An artificial intelligence-based financial data security analysis system
The AI-based financial data security analysis system solves the problems of untimely and inaccurate risk identification in existing technologies, enabling timely risk identification and accurate protection of financial data, providing personalized services, and ensuring the safety of users and financial institutions.
Patent Information
- Application Number
- CN202511449530.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-11
- Publication Date
- 2026-02-06
- Estimated Expiration
- 2045-10-11
AI Technical Summary
Existing technologies, due to the limitations of fixed rules in financial data security analysis, are unable to identify complex and ever-changing financial market risks in a timely and accurate manner, resulting in potential risks not being effectively identified.
An AI-based financial data security analysis system is adopted, which includes financial data collection, AI detection, user profiling analysis, and anomaly threshold management. Through multi-step model training and real-time comparison, abnormal behavior is identified and protective measures are taken.
It enables timely risk identification and accurate protection of financial data, improves the scientific nature and accuracy of anomaly detection, provides personalized services, and safeguards the security of users and financial institutions.
Smart Images

Figure CN120930136B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of financial data security, in particular to a financial data security analysis system based on artificial intelligence. BACKGROUND
[0002] In the financial field, it is crucial to ensure the security of financial data, and the existing technology plays an important role in financial data security analysis, which aims to identify potential risks in financial transactions, protect the assets of financial institutions and users, and maintain the stable operation of the financial market.
[0003] Currently, financial data security analysis is based on fixed rules and historical experience to judge risks, thereby protecting financial data, but the financial market environment is complex and variable, and the transaction mode is constantly innovating, so the fixed rules need to be adjusted to adapt to new types of risks and transaction characteristics, and at the same time, each user's financial data is different, resulting in different financial risks, which leads to the fact that the judgment of risks is not timely and accurate, and many potential risks cannot be effectively identified. In order to reduce this situation, a financial data security analysis system based on artificial intelligence is proposed. SUMMARY
[0004] The purpose of the present application is to provide a financial data security analysis system based on artificial intelligence to solve the problems raised in the background.
[0005] To achieve the above purpose, a financial data security analysis system based on artificial intelligence is provided, which includes a financial data collection unit, an artificial intelligence detection unit, a character portrait analysis unit, an abnormal threshold management unit and a data security management unit.
[0006] The financial data collection unit is used to collect financial data from financial data sources, and at the same time, the financial data is distributed according to the user to which it belongs.
[0007] The artificial intelligence detection unit is used to extract features from financial data, obtain normal features and malicious features, and establish an artificial intelligence detection end according to normal features and malicious features.
[0008] The character portrait analysis unit is used to detect the user's financial data using the artificial intelligence detection end, and at the same time, it analyzes the frequency according to the historical financial data, and establishes the character portrait of the user by intercepting the financial data according to the frequency analysis result.
[0009] The abnormal threshold management unit is used to analyze related financial sectors according to historical financial data, and then set the abnormal threshold by combining the related financial sectors with market financial data and the difference between different time historical financial data.
[0010] The data security management unit is used to verify real-time financial data by combining user profiles and anomaly thresholds. When the verification result shows that the anomaly threshold is exceeded, the real-time financial data is compared with historical financial data and malicious features, and data security protection is provided for the user based on the comparison result.
[0011] As a further improvement to this technical solution, the financial data collection unit requests information sharing from the financial data source, establishes a data transmission channel with the requested financial data source, and performs encrypted preprocessing on the financial data collected in the data transmission channel. The preprocessing includes data cleaning and noise reduction, data standardization and normalization, and data encryption and desensitization.
[0012] As a further improvement to this technical solution, the financial data collection unit includes a data allocation module;
[0013] The data allocation module is used to extract the monitoring range and the financial users within the monitoring range. Then, it combines the encrypted and pre-processed financial data with the financial users to allocate the data and obtain the relevant financial data of the financial users.
[0014] As a further improvement to this technical solution, the artificial intelligence detection unit includes a feature extraction module and a detection end establishment module;
[0015] The feature extraction module is used to extract features from the encrypted preprocessed financial data, obtain the financial features corresponding to each financial data, and classify the financial features into normal features and malicious features.
[0016] The detection terminal establishment module is used to establish an artificial intelligence detection terminal based on financial data with normal characteristics and financial data with malicious characteristics, and to protect the financial data through the artificial intelligence detection terminal.
[0017] As a further improvement to this technical solution, the character profile analysis unit includes a data monitoring module and a profile creation module;
[0018] The data detection module is used to detect real-time and historical financial data generated by users using an artificial intelligence detection terminal, obtain normal and malicious features corresponding to the user's historical financial data, and compare real-time financial data with malicious features. If the real-time financial data and malicious features are the same, data security protection is implemented; otherwise, if the real-time financial data and malicious features are different, further detection is performed.
[0019] The profile building module is used to perform frequency analysis based on historical financial data to obtain the frequency of users' historical operations. Then, it sets time segments based on the frequency, extracts financial data based on the time segments to build user profiles, and obtains the user's corresponding profile.
[0020] As a further improvement of the technical solution, the image establishment module sets the time period in a higher frequency, and the time period is closer to the real-time time.
[0021] The lower the frequency, the farther the time period is from the real-time time.
[0022] As a further improvement of the technical solution, the abnormal threshold management unit comprises a plate analysis module and a threshold setting module.
[0023] The plate analysis module is used to analyze the relevant financial plate of the user's historical financial data, obtain the corresponding relevant financial plate of the user, and obtain the fluctuation data of the relevant financial plate.
[0024] The threshold setting module is used to compare the difference degree of the historical financial data of the user at different times, obtain the difference degree between the historical financial data at different times, extract the maximum difference degree and the maximum difference value corresponding to the two historical financial data and the fluctuation data of the financial plate, and set the abnormal threshold value of the fluctuation data of the relevant financial plate obtained by the plate analysis module, the historical financial data corresponding to the maximum difference degree and the fluctuation data of the financial plate, and the maximum difference value.
[0025] As a further improvement of the technical solution, the data security management unit comprises a verification analysis module and a protection triggering module.
[0026] The verification analysis module is used to verify the real-time financial data in combination with the portrait and the abnormal threshold value, and when the difference value between the real-time financial data and the portrait is greater than the abnormal threshold value, a signal is sent to the protection triggering module for detection, otherwise, when the difference value between the real-time financial data and the portrait is less than the abnormal threshold value, the monitoring continues.
[0027] The protection triggering module is used to receive the signal of the verification analysis module, and then compare the correlation of the real-time financial data with the historical financial data and the malicious features, and when the correlation of the real-time financial data with the historical financial data is lower than the correlation of the real-time financial data with the malicious features, the data security protection is performed on the user, otherwise, when the correlation of the real-time financial data with the historical financial data is higher than the correlation of the real-time financial data with the malicious features, the detection continues.
[0028] As a further improvement of the technical solution, the data security management unit compares the correlation of the real-time financial data with the historical financial data and the malicious features as follows:
[0029] ;
[0030] R xyR is the correlation of real-time financial data and historical financial data, m is the data point number of real-time financial data, k is the data point number of historical financial data, x a is the a-th real-time financial data, is the mean of real-time financial data, is the mean of historical financial data, y b is the b-th historical financial data;
[0031] ;
[0032] wherein, R xz is the correlation of real-time financial data and malicious features, v is the data point number of malicious features, z c is the c-th malicious feature corresponding to historical financial data, is the mean of historical financial data;
[0033] When R xy <R xz , the data security protection operation is executed;
[0034] When R xy >R xz , the monitoring is continued.
[0035] Compared with the prior art, the beneficial effects of the present application are:
[0036] 1. In the financial data security analysis system based on artificial intelligence, the artificial intelligence detection end is constructed in multiple steps, and multiple model training optimization is used, so that the performance is reliable. The data monitoring module compares real-time and malicious feature data in real time with the help of the detection end, and when malicious features are found, safety protection measures such as stopping transactions and freezing accounts are taken quickly to prevent risks in time and protect user funds and financial institutions.
[0037] 2. In the financial data security analysis system based on artificial intelligence, the portrait establishment module establishes a person portrait according to the frequency analysis of historical financial data. In high-frequency periods, transaction details are focused on, and in low-frequency periods, overall situations are focused on. The portrait is updated in real time with transactions, and is adjusted in time when transaction frequency changes, which can accurately reflect user behavior, help financial institutions understand users in depth, provide personalized services, and also help identify abnormal behavior.
[0038] 3. In the financial data security analysis system based on artificial intelligence, the plate analysis module identifies user-related financial plates and obtains fluctuation data, the threshold setting module determines the maximum difference degree by comparing the difference degree of historical data, and sets an abnormal threshold combined with market fluctuations. This way considers multiple factors to make the threshold more scientific and reasonable, and improves the accuracy of abnormal judgment. BRIEF DESCRIPTION OF DRAWINGS
[0039] Fig. 1 This is an overall flowchart of the present invention;
[0040] Fig. 2 This is a schematic diagram of the overall structure of the present invention.
[0041] The meanings of the labels in the diagram are as follows:
[0042] 10. Financial data collection unit; 20. Artificial intelligence detection unit; 30. Personal profile analysis unit; 40. Anomaly threshold management unit; 50. Data security management unit. Detailed Implementation
[0043] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0044] Please see Figs. 1-2 As shown, the purpose of this embodiment is to provide an artificial intelligence-based financial data security analysis system, including a financial data collection unit 10, an artificial intelligence detection unit 20, a user profile analysis unit 30, an anomaly threshold management unit 40, and a data security management unit 50.
[0045] The financial data collection unit 10 is used to collect financial data from financial data sources and distribute the financial data according to the users to which they belong.
[0046] The financial data collection unit 10 establishes a data transmission channel with the financial data source by requesting information sharing from the financial data source. The financial data collected in the data transmission channel is encrypted and preprocessed, including data cleaning and noise reduction, data standardization and normalization, and data encryption and desensitization.
[0047] The financial data collection unit 10 includes a data distribution module;
[0048] The data allocation module is used to extract the monitoring scope and the financial users within the monitoring scope. Then, it combines the encrypted and pre-processed financial data with the financial users to allocate the data and obtain the relevant financial data of the financial users.
[0049] Structured data such as transaction records, basic customer information, and account information are collected from trading platforms, CRM systems, and financial management systems, as well as unstructured data from system operation logs;
[0050] Collaborate with third parties to obtain macroeconomic and industry dynamic data, and collect cybersecurity intelligence data;
[0051] Integrating data into financial data.
[0052] The artificial intelligence detection unit 20 is used for feature extraction according to the financial data, obtaining normal features and malicious features, and establishing an artificial intelligence detection end according to the normal features and the malicious features;
[0053] The artificial intelligence detection unit 20 includes a feature extraction module and a detection end establishment module;
[0054] The feature extraction module is used for feature extraction on the financial data after encryption preprocessing, obtaining the corresponding financial features of each financial data, and classifying the financial features into normal features and malicious features, the specific steps are as follows:
[0055] Obtain encrypted data: extract each data item from the encrypted financial data set, and further process each encrypted data;
[0056] Feature extraction: extract features from encrypted financial data, these features can be various indicators of financial transactions, such as transaction frequency, amount, time interval, etc.;
[0057] Classify the extracted financial features: input the extracted financial features into a classification model, classify according to these features, the classification model can be a machine learning-based algorithm such as decision tree, SVM (Support Vector Machine) or neural network, etc., then set two categories of "normal features" and "malicious features", usually malicious features will involve abnormal transaction patterns or behaviors, such as abnormal transaction amount, frequent small transactions, etc. may be classified as malicious features, then use the trained classifier to classify the extracted features, output the classification result (normal or malicious) corresponding to each financial data;
[0058] Match the classification result with the user: according to the user ID, associate the classification result (normal or malicious) with each user, so that each user's financial data is marked as normal or malicious, count the classified results, analyze the distribution of each type of feature in different users, and identify potential malicious behavior.
[0059] The detection end establishment module is used for establishing an artificial intelligence detection end according to the financial data of normal features and the financial data of malicious features, and performing security protection on the financial data through the artificial intelligence detection end, the specific steps are as follows:
[0060] Data preparation: collect and organize the financial data with labeled normal features and malicious features, divide these data into training set, validation set and test set, the training set is used to train the artificial intelligence model, the validation set is used to adjust the hyperparameters of the model and prevent overfitting, and the test set is used to evaluate the performance of the final model;
[0061] Model selection: According to the characteristics of the data and the needs of the problem, select the appropriate artificial intelligence model to build the detection end, common models include but are not limited to logistic regression, decision tree, random forest, neural network;
[0062] Model training: Use the training set data to train the selected model, in the training process, the model will adjust its parameters (such as neural network weights and biases) according to the input feature data and the corresponding label (normal or malicious), in order to minimize the error between the predicted result and the true label, the loss function includes cross-entropy loss function (suitable for classification problem) etc.;
[0063] Model validation and optimization: Use the validation set data to evaluate the trained model, by adjusting the hyperparameters of the model (such as learning rate, number of layers and number of neurons in neural network, etc.), make the model achieve the best performance on the validation set, you can use cross-validation and other techniques to improve the reliability of the validation;
[0064] Model testing: Use the test set data to test the final determined model, calculate the performance indicators (such as accuracy, recall rate, F1 value, etc.) of the model, to evaluate the generalization ability of the model on unknown data;
[0065] Establishing artificial intelligence detection end: Encapsulate the tested and well-performing model into a real-time detection artificial intelligence detection end, which can receive new financial data, extract features, input into the model for prediction, and judge whether the data belongs to normal features or malicious features;
[0066] The portrait analysis unit 30 is used to detect the user's financial data by using the artificial intelligence detection end, and to analyze the frequency according to the historical financial data, and to intercept the financial data according to the frequency analysis result to establish the user's portrait;
[0067] The portrait analysis unit 30 includes a data monitoring module and a portrait establishment module;
[0068] The data detection module is used to detect the real-time financial data and historical financial data generated by the user by using the artificial intelligence detection end, to obtain the normal features and malicious features corresponding to the user's historical financial data, and to compare the real-time financial data with the malicious features, when the real-time financial data is the same as the malicious features, data security protection is performed, otherwise, when the real-time financial data is different from the malicious features, subsequent continuous detection is performed;
[0069] For the user's historical financial data, the same feature extraction method as when establishing the artificial intelligence detection end is used to extract the corresponding financial features from the data. For example, the size of the transaction amount, the transaction frequency, the change trend of the account balance, etc. The extracted features are input into the artificial intelligence detection end, and the detection end classifies these features to determine whether they belong to normal features or malicious features, thereby obtaining the normal feature and malicious feature sets corresponding to the user's historical financial data;
[0070] The new financial data is input into the artificial intelligence detection end in real time, and the detection end judges according to the prediction result of the model. If the data has malicious features, take appropriate security protection measures, such as blocking transactions, freezing accounts, issuing alerts, etc.; if the data is normal features, allow the relevant operation to continue.
[0071] The portrait establishment module is used to analyze the frequency of historical financial data, obtain the frequency of the user's historical operation, and then set the time period according to the frequency, and intercept the financial data according to the time period to establish the user's portrait, and obtain the user's portrait;
[0072] The higher the frequency, the closer the time period to the real-time time;
[0073] The lower the frequency, the farther the time period from the real-time time, the specific steps are as follows:
[0074] Select the time unit for analysis: Select the appropriate time unit (for example: hour, day, week, etc.) to divide the transaction records, such as reporting the user's transaction frequency every hour, every day, according to the user's historical operation frequency for grouping;
[0075] Calculate the user's transaction frequency in each time period: For different time periods (such as the past 1 hour, the past day, the past week, etc.), count the number of transactions in each time period. Through this calculation, the transaction frequency of each user in different time periods can be obtained, the formula is as follows:
[0076] ;
[0077] Where, F(t start , t end ) is the transaction frequency in the time period, t start and t end are the start and end times of the time period, and E[t start , t end ] is the total number of transactions in the time period;
[0078] Set the time period according to the frequency: according to the user's historical transaction frequency, divide the time period into different categories, and then affect the selection of the time period;
[0079] High-frequency trading: If the number of transactions a user makes in a certain time period (e.g., the past 1 hour, 1 day) exceeds a set threshold (e.g., 5 times), it is considered high-frequency trading;
[0080] Low-frequency trading: If a user's trading frequency is low (e.g., the number of transactions in the past week is less than 5 times), it is considered low-frequency trading;
[0081] According to the user's trading frequency, set the time distance of the corresponding time period, the higher the frequency, the closer the time period to the current time, the formula is as follows:
[0082] ;
[0083] Where D is the relative distance of the time period, the distance from the current time, F is the trading frequency.
[0084] Extract features for each time period: According to different frequency time periods, extract different user behavior features;
[0085] For high-frequency time periods (such as the past 1 hour), the average amount of each transaction, the distribution of transaction types, device types, and transaction time distribution can be extracted;
[0086] For low-frequency time periods (such as the past 1 month), the extracted features focus more on total transaction amount, transaction category proportion, etc.
[0087] Extract user portrait features: According to the transaction records in each time period, calculate features including transaction amount, transaction type, transaction frequency, device information, the formula is as follows:
[0088] ;
[0089] ;
[0090] Where X g is the high-frequency transaction feature calculation, Q average is the average transaction amount, t b is the transaction time distribution, X d is the low-frequency transaction feature calculation, Q total is the total transaction amount, L b is the transaction type distribution, S q is the device usage;
[0091] Dynamic update of user portrait: Whenever a user makes a new transaction, update the user portrait in real time, especially the portrait features of high-frequency trading periods, and when a user's trading frequency changes significantly, adjust the time period it belongs to, and recalculate the relationship between the time period and the frequency.
[0092] The abnormal threshold management unit 40 is used for analyzing related financial sectors according to historical financial data, and then setting an abnormal threshold according to the related financial sectors, market financial data and the difference degree of different time historical financial data;
[0093] The abnormal threshold management unit 40 includes a sector analysis module and a threshold setting module;
[0094] The sector analysis module is used for analyzing related financial sectors of the user's historical financial data, obtaining the corresponding related financial sectors of the user, and obtaining the fluctuation data of the related financial sectors. The specific steps are as follows:
[0095] Identify the corresponding financial sectors of the user: based on the user's transaction type (such as stocks, bonds, futures, etc.) and other transaction characteristics, identify the related financial sectors involved by the user. The financial sectors can be stock sectors, fund sectors, and futures sectors;
[0096] Analyze the fluctuation data of the related financial sectors: collect the market fluctuation data of each financial sector. Common fluctuation data includes volatility, and the formula is as follows:
[0097] ;
[0098] Where, σ BK is the volatility of the sector, p i is the price at the i-th time point, N is the total number of data points in the time interval, is the average value of the sector price.
[0099] The threshold setting module is used for comparing the difference degree of the user's historical financial data at different times, obtaining the difference degree between the historical financial data at different times, extracting the maximum difference degree and the maximum difference value corresponding to the two historical financial data and the fluctuation data of the financial sector, and setting an abnormal threshold according to the fluctuation data of the related financial sectors obtained by the sector analysis module, the historical financial data corresponding to the maximum difference degree and the fluctuation data of the financial sector, and the maximum difference value. The specific steps are as follows:
[0100] Select the comparison time period: select the time period to be compared. Usually, the past time period is compared with the current time period, for example, the current time period can be compared with the financial data of the past 1 hour, 1 day, or 1 week;
[0101] Calculate the difference degree between the historical financial data at different time periods: use the difference degree calculation formula to compare the financial data at different time periods. The difference degree calculation formula is as follows:
[0102] ;
[0103] ;
[0104] ;
[0105] wherein, AQ is the difference degree of transaction amount, Q at is the current transaction amount, Q bt is the past transaction amount, AF is the difference degree of transaction frequency, F at is the current transaction frequency, F bt is the past transaction frequency, AL is the difference degree of transaction type, L at is the current transaction type difference, L bt is the past transaction type;
[0106] Calculate the maximum difference degree: after comparing and calculating the difference degree of each dimension (amount, frequency, type, etc.) in different time periods, find the maximum difference degree value, which represents the largest change in a set of data in the historical financial data. Find the corresponding historical financial data and the fluctuation data of the related financial board at the maximum difference degree, which will be used to analyze the relationship between the user and the market and how to respond to market fluctuations, as follows:
[0107] ;
[0108] wherein, Amax is the maximum difference degree;
[0109] Set threshold: use the maximum difference degree and the fluctuation data of the board to set the abnormal threshold, combine the market fluctuation data with the maximum difference value in the user's historical financial data, as follows:
[0110] ;
[0111] wherein, θ is the abnormal threshold, and a and β are adjustment coefficients for balancing the influence between the maximum difference degree and the fluctuation of the financial module.
[0112] The data security management unit 50 is used to verify the real-time financial data in combination with the character portrait and the abnormal threshold, and when the verification result shows that it exceeds the abnormal threshold, the real-time financial data is compared with the historical financial data and malicious features in terms of correlation, and the user is protected in terms of data security according to the comparison result.
[0113] The data security management unit 50 includes a verification analysis module and a protection triggering module;
[0114] The verification analysis module is used to verify the real-time financial data in combination with the character portrait and the abnormal threshold, and when the difference value between the real-time financial data and the character portrait is greater than the abnormal threshold, a signal is sent to the protection triggering module for detection, otherwise, when the difference value between the real-time financial data and the character portrait is less than the abnormal threshold, it is maintained to continue monitoring;
[0115] Obtain real-time financial data of the user from the data source, and call the previously established user character portrait and the pre-set abnormal threshold value;
[0116] Compare the real-time financial data with the character portrait, and calculate the difference value between the two. The character portrait contains the characteristic patterns of the user's historical financial behavior, such as transaction amount range, transaction time regularity, transaction object preference, etc. The difference degree is determined by comparing the real-time data with these characteristic patterns;
[0117] Compare the calculated difference value with the abnormal threshold value. If the difference value is greater than the abnormal threshold value, it means that the real-time financial data may be abnormal, and a signal is sent to the protection triggering module. If the difference value is less than the abnormal threshold value, it is determined that the data is normal, and the subsequent real-time financial data is continued to be monitored. The protection triggering module is used to receive the signal of the verification and analysis module, and then compare the real-time financial data with the historical financial data and the malicious features. When the correlation between the real-time financial data and the historical financial data is lower than the correlation between the real-time financial data and the malicious features, the user is protected for data security. Otherwise, when the correlation between the real-time financial data and the historical financial data is higher than the correlation between the real-time financial data and the malicious features, the detection is continued. The specific formula is as follows:
[0118] ;
[0119] Where, R xy is the correlation between the real-time financial data and the historical financial data, m is the number of data points of the real-time financial data, k is the number of data points of the historical financial data, x a is the a-th real-time financial data, is the mean value of the real-time financial data, is the mean value of the historical financial data, y b is the b-th historical financial data;
[0120] ;
[0121] Where, R xz is the correlation between the real-time financial data and the malicious features, v is the number of data points of the malicious features, z c is the historical financial data corresponding to the c-th malicious feature, is the mean value of the historical financial data;
[0122] When R xy < R xz , the data security protection operation is performed;
[0123] When R xy > R xz , the monitoring is continued.
[0124] The above shows and describes the basic principles, main features and advantages of the present application. It should be understood by those skilled in the art that the present application is not limited to the above-mentioned embodiments, and the above-mentioned embodiments and descriptions in the specification are only preferred examples of the present application and are not intended to limit the present application. Various changes and improvements can be made to the present application without departing from the spirit and scope of the present application, and these changes and improvements all fall within the scope of the claimed present application. The scope of protection of the present application is defined by the appended claims and their equivalents.
Claims
1. An artificial intelligence-based financial data security analysis system, characterized by: The application relates to a financial data collection unit (10), an artificial intelligence detection unit (20), a character portrait analysis unit (30), an abnormal threshold management unit (40) and a data security management unit (50); The financial data collection unit (10) is used for collecting financial data from a financial data source and distributing the financial data according to users; The artificial intelligence detection unit (20) is used for extracting features from the financial data, obtaining normal features and malicious features, and establishing an artificial intelligence detection end according to the normal features and the malicious features; The character portrait analysis unit (30) is used for detecting the financial data of the user by using the artificial intelligence detection end, performing frequency analysis on the historical financial data, and establishing a character portrait of the user by intercepting the financial data according to the frequency analysis result; The character portrait analysis unit (30) comprises a data monitoring module and a portrait establishment module; The data monitoring module is used for detecting real-time financial data and historical financial data generated by the user by using the artificial intelligence detection end, obtaining normal features and malicious features corresponding to the historical financial data of the user, comparing the real-time financial data with the malicious features, and performing data security protection when the real-time financial data is the same as the malicious features, otherwise, continuously detecting the subsequent real-time financial data; The portrait establishment module is used for performing frequency analysis on the historical financial data, obtaining the frequency of historical operations of the user, setting a time period according to the frequency, establishing a character portrait of the user by intercepting the financial data according to the time period, and obtaining the character portrait corresponding to the user; When the portrait establishment module sets the time period, the higher the frequency, the closer the time period to the real-time time; The lower the frequency, the farther the time period from the real-time time; The abnormal threshold management unit (40) is used for analyzing related financial blocks according to the historical financial data, and setting an abnormal threshold according to the difference between the related financial blocks, market financial data and different time historical financial data; The data security management unit (50) is used for verifying real-time financial data in combination with a character portrait and an abnormal threshold, comparing the real-time financial data with historical financial data and malicious features according to a result of the verification, and performing data security protection on the user according to a comparison result; The character portrait contains feature modes of historical financial behaviors of the user, the difference degree is determined by comparing real-time data with the feature modes, the difference value is compared with an abnormal threshold, if the difference value is greater than the abnormal threshold, it is indicated that the real-time financial data may be abnormal, and a signal is sent to a protection triggering module; If the difference value is less than the abnormal threshold, it is determined that the data is normal, and the subsequent real-time financial data is continuously monitored.
2. The financial data security analysis system based on artificial intelligence according to claim 1, characterized in that: The financial data collection unit (10) establishes a data transmission channel with a requested financial data source by sending an information sharing request to the financial data source, performs encryption preprocessing on the collected financial data in the data transmission channel, and the preprocessing is data cleaning and denoising, data standardization and normalization, data encryption and desensitization. 3.The financial data security analysis system based on artificial intelligence of claim 1, wherein: The financial data collection unit (10) comprises a data distribution module; The data distribution module is used for extracting a monitoring range, extracting a financial user in the monitoring range, and then distributing the encrypted and pretreated financial data to the financial user to obtain related financial data of the financial user.
4. The financial data security analysis system based on artificial intelligence according to claim 1, characterized in that: The artificial intelligence detection unit (20) comprises a feature extraction module and a detection end establishment module; The feature extraction module is used for extracting features of the encrypted and pretreated financial data, obtaining corresponding financial features of each financial data, classifying the financial features, and dividing the financial features into normal features and malicious features; The detection end establishment module is used for establishing an artificial intelligence detection end according to the financial data of the normal features and the financial data of the malicious features, and protecting the financial data through the artificial intelligence detection end.
5. The financial data security analysis system based on artificial intelligence according to claim 1, characterized in that: The abnormal threshold management unit (40) comprises a plate analysis module and a threshold setting module; The plate analysis module is used for analyzing historical financial data of a user to obtain corresponding related financial plates of the user and fluctuation data of the related financial plates; The threshold setting module is used for comparing the historical financial data of the user at different times to obtain a difference degree between the historical financial data at different times, extracting a maximum difference degree and a maximum difference value corresponding to two historical financial data and fluctuation data of a financial plate, and setting an abnormal threshold for the fluctuation data of the related financial plates obtained by the plate analysis module, the historical financial data corresponding to the maximum difference degree, and the maximum difference value.
6. The financial data security analysis system based on artificial intelligence according to claim 1, characterized in that: The data security management unit (50) comprises a verification analysis module and a protection triggering module; The verification analysis module is used for verifying real-time financial data in combination with a portrait and an abnormal threshold, sending a signal to the protection triggering module for detection when a difference value between the real-time financial data and the portrait is greater than the abnormal threshold, and otherwise, maintaining continuous monitoring when the difference value is less than the abnormal threshold; The protection triggering module is used for receiving a signal from the verification analysis module, then comparing the real-time financial data with historical financial data and malicious features in terms of relevance, and performing data security protection on the user when the relevance between the real-time financial data and the historical financial data is lower than the relevance between the real-time financial data and the malicious features, and otherwise, maintaining continuous detection.
7. The financial data security analysis system based on artificial intelligence according to claim 1, characterized in that: The data security management unit (50) compares the real-time financial data with the historical financial data and the malicious features in terms of relevance as follows: ; wherein R xy is the correlation of real-time financial data and historical financial data, m is the number of data points of real-time financial data, k is the number of data points of historical financial data, x a is the a-th real-time financial data, is the mean of real-time financial data, is the mean of historical financial data, y b is the b-th historical financial data; ; where R xz is the correlation of real-time financial data with malicious features, v is the number of data points of malicious features, z c is the historical financial data corresponding to the cth malicious feature, is the mean of historical financial data; When R xy < R xz then perform a data security protection operation; When R xy > R xz then continue monitoring.
Citation Information
Patent Citations
Time sequence monitoring index anomaly detection method based on Gaussian process regression
CN117290801A
Network behavior analysis method based on big data
CN119254817A