Risk Transaction Early Warning Methods and Devices

CN122573471APending Publication Date: 2026-08-14GUANGZHOU HUYA INFORMATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-06-16
Publication Date
2026-08-14

AI Technical Summary

Technical Problem

然而,这些方案通常仅将安装时间作为单一静态因子,或将交易时间与用户历史基线进行比对,识别维度不足,对被骗用户的动态时序风险捕捉能力不足

Benefits of technology

本申请提供一种风险交易预警方法及装置,在根据用户投诉信息确定风险应用后,根据目标用户的用户终端上风险应用的安装时间及交易时间计算获得风险时序特征,并根据风险时序特征和用户操作行为特征一起计算交易行为风险评分,从而判定目标用户的交易动作是否存在被诈骗的风险。如此,从多个维度使用不同的特征判定用户交易动作的风险,可以更精准地识别存在诈骗风险的交易,更加有效地实现风险预警和风险交易拦截。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122573471A_ABST
    Figure CN122573471A_ABST
Patent Text Reader

Abstract

This application provides a risk transaction early warning method and apparatus. The method includes: identifying risky applications based on user complaint information; obtaining the installation time of the risky application on the target user's terminal and the transaction time of using the risky application for transactions, and calculating the interval between the transaction time and the installation time to obtain risk temporal characteristics; obtaining user operation behavior characteristics of the target user's operations on the user terminal; calculating a transaction behavior risk score for transaction requests generated by the user terminal based on the risk temporal characteristics and user operation behavior characteristics; and generating risk transaction early warning information for the transaction behavior based on the transaction behavior risk score. Thus, by using different features from multiple dimensions to determine the risk of user transaction actions, it is possible to more accurately identify transactions with fraud risks and more effectively achieve risk early warning and risk transaction interception.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of application security technology, and more specifically, to a risk transaction early warning method and device. Background Technology

[0002] In the context of risk control in virtual asset transactions, fraudulent order placement is a common scam. Scammers typically induce victims to purchase virtual assets such as game points or prepaid cards through designated third-party risky applications, promising high returns upon completion of the transaction.

[0003] In existing risk control solutions, some technologies are beginning to focus on behavioral characteristics over time, such as detecting whether a user's operation time deviates from historical habits, or determining whether the application on the device was recently installed. However, these solutions typically only treat installation time as a single static factor, or compare transaction time with the user's historical baseline, resulting in insufficient identification dimensions and inadequate ability to capture the dynamic temporal risks of defrauded users. Summary of the Invention

[0004] To overcome the aforementioned shortcomings in the prior art, the purpose of this application is to provide a risk transaction early warning method, the method comprising: Risky applications are identified based on user complaints. The installation time of the risky application on the target user's terminal and the transaction time of the transaction using the risky application are obtained, and the interval between the transaction time and the installation time is calculated to obtain the risk time series characteristics. Acquire user operation behavior characteristics of the target user's operations on the user terminal; For transaction requests generated by the user terminal, a transaction behavior risk score is calculated based on the risk time sequence characteristics and the user operation behavior characteristics; Based on the risk score of the transaction behavior, risk warning information for the transaction behavior is generated.

[0005] In some possible implementations, the step of determining risky applications based on user complaint information includes: Obtain user complaint information within a preset time period; The user complaint information is processed by a large language model using preset prompt words to perform at least two rounds of filtering to obtain the names of multiple candidate applications and the risk confidence level of the candidate applications. The risky application is determined from among the candidate applications based on the risk confidence level.

[0006] In some possible implementations, the step of using preset prompt words to instruct a large language model to perform at least two rounds of filtering on the user complaint information to obtain the names of multiple candidate applications and the risk confidence levels corresponding to the candidate applications includes: By controlling the large language model with a preset first prompt word, the name of the candidate application with fraud risk and the first candidate confidence level of each candidate application are extracted based on the user complaint information to obtain a set of candidate applications. The candidate applications and their corresponding risk confidence levels in the candidate application set are adjusted by using a preset second prompt word.

[0007] In some possible implementations, the step of adjusting the candidate applications and their corresponding risk confidence levels in the candidate application set using a preset second prompt word includes: The large language model is controlled by a preset second prompt word to perform misselection and omission checks on the candidate application set. For a misselected candidate application, the second candidate confidence level of the candidate application is set to 0; for a candidate application that is not misselected, the second candidate confidence level of the candidate application is set to be greater than 0; for a candidate application that is added to the candidate application set after being missed, the second candidate confidence level of the candidate application is set to be greater than 0. For the candidate applications selected by the first prompt word and confirmed to have risks by the second prompt word, the risk confidence level corresponding to the candidate application is obtained by weighted summation based on the first candidate confidence level and the second candidate confidence level.

[0008] In some possible implementations, the method further includes: For the candidate applications that were added to the candidate application set after being missed, the basis for discovering the missed detection is recorded. The large language model is controlled by a preset third prompt word to supplement the candidate application set according to the discovery criteria. For the newly added candidate application set, the third candidate confidence of the candidate application is obtained. For the candidate applications selected and added to the candidate application set through the second and third prompt words, the candidate applications are marked as requiring manual review and confirmation; The step of determining the risky application from among the candidate applications based on the risk confidence level includes: Candidate applications whose risk confidence level is greater than a first preset threshold are labeled as risky applications, thereby obtaining a set of risky applications; Candidate applications whose risk confidence level is less than or equal to a first set threshold and greater than or equal to a second set threshold are marked as requiring manual review and confirmation. Candidate applications that are confirmed to be risky after manual review will be added to the risky application set.

[0009] In some possible implementations, the step of calculating the transaction behavior risk score based on the risk time series characteristics and the user operation behavior characteristics includes: Based on the risk time-series characteristics and the user operation behavior characteristics, the probability value of being induced to install risky applications for the target user is predicted by pre-training a machine learning model. The risk score of the transaction behavior is calculated based on the probability of being induced, the characteristics of user operation behavior, and the risk time series characteristics.

[0010] In some possible implementations, the step of obtaining user operation behavior characteristics based on the target user's operations on the user terminal includes: Get the number of new applications installed on the user terminal within the most recent set number of days. The number of risky applications installed on the user terminal and average application usage frequency And obtain the risk time series features. ; The step of predicting the probability of a target user being induced to install a risky application using a pre-trained user prediction model based on the risk time-series characteristics and the user operation behavior characteristics includes: The number of installations The number of applications installed Average frequency of use of the application and the aforementioned risk time series characteristics Composition of risk vector The input is a pre-trained user prediction model, which predicts the probability value of the target user being tricked into installing risky applications. ;in, .

[0011] In some possible implementations, the step of calculating the transaction behavior risk score based on the induced probability value, the user operation behavior characteristics, and the risk time series characteristics includes: Based on the pre-defined correspondence between multiple time-duration segments and time-series risk weights, the risk time-series characteristics are determined. Corresponding time-series risk weights ; The risk score for the transaction behavior is calculated using the following formula. :

[0012] in, , , , For preset weighting coefficients, The function is used to smooth the number of installations. The impact.

[0013] In some possible implementations, the method further includes: Based on the number of new applications installed by multiple sample users, the number of risky applications installed, the average frequency of application use, and the risk time series characteristics, obtain the sample risk vector corresponding to each sample user; Based on the sample risk vector, the sample users are labeled as induced users and normal users. The user prediction model is trained based on the sample risk vectors corresponding to the induced users and the normal users in the sample to identify the induced users.

[0014] In some possible implementations, the step of generating risk warning information for the transaction behavior based on the transaction behavior risk score includes: Obtain other non-behavioral risk scores; The total risk score is obtained by weighted summation of the transaction behavior risk score and the other non-behavioral risk scores. For the overall risk score at different score levels, generate corresponding risk transaction warning information or execute corresponding transaction interception actions.

[0015] Another objective of this application is to provide a risk trading early warning device, the risk trading early warning device comprising: The application identification module is used to identify risky applications based on user complaint information; The first feature acquisition module is used to acquire the installation time of the risk application on the target user's user terminal and the transaction time of the first transaction using the risk application, and calculate the interval between the transaction time and the installation time to obtain risk time series features. The second feature acquisition module is used to acquire user operation behavior features of the target user's operations on the user terminal. The risk scoring module is used to calculate a transaction behavior risk score for the transaction requests generated by the user terminal based on the risk time sequence characteristics and the user operation behavior characteristics. The risk warning module is used to generate risk warning information for the transaction behavior based on the risk score of the transaction behavior.

[0016] Compared with the prior art, this application has the following beneficial effects: This application provides a risk transaction early warning method and apparatus. After identifying risky applications based on user complaint information, it calculates risk temporal characteristics based on the installation time and transaction time of the risky applications on the target user's terminal. Then, it calculates a transaction behavior risk score based on the risk temporal characteristics and user operation behavior characteristics, thereby determining whether the target user's transaction actions are at risk of being defrauded. In this way, by using different features from multiple dimensions to determine the risk of user transaction actions, it can more accurately identify transactions with fraud risks and more effectively achieve risk early warning and risk transaction interception. Attached Figure Description

[0017] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings used in the embodiments will be briefly introduced below. It should be understood that the following drawings only show some embodiments of this application and should not be regarded as a limitation of the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.

[0018] Figure 1 A flowchart illustrating the steps of the risk transaction early warning method provided in this application embodiment; Figure 2 A schematic diagram of an electronic device provided in an embodiment of this application; Figure 3 This is a schematic diagram of the functional modules of the risk transaction early warning device provided in the embodiments of this application. Detailed Implementation

[0019] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. The components of the embodiments of this application described and shown in the accompanying drawings can generally be arranged and designed in various different configurations.

[0020] Therefore, the following detailed description of the embodiments of this application provided in the accompanying drawings is not intended to limit the scope of the claimed application, but merely to illustrate selected embodiments of the application. All other embodiments obtained by those skilled in the art based on the embodiments of this application without inventive effort are within the scope of protection of this application.

[0021] It should be noted that similar labels and letters in the following figures indicate similar items. Therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures.

[0022] In the description of this application, it should be noted that the terms "center," "upper," "lower," "left," "right," "vertical," "horizontal," "inner," and "outer," etc., indicate the orientation or positional relationship based on the orientation or positional relationship shown in the accompanying drawings, or the orientation or positional relationship commonly used when the product of the invention is in use. They are used only for the convenience of describing this application and simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation. Therefore, they should not be construed as limitations on this application. In addition, the terms "first," "second," and "third," etc., are used only to distinguish descriptions and should not be construed as indicating or implying relative importance.

[0023] Furthermore, terms such as "horizontal," "vertical," and "sag" do not imply that components must be absolutely horizontal or suspended, but rather that they can be slightly tilted. For example, "horizontal" simply means that its direction is more horizontal relative to "vertical," and does not mean that the structure must be completely horizontal, but can be slightly tilted.

[0024] In the description of this application, it should also be noted that, unless otherwise expressly specified and limited, the terms "set up," "install," "connect," and "link" should be interpreted broadly. For example, they can refer to a fixed connection, a detachable connection, or an integral connection; they can refer to a mechanical connection or an electrical connection; they can refer to a direct connection or an indirect connection through an intermediate medium; and they can refer to the internal connection of two components. Those skilled in the art can understand the specific meaning of the above terms in this application based on the specific circumstances.

[0025] Please see Figure 1 , Figure 1 This is a flowchart illustrating the steps of a risk application early warning method provided in this embodiment. The solution provided in this embodiment will be described in detail below.

[0026] Step S110: Determine the risky application based on user complaint information.

[0027] In this embodiment, the system first needs to identify risky applications with fraudulent intent from the complaint information provided by the user.

[0028] It should be noted that the complaint information here refers to the text description submitted to the platform by users after being scammed through fake order scams. This text typically includes the names of third-party applications that the scammers require users to download or use. In practice, the platform receives a large number of user complaints daily, and each complaint may mention multiple misleading applications using direct names, pinyin abbreviations, typos, or veiled expressions.

[0029] For example, one complaint text might say "The other party asked me to download the TaskCat App to accept orders," another complaint might say "I saw order-brushing tasks on the KuaiZuan platform," and still others might only contain the pinyin "rwb" or the misspelled "TaskBang." In step S110, it is necessary to automatically identify and extract risky applications from these massive amounts of unstructured complaint texts.

[0030] During the execution of the above steps, the system can employ various natural language processing techniques to perform the extraction operation, such as rule-based keyword matching, statistical text classification, or semantic understanding based on large language models. The output of the extraction operation is the names of one or more risk applications, which will serve as the basis for association analysis in subsequent steps.

[0031] For example, after step S110, the system may output a list of risky applications containing names such as "TaskCat," "Quick Earn," and "Task Helper." It should be understood that this list of risky applications is not static but dynamically updated as new complaint information is continuously received, thereby ensuring the timeliness and accuracy of risk identification.

[0032] Step S120: Obtain the installation time of the risky application on the target user's terminal and the transaction time of using the risky application for transactions, and calculate the interval between the transaction time and the installation time to obtain the risk time series characteristics.

[0033] In this embodiment, in step S120, two key time points related to the aforementioned risky applications on the user terminal of a specific target user to be evaluated can be obtained.

[0034] It should be noted that the installation time here refers to the specific moment when the risky application is installed on the target user's terminal, such as "13:00 on September 8, 2025". The transaction time here refers to the moment when the target user initiates a virtual asset transaction (such as purchasing game points or recharge cards) using the same risky application, such as "14:00 on September 8, 2025". In some possible implementations, the transaction time obtained in step S120 can be the time when the risky application is first used to execute a transaction.

[0035] Specifically, the system first matches the risk application name (e.g., "Task Cat") output in step S110 with the list of installed applications on the target user's terminal. If the match is successful, the system extracts the installation timestamp of the application. At the same time, the system obtains the timestamp of the user initiating a transaction related to the risk application from the transaction log.

[0036] Then, the system calculates the difference between the transaction time and the installation time, defines this difference as the risk time series characteristic, and denotes it as... .

[0037] For example, if the installation time is 13:00 on September 8, 2025, and the transaction time is 14:00 on September 8, 2025, then The installation time is 1 hour; if the installation time is the previous day, then... It may take more than 24 hours.

[0038] This can be understood as the risk timing characteristic quantifying the urgency of the process from installing a risky application to initiating a transaction; the shorter the time interval, the higher the likelihood that the user is being immediately induced.

[0039] Optionally, in practical applications, if the target user's terminal does not have any of the risky applications identified in step S110 installed, then calculation is not possible. In this case, the feature is not included in subsequent calculations or is directly set to an invalid value.

[0040] Step S130: Obtain user operation behavior characteristics of the target user's operations on the user terminal.

[0041] In this embodiment, more comprehensive behavioral pattern information can be collected from the target user's terminal device through step S130.

[0042] It should be noted that the user operation behavior characteristics here refer to quantitative indicators that can reflect the user's habits of using terminal devices. These indicators do not depend on the existence of specific risky applications, but are extracted from the overall operation behavior.

[0043] It should be understood that risk temporal characteristics reflect users' cumulative behavioral habits over a period of time, while user operational behavior characteristics reflect the temporal correlation of specific risk events. Combining the two can provide a more comprehensive picture of whether a user is being misled.

[0044] Step S140: For transaction requests generated by user terminals, calculate and obtain a transaction behavior risk score based on risk timing characteristics and user operation behavior characteristics.

[0045] In this embodiment, when a target user's terminal generates a transaction request, the system uses the risk timing characteristics obtained in step S120. The user operation behavior characteristics obtained in step S130 are used as input, and a transaction behavior risk score is output through a preset calculation model or scoring function.

[0046] Among them, the higher the risk score of the transaction behavior, the closer the transaction behavior is to the typical pattern of the induced user, and the greater the risk.

[0047] Step S150: Generate risk warning information for trading behavior based on the risk score of the trading behavior.

[0048] In this embodiment, the system can determine whether a transaction has been fraudulent based on the transaction behavior risk score, or based on the transaction behavior risk score along with other risk scores, and generate risk transaction warning information.

[0049] Based on the above design, in the risk transaction early warning method provided in this embodiment, after identifying the risky application based on user complaint information, risk timing characteristics are calculated based on the installation time and transaction time of the risky application on the target user's terminal. A transaction behavior risk score is then calculated together with the risk timing characteristics and user operation behavior characteristics to determine whether the target user's transaction actions are at risk of being defrauded. In this way, using different features from multiple dimensions to determine the risk of user transaction actions can more accurately identify transactions with fraud risks and more effectively achieve risk early warning and risk transaction interception.

[0050] In some possible implementations, step S110 may include the following sub-steps.

[0051] Step S111: Obtain user complaint information within a preset time period.

[0052] In this embodiment, the system first needs to acquire the raw data used for risk transaction early warning. During the execution of the above steps, the system retrieves user complaint records from the complaint database of the business system within the most recent preset time period through a scheduled task.

[0053] It should be noted that the preset time period can be flexibly set according to actual business needs, such as the past 24 hours, the past 3 days, or the past week. In practical applications, to avoid the data volume being too large or too small and affecting the extraction efficiency, a moderate time window is usually selected, such as the most recent 3 days. For example, the system automatically triggers at midnight every day to pull all user complaints received in the past 3 days from the database, obtaining a total of 198 original records.

[0054] Then, the system performs deduplication and cleaning on these original records, such as removing blank complaints, merging duplicate complaints submitted by the same user, and filtering out obviously irrelevant content, ultimately obtaining valid complaint information.

[0055] For example, after cleaning, 180 valid complaint messages are obtained, which will be used as input for subsequent processing by the large language model.

[0056] It should be understood that obtaining user complaint information within a preset time period, rather than all historical complaints, ensures that the list of risky applications can reflect the latest fraud trends in a timely manner, while also controlling the computational overhead of data processing.

[0057] Step S112: Use preset prompt words to instruct the large language model to perform at least two rounds of filtering on user complaint information to obtain the names of multiple candidate applications and the risk confidence levels corresponding to the candidate applications.

[0058] In this embodiment, after obtaining user complaint information, the multi-turn processing capability of a large language model can be used to automatically extract candidate risky applications.

[0059] It should be noted that large language models suffer from illusion defects during single extraction, potentially fabricating non-existent applications or omitting hidden expressions. Therefore, this step employs at least two rounds of screening to overcome these defects.

[0060] During the above steps, the system constructs preset prompts and inputs user complaint information into the large language model. The prompts explicitly require the model to perform an extraction task and output the name of each candidate application and its corresponding risk confidence score. The risk confidence score is a value between 0 and 1, representing the model's degree of certainty that the application is a fraudulent application.

[0061] For example, in the first round of processing, the system can instruct the model to adopt a conservative strategy, extracting only results with high confidence and outputting candidate applications such as "Task Cat, confidence 0.95" and "Quick Earn, confidence 0.82". In the second round of processing, the system feeds back the results from the first round to the model and instructs the model to switch roles to perform cross-validation, identify misjudgments and omissions, and thus correct the confidence or add new applications.

[0062] After at least two rounds of processing, the system obtains the names of multiple candidate applications and their final risk confidence scores. It should be understood that multiple rounds of screening can significantly improve the accuracy and recall of the extraction, making the risk confidence scores more reliable.

[0063] Step S113: Determine the risky application from multiple candidate applications based on the risk confidence level.

[0064] In this embodiment, after obtaining candidate applications and their risk confidence levels, the final risky applications can be selected from them. During the above steps, the system compares the risk confidence level of each candidate application with a preset threshold. It should be noted that there can be one or more thresholds.

[0065] For example, a high threshold (such as 0.7) can be set to directly identify candidate applications with a risk confidence level greater than 0.7 as risk applications; at the same time, candidate applications with a risk confidence level between 0.4 and 0.7 are marked as pending manual review; and candidate applications with a confidence level lower than 0.4 are discarded.

[0066] For example, if the risk confidence level of the candidate application "Task Cat" is 0.95, it will be directly included in the risk application set; if the confidence level of "Quick Task" is 0.65, it will be marked as pending manual review; if the confidence level of "a normal application" is 0.2, it will be discarded.

[0067] Applications that have undergone manual review and confirmation are also added to the risk application set. Therefore, step S113, through a combination of confidence threshold filtering and manual review, ensures that the final identified risk applications have a high degree of credibility.

[0068] Furthermore, in some possible implementations, step S112 may include the following sub-steps.

[0069] Step S1121: By controlling the large language model with a preset first prompt word, extract the names of candidate applications with fraud risk and the first candidate confidence level of each candidate application based on user complaint information, and obtain a set of candidate applications.

[0070] Specifically, in step S1121, the system can instruct the large language model to play the role of "extractor". The system sends a preset first prompt word to the large language model. The prompt word explicitly requires the model to extract all application names that may have fraud risks from user complaint information in a conservative and prudent manner.

[0071] The first prompt specifies that the model must output a first candidate confidence score (ranging from 0 to 1) for each extracted application and provide the basis for extraction (i.e., the original statements in the complaint text). Simultaneously, the first prompt requires the model to adopt a conservative strategy, extracting only applications the model is highly confident about, avoiding low-confidence guesses. Upon receiving the instructions, the model analyzes each user complaint and outputs initial extraction results.

[0072] For example, if a complaint text contains the phrase "the other party asked me to download the TaskCat App to accept orders," the model extracts "TaskCat" and provides the first candidate confidence level. The confidence level is 0.95. Another complaint included "saw order-brushing tasks on the KuaiZuan platform," and the model extracted "KuaiZuan," with the first candidate confidence score being... The confidence score is 0.82. The system collects all model outputs to form a candidate application set. Each entry in this set includes the application name and the first candidate confidence score. Based on the text, output the initial extraction result set {( )}.

[0073] Step S1122: The large language model is controlled by a preset second prompt word to adjust the candidate applications and their corresponding risk confidence in the candidate application set.

[0074] In this embodiment, the candidate applications in the candidate application set can also be added or deleted through a second prompt word, and the candidate applications and their corresponding risk confidence levels can be adjusted.

[0075] Optionally, in step S1122, a preset second prompt word can be used to control the large language model to perform misselection checking and omission checking on the candidate application set. For the misselected candidate applications, the second candidate confidence level of the candidate application is set to 0; for the non-misselected candidate applications, the second candidate confidence level corresponding to the candidate application is set to be greater than 0; for the candidate applications added to the candidate application set after omission, the second candidate confidence level corresponding to the candidate application is set to be greater than 0.

[0076] Specifically, after the candidate application set is obtained in the first round of extraction, step S1122 performs a second round of cross-verification. During the execution of the above steps, the system sends a preset second prompt word to the large language model, which requires the model to switch to the role of a "skeptic" and conduct a critical review of the results of the first round. It should be noted that the core task of the "skeptic" role is to identify two types of problems in the extraction results of the first round: misjudgment (misjudging a normal application as a fraudulent application) and omission (hidden expressions that exist in the complaint but are not extracted).

[0077] The second prompt word clearly instructs the model: for each application extracted in the first round, determine whether it belongs to misjudgment. If it belongs to misjudgment, the second candidate confidence level of the application is set to 0. If it is confirmed to be a fraudulent application, a second candidate confidence level greater than 0 (usually can be maintained or slightly higher than the first confidence level) is set.

[0078] At the same time, rescan the original complaint text to find hidden expressions of fraudulent applications missed in the first round (such as typos, pinyin abbreviations, hidden references, etc.). For the newly discovered applications, add them to the candidate application set, set a second candidate confidence level greater than 0 , and record the discovery basis for the missed detection. After the model executes, the second candidate confidence level of a certain normal e-commerce application may be set to 0 (indicating misjudgment). At the same time, the second candidate confidence level of the newly discovered "Task Help" is set to 0.88, and the discovery basis is recorded as "pinyin abbreviation 'rwb' in Article 15 of the complaint text and typo 'Task Bang' in Article 28".

[0079] For the candidate applications selected through the first prompt word and confirmed to have risks through the second prompt word, weighted summation calculation is performed based on the first candidate confidence level and the second candidate confidence level to obtain the risk confidence level corresponding to the candidate application.

[0080] Specifically, for the candidate applications extracted in the first round and confirmed as risk applications in the second round (i.e., the second candidate confidence is greater than 0), the final risk confidence is calculated by means of weighted fusion.

[0081] During the execution of the above steps, the system obtains the first candidate confidence of the candidate application and the second candidate confidence , and then performs weighted summation according to the preset weight coefficient.

[0082] In some possible implementation manners, the candidate applications can be further supplemented by a third prompt word.

[0083] Specifically, in step S1122, for the candidate applications supplemented into the candidate application set by the second prompt word, the discovery basis for detecting omissions can also be recorded.

[0084] Then, the large language model is controlled by a preset third prompt word to supplement and select the candidate application set according to the discovery basis. For the candidate applications newly supplemented into the candidate application set, the third candidate confidence of the candidate application is obtained.

[0085] Specifically, after omissions are found and the discovery basis is recorded in the second round, a third round of supplementary extraction is performed. During the execution of the above steps, the system automatically fills the discovery basis identified in the second round into a preset third prompt word template to generate a more targeted instruction. This instruction requires the large language model to play the role of a "supplementer" and re-scan the original complaint text, paying special attention to the previously omitted areas.

[0086] It should be noted that in the third round, the applications that have been extracted are not re-scored, and only the new applications that have not been found in the first two rounds are supplemented and extracted.

[0087] For example, the following content may be included in the third prompt word template: "Based on the analysis of the first two rounds, we found that the following areas may have been omitted: {clues of omissions identified in the second round}. Please re-scan the original text, paying special attention to: nested expressions in long sentences, typos (such as 'taskbang' which is actually 'taskhelp'), pinyin abbreviations (such as 'rwb'), and implicit references (such as 'that part-time software'). Supplement and extract the omitted App names and give the third candidate confidence." The model scans according to this instruction and outputs the newly supplemented applications and their third candidate confidences . For example, the model may supplement and extract "taskhelp" (confidence 0.88), "part-time access" (confidence 0.72), "money-making package" (confidence 0.80), etc. These third candidate confidences will be used for subsequent review and judgment.

[0088] It should be noted that since the third round only targets new applications not discovered in the first two rounds and does not involve the already extracted applications, the fusion formula only includes... and Two items.

[0089] For example, the confidence level of the first candidate can be set. The weight w1 = 0.6, the confidence level of the second candidate. If the weight w2 = 0.4, then the risk confidence level is... .

[0090] For example, if the first confidence level of an application... The confidence level is 0.95, the second confidence level. If the confidence level is 0.98, then the final risk confidence level is 0.6 × 0.95 + 0.4 × 0.98 = 0.962; if the first confidence level... The confidence level is 0.82, the second confidence level. If the result is 0 (indicating a false positive), then the final risk confidence level is 0.6 × 0.82 + 0.4 × 0 = 0.492.

[0091] It should be understood that the principle behind weighted configuration is as follows: the first round of comprehensive scanning has broad coverage but may contain errors; the second round of cross-validation has strong error correction capabilities but relies on the results of the first round. Weighted fusion can combine the advantages of both to obtain a more reliable risk confidence level.

[0092] For candidate applications selected to be added to the candidate application set through the second and third prompt words, the candidate applications are marked as requiring manual review and confirmation.

[0093] For applications newly discovered and added to the candidate application set in the second or third round (i.e., applications not extracted in the first round), automatic weighted fusion is not performed; instead, they are directly marked as requiring manual review and confirmation.

[0094] During the above steps, the system records the names of these applications and their corresponding second or third candidate confidence scores. They are then placed into a queue for review.

[0095] It should be noted that since these applications were not covered in the first round of scanning, their confidence level comes only from subsequent supplementary extractions. The risk of automatic adoption is high, so manual verification is required to ensure accuracy.

[0096] For example, if "Task Helper" is extracted in the third round of supplementary data and has a confidence level of 0.88, the system will not automatically include it in the risk application set, but will instead mark it as "awaiting manual review." After manual verification of the original complaint, a decision will be made on whether to add it to the risk application set. This approach strikes a balance between automation efficiency and security. After the above steps, the system obtains the names of multiple candidate applications and their corresponding risk confidence levels (for applications extracted in the first round and confirmed in the second round) or "awaiting review" markings (for applications added later). Next, step S113 will use this information to ultimately determine the risk application.

[0097] Step S113 may include the following sub-steps.

[0098] Step S1131: Candidate applications with a risk confidence level greater than the first set threshold are marked as risky applications to obtain a set of risky applications.

[0099] In step S1131, the system pre-sets a first threshold (e.g., 0.7). For candidate applications whose risk confidence level has been calculated, if the confidence level is greater than the first threshold, the candidate application is directly marked as a risk application and included in the risk application set. For example, if the risk confidence level of an application is 0.88, which is greater than 0.7, it is directly marked as a risk application. Candidate applications marked as requiring manual review and confirmation are temporarily not included in the risk application set and await further processing.

[0100] Step S1132: Mark candidate applications with risk confidence levels less than or equal to the first set threshold and greater than or equal to the second set threshold as requiring manual review and confirmation.

[0101] In step S1132, the system also sets a second preset threshold (e.g., 0.4). Candidate applications with a risk confidence level less than or equal to the first preset threshold and greater than or equal to the second preset threshold are marked as requiring manual review. For example, an application with a risk confidence level of 0.65 (between 0.4 and 0.7) enters the review queue. Candidate applications with a risk confidence level less than the second preset threshold are directly discarded; for example, an application with a risk confidence level of 0.30 is dropped.

[0102] Step S1133 adds candidate applications that have been confirmed to be risky after manual review to the risk application set.

[0103] In step S1133, for applications marked as requiring manual review and confirmation in step S1132, the system pushes them to human reviewers for secondary judgment. During the execution of the above steps, after confirming that the application does indeed pose a fraud risk based on the original complaint text, application background, and other information, the human reviewers add the application to the risky application set.

[0104] For example, if a candidate application with a risk confidence level of 0.65 is confirmed to be a misleading application after manual verification of the original complaint, it will be added to the risk application set. Another application with a confidence level of 0.88 but marked as pending review (possibly extracted in the third round) will also be added to the set after manual confirmation. At this point, the final risk application set is completed and will be used for subsequent steps S120 and beyond.

[0105] In some possible implementations, step S140 may include the following sub-steps.

[0106] Step S141: Based on the risk time sequence characteristics and user operation behavior characteristics, predict the probability value of the target user being induced to install risky applications by pre-training a machine learning model.

[0107] In step S141, the probability of being induced is first predicted using a machine learning model. Specifically, the system uses the first risk time series features... The user's behavior characteristics are combined with these features to form a feature vector, which is then input into a pre-trained binary classification machine learning model. It should be noted that this model can be a common classification algorithm such as XGBoost, logistic regression, or random forest.

[0108] The model's output is an induced probability value. The value ranges from 0 to 1, representing the probability that the user is a "misled user" under the current characteristics. This can be understood as a quantitative assessment of the user's overall tendency to be deceived, serving as a crucial basis for subsequent calculations of behavioral risk scores.

[0109] Step S142: Calculate the transaction behavior risk score based on the probability of being induced, user operation behavior characteristics, and risk time sequence characteristics.

[0110] In step S142, other risk factors are further integrated to calculate the final transaction behavior risk score. During the execution of the above steps, the system uses a preset scoring formula to weight and combine indicators such as the probability of being induced, the time-series risk weight derived from the first risk time-series characteristics, the number of new application installations and the number of risky applications in the user operation behavior characteristics.

[0111] For example, transaction behavior risk scoring It is a continuous numerical value, for example, between 0 and 100. The higher the score, the greater the trading risk.

[0112] Furthermore, in some possible implementations, step S130 may involve obtaining the number of new applications installed on the user terminal within the most recent set number of days. Number of risky applications installed on user terminals and average application usage frequency And obtain risk time series characteristics. .

[0113] Specifically, the system can collect the following data from the user terminal's device behavior logs: the number of new application installations within the most recent set number of days (e.g., the last 7 days), denoted as... The number of applications installed on the user terminal that belong to the risk application set determined in step S110 is denoted as . ; and the average usage frequency of all applications, denoted as .

[0114] Simultaneously, the system acquires the first risk time series characteristics calculated in step S120. For example, if a user has installed 5 new apps in the past 7 days, has 2 risky apps on their device, and uses apps an average of 20 times per day, and... If it is 2 hours, then =5, =2, =20, =2 hours. These values ​​will serve as the basis for subsequent calculations.

[0115] In step S141, the number of installations can be... Number of installed applications Average frequency of application use and risk time series characteristics Composition of risk vector Input a pre-trained user prediction model to predict the probability value of a target user being tricked into installing a risky application. ;in, .

[0116] In step S141, the risk vector can be... Input a pre-trained user prediction model to predict the probability value of a target user being tricked into installing a risky application. .

[0117] Induced probability value The higher the value, the greater the likelihood that the target user may be tricked into installing risky applications.

[0118] In some possible implementations, in step S142, the risk time series characteristics can be determined based on the pre-defined correspondence between multiple time-duration segments and time-series risk weights. Corresponding time-series risk weights Among them, risk time series characteristics The longer the indicated duration, the higher the corresponding time-series risk weight. The larger.

[0119] For example, based on the risk time series characteristics using the following formula Calculate and obtain time series risk weights :

[0120] The risk score for trading behavior is calculated using the following formula. :

[0121] in, , , , For preset weighting coefficients, Function for smoothing installation quantity The impact.

[0122] Specifically, in step S142, the induced probability value obtained in the previous steps is... Number of new app installations in user behavior characteristics and the number of risky applications installed and the current calculation Substitute the values ​​into the preset scoring formula to calculate the risk score for the trading behavior.

[0123] During the execution of the above steps, the system first determines Is it greater than 0?

[0124] like A value greater than 0 indicates the presence of a risky application on the user's terminal. In this case, a complete formula containing four terms is used: the probability of being misled. Multiply by the weight α, and add the time series risk weight. Multiply by the weight β, then add a smoothed value representing the number of new app installs. In addition, the cutoff value for the number of risky applications .

[0125] like =0 indicates that no risky applications were detected on the user terminal. In this case, the time-series risk weighting term and the risky application quantity term are no longer applicable, and the formula simplifies to: .

[0126] It should be noted that, The function is a hyperbolic tangent function with a range of (0,1), used to... The input is smoothly mapped to between 0 and 1 to avoid excessive rating inflation caused by the linear growth in the number of new applications.

[0127] The function's purpose is: when When it is less than 3, take ;when When the value is greater than or equal to 3, the value is set to 1, thus limiting the maximum contribution of the number of risky applications.

[0128] The preset weighting coefficients α, β, γ, and δ can be determined through experimentation or grid search based on actual business needs.

[0129] In some possible implementations, the solution provided in this embodiment may also include the following steps: training the user prediction model used in step S141.

[0130] Step S210: Based on the number of new applications installed, the number of risky applications installed, the average frequency of application use, and the risk time series characteristics of multiple sample users, obtain the sample risk vector corresponding to each sample user.

[0131] In step S210, the system first collects a large amount of historical user data, including known misled users (based on complaint confirmation) and normal users. For each sample user, the system extracts features in the same way as in step S131: number of new application installations, number of risky application installations, average application usage frequency, and first risk time-series feature (i.e., the time interval between installing a risky application and initiating a transaction). These feature values ​​are then combined into a sample risk vector.

[0132] Step S220: Based on the sample risk vector, label the sample users as induced users and normal users.

[0133] While obtaining the risk vector of the samples, the system also needs to provide a label for each sample user. During the above steps, the system clearly labels the sample users into two categories based on the historical complaint handling results and manual verification records: induced users (positive samples) and normal users (negative samples).

[0134] For example, based on historical complaint data and confirmed fraud cases, a database of typical behavioral patterns of lured users is constructed. Typical patterns include: Fast Trading Mode: And the transaction amount is more than twice the average.

[0135] Centralized installation mode: ≥5 new applications installed in the past 7 days, of which ≥2 are suspicious / risky applications.

[0136] Frequent usage pattern: Launching a suspicious app ≥3 times within 1 hour before the transaction, or using it for more than 30 minutes.

[0137] Multiple risk modes: Multiple suspicious applications exist on the device at the same time (indicating that the user has been repeatedly tricked).

[0138] Based on the above model, sample users are labeled as induced users and normal users.

[0139] Step S230: Train a user prediction model to identify induced users based on the sample risk vectors corresponding to induced users and normal users in the sample.

[0140] In step S230, the system can use the sample risk vector as the input feature, the corresponding label (induced or normal) as the supervision signal, and train a binary classification model using a supervised learning algorithm (such as XGBoost, logistic regression, support vector machine, etc.).

[0141] The goal of training is to enable the model to accurately predict whether a user is a lured user based on the input risk vector. After training, the model can be used in the prediction process of step S141, i.e., inputting the target user feature vector collected in real time and outputting the probability value of being lured. .

[0142] In some possible implementations, step S150 may include the following sub-steps.

[0143] Step S151: Obtain other non-behavioral risk scores.

[0144] Specifically, in addition to calculating transaction behavior risk scores, the system also obtains other non-behavioral risk scores. It should be noted that these other non-behavioral risk scores refer to risk assessment results that do not rely on the user's terminal operational behavior characteristics. Examples include static blacklist matching scores based on device fingerprints, transaction amount risk scores based on abnormal transaction amounts, risk scores based on IP address geolocation, and deviation scores based on the user's historical transaction habits. For instance, the system might obtain a device risk score (e.g., from 0 to 100) from the device fingerprint system, or an abnormal amount score from the transaction risk control engine. These scores are independent of the transaction behavior risk scores and can complement each other.

[0145] Step S152: Calculate the total risk score by weighting and summing the transaction behavior risk score and other non-behavioral risk scores.

[0146] In step S152, the transaction behavior risk score and other non-behavioral risk scores are merged into a comprehensive overall risk score. During the execution of the above steps, the system assigns a weight coefficient to each type of score and then performs a weighted summation.

[0147] For example, a risk score for trading behavior can be set. The weight is 0.6, and other non-behavioral risk scores are... If the weight is 0.4, then the total risk score is... .

[0148] For example, if the transaction behavior risk score is 85 points and other non-behavioral risk scores are 40 points, then the total risk score is 0.6 × 85 + 0.4 × 40 = 51 + 16 = 67 points. It should be noted that when multiple other non-behavioral risk scores exist, they can be combined into a single comprehensive non-behavioral score, or they can be weighted separately and then summed. The total risk score integrates multi-dimensional risk information and is more comprehensive than a single score.

[0149] Step S153: For the overall risk score of different score levels, generate corresponding risk transaction warning information or execute corresponding transaction interception actions.

[0150] In step S153, the final action can be determined based on the score level of the total risk score. During the execution of the above steps, the system pre-sets multiple score thresholds to divide the total risk score into several levels.

[0151] For example, a low-risk level is defined as a score < 40 points, a medium-risk level is defined as a score ≤ 40 points < 70 points, and a high-risk level is defined as a score ≥ 70 points.

[0152] For low-risk transactions, the system generates a "allow" instruction or no warning information, and the transaction proceeds normally. For medium-risk transactions, the system generates a warning information, such as through an interface pop-up, SMS notification, or background alarm, to inform business personnel to conduct manual review. The transaction is then allowed or rejected after the review is passed. For high-risk transactions, the system directly executes interception actions, such as rejecting the transaction request, freezing the account, or requiring secondary identity verification, and simultaneously generates a high-risk warning information for recording and notification.

[0153] For example, if the overall risk score is 67 (medium risk), the system can send a warning message to risk control personnel: "User XXX initiated a transaction, with an overall risk score of 67. Please conduct a manual review." If the overall risk score is 85 (high risk), the system will directly block the transaction and return a "Transaction failed, risk too high" message to the user, while also logging the block. This tiered approach avoids harming legitimate users while allowing for decisive intervention in high-risk transactions, achieving a balance between risk control and user experience.

[0154] Please refer to Figure 2 , Figure 2 This is a block diagram of an electronic device 100 provided in this embodiment. The electronic device 100 includes a risk transaction early warning device 110, a machine-readable storage medium 120, a processor 130, and a communication unit 140.

[0155] The machine-readable storage medium 120, processor 130, and communication unit 140 are electrically connected directly or indirectly to each other to achieve data transmission or interaction. For example, these components can be electrically connected to each other through one or more communication buses or signal lines. The risk trading early warning device 110 includes at least one software function module that can be stored in the machine-readable storage medium 120 in the form of software or firmware or embedded in the operating system (OS) of the electronic device 100. The processor 130 is used to execute the executable modules stored in the machine-readable storage medium 120, such as the software function modules and computer programs included in the risk trading early warning device 110.

[0156] The machine-readable storage medium 120 may be, but is not limited to, random access memory (RAM), read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), etc. The machine-readable storage medium 120 is used to store programs, and the processor 130 executes the programs after receiving execution instructions, thereby implementing the risk transaction warning method provided in this embodiment.

[0157] Processor 130 may be an integrated circuit chip with signal processing capabilities. The aforementioned processor can be a general-purpose processor, including a Central Processing Unit (CPU), a Network Processor (NP), etc.; it can also be a Digital Signal Processor (DSP), an Application-Specific Integrated Circuit (ASIC), a Field-Programmable Gate Array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. It can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor can be a microprocessor or any conventional processor.

[0158] Please refer to Figure 3This embodiment also provides a risk transaction early warning device 110, which includes at least one functional module that can be stored in machine-readable storage medium 120 in software form. Functionally, the risk transaction early warning device 110 may include an application identification module 111, a first feature acquisition module 112, a second feature acquisition module 113, a risk scoring module 114, and a risk early warning module 115.

[0159] Application identification module 111 is used to identify risky applications based on user complaint information; In this embodiment, the application identification module 111 can be used to execute... Figure 1 For a detailed description of the application identification module 111 shown in step S110, please refer to the description of step S110.

[0160] The first feature acquisition module 112 is used to acquire the installation time of the risk application on the target user's user terminal and the transaction time of the first transaction using the risk application, and calculate the interval between the transaction time and the installation time to obtain the risk time series feature. In this embodiment, the first feature acquisition module 112 can be used to perform... Figure 1 For a detailed description of the first feature acquisition module 112, see the description of step S120 shown.

[0161] The second feature acquisition module 113 is used to acquire user operation behavior features of the target user on the user terminal; In this embodiment, the second feature acquisition module 113 can be used to perform... Figure 1 For a detailed description of the second feature acquisition module 113, see the description of step S130 shown.

[0162] Risk scoring module 114 is used to calculate and obtain a transaction behavior risk score based on risk timing characteristics and user operation behavior characteristics for transaction requests generated by user terminals. In this embodiment, the risk scoring module 114 can be used to perform... Figure 1 For a detailed description of the risk scoring module 114 shown in step S140, please refer to the description of step S140.

[0163] The risk warning module 115 is used to generate risk warning information for trading behavior based on the risk score of the trading behavior.

[0164] In this embodiment, the risk warning module 115 can be used to execute... Figure 1 For a detailed description of the risk warning module 115, see step S150 shown.

[0165] In summary, this application provides a risk transaction early warning method and apparatus. After identifying risky applications based on user complaint information, it calculates risk temporal characteristics based on the installation time and transaction time of the risky applications on the target user's terminal. Then, it calculates a transaction behavior risk score based on the risk temporal characteristics and user operation behavior characteristics, thereby determining whether the target user's transaction actions are at risk of being defrauded. In this way, by using different features from multiple dimensions to determine the risk of user transaction actions, it can more accurately identify transactions with fraud risks and more effectively achieve risk early warning and risk transaction interception.

[0166] In the embodiments provided in this application, it should be understood that the disclosed apparatus and methods can also be implemented in other ways. The apparatus embodiments described above are merely illustrative. For example, the flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of apparatus, methods, and computer program products according to various embodiments of this application. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than those marked in the drawings. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram and / or flowchart, and combinations of blocks in block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or action, or using a combination of dedicated hardware and computer instructions.

[0167] In addition, the functional modules in the various embodiments of this application can be integrated together to form an independent part, or each module can exist independently, or two or more modules can be integrated to form an independent part.

[0168] If the aforementioned functions are implemented as software functional modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0169] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0170] The above descriptions are merely various embodiments of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A risk transaction early warning method, characterized in that, The method includes: Determine risky applications based on user complaint information; The installation time of the risky application on the target user's terminal and the transaction time of the transaction using the risky application are obtained, and the interval between the transaction time and the installation time is calculated to obtain the risk time series characteristics. Acquire user operation behavior characteristics of the target user's operations on the user terminal; For transaction requests generated by the user terminal, a transaction behavior risk score is calculated based on the risk time sequence characteristics and the user operation behavior characteristics; Based on the risk score of the transaction behavior, risk warning information for the transaction behavior is generated.

2. The method according to claim 1, characterized in that, The step of determining risky applications based on user complaint information includes: Obtain user complaint information within a preset time period; The user complaint information is processed by a large language model using preset prompt words to perform at least two rounds of filtering to obtain the names of multiple candidate applications and the risk confidence level of the candidate applications. The risky application is determined from among the candidate applications based on the risk confidence level.

3. The method according to claim 2, characterized in that, The step of using preset prompt words to instruct a large language model to perform at least two rounds of filtering on the user complaint information to obtain the names of multiple candidate applications and the risk confidence levels corresponding to the candidate applications includes: By controlling the large language model with a preset first prompt word, the name of the candidate application with fraud risk and the first candidate confidence level of each candidate application are extracted based on the user complaint information to obtain a set of candidate applications. The large language model adjusts the candidate applications and their corresponding risk confidence levels in the candidate application set by controlling the preset second prompt word.

4. The method according to claim 3, characterized in that, The step of adjusting the candidate applications and their corresponding risk confidence levels in the candidate application set using a preset second prompt word includes: The large language model is controlled by a preset second prompt word to perform misselection and omission checks on the candidate application set. For a misselected candidate application, the second candidate confidence level of the candidate application is set to 0; for a candidate application that is not misselected, the second candidate confidence level of the candidate application is set to be greater than 0; for a candidate application that is added to the candidate application set after being missed, the second candidate confidence level of the candidate application is set to be greater than 0. For the candidate applications selected by the first prompt word and confirmed to have risks by the second prompt word, the risk confidence level corresponding to the candidate application is obtained by weighted summation based on the first candidate confidence level and the second candidate confidence level.

5. The method according to claim 4, characterized in that, The method further includes: For the candidate applications that are added to the candidate application set through the second prompt word, record the basis for discovering the missed detection; The large language model is controlled by a preset third prompt word to supplement the candidate application set according to the discovery criteria. For the newly added candidate application set, the third candidate confidence of the candidate application is obtained. For the candidate applications selected and added to the candidate application set through the second and third prompt words, the candidate applications are marked as requiring manual review and confirmation; The step of determining the risky application from among the candidate applications based on the risk confidence level includes: Candidate applications whose risk confidence level is greater than a first preset threshold are labeled as risky applications, thereby obtaining a set of risky applications; Candidate applications whose risk confidence level is less than or equal to a first set threshold and greater than or equal to a second set threshold are marked as requiring manual review and confirmation. Candidate applications that are confirmed to be risky after manual review will be added to the risky application set.

6. The method according to claim 1, characterized in that, The step of calculating a transaction behavior risk score based on the risk time series characteristics and the user operation behavior characteristics includes: Based on the risk time-series characteristics and the user operation behavior characteristics, the probability value of being induced to install risky applications for the target user is predicted by pre-training a machine learning model. The risk score of the transaction behavior is calculated based on the probability of being induced, the characteristics of user operation behavior, and the risk time series characteristics.

7. The method according to claim 6, characterized in that, The step of obtaining user operation behavior characteristics based on the target user's operations on the user terminal includes: Get the number of new applications installed on the user terminal within the most recent set number of days. The number of risky applications installed on the user terminal and average application usage frequency And obtain the risk time series features. ; The step of predicting the probability of a target user being induced to install a risky application using a pre-trained user prediction model based on the risk time-series characteristics and the user operation behavior characteristics includes: The number of installations The number of applications installed Average frequency of use of the application and the aforementioned risk time series characteristics Composition of risk vector The input is a pre-trained user prediction model, which predicts the probability value of the target user being tricked into installing risky applications. ;in, .

8. The method according to claim 7, characterized in that, The step of calculating the transaction behavior risk score based on the induced probability value, the user operation behavior characteristics, and the risk time series characteristics includes: Based on the pre-defined correspondence between multiple time-duration segments and time-series risk weights, the risk time-series characteristics are determined. Corresponding time-series risk weights ; The risk score for the transaction behavior is calculated using the following formula. : in, , , , For preset weighting coefficients, The function is used to smooth the number of installations. The impact.

9. The method according to claim 7, characterized in that, The method further includes: Based on the number of new applications installed by multiple sample users, the number of risky applications installed, the average frequency of application use, and the risk time series characteristics, obtain the sample risk vector corresponding to each sample user; Based on the sample risk vector, the sample users are labeled as induced users and normal users. The user prediction model is trained based on the sample risk vectors corresponding to the induced users and the normal users in the sample to identify the induced users.

10. The method according to any one of claims 1 to 9, characterized in that, The step of generating risk warning information for the transaction behavior based on the transaction behavior risk score includes: Obtain other non-behavioral risk scores; The total risk score is obtained by weighted summation of the transaction behavior risk score and the other non-behavioral risk scores. For the overall risk score at different score levels, generate corresponding risk transaction warning information or execute corresponding transaction interception actions.

11. A risk transaction early warning device, characterized in that, The risk transaction early warning device includes: The application identification module is used to identify risky applications based on user complaint information; The first feature acquisition module is used to acquire the installation time of the risk application on the target user's user terminal and the transaction time of the first transaction using the risk application, and calculate the interval between the transaction time and the installation time to obtain risk time series features. The second feature acquisition module is used to acquire user operation behavior features of the target user's operations on the user terminal. The risk scoring module is used to calculate a transaction behavior risk score for the transaction requests generated by the user terminal based on the risk time sequence characteristics and the user operation behavior characteristics. The risk warning module is used to generate risk warning information for the transaction behavior based on the risk score of the transaction behavior.