Intelligent data processing system for intelligent evidence collection
Through the distributed edge probe group, dynamic fraud strategy engine, intelligent evidence chain building module and trusted evidence storage interface, the shortcomings of the intelligent forensics system in terms of adaptability, data processing efficiency, architectural flexibility and privacy compliance are solved, and real-time response, cross-platform evidence flow and trusted evidence storage are achieved, thereby improving the efficiency and reliability of financial anti-fraud evidence collection.
Patent Information
- Application Number
- CN202511211362.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-28
- Publication Date
- 2025-09-30
- Estimated Expiration
- 2045-08-28
AI Technical Summary
When faced with complex digital crime environments, existing intelligent forensics systems lack adaptability, have low data processing efficiency, large architectural limitations, insufficient intelligent analysis capabilities, high privacy compliance risks, difficulty in being compatible with heterogeneous data sources, and have difficulty achieving real-time response and cross-system evidence flow.
It adopts a distributed edge probe group, a dynamic fraud strategy engine, an intelligent evidence chain building module and a trusted evidence storage interface, and achieves real-time response, cross-platform data processing and trusted evidence storage through edge intelligent collaboration and dynamic adversarial learning.
It achieves millisecond-level response capabilities for distributed systems, improves the detection sensitivity of unknown fraud patterns, enhances the judicial authorities' confidence in evidence, ensures privacy compliance, and forms a technical closed loop of edge real-time response - dynamic policy optimization - full-link evidence solidification.
Smart Images

Figure CN120725697A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of data processing, and in particular relates to an intelligent data processing system for intelligent evidence collection. Background Art
[0002] Currently, intelligent data processing systems for intelligent forensics face multiple technical bottlenecks in coping with the increasingly complex digital crime environment. Their core flaws are mainly reflected in the following aspects: A significant weakness of the current system is its lack of adaptability. Traditional forensic tools are mostly designed for specific intrusion behaviors or static network environments, and lack the ability to dynamically respond to new criminal methods (such as the use of encrypted communications or niche applications). When criminals use variant attack techniques, the system is unable to adjust its forensic strategy or autonomously generate new detection modules in real time, resulting in the omission of key evidence. At the same time, inefficient data processing causes serious performance bottlenecks. Faced with exponentially growing amounts of data (including structured and unstructured data), traditional centralized architectures rely on a single central analysis node, causing network congestion and processing delays. For example, massive amounts of audit data need to be transmitted back to the central server for analysis, which makes it difficult to achieve real-time response in a high-speed network environment. In addition, system resources cannot be dynamically scaled according to the scale of the attack, making it prone to crashes under high load and wasting resources under low load.
[0003] Limitations in system architecture further hinder the reliability of forensics. Existing tools often employ rigid designs, making them incompatible with heterogeneous data sources (such as IoT devices, cloud services, and encrypted communications). For example, the rapid iteration of niche apps or the new Hongmeng system results in lengthy adaptation cycles for forensic tools, while anti-forensic techniques (such as data erasure and hiding) make evidence integrity vulnerable. Furthermore, the lack of technical standardization exacerbates compatibility issues. Forensic tools from different vendors lack unified data interfaces and protocols, making the transfer of evidence across systems difficult.
[0004] The shortcomings of intelligent analysis capabilities are equally prominent. Traditional technologies such as OCR can only recognize text in images and are unable to parse the contextual associations of data such as chat logs (such as the relationship between nicknames and content), resulting in fragmented clues. Although AI technology has been applied to automated forensics (such as automatic page turning and screenshots), its underlying models lack the depth to parse encrypted data and dynamic content (such as real-time chat streams), and the black-box nature of the algorithm raises questions about the interpretability of the results. Finally, privacy and compliance risks persist. Large-scale data collection may unauthorized access to sensitive user information (such as medical records), and lagging laws and regulations have resulted in a lack of a clear privacy protection framework in the forensics process, which is prone to ethical disputes.
[0005] In summary, the shortcomings of the existing system in terms of dynamic response, data processing efficiency, architectural flexibility, standardization and compliance urgently need to be overcome through distributed intelligent architecture, adaptive algorithms and cross-domain compliance frameworks. Summary of the Invention
[0006] The present invention proposes an intelligent data processing system for intelligent forensics. This system solves five core problems in financial anti-fraud forensics: delayed real-time response, difficulty in penetrating multi-layer money laundering, missed detection of new fraud patterns, lack of analysis of encrypted transaction intent, and insufficient compliance of judicial evidence storage. Through edge intelligent collaboration and dynamic adversarial learning, it realizes full-chain trusted forensics in complex transaction environments.
[0007] The technical solution of the present invention is implemented as follows: an intelligent data processing system for intelligent evidence collection includes a distributed edge probe group, a dynamic fraud strategy engine, an intelligent evidence chain construction module and a trusted evidence storage interface; The distributed edge probe group is deployed in the core transaction system, with a built-in lightweight protocol parser. It adapts the SWIFT / UnionPay private protocol and real-time desensitization module within the parser, and performs transaction account masking and behavior track hashing at the data source end. The dynamic fraud strategy engine accesses the abnormal transaction flow of the edge probe group and stores cross-institutional transaction pattern vectors through the graph neural network fraud feature library. The real-time threat assessment unit detects the probability of abnormal transaction timing based on the hidden Markov model. The adaptive forensics controller dynamically activates targeted forensics instructions based on the threat value, capturing cross-platform fund flows with high priority and extending the suspicious session evidence storage period. The intelligent evidence chain construction module includes a multi-level fund flow tracking unit and an explainable AI parser. The multi-level fund flow tracking unit penetrates the mapping between virtual accounts and actual controllers through the entity association graph; the explainable AI parser uses attention weight visualization technology to restore the semantics of encrypted transaction instructions and generate a decision heat map. The trusted evidence storage interface stores evidence chains in shards based on an improved Merkle tree. Each shard integrates the digital signature of the edge device and a financial-grade timestamp, and outputs an audit report that meets the requirements. Among them, when the dynamic fraud strategy engine identifies unregistered transaction patterns, it activates the adversarial sample generation mechanism: it uses the generative adversarial network to synthesize new fraud transaction features, updates the graph neural network weights, and isolates the original data into the financial regulatory sandbox.
[0008] Existing financial anti-fraud systems face multiple technical bottlenecks: First, heterogeneous terminal evidence collection is fragmented, and ATM, APP and core system data are processed independently, resulting in a breakdown in the correlation between cross-platform money laundering behaviors (such as nested jumps among multiple accounts). Traditional centralized architectures lose key transaction timing evidence due to data transmission delays; second, the static rule base is rigid, and the detection mechanism based on predefined fraud features (such as fixed threshold triggers) cannot identify unregistered transaction patterns (such as new cross-border cash-outs), and the manual update cycle of the feature base is as long as several weeks; third, virtual account penetration fails, and tracking technology that relies on the surface of account transactions has difficulty mapping the actual controller, especially in encrypted communication scenarios, and cannot parse the intention of fund transfer; fourth, the judicial effectiveness of the chain of evidence is insufficient. Blockchain evidence storage leads to a surge in storage load due to redundant data, and lacks authoritative timestamps and standardized packaging. Judicial institutions have doubts about the integrity of electronic evidence; fifth, privacy compliance risks are out of control, and the original data transmitted back to the central node may unauthorizedly obtain sensitive user information.
[0009] This solution specifically addresses the following technical difficulties: Real-time edge collaboration: By deploying lightweight probes in different domains (dual-mode sniffers on the ATM side, TEE interceptors on the APP side, and core system protocol reverse adapters), desensitization and hashing are completed at the source of the data, eliminating return delays. Difficulties in dynamic strategy generation: Based on the dual-threshold trigger mechanism of the hidden Markov model and the fusion of heterogeneous graph features, the threat level is quantified in real time and resources are dynamically allocated to resolve the contradiction between resource utilization and detection sensitivity of traditional systems; Difficulties in fund penetration technology: Using depth-first search (DFS) enhanced time-series penetration analysis, integrating unstructured data to build a three-dimensional "account-beneficiary-device" map, breaking through the virtual identity concealment barrier; Difficulties in intention interpretability: The hierarchical attention mechanism generates word-level heat maps and behavioral decision trees, restoring encrypted instructions into "subjective malice" evidence that can be understood by the judiciary; Difficulties in judicial adaptation of evidence storage: The dual-chain anchoring structure (alliance chain + judicial chain) and quantum key sharding authorization balance the data immutability and privacy protection requirements.
[0010] As a preferred embodiment, the distributed edge probe group adopts a domain-divided deployment architecture, in which the probe deployed at the ATM terminal integrates a magnetic stripe / chip dual-mode sniffer to capture the physical transaction terminal operation instruction flow in real time; the mobile APP probe is embedded in a trusted execution environment to intercept encrypted communication data through system call hijacking technology; the core transaction system probe loads a private protocol reverse adapter to dynamically generate SWIFT / UnionPay private protocol parsing templates based on the protocol field entropy value; the real-time desensitization module executes a hierarchical data processing pipeline: a format-preserving encryption mask is used for the transaction account, SM3 hash solidification is applied to the behavior trajectory, and key shards protected by the hardware security module are injected.
[0011] As a preferred implementation, in the dynamic fraud strategy engine: the graph neural network fraud feature library adopts heterogeneous graph fusion technology to map transaction entity nodes and relationship edges into high-dimensional feature vectors; the real-time threat assessment unit constructs a dual-threshold trigger mechanism: when the hidden Markov model output abnormal probability exceeds the first threshold, basic forensics is activated, and when it exceeds the second threshold, cross-platform fund flow capture is triggered; the adaptive forensics controller configures a policy priority matrix and dynamically allocates computing resources to the suspicious session evidence link according to the threat value weight.
[0012] As a preferred implementation, the operation process of the intelligent evidence chain construction module is to implement time-series penetration analysis through a multi-level capital flow tracking unit: track the capital flow path based on an improved depth-first search algorithm, and integrate unstructured data sources to construct evidence related to the actual controller; the explainable AI parser deploys a hierarchical attention mechanism: generate a word-level attention weight heat map in the instruction semantic restoration layer, output an operation logic decision tree in the behavioral intention analysis layer, and eliminate model bias interference through adversarial training.
[0013] As a preferred implementation, the operation of the trusted evidence interface is through a dual-chain anchored evidence structure: the improved Merkle tree root hash is synchronously written into the financial alliance chain and the judicial evidence chain, and zero-knowledge proof technology is used to verify cross-chain consistency; dynamic evidence packaging engine: standardized evidence packages are generated as required, and the packages integrate timestamps certified by the National Time Service Center, probe device digital certificates and parser version traceability identifiers; sandbox data isolation mechanism: physical isolation storage is implemented for the original data of unregistered transaction models, and multiple biometric authentications and quantum key sharding decryption authorizations are required for access.
[0014] After adopting the above technical solution, the beneficial effects of the present invention are: in terms of forensic efficiency, the distributed edge probe group achieves millisecond-level response through near-source data processing, completely eliminating the data return delay of the traditional architecture, and ensuring the complete capture of key transaction behavior trajectories; the dynamic strategy engine intelligently allocates computing resources based on a dual-threshold trigger mechanism, significantly improving the detection sensitivity of unknown fraud patterns and overcoming the rigid defects of the static rule base.
[0015] At the system adaptation level, the adversarial sample generation mechanism realizes the real-time dynamic evolution of the fraud feature library, improving the compatibility of protocol iteration to the industry-leading level; the protocol reverse adapter drives the generation of parsing templates through entropy value, effectively responding to the rapid upgrade challenges of private communication protocols.
[0016] In terms of judicial evidence effectiveness, the dual-chain anchored evidence storage structure is combined with zero-knowledge proof technology to build an unalterable cross-chain consistency verification system; the dynamic evidence packaging engine integrates national-level timestamp authentication and device digital certificates to output standardized evidence packages, greatly enhancing the credibility of judicial institutions; the visual decision heat map generated by the hierarchical attention mechanism provides an explanatory basis for the restoration of encrypted transaction intentions that meets the requirements of judicial evidence.
[0017] Regarding privacy compliance, the hierarchical desensitization pipeline utilizes cryptographic enhancements to minimize data collection and strictly adhere to personal information protection principles. A sandbox isolation mechanism integrates quantum key sharding and biometric authentication to establish physical access control barriers, eliminating the risk of unauthorized evidence collection. This ultimately forms a closed technical loop encompassing real-time edge response, dynamic policy optimization, full-chain evidence consolidation, and privacy and security protection, fully meeting the high-standard forensics requirements of financial anti-fraud. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0019] Figure 1 This is a system block diagram of the present invention. DETAILED DESCRIPTION
[0020] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.
[0021] Example: like Figure 1 As shown, the intelligent data processing system for intelligent forensics includes a distributed edge probe group, a dynamic fraud strategy engine, an intelligent evidence chain building module, and a trusted evidence storage interface; The distributed edge probe group is deployed in the core transaction system, with a built-in lightweight protocol parser. It adapts the SWIFT / UnionPay private protocol and real-time desensitization module within the parser, and performs transaction account masking and behavior track hashing at the data source end. The dynamic fraud strategy engine accesses the abnormal transaction flow of the edge probe group and stores cross-institutional transaction pattern vectors through the graph neural network fraud feature library. The real-time threat assessment unit detects the probability of abnormal transaction timing based on the hidden Markov model. The adaptive forensics controller dynamically activates targeted forensics instructions based on the threat value, capturing cross-platform fund flows with high priority and extending the suspicious session evidence storage period. The intelligent evidence chain construction module includes a multi-level fund flow tracking unit and an explainable AI parser. The multi-level fund flow tracking unit penetrates the mapping between virtual accounts and actual controllers through the entity association graph; the explainable AI parser uses attention weight visualization technology to restore the semantics of encrypted transaction instructions and generate a decision heat map. The trusted evidence storage interface stores evidence chains in shards based on an improved Merkle tree. Each shard integrates the digital signature of the edge device and a financial-grade timestamp, and outputs an audit report that meets the requirements. Among them, when the dynamic fraud strategy engine identifies unregistered transaction patterns, it activates the adversarial sample generation mechanism: it uses the generative adversarial network to synthesize new fraud transaction features, updates the graph neural network weights, and isolates the original data into the financial regulatory sandbox.
[0022] The implementation of this system in the cross-border money laundering forensics scenario begins with the coordinated operation of a distributed edge probe group: probes deployed at bank ATM terminals capture physical operation instruction flows (such as abnormal multiple cash withdrawals) through magnetic stripe / chip dual-mode sniffers, mobile app probes hijack encrypted communication data (such as high-frequency small-amount transfer instructions) within the Trusted Execution Environment (TEE), and core transaction system probes activate private protocol reverse adapters, dynamically generate parsing templates based on the entropy value of SWIFT message fields, and strip redundant protocol headers in real time; all probes synchronously execute a hierarchical desensitizing pipeline—using format-preserving encryption (FPE) to mask account numbers, solidifying operation traces through the SM3 hash algorithm, and using hardware security modules (HSMs) to shard and manage keys to ensure that original sensitive data does not leave the domain. When the probe detects an abnormal transaction flow (such as inter-bank fund transfers from multiple accounts), it is immediately pushed to the dynamic fraud strategy engine: the graph neural network fraud feature library first loads the heterogeneous graph fusion technology, maps the transaction entities (accounts / IPs / devices) and relationship edges (transfer discreteness, time intensity) into high-dimensional vectors, and matches known money laundering patterns; the real-time threat assessment unit constructs a transaction state transition probability matrix based on the hidden Markov model to identify timing anomalies (such as large transfers at night that deviate from normal behavior patterns); if the anomaly probability exceeds the preset dual thresholds, the adaptive forensics controller immediately activates targeted instructions - executing basic session notarization for low-threat transactions, and initiating cross-platform fund flow capture and extending the notarization period for high-threat transactions.
[0023] Abnormal data then flows into the intelligent evidence chain construction module: the multi-level capital flow tracking unit implements depth-first search (DFS) enhanced time-series penetration analysis, and constructs a three-dimensional map of "account-actual controller-physical address" by parsing unstructured data such as the registration information of virtual accounts, device fingerprints and related customer service recordings, penetrating the hidden barriers of multi-layer nested accounts; the explainable AI parser operates synchronously: a hierarchical attention mechanism is deployed at the instruction semantic restoration layer to generate word-level weight heat maps to parse encrypted transaction instructions (such as the true intention of the " / " symbol in money laundering code), output an operation decision tree at the behavioral logic layer, and eliminate model bias interference through adversarial training, ultimately forming a "subjective malice" evidence chain that is understandable to the judiciary.
[0024] When the evidence chain is processed by the trusted evidence storage interface, it is first sharded and stored based on a modified Merkle tree. Each shard incorporates the ATM probe's digital signature and a financial-grade timestamp certified by the National Time Service Center. A dual-chain anchoring mechanism is then activated: the Merkle tree root hash is synchronously written to the financial consortium chain and the judicial evidence storage chain, and zero-knowledge proof technology is used to verify cross-chain consistency. A dynamic evidence packaging engine automatically generates standardized evidence packages that embed the probe device certificate, parser version identifier, and operation audit logs. When the system identifies unregistered money laundering patterns (such as new virtual currency cash-outs), the dynamic fraud strategy engine immediately triggers an adversarial sample generation mechanism. This uses a generative adversarial network (GAN) to synthesize highly realistic fraudulent transaction features, which are then fed into a graph neural network for incremental training to update the feature vector set. Simultaneously, the original data is physically isolated in a financial regulatory sandbox. Access requires multi-biometric authentication using iris / voiceprint authentication and quantum key sharding decryption authorization, creating a completely isolated zone for judicial audit and privacy protection. This completes the entire process, from edge data capture, dynamic policy response, judicial evidence of intent, to trusted evidence storage, completely reshaping the technical paradigm of financial anti-fraud evidence collection.
[0025] In a commercial bank's omnichannel transaction security system, a distributed edge probe group employs a domain-based deployment architecture to monitor the entire chain from physical terminals to mobile applications to core systems. Probes deployed at ATM terminals integrate dual-mode sniffers for both magnetic stripe and chip sensors. When criminals attempt to steal bank card information by modifying the ATM reader, the dual-mode sniffer captures anomalies in the physical operation instruction stream in real time—for example, a non-standard data read request following a normal card insertion instruction. This triggers a local desensitization mechanism, masking the card number (retaining the first 6 and last 4 digits) and hashing the transaction history using SHA-256 to prevent the leakage of the original data. The mobile app probe is embedded in a Trusted Execution Environment (TEE). When a user transfers money through mobile banking, if a malicious plug-in is implanted in the app to hijack transaction instructions, the probe intercepts abnormal API calls using system call hijacking technology. For example, a "modify receiving account" command forged by the plug-in will be identified as a non-user-triggered system call, freezing the session and uploading the instruction hash to the cloud. The probe deployed in the core transaction system is loaded with a proprietary protocol reverse adapter. For mixed SWIFT message and UnionPay POS transaction scenarios, the adapter dynamically generates parsing templates by analyzing protocol field entropy (for example, unusual field length fluctuations). When an undefined field combination appears in a cross-border remittance message, it can quickly match the protocol feature library to complete data extraction and desensitization. This domain-based deployment architecture has demonstrated significant advantages in actual operations: in one case, criminals simultaneously installed skimming devices on ATM terminals and implanted phishing apps on target phones, attempting to commit card fraud through "physical theft + remote hijacking." The domain-based probes captured abnormal card reading instructions on the ATM side and forged transfer requests on the app side, respectively. Through cross-domain data correlation, they located suspicious behavior within 10 seconds, providing original data support for subsequent evidence collection.
[0026] In cross-border funds monitoring scenarios, the dynamic fraud strategy engine demonstrates powerful new risk identification capabilities. Its graph neural network fraud feature library stores millions of cross-institutional transaction pattern vectors. For example, cross-border remittances under normal trade transactions typically follow the correlation between "order amount - logistics information - remittance amount," while abnormal patterns manifest as vector features of "multiple small-amount inward remittances combined with a large-amount outward remittance." When a remittance from an offshore account triggers an "unregistered transaction pattern" (such as the first appearance of the "virtual currency staking + cross-border fiat currency exchange" combination), the system immediately initiates a multi-layered processing process. The real-time threat assessment unit calculates the probability of timing anomalies based on the hidden Markov model: by analyzing the transaction timing of the account in the past three months (for example, remittances were usually made at 9 a.m. on weekdays, but this time the operation was performed at 2 a.m.), it outputs an 89% anomaly probability, exceeding the first threshold (70%) and activating basic forensics; as it was subsequently discovered that the flow of funds was associated with the IP address of a known fraud den, the threat value rose to 95%, breaking through the second threshold (90%), and the adaptive forensics controller immediately triggered a high-priority instruction - freezing the fund transfer, extending the session evidence period to 72 hours, and capturing the flow trajectory of the funds in payment institutions and digital currency exchanges through a cross-platform interface. Even more crucial is the role of the adversarial sample generation mechanism: when an unregistered transaction pattern is identified, the generative adversarial network (GAN) immediately synthesizes 100,000 new samples based on existing fraud features (such as simulating the fund splitting patterns of different offshore accounts), and updates the graph neural network weights through backpropagation, thereby improving the model's recognition accuracy of such patterns; at the same time, the original transaction data is isolated in the financial regulatory sandbox, allowing regulators to analyze new fraud methods in a controllable environment, ensuring data security and accelerating model iteration.
[0027] In an investigation into a virtual currency money laundering case, the intelligent evidence chain building module demonstrated its ability to penetrate complex transaction networks. The multi-level fund flow tracking unit, using an entity association graph, penetrated the multi-layered nested structure of "virtual currency wallet - OTC dealer - public account - personal card." First, it identified frequent fund transactions between a virtual account and five OTC dealers. Graph analysis then revealed that these dealers' public accounts ultimately linked to the same controlling shareholder: a blacklisted foreign trade company. Even though this entity hid its connections through three layers of shell companies, the graph was able to map weak correlations such as equity pledges and physical office addresses. Explainable AI parsers address the semantic challenge of recovering encrypted transactions. For a Bitcoin transfer encrypted via a coin-mixing service, the parser employed attention weight visualization technology to assign high attention weights to key fields in the transaction instructions (such as "coin-mixing node ID" and "number of fund splits"). The resulting decision heatmap, with high weights, revealed the transaction's intent to circumvent regulation through frequent splits. This visual analysis plays a crucial role in courtroom cross-examination, allowing judges to intuitively understand the AI's fraud detection logic and avoid disputes arising from "black box decision-making."
[0028] When regulators conduct an audit of a suspicious cross-border transaction, the trusted evidence interface's dual-chain anchored evidence structure ensures the immutability of the evidence. The system first shards the evidence chain (including transaction instructions, fund flow maps, and analysis reports) using a modified Merkle tree. The data is divided into 128 fragments, each of which incorporates the ATM terminal's hardware digital signature (tamper-proof) and a financial-grade timestamp (accurate to the millisecond) from the National Time Service Center. The Merkle tree root hash is then synchronously written to the financial consortium chain (for internal bank audits) and the judicial evidence chain (for regulatory access). The audit reports generated by the dynamic evidence packaging engine strictly comply with the requirements of the "Anti-Money Laundering Regulations for Financial Institutions." These reports include not only transaction timelines and fund flow paths, but also the on-chain address of each evidence fragment. Regulators can directly verify the fragment's integrity and time validity by entering the address in a blockchain browser. For raw data from unregistered transaction patterns (such as the new cross-border remittance records mentioned above), the sandbox data isolation mechanism plays a key role. Auditors must pass dual biometric authentication using fingerprint and Ukey, followed by quantum key sharding (key fragments held by three regulators) to access the isolated data. This ensures both regulatory compliance and data misuse is prevented.
[0029] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention should be included in the scope of protection of the present invention.
Claims
1. Intelligent data processing system for intelligent forensics, characterized by: Includes a distributed edge probe group, a dynamic fraud strategy engine, an intelligent evidence chain building module, and a trusted evidence storage interface; The distributed edge probe group is deployed in the core transaction system, with a built-in lightweight protocol parser. It adapts the SWIFT / UnionPay private protocol and real-time desensitization module within the parser, and performs transaction account masking and behavior track hashing at the data source end. The dynamic fraud strategy engine accesses the abnormal transaction flow of the edge probe group and stores cross-institutional transaction pattern vectors through the graph neural network fraud feature library; the real-time threat assessment unit detects the probability of abnormal transaction timing based on the hidden Markov model; The adaptive forensics controller dynamically activates targeted forensics instructions based on the threat value, capturing cross-platform fund flows with high priority and extending the evidence storage period for suspicious sessions. The intelligent evidence chain construction module includes a multi-level fund flow tracking unit and an explainable AI parser. The multi-level fund flow tracking unit penetrates the mapping between virtual accounts and actual controllers through the entity association graph; the explainable AI parser uses attention weight visualization technology to restore the semantics of encrypted transaction instructions and generate a decision heat map. The trusted evidence storage interface stores evidence chains in shards based on an improved Merkle tree. Each shard integrates the digital signature of the edge device and a financial-grade timestamp, and outputs an audit report that meets the requirements. Among them, when the dynamic fraud strategy engine identifies unregistered transaction patterns, it activates the adversarial sample generation mechanism: it uses the generative adversarial network to synthesize new fraud transaction features, updates the graph neural network weights, and isolates the original data into the financial regulatory sandbox.
2. The intelligent data processing system for intelligent evidence collection according to claim 1, characterized in that: The distributed edge probe group adopts a domain-based deployment architecture, where the probe deployed at the ATM terminal integrates a magnetic stripe / chip dual-mode sniffer to capture the physical transaction terminal operation instruction stream in real time; The mobile APP probe is embedded in a trusted execution environment and intercepts encrypted communication data through system call hijacking technology; The core transaction system probe loads the private protocol reverse adapter and dynamically generates SWIFT / UnionPay private protocol parsing templates based on the protocol field entropy value; The real-time desensitization module implements a hierarchical data processing pipeline: using format-preserving encryption masks for transaction accounts, applying SM3 hashing to behavioral traces, and injecting key shards protected by hardware security modules.
3. The intelligent data processing system for intelligent evidence collection according to claim 1, characterized in that: In the dynamic fraud strategy engine: the graph neural network fraud feature library adopts heterogeneous graph fusion technology to map transaction entity nodes and relationship edges into high-dimensional feature vectors; the real-time threat assessment unit constructs a dual-threshold trigger mechanism: when the abnormal probability of the hidden Markov model output exceeds the first threshold, basic forensics is activated, and when it exceeds the second threshold, cross-platform fund flow capture is triggered; the adaptive forensics controller configures a policy priority matrix and dynamically allocates computing resources to the suspicious session evidence link according to the threat value weight.
4. The intelligent data processing system for intelligent evidence collection according to claim 1, wherein: The operation process of the intelligent evidence chain construction module is to implement time-series penetration analysis through multi-level capital flow tracking units: track the capital flow path based on the improved depth-first search algorithm, and integrate unstructured data sources to construct evidence related to the actual controller; the explainable AI parser deploys a hierarchical attention mechanism: generate word-level attention weight heat maps in the instruction semantic restoration layer, output operation logic decision trees in the behavior intention analysis layer, and eliminate model bias interference through adversarial training.
5. The intelligent data processing system for intelligent evidence collection according to claim 1, characterized in that: The operation of the trusted evidence interface is through a dual-chain anchored evidence structure: the improved Merkle tree root hash is synchronously written into the financial alliance chain and the judicial evidence chain, and zero-knowledge proof technology is used to verify cross-chain consistency; dynamic evidence packaging engine: standardized evidence packages are generated as required, and the packages integrate timestamps certified by the National Time Service Center, probe equipment digital certificates and parser version traceability identifiers; sandbox data isolation mechanism: physical isolation storage is implemented for the original data of unregistered transaction models, and multiple biometric authentication and quantum key sharding decryption authorization are required for access.
Citation Information
Patent Citations
Quantum hidden Markov model solution fraud detection method and system, storage medium and terminal
CN113570452A
Remote digital meeting management system combining block chain and AI large model
CN120263575A
ETC fraud detection method
CN120493249A
System for high integrity real time processing of digital forensics data
US20240412315A1
Cited By
Cross-platform digital asset forensic analysis system for anti-money laundering survey
CN122089325A