Probabilistic Device Profile Matching Pipeline

指纹不是一次 Hash,而是有版本、有缺失语义、有冲突处理和时间衰减的画像归并过程

Probabilistic device profile matching and risk graph pipeline Versioned observations are normalized, candidates are recalled, similarity and conflicts are evaluated, profiles are split or merged, and business feedback ages the resulting risk graph. OBSERVATION INTAKE FEATURE PROCESSING IDENTITY RESOLUTION RISK AND FEEDBACK feedback updates reliability weights, TTL and profile lineage Versioned Observationsbrowser / Android / edge / behaviorsource + observed_at + schema + consent Event-bound EnvelopebizId / session / nonce / timestampclaims remain untrusted until verified Scoped Stable Hintsfirst-party ID / app GUID / accountreset semantics constrain identity links Normalize and Validatecanonicalize / bucket / cross-checkmissing is data; ERROR is not SAFE Feature Registrystability / entropy / integrity / TTLweights vary by platform and version Candidate Recallstrong-ID index / SimHash / ANNretrieve a small historical profile set Availability-aware Similaritysum(w * available * sim) / sum(w * available)exact / distance / set / temporal decay Conflict and Collision Guardimpossible reuse / concurrent location / driftmatch / new profile / split / merge / review Versioned Profile Storeconfidence / lineage / first_seen / last_seenraw signals and derived IDs have separate TTLs Risk Graph Joindevice / account / IP / order / addresstyped, directed, timestamped confidence edges Tiered Decisionallow / limit / challenge / review / denyreason codes + model version + appeal path Outcome and Agingconfirmed fraud / appeal / trusted authdecay stale edges; prevent label poisoning LEGEND observation feature semantics profile / relationship conflict / decision server processing Core invariant: an exact hash can index observations, but identity resolution must tolerate legitimate drift and expose uncertainty. Governance invariant: reset intent, purpose scope and retention policy constrain which historical profiles may be linked.

先召回,再精确匹配

  • 强标识、SimHash 或近邻索引只负责缩小候选集
  • 最终判断必须处理可用字段、冲突和时间衰减
  • 没有候选不等于恶意,可能只是合法的新设备

画像允许分裂与合并

  • 升级与重装可能造成碎片,同型号设备可能误合并
  • 画像需要 lineage、置信度和可回滚的版本历史
  • 碰撞检测应独立于产生指纹的同一套逻辑

反馈也可能污染系统

  • 登录成功、短信通过和人工申诉不是同强度证据
  • 错误标签若直接回灌,会把一次误判训练成长期事实
  • 反馈更新应有来源权重、冷却期和审计记录