An abnormal risk identification method, device and equipment based on a large language model

CN122820320APending Publication Date: 2026-09-25INDUSTRIAL AND COMMERCIAL BANK OF CHINA
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610624254.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-05-08
Publication Date
2026-09-25

AI Technical Summary

Technical Problem

[0002]在线上金融交易场景持续升级迭代的背景下,各类违规异常交易行为不断演化翻新,行为模式日趋复杂多元、隐蔽性持续增强,显著增加了银行等金融机构交易异常风险的识别难度与防控压力

Benefits of technology

[0010]本发明实施例的技术方案,通过获取目标用户的当前交易数据和历史交易数据;根据基于专家规则的第一风险识别模型,确定当前交易数据对应的第一风险值,并根据历史交易数据和基于大语言模型的第二风险识别模型,确定当前交易数据对应的第二风险值;根据第一风险值和第二风险值,确定当前交易数据对应的目标异常风险等级。上述技术方案,通过双模型实现了对用户交易过程中异常风险的全面性检测和识别,即,通过基于专家规则的第一风险识别模型对当前交易数据进行分析得到第一风险值,实现了对目标用户本次交易过程中已知异常模式的检测和识别;通过基于大语言模型的第二风险识别模型对当前交易数据进行分析得到第二风险值,实现了对目标用户本次交易过程中新型异常模式(即未知或复杂异常模式)的检测和识别。之后,通过对第一风险值和第二风险值进行综合分析,确定当前交易数据对应的目标异常风险等级,提高了目标异常风险等级的准确性,进而提高了对用户交易过程中异常风险识别的准确性,减少了用户交易过程中异常风险的误报和漏报,降低了用户上当受骗的可能性,从而保证了用户的资金安全,也增强了银行等金融机构异常风险防控的有效性。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122820320A_ABST
    Figure CN122820320A_ABST
Patent Text Reader

Abstract

The application discloses an abnormal risk identification method and device based on a large language model and equipment, relates to the technical field of big data and the technical field of artificial intelligence, and the method comprises the following steps: acquiring current transaction data and historical transaction data of a target user; determining a first risk value corresponding to the current transaction data according to a first risk identification model based on an expert rule, and determining a second risk value corresponding to the current transaction data according to the historical transaction data and a second risk identification model based on a large language model; and determining a target abnormal risk level corresponding to the current transaction data according to the first risk value and the second risk value. The application improves the accuracy of abnormal risk identification in the transaction process of a user.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the fields of big data technology and artificial intelligence technology, and in particular to an anomaly risk identification method, apparatus, and device based on a large language model. Background Technology

[0002] Against the backdrop of continuous upgrading and iteration of online financial transaction scenarios, various illegal and abnormal transaction behaviors are constantly evolving and changing, with increasingly complex and diverse behavioral patterns and continuously enhanced concealment, which significantly increases the difficulty of identifying and controlling abnormal transaction risks for banks and other financial institutions.

[0003] However, traditional anomaly risk identification models based on expert rules suffer from rigid rules and lack of adaptability because their rule bases rely on human experience. The rule update cycle lags far behind the evolution of anomaly patterns, making it difficult to identify new anomaly patterns. This reduces the accuracy of identifying anomaly risks in the transaction process and weakens the effectiveness of anomaly risk prevention and control for banks and other financial institutions. Summary of the Invention

[0004] This invention provides an anomaly risk identification method, apparatus, and device based on a large language model to improve the accuracy of anomaly risk identification during user transactions.

[0005] According to one aspect of the present invention, an anomaly risk identification method based on a large language model is provided, the method comprising: Obtain the target user's current and historical transaction data; Based on the first risk identification model based on expert rules, the first risk value corresponding to the current transaction data is determined, and based on historical transaction data and the second risk identification model based on a large language model, the second risk value corresponding to the current transaction data is determined. Based on the first risk value and the second risk value, determine the target abnormal risk level corresponding to the current transaction data.

[0006] According to another aspect of the present invention, an anomaly risk identification device based on a large language model is provided, the device comprising: The user transaction data acquisition module is used to acquire the current and historical transaction data of the target user. The transaction risk value determination module is used to determine the first risk value corresponding to the current transaction data based on the first risk identification model based on expert rules, and to determine the second risk value corresponding to the current transaction data based on historical transaction data and the second risk identification model based on a large language model. The abnormal risk level determination module is used to determine the target abnormal risk level corresponding to the current transaction data based on the first risk value and the second risk value.

[0007] According to another aspect of the present invention, an electronic device is provided, the electronic device comprising: At least one processor; and a memory communicatively connected to at least one processor; wherein, The memory stores a computer program that can be executed by at least one processor, such that the at least one processor is able to execute the anomaly risk identification method based on a large language model according to any embodiment of the present invention.

[0008] According to another aspect of the present invention, a computer-readable storage medium is provided, the computer-readable storage medium storing computer instructions for causing a processor to execute and implement the anomaly risk identification method based on a large language model according to any embodiment of the present invention.

[0009] According to another aspect of the present invention, a computer program product is provided, comprising a computer program that, when executed by a processor, implements the anomaly risk identification method based on a large language model according to any embodiment of the present invention.

[0010] The technical solution of this invention involves acquiring the target user's current and historical transaction data; determining a first risk value corresponding to the current transaction data based on a first risk identification model based on expert rules; and determining a second risk value corresponding to the current transaction data based on historical transaction data and a second risk identification model based on a large language model; finally, determining the target abnormal risk level corresponding to the current transaction data based on the first and second risk values. This technical solution achieves comprehensive detection and identification of abnormal risks during user transactions through a dual-model approach. Specifically, the first risk identification model based on expert rules analyzes the current transaction data to obtain the first risk value, enabling the detection and identification of known abnormal patterns during the target user's current transaction; the second risk identification model based on a large language model analyzes the current transaction data to obtain the second risk value, enabling the detection and identification of novel abnormal patterns (i.e., unknown or complex abnormal patterns) during the target user's current transaction. Subsequently, by comprehensively analyzing the first and second risk values, the target abnormal risk level corresponding to the current transaction data is determined, which improves the accuracy of the target abnormal risk level. This, in turn, improves the accuracy of identifying abnormal risks during user transactions, reduces false alarms and missed alarms of abnormal risks during user transactions, lowers the possibility of users being deceived, and thus ensures the safety of users' funds and enhances the effectiveness of abnormal risk prevention and control by banks and other financial institutions.

[0011] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of the present invention, nor is it intended to limit the scope of the invention. Other features of the invention will become readily apparent from the following description. Attached Figure Description

[0012] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0013] Figure 1 This is a flowchart of an anomaly risk identification method based on a large language model according to Embodiment 1 of the present invention; Figure 2 This is a flowchart of an anomaly risk identification method based on a large language model according to Embodiment 2 of the present invention; Figure 3 This is a schematic diagram of an anomaly risk identification device based on a large language model according to Embodiment 3 of the present invention; Figure 4 This is a schematic diagram of the structure of an electronic device that implements the anomaly risk identification method based on a large language model according to an embodiment of the present invention. Detailed Implementation

[0014] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.

[0015] It should be noted that the terms "target," "first," and "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0016] Furthermore, it should be noted that the current and historical transaction data of the target users collected in this invention, as well as the collection, storage, use, processing, transmission, provision, disclosure, and application of related data, all comply with the relevant laws, regulations, and standards of the relevant countries and regions, take necessary confidentiality measures, do not violate public order and good morals, and provide corresponding operation entry points for users to choose to authorize or refuse.

[0017] Example 1 Figure 1 This is a flowchart illustrating an anomaly risk identification method based on a large language model, provided in Embodiment 1 of the present invention. This embodiment is applicable to identifying anomaly risks during user transactions. The method can be executed by an anomaly risk identification device based on a large language model, which can be implemented in hardware and / or software and can be configured in an electronic device. Figure 1 As shown, the method includes: S101. Obtain the target user's current transaction data and historical transaction data.

[0018] The target user refers to a user who conducts transactions through transaction devices provided by banks or other financial institutions. Current transaction data refers to the target user's transaction data in this current transaction; optionally, current transaction data includes, but is not limited to, the current transaction time, current transaction amount, current transaction type, current transaction device number, and the terminal address of the current transaction device. Historical transaction data refers to the target user's transaction data prior to this transaction; for example, historical transaction data could be the target user's transaction data within the year prior to this transaction.

[0019] Specifically, the target user's current and historical transaction data can be obtained through preset data acquisition tools.

[0020] S102. Based on the first risk identification model based on expert rules, determine the first risk value corresponding to the current transaction data, and based on historical transaction data and the second risk identification model based on a large language model, determine the second risk value corresponding to the current transaction data.

[0021] Here, the first risk value refers to the risk value output by the first risk identification model based on expert rules. The second risk value refers to the risk value output by the second risk identification model based on a large language model.

[0022] Specifically, the current transaction data can be input into the first risk identification model based on expert rules to obtain the first risk value corresponding to the current transaction data; at the same time, the current transaction data and historical transaction data can be input into the second risk identification model based on a large language model to obtain the second risk value corresponding to the current transaction data.

[0023] S103. Determine the target abnormal risk level corresponding to the current transaction data based on the first risk value and the second risk value.

[0024] The target abnormal risk level refers to the level of abnormal risk present in the target user's current transaction. Specifically, a comprehensive risk value is determined based on a first risk value and a second risk value. Based on the comprehensive risk value and the mapping relationship between risk values ​​and risk levels in the preset risk level table, the target abnormal risk level corresponding to the current transaction data is determined. The comprehensive risk value is the risk value obtained by combining the first and second risk values. The preset risk level table records preset risk value ranges and preset risk levels, and these ranges and levels are stored together; that is, one preset risk value range corresponds to one preset risk level in the table. For example, the preset risk value range [0, 0.3) corresponds to a low-risk level.

[0025] More specifically, the first risk value and the second risk value can be weighted and averaged to obtain the comprehensive risk value; based on the mapping relationship between risk values ​​and risk levels in the preset risk level table, the risk level corresponding to the comprehensive risk value can be obtained from the preset risk level table as the target abnormal risk level corresponding to the current transaction data.

[0026] Understandably, compared to the technical solution that determines the target abnormal risk level of the current transaction data solely based on the first risk value output by the first risk identification model based on expert rules, a comprehensive risk value is obtained by comprehensively analyzing the first risk value output by the first risk identification model based on expert rules and the second risk value output by the second risk identification model based on the large language model. By leveraging the second risk value output by the second risk identification model based on the large language model, the accuracy of the risk value corresponding to the current transaction data is improved, thereby improving the accuracy of the target abnormal risk level determined based on the comprehensive risk value.

[0027] The technical solution of this invention involves acquiring the target user's current and historical transaction data; determining a first risk value corresponding to the current transaction data based on a first risk identification model based on expert rules; and determining a second risk value corresponding to the current transaction data based on historical transaction data and a second risk identification model based on a large language model; finally, determining the target abnormal risk level corresponding to the current transaction data based on the first and second risk values. This technical solution achieves comprehensive detection and identification of abnormal risks during user transactions through a dual-model approach. Specifically, the first risk identification model based on expert rules analyzes the current transaction data to obtain the first risk value, enabling the detection and identification of known abnormal patterns during the target user's current transaction; the second risk identification model based on a large language model analyzes the current transaction data to obtain the second risk value, enabling the detection and identification of novel abnormal patterns (i.e., unknown or complex abnormal patterns) during the target user's current transaction. Subsequently, by comprehensively analyzing the first and second risk values, the target abnormal risk level corresponding to the current transaction data is determined, which improves the accuracy of the target abnormal risk level. This, in turn, improves the accuracy of identifying abnormal risks during user transactions, reduces false alarms and missed alarms of abnormal risks during user transactions, lowers the possibility of users being deceived, and thus ensures the safety of users' funds and enhances the effectiveness of abnormal risk prevention and control by banks and other financial institutions.

[0028] Example 2 Figure 2 This is a flowchart of an anomaly risk identification method based on a large language model provided in Embodiment 2 of the present invention. Based on the above embodiments, this embodiment further optimizes the process of "determining a first risk value corresponding to the current transaction data according to a first risk identification model based on expert rules, and determining a second risk value corresponding to the current transaction data according to historical transaction data and a second risk identification model based on a large language model," providing an optional implementation scheme. It should be noted that parts not detailed in this embodiment can be referred to in the relevant descriptions of other embodiments. For example... Figure 2 As shown, the method includes: S201. Obtain the target user's current transaction data and historical transaction data.

[0029] S202. Input the current transaction data into the first risk identification model based on expert rules to obtain the first risk value corresponding to the current transaction data.

[0030] Specifically, the current transaction data is input into the first risk identification model based on expert rules. After processing by the first risk identification model based on expert rules, the first risk value corresponding to the current transaction data is obtained.

[0031] S203. Generate risk analysis prompts based on current and historical transaction data.

[0032] Among them, risk analysis prompt words refer to the model prompt words required when analyzing current transaction data using a second risk identification model based on a large language model.

[0033] Specifically, features are extracted from historical transaction data to obtain the target user's first transaction features; features are extracted from current transaction data to obtain the target user's second transaction features; and risk analysis prompts are generated based on the first and second transaction features.

[0034] The first transaction feature refers to the transaction characteristics of the target user extracted from the target user's historical transaction data; optionally, the first transaction feature includes, but is not limited to, commonly used historical transaction periods, average historical transaction amount, standard deviation of historical transaction amount, and commonly used historical transaction types. The second transaction feature refers to the transaction characteristics of the target user extracted from the target user's current transaction data; optionally, the second transaction feature includes, but is not limited to, current transaction time, current transaction amount, and current transaction type.

[0035] More specifically, a first preset feature extraction algorithm can be used to extract features from the target user's historical transaction data to obtain the target user's first transaction features; a second preset feature extraction algorithm can be used to extract features from the current transaction data to obtain the target user's second transaction features; based on the first and second transaction features, the target user's abnormal transaction features can be determined, and risk analysis prompts can be generated based on the abnormal transaction features.

[0036] It should be noted that the first preset feature extraction algorithm differs from the second preset feature extraction algorithm. Specifically, based on the first and second transaction features, abnormal transaction characteristics of the target user are determined; based on these abnormal transaction characteristics, risk analysis prompts are generated. This can be achieved by comparing the second and first transaction features with the first, identifying features where the second and first features differ, and using these as the abnormal transaction characteristics of the target user; and then, based on a preset prompt generation format, converting these abnormal transaction characteristics into risk analysis prompts.

[0037] It is understandable that generating risk analysis prompts based on the abnormal transaction characteristics of target users improves the accuracy of risk analysis prompts, which in turn improves the accuracy of the output results of the second risk identification model based on the large language model, that is, improves the accuracy of the second risk value.

[0038] S204. Input the current transaction data and risk analysis prompts into the second risk identification model based on the large language model to obtain the second risk value corresponding to the current transaction data.

[0039] Specifically, the current transaction data and risk analysis prompts are input into the second risk identification model based on the large language model. After processing by the second risk identification model based on the large language model, the second risk value corresponding to the current transaction data is obtained.

[0040] S205. Based on the first risk value and the second risk value, determine the target abnormal risk level corresponding to the current transaction data.

[0041] The technical solution of this invention involves acquiring the target user's current transaction data and historical transaction data; inputting the current transaction data into a first risk identification model based on expert rules to obtain a first risk value corresponding to the current transaction data; generating risk analysis prompts based on the current and historical transaction data; inputting the current transaction data and risk analysis prompts into a second risk identification model based on a large language model to obtain a second risk value corresponding to the current transaction data; and determining the target abnormal risk level corresponding to the current transaction data based on the first and second risk values. This technical solution, by using the first risk identification model based on expert rules and the second risk identification model based on a large language model to calculate the risk value of the target user's current transaction data, achieves comprehensive detection and identification of abnormal risks during the user's transaction process. Specifically, by analyzing the current transaction data using the first risk identification model based on expert rules to obtain the first risk value, it achieves the detection and identification of known abnormal patterns during the target user's current transaction process; by analyzing the current transaction data using the second risk identification model based on a large language model to obtain the second risk value, it achieves the detection and identification of new abnormal patterns (i.e., unknown or complex abnormal patterns) during the target user's current transaction process. This makes the target abnormal risk level determined by comprehensively analyzing the first and second risk values ​​more accurate. In other words, it improves the accuracy of identifying abnormal risks during user transactions, reduces false alarms and missed alarms of abnormal risks during user transactions, lowers the possibility of users being deceived, thereby ensuring the safety of users' funds and enhancing the effectiveness of abnormal risk prevention and control by banks and other financial institutions.

[0042] Based on the above embodiments, as an optional embodiment of the present invention, after determining the target abnormal risk level corresponding to the current transaction data, it is also possible to: determine the target response strategy corresponding to the current transaction data based on the target abnormal risk level and the correspondence between risk levels and risk response strategies in the risk control database, and execute the target response strategy.

[0043] The risk control database refers to a database used to record risk response strategies corresponding to different levels of abnormal risk. Specifically, using the target abnormal risk level as an index, and based on the correspondence between risk levels and risk response strategies in the risk control database, the risk response strategy corresponding to the target abnormal risk level is retrieved from the risk control database. This strategy is then used as the target response strategy for the current transaction data and executed to control abnormal risks during the target user's transaction, quickly halt the transaction, and prevent user financial losses.

[0044] Example 3 Figure 3 This is a schematic diagram of an anomaly risk identification device based on a large language model, provided in Embodiment 3 of the present invention. This embodiment is applicable to the identification of anomaly risks during user transactions. The device can be implemented in hardware and / or software and can be configured in an electronic device. Figure 3 As shown, the device includes: User transaction data acquisition module 301 is used to acquire the current transaction data and historical transaction data of the target user; The transaction risk value determination module 302 is used to determine the first risk value corresponding to the current transaction data based on the first risk identification model based on expert rules, and to determine the second risk value corresponding to the current transaction data based on historical transaction data and the second risk identification model based on a large language model. The abnormal risk level determination module 303 is used to determine the target abnormal risk level corresponding to the current transaction data based on the first risk value and the second risk value.

[0045] The technical solution of this invention involves acquiring the target user's current and historical transaction data; determining a first risk value corresponding to the current transaction data based on a first risk identification model based on expert rules; and determining a second risk value corresponding to the current transaction data based on historical transaction data and a second risk identification model based on a large language model; finally, determining the target abnormal risk level corresponding to the current transaction data based on the first and second risk values. This technical solution achieves comprehensive detection and identification of abnormal risks during user transactions through a dual-model approach. Specifically, the first risk identification model based on expert rules analyzes the current transaction data to obtain the first risk value, enabling the detection and identification of known abnormal patterns during the target user's current transaction; the second risk identification model based on a large language model analyzes the current transaction data to obtain the second risk value, enabling the detection and identification of novel abnormal patterns (i.e., unknown or complex abnormal patterns) during the target user's current transaction. Subsequently, by comprehensively analyzing the first and second risk values, the target abnormal risk level corresponding to the current transaction data is determined, which improves the accuracy of the target abnormal risk level. This, in turn, improves the accuracy of identifying abnormal risks during user transactions, reduces false alarms and missed alarms of abnormal risks during user transactions, lowers the possibility of users being deceived, and thus ensures the safety of users' funds and enhances the effectiveness of abnormal risk prevention and control by banks and other financial institutions.

[0046] Optionally, the transaction risk value determination module 302 includes: The first risk value determination unit is used to input the current transaction data into the first risk identification model based on expert rules to obtain the first risk value corresponding to the current transaction data. The risk analysis prompt generation unit is used to generate risk analysis prompts based on current and historical transaction data. The second risk value determination unit is used to input the current transaction data and risk analysis prompts into the second risk identification model based on the large language model to obtain the second risk value corresponding to the current transaction data.

[0047] Optional, the risk analysis prompt generation unit includes: The first transaction feature determination subunit is used to extract features from historical transaction data to obtain the first transaction features of the target user; The second transaction feature determination subunit extracts features from the current transaction data to obtain the second transaction features of the target user; The risk analysis prompt generation subunit is used to generate risk analysis prompts based on the first transaction feature and the second transaction feature.

[0048] Optional, the risk analysis prompt word generation subunit is specifically used for: Based on the first and second transaction characteristics, the abnormal transaction characteristics of the target user are determined; Based on the characteristics of abnormal transactions, generate risk analysis prompts.

[0049] Optional, the anomaly risk level determination module 303 is specifically used for: The comprehensive risk value is determined based on the first risk value and the second risk value; Based on the comprehensive risk value and the mapping relationship between risk values ​​and risk levels in the preset risk level table, the target abnormal risk level corresponding to the current transaction data is determined.

[0050] Optionally, the device may also include: The target response strategy determination and execution module is used to determine the target abnormal risk level corresponding to the current transaction data after determining the target abnormal risk level, and then, based on the correspondence between risk levels and risk response strategies in the risk control database, determine the target response strategy corresponding to the current transaction data and execute the target response strategy.

[0051] The anomaly risk identification device based on a large language model provided in this embodiment of the invention can execute the anomaly risk identification method based on a large language model provided in any embodiment of the invention, and has the corresponding functional modules and beneficial effects for executing each anomaly risk identification method based on a large language model.

[0052] According to embodiments of the present invention, the present invention also provides an electronic device, a readable storage medium, and a computer program product.

[0053] Example 4 Figure 4 A schematic diagram of an electronic device 10, which can be used to implement embodiments of the present invention, is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices (e.g., helmets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the invention described and / or claimed herein.

[0054] like Figure 4As shown, the electronic device 10 includes at least one processor 11 and a memory, such as a read-only memory 12 or a random access memory 13, communicatively connected to the at least one processor 11. The memory stores computer programs executable by the at least one processor. The processor 11 can perform various appropriate actions and processes based on the computer program stored in the read-only memory 12 or loaded from storage unit 18 into the random access memory 13. The random access memory 13 may also store various programs and data required for the operation of the electronic device 10. The processor 11, read-only memory 12, and random access memory 13 are interconnected via a bus 14. An input / output interface 15 is also connected to the bus 14.

[0055] Multiple components in electronic device 10 are connected to I / O interface 15, including: input unit 16, such as keyboard, mouse, etc.; output unit 17, such as various types of displays, speakers, etc.; storage unit 18, such as disk, optical disk, etc.; and communication unit 19, such as network card, modem, wireless transceiver, etc. Communication unit 19 allows electronic device 10 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.

[0056] Processor 11 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of processor 11 include, but are not limited to, central processing units, graphics processing units, various special-purpose artificial intelligence computing chips, various processors running machine learning model algorithms, digital signal processors, and any suitable processor, controller, microcontroller, etc. Processor 11 performs the various methods and processes described above, such as anomaly risk identification methods based on large language models.

[0057] In some embodiments, the large language model-based anomaly risk identification method can be implemented as a computer program tangibly contained in a computer-readable storage medium, such as storage unit 18. In some embodiments, part or all of the computer program can be loaded and / or installed on electronic device 10 via read-only memory 12 and / or communication unit 19. When the computer program is loaded into random access memory 13 and executed by processor 11, one or more steps of the large language model-based anomaly risk identification method described above can be performed. Alternatively, in other embodiments, processor 11 can be configured to perform the large language model-based anomaly risk identification method by any other suitable means (e.g., by means of firmware).

[0058] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays, application-specific integrated circuits (ASICs), application-specific standard products (ASICs), systems-on-a-chip (SoCs), payload programmable logic devices, computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.

[0059] Computer programs used to implement the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when executed by the processor, the computer programs cause the functions / operations specified in the flowcharts and / or block diagrams to be performed. The computer programs may be executed entirely on a machine, partially on a machine, or as a standalone software package, partially on a machine and partially on a remote machine, or entirely on a remote machine or server.

[0060] In the context of this invention, a computer-readable storage medium can be a tangible medium that may contain or store a computer program for use by or in conjunction with an instruction execution system, apparatus, or device. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination thereof. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory, read-only memory, erasable programmable read-only memory, optical fibers, portable compact disk read-only memory, optical storage devices, magnetic storage devices, or any suitable combination thereof.

[0061] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a cathode ray tube or liquid crystal display) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).

[0062] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or computing systems that include middleware components (e.g., application servers), or computing systems that include frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., communication networks). Examples of communication networks include local area networks (LANs), wide area networks (WANs), blockchain networks, and the Internet.

[0063] A computing system can include clients and servers. Clients and servers are generally located far apart and typically interact through communication networks. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or cloud host, which is a host product in the cloud computing service system to address the shortcomings of traditional physical hosts and virtual private servers, such as high management difficulty and weak business scalability.

[0064] It should be understood that the various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps described in this invention can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution of this invention can be achieved, and this is not limited herein.

[0065] The specific embodiments described above do not constitute a limitation on the scope of protection of this invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this invention should be included within the scope of protection of this invention.

Claims

1. An anomaly risk identification method based on a large language model, characterized in that, include: Obtain the target user's current and historical transaction data; Based on the first risk identification model based on expert rules, a first risk value corresponding to the current transaction data is determined, and based on the historical transaction data and the second risk identification model based on a large language model, a second risk value corresponding to the current transaction data is determined. Based on the first risk value and the second risk value, the target abnormal risk level corresponding to the current transaction data is determined.

2. The method according to claim 1, characterized in that, The step of determining a first risk value corresponding to the current transaction data based on a first risk identification model based on expert rules, and determining a second risk value corresponding to the current transaction data based on historical transaction data and a second risk identification model based on a large language model, includes: The current transaction data is input into the first risk identification model based on expert rules to obtain the first risk value corresponding to the current transaction data; Based on the current transaction data and the historical transaction data, risk analysis prompts are generated; The current transaction data and the risk analysis prompts are input into the second risk identification model based on a large language model to obtain the second risk value corresponding to the current transaction data.

3. The method according to claim 2, characterized in that, The step of generating risk analysis prompts based on the current transaction data and the historical transaction data includes: Feature extraction is performed on the historical transaction data to obtain the first transaction features of the target user; Feature extraction is performed on the current transaction data to obtain the second transaction features of the target user; Based on the first transaction feature and the second transaction feature, risk analysis prompts are generated.

4. The method according to claim 3, characterized in that, The step of generating risk analysis prompts based on the first transaction feature and the second transaction feature includes: Based on the first transaction characteristics and the second transaction characteristics, the abnormal transaction characteristics of the target user are determined; Based on the characteristics of the abnormal transactions, risk analysis prompts are generated.

5. The method according to claim 1, characterized in that, The step of determining the target abnormal risk level corresponding to the current transaction data based on the first risk value and the second risk value includes: A comprehensive risk value is determined based on the first risk value and the second risk value; Based on the comprehensive risk value and the mapping relationship between risk values ​​and risk levels in the preset risk level table, the target abnormal risk level corresponding to the current transaction data is determined.

6. The method according to claim 1, characterized in that, After determining the target abnormal risk level corresponding to the current transaction data, the method further includes: Based on the target abnormal risk level, and based on the correspondence between risk levels and risk response strategies in the risk control database, the target response strategy corresponding to the current transaction data is determined and executed.

7. An anomaly risk identification device based on a large language model, characterized in that, include: The user transaction data acquisition module is used to acquire the current and historical transaction data of the target user. The transaction risk value determination module is used to determine the first risk value corresponding to the current transaction data according to the first risk identification model based on expert rules, and to determine the second risk value corresponding to the current transaction data according to the historical transaction data and the second risk identification model based on a large language model. An abnormal risk level determination module is used to determine the target abnormal risk level corresponding to the current transaction data based on the first risk value and the second risk value.

8. An electronic device, characterized in that, The electronic device includes: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that can be executed by the at least one processor, the computer program being executed by the at least one processor to enable the at least one processor to perform the anomaly risk identification method based on a large language model as described in any one of claims 1-6.

9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions that cause a processor to execute the anomaly risk identification method based on a large language model as described in any one of claims 1-6.

10. A computer program product, characterized in that, It includes a computer program that, when executed by a processor, implements the anomaly risk identification method based on a large language model as described in any one of claims 1-6.