system
The system addresses the inefficiencies of conventional fraud prevention by using distributed AI for real-time fraud detection and emotionally intelligent warnings, ensuring accurate and user-friendly fraud prevention.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- SOFTBANK GROUP CORP
- Filing Date
- 2024-12-10
- Publication Date
- 2026-06-22
AI Technical Summary
Conventional fraud prevention systems burden users with the responsibility of judging fraudulent information, leading to potential misjudgments due to literacy issues and impose a high load on terminals, making them unsuitable for daily use.
A system that utilizes a 'small AI' on user terminals for initial fraud assessment and a 'large AI' on a server for detailed evaluation, minimizing terminal load and enhancing accuracy by comparing user behavior with a fraud pattern database, with personalized warnings based on emotional state analysis.
Effectively prevents fraud with high accuracy while reducing the burden on user devices and improving user experience through real-time, emotionally tailored warnings.
Smart Images

Figure 2026101164000001_ABST
Abstract
Description
Technical Field
[0001] The technology of the present disclosure relates to a system.
Background Art
[0002] Patent Document 1 discloses a method for controlling a persona chatbot, which is performed by at least one processor, including steps of receiving a user utterance, adding the user utterance to a prompt including an instruction sentence related to an explanation of a character of the chatbot, encoding the prompt, and inputting the encoded prompt into a language model to generate a chatbot utterance in response to the user utterance.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] In modern information society, special fraud via the Internet is increasing, and the risk that users are involved in these frauds is rising. In conventional countermeasure methods, users need to judge fraud information by themselves, so there is a possibility of making wrong judgments due to lack of literacy etc. Furthermore, a system for fraud prevention may impose a high load on a terminal and is not suitable for daily use. Based on such problems, it is required to provide a means for more effectively preventing fraud without burdening users.
Means for Solving the Problems
[0005] This invention detects suspected fraud early by receiving user behavior information via a first evaluation means on the terminal and performing an initial assessment of the possibility of fraud. If the behavior indicates a possibility of fraud, data exceeding a threshold is sent to the server. A second evaluation means on the server compares the received data in detail with a database of past fraud patterns and re-evaluates the fraud risk with high accuracy. If the risk of fraud is determined to be high, the system issues a warning to the user and guides them on the next course of action to encourage appropriate user behavior. This system makes it possible to prevent fraud with high accuracy while minimizing the load on the user's terminal.
[0006] "Behavioral information" refers to data about the operations and information accessed by users on their devices.
[0007] "Terminal" refers to a portable information device used by a user, such as a smartphone or tablet.
[0008] The "first evaluation method" refers to a function that monitors user behavior information on the device and makes an initial assessment of the possibility of fraud.
[0009] "Means of transmitting data" refers to the function of transmitting relevant data to the server when the first evaluation means detects the possibility of fraud.
[0010] A "server" refers to a computer system located in a remote location that receives data from numerous terminals and performs complex processing.
[0011] The "second evaluation method" refers to a function that evaluates detailed fraud risk based on data received on the server.
[0012] A "fraud pattern database" refers to a database that collects and stores patterns and characteristics of fraudulent activities recorded in the past.
[0013] "Means of notifying users" refers to a function that notifies users of a warning and encourages them to take appropriate measures when a risk of fraud is detected. [Brief explanation of the drawing]
[0014] [Figure 1] This is a conceptual diagram showing an example of the configuration of a data processing system according to the first embodiment. [Figure 2] This is a conceptual diagram showing an example of the essential functions of a data processing device and a smart device according to the first embodiment. [Figure 3] This is a conceptual diagram showing an example of the configuration of a data processing system according to the second embodiment. [Figure 4] This is a conceptual diagram showing an example of the main functions of a data processing device and smart glasses according to the second embodiment. [Figure 5] This is a conceptual diagram showing an example of the configuration of a data processing system according to the third embodiment. [Figure 6] This is a conceptual diagram showing an example of the main functions of a data processing device and a headset-type terminal according to the third embodiment. [Figure 7] This is a conceptual diagram showing an example of the configuration of a data processing system according to the fourth embodiment. [Figure 8] This is a conceptual diagram showing an example of the main functions of a data processing device and a robot according to the fourth embodiment. [Figure 9] This shows an emotion map where multiple emotions are mapped. [Figure 10] This shows an emotion map where multiple emotions are mapped. [Figure 11] This is a sequence diagram showing the processing flow of the data processing system in Example 1. [Figure 12] This is a sequence diagram showing the processing flow of the data processing system in Application Example 1. [Figure 13] This is a sequence diagram showing the processing flow of the data processing system in Example 2, which incorporates an emotion engine. [Figure 14] This is a sequence diagram showing the processing flow of the data processing system in Application Example 2, which combines an emotion engine. [Modes for carrying out the invention]
[0015] Hereinafter, an example of an embodiment of a system according to the technology of the present disclosure will be described with reference to the accompanying drawings.
[0016] First, the terms used in the following description will be explained.
[0017] In the following embodiments, a labeled processor (hereinafter simply referred to as "processor") may be a single arithmetic unit or a combination of multiple arithmetic units. Also, the processor may be a single type of arithmetic unit or a combination of multiple types of arithmetic units. Examples of arithmetic units include a CPU (Central Processing Unit), a GPU (Graphics Processing Unit), a GPGPU (General-Purpose computing on Graphics Processing Units), an APU (Accelerated Processing Unit), and the like.
[0018] In the following embodiments, a labeled RAM (Random Access Memory) is a memory in which information is temporarily stored and is used as a work memory by the processor.
[0019] In the following embodiments, a labeled storage is one or more non-volatile storage devices that store various programs and various parameters, etc. Examples of non-volatile storage devices include flash memory (SSD (Solid State Drive)), magnetic disks (e.g., hard disks), or magnetic tapes, and the like.
[0020] In the following embodiments, the signed communication interface (I / F) is an interface that includes a communication processor and an antenna, etc. The communication interface manages communication between multiple computers. Examples of communication standards applicable to the communication interface include wireless communication standards such as 5G (5th Generation Mobile Communication System), Wi-Fi (registered trademark), or Bluetooth (registered trademark).
[0021] In the following embodiments, "A and / or B" is synonymous with "at least one of A and B." That is, "A and / or B" means that it may be A alone, or B alone, or a combination of A and B. Furthermore, in this specification, the same concept as "A and / or B" applies when expressing three or more things linked by "and / or."
[0022] [First Embodiment]
[0023] Figure 1 shows an example of the configuration of the data processing system 10 according to the first embodiment.
[0024] As shown in Figure 1, the data processing system 10 includes a data processing device 12 and a smart device 14. An example of the data processing device 12 is a server.
[0025] The data processing device 12 comprises a computer 22, a database 24, and a communication interface 26. The computer 22 is an example of a "computer" related to the technology of this disclosure. The computer 22 comprises a processor 28, RAM 30, and storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication interface 26 are also connected to the bus 34. The communication interface 26 is connected to a network 54. An example of the network 54 is a WAN (Wide Area Network) and / or a LAN (Local Area Network).
[0026] The smart device 14 comprises a computer 36, a reception device 38, an output device 40, a camera 42, and a communication interface 44. The computer 36 comprises a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The reception device 38, output device 40, and camera 42 are also connected to the bus 52.
[0027] The reception device 38 is equipped with a touch panel 38A and a microphone 38B, etc., and receives user input. The touch panel 38A receives user input by detecting contact with an object (e.g., a pen or finger). The microphone 38B receives user input by detecting the user's voice. The control unit 46A transmits data indicating the user input received by the touch panel 38A and microphone 38B to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the data indicating the user input.
[0028] The output device 40 includes a display 40A and a speaker 40B, and presents data to the user 20 by outputting the data in a form perceptible to the user 20 (e.g., audio and / or text). The display 40A displays visible information such as text and images according to instructions from the processor 46. The speaker 40B outputs audio according to instructions from the processor 46. The camera 42 is a small digital camera equipped with an optical system such as a lens, aperture, and shutter, and an image sensor such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor.
[0029] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various types of information between processor 46 and processor 28 via network 54.
[0030] Figure 2 shows an example of the main functions of the data processing device 12 and the smart device 14.
[0031] As shown in Figure 2, in the data processing device 12, a specific processing is performed by the processor 28. A specific processing program 56 is stored in the storage 32. The specific processing program 56 is an example of a "program" related to the technology of this disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 according to the specific processing program 56 executed on the RAM 30.
[0032] The storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.
[0033] In the smart device 14, the processor 46 performs the reception output processing. The storage 50 stores the reception output program 60. The reception output program 60 is used in conjunction with a specific processing program 56 by the data processing system 10. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output processing is realized by the processor 46 operating as a control unit 46A according to the reception output program 60 executed on the RAM 48.
[0034] Next, the specific processing performed by the specific processing unit 290 of the data processing device 12 will be described. In the following description, the data processing device 12 will be referred to as the "server" and the smart device 14 as the "terminal".
[0035] The system of this invention consists of a "small AI" built into the terminal and a "large AI" installed on the server. This makes it possible to detect fraudulent activities with high accuracy while minimizing the load on the terminal.
[0036] First, the device monitors the user's behavior in the background. A "little AI" works to collect information in real time, such as websites the user visits, emails received, and input information, and performs an initial assessment of the likelihood of fraud. For example, if a user opens an email from a suspicious sender, the device scores the fraud risk based on the email's header information and content.
[0037] Next, if the likelihood of fraud exceeds a certain threshold, the device sends the relevant data to the server. The data sent is compressed to the minimum extent possible, and the system is designed to protect user privacy.
[0038] When the server receives data sent from a terminal, a "large AI" performs a detailed data evaluation. During this evaluation, the server compares the data against a database of past fraud patterns to reassess the risk of fraud. For example, it compares the URL accessed by the user against a list of known fraudulent URLs, and if a match is found, a strong warning is issued.
[0039] Once the evaluation is complete, the server sends the results back to the terminal. The terminal receives these results and displays a warning message to the user. The message includes a summary of the problems found and specific countermeasures (e.g., delete the email, do not click on suspicious links, etc.).
[0040] Based on this warning message, users can avoid potentially fraudulent actions and choose safe next steps. Simultaneously, users can obtain relevant countermeasures through the system's built-in support features.
[0041] In this way, the present invention provides users with effective and efficient fraud prevention measures through a smart and interconnected AI system, thereby supporting peace of mind in daily life.
[0042] The following describes the processing flow.
[0043] Step 1:
[0044] The device constantly monitors the user's activity in the background. When the user browses the web or checks their email, the device collects that information in real time. This information includes URLs accessed, email senders, and parts of the email body.
[0045] Step 2:
[0046] A "little AI" built into the device performs an initial assessment based on the collected information. Here, it scores patterns and keywords related to fraudulent activity, as well as suspicious senders. If the likelihood of fraud is determined to be above a certain level, it proceeds to the next step.
[0047] Step 3:
[0048] If the initial assessment of the device indicates that the likelihood of fraud exceeds a certain threshold, it will send data to the server. The data sent will include details of factors suggesting fraud and related behavioral history. The data will be compressed and sent in a way that protects the user's privacy.
[0049] Step 4:
[0050] The server receives data sent from the terminal. The "big AI" uses the received data to compare it with a database of past fraud patterns and performs a detailed evaluation using advanced algorithms. Here, the fraud risk assessment is recalculated and the result is determined.
[0051] Step 5:
[0052] If the server determines, based on a detailed assessment, that the risk of fraud is high, it will send a warning message to the device. This message will include specific details about the potential fraud, its characteristics, and recommended next steps (specific countermeasures).
[0053] Step 6:
[0054] The device displays warning messages received from the server to the user. If a warning is displayed, the user should review it and take the recommended action, such as deleting phishing emails or avoiding accessing suspicious links.
[0055] Step 7:
[0056] Users can take safety precautions based on the warning messages. They can also utilize the system's built-in support features to obtain further information.
[0057] (Example 1)
[0058] Next, we will describe Example 1. In the following description, the data processing device 12 will be referred to as the "server," and the smart device 14 will be referred to as the "terminal."
[0059] In today's information society, fraudulent activities are constantly evolving, with increasingly diverse methods and techniques. As a result, the risk of many users becoming victims of fraud is increasing. In particular, cyber fraud often employs sophisticated and clever methods, and conventional security measures may not be sufficient. Therefore, new technologies are needed that enable users to accurately detect the risk of fraud and use the internet safely.
[0060] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 1 is realized by the following means.
[0061] In this invention, the server includes a first determination means operating on an information terminal for receiving behavioral information, a second determination means operating on a computer for comparing the received information with a past fraud pattern storage device, and a notification means for notifying the user when the second determination means determines that there is a high risk of fraud. This enables the user to quickly and accurately assess the possibility of fraud and take concrete measures to protect themselves from fraudulent activities.
[0062] "Behavioral information" refers to various types of information related to users' digital actions, such as data entry, website browsing, and sending and receiving emails, performed through information terminals.
[0063] An "information terminal" is a device that users directly operate to input data and communicate, and specifically includes personal computers, smartphones, and tablet devices.
[0064] "The first means of judgment" refers to a software or hardware configuration that operates on an information terminal and is used to initially assess the possibility of fraud based on collected behavioral information.
[0065] "Communication methods" refer to mechanisms and technologies for transmitting information to distant locations, specifically including methods such as the internet, wireless communication, or wired communication.
[0066] A "computer" is a device used for data processing, typically connected to a network as a server, and possessing the ability to perform complex calculations and the matching and analysis of information.
[0067] A "fraud pattern storage device" refers to a database system that stores data and characteristics related to past fraudulent activities, making them accessible as needed.
[0068] The "second decision-making mechanism" refers to a function or algorithm that operates on a computer and performs a detailed evaluation by comparing received behavioral information with existing fraud patterns.
[0069] "Presentation method" refers to a method for displaying or notifying information to a user, and typically refers to an interface that functions as a screen display or audio alert.
[0070] "Support measures" refer to methods or mechanisms for providing users with the advice or additional information necessary to avoid the risk of fraud.
[0071] The system of this invention is composed of a user-operated information terminal and a server connected to a network. The system achieves advanced fraud detection by linking an information terminal with a built-in "small AI" and a server where a "large AI" is installed.
[0072] The device collects user behavior information in real time, and this data is first evaluated by a "small AI." This AI uses a specific algorithm to analyze the input data (e.g., website access history, email header information) and scores the likelihood of fraud. Hardware used here includes smartphones, tablets, and personal computers. If the initial evaluation determines that the likelihood of fraud exceeds a certain threshold, the data is encrypted and sent to the server while protecting privacy.
[0073] The server re-evaluates the received data in detail using a "large-scale AI." During this process, it references past data stored in a fraud pattern storage device and compares it with the user's behavior information. This enables more accurate fraud detection. If fraud is suspected, the relevant information is returned to the terminal, and a warning is issued to the user. This function utilizes a dedicated server or cloud service, demonstrating powerful data processing capabilities.
[0074] Users receive a warning message through their device. This message outlines the potentially fraudulent activity and provides specific recommended actions. Based on this, users can take safety measures and receive additional information and suggestions through the system's built-in support functions. This mechanism minimizes on-device operation and achieves advanced fraud prevention without compromising the user experience.
[0075] As a concrete example, the prompt "Generate examples of phishing emails and their risk assessments. Show how to send a warning message to users based on this information." is input into the AI model. This prompt allows the AI to learn the characteristics of phishing and generate appropriate warning messages and user response strategies.
[0076] The flow of the specific processing in Example 1 will be explained using Figure 11.
[0077] Step 1:
[0078] The device collects user behavior information in the background. Specifically, it obtains information in real time, such as the websites the user visits, emails received, and information entered into forms. The entered data is passed to a small AI via APIs or the device's built-in security software.
[0079] Step 2:
[0080] The small AI on the device performs an initial assessment based on the received behavioral information. Specifically, it uses a machine learning algorithm to calculate fraud risk and compares it with past data patterns. The input is user behavioral information, and the output is a risk score. If the threshold set as the judgment criterion is exceeded, it is determined that further detailed analysis is necessary.
[0081] Step 3:
[0082] If the risk score exceeds a threshold, the device sends the relevant data to the server. This data is encrypted and minimally compressed for privacy protection. The input is the data assessed as high risk, and the output is the encrypted transmitted data.
[0083] Step 4:
[0084] When the server receives data sent from a terminal, it evaluates it in detail using a large AI. The server then reassessss the likelihood of fraud by referencing past cases from a fraud pattern storage device. The input is encrypted data from the terminal, and the output is a detailed risk assessment. This process involves extensive data comparison and analysis to determine the likelihood of fraud with high accuracy.
[0085] Step 5:
[0086] The server sends information back to the terminal based on the evaluation results. The returned information includes instructions on whether or not to issue a warning to the user. Specifically, if a risk is identified, a strong warning message is sent to the terminal. The input is a detailed risk assessment, and the output is a warning message or notification.
[0087] Step 6:
[0088] The terminal displays a warning message to the user based on the results received from the server. This message includes details about potentially fraudulent behavior and advice on the user's next steps. The input is the warning message from the server, and the output is the screen display to the user.
[0089] Step 7:
[0090] Users review warning messages and choose actions to avoid potentially fraudulent behavior. Simultaneously, they can use the system's built-in support features to learn more information and specific defense strategies. The input is the warning message and support information, while the output is the user's safe actions and choices.
[0091] (Application Example 1)
[0092] Next, we will explain Application Example 1. In the following explanation, the data processing device 12 will be referred to as the "server," and the smart device 14 will be referred to as the "terminal."
[0093] Preventing fraud in online transactions and communications is crucial. However, conventional systems have limited ability to detect and warn of fraud in real time, leaving users at risk of becoming victims of fraudulent activities. Therefore, there is a need for technology that can accurately and effectively determine the possibility of fraud and prompt a swift response.
[0094] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 1 is realized by the following means.
[0095] In this invention, the server includes: a first evaluation means operating on an information processing device for receiving behavioral information; means for transmitting information when the probability of fraud exceeds a threshold determined by the first evaluation means; a second evaluation means operating on an information processing device for comparing the received information with a past fraud pattern storage device; means for notifying the user when the second evaluation means determines that the risk of fraud is high; and means for supporting safe transactions by confirming the reliability of transaction information performed by the user and issuing a warning. This enables real-time fraud detection and warning, as well as prompt instructions for action.
[0096] "Behavioral information" is a general term for various types of data related to the activities and operations that users perform on the internet.
[0097] An "information processing device" is hardware that has the ability to process data and perform specific functions.
[0098] The "first evaluation method" refers to a device or program that operates on a terminal and has the function of initially evaluating the possibility of fraud based on the user's behavioral information.
[0099] A "threshold" is a numerical value or level used as a standard when making a judgment based on a certain evaluation.
[0100] "Means of transmitting information" refers to a general term for methods and technologies used to send data to another device or server.
[0101] A "fraud pattern memory device" refers to a storage medium or system for saving data and characteristics related to past fraudulent activities.
[0102] The "second evaluation method" refers to a device or program that operates on a server, verifies the received information, and has the function of evaluating the risk of fraud in detail.
[0103] "User" refers to an individual or group that uses a system or device.
[0104] "Means of notification" refers to methods or devices for transmitting important information or warnings to users.
[0105] "Transaction information" refers to detailed information about purchases and sales conducted online.
[0106] "Reliability" is a concept that describes the degree to which certain information or actions are considered safe.
[0107] A "means of issuing a warning" refers to a system that provides messages or notifications to make users aware of danger and to draw their attention to it.
[0108] Embodiments of the present invention relate to a system for detecting fraudulent activity and warning users. Embodiments of the invention are described below.
[0109] This system is implemented using a terminal and server architecture. Each terminal is equipped with a small AI that monitors and performs initial assessments of user behavior in real time. For example, when a user makes a purchase on an e-commerce site, the terminal immediately assesses the security of the entered information.
[0110] The server utilizes powerful AI to analyze data sent from terminals in detail, referencing a memory database of past fraud patterns to determine the risk of fraud. The Python programming language is used for information processing, and the requests module is used for data transmission. The json module is used for standardizing input and output data. This process allows for highly accurate verification of the reliability of user transaction information.
[0111] Warnings to users are delivered via real-time notifications from their devices. These notifications are generated based on the risk of fraud and are provided along with recommended actions, allowing users to take quick and appropriate action.
[0112] For example, if a user enters credit card information on a website that appears to be fraudulent, the system will analyze the action, immediately issue a warning, and instruct the user to proceed with a secure transaction. Another example of a prompt to be input into the generating AI model is, "Assess the fraud risk of this transaction data and generate a warning message if a risk is detected."
[0113] The system of this invention thus protects users from fraud risks and supports secure online transactions.
[0114] The flow of a specific process in Application Example 1 will be explained using Figure 12.
[0115] Step 1:
[0116] The device monitors user behavior in real time. Inputs include user website visits and transaction information, and output is a fraud likelihood score. A small AI processes this data and makes an initial assessment of the level of risk.
[0117] Step 2:
[0118] If the initial assessment of a device indicates a higher likelihood of fraud than the threshold, that information is sent to the server. The input consists of the initial assessment results and behavioral information, while the output is compressed data. Data compression technology is used to transfer only the minimum necessary information to the server.
[0119] Step 3:
[0120] The server receives data sent from the terminal and evaluates it in detail using a large AI. The input is compressed data, and the output is the re-evaluation result. The risk of fraud is reassessed by comparing it with a memory of past fraud patterns.
[0121] Step 4:
[0122] If the re-evaluation determines that the server is at high risk of fraud, it will return that information to the terminal. The input is the re-evaluation result, and the output is a warning message. The information is then reorganized and quickly sent to the terminal.
[0123] Step 5:
[0124] The terminal receives information from the server and displays a warning message to the user. The input is warning information from the server, and the output is the warning displayed to the user. A generative AI model is used to generate an appropriate warning message in natural language and display it on the user interface.
[0125] Step 6:
[0126] The user will use the warning message to avoid potentially fraudulent actions as appropriate. The input is the warning message, and the output is the user's safe next action. An example of a prompt is, "What should I do next, following this warning?"
[0127] Furthermore, an emotion engine that estimates the user's emotions may be incorporated. That is, the identification processing unit 290 may use the emotion identification model 59 to estimate the user's emotions and perform identification processing using the user's emotions.
[0128] This invention enhances the user experience by incorporating an emotion engine into a system that monitors users' daily digital behavior and prevents fraud. The system consists of three main components: a "small AI" installed on the device, a "big AI" installed on the server, and an emotion engine that identifies the user's emotions.
[0129] The device has the functionality to collect and monitor user behavior information. When a user browses a website or opens an email, that information is collected and analyzed in real time. A built-in "little AI" makes an initial assessment of the likelihood of fraud based on data patterns. If fraud is determined to be possible, the data is sent to the server.
[0130] The server uses a "large AI" to evaluate the received data in detail. The server compares the data with a database of past frauds and behavioral information to reassess the risk of fraud with high accuracy. Once this evaluation is complete, the results are sent to the terminal.
[0131] In addition, the emotion engine analyzes the user's emotional state through sensors and application data. For example, by analyzing the user's voice tone, facial expressions, and operation speed, it determines whether the user is stressed by the warning or responding calmly. Based on this information, the emotion engine provides the user with an optimized warning message.
[0132] The device combines fraud warning information from the server with the results of the emotion engine's analysis to display a warning message to the user. The content and display method of the message are adjusted based on the emotion engine's assessment of the user's emotions. For example, if the user is calm, a general warning message is displayed, while if they are stressed, the message is changed to a polite and gentle tone.
[0133] In this way, the present invention enhances the accuracy of fraud prevention while simultaneously improving the user experience and supporting users in taking appropriate actions.
[0134] The following describes the processing flow.
[0135] Step 1:
[0136] The device monitors the user's behavior in the background. Specifically, it collects data about the user's actions, such as the URLs of websites the user visits and the sender information of emails that are opened. A "little AI" built into the device evaluates the collected data in real time and scores the likelihood of fraud.
[0137] Step 2:
[0138] The device sends data that it determines to be potentially fraudulent during the initial evaluation to a server. This data is encrypted to protect privacy and includes specific factors and related history of fraudulent behavior. At the same time, the device also acquires the user's sentiment information and prepares it for analysis by the sentiment engine.
[0139] Step 3:
[0140] The server analyzes the data received from the terminal. A "large AI" compares it against a fraud pattern database and evaluates the fraud risk of the behavioral data in detail. The server also calculates the fraud risk evaluation result and determines whether it is necessary to inform the user.
[0141] Step 4:
[0142] When the device receives a fraud warning from the server, it simultaneously uses an emotion engine to analyze the user's emotional state. For example, the device uses information from the user's tapping speed, voice input, and facial recognition camera (if necessary) to determine whether the user is tense or relaxed.
[0143] Step 5:
[0144] When generating warning messages to alert users to potential scams, the device considers the user's emotional state, as determined by its emotion engine. If the user is stressed, it displays a gentler, more detailed, and easier-to-understand message. Conversely, if the user is calm, it displays a concise and to-the-point message.
[0145] Step 6:
[0146] Users can review warning messages displayed on their devices and take appropriate action depending on the situation. For example, they might delete suspicious emails or avoid accessing dangerous websites. Users can also access additional support information as needed.
[0147] This processing flow allows users to efficiently avoid the risk of fraud while receiving information optimized according to their individual emotional state.
[0148] (Example 2)
[0149] Next, we will describe Example 2. In the following description, the data processing device 12 will be referred to as the "server" and the smart device 14 as the "terminal".
[0150] In today's world, as users' digital activities diversify, fraudulent methods are also becoming more sophisticated. Therefore, technology is needed that goes beyond simply comparing data with past data, monitoring behavior in real time, understanding users' emotional states, and responding appropriately. Furthermore, providing appropriate and effective warnings and guidance so that users can use the system safely and without annoyance is also a crucial challenge.
[0151] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 2 is realized by the following means.
[0152] In this invention, the server includes information processing means for receiving behavioral data and performing initial analysis, analysis means for comparing the received data with a database of past fraud information and performing a detailed evaluation, and analysis means for analyzing the user's emotional state and determining the optimal warning message. This enables real-time monitoring of fraudulent behavior, provision of optimal warning messages tailored to the user's psychological state, and improvement of the accuracy of fraud prevention measures and the user experience.
[0153] "Behavioral data" refers to information about a user's actions in the digital environment, and includes data such as website browsing history and email open records.
[0154] "Information processing means" refers to a technological element equipped with the function of receiving and analyzing user behavior data, and is used to assess the initial possibility of fraud.
[0155] "Communication methods" refer to technological elements that securely transmit behavioral data from a terminal to a server, and are used to transmit data for determining the possibility of fraud.
[0156] "Analysis means" refers to a technical element that operates on a server and performs a detailed evaluation by comparing received behavioral data with a database of past fraud information.
[0157] "Analysis means" refers to a technical element that analyzes the user's emotional state, thereby selecting and providing the user with the most appropriate warning message.
[0158] A "status monitoring means" is a technological element that has the function of monitoring user behavior data in real time, enabling the early detection of unexpected fraudulent behavior.
[0159] "Display information" refers to visual or auditory alerts or instructions provided to the user, including warnings and guidance.
[0160] This invention provides an advanced evaluation and analysis system for monitoring users' digital behavior and preventing fraudulent activity. Specifically, it incorporates technology that ensures user safety by facilitating communication between the terminal and the server. The details are described below.
[0161] The device collects user behavior data in real time. This data includes website browsing history and email open records, and is used to assess the initial likelihood of fraud. The device is equipped with a "small AI," which uses TENSORFLOW® and other technologies to perform initial assessments in a short amount of time.
[0162] If the device determines that there is a certain level of likelihood of fraud, it securely transmits the data to a server. This communication is encrypted using protocols such as SSL / TLS to protect the user's data from unauthorized access.
[0163] The server uses a "large AI" to analyze the received data in detail. This AI is trained using PyTorch and reassesss the risk of fraud with high accuracy by comparing it against a database of past frauds. Once the assessment is complete, the results are sent back to the terminal.
[0164] Furthermore, the server incorporates an emotion engine that analyzes the user's emotional state from various data such as voice tone, facial expressions, and operation speed. This emotion engine can predict how the user will react to warning messages and determine the optimal message content.
[0165] Based on these evaluation results, users receive warning messages displayed on their devices. These messages vary depending on the level of fraud. For example, if the user is calm, they will be notified with a general warning; if they are stressed, they will be presented with a more helpful and easy-to-understand message.
[0166] For example, if a user opens a suspicious email, the device immediately assesses the possibility of fraud and sends that information to the server. The server uses advanced AI to reassess the risk of fraud, analyzes the user's emotional state, and then sends an appropriate warning message to the device.
[0167] An example of a prompt to input into a generative AI model is, "Describe a system that assesses the likelihood of fraud based on a user's digital behavior and analyzes the user's state using an emotion engine." This prompt can be used to facilitate understanding in natural language.
[0168] The flow of the specific processing in Example 2 will be explained using Figure 13.
[0169] Step 1:
[0170] The device collects user behavior data. As input, it obtains the user's website browsing history and email open records. Based on this data, a "small AI" built into the device performs an initial evaluation to detect abnormal behavioral patterns. Specifically, it compares the input data with existing fraud patterns and calculates the likelihood of fraud. As output, it generates behavioral data that has been determined to be abnormal.
[0171] Step 2:
[0172] The device sends behavioral data deemed highly likely to be fraudulent during the initial evaluation to the server using a "communication method." This transmission uses the SSL / TLS protocol to ensure security. The input here is suspected fraudulent behavioral data, and the output is an encrypted data package.
[0173] Step 3:
[0174] The server uses "analysis tools" to perform a detailed evaluation of the received behavioral data. It receives encrypted behavioral data transmitted from the terminal as input. This data is decrypted and compared with a pre-stored fraud information database using a "large AI." This process identifies similarities to past fraud cases, enabling more accurate fraud detection. The server generates an evaluation result regarding the risk level of the fraud as output.
[0175] Step 4:
[0176] The server uses "analysis tools" to analyze the user's emotional state based on a detailed evaluation of behavioral data. Inputs include user interaction data such as voice tone, facial expression data, and operation speed. The data processing here involves analyzing sensor information integrated by the emotion engine to identify the user's psychological state. At this stage, it is determined whether the user is calm or stressed, and the emotional state evaluation result is obtained as output.
[0177] Step 5:
[0178] The device generates a warning message for the user based on the fraud risk assessment and emotional state assessment results sent from the server. The input is the assessment results received from the server, and the device selects a warning message appropriate for the user based on this. Specifically, it generates a standard warning if the user is relaxed, and a message with a gentler tone if the user is stressed. The output is the warning message that will be displayed.
[0179] (Application Example 2)
[0180] Next, we will explain application example 2. In the following explanation, the data processing device 12 will be referred to as a "server" and the smart device 14 as a "terminal".
[0181] In today's information society, fraudulent activities are becoming increasingly sophisticated, and users need to protect their sensitive information from malicious third parties. However, current fraud prevention systems lack appropriate responses that take into account the emotional state of users. As a result, they often only fuel users' anxiety and fail to provide effective prevention. Therefore, there is a need for a system that effectively reduces the risk of fraud while being mindful of users' emotions.
[0182] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means.
[0183] In this invention, the server includes an initial evaluation means operating on an information processing device for receiving behavioral information, a detailed evaluation means operating on a computing device for comparing the received data with a database of past fraud patterns, and an analysis means for analyzing the emotional state. This makes it possible to accurately assess the risk of fraud based on the user's digital behavior and provide appropriate warning messages according to the user's emotional state.
[0184] "Behavioral information" refers to data about a user's digital activities, including website browsing history and email open history.
[0185] An "information processing device" refers to a computer system that has the function of receiving data and monitoring user behavior.
[0186] "Initial evaluation means" refers to an algorithm that operates on an information processing device and evaluates the possibility of fraud in the first stage based on the received behavioral information.
[0187] "Communication means" refers to a communication module used to transmit data that the initial evaluation means has determined to be potentially fraudulent to an external party.
[0188] A "fraud pattern database" refers to a collection of data that records patterns of fraudulent activities that have occurred in the past.
[0189] A "computational device" refers to a server that possesses the computing power to perform advanced analysis of received behavioral data.
[0190] "Detailed evaluation means" refers to a process that operates on a computing device, compares behavioral information with a fraud pattern database, and evaluates the risk of fraud with high accuracy.
[0191] "Display means" refers to a display device that visually provides users with information about the risk of fraud.
[0192] "Analysis methods" refer to algorithms and sensor technologies used to understand the emotional state of users.
[0193] "Adjustment means" refers to the process of generating optimized notification content based on the user's emotional state.
[0194] To implement this invention, an information processing device, including a smartphone, is used. The information processing device incorporates an initial evaluation means that monitors the user's daily digital behavior information and assesses the likelihood of fraud. This device uses a communication means to transmit data that is deemed to have a high probability of being fraudulent to a server equipped with a computing device.
[0195] The server compares the received data against a database of fraudulent patterns and utilizes detailed evaluation means operating on a computing device to perform a high-level detailed evaluation. If the evaluation confirms a risk of fraud, the server transmits the results to an information processing device equipped with display means for notifying the user.
[0196] Furthermore, an emotion engine acts as an analytical tool to analyze the user's emotional state. This allows the system to grasp the user's emotional state in real time from their voice tone and facial expression data. Based on this analysis, an adjustment mechanism optimizes the content of warning messages provided to the user. For example, if the user shows signs of anxiety, guidance in a gentle tone is provided.
[0197] As a concrete example, when a user opens a suspicious webmail, the information processing unit monitors the user's behavior and delegates the risk assessment to the server. If the emotion engine detects stress from the user's vocal patterns, a remediation mechanism displays a notification such as, "This email requires caution. Please review it calmly." Furthermore, a prompt message such as, "Of the emails you've received recently, what seems suspicious?" can be used to gather additional information.
[0198] The flow of a specific process in Application Example 2 will be explained using Figure 14.
[0199] Step 1:
[0200] The device collects user behavior information and inputs the digital behavior data into the initial assessment system. Here, website visit history and email open history are collected as a dataset. Based on this data, the initial assessment system evaluates the initial fraud risk, and if fraud is suspected, it transmits the data to the server via communication means.
[0201] Step 2:
[0202] The server receives data transmitted from the terminal and inputs it into a detailed evaluation system for comparison with a fraud pattern database. The detailed evaluation system compares past fraud patterns with current user behavior and performs advanced analysis. In this process, data analysis algorithms are used to assess the risk of fraud with greater accuracy, and the results are output to an information processing device.
[0203] Step 3:
[0204] The terminal receives fraud risk information output from the server and issues a warning to the user via a display device. Here, the emotion engine inputs the user's voice tone and facial expression data into an analysis device. This allows the device to determine the user's emotional state in real time, and an adjustment device generates an optimized warning message, which is then displayed on the screen. For example, if a voice tone indicating anxiety is detected, a message such as "This email requires caution. Please calmly review it" will be displayed.
[0205] Step 4:
[0206] The user receives a warning message and is guided on recommended next actions. A prompt based on a generated AI model is then displayed, requesting further information from the user. For example, a question such as, "What in the emails you've recently received looks suspicious?" is presented to collect user feedback. This information is then fed back into the initial evaluation system, contributing to improving the overall accuracy of the system.
[0207] The specific processing unit 290 transmits the result of the specific processing to the smart device 14. In the smart device 14, the control unit 46A causes the output device 40 to output the result of the specific processing. The microphone 38B acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 38B to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the audio data.
[0208] Data generation model 58 is a so-called generative AI (Artificial Intelligence). An example of data generation model 58 is ChatGPT (registered trademark) (Internet search).<URL: https: / / openai.com / blog / chatgpt> ), Gemini (registered trademark) (Internet search) <url: https: gemini.google.com ?hl="ja">Examples of generative AI include the following. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and with inference data such as audio data representing speech, text data representing text, and image data representing images. The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference results in data formats such as audio data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.
[0209] In the above embodiment, an example was given in which specific processing is performed by the data processing device 12, but the technology of this disclosure is not limited thereto, and the specific processing may also be performed by the smart device 14.
[0210] [Second Embodiment]
[0211] Figure 3 shows an example of the configuration of the data processing system 210 according to the second embodiment.
[0212] As shown in Figure 3, the data processing system 210 includes a data processing device 12 and smart glasses 214. An example of the data processing device 12 is a server.
[0213] The data processing device 12 comprises a computer 22, a database 24, and a communication interface 26. The computer 22 is an example of a "computer" related to the technology of this disclosure. The computer 22 comprises a processor 28, RAM 30, and storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication interface 26 are also connected to the bus 34. The communication interface 26 is connected to a network 54. An example of the network 54 is a WAN (Wide Area Network) and / or a LAN (Local Area Network).
[0214] The smart glasses 214 include a computer 36, a microphone 238, a speaker 240, a camera 42, and a communication interface 44. The computer 36 includes a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The microphone 238, speaker 240, and camera 42 are also connected to the bus 52.
[0215] The microphone 238 receives voice signals from the user 20 and receives instructions from the user 20. The microphone 238 captures the voice signals from the user 20, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio according to the instructions from the processor 46.
[0216] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an image sensor such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the area around the user 20 (for example, an imaging range defined by a field of view equivalent to the width of a typical healthy person's field of vision).
[0217] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various information between processor 46 and processor 28 via network 54. The exchange of various information between processor 46 and processor 28 using communication interfaces 44 and 26 is performed in a secure manner.
[0218] Figure 4 shows an example of the main functions of the data processing device 12 and the smart glasses 214. As shown in Figure 4, the data processing device 12 performs specific processing using the processor 28. The storage 32 stores the specific processing program 56.
[0219] The specific processing program 56 is an example of a "program" relating to the technology of this disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.
[0220] The storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.
[0221] In the smart glasses 214, the processor 46 performs the reception output processing. The storage 50 stores the reception output program 60. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output processing is realized by the processor 46 operating as a control unit 46A according to the reception output program 60 executed on the RAM 48.
[0222] Next, the identification processing performed by the identification processing unit 290 of the data processing device 12 will be described. In the following description, the data processing device 12 will be referred to as the "server" and the smart glasses 214 will be referred to as the "terminal".
[0223] The system of this invention consists of a "small AI" built into the terminal and a "large AI" installed on the server. This makes it possible to detect fraudulent activities with high accuracy while minimizing the load on the terminal.
[0224] First, the device monitors the user's behavior in the background. A "little AI" works to collect information in real time, such as websites the user visits, emails received, and input information, and performs an initial assessment of the likelihood of fraud. For example, if a user opens an email from a suspicious sender, the device scores the fraud risk based on the email's header information and content.
[0225] Next, if the likelihood of fraud exceeds a certain threshold, the device sends the relevant data to the server. The data sent is compressed to the minimum extent possible, and the system is designed to protect user privacy.
[0226] When the server receives data sent from a terminal, a "large AI" performs a detailed data evaluation. During this evaluation, the server compares the data against a database of past fraud patterns to reassess the risk of fraud. For example, it compares the URL accessed by the user against a list of known fraudulent URLs, and if a match is found, a strong warning is issued.
[0227] Once the evaluation is complete, the server sends the results back to the terminal. The terminal receives these results and displays a warning message to the user. The message includes a summary of the problems found and specific countermeasures (e.g., delete the email, do not click on suspicious links, etc.).
[0228] Based on this warning message, users can avoid potentially fraudulent actions and choose safe next steps. Simultaneously, users can obtain relevant countermeasures through the system's built-in support features.
[0229] In this way, the present invention provides users with effective and efficient fraud prevention measures through a smart and interconnected AI system, thereby supporting peace of mind in daily life.
[0230] The following describes the processing flow.
[0231] Step 1:
[0232] The device constantly monitors the user's activity in the background. When the user browses the web or checks their email, the device collects that information in real time. This information includes URLs accessed, email senders, and parts of the email body.
[0233] Step 2:
[0234] A "little AI" built into the device performs an initial assessment based on the collected information. Here, it scores patterns and keywords related to fraudulent activity, as well as suspicious senders. If the likelihood of fraud is determined to be above a certain level, it proceeds to the next step.
[0235] Step 3:
[0236] If the initial assessment of the device indicates that the likelihood of fraud exceeds a certain threshold, it will send data to the server. The data sent will include details of factors suggesting fraud and related behavioral history. The data will be compressed and sent in a way that protects the user's privacy.
[0237] Step 4:
[0238] The server receives data sent from the terminal. The "big AI" uses the received data to compare it with a database of past fraud patterns and performs a detailed evaluation using advanced algorithms. Here, the fraud risk assessment is recalculated and the result is determined.
[0239] Step 5:
[0240] If the server determines, based on its detailed assessment, that the risk of fraud is high, it will send a warning message to the device. This message will include specific details about the potential fraud, its characteristics, and recommended next steps (specific countermeasures).
[0241] Step 6:
[0242] The device displays warning messages received from the server to the user. If a warning is displayed, the user should review it and take the recommended action, such as deleting phishing emails or avoiding accessing suspicious links.
[0243] Step 7:
[0244] Users can take safety precautions based on the warning messages. They can also utilize the system's built-in support features to obtain further information.
[0245] (Example 1)
[0246] Next, we will describe Example 1. In the following description, the data processing device 12 will be referred to as the "server," and the smart glasses 214 will be referred to as the "terminal."
[0247] In today's information society, fraudulent activities are constantly evolving, with increasingly diverse methods and techniques. As a result, the risk of many users becoming victims of fraud is increasing. In particular, cyber fraud often employs sophisticated and clever methods, and conventional security measures may not be sufficient. Therefore, new technologies are needed that enable users to accurately detect the risk of fraud and use the internet safely.
[0248] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 1 is realized by the following means.
[0249] In this invention, the server includes a first determination means operating on an information terminal for receiving behavioral information, a second determination means operating on a computer for comparing the received information with a past fraud pattern storage device, and a notification means for notifying the user when the second determination means determines that there is a high risk of fraud. This enables the user to quickly and accurately assess the possibility of fraud and take concrete measures to protect themselves from fraudulent activities.
[0250] "Behavioral information" refers to various types of information related to users' digital actions, such as data entry, website browsing, and sending and receiving emails, performed through information terminals.
[0251] An "information terminal" is a device that users directly operate to input data and communicate, and specifically includes personal computers, smartphones, and tablet devices.
[0252] "The first means of judgment" refers to a software or hardware configuration that operates on an information terminal and is used to initially assess the possibility of fraud based on collected behavioral information.
[0253] "Communication methods" refer to mechanisms and technologies for transmitting information to distant locations, specifically including methods such as the internet, wireless communication, or wired communication.
[0254] A "computer" is a device used for data processing, typically connected to a network as a server, and possessing the ability to perform complex calculations and the matching and analysis of information.
[0255] A "fraud pattern storage device" refers to a database system that stores data and characteristics related to past fraudulent activities, making them accessible as needed.
[0256] The "second decision-making mechanism" refers to a function or algorithm that operates on a computer and performs a detailed evaluation by comparing received behavioral information with existing fraud patterns.
[0257] "Presentation method" refers to a method for displaying or notifying information to a user, and typically refers to an interface that functions as a screen display or audio alert.
[0258] "Support measures" refer to methods or mechanisms for providing users with the advice or additional information necessary to avoid the risk of fraud.
[0259] The system of this invention is composed of a user-operated information terminal and a server connected to a network. The system achieves advanced fraud detection by linking an information terminal with a built-in "small AI" and a server where a "large AI" is installed.
[0260] The device collects user behavior information in real time, and this data is first evaluated by a "small AI." This AI uses a specific algorithm to analyze the input data (e.g., website access history, email header information) and scores the likelihood of fraud. Hardware used here includes smartphones, tablets, and personal computers. If the initial evaluation determines that the likelihood of fraud exceeds a certain threshold, the data is encrypted and sent to the server while protecting privacy.
[0261] The server re-evaluates the received data in detail using a "large-scale AI." During this process, it references past data stored in a fraud pattern storage device and compares it with the user's behavior information. This enables more accurate fraud detection. If fraud is suspected, the relevant information is returned to the terminal, and a warning is issued to the user. This function utilizes a dedicated server or cloud service, demonstrating powerful data processing capabilities.
[0262] Users receive a warning message through their device. This message outlines the potentially fraudulent activity and provides specific recommended actions. Based on this, users can take safety measures and receive additional information and suggestions through the system's built-in support functions. This mechanism minimizes on-device operation and achieves advanced fraud prevention without compromising the user experience.
[0263] As a concrete example, the prompt "Generate examples of phishing emails and their risk assessments. Show how to send a warning message to users based on this information." is input into the AI model. This prompt allows the AI to learn the characteristics of phishing and generate appropriate warning messages and user response strategies.
[0264] The flow of the specific processing in Example 1 will be explained using Figure 11.
[0265] Step 1:
[0266] The device collects user behavior information in the background. Specifically, it obtains information in real time, such as the websites the user visits, emails received, and information entered into forms. The entered data is passed to a small AI via APIs or the device's built-in security software.
[0267] Step 2:
[0268] The small AI on the device performs an initial assessment based on the received behavioral information. Specifically, it uses a machine learning algorithm to calculate fraud risk and compares it with past data patterns. The input is user behavioral information, and the output is a risk score. If the threshold set as the judgment criterion is exceeded, it is determined that further detailed analysis is necessary.
[0269] Step 3:
[0270] If the risk score exceeds a threshold, the device sends the relevant data to the server. This data is encrypted and minimally compressed for privacy protection. The input is the data assessed as high risk, and the output is the encrypted transmitted data.
[0271] Step 4:
[0272] When the server receives data sent from a terminal, it evaluates it in detail using a large AI. The server then reassessss the likelihood of fraud by referencing past cases from a fraud pattern storage device. The input is encrypted data from the terminal, and the output is a detailed risk assessment. This process involves extensive data comparison and analysis to determine the likelihood of fraud with high accuracy.
[0273] Step 5:
[0274] The server sends information back to the terminal based on the evaluation results. The returned information includes instructions on whether or not to issue a warning to the user. Specifically, if a risk is identified, a strong warning message is sent to the terminal. The input is a detailed risk assessment, and the output is a warning message or notification.
[0275] Step 6:
[0276] The terminal displays a warning message to the user based on the results received from the server. This message includes details about potentially fraudulent behavior and advice on the user's next course of action. The input is the warning message from the server, and the output is the screen display to the user.
[0277] Step 7:
[0278] Users review warning messages and choose actions to avoid potentially fraudulent behavior. Simultaneously, they can use the system's built-in support features to learn more information and specific defense strategies. The input is the warning message and support information, while the output is the user's safe actions and choices.
[0279] (Application Example 1)
[0280] Next, we will explain Application Example 1. In the following explanation, the data processing device 12 will be referred to as the "server," and the smart glasses 214 will be referred to as the "terminal."
[0281] Preventing fraud in online transactions and communications is crucial. However, conventional systems have limited ability to detect and warn of fraud in real time, leaving users at risk of becoming victims of fraudulent activities. Therefore, there is a need for technology that can accurately and effectively determine the possibility of fraud and prompt a swift response.
[0282] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 1 is realized by the following means.
[0283] In this invention, the server includes: a first evaluation means that operates on an information processing device for receiving behavior information; a means for transmitting information when the possibility of fraud exceeds a threshold by the first evaluation means; a second evaluation means that operates on an information processing device for collating the received information with a past fraud pattern storage device; a means for notifying a user when the second evaluation means determines that the risk of fraud is high; and a means for confirming the reliability of transaction information executed by the user and assisting in safe transactions by issuing a warning. Thereby, real-time fraud detection and warning, and prompt response instructions become possible.
[0284] "Behavior information" is a general term for various data related to activities and operations performed by a user on the Internet.
[0285] "Information processing device" refers to hardware that processes data and has the ability to execute specific functions.
[0286] "First evaluation means" refers to a device or program that operates on a terminal and has a function of initially evaluating the possibility of fraud based on the behavior information of a user.
[0287] "Threshold" refers to a numerical value or level used as a criterion when making a judgment based on a certain evaluation.
[0288] "Means for transmitting information" is a general term for methods and technologies for sending data to another device or server.
[0289] "Fraud pattern storage device" refers to a storage medium or mechanism for storing data and characteristics related to past fraud acts.
[0290] "Second evaluation means" refers to a device or program that operates on a server, collates the received information, and has a function of evaluating the risk of fraud in detail.
[0291] "User" refers to an individual or group that uses a system or device.
[0292] "Means of notification" refers to methods or devices for transmitting important information or warnings to users.
[0293] "Transaction information" refers to detailed information about purchases and sales conducted online.
[0294] "Reliability" is a concept that describes the degree to which certain information or actions are considered safe.
[0295] A "means of issuing a warning" refers to a system that provides messages or notifications to make users aware of danger and to draw their attention to it.
[0296] Embodiments of the present invention relate to a system for detecting fraudulent activity and warning users. Embodiments of the invention are described below.
[0297] This system is implemented using a terminal and server architecture. Each terminal is equipped with a small AI that monitors and performs initial assessments of user behavior in real time. For example, when a user makes a purchase on an e-commerce site, the terminal immediately assesses the security of the entered information.
[0298] The server utilizes powerful AI to analyze data sent from terminals in detail, referencing a memory database of past fraud patterns to determine the risk of fraud. The Python programming language is used for information processing, and the requests module is used for data transmission. The json module is used for standardizing input and output data. This process allows for highly accurate verification of the reliability of user transaction information.
[0299] Warnings to users are delivered via real-time notifications from their devices. These notifications are generated based on the risk of fraud and are provided along with recommended actions, allowing users to take quick and appropriate action.
[0300] As a specific example, when a user enters credit card information on a website that is suspected of being fraudulent, the system analyzes the action, immediately issues a warning, and instructs the user to proceed with a secure procedure. Also, as an example of a prompt sentence to be input into the generative AI model, there is one such as "Evaluate the fraud risk of this transaction data and generate a warning message if a risk is recognized."
[0301] The system of the present invention protects users from fraud risks in this way and supports secure online transactions.
[0302] The flow of the specific process in Application Example 1 will be described using FIG. 12.
[0303] Step 1:
[0304] The terminal monitors the user's behavior information in real time. The input is the user's website access information and transaction information, and the output is the fraud probability score. A small AI processes this data and initially evaluates the level of risk.
[0305] Step 2:
[0306] If the possibility of fraud exceeds the threshold in the initial evaluation by the terminal, the relevant information is sent to the server. The input is the initial evaluation result and the behavior information, and the output is the compressed data. The data compression technology is used to transfer the minimum necessary information to the server.
[0307] Step 3:
[0308] The server receives the data sent from the terminal and evaluates it in detail using a large AI. The input is the compressed data, and the output is the re-evaluation result. It is compared with the past fraud pattern storage device to re-evaluate the risk of fraud.
[0309] Step 4:
[0310] If the re-evaluation determines that the server is at high risk of fraud, it will return that information to the terminal. The input is the re-evaluation result, and the output is a warning message. The information is then reorganized and quickly sent to the terminal.
[0311] Step 5:
[0312] The terminal receives information from the server and displays a warning message to the user. The input is warning information from the server, and the output is the warning displayed to the user. A generative AI model is used to generate an appropriate warning message in natural language and display it on the user interface.
[0313] Step 6:
[0314] The user will use the warning message to avoid potentially fraudulent actions as appropriate. The input is the warning message, and the output is the user's safe next action. An example of a prompt is, "What should I do next, following this warning?"
[0315] Furthermore, an emotion engine that estimates the user's emotions may be incorporated. That is, the identification processing unit 290 may use the emotion identification model 59 to estimate the user's emotions and perform identification processing using the user's emotions.
[0316] This invention enhances the user experience by incorporating an emotion engine into a system that monitors users' daily digital behavior and prevents fraud. The system consists of three main components: a "small AI" installed on the device, a "big AI" installed on the server, and an emotion engine that identifies the user's emotions.
[0317] The device has the functionality to collect and monitor user behavior information. When a user browses a website or opens an email, that information is collected and analyzed in real time. A built-in "little AI" makes an initial assessment of the likelihood of fraud based on data patterns. If fraud is determined to be possible, the data is sent to the server.
[0318] The server uses a "large AI" to evaluate the received data in detail. The server compares the data with a database of past frauds and behavioral information to reassess the risk of fraud with high accuracy. Once this evaluation is complete, the results are sent to the terminal.
[0319] In addition, the emotion engine analyzes the user's emotional state through sensors and application data. For example, by analyzing the user's voice tone, facial expressions, and operation speed, it determines whether the user is stressed by the warning or responding calmly. Based on this information, the emotion engine provides the user with an optimized warning message.
[0320] The device combines fraud warning information from the server with the results of the emotion engine's analysis to display a warning message to the user. The content and display method of the message are adjusted based on the emotion engine's assessment of the user's emotions. For example, if the user is calm, a general warning message is displayed, while if they are stressed, the message is changed to a polite and gentle tone.
[0321] In this way, the present invention enhances the accuracy of fraud prevention while simultaneously improving the user experience and supporting users in taking appropriate actions.
[0322] The following describes the processing flow.
[0323] Step 1:
[0324] The device monitors the user's behavior in the background. Specifically, it collects data about the user's actions, such as the URLs of websites the user visits and the sender information of emails that are opened. A "little AI" built into the device evaluates the collected data in real time and scores the likelihood of fraud.
[0325] Step 2:
[0326] The device sends data that it determines to be potentially fraudulent during the initial evaluation to a server. This data is encrypted to protect privacy and includes specific factors and related history of fraudulent behavior. At the same time, the device also acquires the user's sentiment information and prepares it for analysis by the sentiment engine.
[0327] Step 3:
[0328] The server analyzes the data received from the terminal. A "large AI" compares it against a fraud pattern database and evaluates the fraud risk of the behavioral data in detail. The server also calculates the fraud risk evaluation result and determines whether it is necessary to inform the user.
[0329] Step 4:
[0330] When the device receives a fraud warning from the server, it simultaneously uses an emotion engine to analyze the user's emotional state. For example, the device uses information from the user's tapping speed, voice input, and facial recognition camera (if necessary) to determine whether the user is tense or relaxed.
[0331] Step 5:
[0332] When generating warning messages to alert users to potential scams, the device considers the user's emotional state, as determined by its emotion engine. If the user is stressed, it displays a gentler, more detailed, and easier-to-understand message. Conversely, if the user is calm, it displays a concise and to-the-point message.
[0333] Step 6:
[0334] Users can review warning messages displayed on their devices and take appropriate action depending on the situation. For example, they might delete suspicious emails or avoid accessing dangerous websites. Users can also access additional support information as needed.
[0335] This processing flow allows users to efficiently avoid the risk of fraud while receiving information optimized according to their individual emotional state.
[0336] (Example 2)
[0337] Next, we will describe Example 2. In the following description, the data processing device 12 will be referred to as the "server" and the smart glasses 214 will be referred to as the "terminal".
[0338] In today's world, as users' digital activities diversify, fraudulent methods are also becoming more sophisticated. Therefore, technology is needed that goes beyond simply comparing data with past data, monitoring behavior in real time, understanding users' emotional states, and responding appropriately. Furthermore, providing appropriate and effective warnings and guidance so that users can use the system safely and without annoyance is also a crucial challenge.
[0339] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 2 is realized by the following means.
[0340] In this invention, the server includes information processing means for receiving behavioral data and performing initial analysis, analysis means for comparing the received data with a database of past fraud information and performing a detailed evaluation, and analysis means for analyzing the user's emotional state and determining the optimal warning message. This enables real-time monitoring of fraudulent behavior, provision of optimal warning messages tailored to the user's psychological state, and improvement of the accuracy of fraud prevention measures and the user experience.
[0341] "Behavioral data" refers to information about a user's actions in the digital environment, and includes data such as website browsing history and email open records.
[0342] "Information processing means" refers to a technological element equipped with the function of receiving and analyzing user behavior data, and is used to assess the initial possibility of fraud.
[0343] "Communication methods" refer to technological elements that securely transmit behavioral data from a terminal to a server, and are used to transmit data for determining the possibility of fraud.
[0344] "Analysis means" refers to a technical element that operates on a server and performs a detailed evaluation by comparing received behavioral data with a database of past fraud information.
[0345] "Analysis means" refers to a technical element that analyzes the user's emotional state, thereby selecting and providing the user with the most appropriate warning message.
[0346] A "status monitoring means" is a technological element that has the function of monitoring user behavior data in real time, enabling the early detection of unexpected fraudulent behavior.
[0347] "Display information" refers to visual or auditory alerts or instructions provided to the user, including warnings and guidance.
[0348] This invention provides an advanced evaluation and analysis system for monitoring users' digital behavior and preventing fraudulent activity. Specifically, it incorporates technology that ensures user safety by facilitating communication between the terminal and the server. The details are described below.
[0349] The device collects user behavior data in real time. This data includes website browsing history and email open records, and is used to assess the initial likelihood of fraud. The device is equipped with a "small AI" that uses TensorFlow and other tools to perform initial assessments in a short amount of time.
[0350] If the device determines that there is a certain level of likelihood of fraud, it securely transmits the data to a server. This communication is encrypted using protocols such as SSL / TLS to protect the user's data from unauthorized access.
[0351] The server uses a "large AI" to analyze the received data in detail. This AI is trained using PyTorch and reassesss the risk of fraud with high accuracy by comparing it against a database of past frauds. Once the assessment is complete, the results are sent back to the terminal.
[0352] Furthermore, the server incorporates an emotion engine that analyzes the user's emotional state from various data such as voice tone, facial expressions, and operation speed. This emotion engine can predict how the user will react to warning messages and determine the optimal message content.
[0353] Based on these evaluation results, users receive warning messages displayed on their devices. These messages vary depending on the level of fraud. For example, if the user is calm, they will be notified with a general warning; if they are stressed, they will be presented with a more helpful and easy-to-understand message.
[0354] For example, if a user opens a suspicious email, the device immediately assesses the possibility of fraud and sends that information to the server. The server uses advanced AI to reassess the risk of fraud, analyzes the user's emotional state, and then sends an appropriate warning message to the device.
[0355] An example of a prompt to input into a generative AI model is, "Describe a system that assesses the likelihood of fraud based on a user's digital behavior and analyzes the user's state using an emotion engine." This prompt can be used to facilitate understanding in natural language.
[0356] The flow of the specific processing in Example 2 will be explained using Figure 13.
[0357] Step 1:
[0358] The device collects user behavior data. As input, it obtains the user's website browsing history and email open records. Based on this data, a "small AI" built into the device performs an initial evaluation to detect abnormal behavioral patterns. Specifically, it compares the input data with existing fraud patterns and calculates the likelihood of fraud. As output, it generates behavioral data that has been determined to be abnormal.
[0359] Step 2:
[0360] The device sends behavioral data deemed highly likely to be fraudulent during the initial evaluation to the server using a "communication method." This transmission uses the SSL / TLS protocol to ensure security. The input here is suspected fraudulent behavioral data, and the output is an encrypted data package.
[0361] Step 3:
[0362] The server uses "analysis tools" to perform a detailed evaluation of the received behavioral data. It receives encrypted behavioral data transmitted from the terminal as input. This data is decrypted and compared with a pre-stored fraud information database using a "large AI." This process identifies similarities to past fraud cases, enabling more accurate fraud detection. The server generates an evaluation result regarding the risk level of the fraud as output.
[0363] Step 4:
[0364] The server uses "analysis tools" to analyze the user's emotional state based on a detailed evaluation of behavioral data. Inputs include user interaction data such as voice tone, facial expression data, and operation speed. The data processing here involves analyzing sensor information integrated by the emotion engine to identify the user's psychological state. At this stage, it is determined whether the user is calm or stressed, and the emotional state evaluation result is obtained as output.
[0365] Step 5:
[0366] The device generates a warning message for the user based on the fraud risk assessment and emotional state assessment results sent from the server. The input is the assessment results received from the server, and the device selects a warning message appropriate for the user based on this. Specifically, it generates a standard warning if the user is relaxed, and a message with a gentler tone if the user is stressed. The output is the warning message that will be displayed.
[0367] (Application Example 2)
[0368] Next, we will explain application example 2. In the following explanation, the data processing device 12 will be referred to as the "server," and the smart glasses 214 will be referred to as the "terminal."
[0369] In today's information society, fraudulent activities are becoming increasingly sophisticated, and users need to protect their sensitive information from malicious third parties. However, current fraud prevention systems lack appropriate responses that take into account the emotional state of users. As a result, they often only fuel users' anxiety and fail to provide effective prevention. Therefore, there is a need for a system that effectively reduces the risk of fraud while being mindful of users' emotions.
[0370] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means.
[0371] In this invention, the server includes an initial evaluation means operating on an information processing device for receiving behavioral information, a detailed evaluation means operating on a computing device for comparing the received data with a database of past fraud patterns, and an analysis means for analyzing the emotional state. This makes it possible to accurately assess the risk of fraud based on the user's digital behavior and provide appropriate warning messages according to the user's emotional state.
[0372] "Behavioral information" refers to data about a user's digital activities, including website browsing history and email open history.
[0373] An "information processing device" refers to a computer system that has the function of receiving data and monitoring user behavior.
[0374] "Initial evaluation means" refers to an algorithm that operates on an information processing device and evaluates the possibility of fraud in the first stage based on the received behavioral information.
[0375] "Communication means" refers to a communication module used to transmit data that the initial evaluation means has determined to be potentially fraudulent to an external party.
[0376] A "fraud pattern database" refers to a collection of data that records patterns of fraudulent activities that have occurred in the past.
[0377] A "computational device" refers to a server that possesses the computing power to perform advanced analysis of received behavioral data.
[0378] "Detailed evaluation means" refers to a process that operates on a computing device, compares behavioral information with a fraud pattern database, and evaluates the risk of fraud with high accuracy.
[0379] "Display means" refers to a display device that visually provides users with information about the risk of fraud.
[0380] "Analysis methods" refer to algorithms and sensor technologies used to understand the emotional state of users.
[0381] "Adjustment means" refers to the process of generating optimized notification content based on the user's emotional state.
[0382] To implement this invention, an information processing device, including a smartphone, is used. The information processing device incorporates an initial evaluation means that monitors the user's daily digital behavior information and assesses the likelihood of fraud. This device uses a communication means to transmit data that is deemed to have a high probability of being fraudulent to a server equipped with a computing device.
[0383] The server compares the received data against a database of fraudulent patterns and utilizes detailed evaluation means operating on a computing device to perform a high-level detailed evaluation. If the evaluation confirms a risk of fraud, the server transmits the results to an information processing device equipped with display means for notifying the user.
[0384] Furthermore, an emotion engine acts as an analytical tool to analyze the user's emotional state. This allows the system to grasp the user's emotional state in real time from their voice tone and facial expression data. Based on this analysis, an adjustment mechanism optimizes the content of warning messages provided to the user. For example, if the user shows signs of anxiety, guidance in a gentle tone is provided.
[0385] As a concrete example, when a user opens a suspicious webmail, the information processing unit monitors the user's behavior and delegates the risk assessment to the server. If the emotion engine detects stress from the user's vocal patterns, a remediation mechanism displays a notification such as, "This email requires caution. Please review it calmly." Furthermore, a prompt message such as, "Of the emails you've received recently, what seems suspicious?" can be used to gather additional information.
[0386] The flow of a specific process in Application Example 2 will be explained using Figure 14.
[0387] Step 1:
[0388] The device collects user behavior information and inputs the digital behavior data into the initial assessment system. Here, website visit history and email open history are collected as a dataset. Based on this data, the initial assessment system evaluates the initial fraud risk, and if fraud is suspected, it transmits the data to the server via communication means.
[0389] Step 2:
[0390] The server receives data transmitted from the terminal and inputs it into a detailed evaluation system for comparison with a fraud pattern database. The detailed evaluation system compares past fraud patterns with current user behavior and performs advanced analysis. In this process, data analysis algorithms are used to assess the risk of fraud with greater accuracy, and the results are output to an information processing device.
[0391] Step 3:
[0392] The terminal receives fraud risk information output from the server and issues a warning to the user via a display device. Here, the emotion engine inputs the user's voice tone and facial expression data into an analysis device. This allows the device to determine the user's emotional state in real time, and an adjustment device generates an optimized warning message, which is then displayed on the screen. For example, if a voice tone indicating anxiety is detected, a message such as "This email requires caution. Please calmly review it" will be displayed.
[0393] Step 4:
[0394] The user receives a warning message and is guided on recommended next actions. A prompt based on a generated AI model is then displayed, requesting further information from the user. For example, a question such as, "What in the emails you've recently received looks suspicious?" is presented to collect user feedback. This information is then fed back into the initial evaluation system, contributing to improving the overall accuracy of the system.
[0395] The specific processing unit 290 transmits the result of the specific processing to the smart glasses 214. In the smart glasses 214, the control unit 46A causes the speaker 240 to output the result of the specific processing. The microphone 238 acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 238 to the data processing unit 12. In the data processing unit 12, the specific processing unit 290 acquires the audio data.
[0396] Data generation model 58 is a type of so-called generative AI (Artificial Intelligence). One example of data generation model 58 is ChatGPT (Internet search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search) <url: https: gemini.google.com ?hl="ja">Examples of generative AI include the following. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and with inference data such as audio data representing speech, text data representing text, and image data representing images. The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference results in data formats such as audio data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.
[0397] In the above embodiment, an example was given in which specific processing is performed by the data processing device 12, but the technology of this disclosure is not limited thereto, and the specific processing may also be performed by the smart glasses 214.
[0398] [Third Embodiment]
[0399] Figure 5 shows an example of the configuration of the data processing system 310 according to the third embodiment.
[0400] As shown in Figure 5, the data processing system 310 includes a data processing device 12 and a headset terminal 314. An example of the data processing device 12 is a server.
[0401] The data processing device 12 comprises a computer 22, a database 24, and a communication interface 26. The computer 22 is an example of a "computer" related to the technology of this disclosure. The computer 22 comprises a processor 28, RAM 30, and storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication interface 26 are also connected to the bus 34. The communication interface 26 is connected to a network 54. An example of the network 54 is a WAN (Wide Area Network) and / or a LAN (Local Area Network).
[0402] The headset terminal 314 includes a computer 36, a microphone 238, a speaker 240, a camera 42, a communication interface 44, and a display 343. The computer 36 includes a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The microphone 238, speaker 240, camera 42, and display 343 are also connected to the bus 52.
[0403] The microphone 238 receives voice signals from the user 20 and receives instructions from the user 20. The microphone 238 captures the voice signals from the user 20, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio according to the instructions from the processor 46.
[0404] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an image sensor such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the area around the user 20 (for example, an imaging range defined by a field of view equivalent to the width of a typical healthy person's field of vision).
[0405] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various information between processor 46 and processor 28 via network 54. The exchange of various information between processor 46 and processor 28 using communication interfaces 44 and 26 is performed in a secure manner.
[0406] Figure 6 shows an example of the main functions of the data processing device 12 and the headset terminal 314. As shown in Figure 6, the data processing device 12 performs specific processing using the processor 28. The storage 32 stores the specific processing program 56.
[0407] The specific processing program 56 is an example of a "program" relating to the technology of this disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.
[0408] The storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.
[0409] In the headset terminal 314, the processor 46 performs the reception output processing. The storage 50 stores the reception output program 60. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output processing is realized by the processor 46 operating as a control unit 46A according to the reception output program 60 executed on the RAM 48.
[0410] Next, the specific processing performed by the specific processing unit 290 of the data processing device 12 will be described. In the following description, the data processing device 12 will be referred to as the "server" and the headset terminal 314 will be referred to as the "terminal".
[0411] The system of this invention consists of a "small AI" built into the terminal and a "large AI" installed on the server. This makes it possible to detect fraudulent activities with high accuracy while minimizing the load on the terminal.
[0412] First, the device monitors the user's behavior in the background. A "little AI" works to collect information in real time, such as websites the user visits, emails received, and input information, and performs an initial assessment of the likelihood of fraud. For example, if a user opens an email from a suspicious sender, the device scores the fraud risk based on the email's header information and content.
[0413] Next, if the likelihood of fraud exceeds a certain threshold, the device sends the relevant data to the server. The data sent is compressed to the minimum extent possible, and the system is designed to protect user privacy.
[0414] When the server receives data sent from a terminal, a "large AI" performs a detailed data evaluation. During this evaluation, the server compares the data against a database of past fraud patterns to reassess the risk of fraud. For example, it compares the URL accessed by the user against a list of known fraudulent URLs, and if a match is found, a strong warning is issued.
[0415] Once the evaluation is complete, the server sends the results back to the terminal. The terminal receives these results and displays a warning message to the user. The message includes a summary of the problems found and specific countermeasures (e.g., delete the email, do not click on suspicious links, etc.).
[0416] Based on this warning message, users can avoid potentially fraudulent actions and choose safe next steps. Simultaneously, users can obtain relevant countermeasures through the system's built-in support features.
[0417] In this way, the present invention provides users with effective and efficient fraud prevention measures through a smart and interconnected AI system, thereby supporting peace of mind in daily life.
[0418] The following describes the processing flow.
[0419] Step 1:
[0420] The device constantly monitors the user's activity in the background. When the user browses the web or checks their email, the device collects that information in real time. This information includes URLs accessed, email senders, and parts of the email body.
[0421] Step 2:
[0422] A "little AI" built into the device performs an initial assessment based on the collected information. Here, it scores patterns and keywords related to fraudulent activity, as well as suspicious senders. If the likelihood of fraud is determined to be above a certain level, it proceeds to the next step.
[0423] Step 3:
[0424] If the initial assessment of the device indicates that the likelihood of fraud exceeds a certain threshold, it will send data to the server. The data sent will include details of factors suggesting fraud and related behavioral history. The data will be compressed and sent in a way that protects the user's privacy.
[0425] Step 4:
[0426] The server receives data sent from the terminal. The "big AI" uses the received data to compare it with a database of past fraud patterns and performs a detailed evaluation using advanced algorithms. Here, the fraud risk assessment is recalculated and the result is determined.
[0427] Step 5:
[0428] If the server determines, based on its detailed assessment, that the risk of fraud is high, it will send a warning message to the device. This message will include specific details about the potential fraud, its characteristics, and recommended next steps (specific countermeasures).
[0429] Step 6:
[0430] The device displays warning messages received from the server to the user. If a warning is displayed, the user should review it and take the recommended action, such as deleting phishing emails or avoiding accessing suspicious links.
[0431] Step 7:
[0432] Users can take safety precautions based on the warning messages. They can also utilize the system's built-in support features to obtain further information.
[0433] (Example 1)
[0434] Next, we will describe Example 1. In the following description, the data processing device 12 will be referred to as the "server," and the headset-type terminal 314 will be referred to as the "terminal."
[0435] In today's information society, fraudulent activities are constantly evolving, with increasingly diverse methods and techniques. As a result, the risk of many users becoming victims of fraud is increasing. In particular, cyber fraud often employs sophisticated and clever methods, and conventional security measures may not be sufficient. Therefore, new technologies are needed that enable users to accurately detect the risk of fraud and use the internet safely.
[0436] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 1 is realized by the following means.
[0437] In this invention, the server includes a first determination means operating on an information terminal for receiving behavioral information, a second determination means operating on a computer for comparing the received information with a past fraud pattern storage device, and a notification means for notifying the user when the second determination means determines that there is a high risk of fraud. This enables the user to quickly and accurately assess the possibility of fraud and take concrete measures to protect themselves from fraudulent activities.
[0438] "Behavioral information" refers to various types of information related to users' digital actions, such as data entry, website browsing, and sending and receiving emails, performed through information terminals.
[0439] An "information terminal" is a device that users directly operate to input data and communicate, and specifically includes personal computers, smartphones, and tablet devices.
[0440] "The first means of judgment" refers to a software or hardware configuration that operates on an information terminal and is used to initially assess the possibility of fraud based on collected behavioral information.
[0441] "Communication methods" refer to mechanisms and technologies for transmitting information to distant locations, specifically including methods such as the internet, wireless communication, or wired communication.
[0442] A "computer" is a device used for data processing, typically connected to a network as a server, and possessing the ability to perform complex calculations and the matching and analysis of information.
[0443] A "fraud pattern storage device" refers to a database system that stores data and characteristics related to past fraudulent activities, making them accessible as needed.
[0444] The "second decision-making mechanism" refers to a function or algorithm that operates on a computer and performs a detailed evaluation by comparing received behavioral information with existing fraud patterns.
[0445] "Presentation method" refers to a method for displaying or notifying information to a user, and typically refers to an interface that functions as a screen display or audio alert.
[0446] "Support measures" refer to methods or mechanisms for providing users with the advice or additional information necessary to avoid the risk of fraud.
[0447] The system of this invention is composed of a user-operated information terminal and a server connected to a network. The system achieves advanced fraud detection by linking an information terminal with a built-in "small AI" and a server where a "large AI" is installed.
[0448] The device collects user behavior information in real time, and this data is first evaluated by a "small AI." This AI uses a specific algorithm to analyze the input data (e.g., website access history, email header information) and scores the likelihood of fraud. Hardware used here includes smartphones, tablets, and personal computers. If the initial evaluation determines that the likelihood of fraud exceeds a certain threshold, the data is encrypted and sent to the server while protecting privacy.
[0449] The server re-evaluates the received data in detail using a "large-scale AI." During this process, it references past data stored in a fraud pattern storage device and compares it with the user's behavior information. This enables more accurate fraud detection. If fraud is suspected, the relevant information is returned to the terminal, and a warning is issued to the user. This function utilizes a dedicated server or cloud service, demonstrating powerful data processing capabilities.
[0450] Users receive a warning message through their device. This message outlines the potentially fraudulent activity and provides specific recommended actions. Based on this, users can take safety measures and receive additional information and suggestions through the system's built-in support functions. This mechanism minimizes on-device operation and achieves advanced fraud prevention without compromising the user experience.
[0451] As a concrete example, the prompt "Generate examples of phishing emails and their risk assessments. Show how to send a warning message to users based on this information." is input into the AI model. This prompt allows the AI to learn the characteristics of phishing and generate appropriate warning messages and user response strategies.
[0452] The flow of the specific processing in Example 1 will be explained using Figure 11.
[0453] Step 1:
[0454] The device collects user behavior information in the background. Specifically, it obtains information in real time, such as the websites the user visits, emails received, and information entered into forms. The entered data is passed to a small AI via APIs or the device's built-in security software.
[0455] Step 2:
[0456] The small AI on the device performs an initial assessment based on the received behavioral information. Specifically, it uses a machine learning algorithm to calculate fraud risk and compares it with past data patterns. The input is user behavioral information, and the output is a risk score. If the threshold set as the judgment criterion is exceeded, it is determined that further detailed analysis is necessary.
[0457] Step 3:
[0458] If the risk score exceeds a threshold, the device sends the relevant data to the server. This data is encrypted and minimally compressed for privacy protection. The input is the data assessed as high risk, and the output is the encrypted transmitted data.
[0459] Step 4:
[0460] When the server receives data sent from a terminal, it evaluates it in detail using a large AI. The server then reassessss the likelihood of fraud by referencing past cases from a fraud pattern storage device. The input is encrypted data from the terminal, and the output is a detailed risk assessment. This process involves extensive data comparison and analysis to determine the likelihood of fraud with high accuracy.
[0461] Step 5:
[0462] The server sends information back to the terminal based on the evaluation results. The returned information includes instructions on whether or not to issue a warning to the user. Specifically, if a risk is identified, a strong warning message is sent to the terminal. The input is a detailed risk assessment, and the output is a warning message or notification.
[0463] Step 6:
[0464] The terminal displays a warning message to the user based on the results received from the server. This message includes details about potentially fraudulent behavior and advice on the user's next course of action. The input is the warning message from the server, and the output is the screen display to the user.
[0465] Step 7:
[0466] Users review warning messages and choose actions to avoid potentially fraudulent behavior. Simultaneously, they can use the system's built-in support features to learn more information and specific defense strategies. The input is the warning message and support information, while the output is the user's safe actions and choices.
[0467] (Application Example 1)
[0468] Next, we will explain Application Example 1. In the following explanation, the data processing device 12 will be referred to as the "server," and the headset-type terminal 314 will be referred to as the "terminal."
[0469] Preventing fraud in online transactions and communications is crucial. However, conventional systems have limited ability to detect and warn of fraud in real time, leaving users at risk of becoming victims of fraudulent activities. Therefore, there is a need for technology that can accurately and effectively determine the possibility of fraud and prompt a swift response.
[0470] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 1 is realized by the following means.
[0471] In this invention, the server includes: a first evaluation means operating on an information processing device for receiving behavioral information; means for transmitting information when the probability of fraud exceeds a threshold determined by the first evaluation means; a second evaluation means operating on an information processing device for comparing the received information with a past fraud pattern storage device; means for notifying the user when the second evaluation means determines that the risk of fraud is high; and means for supporting safe transactions by confirming the reliability of transaction information performed by the user and issuing a warning. This enables real-time fraud detection and warning, as well as prompt instructions for action.
[0472] "Behavioral information" is a general term for various types of data related to the activities and operations that users perform on the internet.
[0473] An "information processing device" is hardware that has the ability to process data and perform specific functions.
[0474] The "first evaluation method" refers to a device or program that operates on a terminal and has the function of initially evaluating the possibility of fraud based on the user's behavioral information.
[0475] A "threshold" is a numerical value or level used as a standard when making a judgment based on a certain evaluation.
[0476] "Means of transmitting information" refers to a general term for methods and technologies used to send data to another device or server.
[0477] A "fraud pattern memory device" refers to a storage medium or system for saving data and characteristics related to past fraudulent activities.
[0478] The "second evaluation method" refers to a device or program that operates on a server, verifies the received information, and has the function of evaluating the risk of fraud in detail.
[0479] "User" refers to an individual or group that uses a system or device.
[0480] "Means of notification" refers to methods or devices for transmitting important information or warnings to users.
[0481] "Transaction information" refers to detailed information about purchases and sales conducted online.
[0482] "Reliability" is a concept that describes the degree to which certain information or actions are considered safe.
[0483] A "means of issuing a warning" refers to a system that provides messages or notifications to make users aware of danger and to draw their attention to it.
[0484] Embodiments of the present invention relate to a system for detecting fraudulent activity and warning users. Embodiments of the invention are described below.
[0485] This system is implemented using a terminal and server architecture. Each terminal is equipped with a small AI that monitors and performs initial assessments of user behavior in real time. For example, when a user makes a purchase on an e-commerce site, the terminal immediately assesses the security of the entered information.
[0486] The server utilizes powerful AI to analyze data sent from terminals in detail, referencing a memory database of past fraud patterns to determine the risk of fraud. The Python programming language is used for information processing, and the requests module is used for data transmission. The json module is used for standardizing input and output data. This process allows for highly accurate verification of the reliability of user transaction information.
[0487] Warnings to users are delivered via real-time notifications from their devices. These notifications are generated based on the risk of fraud and are provided along with recommended actions, allowing users to take quick and appropriate action.
[0488] For example, if a user enters credit card information on a website that appears to be fraudulent, the system will analyze the action, immediately issue a warning, and instruct the user to proceed with a secure transaction. Another example of a prompt to be input into the generating AI model is, "Assess the fraud risk of this transaction data and generate a warning message if a risk is detected."
[0489] The system of this invention thus protects users from fraud risks and supports secure online transactions.
[0490] The flow of a specific process in Application Example 1 will be explained using Figure 12.
[0491] Step 1:
[0492] The device monitors user behavior in real time. Inputs include user website visits and transaction information, and output is a fraud potential score. A small AI processes this data and makes an initial assessment of the level of risk.
[0493] Step 2:
[0494] If the initial assessment of a device indicates a higher likelihood of fraud than the threshold, that information is sent to the server. The input consists of the initial assessment results and behavioral information, while the output is compressed data. Data compression technology is used to transfer only the minimum necessary information to the server.
[0495] Step 3:
[0496] The server receives data sent from the terminal and evaluates it in detail using a large AI. The input is compressed data, and the output is the re-evaluation result. The risk of fraud is reassessed by comparing it with a memory of past fraud patterns.
[0497] Step 4:
[0498] If the re-evaluation determines that the server is at high risk of fraud, it will return that information to the terminal. The input is the re-evaluation result, and the output is a warning message. The information is then reorganized and quickly sent to the terminal.
[0499] Step 5:
[0500] The terminal receives information from the server and displays a warning message to the user. The input is warning information from the server, and the output is the warning displayed to the user. A generative AI model is used to generate an appropriate warning message in natural language and display it on the user interface.
[0501] Step 6:
[0502] The user will use the warning message to avoid potentially fraudulent actions as appropriate. The input is the warning message, and the output is the user's safe next action. An example of a prompt is, "What should I do next, following this warning?"
[0503] Furthermore, an emotion engine that estimates the user's emotions may be incorporated. That is, the identification processing unit 290 may use the emotion identification model 59 to estimate the user's emotions and perform identification processing using the user's emotions.
[0504] This invention enhances the user experience by incorporating an emotion engine into a system that monitors users' daily digital behavior and prevents fraud. The system consists of three main components: a "small AI" installed on the device, a "big AI" installed on the server, and an emotion engine that identifies the user's emotions.
[0505] The device has the functionality to collect and monitor user behavior information. When a user browses a website or opens an email, that information is collected and analyzed in real time. A built-in "little AI" makes an initial assessment of the likelihood of fraud based on data patterns. If fraud is determined to be possible, the data is sent to the server.
[0506] The server uses a "large AI" to evaluate the received data in detail. The server compares the data with a database of past frauds and behavioral information to reassess the risk of fraud with high accuracy. Once this evaluation is complete, the results are sent to the terminal.
[0507] In addition, the emotion engine analyzes the user's emotional state through sensors and application data. For example, by analyzing the user's voice tone, facial expressions, and operation speed, it determines whether the user is stressed by the warning or responding calmly. Based on this information, the emotion engine provides the user with an optimized warning message.
[0508] The device combines fraud warning information from the server with the results of the emotion engine's analysis to display a warning message to the user. The content and display method of the message are adjusted based on the emotion engine's assessment of the user's emotions. For example, if the user is calm, a general warning message is displayed, while if they are stressed, the message is changed to a polite and gentle tone.
[0509] In this way, the present invention enhances the accuracy of fraud prevention while simultaneously improving the user experience and supporting users in taking appropriate actions.
[0510] The following describes the processing flow.
[0511] Step 1:
[0512] The device monitors the user's behavior in the background. Specifically, it collects data about the user's actions, such as the URLs of websites the user visits and the sender information of emails that are opened. A "little AI" built into the device evaluates the collected data in real time and scores the likelihood of fraud.
[0513] Step 2:
[0514] The device sends data that it determines to be potentially fraudulent during the initial evaluation to a server. This data is encrypted to protect privacy and includes specific factors and related history of fraudulent behavior. At the same time, the device also acquires the user's sentiment information and prepares it for analysis by the sentiment engine.
[0515] Step 3:
[0516] The server analyzes the data received from the terminal. A "large AI" compares it against a fraud pattern database and evaluates the fraud risk of the behavioral data in detail. The server also calculates the fraud risk evaluation result and determines whether it is necessary to inform the user.
[0517] Step 4:
[0518] When the device receives a fraud warning from the server, it simultaneously uses an emotion engine to analyze the user's emotional state. For example, the device uses information from the user's tapping speed, voice input, and facial recognition camera (if necessary) to determine whether the user is tense or relaxed.
[0519] Step 5:
[0520] When generating warning messages to alert users to potential scams, the device considers the user's emotional state, as determined by its emotion engine. If the user is stressed, it displays a gentler, more detailed, and easier-to-understand message. Conversely, if the user is calm, it displays a concise and to-the-point message.
[0521] Step 6:
[0522] Users can review warning messages displayed on their devices and take appropriate action depending on the situation. For example, they might delete suspicious emails or avoid accessing dangerous websites. Users can also access additional support information as needed.
[0523] This processing flow allows users to efficiently avoid the risk of fraud while receiving information optimized according to their individual emotional state.
[0524] (Example 2)
[0525] Next, we will describe Example 2. In the following description, the data processing device 12 will be referred to as the "server," and the headset-type terminal 314 will be referred to as the "terminal."
[0526] In today's world, as users' digital activities diversify, fraudulent methods are also becoming more sophisticated. Therefore, technology is needed that goes beyond simply comparing data with past data, monitoring behavior in real time, understanding users' emotional states, and responding appropriately. Furthermore, providing appropriate and effective warnings and guidance so that users can use the system safely and without annoyance is also a crucial challenge.
[0527] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 2 is realized by the following means.
[0528] In this invention, the server includes information processing means for receiving behavioral data and performing initial analysis, analysis means for comparing the received data with a database of past fraud information and performing a detailed evaluation, and analysis means for analyzing the user's emotional state and determining the optimal warning message. This enables real-time monitoring of fraudulent behavior, provision of optimal warning messages tailored to the user's psychological state, and improvement of the accuracy of fraud prevention measures and the user experience.
[0529] "Behavioral data" refers to information about a user's actions in the digital environment, and includes data such as website browsing history and email open records.
[0530] "Information processing means" refers to a technological element equipped with the function of receiving and analyzing user behavior data, and is used to assess the initial possibility of fraud.
[0531] "Communication methods" refer to technological elements that securely transmit behavioral data from a terminal to a server, and are used to transmit data for determining the possibility of fraud.
[0532] "Analysis means" refers to a technical element that operates on a server and performs a detailed evaluation by comparing received behavioral data with a database of past fraud information.
[0533] "Analysis means" refers to a technical element that analyzes the user's emotional state, thereby selecting and providing the user with the most appropriate warning message.
[0534] A "status monitoring means" is a technological element that has the function of monitoring user behavior data in real time, enabling the early detection of unexpected fraudulent behavior.
[0535] "Display information" refers to visual or auditory alerts or instructions provided to the user, including warnings and guidance.
[0536] This invention provides an advanced evaluation and analysis system for monitoring users' digital behavior and preventing fraudulent activity. Specifically, it incorporates technology that ensures user safety by facilitating communication between the terminal and the server. The details are described below.
[0537] The device collects user behavior data in real time. This data includes website browsing history and email open records, and is used to assess the initial likelihood of fraud. The device is equipped with a "small AI" that uses TensorFlow and other tools to perform initial assessments in a short amount of time.
[0538] If the device determines that there is a certain level of likelihood of fraud, it securely transmits the data to a server. This communication is encrypted using protocols such as SSL / TLS to protect the user's data from unauthorized access.
[0539] The server uses a "large AI" to analyze the received data in detail. This AI is trained using PyTorch and reassesss the risk of fraud with high accuracy by comparing it against a database of past frauds. Once the assessment is complete, the results are sent back to the terminal.
[0540] Furthermore, the server incorporates an emotion engine that analyzes the user's emotional state from various data such as voice tone, facial expressions, and operation speed. This emotion engine can predict how the user will react to warning messages and determine the optimal message content.
[0541] Based on these evaluation results, users receive warning messages displayed on their devices. These messages vary depending on the level of fraud. For example, if the user is calm, they will be notified with a general warning; if they are stressed, they will be presented with a more helpful and easy-to-understand message.
[0542] For example, if a user opens a suspicious email, the device immediately assesses the possibility of fraud and sends that information to the server. The server uses advanced AI to reassess the risk of fraud, analyzes the user's emotional state, and then sends an appropriate warning message to the device.
[0543] An example of a prompt to input into a generative AI model is, "Describe a system that assesses the likelihood of fraud based on a user's digital behavior and analyzes the user's state using an emotion engine." This prompt can be used to facilitate understanding in natural language.
[0544] The flow of the specific processing in Example 2 will be explained using Figure 13.
[0545] Step 1:
[0546] The device collects user behavior data. As input, it obtains the user's website browsing history and email open records. Based on this data, a "small AI" built into the device performs an initial evaluation to detect abnormal behavioral patterns. Specifically, it compares the input data with existing fraud patterns and calculates the likelihood of fraud. As output, it generates behavioral data that has been determined to be abnormal.
[0547] Step 2:
[0548] The device sends behavioral data deemed highly likely to be fraudulent during the initial evaluation to the server using a "communication method." This transmission uses the SSL / TLS protocol to ensure security. The input here is suspected fraudulent behavioral data, and the output is an encrypted data package.
[0549] Step 3:
[0550] The server uses "analysis tools" to perform a detailed evaluation of the received behavioral data. It receives encrypted behavioral data transmitted from the terminal as input. This data is decrypted and compared with a pre-stored fraud information database using a "large AI." This process identifies similarities to past fraud cases, enabling more accurate fraud detection. The server generates an evaluation result regarding the risk level of the fraud as output.
[0551] Step 4:
[0552] The server uses "analysis tools" to analyze the user's emotional state based on a detailed evaluation of behavioral data. Inputs include user interaction data such as voice tone, facial expression data, and operation speed. The data processing here involves analyzing sensor information integrated by the emotion engine to identify the user's psychological state. At this stage, it is determined whether the user is calm or stressed, and the emotional state evaluation result is obtained as output.
[0553] Step 5:
[0554] The device generates a warning message for the user based on the fraud risk assessment and emotional state assessment results sent from the server. The input is the assessment results received from the server, and the device selects a warning message appropriate for the user based on this. Specifically, it generates a standard warning if the user is relaxed, and a message with a gentler tone if the user is stressed. The output is the warning message that will be displayed.
[0555] (Application Example 2)
[0556] Next, we will explain application example 2. In the following explanation, the data processing device 12 will be referred to as the "server," and the headset-type terminal 314 will be referred to as the "terminal."
[0557] In today's information society, fraudulent activities are becoming increasingly sophisticated, and users need to protect their sensitive information from malicious third parties. However, current fraud prevention systems lack appropriate responses that take into account the emotional state of users. As a result, they often only fuel users' anxiety and fail to provide effective prevention. Therefore, there is a need for a system that effectively reduces the risk of fraud while being mindful of users' emotions.
[0558] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means.
[0559] In this invention, the server includes an initial evaluation means operating on an information processing device for receiving behavioral information, a detailed evaluation means operating on a computing device for comparing the received data with a database of past fraud patterns, and an analysis means for analyzing the emotional state. This makes it possible to accurately assess the risk of fraud based on the user's digital behavior and provide appropriate warning messages according to the user's emotional state.
[0560] "Behavioral information" refers to data about a user's digital activities, including website browsing history and email open history.
[0561] An "information processing device" refers to a computer system that has the function of receiving data and monitoring user behavior.
[0562] "Initial evaluation means" refers to an algorithm that operates on an information processing device and evaluates the possibility of fraud in the first stage based on the received behavioral information.
[0563] "Communication means" refers to a communication module used to transmit data that the initial evaluation means has determined to be potentially fraudulent to an external party.
[0564] A "fraud pattern database" refers to a collection of data that records patterns of fraudulent activities that have occurred in the past.
[0565] A "computational device" refers to a server that possesses the computing power to perform advanced analysis of received behavioral data.
[0566] "Detailed evaluation means" refers to a process that operates on a computing device, compares behavioral information with a fraud pattern database, and evaluates the risk of fraud with high accuracy.
[0567] "Display means" refers to a display device that visually provides users with information about the risk of fraud.
[0568] "Analysis methods" refer to algorithms and sensor technologies used to understand the emotional state of users.
[0569] "Adjustment means" refers to the process of generating optimized notification content based on the user's emotional state.
[0570] To implement this invention, an information processing device, including a smartphone, is used. The information processing device incorporates an initial evaluation means that monitors the user's daily digital behavior information and assesses the likelihood of fraud. This device uses a communication means to transmit data that is deemed to have a high probability of being fraudulent to a server equipped with a computing device.
[0571] The server compares the received data against a database of fraudulent patterns and utilizes detailed evaluation means operating on a computing device to perform a high-level detailed evaluation. If the evaluation confirms a risk of fraud, the server transmits the results to an information processing device equipped with display means for notifying the user.
[0572] Furthermore, an emotion engine acts as an analytical tool to analyze the user's emotional state. This allows the system to grasp the user's emotional state in real time from their voice tone and facial expression data. Based on this analysis, an adjustment mechanism optimizes the content of warning messages provided to the user. For example, if the user shows signs of anxiety, guidance in a gentle tone is provided.
[0573] As a concrete example, when a user opens a suspicious webmail, the information processing unit monitors the user's behavior and delegates the risk assessment to the server. If the emotion engine detects stress from the user's vocal patterns, a remediation mechanism displays a notification such as, "This email requires caution. Please review it calmly." Furthermore, a prompt message such as, "Of the emails you've received recently, what seems suspicious?" can be used to gather additional information.
[0574] The flow of a specific process in Application Example 2 will be explained using Figure 14.
[0575] Step 1:
[0576] The device collects user behavior information and inputs the digital behavior data into the initial assessment system. Here, website visit history and email open history are collected as a dataset. Based on this data, the initial assessment system evaluates the initial fraud risk, and if fraud is suspected, it transmits the data to the server via communication means.
[0577] Step 2:
[0578] The server receives data transmitted from the terminal and inputs it into a detailed evaluation system for comparison with a fraud pattern database. The detailed evaluation system compares past fraud patterns with current user behavior and performs advanced analysis. In this process, data analysis algorithms are used to assess the risk of fraud with greater accuracy, and the results are output to an information processing device.
[0579] Step 3:
[0580] The terminal receives fraud risk information output from the server and issues a warning to the user via a display device. Here, the emotion engine inputs the user's voice tone and facial expression data into an analysis device. This allows the device to determine the user's emotional state in real time, and an adjustment device generates an optimized warning message, which is then displayed on the screen. For example, if a voice tone indicating anxiety is detected, a message such as "This email requires caution. Please calmly review it" will be displayed.
[0581] Step 4:
[0582] The user receives a warning message and is guided on recommended next actions. A prompt based on a generated AI model is then displayed, requesting further information from the user. For example, a question such as, "What in the emails you've recently received looks suspicious?" is presented to collect user feedback. This information is then fed back into the initial evaluation system, contributing to improving the overall accuracy of the system.
[0583] The specific processing unit 290 transmits the result of the specific processing to the headset terminal 314. In the headset terminal 314, the control unit 46A causes the speaker 240 and display 343 to output the result of the specific processing. The microphone 238 acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 238 to the data processing unit 12. In the data processing unit 12, the specific processing unit 290 acquires the audio data.
[0584] Data generation model 58 is a type of so-called generative AI (Artificial Intelligence). One example of data generation model 58 is ChatGPT (Internet search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search) <url: https: gemini.google.com ?hl="ja">Examples of generative AI include the following. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and with inference data such as audio data representing speech, text data representing text, and image data representing images. The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference results in data formats such as audio data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.
[0585] In the above embodiment, an example was given in which specific processing is performed by the data processing device 12, but the technology of this disclosure is not limited thereto, and specific processing may also be performed by the headset terminal 314.
[0586] [Fourth Embodiment]
[0587] Figure 7 shows an example of the configuration of the data processing system 410 according to the fourth embodiment.
[0588] As shown in Figure 7, the data processing system 410 includes a data processing device 12 and a robot 414. An example of the data processing device 12 is a server.
[0589] The data processing device 12 comprises a computer 22, a database 24, and a communication interface 26. The computer 22 is an example of a "computer" related to the technology of this disclosure. The computer 22 comprises a processor 28, RAM 30, and storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication interface 26 are also connected to the bus 34. The communication interface 26 is connected to a network 54. An example of the network 54 is a WAN (Wide Area Network) and / or a LAN (Local Area Network).
[0590] The robot 414 includes a computer 36, a microphone 238, a speaker 240, a camera 42, a communication interface 44, and a controlled object 443. The computer 36 includes a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The microphone 238, speaker 240, camera 42, and controlled object 443 are also connected to the bus 52.
[0591] The microphone 238 receives voice signals from the user 20 and receives instructions from the user 20. The microphone 238 captures the voice signals from the user 20, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio according to the instructions from the processor 46.
[0592] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an image sensor such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the area around the user 20 (for example, an imaging range defined by a field of view equivalent to the width of a typical healthy person's field of vision).
[0593] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various information between processor 46 and processor 28 via network 54. The exchange of various information between processor 46 and processor 28 using communication interfaces 44 and 26 is performed in a secure manner.
[0594] The controlled object 443 includes a display device, LEDs in the eyes, and motors that drive the arms, hands, and feet. The posture and gestures of the robot 414 are controlled by controlling the motors of the arms, hands, and feet. Some of the robot 414's emotions can be expressed by controlling these motors. Furthermore, the robot 414's facial expressions can also be expressed by controlling the illumination state of the LEDs in its eyes.
[0595] Figure 8 shows an example of the main functions of the data processing device 12 and the robot 414. As shown in Figure 8, the data processing device 12 performs specific processing using the processor 28. The storage 32 stores the specific processing program 56.
[0596] The specific processing program 56 is an example of a "program" relating to the technology of this disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.
[0597] The storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.
[0598] In robot 414, the processor 46 performs the reception output processing. The storage 50 stores the reception output program 60. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output processing is realized by the processor 46 operating as a control unit 46A according to the reception output program 60 executed on the RAM 48.
[0599] Next, the specific processing performed by the specific processing unit 290 of the data processing device 12 will be described. In the following description, the data processing device 12 will be referred to as the "server" and the robot 414 as the "terminal".
[0600] The system of this invention consists of a "small AI" built into the terminal and a "large AI" installed on the server. This makes it possible to detect fraudulent activities with high accuracy while minimizing the load on the terminal.
[0601] First, the device monitors the user's behavior in the background. A "little AI" works to collect information in real time, such as websites the user visits, emails received, and input information, and performs an initial assessment of the likelihood of fraud. For example, if a user opens an email from a suspicious sender, the device scores the fraud risk based on the email's header information and content.
[0602] Next, if the likelihood of fraud exceeds a certain threshold, the device sends the relevant data to the server. The data sent is compressed to the minimum extent possible, and the system is designed to protect user privacy.
[0603] When the server receives data sent from a terminal, a "large AI" performs a detailed data evaluation. During this evaluation, the server compares the data against a database of past fraud patterns to reassess the risk of fraud. For example, it compares the URL accessed by the user against a list of known fraudulent URLs, and if a match is found, a strong warning is issued.
[0604] Once the evaluation is complete, the server sends the results back to the terminal. The terminal receives these results and displays a warning message to the user. The message includes a summary of the problems found and specific countermeasures (e.g., delete the email, do not click on suspicious links, etc.).
[0605] Based on this warning message, users can avoid potentially fraudulent actions and choose safe next steps. Simultaneously, users can obtain relevant countermeasures through the system's built-in support features.
[0606] In this way, the present invention provides users with effective and efficient fraud prevention measures through a smart and interconnected AI system, thereby supporting peace of mind in daily life.
[0607] The following describes the processing flow.
[0608] Step 1:
[0609] The device constantly monitors the user's activity in the background. When the user browses the web or checks their email, the device collects that information in real time. This information includes URLs accessed, email senders, and parts of the email body.
[0610] Step 2:
[0611] A "little AI" built into the device performs an initial assessment based on the collected information. Here, it scores patterns and keywords related to fraudulent activity, as well as suspicious senders. If the likelihood of fraud is determined to be above a certain level, it proceeds to the next step.
[0612] Step 3:
[0613] If the initial assessment of the device indicates that the likelihood of fraud exceeds a certain threshold, it will send data to the server. The data sent will include details of factors suggesting fraud and related behavioral history. The data will be compressed and sent in a way that protects the user's privacy.
[0614] Step 4:
[0615] The server receives data sent from the terminal. The "big AI" uses the received data to compare it with a database of past fraud patterns and performs a detailed evaluation using advanced algorithms. Here, the fraud risk assessment is recalculated and the result is determined.
[0616] Step 5:
[0617] If the server determines, based on its detailed assessment, that the risk of fraud is high, it will send a warning message to the device. This message will include specific details about the potential fraud, its characteristics, and recommended next steps (specific countermeasures).
[0618] Step 6:
[0619] The device displays warning messages received from the server to the user. If a warning is displayed, the user should review it and take the recommended action, such as deleting phishing emails or avoiding accessing suspicious links.
[0620] Step 7:
[0621] Users can take safety precautions based on the warning messages. They can also utilize the system's built-in support features to obtain further information.
[0622] (Example 1)
[0623] Next, we will describe Example 1. In the following description, the data processing device 12 will be referred to as the "server" and the robot 414 as the "terminal".
[0624] In today's information society, fraudulent activities are constantly evolving, with increasingly diverse methods and techniques. As a result, the risk of many users becoming victims of fraud is increasing. In particular, cyber fraud often employs sophisticated and clever methods, and conventional security measures may not be sufficient. Therefore, new technologies are needed that enable users to accurately detect the risk of fraud and use the internet safely.
[0625] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 1 is realized by the following means.
[0626] In this invention, the server includes a first determination means operating on an information terminal for receiving behavioral information, a second determination means operating on a computer for comparing the received information with a past fraud pattern storage device, and a notification means for notifying the user when the second determination means determines that there is a high risk of fraud. This enables the user to quickly and accurately assess the possibility of fraud and take concrete measures to protect themselves from fraudulent activities.
[0627] "Behavioral information" refers to various types of information related to users' digital actions, such as data entry, website browsing, and sending and receiving emails, performed through information terminals.
[0628] An "information terminal" is a device that users directly operate to input data and communicate, and specifically includes personal computers, smartphones, and tablet devices.
[0629] "The first means of judgment" refers to a software or hardware configuration that operates on an information terminal and is used to initially assess the possibility of fraud based on collected behavioral information.
[0630] "Communication methods" refer to mechanisms and technologies for transmitting information to distant locations, specifically including methods such as the internet, wireless communication, or wired communication.
[0631] A "computer" is a device used for data processing, typically connected to a network as a server, and possessing the ability to perform complex calculations and the matching and analysis of information.
[0632] A "fraud pattern storage device" refers to a database system that stores data and characteristics related to past fraudulent activities, making them accessible as needed.
[0633] The "second decision-making mechanism" refers to a function or algorithm that operates on a computer and performs a detailed evaluation by comparing received behavioral information with existing fraud patterns.
[0634] "Presentation method" refers to a method for displaying or notifying information to a user, and typically refers to an interface that functions as a screen display or audio alert.
[0635] "Support measures" refer to methods or mechanisms for providing users with the advice or additional information necessary to avoid the risk of fraud.
[0636] The system of this invention is composed of a user-operated information terminal and a server connected to a network. The system achieves advanced fraud detection by linking an information terminal with a built-in "small AI" and a server where a "large AI" is installed.
[0637] The device collects user behavior information in real time, and this data is first evaluated by a "small AI." This AI uses a specific algorithm to analyze the input data (e.g., website access history, email header information) and scores the likelihood of fraud. Hardware used here includes smartphones, tablets, and personal computers. If the initial evaluation determines that the likelihood of fraud exceeds a certain threshold, the data is encrypted and sent to the server while protecting privacy.
[0638] The server re-evaluates the received data in detail using a "large-scale AI." During this process, it references past data stored in a fraud pattern storage device and compares it with the user's behavior information. This enables more accurate fraud detection. If fraud is suspected, the relevant information is returned to the terminal, and a warning is issued to the user. This function utilizes a dedicated server or cloud service, demonstrating powerful data processing capabilities.
[0639] Users receive a warning message through their device. This message outlines the potentially fraudulent activity and provides specific recommended actions. Based on this, users can take safety measures and receive additional information and suggestions through the system's built-in support functions. This mechanism minimizes on-device operation and achieves advanced fraud prevention without compromising the user experience.
[0640] As a concrete example, the prompt "Generate examples of phishing emails and their risk assessments. Show how to send a warning message to users based on this information." is input into the AI model. This prompt allows the AI to learn the characteristics of phishing and generate appropriate warning messages and user response strategies.
[0641] The flow of the specific processing in Example 1 will be explained using Figure 11.
[0642] Step 1:
[0643] The device collects user behavior information in the background. Specifically, it obtains information in real time, such as the websites the user visits, emails received, and information entered into forms. The entered data is passed to a small AI via APIs or the device's built-in security software.
[0644] Step 2:
[0645] The small AI on the device performs an initial assessment based on the received behavioral information. Specifically, it uses a machine learning algorithm to calculate fraud risk and compares it with past data patterns. The input is user behavioral information, and the output is a risk score. If the threshold set as the judgment criterion is exceeded, it is determined that further detailed analysis is necessary.
[0646] Step 3:
[0647] If the risk score exceeds a threshold, the device sends the relevant data to the server. This data is encrypted and minimally compressed for privacy protection. The input is the data assessed as high risk, and the output is the encrypted transmitted data.
[0648] Step 4:
[0649] When the server receives data sent from a terminal, it evaluates it in detail using a large AI. The server then reassessss the likelihood of fraud by referencing past cases from a fraud pattern storage device. The input is encrypted data from the terminal, and the output is a detailed risk assessment. This process involves extensive data comparison and analysis to determine the likelihood of fraud with high accuracy.
[0650] Step 5:
[0651] The server sends information back to the terminal based on the evaluation results. The returned information includes instructions on whether or not to issue a warning to the user. Specifically, if a risk is identified, a strong warning message is sent to the terminal. The input is a detailed risk assessment, and the output is a warning message or notification.
[0652] Step 6:
[0653] The terminal displays a warning message to the user based on the results received from the server. This message includes details about potentially fraudulent behavior and advice on the user's next course of action. The input is the warning message from the server, and the output is the screen display to the user.
[0654] Step 7:
[0655] Users review warning messages and choose actions to avoid potentially fraudulent behavior. Simultaneously, they can use the system's built-in support features to learn more information and specific defense strategies. The input is the warning message and support information, while the output is the user's safe actions and choices.
[0656] (Application Example 1)
[0657] Next, we will explain Application Example 1. In the following explanation, the data processing device 12 will be referred to as the "server" and the robot 414 as the "terminal".
[0658] Preventing fraud in online transactions and communications is crucial. However, conventional systems have limited ability to detect and warn of fraud in real time, leaving users at risk of becoming victims of fraudulent activities. Therefore, there is a need for technology that can accurately and effectively determine the possibility of fraud and prompt a swift response.
[0659] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 1 is realized by the following means.
[0660] In this invention, the server includes: a first evaluation means operating on an information processing device for receiving behavioral information; means for transmitting information when the probability of fraud exceeds a threshold determined by the first evaluation means; a second evaluation means operating on an information processing device for comparing the received information with a past fraud pattern storage device; means for notifying the user when the second evaluation means determines that the risk of fraud is high; and means for supporting safe transactions by confirming the reliability of transaction information performed by the user and issuing a warning. This enables real-time fraud detection and warning, as well as prompt instructions for action.
[0661] "Behavioral information" is a general term for various types of data related to the activities and operations that users perform on the internet.
[0662] An "information processing device" is hardware that has the ability to process data and perform specific functions.
[0663] The "first evaluation method" refers to a device or program that operates on a terminal and has the function of initially evaluating the possibility of fraud based on the user's behavioral information.
[0664] A "threshold" is a numerical value or level used as a standard when making a judgment based on a certain evaluation.
[0665] "Means of transmitting information" refers to a general term for methods and technologies used to send data to another device or server.
[0666] A "fraud pattern memory device" refers to a storage medium or system for saving data and characteristics related to past fraudulent activities.
[0667] The "second evaluation method" refers to a device or program that operates on a server, verifies the received information, and has the function of evaluating the risk of fraud in detail.
[0668] "User" refers to an individual or group that uses a system or device.
[0669] "Means of notification" refers to methods or devices for transmitting important information or warnings to users.
[0670] "Transaction information" refers to detailed information about purchases and sales conducted online.
[0671] "Reliability" is a concept that describes the degree to which certain information or actions are considered safe.
[0672] A "means of issuing a warning" refers to a system that provides messages or notifications to make users aware of danger and to draw their attention to it.
[0673] Embodiments of the present invention relate to a system for detecting fraudulent activity and warning users. Embodiments of the invention are described below.
[0674] This system is implemented using a terminal and server architecture. Each terminal is equipped with a small AI that monitors and performs initial assessments of user behavior in real time. For example, when a user makes a purchase on an e-commerce site, the terminal immediately assesses the security of the entered information.
[0675] The server utilizes powerful AI to analyze data sent from terminals in detail, referencing a memory database of past fraud patterns to determine the risk of fraud. The Python programming language is used for information processing, and the requests module is used for data transmission. The json module is used for standardizing input and output data. This process allows for highly accurate verification of the reliability of user transaction information.
[0676] Warnings to users are delivered via real-time notifications from their devices. These notifications are generated based on the risk of fraud and are provided along with recommended actions, allowing users to take quick and appropriate action.
[0677] For example, if a user enters credit card information on a website that appears to be fraudulent, the system will analyze the action, immediately issue a warning, and instruct the user to proceed with a secure transaction. Another example of a prompt to be input into the generating AI model is, "Assess the fraud risk of this transaction data and generate a warning message if a risk is detected."
[0678] The system of this invention thus protects users from fraud risks and supports secure online transactions.
[0679] The flow of a specific process in Application Example 1 will be explained using Figure 12.
[0680] Step 1:
[0681] The device monitors user behavior in real time. Inputs include user website visits and transaction information, and output is a fraud potential score. A small AI processes this data and makes an initial assessment of the level of risk.
[0682] Step 2:
[0683] If the initial assessment of a device indicates a higher likelihood of fraud than the threshold, that information is sent to the server. The input consists of the initial assessment results and behavioral information, while the output is compressed data. Data compression technology is used to transfer only the minimum necessary information to the server.
[0684] Step 3:
[0685] The server receives data sent from the terminal and evaluates it in detail using a large AI. The input is compressed data, and the output is the re-evaluation result. The risk of fraud is reassessed by comparing it with a memory of past fraud patterns.
[0686] Step 4:
[0687] If the re-evaluation determines that the server is at high risk of fraud, it will return that information to the terminal. The input is the re-evaluation result, and the output is a warning message. The information is then reorganized and quickly sent to the terminal.
[0688] Step 5:
[0689] The terminal receives information from the server and displays a warning message to the user. The input is warning information from the server, and the output is the warning displayed to the user. A generative AI model is used to generate an appropriate warning message in natural language and display it on the user interface.
[0690] Step 6:
[0691] The user will use the warning message to avoid potentially fraudulent actions as appropriate. The input is the warning message, and the output is the user's safe next action. An example of a prompt is, "What should I do next, following this warning?"
[0692] Furthermore, an emotion engine that estimates the user's emotions may be incorporated. That is, the identification processing unit 290 may use the emotion identification model 59 to estimate the user's emotions and perform identification processing using the user's emotions.
[0693] This invention enhances the user experience by incorporating an emotion engine into a system that monitors users' daily digital behavior and prevents fraud. The system consists of three main components: a "small AI" installed on the device, a "big AI" installed on the server, and an emotion engine that identifies the user's emotions.
[0694] The device has the functionality to collect and monitor user behavior information. When a user browses a website or opens an email, that information is collected and analyzed in real time. A built-in "little AI" makes an initial assessment of the likelihood of fraud based on data patterns. If fraud is determined to be possible, the data is sent to the server.
[0695] The server uses a "large AI" to evaluate the received data in detail. The server compares the data with a database of past frauds and behavioral information to reassess the risk of fraud with high accuracy. Once this evaluation is complete, the results are sent to the terminal.
[0696] In addition, the emotion engine analyzes the user's emotional state through sensors and application data. For example, by analyzing the user's voice tone, facial expressions, and operation speed, it determines whether the user is stressed by the warning or responding calmly. Based on this information, the emotion engine provides the user with an optimized warning message.
[0697] The device combines fraud warning information from the server with the results of the emotion engine's analysis to display a warning message to the user. The content and display method of the message are adjusted based on the emotion engine's assessment of the user's emotions. For example, if the user is calm, a general warning message is displayed, while if they are stressed, the message is changed to a polite and gentle tone.
[0698] In this way, the present invention enhances the accuracy of fraud prevention while simultaneously improving the user experience and supporting users in taking appropriate actions.
[0699] The following describes the processing flow.
[0700] Step 1:
[0701] The device monitors the user's behavior in the background. Specifically, it collects data about the user's actions, such as the URLs of websites the user visits and the sender information of emails that are opened. A "little AI" built into the device evaluates the collected data in real time and scores the likelihood of fraud.
[0702] Step 2:
[0703] The device sends data that it determines to be potentially fraudulent during the initial evaluation to a server. This data is encrypted to protect privacy and includes specific factors and related history of fraudulent behavior. At the same time, the device also acquires the user's sentiment information and prepares it for analysis by the sentiment engine.
[0704] Step 3:
[0705] The server analyzes the data received from the terminal. A "large AI" compares it against a fraud pattern database and evaluates the fraud risk of the behavioral data in detail. The server also calculates the fraud risk evaluation result and determines whether it is necessary to inform the user.
[0706] Step 4:
[0707] When the device receives a fraud warning from the server, it simultaneously uses an emotion engine to analyze the user's emotional state. For example, the device uses information from the user's tapping speed, voice input, and facial recognition camera (if necessary) to determine whether the user is tense or relaxed.
[0708] Step 5:
[0709] When generating warning messages to alert users to potential scams, the device considers the user's emotional state, as determined by its emotion engine. If the user is stressed, it displays a gentler, more detailed, and easier-to-understand message. Conversely, if the user is calm, it displays a concise and to-the-point message.
[0710] Step 6:
[0711] Users can review warning messages displayed on their devices and take appropriate action depending on the situation. For example, they might delete suspicious emails or avoid accessing dangerous websites. Users can also access additional support information as needed.
[0712] This processing flow allows users to efficiently avoid the risk of fraud while receiving information optimized according to their individual emotional state.
[0713] (Example 2)
[0714] Next, we will describe Example 2. In the following description, the data processing device 12 will be referred to as the "server" and the robot 414 as the "terminal".
[0715] In today's world, as users' digital activities diversify, fraudulent methods are also becoming more sophisticated. Therefore, technology is needed that goes beyond simply comparing data with past data, monitoring behavior in real time, understanding users' emotional states, and responding appropriately. Furthermore, providing appropriate and effective warnings and guidance so that users can use the system safely and without annoyance is also a crucial challenge.
[0716] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 2 is realized by the following means.
[0717] In this invention, the server includes information processing means for receiving behavioral data and performing initial analysis, analysis means for comparing the received data with a database of past fraud information and performing a detailed evaluation, and analysis means for analyzing the user's emotional state and determining the optimal warning message. This enables real-time monitoring of fraudulent behavior, provision of optimal warning messages tailored to the user's psychological state, and improvement of the accuracy of fraud prevention measures and the user experience.
[0718] "Behavioral data" refers to information about a user's actions in the digital environment, and includes data such as website browsing history and email open records.
[0719] "Information processing means" refers to a technological element equipped with the function of receiving and analyzing user behavior data, and is used to assess the initial possibility of fraud.
[0720] "Communication methods" refer to technological elements that securely transmit behavioral data from a terminal to a server, and are used to transmit data for determining the possibility of fraud.
[0721] "Analysis means" refers to a technical element that operates on a server and performs a detailed evaluation by comparing received behavioral data with a database of past fraud information.
[0722] "Analysis means" refers to a technical element that analyzes the user's emotional state, thereby selecting and providing the user with the most appropriate warning message.
[0723] A "status monitoring means" is a technological element that has the function of monitoring user behavior data in real time, enabling the early detection of unexpected fraudulent behavior.
[0724] "Display information" refers to visual or auditory alerts or instructions provided to the user, including warnings and guidance.
[0725] This invention provides an advanced evaluation and analysis system for monitoring users' digital behavior and preventing fraudulent activity. Specifically, it incorporates technology that ensures user safety by facilitating communication between the terminal and the server. The details are described below.
[0726] The device collects user behavior data in real time. This data includes website browsing history and email open records, and is used to assess the initial likelihood of fraud. The device is equipped with a "small AI" that uses TensorFlow and other tools to perform initial assessments in a short amount of time.
[0727] If the device determines that there is a certain level of likelihood of fraud, it securely transmits the data to a server. This communication is encrypted using protocols such as SSL / TLS to protect the user's data from unauthorized access.
[0728] The server uses a "large AI" to analyze the received data in detail. This AI is trained using PyTorch and reassesss the risk of fraud with high accuracy by comparing it against a database of past frauds. Once the assessment is complete, the results are sent back to the terminal.
[0729] Furthermore, the server incorporates an emotion engine that analyzes the user's emotional state from various data such as voice tone, facial expressions, and operation speed. This emotion engine can predict how the user will react to warning messages and determine the optimal message content.
[0730] Based on these evaluation results, users receive warning messages displayed on their devices. These messages vary depending on the level of fraud. For example, if the user is calm, they will be notified with a general warning; if they are stressed, they will be presented with a more helpful and easy-to-understand message.
[0731] For example, if a user opens a suspicious email, the device immediately assesses the possibility of fraud and sends that information to the server. The server uses advanced AI to reassess the risk of fraud, analyzes the user's emotional state, and then sends an appropriate warning message to the device.
[0732] An example of a prompt to input into a generative AI model is, "Describe a system that assesses the likelihood of fraud based on a user's digital behavior and analyzes the user's state using an emotion engine." This prompt can be used to facilitate understanding in natural language.
[0733] The flow of the specific processing in Example 2 will be explained using Figure 13.
[0734] Step 1:
[0735] The device collects user behavior data. As input, it obtains the user's website browsing history and email open records. Based on this data, a "small AI" built into the device performs an initial evaluation to detect abnormal behavioral patterns. Specifically, it compares the input data with existing fraud patterns and calculates the likelihood of fraud. As output, it generates behavioral data that has been determined to be abnormal.
[0736] Step 2:
[0737] The device sends behavioral data deemed highly likely to be fraudulent during the initial evaluation to the server using a "communication method." This transmission uses the SSL / TLS protocol to ensure security. The input here is suspected fraudulent behavioral data, and the output is an encrypted data package.
[0738] Step 3:
[0739] The server uses "analysis tools" to perform a detailed evaluation of the received behavioral data. It receives encrypted behavioral data transmitted from the terminal as input. This data is decrypted and compared with a pre-stored fraud information database using a "large AI." This process identifies similarities to past fraud cases, enabling more accurate fraud detection. The server generates an evaluation result regarding the risk level of the fraud as output.
[0740] Step 4:
[0741] The server uses "analysis tools" to analyze the user's emotional state based on a detailed evaluation of behavioral data. Inputs include user interaction data such as voice tone, facial expression data, and operation speed. The data processing here involves analyzing sensor information integrated by the emotion engine to identify the user's psychological state. At this stage, it is determined whether the user is calm or stressed, and the emotional state evaluation result is obtained as output.
[0742] Step 5:
[0743] The device generates a warning message for the user based on the fraud risk assessment and emotional state assessment results sent from the server. The input is the assessment results received from the server, and the device selects a warning message appropriate for the user based on this. Specifically, it generates a standard warning if the user is relaxed, and a message with a gentler tone if the user is stressed. The output is the warning message that will be displayed.
[0744] (Application Example 2)
[0745] Next, we will explain application example 2. In the following explanation, the data processing device 12 will be referred to as the "server" and the robot 414 as the "terminal".
[0746] In today's information society, fraudulent activities are becoming increasingly sophisticated, and users need to protect their sensitive information from malicious third parties. However, current fraud prevention systems lack appropriate responses that take into account the emotional state of users. As a result, they often only fuel users' anxiety and fail to provide effective prevention. Therefore, there is a need for a system that effectively reduces the risk of fraud while being mindful of users' emotions.
[0747] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means.
[0748] In this invention, the server includes an initial evaluation means operating on an information processing device for receiving behavioral information, a detailed evaluation means operating on a computing device for comparing the received data with a database of past fraud patterns, and an analysis means for analyzing the emotional state. This makes it possible to accurately assess the risk of fraud based on the user's digital behavior and provide appropriate warning messages according to the user's emotional state.
[0749] "Behavioral information" refers to data about a user's digital activities, including website browsing history and email open history.
[0750] An "information processing device" refers to a computer system that has the function of receiving data and monitoring user behavior.
[0751] "Initial evaluation means" refers to an algorithm that operates on an information processing device and evaluates the possibility of fraud in the first stage based on the received behavioral information.
[0752] "Communication means" refers to a communication module used to transmit data that the initial evaluation means has determined to be potentially fraudulent to an external party.
[0753] A "fraud pattern database" refers to a collection of data that records patterns of fraudulent activities that have occurred in the past.
[0754] A "computational device" refers to a server that possesses the computing power to perform advanced analysis of received behavioral data.
[0755] "Detailed evaluation means" refers to a process that operates on a computing device, compares behavioral information with a fraud pattern database, and evaluates the risk of fraud with high accuracy.
[0756] "Display means" refers to a display device that visually provides users with information about the risk of fraud.
[0757] "Analysis methods" refer to algorithms and sensor technologies used to understand the emotional state of users.
[0758] "Adjustment means" refers to the process of generating optimized notification content based on the user's emotional state.
[0759] To implement this invention, an information processing device, including a smartphone, is used. The information processing device incorporates an initial evaluation means that monitors the user's daily digital behavior information and assesses the likelihood of fraud. This device uses a communication means to transmit data that is deemed to have a high probability of being fraudulent to a server equipped with a computing device.
[0760] The server compares the received data against a database of fraudulent patterns and utilizes detailed evaluation means operating on a computing device to perform a high-level detailed evaluation. If the evaluation confirms a risk of fraud, the server transmits the results to an information processing device equipped with display means for notifying the user.
[0761] Furthermore, an emotion engine acts as an analytical tool to analyze the user's emotional state. This allows the system to grasp the user's emotional state in real time from their voice tone and facial expression data. Based on this analysis, an adjustment mechanism optimizes the content of warning messages provided to the user. For example, if the user shows signs of anxiety, guidance in a gentle tone is provided.
[0762] As a concrete example, when a user opens a suspicious webmail, the information processing unit monitors the user's behavior and delegates the risk assessment to the server. If the emotion engine detects stress from the user's vocal patterns, a remediation mechanism displays a notification such as, "This email requires caution. Please review it calmly." Furthermore, a prompt message such as, "Of the emails you've received recently, what seems suspicious?" can be used to gather additional information.
[0763] The flow of a specific process in Application Example 2 will be explained using Figure 14.
[0764] Step 1:
[0765] The device collects user behavior information and inputs the digital behavior data into the initial assessment system. Here, website visit history and email open history are collected as a dataset. Based on this data, the initial assessment system evaluates the initial fraud risk, and if fraud is suspected, it transmits the data to the server via communication means.
[0766] Step 2:
[0767] The server receives data transmitted from the terminal and inputs it into a detailed evaluation system for comparison with a fraud pattern database. The detailed evaluation system compares past fraud patterns with current user behavior and performs advanced analysis. In this process, data analysis algorithms are used to assess the risk of fraud with greater accuracy, and the results are output to an information processing device.
[0768] Step 3:
[0769] The terminal receives fraud risk information output from the server and issues a warning to the user via a display device. Here, the emotion engine inputs the user's voice tone and facial expression data into an analysis device. This allows the device to determine the user's emotional state in real time, and an adjustment device generates an optimized warning message, which is then displayed on the screen. For example, if a voice tone indicating anxiety is detected, a message such as "This email requires caution. Please calmly review it" will be displayed.
[0770] Step 4:
[0771] The user receives a warning message and is guided on recommended next actions. A prompt based on a generated AI model is then displayed, requesting further information from the user. For example, a question such as, "What in the emails you've recently received looks suspicious?" is presented to collect user feedback. This information is then fed back into the initial evaluation system, contributing to improving the overall accuracy of the system.
[0772] The specific processing unit 290 transmits the result of the specific processing to the robot 414. In the robot 414, the control unit 46A causes the speaker 240 and the controlled object 443 to output the result of the specific processing. The microphone 238 acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 238 to the data processing unit 12. In the data processing unit 12, the specific processing unit 290 acquires the audio data.
[0773] Data generation model 58 is a type of so-called generative AI (Artificial Intelligence). One example of data generation model 58 is ChatGPT (Internet search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search) <url: https: gemini.google.com ?hl="ja">Examples of generative AI include the following. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and with inference data such as audio data representing speech, text data representing text, and image data representing images. The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference results in data formats such as audio data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.
[0774] In the above embodiment, an example was given in which the specific processing is performed by the data processing device 12, but the technology of this disclosure is not limited thereto, and the specific processing may also be performed by the robot 414.
[0775] Furthermore, the emotion identification model 59, acting as an emotion engine, may determine the user's emotion according to a specific mapping. Specifically, the emotion identification model 59 may determine the user's emotion according to a specific mapping, which is an emotion map (see Figure 9). Similarly, the emotion identification model 59 may also determine the robot's emotion, and the identification processing unit 290 may perform identification processing using the robot's emotion.
[0776] Figure 9 shows an emotion map 400 in which multiple emotions are mapped. In the emotion map 400, emotions are arranged in concentric circles radiating from the center. The closer to the center of the concentric circles, the more primitive the emotions are located. Further out of the concentric circles, emotions representing states and actions arising from mental states are located. Emotion is a concept that includes feelings and mental states. On the left side of the concentric circles, emotions that are generally generated from reactions occurring in the brain are located. On the right side of the concentric circles, emotions that are generally induced by situational judgment are located. Above and below the concentric circles, emotions that are generally generated from reactions occurring in the brain and induced by situational judgment are located. In addition, the emotion of "pleasure" is located on the upper side of the concentric circles, and the emotion of "displeasure" is located on the lower side. Thus, in the emotion map 400, multiple emotions are mapped based on the structure in which emotions arise, and emotions that are likely to occur simultaneously are mapped close together.
[0777] These emotions are distributed at the 3 o'clock position on the Emotion Map 400, and usually fluctuate between feelings of security and anxiety. In the right half of the Emotion Map 400, situational awareness takes precedence over internal feelings, resulting in a calm impression.
[0778] The inside of the Emotion Map 400 represents inner thoughts, while the outside represents actions. Therefore, the further you go from the outside of the Emotion Map 400, the more visible (expressed in actions) your emotions become.
[0779] Here, human emotions are based on various balances, such as posture and blood sugar levels. When these balances deviate from the ideal, it results in discomfort, and when they approach the ideal, it results in pleasure. Similarly, in robots, cars, motorcycles, etc., emotions can be created based on various balances, such as posture and battery level. When these balances deviate from the ideal, it results in discomfort, and when they approach the ideal, it results in pleasure. The emotion map can be generated, for example, based on Dr. Mitsuyoshi's emotion map (Research on a system for analyzing brain physiological signals of speech emotion recognition and emotion, Tokushima University, doctoral dissertation: https: / / ci.nii.ac.jp / naid / 500000375379). The left half of the emotion map contains emotions belonging to a region called "response," where sensation is dominant. The right half of the emotion map contains emotions belonging to a region called "situation," where situational awareness is dominant.
[0780] The emotion map defines two emotions that promote learning. One is the emotion around the middle of the negative "repentance" and "reflection" on the situation side. In other words, it is when the robot experiences negative emotions such as "I never want to feel this way again" or "I don't want to be scolded again." The other is the emotion around the positive "desire" on the reaction side. In other words, it is when the robot has positive feelings such as "I want more" or "I want to know more."
[0781] The emotion identification model 59 inputs user input into a pre-trained neural network, obtains emotion values representing each emotion shown in the emotion map 400, and determines the user's emotion. This neural network is pre-trained based on multiple training data sets, which are combinations of user input and emotion values representing each emotion shown in the emotion map 400. Furthermore, this neural network is trained so that emotions located close together have similar values, as shown in the emotion map 900 in Figure 10. Figure 10 shows an example where multiple emotions such as "reassured," "calm," and "confident" have similar emotion values.
[0782] The above description primarily focuses on the functions of the data processing device 12 in relation to this disclosure. However, the system related to this disclosure is not necessarily implemented on a server. The system related to this disclosure may be implemented as a general information processing system. This disclosure may be implemented, for example, as a software program that runs on a personal computer or as an application that runs on a smartphone. The method related to this disclosure may be provided to users in SaaS (Software as a Service) format.
[0783] In the above embodiment, an example was given in which a specific process is performed by a single computer 22. However, the technology of this disclosure is not limited thereto, and a distributed processing of the specific process may be performed by multiple computers, including computer 22. For example, a data generation model 58 may be provided in an external device of the data processing device 12, and the external device may generate data according to the input data.
[0784] In the above embodiment, an example was given in which the specific processing program 56 is stored in the storage 32, but the technology of this disclosure is not limited thereto. For example, the specific processing program 56 may be stored in a portable, computer-readable, non-temporary storage medium such as a USB (Universal Serial Bus) memory. The specific processing program 56 stored in the non-temporary storage medium is installed in the computer 22 of the data processing device 12. The processor 28 executes specific processing according to the specific processing program 56.
[0785] Alternatively, the specific processing program 56 may be stored in a storage device such as a server connected to the data processing device 12 via the network 54, and the specific processing program 56 may be downloaded and installed on the computer 22 in response to a request from the data processing device 12.
[0786] Furthermore, it is not necessary to store the entirety of the specific processing program 56 in a storage device such as a server connected to the data processing device 12 via the network 54, or to store the entirety of the specific processing program 56 in the storage 32; it is acceptable to store only a portion of the specific processing program 56.
[0787] The following types of processors can be used as hardware resources to perform specific processing. Examples of processors include a CPU, a general-purpose processor that functions as a hardware resource to perform specific processing by executing software, i.e., a program. Other examples of processors include dedicated electrical circuits, such as FPGAs (Field-Programmable Gate Arrays), PLDs (Programmable Logic Devices), or ASICs (Application Specific Integrated Circuits), which have circuit configurations specifically designed to perform specific processing. All of these processors have built-in or connected memory, and all of them perform specific processing by using memory.
[0788] The hardware resource that performs a specific process may consist of one of these various processors, or it may consist of a combination of two or more processors of the same or different types (for example, a combination of multiple FPGAs, or a combination of a CPU and an FPGA). Alternatively, the hardware resource that performs a specific process may consist of a single processor.
[0789] Examples of configurations using a single processor include, firstly, a configuration in which one or more CPUs and software are combined to form a single processor, and this processor functions as a hardware resource that performs a specific process. Secondly, there is a configuration using a processor that realizes the functions of the entire system, including multiple hardware resources that perform a specific process, on a single IC chip, as exemplified by SoCs (System-on-a-chip). In this way, a specific process is realized using one or more of the above types of processors as hardware resources.
[0790] Furthermore, the hardware structure of these various processors can more specifically utilize electrical circuits that combine circuit elements such as semiconductor devices. Also, the specific processing described above is merely an example. Therefore, it goes without saying that unnecessary steps can be deleted, new steps added, or the processing order rearranged, as long as it does not deviate from the main purpose.
[0791] The descriptions and illustrations presented above are detailed explanations of the technical aspects of this disclosure and are merely examples of the technical aspects. For example, the above descriptions of the structure, function, operation, and effect are examples of the structure, function, operation, and effect of the technical aspects of this disclosure. Therefore, it goes without saying that you may delete unnecessary parts, add new elements, or replace elements in the descriptions and illustrations presented above, as long as you do not deviate from the essence of the technical aspects of this disclosure. Furthermore, in order to avoid confusion and facilitate understanding of the technical aspects of this disclosure, explanations of common technical knowledge and the like that do not require special explanation to enable the implementation of the technical aspects of this disclosure have been omitted from the descriptions and illustrations presented above.
[0792] All documents, patent applications, and technical standards described herein are incorporated by reference to the same extent as if each individual document, patent application, and technical standard were specifically and individually noted to be incorporated by reference.
[0793] The following is further disclosed regarding the embodiments described above.
[0794] (Claim 1)
[0795] A first evaluation means that operates on a terminal for receiving behavioral information,
[0796] A means for transmitting data when the likelihood of fraud exceeds a threshold according to the first evaluation means,
[0797] A second evaluation means operating on a server for comparing the received data with a database of past fraud patterns,
[0798] A means of notifying the user if the second evaluation means determines that there is a high risk of fraud,
[0799] A system that includes this.
[0800] (Claim 2)
[0801] The system according to claim 1, further comprising log monitoring means for collecting information on suspected fraudulent behavior in real time.
[0802] (Claim 3)
[0803] The system according to claim 1, further comprising means for providing guidance to the user in the warning message, including a recommended next action.
[0804] "Example 1"
[0805] (Claim 1)
[0806] A first decision-making means that operates on an information terminal for receiving behavioral information,
[0807] A communication means that transmits information when the possibility of fraud exceeds a threshold according to the first determination means,
[0808] A second determination means operating on a computer for comparing the received information with a past fraud pattern storage device,
[0809] A notification means for informing the user if the second determination means determines that there is a high risk of fraud,
[0810] A means of supporting users in obtaining countermeasures to avoid risks based on the information they have sent,
[0811] A system that includes this.
[0812] (Claim 2)
[0813] The system according to claim 1, further comprising recording and monitoring means for collecting information on suspected fraudulent behavior in real time.
[0814] (Claim 3)
[0815] The system according to claim 1, further comprising means for providing advice to the user, including a recommended next action, in the warning message provided to the user.
[0816] "Application Example 1"
[0817] (Claim 1)
[0818] A first evaluation means operating on an information processing device for receiving behavioral information,
[0819] A means for transmitting information when the likelihood of fraud exceeds a threshold according to the first evaluation means,
[0820] A second evaluation means operating on an information processing device for comparing received information with past fraud pattern storage device,
[0821] A means of notifying the user if the second evaluation means determines that there is a high risk of fraud,
[0822] A means to support secure transactions by verifying the reliability of transaction information performed by the user and issuing warnings,
[0823] A system that includes this.
[0824] (Claim 2)
[0825] The system according to claim 1, further comprising a status monitoring means for collecting information on behaviors suspected of being fraudulent in real time.
[0826] (Claim 3)
[0827] The system according to claim 1, further comprising means for providing guidance in the warning message provided to the user, including a recommended next action.
[0828] "Example 2 of combining an emotion engine"
[0829] (Claim 1)
[0830] Information processing means for receiving behavioral data and performing initial analysis,
[0831] A communication means that transmits data when the possibility of fraud exceeds a predetermined threshold, based on the information processing means,
[0832] An analytical method for comparing received data with a database of past fraud information and conducting a detailed evaluation,
[0833] An analytical means for analyzing the user's emotional state and determining the optimal warning message,
[0834] A means of providing information to the user when the aforementioned analysis means determines that there is a high risk of fraud,
[0835] A system that includes this.
[0836] (Claim 2)
[0837] The system according to claim 1, further comprising a status monitoring means for monitoring in real time behavioral data suspected of being fraudulent.
[0838] (Claim 3)
[0839] The system according to claim 1, further comprising means for providing warning information to the user, including instructions that include a recommended next action.
[0840] "Application example 2 when combining with an emotional engine"
[0841] (Claim 1)
[0842] An initial evaluation means operating on an information processing device for receiving behavioral information,
[0843] A communication means that transmits data when the probability of fraud exceeds a threshold as determined by the initial evaluation means,
[0844] A detailed evaluation means operating on a computing device for comparing received data with a database of past fraudulent patterns,
[0845] A display means for notifying the user if the detailed evaluation means determines that there is a high risk of fraud,
[0846] Analytical means for analyzing emotional states,
[0847] Based on the analysis results of the aforementioned analysis means, an adjustment means for optimizing the notification content to the user,
[0848] A system that includes this.
[0849] (Claim 2)
[0850] The system according to claim 1, further comprising recording and monitoring means for collecting information on suspected fraudulent behavior in real time.
[0851] (Claim 3)
[0852] The system according to claim 1, further comprising means for providing guidance in the warning message provided to the user, including a recommended next action. [Explanation of Symbols]
[0853] 10, 210, 310, 410 Data Processing Systems 12 Data Processing Devices 14 Smart Devices 214 Smart Glasses 314 Headset-type terminal 414 Robots< / url:> < / url:> < / url:> < / url:>
Claims
1. A first evaluation means operating on an information processing device for receiving behavioral information, A means for transmitting information when the probability of fraud exceeds a threshold according to the first evaluation means, A second evaluation means operating on an information processing device for comparing received information with a past fraud pattern storage device, A means of notifying the user if the second evaluation means determines that there is a high risk of fraud, A means to support secure transactions by verifying the reliability of transaction information performed by the user and issuing warnings, A system that includes this.
2. The system according to claim 1, further comprising a status monitoring means for collecting information on behaviors suspected of being fraudulent in real time.
3. The system according to claim 1, further comprising means for providing guidance in the warning message provided to the user, including a recommended next action.
Citation Information
Patent Citations
Persona chatbot control method and system
JP2022180282A