Intelligent network false information identification and early warning system based on multi-modal behavior map
Through an intelligent network false information identification and early warning system based on multimodal behavior map, the problem that single-modal data analysis in the existing technology is difficult to capture the dynamic characteristics of fraudulent behavior is solved, and high-accuracy identification of fraud gangs is achieved, reducing the risk of misjudgment, and adapting to complex scenarios.
Patent Information
- Application Number
- CN202510615893.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-14
- Publication Date
- 2025-06-13
- Estimated Expiration
- 2045-05-14
AI Technical Summary
Existing anti-fraud technologies rely on single-modal data analysis, lack the unified modeling ability of cross-platform and cross-modal data, it is difficult to capture the dynamic evolutionary timing characteristics of fraudulent behavior, and it is impossible to effectively associate cross-platform entities, resulting in low recognition rate of gang crimes, high false alarm rate, and poor real-time performance.
An intelligent network false information identification and early warning system based on multimodal behavior map is adopted. The original user behavior data is collected from multiple data sources through the data acquisition module. The dynamic behavior map construction module is built and updated in real time. The timing reasoning model training module trains the false information timing reasoning model, and the risk warning module performs false information identification and risk warning based on the model and historical abnormal behavior map library.
Significantly improve the identification accuracy of fraud gangs, enhance correlation analysis capabilities, reduce the risk of misjudgment, adapt to complex scenarios, and avoid missed detection caused by the inability to capture long-term cross-platform behavior in the existing technology.
Smart Images

Figure CN120145279A_ABST
Abstract
Description
Technical Field
[0001] Embodiments of the present application relate to the field of intelligent network false information identification and early warning, and specifically to an intelligent network false information identification and early warning system based on a multi-modal behavior graph. Background Art
[0002] Existing anti-fraud technologies mainly rely on single-modal data analysis and lack the ability to unify the modeling of cross-platform and cross-modal data. Traditional systems match through preset static rules or a single machine learning model, making it difficult to capture the dynamic evolution time series characteristics of fraud behaviors. Although some solutions use large language models to analyze text semantics, they are not deeply integrated with the behavior graph, resulting in the disconnection between semantic risks and entity associations. In addition, existing technologies cannot effectively associate cross-platform entities. The data island problem leads to a low identification rate and a high false alarm rate for gang crimes, and relies on post-event manual review, with poor real-time performance. Although the large model solution can analyze text intentions, it faces problems such as high computing power requirements and difficulty in real-time deployment. Existing fusion systems also lack a feature collaboration mechanism guided by the graph topology, restricting the timeliness of early warning. Summary of the Invention
[0003] This section of the content of the present application is used to briefly introduce concepts, which will be described in detail in the subsequent detailed implementation section. This section of the content of the present application is not intended to identify the key features or essential features of the claimed technical solution, nor is it intended to limit the scope of the claimed technical solution.
[0004] Some embodiments of the present application propose an intelligent network false information identification and early warning system based on a multi-modal behavior graph to solve the technical problems mentioned in the above background art section.
[0005] In a first aspect, some embodiments of the present application provide an intelligent network false information identification and early warning system based on a multi-modal behavior graph. The intelligent network false information identification and early warning system includes: a data collection module configured to collect raw user behavior data from multiple data sources, where the raw user behavior data includes multiple entity names; a dynamic behavior graph construction module configured to construct a dynamic behavior graph according to the raw user behavior data, and to monitor in real time new behavior stream data corresponding to the raw user behavior data, and update the topological structure of the dynamic behavior graph according to the new behavior stream data to obtain an updated dynamic behavior graph; a temporal reasoning model training module configured to extract positive and negative samples from a historical false case library, construct a behavior sequence data set with time stamps, and train an initial false information temporal reasoning model according to the behavior sequence data set to obtain a trained false information temporal reasoning model, where the false information temporal reasoning model is used to identify the risk score of the dynamic behavior graph; a risk early warning module configured to identify false information in the updated dynamic behavior graph according to the false information temporal reasoning model and a historical abnormal behavior graph library to generate corresponding false identification information and perform risk early warning, where the false identification information includes a risk identification result and an associated evidence chain.
[0006] Optionally, constructing a dynamic behavior graph according to the raw user behavior data includes: extracting each entity node and the association relationship between entities from the raw user behavior data; generating a dynamic behavior graph corresponding to each entity node and the association relationship between entities based on a graph database, where the node attributes of the entity nodes in the dynamic behavior graph include: time stamp, operation type, and edge weight.
[0007] Optionally, monitoring in real time new behavior stream data corresponding to the raw user behavior data and updating the topological structure of the dynamic behavior graph according to the new behavior stream data to obtain an updated dynamic behavior graph includes: monitoring new behavior stream data corresponding to the raw user behavior data in multiple data sources within a preset time period; in response to the monitored new behavior stream data indicating a new device binding an account, parsing the new behavior stream data into a new edge; in response to the monitored new behavior stream data indicating a cross-region login behavior, parsing the new behavior stream data into an updated edge attribute; updating the dynamic behavior graph according to the new edge and the updated edge attribute; adjusting the weight of the historical edges of the dynamic behavior graph according to a preset rule; in response to determining that a device corresponding to a device entity node in the dynamic behavior graph meets a preset risk condition, constructing a subgraph by expanding two-hop neighbors outward with the device entity node as the center, and recalculating the weights of all edges in the dynamic behavior graph.
[0008] Optionally, training the initial false information temporal reasoning model according to the behavior sequence data set to obtain a trained false information temporal reasoning model includes: fusing the social text features and transaction data features included in each behavior sequence data in the behavior sequence data set to generate fused features, obtaining a fused feature set; training the initial false information temporal reasoning model according to the fused feature set to obtain a trained false information temporal reasoning model.
[0009] Optionally, identifying false information in the updated dynamic behavior graph according to the false information temporal reasoning model and the historical abnormal behavior graph library to generate corresponding false identification information includes: inputting the updated dynamic behavior graph into the false information temporal reasoning model to obtain a behavior risk score corresponding to the updated dynamic behavior graph as a risk identification result; determining the similarity between the updated dynamic behavior graph and each historical abnormal behavior graph in the historical abnormal behavior graph library to obtain a similarity set; determining the historical abnormal behavior graph corresponding to the similarity meeting the preset condition in the similarity set as an associated historical abnormal behavior graph, obtaining a group of associated historical abnormal behavior graphs; in response to determining that the behavior risk score is greater than or equal to the preset score, performing multi-dimensional verification on the updated dynamic behavior graph and outputting multi-dimensional association information; merging the group of associated historical abnormal behavior graphs and the multi-dimensional association information into an associated evidence chain; merging the risk identification result and the associated evidence chain into false identification information.
[0010] In a second aspect, some embodiments of the present application provide an intelligent network false information identification and early warning device based on a multi-modal behavior graph. The device includes: an acquisition unit configured to acquire original user behavior data from multiple data sources, where the original user behavior data includes: multiple entity names; a graph construction unit configured to construct a dynamic behavior graph according to the original user behavior data, and real-time monitor new behavior stream data corresponding to the original user behavior data, and update the topological structure of the dynamic behavior graph according to the new behavior stream data to obtain an updated dynamic behavior graph; a model training unit configured to extract positive and negative samples from a historical false case library, construct a behavior sequence data set with timestamps, and train an initial false information temporal reasoning model according to the behavior sequence data set to obtain a trained false information temporal reasoning model, where the false information temporal reasoning model is used to identify the risk score of the dynamic behavior graph; a risk early warning unit configured to identify false information in the updated dynamic behavior graph according to the false information temporal reasoning model and the historical abnormal behavior graph library to generate corresponding false identification information and perform risk early warning, where the false identification information includes: a risk identification result and an associated evidence chain.
[0011] In a third aspect, some embodiments of the present application provide an electronic device, including: one or more processors; a storage device storing one or more programs thereon, which, when executed by the one or more processors, cause the one or more processors to implement the system described in any implementation manner of the above first aspect.
[0012] In a fourth aspect, some embodiments of the present application provide a computer-readable medium storing a computer program thereon, wherein when the program is executed by a processor, the system described in any implementation manner of the above first aspect is implemented.
[0013] The above various embodiments of the present application have the following beneficial effects: Through the intelligent network false information identification and early warning system based on the multi-modal behavior graph of some embodiments of the present application, through the synergistic effect of the dynamic behavior graph and the large language model, the identification accuracy of fraud gangs is significantly improved, specifically manifested as follows: 1. Enhance the correlation analysis ability: Utilize the topological structure of the graph to fuse multi-modal data, break through the limitations of traditional single-dimensional detection, and effectively identify the hidden correlation relationships between users, devices, and accounts; 2. Reduce the risk of misjudgment: Capture dynamic behavior characteristics (such as abnormal transfer frequency, device switching rules) through the time series reasoning model, distinguish normal operations from fraudulent behaviors, and reduce false alarms caused by static rules; 3. Adapt to complex scenarios: Have stronger robustness to the phased evolution of gang behaviors (such as decentralized registration, centralized crime), avoid the situation in the prior art where traditional models are difficult to identify phased split behaviors due to the inability to capture long-term cross-platform behaviors, resulting in missed detections. BRIEF DESCRIPTION OF THE DRAWINGS
[0014] In combination with the accompanying drawings and with reference to the following specific embodiments, the above and other features, advantages, and aspects of the embodiments of the present application will become more obvious. Throughout the accompanying drawings, the same or similar reference numerals represent the same or similar elements. It should be understood that the drawings are schematic, and the elements and elements are not necessarily drawn to scale.
[0015] Figure 1 is a flowchart of some embodiments of the intelligent network false information identification and early warning system based on the multi-modal behavior graph according to the present application; Figure 2 is an exemplary architecture diagram of the intelligent network false information identification and early warning system based on the multi-modal behavior graph of some embodiments of the present application; Figure 3 is a schematic structural diagram of some embodiments of the intelligent network false information identification and early warning device based on the multi-modal behavior graph according to the present application; Figure 4 is a schematic structural diagram of an electronic device suitable for implementing some embodiments of the present application; Description of the drawing reference numerals: 301 - acquisition unit; 302 - atlas construction unit; 303 - model training unit; 304 - risk warning unit. Detailed implementation manners
[0016] Embodiments of the present application will be described in more detail below with reference to the accompanying drawings. Although some embodiments of the present application are shown in the drawings, it should be understood that the present application can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. On the contrary, these embodiments are provided to more thoroughly and completely understand the present application. It should be understood that the drawings and embodiments of the present application are only for exemplary purposes and are not used to limit the protection scope of the present application.
[0017] In addition, it should be noted that for the sake of convenience of description, only parts related to the relevant invention are shown in the drawings. Without conflict, the embodiments in the present application and the features in the embodiments can be combined with each other.
[0018] It should be noted that the concepts such as "first" and "second" mentioned in the present application are only used to distinguish different devices, modules or units, and are not used to limit the order or interdependence relationship of the functions performed by these devices, modules or units.
[0019] It should be noted that the modifications of "one" and "multiple" mentioned in the present application are illustrative rather than restrictive. Those skilled in the art should understand that unless otherwise clearly specified in the context, it should be understood as "one or more".
[0020] The names of the messages or information exchanged between multiple devices in the embodiments of the present application are only for illustrative purposes and are not used to limit the scope of these messages or information.
[0021] The present application will be described in detail below with reference to the drawings and in combination with the embodiments.
[0022] Figure 1 It is a process of some embodiments of an intelligent network false information identification and warning system based on a multi-modal behavior atlas in some embodiments of the present application. The intelligent network false information identification and warning system based on a multi-modal behavior atlas includes the following steps: Step 101, a data acquisition module, is configured to: acquire original user behavior data from multiple data sources.
[0023] In some embodiments, the data acquisition module is configured to: collect raw user behavior data from multiple data sources. Among them, the above-mentioned raw user behavior data includes: multiple entity names. The data acquisition module can be a processor for collecting data in the intelligent network false information identification and early warning system. For example, the data acquisition module can collect structured and unstructured data in real time from communication operators, payment platforms, and social networks, use large language models to perform intent recognition and semantic annotation on unstructured text, and solve the problem of cross-platform data heterogeneity through entity alignment technology. The raw user behavior data can include login logs, transaction records, device fingerprint databases, etc. of multiple users. The raw user behavior data can represent the account transaction behavior data of one or more users. For example, the raw user behavior data can represent the behavior data of users transferring funds to each other through devices. The multiple data sources can refer to data sources such as communication operators, payment platforms, and social network platforms.
[0024] It should be noted that, please refer to Figure 2 , the intelligent network false information identification and early warning system can be composed of a data acquisition module (multi-modal data acquisition layer), a dynamic behavior graph construction module (dynamic behavior graph construction layer), a time series reasoning model training module (time series reasoning engine / reasoning layer), and a risk early warning module (early warning decision module / application layer). The time series reasoning model training module can be a processor for training the false information time series reasoning model. The dynamic behavior graph construction module can be a processor for constructing a dynamic behavior graph.
[0025] The multi-modal data acquisition layer collects structured and unstructured data in real time from communication operators, payment platforms, and social networks, uses large language models to perform intent recognition and semantic annotation on unstructured text, and solves the problem of cross-platform data heterogeneity through entity alignment technology.
[0026] The dynamic behavior graph construction layer, based on knowledge graph technology, uses entities such as user ID, device number, and account (bank account) as nodes, and uses interaction relationships (such as call frequency , transfer path ) as edges to construct a multi-modal dynamic behavior graph. Among them, the entity nodes are embedded with a fusion of traditional features and semantic vectors extracted by large models, and the edge weights are updated in real time through the following formula:
[0027] Among them, is the time decay factor (default value is 0.05), and The time-triggered increment refers to the enhancement factor added to the edge weight when the abnormal behavior threshold under certain time dimensions is met. For example, "transferring more than 5 times a day" triggers an increase in the edge weight by 0.3. This value is a pre-set hyperparameter that can be configured and optimized according to actual business requirements or historical data statistics. It is the timestamp of the most recent update of the edge. t represents the current time.
[0028] : It represents the updated weight of the edge between node i and node j at the current moment t, reflecting the latest behavioral association strength between the two entities.
[0029] : It represents the weight of the edge between node i and node j at the time of the last update ; λ: The time decay factor controls the decay rate of the association over time. The default value is 0.05 and it is adjustable. This factor is used to weaken the impact of outdated behaviors on the current judgment.
[0030] : It represents the time interval from the last behavior occurrence to the current time, and the unit can be hours or seconds, depending on the system settings.
[0031] : The time-triggered increment is the amount of weight enhancement when specific high-frequency behavior conditions are met. For example, when "transferring more than 5 times a day" is triggered, the increment is set to 0.3. This value is a pre-set hyperparameter that can be optimized according to business rules or historical statistics.
[0032] : The event indicator function (Indicator Function) takes the value 1 if the set event condition is met, otherwise 0. It is used to indicate whether to perform the adjustment of the edge weight increment.
[0033] The time series inference engine (inference layer) adopts a fusion model of graph neural network (GNN) and Transformer. Among them, the GNN layer is used to capture the topological associations between entities (such as the account sharing relationship of fraud gangs), and the Transformer layer is used to analyze the time series evolution pattern of fraud behaviors (such as the behavior chain from the induction period to the transfer period), and finally outputs the real-time risk score of user behaviors.
[0034] The risk warning module (application layer) then realizes the full-chain prevention and control from individual anomaly detection to the case stringing and analysis of gang crimes based on the multi-level risk score fusion algorithm. The risk warning module can be a processor with a multi-level risk score fusion algorithm built in.
[0035] Step 102, the dynamic behavior graph construction module is configured to: construct a dynamic behavior graph according to the above-mentioned original user behavior data, and real-time monitor the new behavior stream data corresponding to the above-mentioned original user behavior data, and update the topological structure of the above-mentioned dynamic behavior graph according to the above-mentioned new behavior stream data to obtain an updated dynamic behavior graph.
[0036] In some embodiments, the dynamic behavior graph construction module is configured to: construct a dynamic behavior graph according to the above-mentioned original user behavior data, and real-time monitor the new behavior stream data corresponding to the above-mentioned original user behavior data, and update the topological structure of the above-mentioned dynamic behavior graph according to the above-mentioned new behavior stream data to obtain an updated dynamic behavior graph. Extract various entity nodes (including user ID, device number, bank account) and association relationships (such as IP address sharing, transfer frequency, call frequency, transfer path) from the above-mentioned original user behavior data. Among them, the user ID can represent the ID name of the transfer user or the receiving user. The device number can represent the ID number of the device operated by the transfer user or the receiving user. The bank account can represent the bank account of the transfer user or the receiving user. IP address sharing can mean that two users share an IP address. The transfer frequency can represent the number of transfers of a certain bank account within a preset time period. The call frequency can represent the frequency of calls between two devices. The transfer path can represent the way of transfer. For example, it can be in the way of transferring from a social platform to a bank account, or in the way of transferring from a bank account to a bank account.
[0037] In practice, the dynamic behavior graph construction module can construct a dynamic behavior graph according to the above-mentioned original user behavior data through the following steps: First step, extract various entity nodes and the association relationships between the entities from the above-mentioned original user behavior data. Here, various entity nodes (including user ID, device number, bank account) and association relationships (such as IP address sharing, transfer frequency, call frequency, transfer path) can be extracted from the above-mentioned original user behavior data by means of traversal.
[0038] Second step, generate a dynamic behavior graph corresponding to the above-mentioned various entity nodes and the association relationships between the entities based on the graph database. Among them, the node attributes of the entity nodes in the above-mentioned dynamic behavior graph include: timestamp, operation type, edge weight. The graph database can refer to the Neo4j graph database. For example, a dynamic behavior graph can be constructed with entities such as user ID, device number, bank account as nodes and association relationships (such as IP address sharing, transfer frequency, call frequency, transfer path) as edges. The operation type can represent the behavior type. For example, the operation type can represent a browsing operation type, a transfer operation type. The timestamp can represent the time node when the behavior is sent. The generation method of the edge weight can refer to the above-mentioned generation method of the edge weight.
[0039] In practice, the dynamic behavior graph construction module can update the topological structure of the above dynamic behavior graph through the following steps to obtain an updated dynamic behavior graph: First, monitor the new behavior stream data corresponding to the above original user behavior data in multiple data sources within a preset time period. The preset time period can refer to the preset duration closest to the current time. For example, monitor whether there is new behavior stream data such as new user login / transfer or device binding.
[0040] Second, in response to the monitored new behavior stream data indicating a new device binding an account, parse the new behavior stream data into a new edge. For example, if it is detected that the new behavior stream data indicates a new device binding an account, it is parsed as: "new edge (device, account, binding relationship)".
[0041] Third, in response to the monitored new behavior stream data indicating a cross-region login behavior, parse the new behavior stream data into an updated edge attribute. For example, if the monitored new behavior stream data indicates a cross-region login behavior, then generate "updated edge attribute (login location, time)".
[0042] Fourth, update the above dynamic behavior graph according to the above new edge and the above updated edge attribute. For example, a new edge can be added to the dynamic behavior graph, or the corresponding edge attribute (updated edge attribute) can be updated on the dynamic behavior graph.
[0043] Fifth, adjust the weights of the historical edges of the above dynamic behavior graph according to preset rules.
[0044] For example, adjust the weights of the historical edges in the above dynamic behavior graph according to preset rules (such as a time decay factor). The adjustment of the weights of the historical edges adopts an exponential decay strategy, that is:
[0045] where, is the time decay factor (default value is 0.05), and is is the time-triggered increment, which refers to the enhancement factor added to the edge weight when the abnormal behavior threshold in certain time dimensions is met. For example, "transfer more than 5 times a day" triggers an increase of 0.3 in the edge weight. This value is a preset hyperparameter and can be configured and optimized according to actual business requirements or historical data statistics. is the timestamp of the last update of the edge. t represents the current time.
[0046] : represents the updated weight of the edge between node i and node j at the current moment t, reflecting the latest behavior association strength between the two entities.
[0047] : represents the weight of the edge between node i and node j at the last update time ; λ: Time decay factor, which controls the decay rate of associations over time. The default value is 0.05 and it is adjustable. This factor is used to weaken the impact of outdated behaviors on the current judgment.
[0048] : represents the time interval from the last occurrence of the behavior to the current time, and the unit can be hours or seconds, depending on the system settings.
[0049] : Time trigger increment, which is the increment of the weight when specific high-frequency behavior conditions are met. For example, when the condition "transfer more than 5 times in a single day" is triggered, the increment is set to 0.3. This value is a preset hyperparameter and can be optimized according to business rules or historical statistics.
[0050] : Event Indicator Function, which takes the value of 1 if the set event condition is met, otherwise 0. It is used to indicate whether to perform the adjustment of the edge weight increment.
[0051] In the sixth step, in response to determining that a device corresponding to a device entity node in the dynamic behavior graph meets a preset risk condition, a subgraph is constructed by expanding two-hop neighbors outward with this device entity node as the center, and the weights of all edges in the dynamic behavior graph are recalculated. The preset risk condition can be: the number of bound accounts of the same device within 24 hours > 5. If new or stronger abnormal interaction patterns are found among multiple nodes, they are used as local subgraphs to replace the original structure in the dynamic behavior graph.
[0052] Step 103, the time-series reasoning model training module, is configured to: extract positive and negative samples from the historical false case library, construct a time-stamped behavior sequence data set, and train the initial false information time-series reasoning model according to the above behavior sequence data set to obtain a trained false information time-series reasoning model.
[0053] In some embodiments, the temporal reasoning model training module is configured to: extract positive and negative samples from the historical false case library, construct a timestamped behavior sequence data set, and train an initial false information temporal reasoning model based on the above behavior sequence data set to obtain a trained false information temporal reasoning model. Among them, the false information temporal reasoning model is used to identify the risk score of the dynamic behavior graph. False information can represent fraud information, that is, whether the user has been defrauded. The historical false case library can refer to the historical fraud case library. For example, historical fraud cases can represent cases of being defrauded by telecommunications fraud. The behavior sequence data can represent the behavior data of a certain historical user on whether they have been defrauded within a historical time period. The behavior sequence data can also include social text features and transaction data features. Social text features can represent the text for users to communicate. Transaction data features can refer to the transfer transaction data of a certain historical user within a historical time period. For example, the above execution entity can refer to the training method of the deep neural network model to train the initial false information temporal reasoning model to obtain a trained false information temporal reasoning model. The initial false information temporal reasoning model can be a fusion model of a graph neural network (GNN) and a Transformer.
[0054] In practice, the temporal reasoning model training module can train the initial false information temporal reasoning model through the following steps to obtain a trained false information temporal reasoning model: First step, fuse the social text features and transaction data features included in each behavior sequence data in the above behavior sequence data set to generate fusion features and obtain a fusion feature set. The behavior sequence data can include multiple behavior data. For example, the social text features and transaction data features included in each behavior data can be dynamically weighted and combined. Among them, the attention mechanism is used to fuse semantic information and behavior features, and its weight assignment is calculated by the following formula:
[0055] Among them, represents the social text feature; represents the transaction data feature. and are trainable parameters, and the vector after dynamic weighted combination will be used as the input feature of the behavior sequence data.
[0056] : represents the fusion weight of the social text feature and the transaction data feature in the m-th behavior data, used to measure the attention degree of this behavior data in the overall behavior sequence data.
[0057] : represents the vector representation of the social text feature (such as the embedding vector encoded by the large language model for chat records and speech fragments).
[0058] : The vector representation indicating the characteristics of transaction data (such as the embedding results of structured data like transfer amount, timestamp, transaction direction, etc.).
[0059] : It represents the fused input formed by concatenating two vectors, used to capture cross-modal context.
[0060] : A trainable weight matrix, which acts on the transformation of the concatenated vectors and is used to learn the linear mapping of semantics and structure.
[0061] : A trainable weight vector, used to calculate the "similarity" weight in the attention score.
[0062] tanh() : An activation function, used to introduce non-linear mapping and improve the model's ability to express complex relationships.
[0063] exp() : It forms a softmax operation with the normalization term in the denominator, making the sum of the attention weights of all behaviors equal to 1.
[0064] In the second step, based on the above fused feature set, the above initial false information temporal reasoning model is trained to obtain a trained false information temporal reasoning model.
[0065] For example, the Transformer encoder can be used to extract sequence features (referring to the continuous behavior sequence of users within a certain time window, including events such as login, transfer, registration, device switching, etc. and their timestamps, platforms, device numbers, etc. context features), and its multi-head attention mechanism is calculated as follows:
[0066] Among them, Q, K, and V respectively correspond to the query, key, and value matrices, is the dimension scaling factor.
[0067] Q: Query Matrix, generated from the current input sequence, indicating "what to pay attention to".
[0068] K: Key Matrix, generated from the context information, indicating "the content identifier that can be paid attention to".
[0069] V: Value Matrix, corresponding to K one by one, indicating the actual information extracted or transmitted.
[0070] : The dimension of the key vector (key dimension scaling factor), which is used to prevent the inner product result from being too large and causing the vanishing gradient. It is usually the number of columns of K.
[0071] softmax: A normalization function that converts the attention scores into a probability distribution, making the sum of all items equal to 1.
[0072] Final output: It is the value matrix V weighted by attention, which reflects the degree of attention of the current input to each item in the entire behavior sequence.
[0073] The behavior sequence data is encoded as a sequence of vectors and input into the Transformer encoder. The output aggregated representation is h (the global feature vector of the behavior sequence data), and w and b are trainable parameters used for the final risk score. The final risk score is output through the Sigmoid function:
[0074] h: The global aggregated vector of the behavior sequence (Transformer output), representing the comprehensive representation of the user behavior within the entire time window.
[0075] Represents the Sigmoid function of the risk score.
[0076] w: A trainable weight vector used for linear mapping.
[0077] b: A trainable bias term, which together with forms the output of the final linear layer.
[0078] Sigmoid activation function: Converts the linear result into a probability value, and the output range is (0, 1), representing the probability meaning of the risk score.
[0079] To ensure the real-time performance of model inference, the system adopts an edge computing and cloud collaboration architecture, and tasks are allocated according to the computational complexity and data volume of the input behavior stream. The specific strategy is as follows:
[0080] Among them, is an empirical threshold (such as 1.2 TFLOPS / GB), which is used to distinguish inference tasks suitable for execution on the edge side or in the cloud. This mechanism effectively reduces latency and improves the second-level response ability.
[0081] : An instance of the input behavior stream data (behavior sequence data), representing a set of user behavior events collected at a certain moment.
[0082] Represents the task allocation strategy function.
[0083] FLOPs(x): Behavioral flow The required number of floating - point operations for model inference (Floating Point Operations), representing the computational complexity.
[0084] DataSize(x): The volume size of the input data, which can be in units of MB or GB.
[0085] : Empirical threshold (such as 1.2 TFLOPs / GB), representing the ratio boundary between computational complexity and data volume. It is the demarcation value for whether a task is suitable for execution at the edge or in the cloud.
[0086] Output: If the ratio is low (i.e., light computation and small data), the inference task is executed at Edge (edge node); if the ratio is high (computation or data is too large), it is transferred to Cloud (cloud center) for execution.
[0087] Step 104, the risk warning module is configured to: identify false information in the above - mentioned updated dynamic behavior graph according to the above - mentioned false information time - series inference model and historical abnormal behavior graph library, generate corresponding false identification information, and conduct risk warning.
[0088] In some embodiments, the risk warning module is configured to: identify false information in the above - mentioned updated dynamic behavior graph according to the above - mentioned false information time - series inference model and historical abnormal behavior graph library, generate corresponding false identification information, and conduct risk warning. Among them, the above - mentioned false identification information includes: risk identification results and associated evidence chains.
[0089] In practice, the risk warning module can identify false information in the above - mentioned updated dynamic behavior graph according to the above - mentioned false information time - series inference model and historical abnormal behavior graph library through the following steps to generate corresponding false identification information: First step, input the above - mentioned updated dynamic behavior graph into the above - mentioned false information time - series inference model to obtain the behavior risk score corresponding to the above - mentioned updated dynamic behavior graph as the risk identification result.
[0090] For example, taking the individual behavior risk score output by the trained false information time - series inference model as the basic risk assessment sub - module, its output and the updated dynamic behavior graph are jointly used as inputs and fed into a fusion module to calculate the group risk score:
[0091] Among them, , , Is the adjustable weight (default values: 0.4, 0.4, 0.2), Reflects the importance of the reaction entity node.
[0092] : Represents the final group risk score, measuring the likelihood of organized fraud or abnormal behavior in a whole subgraph (such as a user group).
[0093] : The structural risk score based on the output of the graph neural network, reflecting the abnormal topological structure (such as the account sharing relationship of a gang type) among entities in the dynamic behavior graph.
[0094] : The behavioral evolution risk score based on the output of the Transformer model, capturing the fraud behavior chain in the time dimension (such as "induce - add friend - transfer").
[0095] : The entity node 's graph importance score, reflecting its influence or centrality degree in the graph, and the higher the score, the more "critical" it is.
[0096] In the second step, determine the similarity between the above - updated dynamic behavior graph and each historical abnormal behavior graph in the above - mentioned historical abnormal behavior graph library to obtain a similarity set. The historical abnormal behavior graph library can refer to a database that stores each dynamic behavior graph with abnormal transaction behaviors processed historically. For example, the similarity between the updated dynamic behavior graph G1 and each normal behavior graph G2 in the historical abnormal behavior graph library can be quantified by the following formula:
[0097] Among them, Is the graph edit distance, Is the node overlap penalty factor (default value: 0.8).
[0098] : The updated dynamic behavior graph And the historical abnormal behavior graph 's similarity score, and the closer the value is to 1, the more similar they are.
[0099] : The updated dynamic behavior graph that needs to be identified currently, usually an abnormal local area extracted from the real - time graph.
[0100] : The known fraud behavior template graph saved in the historical abnormal behavior graph library.
[0101] The graph edit distance (Graph Edit Distance) represents the distance from Convert to The minimum number of editing operations required (such as adding or deleting nodes, edges, etc.). The smaller the value, the more similar.
[0102] : The node overlap penalty coefficient, which controls the normalization range of similarity. The default value is 0.8. The smaller the value, the greater the penalty for differences.
[0103] In the third step, determine the historical abnormal behavior graph corresponding to the similarity that meets the preset conditions in the above similarity set as the associated historical abnormal behavior graph, and obtain a group of associated historical abnormal behavior graphs. For example, the preset condition can be: the similarity is greater than 0.8.
[0104] In the fourth step, in response to determining that the above behavior risk score is greater than or equal to the preset score, perform multi-dimensional verification on the above updated dynamic behavior graph and output multi-dimensional association information. For example, multi-dimensional verification can include: Device dimension: Check whether the device switching frequency deviates from the normal threshold, that is, the number of times the user changes devices within a certain time window (such as 24 hours). Identify the uniqueness of the device through device fingerprints (such as IMEI, MAC, browser characteristics). If it is found that the same account switches frequently between multiple devices within a short period of time, exceeding the preset threshold (such as 3 times / 24h), it is marked as suspicious and further behavior analysis is triggered. Funds dimension: Analyze whether the transfer amount distribution conforms to the "scattered transfer - concentrated transfer" mode.
[0105] In the fifth step, merge the above group of associated historical abnormal behavior graphs with the above multi-dimensional association information into an associated evidence chain.
[0106] In the sixth step, merge the above risk identification results with the above associated evidence chain into false identification information.
[0107] Further refer to Figure 3 , as an implementation of the systems shown in the above figures, the present application provides some embodiments of an intelligent network false information identification and warning device based on a multi-modal behavior graph. These device embodiments correspond to Figure 1 the system embodiments shown, and the intelligent network false information identification and warning device based on the multi-modal behavior graph can be specifically applied to various electronic devices.
[0108] Such as Figure 3As shown in the figure, the intelligent network false information recognition and early warning device based on the multi-modal behavior graph of some embodiments includes: a collection unit 301, a graph construction unit 302, a model training unit 303, and a risk early warning unit 304. Among them, the collection unit 301 is configured to collect original user behavior data from multiple data sources, where the original user behavior data includes: multiple entity names; the graph construction unit 302 is configured to construct a dynamic behavior graph according to the original user behavior data, and to monitor in real time the new behavior stream data corresponding to the original user behavior data, and update the topological structure of the dynamic behavior graph according to the new behavior stream data to obtain an updated dynamic behavior graph; the model training unit 303 is configured to extract positive and negative samples from the historical false case library, construct a behavior sequence data set with time stamps, and train an initial false information time series inference model according to the behavior sequence data set to obtain a trained false information time series inference model, where the false information time series inference model is used to identify the risk score of the dynamic behavior graph; the risk early warning unit 304 is configured to identify false information in the updated dynamic behavior graph according to the false information time series inference model and the historical abnormal behavior graph library to generate corresponding false identification information and perform risk early warning, where the false identification information includes: risk identification results and associated evidence chains.
[0109] It can be understood that the units described in the intelligent network false information recognition and early warning device based on the multi-modal behavior graph correspond to the various steps in the system described in the reference Figure 1 Therefore, the operations, features, and beneficial effects described above for the system also apply to the intelligent network false information recognition and early warning device based on the multi-modal behavior graph and the units included therein, and will not be repeated here.
[0110] Next, refer to Figure 4 , which shows a schematic structural diagram of an electronic device (such as a computing device) suitable for implementing some embodiments of the present application. Figure 4 The electronic device shown is only an example and should not impose any limitations on the functions and usage scopes of the embodiments of the present application. As Figure 4As shown, the computer device includes a processor, a memory, and a network interface connected via a system bus. Among them, the memory may include a non-volatile storage medium and an internal memory. The non-volatile storage medium can store an operating system and computer programs. The computer programs include program instructions, which when executed, can cause the processor to execute any intelligent network false information identification and early warning system based on a multi-modal behavior map. The processor is used to provide computing and control capabilities to support the operation of the entire computer device. The internal memory provides an environment for the operation of the computer programs in the non-volatile storage medium. When the computer programs are executed by the processor, the processor can be caused to execute any intelligent network false information identification and early warning system based on a multi-modal behavior map. The network interface is used for network communication, such as sending assigned tasks, etc. Those skilled in the art can understand that Figure 4 the structure shown in is only a block diagram of some structures related to the solution of this application, and does not constitute a limitation on the computer device to which the solution of this application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine some components, or have different component arrangements.
[0111] It should be understood that the processor may be a central processing unit (CPU), and the processor may also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. Among them, the general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.
[0112] Among them, in one embodiment, the above-mentioned processor is used to run a computer program stored in the memory to implement the following steps: A data acquisition module, configured to: collect original user behavior data from multiple data sources, where the above-mentioned original user behavior data includes: multiple entity names; A dynamic behavior graph construction module, configured to: construct a dynamic behavior graph according to the above-mentioned original user behavior data, and real-time monitor new behavior stream data corresponding to the above-mentioned original user behavior data, and update the topological structure of the above-mentioned dynamic behavior graph according to the above-mentioned new behavior stream data to obtain an updated dynamic behavior graph; A time-series reasoning model training module, configured to: extract positive and negative samples from a historical false case library, construct a behavior sequence data set with timestamps, and train an initial false information time-series reasoning model according to the above-mentioned behavior sequence data set to obtain a trained false information time-series reasoning model, where the false information time-series reasoning model is used to identify the risk score of the dynamic behavior graph; A risk warning module, configured to: identify false information in the above-mentioned updated dynamic behavior graph according to the above-mentioned false information time-series reasoning model and the historical abnormal behavior graph library to generate corresponding false identification information and perform risk warning, where the above-mentioned false identification information includes: a risk identification result and an associated evidence chain.
[0113] An embodiment of the present application also provides a computer-readable storage medium, on which a computer program is stored, and the computer program includes program instructions. The system implemented when the program instructions are executed may refer to each embodiment of the intelligent network false information identification and warning system based on a multi-modal behavior graph of the present application.
[0114] Among them, the above-mentioned computer-readable storage medium may be an internal storage unit of the above-mentioned computer device in the foregoing embodiment, such as the hard disk or memory of the above-mentioned computer device. The above-mentioned computer-readable storage medium may also be an external storage device of the above-mentioned computer device, such as a plug-in hard disk equipped on the above-mentioned computer device, a smart media card (SmartMedia Card, SMC), a secure digital (Secure Digital, SD) card, a flash card (Flash Card), etc.
[0115] It should be noted that in this article, the term "including", "comprising" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, system, article or system including a series of elements not only includes those elements, but also includes other elements not expressly listed, or also includes elements inherent to such process, system, article or system. Without further limitations, an element defined by the statement "including a..." does not exclude the existence of additional identical elements in the process, system, article or system including that element.
[0116] The above description is only some preferred embodiments of the present application and an explanation of the applied technical principles. Those skilled in the art should understand that the scope of the invention involved in the embodiments of the present application is not limited to the technical solutions formed by the specific combination of the above technical features, and should also cover other technical solutions formed by any combination of the above technical features or their equivalent features without departing from the above inventive concept. For example, the technical solutions formed by mutually replacing the above features with the technical features (but not limited to) disclosed in the embodiments of the present application that have similar functions.
Claims
1. An intelligent network false information identification and early warning system based on multimodal behavior graph, characterized in that: include: The data collection module is configured to: collect original user behavior data from multiple data sources, wherein the original user behavior data includes: multiple entity names; The dynamic behavior graph construction module is configured to: construct a dynamic behavior graph according to the original user behavior data, monitor the newly added behavior stream data corresponding to the original user behavior data in real time, and update the topological structure of the dynamic behavior graph according to the newly added behavior stream data to obtain an updated dynamic behavior graph; The temporal reasoning model training module is configured to: extract positive and negative samples from the historical false case library, construct a behavior sequence data set with timestamps, and train the initial false information temporal reasoning model according to the behavior sequence data set to obtain a trained false information temporal reasoning model, wherein the false information temporal reasoning model is used to identify the risk score of the dynamic behavior map; The risk warning module is configured to: identify false information on the updated dynamic behavior graph based on the false information temporal reasoning model and the historical abnormal behavior graph library to generate corresponding false identification information and issue a risk warning, wherein the false identification information includes: risk identification results and associated evidence chains.
2. The intelligent network false information identification and early warning system according to claim 1 is characterized in that: The step of constructing a dynamic behavior graph based on the original user behavior data includes: Extracting each entity node and the association relationship between entities from the original user behavior data; Based on the graph database, a dynamic behavior graph corresponding to each entity node and the association relationship between entities is generated, wherein the node attributes of the entity node in the dynamic behavior graph include: timestamp, operation type, and edge weight.
3. The intelligent network false information identification and early warning system according to claim 2 is characterized in that: The real-time monitoring of the newly added behavior stream data corresponding to the original user behavior data, and updating the topological structure of the dynamic behavior graph according to the newly added behavior stream data to obtain an updated dynamic behavior graph, includes: Monitoring newly added behavior flow data corresponding to the original user behavior data within a preset time period in multiple data sources; In response to the monitored newly added behavior flow data indicating a new device binding account, the newly added behavior flow data is parsed into a newly added edge; In response to the monitored newly added behavior flow data indicating a cross-region login behavior, the newly added behavior flow data is parsed into an update edge attribute; updating the dynamic behavior graph according to the newly added edge and the updated edge attribute; According to preset rules, adjusting the weights of the historical edges of the dynamic behavior graph; In response to determining that a device corresponding to a device entity node in the dynamic behavior graph meets a preset risk condition, a subgraph is constructed by expanding two-hop neighbors outward with the device entity node as the center, and the weights of all edges of the dynamic behavior graph are recalculated.
4. The intelligent network false information identification and early warning system according to claim 3 is characterized in that: The initial false information temporal reasoning model is trained according to the behavior sequence data set to obtain a trained false information temporal reasoning model, including: Fusing the social text features and transaction data features included in each behavior sequence data in the behavior sequence data set to generate a fused feature, thereby obtaining a fused feature set; The initial false information temporal reasoning model is trained according to the fusion feature set to obtain a trained false information temporal reasoning model.
5. The intelligent network false information identification and early warning system according to claim 3 is characterized in that: The step of identifying false information on the updated dynamic behavior graph according to the false information temporal reasoning model and the historical abnormal behavior graph library to generate corresponding false identification information includes: Inputting the updated dynamic behavior graph into the false information temporal reasoning model to obtain a behavior risk score corresponding to the updated dynamic behavior graph as a risk identification result; Determine the similarity between the updated dynamic behavior graph and each historical abnormal behavior graph in the historical abnormal behavior graph library to obtain a similarity set; Determine the historical abnormal behavior graphs corresponding to the similarities of the similarity set that meet the preset conditions as the associated historical abnormal behavior graphs, and obtain an associated historical abnormal behavior graph group; In response to determining that the behavior risk score is greater than or equal to a preset score, performing multi-dimensional verification on the updated dynamic behavior graph and outputting multi-dimensional correlation information; Combining the associated historical abnormal behavior graph group and the multi-dimensional associated information into an associated evidence chain; The risk identification result and the associated evidence chain are combined into false identification information.
Citation Information
Patent Citations
Cross-document false information detection method based on contrast graph learning
CN117852526A
Knowledge graph driven power supply chain risk early warning method and related device
CN119624132A
Financial transaction anomaly detection and risk assessment method and device based on artificial intelligence
CN119693111A
Behavior recognition method, device, equipment, storage medium and computer program product
CN119760475A
Risk prediction method and apparatus, and device and storage medium
WO2023065545A1
Cited By
Financial API (Application Program Interface) link fine-grained anomaly tracing method and system, medium and equipment
CN120639391A
Recruitment false employment information identification and early warning method and system based on reinforcement learning
CN122415045A