Risk identification method and system
Patent Information
- Application Number
- CN202610810389.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-06-05
- Publication Date
- 2026-09-11
AI Technical Summary
然而,随着欺诈手段的演化,申请者常通过伪造、变造或复用他人信息的方式规避单点检测,导致传统风险评估方式的效果难以达到预期,影响资产质量与运营安全
Smart Images

Figure CN122736755A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of financial technology, and in particular to a risk identification method and system. Background Technology
[0002] With the full online transformation of various resource disbursement services (financial loans, resource applications, etc.), the scale of these services is growing rapidly. Risk assessment based on application data is a core element in ensuring fund security. Existing risk assessment solutions typically rely on rule engines or machine learning models to extract and verify isolated features of fields in the current application (such as applicant's name, mobile phone number, ID number, address, etc.). However, with the evolution of fraud methods, applicants often circumvent single-point detection by forging, altering, or reusing others' information, rendering traditional risk assessment methods ineffective and impacting asset quality and operational security. Summary of the Invention
[0003] To address the aforementioned problems in the prior art, this invention discloses a risk identification method and system that can improve the comprehensiveness and accuracy of risk identification, while also increasing its efficiency. The technical solution disclosed in this invention is as follows: According to one aspect of the disclosed embodiments of the present invention, a risk identification method is provided, the method comprising: Obtain multiple initial request information carried by the resource allocation request, as well as a historical relationship graph; the historical relationship graph is used to characterize the association between the request information carried by the historical resource allocation requests. At least one initial request information is modified to obtain multiple target request information; the multiple target request information includes modified target information and other initial request information, wherein the other initial request information is the request information other than the modified initial request information among the multiple initial request information. In the historical relationship graph, the node corresponding to the target correction information is taken as the target node, and the attribute information corresponding to the target node and its associated nodes is matched in parallel with the corresponding target request information to obtain the matching result corresponding to each target request information. Based on the matching results corresponding to each target request information, the risk identification result of the resource allocation request is determined.
[0004] Optionally, determining the risk identification result of the resource allocation request based on the matching result corresponding to each target request information includes: Based on the matching result between the attribute information corresponding to each node in each adjacent node pair and the corresponding target request information, at least one unilateral risk identification result is determined; the adjacent node pair includes the target node and two nodes in the associated nodes connected by an associated edge. If the unilateral risk identification result meets the first preset unilateral risk result, calculate the risk assessment result corresponding to the resource allocation request; the risk severity corresponding to the first preset unilateral risk result is lower than the preset severity. If the risk assessment results meet the preset conditions, the risk identification results are determined.
[0005] Optionally, determining the risk identification result when the risk assessment result meets preset conditions includes: If the risk assessment result meets the preset conditions, determine the initial risk identification result of the resource allocation request; Based on the matching results between the attribute information of each node in each pair of adjacent nodes in the relational subgraph and the corresponding target request information, the corresponding unilateral risk identification results are adjusted to obtain the subgraph risk identification results; the relational subgraph includes the target node and at least three nodes in the associated nodes connected by at least two associated edges; The risk identification result is determined from the initial risk identification result and the subgraph risk identification result.
[0006] Optionally, when the unilateral risk identification result meets the first preset unilateral risk result, calculating the risk assessment result corresponding to the resource allocation request includes: Obtain initial count information; The at least one unilateral risk identification result is iterated through; When the current unilateral risk identification result is reached and the current unilateral risk identification result satisfies the first preset unilateral risk result, the initial count information is incremented by a preset value until the traversal ends, and the target count information is obtained. The target count information is multiplied by the preset evaluation information to obtain the risk evaluation result.
[0007] Optionally, the risk identification result includes a first risk identification result, and the method further includes: If the unilateral risk identification result satisfies the second preset unilateral risk result, the risk identification result is determined to be the first risk identification result; the risk severity corresponding to the second preset unilateral risk result is lower than the preset severity.
[0008] Optionally, the risk identification result includes a first risk identification result, a second risk identification result, and a third risk identification result, wherein determining the risk identification result when the risk assessment result meets preset conditions includes: If the risk assessment result is greater than or equal to the first preset assessment threshold, the risk identification result is determined to be the first risk identification result; If the risk assessment result is greater than or equal to the second preset assessment threshold and less than the first preset assessment threshold, the risk identification result is determined to be the second risk identification result. If the risk assessment result is less than the second preset assessment threshold, the risk identification result is determined to be the third risk identification result.
[0009] Optionally, determining at least one unilateral risk identification result based on the matching result between the attribute information corresponding to each node in each adjacent node pair and the corresponding target request information includes: Based on the matching results between the attribute information of each node in each adjacent node pair and the corresponding target request information, determine the combination of unilateral risk features corresponding to each adjacent node pair; Based on a preset mapping relationship, the unilateral risk identification result corresponding to the unilateral risk feature combination is determined; the preset mapping relationship is used to characterize the correspondence between the unilateral risk pattern and the unilateral risk identification result.
[0010] Optionally, the preset mapping relationship is determined in the following way: Identify multiple frequent association structures in the historical relationship graph; each frequent association structure includes at least one association edge and a corresponding node; In the instance of the historical resource distribution request, calculate the attribute combination distribution parameters of the associated nodes in each frequent association structure; If the deviation between the distribution parameter and the corresponding preset distribution parameter is greater than a preset deviation threshold, the frequently associated structure and its corresponding attribute combination are determined as a unilateral risk feature combination. Based on the risk identification accuracy of each unilateral risk feature combination, determine the unilateral risk identification result corresponding to each unilateral risk feature combination; The correspondence between each combination of unilateral risk features and the unilateral risk identification result is determined as the preset mapping relationship.
[0011] Optionally, obtaining the historical relationship graph includes: Obtain the request information carried in the historical resource distribution request, the request information including request object identification information, associated object identification information, the organization to which the request object belongs, and the living area information of the request object; The request object identification information, the associated object identification information, the affiliated organization information, and the living area information are respectively mapped to nodes; Based on the pairwise relationships between the request object identifier information, the associated object identifier information, the affiliated organization information, and the living area information, determine the association edge between the corresponding two nodes; Based on the nodes and associated edges, the historical relationship graph is generated.
[0012] According to another aspect of the disclosed embodiments of the present invention, a risk identification system is provided, the system comprising: The acquisition module is used to acquire multiple initial request information carried by the resource allocation request, as well as a historical relationship graph; the historical relationship graph is used to characterize the association between the request information carried by the historical resource allocation requests. A correction module is used to correct at least one initial request information to obtain multiple target request information; the multiple target request information includes corrected target information and other initial request information, wherein the other initial request information is request information other than the corrected initial request information among the multiple initial request information. The matching module is used to take the node corresponding to the target correction information in the historical relationship graph as the target node, and to perform parallel matching of the attribute information corresponding to the target node and its associated nodes with the corresponding target request information to obtain the matching result corresponding to each target request information. The risk identification result determination module is used to determine the risk identification result of the resource allocation request based on the matching result corresponding to each target request information.
[0013] According to another aspect of the disclosed embodiments of the present invention, an electronic device for risk identification is provided, including a processor and a memory, wherein the memory stores at least one instruction, the at least one instruction being loaded and executed by the processor to implement the risk identification method described in any of the preceding claims.
[0014] According to another aspect of the disclosed embodiments of the present invention, a computer-readable storage medium is provided, wherein at least one instruction is stored therein, the at least one instruction being loaded and executed by a processor to implement the risk identification method described in any of the preceding claims.
[0015] According to another aspect of the disclosed embodiments of the present invention, a computer program product containing instructions is provided, which, when run on a computer, causes the computer to perform the service risk identification method described in any of the above embodiments of the present invention.
[0016] The risk identification method and system provided by this invention have the following technical effects: This invention acquires multiple initial request information carried by a resource allocation request, as well as a historical relationship graph, wherein the historical relationship graph is used to characterize the association between the request information carried by historical resource allocation requests. Then, at least one initial request information is modified to obtain multiple target request information, wherein the multiple target request information includes modified target information and other initial request information, which are request information other than the modified initial request information. Furthermore, the node corresponding to the target modified information in the historical relationship graph is taken as the target node, and the attribute information corresponding to the target node and its associated nodes is matched in parallel with the corresponding target request information to obtain the matching result corresponding to each target request information. Based on the matching result corresponding to each target request information, the risk identification result of the resource allocation request is determined.
[0017] Therefore, by correcting the initial request information carried in the resource allocation request, generating target corrected information, and retaining other initial information, the risk misjudgment and omission caused by input errors can be solved by dynamically correcting the request information. Subsequently, the corrected information is used as an anchor point to locate the target node in the historical relationship graph, and multi-dimensional attribute information in its associated neighborhood is matched in parallel. Based on the multi-dimensional matching results, the risk of the resource allocation request is comprehensively judged, thereby realizing targeted association query and cross-information association risk identification, improving the comprehensiveness and accuracy of risk identification, and improving the efficiency of risk identification.
[0018] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and are not intended to limit this disclosure. Attached Figure Description
[0019] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0020] Figure 1 This is a flowchart illustrating a risk identification method according to an exemplary embodiment; Figure 2 This is a schematic diagram illustrating a modified interface according to an exemplary embodiment; Figure 3 This is a schematic diagram illustrating a process for determining risk identification results according to an exemplary embodiment; Figure 4This is a schematic diagram illustrating another process for determining risk identification results according to an exemplary embodiment; Figure 5 This is a block diagram illustrating a risk identification system according to an exemplary embodiment; Figure 6 This is a block diagram illustrating a terminal electronic device for risk identification according to an exemplary embodiment; Figure 7 This is a block diagram illustrating a server electronic device for risk identification according to an exemplary embodiment. Detailed Implementation
[0021] To enable those skilled in the art to better understand the technical solutions disclosed in this invention, the technical solutions in the disclosed embodiments will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are merely some embodiments of this invention, and not all embodiments. All other embodiments obtained by those skilled in the art based on the embodiments of this invention without creative effort are within the scope of protection of this invention.
[0022] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention disclosed herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or server that comprises a series of steps or units is not necessarily limited to those explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or devices.
[0023] The following describes one risk identification method of this application; please refer to [link / reference]. Figure 1 , Figure 1 This is a flowchart illustrating a risk identification method according to an exemplary embodiment. This specification provides the operational steps of the method as described in the embodiments or flowchart, but based on conventional or non-inventive labor, more or fewer operational steps may be included. The order of steps listed in the embodiments is merely one possible execution order among many and does not represent the only execution order. In actual system or server product execution, the method can be executed sequentially or in parallel (e.g., in a parallel processor or multi-threaded processing environment) as shown in the embodiments or drawings. Specifically, as... Figure 1 As shown, the above method may include: S101: Obtain information on multiple initial requests carried in the resource allocation request, as well as the historical relationship graph.
[0024] In one specific embodiment, the resource allocation request can be any resource allocation request that requires risk identification. Specifically, the resource allocation request may include a credit loan request, a server resource or cloud computing power quota request, an energy quota request, etc. Correspondingly, the resources allocated in the resource allocation request may be financial resources, server resources or cloud computing power resources, energy resources, etc. The initial request information may be the information provided by the requesting object when initiating the resource allocation request, and the information required for the resource allocation request. The request information may include the requesting object's identification information, associated object's identification information, the requesting object's affiliated organization information, and the requesting object's living area information. Specifically, the requesting object's identification information may include the requesting object's name, contact information, and identification number, etc. The associated object's identification information may include the associated object's name, contact information, etc. The associated object may be an object associated with the requesting object (such as the requesting object's contact person), the requesting object's affiliated organization information may include the name and address of the requesting object's work unit, etc., and the requesting object's living area information may include the requesting object's residential address information (such as permanent address, home address, etc.). Optionally, the request information may also include the requested resource quantity, request period, etc. Specifically, in the case of a credit loan request, the requested resource quantity may be the loan amount.
[0025] In one specific embodiment, the historical relationship graph can be used to characterize the association between the request information carried by historical resource allocation requests. The historical resource allocation requests occurred before the current resource allocation requests that require risk identification, and the request information carried by the historical resource allocation requests has been recorded and stored.
[0026] Optionally, obtaining the historical relationship graph mentioned above may include: Obtain the request information carried in historical resource distribution requests. The request information includes the request object identification information, the associated object identification information, the organization to which the request object belongs, and the living area information of the request object. Map the request object identification information, associated object identification information, affiliated organization information, and living area information to nodes respectively; Based on the pairwise relationships between the request object identifier information, associated object identifier information, affiliated organization information, and living area information, determine the association edge between the corresponding two nodes; A historical relationship graph is generated based on nodes and associated edges.
[0027] In one specific embodiment, the information types included in the request information can be consistent with the initial request information described above. Each information type can be mapped to a node type. The historical relationship graph can include multiple different node types. Specifically, node types can include request object nodes (unique identifiers of request objects), living area nodes, contact information nodes, organization name nodes, organization address nodes, and organization contact information nodes. Each node type contains one or more attributes. Specifically, the request object node can contain the name and ID number of the request object, the contact information node can contain the contact information of the request object and related objects, the organization name node can contain the name of the request object's work unit and unified social credit code, the organization address node can contain the detailed address of the request object's work unit, the organization contact information node can contain the contact information of the request object's work unit, and the living area node can contain the detailed residential address of the request object.
[0028] In one specific embodiment, the associated edge can be used to define the association relationship between nodes. Specifically, the associated edge can include a request object associated edge, an associated object associated edge, an organization associated edge, an organization address associated edge, an organization contact information associated edge, and a living area associated edge. The request object associated edge can connect the request object node and the contact information node. The associated object associated edge can connect the request object node and the contact information node, representing the edge type of the association relationship of the contact information filled in by an applicant. The organization associated edge can connect the request object node and the organization name node. The organization address associated edge can connect the organization name node and the organization address node. The organization contact information associated edge can connect the organization name node and the organization contact information node. The living area associated edge can connect the request object node and the living area node.
[0029] In practical applications, the data of existing historical resource issuance requests are imported in batches, processed in batches according to the application time, and data cleaning, deduplication, and data consistency checks are performed. The data of tens of millions of historical applications is converted into a knowledge graph structure to form a historical relationship graph.
[0030] S103: Correct at least one initial request information to obtain multiple target request information.
[0031] In one specific embodiment, the multiple target request information may include corrected target information and other initial request information. The other initial request information may be request information other than the corrected initial request information among the multiple initial request information. That is, the multiple target request information may include corrected information obtained by correcting a portion of the multiple initial request information, as well as other uncorrected portions of the multiple initial request information other than the corrected portion.
[0032] In practical applications, the system provides a correction interface for approvers to operate, such as... Figure 2 As shown, the correction interface may include: an original information display area: displaying the initial request information; a correction input area: providing input boxes for approvers to revise the fields that need correction; a correction confirmation control: after the approver completes the correction, clicking confirmation triggers the generation of the revised application information; and a correction record area: displaying the history of this correction, including the value before correction, the value after correction, the correction time, and the operator. Approvers can revise any one or more fields from the following categories: contact information of the requesting party, contact person's contact information, work unit name, work unit address, work unit contact information, and residential address, based on the actual situation. For example, if a typo is found in the contact information filled in by the applicant, the approver can correct "138xxxx2222" to "138xxxx2223".
[0033] Optional, the correction function is optional, and the system can also proceed to the next matching step automatically without correction. It supports both human-machine collaborative correction mode and fully automatic matching mode, and has flexible applicability.
[0034] S105: In the historical relationship graph, the node corresponding to the target correction information is taken as the target node, and the attribute information corresponding to the target node and its associated nodes is matched in parallel with the corresponding target request information to obtain the matching result corresponding to each target request information.
[0035] Specifically, the attribute information values contained in the nodes are matched with the target request information values. For example, the name of the current requesting object can be matched with the names of historical requesting objects and historically associated objects; the contact information of the current requesting object can be matched with the contact information of historical requesting objects and historically associated objects; the work address of the current requesting object can be matched with the work address and residential address of historical requesting objects; the work contact information of the current requesting object can be matched with the work contact information of historical requesting objects; and the residential address of the current requesting object can be matched with the work address and residential address of historical requesting objects. This cross-dimensional association matching can be achieved through multi-hop queries in the knowledge graph. The matching results can be used to indicate whether the attribute information values are consistent with the corresponding target request information values.
[0036] In practical applications, the correction action is not just about modifying the string, but also serves as a dynamic anchor point for graph queries. When the approver corrects the "unit name", the system does not simply replace the string, but can also dynamically increase the query weight of that node during graph queries.
[0037] S107: Based on the matching results corresponding to each target request information, determine the risk identification result of the resource allocation request.
[0038] In one specific embodiment, the risk identification result can be used to characterize the severity of the risk in a resource allocation request and its impact on the overall business. The risks involved in the resource allocation request may include, but are not limited to, information misuse, theft, fraud, or deception. Specifically, the risk identification result can be represented by a score, a level, etc. When represented by a score, a higher score indicates a higher degree of risk severity and a greater impact on the overall business. When represented by a level, for example, the risk identification result can be divided into three levels: high, medium, and low. A high-level risk identification result indicates a high degree of risk severity and a high degree of impact on the overall business.
[0039] Optional, such as Figure 3 As shown, the risk identification results for resource allocation requests, determined based on the matching results corresponding to each target request information, may include: S301: Based on the matching results between the attribute information of each node in each adjacent node pair and the corresponding target request information, determine at least one unilateral risk identification result.
[0040] In one specific embodiment, an adjacent node pair may include two nodes connected by an association edge, which are both target nodes and associated nodes. The unilateral risk identification result can be the matching result between the attribute information of the two nodes connected by an association edge and the corresponding target request information, and the corresponding risk identification result. In practical applications, when the adjacent nodes are a request object node and a contact information node, if the contact information node contains the same contact information for historical request objects as the current resource allocation request, but the name of the historical request object contained in the request object node associated with the contact information node is different from the name of the request object in the current resource allocation request, then there is a risk of identity theft, and the risk identification result corresponding to this matching result can be high-risk. Alternatively, when the adjacent nodes are a request object node and a contact information node, another situation may occur: if the contact information node contains the same contact information for historical associated objects as the current resource allocation request, but the name of the historical request object contained in the request object node associated with the contact information node is different from the name of the request object in the current resource allocation request, then there is a risk of association reuse, and the risk identification result corresponding to this matching result can be medium-risk.
[0041] Optionally, determining at least one unilateral risk identification result based on the matching results between the attribute information corresponding to each node in each adjacent node pair and the corresponding target request information may include: Based on the matching results between the attribute information of each node in each adjacent node pair and the corresponding target request information, determine the combination of unilateral risk features corresponding to each adjacent node pair; Based on the preset mapping relationship, determine the unilateral risk identification result corresponding to the combination of unilateral risk features.
[0042] In one specific embodiment, the combination of unilateral risk features may include target request information and corresponding attribute information for matching, as well as the matching results (consistent or inconsistent) of each information. A preset mapping relationship can be used to characterize the correspondence between unilateral risk patterns and unilateral risk identification results.
[0043] Optionally, the above-mentioned preset mapping relationship can be determined in the following way: Identify multiple frequent association structures in the historical relationship graph; each frequent association structure includes at least one association edge and a corresponding node. In instances of historical resource allocation requests, calculate the attribute combination distribution parameters of associated nodes in each frequently associated structure; If the deviation between the distribution parameter and the corresponding preset distribution parameter is greater than the preset deviation threshold, the frequently associated structure and its corresponding attribute combination will be determined as a unilateral risk feature combination. Based on the risk identification accuracy of each unilateral risk feature combination, determine the unilateral risk identification result corresponding to each unilateral risk feature combination; The correspondence between each combination of unilateral risk features and the unilateral risk identification result is determined as a preset mapping relationship.
[0044] In one specific embodiment, the attribute combination distribution parameter can be used to characterize the distribution of different attribute combination conditions in historical resource allocation request instances for a frequently associated structure. That is, for an instance of a frequently associated structure appearing in a historical resource allocation request, the distribution characteristics of the value combinations (e.g., same / different, consistent / conflicting, reuse count, etc.) formed by its associated nodes on a preset attribute dimension are statistically analyzed, including but not limited to occurrence frequency, inconsistency ratio, or anchor point neighborhood count statistics. Specifically, for each historical occurrence (instance) of a frequently associated structure, based on node attributes, a distributional statistic / proportion index is calculated to measure the commonality of a certain attribute combination state (consistent / inconsistent / reusable / conflicting) under that associated structure.
[0045] In one specific embodiment, a unilateral risk feature combination can be composed of a unilateral topological unit (single-hop node-edge-node) with a frequently associated structure and the attribute combination conditions corresponding to the unit. When the attribute combination distribution parameters of the unit deviate significantly from the preset benchmark distribution, the unit and the attribute combination conditions are recorded together as a unilateral risk feature combination and used to construct a preset mapping relationship.
[0046] In practical applications, frequently occurring entity connection structures (frequent association structures) can be mined from historical request data. Anomaly detection is performed on the statistical distribution of attribute combinations on these structures to filter out risk feature combinations with high discriminative power, thereby constructing a pre-defined mapping relationship. First, all historical resource disbursement request data (such as credit applications) is acquired. Unstructured information in the requests is standardized (e.g., address cleaning, name denoising, and phone number normalization) to construct a historical relationship graph. Then, the gSpan frequent subgraph mining algorithm is used to process the graph, filtering out subgraphs that appear more frequently in historical requests than a certain frequency value as frequent association structures. For example, a frequent association structure might be mined with the topology: Request object node A - [Request object association edge] - Contact information node - [Request object association edge] - Request object node B (i.e., a contact information is used by two request objects simultaneously as the request object's own contact information). Next, for each frequent association structure, all instances of it in the historical relationship graph are traversed. For each structure, the attribute combinations of its associated nodes are extracted. The attribute combination distribution parameter can be the percentage of instances in the structure that satisfy a specific attribute conflict condition. Next, a baseline distribution and deviation determination are performed. Using data from historical compliant requests (approved and without default), the baseline distribution parameter value of the above structure in normal samples is calculated. The actual distribution parameter is also calculated for all historical requests (including risk samples). If there is a significant deviation between the actual distribution and the baseline distribution parameter, the frequently associated structure and its corresponding attribute combination conditions are encapsulated into a one-sided risk feature combination. Then, using historical labeled data, the risk identification accuracy of the one-sided risk feature combination is calculated. Thresholds are set (e.g., 20%, 50%), and the risks corresponding to the one-sided risk feature combination are classified into high, medium, and low risk levels, thus obtaining a preset mapping relationship. Specifically, high-severity risks can directly point to identity theft, organized fraud, or confirmed associated risks; moderately severe risks can point to information anomalies that do not necessarily constitute fraud and require further verification; and low-severity risks can point to potential associations that may be reasonable (e.g., shared office addresses).
[0047] Specifically, the preset mapping relationship can be shown in Table 1:
[0048] Table 1 Preset Mapping Relationship Table
[0049] S303: If the unilateral risk identification result meets the first preset unilateral risk result, calculate the risk assessment result corresponding to the resource allocation request.
[0050] In one specific embodiment, the risk severity corresponding to the first preset unilateral risk result is lower than the preset severity. Taking the risk identification result as a level representation, the first preset unilateral risk result can include medium level and low level. The risk assessment result can be a score for the non-high-level risks involved in the resource allocation request.
[0051] Optionally, if the unilateral risk identification result meets the first preset unilateral risk result, the risk assessment result corresponding to the computing resource allocation request includes: Obtain initial count information; Iterate through at least one unilateral risk identification result; If the current unilateral risk identification result is reached during the traversal, and the current unilateral risk identification result meets the first preset unilateral risk result, the initial count information is incremented by a preset value until the traversal ends, and the target count information is obtained. The target count information is multiplied by the preset evaluation information to obtain the risk assessment result.
[0052] In one specific embodiment, the initial count information can be set to 0, the preset value can be set to 1, and the preset evaluation information can be set according to application requirements, for example, it can be set to 10. A resource allocation request may involve multiple risks. For each currently identified unilateral risk as low to medium risk, the count is incremented by 1. The final count represents the number of low to medium risks among the multiple risks involved in the request. This number is then multiplied by the preset evaluation information to obtain the risk evaluation result of the resource allocation request.
[0053] S305: If the risk assessment results meet the preset conditions, determine the risk identification results.
[0054] Specifically, the preset conditions can be set according to the actual application requirements.
[0055] Optional, such as Figure 4 As shown, when the risk assessment results meet the preset conditions, the determination of the risk identification results may include: S401: If the risk assessment results meet the preset conditions, determine the initial risk identification results of the resource allocation request.
[0056] Specifically, the corresponding risk identification results can be determined based on the aforementioned risk assessment results, namely the initial risk identification results mentioned above.
[0057] S403: Based on the matching results between the attribute information of each node in each pair of adjacent nodes in the relational subgraph and the corresponding target request information, adjust the corresponding unilateral risk identification results to obtain the subgraph risk identification results.
[0058] In one specific embodiment, the relational subgraph may include at least three nodes connected by at least two related edges among the target node and associated nodes. Specifically, multiple one-sided matching results can be cross-validated in association, and the risk results corresponding to the original one-sided matching results can be adjusted to obtain the risk identification results of the aforementioned subgraph. Thus, based on the combination and superposition of matching results (i.e., simultaneous hits), the risk results corresponding to the original one-sided matching results are improved and strengthened.
[0059] Specifically, the combination and superposition of matching results can be seen in Table 2: Table 2. Combination and Overlay of Matching Results
[0060] Optionally, the risk level can be increased based on the discrepancy between at least two matches between various related attribute information and the request information. This could be achieved by raising the risk level from medium to high, or from low to high. For example, using cross-validation of the three fields of organization information (organization name, organization address, and organization contact information), if only one type of information matches while the other two do not, the risk level can be increased by one level. If two types of information match while the other does not, the risk level can be increased by two levels. Alternatively, if the matching results of the contact information of the requesting party and the contact information of their associated persons both point to the same risk subject, the risk level can be increased by two levels.
[0061] S405: Determine the risk identification results from the initial risk identification results and the subgraph risk identification results.
[0062] In one specific embodiment, the risk identification result with the higher risk level between the initial risk identification result and the subgraph risk identification result can be determined as the aforementioned risk identification result. For example, if the initial risk identification result is medium level and the subgraph risk identification result is high level, then the final risk identification result is high level.
[0063] Optionally, the risk identification results may include a first risk identification result, a second risk identification result, and a third risk identification result, with the severity of the corresponding risks decreasing sequentially. When the risk identification results are represented by levels, the first risk identification result, the second risk identification result, and the third risk identification result may correspond to high level, medium level, and low level, respectively.
[0064] Under the premise that the risk assessment results meet the preset conditions, the risk identification results can include: If the risk assessment result is greater than or equal to the first preset assessment threshold, the risk identification result is determined as the first risk identification result. If the risk assessment result is greater than or equal to the second preset assessment threshold and less than the first preset assessment threshold, the risk identification result is determined as the second risk identification result. If the risk assessment result is less than the second preset assessment threshold, the risk identification result is determined as the third risk identification result.
[0065] In one specific embodiment, the corresponding risk identification result can be determined based on the preset range into which the risk assessment result falls. The higher the risk assessment result, the higher the risk level of the corresponding risk identification result. Specifically, the first preset assessment threshold and the second preset assessment threshold can be set according to actual application needs. For example, the first preset assessment threshold and the second preset assessment threshold can be set to 20 points and 50 points, respectively.
[0066] Optionally, the above method may also include: If the unilateral risk identification result meets the second preset unilateral risk result, the risk identification result is determined as the first risk identification result.
[0067] In one specific embodiment, the risk severity corresponding to the second preset unilateral risk result is lower than the preset severity. Taking the risk identification result as a level representation, the first preset unilateral risk result can include a high level. The first risk identification result can correspond to a high level.
[0068] In practical applications, after matching the attributes of the nodes associated with a single edge with the corresponding request information, the matching result can determine that the corresponding risk is high (e.g., the highest level). This risk identification result can then be directly output for high-risk warning, facilitating timely identification of the risk in the resource allocation request and appropriate handling. If the risk result determined by the one-sided matching result is low to medium risk, on the one hand, a risk score (i.e., risk assessment result) can be calculated based on the number of identified low to medium risk risks and their corresponding weights to determine the corresponding risk level. On the other hand, multiple one-sided matching results can be cross-validated, adjusting the risk result corresponding to the original one-sided matching result. The higher of the two risk results is then determined as the final output risk result, and the resource allocation request is handled accordingly.
[0069] In one specific implementation, when a single request needs correction, the following example illustrates the process for correcting the contact information of the requesting party. In the current resource allocation request A, the requesting party fills in their contact information as "138xxxx2222" and their name as "Zhang San". The approver discovers a typo in the approval interface; the phone number should actually be "138xxxx2223". The approver corrects "138xxxx2222" to "138xxxx2223" in the contact information correction input box on the correction interface and clicks the confirmation button. The system generates the corrected request information, where the requesting party's contact information is updated to "138xxxx2223". Then, the corrected contact information "138xxxx2223" was matched with historical credit data stored based on the knowledge graph: it was found that the contact information of the requesting object in historical resource disbursement request B was the same, but the name was "Li Si", triggering the risk mode (1) in Table 1 above; at the same time, it was found that the contact information of the associated object in historical resource disbursement request C was "138xxxx2223", and the contact person's name was "Zhang San", triggering the risk mode (2) in Table 1 above. Further, based on the matching results, it was determined that resource disbursement request A had a high risk, a high-risk warning was generated and pushed to the approval personnel.
[0070] In a situation where multiple request details need correction, the current resource allocation request D contains the following information: the requester's contact information is 139xxxx2222, the associated contact information is 138xxxx3333, the requester's employer is XX Technology Co., Ltd., the employer's address is Building C, District B, City A, and the employer's contact number is 010-xyz. During the review, the approver discovered the following issues: 1. The name corresponding to the associated contact information "138xxxx3333" should be "Wang Wu," not "Wang Wu" as filled in by the applicant; 2. The employer's name "XX Technology Co., Ltd." should actually be "XX Technology Co., Ltd." The approver corrected both the associated contact information and the employer's name on the correction interface. Subsequently, the corrected information was matched in multiple dimensions. The contact information of the requested object was the same as that of the associated object in the historical resource distribution request E, triggering the risk mode (3) in Table 1 above. The corrected associated object name "Wang Wu" and the associated object contact information "138xxxx3333" matched the corresponding information of the requested object in the historical resource distribution request F, triggering the risk mode (5) in Table 1 above. The corrected unit name "XX Technology Co., Ltd." was the same as the unit name in the historical resource distribution request G, but the unit address was "a city d district e building", triggering the risk mode (8) in Table 1 above. At the same time, the unit telephone number "010-xyz" was the same as the unit contact information in the historical resource distribution request H, but the unit name was "YY Technology Co., Ltd.", triggering the risk mode (13) in Table 1 above. Furthermore, if there were any pairwise inconsistencies in the three fields of unit name, unit address, and unit telephone number (name and address inconsistency, telephone and name inconsistency), the risk level was raised by one level. Finally, a high-risk warning was output, along with a detailed risk mode hit list and cross-validation explanation.
[0071] Optionally, the above method may also include: Based on the risk identification results of resource allocation requests, determine the handling strategy for resource allocation requests.
[0072] Specifically, taking the risk identification results as high-level, medium-level, and low-level as an example, if the risk identification result is high-level, the handling strategy can be to automatically reject the resource allocation request or transfer it to manual review; if the risk identification result is medium-level, the handling strategy can be to suggest manual review; if the risk identification result is low-level, the handling strategy can be to accumulate points and trigger an early warning after reaching a threshold.
[0073] As can be seen from the technical solutions provided in the embodiments of this specification above, this specification obtains multiple initial request information carried by a resource allocation request, as well as a historical relationship graph. The historical relationship graph is used to characterize the association between the request information carried by historical resource allocation requests. Then, at least one initial request information is modified to obtain multiple target request information. The multiple target request information includes the modified target modification information and other initial request information, which are the request information other than the modified initial request information among the multiple initial request information. Furthermore, the node corresponding to the target modification information in the historical relationship graph is taken as the target node, and the attribute information corresponding to the target node and its associated nodes is matched in parallel with the corresponding target request information to obtain the matching result corresponding to each target request information. Based on the matching result corresponding to each target request information, the risk identification result of the resource allocation request is determined.
[0074] Therefore, by correcting the initial request information carried in the resource allocation request, generating target corrected information, and retaining other initial information, the risk misjudgment and omission caused by input errors can be solved by dynamically correcting the request information. Subsequently, the corrected information is used as an anchor point to locate the target node in the historical relationship graph, and multi-dimensional attribute information in its associated neighborhood is matched in parallel. Based on the multi-dimensional matching results, the risk of the resource allocation request is comprehensively judged, thereby realizing targeted association query and cross-information association risk identification, improving the comprehensiveness and accuracy of risk identification, and improving the efficiency of risk identification.
[0075] This invention also provides a risk identification system, such as... Figure 5 As shown, the system includes: The acquisition module 510 is used to acquire multiple initial request information carried by the resource allocation request, as well as a historical relationship graph; the historical relationship graph is used to characterize the association between the request information carried by the historical resource allocation requests. The correction module 520 is used to correct at least one initial request information to obtain multiple target request information; the multiple target request information includes corrected target information and other initial request information, wherein the other initial request information is request information other than the corrected initial request information among the multiple initial request information. The matching module 530 is used to take the node corresponding to the target correction information in the historical relationship graph as the target node, and perform parallel matching of the attribute information corresponding to the target node and its associated nodes with the corresponding target request information to obtain the matching result corresponding to each target request information. The risk identification result determination module 540 is used to determine the risk identification result of the resource allocation request based on the matching result corresponding to each target request information.
[0076] Optionally, the risk identification result determination module 540 includes: The first unilateral risk identification result determination unit is used to determine at least one unilateral risk identification result based on the matching result between the attribute information corresponding to each node in each adjacent node pair and the corresponding target request information; the adjacent node pair includes the target node and two nodes in the associated nodes connected by an associated edge; The first risk assessment result determination unit is used to calculate the risk assessment result corresponding to the resource allocation request when the unilateral risk identification result meets the first preset unilateral risk result; the risk severity corresponding to the first preset unilateral risk result is lower than the preset severity. The first risk identification result determination unit is used to determine the risk identification result when the risk assessment result meets the preset conditions.
[0077] Optionally, the first risk identification result determination unit includes: The initial risk identification result determination unit is used to determine the initial risk identification result of the resource allocation request when the risk assessment result meets the preset conditions; The subgraph risk identification result determination unit is used to adjust the corresponding unilateral risk identification result based on the matching result between the attribute information corresponding to each node of each adjacent node pair in the relational subgraph and the corresponding target request information, so as to obtain the subgraph risk identification result; the relational subgraph includes the target node and at least three nodes of the associated nodes connected by at least two associated edges; The second risk identification result determination unit is used to determine the risk identification result from the initial risk identification result and the subgraph risk identification result.
[0078] Optionally, the first risk assessment result determination unit includes: The first acquisition unit is used to acquire initial count information; A traversal unit is used to traverse the at least one unilateral risk identification result; The target count information determination unit is used to increase the initial count information by a preset value when the current unilateral risk identification result is reached and the current unilateral risk identification result satisfies the first preset unilateral risk result, until the traversal ends, so as to obtain the target count information; The second risk assessment result determination unit is used to multiply the target count information with the preset assessment information to obtain the risk assessment result.
[0079] Optionally, the risk identification result includes a first risk identification result, and the system further includes: The third risk identification result determination unit is used to determine the risk identification result as the first risk identification result when the unilateral risk identification result meets the second preset unilateral risk result; the risk severity corresponding to the second preset unilateral risk result is lower than the preset severity.
[0080] Optionally, the risk identification results include a first risk identification result, a second risk identification result, and a third risk identification result, wherein the first risk identification result determination unit includes: The fourth risk identification result determination unit is used to determine the risk identification result as the first risk identification result when the risk assessment result is greater than or equal to the first preset assessment threshold. The fifth risk identification result determination unit is used to determine the risk identification result as the second risk identification result when the risk evaluation result is greater than or equal to the second preset evaluation threshold and less than the first preset evaluation threshold. The sixth risk identification result determination unit is used to determine the risk identification result as the third risk identification result when the risk assessment result is less than the second preset assessment threshold.
[0081] Optionally, the first unilateral risk identification result determination unit includes: The unilateral risk feature combination determination unit is used to determine the unilateral risk feature combination corresponding to each adjacent node pair based on the matching result between the attribute information corresponding to each node in each adjacent node pair and the corresponding target request information. The second unilateral risk identification result determination unit is used to determine the unilateral risk identification result corresponding to the unilateral risk feature combination according to the preset mapping relationship; the preset mapping relationship is used to characterize the correspondence between the unilateral risk pattern and the unilateral risk identification result.
[0082] Optionally, the system further includes: A frequent association structure determination module is used to determine multiple frequent association structures in the historical relationship graph; each frequent association structure includes at least one association edge and a corresponding node; The distribution parameter determination module is used to calculate the attribute combination distribution parameters of the associated nodes in each frequent association structure in the instance of the historical resource allocation request. The unilateral risk feature combination determination module is used to determine the combination of frequently associated structures and their corresponding attributes as a unilateral risk feature combination when the deviation between the distribution parameter and the corresponding preset distribution parameter is greater than a preset deviation threshold. The unilateral risk identification result determination module is used to determine the unilateral risk identification result corresponding to each unilateral risk feature combination based on the risk identification accuracy of each unilateral risk feature combination. The preset mapping relationship determination module is used to determine the correspondence between each combination of unilateral risk features and the unilateral risk identification result as the preset mapping relationship.
[0083] Optionally, the acquisition module 510 includes: The second acquisition unit is used to acquire the request information carried in the historical resource distribution request, the request information including request object identification information, associated object identification information, the organization to which the request object belongs and the living area information of the request object; The mapping unit is used to map the request object identification information, the associated object identification information, the affiliated organization information, and the living area information into nodes respectively; The association edge determination unit is used to determine the association edge between two corresponding nodes based on the pairwise association relationships between the request object identification information, the associated object identification information, the affiliated organization information, and the living area information; The historical relationship graph generation unit is used to generate the historical relationship graph based on the nodes and associated edges.
[0084] Regarding the system in the above embodiments, the specific ways in which each module performs operations have been described in detail in the embodiments related to the method, and will not be elaborated here.
[0085] Figure 6 This is a block diagram illustrating a terminal electronic device for risk identification according to an exemplary embodiment. The electronic device may be a terminal, and its internal structure diagram may be as follows: Figure 6 As shown, the electronic device includes a processor, memory, network interface, display screen, and input devices connected via a system bus. The processor provides computing and control capabilities. The memory includes a non-volatile storage medium and internal memory. The non-volatile storage medium stores the operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage medium. The network interface is used to communicate with external terminals via a network connection. When the computer program is executed by the processor, it implements a risk identification method. The display screen can be a liquid crystal display (LCD) or an e-ink display. The input devices can be a touch layer covering the display screen, buttons, a trackball, or a touchpad mounted on the device's casing, or an external keyboard, touchpad, or mouse.
[0086] Figure 7 This is a block diagram illustrating a server electronic device for risk identification according to an exemplary embodiment. The electronic device may be a server, and its internal structure diagram may be as follows: Figure 7 As shown, the electronic device includes a processor, memory, and a network interface connected via a system bus. The processor provides computing and control capabilities. The memory includes a non-volatile storage medium and internal memory. The non-volatile storage medium stores the operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage medium. The network interface is used to communicate with external terminals via a network connection. When the computer program is executed by the processor, it implements a risk identification method.
[0087] Those skilled in the art will understand that Figure 6 or Figure 7 The structures shown are merely block diagrams of some structures related to the disclosed solutions of this invention, and do not constitute a limitation on the electronic devices to which the disclosed solutions of this invention are applied. Specific electronic devices may include more or fewer components than those shown in the figures, or combine certain components, or have different component arrangements.
[0088] In an exemplary embodiment, an electronic device for risk identification is also provided, including a processor and a memory, the memory storing at least one instruction, which is loaded and executed by the processor to implement the risk identification method as disclosed in the embodiments of the present invention.
[0089] In an exemplary embodiment, a computer-readable storage medium is also provided, which stores at least one instruction, which is loaded and executed by a processor to implement the risk identification method in the disclosed embodiments of the present invention.
[0090] In an exemplary embodiment, a computer program product containing instructions is also provided, which, when run on a computer, causes the computer to perform the risk identification method disclosed in this invention.
[0091] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. This computer program can be stored in a non-volatile computer-readable storage medium. When executed, the computer program can include the processes of the embodiments of the above methods. Any references to memory, storage, databases, or other media used in the embodiments provided by this invention can include non-volatile and / or volatile memory. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), dual data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), RAMbus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and RAMbus dynamic RAM (RDRAM), etc.
[0092] Other embodiments of the invention will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This invention is intended to cover any variations, uses, or adaptations of the invention that follow the general principles disclosed herein and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of the invention are indicated by the following claims.
[0093] It should be understood that the present invention is not limited to the precise structures described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of the present invention is limited only by the appended claims.
Claims
1. A risk identification method, characterized in that, The method includes: Obtain multiple initial request information carried by the resource allocation request, as well as a historical relationship graph; the historical relationship graph is used to characterize the association between the request information carried by the historical resource allocation requests. At least one initial request information is modified to obtain multiple target request information; the multiple target request information includes modified target information and other initial request information, wherein the other initial request information is the request information other than the modified initial request information among the multiple initial request information. In the historical relationship graph, the node corresponding to the target correction information is taken as the target node, and the attribute information corresponding to the target node and its associated nodes is matched in parallel with the corresponding target request information to obtain the matching result corresponding to each target request information. Based on the matching results corresponding to each target request information, the risk identification result of the resource allocation request is determined.
2. The method according to claim 1, characterized in that, The step of determining the risk identification result of the resource allocation request based on the matching result corresponding to each target request information includes: Based on the matching result between the attribute information corresponding to each node in each adjacent node pair and the corresponding target request information, at least one unilateral risk identification result is determined; the adjacent node pair includes the target node and two nodes in the associated nodes connected by an associated edge. If the unilateral risk identification result meets the first preset unilateral risk result, calculate the risk assessment result corresponding to the resource allocation request; the risk severity corresponding to the first preset unilateral risk result is lower than the preset severity. If the risk assessment results meet the preset conditions, the risk identification results are determined.
3. The method according to claim 2, characterized in that, Determining the risk identification result when the risk assessment result meets preset conditions includes: If the risk assessment result meets the preset conditions, determine the initial risk identification result of the resource allocation request; Based on the matching results between the attribute information of each node in each pair of adjacent nodes in the relational subgraph and the corresponding target request information, the corresponding unilateral risk identification results are adjusted to obtain the subgraph risk identification results; the relational subgraph includes the target node and at least three nodes in the associated nodes connected by at least two associated edges; The risk identification result is determined from the initial risk identification result and the subgraph risk identification result.
4. The method according to claim 2, characterized in that, The step of calculating the risk assessment result corresponding to the resource allocation request when the unilateral risk identification result meets the first preset unilateral risk result includes: Obtain initial count information; The at least one unilateral risk identification result is iterated through; When the current unilateral risk identification result is reached and the current unilateral risk identification result satisfies the first preset unilateral risk result, the initial count information is incremented by a preset value until the traversal ends, and the target count information is obtained. The target count information is multiplied by the preset evaluation information to obtain the risk evaluation result.
5. The method according to claim 2, characterized in that, The risk identification result includes a first risk identification result, and the method further includes: If the unilateral risk identification result satisfies the second preset unilateral risk result, the risk identification result is determined to be the first risk identification result; the risk severity corresponding to the second preset unilateral risk result is lower than the preset severity.
6. The method according to claim 2, characterized in that, The risk identification results include a first risk identification result, a second risk identification result, and a third risk identification result. Determining the risk identification result when the risk assessment result meets preset conditions includes: If the risk assessment result is greater than or equal to the first preset assessment threshold, the risk identification result is determined to be the first risk identification result; If the risk assessment result is greater than or equal to the second preset assessment threshold and less than the first preset assessment threshold, the risk identification result is determined to be the second risk identification result. If the risk assessment result is less than the second preset assessment threshold, the risk identification result is determined to be the third risk identification result.
7. The method according to claim 2, characterized in that, The step of determining at least one unilateral risk identification result based on the matching result between the attribute information corresponding to each node in each adjacent node pair and the corresponding target request information includes: Based on the matching results between the attribute information of each node in each adjacent node pair and the corresponding target request information, determine the combination of unilateral risk features corresponding to each adjacent node pair; Based on a preset mapping relationship, the unilateral risk identification result corresponding to the unilateral risk feature combination is determined; the preset mapping relationship is used to characterize the correspondence between the unilateral risk pattern and the unilateral risk identification result.
8. The method according to claim 7, characterized in that, The preset mapping relationship is determined according to the following method: Identify multiple frequent association structures in the historical relationship graph; each frequent association structure includes at least one association edge and a corresponding node; In the instance of the historical resource distribution request, calculate the attribute combination distribution parameters of the associated nodes in each frequent association structure; If the deviation between the distribution parameter and the corresponding preset distribution parameter is greater than a preset deviation threshold, the frequently associated structure and its corresponding attribute combination are determined as a unilateral risk feature combination. Based on the risk identification accuracy of each unilateral risk feature combination, determine the unilateral risk identification result corresponding to each unilateral risk feature combination; The correspondence between each combination of unilateral risk features and the unilateral risk identification result is determined as the preset mapping relationship.
9. The method according to any one of claims 1 to 8, characterized in that, The acquisition of the historical relationship map includes: Obtain the request information carried in the historical resource distribution request, the request information including request object identification information, associated object identification information, the organization to which the request object belongs, and the living area information of the request object; The request object identification information, the associated object identification information, the affiliated organization information, and the living area information are respectively mapped to nodes; Based on the pairwise relationships between the request object identifier information, the associated object identifier information, the affiliated organization information, and the living area information, determine the association edge between the corresponding two nodes; Based on the nodes and associated edges, the historical relationship graph is generated.
10. A risk identification system, characterized in that, The system includes: The acquisition module is used to acquire multiple initial request information carried by the resource allocation request, as well as a historical relationship graph; the historical relationship graph is used to characterize the association between the request information carried by the historical resource allocation requests. A correction module is used to correct at least one initial request information to obtain multiple target request information; the multiple target request information includes corrected target information and other initial request information, wherein the other initial request information is request information other than the corrected initial request information among the multiple initial request information. The matching module is used to take the node corresponding to the target correction information in the historical relationship graph as the target node, and to perform parallel matching of the attribute information corresponding to the target node and its associated nodes with the corresponding target request information to obtain the matching result corresponding to each target request information. The risk identification result determination module is used to determine the risk identification result of the resource allocation request based on the matching result corresponding to each target request information.