WO2020181911A1 - 一种风险识别方法及装置 - Google Patents

一种风险识别方法及装置 Download PDF

Info

Publication number
WO2020181911A1
WO2020181911A1 PCT/CN2020/070679 CN2020070679W WO2020181911A1 WO 2020181911 A1 WO2020181911 A1 WO 2020181911A1 CN 2020070679 W CN2020070679 W CN 2020070679W WO 2020181911 A1 WO2020181911 A1 WO 2020181911A1
Authority
WO
WIPO (PCT)
Prior art keywords
risk
event
subject
category
information
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2020/070679
Other languages
English (en)
French (fr)
Inventor
金宏
叶芸
赵乾坤
刘星
袁锦程
肖凯
王维强
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Alibaba Group Holding Ltd
Original Assignee
Alibaba Group Holding Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Alibaba Group Holding Ltd filed Critical Alibaba Group Holding Ltd
Publication of WO2020181911A1 publication Critical patent/WO2020181911A1/zh
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q10/00Administration; Management
    • G06Q10/06Resources, workflows, human or project management; Enterprise or organisation planning; Enterprise or organisation modelling
    • G06Q10/063Operations research, analysis or management
    • G06Q10/0635Risk analysis of enterprise or organisation activities

Definitions

  • the embodiments of this specification relate to the field of data processing technology, and in particular to a risk identification method and device.
  • Fraud case analysis occupies a very important position in the entire risk control strategy and business operations. Analysts need to spend a lot of time and energy to analyze the case to determine whether a case is a fraud case. The analysis efficiency is low, and the analysis results will vary due to Different analysts produce differences.
  • the embodiments of this specification provide a method and device for risk identification, which solve the technical problem of low analysis efficiency in the prior art and differences in analysis results due to different analysts.
  • the embodiment of this specification provides a risk identification method, including:
  • the pattern information of each risk behavior category is generated.
  • the pattern information of each risk behavior category includes: more than one risk behavior characteristics corresponding to each risk behavior information and each The weight of each of the risk behavior characteristics;
  • the risk identification of the target event is performed according to the pattern information of each risk behavior
  • the embodiment of this specification provides a risk identification method, including:
  • the model information of each risk subject category is generated.
  • the model information of each risk subject category includes: more than one risk subject characteristics corresponding to the information related to each risk subject and The weight of the characteristics of each risk subject;
  • the embodiment of this specification provides a risk identification device, including:
  • a case portrait generating unit configured to generate a case portrait of each risk event sample in a plurality of risk event samples, the case portrait including risk behavior information
  • the cluster processing unit is configured to perform cluster processing on the multiple risk event samples based on the risk behavior information of each risk event sample to obtain multiple risk behavior categories;
  • the pattern generation unit is configured to generate pattern information of each risk behavior category according to the risk event samples included in each risk behavior category, and the pattern information of each risk behavior category includes: more than one corresponding to each risk behavior information The risk behavior characteristics of and the weight of each of the risk behavior characteristics;
  • the identification unit is used to identify the target event according to the pattern information of each risk behavior when the risk identification of the target event is required.
  • the embodiment of this specification provides a risk identification device, including:
  • a case portrait generating unit for generating a case portrait of each of the risk event samples in a plurality of risk event samples, the case portrait including information related to the risk subject;
  • the cluster processing unit is configured to perform cluster processing on the multiple risk event samples based on the risk subject related information of each risk event sample to obtain multiple risk subject categories;
  • the pattern generation unit is configured to generate pattern information of each risk subject category according to the risk event samples included in each risk subject category, and the pattern information of each risk subject category includes: one corresponding to each risk subject related information The above risk subject characteristics and the weight of each said risk subject characteristic;
  • the identification unit is used to identify the event according to the pattern information of each risk subject when the event needs to be risk identified.
  • the embodiments of this specification provide a computer-readable storage medium on which a computer program is stored, and the program is executed by a processor to execute the steps of the method.
  • the embodiments of this specification also provide a computer device including a memory, a processor, and a computer program stored on the memory and capable of running on the processor, and the processor implements the steps of the method when the program is executed.
  • the case portraits include risk behavior information or risk subject related information; based on the risk behavior information or risk subject related information of each risk event sample, Multiple risk event samples are clustered to obtain multiple risk behavior categories or risk subject categories; according to the risk event samples included in each risk behavior category or risk subject category, pattern information for each risk behavior category or risk subject category is generated
  • identify the target event based on the pattern information of each risk behavior category or risk subject category, so as to realize the transaction audited by the identified strategy, reported but not finalized Intelligent trial of cases such as transactions, other uncompleted or completed or ongoing transactions, which can realize the automatic driving of the risk control system, and solve the low analysis efficiency in the existing technology.
  • the analysis results are different due to different analysts. And the technical issues that make the difference.
  • Fig. 1 shows a method flowchart of a risk identification method according to an embodiment of this specification
  • FIG. 2 shows a schematic diagram of a personal portrait in the risk identification method in FIG. 1;
  • Fig. 3 shows a method flowchart of a risk identification method according to another embodiment of this specification
  • Fig. 4 shows a schematic diagram of a risk identification device according to an embodiment of this specification
  • Figure 5 shows a schematic diagram of a risk identification device according to another embodiment of this specification.
  • Fig. 6 shows a schematic diagram of a computer device according to an embodiment of the present specification.
  • the first embodiment of this specification provides a risk identification method.
  • the risk identification method can be used for case analysis, such as game cases, telecommunications cases, etc., and can also be used in safety education to improve the risk identification ability of relevant personnel, or generate risk prevention and control strategies for use in risk control engines .
  • FIG. 1 is a method flowchart of a risk identification method according to an embodiment of this specification.
  • the risk identification method includes the following steps:
  • Step 110 Obtain multiple risk event samples, and generate a case portrait of each risk event sample, where the case portrait includes case description information.
  • the sample of risk events is obtained from cases that have been characterized, and can be typical cases selected from the cases that have been qualitative, or they can be randomly selected from cases; it can also be all cases that have been qualitative.
  • the specific selection method of risk event samples is not limited, and risk event samples can be selected according to requirements.
  • a case portrait of each risk event sample is generated.
  • the case portrait is used to describe information for each risk event, so that the description information of each risk event can be quickly obtained.
  • the case description information may be one or more of user information, risk subject related information, fund exchange information, case description information, and the like.
  • User information may include name, gender, age, account number and other related information.
  • the risk subject is the subject that performs the risk behavior.
  • the risk subject related information includes the risk subject’s ID such as name or account number or ID number, the risk subject’s instant messaging application account such as QQ, WeChat, etc., and the risk subject’s payment application account such as One or more of Alipay account number, bank card information of risk subject, equipment number of risk subject, IP address of risk subject, etc.
  • the fund transaction information includes information such as the transfer amount and transfer method, and the case description information includes risk behavior information, the cause, process, and result of the case.
  • Risk behavior information refers to the behavior of the risk subject, such as opening flower consumption, opening borrowing and borrowing money, changing the bound mobile phone number, changing the bound email number, changing the password, changing the payment location, changing the delivery address, and purchasing specific One or more of the commodities.
  • Huabei and Borrowbe are both a kind of lending tool, including user information, through which users can borrow. Purchasing a specific product, such as buying a category that has not been purchased before, buying the same product repeatedly, etc.
  • the case portrait also includes qualitative reasons, that is, the process and reasons for determining the event as a risk event.
  • the qualitative reason is obtained by analyzing the reason code of the discriminant model. Specifically, the method for obtaining the qualitative reason is specifically:
  • An interpretable algorithm is used to obtain multiple qualitative variables and rankings of risk events from the case description information; and to obtain qualitative reasons based on the ranking of multiple qualitative variables of risk events.
  • the case profile may also include: qualitative processing (such as determining a risk event), in-event identification (such as unaudited transaction UCT strategy), etc., in-event identification (ie, real-time identification, such as for each entry Risk judgment for the transaction), etc.
  • qualitative processing such as determining a risk event
  • in-event identification such as unaudited transaction UCT strategy
  • in-event identification ie, real-time identification, such as for each entry Risk judgment for the transaction
  • the embodiment of this specification uses a game case as an example to illustrate the case portrait.
  • the case portrait includes qualitative processing, users, risk subjects, capital transactions, identification in the event, description of the case, and qualitative reasons.
  • the two parties because the two parties (the user and the risk subject) have no credible relationship and there is no historical transaction, they are classified as a risk event.
  • step 120 is entered.
  • Step 120 Based on the case behavior information of each risk event sample, clustering multiple risk event samples to obtain multiple risk behavior categories.
  • the risk event samples can be clustered according to one or more types of information included in the case description information to obtain multiple risk event categories.
  • the risk event samples are clustered mainly based on risk behavior information, which will be described in detail below.
  • Clustering is the processing of clustering algorithms on samples.
  • the clustering algorithm is a type of algorithm that automatically classifies things.
  • the clustering algorithm is a typical unsupervised learning algorithm. In the clustering algorithm, different Similarity measurement method gathers things with similar attributes into the same category.
  • the clustering algorithm is based on similarity, and there are more similarities between patterns in a cluster than patterns not in the same cluster.
  • the risk event category represents the category of each risk event sample.
  • the risk event category can be set to 1, 2, 3, or a, b, or c.
  • this application uses an unsupervised algorithm—clustering algorithm, there is no Label samples. Therefore, this risk event category is just a category label and does not represent any characteristic information of the category.
  • risk event categories of the risk event samples of each category are the same, that is, clustering the same or similar groups into the same category, and set them as categories If the information is the same, the risk behavior information of all risk event samples of this category is the same or similar.
  • the following example illustrates the clustering of risk event samples based on risk behavior information. Assuming that the number of risk event samples is 5 (numbered 1 to 5), clustering risk event samples based on risk behavior information. Obtain the risk event categories of 2 risk behaviors, as shown in Table 1.
  • Table 1 Schematic table of clustering processing based on risk behavior information
  • Sample Risk behavior information Clustering result Sample 1 Change password, change mobile phone Risky behavior 1 Sample 2 Open to borrow money Risky behavior 2 Sample 3 Change password, change email address Risky behavior 1 Sample 4 Open huabei consumption Risky behavior 2 Sample 5 Open huabei consumption Risky behavior 2
  • risk event sample 1 and risk event sample 3 are similar, they are all changing passwords, changing mobile phones, and changing email addresses. Then risk event sample 1 and risk event sample 3 are combined.
  • the category is the risk event category of risk behavior 1; while the risk behaviors of risk event sample 2, risk event sample 4, and risk event sample 5 are similar, all of which are through the opening of borrowing money and spending, then the risk event sample 2.
  • Risk event sample 4 and risk event sample 5 are clustered into risk event categories of risk behavior 2. That is, based on the risk behavior information, five samples are gathered into two risk event categories, risk event category of risk behavior 1 and risk event category of risk behavior 2.
  • the clustering of multiple risk event samples based on the risk behavior information of each risk event sample to obtain multiple risk event categories includes:
  • sequence data is generated, the graph vector is constructed by the node2vec method to obtain the first clustering feature, and the graph vector is constructed by the word2vec method to obtain the second clustering feature;
  • the structured vector feature is combined with the first clustering feature and the second clustering feature to obtain structured data; clustering is performed on the structured data using a clustering algorithm to obtain multiple risk events category.
  • the preset structured vector feature is set by the developer based on business experience. It is also called empirical variable or empirical feature. By setting this preset structured vector feature, the clustering result is closer to the real result. After obtaining Xi, Xj, and Xk, by concatenating Xi, Xj, and Xk according to columns, the result of clustering risk event samples based on risk behavior information can be obtained.
  • step 130 is entered.
  • Step 130 Generate pattern information of each risk behavior category according to the risk event samples included in each risk behavior category, where the pattern information of each risk behavior category includes: more than one risk behavior corresponding to each risk behavior information Characteristics and the weight of each of the risk behavior characteristics.
  • step 130 is entered to generate pattern information based on each risk behavior category.
  • the specific risk behavior information can be extracted by keywords or through AI (artificial intelligence) to generate the risk event samples of the risk event category.
  • the risk behavior information can also be directly obtained based on the case portraits of the risk event samples in the risk event category.
  • Each mode information corresponds to a risk behavior category, that is, a risk behavior category has only one mode information.
  • the number of risk behavior characteristics contained in each mode information is determined based on the risk behavior information contained in the risk behavior component samples of the risk behavior component category. There may be one or multiple risk behavior characteristics corresponding to each risk behavior in each mode information.
  • the weight of each risk behavior feature is determined according to the importance of the risk behavior feature, the important risk behavior feature weight is high, and the secondary risk behavior feature weight is low, that is, the more important risk behavior feature weight value Higher.
  • the risk behavior characteristics corresponding to each risk behavior information include: enabling specific functions, enabling specific permissions, changing the bound phone number, changing the bound email address, changing the password, and paying. Change of location, change of delivery address and/or purchase of specific goods. That is, the risk behavior characteristics corresponding to the risk behavior information can be to enable specific functions, enable specific permissions, change the bound mobile phone number, change the bound email number, change the password, change the payment location, change the delivery address, and purchase specific One or more of commodities, etc. Purchasing a specific product, such as buying a category that has not been purchased before, buying the same product repeatedly, etc.
  • risk behavior characteristics For example, in a certain risk behavior category, there are three risk behavior characteristics: turn on a specific function, change the payment location, and change the delivery address. Among them, the importance of the risk behavior feature of "turn on a particular function, turn on a particular permission" If it is the highest, the weight value of this risk behavior feature is the largest. If it is set to 0.8, the importance of the other two risk behavior characteristics is the same, then the weight value of the two risk behavior characteristics is set to the same, such as 0.2.
  • the generating pattern information of each risk behavior category according to the risk event samples included in each risk behavior category includes:
  • This method is carried out by a human setting method. After determining the risk behavior characteristics based on the risk behavior information, the weight of each risk behavior characteristic is determined according to the importance of the risk behavior characteristics. The importance of each risk behavior feature can be set based on experience or based on the results of big data analysis.
  • the risk behavior information of the risk event sample of this risk behavior category is the opening of borrowing money. Based on the risk behavior information, it can be determined that the risk is related to the risk.
  • the risk behavior characteristic corresponding to the behavior information turn on a specific function and set the weight of the risk behavior characteristic to 1, then you can obtain the pattern information 1 of the risk behavior category.
  • the risk behavior information of a certain risk behavior category is password change and mobile phone replacement. Based on the risk behavior information, two risk behavior characteristics corresponding to the risk behavior information are determined, risk behavior feature 1—change the bound mobile phone number, Risk behavior feature 2—change the password, set the weight of risk behavior feature 1 to 0.5, and risk behavior feature 2 to 0.5, and obtain mode information 2, as shown in Table 2 below.
  • the generating pattern information of each risk behavior category according to the risk event samples included in each risk behavior category includes:
  • the pattern information of the risk behavior category is obtained.
  • This method is to obtain mode information through a preset model.
  • the preset model is used to analyze the risk event samples of the input risk behavior category, and output the risk behavior characteristics and weights corresponding to the risk behavior of the risk behavior category.
  • the preset mode may specifically be a model based on a neural network such as a convolutional neural network (Convolutional Neural Networks, CNN) model or a recurrent neural network (RNN).
  • CNN convolutional neural network
  • RNN recurrent neural network
  • step 140 After obtaining the mode information, go to step 140.
  • Step 140 When risk identification of the target event is required, risk identification of the target event is performed according to the pattern information of each risk behavior category.
  • the target event may be one or more events, including but not limited to transactions audited by an identification strategy, transactions reported but not finalized, other uncompleted or completed or ongoing transactions, etc. By determining whether the target event is a risk event, potential risk behaviors can be discovered, and hidden risk events can also be unearthed. When it is identified that the target event is a risk event, it can be intercepted or reminded.
  • the risk identification of the target event according to the pattern information of each risk behavior category includes: scoring the target event according to the pattern information of each risk behavior category to obtain a scoring result; According to the scoring result, it is determined whether the target event is a risk event.
  • the scoring the target event according to the pattern information of each risk behavior category to obtain the scoring result includes:
  • the pattern information extracted from the target event and each risk behavior category includes more than one risk behavior feature
  • a scoring result of the target event in each risk behavior category is obtained.
  • the risk behavior feature of mode information 1 obtained based on the risk behavior category is to turn on a specific function, and the weight of the risk behavior feature is 1 as an example for illustration. Identify whether the target event has a specific function enabled, such as whether it is enabled for consumption, borrowing, and so on. If so, extract the feature and obtain the weight value 1 corresponding to the feature, and then obtain the target event in mode information 1 The scoring result of the corresponding risk behavior category is 1.
  • the pattern information 2 of a certain risk behavior category has two risk behavior characteristics, risk behavior characteristic 1—change the bound mobile phone number, risk behavior characteristic 2—change password, set the weight of risk behavior characteristic 1 to 0.5, risk Behavior feature 2 is 0.5. Identify whether the target event has a password change and whether it is a change of the bound mobile phone number. If the target event has risk behavior feature 2—change the password, based on the weight of risk behavior feature 2, the score is 0.5.
  • the determining whether the target event is a risk event based on the scoring result includes: determining whether the scoring result of the target event in each risk behavior category is greater than the preset score of the risk behavior category Value; if yes, it is determined that the target event is a risk event of the risk behavior category.
  • the target event is determined to be a risk event of a certain risk behavior category. For example, if the score result of a target event is 0.9 and the default value is set to 0.8, then the score result is greater than the default value and the Based on the risk events of the risk behavior category, transactions can be intercepted or users can be reminded.
  • the risk level of the target event can be identified based on the preset scores. For example, the risk level is high, the risk level is low, and the risk level is medium. Based on the different risk levels, generate Unwanted strategies. If the risk is high, the intercepted prevention and control strategy directly intercepts the transaction. If the risk is low, a prompt message is generated to remind the user that there is a risk. By generating a prevention and control strategy, it can be automatically and intelligently recommended to the user or enforced before the user reports the case, reducing the occurrence of risk events. Through this method, it can be connected with the risk control engine to realize the automatic and intelligent recommendation of the strategy. Thereby improving the security of transactions.
  • the risk identification of the target event according to the pattern information of each risk behavior category includes:
  • the target event is a risk event.
  • the method further includes: generating a safety education page based on the mode information, and displaying the safety education page. Specifically, if the mode information is based on the behavior category of the case—change the bound phone number, change the password, and then promote the modification of safer passwords based on users who may be stolen. Based on the model information, safety education information can be generated for different groups of people, so that safety education can be conducted for different groups of people, and the operation of users' minds can be realized.
  • the method of the embodiment of this specification can be used for the service of intelligent trial.
  • the event that needs to be reviewed is the target event, and the event is applied for through the method of the embodiment of this specification to determine which risk behavior category the event belongs to. , So as to realize the automatic driving of the risk control system.
  • clustering can be performed on the target events of each risk behavior category to obtain more than one risk subject category, and then obtain the pattern information of each risk subject category, based on The pattern information identifies the event to be identified; it is also possible to directly extract the risk subject-related information of the target event included in each risk behavior category, and identify the event to be identified based on the relevant information of the risk subject, as described in detail below.
  • the method further includes:
  • cluster the target events of the risk behavior category Based on the risk subject-related information of each target event of each risk behavior category, cluster the target events of the risk behavior category to obtain more than one risk subject category;
  • the model information of each risk subject category is generated;
  • the model information of each risk subject category specifically includes: more than one risk subject characteristics corresponding to the relevant information of each risk subject, and The weight of the characteristics of each risk subject;
  • multiple target events can be clustered based on the risk subject related information to obtain more than one risk subject category.
  • the means of detecting risk subject groups can be connected graph association through strong media, establishing the relationship between user and device number, user and card number, user and phone number, and expanding the risk subject group through layer-by-layer correlation. For example, user 1 and card 1 are associated, card 1 and user 2 are associated, user 1 is associated with device 1, and device 1 and user 3 are associated. Through the Unicom relationship, it can be found that user 1, user 2, and user 3 belong to the same Risk subject group.
  • risk behaviors can also be performed by autonomously selecting media such as IP addresses. Based on the clustering algorithm, the related risk subjects are clustered together to obtain the risk subject categories obtained by clustering the risk subjects.
  • the risk subject characteristics corresponding to the relevant information of each risk subject include: ID, instant messaging application account, payment application account, bank card information, phone number, email address, operating device number and/or IP address. That is, the risk subject characteristics corresponding to the relevant information of each risk subject include: one of ID, instant messaging application account, payment application account, bank card information, telephone number, e-mail address, operating device number, IP address, etc. Or multiple. ID, instant messaging application account, payment application account, bank card information, phone number, e-mail address, operating device number, and IP address are all information for risk subjects.
  • Each model information corresponds to a risk subject category, that is, there is only one model information for a risk subject category.
  • the number of risk subject characteristics contained in each model information is determined based on the risk subject related information contained in the risk event sample of the risk subject category.
  • the weight of each of the risk subject characteristics is determined according to the importance of the risk subject’s characteristics, the important risk subject’s characteristic weight is higher, and the secondary risk subject’s characteristic weight is low, that is, the more important risk subject’s characteristic weight value Higher.
  • the risk subject related information in this risk subject category includes users, equipment, and cards. Therefore, based on the risk subject related information, Obtain three risk subject characteristics: ID, bank card information, and operating device number. Among them, the risk subject feature—the operating device number is the most important, and the weight value of this risk subject feature is the largest, such as set to 0.7, the other two Risk subject characteristics—ID and bank card information are the second most important, and they can be set to 0.2 and 0.3 respectively to generate model information.
  • the identification of the event to be identified through the pattern information of each risk subject category includes:
  • the model information of a certain risk subject category includes three risk subject related characteristics: ID, bank card information, and operating device number, with weights of 0.2, 0.3, and 0.7 respectively. Extract whether the event to be identified has three relevant characteristics of risk subjects. If it is identified that the event to be identified has two of the risk subject related feature IDs and operating device numbers, then extract the relevant characteristics of the two risk subjects based on the relevant characteristics of the two risk subjects The weight of, the scoring result of the event to be identified can be obtained as 0.9. Based on the scoring result, the event to be identified can be determined as a risk event.
  • the method further includes:
  • the risk subject related information includes the risk subject’s ID such as name or account number or ID number, the risk subject’s instant messaging application account such as QQ, WeChat, etc., the risk subject’s payment application account such as Alipay account, etc., and the risk subject’s bank card.
  • the risk subject s ID such as name or account number or ID number
  • the risk subject s instant messaging application account such as QQ, WeChat, etc.
  • the risk subject s payment application account such as Alipay account, etc.
  • the risk subject’s bank card One or more of information, equipment number of risk subject, IP address of risk subject, etc.
  • the ID of the risk subject in the event to be identified is the same as the ID of the risk subject of the target event of a certain risk behavior category, then according to the preset rule, the ID of the risk subject is the same to determine whether the event to be identified is a risk event.
  • the embodiment of this specification obtains case portraits of multiple risk event samples, where the case portraits include risk behavior information; based on the risk behavior information of each risk event sample, clustering the multiple risk event samples to obtain multiple Risk behavior categories; according to the risk event samples included in each risk behavior category, the pattern information of each risk behavior category is generated.
  • the pattern information of each risk behavior category Risk identification of the target event can realize the intelligent trial of the transactions audited by the identified strategy, the reported but unfinished transaction, and other unfinished or completed or ongoing transactions, so as to achieve risk control
  • the automatic driving of the system solves the technical problem of low analysis efficiency in the existing technology and the difference of analysis results due to different analysts.
  • this application clusters risk event samples based on risk behavior information, and realizes classification of risk event samples from different perspectives of risk behavior, so that the pattern information generated based on each wind behavior category can better reflect the category.
  • the risk identification method includes:
  • Step 310 Obtain a plurality of risk event samples, and generate a case portrait of each risk event sample, where the case portrait includes information related to the risk subject.
  • Step 320 Based on the risk subject related information of each risk event sample, clustering the multiple risk event samples to obtain multiple risk subject categories.
  • a risk subject group refers to two or more members, based on the common intention and goal of violating the law, using common needs, interests, values and other psychological factors as the spiritual bond, entangled together, and carried out multiple joint actions that are illegal. Risky behavior. Based on the risk subject's information, the risk subject group associated with the risk subject in the risk event sample can be determined, and based on the risk subject group, risk subject clustering can be performed.
  • the corresponding risk subjects behind all risk events are of a group nature.
  • a label propagation (LPA) algorithm can be used.
  • the logical structure of the LPA algorithm is as follows: At the beginning, a full network of all samples is constructed. Through the qualitative results of the case, qualitative black samples are found. Starting from the black samples, after multiple rounds of iterations, it can be found that the surrounding samples are slowly contagious. At this point, two subgroups are discovered as risk subject groups. The program starts from the black sample to infect the remaining samples, scores the remaining samples, and judges whether the sample is a risk event according to the size of the score, so as to achieve the purpose of discovering the risk subject group.
  • multiple risk event samples can be clustered based on the risk subject related information to obtain multiple risk event categories.
  • the means of detecting risk subject groups can be connected graph association through strong media, establishing the relationship between user and device number, user and card number, user and phone number, and expanding the risk subject group through layer-by-layer correlation. For example, user 1 and card 1 are associated, card 1 and user 2 are associated, user 1 is associated with device 1, and device 1 and user 3 are associated. Through the Unicom relationship, it can be found that user 1, user 2, and user 3 belong to the same Risk subject group.
  • risk behaviors can also be performed by autonomously selecting media such as IP addresses. Based on the clustering algorithm, the related risk subjects are gathered together to obtain the risk event category obtained by clustering the risk subjects.
  • the risk subject characteristics corresponding to the relevant information of each risk subject include: ID, instant messaging application account, payment application account, bank card information, phone number, email address, operating device number and/or IP address. That is, the risk subject characteristics corresponding to each risk subject include: one or more of ID, instant messaging application account, payment application account, bank card information, phone number, email address, operating device number, IP address, etc. Kind. ID, instant messaging application account, payment application account, bank card information, phone number, e-mail address, operating device number, and IP address are all information for risk subjects.
  • step 330 is entered.
  • Step 330 Generate model information of each risk subject category according to the risk event samples included in each risk subject category.
  • the model information of each risk subject category includes: more than one risk corresponding to the information related to each risk subject Subject characteristics and the weight of each risk subject characteristic.
  • Each model information corresponds to a risk subject category, that is, there is only one model information for a risk subject category.
  • the number of risk subject characteristics contained in each model information is determined based on the risk subject related information contained in the risk event sample of the risk subject category.
  • the weight of each of the risk subject characteristics is determined according to the importance of the risk subject’s characteristics, the important risk subject’s characteristic weight is higher, and the secondary risk subject’s characteristic weight is low, that is, the more important risk subject’s characteristic weight value Higher.
  • the risk subject related information in this risk subject category includes users, equipment, and cards. Therefore, based on the risk subject related information, Obtain three risk subject characteristics: ID, bank card information, and operating device number. Among them, the risk subject feature—the operating device number is the most important, and the weight value of this risk subject feature is the largest, such as set to 0.7, the other two Risk subject characteristics—ID and bank card information are the second most important, and they can be set to 0.2 and 0.3 respectively to generate model information.
  • the model information of each risk subject category is generated, including:
  • This method is carried out by means of human setting. After determining the characteristics of the risk subject based on the relevant information of the risk subject, the weight of each of the risk subject characteristics is determined according to the importance of the risk subject's characteristics. The importance of the characteristics of each risk subject can be set based on experience or based on the results of big data analysis.
  • the risk subject related information in this risk subject category includes user, equipment, and card. Based on this information, the three risk subject characteristics of the model information of the risk subject category can be determined : ID, bank card information, operating equipment number. Since the risk subject feature—the operating equipment number is the most important, the weight value of this risk subject feature is the largest, such as set to 0.7. The other two risk subject features—ID, bank The importance of card information is second, set to 0.2 and 0.3 respectively.
  • model information for each risk subject category including:
  • the model information of the risk subject category is obtained.
  • This method is to obtain mode information through a preset model.
  • the preset model is used to analyze the input risk event samples of a certain risk subject category, and output the risk subject related information corresponding to the risk subject characteristics and weights of the risk subject component category.
  • the preset mode may specifically be a model based on a neural network such as a convolutional neural network (Convolutional Neural Networks, CNN) model or a recurrent neural network (RNN).
  • a convolutional neural network Convolutional Neural Networks, CNN
  • RNN recurrent neural network
  • step 340 After obtaining the mode information, go to step 340.
  • Step 340 When it is necessary to perform risk identification on an event, perform risk identification on the event according to the pattern information of each risk subject.
  • the target event may be one or more events, including but not limited to transactions audited by an identification strategy, transactions reported but not finalized, other uncompleted or completed or ongoing transactions, etc. By determining whether the target event is a risk event, potential risk behaviors can be discovered, and hidden risk events can also be unearthed. When it is identified that the target event is a risk event, it can be intercepted or reminded.
  • the performing risk identification of the event according to the pattern information of each risk subject category includes:
  • the embodiment of this specification obtains case portraits of multiple risk event samples, the case portraits include risk subject related information; based on the risk subject related information of each risk event sample, clustering the multiple risk event samples, Obtain multiple risk subject categories; according to the risk event samples included in each risk subject category, generate model information for each risk subject category, and according to the model information of each risk subject category when risk identification of the target event is required ,
  • the risk identification of the target event can realize the intelligent trial of the transaction audited by the identified strategy, the reported but not finalized transaction, other unfinished or completed or ongoing transactions, etc., so as to achieve
  • the automatic driving of the risk control system solves the technical problem of low analysis efficiency in the existing technology and the difference of analysis results due to different analysts.
  • this application clusters the risk event samples based on the relevant information of the risk subject, so as to classify the risk event samples from different perspectives of the risk subject, so that the pattern information generated based on each risk subject category can better reflect this The characteristics of the category of risk events, and then when identifying the target event, improve the risk recognition rate.
  • the risk identification device includes:
  • a case portrait generating unit 410 configured to generate a case portrait of each risk event sample in a plurality of risk event samples, the case portrait including risk behavior information;
  • the cluster processing unit 420 is configured to perform cluster processing on the multiple risk event samples based on the risk behavior information of each risk event sample to obtain multiple risk behavior categories;
  • the pattern generating unit 430 is configured to generate pattern information of each risk behavior category according to the risk event samples included in each risk behavior category, and the pattern information of each risk behavior category includes: one corresponding to each risk behavior information The above risk behavior characteristics and the weight of each risk behavior characteristic;
  • the identification unit 440 is configured to identify the target event according to the pattern information of each risk behavior when the risk identification of the target event is required.
  • the device further includes an obtaining unit configured to obtain risk subject-related information of each target event of each risk behavior category; the cluster processing unit 240 is also configured to obtain information based on each risk behavior category For the risk subject related information of each target event, cluster the target events of the risk behavior category to obtain more than one risk subject category;
  • the pattern generation unit 430 is further configured to generate pattern information of each risk subject category according to the target events included in each risk subject category; the pattern information of each risk subject category specifically includes: information related to each risk subject Corresponding more than one characteristic of risk subject and the weight of each characteristic of said risk subject;
  • the identification unit 440 is further configured to identify the event to be identified through the pattern information of each risk subject category.
  • the risk behavior characteristics corresponding to each risk behavior information are: enable specific functions, enable specific permissions, change the bound phone number, change the bound email address, change the password, change the payment location, change the delivery Address or purchase a specific item.
  • the device further includes an obtaining unit, which is used to obtain risk subject related information of the target event of each risk behavior category; the identification unit 440 is also used to treat risk subject related information of each risk behavior category Identify the event for identification.
  • the identification unit 440 is specifically configured to extract the characteristics of the risk subject corresponding to the pattern information of each risk event category in the target event, and determine the characteristics of the risk subject based on the extracted characteristics of the risk subject and the weight corresponding to each risk subject feature State whether the target event is a risk event of the risk subject category.
  • the risk subject characteristics corresponding to the relevant information of each risk subject are: ID, instant messaging application account, payment application account, bank card information, telephone number, e-mail address, operating device number or IP address.
  • the embodiment of this specification obtains case portraits of multiple risk event samples, where the case portraits include risk behavior information; based on the risk behavior information of each risk event sample, clustering the multiple risk event samples to obtain multiple Risk behavior categories; according to the risk event samples included in each risk behavior category, the pattern information of each risk behavior category is generated.
  • the pattern information of each risk behavior category Risk identification of the target event can realize the intelligent trial of the transactions audited by the identified strategy, the reported but unfinished transaction, and other unfinished or completed or ongoing transactions, so as to achieve risk control
  • the automatic driving of the system solves the technical problem of low analysis efficiency in the existing technology and the difference of analysis results due to different analysts.
  • this application clusters risk event samples based on risk behavior information, and realizes classification of risk event samples from different perspectives of risk behavior, so that the pattern information generated based on each wind behavior category can better reflect the category.
  • the risk identification device includes:
  • the case portrait generating unit 510 is configured to generate a case portrait of each risk event sample in a plurality of risk event samples, the case portrait including information related to the risk subject;
  • the cluster processing unit 520 is configured to perform cluster processing on the multiple risk event samples based on the risk subject related information of each risk event sample to obtain multiple risk subject categories;
  • the pattern generation unit 530 is configured to generate pattern information of each risk subject category according to the risk event samples included in each risk subject category, and the pattern information of each risk subject category includes: information corresponding to each risk subject More than one risk subject characteristics and the weight of each said risk subject characteristic;
  • the identification unit 540 is configured to perform risk identification on the event according to the pattern information of each risk subject when the event needs to be risk identified.
  • the identification unit 540 is specifically configured to extract the risk subject characteristics corresponding to the pattern information of each risk subject category in the event, and based on the extracted risk subject characteristics and the weight corresponding to each risk subject feature, Determine whether the event is a risk event.
  • the risk subject characteristics corresponding to the relevant information of each risk subject are: ID, instant messaging application account, payment application account, bank card information, telephone number, e-mail address, operating device number or IP address.
  • the embodiment of this specification obtains case portraits of multiple risk event samples, the case portraits include risk subject related information; based on the risk subject related information of each risk event sample, clustering the multiple risk event samples, Obtain multiple risk subject categories; according to the risk event samples included in each risk subject category, generate model information for each risk subject category, and according to the model information of each risk subject category when risk identification of the target event is required ,
  • the risk identification of the target event can realize the intelligent trial of the transaction audited by the identified strategy, the reported but not finalized transaction, other unfinished or completed or ongoing transactions, etc., so as to achieve
  • the automatic driving of the risk control system solves the technical problem of low analysis efficiency in the existing technology and the difference of analysis results due to different analysts.
  • this application clusters the risk event samples based on the relevant information of the risk subject, so as to classify the risk event samples from different perspectives of the risk subject, so that the pattern information generated based on each risk subject category can better reflect this The characteristics of the category of risk events, and then when identifying the target event, improve the risk recognition rate.
  • the embodiment of this specification also provides a computer-readable storage medium on which a computer program is stored, and when the program is executed by a processor, the steps of any of the foregoing methods are implemented.
  • the embodiment of this specification also provides a computer device, as shown in FIG. 6, including a memory 604, a processor 602, and being stored on the memory 604 and running on the processor 602 When executing the program, the processor 602 implements the steps of any of the methods described above.
  • bus 600 may include any number of interconnected buses and bridges
  • bus 600 will include one or more processors represented by processor 602 and memory 604
  • the various circuits of the memory are linked together.
  • the bus 600 can also link various other circuits such as peripheral devices, voltage regulators, power management circuits, etc., which are all known in the art, and therefore, no further description will be given herein.
  • the bus interface 605 provides an interface between the bus 600 and the receiver 601 and transmitter 603.
  • the receiver 601 and the transmitter 603 may be the same element, that is, a transceiver, which provides a unit for communicating with various other terminal devices on the transmission medium.
  • the processor 602 is responsible for managing the bus 600 and general processing, and the memory 604 may be used to store data used by the processor 602 when performing operations.
  • the embodiment of this specification obtains case portraits of multiple risk event samples, the case portraits include case description information; based on the case description information of each risk event sample, cluster processing of the multiple risk event samples is performed to obtain more Each risk event category; according to the risk event samples included in each risk event category, the pattern information of each risk event category is generated, and when the risk identification of the target event is required, the pattern information of each risk event category Risk identification of the target event can realize the intelligent trial of the transactions audited by the identified strategy, the reported but unfinished transaction, and other unfinished or completed or ongoing transactions, so as to achieve risk control
  • the automatic driving of the system solves the technical problem of low analysis efficiency in the existing technology and the difference of analysis results due to different analysts.
  • this application clusters risk event samples based on risk behavior information and risk subject related information, so as to classify risk event samples from different perspectives, so that the pattern information generated based on each risk event category can be more reflected
  • the characteristics of this category of risk events can further improve the risk recognition rate when identifying target events.
  • modules or units or components in the embodiments can be combined into one module or unit or component, and in addition, they can be divided into multiple sub-modules or sub-units or sub-components. Except that at least some of such features and/or processes or units are mutually exclusive, any combination can be used to compare all features disclosed in this specification (including the accompanying claims, abstract and drawings) and any method or methods disclosed in this manner or All the processes or units of the equipment are combined. Unless expressly stated otherwise, each feature disclosed in this specification (including the accompanying claims, abstract and drawings) may be replaced by an alternative feature that provides the same, equivalent or similar purpose.
  • the various component embodiments of the present invention may be implemented by hardware, or by software modules running on one or more processors, or by their combination.
  • a microprocessor or a digital signal processor (DSP) may be used in practice to implement some or all of the functions of some or all of the gateway, proxy server, and system according to the embodiments of the present invention.
  • DSP digital signal processor
  • the present invention can also be implemented as a device or device program (for example, a computer program and a computer program product) for executing part or all of the methods described herein.
  • Such a program for realizing the present invention may be stored on a computer-readable medium, or may have the form of one or more signals. Such signals can be downloaded from Internet websites, or provided on carrier signals, or provided in any other form.

Landscapes

  • Business, Economics & Management (AREA)
  • Human Resources & Organizations (AREA)
  • Engineering & Computer Science (AREA)
  • Strategic Management (AREA)
  • Entrepreneurship & Innovation (AREA)
  • Economics (AREA)
  • Operations Research (AREA)
  • Game Theory and Decision Science (AREA)
  • Development Economics (AREA)
  • Marketing (AREA)
  • Educational Administration (AREA)
  • Quality & Reliability (AREA)
  • Tourism & Hospitality (AREA)
  • Physics & Mathematics (AREA)
  • General Business, Economics & Management (AREA)
  • General Physics & Mathematics (AREA)
  • Theoretical Computer Science (AREA)
  • Information Retrieval, Db Structures And Fs Structures Therefor (AREA)

Abstract

一种风险识别方法和装置,所述包括:获得多个风险事件样本,并生成每个所述风险事件样本的个案画像(步骤110),所述个案画像包括风险行为信息;基于每个风险事件样本的风险行为信息,对所述多个风险事件样本进行聚类处理,获得多个风险行为类别(步骤120),根据每个风险行为类别包括的风险事件样本,生成每个风险行为类别的模式信息(步骤130),所述每个风险行为类别的模式信息包括:一个以上风险行为特征、及每个所述风险行为特征的权重;当需要对目标事件进行风险识别时,根据每个风险行为类别的模式信息,对目标事件进行风险识别(步骤140),可以实现风控体系的自动驾驶。

Description

一种风险识别方法及装置 技术领域
本说明书实施例涉及数据处理技术领域,尤其涉及一种风险识别方法及装置。
背景技术
欺诈案件分析在整个风控策略和业务运营中占据了非常重要的位置,分析人员需要花费大量的时间和精力对案件进行分析,去确定一个案件是否为欺诈案件,分析效率低,分析结果会因分析人员的不同而产生差异。
发明内容
本说明书实施例提供及一种风险识别方法及装置,解决了现有技术中分析效率低,分析结果因分析人员的不同而产生差异的技术问题。
本说明书实施例提供一种风险识别方法,包括:
获得多个风险事件样本,并生成每个所述风险事件样本的个案画像,所述个案画像包括风险行为信息;
基于每个风险事件样本的风险行为信息,对所述多个风险事件样本进行聚类处理,获得多个风险行为类别;
根据每个风险行为类别包括的风险事件样本,生成每个风险行为类别的模式信息,所述每个风险行为类别的模式信息包括:与每个风险行为信息对应的一个以上的风险行为特征以及每个所述风险行为特征的权重;
当需要对目标事件进行风险识别时,根据所述每个风险行为的模式信息,对所述目标事件进行风险识别
本说明书实施例提供一种风险识别方法,包括:
获得多个风险事件样本,并生成每个所述风险事件样本的个案画像,所述个案画像包括风险主体相关信息;
基于每个风险事件样本的风险主体相关信息,对所述多个风险事件样本进行聚类处理, 获得多个风险主体类别;
根据每个风险主体类别包括的风险事件样本,生成每个风险主体类别的模式信息,所述每个风险主体类别的模式信息包括:与每个风险主体相关信息对应的一个以上的风险主体特征以及每个所述风险主体特征的权重;
当需要对事件进行风险识别时,根据所述每个风险主体的模式信息,对所述事件进行风险识别。
本说明书实施例提供一种风险识别装置,包括:
个案画像生成单元,用于生成多个风险事件样本中每个所述风险事件样本的个案画像,所述个案画像包括风险行为信息;
聚类处理单元,用于基于每个风险事件样本的风险行为信息,对所述多个风险事件样本进行聚类处理,获得多个风险行为类别;
模式生成单元,用于根据每个风险行为类别包括的风险事件样本,生成每个风险行为类别的模式信息,所述每个风险行为类别的模式信息包括:与每个风险行为信息对应的一个以上的风险行为特征以及每个所述风险行为特征的权重;
识别单元,用于当需要对目标事件进行风险识别时,根据所述每个风险行为的模式信息,对所述目标事件进行风险识别。
本说明书实施例提供一种风险识别装置,包括:
个案画像生成单元,用于生成多个风险事件样本中每个所述风险事件样本的个案画像,所述个案画像包括风险主体相关信息;
聚类处理单元,用于基于每个风险事件样本的风险主体相关信息,对所述多个风险事件样本进行聚类处理,获得多个风险主体类别;
模式生成单元,用于根据每个风险主体类别包括的风险事件样本,生成每个风险主体类别的模式信息,所述每个风险主体类别的模式信息包括:与每个风险主体相关信息对应的一个以上的风险主体特征以及每个所述风险主体特征的权重;
识别单元,用于当需要对事件进行风险识别时,根据所述每个风险主体的模式信息,对所述事件进行风险识别。
本说明书实施例提供一种计算机可读存储介质,其上存储有计算机程序,该程序被处理器执行时所述方法的步骤。
本说明书实施例还提供一种计算机设备,包括存储器、处理器及存储在存储器上并可在处理器上运行的计算机程序,所述处理器执行所述程序时实现所述方法的步骤。
本说明书实施例有益效果如下:
本说明书实施例中,通过获得多个风险事件样本的个案画像,所述个案画像包括风险行为信息或风险主体相关信息;基于每个风险事件样本的风险行为信息或风险主体相关信息,对所述多个风险事件样本进行聚类处理,获得多个风险行为类别或风险主体类别;根据每个风险行为类别或风险主体类别包括的风险事件样本,生成每个风险行为类别或风险主体类别的模式信息,在需要对目标事件进行风险识别时,根据所述每个风险行为类别或风险主体类别的模式信息,对目标事件进行风险识别,从而可以实现对被识别策略稽核的交易、被举报但未定型的交易、其它未完成的或已完成的或正在进行中的交易等案件的智能审理,从而可以实现风控体系的自动驾驶,解决了现有技术中分析效率低,分析结果因分析人员的不同而产生差异的技术问题。
附图说明
通过阅读下文优选实施方式的详细描述,各种其他的优点和益处对于本领域普通技术人员将变得清楚明了。附图仅用于示出优选实施方式的目的,而并不认为是对本说明书的限制。而且在整个附图中,用相同的参考符号表示相同的部件。在附图中:
图1示出了本说明书一个实施例的一种风险识别方法的方法流程图;
图2示出了图1中的风险识别方法中的个人画像的示意图;
图3示出了本说明书另一个实施例的一种风险识别方法的方法流程图;
图4示出了根据本说明书一个实施例的一种风险识别装置的示意图;
图5示出了根据本说明书另一个实施例的一种风险识别装置的示意图;
图6示出了根据本说明书一个实施例的计算机设备的示意图。
具体实施方式
为了更好地理解上述技术方案,下面通过附图以及具体实施例对本说明书实施例的技术方案做详细说明,应当理解本说明书实施例以及实施例中的具体特征是对本说明书实施例技术方案的详细说明,而不是对本说明书技术方案的限定。在不冲突的情况下,本说明书实施例以及实施例中的技术特征可以相互组合。
实施例一
本说明书实施例一提供一种风险识别方法。所述风险识别方法可用于案件分析,如游戏类案件、电信类案件等,也可以用于安全教育中,以提高相关人员的风险识别能力,或者生成风险防控策略,用于风控引擎中。以下对所述风险识别方法进行详细描述。
请参见图1,图1为本说明书实施例的一种风险识别方法的方法流程图。所述风险识别方法包括以下步骤:
步骤110,获得多个风险事件样本,并生成每个所述风险事件样本的个案画像,所述个案画像包括案件描述信息。风险事件样本是从已经定性为案件中获得的,可以是从已经定性的案件中挑选的典型案件,也可以是从案件中随机挑选出来的;还可以是已经定性案件的所有案件。
在本实施例中,对风险事件样本的具体选择方式不做限定,可以根据需求进行风险事件样本的选择。在获得多个风险事件样本后,生成每个风险事件样本的个案画像。个案画像用于为每个风险事件的描述信息,以便于能够进行每个风险事件的描述信息的快速获取。
所述案件描述信息可以为用户信息、风险主体相关信息、资金往来信息、案情描述信息等中的一种或者多种。用户信息可以包括姓名、性别、年龄、账号等相关信息。风险主体是执行风险行为的主体,所述风险主体相关信息包括风险主体的ID如姓名或账号或身份证号等、风险主体的即时通讯应用账号如QQ、微信等、风险主体的支付应用账号如支付宝账号等、风险主体的银行卡信息、风险主体的设备号、风险主体的IP地址等中的一种或者多种。
资金往来信息包括转账金额、转账方式等信息,案情描述信息包括风险行为信息、案件起因、过程、结果等信息。风险行为信息即风险主体的行为,如开通花呗消费、开通借呗借钱、更换绑定的手机号码、更换绑定的电子邮箱号码、更改密码、支付位置变化、变更收货地址、购买特定商品中的一种或者多种。开通花呗消费、开通借呗借钱等,其中,花呗和借呗均为一种借贷工具,包括用户的信息,用户可以通过该工具进行借贷。购买特定商品,如 购买以前未曾购买过的类别的商品,反复购买同一种商品等。
在本实施方式中,所述个案画像还包括定性原因,即将该事件确定为风险事件的过程及原因。其中,所述定性原因是通过对判别模型进行reason code的解析而得,具体地,所述定性原因的获得方法,具体为:
采用可解释性算法,从所述案情描述信息中获得多个风险事件定性变量及排序;基于多个风险事件定性变量的排序,获得定性原因。
可解释性算法,这里可以采用tree based learning(集成树算法)算法或SHAP(SHapley Additive exPlanations)算法。针对经典机器学习算法,如GBDT、XGBOOST算法,我们采用采用tree based learning(集成树算法)的方法给出多个案件定性变量的排序,根据排序结果获得定性原因;针对深度学习算法,采用SHAP(SHapley Additive exPlanations)算法来给出每个打分变量的重要性排序,根据排序结果获得定性原因。比如说:某个事件里面因为双方无可信关系、历史没有交易而被定性为风险事件。
在其它实施方式中,所述个案画像还可以包括:定性处理(如确定为风险事件)、事中识别(如交易uct策略未稽核)等,事中识别(即实时识别,如对每笔进来的交易进行风险判断)等。
本说明书实施例以一游戏类案件为例进行个案画像的说明,如图2所示,所述个案画像包括定性处理、用户、风险主体、资金往来、事中识别、案情描述、以及定性原因。在该示例中,因为双方(用户和风险主体)无可信关系、而且历史没有交易而被定性为风险事件。
生成个案画像之后,进入步骤120。
步骤120,基于每个风险事件样本的案件行为信息,对多个所述风险事件样本进行聚类处理,获得多个风险行为类别。
在对风险事件样本进行聚类时,可以根据案件描述信息所包括一种或者多种信息对风险事件样本进行聚类,从而获得多个风险事件类别。
在本实施方式中,主要根据风险行为信息对风险事件样本进行聚类,以下进行详细说明。
聚类处理是对样本进行聚类算法的处理,聚类算法是对事物自动归类的一类算法,聚类算法是一种典型的无监督的学习算法,在聚类算法中通过定义不同的相似性的度量方法,将具有相似属性的事物聚集到同一个类中。聚类算法是以相似性为基础,在一个聚类中的模式 之间比不在同一聚类中的模式之间具有更多的相似性。
风险事件类别表示每个风险事件样本的类别,如可将风险事件类别设置为1、2、3或,a、b、c均可,由于本申请采用的是无监督算法—聚类算法,没有标记样本,因此,这个风险事件类别只是一个类别标记,并不表示任何该类别的特征信息。
在对所有的风险事件样本进行聚类处理后,将所有的风险事件样本分为多个风险事件类别,定义出多个风险事件类别的id,如风险行为1、风险行为2、风险行为3等,其中风险行为1、风险行为2、风险行为3即为风险事件类别,每个类的风险事件样本的风险事件类别相同,即通过聚类将相同或者相近似的聚为同一类,设置为类别信息相同,该类的所有风险事件样本的风险行为信息相同或者相近似。
以下举例对基于风险行为信息对风险事件样本进行的聚类处理进行说明,假设风险事件样本的数目为5个(编号分别为1~5),基于风险行为信息对风险事件样本进行聚类处理,获得2个风险行为的风险事件类别,如表1所示。
表1 基于风险行为信息的聚类处理示意表
样本 风险行为信息 聚类结果
样本1 改密码、换绑手机 风险行为1
样本2 开通借呗借钱 风险行为2
样本3 改密码、换绑电子邮箱 风险行为1
样本4 开通花呗消费 风险行为2
样本5 开通花呗消费 风险行为2
在5个风险事件样本中,由于风险事件样本1、风险事件样本3的风险行为相近似,都是改密码、换绑手机、换绑电子邮箱,则将风险事件样本1和风险事件样本3聚类为风险行为1的风险事件类别;而风险事件样本2、风险事件样本4和风险事件样本5的风险行为相近似,都是通过开通借呗借钱、开通花呗消费,则将风险事件样本2、风险事件样本4和风险事件样本5聚类为风险行为2的风险事件类别。即,基于风险行为信息,将5个样本聚为两个风险事件类别,风险行为1的风险事件类别和风险行为2的风险事件类别。
具体地,基于风险行为的具体聚类算法过程如下:
具体地,所述基于每个风险事件样本的风险行为信息,对多个所述风险事件样本进行聚类处理,获得多个风险事件类别,包括:
基于每个所述风险事件样本的风险行为信息,生成序列数据,通过node2vec的方法构建图向量,获得第一聚类特征,以及通过word2vec的方法构建图向量,获得第二聚类特征;将预设的结构化向量特征与所述第一聚类特征、以及所述第二聚类特征结合,获得结构化数据;采用聚类算法对所述结构化数据进行聚类处理,获得多个风险事件类别。
具体地,第一聚类特征为Xi(i=1,…,n,n为大于1的整数,i为正整数),第二聚类特征为Xj(j=n+1,…,m,j为大于n小于等于m的整数,m为大于n的整数),预设的结构化向量特征为Xk(k=m+1,…,l,k为大于m小于等于l的整数,l为大于m的整数)。预设的结构化向量特征为开发人员根据业务经验设定的,也叫经验变量,或者经验特征,通过设置这个预设的结构化向量特征,是的聚类结果与真实结果更相近。在获得Xi、Xj、Xk后,通过将Xi、Xj、Xk按照列拼接,即可获得基于风险行为信息对风险事件样本进行聚类的结果。
在对风险事件样本进行聚类处理,获得风行为类别后,进入步骤130。
步骤130,根据每个风险行为类别包括的风险事件样本,生成每个风险行为类别的模式信息,所述每个风险行为类别的模式信息包括:与每个风险行为信息对应的一个以上的风险行为特征以及每个所述风险行为特征的权重。
在获得基于风险行为信息对风险事件样本进行聚类处理,获得风险行为类别的结果后,进入步骤130,基于每个风险行为类别生成模式信息。
在获得每个风险行为类别后,分析该类别风险事件样本的具体风险行为信息,风险行为信息具体可以通过提取关键字或者通过AI(人工智能),即可生成该风险事件类别的风险事件样本的风险行为信息,也可以基于该风险事件类别中的风险事件样本的个案画像,直接获得该类别的风险事件样本的风险行为信息。
每个模式信息对应一个风险行为件类别,也就是说,一个风险行为件类别只有一个模式信息。每个模式信息所包含的风险行为特征的数量是根据该风险行为件类别的风险行为件样本所包含的风险行为信息确定的。每个模式信息中与每种风险行为对应的风险行为特征可以为一个,也可以为多个。每个所述风险行为特征的权重是根据该风险行为特征的重要性确定的,重要的风险行为特征权重高,次要的风险行为特征权重低,也就是说,越重要的风险行为特征权重值越高。
具体地,在本实施方式中,所述与每个风险行为信息对应的风险行为特征包括:开启特定的功能、开启特定的权限、更换绑定电话号码、更改绑定电子邮箱、更改密码、支付位置 变化、变更收货地址和/或购买特定商品。即,与风险行为信息对应的风险行为特征可以为开启特定的功能、开启特定的权限、更换绑定手机号码、更换绑定电子邮箱号码、更改密码、支付位置变化、变更收货地址、购买特定商品等中的一种或者多种。购买特定商品,如购买以前未曾购买过的类别的商品,反复购买同一种商品等。
如在某一种风险行为类别中,包括三个风险行为特征:开启特定的功能、支付位置变化、变更收货地址,其中“开启特定的功能、开启特定的权限”这个风险行为特征的重要程度最高,则将这个风险行为特征的权重值最大,如设置为0.8,另外两个风险行为特征的重要程度是一样的,则将这两个风险行为特征的权重值设置为相同,如0.2。
获得每个风险行为类别的模式信息至少有以下两种获得方式:
方式1:
具体地,所述根据每个风险行为类别包括的风险事件样本,生成每个风险行为类别的模式信息,包括:
针对每个风险行为类别的风险事件样本,提取与该风险行为类别的风险行为信息对应的一个以上风险行为特征;
确定一个以上风险行为特征中每个风险行为特征对应的权重,生成该风险行为类别的模式信息。
本方式是通过人设定的方式进行的,基于风险行为信息,确定风险行为特征后,再根据该风险行为特征的重要性确定每个所述风险行为特征的权重。每个风险行为特征的重要性可以根据经验设置,也可以根据大数据分析结果进行设置。
继续以前述的基于风险行为2的风险行为类别的风险事件样本为例进行说明,该风险行为类别的风险事件样本的风险行为信息为开通借呗借钱,基于风险行为信息,可确定与该风险行为信息对应的风险行为特征—开启特定的功能,设定该风险行为特征的权重为1,即可获得该风险行为类别的模式信息1。
又如,某风险行为类别的风险行为信息为改密码、换绑手机,基于该风险行为信息,确定与该风险行为信息对应的两个风险行为特征,风险行为特征1—更换绑定手机号码,风险行为特征2—更改密码,设定风险行为特征1的权重为0.5,风险行为特征2为0.5,获得模式信息2,如下表2所示。
表2 模式信息的示意
Figure PCTCN2020070679-appb-000001
方式2:
具体地,所述根据每个风险行为类别包括的风险事件样本,生成每个风险行为类别的模式信息,包括:
将每个风险行为类别的风险事件样本输入到预设模型;
获得所述预设模型输出该风险行为类别的风险行为信息对应的一个以上风险行为特征及每个风险行为特征的权重;
基于输出该风险行为类别的风险行为对应的一个以上风险行为特征及每个风险行为特征的权重,获得该风险行为类别的模式信息。
该方式是通过预设模型的获得模式信息。该预设模型是用于对输入的风险行为类别的风险事件样本进行分析,输出该风险行为类别的风险行为对应风险行为特征及权重。所述预设模式具体可以为基于神经网络如卷积神经网络(Convolutional Neural Networks,CNN)模型、循环神经网络(RNN)的模型。
在获得模式信息后,进入步骤140。
步骤140,当需要对目标事件进行风险识别时,根据所述每个风险行为类别的模式信息,对目标事件进行风险识别。
所述目标事件可以为一件或者多件,包括但不限于被识别策略稽核的交易、被举报但未定型的交易、其它未完成的或已完成的或正在进行中的交易等事件。通过确定目标事件是否为风险事件,从而可以发现潜在的风险行为,也可以挖掘出隐在的风险事件。在识别出所述目标事件为风险事件时,可以拦截或者提醒。
具体地,所述根据所述每个风险行为类别的模式信息,对目标事件进行风险识别,包括:根据每个风险行为类别的模式信息,对所述目标事件进行打分,获得打分结果;基于所述打分结果,确定所述目标事件是否为风险事件。
具体地,所述根据每个风险行为类别的模式信息,对所述目标事件进行打分,获得打分结果,包括:
在所述目标事件中提取与每个风险行为类别的模式信息包括一个以上风险行为特征;
基于提取的风险行为特征及每个所述风险行为特征对应的权重,获得所述目标事件在每个风险行为类别的打分结果。
如,基于风险行为类别获得的模式信息1的风险行为特征为开启特定的功能,该风险行为特征的权重为1为例进行说明。识别目标事件是否有开启特定的功能,如是否有开启花呗消费、开启借呗借钱等,若是,则提取该特征,获得该特征对应的权重值1,则可获得目标事件在模式信息1对应的风险行为类别的打分结果,打分结果为1。
又如,某个风险行为类别的模式信息2具有两个风险行为特征,风险行为特征1—更换绑定手机号码,风险行为特征2—更改密码,设定风险行为特征1的权重为0.5,风险行为特征2为0.5,识别目标事件是否有改密码,是否为更换绑定手机号码,若目标事件具有风险行为特征2—更改密码,基于风险行为特征2的权重,获得打分结果为0.5。
在获得打分结果后,所述基于所述打分结果,确定所述目标事件是否为风险事件,包括:判断所述目标事件在每个风险行为类别的打分结果是否大于该风险行为类别的预设分值;若是,则确定所述目标事件为该风险行为类别的风险事件。
通过设定预设分值,确定目标事件为某个风险行为类别的风险事件,如某一目标事件的打分结果为0.9,预设值设定为0.8,则打分结果大于预设值,确定该风险行为类别的风险事件,基于此,可进行交易拦截或者对用户进行提醒。
在其它实施方式中,可以多设置几个预设分值,基于预设分值识别目标事件的风险程度的级别,如风险程度高、风险程度低、风险程度中,基于风险程度的不同,生成不要的策略,如风险程度高,则拦截的防控策略,直接拦截交易,如风险程度低,则,生成提示信息,提示用户有风险。通过生成防控策略,能够在用户报案之前自动地、智能地推荐给用户或者强制执行,减少风险事件的发生,通过该方法,可与风控引擎打通,实现策略的自动化、智能化的推荐,从而提高交易的安全性。
也可以直接提取特征,确定目标事件是否为风险事件,具体地,所述根据所述每个风险行为类别的模式信息,对所述目标事件进行风险识别,包括:
提取所述目标事件中与每个风险行为类别的模式信息对应的风险行为特征;
基于提取的风险行为特征及每个所述风险行为特征对应的权重,确定所述目标事件是否为风险事件。
进一步地,所述方法还包括:基于所述模式信息,生成安全教育页面,并展示所述安全教育页面。具体地,如模式信息为基于案件行为类别——更换绑定电话号码、更改密码,则根据潜在可能被盗的用户去宣传修改更安全的密码等。通过基于模式信息,可以针对不同的人群生成安全教育信息,从而可以针对不同的人群进行安全教育,实现用户心智的运营。
又,本说明书实施例的方法可以用于智能审理的服务,将需要审理的事件作为目标事件,通过本说明书实施例的方法对事件进行申请,即可确定该事件属于哪个风险行为类别的风险事件,从而可以实现风控体系的自动驾驶。
进一步地,在获得每个风险行为类别的目标事件后,可以对每个风险行为类别的目标事件进行聚类处理,获得一个以上的风险主体类别,再获得每个风险主体类别的模式信息,基于模式信息对待识别事件进行识别;也可以直接提取每个风险行为类别包括的目标事件的风险主体相关信息,基于风险主体相关信息对待识别事件进行识别,以下分别进行详细介绍。
A、具体地,所述方法还包括:
获得每个风险行为类别的各目标事件的风险主体相关信息;
基于每个风险行为类别的各目标事件的风险主体相关信息,对该风险行为类别的目标事件进行聚类处理,获得一个以上的风险主体类别;
根据每个风险主体类别包括的目标事件,生成每个风险主体类别的模式信息;所述每个风险主体类别的模式信息具体包括:与每个风险主体相关信息对应的一个以上风险主体特征、及每个所述风险主体特征的权重;
通过每个风险主体类别的模式信息对待识别事件进行识别。
在获得每个风险行为类别的目标事件的风险主体相关信息后,即可对多个目标事件进行基于风险主体相关信息进行聚类出来,获得一个以上的风险主体类别。检测风险主体群的手段可以通过强介质进行连通图关联,建立用户和设备号、用户和卡号、用户和电话号码等关系,通过逐层关联向外拓展挖掘风险主体群。如用户1和卡1有关联,卡1和用户2有关联,用户1和设备1有关联,设备1和用户3有关联,通过联通关系最终可以发现,用户1、用户2、用户3属于同一风险主体群。另外也可通过自主选择介质如IP地址的方式来执行风险行为。基于聚类算法,将相关联的风险主体聚在一起,获得基于风险主体进行聚类处理获 得的风险主体类别。
具体地,所述与每个风险主体相关信息对应的风险主体特征包括:ID、即时通讯应用账号、支付应用账号、银行卡信息、电话号码、电子邮箱、操作设备号码和/或IP地址。即,所述与每个风险主体相关信息对应的风险主体特征包括:ID、即时通讯应用账号、支付应用账号、银行卡信息、电话号码、电子邮箱、操作设备号码、IP地址等中的一种或多种。ID、即时通讯应用账号、支付应用账号、银行卡信息、电话号码、电子邮箱、操作设备号码、IP地址均为风险主体的信息。
在获得每个风险主体类别后,分析该类别的目标事件的风险主体相关信息。每个模式信息对应一个风险主体类别,也就是说,一个风险主体类别只有一个模式信息。每个模式信息所包含的风险主体特征的数量是根据该风险主体类别的风险事件样本所包含的风险主体相关信息确定的。每个模式信息中与风险主体对应的风险主体特征可以为一个,也可以为多个。每个所述风险主体特征的权重是根据该风险主体特征的重要性确定的,重要的风险主体特征权重高,次要的风险主体特征权重低,也就是说,越重要的风险主体特征权重值越高。
继续以前述用户1、用户2、用户3属于同一风险主体群这一示例进行说明,该风险主体类别中的风险主体相关信息包括用户、设备、卡,因此,基于该等风险主体相关信息,可以获得三个风险主体特征:ID、银行卡信息、操作设备号码,其中,风险主体特征—操作设备号码的重要程度最高,则将这个风险主体特征的权重值最大,如设置为0.7,另外两个风险主体特征—ID、银行卡信息的重要程度次之,则分别设置为0.2和0.3,即可生成模式信息。
具体地,所述通过每个风险主体类别的模式信息对待识别事件进行识别,包括:
提取所述待识别事件中与每个风险主体类别的模式信息对应的风险主体特征;
基于提取的风险主体特征及每个所述风险主体特征对应的权重,确定所述待识别事件是否为风险事件。
如,某风险主体类别的模式信息,包括三个风险主体相关特征:ID、银行卡信息、操作设备号码,权重分别为0.2、0.3、0.7。提取待识别事件是否有三个风险主体相关特征,若识别出待识别事件具有其中两个风险主体相关特征ID、操作设备号码,则提取该两个风险主体相关特征,基于该两个风险主体相关特征的权重,则可获得待识别事件的打分结果为0.9,基于该打分结果,可确定待识别事件为风险事件。
B、具体地,所述方法还包括:
获得每个风险行为类别的目标事件的风险主体相关信息;
通过每个风险行为类别的风险主体相关信息,对待识别事件进行识别。
所述风险主体相关信息包括风险主体的ID如姓名或账号或身份证号等、风险主体的即时通讯应用账号如QQ、微信等、风险主体的支付应用账号如支付宝账号等、风险主体的银行卡信息、风险主体的设备号、风险主体的IP地址等中的一种或者多种。
获得每个风险行为类别的目标事件的风险主体相关信息后,确定待识别事件中的是否具有该等风险主体相关信息中的一个或者多个,然后再根据预设规则,确定待识别事件是否为风险事件。
如,待识别事件中的风险主体的ID与某一风险行为类别的目标事件的风险主体的ID相同,则根据预设规则风险主体的ID相同,则确定待识别事件是否为风险事件。
本说明书实施例通过获得多个风险事件样本的个案画像,所述个案画像包括风险行为信息;基于每个风险事件样本的风险行为信息,对所述多个风险事件样本进行聚类处理,获得多个风险行为类别;根据每个风险行为类别包括的风险事件样本,生成每个风险行为类别的模式信息,在需要对目标事件进行风险识别时,根据所述每个风险行为类别的模式信息,对目标事件进行风险识别,从而可以实现对被识别策略稽核的交易、被举报但未定型的交易、其它未完成的或已完成的或正在进行中的交易等案件的智能审理,从而可以实现风控体系的自动驾驶,解决了现有技术中分析效率低,分析结果因分析人员的不同而产生差异的技术问题。
另外,本申请分别基于风险行为信息对风险事件样本进行聚类处理,实现从风险行为的不同的角度对风险事件样本进行分类处理,使得基于每个风行为类别生成的模式信息能够更体现该类别的风险事件的特点,进而在对目标事件识别时,提高风险识别率。
实施例二
于同样的发明构思,本申请还提供一种风险识别方法,如图3所示,所述风险识别方法包括:
步骤310,获得多个风险事件样本,并生成每个所述风险事件样本的个案画像,所述个案画像包括风险主体相关信息。
个案画像参见实施例一的描述,在此不再赘述。
步骤320,基于每个风险事件样本的风险主体相关信息,对所述多个风险事件样本进行聚类处理,获得多个风险主体类别。
一个风险主体群是指两个以上成员之间,基于共同的违反法律的意图和目标,以共同的需要、兴趣、价值观念等心理因素作为精神纽带,纠合在一起,进行多次共同进行不合法风险行为。基于风险主体的信息,可以确定风险事件样本中与该风险主体关联的风险主体群,基于该风险主体群,就可以进行风险主体聚类处理。
一般来说,所有风险事件背后对应的风险主体都是呈群体性质的,从风险事件出发挖掘出背后的群体,以便快速防控风险事件和进行线下打击。在该步骤中,可以采用标签传播(LPA)的算法。LPA算法的逻辑结构如下:一开始构建所有样本的一个全网络,通过案件定性的结果,发现定性的黑样本,从黑样本出发,经过多轮迭代,就可以发现周围的样本慢慢都可以传染到,以此发现两个子群为风险主体群。该方案从黑样本出发去侵染剩余样本,给剩余样本打分,根据得分的大小判断该样本是否是风险事件,以此来达到发现风险主体群的目的。
在获得每个风险事件样本的风险主体相关信息后,即可对多个风险事件样本进行基于风险主体相关信息进行聚类出来,获得多个风险事件类别。检测风险主体群的手段可以通过强介质进行连通图关联,建立用户和设备号、用户和卡号、用户和电话号码等关系,通过逐层关联向外拓展挖掘风险主体群。如用户1和卡1有关联,卡1和用户2有关联,用户1和设备1有关联,设备1和用户3有关联,通过联通关系最终可以发现,用户1、用户2、用户3属于同一风险主体群。另外也可通过自主选择介质如IP地址的方式来执行风险行为。基于聚类算法,将相关联的风险主体聚在一起,获得基于风险主体进行聚类处理获得的风险事件类别。
具体地,所述与每个风险主体相关信息对应的风险主体特征包括:ID、即时通讯应用账号、支付应用账号、银行卡信息、电话号码、电子邮箱、操作设备号码和/或IP地址。即,所述与每个风险主体对应的风险主体特征包括:ID、即时通讯应用账号、支付应用账号、银行卡信息、电话号码、电子邮箱、操作设备号码、IP地址等中的一种或多种。ID、即时通讯应用账号、支付应用账号、银行卡信息、电话号码、电子邮箱、操作设备号码、IP地址均为风险主体的信息。
在对风险事件样本进行聚类处理,获得风险事件类别后,进入步骤330。
步骤330,根据每个风险主体类别包括的风险事件样本,生成每个风险主体类别的模 式信息,所述每个风险主体类别的模式信息包括:与每个风险主体相关信息对应的一个以上的风险主体特征以及每个所述风险主体特征的权重。
在获得每个风险主体类别后,分析该类别的风险事件样本的风险主体相关信息。每个模式信息对应一个风险主体类别,也就是说,一个风险主体类别只有一个模式信息。每个模式信息所包含的风险主体特征的数量是根据该风险主体类别的风险事件样本所包含的风险主体相关信息确定的。每个模式信息中与风险主体对应的风险主体特征可以为一个,也可以为多个。每个所述风险主体特征的权重是根据该风险主体特征的重要性确定的,重要的风险主体特征权重高,次要的风险主体特征权重低,也就是说,越重要的风险主体特征权重值越高。
继续以前述用户1、用户2、用户3属于同一风险主体群这一示例进行说明,该风险主体类别中的风险主体相关信息包括用户、设备、卡,因此,基于该等风险主体相关信息,可以获得三个风险主体特征:ID、银行卡信息、操作设备号码,其中,风险主体特征—操作设备号码的重要程度最高,则将这个风险主体特征的权重值最大,如设置为0.7,另外两个风险主体特征—ID、银行卡信息的重要程度次之,则分别设置为0.2和0.3,即可生成模式信息。
获得每个风险主体类别的模式信息的方式至少有如下两种:
方式1:
具体地,根据每个风险主体类别包括的风险事件样本,生成每个风险主体类别的模式信息,包括:
针对每个风险主体类别的风险事件样本,提取与该风险主体类别的风险主体对应的一个以上风险主体特征;
确定一个或者多个风险主体特征对应的权重,生成该风险主体类别的模式信息。
本方式是通过人设定的方式进行的,基于风险主体相关信息,确定风险主体特征后,再根据该风险主体特征的重要性确定每个所述风险主体特征的权重。每个风险主体特征的重要性可以根据经验设置,也可以根据大数据分析结果进行设置。
继续以前述的风险主体类别为例进行说明,该风险主体类别中的风险主体相关信息包括用户、设备、卡,基于该信息,即可确定出该风险主体类别的模式信息的三个风险主体特征:ID、银行卡信息、操作设备号码,由于风险主体特征—操作设备号码的重要程度最高,则将这个风险主体特征的权重值最大,如设置为0.7,另外两个风险主体特征—ID、银行卡信息的重要程度次之,则分别设置为0.2和0.3。
方式2:
根据每个风险主体类别包括的风险事件样本,生成每个风险主体类别的模式信息,包括:
将每个风险主体类别的风险事件样本输入到预设模型;
获得所述预设模型输出该风险主体类别的风险主体相关信息对应的一个以上风险主体特征及每个风险主体特征的权重;
基于输出该风险主体类别的风险主体相关信息对应的一个以上风险主体特征及每个风险主体特征的权重,获得该风险主体类别的模式信息。
该方式是通过预设模型的获得模式信息。该预设模型是用于对输入的某一风险主体类别的风险事件样本进行分析,输出该风险主体件类别的风险主体相关信息对应风险主体特征及权重。所述预设模式具体可以为基于神经网络如卷积神经网络(Convolutional Neural Networks,CNN)模型、循环神经网络(RNN)的模型。
在获得模式信息后,进入步骤340。
步骤340,当需要对事件进行风险识别时,根据所述每个风险主体的模式信息,对所述事件进行风险识别。
所述目标事件可以为一件或者多件,包括但不限于被识别策略稽核的交易、被举报但未定型的交易、其它未完成的或已完成的或正在进行中的交易等事件。通过确定目标事件是否为风险事件,从而可以发现潜在的风险行为,也可以挖掘出隐在的风险事件。在识别出所述目标事件为风险事件时,可以拦截或者提醒。
具体地,所述根据所述每个风险主体类别的模式信息,对所述事件进行风险识别,包括:
提取所述事件中与每个风险主体类别的模式信息对应的风险主体特征;
基于提取的风险主体特征及每个所述风险主体特征对应的权重,确定所述事件是否为风险事件。
如,某风险主体类别的模式信息,包括三个风险主体相关特征:ID、银行卡信息、操作设备号码,权重分别为0.2、0.3、0.7。提取目标事件是否有三个风险主体相关特征,若识别出目标事件具有其中两个风险主体相关特征ID、操作设备号码,则提取该两个风险主体相 关特征,基于该两个风险主体相关特征的权重,则可获得目标事件的打分结果为0.2+0.7=0.9,基于该打分结果,确定该目标事件为风险事件。
本说明书实施例通过获得多个风险事件样本的个案画像,所述个案画像包括风险主体相关信息;基于每个风险事件样本的风险主体相关信息,对所述多个风险事件样本进行聚类处理,获得多个风险主体类别;根据每个风险主体类别包括的风险事件样本,生成每个风险主体类别的模式信息,在需要对目标事件进行风险识别时,根据所述每个风险主体类别的模式信息,对目标事件进行风险识别,从而可以实现对被识别策略稽核的交易、被举报但未定型的交易、其它未完成的或已完成的或正在进行中的交易等案件的智能审理,从而可以实现风控体系的自动驾驶,解决了现有技术中分析效率低,分析结果因分析人员的不同而产生差异的技术问题。
另外,本申请分别基于风险主体相关信息对风险事件样本进行聚类处理,实现从风险主体的不同的角度对风险事件样本进行分类处理,使得基于每个风险主体类别生成的模式信息能够更体现该类别的风险事件的特点,进而在对目标事件识别时,提高风险识别率。
实施例三
基于同样的发明构思,本申请还提供一种风险识别装置,如图4所示,所述风险识别装置,包括:
个案画像生成单元410,用于生成多个风险事件样本中每个所述风险事件样本的个案画像,所述个案画像包括风险行为信息;
聚类处理单元420,用于基于每个风险事件样本的风险行为信息,对所述多个风险事件样本进行聚类处理,获得多个风险行为类别;
模式生成单元430,用于根据每个风险行为类别包括的风险事件样本,生成每个风险行为类别的模式信息,所述每个风险行为类别的模式信息包括:与每个风险行为信息对应的一个以上的风险行为特征以及每个所述风险行为特征的权重;
识别单元440,用于当需要对目标事件进行风险识别时,根据所述每个风险行为的模式信息,对所述目标事件进行风险识别。
具体地,所述装置还包括获得单元,所述获得单元用于获得每个风险行为类别的各目标事件的风险主体相关信息;所述聚类处理单元240还用于基于每个风险行为类别的各目标事件的风险主体相关信息,对该风险行为类别的目标事件进行聚类处理,获得一个以上的风 险主体类别;
所述模式生成单元430还用于根据每个风险主体类别包括的目标事件,生成每个风险主体类别的模式信息;所述每个风险主体类别的模式信息具体包括:与每个风险主体相关信息对应的一个以上风险主体特征、及每个所述风险主体特征的权重;
所述识别单元440还用于通过每个风险主体类别的模式信息对待识别事件进行识别。
具体地,所述与每个风险行为信息对应的风险行为特征为:开启特定的功能、开启特定的权限、更换绑定电话号码、更换绑定电子邮箱、更改密码、支付位置变化、变更收货地址或购买特定商品。
所述装置还包括获得单元,所述获得单元用于获得每个风险行为类别的目标事件的风险主体相关信息;所述识别单元440还用于通过每个风险行为类别的风险主体相关信息,对待识别事件进行识别。
所述识别单元440具体用于提取所述目标事件中与每个风险事件类别的模式信息对应的风险主体特征,并基于提取的风险主体特征及每个所述风险主体特征对应的权重,确定所述目标事件是否为该风险主体类别的风险事件。
具体地,所述与每个风险主体相关信息对应的风险主体特征为:ID、即时通讯应用账号、支付应用账号、银行卡信息、电话号码、电子邮箱、操作设备号码或IP地址。
本说明书实施例通过获得多个风险事件样本的个案画像,所述个案画像包括风险行为信息;基于每个风险事件样本的风险行为信息,对所述多个风险事件样本进行聚类处理,获得多个风险行为类别;根据每个风险行为类别包括的风险事件样本,生成每个风险行为类别的模式信息,在需要对目标事件进行风险识别时,根据所述每个风险行为类别的模式信息,对目标事件进行风险识别,从而可以实现对被识别策略稽核的交易、被举报但未定型的交易、其它未完成的或已完成的或正在进行中的交易等案件的智能审理,从而可以实现风控体系的自动驾驶,解决了现有技术中分析效率低,分析结果因分析人员的不同而产生差异的技术问题。
另外,本申请分别基于风险行为信息对风险事件样本进行聚类处理,实现从风险行为的不同的角度对风险事件样本进行分类处理,使得基于每个风行为类别生成的模式信息能够更体现该类别的风险事件的特点,进而在对目标事件识别时,提高风险识别率。
实施例四
基于同样的发明构思,本申请还提供一种风险识别装置,如图5所示,所述风险识别装置包括:
个案画像生成单元510,用于生成多个风险事件样本中每个所述风险事件样本的个案画像,所述个案画像包括风险主体相关信息;
聚类处理单元520,用于基于每个风险事件样本的风险主体相关信息,对所述多个风险事件样本进行聚类处理,获得多个风险主体类别;
模式生成单元530,用于根据每个风险主体类别包括的风险事件样本,生成每个风险主体类别的模式信息,所述每个风险主体类别的模式信息包括:与每个风险主体相关信息对应的一个以上的风险主体特征以及每个所述风险主体特征的权重;
识别单元540,用于当需要对事件进行风险识别时,根据所述每个风险主体的模式信息,对所述事件进行风险识别。
具体地,所述识别单元540具体用于提取所述事件中与每个风险主体类别的模式信息对应的风险主体特征,并基于提取的风险主体特征及每个所述风险主体特征对应的权重,确定所述事件是否为风险事件。
具体地,所述与每个风险主体相关信息对应的风险主体特征为:ID、即时通讯应用账号、支付应用账号、银行卡信息、电话号码、电子邮箱、操作设备号码或IP地址。
本说明书实施例通过获得多个风险事件样本的个案画像,所述个案画像包括风险主体相关信息;基于每个风险事件样本的风险主体相关信息,对所述多个风险事件样本进行聚类处理,获得多个风险主体类别;根据每个风险主体类别包括的风险事件样本,生成每个风险主体类别的模式信息,在需要对目标事件进行风险识别时,根据所述每个风险主体类别的模式信息,对目标事件进行风险识别,从而可以实现对被识别策略稽核的交易、被举报但未定型的交易、其它未完成的或已完成的或正在进行中的交易等案件的智能审理,从而可以实现风控体系的自动驾驶,解决了现有技术中分析效率低,分析结果因分析人员的不同而产生差异的技术问题。
另外,本申请分别基于风险主体相关信息对风险事件样本进行聚类处理,实现从风险主体的不同的角度对风险事件样本进行分类处理,使得基于每个风险主体类别生成的模式信息能够更体现该类别的风险事件的特点,进而在对目标事件识别时,提高风险识别率。
实施例五
基于与前述实施例中同样的发明构思,本说明书实施例还提供一种计算机可读存储介质,其上存储有计算机程序,该程序被处理器执行时实现前文任一所述方法的步骤。
实施例六
基于与前述实施例中同样的发明构思,本说明书的实施例还提供一种计算机设备,如图6所示,包括存储器604、处理器602及存储在存储器604上并可在处理器602上运行的计算机程序,所述处理器602执行所述程序时实现前文任一所述方法的步骤。
其中,在图6中,总线架构(用总线600来代表),总线600可以包括任意数量的互联的总线和桥,总线600将包括由处理器602代表的一个或多个处理器和存储器604代表的存储器的各种电路链接在一起。总线600还可以将诸如外围设备、稳压器和功率管理电路等之类的各种其他电路链接在一起,这些都是本领域所公知的,因此,本文不再对其进行进一步描述。总线接口605在总线600和接收器601和发送器603之间提供接口。接收器601和发送器603可以是同一个元件,即收发机,提供用于在传输介质上与各种其他终端设备通信的单元。处理器602负责管理总线600和通常的处理,而存储器604可以被用于存储处理器602在执行操作时所使用的数据。
通过本说明书的一个或者多个实施例,本说明书具有以下有益效果或者优点:
本说明书实施例通过获得多个风险事件样本的个案画像,所述个案画像包括案件描述信息;基于每个风险事件样本的案件描述信息,对所述多个风险事件样本进行聚类处理,获得多个风险事件类别;根据每个风险事件类别包括的风险事件样本,生成每个风险事件类别的模式信息,在需要对目标事件进行风险识别时,根据所述每个风险事件类别的模式信息,对目标事件进行风险识别,从而可以实现对被识别策略稽核的交易、被举报但未定型的交易、其它未完成的或已完成的或正在进行中的交易等案件的智能审理,从而可以实现风控体系的自动驾驶,解决了现有技术中分析效率低,分析结果因分析人员的不同而产生差异的技术问题。
另外,本申请分别基于风险行为信息和风险主体相关信息对风险事件样本进行聚类处理,实现从不同的角度对风险事件样本进行分类处理,使得基于每个风险事件类别生成的模式信息能够更体现该类别的风险事件的特点,进而在对目标事件识别时,提高风险识别率。
在此提供的算法和显示不与任何特定计算机、虚拟系统或者其它设备固有相关。各种通用系统也可以与基于在此的示教一起使用。根据上面的描述,构造这类系统所要求的结构 是显而易见的。此外,本发明也不针对任何特定编程语言。应当明白,可以利用各种编程语言实现在此描述的本发明的内容,并且上面对特定语言所做的描述是为了披露本发明的最佳实施方式。
在此处所提供的说明书中,说明了大量具体细节。然而,能够理解,本发明的实施例可以在没有这些具体细节的情况下实践。在一些实例中,并未详细示出公知的方法、结构和技术,以便不模糊对本说明书的理解。
类似地,应当理解,为了精简本公开并帮助理解各个发明方面中的一个或多个,在上面对本发明的示例性实施例的描述中,本发明的各个特征有时被一起分组到单个实施例、图、或者对其的描述中。然而,并不应将该公开的方法解释成反映如下意图:即所要求保护的本发明要求比在每个权利要求中所明确记载的特征更多的特征。更确切地说,如下面的权利要求书所反映的那样,发明方面在于少于前面公开的单个实施例的所有特征。因此,遵循具体实施方式的权利要求书由此明确地并入该具体实施方式,其中每个权利要求本身都作为本发明的单独实施例。
本领域那些技术人员可以理解,可以对实施例中的设备中的模块进行自适应性地改变并且把它们设置在与该实施例不同的一个或多个设备中。可以把实施例中的模块或单元或组件组合成一个模块或单元或组件,以及此外可以把它们分成多个子模块或子单元或子组件。除了这样的特征和/或过程或者单元中的至少一些是相互排斥之外,可以采用任何组合对本说明书(包括伴随的权利要求、摘要和附图)中公开的所有特征以及如此公开的任何方法或者设备的所有过程或单元进行组合。除非另外明确陈述,本说明书(包括伴随的权利要求、摘要和附图)中公开的每个特征可以由提供相同、等同或相似目的替代特征来代替。
此外,本领域的技术人员能够理解,尽管在此的一些实施例包括其它实施例中所包括的某些特征而不是其它特征,但是不同实施例的特征的组合意味着处于本发明的范围之内并且形成不同的实施例。例如,在下面的权利要求书中,所要求保护的实施例的任意之一都可以以任意的组合方式来使用。
本发明的各个部件实施例可以以硬件实现,或者以在一个或者多个处理器上运行的软件模块实现,或者以它们的组合实现。本领域的技术人员应当理解,可以在实践中使用微处理器或者数字信号处理器(DSP)来实现根据本发明实施例的网关、代理服务器、系统中的一些或者全部部件的一些或者全部功能。本发明还可以实现为用于执行这里所描述的方法的一部分或者全部的设备或者装置程序(例如,计算机程序和计算机程序产品)。这样的实现 本发明的程序可以存储在计算机可读介质上,或者可以具有一个或者多个信号的形式。这样的信号可以从因特网网站上下载得到,或者在载体信号上提供,或者以任何其他形式提供。
应该注意的是上述实施例对本发明进行说明而不是对本发明进行限制,并且本领域技术人员在不脱离所附权利要求的范围的情况下可设计出替换实施例。在权利要求中,不应将位于括号之间的任何参考符号构造成对权利要求的限制。单词“包含”不排除存在未列在权利要求中的元件或步骤。位于元件之前的单词“一”或“一个”不排除存在多个这样的元件。本发明可以借助于包括有若干不同元件的硬件以及借助于适当编程的计算机来实现。在列举了若干装置的单元权利要求中,这些装置中的若干个可以是通过同一个硬件项来具体体现。单词第一、第二、以及第三等的使用不表示任何顺序。可将这些单词解释为名称。

Claims (17)

  1. 一种风险识别方法,包括:
    获得多个风险事件样本,并生成每个所述风险事件样本的个案画像,所述个案画像包括风险行为信息;
    基于每个风险事件样本的风险行为信息,对所述多个风险事件样本进行聚类处理,获得多个风险行为类别;
    根据每个风险行为类别包括的风险事件样本,生成每个风险行为类别的模式信息,所述每个风险行为类别的模式信息包括:与每个风险行为信息对应的一个以上的风险行为特征以及每个所述风险行为特征的权重;
    当需要对目标事件进行风险识别时,根据所述每个风险行为的模式信息,对所述目标事件进行风险识别。
  2. 根据权利要求1所述的方法,所述与每个风险行为信息对应的风险行为特征包括:
    开启特定的功能、开启特定的权限、更换绑定电话号码、更改绑定电子邮箱、更改密码、支付位置变化、变更收货地址和/或购买特定商品。
  3. 根据权利要求1所述的方法,所述方法还包括:
    获得每个风险行为类别的目标事件;
    获得每个风险行为类别的各目标事件的风险主体相关信息;
    基于每个风险行为类别的各目标事件的风险主体相关信息,对该风险行为类别的目标事件进行聚类处理,获得一个以上的风险主体类别;
    根据每个风险主体类别包括的目标事件,生成每个风险主体类别的模式信息;所述每个风险主体类别的模式信息具体包括:与每个风险主体相关信息对应的一个以上风险主体特征、及每个所述风险主体特征的权重;
    通过每个风险主体类别的模式信息对待识别事件进行识别。
  4. 根据权利要求1所述的方法,所述方法还包括:
    获得每个风险行为类别的目标事件;
    获得每个风险行为类别的目标事件的风险主体相关信息;
    通过每个风险行为类别的风险主体相关信息,对待识别事件进行识别。
  5. 根据权利要求3或4所述的方法,所述与每个风险主体相关信息对应的风险主体特征包括:
    ID、即时通讯应用账号、支付应用账号、银行卡信息、电话号码、电子邮箱、操作 设备号码和/或IP地址。
  6. 根据权利要求1所述的方法,所述根据所述每个风险行为的模式信息,对所述目标事件进行风险识别,包括:
    提取所述目标事件中与每个风险行为类别的模式信息对应的风险行为特征;
    基于提取的风险行为特征及每个所述风险行为特征对应的权重,确定所述目标事件是否为该风险行为类别的风险事件。
  7. 根据权利要求1所述的方法,所述方法还包括:
    基于所述模式信息,生成安全教育页面,并展示所述安全教育页面。
  8. 一种风险识别方法,包括:
    获得多个风险事件样本,并生成每个所述风险事件样本的个案画像,所述个案画像包括风险主体相关信息;
    基于每个风险事件样本的风险主体相关信息,对所述多个风险事件样本进行聚类处理,获得多个风险主体类别;
    根据每个风险主体类别包括的风险事件样本,生成每个风险主体类别的模式信息,所述每个风险主体类别的模式信息包括:与每个风险主体相关信息对应的一个以上的风险主体特征以及每个所述风险主体特征的权重;
    当需要对事件进行风险识别时,根据所述每个风险主体的模式信息,对所述事件进行风险识别。
  9. 根据权利要求8所述的方法,所述根据所述每个风险主体类别的模式信息,对所述事件进行风险识别,包括:
    提取所述事件中与每个风险主体类别的模式信息对应的风险主体特征;
    基于提取的风险主体特征及每个所述风险主体特征对应的权重,确定所述事件是否为风险事件。
  10. 一种风险识别装置,包括:
    个案画像生成单元,用于生成多个风险事件样本中每个所述风险事件样本的个案画像,所述个案画像包括风险行为信息;
    聚类处理单元,用于基于每个风险事件样本的风险行为信息,对所述多个风险事件样本进行聚类处理,获得多个风险行为类别;
    模式生成单元,用于根据每个风险行为类别包括的风险事件样本,生成每个风险行为类别的模式信息,所述每个风险行为类别的模式信息包括:与每个风险行为信息对应的一个以上的风险行为特征以及每个所述风险行为特征的权重;
    识别单元,用于当需要对目标事件进行风险识别时,根据所述每个风险行为的模式信息,对所述目标事件进行风险识别。
  11. 根据权利要求10所述的装置,所述装置还包括获得单元;所述获得单元用于获得每个风险行为类别的各目标事件的风险主体相关信息;
    所述聚类处理单元还用于基于每个风险行为类别的各目标事件的风险主体相关信息,对该风险行为类别的目标事件进行聚类处理,获得一个以上的风险主体类别;
    所述模式生成单元还用于根据每个风险主体类别包括的目标事件,生成每个风险主体类别的模式信息;所述每个风险主体类别的模式信息具体包括:与每个风险主体相关信息对应的一个以上风险主体特征、及每个所述风险主体特征的权重;
    所述识别单元还用于通过每个风险主体类别的模式信息对待识别事件进行识别。
  12. 根据权利要求10所述的装置,所述装置还包括获得单元;所述获得单元用于获得每个风险行为类别的目标事件的风险主体相关信息;
    所述识别单元还用于通过每个风险行为类别的风险主体相关信息,对待识别事件进行识别。
  13. 根据权利要求10所述的装置,所述识别单元具体用于提取所述目标事件中与每个风险行为类别的模式信息对应的风险行为特征,并基于提取的风险行为特征及每个所述风险行为特征对应的权重,确定所述目标事件是否为该风险行为类别的风险事件。
  14. 一种风险识别装置,包括:
    个案画像生成单元,用于生成多个风险事件样本中每个所述风险事件样本的个案画像,所述个案画像包括风险主体相关信息;
    聚类处理单元,用于基于每个风险事件样本的风险主体相关信息,对所述多个风险事件样本进行聚类处理,获得多个风险主体类别;
    模式生成单元,用于根据每个风险主体类别包括的风险事件样本,生成每个风险主体类别的模式信息,所述每个风险主体类别的模式信息包括:与每个风险主体相关信息对应的一个以上的风险主体特征以及每个所述风险主体特征的权重;
    识别单元,用于当需要对事件进行风险识别时,根据所述每个风险主体的模式信息,对所述事件进行风险识别。
  15. 根据权利要求14所述的装置,所述识别单元具体用于提取所述事件中与每个风险主体类别的模式信息对应的风险主体特征,并基于提取的风险主体特征及每个所述风险主体特征对应的权重,确定所述事件是否为风险事件。
  16. 一种计算机可读存储介质,其上存储有计算机程序,其特征在于,该程序被处 理器执行时实现权利要求1-9任一项所述方法的步骤。
  17. 一种计算机设备,包括存储器、处理器及存储在存储器上并可在处理器上运行的计算机程序,其特征在于,所述处理器执行所述程序时实现权利要求1-9任一项所述方法的步骤。
PCT/CN2020/070679 2019-03-14 2020-01-07 一种风险识别方法及装置 Ceased WO2020181911A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201910195344.5A CN110084468B (zh) 2019-03-14 2019-03-14 一种风险识别方法及装置
CN201910195344.5 2019-03-14

Publications (1)

Publication Number Publication Date
WO2020181911A1 true WO2020181911A1 (zh) 2020-09-17

Family

ID=67412458

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2020/070679 Ceased WO2020181911A1 (zh) 2019-03-14 2020-01-07 一种风险识别方法及装置

Country Status (3)

Country Link
CN (1) CN110084468B (zh)
TW (1) TWI752349B (zh)
WO (1) WO2020181911A1 (zh)

Cited By (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN113033966A (zh) * 2021-03-03 2021-06-25 携程旅游信息技术(上海)有限公司 风险目标识别方法、装置、电子设备和存储介质
CN113571157A (zh) * 2021-04-20 2021-10-29 杭州袋虎信息技术有限公司 基于fmt特征智能识别风险人员心理画像系统
CN114820210A (zh) * 2022-04-25 2022-07-29 中国农业银行股份有限公司 用户风险的评估方法、装置、电子设备及存储介质
CN119832261A (zh) * 2024-12-24 2025-04-15 中国银联股份有限公司 团队用户识别方法、装置、电子设备、介质和程序产品
US12423702B2 (en) 2021-10-09 2025-09-23 Mastercard International Incorporated Neural network based methods and systems for increasing approval rates of payment transactions

Families Citing this family (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN110084468B (zh) * 2019-03-14 2020-09-01 阿里巴巴集团控股有限公司 一种风险识别方法及装置
CN110474899B (zh) * 2019-08-09 2022-01-14 腾讯科技(深圳)有限公司 一种业务数据处理方法、装置、设备及介质
CN110766040B (zh) * 2019-09-03 2024-02-06 创新先进技术有限公司 用于对交易风险数据进行风险聚类的方法及装置
CN115983999A (zh) * 2023-01-10 2023-04-18 南方电网调峰调频发电有限公司鲁布革水力发电厂 一种电力市场的电力交易数据风险分析方法及系统
CN116049708B (zh) * 2023-01-29 2026-03-27 中国银联股份有限公司 一种基于图谱的关联关系筛选方法及装置
CN117035082A (zh) * 2023-10-10 2023-11-10 北京江融信科技有限公司 一种用于识别欺诈团伙的知识图谱实时运算方法和系统

Citations (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20140172497A1 (en) * 2012-12-17 2014-06-19 Electronics And Telecommunications Research Institute Apparatus and method for managing risk based on prediction on social web media
CN105590156A (zh) * 2014-11-25 2016-05-18 中国银联股份有限公司 高风险银行卡的检测方法以及数据处理装置
CN108805444A (zh) * 2018-06-07 2018-11-13 北京字节跳动网络技术有限公司 评估方法、装置、设备和计算机可读存储介质
CN109063966A (zh) * 2018-07-03 2018-12-21 阿里巴巴集团控股有限公司 风险账户的识别方法和装置
CN109242499A (zh) * 2018-09-19 2019-01-18 中国银行股份有限公司 一种交易风险预测的处理方法、装置及系统
CN109272323A (zh) * 2018-09-14 2019-01-25 阿里巴巴集团控股有限公司 一种风险交易识别方法、装置、设备及介质
CN110084468A (zh) * 2019-03-14 2019-08-02 阿里巴巴集团控股有限公司 一种风险识别方法及装置

Family Cites Families (13)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US8924269B2 (en) * 2006-05-13 2014-12-30 Sap Ag Consistent set of interfaces derived from a business object model
CN110009372B (zh) * 2012-08-03 2023-08-18 创新先进技术有限公司 一种用户风险识别方法和装置
CN104778166B (zh) * 2014-01-09 2018-02-13 腾讯科技(深圳)有限公司 页面安全标识显示方法、装置和网络系统
CN105703966A (zh) * 2014-11-27 2016-06-22 阿里巴巴集团控股有限公司 网络行为风险识别方法及装置
CN106296195A (zh) * 2015-05-29 2017-01-04 阿里巴巴集团控股有限公司 一种风险识别方法及装置
CN106355405A (zh) * 2015-07-14 2017-01-25 阿里巴巴集团控股有限公司 风险识别方法、装置及风险防控系统
US10033702B2 (en) * 2015-08-05 2018-07-24 Intralinks, Inc. Systems and methods of secure data exchange
CN106067088A (zh) * 2016-05-30 2016-11-02 中国邮政储蓄银行股份有限公司 电子银行访问行为的检测方法和装置
CN107391569B (zh) * 2017-06-16 2020-09-15 阿里巴巴集团控股有限公司 数据类型的识别、模型训练、风险识别方法、装置及设备
CN108108902B (zh) * 2017-12-26 2021-06-29 创新先进技术有限公司 一种风险事件告警方法和装置
CN108399509A (zh) * 2018-04-12 2018-08-14 阿里巴巴集团控股有限公司 确定业务请求事件的风险概率的方法及装置
CN109409641A (zh) * 2018-09-03 2019-03-01 平安科技(深圳)有限公司 风险评价方法、装置、计算机设备和存储介质
CN109325691B (zh) * 2018-09-27 2020-10-16 上海观安信息技术股份有限公司 异常行为分析方法、电子设备及计算机程序产品

Patent Citations (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20140172497A1 (en) * 2012-12-17 2014-06-19 Electronics And Telecommunications Research Institute Apparatus and method for managing risk based on prediction on social web media
CN105590156A (zh) * 2014-11-25 2016-05-18 中国银联股份有限公司 高风险银行卡的检测方法以及数据处理装置
CN108805444A (zh) * 2018-06-07 2018-11-13 北京字节跳动网络技术有限公司 评估方法、装置、设备和计算机可读存储介质
CN109063966A (zh) * 2018-07-03 2018-12-21 阿里巴巴集团控股有限公司 风险账户的识别方法和装置
CN109272323A (zh) * 2018-09-14 2019-01-25 阿里巴巴集团控股有限公司 一种风险交易识别方法、装置、设备及介质
CN109242499A (zh) * 2018-09-19 2019-01-18 中国银行股份有限公司 一种交易风险预测的处理方法、装置及系统
CN110084468A (zh) * 2019-03-14 2019-08-02 阿里巴巴集团控股有限公司 一种风险识别方法及装置

Cited By (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN113033966A (zh) * 2021-03-03 2021-06-25 携程旅游信息技术(上海)有限公司 风险目标识别方法、装置、电子设备和存储介质
CN113571157A (zh) * 2021-04-20 2021-10-29 杭州袋虎信息技术有限公司 基于fmt特征智能识别风险人员心理画像系统
US12423702B2 (en) 2021-10-09 2025-09-23 Mastercard International Incorporated Neural network based methods and systems for increasing approval rates of payment transactions
CN114820210A (zh) * 2022-04-25 2022-07-29 中国农业银行股份有限公司 用户风险的评估方法、装置、电子设备及存储介质
CN119832261A (zh) * 2024-12-24 2025-04-15 中国银联股份有限公司 团队用户识别方法、装置、电子设备、介质和程序产品

Also Published As

Publication number Publication date
CN110084468B (zh) 2020-09-01
TW202034248A (zh) 2020-09-16
TWI752349B (zh) 2022-01-11
CN110084468A (zh) 2019-08-02

Similar Documents

Publication Publication Date Title
CN110084468B (zh) 一种风险识别方法及装置
Zhu et al. NUS: Noisy-sample-removed undersampling scheme for imbalanced classification and application to credit card fraud detection
Wu et al. Rethinking membership inference attacks against transfer learning
Hu et al. Cost-sensitive GNN-based imbalanced learning for mobile social network fraud detection
Fu et al. Credit card fraud detection using convolutional neural networks
Modi et al. Review on fraud detection methods in credit card transactions
WO2021003681A1 (en) Method and system for neuropsychological performance test
Teng et al. Leveraging adversarial augmentation on imbalance data for online trading fraud detection
Borkar et al. Real or fake identity deception of social media accounts using recurrent neural network
CN114254624B (zh) 一种确定网站类型的方法及其系统
Xiao et al. Explainable fraud detection for few labeled time series data
CN107070702B (zh) 基于合作博弈支持向量机的用户账号关联方法及其装置
Sonowal et al. A model to detect fake profile on Instagram using rule-based approach
Singla Machine Learning for Finance
Liu et al. A Big Data-Based Anti-Fraud Model for Internet Finance.
WO2020093817A1 (zh) 一种核身方法及装置
CN115630147A (zh) 应答方法、装置、电子设备及存储介质
CN115510131A (zh) 数据项展示方法及装置
Sinčák Machine learning methods in payment card fraud detection
US20240311915A1 (en) Systems and methods for incentivizing behavior using data projection
Wu et al. Backdoor for debias: mitigating model bias with backdoor attack-based artificial bias
US20260087104A1 (en) Data privacy protection and removal for artificial intelligence model training and deployment
Rahman et al. Comparative Study of Feature Selection Techniques in Machine Learning Algorithms for Predicting Female School Attrition in Bangladesh
Wang et al. Addressing Imbalance Data for Online Fraud Detection
Nam Modelling Stock Market Manipulation in Online Forums

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 20769297

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 20769297

Country of ref document: EP

Kind code of ref document: A1