Method for identifying groups of users of interest within a set of users using a transactional service, corresponding computer program product and device

The method addresses inefficiencies in identifying user groups by pruning irrelevant users and interactions using characteristic comparisons and deletion rules, effectively detecting fraudsters in large networks with minimal data, enhancing transactional service security.

WO2026046695A1PCT designated stage Publication Date: 2026-03-05ORANGE SA
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
PCT/EP2025/072860
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-08-29
Filing Date
2025-08-08
Publication Date
2026-03-05

AI Technical Summary

Technical Problem

Existing methods for identifying groups of users of interest in transactional services, such as fraudsters, are inefficient with small data samples, require extensive data processing, and fail to consider the relational dimension of user interactions, making them unsuitable for large user networks.

Method used

A method involving pruning user sets based on characteristic comparisons and deletion rules to identify groups of interest, utilizing a graph representation to remove irrelevant users and interactions, focusing on topological and semantic features.

Benefits of technology

Enables efficient identification of user groups without requiring large reference groups, scalable for large networks, and provides real-time detection and action on suspected fraudsters.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2025072860_05032026_PF_FP_ABST
    Figure EP2025072860_05032026_PF_FP_ABST
Patent Text Reader

Abstract

The present invention relates to a method for identifying at least one group of interest within a set of users using a transactional service via terminals. The method is implemented in an identification device and comprises the following steps: - receiving a request to detect a group of interest relative to a reference group of users; - deleting (E2) at least one user and / or one interaction between two users of the set of users, thereby delivering a pruned set of users, taking into account a deletion rule and the result of a comparison of user / interaction characteristics with at least one characteristic representative of the reference group; - identifying (E3) the group of interest among the users of the pruned set of users.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] DESCRIPTION

[0002] Method for identifying groups of users of interest within a set of users of a transactional service, computer program product and corresponding device

[0003] technical field

[0004] The invention falls within the field of social networks of users sharing a transactional service, such as a telecommunications or payment service, via their communication terminal. More specifically, the invention relates to a technique for identifying one or more groups of users of interest within a set of users of a transactional service.

[0005] The invention applies to all contexts of transactional service implementing telecommunications or financial transactions for which it is possible to establish a social relationship between the different users of this service.

[0006] Technological background

[0007] In recent years, the analysis of socio-transactional networks has received increasing attention. It is of major interest in understanding the habits of service users through the exploitation of relational data. Such data is obtained, in particular, from interactions between users of a service via their communication devices. Whether it comes from social media, telecommunications services, or financial transactions, companies in these sectors have understood the importance of extracting and using information from this relational data to enrich their understanding of user behavior, improve service personalization, and / or enhance the security of the services offered, for example, by combating fraud and misuse.These interactions often reveal complex social structures and dynamics, such as user groups linked by common interests, which are worth analyzing in order to improve the functioning of the service concerned.

[0008] In the context of implementing a financial service, such as mobile banking, the data created by the relationships that users of this service maintain with each other can constitute relevant data for detecting the presence of banking fraud or misuse of this service.

[0009] Several methods exist in the state of the art for identifying users of interest, such as fraudsters, within a service's user network. One such method relies on machine learning, which uses a mathematical model and predefined rules to analyze relational data, interpret it, and identify groups of interest based on characteristics common to the service's users. However, to be effective, this method requires a large amount of labeled data. It is therefore not suitable for small samples. Furthermore, it is relatively insensitive to the topological and temporal variability of the target groups of interest, which limits its implementation to a relatively small number of application contexts.Indeed, in an operational context, it is important to be able to identify groups of users of interest whose topology may vary depending on the time and the users, as is the case for example for the management of bank fraud risks, where some individuals are particularly agile in their strategies to circumvent the countermeasures implemented by banking services.

[0010] A second known method relies on user community detection. This method involves analyzing transactional data to identify the highest density of interactions within a user group relative to the entire user network, grouping them into one or more user communities (family, friends, professional or business contacts, etc.). Variations allow for associating multiple user groups with the same entity; these are known as "overlapping communities." However, this method is complex to implement, particularly on large user networks. Effectively, it requires processing a substantial volume of data (several million users and several hundred million transactions). Furthermore, relatively expensive post-processing is often necessary to accurately identify groups of interest.Indeed, community detection algorithms are capable of identifying generic groups across the entire transactional network but are unable to classify these groups into precise categories without post-processing, which is not optimal.

[0011] Finally, a third known method relies on graph matching. This approach involves transforming data into transactional graphical representations and analyzing, from these representations, the topological structure of the target user groups, with the goal of identifying service users with similar topological characteristics. One limitation of this approach is its failure to consider the environment of the target user group and all its interconnections with the service's users—in other words, the relational dimension of service interactions. Furthermore, this approach is also complex to implement on large user networks.

[0012] Therefore, there is a need to provide an effective technique for identifying groups of users of interest, even when faced with a small number of users and / or a limited amount of available data. In particular, there is a need for a technique for identifying groups of users of interest that is scalable and as generic as possible.

[0013] Description of the invention

[0014] The present technique addresses this need by proposing a method for identifying at least one subset of users, referred to as a group of interest, within a set of users of a transactional service via terminals. This method is implemented in an identification device and comprises the steps of: receiving a request to detect said at least one group of interest relative to at least one reference group of users previously identified among the users of said set; deleting at least one user and / or an interaction, within the framework of said transactional service, between two users of said set, delivering a pruned set of users.said deletion taking into account at least one deletion rule and the result of a comparison of at least one characteristic associated with said at least one user and / or with said at least one interaction with at least one characteristic representative of said reference group, identification of said at least one interest group among the users of said pruned set.

[0015] Thus, this technique relies on removing users from a set of users who do not share characteristics with a reference group, in order to highlight the remaining users as being, conversely, close to the reference group. This technique therefore contradicts known techniques that rely on searching for common characteristics to identify users within a set of users who are close to a reference group.

[0016] Thanks to this pruning principle based on the characteristics of all users in the set, this technique does not require a large reference group to be effective, even with a very large number of users in the search set. This contrasts with known techniques based on machine learning, for example, which require a large amount of reference data to be effective. Furthermore, one or more deletion rules are implemented in addition to the characteristic comparisons to improve the accuracy of this technique. These deletion rules can, for example, take into account the topology of the users to be removed.

[0017] Once irrelevant users are removed from the initial set, the remaining user groups correspond to the subgroups being sought.

[0018] According to a particular aspect of the present technique, the method includes a preliminary step, implemented for at least one user from a plurality of users of said set and / or for at least one interaction between two users of said plurality of users, of associating at least one characteristic with said user and / or with said interaction, delivering a plurality of characteristics associated with said at least one user and / or with said at least one interaction.

[0019] This approach involves extracting one or more characteristics specific to one or more users from the set, or a subset, including characteristics associated with interactions between these users. These characteristics can then be compared with those representative of the reference group. Indeed, this phase of associating characteristics with at least one user and / or at least one interaction is also applied to the users of the reference group. In this way, it is possible to characterize one or more users of the set with both topological and semantic features, unlike some known techniques that rely solely on the topology of a set to select users.

[0020] In a specific implementation, these associated characteristics are saved in at least one database. This improves the performance of the pruning stage.

[0021] According to a particular aspect of the present technique, the deletion includes: o for at least one user and at least one interaction between two users from a plurality of users of said set:

[0022] ■ comparison of at least one characteristic associated with at least one user or with at least one interaction with at least one characteristic representative of said reference group, providing a proximity distance,

[0023] ■ when the proximity distance is greater than a predetermined threshold, selection of said at least one user or of said at least one interaction and addition in a subgroup of no interest, o deletion of said set, according to said at least one deletion rule, of said at least one user or of said at least one interaction selected in the subgroup of no interest, delivering said pruned set.

[0024] Thus, according to this approach, pruning within the user set is based on distance measurements between the characteristics associated with a given user and / or interaction and the representative characteristics of the reference group. These measurements are then compared to a predefined threshold to determine whether that given user and / or interaction should be removed. Subsequently, one or more removal rules are used to refine the decisions based on the distance measurements between characteristics, removing only users / interactions that are irrelevant to the reference group.

[0025] According to another aspect of the present technique, the method includes assigning a label to at least one user of said identified interest group, forming a subgroup of interest, said label being representative of the implementation of an action belonging to the group comprising: the issuance of an alert or information message to the terminals of users of said set or subgroup of non-interest; the eviction of said transactional service from users of the subgroup of interest.

[0026] This technique is implemented in an application context aimed at optimizing the operation of the transactional service used by users of the set, for example, by detecting groups of fraudsters of a certain type among all users of the service, starting from an identified group of fraudsters constituting the reference group. In such circumstances, all users of the service, not identified as fraudsters, have a vested interest in being informed of the presence of fraudsters within the user set to which they belong. Once the groups of fraudsters are detected, this technique therefore also makes it possible to inform other users of the service. It is also possible to deny access to the service to groups of users identified as fraudsters through the implementation of this technique.

[0027] According to another aspect of the present technique, the method comprises creating a graph representing said user set, said graph comprising a plurality of nodes corresponding to said users of said transactional service and a plurality of edges corresponding to the interactions between said users, and where: said comparison comprises, for at least one node and at least one edge of said graph: o a measurement of a distance between a feature vector associated with said at least one node and / or said at least one edge and a feature vector associated with said reference group, yielding a proximity distance, o a comparison of said proximity distance yielded with a predetermined threshold, yielding a positive comparison result when said proximity distance is greater than said threshold, said deletion comprises a deletion according to said at least one deletion rule, of said graph,said at least one node and / or edge when said comparison result is positive, yielding a pruned graph, said identification includes the determination of at least one subgraph of interest in said pruned graph.

[0028] From this perspective, the graph approach to representing a set of service users allows for the consideration of the social / relational dimension of interactions within a transactional service. The characteristics associated with the nodes, representing users, and the edges, representing interactions between users, are extracted as characteristic vectors. Comparisons are then made using distance measurements between characteristic vectors, and user / interaction removal involves pruning the graph by deleting nodes and the edges between them. The remaining connected nodes in the pruned graph then correspond to the groups of interest being sought.

[0029] According to a particular implementation, the characteristics associated with the users and interactions of said set belong to the group comprising: topological characteristics, intrinsic characteristics of said service, characteristics calculated by learning.

[0030] This list of features is not exhaustive.

[0031] According to a particular implementation, said at least one removal rule belongs to the group comprising: a so-called node rule, removing all users of said set present in the group of no interest, a so-called arc rule, removing all interactions of said set present in the group of no interest, a so-called simple rule, removing all users and interactions of said set present in the group of no interest, a so-called arc majority rule, removing all users and interactions of said set present in the group of no interest except nodes having a ratio of neighbors absent from the group of no interest greater than a predefined threshold.

[0032] This list of rules is not exhaustive.

[0033] In another embodiment of the invention, a computer program product is proposed which includes program code instructions for implementing the aforementioned process in any of its various implementation modes, when said program is executed on a computer.

[0034] In another embodiment of the present technique, a computer-readable and non-transient storage medium is proposed, storing a computer program comprising a set of instructions executable by a computer to implement the aforementioned process in any of its various implementation modes.

[0035] In another embodiment of the present technique, a device is proposed for identifying at least one subset of users, referred to as a group of interest, within a set of users of a transactional service via terminals, said identification device comprising at least one processor configured to: receive a detection request for said at least one group of interest relative to at least one reference group of users previously identified among the users of said set, and delete at least one user and / or an interaction, within the framework of said transactional service, between two users of said set, delivering a pruned set of users.said deletion, taking into account at least one deletion rule and the result of a comparison of at least one characteristic associated with said at least one user and / or with said at least one interaction with at least one characteristic representative of said reference group, identifies said at least one interest group among the users of said pruned set. Advantageously, the identification device includes means for implementing the steps it performs in the process as described above, in any of its various modes of implementation.

[0036] List of figures

[0037] Other features and advantages of the invention will become apparent from the following description, given by way of indicative and non-limiting example, and the accompanying drawings, in which: Figure 1 is a schematic view of an example of a communication system in which the method of the invention is implemented according to a particular embodiment;

[0038] Figure 2 is a simplified example of a graphical representation of the social network of users illustrated in Figure 1;

[0039] Figure 3 presents a flowchart of a particular embodiment of the process according to the invention;

[0040] Figure 4 represents the simplified structure of a device implementing the process according to a particular embodiment of the invention.

[0041] Detailed description of the invention

[0042] The general principle of this technique relies on using a pruning mechanism to remove users who do not share characteristics with a reference group of users identified within a user set (or user network) of a transactional service. This highlights the remaining users as being, conversely, close to the reference group. Thanks to this clever principle, this technique does not require the creation of large reference groups to be effective, even with a large number of users in the search set, unlike approaches proposed in the prior art.

[0043] The following description considers an example of implementing this technique in the context of a transactional service for managing anti-fraud financial transactions. This technique is, of course, not limited to this particular application context and can be applied to any type of transactional service subscribed to by a group of users where the identification of a subset of users within that group must be implemented via their communication terminals, for the purpose of optimizing the operation of the transactional service.

[0044] Figure 1 illustrates an example of a communication system (CS) implementing the method of the invention. Such a communication system (CS) comprises a management server (MS) and a set of user terminals (UTl-UTn) capable of being interconnected within a communication network, for example, a network operating according to the Internet Protocol (IP). The UTl-UTn terminals are standard communication terminals, such as mobile phones, tablets, or computers, each subscribed to the same transactional service, for example, a payment or banking service supported by the IP network.This transactional service, referred to as service “ST” in the rest of the description, allows users of UTl-UT-n terminals connected to the Internet to connect in order to establish telecommunications and / or financial transactions between these users via their communication terminals: bank transfer, bank debit, credit, mandate, advice and assistance in financial management, electronic money management for example.

[0045] This ST transactional service can be an opportunity for fraudsters to try to divert some of these exchanges (telecommunications and / or transactions) to their advantage by contacting their targets in a fortuitous way (for example: sending messages, widespread calls, etc.) or by pretending to be a trusted relationship (for example: targeted scam attempt, misappropriation or identity theft, etc.).

[0046] Based on past interactions between users, it is possible to construct membership groups (also called "social groups") forming a set of users (also called a "socio-transactional" network). These membership groups consist of individuals who share relationships that lead them to communicate in various ways. These relationships between individuals (for example: relational, interest-based, or geographical proximity) are identifiable and quantifiable (for example: call frequency, call duration, transaction amount, transaction frequency, etc.). A user can therefore be assigned one or more membership groups based on the relationships they maintain with other users of the ST transactional service.

[0047] To build this user network, the SG management server uses relational data from interactions between users of the ST service (for example: sender / recipient user identities, amount of a financial transaction, call duration, call frequency, financial transaction frequency, date, IBAN (International Bank Account Number), etc.). This relational data is stored in a database, which records the history of interactions since a given date (for example, since the user subscribed to the ST service). From this data, the SG management server creates a graphical representation of the service's user base as a tree graph of nodes representing users and links (or edges) representing interactions between users. An edge defines the relationship between two nodes in the graph.Figure 2 gives an example of a simplified graph representing the social network of users illustrated in Figure 1. This socio-transactional graph is stored and administered by the SG management server in addition to the relational data saved in the database.

[0048] It is understood that the number of users represented here is intentionally limited, for purely pedagogical purposes, so as not to overload the figures and the associated description. A larger number of terminals can, of course, be considered without departing from the scope of the invention. The SG management server periodically, for example when a new user subscribes to the ST service or upon receiving a request to update the ST service user network, constructs or updates the user network and the associated socio-transactional graph.

[0049] The construction of socio-transactional graphs relies on a set of algorithms known from the state of the art and optimized to adapt to the structure, volume of relational data and the application context.

[0050] A flowchart of a particular embodiment of the identification method according to the invention is now shown in relation to Figure 3. This flowchart illustrates the main steps in implementing the method within the specific context of a subscription to the ST transactional service discussed above. The purpose of this flowchart is to identify users suspected of fraud and to implement appropriate actions. These steps are carried out by an identification device, the principle of which is described later in relation to Figure 4.

[0051] The process is triggered upon receipt of a request to detect a group of interest relative to a reference group of users previously identified within the set of users of the ST service. This request is transmitted, for example, by the supervisor of the ST service after having identified the reference group via its human-machine interface.

[0052] For illustrative purposes, we will consider the group of interest sought within the aforementioned set of users of the ST service to be a group of users classified as "fraudsters committing bank account fraud." The group of users previously identified by the supervisor as the reference group is subsequently referred to as the "fraudster group."

[0053] In an EO step (noted "ASS_CA" in the figure), the identification device delivers a list of characteristics associated with each user from the set of users of the ST service and a list of characteristics associated with each interaction between two users from this set.

[0054] To achieve this, the socio-transactional graph representing all users of the ST service is first retrieved from the database by the identification system. Since the nodes of the graph correspond to the users of the service and the arcs to the interactions between users (transactions or communications), the identification system associates, for each node (i.e., for each user), one or more characteristics with that node, and for each arc (i.e., for each interaction between two users), one or more characteristics with that arc, in order to produce the two lists of characteristics mentioned above, one associated with the nodes and the other associated with the arcs of the socio-transactional graph.

[0055] The types of characteristics associated with nodes and interactions, and which the identification system can access, are as follows (this list is not exhaustive): topological characteristics, such as the degree or coefficient of local clustering of the nodes; intrinsic characteristics of the ST service, such as the average account balance, the number of bank transactions, or the frequency of exchanges; and characteristics calculated by machine learning using an algorithm such as node2Vec, fastRP, or GIN (Graph Isomorphism Network).

[0056] This EO step allows us to extract one or more characteristics specific to each node of the graph (i.e., each user in the set), including characteristics associated with the edges (i.e., the interactions between these users), which are then compared with the representative characteristics of the reference group of fraudsters. Indeed, this phase of associating characteristics with each user and / or each interaction is applied a fortiori to the users of the reference group. In this way, it is possible to characterize each user in the ST user network with both topological and semantic characteristics, thus taking into account the "relational" dimension of the service's interactions.

[0057] Once the association phase is complete, the identification system stores the characteristics associated with the nodes and interactions in the database. This storage improves the performance of the pruning step described below.

[0058] Once the detection request is received and processed, the identification system proceeds, in step El (denoted "COMP_CA"), to compare the characteristics associated with users and / or interactions between users across the entire ST service with the representative characteristics of the reference group of fraudsters, based on an analysis of the topological and semantic features of the graph obtained in the previous step. This step determines whether users (nodes) and / or interactions (arcs) between users (nodes) can be removed.

[0059] To do this, the identification device performs, for each node and each arc of the graph: a measurement of a distance between a vector of characteristics associated with a node and / or an arc and a vector of characteristics associated with the reference group, called proximity distance, and a comparison of the proximity distance with a predetermined threshold, delivering a positive or negative result.

[0060] The comparison result is positive when the proximity distance is greater than the predetermined threshold, and negative when the proximity distance is less than the predetermined threshold. When the comparison result is positive, the device selects the relevant node (i.e., user) and / or the relevant arc (i.e., interaction) and adds it to a subgroup of no interest, which is subsequently removed. This subgroup of no interest represents the users and / or user interactions intended to be excluded from the identification applied to all users of the ST service.

[0061] The proximity distance calculation and comparison phases rely on the use of at least one of the following methods: cosine similarity, Manhattan distance, or any other statistical learning method.

[0062] This proximity distance represents, in a way, a level of similarity between the user characteristics / interactions of a given user of the service and the representative user characteristics / interactions of the reference group of fraudsters. This proximity distance evolves over time depending on the interactions between these users.

[0063] Then, in step E2 (denoted "SUP_U / I"), the identification device removes users from the entire ST service and / or user interactions, in order to deliver a pruned set of users based on a comparison of characteristics. This removal step is carried out taking into account, on the one hand, one or more predefined removal rules, and on the other hand, the results from the comparison step El.

[0064] More specifically, the identification mechanism removes from the initial socio-transactional graph each node and / or edge for which the result from the comparison step El is positive, according to the selected removal rule(s). At the end of this step, the identification mechanism delivers a pruned socio-transactional graph. This step involves removing from the set of users of the ST service, according to the selected removal rule(s), the users and / or interactions selected from the subgroup of no interest obtained at the end of step El, to deliver a pruned set of users. In other words, removing users and / or interactions consists of pruning the graph by removing nodes and the edges between nodes; the remaining connected nodes in the pruned graph then correspond to the groups of interest being sought.

[0065] The following are the deletion rules that the identification device can take into account (without being exhaustive): a rule, called a node rule, whose principle is to delete all users of said set present in the subgroup of no interest, a rule, called an arc rule, whose principle is to delete all interactions of said set present in the subgroup of no interest, a rule, called a simple rule, deleting all users and interactions of said set present in the subgroup of no interest, a rule, called an arc majority rule, deleting all users and interactions of said set present in the subgroup of no interest, except for nodes having a ratio of neighbors absent from the subgroup of no interest greater than a predefined threshold.

[0066] These rules allow the identification system to refine its decisions based on distance measurements between characteristic vectors associated with the nodes and edges in the graph, and to remove only those nodes and edges that are irrelevant to the reference group of fraudsters. This amounts to pruning the entire user base by removing only those users and / or interactions within the subgroup of irrelevant interest (users and / or interactions irrelevant to the reference group).

[0067] In the case of applying a simple rule, which consists for example of carrying out a "rough" pruning of users and interactions present in the subgroup of no interest, it may be interesting, as a complement, for the identification device to carry out a new pruning phase by applying a more precise deletion rule.

[0068] In an advantageous implementation, the pruning phase applied to the nodes and edges of the graph is performed at least partially concurrently. This implementation is particularly well-suited to large user networks.

[0069] Once the pruned graph is established by the identification system, the latter determines, in step E3 (labeled "IDE_NI" in the figure), a group of nodes of interest from among the nodes of the pruned graph. This group of nodes of interest corresponds to the users of the ST service identified as fraudsters (i.e., a subset of users from among the users of the pruned user set constituting the group of interest being sought). This group of nodes can take the form of a subgraph of interest calculated from the pruned graph. This subgraph of interest is therefore representative of the group of users suspected of fraud.

[0070] Let's take, as an illustrative example, the aforementioned edge majority rule. In this example, we assume that the identification device is configured to calculate the following "edgeMajority" indicator for each of the nodes v belonging to the subgroup of no interest:

[0071] With :

[0072] E(v), a vector representing the set of arcs connected to node v

[0073] E(v) \ Ebad, a representative ratio of all arcs connected to node v and which have not been deleted.

[0074] If the result of the "edgeMajority" indicator is greater than a fixed threshold (0.5, for example), the node in question is removed from the subgroup of no interest. Thus, after calculating the set of nodes v in the subgroup of no interest, the identification mechanism removes from the graph all the nodes that were not removed from the subgroup of no interest, as well as all the edges of the subgroup of no interest and the edges connected (to / from) said nodes that were not removed.

[0075] One of the advantages of the graph-based approach to representing users of the socio-transactional service discussed above lies in its ability to account for the social / relational dimension of interactions within the service through the integration of its topological and semantic characteristics. The characteristics associated with the nodes (representing users) and edges (representing interactions between users) of the graph are extracted as feature vectors. Comparisons are then performed as distance measurements between feature vectors, and user / interaction deletions involve pruning the graph by removing nodes and edges.

[0076] Once the group of fraudsters is identified, the identification system provides the service supervisor, via its human-machine interface, with information about the identified group in the form of a list of the individuals concerned or a graphical representation of the subgraph of interest. This allows the supervisor to know which ST service users are suspected of bank account fraud and to take appropriate action (escalating the information to a bank fraud expert, implementing informational and / or corrective measures, etc.).

[0077] The identification system then proceeds, in step E4 (labeled "MO_ACT" in the figure), to assign a label to one or more users within the identified group of fraudsters, for the purpose of implementing actions. This label assignment can be performed automatically based on at least one predefined assignment criterion in the algorithm, or manually by the service supervisor via their user interface. The users assigned a label form a subgroup of interest targeted by the following actions: sending an alert or information message to the terminals of users in the non-interest subgroup (users not identified as fraudsters) or, alternatively, to the terminals of all users of the ST service; and removing the users of the subgroup of interest from the ST service.

[0078] Thus, the identification system is configured to inform, or even alert, users of the ST service who are not identified as fraudsters, of the presence of fraudsters within their user group. Once groups of fraudsters are detected, the process also allows other users of the ST service to be informed. As an alternative or complement, the identification system is configured to block access to the ST service for the fraudster group. This step makes it possible to identify suspicious or abusive uses of the service in near real-time and to stop them as quickly as possible.

[0079] Other types of actions can of course be implemented depending on the application context and the type of interest group being targeted. For example, it is entirely possible, within the framework of this technique, to send an informational message to users of a transactional service, identified as target consumers of a given product, for marketing targeting purposes.

[0080] In the specific embodiment described here, the identification process is triggered upon receipt of a request to detect a group of interest, transmitted on an ad hoc basis by the ST service supervisor. This implementation allows the supervisor to identify groups of interest in real time (or near real time) from one or more reference groups previously identified and selected by the supervisor. Indeed, before transmitting the request, the supervisor may have previously conducted a field investigation and detected a new type of fraud or misuse of the service based on the collected data. This makes it possible to construct a query for detecting groups of interest relative not to a single reference group, but to several user reference groups.This makes it possible to identify if there are other user groups with similar characteristics, and possibly to discover if a new type of fraud is currently being committed and detectable from the data collected by the SG server.

[0081] As an alternative or complement, this query can be generated automatically and periodically to trigger the algorithm regularly, for example, once a day, once a week, or once a month, depending on the needs. The triggering frequency is predefined and known to the identification system. This implementation allows for regular monitoring of the emergence of new interest groups and continuous adaptation to changes in the structure of these groups. It also allows for adaptation to fraudsters' circumvention methods. Suspicious users and transactions are identified beforehand by a software process and referred to a fraud expert for classification (fraudulent / suspicious / legitimate). Confirmed cases, or those classified as such, can then constitute the reference groups to be considered by the algorithm.The supervisor saves the identified reference groups in the database and assigns an identifier to each group type. This allows for the identification of groups of interest relative to multiple types of reference groups simultaneously, thus optimizing the search for those groups.

[0082] Furthermore, in the specific embodiment described here, the feature association step (EO step) is implemented for each user of the ST service and for each interaction between users. Alternatively, such a feature association step is implemented for only a subset of the ST service users, for example, when a preliminary sorting is performed on all ST service users (sorting performed manually by the service supervisor or sorting performed by the device according to a predefined sorting criterion). This alternative approach, when applicable, speeds up calculations.

[0083] Figure 4 shows the simplified structure of an identification device 40 implementing the identification method according to the invention (for example the particular embodiment described above in relation to Figure 3).

[0084] In one particular implementation, this identification device is a computer and / or electronic device implemented within the management server itself. Alternatively, this identification device is a separate piece of equipment connected to the SG management server.

[0085] This identification device 40 comprises a random access memory 43 (for example, RAM), a processing unit 41, equipped for example with a processor, and controlled by a computer program stored in a read-only memory 42 (for example, ROM or a hard drive). At initialization, the code instructions of the computer program are, for example, loaded into the random access memory 43 before being executed by the processor of the processing unit 41. The processing unit 41 receives as input a REQ request to detect one (or more) group(s) of interest within a set of users of a given transactional service.The processor of processing unit 41 processes the content of the request and proceeds to identify the group of interest based on the pruning principle detailed above and generates as output INF information representative of the identified group of users of interest, an ALT alert message to user terminals and / or an EVC eviction request for users of the group of interest, according to the instructions of the computer program.

[0086] Figure 4 illustrates only one particular way, among several possible ways, of implementing the algorithm detailed above, in relation to Figure 3. Indeed, the technique of the invention can be implemented interchangeably:

[0087] - on a reprogrammable computing machine (a PC, a DSP processor, or a microcontroller) executing a program comprising a sequence of instructions, or

[0088] - on a dedicated computing machine (for example a set of logic gates such as an FPGA or an ASIC, or any other hardware module).

[0089] In the case where the invention is implemented on a reprogrammable computing machine, the corresponding program (i.e. the sequence of instructions) may be stored in a removable storage medium (such as, for example, a floppy disk, a CD-ROM or a DVD-ROM) or not, this storage medium being readable partially or totally by a computer or a processor.

Claims

DEMANDS 1. A method for identifying at least one subset of users, referred to as a group of interest, within a set of users of a transactional service via terminals (UT1-UT-n), said method being implemented in an identification device and comprising the steps of: receiving a detection request for said at least one group of interest relative to at least one reference group of users previously identified among the users of said set, deleting (E2) at least one user and / or an interaction, within the framework of said transactional service, between two users of said set, delivering a pruned set of users, said deleting taking into account at least one deletion rule and the result of a comparison of at least one characteristic associated with said at least one user and / or with said at least one interaction with at least one characteristic representative of said reference group,identification (E3) of said at least one interest group among the users of said pruned set.

2. Identification method according to claim 1 comprising a preliminary step, implemented for at least one user of a plurality of users of said set and / or for at least one interaction between two users of said plurality of users, of associating (EO) at least one characteristic to said at least one user and / or to said at least one interaction, delivering a plurality of characteristics associated with said at least one user and / or to said at least one interaction.

3. Identification method according to claim 1 or claim 2 wherein the deletion comprises: o for at least one user and at least one interaction between two users of a plurality of users of said set: ■ comparison (El) of at least one characteristic associated with at least one user or with at least one interaction with at least one characteristic representative of said reference group, providing a proximity distance, ■ when the proximity distance is greater than a predetermined threshold, selection (El) of said at least one user or of said at least one interaction and addition to a subgroup of no interest, o removal of said set, according to said at least one removal rule, of the users and interactions selected in the subgroup of no interest, delivering said pruned set.

4. Identification method according to claim 3, comprising the assignment (E4) of a label to at least one user of said identified interest group, forming a subgroup of interest, said label being representative of the implementation of an action belonging to the group comprising: the issuance of an alert or information message to the terminals of the users of said group or of said subgroup of non-interest; the eviction of said transactional service from the users of the subgroup of interest.

5. An identification method according to any one of claims 3 and 4, comprising the creation of a graph representing said user set, said graph comprising a plurality of nodes corresponding to said users of said transactional service and a plurality of edges corresponding to the interactions between said users, and wherein: said comparison (E1) comprises, for at least one node and at least one edge of said graph: o a measurement of a distance between a feature vector associated with said at least one node and / or said at least one edge and a feature vector associated with said reference group, yielding a proximity distance, o a comparison of said proximity distance yielded with a predetermined threshold, yielding a positive comparison result when said proximity distance is greater than said threshold, said deletion (E2) comprises a deletion according to said at least one deletion rule, of said graph,said at least one node and / or said at least one edge when said comparison result is positive, yielding a pruned graph, said identification (E3) includes the determination of at least one subgraph of interest in said pruned graph.

6. Identification method according to any one of claims 1 to 5, wherein the features associated with the users and interactions of said set belong to the group comprising: topological features, intrinsic features of said service, features calculated by learning.

7. Identification method according to claim 5, wherein said at least one deletion rule belongs to the group comprising: a so-called node rule, removing all users of said set present in the subgroup of no interest, a so-called arc rule, removing all interactions of said set present in the subgroup of no interest, a so-called simple rule, removing all users and interactions of said set present in the subgroup of no interest, a so-called arc majority rule, removing all users and interactions of said set present in the subgroup of no interest except the nodes having a ratio of neighbors absent from the subgroup of no interest greater than a predefined threshold.

8. A device for identifying at least one subset of users, referred to as a group of interest, within a set of users of a transactional service via terminals, said identification device comprising at least one processor configured to: receive a detection request for said at least one group of interest relative to at least one reference group of users previously identified among the users of said set; delete at least one user and / or an interaction, within the framework of said transactional service, between two users of said set, delivering a pruned set of users, said deletion taking into account at least one deletion rule and the result of a comparison of at least one characteristic associated with said at least one user and / or said at least one interaction with at least one characteristic representative of said reference group;identify at least one interest group among the users of said pruned set.

9. Product computer program, comprising program code instructions for implementing the method according to at least one of claims 1 to 7, when said program is executed on a computer.

10. A computer-readable and non-transient storage medium storing a computer program product according to claim 9.

Citation Information

Patent Citations

  • Fraudulent customer group identification method and device, terminal equipment and computer storage medium

    CN113592517A

  • Fraud community discovery method and device, equipment and storage medium

    CN114077709A