Information processing device, information processing method and program
Patent Information
- Application Number
- JP2023167543
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-09-28
- Publication Date
- 2025-10-31
AI Technical Summary
Conventional risk management systems fail to effectively identify users suspected of fraudulently using electronic payment services due to the lack of utilization of trained machine learning models.
An information processing device and method that employs a trained machine learning model to analyze user data, including usage history, to determine fraudulent activity, and incorporates a relearning mechanism to enhance model accuracy by updating learning data with confirmed fraudulent instances.
Enables accurate identification of users engaging in fraudulent electronic payment activities, improving prediction accuracy and adaptability to changing user behavior patterns.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[Technical field]
[0001] The present invention relates to an information processing device, an information processing method, and a program. [Background technology]
[0002] Conventionally, a computerized risk management method and a risk management system for facilitating the analysis and quantification of risks associated with financial transactions have been disclosed (Patent Document 1). The system generates a risk index or other rating based on a weighted algorithm applied to criteria. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Special Publication No. 2005-509196 Summary of the Invention [Problem to be solved by the invention]
[0004] Conventional technologies do not use trained models trained through machine learning, and therefore may not be able to properly extract users of interest suspected of fraudulent use of electronic payment services.
[0005] The present invention has been made in consideration of the above circumstances, and one of its objectives is to provide an information processing device, an information processing method, and a program that can appropriately extract users of interest who are suspected of making fraudulent use of electronic payment services. [Means for solving the problem]
[0006] One aspect of the present invention is an information processing device that includes an inference unit that inputs input data having a plurality of data items including a user's usage history of an electronic payment service into a trained model that has been trained in advance by machine learning, and derives output data indicating whether a user related to the input data is a user of interest suspected of having committed fraudulent use of the electronic payment service, wherein the trained model has been trained by machine learning using the input data for a plurality of users and tag information indicating whether each of the plurality of users is a user who has committed the fraudulent use as training data, and further includes a re-learning unit that adds a pair of the input data for at least some of the users from whom information indicating that the user is the user of interest has been derived by the inference unit and tag information indicating that the user is a user who has committed the fraudulent use to the training data, and re-learns the trained model. Effect of the Invention
[0007] According to one aspect of the present invention, it is possible to provide an information processing device, an information processing method, and a program that can appropriately extract a user of interest who is suspected of making fraudulent use of an electronic payment service. [Brief description of the drawings]
[0008] [Figure 1] FIG. 1 is a diagram showing an example of a configuration for realizing an electronic payment service. [Diagram 2] This is a sequence diagram (part 1) illustrating the general flow of electronic payment. [Diagram 3] This is a sequence diagram (part 2) illustrating the general flow of electronic payment. [Figure 4] 1 is a configuration diagram of a payment server 100 according to a first embodiment. [Diagram 5] FIG. 13 is a diagram showing an example of the contents of user information 172. [Figure 6] FIG. 13 is a diagram showing an example of the contents of affiliated store / store information 176. [Figure 7] FIG. 2 is a diagram illustrating a configuration of an information processing device 200. [Figure 8] FIG. 13 is a diagram showing an example of the contents of a score table 278. [Figure 9] 11 is a diagram for explaining the processing content of a learning unit 230. FIG. [Figure 10] FIG. 13 is a diagram showing an example of a trend analysis information display screen IM1. [Figure 11] FIG. 11 is a diagram showing an example of the processing contents of a re-learning unit 240. [Figure 12] FIG. 13 is a diagram showing an example of a user number transition display screen IM2. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0009] Hereinafter, an information processing device, an information processing method, and a program according to the present invention will be described with reference to the drawings. The information processing device derives output data indicating whether or not a user who uses an electronic payment service is a target user who is suspected of having made fraudulent use of the electronic payment service. First, the electronic payment service will be described, and then the functions of the information processing device will be described.
[0010] [Electronic payment service] An electronic payment service is provided, for example, by cooperation between an application program (payment app) and a payment server. An electronic payment service is a service that supports payments for the purchase of goods and services at a store. A store is, for example, a physical store (real-world store) that exists in real space, but may also include a virtual store for electronic commerce. A virtual store may also include one provided by an entity other than the operator of the electronic payment service. In that case, when making a payment for a purchase at the virtual store, the screen is controlled to transition to an interface screen for the electronic payment service. In an electronic payment service, a store is treated as belonging to, for example, an affiliated store (brand), and processing such as payment when a purchase is made at a store is mainly carried out between the user and the affiliated store. Alternatively, processing such as payment may be carried out between the user and the store.
[0011] FIG. 1 is a diagram showing an example of a configuration for realizing an electronic payment service and an information processing device. The electronic payment service is realized mainly by a payment server 100. The payment server 100 communicates with, for example, one or more user terminal devices 10, one or more first store terminal devices 50, and one or more second store terminal devices 70 via a network NW. The network NW includes, for example, the Internet, a LAN (Local Area Network), a wireless base station, a provider device, and the like. The information processing device 200 is connected to the payment server 100 via a narrow area network (not shown), for example. Not limited to this, the information processing device 200 may be connected to the payment server 100 via the network NW, or may be a function of the payment server 100.
[0012] The user terminal device 10 is, for example, a portable terminal device such as a smartphone or a tablet terminal. The user terminal device 10 is a computer device having at least an optical reading function, a communication function, a display function, an input reception function, and a program execution function. In the following description, components for realizing these functions are referred to as a camera, a communication device, a touch panel, a CPU (Central Processing Unit), etc. In the user terminal device 10, a processor such as a CPU executes a payment application 20, thereby operating to provide an electronic payment service to a user in cooperation with a payment server 100. The payment application 20 is installed in the user terminal device 10 from, for example, an application store, and controls the camera, communication device, touch panel, etc.
[0013] The first store terminal device 50 is installed, for example, in a store. The first store terminal device 50 is a computer device having at least a product price acquisition function, an optical reading function, a program execution function, and a communication function. The first store terminal device 50 includes a so-called POS (Point of Sale) device, and the product price acquisition function and the optical reading function may be realized by the POS device. The store code image 60 is placed in the store, and is a code image such as a QR code (registered trademark) printed on a paper or plastic medium. The store code image 60 may be displayed on a display placed in the store (which may be the display of a terminal device such as a smartphone).
[0014] The second store terminal device 70 is used by the operator of the affiliated store. The second store terminal device 70 is a smartphone, a tablet terminal, a personal computer, or the like. An interface 72 for affiliated stores runs on the second store terminal device 70. The interface 72 for affiliated stores may be an app for affiliated stores or a browser. The interface 72 for affiliated stores accepts coupon settings and the like made by the operator of the affiliated store and transmits them to the payment server 100. The second store terminal device 70, which is a smartphone, has the function of displaying a code image corresponding to a store code image and reading a code image displayed by the user terminal device 10 by executing the app for affiliated stores.
[0015] The payment server 100 realizes electronic payment based on payment information received from the user terminal device 10 or the first store terminal device 50. The first store terminal device 50 may include a POS device and an affiliated store server, in which case the payment information is sent from the POS device via the affiliated store server to the payment server 100. In the following explanation, no distinction is made between these two and it is assumed that the payment information is sent from the first store terminal device 50.
[0016] 2 and 3 are sequence diagrams illustrating the general flow of electronic payment. There may be two patterns of electronic payment: pattern 1 and pattern 2.
[0017] In the case of pattern 1 (hereinafter referred to as user scan) shown in FIG. 2, the user terminal device 10 with the payment application 20 activated decodes the store code image 60 by the optical reading function (S1). The store code image 60 includes store URL (Uniform Resource Locator) information. This store URL is an electronic payment service domain to which store-identifying information is added, and is associated with an affiliated store ID, a store ID, etc. in the payment server 100 (described later). The payment application 20 transmits the first payment information including the store URL and the account ID to the payment server 100 (S2). The payment server 100 searches for store information (described later) from the affiliated store ID and the store ID corresponding to the store URL, acquires the affiliated store name and the store name information (S3), and transmits it to the payment application 20 (S4). The user inputs the payment amount into the user terminal device 10 on the screen on which the affiliated store name and the store name are displayed (S5). Then, the user terminal device 10 generates second payment information including at least the payment amount, and transmits it to the payment server 100 (S6). The payment server 100 performs electronic payment based on the received second payment information (S7). The payment server 100 then transmits a payment completion notice (information for displaying a payment completion screen) to the payment application 20 (S8), and the payment application 20 displays the payment completion screen (S9). Note that when the store code image 60 is displayed on a display installed in the store, the store code image 60 may include not only the store URL but also information on the payment amount. In this case, the step of the user inputting the payment amount is omitted, and the information on the payment amount is included in the first payment information and transmitted to the payment server 100. Information on the affiliated store name and the store name may be included in the payment completion screen and displayed.
[0018] In the case of pattern 2 (hereinafter referred to as store scan) shown in FIG. 3, when the payment application 20 is started, when a payment operation is performed in the payment application 20, when an automatic update timing (e.g., every minute) occurs, and at other timings, the payment application 20 transmits a request for issuing a one-time code to the payment server 100 (S11). The payment server 100 generates a one-time code (S12) and transmits it to the payment application 20 (S13). The payment application 20 displays a code image such as a QR code or a barcode generated based on the one-time code (S14). The user holds (presents) the display surface of the user terminal device 10 over the first store terminal device 50, and the first store terminal device 50 decodes the code image by an optical reading function and obtains the one-time code, etc. (S15). The first store terminal device 50 then generates payment information including the one-time code, payment amount, affiliated store ID, store ID, etc., and transmits it to the payment server 100 (S16). The payment amount information is acquired in advance by reading a barcode or manually entering it. The payment server 100 identifies the user corresponding to the one-time code based on the received information and performs electronic payment (S17). The payment server 100 then transmits a payment completion notice to the payment application 20 (S18), and the payment application 20 displays a payment completion screen (S19).
[0019] Note that electronic payment may be performed using only one of the above patterns. Furthermore, the "account ID" described in FIG. 2 may be other information (e.g., a phone number) that can be used as user identification information. Furthermore, issuance of a one-time code may be omitted in the store scan, and the payment application 20 may display a code image generated based on the user's account ID. In this case, the payment server 100 identifies the user corresponding to the account ID instead of identifying the user corresponding to the one-time code.
[0020] FIG. 4 is a configuration diagram of the payment server 100. The payment server 100 includes, for example, a communication unit 110, a payment content providing unit 120, a payment processing unit 130, an information management unit 140, and a storage unit 170. The components other than the communication unit 110 and the storage unit 170 are realized by, for example, a hardware processor such as a CPU executing a program (software). Some or all of these components may be realized by hardware (including circuitry) such as an LSI (Large Scale Integration), an ASIC (Application Specific Integrated Circuit), an FPGA (Field-Programmable Gate Array), or a GPU (Graphics Processing Unit), or may be realized by cooperation between software and hardware. The program may be stored in advance in a storage device such as an HDD (Hard Disk Drive) or a flash memory (a storage device having a non-transient storage medium), or may be stored in a removable storage medium such as a DVD or a CD-ROM (a non-transient storage medium), and may be installed in the storage device by mounting the storage medium in a drive device.
[0021] The storage unit 170 is a HDD, a flash memory, a RAM (Random Access Memory), etc. The storage unit 170 may be a NAS (Network Attached Storage) device that the payment server 100 can access via a network. The storage unit 170 stores information such as user information 172, payment content information 174, and affiliated store / shop information 176.
[0022] The communication unit 110 is a communication interface for connecting to the network NW. The communication unit 110 is, for example, a network interface card.
[0023] The payment content providing unit 120 has, for example, a function of a Web server, and provides information (content) for displaying various screens of the electronic payment service to the user terminal device 10. The payment content providing unit 120 appropriately reads necessary content from the payment content information 174 and provides it to the user terminal device 10. The user terminal device 10 accepts various inputs by the user while the content is being played by the payment application 20, and transmits the above-mentioned payment information and the like to the payment server 100.
[0024] The payment processing unit 130 performs payment processing based on the payment information transmitted by the user terminal device 10 or the first store terminal device 50. The payment processing unit 130 performs payment processing while referring to the user information 172.
[0025] FIG. 5 is a diagram showing an example of the contents of the user information 172. The user information 172 is an example of the registration information of a user. The user information 172 is information associated with, for example, a user URL, an account ID, a telephone number, a password, an email address, a user ID, a name, an address, a date of birth, a registration date, a charge balance, a post-payment setting, a post-payment limit, a post-payment usage amount, a post-payment available amount, a payment method setting, a bank account, a credit card number, a charge history information, a payment history information, and a P2P remittance history information. The user URL is used for remittance processing between users. When registering for the electronic payment service, it is necessary to register a telephone number and a password. The account ID is issued to the user by the payment server 100, and the user ID is an ID that can be set by the user at will (does not have to be set). Similarly, the email address, and the name, address, and date of birth are information that can be set by the user at will (does not have to be set). The registration date is the date on which the user registered for the electronic payment service (the date on which the account was created). Hereinafter, the user's instance (electronic payment account) to which this information is associated will be referred to as an account.
[0026] The charge balance is information indicating the balance of electronic money that is set by a user by transferring money to the account in advance. The means of transfer include transfer from an ATM (Automatic Teller Machine) of a designated company (bank) and transfer from a registered bank account. The deferred payment setting is information indicating whether or not the setting for enabling electronic payment by deferred payment has been completed, and is set to either "completed" or "not completed." The deferred payment limit is the limit of deferred payment that can be used each month, the deferred payment usage amount is the amount of deferred payment that has already been used in the current month, and the deferred payment available amount is the amount of deferred payment that can be used in the current month, which is calculated by subtracting the deferred payment usage amount from the deferred payment limit. Although only one deferred payment limit is shown in the figure, in reality, there is also a daily upper limit, and the lower of these may be set as the deferred payment limit. The payment method setting is setting information indicating whether the user will make electronic payment using the charge balance or by deferred payment at that time. The bank account and credit card number are information (account number, card number) of a bank account or credit card number that can be deposited into the electronic payment service, respectively. Charge history information is a history of the user's previous transfers to an electronic payment service to increase the charge balance. Payment history information is information showing the details of payments made by the user (date and time, store ID of the store where the purchase was made, payment amount, payment method, etc.) for each payment. P2P remittance history information is related to remittances between users (P2P remittances) included in electronic payment services, and is information showing the history of P2P remittances made by the user (date and time, remittance amount, remittance destination user, etc.) for each remittance process.
[0027] When payment information is acquired from the user terminal device 10 or the first store terminal device 50, the payment processing unit 130 refers to the user information 172 to acquire the "payment method setting" of the user. For a user whose "payment method setting" is set to "charge balance", the payment processing unit 130 performs electronic payment as follows. For example, the payment processing unit 130 performs electronic payment by decreasing the charge balance managed in association with the user ID and increasing the item value of the affiliated store's sales. The item value of the affiliated store's sales is not used as electronic money itself, for example, and an amount corresponding to the item value of the sales is transferred to a bank account in a cycle according to an agreement between the affiliated store and the electronic payment service.
[0028] The payment processing unit 130 performs electronic payment for users whose "setting information" is set to "deferred payment" as follows. Deferred payment is set separately from "credit payment" in cooperation with a credit card company that is a separate entity from the operator of the electronic payment service, and the operator of the electronic payment service acts as a creditor and allows electronic payment that is not dependent on the charge balance within the deferred payment limit. In order to receive the deferred payment service, a credit card provided by the operator of the electronic payment service may be required. The amount used for deferred payment is settled on the payment date of the following month, for example, by debiting from a bank account, for one month. In this case, the payment processing unit 130 performs provisional payment by adding the payment amount to the deferred payment amount and subtracting the same amount from the deferred payment available amount, and when the closing date comes, it performs processing to debit the payment for the current month on the payment date of the following month as described above. In addition, if the payment amount exceeds the deferred payment available amount at the time of provisional payment, an error notification is returned to the payment application 20.
[0029] 6 is a diagram showing an example of the contents of affiliated store / store information 176. The affiliated store / store information 176 includes, for example, a first table 176A in which an affiliated store ID and a store ID are associated with a store URL, a second table 176B in which an affiliated store name and sales amount (described above) are associated with an affiliated store ID, and a third table 176C in which a store ID is associated with a store ID. In addition to the above information, the affiliated store / store information 176 includes information such as the category of the affiliated store or store, the location of the store, and payment patterns.
[0030] The information management unit 140 manages user information 172 and affiliated store / store information 176 based on information acquired from the user terminal device 10 and the second store terminal device 70. The information management unit 140 adds new records to, edits, and deletes the user information 172 and affiliated store / store information 176.
[0031] [Information processing device] FIG. 7 is a configuration diagram of the information processing device 200. The information processing device 200 includes, for example, an information acquisition unit 210, an inference unit 220, a learning unit 230, a relearning unit 240, a display control unit 250, and a storage unit 270. The components other than the storage unit 270 are realized by, for example, a hardware processor such as a CPU executing a program (software). Some or all of these components may be realized by hardware (including circuitry) such as an LSI, ASIC, FPGA, or GPU, or may be realized by cooperation between software and hardware. The program may be stored in advance in a storage device such as an HDD or flash memory (a storage device having a non-transient storage medium), or may be stored in a removable storage medium such as a DVD or CD-ROM (a non-transient storage medium), and may be installed in the storage device by mounting the storage medium in a drive device.
[0032] The storage unit 270 is a HDD, a flash memory, a RAM, etc. The storage unit 270 may be a NAS device accessible by the information processing device 200 via a network. The storage unit 270 stores information such as learning data 272, a trained model 274, input data 276, and a score table 278.
[0033] The information processing device 200 may be an integrated device as shown in the figure, or may be a device having a distributed configuration. For example, the inference unit 220, the learning unit 230, and the relearning unit 240 may be realized by separate devices.
[0034] [Inference stage] The information acquisition unit 210 acquires data necessary for the inference unit 220 to perform inference processing from the payment server 100 or the like, and stores the data in the storage unit 270 as input data 276. The input data 276 is data having a plurality of data items including the user's usage history of the electronic payment service. The input data 276 has, for example, the following data items. The "history information" in (3) and (5) may include one or both of information each time a remittance or charge is made and statistical information obtained from the amount, frequency, etc. (1) Basic statistical information regarding user attributes and electronic payment history (2) Category information of the store where the electronic payment was made (3) P2P remittance history information (4) Information on credit cards that are linked to electronic payment services (credit cards that can be used to deposit funds into electronic payment services) (5) Charge history information (6) Terminal information of the user terminal device 10 (such as OS)
[0035] The inference unit 220 inputs the input data into the trained model 274 that has been trained in advance by machine learning, and derives output data indicating whether or not the user related to the input data is a target user suspected of having made fraudulent use of the electronic payment service. The fraudulent use is, for example, a fraudulent remittance act such as money laundering. Since it is assumed that users who make this type of fraudulent remittance act often have characteristic charge history information and P2P remittance history information, the information processing device 200 performs inference processing by including these in the input data as described above. This allows the information processing device 200 to appropriately extract a target user suspected of having made fraudulent use of the electronic payment service.
[0036] The inference unit 220 outputs, as output data, a score indicating the degree to which fraudulent use of an electronic payment service is suspected, a classification label obtained by comparing the score with a threshold and digitizing it, and a level obtained by discretizing the level. All of these may be the output of the trained model 274, or the inference unit 220 may separately perform a calculation process or the like to compare the score output by the trained model 274 with a threshold.
[0037] The inference unit 220 stores the score, classification label, and level in the storage unit 270 as a score table 278. FIG. 8 is a diagram showing an example of the contents of the score table 278. In the score table 278, for example, classification labels, scores, levels, and update dates are associated with user identification information such as account IDs. A classification label having a value of 1 indicates that the user is a target user, and a value of 0 indicates that the user is not a target user. Alternatively, a user having a classification label of 1 and a level of 5 may be defined as a target user, and the rest may be defined as a non-target user. That is, the classification label alone, or a combination of the classification label and the level, is an example of "output data indicating whether or not the user is a target user". The score is derived to a value between 0 and 1, for example. The level is set to 0 if the score is 0 or more and less than 0.5, 1 if the score is 0.5 or more and less than 0.6, 2 if the score is 0.6 or more and less than 0.7, 3 if the score is 0.7 or more and less than 0.8, 4 if the score is 0.8 or more and less than 0.9, and 5 if the score is 0.9 or more. The update date indicates the date on which the inference process was performed by the inference unit 220. For example, for a user at level 5, the electronic payment history information is verified again by a human eye, and then measures such as freezing the account are taken.
[0038] [Learning stage] The learning unit 230 generates a trained model 274. The trained model 274 is trained by machine learning using input data for a plurality of users and tag information indicating whether each of the plurality of users is a user who has engaged in fraudulent use (hereinafter, a fraudulent user) as training data.
[0039] 9 is a diagram for explaining the processing contents of the learning unit 230. The learning unit 230 adjusts the parameters of the machine learning model by backpropagation so that the scores derived as a result of inputting input data for a plurality of users including a first group of users and a second group of users into the machine learning model are values within a range indicating that the first group of users are not fraudulent users, and values within a range indicating that the second group of users are fraudulent users. The machine learning model at the time when the adjustment of the parameters and the like for all input data is completed becomes the trained model 274.
[0040] The first group of users is given tag information indicating that they are not fraudulent users, and the second group of users is given tag information indicating that they are fraudulent users. The first group of users is, for example, users who have accounts in electronic payment services and make electronic payments at a frequency above a certain level (for example, make payments more than k times in xx days), that is, a predetermined number of users randomly sampled from active users. The second group of users is users who are suspected of fraudulent money transfers or users who have been requested for inquiry by the police and are therefore highly likely to be fraudulent users.
[0041] By generating the trained model 274 in this way, it is possible to appropriately extract a user of interest who is suspected of having made fraudulent use of an electronic payment service. In conventional techniques of this type, whether or not a user is a fraudulent user is determined solely based on information used during identity verification, and it is not possible to make a determination based on dynamic information such as the history of using an electronic payment service. In this regard, according to the present embodiment, the charge history information and P2P remittance history information, which are assumed to be highly likely to be characteristic information of a fraudulent user, are used as input data to extract a user of interest using the trained model 274, and therefore the user of interest can be appropriately extracted.
[0042] [Trend analysis (part 1)] The display control unit 250 displays on a display device (not shown) trend analysis information indicating which part of the input data the generated trained model 274 (which may include a model retrained as described later) emphasizes when deriving a score. The display device may be attached to the information processing device 200, or may be connected to the information processing device 200 via various networks. The trend analysis information is acquired, for example, via an API (Application Programming Interface) provided by a machine learning platform. FIG. 10 is a diagram showing an example of a trend analysis information display screen IM1. The trend analysis information display screen IM1 shows that there is a tendency to output multiple target events, such as (1) users who make many electronic payments at stores belonging to category XX, (2) users whose P2P remittance history tends to be XX, (3) users whose charge balance is XX, (4) users who make many electronic payments in a specific time period, (5) users whose charge method tends to be XX, and (6) users whose terminal settings are XX, as target users, and the target events are listed in order of their degree of contribution. Additionally, a trend graph is displayed that visualizes the details of the contribution level for each of the events of interest.
[0043] By displaying the trend analysis information display screen IM1 on the display device in this manner, the operator of the information processing device 200 can intuitively understand whether the processing performed in the inference process matches the operator's sense.
[0044] [Relearn] For at least some of the users from whom the inference unit 220 (i.e., the trained model 274) has derived information indicating that they are the users of interest, the re-learning unit 240 adds a pair of input data relating to the users and tag information indicating that the users have engaged in fraudulent use to the training data 272 after confirming that the users have engaged in fraudulent use, for example, by offline processing, and re-learns the trained model 274. The offline processing is, for example, a process of verifying electronic payment history information, which is a condition for the aforementioned account freezing. The re-learning unit 240 performs the above process for users from whom the inference unit 220 has output information indicating that they are at level 5.
[0045] 11 is a diagram showing an example of the processing contents of the re-learning unit 240. The re-learning unit 240 extracts input data of users for which information indicating that they are the target user is output in the inference processing. These users are verified by offline processing as described above. If it is confirmed by offline processing that they have engaged in fraudulent use, the re-learning unit 240 adds tag information indicating that they are fraudulent users to the input data of those users and adds the data to be trained 272. Then, the re-learning unit 240 re-learns the trained model 274 by carrying out processing similar to that of the training unit 230.
[0046] This process can enrich the volume of the learning data 272 and improve the accuracy of the trained model 274. The second group of users described in FIG. 9 is usually overwhelmingly fewer in number than the first group of users. For this reason, if the number of users in the second group initially prepared is insufficient, there is a concern that the trained model 274 cannot be generated with high accuracy. In this regard, according to the present embodiment, for at least a portion of the users who are identified as the target users by the inference process, tag information indicating that they are unauthorized users is added to the input data and the data is added to the learning data 272, and re-training is performed, so that the accuracy of the trained model 274 can be improved.
[0047] In addition, it has been difficult to perform this type of prediction on a rule base in the past. A simple rule base using a decision tree or the like was not able to perform prediction with sufficient accuracy, but it has been found that by using the trained model 274 generated by machine learning, prediction can be performed under complex and multifaceted conditions, and prediction accuracy can be improved. In addition, the behavioral patterns of fraudulent users are not necessarily the same for a long period of time, and it may be difficult to perform stable predictions based on fixed criteria. However, since the trained model 274 can be updated by re-learning many times, it is possible to flexibly follow changes in the behavioral patterns of fraudulent users. By performing the above-mentioned processing of the re-learning unit 240, it is possible to flexibly follow changes in the behavioral patterns of fraudulent users while expanding the learning data 272 to improve prediction accuracy.
[0048] [Trend analysis (part 2)] The display control unit 250 may display the transition of the number of users for each level on the display device in response to the inference process being repeatedly executed, for example, once a week for a user newly added as a target of the inference process. FIG. 12 is a diagram showing an example of a user number transition display screen IM2. When generating this screen, the display control unit 250 refers to the "update date" item in the score table 278, and reflects the user in the part of the graph after the update date. In this way, by displaying the transition of the number of users for each level, the operator can grasp the nature of the trained model 274 from another aspect, and the reliability of the inference process can be improved. In addition, the display control unit 250 may display the ranking result of the score for each fraudulent user on the display device, or may display other statistical information on the display device.
[0049] According to the embodiment described above, it is possible to appropriately extract users of interest who are suspected of making fraudulent use of electronic payment services.
[0050] The above describes the form for carrying out the present invention using an embodiment, but the present invention is not limited to such an embodiment, and various modifications and substitutions can be made within the scope that does not deviate from the gist of the present invention. [Explanation of symbols]
[0051] 10 User terminal device 20. Payment App 100 Payment Server 200 Information processing device 210 Information Acquisition Department 220 Reasoning Department 230 Learning Department 240 Re-learning section 250 Display control unit 270 Storage section
Claims
1. an inference unit that inputs input data having a plurality of data items including a user's usage history of an electronic payment service into a trained model that has been trained in advance by machine learning, and derives output data indicating whether or not a user related to the input data is a target user who is suspected of having performed a fraudulent remittance act using the electronic payment service; The trained model is trained by machine learning using the input data for a plurality of users and tag information indicating whether each of the plurality of users is a user who has committed the fraudulent remittance act as training data. Information processing device.
2. The electronic payment service enables users to transfer money between themselves; The input data includes history information of remittances between the users.
2. The information processing device according to claim 1.
3. The electronic payment service allows a user to make an electronic payment based on a charge balance previously charged by the user, The input data includes category information of the store where the electronic payment was made.
2. The information processing device according to claim 1.
4. The input data includes credit card ownership information associated with the electronic payment service. The information processing device according to claim 1 .
5. The credit card is a credit card that can be used to add money to the charge balance of the electronic payment service. The information processing device according to claim 4 .
6. The electronic payment service allows users to make electronic payments based on a charge balance previously charged by the users, and enables remittance between users; The input data includes history information of remittances between the users and category information of the store where the electronic payment was made. The information processing device according to claim 1 .
7. The electronic payment service allows users to make electronic payments based on a charge balance previously charged by the users, and enables remittance between users; The input data includes history information of remittances between the users and information on credit cards linked to the electronic payment service. The information processing device according to claim 1 .
8. The electronic payment service allows users to make electronic payments based on a charge balance previously charged by the users, and enables remittance between users; The input data includes history information of remittances between the users, category information of the store where the electronic payment was made, and credit card ownership information linked to the electronic payment service. The information processing device according to claim 1 .
9. The credit card is a credit card that can be used to add money to the charge balance of the electronic payment service.
9. The information processing device according to claim 7 or 8.
10. The trained model outputs a score indicating the degree to which the user is suspected of fraudulent use of the electronic payment service, a display control unit that displays, on a display device, a transition in the number of users for each level into which the scores are discretized; The information processing device according to any one of claims 1 to 8.
11. The information processing device inputting input data having a plurality of data items including a user's usage history of an electronic payment service into a trained model trained in advance by machine learning, and executing an inference process to derive output data indicating whether or not the user related to the input data is a target user suspected of having engaged in fraudulent remittance activities using the electronic payment service; The trained model is trained by machine learning using the input data for a plurality of users and tag information indicating whether each of the plurality of users is a user who has performed the fraudulent remittance as training data. Information processing methods.
12. In the information processing device, inputting input data having a plurality of data items including a user's usage history of an electronic payment service into a trained model trained in advance by machine learning, and executing an inference process to derive output data indicating whether or not the user related to the input data is a target user suspected of having engaged in fraudulent remittance activities using the electronic payment service; The trained model is trained by machine learning using the input data for a plurality of users and tag information indicating whether each of the plurality of users is a user who has performed the fraudulent remittance as training data. program.