Access control using temporal neural attributes for time series data

WO2026206958A1PCT designated stage Publication Date: 2026-10-01EQUIFAX INC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/US2026/020559
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2025-03-24
Filing Date
2026-03-24
Publication Date
2026-10-01

Smart Images

  • Figure US2026020559_01102026_PF_FP_ABST
    Figure US2026020559_01102026_PF_FP_ABST
Patent Text Reader

Abstract

A method can include receiving time-series data that includes information about interactions involving an entity. The method can include aggregating, using a first model, the time-series data to generate aggregated data based on the interactions. The method can include generating, using a second model, temporal neural attributes (TNAs) based on the aggregated data. The method can include generating, using a third model, an access indicator by using the TNAs as input to the third model. The method can include outputting a command with instructions executable to control access to an interactive computing environment based on the access indicator.
Need to check novelty before this filing date? Find Prior Art

Description

Attorney Docket No. 096923-1548510 (EFX-213WO)ACCESS CONTROL USING TEMPORAL NEURAL ATTRIBUTES FOR TIME SERIES DATACross-Reference To Related Applications

[0001] This claims the benefit of U.S. Provisional Patent Application No. 63 / 776,600, filed March 24, 2025, and titled “ACCESS CONTROL USING RECURRENT NEURAL ATTRIBUTES FOR TIME SERIES DATA,” the entire disclosure of which is incorporated by reference herein in its entirety.Technical Field

[0002] The present disclosure relates generally to risk assessment and interaction control. More specifically, but not by way of limitation, this disclosure relates to access control using temporal neural attributes.Background

[0003] Various interactions are performed frequently through an interactive computing environment such as a website, a user interface, etc. The interactions may involve transferring resources for, or otherwise based on, content or goods that can be provided via the interactive computing environment. In some cases, malicious entities may interfere with legitimate interactions, may attempt to initiate illegitimate interactions, and so on. Additionally, computing environments may receive a large volume of access requests, and it may be difficult to determine whether each request is legitimate or safe. Determining whether access requests, interactions, and the like are legitimate, safe, or a combination thereof can be difficult.Summary

[0004] Aspects of the disclosed technology can include any combination of the features described herein. For example, a method can include receiving, by a processor, time-series data relating to an entity. The time-series data can include a set of different time-series information about a set of interactions involving the entity. The method can include aggregating, by the processor and using a first model, the set of different time-series information to generate aggregated data based on the set of interactions. The method can include generating, by the processor and using a second model, a set of temporal neural attributes (TNAs) based on the aggregated data. The method can include generating, by the processor and using a third model, an access indicator by using the set of TNAs as input to the third model. The method caninclude outputting, by the processor, a command comprising instructions executable to control access to an interactive computing environment based on the access indicator.

[0005] In some examples, the first model can include a transformer model, the second model can be the same model as the first model, and the transformer model can include instructions executable to cause the transformer model to aggregate the time-series data and to generate the set of TNAs. Aggregating the set of different time-series information can include (i) grouping sub-interactions indicated by the times-series data into interaction groups based on interaction type per archive and (ii) generating a time-series value that represents the interaction groups per archive.

[0006] In some examples, the first model can include an aggregator model, the second model can include a set of long short-term memory (LSTM) networks, and each LSTM network of the set of LSTM networks can include different instructions to cause the LSTM network to generate a different TNA of the set of TNAs.

[0007] In some examples, the set of interactions can have a set of different interaction types. Aggregating the time-series data can include (i) generating a first grouping of data and a second grouping of data from the time-series data in which the first grouping of data includes data from a first type of interaction of the different interaction types and in which the second grouping of data includes data from a second type of interaction of the different interaction types, (ii) generating, for the first interaction type, a first counter attribute that tracks a first total number of interactions of the set of interactions of the first interaction type at a particular point in time, and (iii) generating, for the second interaction type, a second counter attribute that tracks a second total number of interactions of the set of interactions of the second interaction type at the particular point in time.

[0008] In some examples, the first counter attribute can include a set of individual counter attributes. Each individual counter attribute of the set of individual counter attributes can correspond with a different time period.

[0009] In some examples, aggregating the time-series data can additionally include generating an aggregated interaction type attribute by aggregating versions of interaction attributes across interactions of a corresponding interaction type for each time period in the time-series data.

[0010] In some examples, the second model can include a set of individual networks. Additionally or alternatively, generating the set of TNAs can include, for each network in the set of individual networks, generating an output using a dense output layer. The output can include a single scalar value or a vector embedding, and the output can include a TNA of theset of TNAs that represents temporal information from corresponding data of the time-series data.

[0011] In some examples, generating the set of TNAs can additionally include generating a feature vector by concatenating each TNA of the set of TNAs and a set of entity-specific attributes. The feature vector can correspond with the entity, and the input into the third model can include the feature vector.

[0012] This summary is not intended to identify key or essential features of the claimed subject matter, nor is it intended to be used in isolation to determine the scope of the claimed subject matter. The subject matter should be understood by reference to appropriate portions of the entire specification, any or all drawings, and each claim.

[0013] The foregoing, together with other features and examples, will become more apparent upon referring to the following specification, claims, and accompanying drawings.Brief Descriptions of the Drawings

[0014] FIG. 1 is a block diagram illustrating an example of a computing environment in which temporal neural attributes can be used for access control according to certain aspects of the present disclosure.

[0015] FIG. 2 is a flow chart illustrating an example of a process for using temporal neural attributes for access control according to certain aspects of the present disclosure.

[0016] FIG. 3 is a flow chart illustrating an example of a process for determining an access indicator using temporal neural attributes according to certain aspects of the present disclosure.

[0017] FIG. 4 is a flow diagram of a data flow for generating an access indicator for controlling access or an interaction based on a set of temporal neural attributes that can be generated by a set of long short-term memory networks according to certain aspects of the present disclosure.

[0018] FIG. 5 is a flow diagram of a data flow for generating an access indicator for controlling access or an interaction based on a set of temporal neural attributes that can be generated by a transformer model according to certain aspects of the present disclosure.

[0019] FIG. 6 is a block diagram depicting an example of a computing device, which can be used to implement the embodiments described herein, according to some aspects of the present disclosure.Detailed Description

[0020] Certain aspects and features relate to temporal neural attributes (TNAs) that can be used for access control and for other suitable purposes. The access control can involve controlling access to an interactive computing environment, to instructions for initiating, completing, or approving an interaction with an entity, etc. The TNAs can be generated using one or more machine-learning techniques, one or more artificial intelligence techniques, or a combination thereof. For example, the TNAs may be generated using long short-term memory (LSTM) networks, recurrent neural networks (RNNs, such as via recurrent neural attributes (RNAs)), transformer models, other suitable networks or models, or any combination thereof. The TNAs may be generated based on time-series data for an entity. The time-series data may include data about interactions involving the entity over certain periods of time. The TNAs may be generated to capture temporal information or patterns about the interactions, about the entity, or a combination thereof.

[0021] Certain aspects described herein, which can include temporal neural attributes for access control, can improve at least the technical fields of controlling an interaction, access control for a computing environment, data security associated with an interaction, or any combination thereof. For instance, TNAs may improve the technical field of controlling an interaction by reducing or eliminating instances of malicious activity by extracting temporal behavioral patterns from the TNAs. Additionally, or alternatively, TNAs may improve the technical field of access control for a computing environment by reducing or eliminating instances of unauthorized access to the computing environment using temporal information gleaned using the TNAs. Additionally, or alternatively, TNAs may improve the technical field of data security associated with an interaction by reducing or eliminating instances of data breach, unintentional data disclosure, or unauthorized data disclosure via illegitimate interactions.

[0022] In some examples, temporal neural attributes (TNAs) can be used for non-linearly transforming time series data into informative and explainable features for downstream modeling tasks. TNAs can leverage recurrent neural networks (RNNs), long short-term memory (LSTM) networks, transformer models, other suitable networks or models, or any combination thereof to process temporal sequences of attributes into scalar values, vector embeddings or a combination thereof. The scalar values or vector embeddings can represent the time-series data. In some examples, using TNAs can address limitations of hand-crafted feature engineering for modeling tasks by automatically extracting complex temporal patterns while retaining interpretability of outputs. TNAs can provide flexible and powerful frameworksthat can be used for various access control tasks, such as computing environment access control, resource transfer access control, and the like, and TNAs can be adapted for general-purpose feature learning, synthetic data generation, etc.

[0023] Models built upon credit data or other interaction data may rely heavily on accurate and informative features derived from time series data. In some examples, an interaction can include a trade between entities, trade data between different trades, and the like. Additionally, or alternatively, an interaction can include one or more sub-interactions between data represented by the overarching trade. The time series data may include data that can capture a history of accounts for a target entity and interaction behavior of the target entity over time. The data may be regularly updated and consolidated into monthly snapshots, such as archives, which can form the time series data representing a sequence of observations for various interaction attributes. The interaction attributes can include balance, resource transfer totals, and other behaviors. Other risk models may use individual-level attributes derived from the time-series data through rule-based and hard-coded techniques. These techniques can involve aggregating and summarizing time-series information using hand-crafted heuristics to generate static, individual-level features, which may have limits, lack context or other valuable information, etc. The limits may include loss of temporal information, limited non-linearity, manual effort, and lack of explainability. For example, aggregating time series data into static features can cause a loss of temporal patterns and dependencies present in the original time¬ series data. Additionally, or alternatively, non-linearity may be limited since hand-crafted features may fail to capture complex, non-linear relationships within the time series data that may improve predictive power. Additionally, or alternatively, developing effective rule-based features involves significant manual effort, domain expertise, and iterative refinement that may not always be available in every instance. Additionally, or alternatively, while rule-based systems may have a certain degree of interpretability, the complexity of rule-based systems can render it challenging to fully understand or to explain the interaction of numerous features in a model

[0024] TNAs can address the above-mentioned limitations such as by providing automated feature engineering from time-series data and by providing other suitable improvements The TNAs can leverage RNNs, LSTMs, transformer models, or a combination thereof to directly process temporal sequences of attributes from time-series data. Using TNAs in this way can enable extraction of complex, non-linear patterns and temporal dependencies while retaining explainability of the outputs generated using TN As.

[0025] A system can use TNAs for various purposes such as access control, generating explainable outputs for time-series data, and the like The system can use various techniques involving the TNAs. For example, the system can perform an aggregation such as via an aggregator. The aggregation can involve grouping interactions by type, generating a counter attribute, generating an aggregated interaction type attribute, other suitable techniques, or any combination thereof. Regarding grouping, the system can, for each entity, group interactions based on a type of interaction. Examples of the types of interactions can include interactions using a particular card, interactions with a particular provider entity, and the like. The grouping of interactions into different interaction types may leverage different combinations of fields of the interactions. Once grouped, a separate instantiation of each interaction attribute for each interaction type can be generated.

[0026] Regarding counter attributes, the system can, for each defined interaction type, generate a new counter attribute. The counter attribute can record a number of interactions of a corresponding interaction type for each individual at each point in time. The counter attribute may count open interactions or those interactions that have been initiated but not completed. In other examples, the counter attribute may also, or alternatively, count interactions that have been initiated and completed. Additionally, or alternatively, multiple counter attributes may be generated. The counter attributes can capture changes in a number of interactions over time, which can reflect a behavior of an individual. The behavior can include when accounts may be opened, when accounts may be closed, when interactive computing environments may be accessed, and so on.

[0027] Regarding an aggregated interaction type attribute, the system can, for each interaction type, aggregate versions of relevant interaction attributes. The aggregated versions of relevant interaction attributes can be calculated across each of the interactions of a corresponding interaction type for each archive in the time-series. The system may use various aggregation functions, such as sum, minimum, maximum, average, standard deviation, etc., to perform aggregation. The particular aggregation function, or aggregation functions, chosen by the system may depend on a particular or desired interaction attribute and data desired to be captured. The aggregated interaction type attribute can consolidate interaction-level information within each interaction type into individual -level time-series.

[0028] An outcome of aggregation performed by the system may include a well-defined, individual-level time-series structure. For example, the system can use the various aspects of the above-described aggregation to transform ragged, interaction-centric data into the well- defined, individual-level time-series data structure. In some examples, the well-defined,individual -level time-series data structure can be represented as [individual, archive, feature] or other suitable structures. The feature dimension of the well-defined, individual-level time¬ series data structure can include newly created counter attributes and aggregated interaction attributes for each interaction type, or other suitable attributes. The well-defined, individual¬ level time-series data structure may be well-suited for processing by RNNs, LSTMs, transformer models, and the like, and the well-defined, individual-level time-series data structure can allow straight-forward incorporation of additional individual-level information such as inquiry data or other suitable individual-level data.

[0029] The system can use output from aggregation to perform techniques relating to feature creation. For example, the system can leverage LSTM networks, RNN networks, transformer models, other networks or models, or any combination thereof to extract temporal patterns from the aggregated time-series data. For each feature generated in the aggregation techniques performed by the system, a dedicated network or transformer model can be used. In examples in which LSTM models are used by the system, a different LSTM model can be assigned to each feature generated in the aggregation stage. Further in examples in which LSTM models are used by the system, the system can perform univariate LSTM processing. For each aggregated feature, a separate LSTM network may process the time-series data for the aggregated feature Each LSTM network may be designed to learn temporal dependencies and extract relevant data from the time-series it processes. Additionally, or alternatively, outputs from the LSTM networks can be used by the system to generate a TNA output. Each LSTM network can produce an output, which, subsequent to passing through a dense output layer, can include a single scalar value or vector embedding. The output may be or otherwise represent a TNA for the specific feature. In some examples, the TNA encapsulates the learned temporal information from the input time-series.

[0030] To learn TN As, the system can perform training to solve a specific task. For example, the system can perform TNA concatenation and downstream modeling. The output TNAs from each of the LSTM networks can be concatenated into a feature vector corresponding with one or more individuals. Additional individual-level attributes can be concatenated as well as the TNAs. The feature vector can feed into one or more dense layers with an appropriate output. For example, the feature vector can be provided as input into (i) a logistic regression for a binary classification, (ii) a softmax layer for multi-class classification, (iii) a linear regression for regression tasks, and so on.

[0031] The TNAs may allow any outputs from the system or above-described techniques to retain a maximum degree of explainability. For example, techniques involving TNAs, asdescribed above, can have inherent explainability, particularly when coupled with linear downstream models such as logistic regression. While LSTM networks may be non-linear models, the architecture of the TNAs can allow a high degree of interpretability to be retained by the outputs of the system. Since each TNA can be generated by a dedicated LSTM network, or other network or model, processing a specific, pre-aggregated feature, the contribution of each TNA to the final model output can be traced. In a linear model, the coefficients associated with each TNA may directly indicate the importance and direction of effect of the corresponding time-series feature. For instance, a positive coefficient for the TNA derived from a first feature in a logistic regression model for default prediction can indicate that a sum of revolver balances over time is associated with increased default risk. Conclusions may be able to be made about the details or even directionality of the association with further enhancements such as time-horizon-specific TNAs, monotonic temporal neural attributes (mTNAs), and the like.

[0032] In some examples, a score model can process the ’TNAs to generate an output. The output can include a probability of an interaction failing or other suitable probabilities or indicators. The output can be used to control access to one or more interactive computing environments by a target entity.

[0033] Techniques involving TNAs can be enhances, customized, or a combination thereof to apply to different scenarios, to address specific application requirements, to extract more nuanced temporal information, or any combination thereof. The customizations or enhancements can include time-horizon-specific TNAs, mTNAs, general purpose temporal neural attributes (gpTNAs), or other suitable customizations or enhancements. Time-horizon- specific TNAs, and incorporating time granularity, can be used to capture time- sen si five information and different temporal perspectives. The system can leverage time-horizon- specific ’TNAs and time granularity by generating truncated copies of the time-series data for different time horizons such as one month, three months, six months, and so on. For each time horizon, a separate set of TNAs can be learned. For example, TNAs can be learned for a first attribute over three months and separately for the first attribute over six months. The resulting TNAs can be expressly linked to specific time horizons.

[0034] The system can use mTNAs in certain applications such as those involving monotonicity constraints. To incorporate monotonicity into TNAs, monotonic LSTM networks can be leveraged. By using monotonic LSTMs, the system can implement a model that can learn monotonic relationships between the feature of the time-series and a target variable. By using monotonic LSTMs, the learned RNN features can respect the desired monotonicityconstraints to facilitate generating directionally consistent reason codes. Different directional constraints can be implemented over different time windows or aggregations of a common interaction attribute while preserving comprehensibility, explainability, actionability, etc.

[0035] The system can generalize TNAs using gpTNAs. For example, while the system can use TNAs specifically trained for a specific downstream task or prediction, the system can use gpTNAs for general-purpose tasks. The gpTNAs may not be tied to a single objective, and the gpTNAs can be generated using various techniques such as multiple objective function optimization, techniques involving self-supervised encoder-decoder, techniques involving a variational autoencoder, techniques involving a generative TNA, and so on. The system can implement multiple objective function optimization by using multiple downstream networks. Each of the downstream networks may solve a different task and can draw upon a shared set of TNA features. This can encourage the TNA learning process to extract features that can be broadly informative and useful across various tasks to lead to more general-purpose representations.

[0036] The system can use a self-supervised encoder-decoder architecture. An LSTM network can be an encoder and can process input time-series data to generate a TNA vector. The TNA vector can be provided as input into a decoder LSTM network that can attempt to reconstruct the original input time-series data. By training the encoder-decoder to minimize reconstruction error, the encoder LSTM network can learn to extract informative features that capture temporal dynamics of the input time-series data without explicit task-specific labels. The TNA vector generated by the encoder LSTM network can be or otherwise represent a general-purpose feature representation.

[0037] The system can use a variational autoencoder by incorporating a variational autoencoder objective into an encoder-decoder framework. Similar to the self-supervised encoder-decoder architecture, the system can use an encoder LSTM network to process the input time-series data. Additionally, or alternatively, to directly outputting a TNA vector, the encoder LSTM network can output a mean vector and a standard deviation vector. The output vectors can parameterize a latent distribution such as a Gaussian distribution. A sample may be drawn from the latent distribution, and the sample may become the TNA vector. Additionally, or alternatively, the mean vectors may be used as the TNAs. The TNA vector can then be provided to a decoder LSTM network that can attempt to reconstruct the input timeseries data. The variational autoencoder objective can include a reconstruction loss and a regularization term that can encourage the latent space, which may be represented by the mean vector and the standard deviation vector, to be well-structured. This can lead to more robustand disentangled TNA representations. Additionally, or alternatively, the variational autoencoder framework may have an inherent capability to generate synthetic TNA features by sampling from the learned latent distribution. When combined with differentially private deep learning training techniques, differentially private synthetic TNA features and differentially private synthetic interaction data can be generated.

[0038] The system can additionally leverage generative TNAs. One possible limitation of the variational autoencoder approach may be that each variational autoencoder may learn an independent marginal distribution, and independent sampling from each feature distribution may produce unrealistic data. Sampling quality and TNA feature quality may be improved by learning a generative model of the joint distribution of TNAs.

[0039] A system that uses TNAs, as described above, may have various advantages over systems that do not use TNAs. For example, the system may have the capacity to perform automated feature engineering For example, the TNAs may automate feature extraction to reduce or obviate the need for manual feature engineering, domain expertise, iterative refinement, and the like associated with rule-based approaches. Additionally, or alternatively, the system can extract non-linear temporal patterns. The LSTMs, or other networks or models (e.g., RNNs, transformer models, etc.), can include powerful non-linear models that can capture complex temporal dependencies and patterns within time-series data. The complex temporal dependencies and patterns within time-series data may be missed by linear techniques or rule¬ based techniques Additionally, or alternatively, the system can experience improved predictive performances of models the system implements. For example, by leveraging the rich temporal information and non-linear modeling capabilities of the LSTMs, or the other networks or models, TNAs can improve the predictive performance of downstream models compared to models built on other features without TNAs. Additionally, or alternatively, the system can generate output with enhanced explainability such as with respect to black-box deep learning. Techniques involving TNAs retain a high degree of explainability. For example, the modular architecture, in which each TNA is linked to specific input time-series features and potentially time horizon, implemented by the system can allow a characterization of the information of each TNA. The system can implement rnTNAs to further enhance explainability by ensuring a directionally consistent mapping. Additionally, or alternatively, the system can use TNAs to adapt to various application requirements or goals. For example, the system can implement time-granularity specific TNAs, mTNAs, gpTNAs, generative TNAs, and the like. Additionally, or alternatively, the system can use TNAs to apply to time-series data ofindividual "level attributes to offer a unified framework for temporal feature engineering across different types of interaction data.

[0040] These illustrative examples are given to introduce the reader to the general subject matter discussed here and are not intended to limit the scope of the disclosed concepts. The following sections describe various additional features and examples with reference to the drawings in which like numerals indicate like elements, and directional descriptions are used to describe the illustrative examples but, like the illustrative examples, should not be used to limit the present disclosure.Example of a Computing Environment for Artificial Intelligence Techniques for Entity Disambiguation

[0041] Referring now to the drawings, FIG. 1 is a block diagram illustrating an example of a computing environment 100 in which temporal neural attributes can be used for access control according to certain aspects of the present disclosure. FIG. 1 illustrates examples of hardware components of a risk assessment computing system 130 according to some aspects. The risk assessment computing system 130 can be a specialized computing system that may be used for processing large amounts of data, such as for controlling access to an interactive computing environment 107, for facilitating control of an interaction between a target entity (e.g., a requesting entity) and a providing entity, for determining a likelihood that a request submitted by the receiving entity is legitimate, etc., using a large number of computer processing cycles. The risk assessment computing system 130 can include a risk assessment server 118 for validating risk assessment data from various sources. In some examples, the risk assessment computing system 130 can include other suitable components, servers, subsystems, and the like.

[0042] The risk assessment server 118 can include one or more processing devices that can execute program code such as a risk assessment application 114, a risk prediction model 120, a temporal neural attribute (TNA)-based model 121, and so on. The program code can be stored on a non-transitory computer-readable medium or other suitable medium. The risk assessment server 118 can perform risk assessment validation operations or access control operations for validating or otherwise authenticating, for example using other suitable modules, services, models, components, etc. of the risk assessment server 118, received data such as time-series data, entity data, item data, and interaction data, or other suitable data received from user computing systems 106, client computing systems 104, external data systems 109, one or more data repositories, or any suitable combination thereof. Examples of the received data caninclude historical data 125, training dataset 126, etc. The received data can be or otherwise include time-series data. In some examples, the risk assessment application 114 can authenticate the request, or facilitate authentication of the request, by utilizing TNAs based on the TNA model 121, real-time data 124, the historical data 125, the training dataset 126, any information determined therefrom, or by using any other suitable data.

[0043] The real-time data 124 may be received by or from the external data systems 109, though the real-time data 124 may be received by or from other suitable sources. The historical data 125 can be determined or stored in one or more network-attached storage units on which various repositories, databases, or other structures are stored. An example of these data structures can include the entity data and interaction data repository 123. In some examples, a combination of the real-time data 124 and the historical data 125 can include time-series data. The time-series data can be acquired or otherwise received on a per-entity basis. Additionally or alternatively, a training dataset 126 can be stored in the entity data and interaction data repository 123. In some examples, the training dataset 126 can be used to train one or more artificial intelligence models, one or more machine-learning models, which may include a supervised machine-learning model, an unsupervised machine-learning model, a generative artificial intelligence model, a large language model, and the like, included in the risk assessment server 118. In some examples, the training dataset 126 can include synthetic data generated by prompting a separate large language model to generate the synthetic data.

[0044] The TNA model 121 can be trained to generate one or more signals or attributes based on the real-time data 124, the historical data 125, or a combination thereof such as the time-series data. The TNA model 121, or any model included therein, can be trained to determine a set of TNAs based on the time-series data, and the risk prediction model 120 may be trained or configured to generate one or more indicators, such as access indicators, to control access to the interactive computing environment 107 using the TNAs, to facilitate control of an interaction requested by the requesting entity, or to otherwise provide digital enablement for the requesting entity. Controlling the interaction can include initiating the interaction, denying the interaction, or other suitable control of the interaction.

[0045] Network-attached storage units may store a variety of different types of data organized in a variety of different ways and from a variety of different sources. For example, the network-attached storage unit may include storage other than primary storage located within the risk assessment server 118 that is directly accessible by processors located therein. In some aspects, the network-attached storage unit may include secondary, tertiary, or auxiliary storage, such as large hard drives, servers, and virtual memory, among other types of suitablestorage. Storage devices may include portable or non-portable storage devices, optical storage devices, and various other mediums capable of storing and containing data. A machine-readable storage medium or computer-readable storage medium may include a non-transitory medium in which data can be stored and that does not include carrier waves or transitory electronic signals. Examples of a non-transitory medium may include, for example, a magnetic disk or tape, optical storage media such as a compact disk or digital versatile disk, flash memory, memory devices, or other suitable media.

[0046] The risk assessment computing system 130 can communicate with various other computing systems. The other computing systems can include user computing systems 106, such as smartphones, personal computers, and the like, client computing systems 104, or other suitable computing systems. For example, the user computing systems 106 may transmit, such as in response to receiving input from a requesting entity, requests for accessing the interactive computing environment 107, one or more requests for initiating one or more interactions, or the like to the client computing systems 104. In response, the client computing systems 104 can send authentication queries, risk assessment queries, or the like to the risk assessment server 118, and the risk assessment server 118 can receive data about the interaction, historical data, time-series data, or the like for generating TNAs, generating signals, determining access indicators, or a combination thereof. While FIG. 1 illustrates that the risk assessment computing system 130 and the client computing systems 104 are separate systems, the risk assessment computing system 130 and the client computing systems 104 can be one system. For example, the risk assessment computing system 130 can be a part of the client computing systems 104, or vice versa.

[0047] As illustrated in FIG. 1, the risk assessment computing system 130 may interact with the client computing systems 104, the user computing systems 106, or a combination thereof via one or more public data networks 108 to facilitate interactions between users of the user computing systems 106 and the interactive computing environment 107. For example, the risk assessment computing system 130 can facilitate the client computing systems 104 providing a user interface to the user computing system 106 for receiving various data from the user. The risk assessment computing system 130 can transmit validated assessment data, for example an access indicator, scores, one or more TNAs, a responsive message, etc., to the client computing systems 104 for providing, challenging, or rejecting access of the target entity to the interactive computing environment 107, for facilitating a decision with respect to control of the interaction, for establishing temporal behavior patterns, or the like. In some examples, the risk assessment computing system 130 can additionally communicate with third-partysystems, such as external data systems 109, to receive assessment data, entity data, interaction data, item data, time-series data, or any combination thereof, through the public data network 108. In some examples, the third-party systems can provide real-time, such as streamed, data about the requesting entity, historical data about the requesting entity, etc. to the risk assessment computing system 130.

[0048] Each client computing system 104 may include one or more devices such as individual servers or groups of servers operating in a distributed manner. A client computing system 104 can include any computing device or group of computing devices operated by a provider or other suitable entity that can provide real-world items or services. The client computing system 104 can include one or more server devices. The one or more server devices can include or can otherwise access one or more non-transitory computer-readable media.

[0049] The client computing system 104 can include one or more processing devices that can be capable of providing an interactive computing environment 107, such as a user interface, that can perform various operations. The interactive computing environment 107 can include executable instructions stored in one or more non-transitory computer-readable media. The instructions providing the interactive computing environment can configure one or more processing devices to perform the various operations. In some examples, the executable instructions for the interactive computing environment can include instructions that provide one or more graphical interfaces. The graphical interfaces can be used by a user computing system to access various functions of the interactive computing environment 107. For instance, the interactive computing environment 107 may transmit data to and receive data, such as via the graphical interface, from a user computing system to shift between different states of the interactive computing environment 107, where the different states allow one or more electronic interactions between the user computing system 106 and the client computing system 104 to be performed.

[0050] In some examples, the client computing system 104 may include other computing resources associated therewith, such as server computers hosting and managing virtual machine instances for providing cloud computing services, server computers hosting and managing online storage resources for users, server computers for providing database services, and others. The interaction between the user computing system 106, the client computing system 104, and the risk assessment computing system 130, or any suitable sub-combination thereof may be performed through graphical user interfaces, such as the user interface, presented by the risk assessment computing system 130, the client computing system 104, other suitable computing systems of the computing environment 100, or any suitable combination thereof. The graphicaluser interfaces can be presented to the user computing system 106. Application programming interface (API) calls, web service calls, or other suitable techniques can be used to facilitate interaction between any suitable combination or sub-combination of the client computing system 104, the user computing system 106, and the risk assessment computing system 130.

[0051] A user computing system 106 can include any computing device or other communication device that can be operated by a user or entity, such as the requesting entity, which may include an individual, an organization, etc. The user computing system 106 can include one or more computing devices such as laptops, smartphones, and other personal computing devices. A user computing system 106 can include executable instructions stored in one or more non-transitory computer-readable media. The user computing system 106 can additionally include one or more processing devices configured to execute program code to perform various operations. In various examples, the user computing system 106 can allow a user to access certain online services or other suitable products, services, or computing resources from a client computing system 104, to engage in mobile commerce or other suitable interactions with the client computing system 104, to obtain controlled access to electronic content, such as the interactive computing environment 107, hosted by the client computing system 104, etc.

[0052] In some examples, the requesting entity can use the user computing system 106 to engage in, or request to engage in, an electronic interaction, or an electronic reverse interaction, with the client computing system 104 via the interactive computing environment 107. The risk assessment computing system 130 can receive a request, for example from the user computing system 106, to access the interactive computing environment 107 and, subsequently, to initiate the interaction, and can use data, such as the real-time data 124, the historical data 125, timeseries data, an entity name associated with the requesting entity, or any other suitable data or signals determined therefrom, to generate a responsive message to facilitate a decision regarding how to control the interaction. Examples of the decision can include allowing the interaction to proceed, challenging the interaction, and denying the interaction.

[0053] An electronic interaction between the user computing system 106 and the client computing system 104 can include, for example, the user computing system 106 being used to request products or content from the client computing system 104, and so on, and a reverse interaction may be the electronic interaction in reverse such as the user computing system 106 being used to request resources or data from the client computing system 104 in exchange for resources or data previously provided by the user computing system 106. An electronic interaction between the user computing system 106 and the client computing system 104 caninclude, for example, one or more queries for a set of sensitive or otherwise controlled data, accessing online services provided via the interactive computing environment 107, submitting an online application to the client computing system 104 via the interactive computing environment 107, operating an electronic tool, such as a content-modification feature, an application-processing feature, within the interactive computing environment 107, etc.

[0054] In some examples, an interactive computing environment 107 implemented through the client computing system 104 can be used to provide access to various online functions. As a simplified example, a user interface or other interactive computing environment 107 provided by the client computing system 104 can include electronic functions for requesting computing resources, online storage resources, network resources, database resources, real-world items or goods, or other types of resources or data.

[0055] A user computing system 106 can be used to request access to the interactive computing environment 107 provided by the client computing system 104, to request an interaction via the interactive computing environment 107, or to perform other actions. The client computing system 104 can submit a request, such as in response to a request made by the user computing system 106 to access the interactive computing environment 107 or to initiate an interaction, for risk assessment to the risk assessment computing system 130 and can selectively grant or deny access to various electronic functions, or the interaction, based on risk assessment performed by the risk assessment computing system 130. Based on the request, the risk assessment computing system 130 can determine one or more signals or an access indicator for data associated with the request provided by a receiving entity, which may submit or may have submitted the request via the user computing system 106. Based on an access indicator determined using output from the TNA model 121 as input to the risk prediction model 120, the risk assessment computing system 130, the client computing system 104, or a combination thereof can determine whether to grant the access request of the user computing system 106 to certain features of the interactive computing environment 107 or whether to allow, challenge, or deny the interaction. The risk assessment computing system 130, the client computing system 104, or a combination thereof can use the risk indicator for other suitable purposes such as identifying a manipulated identity or controlling a real-world interaction.

[0056] In a simplified example, the system illustrated in FIG. 1 can configure the risk assessment server 118 to be used for controlling access to the interactive computing environment 107, for facilitating a decision regarding whether to allow the interaction, or the like. The risk assessment server 118 can receive time-series data about a requesting entity that submitted a request via the interactive computing environment 107, for example, based on theinformation, such as information collected by the client computing system 104 via a user interface provided to the user computing system 106, provided by the client computing system 104 or received via other suitable computing systems. The risk assessment server 118 can additionally or alternatively receive historical interaction data, historical item data, real-time data, synthetic training data, and the like relating to the request. The risk assessment server 118 can invoke the TNA model 121 to generate one or more TNAs using the received data, such as the time-series data, and can use the output TNAs from the TNA model 121 to determine an access indicator or the like for the request. The risk assessment server 118 can transmit the access indicator, or any responsive message or inference derived therefrom, to the client computing system 104 for use in controlling access to the interactive computing environment 107, for use in controlling the interaction, and so on.

[0057] The access indicator, or the responsive message, can be used, for example by the risk assessment computing system 130 or the client computing system 104, to determine whether a risk associated with the allowing the interaction to proceed exceeds a threshold, thereby granting, challenging, or denying the request to initiate the interaction. For example, if the risk assessment computing system 130 determines that the access indicator indicates that a risk of allowing the interaction to proceed is lower than a threshold value, then the client computing system 104 associated with the service provider can generate or otherwise provide access permission to the user computing system 106 that requested the interaction. The access permission can include, for example, cryptographic keys used to generate valid access credentials or decryption keys used to decrypt access credentials. The client computing system 104 can also allocate resources to the requesting entity and provide a dedicated web address for the allocated resources to the user computing system 106, for example, by adding the user computing system 106 in the access permission. With the obtained access credentials or the dedicated web address, the user computing system 106 can establish a secure network connection to the interactive computing environment 107 hosted by the client computing system 104 and access the resources via invoking API calls, web service calls, HTTP requests, other suitable mechanisms or techniques, etc. Additionally or alternatively, the obtained access credentials or the dedicated web address can be used by the user computing system 106 to initiate the interaction.

[0058] In some examples, the risk assessment computing system 130 may determine whether to grant, challenge, or deny the request made by the user computing system 106 for accessing the interactive computing environment 107 or for initiating the interaction. For example, and based on the access indicator or inferences derived therefrom, the risk assessmentcomputing system 130 can determine that the request made by the requesting entity is a legitimate request and may authenticate the request. In other examples, the risk assessment computing system 130 can challenge or deny the interaction if the risk assessment computing system 130 determines that the request made by the requesting entity may not be a legitimate request or may otherwise be associated with malicious activity.

[0059] Each communication within the computing environment 100 may occur over one or more data networks, such as a public data network 108, a network 116 such as a private data network, or some combination thereof. A data network may include one or more of a variety of different types of networks, including a wireless network, a wired network, or a combination of a wired and wireless network. Examples of suitable networks include the Internet, a personal area network, a local area network (“LAN”), a wide area network (“WAN”), and a wireless local area network (“WLAN”). A wireless network may include a wireless interface or a combination of wireless interfaces. A wired network may include a wired interface. The wired or wireless networks may be implemented using routers, access points, bridges, gateways, or the like, to connect devices in the data network.

[0060] The number of devices depicted in FIG. 1 is provided for illustrative purposes. Different numbers of devices may be used. For example, while certain devices or systems are shown as single devices in FIG. 1, multiple devices may instead be used to implement these devices or systems. Similarly, devices or systems that are shown as separate, such as the risk assessment server 118 and the entity data and interaction data repository 123, etc., may be instead implemented in a single device or system. Similarly and as discussed above, the risk assessment computing system 130 may be a part of the client computing system 104.Arti ficial Intelligence Techniques for Entity Disambiguation

[0061] FIG. 2 is a flow chart illustrating an example of a process 200 for using temporal neural attributes (TNAs) for access control according to certain aspects of the present disclosure. One or more computing devices, such as the risk assessment computing system 130, may implement operations illustrated in FIG. 2 by executing suitable program code such as the TNA model 121, the risk prediction model 120, or the like. For illustrative purposes, the process 200 is described with reference to certain examples depicted in the figures. Other implementations, however, are possible.

[0062] At block 202, the process 200 involves receiving time-series data relating to an entity. The time-series data may include information about a set of interactions involving the entity. For example, the entity may have requested, or may currently be requesting, initiationof each interaction included in the set of interactions. The time-series data may include data for multiple interactions involving the entity over a certain period of time. In some examples, the time-series data may be requested in response to receiving a request for access by an entity to a computing environment, in response to a request to initiate or complete an interaction involving the entity, and the like. In response to receiving the request, a system, such as the risk assessment computing system 130, may request the time-series data via historical data recorded for previous interaction instances, via real-time data for up-to-date interaction instances, or a combination thereof.

[0063] At block 204, the process 200 involves invoking a first model. The first model may include instructions for aggregating the time-series data into aggregated data for further processing. For example, the first model may include an aggregator model that can aggregate input time-series data into the aggregated data. In some examples, such as examples in which a transformer model is invoked as the first model, aggregation may be skipped or otherwise not performed by the transformer model. Aggregating the time-series data can involve grouping interactions by type, generating a counter attribute, generating an aggregated interaction type attribute, other suitable techniques, or any combination thereof.

[0064] In some examples, the first model may include an aggregator. Additionally, or alternatively, the set of interactions can have different interaction types. Aggregating the timeseries data can include generating a first grouping of data and a second grouping of data from the time-series data. The first grouping of data can include data from a first type of interaction of the different interaction types, and wherein the second grouping of data can include data from a second type of interaction of the different interaction types. Additionally, or alternatively, aggregating the time-series data can include generating, for the first interaction type, a first counter attribute that tracks a first total number of interactions of the set of interactions of the first interaction type at a particular point in time. Additionally, or alternatively, aggregating the time-series data can include generating, for the second interaction type, a second counter attribute that tracks a second total number of interactions of the set of interactions of the second interaction type at the particular point in time. In some examples, the first counter attribute can include individual counter attributes, and each individual counter attribute can correspond with a different time period of the time-series data. Additionally, or alternatively, aggregating the time-series data can include generating an aggregated interaction type attribute by aggregating versions of interaction atributes across interactions of a corresponding interaction type for each time period in the time-series data.

[0065] At block 206, the process 200 involves generating a set of neural attributes (TNAs)by invoking a second model. In some examples, the set of TNAs may be generated by a transformer model, and in these examples, the time-series data may not be aggregated prior to the transformer model generating the set of TNAs based on the time-series data. In such examples, the first model and the second model may be the same model. In other examples, the second model may be different from the first model, and the second model may include one or more long short-term memory (LSTM) networks. Each LSTM network may receive a portion of the aggregated data and may generate a different TNA to include in the set of TNAs. Each TNA of the set of TNAs can include a different attribute, or set of attributes, that can represent temporal information about interactions involving the entity.

[0066] In some examples, the second model can include multiple individual networks. Generating the set of TNAs can include, for each network in the multiple individual networks, generating an output using a dense output layer in which the output is a single scalar value or a vector embedding. The output is a TNA of the set of TNAs that represents temporal information from corresponding data of the time-series data. In some examples, an LSTM network can generate the TNA. Additionally, or alternatively, generating the set of TNAs can include generating a feature vector by concatenating each TNA of the set of TNAs and a plurality of entity-specific attributes. The feature vector can correspond with the entity, and the input into the third model can be or include the feature vector.

[0067] At block 208, the process 200 involves generating an access indicator using a third model. The third model may be different from the first model, the second model, or a combination thereof. For example, the third model may include a downstream model configured to generate output that can be applied to real-world decisions based on the set of TNAs. For example, the third model may include a hard-coded model, an artificial intelligence model, or any combination thereof that can receive the set of TNAs and can generate output that includes the access indicator. In some examples, the access indicator can include a risk indicator or signal that can be used to determine whether to provide access for an entity to a computing environment, to determine whether to allow an interaction to be initiated or completed, and so on. The third model may receive the set of TNAs and can generate an inference based on the temporal patterns, such as a temporal behavior pattern, of the entity in which the inference can include the access indicator.

[0068] At block 210, the process 200 involves outputting a command with instructions to control access to an interactive computing environment based on the access indicator. For example, the third model may generate the access indicator, and a fourth model may generate the command with the instructions. In some examples, the fourth model may be the third modelsuch that the third model may be configured to generate the access indicator and generate the command with the instructions based on the access indicator.Techniques for Controlling an Interaction Using Artificial Intelligence

[0069] FIG. 3 is a flow chart illustrating an example of a process 300 for determining an access indicator using temporal neural attributes (TNAs) according to certain aspects of the present disclosure. One or more computing devices, such as the risk assessment computing system 130, may implement operations illustrated in FIG. 3 by executing suitable program code such as the TNA model 121, the risk prediction model 120, and the like. For illustrative purposes, the process 300 is described with reference to certain examples depicted in the figures. Other implementations, however, are possible.

[0070] At block 302, the process 300 involves receiving a risk assessment query for a target entity, such as the requesting entity, from a remote computing device such as a computing device associated with the target entity. The risk assessment query can also be received by the risk assessment server 118 from a remote computing device associated with an entity authorized to request risk assessment of the target entity or any request submitted thereby. The risk assessment query may involve a request for determining whether the target entity, or a request for initiating the interaction or access to a computing environment associated therewith, is associated with potentially malicious intent, such as various types of hacking or fraud, or the like.

[0071] At block 304, the process 300 involves accessing a risk prediction model 120 trained or otherwise configured to generate an access indicator based on one or more TNAs generated using the TNA model 121. In some examples, the risk prediction model 120 may additionally or alternatively be or include one or more proprietary models (e.g., artificial intelligence models, machine-learning models, etc.), one or more heuristics models, and / or one or more simulation models. The TNA model 121 can include one or more supervised machinelearning models, one or more unsupervised machine-learning models, one or more generative artificial intelligence models, or the like, and the TNA model 121 may be trained on, or receive as input, data such as entity data, identity data, historical interaction data, historical item data, time-series data, and the like, which may be or include real-world data, synthetically generated data from a separate LLM, or any combination thereof. Additionally, or alternatively, one or more TNAs can be generated by the TNA model 121 as described at least with respect to the block 206. Examples of entity data can include identity data, such as name, address, etc., and examples of interaction data can include a time of interaction, a number of resources associatedwith the interaction, a success status of a corresponding interaction or reversal thereof, though other examples of either are possible. The access indicator can indicate a level of risk associated with the target entity, or the request associated therewith, and the access indicator can include indicators such as an identity score or a behavior score of the target entity.

[0072] At block 306, the process 300 involves computing an access indicator for the target entity based on the set of TNAs. In some examples, the risk prediction model 120 can be used to determine the access indicator, though in other examples, other components or models (e.g., the TNA model 121) of the risk assessment computing system 130 can be used to determine the access indicator. The set of TNAs generated by or otherwise received from the TNA model 121, can be used as input to the risk prediction model 120. The risk prediction model 120 can generate output by combining the set of TNAs, can evaluate the set of TNAs, can compare the set of TNAs to historical TNAs, can generate one or more inferences, such as temporal patterns, based on the set of TNAs, or the like. The output of the risk prediction model 120 can be or include the access indicator for the target entity.

[0073] At block 308, the process 300 involves transmitting a responsive message based on the access indicator, which may be determined at the block 306. In some examples, the risk assessment server 118, or any other suitable module, model, or computing device, can transmit the responsive message to a computing device, such as the client computing system 104, or any other suitable computing device. The responsive message can vary based on the access indicator. For example, the responsive message may indicate that the request submitted by the target entity is a legitimate request (e.g., not associated with potentially malicious intent) and may recommend granting approval to the request based on the responsive message. In other examples, the responsive message may indicate that the request submitted by the target entity is likely associated with malicious intent or may otherwise not be associated with legitimate activity and may recommend challenging or denying the request.

[0074] In some examples, the responsive message may be generated and transmitted based on the TNA model 121. For example, the risk prediction model 120 can generate an access indicator for the request submitted by the target entity based on the set of TNAs generated by the TNA model 121, and the risk assessment server 118 can generate the responsive message based on the access indicator. The access indicator can include a credit score, a fraud score, an identity score, a behavior score or pattern, other suitable scores or temporal information indicating risk or behavior in one or more than one dimension associated with the target entity or the request associated therewith, or any suitable combination thereof. The risk prediction1model 120 can generate the access indicator by applying a clustering model to the set of TNAs or using other suitable techniques.

[0075] The risk assessment server 118 can determine, based on the access indicator generated by the risk prediction model 120, whether to recommend granting, challenging, or denying the request submitted by the target entity. In some examples, the risk assessment computing system 130 can generate and transmit the responsive message to grant, challenge, or deny the request based on a recommendation provided by the risk prediction model 120. In other examples, the risk assessment computing system 130 can directly control (e.g., allow, challenge, or deny) the interaction based on the responsive message or any data included therein. For example, if the responsive message indicates that the request exceeds a threshold risk value, then the responsive message may control initiation or completion of the interaction by preventing resources from being exchanged.Examples of Architectures Implementing TNAs for Access Control and Other Techniques

[0076] FIG. 4 is a flow diagram of a data flow 400 for generating an access indicator for controlling access or an interaction based on a set of temporal neural attributes that can be generated by a set of long short-term memory networks according to certain aspects of the present disclosure. As illustrated in FIG. 4, the data flow 400 may begin with time-series data 402. The time-series data 402 may relate to an entity. For example, the time-series data 402 may include data about a set of interactions over a certain period of time in which each interaction of the set of interactions may be initiated by, or otherwise involve, the entity.

[0077] An aggregator 404 may receive the time-series data 402 and may aggregate the time-series data 402 into aggregated data 406. For example, the aggregator 404 may aggregate each field of the time-series data 402 into a different column of the aggregated data 406. As illustrated in FIG. 4, the aggregated data 406 can include multiple columns of output data. The columns can include a first column 407A, a second column 407B, a third column 407C, and a fourth column 407D, though other suitable numbers, such as less than four or more than four, of columns are possible for the aggregated data 406. The first column 407A, the second column 407B, and the third column 407C can represent aggregated data values from the time-series data 402, and the fourth column 407D can represent an archive tracker that can link rows of the aggregated data 406 with different archives or time periods in the time-series data 402.

[0078] The aggregated data 406 may be provided to a second model. As illustrated in FIG.4, the second model may include a set of LSTM networks that can include a first LSTM network 408A, a second LSTM network 408B, and a third LSTM network 408C, though othersuitable numbers of LSTM networks are possible to include in the second model. In some examples, particular columns of the aggregated data 406 may be fed into different networks of the second model. For example, and as illustrated in FIG. 4, the first column 407A may be provided to the first LSTM network 408A, the second column 407B may be provided to the second LSTM network 408B, and the third column 407C may be provided to the third LSTM network 408C, etc. Each network of the second model may be trained or otherwise configured to generate an individual output, and the individual output can be a TNA specific to the input data provided to the network. For example, and as illustrated in FIG. 4, the first LSTM network 408A may generate a first TNA 410A, the second LSTM network 408B may generate a second TNA 410B, the third LSTM network 408C may generate a third TNA 410C, and so on. In some examples, each TNA generated by the second model can represent temporal patterns of data from the time-series data 402 and may preserve interpretability of outputs generated via the data flow 400.

[0079] The TNAs generated by the second model can be provided to a third model 412 that can be used to generate an output 414 that can be used for multiple downstream tasks. Some examples of the downstream tasks can include controlling access to a computing environment, making a decision regarding whether to reject an interaction request, and the like. The third model 412 can include an artificial intelligence model, a machine-learning model, a hard-coded algorithm or heuristic, other suitable models, or any combination thereof. In a particular example, the third model 412 can include a neural network, and the output 414 can be an inference output of the neural network.

[0080] In some examples, the third model 412 can receive the TNAs and one or more additional attributes. As illustrated in FIG. 4, the third model 412 can receive the first TNA 410A, the second TNA 410B, the third TNA 410C, and a set of entity attributes 416. The set of entity attributes 416 can include one or more attributes that are specific to an individual and that may represent a behavior of the individual. For example, the set of entity attributes 416 can include an identity score of the individual, a risk score of the individual, or other suitable scores that can be provided as input to the third model 412. The third model 412 may receive the first TNA 410A, the second TNA 410B, the third TNA 410C, and a set of entity attributes 416, and the third model 412 may generate the output 414 by executing code, by generating a set of inferences, or a combination thereof. The output 414 can include an access indicator that can be used as input to a separate model or a separate process for determining whether to allow the individual to access the computing environment or for other suitable purposes.

[0081] FIG. 5 is a flow diagram of a data flow 500 for generating an access indicator for controlling access or an interaction based on a set of temporal neural attributes (TNAs) that can be generated by a transformer model according to certain aspects of the present disclosure. As illustrated in FIG. 5, the data flow 500 may begin with the time-series data 402. The time-series data 402 may relate to an entity. For example, the time-series data 402 may include data about a set of interactions over a certain period of time in which each interaction of the set of interactions may be initiated by, or otherwise involve, the entity.

[0082] The time-series data 402 may be provided to or otherwise received by a first model 502 such as a transformer model, an aggregator, other suitable machine-learning model, etc. The first model 502, such as in examples in which the first model 502 is a transformer model, may include a bilinear self-attention regression (BSAR) transformer block. The first model 502 may be applied to data from the time-series data 402 after the data has been aggregated or before (or without) aggregating the data. For example, multiple iterations of the first model 502 may replace the LSTM models illustrated and described with respect to FIG. 4. In other examples, such as those illustrated by FIG. 5, the time-series data 402 may not be aggregated and may be provided as-a-whole directly to the first model 502. The first model 502 may generate aggregated data 406, may generate a set of TNAs, may generate other suitable outputs, or any combination thereof. For example, the first model 502 can generate the aggregated data 406 that includes multiple columns of aggregated data from the time-series data 402, and the aggregated data 406 can be provided to a first ML model 408A, a second ML model 408B, and a third ML model 408C, which can generate the first TNA 410A, the second TNA 410B, and the third TNA 410C, respectively. In other examples, the first model 502 can directly generate the first TNA 410A, the second TNA 410B, and the third TNA 410C. For example, the first model 502 can receive the time-series data 402, without previously aggregating the data, and can generate the first TNA 410A, the second TNA 410B, and the third TNA 410C based on the time-series data 402.

[0083] The TNAs generated by the first model 502 can be provided to a third model 412 that can be used to generate an output 414 that can be used for multiple downstream tasks. Some examples of the downstream tasks can include controlling access to a computing environment, making a decision regarding whether to reject an interaction request, providing specific content for the entity, and the like. The third model 412 can include an artificial intelligence model, a machine-learning model, a hard-coded algorithm or heuristic, other suitable models, or any combination thereof. In a particular example, the third model 412 can include a neural network, and the output 414 can be an inference output of the neural network.

[0084] In some examples, the third model 412 can receive the TNAs and one or more additional attributes. For example, the third model 412 can receive the first TNA 410A, the second TNA 41 OB, the third TNA 410C, and a set of entity attributes 416, though in other examples, the set of entity attributes 416 may be omitted. The set of entity attributes 416 can include one or more attributes that are specific to an individual and that may represent a behavior of the individual. For example, the set of entity attributes 416 can include an identity score of the individual, a risk score of the individual, or other suitable scores that can be provided as input to the third model 412. The third model 412 may receive the first TNA 410A, the second TNA 41 OB, the third TNA 410C, and a set of entity attributes 416, and the third model 412 may generate the output 414 by executing code, by generating a set of inferences, or a combination thereof. The output 414 can include an access indicator that can be used as input to a separate model or a separate process for determining whether to allow the individual to access the computing environment or for other suitable purposes.Example of Computing System

[0085] Any suitable computing system or group of computing systems can be used to perform the operations for the artificial intelligence techniques described herein. For example, FIG. 6 is a block diagram illustrating an example of a computing device 600, which can be used to implement the risk assessment server 118, the TNA model 121, or other suitable components of the computing environment 100. The computing device 600 can include various devices for communicating with other devices in the computing environment 100, for example as described with respect to FIG. 1. The computing device 600 can include various devices for performing one or more data consolidation or validation operations, artificial intelligence operations, or other suitable operations, described above with respect to FIGS. 1-5.

[0086] The computing device 600 can include a processor 602 that is communicatively coupled to a memory 604. The processor 602 can execute computer-executable program code stored in the memory 604, can access information stored in the memory 604, or both. Program code may include machine-executable instructions that may represent a procedure, a function, a subprogram, a program, a routine, a subroutine, a module, a software package, a class, or any combination of instructions, data structures, or program statements. A code segment may be coupled to another code segment or a hardware circuit by passing or receiving information, data, arguments, parameters, or memory contents. Information, arguments, parameters, data,etc., may be passed, forwarded, or transmitted via any suitable means including memory sharing, message passing, token passing, network transmission, among others.

[0087] Examples of a processor 602 can include a microprocessor, an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or any other suitable processing device. The processor 602 can include any suitable number of processing devices, including one. The processor 602 can include or communicate with a memory 604. The memory 604 can store program code that, when executed by the processor 602, causes the processor 602 to perform the operations described herein.

[0088] The memory 604 can include any suitable non-transitory computer-readable medium. The computer-readable medium can include any electronic, optical, magnetic, or other storage device capable of providing a processor with computer-readable program code or other program code. Non-limiting examples of a computer-readable medium can include a magnetic disk, memory chip, optical storage, flash memory, storage class memory, ROM, RAM, an ASIC, magnetic storage, or any other medium from which a computer processor can read and execute program code. The program code may include processor-specific program code generated by a compiler or an interpreter from code written in any suitable computerprogramming language. Examples of suitable programming language can include Hadoop, C, C++, C#, Visual Basic, Java, Python, Perl, JavaScript, ActionScript, etc.

[0089] The computing device 600 may also include a number of external or internal devices such as input or output devices. For example, the computing device 600 is illustrated with an input / output interface 608 that can receive input from input devices or provide output to output devices. A bus 606 can also be included in the computing device 600. The bus 606 can communicatively couple one or more components of the computing device 600.

[0090] The computing device 600 can execute program code 614 that can include the TNA model 121, or any other suitable computer model, computer module, computer service, or the like. The program code 614 for the TNA model 121 and the like may be resident in any suitable computer-readable medium and may be executed on any suitable processing device. For example, as depicted in FIG. 6, the program code 614 for the TNA model 121 can reside in, or may otherwise be included in, the memory 604 at the computing device 600 along with the program data 616 associated with the program code 614. Executing the TNA model 121 can configure the processor 602 to perform one or more of the operations, such as the artificial intelligence operations, described herein.

[0091] In some aspects, the computing device 600 can include one or more output devices. One example of an output device can be the network interface device 610 illustrated in FIG. 6.A network interface device 610 can include any device or group of devices suitable for establishing a wired or wireless data connection to one or more data networks described herein. Non-limiting examples of the network interface device 610 can include an Ethernet network adapter, a modem, etc.

[0092] Another example of an output device can include the presentation device 612 depicted in FIG. 6. A presentation device 612 can include any device or group of devices suitable for providing visual, auditory, or other suitable sensory output. Non-limiting examples of the presentation device 612 can include a touchscreen, a monitor, a speaker, a separate mobile computing device, etc. In some aspects, the presentation device 612 can include a remote client-computing device that can communicate with the computing device 600 using one or more data networks described herein. In other aspects, the presentation device 612 can be optional.

[0093] The foregoing description of some examples has been presented only for the purpose of illustration and description and is not intended to be exhaustive or to limit the disclosure to the precise forms disclosed. Numerous modifications and adaptations thereof will be apparent to those skilled in the art without departing from the spirit and scope of the disclosure.

Claims

Attorney Docket No. 096923-1548510 (EFX-213WO)ClaimsWhat is claimed is:

1. A computer-implemented method comprising:receiving, by a processor, time-series data relating to an entity, the time-series data comprising a plurality of different time-series information about a set of interactions involving the entity;pre-processing, by the processor and using a first model, the plurality of different timeseries information to generate pre-processed data based on the set of interactions;generating, by the processor and using a second model, a set of temporal neural attributes (TNAs) based on the pre-processed data;generating, by the processor and using a third model, an access indicator by using the set of TNAs as input to the third model; andoutputting, by the processor, a command comprising instructions executable to control access to an interactive computing environment based on the access indicator.

2. The computer-implemented method of claim 1, wherein the first model is a transformer model, wherein the second model is the same model as the first model, wherein the transformer model comprises instructions executable to cause the transformer model to aggregate the timeseries data and to generate the set of TNAs, and wherein pre-processing the plurality of different time-series information comprises (i) grouping sub-interactions indicated by the times-series data into interaction groups based on interaction type per archive and (ii) generating a time-series value that represents the interaction groups per archive.

3. The computer-implemented method of claim 1, wherein the first model is an aggregator model, wherein the second model is a plurality of long short-term memory (LSTM) networks, and wherein each LSTM network of the plurality of LSTM networks comprises different instructions to cause the LSTM network to generate a different TNA of the set of TNAs.

4. The computer-implemented method of claim 1, wherein the set of interactions has a plurality of different interaction types, and wherein pre-processing the time-series data comprises:generating a first grouping of data and a second grouping of data from the time-series data, wherein the first grouping of data includes data from a first type of interaction of theAttorney Docket No. 096923-1548510different interaction types, and wherein the second grouping of data includes data from a second type of interaction of the different interaction types;generating, for the first interaction type, a first counter attribute that tracks a first total number of interactions of the set of interactions of the first interaction type at a particular point in time; andgenerating, for the second interaction type, a second counter attribute that tracks a second total number of interactions of the set of interactions of the second interaction type at the particular point in time.

5. The computer-implemented method of claim 4, wherein the first counter attribute comprises a plurality of individual counter attributes, wherein each individual counter attribute of the plurality of individual counter attributes corresponds with a different time period.

6. The computer-implemented method of claim 4, wherein pre-processing the time-series data further comprises generating an aggregated interaction type attribute by aggregating versions of interaction attributes across interactions of a corresponding interaction type for each time period in the time-series data.

7. The computer-implemented method of claim 1, wherein the second model comprises a plurality of individual networks, wherein generating the set of TNAs comprises, for each network in the plurality of individual networks, generating an output using a dense output layer, wherein the output is a single scalar value or a vector embedding, and wherein the output is a TNA of the set of TNAs that represents temporal information from corresponding data of the time-series data.

8. The computer-implemented method of claim 7, wherein generating the set of TNAs further comprises generating a feature vector by concatenating each TNA of the set of TNAs and a plurality of entity-specific attributes, wherein the feature vector corresponds with the entity, and wherein the input into the third model is the feature vector.

9. A system comprising:a processor; anda non-transitory computer-readable medium comprising instructions that are executable by the processor to cause the processor to:Attorney Docket No. 096923-1548510receive time-series data relating to an entity, the time-series data comprising a plurality of different time-series information about a set of interactions involving the entity;aggregate, using a first model, the plurality of different time-series information to generate aggregated data based on the set of interactions;generate, using a second model, a set of temporal neural attributes (TNAs) based on the aggregated data;generate, using a third model, an access indicator by using the set of TNAs as input to the third model; andoutput a command comprising instructions executable to control access to an interactive computing environment based on the access indicator.

10. The system of claim 9, wherein the first model is a transformer model, wherein the second model is the same model as the first model, wherein the transformer model comprises instructions executable to cause the transformer model to aggregate the time-series data and to generate the set of TNAs, and wherein aggregate the plurality of different time-series information comprises (i) grouping sub-interactions indicated by the times-series data into interaction groups based on interaction type per archive and (ii) generating a time-series value that represents the interaction groups per archive.

11. The system of claim 9, wherein the first model is an aggregator model, wherein the second model is a plurality of long short-term memory (LSTM) networks, and wherein each LSTM network of the plurality of LSTM networks comprises different instructions to cause the LSTM network to generate a different TNA of the set of TNAs.

12. The system of claim 9, wherein the set of interactions has a plurality of different interaction types, and wherein aggregate the time-series data comprises:generating a first grouping of data and a second grouping of data from the time-series data, wherein the first grouping of data includes data from a first type of interaction of the different interaction types, and wherein the second grouping of data includes data from a second type of interaction of the different interaction types;generating, for the first interaction type, a first counter attribute that tracks a first total number of interactions of the set of interactions of the first interaction type at a particular point in time; andAttorney Docket No. 096923-1548510generating, for the second interaction type, a second counter attribute that tracks a second total number of interactions of the set of interactions of the second interaction type at the particular point in time, wherein the first counter attribute comprises a plurality of individual counter attributes, wherein each individual counter attribute of the plurality of individual counter attributes corresponds with a different time period.

13. The system of claim 12, wherein aggregate the time-series data further comprises generating an aggregated interaction type attribute by aggregating versions of interaction attributes across interactions of a corresponding interaction type for each time period in the time-series data.

14. The system of claim 9, wherein the second model comprises a plurality of individual networks, wherein generate the set of TNAs comprises, for each network in the plurality of individual networks, generating an output using a dense output layer, wherein the output is a single scalar value or a vector embedding, wherein the output is a TNA of the set of TNAs that represents temporal information from corresponding data of the time-series data, wherein generate the set of TNAs further comprises generating a feature vector by concatenating each TNA of the set of TNAs and a plurality of entity-specific attributes, wherein the feature vector corresponds with the entity, and wherein the input into the third model is the feature vector.

15. A non-transitory computer-readable medium comprising instructions that are executable by a processing device to cause the processing device to:receive time-series data relating to an entity, the time-series data comprising a plurality of different time-series information about a set of interactions involving the entity;aggregate, using a first model, the plurality of different time-series information to generate aggregated data based on the set of interactions;generate, using a second model, a set of temporal neural attributes (TNAs) based on the aggregated data;generate, using a third model, an access indicator by using the set of TNAs as input to the third model; andoutput a command comprising instructions executable to control access to an interactive computing environment based on the access indicator.Attorney Docket No. 096923-154851016. The non-transitory computer-readable medium of claim 15, wherein the first model is a transformer model, wherein the second model is the same model as the first model, wherein the transformer model comprises instructions executable to cause the transformer model to aggregate the time-series data and to generate the set of TNAs, and wherein aggregate the plurality of different time-series information comprises (i) grouping sub-interactions indicated by the times-series data into interaction groups based on interaction type per archive and (ii) generating a time-series value that represents the interaction groups per archive.

17. The non-transitory computer-readable medium of claim 15, wherein the first model is an aggregator model, wherein the second model is a plurality of long short-term memory (LSTM) networks, and wherein each LSTM network of the plurality of LSTM networks comprises different instructions to cause the LSTM network to generate a different TNA of the set of TNAs.

18. The non-transitory computer-readable medium of claim 15, wherein the set of interactions has a plurality of different interaction types, and wherein aggregate the time-series data comprises:generating a first grouping of data and a second grouping of data from the time-series data, wherein the first grouping of data includes data from a first type of interaction of the different interaction types, and wherein the second grouping of data includes data from a second type of interaction of the different interaction types;generating, for the first interaction type, a first counter attribute that tracks a first total number of interactions of the set of interactions of the first interaction type at a particular point in time; andgenerating, for the second interaction type, a second counter attribute that tracks a second total number of interactions of the set of interactions of the second interaction type at the particular point in time, wherein the first counter attribute comprises a plurality of individual counter attributes, wherein each individual counter attribute of the plurality of individual counter attributes corresponds with a different time period.

19. The non-transitory computer-readable medium of claim 18, wherein aggregate the timeseries data further comprises generating an aggregated interaction type attribute by aggregating versions of interaction attributes across interactions of a corresponding interaction type for each time period in the time-series data.Attorney Docket No. 096923-154851020. The non-transitory computer-readable medium of claim 15, wherein the second model comprises a plurality of individual networks, wherein generate the set of TNAs comprises, for each network in the plurality of individual networks, generating an output using a dense output layer, wherein the output is a single scalar value or a vector embedding, wherein the output is a TNA of the set of TNAs that represents temporal information from corresponding data of the time-series data, wherein generate the set of TNAs further comprises generating a feature vector by concatenating each TNA of the set of TNAs and a plurality of entity-specific attributes, wherein the feature vector corresponds with the entity, and wherein the input into the third model is the feature vector.