Financial fraud behavior intelligent tracking and early warning system

By building a risk data chain and identifying risk nodes in financial interaction events, the problem of traditional technologies being difficult to accurately judge financial fraud behavior is solved, and efficient intelligent tracking and early warning are achieved.

CN120707143APending Publication Date: 2025-09-26SHENZHEN SED LOGIC BUSINESS EQUIP CO LTD

Patent Information

Application Number
CN202510804201.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-17
Publication Date
2025-09-26

AI Technical Summary

Technical Problem

Traditional risk control and anti-fraud methods are difficult to handle large-scale, high-dimensional, and complexly correlated financial interaction event data. Their accuracy and efficiency need to be improved, and they are unable to locally determine the risk information of risk nodes based on the risk data chain, and then judge whether there is financial fraud.

Method used

By acquiring risk behaviors, interaction objects, and behavioral signals in financial interaction events, a risk data chain is constructed to determine the risk information of each risk node. Based on this, it is judged whether there is financial fraud and intelligent tracking and early warning are achieved.

Benefits of technology

It achieves accurate judgment from local risk nodes to the overall situation, and improves the accuracy and efficiency of tracking and early warning of financial fraud.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120707143A_ABST
    Figure CN120707143A_ABST
Patent Text Reader

Abstract

The invention discloses a financial fraud behavior intelligent tracking and early warning system, and the system comprises an obtaining module which is used for obtaining a risk behavior in a financial interaction event, and a plurality of interaction objects and a plurality of interaction behavior signals corresponding to the risk behavior; the construction module is used for constructing a risk data chain based on the plurality of interaction objects and the plurality of interaction behavior signals; the first determination module is used for determining risk information of each risk node in the risk data chain; the judgment module is used for judging whether financial fraud behaviors exist or not according to the risk information of each risk node; and the tracking and early warning module is used for carrying out intelligent tracking and early warning on the financial fraudulent behavior according to the risk data chain when the financial fraudulent behavior is determined to exist. The risk information of the risk node is locally determined based on the risk data link, whether financial fraud behaviors exist or not is judged from the whole risk data link, and accurate tracking and early warning are achieved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of tracking and early warning technology, and in particular to an intelligent tracking and early warning system for financial fraud. Background Art

[0002] With the development and widespread adoption of financial technology, online transactions are becoming increasingly frequent, bringing with them risky and fraudulent behavior. Traditional risk control and anti-fraud methods typically rely on holistic perception, which can detect and prevent risky and fraudulent behavior to a certain extent. However, they struggle to process large-scale, high-dimensional, and complex financial interaction event data, resulting in a need for improved accuracy and efficiency.

[0003] When conducting overall perception, rules need to be set manually, and their accuracy is limited by the experience and knowledge of experts, and they cannot adapt to the rapid evolution of risky and fraudulent behaviors; it is impossible to determine the risk information of risk nodes locally based on the risk data chain, and then judge whether there is financial fraud from the overall risk data chain. At the same time, it is also impossible to achieve accurate tracking and early warning. Summary of the Invention

[0004] The present invention aims to at least partially address one of the technical problems encountered in the aforementioned technologies. To this end, the present invention provides an intelligent tracking and early warning system for financial fraud. This system uses a risk data chain to locally determine risk information for risk nodes, and then uses the entire risk data chain to determine whether financial fraud has occurred, thereby enabling accurate tracking and early warning.

[0005] To achieve the above objectives, the present invention provides an intelligent tracking and early warning system for financial fraud, including:

[0006] An acquisition module, configured to acquire risk behaviors in financial interaction events, as well as multiple interaction objects and multiple interaction behavior signals corresponding to the risk behaviors;

[0007] A construction module for constructing a risk data chain based on multiple interaction objects and multiple interaction behavior signals;

[0008] A first determination module is used to determine the risk information of each risk node in the risk data chain;

[0009] The judgment module is used to judge whether there is financial fraud based on the risk information of each risk node;

[0010] The tracking and early warning module is used to intelligently track and warn financial fraud behaviors based on the risk data chain when financial fraud behaviors are determined to exist.

[0011] According to some embodiments of the present invention, the risky behaviors include identity fraud, fraudulent transactions, fund theft, and forged credentials;

[0012] The multiple interaction objects corresponding to the risky behavior include user accounts, payment systems, third-party payment platforms, merchant terminals, and fund custodian institutions;

[0013] The multiple interactive behavior signals include:

[0014] Abnormal account behavior, including remote logins, sudden changes in device fingerprints, and trial-and-error transactions;

[0015] Abnormal transaction patterns, including transfers during non-business hours and payment recipients that deviate from historical transaction habits;

[0016] Signs of data tampering, including detection of photoshopped ID card photos and biometric verification failures.

[0017] According to some embodiments of the present invention, a building block comprises:

[0018] Establish a module to mark each interactive object as a risk node, collect multi-source data of each risk node in real time based on the signal capture layer, and establish a behavioral baseline;

[0019] A modeling module is used to model multiple interactive behavior signals based on the signal modeling layer and determine static and dynamic features;

[0020] The analysis module is used to input behavioral baselines, static features, and dynamic features into the relationship compilation layer, restore the risk transmission path through graph calculation and association analysis, and build a risk data chain based on the risk transmission path.

[0021] According to some embodiments of the present invention, establishing a module includes:

[0022] A first acquisition module is configured to collect transaction data of each risk node based on the transaction system included in the signal capture layer; the transaction data includes order flow, capital flow, and position data;

[0023] A second collection module is used to collect log data of each risk node based on the log system included in the signal capture layer; the log data includes API call logs, device fingerprints, and network traffic;

[0024] The third acquisition module is used to collect external data of each risk node based on the external evaluation system included in the signal capture layer; the external data includes blacklist and rating data;

[0025] The processing module is used to standardize the transaction data, log data and external data to establish a behavioral baseline; the standardization processing includes unified timestamp, ID mapping and feature normalization.

[0026] According to some embodiments of the present invention, the modeling module includes:

[0027] A second determination module is used to determine static features based on a rule engine and statistical modeling;

[0028] The third determination module is used to determine dynamic features based on time series feature modeling and graph computing feature modeling.

[0029] According to some embodiments of the present invention, the analysis module includes:

[0030] The fourth determination module is used to input the behavioral baseline, static features, and dynamic features into the relationship compilation layer, and determine risk nodes and edge weights through graph calculation and association analysis; the risk nodes include accounts, devices, IP addresses, merchants, and algorithm strategies; the edge weights include transaction amounts, co-occurrence times, time intervals, and similarity scores;

[0031] The scenario analysis module is used to restore the risk transmission path based on risk nodes and edge weights, perform scenario analysis and processing in the risk transmission path, and build a risk data chain based on the analysis and processing results; the scenario analysis and processing includes capital closed-loop identification, algorithm strategy similarity and propagation path.

[0032] According to some embodiments of the present invention, the first determining module includes:

[0033] The first generation module is used to generate a historical profile based on the historical behavior data of each risk node in the risk data chain;

[0034] The second generation module is used to generate a current profile based on the current behavior data of each risk node in the risk data chain;

[0035] The comparison module is used to compare the historical profile with the current profile and determine the risk information based on the comparison results.

[0036] According to some embodiments of the present invention, the comparison module is configured to calculate a degree of match between the historical portrait and the current portrait;

[0037] The matching degree is compared with a preset matching degree threshold. When it is determined that the matching degree is greater than the preset matching degree threshold, it indicates that there is no risk information for the current risk node; otherwise, it indicates that there is risk information for the current risk node.

[0038] According to some embodiments of the present invention, the judgment module is used to count a first number of risk nodes with risk information and a second number of risk nodes, calculate the ratio of the first number to the second number, and when it is determined that the ratio is greater than a preset ratio, it indicates that financial fraud has occurred.

[0039] According to some embodiments of the present invention, the tracking and warning module includes:

[0040] The fifth determination module is used to determine the fraud scenario and the fraud sequence information in the fraud scenario based on the risk data chain when determining that financial fraud exists; the fraud sequence information includes the fraud sub-chain, fraud node, and fraud method;

[0041] a splicing module, configured to obtain multiple sets of fraud data based on the fraud sequence information; map the multiple sets of fraud data into multiple mapping spaces, with each set of fraud data corresponding to one mapping space; generate views in the mapping space based on window parameters, and splice the generated views into a fraud sequence diagram and display the result;

[0042] The sixth determination module is used to count the number of frauds suffered by each fraud node according to the fraud sequence diagram; determine the warning level of each fraud node according to the number of frauds, and intelligently track and warn financial fraud behaviors according to the warning level.

[0043] The present invention proposes an intelligent tracking and early warning system for financial fraud, which determines the risk information of risk nodes locally based on the risk data chain, and then judges whether there is financial fraud from the overall risk data chain, thereby achieving accurate tracking and early warning.

[0044] Other features and advantages of the present invention will be described in the following description, and in part will become apparent from the description, or will be understood by practicing the present invention. The purpose and other advantages of the present invention can be realized and obtained by the structures particularly pointed out in the written description and the accompanying drawings.

[0045] The technical solution of the present invention is further described in detail below through the accompanying drawings and embodiments. BRIEF DESCRIPTION OF THE DRAWINGS

[0046] The accompanying drawings are used to provide a further understanding of the present invention and constitute a part of the specification. Together with the embodiments of the present invention, they are used to explain the present invention and do not constitute a limitation of the present invention. In the accompanying drawings:

[0047] Figure 1 is a block diagram of an intelligent tracking and early warning system for financial fraud according to one embodiment of the present invention;

[0048] Figure 2 is a block diagram of building blocks according to one embodiment of the present invention;

[0049] Figure 3 is a block diagram of a setup module according to one embodiment of the present invention. DETAILED DESCRIPTION

[0050] The preferred embodiments of the present invention are described below with reference to the accompanying drawings. It should be understood that the preferred embodiments described herein are only used to illustrate and explain the present invention, and are not used to limit the present invention.

[0051] like Figure 1 As shown, the embodiment of the present invention provides an intelligent tracking and early warning system for financial fraud, including:

[0052] An acquisition module, configured to acquire risk behaviors in financial interaction events, as well as multiple interaction objects and multiple interaction behavior signals corresponding to the risk behaviors;

[0053] A construction module for constructing a risk data chain based on multiple interaction objects and multiple interaction behavior signals;

[0054] A first determination module is used to determine the risk information of each risk node in the risk data chain;

[0055] The judgment module is used to judge whether there is financial fraud based on the risk information of each risk node;

[0056] The tracking and early warning module is used to intelligently track and warn financial fraud behaviors based on the risk data chain when financial fraud behaviors are determined to exist.

[0057] The working principle of the above technical solution is as follows: Transaction flows and log records are accessed through Kafka or Flink. Historical risk cases are loaded from databases (such as MySQL and HBase). Risk signals are extracted based on machine learning models. A construction module is used to build a risk data chain based on multiple interactive objects and multiple interactive behavior signals. The risk data chain includes a time series chain: risk events are sorted by timestamp to form an event sequence. A relationship chain: a graph structure is constructed based on account / device associations. The first determination module is used to determine the risk information of each risk node in the risk data chain by comparing the historical data of the risk node with the current data. The judgment module is used to determine whether financial fraud exists based on the risk information of each risk node, thereby realizing the judgment of financial fraud from the local to the overall level. The tracking and warning module is used to intelligently track and warn financial fraud behavior based on the risk data chain when financial fraud is determined to exist. Intelligent tracking and warning of financial fraud behavior are performed based on the amount of risk data, improving the accuracy of tracking and warning.

[0058] The beneficial effects of the above technical solution are: based on the risk data chain, the risk information of the risk node is determined locally, and then the existence of financial fraud is judged from the overall risk data chain, so as to achieve accurate tracking and early warning.

[0059] According to some embodiments of the present invention, the risky behaviors include identity fraud, fraudulent transactions, fund theft, and forged credentials;

[0060] The multiple interaction objects corresponding to the risky behavior include user accounts, payment systems, third-party payment platforms, merchant terminals, and fund custodian institutions;

[0061] The multiple interactive behavior signals include:

[0062] Abnormal account behavior, including remote logins, sudden changes in device fingerprints, and trial-and-error transactions;

[0063] Abnormal transaction patterns, including transfers during non-business hours and payment recipients that deviate from historical transaction habits;

[0064] Signs of data tampering, including detection of photoshopped ID card photos and biometric verification failures.

[0065] like Figure 2 As shown, according to some embodiments of the present invention, the building module includes:

[0066] Establish a module to mark each interactive object as a risk node, collect multi-source data of each risk node in real time based on the signal capture layer, and establish a behavioral baseline;

[0067] A modeling module is used to model multiple interactive behavior signals based on the signal modeling layer and determine static and dynamic features;

[0068] The analysis module is used to input behavioral baselines, static features, and dynamic features into the relationship compilation layer, restore the risk transmission path through graph calculation and association analysis, and build a risk data chain based on the risk transmission path.

[0069] The working principle of the above technical solution is as follows: Each interactive object is labeled as a risk node. The signal capture layer collects multi-source data for each risk node in real time, performs time series analysis, and calculates the mean and variance of historical data (such as the average daily transaction amount of an account) to obtain the first behavioral baseline. Cluster analysis is also performed to cluster similar nodes (such as devices in the same region) to generate a group behavioral baseline, which serves as the second behavioral baseline. The behavioral baseline is determined based on the first and second behavioral baselines. The modeling module is used to model multiple interactive behavioral signals based on the signal modeling layer, determining static and dynamic characteristics. The analysis module outputs the risk transmission path (such as the flow of funds from A to B to C) and the complete risk data chain. Graph computing and association analysis include graph construction: storing nodes (accounts, devices) and edges (transactions, login relationships) in a graph database (such as Neo4j). Path discovery: Using the shortest path algorithm (Dijkstra) or community detection (Louvain) to restore the risk transmission path.

[0070] The beneficial effects of the above technical solution are: by establishing risk node marking in the module, feature engineering in the modeling module, and graph calculation in the analysis module, the complete fraud path can be restored from fragmented signals, new fraud patterns can be adapted in real time, and the accuracy of correlation analysis can be improved, thereby improving the accuracy of financial fraud behavior tracking and early warning.

[0071] like Figure 3 As shown, according to some embodiments of the present invention, a module is established, including:

[0072] A first acquisition module is configured to collect transaction data of each risk node based on the transaction system included in the signal capture layer; the transaction data includes order flow, capital flow, and position data;

[0073] A second collection module is used to collect log data of each risk node based on the log system included in the signal capture layer; the log data includes API call logs, device fingerprints, and network traffic;

[0074] A third collection module is used to collect external data of each risk node based on the external evaluation system included in the signal capture layer; the external data includes blacklists and rating data;

[0075] The processing module is used to standardize the transaction data, log data and external data to establish a behavioral baseline; the standardization processing includes unified timestamp, ID mapping and feature normalization.

[0076] The above technical solution works as follows: Unified timestamps: Convert all data timestamps to the UTC time zone. ID mapping: Create a unified mapping table for account IDs and device IDs. Feature normalization: Perform min-max normalization on features such as amount and frequency.

[0077] The beneficial effects of the above technical solution are: through multi-source data collection and standardized processing, a module is established to eliminate the heterogeneity of transactions, logs, and external data, dynamically update the baseline, reflect the normal behavior patterns of risk nodes in real time, and provide high-quality input for the construction of the risk data chain.

[0078] According to some embodiments of the present invention, the modeling module includes:

[0079] A second determination module is used to determine static features based on a rule engine and statistical modeling;

[0080] The third determination module is used to determine dynamic features based on time series feature modeling and graph computing feature modeling.

[0081] The working principle of the above technical solution: The static features include account attribute features, device fingerprint features, merchant / institution features, and algorithm strategy features. Account attribute features are inherent attributes determined during account registration, such as registration duration, ID type, number of bound devices, and number of associated accounts. Device fingerprint features are hash values ​​of device hardware and configuration information, such as device model, operating system version, sensor list, and IP location. Merchant / institution features are compliance attributes of merchants or financial institutions, such as industry classification, historical complaint rate, rating level, and regulatory penalty record. Algorithm strategy features are inherent parameters of quantitative strategies or AI models, such as factor exposure, position concentration, drawdown threshold, and upper trading frequency limit. Static features are determined based on a rules engine. For example, if the number of associated devices is greater than 5 and the registration duration is less than 30 days, the account is marked as high risk. Static features are determined based on statistical modeling, such as using quantile statistics or boxplots to identify outliers. Dynamic features include time-series trading features, network behavior features, correlation features, and algorithm operation features. Time series transaction features: The time series of an account or device's transaction behavior. Examples include transaction frequency, amount distribution, transaction time window, and counterparty concentration. Network behavior features: The network activity patterns of a device or system. Examples include API call frequency, traffic anomalies, protocol distribution, and DDoS attack characteristics. Correlation features: The real-time impact of external information on an account or institution. Examples include popularity, keyword sentiment, propagation speed, and information source credibility. Algorithm operation features: The real-time execution status of a quantitative strategy or AI model. Examples include strategy drawdown, parameter drift, factor expiration, and execution delay. Time series feature modeling includes: Sliding window statistics: Calculating the median transaction amount of an account over the past seven days and comparing it with the current transaction amount. LSTM network prediction: Taking a historical transaction amount sequence as input, predicting the next transaction amount. Graph computing feature modeling: Identifying closed-capital loops: Constructing a directed graph of account-transaction-account relationships and using a shortest path algorithm (such as Dijkstra's algorithm) to identify closed-capital loops. Mining associated account groups: Using the Louvain algorithm to partition accounts into communities and identify high-density association groups.

[0082] The beneficial effects of the above technical solution are: modeling multiple interactive behavior signals based on the signal modeling layer, and accurately determining static features and dynamic features.

[0083] According to some embodiments of the present invention, the analysis module includes:

[0084] The fourth determination module is used to input the behavioral baseline, static features, and dynamic features into the relationship compilation layer, and determine risk nodes and edge weights through graph calculation and association analysis; the risk nodes include accounts, devices, IP addresses, merchants, and algorithm strategies; the edge weights include transaction amounts, co-occurrence times, time intervals, and similarity scores;

[0085] The scenario analysis module is used to restore the risk transmission path based on risk nodes and edge weights, perform scenario analysis and processing in the risk transmission path, and build a risk data chain based on the analysis and processing results; the scenario analysis and processing includes capital closed-loop identification, algorithm strategy similarity and propagation path.

[0086] The working principle of the above technical solution: Accounts, devices, IP addresses and other entities are regarded as nodes in the graph. Transaction amount: The amount in the transaction flow is directly used as the weight. Co-occurrence count: Counts the number of times two nodes co-occur within a time window. Time interval: Calculates the time difference between interactions between nodes and normalizes it into a weight. Similarity score: Uses cosine similarity or Jaccard similarity to calculate the similarity of node features. Risk transmission path restoration includes: Shortest path algorithm: Uses Dijkstra or A* algorithm to find high-weight paths. Community detection: Uses Louvain or Label Propagation algorithm to discover closely related node communities. Scenario analysis processing includes closed-loop identification of funds: Detects the circular flow of funds between multiple accounts. Algorithm strategy similarity: Identifies groups of accounts that use similar trading strategies. Propagation path: Combines external data to analyze the propagation path of negative information.

[0087] The beneficial effects of the above technical solution are as follows: The fourth determination module determines risk nodes and edge weights. The scenario analysis module restores the risk transmission path and constructs a risk data chain, identifying high-risk transmission paths from complex interactions, and updating node weights and path scores in real time, providing a structured data chain for risk warning and disposal.

[0088] According to some embodiments of the present invention, the first determining module includes:

[0089] The first generation module is used to generate a historical profile based on the historical behavior data of each risk node in the risk data chain;

[0090] The second generation module is used to generate a current profile based on the current behavior data of each risk node in the risk data chain;

[0091] The comparison module is used to compare the historical profile with the current profile and determine the risk information based on the comparison results.

[0092] The working principle of the above technical solution: the first generation module is used to generate a historical portrait based on the historical behavior data of each risk node in the risk data chain; the second generation module is used to generate a current portrait based on the current behavior data of each risk node in the risk data chain; the comparison module is used to compare the historical portrait with the current portrait and determine the risk information based on the comparison result. The historical portrait is generated based on the historical behavior data of each risk node in the risk data chain, including: performing data analysis on the historical behavior data, determining the scene data and content data, dividing the scene data based on the preset scene categories, and determining a number of scene nodes; obtaining the node hierarchy of each scene node, and determining the connection relationship between each scene node according to the node hierarchy; filling the content data into the corresponding scene node, and constructing a scene tree according to the connection relationship; performing feature extraction on the content data in each scene node in the scene tree, and determining the risk node labels under different scenarios; and constructing a historical portrait based on the risk node labels under different scenarios. The method for constructing the current portrait is consistent with the method for constructing the historical portrait.

[0093] The beneficial effect of the above technical solution is that it facilitates accurate determination of risk information.

[0094] According to some embodiments of the present invention, the comparison module is configured to calculate a degree of match between the historical portrait and the current portrait;

[0095]

[0096] Among them, X i is the weight of historical portrait X; Y i is the component of the current portrait Y; n is the number of components of the feature vector of the generated portrait; P1 is the first user label determined based on the historical portrait; P2 is the second user label determined based on the current portrait; C is the type coefficient of the current behavior;

[0097] The matching degree is compared with a preset matching degree threshold. When it is determined that the matching degree is greater than the preset matching degree threshold, it indicates that there is no risk information for the current risk node; otherwise, it indicates that there is risk information for the current risk node.

[0098] The working principle of the above technical solution is: the first user tag and the second user tag are not exactly the same, so |P1-P2| is not 0. is a label discrepancy penalty term used to mitigate the impact of label discrepancies. The components of the feature vector include the user's operation behavior and operation duration. The first user label, determined based on the historical profile, represents the user's historical operation habits. The second user label represents the user's current operation habits.

[0099] The beneficial effects of the above technical solution are as follows: the matching degree is compared with a preset matching degree threshold. If the matching degree is greater than the preset matching degree threshold, it indicates that the current risk node does not have risk information; otherwise, it indicates that the current risk node has risk information. The difference in the image is converted into an interpretable numerical value. The label difference penalty term and threshold are adapted to different scenarios to facilitate accurate determination of the risk information of each risk node.

[0100] According to some embodiments of the present invention, the judgment module is used to count a first number of risk nodes with risk information and a second number of risk nodes, calculate the ratio of the first number to the second number, and when it is determined that the ratio is greater than a preset ratio, it indicates that financial fraud has occurred.

[0101] The working principle and beneficial effects of the above technical solution: Through risk ratio calculation, the judgment module can quantify the risk concentration, intuitively reflect the degree of aggregation of risk nodes, and accurately determine whether there is financial fraud.

[0102] According to some embodiments of the present invention, the tracking and warning module includes:

[0103] The fifth determination module is used to determine the fraud scenario and the fraud sequence information in the fraud scenario based on the risk data chain when determining that financial fraud exists; the fraud sequence information includes the fraud sub-chain, fraud node, and fraud method;

[0104] a splicing module, configured to obtain multiple sets of fraud data based on the fraud sequence information; map the multiple sets of fraud data into multiple mapping spaces, with each set of fraud data corresponding to one mapping space; generate views in the mapping space based on window parameters, and splice the generated views into a fraud sequence diagram and display the result;

[0105] The sixth determination module is used to count the number of frauds suffered by each fraud node according to the fraud sequence diagram; determine the warning level of each fraud node according to the number of frauds, and intelligently track and warn financial fraud behaviors according to the warning level.

[0106] The above technical solution works by using association rule mining (such as the Apriori algorithm) to identify frequent fraud patterns. Time series analysis or graph traversal algorithms (such as Determined File System (DFS) / Boundary File System (BFS)) are used to extract fraud subchains and fraud nodes. Fraud data is mapped to different spaces (such as time space and amount space). Multi-view charts are generated using Matplotlib or Plotly. Subplots are used to create a complete fraud sequence chart. The number of times each node appears in historical fraud is counted. Quantiles or clustering algorithms (such as K-Means) are used to classify the fraud data.

[0107] The beneficial effects of the above technical solution are as follows: through fraud scenario extraction, sequence diagram generation and warning level classification, the tracking and warning module can accurately locate the fraud path, intuitively display the fraud sub-chain and nodes, and dynamically warn: adjust the risk level in real time according to the number of frauds, and accurately realize intelligent tracking and warning of financial fraud behaviors.

[0108] Obviously, those skilled in the art may make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if such changes and modifications fall within the scope of the claims and their equivalents, the present invention is intended to include such changes and modifications.

Claims

1. An intelligent tracking and early warning system for financial fraud, characterized in that: include: An acquisition module, configured to acquire risk behaviors in financial interaction events, as well as multiple interaction objects and multiple interaction behavior signals corresponding to the risk behaviors; A construction module for constructing a risk data chain based on multiple interaction objects and multiple interaction behavior signals; A first determination module is used to determine the risk information of each risk node in the risk data chain; The judgment module is used to judge whether there is financial fraud based on the risk information of each risk node; The tracking and early warning module is used to intelligently track and warn financial fraud behaviors based on the risk data chain when financial fraud behaviors are determined to exist.

2. The intelligent tracking and early warning system for financial fraud according to claim 1, characterized in that: The risky behaviors include identity fraud, fraudulent transactions, fund theft, and forged credentials; The multiple interaction objects corresponding to the risky behavior include user accounts, payment systems, third-party payment platforms, merchant terminals, and fund custodian institutions; The multiple interactive behavior signals include: Abnormal account behavior, including remote logins, sudden changes in device fingerprints, and trial-and-error transactions; Abnormal transaction patterns, including transfers during non-business hours and payment recipients that deviate from historical transaction habits; Signs of data tampering, including detection of photoshopped ID card photos and biometric verification failures.

3. The intelligent tracking and early warning system for financial fraud according to claim 1, characterized in that: Building blocks, including: Establish a module to mark each interactive object as a risk node, collect multi-source data of each risk node in real time based on the signal capture layer, and establish a behavioral baseline; A modeling module is used to model multiple interactive behavior signals based on the signal modeling layer and determine static and dynamic features; The analysis module is used to input behavioral baselines, static features, and dynamic features into the relationship compilation layer, restore the risk transmission path through graph calculation and association analysis, and build a risk data chain based on the risk transmission path.

4. The intelligent tracking and early warning system for financial fraud according to claim 3, characterized in that: Build modules, including: A first acquisition module is configured to collect transaction data of each risk node based on the transaction system included in the signal capture layer; the transaction data includes order flow, capital flow, and position data; A second collection module is used to collect log data of each risk node based on the log system included in the signal capture layer; the log data includes API call logs, device fingerprints, and network traffic; A third collection module is used to collect external data of each risk node based on the external evaluation system included in the signal capture layer; the external data includes blacklists and rating data; The processing module is used to standardize the transaction data, log data and external data to establish a behavioral baseline; the standardization processing includes unified timestamp, ID mapping and feature normalization.

5. The intelligent tracking and early warning system for financial fraud according to claim 3, characterized in that: Modeling modules, including: A second determination module is used to determine static features based on a rule engine and statistical modeling; The third determination module is used to determine dynamic features based on time series feature modeling and graph computing feature modeling.

6. The intelligent tracking and early warning system for financial fraud according to claim 3, characterized in that: Analysis modules, including: The fourth determination module is used to input the behavioral baseline, static features, and dynamic features into the relationship compilation layer, and determine risk nodes and edge weights through graph calculation and association analysis; the risk nodes include accounts, devices, IP addresses, merchants, and algorithm strategies; the edge weights include transaction amounts, co-occurrence times, time intervals, and similarity scores; The scenario analysis module is used to restore the risk transmission path based on risk nodes and edge weights, perform scenario analysis and processing in the risk transmission path, and build a risk data chain based on the analysis and processing results; the scenario analysis and processing includes capital closed-loop identification, algorithm strategy similarity and propagation path.

7. The intelligent tracking and early warning system for financial fraud according to claim 1, characterized in that: The first determination module includes: The first generation module is used to generate a historical profile based on the historical behavior data of each risk node in the risk data chain; The second generation module is used to generate a current profile based on the current behavior data of each risk node in the risk data chain; The comparison module is used to compare the historical profile with the current profile and determine the risk information based on the comparison results.

8. The intelligent tracking and early warning system for financial fraud according to claim 7, characterized in that: Comparison module, used to calculate the matching degree between historical portraits and current portraits; The matching degree is compared with a preset matching degree threshold. When it is determined that the matching degree is greater than the preset matching degree threshold, it indicates that there is no risk information for the current risk node; otherwise, it indicates that there is risk information for the current risk node.

9. The intelligent tracking and early warning system for financial fraud according to claim 8, characterized in that: The judgment module is used to count a first number of risk nodes with risk information and a second number of risk nodes, calculate a ratio of the first number to the second number, and when it is determined that the ratio is greater than a preset ratio, it indicates that financial fraud exists.

10. The intelligent tracking and early warning system for financial fraud according to claim 1, characterized in that: Tracking and early warning module, including: The fifth determination module is used to determine the fraud scenario and the fraud sequence information in the fraud scenario based on the risk data chain when determining that financial fraud exists; the fraud sequence information includes the fraud sub-chain, fraud node, and fraud method; a splicing module, configured to obtain multiple sets of fraud data based on the fraud sequence information; map the multiple sets of fraud data into multiple mapping spaces, with each set of fraud data corresponding to one mapping space; generate views in the mapping space based on window parameters, and splice the generated views into a fraud sequence diagram and display the result; The sixth determination module is used to count the number of frauds suffered by each fraud node according to the fraud sequence diagram; determine the warning level of each fraud node according to the number of frauds, and intelligently track and warn financial fraud behaviors according to the warning level.

Citation Information

Patent Citations

  • Fraudulent behavior tracking method based on security intelligence and device thereof and related equipment

    CN113988886A

  • Abnormal account detection method and device based on user portrait, equipment and medium

    CN114020578A

  • Suspicious customer identification and submission method and system based on multivariate data

    CN119741109A

  • Intelligent risk control system based on block chain

    CN120070021A

  • Fraud detection in heterogeneous information networks

    US10460320B1

Cited By

  • Financial business risk control management system based on big data model

    CN121724736A

  • A financial business risk control management system based on big data models

    CN121724736B

  • Financial fraud detection system based on multi-modal data fusion

    CN121788249A

  • Supply chain financial fraud behavior identification method and system for multi-source data

    CN121836900A

  • Artificial intelligence-based front-end burying point recommendation method and system

    CN122153169A