers. Examples of controllers include, but are not limited to, the following microcontrollers: ARC 625D, Atmel AT91SAM, Microchip PIC18F26K20, and Silicon Labs C8051F320. A memory controller can also be implemented as part of the control logic of the memory. Those skilled in the art will also recognize that, in addition to implementing the controller in purely computer-readable program code form, the same functionality can be achieved by logically programming the method steps to make the controller take the form of logic gates, switches, application-specific integrated circuits, programmable logic controllers, and embedded microcontrollers. Therefore, such a controller can be considered a hardware component, and the means included therein for implementing various functions can also be considered as structures within the hardware component. Alternatively, the means for implementing various functions can be considered as both software modules implementing the method and structures within the hardware component.
[0102] The systems, devices, modules, or units described in the above embodiments can be implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer. Specifically, a computer can be, for example, a personal computer, laptop computer, cellular phone, camera phone, smartphone, personal digital assistant, media player, navigation device, email device, game console, tablet computer, wearable device, or any combination of these devices.
[0103] For ease of description, the above apparatus is described by dividing it into various functional units. Of course, when implementing the embodiments of this specification, the functions of each unit can be implemented in one or more software and / or hardware.
[0104] Those skilled in the art will understand that one or more embodiments of this specification can be provided as a method, system, or computer program product. Therefore, one or more embodiments of this specification may take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this specification may take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0105] This specification is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this specification. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable test processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable test processing apparatus, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0106] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable test processing equipment to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0107] These computer program instructions can also be loaded onto a computer or other programmable test processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0108] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.
[0109] Memory may include non-persistent storage in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of computer-readable media.
[0110] Computer-readable media include both permanent and non-permanent, removable and non-removable media that can store information using any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, disk storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.
[0111] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of features includes not only those features but also other features not expressly listed, or features inherent to such process, method, article, or apparatus. Without further limitations, a feature defined by the phrase "comprising one..." does not exclude the presence of other identical features in the process, method, article, or apparatus that includes said feature.
[0112] One or more embodiments of this specification can be described in the general context of computer-executable instructions, such as program modules, that are executed by a computer. Generally, program modules include routines, programs, objects, components, data structures, etc., that perform a particular task or implement a particular abstract data type. One or more embodiments of this specification can also be practiced in distributed computing environments where tasks are performed by remote processing devices connected via a communication network. In distributed computing environments, program modules can reside in local and remote computer storage media, including storage devices.
[0113] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to interchangeably. Each embodiment focuses on describing the differences from other embodiments. In particular, the system embodiments are basically similar to the method embodiments, so the description is relatively simple; relevant parts can be referred to the descriptions in the method embodiments.
[0114] The above description is merely an embodiment of this document and is not intended to limit the scope of this document. Various modifications and variations can be made to this document by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this document should be included within the scope of the claims of this document.
Claims
1. A data anomaly handling method, comprising: Based on the access authorization request submitted by the user through the data access application, the user's service data is transformed into structured data. The structured data is input into the data detection component to detect service data anomalies, obtain abnormal service data and data anomaly parameters, and synchronize them to the rule engine; The rule engine performs rule mapping and rule compilation for data anomaly handling based on the abnormal service data and the data anomaly parameters to obtain anomaly handling rules. The structured data is matched for anomaly handling based on the anomaly handling rules, and the data anomaly handling interaction is performed based on the matching results.
2. The data anomaly handling method according to claim 1, wherein the service data is obtained in the following manner: The user's multi-source heterogeneous accounting data is obtained from the data source system by calling the multi-source data interface; Obtain the accounting-related materials uploaded by the user in relation to the multi-source heterogeneous accounting data; in, The accounting-related materials include: user resource data for resource services, user service data for medical services, and / or user payment records for payment services.
3. The data anomaly handling method according to claim 2, wherein the step of performing a structured transformation on the user's service data to obtain structured data includes: The multi-source heterogeneous accounting data is subjected to structured transformation to obtain multi-source structured data; The accounting data is identified and extracted from the accounting-related materials to obtain related accounting data, and the related accounting data is mapped with the multi-source structured data to obtain structured accounting data.
4. The data anomaly handling method according to claim 1, wherein the data detection component includes a pre-trained data anomaly detection model; Accordingly, the service data anomaly detection is implemented in the following way: The structured data is time-series aligned, and features are extracted from the time-series structured data to obtain a time-series feature set; The time-series feature set is input into a multi-label classification network for multi-label classification processing to obtain multiple abnormal service data and data anomaly parameters for each abnormal service data.
5. The data anomaly processing method according to claim 4, wherein the step of performing time-series alignment on the structured data and extracting features from the time-series structured data to obtain a time-series feature set includes: Temporal features are obtained by extracting temporal features from the structured service data in the structured data; The associated data in the structured data is feature-normalized to obtain associated data features, and the time-series features are fused with the associated data features through cross-modal feature fusion to obtain the time-series feature set.
6. The data anomaly handling method according to claim 1, wherein the step of performing rule mapping and rule compilation for data anomaly handling based on the anomaly service data and the data anomaly parameters to obtain anomaly handling rules includes: The abnormal service data and the data anomaly parameters are mapped to a preset parameter set for data anomaly processing to obtain an initial parameter set. The initial parameter set is validated to obtain the target parameter set, and the target parameter set is compiled into rules to obtain the exception handling rules.
7. The data anomaly handling method according to claim 6, wherein the step of performing rule mapping and rule compilation for data anomaly handling based on the anomaly service data and the data anomaly parameters to obtain anomaly handling rules further includes: The anomaly handling rules are input into the correlation detection data model for correlation detection of the anomaly handling rules. If the detection fails, the parameters of the anomaly handling rules are corrected.
8. The data anomaly handling method according to claim 1, wherein the step of performing anomaly handling matching on the structured data based on the anomaly handling rules, and performing data anomaly handling interaction according to the matching results, includes: Based on the aforementioned anomaly handling rules, the structured data is subjected to rule matching processing to obtain anomaly matching results, which are then interpreted to obtain anomaly interpreted data. Anomaly handling prompts are generated based on the anomaly interpretation data and input into a large language model to generate anomaly handling strategies, thereby obtaining the anomaly handling strategy.
9. The data anomaly handling method according to claim 8, wherein the step of performing anomaly handling matching on the structured data based on the anomaly handling rules and performing data anomaly handling interaction according to the matching results further includes: The accounting protocol corresponding to the abnormal service data is updated based on the aforementioned exception handling strategy. The updated accounting agreement was signed, and the agreement was then stored as evidence.
10. The data anomaly handling method according to claim 1, further comprising: Detect whether the resource parameters carried in the resource request submitted by the user exceed the billing parameters of the billing protocol; If so, freeze or restrict the user's resource permissions, or generate an accounting reminder for the resource request and send the reminder to the system.
11. A data anomaly processing device, comprising: The data transformation module is configured to perform structured transformation on the user's service data to obtain structured data based on the access authorization request submitted by the user through the data access application. The data detection module is configured to input the structured data into the data detection component to perform service data anomaly detection, obtain abnormal service data and data anomaly parameters, and synchronize them to the rule engine; The rule processing module is configured to perform rule mapping and rule compilation for data anomaly processing based on the abnormal service data and the data anomaly parameters through the rule engine to obtain anomaly processing rules; The exception handling module is configured to perform exception handling matching on the structured data based on the exception handling rules, and to perform data exception handling interaction based on the matching results.
12. A data anomaly processing device, comprising: processor; And, a memory configured to store computer-executable instructions, which, when executed, cause the processor to: Based on the access authorization request submitted by the user through the data access application, the user's service data is transformed into structured data. The structured data is input into the data detection component to detect service data anomalies, obtain abnormal service data and data anomaly parameters, and synchronize them to the rule engine; The rule engine performs rule mapping and rule compilation for data anomaly handling based on the abnormal service data and the data anomaly parameters to obtain anomaly handling rules. The structured data is matched for anomaly handling based on the anomaly handling rules, and the data anomaly handling interaction is performed based on the matching results.
13. A computer-readable storage medium for storing computer-executable instructions that, when executed, implement the steps of the method of claim 1.