Risk prevention and control method and device, storage medium, program product and electronic equipment
Patent Information
- Application Number
- CN202610924892.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-06-24
- Publication Date
- 2026-09-29
AI Technical Summary
在物流仓储场景中,资产为在途货物或仓储库存的实物数量,资产损失风险表现为出入库状态同步异常、分拣系统重复扣减库存导致的实物资产账实不符
[0010]本说明书一些实施例提供的技术方案带来的有益效果至少包括:
Smart Images

Figure CN122838822A_ABST
Abstract
Description
Technical Field
[0001] This specification relates to the field of risk control, and in particular to a risk control method, device, storage medium, program product, and electronic device. Background Technology
[0002] Asset loss risk refers to the risk that the quantifiable equity of a transaction object may be reduced unexpectedly due to system logic defects, abnormal data status, or processing timing errors.
[0003] For example, in financial payment scenarios, assets are user account balances or funds awaiting settlement. Asset loss risks manifest as duplicate deductions, incorrect amount calculations, and funding gaps due to inconsistent transfer statuses. In online gaming scenarios, assets are virtual currency, virtual equipment, or user points. Asset loss risks manifest as duplicate item distribution, transaction amount overflows, and anomalies in virtual property due to inconsistencies between point deductions and item arrival statuses. In e-commerce scenarios, assets are the quantity of inventory or platform coupon amounts. Asset loss risks manifest as overselling, duplicate coupon redemptions, and wasted salable resources due to inconsistencies between inventory deductions and order statuses. In logistics and warehousing scenarios, assets are the physical quantity of goods in transit or warehouse inventory. Asset loss risks manifest as abnormal synchronization of inbound and outbound statuses and discrepancies between physical assets recorded and actual inventory due to duplicate inventory deductions by the sorting system.
[0004] Current asset loss risk prevention and control systems suffer from problems such as reliance on manual labor, outdated risk identification, and dependence on post-event prevention. For example, during the requirement document and technical solution proposal stage, risk control personnel review these documents and solutions based on their personal understanding to detect potential risks. However, different risk control personnel have different standards for risk judgment, resulting in significant differences in the depth of risk identification, and many potential risks fail to be effectively identified. Furthermore, during the requirement document and technical solution release stage, risk analysis often remains at the formal document level, with limited ability to uncover deeper logical flaws. Summary of the Invention
[0005] This specification provides a risk control method, apparatus, storage medium, program product, and electronic device, which can solve the above-mentioned problems. The technical solution is as follows: Firstly, embodiments of this specification provide a risk prevention and control method, the method comprising: Obtain project information corresponding to the projects to be published; Based on a pre-set risk knowledge base, the project data is analyzed using a large language model to identify financial loss risks and obtain a risk identification report. The risk identification report includes at least one of the following: at least one type of risk identified, risk testing coverage, and risk prevention and control coverage. The release of the project to be released is controlled based on the risk identification report.
[0006] Secondly, embodiments of this specification provide a risk control device, the device comprising: The data acquisition module is used to acquire project data corresponding to the project to be published. The risk identification module is used to identify financial loss risks in the project data based on a preset risk knowledge base and a large language model, and to obtain a risk identification report; wherein the risk identification report includes at least one of the following: at least one type of risk identified, risk test coverage, and risk prevention and control coverage; The release control module is used to control the release of the project to be released based on the risk identification report.
[0007] Thirdly, embodiments of this specification provide a computer storage medium storing a plurality of instructions adapted for loading by a processor and executing the above-described method steps.
[0008] Fourthly, embodiments of this specification provide a computer program product that stores multiple instructions adapted for loading by a processor and executing the above-described method steps.
[0009] Fifthly, embodiments of this specification provide an electronic device that may include: a processor and a memory; wherein the memory stores a computer program adapted to be loaded by the processor and to execute the above-described method steps.
[0010] The beneficial effects of the technical solutions provided in some embodiments of this specification include at least the following: In this embodiment, project data, including requirement descriptions and system implementation information corresponding to the project to be released, is acquired. Based on a pre-built risk knowledge base, a large language model is used to identify asset loss risks in the project data. This moves the risk identification process from the online stage to the design verification stage, identifying potential asset loss risks before project release, effectively preventing defective projects from entering the production environment, and significantly narrowing the scope of asset loss impact. Furthermore, in this embodiment, the large language model is applied to the field of asset loss risk analysis. By constructing a risk knowledge base and standardized risk identification reports, the large language model can replace manual work in identifying asset loss risks based on specific role settings, process steps, and output specifications. This achieves intelligent asset loss risk analysis and overcomes the problems of insufficient analysis coverage and superficiality caused by over-reliance on manual experience review. Finally, in this embodiment, the risk identification report can include information such as risk points belonging to different risk types, risk testing coverage, and risk prevention coverage. The risk identification report enables a quantitative assessment of the completeness of risk exposure and prevention, ensuring the accuracy of management of the project to be released based on the risk identification report and significantly improving the reliability of asset loss risk prevention. Attached Figure Description
[0011] To more clearly illustrate the technical solutions in the embodiments or prior art of this specification, the drawings used in the description of the embodiments or prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this specification. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0012] Figure 1 This is a schematic diagram of the architecture of a risk control method provided in the embodiments of this specification; Figure 2 This is a flowchart illustrating a risk control method provided in the embodiments of this specification; Figure 3 This is a schematic diagram of a module with multiple processes provided in the embodiments of this specification; Figure 4 This is a flowchart illustrating a risk control method provided in the embodiments of this specification; Figure 5 This is a schematic diagram of a process for identifying financial loss risks using a large model, as provided in the embodiments of this specification. Figure 6 This is a flowchart illustrating a risk control method provided in the embodiments of this specification; Figure 7 This is a schematic diagram of the nodes of a risk control process provided in the embodiments of this specification; Figure 8This is a schematic diagram of the structure of a risk control device provided in the embodiments of this specification; Figure 9 This is a schematic diagram of the structure of an electronic device provided in the embodiments of this specification. Detailed Implementation
[0013] The technical solutions in the embodiments of this specification will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this specification, and not all embodiments. Based on the embodiments in this specification, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this specification.
[0014] In the description of this specification, it should be understood that the terms "first," "second," etc., are used for descriptive purposes only and should not be construed as indicating or implying relative importance. In the description of this specification, it should be noted that, unless otherwise expressly specified and limited, "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units is not limited to the listed steps or units, but may optionally include steps or units not listed, or may optionally include other steps or units inherent to these processes, methods, products, or devices. Those skilled in the art can understand the specific meaning of the above terms in this specification based on the specific circumstances. Furthermore, in the description of this specification, unless otherwise stated, "multiple" means two or more. "And / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A alone, A and B simultaneously, and B alone. The character " / " generally indicates that the preceding and following related objects are in an "or" relationship.
[0015] The present specification will now be described in detail with reference to specific embodiments.
[0016] It should be noted that the information (including but not limited to user device information, user personal information, etc.), data (including but not limited to data used for analysis, stored data, displayed data, etc.), and signals involved in the embodiments of this specification are all authorized by the user or fully authorized by all parties, and the collection, use, and processing of related data must comply with the relevant laws, regulations, and standards of the relevant countries and regions. For example, the features, information, and data involved in this specification were all obtained under full authorization.
[0017] like Figure 1 As shown, Figure 1 This is a flowchart illustrating a risk control method provided in the embodiments of this specification. Figure 1It includes at least a server 101 for implementing risk control methods, and multiple electronic devices for uploading project information for projects to be published or viewing risk identification reports. These multiple electronic devices include at least electronic devices 1021, 1022, and 1023. It is understood that... Figure 1 The number of servers and electronic devices shown is for illustrative purposes only, and the embodiments in this specification do not impose any limitations on them.
[0018] The aforementioned server 101 can be a standalone server device, such as a rack-mounted, tower-mounted, or cabinet-type server device, or a workstation, mainframe computer, or other hardware device with strong computing power; it can also be a server cluster composed of multiple servers. The servers in the service cluster can be composed in a symmetrical manner, where each server is functionally and hierarchically equivalent in the transaction chain, and each server can provide services to the outside world independently. Providing services independently can be understood as not requiring the assistance of other servers.
[0019] For example, a server can be multiple physical servers, each with independent hardware. Alternatively, a server can be multiple virtual servers deployed within the same hardware resource pool. Virtual server deployment methods include, but are not limited to, VMware, VirtualBox, and Virtual PC.
[0020] It is understood that server 101 also possesses other service capabilities and functions to complete the tasks described in the following embodiments. For example, server 101 also provides portal services, resource management services, and CI / CD services, etc.
[0021] Electronic devices include, but are not limited to: wearable devices, handheld devices, personal computers, tablets, in-vehicle devices, smartphones, computing devices, or other processing devices connected to a wireless modem. Electronic devices may have different names in different networks, such as: user equipment, access terminal, user unit, user station, mobile station, mobile station, remote station, remote terminal, mobile device, user terminal, terminal, wireless communication equipment, user agent or user device, cellular phone, cordless phone, personal digital assistant (PDA), and electronic devices in 5G networks or future evolved networks.
[0022] In the embodiments of this specification, electronic devices such as electronic devices 1021, 1022, and 1023 may also be equipped with display devices. These display devices can be various devices capable of display functions, such as cathode ray tube displays (CR), light-emitting diode displays (LED), electronic ink screens, liquid crystal displays (LCD), and plasma display panels (PDP). For example, a user can use the display device on electronic device 1021 to send project information for a project to be published to server 101, or view a risk identification report for a project to be published sent by server 101.
[0023] Multiple electronic devices and multiple servers can communicate through communication links established by communication protocols. For example, the network can be a wireless network or a wired network. Wireless networks include, but are not limited to, cellular networks, wireless LANs, infrared networks, or Bluetooth networks. Wired networks include, but are not limited to, Ethernet, universal serial bus (USB), or controller area networks. In one or more embodiments of the specification, technologies and / or formats including Hyper Text Markup Language (HTML), Extensible Markup Language (XML), etc., are used to represent data exchanged over the network (such as target compressed packets). Furthermore, conventional encryption technologies such as Secure Socket Layer (SSL), Transport Layer Security (TLS), Virtual Private Network (VPN), and Internet Protocol Security (IPsec) can be used to encrypt all or some of the links. In other embodiments, customized and / or dedicated data communication technologies can be used to replace or supplement the aforementioned data communication technologies.
[0024] In one embodiment, such as Figure 2 The diagram shown is a flowchart illustrating a risk control method provided in an embodiment of this specification. This method can be implemented using a computer program and can run on a risk control device based on the von Neumann architecture. The computer program can be integrated into an application or run as a standalone utility application.
[0025] Specifically, the risk prevention and control methods include: S102. Obtain the project information corresponding to the project to be published.
[0026] Obtaining project data corresponding to a project to be released refers to automatically retrieving a set of documents associated with the software iteration unit that is about to enter the release process from the R&D management platform in response to a test submission or release request event triggered during the design verification phase.
[0027] A project awaiting release refers to a software iteration unit that is about to be approved for release and launched, including but not limited to new functional modules, transaction rules and strategies, algorithm model configurations, or application version updates. Project documentation refers to multiple documents required to support the implementation of this software iteration unit, such as requirements description documents describing transaction goals and processing logic, and system design documents describing system architecture, interface definitions, data flow, and exception handling mechanisms.
[0028] S104. Based on a pre-set risk knowledge base, identify financial loss risks from project data using a large language model to obtain a risk identification report.
[0029] A risk knowledge base can be understood as a searchable collection of risk knowledge data formed by standardizing and archiving historical risk data such as project information, asset loss incidents, and prevention and control rules.
[0030] Specifically, the risk knowledge base can include historical asset loss risk scenarios, i.e., real-world cases of asset damage caused by system defects or logical vulnerabilities in past projects, along with their root cause analyses. The risk knowledge base can also include an asset loss risk white paper, defining the judgment criteria and technical characteristics of typical risk types such as consistency risk, timeliness risk, and calculation error risk. The risk knowledge base can also include multiple risk test cases for risk testing of projects before release. Furthermore, the risk knowledge base can include risk prevention and control rules, including multiple risk points under various risk types and corresponding in-process and post-process prevention and control rules for each risk point. This risk knowledge data is stored in vectorized or structured tag form to support indexing and retrieval by large language models when identifying asset loss risks.
[0031] Large language models refer to large-scale pre-trained neural network models with natural language understanding and generation capabilities, such as generative models based on the Transformer architecture or industry-specific models fine-tuned using corpora from the financial and software engineering fields. Large language models possess semantic parsing, logical reasoning, and pattern matching capabilities. In the embodiments of this specification, either a general-purpose large language model can be directly invoked, or a large language model fine-tuned for domain adaptation can be deployed.
[0032] A risk identification report shall include at least one of the following: at least one type of risk identified, risk testing coverage, and risk prevention and control coverage. Each risk type may correspond to at least one specific risk point.
[0033] Risk type clearly lists the specific asset loss risk categories that exist in the project. Typical risk types include consistency risk, such as duplicate deductions caused by cross-system state asynchrony; timeliness risk, such as duplicate processing caused by lack of idempotent control for timeout retries; and calculation error risk, such as loss of amount accuracy or improper handling of boundary conditions.
[0034] Risk test coverage refers to whether the existing test case system has established corresponding verification scenarios for different risk types, that is, whether the multiple possible risk points corresponding to the risk type are covered by the testing process.
[0035] Risk control coverage can be understood as whether the project materials have configured corresponding in-process and post-process control rules for different risk types, such as in-process monitoring, circuit breaker and flow restriction, and online backup measures such as post-process reconciliation and compensation.
[0036] Using the risk identification report as the output standard, the large language model combines risk knowledge data from the risk knowledge base to conduct in-depth analysis of project materials. It focuses on identifying whether there are risk points belonging to typical asset loss risk types such as consistency, timeliness, and calculation errors. It also simultaneously evaluates the coverage of risk testing and risk prevention and control, and weights and quantifies the above-mentioned multiple risk points, risk testing coverage, and risk prevention and control coverage to form a digital water level score that can be directly involved in management and control decisions, as part of the risk identification report.
[0037] S106. Based on the risk identification report, control the release of projects to be released.
[0038] The risk identification report will be used as the admission criterion for projects to enter the release process. The multi-dimensional data and scores in the risk identification report will be analyzed, and corresponding control measures will be implemented for the projects to be released. These control measures will include at least direct release, interception and blocking, return for supplementary rectification, and marking for observation.
[0039] For example, if a risk identification report identifies the risk type of a project to be published, such as consistency risk, timeliness risk, or calculation error risk, and the specific risk point corresponding to the risk type would cause serious losses, then the publication of the project to be published will be blocked.
[0040] For example, if a risk identification report indicates that the risk testing coverage of the project to be released is below the coverage threshold, it means that the corresponding risk type has not been effectively verified, and the release of the project to be released will be blocked.
[0041] For example, if the risk identification report indicates that the project data has configured risk control measures such as real-time monitoring and alarms, abnormal circuit breakers, traffic limiting, or post-event reconciliation and compensation for the identified risk types, and the risk control coverage meets the preset requirements, then it is determined that the project has an effective fallback mechanism after going live, and the project to be released can be published.
[0042] In this embodiment, project data, including requirement descriptions and system implementation information corresponding to the project to be released, is acquired. Based on a pre-built risk knowledge base, a large language model is used to identify asset loss risks in the project data. This moves the risk identification process from the online stage to the design verification stage, identifying potential asset loss risks before project release, effectively preventing defective projects from entering the production environment, and significantly narrowing the scope of asset loss impact. Furthermore, in this embodiment, the large language model is applied to the field of asset loss risk analysis. By constructing a risk knowledge base and standardized risk identification reports, the large language model can replace manual work in identifying asset loss risks based on specific role settings, process steps, and output specifications. This achieves intelligent asset loss risk analysis and overcomes the problems of insufficient analysis coverage and superficiality caused by over-reliance on manual experience review. Finally, in this embodiment, the risk identification report can include information such as risk points belonging to different risk types, risk testing coverage, and risk prevention coverage. The risk identification report enables a quantitative assessment of the completeness of risk exposure and prevention, ensuring the accuracy of management of the project to be released based on the risk identification report and significantly improving the reliability of asset loss risk prevention.
[0043] like Figure 3 As shown, Figure 3 This is a schematic diagram of multiple processes provided in the embodiments of this specification. The risk control system achieves closed-loop management of asset loss risks from the source of R&D identification to continuous evolution and prevention through the coordinated operation of four core modules: the pre-project release process 201, the asset loss risk identification process 202, the risk knowledge base construction process 203, and the iterative optimization process 204.
[0044] The pre-release process 201 includes four stages: project design, code implementation, testing and verification, and pre-release preparation. In the project design stage, users submit project materials including the project design plan. In the code implementation stage, functional coding is performed based on the project design plan. In the testing and verification stage, functional testing and loss-specific testing are performed based on the functional code data. Once the tests are passed, the project enters the pre-release preparation stage. The risk control system automatically triggers the loss risk identification process 202, which identifies loss risks in the project materials and generates a risk identification report, thereby managing the project before release.
[0045] In the asset loss risk identification process 202, based on the project information obtained in the pre-project release process 201, the project information is used to identify asset loss risks through a large language model based on a preset risk knowledge base. The risk knowledge base not only provides risk knowledge data for the identification process but also continuously receives risk identification reports generated by the asset loss risk identification process. The risk identification report is then output and submitted to the manual review node. Based on the risk identification report, the human reviewer conducts a secondary confirmation and adjustment of the risk level, scope of impact, and control measures corresponding to the project to be released. The project to be released is then managed based on the results of the manual review and the risk identification report.
[0046] The risk knowledge base construction process 203 includes at least complex, multi-dimensional archived risk case nodes and multi-dimensional risk exposure trend statistics nodes to build the risk knowledge base.
[0047] In this embodiment, risk identification reports and project materials are associated and stored in a risk knowledge base. Specifically, risk cases are archived according to the multi-dimensional risk attributes corresponding to asset loss risks. These multi-dimensional risk attributes include at least transaction domain, asset chain, and anomaly pattern. The transaction domain attribute identifies the transaction category to which the asset loss risk belongs, the asset chain attribute records the processing path of the asset's flow between platforms, and the anomaly pattern attribute characterizes the technical root cause type of the asset loss risk. During archiving, the risk type, risk test coverage, risk control coverage, and corresponding manual review results included in the risk identification report are associated and stored with the requirement description information and system implementation information in the project materials, mapped according to the aforementioned multi-dimensional risk attributes.
[0048] Furthermore, risk exposure trend statistics can be performed across multiple dimensions, including team, version, and iteration. These statistics are based on quantitative analysis of changes in data such as the types and quantities of risks identified within each iteration cycle, the compliance rates of risk testing coverage and risk prevention coverage, forming inheritable, measurable, and statistically significant risk knowledge data for user access.
[0049] When a new project is launched, asset risks can be identified by using a large language model based on a risk knowledge base. This allows for the rapid reuse of risk knowledge data such as historical cases and prevention and control rules accumulated in the risk knowledge base, thereby systematically avoiding the risk of recurring asset losses.
[0050] In iterative optimization process 204, a data-driven flywheel is constructed, from identification to prevention to drills to optimization. Specifically, it receives the risk identification report output from asset loss risk identification process 202, continuously identifying risk types and specific risk points during the identification phase. In the prevention phase, based on the risk identification report, monitoring rules and prevention strategies for risk points are constructed. In the drill phase, real-world attack paths are simulated through attack and defense drills, transaction verification, and transaction validation to verify the effectiveness of the defense system. In the optimization phase, asset loss test cases are generated based on the drill and verification results, and the verified and effective prevention experience is fed back to the risk knowledge base construction process 203. Simultaneously, the parameters of the large language model and identification rules in asset loss risk identification process 202 are optimized in reverse, continuously improving the accuracy of risk identification and the completeness of prevention in practical iterations.
[0051] In this manual, the risk control system achieves end-to-end management of asset security through a modular design. The system is responsible for summarizing, making decisions about, and performing multi-dimensional statistics on asset loss risks. It also integrates with other tools and platforms, such as attack and defense drill platforms, test scenario coverage platforms, production traffic management platforms, offline data exploration platforms, and verification platforms. Based on a large number of risk cases accumulated in the risk knowledge base, it automatically generates asset loss test cases to support practical scenarios such as attack and defense drills and critical security verification. This forms a data-driven flywheel from identification to prevention to drills to optimization, continuously strengthening asset loss prevention capabilities in real-world scenarios.
[0052] In one embodiment, project materials are parsed and metadata is extracted to obtain technical feature text data; based on a preset risk knowledge base, the technical feature text data is used to identify financial loss risks through a large language model to obtain a risk identification report.
[0053] Project materials include requirements description documents and system design documents. Since these project materials are unstructured or semi-structured data, they cannot be directly used by large language models for asset loss risk identification; therefore, document parsing and metadata extraction are required first.
[0054] Document parsing refers to the use of natural language processing and multimodal parsing techniques to identify and extract content from various media within project documents. For natural language text in requirements description documents, it involves word segmentation, syntactic analysis, and semantic understanding. For image content such as sequence diagrams and flowcharts in system design documents, it involves graphic element recognition and logical relationship extraction. For structured fragments such as interface definitions and data table structures, it involves parsing fields, types, and relationships. Through document parsing, heterogeneous text, images, and structured data in project documents are uniformly transformed into an initial content representation that can be understood by a machine.
[0055] Metadata extraction and processing refers to extracting key transaction and technical metadata related to asset transfer, status changes, and anomaly handling from the initial content representation based on document parsing and a pre-defined asset loss risk identification dimension. This process performs targeted feature extraction for asset loss risk identification tasks, mapping the transaction logic in project documents into standardized technical features.
[0056] The technical feature text data is output in a structured form, serving as a standardized input for subsequent large language models to identify asset loss risks, enabling large language models to identify asset loss risks based on unified transaction and technical semantics.
[0057] In one embodiment, such as Figure 4 The diagram shown is a flowchart illustrating a risk control method provided in an embodiment of this specification. This method can be implemented using a computer program and can run on a risk control device based on the von Neumann architecture. The computer program can be integrated into an application or run as a standalone utility application.
[0058] Specifically, the risk prevention and control methods include: S202. Obtain the project information corresponding to the project to be published.
[0059] See S102 above, which will not be repeated here.
[0060] S204. Using a large language model and a pre-set risk knowledge base, identify the financial loss risk of the existing content in the project data that matches the risk knowledge base, and obtain the stock analysis results.
[0061] Existing content refers to the portion of project materials whose characteristics, such as the transaction domain, technical implementation path, or asset chain, are semantically consistent or structurally similar to existing risk cases in the risk knowledge base. For example, if the project materials include content such as "first deducting the user's asset balance, then calling an external interface to complete the transfer, and without configuring a timeout compensation mechanism," this content highly matches the "Consistency Risk - No Compensation for Timeout" risk case already archived in the risk knowledge base in terms of asset transfer chain and abnormal patterns, thus constituting matching existing content.
[0062] The large language model identifies asset loss risks in matched existing content. This means that, based on the aforementioned matching relationships, the large language model directly references risk knowledge data from the risk knowledge base, such as risk types, root cause analyses, and prevention and control rules for corresponding risk cases, to determine whether the project data contains the same or similar asset loss risks. The identification process is not a process of re-inference discovery, but rather a process of correlation mapping and replication confirmation based on historically verified risk knowledge data.
[0063] The results of the inventory analysis are the output of the above identification process. The results may include matching fragments of inventory content from the project data, corresponding risk case identifiers, identified asset loss risk types, risk similarity scores, and risk prevention and control measures.
[0064] like Figure 5 As shown, Figure 5 This is a flowchart illustrating a process for identifying financial loss risks using a large-scale model, as provided in the embodiments of this specification. The project data 301 undergoes document parsing and metadata extraction to obtain technical feature text data 302. The large-scale language model, combined with a risk knowledge base 303, identifies financial loss risks in the existing content of the technical feature text data 302, resulting in an inventory analysis result 305.
[0065] S206. Using a large language model, identify the risk of financial loss for incremental content in project data that does not match the risk knowledge base, and obtain the results of incremental analysis.
[0066] Incremental content refers to content in project materials that is not included in the existing content. The characteristics of incremental content cannot be effectively matched with existing risk cases in the risk knowledge base. Incremental content may be semantically similar to existing risk cases but does not reach a preset matching threshold, or it may belong to a completely new business area, innovative interaction mode, or technical architecture not yet covered by the risk knowledge base.
[0067] For incremental content, the large language model uses its general semantic understanding capabilities and knowledge of asset loss risk domains to conduct in-depth reasoning and analysis, autonomously uncovering potential asset loss risk types. By analyzing the transaction processing flow, asset transfer nodes, abnormal branches, and boundary conditions in the incremental content, the large language model identifies whether there are asset loss risk types caused by factors such as state asynchrony, timeout retries, calculation accuracy, or concurrency control.
[0068] Incremental analysis results can include the identified types of asset loss risks, as well as specific risk points, risk triggering conditions, and the scope of risk impact.
[0069] In one embodiment, a large language model is used to identify the incremental content in the project data that does not match the risk knowledge base to obtain the first incremental analysis result, and to identify the manually annotated risk analysis content in the project data to obtain the second incremental analysis result; based on the asset loss risk template, the first and second incremental analysis results are templated to obtain the incremental analysis result.
[0070] Specifically, the manually annotated risk analysis content in project materials refers to the dedicated asset loss risk analysis module in the system design analysis document, also known as the system analysis document. In this module, the architect or risk control personnel have explicitly stated, in natural language, their manual predictions of potential asset loss risks for this function during the design phase. For example, they might state, "This function involves cross-system asset transfers, and there is a consistency risk that external interface timeouts may result in successful deductions but failed transfers." The large language model locates and parses this module in the system analysis document, extracting manually annotated risk descriptions, risk levels, and prevention and control recommendations, forming a second incremental analysis result.
[0071] Furthermore, based on the asset loss risk template, the first and second incremental analysis results are templated, including splitting and integrating, to obtain the incremental analysis results. Because the first incremental analysis result comes from the automatic inference output of a large language model, while the second incremental analysis result is extracted from manually annotated risk analysis content, they differ in expression format, granularity, and classification standards. Therefore, through templated processing, according to preset dimensions such as transaction category, transaction subcategory, involved systems, and risk point descriptions, the first and second incremental analysis results are split and formatted respectively, and the formatted data is integrated into the incremental analysis results, ensuring that each risk record in the incremental analysis results has a unified structured attribute.
[0072] After template processing, the results of the first and second incremental analyses are integrated into a single incremental analysis result with consistent format and aligned dimensions, serving as standardized input for the subsequent generation of risk identification reports.
[0073] like Figure 5 As shown, the large language model identifies the asset loss risk in the incremental content of the technical feature text data 302 to obtain the first incremental analysis result, and identifies the manually annotated risk analysis content to obtain the second incremental analysis result. Based on the asset loss risk template, the first and second incremental analysis results are templated to obtain the stock analysis result 304.
[0074] S208. Based on the results of the stock analysis and the incremental analysis, a risk identification report is obtained.
[0075] The risk identification report is obtained by combining the results of existing and incremental analysis.
[0076] In one embodiment, the existing analysis results and the incremental analysis results are integrated and optimized based on the confidence levels corresponding to the existing analysis results and the incremental analysis results, respectively, to obtain a preliminary risk identification report; the multiple risk points included in the preliminary risk identification report are filtered to obtain a risk identification report; wherein the multiple risk points belong to different risk types.
[0077] Specifically, different confidence weights are assigned to the stock analysis results and the incremental analysis results. Since the stock analysis results are obtained by identifying financial loss risks based on verified risk cases in the risk knowledge base, while the incremental analysis results are autonomously mined by the large language model based on general reasoning capabilities, the confidence weight of the stock analysis results is greater than that of the incremental analysis results.
[0078] In this embodiment, the incremental analysis results include a first incremental analysis result and a second incremental analysis result. The second incremental analysis result is identified by manually annotated risk analysis content, so the confidence level of the second incremental analysis result is greater than that of the first incremental analysis result.
[0079] During the integration and optimization phase, multiple risk points included in both existing and incremental analysis results are examined, each belonging to a different risk type. Conflicting risk points are adjudicated and information is fused based on the aforementioned confidence weights. For example, if the existing analysis results have identified a consistency risk in an asset transfer chain, and the first or second incremental analysis result also identifies the same or similar risk, then the risk type definition, risk level, and recommended control rules from the existing analysis results are used as a benchmark, and differentiated descriptions from other sources are merged as supplementary details to avoid duplicate recording. If the incremental analysis results identify new risk points not covered by the existing analysis results, they are directly included in the preliminary risk identification report.
[0080] Through the above integration and optimization, the preliminary risk identification report retains high-confidence historical experience while incorporating novel risk perspectives from incremental discoveries, achieving unified aggregation and deduplication optimization of multi-source risk data.
[0081] Subsequently, the system performs filtering on the preliminary risk identification report. This filtering process may include responding to human feedback on risk points and removing risk points that are explicitly marked as unacceptable by the human analyst from the preliminary risk identification report. For example, the large language model may identify a log printing field as having a risk of asset leakage in the first incremental analysis result, but after human review, it may be confirmed that the field is anonymized pseudonymous data and does not constitute a risk of asset loss; in this case, the risk point will be filtered out.
[0082] In addition, the system performs deduplication filtering on multiple risk points based on preset repetition rules. When risk points described by different sources overlap in transaction category, transaction subcategory, involved system, and risk point description, the record from the source with the highest confidence level is retained, and redundant entries are deleted. After the above filtering process, the final risk identification report is obtained.
[0083] like Figure 5As shown, based on the confidence levels corresponding to the stock analysis result 305 and the incremental analysis result 304, the stock analysis result 305 and the incremental analysis result 304 are integrated and optimized to obtain a preliminary risk identification report. Then, multiple asset loss risk points included in the preliminary risk identification report are filtered to obtain a risk identification report 306.
[0084] By configuring differentiated confidence levels for existing and incremental analysis results and establishing a fusion adjudication mechanism, the problem of standardized integration when multi-source identification results conflict is effectively solved. This avoids the proliferation of false alarms caused by relying solely on large language models for automatic identification, and also prevents the risk of missed detection caused by over-reliance on historical experience, significantly improving the accuracy and executability of risk identification reports.
[0085] S210. Based on the risk identification report, control the release of projects to be released.
[0086] See S106 above; it will not be repeated here.
[0087] In one embodiment, such as Figure 6 The diagram shown is a flowchart illustrating a risk control method provided in an embodiment of this specification. This method can be implemented using a computer program and can run on a risk control device based on the von Neumann architecture. The computer program can be integrated into an application or run as a standalone utility application.
[0088] Specifically, the risk prevention and control methods include: S302. Obtain the project information corresponding to the project to be published.
[0089] In one embodiment, the process involves obtaining the project data to be processed corresponding to the project to be published, and then standardizing the project data to obtain project data. The project data includes multiple standardized documents.
[0090] Specifically, the system monitors test submission or release application events in the R&D management platform. In response to these events, it automatically retrieves the project data associated with the project to be released and standardizes the structured text, sequence diagrams, interface definitions, and data table structures contained in this data. This standardizes the project data to obtain standardized input data for subsequent risk identification. The project data includes multiple standardized documents, such as requirement description documents, system design documents, and iteration IDs.
[0091] like Figure 7 As shown, Figure 7This is a schematic diagram of a risk control process provided in the embodiments of this specification. After the developer completes the project submission on the testing platform 401, a risk control event is triggered. Based on the triggering of the risk control event, the risk control system standardizes the pending project data corresponding to the project, obtaining project data including multiple standardized documents, and triggers a notification to identify the financial loss risk of the project data.
[0092] S304. Based on a pre-set risk knowledge base, identify financial loss risks from project data using a large language model to obtain a risk identification report.
[0093] See S104 above; it will not be repeated here.
[0094] S306. Obtain a human assessment report that verifies the risk identification report.
[0095] The risk control system sends the risk identification report to the reviewer's electronic device for manual review. This manual review process includes reviewing multiple asset loss risk points, risk testing coverage, and risk control coverage in the risk identification report, and then obtaining a manual assessment report.
[0096] The manual assessment report may include a list of confirmed and valid risk points, along with the risk type, risk level, and risk description for each risk point; a list of rejected risk points and the basis for rejection; a list of manually identified risk points and the basis for supplementation; a review conclusion on the coverage of risk testing and risk control; and control recommendations.
[0097] like Figure 5 As shown, project data 402 undergoes multimodal enhanced parsing, which involves document parsing and metadata extraction, to obtain technical feature text data 404. A large language model, combined with a risk knowledge base 403, identifies the financial loss risk of the technical feature text data 404. This can include identifying financial loss risks for both incremental and existing content, resulting in a risk assessment report 405. The risk assessment report 405 is then sent to the reviewer's electronic device for manual confirmation, resulting in a manual assessment report 406.
[0098] S308. Based on the risk identification report, manual assessment report, and risk knowledge base, an iterative risk identification report is obtained.
[0099] Specifically, the risk assessment report includes the identification conclusions obtained after the large language model performs stock and incremental analysis on the project data, the manual assessment report includes the manual assessment results after reviewing the risk assessment report, and the risk knowledge base 403 is used as stock knowledge support, including structured archived risk knowledge data.
[0100] In generating iterative loss risk reports, the risk assessment report can be used as a base, with modifications made based on the manual assessment report. For example, valid risk points identified in the manual assessment report can be retained, their risk levels adjusted accordingly, risk points marked as false alarms in the manual assessment report can be removed, and additional risk points identified in the manual assessment report can be added. Furthermore, the risk knowledge base is invoked to perform historical correlation and rule matching on each modified risk point. For instance, based on the transaction domain attributes, asset link attributes, and anomaly pattern attributes of each risk point, similar risk cases are retrieved from the risk knowledge base, automatically associating historical accident root causes, historical loss scales, and verified prevention and control rule requirements, ultimately resulting in the iterative loss risk report.
[0101] The iterative loss risk report should at least include the pre-event coverage status, i.e., whether the risk testing coverage for each risk point has reached the preset threshold and a detailed list of any uncovered gaps. The iterative loss risk report may also include the in-event coverage status, i.e., whether the risk prevention and control coverage for each risk point has reached the preset threshold and the status of prevention and control measures. The iterative loss risk report may also include priority tags, i.e., the priority assigned to each risk point based on the severity of the risk type, the risk level adjusted by manual assessment, and the historical loss scale associated with the risk knowledge base.
[0102] like Figure 5 As shown, based on the risk identification report 405, the manual assessment report 406, and the risk knowledge base 406, the iterative risk identification report 407 is obtained.
[0103] S310. Based on the iterative risk identification report, control the release of projects to be released.
[0104] The iteration risk identification report is used as the admission criterion for projects to enter the release process. The multi-dimensional data and scores in the iteration risk identification report are analyzed, and corresponding control measures are implemented for projects to be released.
[0105] In one embodiment, based on the iterative risk identification report, if it is determined that the project to be published exists in the whitelist, or meets the publication conditions related to the manual assessment report, or meets the publication conditions related to the risk identification report, the project to be published is published.
[0106] As shown in Figure 5, the first step is to check if the project to be released is on the whitelist. The whitelist includes low-risk project types that have been historically verified or regular iterations that do not involve changes in asset loss risk. If the project to be released is confirmed to be on the whitelist, it is directly released through the release process for rapid approval.
[0107] Furthermore, if a project to be published is not on the whitelist, the system will determine whether it meets the publication criteria outlined in the manual assessment report. In other words, the manual decision from the assessment report will be adopted for project management. If the manual decision recommends publication, the publication will be executed. If the manual assessment recommends blocking, the blocking will be executed.
[0108] Furthermore, if no manual assessment results are available in the iterative risk identification report, the system determines whether the project to be released meets the release conditions related to the risk identification report, i.e., it uses the large language model's decision-making to manage the project to be released. If the large language model determines there is no risk, the release is accelerated through iteration. This level of determination applies to regular iterations that are confirmed as low-risk after automatic scanning by the large language model, improving release efficiency while ensuring basic security.
[0109] Furthermore, if the risk identification report identifies at least one asset loss risk, then a hard indicator verification process begins. Based on the pre-event and in-event coverage status in the iterative risk identification report, it is checked whether the risk control coverage corresponding to each identified risk type reaches the preset coverage threshold (e.g., ...). Figure 7 The value shown is 100% (this embodiment may also include other values). Simultaneously, the iterative risk identification report is checked for any high-priority risk points awaiting manual adoption. If the risk control coverage meets the preset threshold and there are no high-priority risk points awaiting adoption, the project is released. If the risk control coverage does not meet the standard, or there are high-priority risk points awaiting adoption, the release conditions are not met, dynamic blocking is implemented, the project is prohibited from going live, and the project is returned to the development or testing phase for rectification.
[0110] This embodiment constructs a tiered and progressive release access mechanism, which specifically includes directly allowing low-risk projects or regular iterations that have been historically verified to be released through a whitelist mechanism, and prioritizing human decision-making in the manual evaluation report, and then checking whether the project to be released meets the release conditions related to the risk identification report. Under the premise of ensuring the bottom line of asset loss risk prevention and control, it achieves a dynamic balance between asset loss risk prevention and control and R&D release efficiency.
[0111] The following are embodiments of the apparatus described in this specification, which can be used to execute the embodiments of the methods described in this specification. For details not disclosed in the apparatus embodiments of this specification, please refer to the embodiments of the methods described in this specification.
[0112] Please see Figure 8 This diagram illustrates the structure of a risk control device provided in an exemplary embodiment of this specification. The risk control device can be implemented as all or part of a whole through software, hardware, or a combination of both. The device includes a data acquisition module 501, a risk identification module 502, and a release control module 503.
[0113] The data acquisition module 501 is used to acquire project data corresponding to the project to be published. The risk identification module 502 is used to identify financial loss risks in the project data based on a preset risk knowledge base and a large language model, and to obtain a risk identification report; wherein the risk identification report includes at least one of the following: at least one type of risk identified, risk test coverage, and risk prevention and control coverage. The release control module 503 is used to control the release of the project to be released based on the risk identification report.
[0114] In one or more embodiments, the risk identification module 502 includes: The stock identification unit is used to identify the risk of financial loss in the stock content of the project data that matches the risk knowledge base through a large language model and a preset risk knowledge base, and to obtain the stock analysis results. The incremental identification unit is used to identify the risk of financial loss in incremental content in the project data that does not match the risk knowledge base through the large language model, and obtain the incremental analysis results. The risk identification unit is used to generate a risk identification report based on the stock analysis results and the incremental analysis results.
[0115] In one or more embodiments, the incremental identification unit is specifically used to identify the incremental content in the project data that does not match the risk knowledge base through the large language model to obtain a first incremental analysis result, and to identify the manually annotated risk analysis content in the project data to obtain a second incremental analysis result; based on the asset loss risk template, the first incremental analysis result and the second incremental analysis result are templated to obtain the incremental analysis result.
[0116] In one or more embodiments, the risk identification unit is specifically configured to integrate and optimize the existing analysis results and the incremental analysis results based on the confidence levels corresponding to the existing analysis results and the incremental analysis results, respectively, to obtain a preliminary risk identification report; and to filter multiple risk points included in the preliminary risk identification report to obtain a risk identification report; wherein the multiple risk points belong to different risk types.
[0117] In one or more embodiments, the risk identification module 502 is specifically used to perform document parsing and metadata extraction processing on the project data to obtain technical feature text data; based on a preset risk knowledge base, it uses a large language model to identify financial loss risks in the technical feature text data to obtain a risk identification report.
[0118] In one or more embodiments, the release control module 503 includes: The first control unit is used to obtain a manual assessment report that is manually confirmed by the risk identification report; The second control unit is used to obtain an iterative risk identification report based on the risk identification report, the manual assessment report, and the risk knowledge base; The third control unit is used to control the release of the project to be released based on the iterative risk identification report.
[0119] In one or more embodiments, the third control unit is specifically used to release the project to be released when it determines, based on the iterative risk identification report, that the project to be released exists in the whitelist, or meets the release conditions related to the manual assessment report, or meets the release conditions related to the risk identification report.
[0120] In one or more embodiments, the data acquisition module 501 is specifically used to acquire the data of the project to be published that needs to be processed, and to perform standardization processing on the data of the project to be processed to obtain project data; wherein, the project data includes multiple standardized documents.
[0121] In one or more embodiments, the risk control device further includes: The storage module is used to associate and store the risk identification report and the project information in the risk knowledge base.
[0122] In this embodiment, project data, including requirement descriptions and system implementation information corresponding to the project to be released, is acquired. Based on a pre-built risk knowledge base, a large language model is used to identify asset loss risks in the project data. This moves the risk identification process from the online stage to the design verification stage, identifying potential asset loss risks before project release, effectively preventing defective projects from entering the production environment, and significantly narrowing the scope of asset loss impact. Furthermore, in this embodiment, the large language model is applied to the field of asset loss risk analysis. By constructing a risk knowledge base and standardized risk identification reports, the large language model can replace manual work in identifying asset loss risks based on specific role settings, process steps, and output specifications. This achieves intelligent asset loss risk analysis and overcomes the problems of insufficient analysis coverage and superficiality caused by over-reliance on manual experience review. Finally, in this embodiment, the risk identification report can include information such as risk points belonging to different risk types, risk testing coverage, and risk prevention coverage. The risk identification report enables a quantitative assessment of the completeness of risk exposure and prevention, ensuring the accuracy of management of the project to be released based on the risk identification report and significantly improving the reliability of asset loss risk prevention.
[0123] It should be noted that the risk control device provided in the above embodiments is only illustrated by the division of the above functional modules when executing the risk control method. In actual applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above. In addition, the risk control device and the risk control method embodiments provided in the above embodiments belong to the same concept, and the implementation process is detailed in the method embodiments, which will not be repeated here.
[0124] The example numbers in this specification are for descriptive purposes only and do not represent the superiority or inferiority of the examples.
[0125] This specification also provides a computer storage medium that can store multiple instructions adapted to be loaded and executed by a processor as described above. Figure 1 - Figure 7 The risk control method of the illustrated embodiment can be found in the following document for detailed implementation process: Figure 1 - Figure 7 The specific details of the illustrated embodiments will not be elaborated here.
[0126] This specification also provides a computer program product that stores at least one instruction, which is loaded and executed by a processor as described above. Figure 1 - Figure 7 The risk control method of the illustrated embodiment can be found in the following document for detailed implementation process: Figure 1 - Figure 7 The specific details of the illustrated embodiments will not be elaborated here.
[0127] Please see Figure 9 This document provides a schematic diagram of the structure of an electronic device as an embodiment of the present specification. Figure 9 As shown, the electronic device 600 may include: at least one processor 601, at least one network interface 604, user interface 603, memory 605, and at least one communication bus 602.
[0128] The communication bus 602 is used to enable communication between these components.
[0129] The user interface 603 may include a display screen and a camera. Optionally, the user interface 603 may also include a standard wired interface and a wireless interface.
[0130] The network interface 604 may optionally include a standard wired interface or a wireless interface (such as a Wi-Fi interface).
[0131] The processor 601 may include one or more processing cores. The processor 601 connects to various parts within the electronic device 600 using various interfaces and lines, and performs various functions and processes data by running or executing instructions, programs, code sets, or instruction sets stored in the memory 605, and by calling data stored in the memory 605. Optionally, the processor 601 may be implemented using at least one hardware form of Digital Signal Processing (DSP), Field-Programmable Gate Array (FPGA), or Programmable Logic Array (PLA). The processor 601 may integrate one or a combination of several of the following: a Central Processing Unit (CPU), a Graphics Processing Unit (GPU), and a modem. The CPU primarily handles the operating system, user interface, and applications; the GPU is responsible for rendering and drawing the content to be displayed on the screen; and the modem handles wireless communication. It is understood that the modem may also not be integrated into the processor 601 and may be implemented as a separate chip.
[0132] The memory 605 may include random access memory (RAM) or read-only memory. Optionally, the memory 605 may include a non-transitory computer-readable storage medium. The memory 605 may be used to store instructions, programs, code, code sets, or instruction sets. The memory 605 may include a program storage area and a data storage area, wherein the program storage area may store instructions for implementing an operating system, instructions for at least one function (such as touch function, sound playback function, image playback function, etc.), instructions for implementing the above-described method embodiments, etc.; the data storage area may store data involved in the above-described method embodiments, etc. Optionally, the memory 605 may also be at least one storage device located remotely from the aforementioned processor 601. Figure 9 As shown, the memory 605, which serves as a computer storage medium, may include an operating system, a network communication module, a user interface module, and a risk control application.
[0133] exist Figure 9In the illustrated electronic device 600, the user interface 603 is mainly used to provide an input interface for the user and to acquire user input data; while the processor 601 can be used to call the risk prevention and control application stored in the memory 605 and specifically perform the following operations: Obtain project information corresponding to the projects to be published; Based on a pre-set risk knowledge base, the project data is analyzed using a large language model to identify financial loss risks and obtain a risk identification report. The risk identification report includes at least one of the following: at least one type of risk identified, risk testing coverage, and risk prevention and control coverage. The release of the project to be released is controlled based on the risk identification report.
[0134] In one embodiment, the processor 601 executes the preset risk knowledge base and uses a large language model to identify financial loss risks in the project data, obtaining a risk identification report, specifically including: Using a large language model and a pre-set risk knowledge base, the existing content in the project data that matches the risk knowledge base is used to identify financial loss risks, and the results of the existing analysis are obtained. Using the large language model, incremental content in the project data that does not match the risk knowledge base is identified for financial loss risk, and incremental analysis results are obtained. Based on the results of the existing stock analysis and the results of the incremental analysis, a risk identification report is obtained.
[0135] In one embodiment, the processor 601 executes the step of identifying financial loss risks by using the large language model to identify incremental content in the project data that does not match the risk knowledge base, and obtains incremental analysis results, specifically including: Using the large language model, the incremental content in the project data that does not match the risk knowledge base is identified to obtain the first incremental analysis result, and the manually annotated risk analysis content in the project data is identified to obtain the second incremental analysis result. Based on the asset loss risk template, the first incremental analysis result and the second incremental analysis result are templated to obtain the incremental analysis result.
[0136] In one embodiment, the processor 601 executes the process of obtaining a risk identification report based on the stock analysis results and the incremental analysis results, specifically including: Based on the confidence levels corresponding to the stock analysis results and the incremental analysis results, the stock analysis results and the incremental analysis results are integrated and optimized to obtain a preliminary risk identification report; The multiple risk points included in the preliminary risk identification report are filtered to obtain a risk identification report; wherein the multiple risk points belong to different risk types.
[0137] In one embodiment, the processor 601 executes the preset risk knowledge base and uses a large language model to identify financial loss risks in the project data, obtaining a risk identification report, specifically including: The project materials are parsed and metadata is extracted to obtain technical feature text data; Based on a pre-set risk knowledge base, a risk identification report is obtained by using a large language model to identify financial loss risks in the technical feature text data.
[0138] In one embodiment, the processor 601 executes the step of determining whether to block the project to be released based on the risk identification report, specifically including: Obtain a human assessment report that verifies the risk identification report; Based on the risk identification report, the manual assessment report, and the risk knowledge base, an iterative risk identification report is obtained; Based on the iterative risk identification report, the release of the project to be released is controlled.
[0139] In one embodiment, processor 601 executes the release control of the project to be released based on the iterative risk identification report, specifically including: Based on the iterative risk identification report, if it is determined that the project to be published exists in the whitelist, or meets the publication conditions related to the manual assessment report, or meets the publication conditions related to the risk identification report, then the project to be published is published.
[0140] In one embodiment, the processor 601 performs the step of obtaining project information corresponding to the project to be published, specifically including: Obtain the project data to be processed corresponding to the project to be published, and perform standardization processing on the project data to obtain project data; wherein, the project data includes multiple standardized documents.
[0141] In one embodiment, processor 601 also performs: The risk identification report and the project information are associated and stored in the risk knowledge base.
[0142] In this embodiment, project data, including requirement descriptions and system implementation information corresponding to the project to be released, is acquired. Based on a pre-built risk knowledge base, a large language model is used to identify asset loss risks in the project data. This moves the risk identification process from the online stage to the design verification stage, identifying potential asset loss risks before project release, effectively preventing defective projects from entering the production environment, and significantly narrowing the scope of asset loss impact. Furthermore, in this embodiment, the large language model is applied to the field of asset loss risk analysis. By constructing a risk knowledge base and standardized risk identification reports, the large language model can replace manual work in identifying asset loss risks based on specific role settings, process steps, and output specifications. This achieves intelligent asset loss risk analysis and overcomes the problems of insufficient analysis coverage and superficiality caused by over-reliance on manual experience review. Finally, in this embodiment, the risk identification report can include information such as risk points belonging to different risk types, risk testing coverage, and risk prevention coverage. The risk identification report enables a quantitative assessment of the completeness of risk exposure and prevention, ensuring the accuracy of management of the project to be released based on the risk identification report and significantly improving the reliability of asset loss risk prevention.
[0143] Those skilled in the art will understand that all or part of the processes in the above embodiments can be implemented. Each of the above methods can be executed by a computer program instructing related hardware. The program corresponding to each method can be stored in a computer-readable storage medium. When executed, the program can include the processes of the embodiments of the above methods. The storage medium of the electronic device 600 can be a magnetic disk, optical disk, read-only memory, or random access memory, etc.
[0144] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0145] The above-disclosed embodiments are merely preferred embodiments of this specification and should not be construed as limiting the scope of this specification. Therefore, any equivalent variations made in accordance with the claims of this specification shall still fall within the scope of this specification.
Claims
1. A risk prevention and control method, the method comprising: Obtain project information corresponding to the projects to be published; Based on a pre-set risk knowledge base, the project data is analyzed using a large language model to identify financial loss risks and obtain a risk identification report. The risk identification report includes at least one of the following: at least one type of risk identified, risk testing coverage, and risk prevention and control coverage. The release of the project to be released is controlled based on the risk identification report.
2. The risk prevention and control method according to claim 1, wherein the step of identifying financial loss risks of the project data based on a preset risk knowledge base and using a large language model to obtain a risk identification report includes: Using a large language model and a pre-set risk knowledge base, the existing content in the project data that matches the risk knowledge base is used to identify financial loss risks, and the results of the existing analysis are obtained. Using the large language model, incremental content in the project data that does not match the risk knowledge base is identified for financial loss risk, and incremental analysis results are obtained. Based on the results of the existing stock analysis and the results of the incremental analysis, a risk identification report is obtained.
3. The risk prevention and control method according to claim 2, wherein the step of identifying the incremental content in the project data that does not match the risk knowledge base through the large language model to obtain the incremental analysis results includes: Using the large language model, the incremental content in the project data that does not match the risk knowledge base is identified to obtain the first incremental analysis result, and the manually annotated risk analysis content in the project data is identified to obtain the second incremental analysis result. Based on the asset loss risk template, the first incremental analysis result and the second incremental analysis result are templated to obtain the incremental analysis result.
4. The risk prevention and control method according to claim 2, wherein obtaining a risk identification report based on the stock analysis results and the incremental analysis results includes: Based on the confidence levels corresponding to the stock analysis results and the incremental analysis results, the stock analysis results and the incremental analysis results are integrated and optimized to obtain a preliminary risk identification report; The preliminary risk identification report is filtered to obtain a risk identification report; wherein the multiple risk points belong to different risk types.
5. The risk prevention and control method according to claim 1, wherein the step of identifying financial loss risks of the project data based on a preset risk knowledge base and using a large language model to obtain a risk identification report includes: The project materials are parsed and metadata is extracted to obtain technical feature text data; Based on a pre-set risk knowledge base, a risk identification report is obtained by using a large language model to identify financial loss risks in the technical feature text data.
6. The risk control method according to claim 1, wherein controlling the release of the project to be released based on the risk identification report includes: Obtain a manual assessment report that verifies the risk identification report; Based on the risk identification report, the manual assessment report, and the risk knowledge base, an iterative risk identification report is obtained; Based on the iterative risk identification report, the release of the project to be released is controlled.
7. The risk control method according to claim 6, wherein controlling the release of the project to be released based on the iterative risk identification report includes: Based on the iterative risk identification report, if it is determined that the project to be published exists in the whitelist, or meets the publication conditions related to the manual assessment report, or meets the publication conditions related to the risk identification report, then the project to be published is published.
8. The risk control method according to claim 1, wherein obtaining the project information corresponding to the project to be published includes: Obtain the project data to be processed corresponding to the project to be published, and perform standardization processing on the project data to obtain project data; wherein, the project data includes multiple standardized documents.
9. The risk prevention and control method according to claim 1, further comprising: The risk identification report and the project information are associated and stored in the risk knowledge base.
10. A risk control device, the device comprising: The data acquisition module is used to acquire project data corresponding to the project to be published. The risk identification module is used to identify financial loss risks in the project data based on a preset risk knowledge base and a large language model, and to obtain a risk identification report; wherein the risk identification report includes at least one of the following: at least one type of risk identified, risk test coverage, and risk prevention and control coverage; The release control module is used to control the release of the project to be released based on the risk identification report.
11. A computer storage medium storing a plurality of instructions adapted for loading by a processor and executing the method steps of any one of claims 1 to 9.
12. A computer program product storing a plurality of instructions adapted for loading by a processor and executing the method steps of any one of claims 1 to 9.
13. An electronic device, comprising: A processor and a memory; wherein the memory stores a computer program adapted to be loaded by the processor and executed the method steps as claimed in any one of claims 1 to 9.