Risky transaction identification method and apparatus, electronic device, medium, and program product
By acquiring transaction information and basic information, and combining risk factors, team characteristics, and reasoning characteristics, transaction risk parameters are constructed. Risk judgment is then made using an identification model, which solves the problem of low accuracy in transaction risk judgment in existing technologies and achieves more accurate risk identification.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- CHINA UNIONPAY
- Filing Date
- 2025-09-22
- Publication Date
- 2026-05-21
AI Technical Summary
In existing technologies, the accuracy of transaction risk assessment is relatively low, mainly because the features are too simplistic and cannot comprehensively assess the risks of both parties in the transaction.
By acquiring transaction and basic information from both users and merchants, and combining this with risk factor characteristics, team characteristics, and reasoning characteristics, transaction risk parameters are constructed, and risk assessment is performed using an identification model.
It improves the accuracy of transaction risk assessment by providing more precise risk identification and prediction through multi-dimensional analysis of the risks of both parties in the transaction.
Smart Images

Figure CN2025122995_21052026_PF_FP_ABST
Abstract
Description
Risk transaction identification methods, devices, electronic equipment, media, and program products
[0001] Cross-references to related applications
[0002] This application claims priority to Chinese patent application CN202411651806.7, filed on November 18, 2024, entitled “Risk Transaction Identification Method, Apparatus, Electronic Device, Media and Program Product”, the entire contents of which are incorporated herein by reference. Technical Field
[0003] This application relates to the field of data processing, and more particularly to a method, apparatus, electronic device, medium, and program product for identifying risky transactions. Background Technology
[0004] With the development of internet technology, more and more users are trading online. However, online trading carries risks, such as malicious order manipulation and arbitrage.
[0005] In the exemplary technology, risk factors such as transaction time and transaction amount are obtained from the transaction information of both parties. The risk factors are matched with the corresponding historical profiles, and the existence of risks in the transaction is determined based on the historical profiles.
[0006] However, the aforementioned features used to determine whether a transaction is risky are too simplistic and have low accuracy in assessing transaction risk. Summary of the Invention
[0007] This application provides a risk transaction identification method, device, electronic device, medium, and program product, which solves the problem of low accuracy in judging transaction risks.
[0008] Firstly, this application provides a method for identifying risky transactions, the method comprising:
[0009] Obtain target transaction information between the user and the merchant, and obtain the first basic information of the merchant and the second basic information of the user;
[0010] Risk element characteristics are obtained based on the target transaction information, and team characteristics of the target group are determined based on the risk element characteristics, wherein the target group includes at least one of the user and the merchant.
[0011] The merchant's first inference feature is determined based on the first basic information, and the user's second inference feature is determined based on the second basic information.
[0012] Based on the risk element characteristics, the team characteristics, the first reasoning characteristics, and the second reasoning characteristics, the transaction risk parameters between the user and the merchant are determined, and based on the transaction risk parameters, it is determined whether there is a transaction risk between the user and the merchant.
[0013] In some embodiments, determining the team characteristics of the target group based on the risk factor characteristics includes:
[0014] Among the various risk element characteristics, the first characteristic of the user and the second characteristic of the merchant are determined;
[0015] The user feature vector of the user side is determined based on the first feature, and the merchant feature vector of the merchant side is determined based on the second feature.
[0016] Determine the first feature vector corresponding to the target similarity between the merchant feature vector and the user feature vector;
[0017] Based on the user feature vector, the merchant feature vector, and the first feature vector, a second feature vector is constructed, and clustering features are determined based on the second feature vector to serve as the team features corresponding to the target group.
[0018] In some embodiments, determining the first feature vector corresponding to the target similarity between the merchant feature vector and the user feature vector includes:
[0019] Determine the target similarity between the merchant feature vector and the user feature vector;
[0020] In response to the target similarity being less than a preset similarity, a first feature vector corresponding to the target similarity is constructed.
[0021] In some embodiments, determining clustering features based on the second feature vector includes:
[0022] The second feature vector is input into the clustering model to obtain the clustering features output by the clustering model.
[0023] In some embodiments, determining the merchant's first inference feature based on the first basic information and the user's second inference feature based on the second basic information includes:
[0024] The first identifier of the merchant is obtained based on the first basic information, and the second identifier of the user is obtained based on the second basic information;
[0025] Obtain the first knowledge fragment associated with the first identifier and the second knowledge fragment associated with the second identifier;
[0026] The merchant's first inference feature is determined based on the first knowledge fragment, and the user's second inference feature is determined based on the second knowledge fragment.
[0027] In some embodiments, determining the merchant's first inference feature based on the first knowledge fragment and determining the user's second inference feature based on the second knowledge fragment includes:
[0028] Among the various risk element characteristics, the first characteristic of the user and the second characteristic of the merchant are determined;
[0029] Obtain the risk scenarios corresponding to the target transaction information;
[0030] Based on the first feature, the second feature, the risk scenario, the team feature, the first knowledge fragment, and the second knowledge fragment, the first reasoning feature and the second reasoning feature are determined.
[0031] In some embodiments, determining the transaction risk parameters between the user and the merchant based on the risk factor characteristics, the team characteristics, the first inference characteristic, and the second inference characteristic includes:
[0032] Based on the risk element characteristics, the team characteristics, the first reasoning characteristic, and the second reasoning characteristic, a first combined characteristic is constructed;
[0033] The first combination of features is input into the recognition model to obtain the transaction risk parameters output by the recognition model.
[0034] In some embodiments, constructing a first combined feature based on the risk element feature, the team feature, the first inference feature, and the second inference feature includes:
[0035] Determine the importance parameter for each third feature, wherein each third feature includes the risk element feature, the team feature, the first inference feature, and the second inference feature;
[0036] Based on the importance parameter, a fourth feature is determined among each of the third features, wherein the fourth feature is a third feature whose importance parameter is greater than a preset threshold;
[0037] The first combined feature is obtained by concatenating the individual fourth features.
[0038] In some embodiments, before inputting the first combined features into the recognition model to obtain the transaction risk parameters output by the recognition model, the method further includes:
[0039] Multiple training samples are obtained, the training samples include a second combined feature and a risk label. The second combined feature is constructed based on risk element features, team features and reasoning features obtained from historical transaction information. The risk label is used to indicate whether there is transaction risk in the historical transaction information.
[0040] The recognition model is obtained by training the preset model based on each of the training samples.
[0041] Secondly, this application provides a risk transaction identification device, comprising:
[0042] The first acquisition module is used to acquire target transaction information between the user and the merchant, and to acquire the first basic information of the merchant and the second basic information of the user.
[0043] The second acquisition module is used to acquire risk element characteristics based on the target transaction information, and to determine the team characteristics of the target group based on the risk element characteristics, wherein the target group includes at least one of the user and the merchant.
[0044] The first determining module is used to determine the first inference feature of the merchant based on the first basic information, and the second inference feature of the user based on the second basic information;
[0045] The second determining module is used to determine the transaction risk parameters between the user and the merchant based on the risk element characteristics, the team characteristics, the first reasoning characteristics, and the second reasoning characteristics, and to determine whether there is a transaction risk between the user and the merchant based on the transaction risk parameters.
[0046] Thirdly, this application provides an electronic device, including: a processor, and a memory and a communication interface communicatively connected to the processor;
[0047] The communication interface is used to communicate with other communication devices;
[0048] The memory is used to store computer-executed instructions;
[0049] The processor is used to execute computer execution instructions stored in the memory to implement the risk transaction identification method provided in the first aspect.
[0050] Fourthly, this application provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, implement the risk transaction identification method provided in the first aspect.
[0051] Fifthly, this application provides a computer program product, including a computer program that, when executed by a processor, implements the risk transaction identification method as provided in the first aspect.
[0052] The risk transaction identification method, device, electronic device, medium, and program products provided in this application acquire transaction information and basic information between users and merchants, obtain risk element characteristics based on the transaction information, determine team characteristics of target groups based on the risk element characteristics, determine the first inference characteristics of users and the second inference characteristics of merchants through the basic information, and determine transaction risk parameters through risk element characteristics, team characteristics, first inference characteristics, and second inference characteristics, thereby determining whether there is transaction risk between the two parties based on the transaction risk parameters. In this application, the existence of transaction risk between the two parties is determined through multiple characteristics such as risk element characteristics, team characteristics, and inference characteristics, that is, the existence of transaction risk between the two parties is analyzed from multiple dimensions, which improves the accuracy of transaction risk judgment. Attached Figure Description
[0053] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.
[0054] Figure 1 is a schematic diagram of the scenarios involved in the risk transaction identification method of this application;
[0055] Figure 2 is a flowchart illustrating the steps of the risk transaction identification method provided in this embodiment of the application.
[0056] Figure 3 is a schematic flowchart of the risk transaction identification method provided in the embodiments of this application (II).
[0057] Figure 4 is a flowchart illustrating the steps of the risk transaction identification method provided in this embodiment of the application.
[0058] Figure 5 is a flowchart illustrating the steps of the risk transaction identification method provided in this embodiment of the application.
[0059] Figure 6 is a flowchart illustrating the steps of the risk transaction identification method provided in this embodiment of the application.
[0060] Figure 7 is a schematic diagram of the program modules of a risk transaction identification device provided in an embodiment of this application;
[0061] Figure 8 is a schematic diagram of the hardware structure of an electronic device provided in an embodiment of this application.
[0062] The accompanying drawings illustrate specific embodiments of this application, which will be described in more detail below. These drawings and descriptions are not intended to limit the scope of the concept in any way, but rather to illustrate the concept of this application to those skilled in the art through reference to particular embodiments. Detailed Implementation
[0063] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions in the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application. Furthermore, although the disclosure in this application is described according to one or several exemplary examples, it should be understood that each aspect of these disclosures can also constitute a complete implementation method on its own.
[0064] It should be noted that the brief descriptions of terms in this application are only for the convenience of understanding the embodiments described below, and are not intended to limit the embodiments of this application. Unless otherwise stated, these terms should be understood in their ordinary and common meaning.
[0065] The acquisition, storage, use, and processing of data (including but not limited to features and information mentioned in this document) in the technical solution of this application all comply with the relevant provisions of national laws and regulations.
[0066] Furthermore, the terms “comprising” and “having”, and any variations thereof, are intended to cover but not exclusively include, for example, a product or device that includes a series of components is not necessarily limited to those that are explicitly listed, but may include other components that are not explicitly listed or that are inherent to such product or device.
[0067] The term "module" as used in the embodiments of this application refers to any known or subsequently developed hardware, software, firmware, artificial intelligence, fuzzy logic, or combination of hardware and / or software code capable of performing the functions associated with that element.
[0068] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, use and processing of the relevant data must comply with relevant laws, regulations and standards, and corresponding operation entry points are provided for users to choose to authorize or refuse.
[0069] With the development of internet technology, more and more users are trading online. However, online trading carries risks, such as malicious order manipulation and arbitrage.
[0070] In the exemplary technology, risk factors such as transaction time and transaction amount are obtained from the transaction information of both parties. The risk factors are matched with the corresponding historical profiles, and the existence of risks in the transaction is determined based on the historical profiles.
[0071] However, the aforementioned features used to determine whether a transaction is risky are too simplistic and have low accuracy in assessing transaction risk.
[0072] Based on the aforementioned technical problems, the source of the technical concept for this application is as follows:
[0073] Based on real-time user marketing data, decision engines or model algorithms are used to identify and address risks or send them to marketing campaign organizers. This allows for confirmation of marketing risks from a business perspective, enabling early implementation of risk control measures. Marketing risk identification involves complex business scenarios, requiring a comprehensive assessment of the harm and impact of marketing activities by combining numerous characteristic data points such as campaign type, risk control strategies, whether it's a team effort, and historical violations.
[0074] The transaction business itself has a "two-way" characteristic, such as user-merchant and transfer initiator-recipient. By mining deeper feature information from each, and assessing their "consistency" by the degree of similarity between the two, it is helpful to judge the transaction risk.
[0075] The local profiling knowledge base contains knowledge from various sources, including basic user information, historical transactions, violation history, merchant profiles, and intelligence knowledge. The traditional approach involves converting profiling features into risk features, associating them with current traffic, and then inputting them into a classifier. This approach relies heavily on the experience of risk control personnel and suffers from problems such as a large workload in feature engineering, difficulty in identifying the importance of knowledge, and a low upper limit for feature dimensions. Large Language Model (LLM) technology excels in information extraction, summarization, and reasoning, and has gained increasing attention and application. However, general-purpose large models cannot meet actual business needs, mainly due to knowledge illusion, lack of professional knowledge, and data security issues. Retrieval-Augmented Generation (RAG) technology can dynamically retrieve information from external knowledge sources and use this retrieved data as a reference for answers. This greatly improves the accuracy and relevance of answers, effectively solving the problems of large language models.
[0076] Based on this, this application designs a scheme that combines risk element characteristics, team characteristics, and profile reasoning features to judge transaction risks, thereby achieving more accurate and interpretable risk identification and prediction.
[0077] Referring to Figure 1, which is a schematic diagram of an application scenario for the risk transaction identification method of this application, the risk transaction identification device 100 acquires target transaction information and basic information between the user and the merchant. Based on the target transaction information, it acquires risk element characteristics and determines the team characteristics of the target group through these risk element characteristics. The target group includes at least one of the user and the merchant. Based on the basic information, it determines the user's first inference characteristic and the merchant's second inference characteristic. Based on the risk element characteristics, team characteristics, first inference characteristic, and second inference characteristic, it determines the transaction risk parameters between the two parties. Based on these transaction risk parameters, it determines whether a transaction risk exists between the two parties. When the risk transaction identification device 100 determines that a transaction risk exists between the two parties, it outputs a prompt message indicating that the transaction is risky.
[0078] The technical solution shown in this application will be described in detail below with reference to Figure 1 and specific embodiments. It should be noted that the following embodiments may exist independently or in combination with each other, and the same or similar content will not be described again in different embodiments.
[0079] Referring to Figure 2, which is a flowchart illustrating the risk transaction identification method provided in this embodiment, the risk transaction identification method includes:
[0080] Step S201: Obtain the target transaction information between the user and the merchant, and obtain the first basic information of the merchant and the second basic information of the user.
[0081] In this embodiment, the executing entity is a risk transaction identification device. For ease of description, the term "device" will be used to refer to the risk transaction identification device below. The device can be a server or a terminal device equipped with risk transaction identification.
[0082] The device acquires transaction information between the user and the merchant, which is defined as the target transaction information. The two parties in the transaction information include the user selling the goods and the user buying the goods. The user selling the goods is defined as the merchant, and the user buying the goods is defined as the user.
[0083] After obtaining the target transaction information, the device then acquires the merchant's first basic information and the user's second basic information. The first basic information includes the merchant's ID, account, and device identifier; the second basic information includes the user's ID, account, and device identifier.
[0084] Step S202: Obtain risk element characteristics based on target transaction information, and determine the team characteristics of the target group based on the risk element characteristics. The target group includes at least one of the user side and the merchant side.
[0085] After obtaining the target transaction information, risk factor characteristics are extracted from it. For example, risk factor characteristics include, but are not limited to, user ID, merchant ID, transaction time, transaction amount, discount amount, merchant name, merchant number, merchant type, device type, and device risk. The risk factor characteristics are shown in the table below:
[0086] After obtaining the risk element characteristics, the device determines the team characteristics of the target group based on these characteristics. The target group includes at least one of the user and the merchant; that is, the target group is a group to which the user belongs, a group to which the merchant belongs, or a joint group of the merchant and the user. It is understood that the device determines the team characteristics of the user's group, the merchant's group, and / or the characteristics of the joint user-merchant group based on the risk element characteristics. For example, after obtaining the risk element characteristics, the device separates them into user characteristics and merchant characteristics. User characteristics include user account type, payment method, bank card type, payment amount, discount amount, device information, etc.; merchant characteristics include merchant name, location, type, size, etc. After obtaining the merchant characteristics, the device determines the characteristics matching the merchant characteristics as team characteristics, determines the characteristics matching the user characteristics as team characteristics, or determines the characteristics matching the user characteristics and product characteristics as team characteristics. For example, team characteristics refer to the characteristics of the group to which a merchant belongs. Based on the characteristics of each merchant, the device can determine that the merchant belongs to an individual user. Individual users have multiple characteristics, and these multiple characteristics of individual users are used as group characteristics. Another example is that team characteristics refer to the characteristics of the group to which a user belongs. Based on the characteristics of each user, the device can determine that the user belongs to group A. The device pre-stores the characteristics of group A, and these characteristics of group A are used as group characteristics. Furthermore, team characteristics refer to the characteristics of a group that includes both users and merchants. Based on user characteristics and merchant characteristics, the device determines that the user and merchant belong to a joint group of upstream supplier A and downstream application provider B, and uses the pre-stored characteristics of this joint group as group characteristics.
[0087] Step S203: Determine the merchant's first inference feature based on the first basic information, and determine the user's second inference feature based on the second basic information.
[0088] To accurately determine whether there is transaction risk between the user and the merchant, the device will further determine the reasoning characteristics of both parties. The merchant's reasoning characteristics are defined as the first reasoning characteristics, and the user's reasoning characteristics are defined as the second reasoning characteristics.
[0089] For example, the device obtains a first identifier of the merchant from the first basic information and a second identifier of the user from the second basic information. The device obtains historical transaction information associated with the first identifier from the database, and obtains existing risk characteristics as first inference characteristics by reasoning and analyzing the historical transaction information. For example, after analyzing the historical information, it is found that the merchant has engaged in malicious order-brushing behavior, and the malicious order-brushing behavior is the first inference characteristic. The device obtains historical transaction information associated with the second identifier from the database, and obtains risk characteristics of the user as first inference characteristics by analyzing and reasoning the historical transaction information associated with the second identifier. For example, the user frequently receives consumer vouchers, which constitutes arbitrage behavior, and the arbitrage behavior is the second inference characteristic.
[0090] Step S204: Based on the risk element characteristics, team characteristics, first inference characteristics, and second inference characteristics, determine the transaction risk parameters between the user and the merchant, and determine whether there is a transaction risk between the user and the merchant based on the transaction risk parameters.
[0091] After the first inference feature and the second inference feature, the device determines the transaction risk parameters between the user and the merchant based on the risk element feature, team feature, the first inference feature and the second inference feature.
[0092] For example, risk element characteristics, team characteristics, first inference characteristics, and second inference characteristics are input into the identification model, and the identification model outputs risk transaction parameters. Risk transaction parameters can be labels or scores.
[0093] After obtaining transaction risk parameters, the device can determine whether there is a transaction risk between the user and the merchant. In one example, the transaction risk parameter is a label; if the label indicates a risky transaction, then it is determined that there is a transaction risk between the user and the merchant. In another example, the risk transaction parameter is a score; if the score is greater than or equal to a preset score, it is determined that there is a transaction risk between the user and the merchant; if the score is less than the preset score, it is determined that there is no transaction risk between the user and the merchant.
[0094] When the device determines that there is no transaction risk between the user and the merchant, it outputs a prompt message. This message includes, but is not limited to, the risk level, risk score, source of risk, and risk type. The risk score is the transaction risk parameter used to assign a value; the higher the score, the higher the risk level. Sources of risk include, for example, abnormal transaction patterns or unusual merchant behavior. The risk type is a transaction risk parameter used as a label; risk types include fraud risk, credit risk, etc.
[0095] In this embodiment, transaction information and basic information between the user and the merchant are obtained. Risk element characteristics are acquired based on the transaction information, and team characteristics of the target group are determined based on these risk element characteristics. First inference characteristics of the user and second inference characteristics of the merchant are determined using the basic information. Transaction risk parameters are then determined using the risk element characteristics, team characteristics, first inference characteristics, and second inference characteristics. Based on these parameters, it is determined whether there is transaction risk between the two parties. This application uses multiple characteristics, such as risk element characteristics, team characteristics, and inference characteristics, to determine whether there is transaction risk between the two parties. This multi-dimensional analysis improves the accuracy of transaction risk assessment.
[0096] Referring to Figure 3, which is a flowchart of the risk transaction identification method of this application, based on the embodiment shown in Figure 2, step S202 includes:
[0097] Step S301: Among the various risk factor characteristics, determine the first characteristic of the user and the second characteristic of the merchant.
[0098] In this embodiment, the device uses the user's characteristics as the first characteristic among the various risk factor characteristics, and determines the merchant's characteristics as the second characteristic. The first characteristic includes user account type, payment method, bank card type, payment amount, discount amount, device information, etc.; the second characteristic includes merchant's name, location, type, scale, etc.
[0099] Step S302: Determine the user feature vector of the user side based on the first feature, and determine the merchant feature vector of the merchant side based on the second feature.
[0100] After determining the first feature and the second feature, the device determines the feature vector corresponding to the user as the user feature vector based on the first feature, and determines the feature vector of the merchant as the merchant feature vector based on the second feature.
[0101] For example, the device first processes the first and second features, including standardization and normalization of numerical features, categorical feature encoding, handling of missing values, and outlier detection and processing. The processed first and second features are then input into a dual-tower model. The dual-tower model includes a user tower and a merchant tower. The dual-tower model uses a multilayer perceptron neural network to process the first feature input to the user tower and the second feature input to the merchant tower. Each layer of the network structure includes a linear layer and an activation function, and batch normalization and Dropout can be added to the network structure to enhance the model's generalization ability. The dual-tower model is optimized through supervised learning, with the loss function typically being cross-entropy loss, aiming to maximize the receiver operating characteristic curve (ROC) on the validation set. During training, a mini-batch gradient descent optimization algorithm can be used to accelerate convergence and avoid local optima. The hyperparameters of the dual-tower model (such as learning rate, hidden layer size, Dropout ratio, etc.) can be tuned using methods such as grid search or random search. Once the multilayer neural network model has converged and the ROC curve meets the criteria, the training is complete, and the dual-tower model is obtained. In the dual-tower model, the output of the feature layer of the last layer of the user tower is used as the user feature vector, and the output of the feature layer of the last layer of the merchant tower is used as the merchant feature vector.
[0102] Step S303: Determine the first feature vector corresponding to the target similarity between the merchant feature vector and the user feature vector.
[0103] After obtaining the user feature vector and the merchant feature vector, the similarity between the merchant feature vector and the user feature vector is determined as the target similarity. The target similarity can be calculated using the cosine similarity algorithm on the user feature vector and the merchant feature vector. After obtaining the target similarity, the target similarity is encoded to obtain the feature vector corresponding to the target similarity, which is used as the first feature vector.
[0104] Furthermore, the lower the similarity between the user and the merchant, the greater the feature differences on both sides of the surface double-tower, indicating abnormal transactions or fraudulent behavior. For example, if a user suddenly makes a large discount transaction with a merchant they have never transacted with before at an abnormal time, this behavior will have a low similarity in the feature space. To address this, the device first determines the target similarity between the merchant's feature vector and the user's feature vector. When the target similarity is less than a preset similarity, it can be determined that the transaction may be risky. Therefore, a first feature vector corresponding to the target similarity is constructed. Based on the first feature vector, team characteristics are determined, and then the existence of transaction risk is determined based on team characteristics, risk element characteristics, first inference characteristics, and second inference characteristics. When the target similarity is greater than or equal to the preset similarity, it can be determined that the transaction is not risky. In this case, it is not necessary to construct the first feature vector corresponding to the target similarity, and the target transaction information is marked as a risk-free transaction.
[0105] Step S304: Construct a second feature vector based on the user feature vector, merchant feature vector, and first feature vector, and determine clustering features based on the second feature vector as team features corresponding to the target group.
[0106] After obtaining the first feature vector, the device constructs a second feature vector based on the user feature vector, the merchant feature vector, and the first feature vector. For example, the second feature vector can be obtained by concatenating the user feature vector, the merchant feature vector, and the first feature vector.
[0107] In one example, after obtaining the second feature vector, the device uses it as a data point and clusters it with existing feature points to obtain multiple clusters of data points. The device then determines the label, size, and internal variance of each cluster. The label refers to the category to which the cluster belongs, the size refers to the number of data points in the cluster, and the internal variance refers to the dispersion of the data points in the cluster. The label can be defined as a class label; therefore, the size can also be defined as the class size, and the internal variance is defined as the intra-class variance. The class label, class size, and intra-class variance of the cluster containing the second feature vector constitute the team feature. The second feature vector and each existing data point can be obtained through a clustering algorithm. Specifically, the clusters are first obtained based on the clustering algorithm, the number of data points in each cluster is the class size, and the intra-class variance can be calculated based on each data point in the cluster. Then, the optimal value of K is determined based on the silhouette coefficient, and finally, the class label corresponding to each data point is determined based on K. K refers to the number of clusters. The method for calculating the silhouette coefficient is as follows:
[0108] For a data point i, first calculate the average distance a between it and other data points in the cluster. i (Intra-cluster similarity). Then calculate the average distance b between this point and other intra-cluster data points that are not in the cluster containing this point. i (Inter-cluster similarity) is calculated, selecting the cluster with the smallest distance as the average inter-cluster distance for data point i. The silhouette coefficient of data point i is then calculated. Finally, K can be obtained based on the mapping relationship between the profile coefficient and K.
[0109] In another example, the second feature vector is input into the clustering model, and the clustering features output by the clustering model are used as team features. That is, the model determines the cluster to which the second feature vector belongs, the class size of the cluster, the class label, and the intra-class variance.
[0110] It should be noted that clustering models can be trained using unsupervised clustering learning. Considering the potential error perturbations introduced by unsupervised clustering learning, it is necessary to name the class labels based on the instances (transaction time, amount, device, and merchant consistency), and simultaneously verify the reliability of the clusters. For clusters with weak reliability, the importance of features needs to be reduced, and enhanced verification methods such as facial recognition and SMS verification should be prioritized.
[0111] In this embodiment, the device classifies the risk factor characteristics to obtain the first characteristic of the user and the second characteristic of the merchant, thereby accurately determining the team characteristics of the group to which the merchant belongs based on the first and second characteristics.
[0112] Referring to Figure 4, which is a flowchart of the risk transaction identification method of this application, based on the embodiment shown in Figure 2 or 3, step S203 includes:
[0113] Step S401: Obtain the first identifier of the merchant based on the first basic information, and obtain the second identifier of the user based on the second basic information.
[0114] In this embodiment, the device obtains the merchant's identifier from the first basic information and defines it as the first identifier, and obtains the user's identifier from the second basic information as the second identifier.
[0115] Step S402: Obtain the first knowledge fragment associated with the first identifier and the second knowledge fragment associated with the second identifier.
[0116] The device communication connection includes a local knowledge base, which contains knowledge from various sources such as basic user information, historical transactions, violation history, merchant profiles, intelligence knowledge, and activity rules. This knowledge information can be segmented into sub-knowledge information according to identifier dimensions. Identifier dimensions include, for example, account (phone number, user ID, identity identifier), merchant, device, team, and activity dimensions. Sub-indicator fragments are vectorized to obtain knowledge fragments for storage, and these knowledge fragments are associated with their corresponding identifier dimensions for storage. Knowledge fragments can serve as profile features; examples of knowledge fragments are shown in the table below.
[0117] After obtaining the first identifier and the second identifier, the device performs a data retrieval in the local knowledge base based on the first identifier and the second identifier, obtains the knowledge fragment associated with the first identifier as the first knowledge fragment, and obtains the knowledge fragment associated with the second identifier as the second knowledge fragment.
[0118] Step S403: Determine the merchant's first inference feature based on the first knowledge fragment, and determine the user's second inference feature based on the second knowledge fragment.
[0119] After determining the first knowledge fragment and the second knowledge fragment, the merchant's first reasoning feature is determined based on the first knowledge fragment, and the user's second reasoning feature is determined based on the second knowledge fragment.
[0120] For example, the first inference feature and the second inference feature are as follows:
[0121] Among them, the inference features corresponding to accounts, devices, and activities are the second inference features of the user side, while teams and merchants are the first inference features of the merchant side.
[0122] In this embodiment, knowledge fragments are retrieved based on the first basic information and the second basic information, and inference features are obtained based on the knowledge fragments. Then, based on the inference features, it is accurately determined whether there is a transaction risk between the two parties.
[0123] Referring to Figure 5, which is a flowchart of the risk transaction identification method of this application, based on the embodiment shown in Figure 4, step S403 includes:
[0124] Step S501: Among the various risk factor characteristics, determine the first characteristic of the user and the second characteristic of the merchant.
[0125] In this embodiment, the device determines the first characteristic of the user and the second characteristic of the merchant among the risk factor characteristics.
[0126] The first feature includes user account type, payment method, bank card type, payment amount, discount amount, device information, etc.; the second feature includes merchant name, location, type, scale, etc.
[0127] Step S502: Obtain the risk scenario corresponding to the target transaction information.
[0128] Step S503: Determine the first reasoning feature and the second reasoning feature based on the first feature, the second feature, the risk scenario, the team features, the first knowledge fragment, and the second knowledge fragment.
[0129] After determining the first and second features, the device identifies the risk scenario corresponding to the target transaction information. The risk scenario is a scenario where the current transaction may face risks. Examples of risk scenarios include anti-fraud scenarios and telecommunications fraud scenarios.
[0130] The device obtains a transaction identifier from the target transaction information, and the scenario associated with the transaction identifier is designated as a risk scenario.
[0131] The device determines the first reasoning feature and the second reasoning feature based on the first feature, the second feature, the risk scenario, the team feature, the first knowledge fragment, and the second reasoning feature.
[0132] For example, by inputting the first feature, the second feature, the risk scenario, the team feature, the first knowledge fragment, and the second inference feature into the large language model, the first inference feature and the second inference feature output by the large language model can be obtained. The large language model is trained on samples in the training set. The samples include features corresponding to the inferred text, and the inference position is, for example, the text corresponding to the inference feature described below. In addition, the samples also include risk element features of the user side and the merchant side in historical transaction information, risk scenarios corresponding to historical transaction information, knowledge fragments associated with the user's identifier, and knowledge fragments associated with the merchant side.
[0133] The first and second inference features obtained using the above method are as follows:
[0134] The inference features corresponding to multi-dimensional 1, multi-dimensional 2, multi-dimensional 3, multi-dimensional 4, multi-dimensional 5, and multi-dimensional 7 can be the first inference feature corresponding to the user, while multi-dimensional 6 is the second inference feature corresponding to the merchant.
[0135] It should be noted that since the inference features are obtained through multiple features, the first and second inference features mentioned above do not need to be distinguished as belonging to the user or the merchant.
[0136] In this embodiment, the device combines multiple features to summarize risk factors, thereby obtaining more accurate reasoning features and improving the accuracy of transaction risk identification.
[0137] Referring to Figure 6, which is a flowchart of the risk transaction identification method of this application, based on any of the embodiments shown in Figures 2 to 5, step S204 includes:
[0138] Step S601: Construct the first combined features based on the risk element characteristics, team characteristics, first reasoning characteristics, and second reasoning characteristics.
[0139] In this embodiment, the device constructs a first combined feature based on risk element features, team features, a first reasoning feature, and a second reasoning feature.
[0140] In one example, the first combined feature is obtained by combining the risk element feature, team feature, first reasoning feature, and second reasoning feature.
[0141] In another example, there are too many features to combine, requiring the removal of less important features. To address this, the device determines the importance parameter for each third feature, which includes the aforementioned risk element feature, team feature, first inference feature, and second inference feature. The device can determine the importance parameter of the third feature using methods such as random forests or regularization, or it can obtain the corresponding importance parameter based on the type of the third feature. The importance parameter corresponding to the type is manually set, and the higher the importance parameter, the more important the feature. Based on the importance parameter, the device determines the fourth feature from among the third features; the fourth feature is the third feature whose importance parameter is greater than a preset threshold. The device then concatenates the various fourth features to obtain the first combined feature.
[0142] Step S602: Input the first combination of features into the recognition model to obtain the transaction risk parameters output by the recognition model.
[0143] After obtaining the first combination of features, the device inputs the first combination of features into the recognition model, and the parameters output by the recognition model are the transaction risk parameters.
[0144] The identification model can be obtained through training. For example, the device acquires multiple training samples, which include a second set of combined features and risk labels. The second set of combined features is constructed based on risk element features, team features, and reasoning features obtained from historical transaction information. The risk labels are used to indicate whether there is transaction risk in the historical transaction information. The device can obtain the identification model by training a preset model based on each training sample; the preset model can be a regression model.
[0145] In this embodiment, combined features are obtained by concatenating risk element features, team features, first reasoning features, and second reasoning features. These combined features are then input into the recognition model to obtain accurate risk transaction parameters.
[0146] Based on the content described in the above embodiments, this application also provides a risk transaction identification device. Referring to Figure 7, which is a schematic diagram of the program modules of a risk transaction identification device provided in this application, in some embodiments, the risk transaction identification device 700 includes:
[0147] The first acquisition module 710 is used to acquire target transaction information between the user and the merchant, and to acquire the merchant's first basic information and the user's second basic information.
[0148] The second acquisition module 720 is used to acquire risk element characteristics based on the target transaction information and determine the team characteristics of the target group based on the risk element characteristics. The target group includes at least one of the user side and the merchant side.
[0149] The first determining module 730 is used to determine the first inference feature of the merchant based on the first basic information, and the second inference feature of the user based on the second basic information.
[0150] The second determining module 740 is used to determine the transaction risk parameters between the user and the merchant based on the risk element characteristics, team characteristics, first reasoning characteristics and second reasoning characteristics, and to determine whether there is a transaction risk between the user and the merchant based on the transaction risk parameters.
[0151] In some embodiments, the risk transaction identification device 700 is specifically used for:
[0152] Among the characteristics of each risk element, the first characteristic of the user and the second characteristic of the merchant are determined.
[0153] The user feature vector is determined based on the first feature, and the merchant feature vector is determined based on the second feature.
[0154] Determine the first feature vector corresponding to the target similarity between the merchant feature vector and the user feature vector;
[0155] Based on the user feature vector, merchant feature vector, and first feature vector, a second feature vector is constructed, and clustering features are determined based on the second feature vector to serve as the team features corresponding to the target group.
[0156] In some embodiments, the risk transaction identification device 700 is specifically used for:
[0157] Determine the target similarity between merchant feature vectors and user feature vectors;
[0158] In response to a target similarity less than a preset similarity, a first feature vector corresponding to the target similarity is constructed.
[0159] In some embodiments, the risk transaction identification device 700 is specifically used for:
[0160] The second feature vector is input into the clustering model to obtain the clustering features output by the clustering model.
[0161] In some embodiments, the risk transaction identification device 700 is specifically used for:
[0162] The merchant's first identifier is obtained based on the first basic information, and the user's second identifier is obtained based on the second basic information.
[0163] Obtain the first knowledge fragment associated with the first identifier and the second knowledge fragment associated with the second identifier;
[0164] The first inference feature of the merchant is determined based on the first knowledge fragment, and the second inference feature of the user is determined based on the second knowledge fragment.
[0165] In some embodiments, the risk transaction identification device 700 is specifically used for:
[0166] Among the characteristics of each risk element, the first characteristic of the user and the second characteristic of the merchant are determined.
[0167] Obtain the risk scenarios corresponding to the target transaction information;
[0168] Based on the first feature, the second feature, the risk scenario, the team characteristics, the first knowledge fragment, and the second knowledge fragment, determine the first reasoning feature and the second reasoning feature.
[0169] In some embodiments, the risk transaction identification device 700 is specifically used for:
[0170] Based on the characteristics of risk elements, team characteristics, first reasoning characteristics, and second reasoning characteristics, construct the first combination characteristics;
[0171] The first set of features is input into the recognition model to obtain the transaction risk parameters output by the recognition model.
[0172] In some embodiments, the risk transaction identification device 700 is specifically used for:
[0173] Determine the importance parameters for each third feature, which includes risk element features, team features, first inference features, and second inference features;
[0174] Based on the importance parameter, a fourth feature is determined among the various third features. The fourth feature is the third feature whose importance parameter is greater than a preset threshold.
[0175] The individual fourth features are concatenated to obtain the first combined feature.
[0176] In some embodiments, the risk transaction identification device 700 is specifically used for:
[0177] Multiple training samples are obtained, including a second combination of features and risk labels. The second combination of features is constructed based on risk element features, team features, and inference features obtained from historical transaction information. The risk labels are used to indicate whether there are transaction risks in historical transaction information.
[0178] The recognition model is obtained by training the preset model based on each training sample.
[0179] It should be noted that the specific steps of the risk transaction identification method executed by the risk transaction identification device are as described in the above embodiments, and will not be repeated here.
[0180] Furthermore, based on the content described in the above embodiments, this application also provides an electronic device, which includes at least one processor, a communication interface and a memory connected to the processor; wherein the communication interface is used to communicate with other communication devices, and the memory stores computer execution instructions; the at least one processor executes the computer execution instructions stored in the memory to implement the various steps in the risk transaction identification method described in the above embodiments.
[0181] To better understand the embodiments of this application, please refer to FIG8, which is a schematic diagram of the hardware structure of an electronic device provided in an embodiment of this application.
[0182] As shown in Figure 8, the electronic device 800 of this embodiment includes: a processor 801, a memory 802, and a communication interface 804; wherein:
[0183] Memory 802 is used to store instructions executed by the computer;
[0184] Communication interface 804 is used to communicate with other communication devices;
[0185] The processor 801 is configured to execute computer execution instructions stored in memory to implement the various steps in the query optimization method described in the above embodiments.
[0186] Alternatively, the memory 802 can be either standalone or integrated with the processor 801.
[0187] When the memory 802 is set up independently, the device also includes a bus 803 for connecting the memory 802, the communication interface 804, and the processor 801.
[0188] This application provides a computer-readable storage medium storing computer-executable instructions. When a processor executes the computer-executable instructions, it implements the various steps of the risk transaction identification method described in the above embodiments.
[0189] This application provides a computer program product, including a computer program that, when executed by a processor, implements the various steps of the risk transaction identification method described in the above embodiments.
[0190] In the several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative; for instance, the division of modules is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple modules may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be indirect coupling or communication connection through some interfaces, devices, or modules, and may be electrical, mechanical, or other forms.
[0191] The modules described as separate components may or may not be physically separate. The components shown as modules may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs.
[0192] Furthermore, the functional modules in the various embodiments of this application can be integrated into one processing unit, or each module can exist physically separately, or two or more modules can be integrated into one unit. The unit composed of the above modules can be implemented in hardware or in the form of hardware plus software functional units.
[0193] The integrated modules described above, implemented as software functional modules, can be stored in a computer-readable storage medium. These software functional modules, stored in a storage medium, include several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) or processor to execute some steps of the methods of the various embodiments of this application.
[0194] It should be understood that the aforementioned processor can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), etc. A general-purpose processor can be a microprocessor or any conventional processor. The steps of the method disclosed in the application can be directly manifested as being executed by a hardware processor, or executed by a combination of hardware and software modules within the processor.
[0195] The memory may include high-speed memory, and may also include non-volatile memory, such as at least one disk storage device, and may also be a USB flash drive, portable hard drive, read-only memory, disk or optical disc, etc.
[0196] The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. Buses can be categorized as address buses, data buses, control buses, etc. For ease of illustration, the buses shown in the accompanying drawings are not limited to a single bus or a single type of bus.
[0197] The aforementioned storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory, electrically erasable programmable read-only memory, erasable programmable read-only memory, programmable read-only memory, read-only memory, magnetic storage, flash memory, magnetic disk, or optical disk. The storage medium can be any available medium that can be accessed by a general-purpose or special-purpose computer.
[0198] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some or all of the technical features therein. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of this application.
Claims
1. A method for identifying risky transactions, comprising: Obtain target transaction information between the user and the merchant, and obtain the first basic information of the merchant and the second basic information of the user; Risk element characteristics are obtained based on the target transaction information, and team characteristics of the target group are determined based on the risk element characteristics, wherein the target group includes at least one of the user and the merchant. The merchant's first inference feature is determined based on the first basic information, and the user's second inference feature is determined based on the second basic information. Based on the risk element characteristics, the team characteristics, the first reasoning characteristics, and the second reasoning characteristics, the transaction risk parameters between the user and the merchant are determined, and based on the transaction risk parameters, it is determined whether there is a transaction risk between the user and the merchant.
2. The method of identifying risky transactions according to claim 1, wherein, The process of determining the team characteristics of the target group based on the risk factor characteristics includes: Among the various risk element characteristics, the first characteristic of the user and the second characteristic of the merchant are determined; The user feature vector of the user side is determined based on the first feature, and the merchant feature vector of the merchant side is determined based on the second feature. Determine the first feature vector corresponding to the target similarity between the merchant feature vector and the user feature vector; Based on the user feature vector, the merchant feature vector, and the first feature vector, a second feature vector is constructed, and clustering features are determined based on the second feature vector to serve as the team features corresponding to the target group.
3. The method of identifying risky transactions according to claim 2, wherein, The step of determining the first feature vector corresponding to the target similarity between the merchant feature vector and the user feature vector includes: Determine the target similarity between the merchant feature vector and the user feature vector; In response to the target similarity being less than a preset similarity, a first feature vector corresponding to the target similarity is constructed.
4. The method of identifying risky transactions according to claim 2, wherein, The step of determining clustering features based on the second feature vector includes: The second feature vector is input into the clustering model to obtain the clustering features output by the clustering model.
5. The method of identifying risky transactions according to claim 1, wherein, The step of determining the merchant's first inference feature based on the first basic information and the user's second inference feature based on the second basic information includes: The first identifier of the merchant is obtained based on the first basic information, and the second identifier of the user is obtained based on the second basic information; Obtain the first knowledge fragment associated with the first identifier and the second knowledge fragment associated with the second identifier; The merchant's first inference feature is determined based on the first knowledge fragment, and the user's second inference feature is determined based on the second knowledge fragment.
6. The method of identifying risky transactions according to claim 5, wherein, The step of determining the merchant's first inference feature based on the first knowledge fragment and determining the user's second inference feature based on the second knowledge fragment includes: Among the various risk element characteristics, the first characteristic of the user and the second characteristic of the merchant are determined; Obtain the risk scenarios corresponding to the target transaction information; Based on the first feature, the second feature, the risk scenario, the team feature, the first knowledge fragment, and the second knowledge fragment, the first reasoning feature and the second reasoning feature are determined.
7. The method of identifying risky transactions according to claim 1, wherein, The step of determining the transaction risk parameters between the user and the merchant based on the risk factor characteristics, the team characteristics, the first inference characteristic, and the second inference characteristic includes: Based on the risk element characteristics, the team characteristics, the first reasoning characteristic, and the second reasoning characteristic, a first combined characteristic is constructed; The first combination of features is input into the recognition model to obtain the transaction risk parameters output by the recognition model.
8. The method of identifying risky transactions according to claim 7, wherein, The construction of the first combined feature based on the risk element characteristics, the team characteristics, the first reasoning feature, and the second reasoning feature includes: Determine the importance parameter for each third feature, wherein each third feature includes the risk element feature, the team feature, the first inference feature, and the second inference feature; Based on the importance parameter, a fourth feature is determined among each of the third features, wherein the fourth feature is a third feature whose importance parameter is greater than a preset threshold; The first combined feature is obtained by concatenating the individual fourth features.
9. The method of identifying risky transactions according to claim 7, wherein, Before inputting the first combined features into the recognition model to obtain the transaction risk parameters output by the recognition model, the method further includes: Multiple training samples are obtained, the training samples include a second combined feature and a risk label. The second combined feature is constructed based on risk element features, team features and reasoning features obtained from historical transaction information. The risk label is used to indicate whether there is transaction risk in the historical transaction information. The recognition model is obtained by training the preset model based on each of the training samples.
10. A risk transaction identification device, comprising: The first acquisition module is used to acquire target transaction information between the user and the merchant, and to acquire the first basic information of the merchant and the second basic information of the user. The second acquisition module is used to acquire risk element characteristics based on the target transaction information, and to determine the team characteristics of the target group based on the risk element characteristics, wherein the target group includes at least one of the user and the merchant. The first determining module is used to determine the first inference feature of the merchant based on the first basic information, and the second inference feature of the user based on the second basic information; The second determining module is used to determine the transaction risk parameters between the user and the merchant based on the risk element characteristics, the team characteristics, the first reasoning characteristics, and the second reasoning characteristics, and to determine whether there is a transaction risk between the user and the merchant based on the transaction risk parameters.
11. An electronic device comprising: A processor, and a memory and a communication interface communicatively connected to the processor; The communication interface is used to communicate with other communication devices; The memory is used to store computer-executed instructions; The processor is used to execute computer execution instructions stored in the memory to implement the risk transaction identification method as described in any one of claims 1-9.
12. A computer readable storage medium, having stored therein computer-executable instructions that, when executed by a processor, implement the method of identifying risky transactions according to any one of claims 1-9.
13. A computer program product comprising a computer program, characterized in that, The computer program, when executed by a processor, implements the method of identifying risky transactions according to any one of claims 1-9.