A user risk determination method, apparatus, device, and storage medium

By integrating multi-dimensional features and enhancing the risk transmission link library, a comprehensive risk index for the aviation fraud detection system is generated, which solves the shortcomings of the existing system in fraud identification and achieves accurate identification and rapid response.

CN122434567APending Publication Date: 2026-07-21CHINA SOUTHERN AIRLINES DIGITAL TECHNOLOGY (GUANGDONG) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
CHINA SOUTHERN AIRLINES DIGITAL TECHNOLOGY (GUANGDONG) CO LTD
Filing Date
2026-04-01
Publication Date
2026-07-21

Smart Images

  • Figure CN122434567A_ABST
    Figure CN122434567A_ABST
Patent Text Reader

Abstract

The application provides a user risk determination method, device and equipment and a storage medium, and relates to the technical field of information. The method comprises the following steps: acquiring user data, wherein the user data comprises user attribute data, user behavior record data and external data associated with the user, the external data comprises at least one of internet behavior data, credit data or non-operator data; performing fusion and feature engineering processing on the user data to generate multi-dimensional feature information for representing user risk; performing risk transmission enhancement on the multi-dimensional feature information based on a preset risk transmission link library to obtain strengthened risk feature information, wherein the risk transmission link library defines the association relationship and transmission strength between different risk features and risk types; and determining the comprehensive risk index of the user according to the strengthened risk feature information.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of information technology, and in particular to a method, apparatus, device, and storage medium for determining user risk. Background Technology

[0002] Frequent flyer programs are a core component of airline customer loyalty management, playing a crucial role in enhancing customer stickiness and operational efficiency. However, with the continuous surge in membership and the increasing complexity of benefits systems, fraudulent activities such as flight delay fraud, points theft, and account misuse are becoming increasingly professional and covert, posing a significant risk to airline operations.

[0003] Currently, the detection of aviation fraud mainly relies on detection systems with manually preset rules and traditional machine learning models, which identify abnormal behavior by setting static thresholds.

[0004] Because the rules rely on manual pre-setting and are difficult to proactively adapt to the iterative evolution of fraud patterns, it is difficult to accurately identify fraudulent behavior. Summary of the Invention

[0005] This application provides a user risk determination method, apparatus, device, and storage medium for accurately identifying user risky behaviors.

[0006] Firstly, this application provides a user risk determination method. This method is applied to an electronic device. The subject executing this method can be the electronic device itself, or a component or device applied to the electronic device (e.g., a processor, chip, or chip system), or a logic module or software capable of implementing all or part of the functions of the electronic device, including: Acquire user data, which includes user attribute data, user behavior record data, and external data associated with the user. External data includes at least one of internet behavior data, credit data, or non-carrier data. User data is fused and feature-engineered to generate multidimensional feature information to characterize user risk; Based on a pre-defined risk transmission link library, risk transmission is enhanced through multi-dimensional feature information to obtain enhanced risk feature information. The risk transmission link library defines the correlation and transmission strength between different risk features and risk types. Based on the enhanced risk characteristics information, the user's comprehensive risk index is determined.

[0007] In the first aspect, by acquiring at least one external data source, including user attribute data, user behavior record data, internet behavior data, credit data, or non-carrier data, information related to user risk can be collected from multiple dimensions. After fusing and feature engineering the collected user data, multi-dimensional feature information is generated, transforming the original heterogeneous data into a unified risk representation. Risk transmission is enhanced based on a pre-defined risk transmission link library, which defines the correlation and transmission strength between different risk features and risk types, thus highlighting feature combinations closely related to the risk transmission link. The enhanced risk feature information is used to determine the user's comprehensive risk index, ensuring that the final risk quantification result incorporates the correlation logic between features, thereby improving the accuracy of identifying complex and hidden risk patterns and achieving precise identification of user risk levels.

[0008] In conjunction with the first aspect, one possible implementation involves fusing and feature-engineering user data to generate multidimensional feature information characterizing user risk, including: Statistical features of time-series data in user data are extracted using multiple time windows to obtain time-series risk features; The structured data in the user data is encoded and transformed to obtain scenario risk characteristics; Semantic risk features are obtained by embedding unstructured data in user data. The temporal risk features, scenario risk features, and semantic risk features are fused to generate an initial risk feature set; The initial risk feature set is input into the feature enhancement network for processing to generate multidimensional feature information. The feature enhancement network is used to enhance the feature components related to abnormal risks in the initial risk feature set.

[0009] In this implementation, statistical feature extraction of time-series data from user data across multiple time windows captures the dynamic changes in user behavior over time, forming time-series risk features. Structured data is encoded and transformed, converting discrete or categorical data into numerical representations to obtain scenario-based risk features. Unstructured data is embedded and represented, transforming irregular data such as text and images into semantic vectors to obtain semantic risk features. These three types of initial risk features are fused to generate an initial risk feature set, which is then input into a feature enhancement network. This network specifically enhances the feature components related to abnormal risks within the initial risk feature set, amplifying hidden abnormal signals and suppressing interference from redundant or irrelevant features. This generates more discriminative multidimensional feature information, improving the sensitivity and robustness of subsequent risk assessment.

[0010] In conjunction with the first aspect, in one possible implementation, the feature enhancement network includes a temporal attention module, a scene-adaptive risk convolution module, a cross-domain behavior association graph module, and a feature modulation module. The initial risk feature set is input into the feature enhancement network for processing, including: Temporal mutation features are extracted from the initial risk feature set using a temporal attention module; The scene-adaptive risk convolution module extracts scene convolution features from the initial risk feature set. A cross-domain behavior association graph module is used to construct an association graph containing behavior nodes, attribute nodes, and risk nodes. Based on the association graph, cross-domain coupling features are extracted from the initial risk feature set. The feature modulation module fuses temporal mutation features, scene convolution features, and cross-domain coupling features, and enhances the abnormal components in the fused features. Then, the enhanced features are weighted and fused with the temporal mutation features, scene convolution features, and cross-domain coupling features to generate multi-dimensional feature information.

[0011] In this implementation, the feature enhancement network employs a temporal attention module to extract and amplify periodic anomaly patterns from the initial risk feature set, thereby increasing attention to sudden abnormal behaviors. A scenario-adaptive risk convolution module extracts scenario convolution features, enabling targeted expression of local risk patterns across different business scenarios. A cross-domain behavior association graph module constructs an association graph containing behavior nodes, attribute nodes, and risk nodes, and extracts cross-domain coupling features based on this graph, enabling the discovery of nonlinear relationships across data domains. The feature modulation module fuses temporal anomaly features, scenario convolution features, and cross-domain coupling features, enhances the anomalous components in the fused features, and then weights and fuses the enhanced features with the aforementioned three types of features. The resulting multi-dimensional feature information retains the original risk signals of each dimension while amplifying anomaly patterns, achieving organic integration of multi-source features and significantly improving the ability to identify complex and concealed fraudulent behaviors.

[0012] In conjunction with the first aspect, one possible implementation involves enhancing risk transmission by weighting multi-dimensional feature information based on a pre-defined risk association graph risk transmission link library, including: Match a subset of features from multidimensional feature information that matches at least one risk transmission link in the risk transmission link library of the risk association map; Based on the transmission strength corresponding to the matched risk transmission link, the features in the feature subset are enhanced to generate enhanced risk feature information.

[0013] In this implementation, a subset of features matching at least one risk transmission link in the risk transmission link library is selected from multi-dimensional feature information. This allows for the rapid identification of feature combinations in the current user behavior that are associated with known fraud patterns. Based on the transmission strength corresponding to the matched risk transmission link, the features in this subset are enhanced, giving higher expression weights to feature signals that conform to historical fraud transmission paths. This selective feature enhancement method embeds prior risk knowledge into the feature processing flow, making the enhanced risk feature information closer to the behavioral logic of real fraud, thereby improving the accuracy of risk identification.

[0014] In conjunction with the first aspect, in one possible implementation, a user's comprehensive risk index is determined based on the enhanced risk characteristic information, including: The enhanced risk feature information is input into the trained risk index prediction model, which outputs a comprehensive risk index. The risk index prediction model is a model trained based on historical user data and its corresponding risk loss labels.

[0015] In this implementation, enhanced risk feature information is input into a trained risk index prediction model, which is trained based on historical user data and its corresponding risk loss labels. By learning the mapping relationship between risk features and actual losses in historical data, the model can perform nonlinear transformations and regressions on the input enhanced risk feature information, outputting a comprehensive risk index. Because risk loss labels are introduced during training, the output comprehensive risk index not only reflects the probability of risk existence but also quantifies the expected level of loss that the risk may cause, achieving accurate risk pricing and comparable ranking, facilitating differentiated risk management measures based on the index magnitude.

[0016] In conjunction with the first aspect, in one possible implementation, the method further includes: Implement corresponding risk management strategies based on the comprehensive risk index.

[0017] In this implementation, corresponding risk management strategies are executed based on the comprehensive risk index. This step directly translates the results of the risk quantification assessment into actual risk control actions, enabling risk identification to move beyond the analysis stage and trigger targeted interventions. By linking assessment with execution, measures such as prevention, warning, or restriction can be taken promptly when high-risk users are identified, effectively stopping the continuation of fraudulent activities or reducing potential economic losses, thus forming an operational closed loop from risk identification to risk control.

[0018] In conjunction with the first aspect, one possible implementation involves executing corresponding risk management strategies based on a comprehensive risk index, including: The comprehensive risk index is compared with multiple preset risk thresholds; If the comprehensive risk index exceeds the first risk threshold, a risk warning message will be generated and sent. If the overall risk index exceeds the second risk threshold, which is higher than the first risk threshold, temporary restrictions on the corresponding user account will be automatically triggered.

[0019] In this implementation, a comprehensive risk index is compared with multiple preset risk thresholds. If the comprehensive risk index exceeds the first risk threshold, a risk warning is generated and sent, triggering only notification-type actions to avoid excessive interference with low-risk users. If the comprehensive risk index exceeds a second risk threshold, which is higher than the first risk threshold, temporary restrictions on the corresponding user account are automatically triggered, proactively blocking high-risk users. By setting multiple different levels of thresholds and matching differentiated actions, risk-level control is achieved: low-risk users are primarily warned, while high-risk users are primarily restricted, thus ensuring a normal user experience while rapidly and forcefully blocking serious risky behaviors.

[0020] In conjunction with the first aspect, in one possible implementation, the method further includes: Obtain feedback data on the execution results of risk management strategies. The feedback data includes false alarm confirmation information, false alarm confirmation information, and / or risk type confirmation information. Based on the feedback data from the execution results, update the transmission strength in the risk transmission link library and / or optimize the parameters of the feature enhancement network.

[0021] In this implementation, feedback data on the execution results of risk handling strategies is acquired. This feedback data includes false positive confirmation information, false negative confirmation information, and / or risk type confirmation information. This feedback data reflects the actual effectiveness of risk control measures and genuine fraud labels. Based on the execution result feedback data, the transmission strength in the risk transmission link library and / or the parameters of the feature enhancement network are updated, enabling the risk transmission link library and feature enhancement network to learn from actual handling results and dynamically adapt to changes in new fraud patterns. This iterative optimization mechanism based on real feedback can achieve incremental updates at the minute level without fully retraining the model, effectively shortening the model's response cycle to new frauds and solving the problem of iterative lag in traditional risk control systems.

[0022] Secondly, this application provides a user risk determination device, comprising: The data acquisition module is used to acquire user data, which includes user attribute data, user behavior record data, and external data associated with the user. External data includes at least one of internet behavior data, credit data, or non-carrier data. The feature generation module is used to fuse and perform feature engineering on user data to generate multidimensional feature information that characterizes user risk. The information enhancement module is used to enhance the risk transmission of multi-dimensional feature information based on a preset risk transmission link library to obtain enhanced risk feature information. The risk transmission link library defines the correlation and transmission strength between different risk features and risk types. The index generation module is used to determine the user's comprehensive risk index based on the enhanced risk characteristic information.

[0023] In conjunction with the second aspect, in one possible implementation, the feature generation module is also used to extract statistical features from time-series data in user data across multiple time windows to obtain time-series risk features; The structured data in the user data is encoded and transformed to obtain scenario risk characteristics; Semantic risk features are obtained by embedding unstructured data in user data. The temporal risk features, scenario risk features, and semantic risk features are fused to generate an initial risk feature set; The initial risk feature set is input into the feature enhancement network for processing to generate multidimensional feature information. The feature enhancement network is used to enhance the feature components related to abnormal risks in the initial risk feature set.

[0024] In conjunction with the second aspect, in one possible implementation, the feature enhancement network includes a temporal attention module, a scene-adaptive risk convolution module, a cross-domain behavior association graph module, and a feature modulation module.

[0025] The feature generation module is also used to extract temporal mutation features from the initial risk feature set through the temporal attention module; The scene-adaptive risk convolution module extracts scene convolution features from the initial risk feature set. A cross-domain behavior association graph module is used to construct an association graph containing behavior nodes, attribute nodes, and risk nodes. Based on the association graph, cross-domain coupling features are extracted from the initial risk feature set. The feature modulation module fuses temporal mutation features, scene convolution features, and cross-domain coupling features, and enhances the abnormal components in the fused features. Then, the enhanced features are weighted and fused with the temporal mutation features, scene convolution features, and cross-domain coupling features to generate multi-dimensional feature information.

[0026] In conjunction with the second aspect, in one possible implementation, the information enhancement module is also used to match a subset of features from the multidimensional feature information that matches at least one risk transmission link in the risk transmission link library of the risk association graph; Based on the transmission strength corresponding to the matched risk transmission link, the features in the feature subset are enhanced to generate enhanced risk feature information.

[0027] In conjunction with the second aspect, in one possible implementation, the information enhancement module is also used to match a subset of features from the multidimensional feature information that matches at least one risk transmission link in the risk transmission link library; Based on the transmission strength corresponding to the matched risk transmission link, the weight values ​​of each feature in the feature subset are increased to generate enhanced risk feature information.

[0028] In conjunction with the second aspect, in one possible implementation, the index generation module is also used to input the enhanced risk feature information into the trained risk index prediction model, and the risk index prediction model outputs a comprehensive risk index. The risk index prediction model is a model trained based on historical user data and its corresponding risk loss labels.

[0029] In conjunction with the second aspect, in one possible implementation, the user risk determination device also includes a risk management module for executing corresponding risk management strategies based on a comprehensive risk index.

[0030] In conjunction with the second aspect, in one possible implementation, the risk management module is also used to compare the comprehensive risk index with multiple preset risk thresholds; If the comprehensive risk index exceeds the first risk threshold, a risk warning message will be generated and sent. If the overall risk index exceeds the second risk threshold, which is higher than the first risk threshold, temporary restrictions on the corresponding user account will be automatically triggered.

[0031] In conjunction with the second aspect, in one possible implementation, the risk handling module is also used to obtain execution result feedback data of the risk handling strategy, including false alarm confirmation information, missed alarm confirmation information and / or risk type confirmation information; Based on the feedback data from the execution results, update the transmission strength in the risk transmission link library and / or optimize the parameters of the feature enhancement network.

[0032] Thirdly, this application provides an electronic device comprising: a processor and a memory; the memory storing processor-executable instructions; when the processor is configured to execute the instructions, causing the electronic device to implement the method of the first aspect described above.

[0033] Fourthly, this application provides a computer-readable storage medium comprising: computer software instructions; which, when executed in an electronic device, cause the electronic device to implement the method described in the first aspect.

[0034] Fifthly, this application provides a computer program product comprising a computer program; when the computer program is run in an electronic device, it causes the electronic device to implement the method described in the first aspect.

[0035] The beneficial effects of the second to fifth aspects mentioned above are described in the corresponding description of the first aspect and will not be repeated here. Attached Figure Description

[0036] Figure 1 This is a schematic diagram illustrating the application environment of a user risk determination method provided in an embodiment of this application. Figure 2 This application provides a schematic diagram of a user risk determination system architecture. Figure 3 A flowchart illustrating a user risk determination method provided in an embodiment of this application; Figure 4 This is a schematic diagram illustrating the principle of multidimensional feature information generation provided in the embodiments of this application; Figure 5 This is a schematic diagram of the cross-domain behavior association graph network structure provided in the embodiments of this application; Figure 6 This is a schematic diagram illustrating the composition of a user risk determination device provided in an embodiment of this application; Figure 7 This is a schematic diagram of the composition of an electronic device provided in an embodiment of this application. Detailed Implementation

[0037] The following is a detailed description, with reference to the accompanying drawings, of a user risk determination method, apparatus, device, and storage medium provided in this application.

[0038] In this article, the term "and / or" is merely a description of the relationship between related objects, indicating that there can be three relationships. For example, A and / or B can represent three situations: A exists alone, A and B exist simultaneously, and B exists alone.

[0039] The terms "first" and "second," etc., used in the specification and drawings of this application are used to distinguish different objects or to distinguish different treatments of the same object, rather than to describe a specific order of objects.

[0040] Furthermore, the terms "comprising" and "having," and any variations thereof, used in the description of this application are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or apparatus that includes a series of steps or units is not limited to the steps or units listed, but may optionally include other steps or units not listed, or may optionally include other steps or units inherent to such process, method, product, or apparatus.

[0041] It should be noted that in the embodiments of this application, the words "exemplary" or "for example" are used to indicate examples, illustrations, or explanations. Any embodiment or design scheme described as "exemplary" or "for example" in the embodiments of this application should not be construed as being more preferred or advantageous than other embodiments or design schemes. Specifically, the use of the words "exemplary" or "for example" is intended to present the relevant concepts in a specific manner.

[0042] To facilitate a clear description of the technical solutions of the embodiments of this application, the terms "first" and "second" are used in the embodiments of this application to distinguish the same or similar items with essentially the same function and effect. Those skilled in the art can understand that the terms "first" and "second" are not intended to limit the quantity or execution order.

[0043] In the description of this application, unless otherwise stated, "a plurality of" means two or more.

[0044] Frequent flyer programs are a core component of airline customer loyalty management, playing a crucial role in enhancing customer loyalty and optimizing operational efficiency. However, with the continuous surge in membership—some airlines now boasting over 100 million members—and the increasing complexity of membership benefits systems, fraudulent activities are becoming more professional, covert, and organized, posing a systemic risk to airlines' refined operations.

[0045] The aviation industry currently faces four major fraud scenarios, causing significant economic losses: First, flight delay fraud, where members fraudulently obtain mileage by forging delay certificates and repeatedly reporting delays for the same flight, resulting in an average annual loss of 110 million yuan for the industry; second, mileage points redemption fraud, where black market operators use methods such as bulk account registration and account theft to redeem mobile phones, gift cards, and other highly liquid non-aviation goods for resale, resulting in an average annual loss of 150 million yuan; third, mileage points redemption for air tickets, specifically including methods such as stealing mileage to redeem air tickets and then reselling them, exploiting account merging and mileage transfer loopholes to redeem air tickets in bulk, and forging identity information to redeem air tickets for others, resulting in an average annual loss of 80 million yuan; and fourth, account theft fraud, where phishing attacks, credential stuffing, and device hijacking are used to gain control of member accounts, providing support for other fraud scenarios, resulting in an average annual loss of 40 million yuan. These four scenarios combined result in an average annual loss of over 380 million yuan for the industry.

[0046] Faced with the aforementioned fraud threats, the frequent flyer member risk control system suffers from significant technical deficiencies. Risk identification is delayed, relying on manually preset "member suspiciousness index" rules, which cannot dynamically adapt to the iterative evolution of fraud patterns, such as new forgery techniques for false documents and cross-platform fraud methods. This results in a persistently high rate of missed detections for new types of fraud, often requiring rules to be updated only after losses occur—a typical "passive defense" model. The judgment logic is subjective; existing machine learning algorithms, such as logistic regression and traditional neural networks, can only uncover single-dimensional or simple combinations of features, making it difficult to capture coupled risks across scenarios and data domains. For example, fraudulent goods redemption involving "login from a different location + redemption during inactive periods + receiving goods via virtual operator numbers," and fraudulent ticket redemption involving "bulk account mileage transfers + short-term high-class ticket redemption + non-registered passenger travel," generally have an accuracy rate of less than 30% in identifying concealed fraud. Data collaboration is fragmented. Internal airline data, such as basic member information, travel records, and points accumulation, is isolated from external data, such as internet location information, third-party credit tags, and virtual operator blacklists. This data silo results in an incomplete risk view, hindering comprehensive and multi-dimensional risk perception. Engineering implementation is poorly adaptable. Existing algorithms generally suffer from an imbalance between accuracy and real-time performance. Traditional deep learning models often take over 500ms for inference per member when processing multi-dimensional heterogeneous risk control data, failing to support real-time monitoring of hundreds of millions of members. Furthermore, they lack self-evolution capabilities, requiring full retraining of the model after the emergence of new types of fraud, with iteration cycles lasting several weeks. Simultaneously, issues such as black-box decision-making and insufficient privacy protection further limit the effectiveness of engineering applications. These combined problems have led to an average annual increase of 15% in industry fraud losses.

[0047] To address the aforementioned technical problems, this application provides a method, apparatus, device, and storage medium for determining user risk. The approach involves acquiring user attribute data, user behavior record data, and at least one external data source, such as internet behavior data, credit data, or non-carrier data, to gather information related to user risk from multiple dimensions. After fusing and feature engineering the collected user data, multi-dimensional feature information is generated, transforming the original heterogeneous data into a unified risk representation. Risk transmission is enhanced based on a pre-defined risk transmission link library, which defines the correlation and transmission strength between different risk features and risk types, thus highlighting feature combinations closely related to the risk transmission link. A comprehensive risk index for the user is determined based on the enhanced risk feature information, ensuring that the final risk quantification result incorporates the correlation logic between features, thereby improving the accuracy of identifying complex and hidden risk patterns and achieving precise identification of user risk levels.

[0048] The embodiments provided in this application will now be described in detail with reference to the accompanying drawings.

[0049] The user risk determination method provided in this application can be applied to, for example... Figure 1 The application environment shown. For example... Figure 1 As shown, the application environment includes: For example, the first device can be a terminal device or a server, and the second device can be a server.

[0050] Terminal device 100 and server 101.

[0051] The terminal device 100 includes an application 102 that supports user risk determination functionality. The client of the application 102, which supports user risk determination functionality, is used in the terminal device 100 to visually demonstrate the risk determination process during the execution of the user risk determination method according to this embodiment.

[0052] This client provides a user interface, which can take the form of a World Wide Web (Web) page accessed through a browser or a native application that needs to be downloaded and installed. The terminal is specifically a user equipment (UE), which includes, but is not limited to, smartphones, tablets, laptops, desktop computers, Internet of Things (IoT) terminals, and Vehicle-to-Everything (V2X) terminals. The terminal accesses the access network via a wireless air interface and has the capability to carry voice services, data transmission services, and multimedia services. It can also enable direct communication between different terminals based on device-to-device (D2D) direct connection technology or V2X technology.

[0053] This client is used to receive users' risk assessment requests and display comprehensive risk indices or risk warning information to users.

[0054] In another example, the user risk determination method provided in this application can be applied to server 101. Server 101 runs an application 102 that supports user risk determination. This application is responsible for processing requests sent by clients and executing a user risk determination method that includes acquiring user data, fusing and feature engineering the user data to generate multi-dimensional feature information, enhancing risk transmission based on a risk transmission link library to obtain enhanced risk feature information, and determining the user's comprehensive risk index based on the enhanced risk feature information.

[0055] In one alternative embodiment, the terminal device 100 and the server 101 can be interconnected via a wired or wireless network.

[0056] Server 101 includes a first memory and a first processor. The first memory stores a user risk determination program; this user risk determination program is invoked and executed by the first processor to implement the user risk determination method provided in this application. The first memory may include, but is not limited to, the following: random access memory (RAM), read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), and electrically erasable programmable read-only memory (EEPROM). The first processor may consist of one or more integrated circuit chips. Optionally, the first processor may be a general-purpose processor, such as a central processing unit (CPU) or a network processor (NP). Optionally, the first processor can implement the user risk determination method provided in this application by running programs or code.

[0057] Database system 103 is deployed on a dedicated server to store user data, including user attribute data, user behavior record data, external data (internet behavior data, credit data, or non-carrier data), risk transmission link library, feature enhancement network parameters, and risk handling strategy execution logs. It can include various types of databases, such as relational databases and non-relational databases. Database system 103 can respond to events such as updates to user data, changes to the risk transmission link library, or adjustments to feature enhancement network parameters by synchronously updating or invalidating relevant data in the cache.

[0058] This application embodiment also provides a user risk determination system, which can be set up in... Figure 1 In the application environment shown, such as Figure 2 As shown, the user risk determination system may include: The cross-domain security fusion layer 201 is used to acquire user data, which includes user attribute data, user behavior record data, and external data associated with the user. External data includes at least one of internet behavior data, credit data, or non-carrier data. It is also used to perform secure fusion processing on data from different data sources.

[0059] The multi-dimensional risk feature mining layer 202 is used to fuse and feature-engineer user data to generate multi-dimensional feature information to characterize user risks. Specifically, it includes: extracting statistical features from time-series data in user data through multiple time windows to obtain time-series risk features; encoding and transforming structured data to obtain scenario risk features; embedding and representing unstructured data to obtain semantic risk features; fusing time-series risk features, scenario risk features, and semantic risk features to generate an initial risk feature set; and inputting the initial risk feature set into a feature enhancement network for processing to generate multi-dimensional feature information. The feature enhancement network is used to enhance the feature components related to abnormal risks in the initial risk feature set.

[0060] The risk association enhancement layer 203 is used to enhance the feature weights and risk transmission of multi-dimensional feature information based on a preset risk association graph or risk transmission link library, thereby obtaining enhanced risk feature information. The risk association graph or risk transmission link library defines the association relationship and transmission strength between different risk features and risk types. Specifically, it includes: matching a feature subset that matches at least one risk transmission link in the risk association graph or risk transmission link library from the multi-dimensional feature information, and enhancing the features in the feature subset according to the transmission strength corresponding to the matched risk transmission link.

[0061] The dynamic risk quantification layer 204 is used to determine the user's comprehensive risk index based on the enhanced risk feature information. Specifically, it includes: inputting the enhanced risk feature information into the trained risk index prediction model, and outputting the comprehensive risk index by the risk index prediction model. The risk index prediction model is a model trained based on historical user data and its corresponding risk loss labels.

[0062] The adaptive early warning decision layer 205 is used to execute corresponding risk management strategies based on a comprehensive risk index. Specifically, it includes: comparing the comprehensive risk index with multiple preset risk thresholds; if the comprehensive risk index exceeds a first risk threshold, generating and sending risk warning information; if the comprehensive risk index exceeds a second risk threshold higher than the first risk threshold, automatically triggering temporary restriction measures on the corresponding user account; and also used to obtain execution result feedback data of the risk management strategy, including false alarm confirmation information, missed alarm confirmation information and / or risk type confirmation information, and updating the transmission strength in the risk association graph or risk transmission link library and / or optimizing the parameters of the feature enhancement network based on the execution result feedback data.

[0063] Data storage device 206 is used to store user data, multi-dimensional feature information, risk correlation graphs or risk transmission link libraries, comprehensive risk indices, and feedback data on the execution results of risk management strategies.

[0064] Data processing node 207 is used to perform computational tasks in the multi-dimensional risk feature mining layer, risk correlation enhancement layer, dynamic risk quantification layer, and adaptive early warning decision layer.

[0065] Federated learning node 208 is used to update the transmission strength in the risk correlation graph or risk transmission link library and / or optimize the parameters of the feature enhancement network based on the execution result feedback data from multiple risk control platform terminals in a federated learning manner.

[0066] The risk control platform terminal 209 is used to display risk warning information to users or risk control personnel, receive feedback data on the execution results of risk handling strategies, and configure risk threshold parameters.

[0067] Network interface 210 is used to realize data communication between the cross-data source security fusion layer and external data sources, as well as information interaction between the adaptive early warning decision layer and the risk control platform terminal.

[0068] It should be noted that the system architecture described in the embodiments of this application is for the purpose of more clearly illustrating the technical solutions of the embodiments of this application, and does not constitute a limitation on the technical solutions provided in the embodiments of this application. As those skilled in the art will know, with the evolution of system architecture, the technical solutions provided in the embodiments of this application are also applicable to similar technical problems.

[0069] See Figure 3 This is a flowchart illustrating a user risk determination method provided in an embodiment of this application. Figure 3 As shown, the user risk determination method provided in this application can be implemented through the aforementioned server, specifically including the following steps S300~S303.

[0070] S300, the server obtains user data.

[0071] User data includes user attribute data, user behavior record data, and external data associated with the user. External data includes at least one of internet behavior data, credit data, or non-carrier data.

[0072] Users, such as airline members, can redeem points for air tickets, non-aviation merchandise (such as mobile phones and gift cards), or transfer miles. They can also use points to claim delay compensation after flight delays. These operations all fall under business scenarios that require risk detection.

[0073] User attribute data includes membership level, authentication status, and registration time. User behavior logs are dynamic operation logs generated by user actions, such as login time, points redemption records, and travel order records. External data refers to information from external third parties, used to supplement the dimensions of user risk profiles. This includes internet behavior data such as IP address location or web browsing history; credit data such as third-party credit scores or historical default records; and non-carrier data such as virtual operator blacklists or abnormal e-commerce delivery address markers. These external data, along with internal user attribute and behavior log data, are independent yet complementary, collectively forming a complete multi-source input. The server, through a data interface, reads the internal database in real time when a user initiates an action, and simultaneously initiates encrypted queries to external data sources through a security gateway to obtain the aforementioned data types, providing foundational information for subsequent risk identification.

[0074] S301. The server performs fusion and feature engineering on user data to generate multi-dimensional feature information to characterize user risk.

[0075] Fusion and feature engineering refers to the process of transforming multi-source, heterogeneous, and differently formatted raw user data into a unified, high-dimensional feature vector—i.e., multi-dimensional feature information—that reflects risk-related patterns through a series of transformations, alignments, and combinations. User attribute data, user behavior record data, and external data differ in format: user attribute data is structured discrete values, user behavior record data is a time-series sequence, some information in external data (such as credit scores) is numerical, and IP addresses in internet behavior data are categorical or textual. The server first performs appropriate feature extraction operations on different data types, such as calculating statistics within a sliding window from time-series behavior, performing encoding mapping from structured attributes, and extracting vectorized representations from external text or image information. Subsequently, the server concatenates or weights these heterogeneous features along the feature dimension to form a unified feature vector. During the fusion process, the server also performs cross-data source alignment operations to ensure that features from different sources for the same user correctly correspond along the sample dimension. The multi-dimensional feature information generated after fusion and feature engineering is then presented. A numerically normalized real-valued vector preserves the effective signals in the original data while removing redundancy and noise, providing a standardized input for subsequent risk correlation enhancement and risk index calculation.

[0076] S302. The server enhances the risk transmission of multi-dimensional feature information based on a preset risk transmission link library to obtain enhanced risk feature information.

[0077] The risk transmission link library defines the correlation and transmission strength between different risk features and risk types. A risk transmission link describes how multiple risk features combine to ultimately form a specific fraud type; each link identifies the evolutionary chain from initial risk features to end-user risk behavior. The server matches multi-dimensional feature information with the risk transmission link library, identifies feature combinations that hit the links, and enhances these combinations through risk transmission link enhancement. This strengthens the feature signals closely related to known risk patterns in the vector representation while suppressing irrelevant noise. Enhanced risk feature information is then generated after risk transmission enhancement. This information, while retaining the original feature information, highlights feature combinations closely related to known risk patterns, enabling subsequent risk quantification steps to more accurately focus on risk features that truly have early warning value.

[0078] S303. The server determines the user's comprehensive risk index based on the enhanced risk characteristic information.

[0079] The comprehensive risk index is a quantitative score normalized to a continuous range of 0 to 100, used to characterize the overall risk level inherent in a user's current behavior or account status, where 0 indicates no risk or extremely low risk, and 100 indicates the highest risk level. Enhanced risk feature information is the result of weighting and adjusting the original multi-dimensional feature information. The magnitude of each feature component in this information reflects the strength of different risk signals. The comprehensive risk index aggregates these feature components into a single value through a preset mapping rule, achieving an overall quantification of the user's risk level. The server performs a conversion operation from a high-dimensional feature space to a one-dimensional risk score, fusing multiple risk signals in the enhanced risk feature information into an intuitive and comparable score. This score preserves the relative importance differences between different risk dimensions and facilitates subsequent tiered warnings or automatic handling operations based on preset thresholds.

[0080] In this embodiment, by acquiring at least one external data source, including user attribute data, user behavior record data, internet behavior data, credit data, or non-carrier data, information related to user risk can be collected from multiple dimensions. After fusing and feature engineering the collected user data, multi-dimensional feature information is generated, transforming the original heterogeneous data into a unified risk representation. Risk transmission is enhanced based on a pre-defined risk transmission link library, which defines the correlation and transmission strength between different risk features and risk types, thus highlighting feature combinations closely related to the risk transmission link. The user's comprehensive risk index is determined based on the enhanced risk feature information, ensuring that the final risk quantification result incorporates the correlation logic between features, thereby improving the accuracy of identifying complex and hidden risk patterns and achieving precise identification of user risk levels.

[0081] In one embodiment, step S301 includes: S3011. Perform multi-time-window statistical feature extraction on the time-series data in the user data to obtain time-series risk features.

[0082] The server first performs anonymization on user data, processing it differently based on different privacy levels. For core privacy data, including user ID numbers and transaction passwords, the Paillier homomorphic encryption algorithm is used to ensure that the encrypted data can still participate in subsequent calculations without revealing the plaintext, thus protecting data privacy while preserving data usability. For sensitive data, including travel records and points transaction history, differential privacy protection is implemented by adding controlled Laplace noise. This introduces controlled perturbations into the data to mask individual information while retaining overall statistical characteristics. The noise intensity ε is a perturbation amplitude control parameter, ranging from 0.01 to 0.05; the smaller the ε, the lower the data distortion. For publicly available data, including flight status and industry blacklists, the original format is directly retained. Through this layered anonymization, data usability is preserved while meeting personal information protection regulations, providing privacy-compliant input for subsequent cross-domain data fusion and feature mining.

[0083] Next, the server employs a federated feature disentangling fusion (FFDT) mechanism. Each data holder extracts features from their local data and encrypts them. The encrypted feature vectors are then transmitted to the federated learning nodes via a network interface. A secure multi-party computation protocol is used to securely align the feature dimensions of internal and external data, achieving encrypted overlay and fusion of the feature vectors to generate fused user data. This fusion process achieves cross-institutional feature reuse without removing the original data from the database, satisfying privacy compliance requirements while integrating multi-source risk information, providing a complete data foundation for the subsequent generation of feature tensors containing full-domain risk dimensions. The federated disentangling fusion is shown in formula (1): (1) In the formula: A structured data vector describing user behavior, with dimension D=512; De-identified risk feature vectors provided to external organizations; For Paillier encryption / decryption functions (physical function: to perform data encryption and decryption). This is a cryptographic feature fusion operator based on a secret sharing protocol (physical function: to realize feature superposition in the encrypted state and output fused features).

[0084] The server uses a sliding window mechanism to traverse the merged user data, performing statistics for each window and combining the statistical results of all windows in chronological order into a vector form to form time-series risk features. Time-series data refers to a sequence of user behavior records with timestamps, such as login time, points change records, redemption operation time, and travel order generation time. These data are arranged in chronological order, reflecting the changing patterns of user behavior on the time axis. Multiple time windows refer to dividing the time axis into multiple time intervals of different lengths or offsets, such as the last 1-hour window, the last 24-hour window, the last 7-day window, the last 30-day window, and continuous windows with a sliding step of 1 day. Each window covers a subsequence of behavior within a certain period. Statistical feature extraction involves performing mathematical statistical operations on the time-series data within each time window to calculate quantitative indicators that can characterize the behavioral patterns within that window, including behavior frequency (the total number of operations occurring within the window), mean time interval (the average time difference between adjacent operations), behavioral mutation value (the magnitude of the difference in frequency or interval between the current window and the previous window), periodicity intensity (whether the behavior exhibits a fixed periodic pattern), and peak period distribution (the time periods in which operations are concentrated). This feature captures the dynamic change patterns of user behavior over time, especially abnormal fluctuations that deviate from the historical normal range (such as sudden high-frequency operations after a long period of silence), providing a basic input for subsequent identification of time-series risk behaviors.

[0085] In one possible implementation, secure multi-party computation (MPC) and secure hash algorithm (SHA-256) can be used as an alternative to the FFDT desensitization method.

[0086] S3012. Encode and transform the structured data in the user data to obtain scenario risk characteristics.

[0087] Structured data refers to information with a predefined data model or fixed field format, such as membership level, authentication status, and registration channel in user attributes, and shipping address, device information, and redeemed product category in user behavior records. This data is typically stored in discrete categories, ordered levels, or fixed-format text, and cannot be directly used for numerical calculations. Encoding conversion is the process of converting this non-numerical categorical or textual data into numerical vectors, allowing the converted numerical form to be processed by subsequent mathematical models. The server uses one-hot encoding to convert the discrete categorical fields in the structured data: for a categorical variable with N possible values, the server creates a binary vector of length N, where only one position is 1 (representing the current value), and the rest are 0. For example, the member quantity variable N represents the scale of members to be detected, adapting to values ​​in the hundreds of millions. All numerical vectors transformed by one-hot encoding are concatenated in field order to form a fixed-dimensional feature vector, which is the scenario risk feature. Scenario risk features transform the specific business scenario and contextual attributes of user operations into mathematical representations, enabling the model to distinguish between normal and abnormal behaviors in different scenarios. For example, the risk benchmark for the same user differs under different membership levels, thus providing a structured input basis for scenario-adaptive risk identification.

[0088] S3013. Embed unstructured data in user data to obtain semantic risk features.

[0089] Embedding representation is the process of converting unstructured data into numerical vector form. For unstructured data, including delay certificate images and declaration texts, a convolutional neural network (CNN) model is used to extract image texture features, and term frequency-inverse document frequency (TF-IDF) is used to extract text keyword features, which are then converted into vector form. The server fuses the image texture feature vectors and the text keyword feature vectors to obtain semantic risk features. Semantic risk features transform the visual and textual information in unstructured data into a unified numerical representation, providing data from image and text sources for subsequent risk identification.

[0090] S3014. Integrate temporal risk features, scenario risk features, and semantic risk features to generate an initial risk feature set.

[0091] For each member within each time window, the server will sequentially concatenate the time-series risk features, scenario risk features, and semantic risk features corresponding to that member and that time window into an initial risk feature set. Where N is the number of users to be detected, T is the number of time windows, and D is the number of features representing a single member in a single time window. The default value of D is 512, which provides a structured input with a unified format for generating multi-dimensional feature information in the future.

[0092] S3015. Input the initial risk feature set into the feature enhancement network for processing to generate multidimensional feature information.

[0093] Feature enhancement networks are used to amplify the features related to anomalous risks in an initial risk feature set. A feature enhancement network is a pre-built model whose function is to enhance the features related to anomalous risks in the initial risk feature set. The feature enhancement network performs multi-dimensional risk feature extraction on the initial risk feature set to obtain multiple intermediate risk features. The feature enhancement network fuses these multiple intermediate risk feature representations, amplifies the anomalous components in the fusion result, and then performs a weighted fusion of the enhanced features with the multiple intermediate risk feature representations to generate multi-dimensional feature information. This multi-dimensional feature information is used for subsequent risk transmission enhancement and comprehensive risk index calculation.

[0094] In one embodiment, the feature enhancement network includes a temporal attention module, a scene-adaptive risk convolution module, a cross-domain behavior association graph module, and a feature modulation module.

[0095] like Figure 4As shown, the temporal attention module is used to capture abrupt change patterns of behavior along the time axis and dependencies over long time spans from the initial risk feature set. The scenario-adaptive risk convolution module is used to extract local risk patterns associated with different business operation scenarios from the initial risk feature set. The cross-domain behavior association graph module is used to construct an association graph containing behavior nodes, attribute nodes, and risk nodes, and to mine cross-domain coupling features across data sources based on the association graph.

[0096] The temporal attention module, scene-adaptive risk convolution module, and cross-domain behavior association graph module process the initial risk feature set in parallel, outputting intermediate risk features such as temporal risk features, scene risk features, and cross-domain coupling features. The feature modulation module receives the temporal risk features, scene risk features, and cross-domain coupling features. The anomaly enhancement module (AFE) enhances the anomalous components deviating from the normal distribution among the three types of features received, and then fuses the three types of features with the anomalously enhanced features to generate multi-dimensional feature information. Finally, the server outputs the multi-dimensional feature information to the risk association enhancement layer.

[0097] In one possible implementation, step S3015 includes: S30151. The server extracts temporal mutation features from the initial risk feature set through the temporal attention module.

[0098] The temporal attention module extracts temporal mutation features through a temporal pulse attention network (TPAN). The TPAN is a deep learning network used to capture mutation patterns and long-range dependencies in user behavior over time. Its core mechanism includes attention weight calculation and temporal differential encoding. Attention weight calculation compares the feature vector of each time window in the risk feature tensor with the user's historical behavior benchmark. An exponential function amplifies the difference between the current behavior and the historical benchmark, thus generating an attention weight for each time window. This weight quantifies the anomalous significance of the behavior within that time window, enabling the model to focus on windows of behavioral mutation, such as frequent flight delay reports by low-frequency members or sudden large-scale point redemptions by dormant accounts. The processing by the TPAN is shown in formula (2): (2) In the formula: Let be the attention weight for the t-th time window, used to quantify the degree of abnormality in the behavior of that window. The higher the weight, the more significant the abnormality. The total weight is 1. Let be the feature vector of the t-th window; This is a vector of the average values ​​of the previous 90 days. The differences are amplified by an exponential function to ensure that abrupt changes receive more attention. It serves as a benchmark for members' historical normal behavior and is used to determine whether current behavior has changed.

[0099] Temporal differential encoding calculates the difference between feature vectors of adjacent time windows and introduces a time decay coefficient to give higher weight to recent behaviors, thereby capturing the continuous magnitude of behavior changes in the short term, such as frequent point transfers or drastic changes in login location within a short period. The temporal spike attention network combines the attention weights with the differentially encoded features, outputting temporal abrupt change features that reflect the intensity of behavioral abrupt changes and long-term dependencies. These temporal abrupt change features provide temporal-dimensional risk information for subsequent processing, helping to identify user risk behaviors with temporal anomalies. The final output is a global temporal abrupt change risk feature. The timing differential coding is shown in formula (3): (3) Temporal difference features are the behavioral differences between the current window and the previous window, used to quantify the magnitude of behavioral abrupt changes. =0.85 is a time decay coefficient, which gives higher weight to recent behavior, consistent with the characteristic of short-term outbreaks of user risky behavior.

[0100] In one possible implementation, the temporal spike attention network method can be replaced by a gated recurrent unit (GRU) combined with an attention method, without requiring graphics processing unit (GPU) acceleration.

[0101] S30152. Extract scene convolution features from the initial risk feature set through the scene adaptive risk convolution module.

[0102] Scene-adaptive risk convolution (SARC) is a feature extraction network that aims to activate corresponding convolutional kernel groups based on the specific scenario of a user's current operation, encoding the scenario's inherent risk rules as bias terms in the convolutional kernels. The SARC module first identifies the business scenario type corresponding to the risky operation. For example, business scenario types may include flight delay reporting, points redemption for goods, and points redemption for airline tickets. For flight delay reporting scenarios, such as points redemption for airline tickets, the activated convolutional kernel groups include ticket validity kernels, cabin class kernels, mileage transfer kernels, and passenger information kernels, used to capture user risk behaviors such as short-term high-class ticket redemption, mileage transfer across accounts, and redeeming tickets for others. The server encodes the risk rules corresponding to each scenario, such as short-term high-class ticket redemption and multiple accounts associated with the same passenger, into the bias terms of the corresponding convolutional kernels, enabling the convolutional kernels to actively strengthen feature signals that conform to the risk rules when extracting scenario convolutional features. The kernel size *k* represents the range of local feature extraction. In the airline ticket redemption scenario, *k*=3, suitable for the three-part feature extraction of "mileage transfer - cabin class - passenger information". The bias term *b* is the rule enhancement coefficient, corresponding to the weight of different fraud rules, with a value ranging from 0.1 to 0.3. The higher the rule confidence, the larger *b* becomes. The final output is the scene convolutional feature. The scenario-adaptive risk convolution outputs scenario-specific enhanced scenario convolution features, which focus on whether the user's behavior in the business scenario conforms to the inherent fraud pattern of that scenario.

[0103] S30153. Construct a cross-domain behavior association graph containing behavior nodes, attribute nodes, and risk nodes through the cross-domain behavior association graph module, and extract cross-domain coupling features from the initial risk feature set based on the association graph.

[0104] Cross-domain behavior association graph network (CDAGN) is a neural network model that mines cross-domain coupling relationships of member behaviors based on graph structures. It constructs an association graph from various user behaviors, attributes, and risk factors, and uses graph convolution operations to extract high-order association features between nodes. The server first constructs the association graph. The association graph consists of a node set V, association edges E, and association strength weights W. The node set includes three categories: behavioral nodes, attribute nodes, and risk nodes. Behavioral nodes correspond to specific user actions, including login from a different location, mileage transfer, points redemption, and flight delay reporting. Attribute nodes correspond to inherent user attributes, including membership level, account registration duration, passenger authentication status, and device fingerprint type. Risk nodes correspond to known risk type labels, including points-for-ticket risk labels, merchandise redemption risk labels, flight delay risk labels, and account theft labels. Association edges represent the logical relationships between nodes; for example, there is an association edge between the login from a different location behavior node and the points redemption behavior node, and between the mileage transfer behavior node and the points-for-ticket fraud risk node. The association strength weight W quantifies the tightness of the association between nodes, based on the frequency of simultaneous occurrence of nodes in a historical fraud case database. The weight ranges from 0 to 1; a higher weight indicates a greater likelihood of fraud propagation paths between nodes. After constructing the association graph, graph convolution operations are performed on it. Cross-domain coupling features are also included. As shown in formula (4): (4) This is a normalized adjacency matrix used to eliminate the influence of node degree differences on the calculation results. This is the normalized feature matrix. The convolution weights are the transformation coefficients of the node features. This is a bias term. The ReLU activation function is used to introduce non-linear features and improve the model's expressive power.

[0105] After graph convolution operations, the cross-domain behavior association graph outputs cross-domain coupling features that reflect the deep coupling relationships between behavior nodes, attribute nodes, and risk nodes. This feature reveals hidden fraud patterns that cannot be detected by single-dimensional analysis, such as the correlation strength of each link in a complete fraud chain involving bulk new account registration, mileage transfer, short-term ticket redemption, and non-personalized passenger travel. It provides cross-domain feature input for subsequent risk transmission path matching and risk quantification.

[0106] In one possible implementation, a heterogeneous graph attention network (HAN) can be used to replace the cross-domain behavioral association graph. This adapts to multiple types of cross-data sources (such as newly added social relationship data), provides more comprehensive feature capture dimensions, and does not change the core logic of 3D feature mining.

[0107] In one possible implementation, such as Figure 5As shown, taking frequent flyer member risk control as an application scenario, the pre-defined association graph can be modeled using a graph structure G=(V,E,W) to address potential abnormal behaviors that members may exhibit when using points to redeem tickets, report flight delays, or transfer mileage. Here, V is a set of nodes, containing three types: behavioral nodes, attribute nodes, and risk nodes. Behavioral nodes specifically include login from a different location, mileage transfer, batch new account registration, short-term ticket redemption, and flight delay reporting; attribute nodes specifically include member level, device fingerprint, passenger authentication status, and delivery address consistency; risk nodes specifically include points-based ticket risk events and flight delay risk events. E is a set of association edges used to connect logically related nodes, such as an association edge between the login from a different location node and the mileage transfer node, or between the batch new account registration node and the short-term ticket redemption node. W is the association strength weight, used to quantify the tightness of the association between two nodes. The weight ranges from 0 to 1, with higher values ​​indicating a greater probability of both nodes appearing together in historical risk cases or a stronger transmission relationship. For example, the weight between mileage transfer and the risk of frequent mileage tickets is 0.92, indicating a high correlation between frequent mileage transfer and the risk of frequent mileage tickets; the weight between login from a different location and flight delay reporting is 0.85, reflecting a high probability of anomalies in reporting flight delays after login from a different location; and the weight between passenger consistency and the risk of frequent mileage tickets is 0.95, indicating that inconsistent passenger information is a key risk signal in the frequent mileage ticket scenario. Through this graph structure, the server can organize isolated behavioral nodes and attribute nodes into risk transmission links according to their associated edges and weights. This allows it to match the links corresponding to the member's current characteristics in subsequent processing and strengthen the corresponding characteristics based on their weights.

[0108] S30154. The server uses a feature modulation module to fuse temporal mutation features, scene convolution features, and cross-domain coupling features, and enhances the abnormal components in the fused features. Then, the enhanced features are weighted and fused with the temporal mutation features, scene convolution features, and cross-domain coupling features to generate multi-dimensional feature information.

[0109] Anomaly enhancement features are features obtained by amplifying high-risk anomaly signals. These features are used to improve the identification of covert user risky behaviors and prevent weak but crucial anomaly information from being overwhelmed by normal behavioral features. The server's anomaly enhancement module first uses the Isolation Forest algorithm to perform anomaly detection on the input temporal features, scene features, and cross-domain features, calculating anomaly scores for each feature dimension based on its deviation from the overall distribution. The anomaly score represents the degree to which a feature deviates from the normal distribution, with a value of 0-1. A score ≥0.7 is considered a high-risk anomaly.

[0110] The Isolation Forest algorithm constructs multiple isolated trees by randomly partitioning the feature space. Outliers receive higher anomaly scores due to their shorter path lengths. After the server obtains the anomaly scores, it performs adaptive enhancement processing on the original features. (Anomaly Enhancement Features) As shown in formula (5): (5) In the formula: variables The feature splicing result is the original fused feature without enhancement, to avoid hidden abnormal features being masked by normal features.

[0111] The anomaly score ranges from 0 to 1, with higher scores indicating greater enhancement. This process significantly amplifies the values ​​of the anomaly feature dimension, while the values ​​of the normal feature dimension remain largely unchanged. The server outputs the enhanced anomaly feature, which retains all the information from the original multidimensional risk features while highlighting the feature components with high anomaly risk, providing a more discriminative input for subsequent feature fusion and risk path matching.

[0112] The server first calculates the mutual information value between each feature dimension and the historical risk label in the temporal mutation feature, scene convolution feature and cross-domain coupling feature. The mutual information value is used to quantify the correlation strength between the feature and fraud. The higher the mutual information value, the greater the contribution of the feature to fraud identification.

[0113] The server assigns corresponding fusion weights based on the proportion of mutual information values ​​for each feature. The fusion weights satisfy The server multiplies the temporal features, scene features, cross-domain features, and anomaly enhancement features by their respective fusion weights, and then sums the weighted features element-wise to obtain multidimensional feature information. The calculation formula (6) is shown below: (6) This multidimensional feature information integrates behavioral mutation information from the time-series dimension, business rule information from the scenario dimension, correlation and coupling information from the cross-data source dimension, and high-risk signal amplification information from the anomaly enhancement dimension, forming a comprehensive feature representation with low redundancy and high expressiveness, providing a structurally complete and information-rich input for subsequent risk transmission path matching.

[0114] In this embodiment, statistical feature extraction of time-series data from user data across multiple time windows captures the dynamic changes in user behavior over time, forming time-series risk features. Structured data is encoded and converted, transforming discrete or categorical data into numerical representations to obtain scenario risk features. Unstructured data is embedded and represented, converting irregular data such as text and images into semantic vectors to obtain semantic risk features. These three types of initial risk features are fused to generate an initial risk feature set, which is then input into a feature enhancement network. This network specifically enhances the feature components related to abnormal risks within the initial risk feature set, amplifying hidden abnormal signals and suppressing interference from redundant or irrelevant features. This generates more discriminative multidimensional feature information, improving the sensitivity and robustness of subsequent risk assessment.

[0115] In the feature enhancement network, the temporal attention module extracts and strengthens periodic abnormal patterns in the temporal mutation features from the initial risk feature set, giving higher attention to sudden abnormal behaviors; the scene-adaptive risk convolution module extracts scene convolution features, enabling targeted expression of local risk patterns under different business scenarios; the cross-domain behavior association graph module constructs an association graph containing behavior nodes, attribute nodes, and risk nodes, and extracts cross-domain coupling features based on this association graph, which can explore nonlinear relationships across data domains. The feature modulation module fuses the temporal mutation features, scene convolution features, and cross-domain coupling features, and enhances the abnormal components in the fused features. Then, the enhanced features are weighted and fused with the aforementioned three types of features. The resulting multi-dimensional feature information not only retains the original risk signals of each dimension but also strengthens the abnormal patterns, while achieving the organic integration of multi-source features, thereby significantly improving the ability to identify complex and covert fraudulent behaviors.

[0116] In one embodiment, step S302 includes: S3021. The server matches a subset of features from the multi-dimensional feature information that matches at least one risk transmission link in the risk transmission link library.

[0117] The risk transmission link library is built upon historical risk data. For example, historical risk data could be records of user behavior that have been confirmed as fraudulent by an airline. Each record contains a complete sequence of user behavior characteristics before and after the fraud occurred, the timeline of operations, the business scenarios involved, and the ultimately confirmed risk type. The risk transmission link is extracted using the Apriori association rule algorithm to construct the risk transmission link library.

[0118] Risk transmission chain This includes the correspondence between risk characteristics and risk types. Risk characteristics are the specific behavioral manifestations of each node in the path, while risk types are the final fraud categories corresponding to that path, such as flight delay fraud, points redemption for goods fraud, points redemption for airline tickets fraud, or account theft fraud. Transmission strength. This is a statistical value representing the frequency with which a specific risk transmission link matches real fraud cases in historical data. The value ranges from 0 to 1, with higher strength indicating a stronger association between the link and the risk types corresponding to multiple risk characteristics. The server processes massive amounts of historical fraud data using association rule mining algorithms, extracting frequently occurring feature combination sequences and calculating their confidence levels to construct a risk transmission link library, providing a benchmark for real-time risk transmission link matching.

[0119] The server uses the risk transmission link library to match a subset of features from multi-dimensional feature information that are compatible with the risk transmission link.

[0120] S3022. Based on the transmission strength corresponding to the matched risk transmission link, the features in the feature subset are enhanced to generate enhanced risk feature information.

[0121] Enhancement of features within a feature subset involves strengthening the combination of features belonging to that path within the multidimensional feature information. Specifically, this is achieved by increasing the numerical value or weight proportion of these feature subsets, thus making the risk values ​​conforming to typical risk transmission chains more prominent. When multiple target paths are matched, the server combines the transmission probabilities of each path and performs superimposed enhancement to ensure that high-risk features with overlapping paths receive a higher enhancement magnitude. The enhanced risk feature information... The calculation is shown in formula (7): (7) In the formula: The set of links that were successfully matched. =0.1-0.5 is the link enhancement coefficient used to control the enhancement level and avoid over-enhancement that could lead to misjudgment. This represents the path transmission strength. After generating enhanced multi-dimensional feature information, the originally isolated and scattered temporal, scene, and cross-domain features are integrated into a combined representation with a clear risk transmission logic, effectively improving the identification of covert and organized user risk behaviors and providing more accurate input for the subsequent generation of a comprehensive risk index.

[0122] In this embodiment, a subset of features matching at least one risk transmission link in the risk transmission link library is selected from multi-dimensional feature information. This allows for the rapid identification of feature combinations in the current user behavior that are related to known fraud patterns. Based on the transmission strength corresponding to the matched risk transmission link, the features in this subset are enhanced, giving higher expression weights to feature signals that conform to historical fraud transmission paths. This selective feature enhancement method embeds prior risk knowledge into the feature processing flow, making the enhanced risk feature information closer to the behavioral logic of real fraud, thereby improving the accuracy of risk identification.

[0123] In one embodiment, step S303 includes: S3031. The server inputs the enhanced risk feature information into the trained risk index prediction model, and the risk index prediction model outputs the comprehensive risk index.

[0124] The risk index prediction model is trained based on historical user data and its corresponding risk loss labels. The server inputs the enhanced risk feature information into the trained risk index prediction model, decomposes it into three types of risk features, and calculates the corresponding sub-indices for each.

[0125] Operational Risk Sub-index This corresponds to the risk level of users' actions in areas such as logging into the system, reporting flight delays, and redeeming points, and is used to quantify the degree of abnormality in these actions. Identity Risk Sub-Index Corresponding to the user's identity attribute dimension, this includes risk levels related to the completeness of basic user information, the consistency of authentication status, and the authenticity of passenger information, used to quantify the credibility of identity attributes. Related Risk Sub-Indices Corresponding to the dimension of user relationships across different data sources, including mileage transfer relationships between accounts, device sharing relationships, and shipping address association relationships, the risk level is used to quantify the degree of anomalies in cross-domain associations. The server extracts quantified risk sub-indices from three dimensions—operational behavior, identity attributes, and cross-domain associations—by dimensionally splitting and independently calculating the enhanced risk features. These three sub-indices are independent of each other but collectively cover the main sources of user risky behavior.

[0126] The risk index prediction model then determines the weights of the operational risk sub-index, identity risk sub-index, and associated risk sub-index based on historical risk loss data. Historical risk loss data is statistical information on the actual economic losses caused by different risk types in the recent period. The validity period can be 30 days, such as the loss amount for flight delay risk within 30 days, the loss amount for redeeming goods with points within 30 days, the loss amount for redeeming air tickets with points within 30 days, and the loss amount for account theft risk within 30 days. This loss data can reflect the actual degree of harm caused to the airline by various user risk behaviors. By classifying, summarizing, and calculating the historical risk loss data, the proportion of loss amount related to operational risk, identity risk, and associated risk is calculated respectively, and these loss proportions are used as the basis for determining the weights of the three sub-indices. As shown in the sub-index weight formula (8): (8) In the formula, To address the cumulative losses over the past 30 days in response to the risks, For the corresponding sub-index weights, satisfying .

[0127] The higher the amount of loss, the higher the weight of the risk dimension, so that the user's comprehensive risk index can dynamically adapt to the actual distribution of recent risk losses, prioritize the prevention and control of the risk type that causes the greatest economic loss, and improve the allocation efficiency of risk control resources and the actual effect of risk prevention and control.

[0128] The operational risk sub-index, identity risk sub-index, and association risk sub-index quantify the user's risk level from three dimensions: operational behavior, identity attributes, and cross-domain association, respectively. The weights are dynamically allocated based on historical risk loss data, reflecting the actual contribution of different risk dimensions to the overall risk loss in the current period. The risk index prediction model multiplies each sub-index by its corresponding weight, and then adds the three products to calculate a comprehensive weighted risk index. This weighted risk index integrates risk information from three dimensions and highlights the impact of high-risk types with a loss-oriented approach, providing a basic quantitative result for subsequent refined correction based on the user's individual compliance history. The weighted risk index is shown in formula (9): (9) In the formula: As a weighted risk index, it achieves loss-driven weighted fusion of three sub-indices: operation, identity, and association, without considering individual user compliance differences.

[0129] User credibility score is a quantitative indicator used to measure the compliance level of a user's historical behavior. It is calculated based on information such as the user's account usage records, transaction behavior compliance, and identity authentication completeness over the past year. The score ranges from 0 to 1, with a higher score indicating more compliant and credible historical behavior. The server combines a weighted risk index with the credibility score, adjusting the risk index to lower the risk index of high-credibility users while retaining or appropriately increasing the risk index of low-credibility users. This reduces misjudgments of current abnormal behavior due to a user's good historical reputation, resulting in a more accurate comprehensive risk index that reflects the user's current true risk probability. The comprehensive user risk index is a value normalized to 0 to 100, used to intuitively represent the user's risk level, allowing subsequent early warning decisions to classify and handle risks according to thresholds. The calculation is shown in formula (10): (10) In the formula, Assign a credibility score to the user. This is the calibration coefficient.

[0130] In one possible implementation, the sub-index weighting formula can be replaced by a two-factor formula for loss and incidence: ,

[0131] It is suitable for scenarios with small loss fluctuations but large occurrence rate fluctuations; the feedback loop can be replaced by hourly batch iterations and manual rule updates, resulting in lower engineering maintenance costs while still ensuring the model's iterative optimization capabilities.

[0132] In one possible implementation, the risk index prediction model assumes that operational risk, identity risk, and association risk are independent of each other, and that their triggering logics do not directly overlap. The correlation coefficients of the three types of risks are <0.2, satisfying the independence assumption.

[0133] All three risk sub-indices follow a normal distribution: , , ,in The mean of the sub-indices. For variance; The risk index is positively correlated with risk loss, meaning that the higher the risk index, the greater the loss caused by the risky behavior, which is consistent with the actual scenario of high risk and high loss.

[0134] The core objective of the risk index prediction model is to minimize the risk identification misjudgment rate (including misjudging normal users as risky users and vice versa), that is, to maximize the risk index differentiation between risky users and normal users.

[0135] Objective function:

[0136] Physical meaning of the variable: The probability that a high-risk user is mistakenly identified as a normal user (false positive rate); Loss due to missed detection (physical meaning: the average loss caused by a single missed detection risk); The probability that a normal user is mistakenly identified as a risk (false positive rate); Losses due to misjudgment (physical meaning: the amount of user complaints and reputational damage caused by misjudgment).

[0137] Minimizing the false positive rate is equivalent to maximizing the posterior probability. and The difference is used to solve for the initial weights by combining maximum likelihood estimation (MLE): First, based on one year of historical risk data, the mean of the three types of risk sub-indices is calculated. and variance As an estimate of the parameters of the normal distribution, the goodness of fit is above 0.88; Secondly, construct the likelihood function: ,in The sample labels are 1 for fraud and 0 for normal. The correlation between quantitative risk indices and risk labels; Next, take the logarithm and derivative of the likelihood function, set the derivative to 0, and solve for the initial weights. (satisfy ), adapted to the characteristics where operational risks account for the highest proportion in aviation scenarios; Finally, real-time loss data is introduced to correct the initial weights: the loss weight factor is defined as follows: ( (To correspond to the cumulative losses over the past 30 days), the final weight is a weighted fusion of the initial weight and the loss weight factor: (Physical meaning: 60% of the weights are derived from historical data training to ensure stability, and 40% are derived from real-time loss to ensure dynamic adaptability.)

[0138] In this embodiment, enhanced risk feature information is input into a trained risk index prediction model, which is trained based on historical user data and its corresponding risk loss labels. By learning the mapping relationship between risk features and actual losses in historical data, the model can perform nonlinear transformations and regressions on the input enhanced risk feature information, outputting a comprehensive risk index. Because risk loss labels are introduced during training, the output comprehensive risk index not only reflects the probability of risk existence but also quantifies the expected level of loss that the risk may cause, achieving accurate risk pricing and comparable ranking, facilitating differentiated risk management measures based on the index magnitude.

[0139] In one embodiment, the user risk determination method further includes: S304. The server executes corresponding risk management strategies based on the comprehensive risk index.

[0140] A risk management strategy is a set of predefined actions to implement differentiated control measures based on a user's risk level. Specific actions may include issuing risk alerts, triggering manual review, restricting account functions, or suspending specific operational permissions. The comprehensive risk index, as a quantified risk measure, directly determines the selection and intensity of the risk management strategy. After obtaining the comprehensive risk index, the server compares it with multiple internally stored risk level judgment criteria, matches the corresponding risk management strategy based on the comparison results, and automatically triggers the actions specified in that strategy. By implementing risk management strategies, the system can promptly block risky behaviors and reduce potential losses when high-risk users are identified, while minimizing unnecessary interference for low-risk users, achieving a balance between risk control and user experience.

[0141] In one possible implementation, step S304 includes: S3041. The server compares the comprehensive risk index with multiple preset risk thresholds.

[0142] The preset risk thresholds are based on historical risk identification data from the past 90 days. The Otsu algorithm adaptively calculates the optimal risk index grading thresholds, dynamically dividing the risk index into three levels: high risk, medium risk, and low risk. For example, high risk corresponds to a score of 70 or above, medium risk to 40 to 70, and low risk to below 40. After obtaining the current user's comprehensive risk index, the server first compares it with multiple preset risk thresholds to determine the risk level to which the index belongs.

[0143] S3042. If the comprehensive risk index exceeds the first risk threshold, the server will generate and send a risk warning message.

[0144] For example, if the first risk threshold is 40 points, and the comprehensive risk index exceeds 40 points, it indicates that the user's behavior is of medium risk. A corresponding warning message will be generated according to the preset handling strategy. The medium-risk warning message will trigger enhanced control or manual review. If the comprehensive risk index is below the first threshold, it indicates that the comprehensive risk index is low risk, and only log entries will be made or no action will be taken.

[0145] S3043. If the comprehensive risk index exceeds the second risk threshold which is higher than the first risk threshold, the server will automatically trigger temporary restrictions on the corresponding user account.

[0146] For example, if the first risk threshold is 70 points, and the comprehensive risk index exceeds 70 points, it indicates that the user's behavior is of medium risk, triggering immediate blocking of the user's operation or secondary identity verification.

[0147] Upon triggering an alert or temporary restrictions, the server automatically generates an interpretable report containing three levels of information: a feature layer annotating the specific behavioral characteristics that triggered the alert, such as short-term flight ticket redemption during inactive periods or bulk mileage transfers between accounts; a rule layer explaining the fraud rules matched by that feature, such as short-term high-class flight ticket redemption rules in flight ticket redemption scenarios; and a risk layer indicating the final risk type, such as points redemption for flight ticket fraud. The alert information and the interpretable report are output together to the risk control personnel's workbench for manual review and processing, thereby overcoming the problem of opaque decision-making processes in artificial intelligence algorithms and improving the risk control personnel's trust in the alert results and the efficiency of review.

[0148] In one possible implementation, step S304 further includes: S3044. The server obtains the execution result feedback data of the risk handling strategy. The execution result feedback data includes false alarm confirmation information, missed alarm confirmation information and / or risk type confirmation information.

[0149] Feedback data represents the decision made by risk control users after reviewing warning information or temporary restrictions imposed on users. This includes confirmations of misjudgments, missed reports, and risk types. The server collects this feedback information and sends it back to the data layer, triggering an incremental update mechanism for the model. During this incremental update, the server invokes a large model agent to analyze the feedback data, automatically extracting new user risk behavior characteristics, such as texture features of new types of fraudulent credentials and pattern features of fraudulent passenger information in ticket redemption scenarios.

[0150] S3045. Based on the execution result feedback data, the server updates the transmission strength in the risk transmission link library and / or optimizes the parameters of the feature enhancement network.

[0151] The server extracts new features based on the execution results feedback data. It optimizes the risk transmission link library, adding or adjusting risk transmission links and their probabilities. Simultaneously, it updates the parameters of the temporal spike attention network, scene-adaptive risk convolution, and cross-domain behavior association graph network in the feature enhancement network. This allows the feature enhancement network to quickly adapt to the latest evolution of risk patterns. The entire incremental update process is completed within minutes, eliminating the need for full model retraining, significantly shortening the model iteration cycle, achieving self-evolutionary risk control capabilities, and ensuring continuous and effective perception and early warning of new user risk behaviors.

[0152] In this embodiment, a corresponding risk management strategy is implemented based on the comprehensive risk index. This step directly transforms the risk quantification assessment results into actual risk control actions, enabling risk identification to move beyond the analysis stage and trigger targeted intervention measures. By linking assessment with execution, measures such as blocking, warning, or restricting can be taken promptly when high-risk users are identified, effectively preventing the continuation of fraudulent activities or reducing potential economic losses, thus forming an operational closed loop from risk identification to risk control.

[0153] The system compares a comprehensive risk index with multiple preset risk thresholds. If the comprehensive risk index exceeds the first risk threshold, a risk warning is generated and sent, triggering only a notification-type action to avoid excessive interference with low-risk users. If the comprehensive risk index exceeds a second risk threshold, which is higher than the first risk threshold, temporary restrictions on the corresponding user account are automatically triggered, proactively blocking high-risk users. By setting multiple different levels of thresholds and matching differentiated actions, risk-level control is achieved: low-risk users are primarily warned, while high-risk users are primarily restricted, thus ensuring a normal user experience while rapidly and forcefully blocking serious risky behaviors.

[0154] The system acquires feedback data on the execution results of risk management strategies. This feedback data includes false positive confirmation information, false negative confirmation information, and / or risk type confirmation information. This feedback data reflects the actual effectiveness of risk control measures and genuine fraud labels. Based on the execution result feedback data, the transmission strength in the risk transmission link library and / or the parameters of the feature enhancement network are updated, enabling the risk transmission link library and feature enhancement network to learn from actual handling results and dynamically adapt to changes in new fraud patterns. This iterative optimization mechanism based on real feedback can achieve incremental updates at the minute level without fully retraining the model, effectively shortening the model's response cycle to new frauds and solving the problem of iterative lag in traditional risk control systems.

[0155] In one embodiment, the user risk behavior perception method provided in this application can be implemented using the Python language, as shown in the following example code: # Excerpt 1: Core Code of Federated Feature Desensitization and Fusion (FFDF) import paillier from sklearn.preprocessing import Normalizer # Initialize the Paillier cipher (physical meaning: generate encryption key pairs for core data encryption operations) public_key, private_key = paillier.generate_paillier_keypair() def ffdf_fusion(internal_features, external_encrypt_features, public_key, private_key): """ Federal feature desensitization and fusion function to achieve secure fusion of multi-source data. parameter: internal_features: Internal features of the airline (physical meaning: N×D dimensional feature matrix, where N is the number of members and D is the feature dimension) external_encrypt_features: External encryption features (physical meaning: N×D dimensional encryption feature matrix, data does not leave the database). public_key / private_key: Paillier key pair (physical function: to perform data encryption and decryption operations) return: aligned_features: Aligned and fused feature matrix (physical meaning: standardized security features, for subsequent mining). """ # Internal feature encryption (physical operation: local encryption to prevent leakage of original data) encrypt_internal = public_key.encrypt_matrix(internal_features) # Decryption of external encrypted feature dimensions (physical operation: only decrypts the feature dimensions, without revealing the original data) decrypt_external = private_key.decrypt_matrix(external_encrypt_features) # Encryption Feature Fusion (Physical Operation: Feature superposition based on secret sharing protocol, corresponding to fusion operator ⊕) # Core operation: Aligning the internal encryption features with the external decryption features dimensionally, then superimposing them element by element. fused_features = [] for enc_in, dec_ext in zip(encrypt_internal, decrypt_external): # Secure fusion of encrypted and plaintext features (Paillier encryption supports homomorphic addition) fused = enc_in + dec_ext fused_features.append(fused) # Decrypt the fusion result (decryption only locally to ensure data security) fused_features = private_key.decrypt_matrix(fused_features) # Standardization (Physical operations: Unified format, elimination of dimensional influence) aligned_features = Normalizer(norm='l2').fit_transform(fused_features) return aligned_features As can be seen, the above mainly describes the solutions provided by the embodiments of this application from a methodological perspective. To achieve the above functions, the embodiments of this application provide corresponding hardware structures and / or software modules for executing each function. Those skilled in the art should readily recognize that, in conjunction with the modules and algorithm steps of the various examples described in the embodiments disclosed herein, the embodiments of this application can be implemented in hardware or a combination of hardware and computer software. Whether a function is executed by hardware or by computer software driving hardware depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this invention.

[0156] This application embodiment can divide the user risk determination device into functional modules based on the above method example. For example, each function can be divided into its own functional modules, or two or more functions can be integrated into one processing module. The integrated module can be implemented in hardware or as a software functional module. Optionally, the module division in this application embodiment is illustrative and only represents one logical functional division; other division methods may be used in actual implementation.

[0157] In some embodiments, this application also provides a user risk determination apparatus. This user risk determination apparatus may include one or more functional modules for implementing the user risk determination method of the above method embodiments.

[0158] For example, Figure 6 This is a schematic diagram illustrating the composition of a user risk determination device provided in an embodiment of this application.Figure 6 As shown, the user risk determination device 400 includes: a data acquisition module 401, a feature generation module 402, an information enhancement module 403, and an index generation module 404.

[0159] The data acquisition module 401 is used to acquire user data, which includes user attribute data, user behavior record data, and external data associated with the user. The external data includes at least one of Internet behavior data, credit data, or non-operator data. The feature generation module 402 is used to fuse and perform feature engineering on user data to generate multi-dimensional feature information to characterize user risk. The information enhancement module 403 is used to enhance the risk transmission of multi-dimensional feature information based on a preset risk transmission link library to obtain enhanced risk feature information. The risk transmission link library defines the correlation and transmission strength between different risk features and risk types. The index generation module 404 is used to determine the user's comprehensive risk index based on the enhanced risk characteristic information.

[0160] In one embodiment, the feature generation module 402 is further used to perform multi-time window statistical feature extraction on the time series data in the user data to obtain time series risk features; The structured data in the user data is encoded and transformed to obtain scenario risk characteristics; Semantic risk features are obtained by embedding unstructured data in user data. The temporal risk features, scenario risk features, and semantic risk features are fused to generate an initial risk feature set; The initial risk feature set is input into the feature enhancement network for processing to generate multidimensional feature information. The feature enhancement network is used to enhance the feature components related to abnormal risks in the initial risk feature set.

[0161] In one embodiment, the feature enhancement network includes a temporal attention module, a scene-adaptive risk convolution module, a cross-domain behavior association graph module, and a feature modulation module.

[0162] The feature generation module 402 is also used to extract temporal mutation features from the initial risk feature set through the temporal attention module; The scene-adaptive risk convolution module extracts scene convolution features from the initial risk feature set. A cross-domain behavior association graph module is used to construct an association graph containing behavior nodes, attribute nodes, and risk nodes. Based on the association graph, cross-domain coupling features are extracted from the initial risk feature set. The feature modulation module fuses temporal mutation features, scene convolution features, and cross-domain coupling features, and enhances the abnormal components in the fused features. Then, the enhanced features are weighted and fused with the temporal mutation features, scene convolution features, and cross-domain coupling features to generate multi-dimensional feature information.

[0163] In one embodiment, the information enhancement module 403 is further configured to match a subset of features from the multidimensional feature information that matches at least one risk transmission link in the risk transmission link library of the risk association graph; Based on the transmission strength corresponding to the matched risk transmission link, the features in the feature subset are enhanced to generate enhanced risk feature information.

[0164] In one embodiment, the index generation module 404 is further configured to input the enhanced risk feature information into the trained risk index prediction model, and output a comprehensive risk index from the risk index prediction model. The risk index prediction model is a model trained based on historical user data and its corresponding risk loss labels.

[0165] In one embodiment, the user risk determination device 400 further includes a risk handling module 405, which is used to execute corresponding risk handling strategies based on a comprehensive risk index.

[0166] In one embodiment, the risk handling module 405 is further configured to compare the comprehensive risk index with multiple preset risk thresholds; If the comprehensive risk index exceeds the first risk threshold, a risk warning message will be generated and sent. If the overall risk index exceeds the second risk threshold, which is higher than the first risk threshold, temporary restrictions on the corresponding user account will be automatically triggered.

[0167] In one embodiment, the risk handling module 405 is further configured to obtain execution result feedback data of the risk handling strategy, including false alarm confirmation information, missed alarm confirmation information and / or risk type confirmation information; Based on the feedback data from the execution results, update the transmission strength in the risk transmission link library and / or optimize the parameters of the feature enhancement network.

[0168] When implementing the functions of the integrated modules described above in hardware, this embodiment of the invention provides a possible schematic diagram of the electronic device involved in the above embodiments. For example... Figure 7 As shown, the electronic device 500 includes: a processor 502, a communication interface 503, and a bus 504. Optionally, the electronic device 500 may also include a memory 501.

[0169] Processor 502 may implement or execute various exemplary logic blocks, modules, and circuits described in conjunction with the disclosure of this application. Processor 502 may be a central processing unit, a general-purpose processor, a digital signal processor, an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. It may implement or execute various exemplary logic blocks, modules, and circuits described in conjunction with the disclosure of this application. Processor 502 may also be a combination that implements computing functions, such as including one or more microprocessor combinations, a combination of a DSP and a microprocessor, etc.

[0170] Communication interface 503 is used to connect to other devices via a communication network. This communication network can be Ethernet, wireless access network, wireless local area network (WLAN), etc.

[0171] The memory 501 may be a read-only memory (ROM) or other type of static storage device capable of storing static information and instructions, random access memory (RAM) or other type of dynamic storage device capable of storing information and instructions, or electrically erasable programmable read-only memory (EEPROM), disk storage medium or other magnetic storage device, or any other medium capable of carrying or storing desired program code in the form of instructions or data structures and accessible by a computer, but is not limited thereto.

[0172] In one possible implementation, the memory 501 can exist independently of the processor 502. The memory 501 can be connected to the processor 502 via a bus 504 and is used to store instructions or program code. When the processor 502 calls and executes the instructions or program code stored in the memory 501, it can implement the user risk determination method provided in this embodiment of the invention.

[0173] In another possible implementation, the memory 501 can also be integrated with the processor 502.

[0174] Bus 504 can be an extended industry standard architecture (EISA) bus, etc. Bus 504 can be divided into address bus, data bus, control bus, etc. For ease of representation, Figure 7 The bus is represented by a single thick line, but this does not mean that there is only one bus or one type of bus.

[0175] Through the above description of the implementation methods, those skilled in the art can clearly understand that, for the sake of convenience and brevity, only the division of the above functional modules is used as an example. In actual applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the service calling device can be divided into different functional modules to complete all or part of the functions described above.

[0176] This application also provides a computer-readable storage medium. All or part of the processes in the above method embodiments can be executed by computer instructions instructing related hardware. The program can be stored in the aforementioned computer-readable storage medium, and when executed, it can include the processes of the above method embodiments. The computer-readable storage medium can be any of the foregoing embodiments or memory. The aforementioned computer-readable storage medium can also be an external storage device of the aforementioned service invocation device, such as a plug-in hard drive, smart media card (SMC), secure digital (SD) card, flash card, etc., equipped on the aforementioned service invocation device. Further, the aforementioned computer-readable storage medium can include both internal storage units of the aforementioned service invocation device and external storage devices. The aforementioned computer-readable storage medium is used to store the aforementioned computer program and other programs and data required by the aforementioned service invocation device. The aforementioned computer-readable storage medium can also be used to temporarily store data that has been output or will be output.

[0177] This application also provides computer instructions. All or part of the processes in the above method embodiments can be executed by computer instructions to instruct related hardware (such as computers, processors, network devices, and terminals). The program can be stored in the aforementioned computer-readable storage medium.

[0178] This application also provides a computer program product that, when run on a computer, causes the above-described method embodiments to be executed.

[0179] This application also provides a chip system. The chip system may be composed of chips or may include chips and other discrete devices, without limitation. The chip system includes a processor and a transceiver. All or part of the processes in the above method embodiments can be completed by this chip system, such as the chip system being used to implement the functions performed by the network devices or terminals in the above method embodiments.

[0180] In one possible design, the chip system further includes a memory for storing program instructions and / or data. When the chip system is running, the processor executes the program instructions stored in the memory to enable the chip system to perform the functions performed by the network device or terminal in the above method embodiments.

[0181] The above are merely specific embodiments of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions within the technical scope disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A method for determining user risk, characterized in that, include: Acquire user data, which includes user attribute data, user behavior record data, and external data associated with the user, including at least one of internet behavior data, credit data, or non-carrier data; The user data is fused and feature-engineered to generate multidimensional feature information to characterize user risk; The risk transmission is enhanced based on a preset risk transmission link library to obtain enhanced risk feature information. The risk transmission link library defines the correlation and transmission strength between different risk features and risk types. Based on the enhanced risk characteristic information, the user's comprehensive risk index is determined.

2. The method according to claim 1, characterized in that, The process of fusing and feature engineering the user data to generate multidimensional feature information for characterizing user risk includes: Statistical features of time series data in the user data are extracted using multiple time windows to obtain time series risk features; The structured data in the user data is encoded and transformed to obtain scenario risk characteristics; The unstructured data in the user data is embedded to obtain semantic risk features; The temporal risk features, the scenario risk features, and the semantic risk features are fused to generate an initial risk feature set; The initial risk feature set is input into a feature enhancement network for processing to generate the multidimensional feature information. The feature enhancement network is used to enhance the feature components related to abnormal risks in the initial risk feature set.

3. The method according to claim 2, characterized in that, The feature enhancement network includes a temporal attention module, a scene-adaptive risk convolution module, a cross-domain behavior association graph module, and a feature modulation module. The process of inputting the initial risk feature set into the feature enhancement network for processing includes: Temporal mutation features are extracted from the initial risk feature set using a temporal attention module; The scene-adaptive risk convolution module extracts scene convolution features from the initial risk feature set. A cross-domain behavior association graph module is used to construct an association graph containing behavior nodes, attribute nodes, and risk nodes. Based on the association graph, cross-domain coupling features are extracted from the initial risk feature set. The feature modulation module fuses the temporal abrupt change features, the scene convolutional features, and the cross-domain coupling features, and enhances the abnormal components in the fused features. Then, the enhanced features are weighted and fused with the temporal abrupt change features, the scene convolutional features, and the cross-domain coupling features to generate the multidimensional feature information.

4. The method according to claim 1, characterized in that, The risk transmission enhancement based on the preset risk transmission link library for the multi-dimensional feature information includes: From the multidimensional feature information, a subset of features that matches at least one risk transmission link in the risk transmission link library is selected; Based on the transmission strength corresponding to the matched risk transmission link, the features in the feature subset are enhanced to generate the enhanced risk feature information.

5. The method according to claim 1, characterized in that, The step of determining the user's comprehensive risk index based on the enhanced risk characteristic information includes: The enhanced risk feature information is input into the trained risk index prediction model, and the risk index prediction model outputs the comprehensive risk index. The risk index prediction model is a model trained based on historical user data and its corresponding risk loss labels.

6. The method according to any one of claims 1-5, characterized in that, The method further includes: Based on the comprehensive risk index, implement corresponding risk management strategies.

7. The method according to claim 6, characterized in that, The implementation of corresponding risk management strategies based on the comprehensive risk index includes: The comprehensive risk index is compared with multiple preset risk thresholds; If the comprehensive risk index exceeds the first risk threshold, a risk warning message is generated and sent. If the comprehensive risk index exceeds a second risk threshold that is higher than the first risk threshold, temporary restrictions on the corresponding user account will be automatically triggered.

8. The method according to claim 6, characterized in that, The method further includes: Obtain execution result feedback data of the risk handling strategy, including false alarm confirmation information, missed alarm confirmation information and / or risk type confirmation information; Based on the feedback data of the execution results, update the transmission strength in the risk transmission link library and / or optimize the parameters of the feature enhancement network.

9. A user risk determination device, characterized in that, include: The data acquisition module is used to acquire user data, which includes user attribute data, user behavior record data, and external data associated with the user. The external data includes at least one of internet behavior data, credit data, or non-carrier data. The feature generation module is used to fuse and perform feature engineering on the user data to generate multidimensional feature information that characterizes user risk. The information enhancement module is used to enhance the risk transmission of the multidimensional feature information based on a preset risk transmission link library to obtain enhanced risk feature information, wherein the risk transmission link library defines the correlation and transmission strength between different risk features and risk types. The index generation module is used to determine the user's comprehensive risk index based on the enhanced risk characteristic information.

10. An electronic device, characterized in that, It includes a processor and a memory, the processor being coupled to the memory; the memory is used to store computer instructions, which are loaded and executed by the processor to enable the computer device to implement the user risk determination method as described in any one of claims 1 to 8.

11. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes computer-executable instructions that, when executed on a computer, cause the computer to perform the user risk determination method as described in any one of claims 1 to 8.

12. A computer program product, characterized in that, The computer program product includes a computer program that, when run on an electronic device, causes the electronic device to perform the user risk determination method as described in any one of claims 1 to 8.