Payment fraud real-time identification and disposal method and system based on machine learning

By constructing a transaction relationship graph and utilizing graph attention networks, knowledge graphs, and reinforcement learning, the shortcomings of existing payment fraud detection technologies are addressed. This enables efficient identification of complex transaction patterns and optimization of flexible verification strategies, thereby improving payment security and user experience.

CN120996814AActive Publication Date: 2025-11-21JIANGSU YAOER LINGJIU TECHNOLOGY SERVICE CO LTD
View PDF 8 Cites 0 Cited by

Patent Information

Application Number
CN202511525550.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-10-24
Publication Date
2025-11-21
Estimated Expiration
2045-10-24

AI Technical Summary

Technical Problem

Existing payment fraud detection technologies cannot effectively model the complex relationship networks between transaction participants, lack flexibility and adaptability, and are difficult to identify group fraud and complex related transaction patterns. Furthermore, traditional verification methods lack systematic optimization and cannot achieve the best balance between security and convenience.

Method used

A transaction relationship graph is constructed, and graph attention networks are used for feature embedding and association strength modeling. A hierarchical verification action space is constructed based on knowledge graphs. An adaptive verification strategy generator is constructed through reinforcement learning to dynamically adjust the verification strategy to identify abnormal transaction patterns and optimize the combination of verification methods.

Benefits of technology

It improves the accuracy and flexibility of fraud identification, reduces the false positive rate, optimizes user experience and verification costs, and achieves the optimal balance between fraud risk and user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120996814A_ABST
    Figure CN120996814A_ABST
Patent Text Reader

Abstract

The invention provides a payment fraud real-time identification and disposal method and system based on machine learning, and relates to the technical field of computers, and the method comprises the steps: constructing a transaction relation graph, recognizing an abnormal transaction mode through a graph attention network, and calculating a transaction suspicious degree score; and when the preset threshold value is exceeded, triggering a self-adaptive verification strategy based on the knowledge graph and reinforcement learning, executing a corresponding verification means and processing a transaction result. According to the invention, accurate identification and efficient disposal of fraudulent transactions can be realized, the payment security is improved, the error interception rate is reduced, and the user experience is optimized.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of computer, and in particular to a payment fraud real-time identification and disposal method and system based on machine learning. BACKGROUND

[0002] With the popularization of electronic payment, payment fraud activities are increasingly rampant, posing a serious threat to financial security. Traditional payment fraud detection methods mainly rely on rule engines and simple statistical models, which cannot effectively cope with the rapid evolution of fraud methods. In recent years, machine learning technology has been widely applied in fraud detection, analyzing multi-dimensional data such as user behavior characteristics, transaction patterns, and device information, improving the accuracy of fraud identification. The current mainstream fraud detection system usually uses traditional machine learning algorithms such as decision trees, random forests, and support vector machines or deep learning models, combined with risk control rules for risk assessment. After detecting suspicious transactions, the corresponding verification process will be triggered, such as SMS verification, biometric authentication, or telephone confirmation, to confirm the authenticity of the transaction.

[0003] However, the existing payment fraud detection technology has the following shortcomings: Firstly, the existing technology generally uses isolated feature analysis methods, which cannot effectively model the complex relationship network between transaction participants, resulting in limited ability to identify gang fraud and complex associated transaction patterns. Due to the failure to fully utilize the rich relationship information contained in the graph structure data, it is difficult to discover hidden fraud patterns and abnormal transaction paths.

[0004] Secondly, the existing fraud transaction verification strategy is usually preset and fixed, lacking flexibility and adaptability, and cannot dynamically adjust the verification means according to different transaction scenarios and risk levels. This one-size-fits-all verification mechanism will lead to insufficient verification of high-risk transactions and excessive verification of low-risk transactions, affecting user experience and increasing operating costs.

[0005] Finally, the selection of traditional verification means lacks a systematic optimization method, failing to consider various verification means from multiple aspects such as cost, effect, and user experience, making it difficult to achieve the best balance between security and convenience. The combination strategy between verification means also lacks scientific basis, and cannot adjust the verification strategy in real time according to the dynamic changes of fraud risk, resulting in low prevention and control efficiency. SUMMARY

[0006] The embodiments of the present application provide a payment fraud real-time identification and disposal method and system based on machine learning, which can solve the problems in the prior art.

[0007] In a first aspect, the embodiments of the present application provide a payment fraud real-time identification and disposal method based on machine learning, comprising: obtaining a user identifier, extracting historical payment device records and historical payee information of the user from a user historical behavior database based on the user identifier; constructing the user identifier, the payment device and the payee as nodes, and constructing payment behavior as edges to generate a transaction relationship graph, performing feature embedding on the nodes in the transaction relationship graph, modeling the association strength between the nodes by using a graph attention network, identifying abnormal transaction association patterns, and calculating a transaction suspiciousness score based on the node embedding features and the association strength; comparing the transaction suspiciousness score with a preset suspiciousness threshold, and triggering a transaction verification process when the preset suspiciousness threshold is exceeded; taking transaction features as environmental states, constructing a hierarchical verification means action space based on a knowledge graph, constructing a relationship edge set by calculating similarity measurement values and dependency relationship values between verification means nodes, realizing adaptive division of security levels according to dynamic security scores of the verification means nodes, calculating comprehensive utility values of verification combinations by node unit cost and associated conflict cost; constructing a reinforcement learning-based adaptive verification strategy generator, executing the verification combination output by the adaptive verification strategy generator to obtain a verification result; when the verification is passed, releasing the transaction, and when the verification is not passed, rejecting the transaction and pushing a risk reminder to the user.

[0008] constructing the user identifier, the payment device and the payee as nodes, and constructing payment behavior as edges to generate a transaction relationship graph includes: constructing user identifier information as a first type of node, constructing payment device information as a second type of node, and constructing payee information as a third type of node; using transaction time, transaction amount and transaction type as payment behavior information, and constructing directed edges between the first type of node or the second type of node and the third type of node according to the payment behavior information, wherein the starting point of the directed edge is the node initiating payment, the end point of the directed edge is the node receiving payment, and the corresponding payment behavior information is labeled on the directed edge; constructing a node adjacency matrix to represent the connection relationship between the first type of node, the second type of node and the third type of node, wherein the rows and columns of the node adjacency matrix correspond to different types of nodes, and the matrix elements represent whether there is a directed edge connection between the nodes; constructing an edge attribute matrix to store the payment behavior information on the directed edge, wherein the edge attribute matrix and the node adjacency matrix have the same dimensions, and the matrix elements record the transaction time, transaction amount and transaction type of the corresponding directed edge; and generating a topological structure of a transaction relationship graph based on the node adjacency matrix and the edge attribute matrix.

[0009] The correlation strength between nodes is modeled by using a graph attention network, and an abnormal transaction correlation pattern is identified, and a transaction suspiciousness score is calculated based on node embedding features and correlation strength, including: An initial feature vector is configured for a node in a transaction relationship graph, and the initial feature vector is input into a feature transformation matrix to obtain a transformed feature, the transformed features corresponding to adjacent nodes are spliced and input into an attention vector to generate an attention coefficient between node pairs, the attention coefficient is normalized to obtain an attention weight, and the node features are aggregated and updated based on the attention weight to obtain an attention feature of the node; The attention feature sequence of the user's historical transactions is extracted, the attention coefficient between the user-device nodes is multiplied by the negative exponential decay value of the transaction time interval to obtain the user-device correlation strength; the attention coefficient between the user-cashier nodes is weighted and summed to obtain the user-cashier correlation strength; the cosine similarity of the attention features between the device-cashier nodes is multiplied by the attention coefficient to obtain the device-cashier correlation strength; and the three kinds of correlation strength are spliced and input into a fully connected layer to obtain a multi-dimensional fusion feature vector; The difference between the correlation strength of the current transaction and the average correlation strength of the user's historical transactions is calculated, and the difference is divided by the standard deviation to obtain a time series anomaly score; the probability distribution information entropy of the three kinds of correlation strength is calculated to obtain a structural anomaly score; and the time series anomaly score, the structural anomaly score and the multi-dimensional fusion feature vector are spliced and input into a three-layer fully connected network to obtain a transaction suspiciousness score through a Sigmoid function mapping.

[0010] The transaction features are taken as environmental states, a hierarchical verification means action space is constructed based on a knowledge graph, a relationship edge set is constructed by calculating the similarity measurement value and the dependency relationship value between the verification means nodes, the adaptive division of the security level is realized according to the dynamic security score of the verification means nodes, and the comprehensive utility value of the verification combination is calculated by the node unit cost and the associated conflict cost, including: A verification means knowledge graph is constructed, and the verification means knowledge graph includes a verification means node set and a relationship edge set; Based on the feature vector of the verification means node, the similarity measurement value between the nodes is obtained by weighting the cosine similarity of the feature vector and the overlap degree of the applicable scene set, and the dependency relationship value is calculated based on the co-occurrence number of the verification means nodes, and the similarity measurement value and the dependency relationship value are taken as the weights of the relationship edge set; According to the basic security score of the verification means node and the weight information of the relationship edge set, the dynamic security score of the verification means node is calculated by combining the historical performance score and the adaptability score of the verification means in different scenes, and the verification means node is dynamically divided into different security levels based on the dynamic security score; A cost budget constraint model is established for the verification means nodes of different security levels, a unit cost is calculated based on the resource consumption cost of the verification means nodes, a conflict cost is calculated based on the conflict information between the nodes obtained through the relationship edge set, and the unit cost and the conflict cost are integrated to obtain a combination utility value under the condition of meeting the budget constraint.

[0011] A cost budget constraint model is established for the verification means nodes of different security levels, a unit cost is calculated based on the resource consumption cost of the verification means nodes, a conflict cost is calculated based on the conflict information between the nodes obtained through the relationship edge set, and the unit cost and the conflict cost are integrated to obtain a combination utility value under the condition of meeting the budget constraint. The calculation resource consumption, memory resource consumption and time consumption of the verification means nodes are respectively given corresponding weights and a weighted sum is calculated to obtain a unit resource cost, a security level cost coefficient is calculated according to the security level to which the verification means node belongs, and the unit resource cost is multiplied by the security level cost coefficient to obtain a node basic cost of each verification means node. The calculation resource consumption, memory resource consumption and time consumption of the verification means nodes are respectively given corresponding weights and a weighted sum is calculated to obtain a unit resource cost, a security level cost coefficient is calculated according to the security level to which the verification means node belongs, and the unit resource cost is multiplied by the security level cost coefficient to obtain a node basic cost of each verification means node. The global budget upper limit and the hierarchical budget upper limit of each security level are set as the budget constraint condition, and it is judged whether the sum of the node basic costs and the sum of the cumulative conflict costs meet the budget constraint condition. For the verification means nodes that meet the budget constraint condition, the security score, performance score and user experience score of each verification means node are calculated, the security score, performance score and user experience score are respectively given corresponding weights and a weighted sum is calculated to obtain a node utility value, and a combination utility value of the verification combination is obtained based on the node utility value minus the cumulative conflict cost.

[0012] An adaptive verification strategy generator based on reinforcement learning is constructed, the verification combination output by the adaptive verification strategy generator is executed, and a verification result is obtained. A transaction feature vector, a user portrait feature vector and a scene context feature vector are obtained and spliced to form an environment state representation vector, a state code is obtained by linear transformation of the environment state representation vector through an encoding weight matrix and processing through an activation function. A verification means set of multiple security levels is divided according to the state code, a selection state of each verification means is composed into an action vector, a total selection quantity constraint and a selection quantity constraint within different security levels are set for the action vector, and a candidate verification means combination set meeting the constraint condition is generated. The state code is input into an Actor network and a Critic network at the same time, the Actor network extracts features of the state code through a multilayer perceptron structure to generate a selection probability distribution of each combination of the candidate verification method combination set, and the Critic network adopts a double-layer neural network structure, the first layer performs dimension reduction mapping on the state code, the second layer outputs a state value evaluation score to obtain a value score corresponding to the current state code; Each combination of the candidate verification method combination set is sorted according to the selection probability distribution, a verification method combination with the highest value score is selected as an optimal verification strategy output, and a verification result is obtained.

[0013] In a second aspect of the embodiment of the application, a payment fraud real-time identification and disposal system based on machine learning is provided, comprising: A first unit is configured to obtain a user identifier, extract historical payment device records and historical payee information of the user from a user historical behavior database based on the user identifier; A second unit is configured to construct the user identifier, the payment device and the payee as nodes, construct the payment behavior as edges, generate a transaction relationship graph, perform feature embedding on the nodes in the transaction relationship graph, model the association strength between the nodes by using a graph attention network, identify an abnormal transaction association mode, and calculate a transaction suspiciousness score based on the node embedding features and the association strength; A third unit is configured to compare the transaction suspiciousness score with a preset suspiciousness threshold, and trigger a transaction verification process when the preset suspiciousness threshold is exceeded; A fourth unit is configured to take transaction features as an environment state, construct a hierarchical verification method action space based on a knowledge graph, construct a relationship edge set by calculating similarity measurement values and dependency relationship values between verification method nodes, realize adaptive division of security levels according to dynamic security scores of the verification method nodes, calculate a comprehensive utility value of a verification combination by a node unit cost and an associated conflict cost, construct an adaptive verification strategy generator based on reinforcement learning, execute a verification combination output by the adaptive verification strategy generator, and obtain a verification result; A fifth unit is configured to release the transaction when the verification is passed, and reject the transaction and push a risk reminder to the user when the verification is not passed.

[0014] In a third aspect of the embodiment of the application, An electronic device is provided, comprising: A processor; A memory for storing processor-executable instructions; The processor is configured to invoke the instructions stored in the memory to execute the method described above.

[0015] A fourth aspect of the embodiments of the present application, A computer readable storage medium is provided, and computer program instructions are stored on the computer readable storage medium, and the computer program instructions are executed by a processor to implement the method described above.

[0016] The beneficial effects of the present application are as follows: The present application can effectively identify abnormal transaction patterns, improve the accuracy of fraud identification, and reduce the misjudgment rate by constructing a transaction relationship graph and using a graph attention network for feature embedding and correlation strength modeling, thereby providing more accurate technical support for financial security.

[0017] The present application constructs a hierarchical verification means action space based on a knowledge graph, and realizes adaptive division of the verification means by calculating node similarity and dependency relationship, so that the risk control measures are more flexible and efficient, and the most suitable verification combination can be intelligently selected according to different risk levels, thereby optimizing the user experience.

[0018] The present application adopts a reinforcement learning method to construct an adaptive verification strategy generator, calculates the comprehensive utility value of the verification combination, reduces the verification cost while ensuring safety, improves the system processing efficiency, realizes the optimal balance between fraud risk and user experience, and provides a more efficient risk control scheme for financial institutions. BRIEF DESCRIPTION OF DRAWINGS

[0019] Figure 1 The flowchart of the payment fraud real-time identification and disposal method based on machine learning of the embodiments of the present application is shown in the figure. Figure 2 The performance comparison and analysis diagram of different technical solutions is shown in the figure. Figure 3 The verification combination utility value comparison diagram under different budget constraints is shown in the figure. DETAILED DESCRIPTION

[0020] In order to make the purpose, technical scheme and advantages of the embodiments of the present application clearer, the technical scheme of the embodiments of the present application will be described clearly and completely below in combination with the drawings of the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor are within the scope of protection of the present application.

[0021] The technical scheme of the present application will be described in detail below with specific embodiments. The following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described in some embodiments.

[0022] Figure 1A flowchart of a payment fraud real-time identification and handling method based on machine learning according to an embodiment of the present application is shown in FIG. 1, which comprises the following steps: Figure 1 obtaining a user identifier, and extracting historical payment device records and historical payee information of the user from a user historical behavior database based on the user identifier; constructing the user identifier, payment device and payee as nodes, and constructing payment behavior as edges to generate a transaction relationship graph, performing feature embedding on the nodes in the transaction relationship graph, modeling the correlation strength between the nodes by using a graph attention network, identifying abnormal transaction correlation patterns, and calculating a transaction suspiciousness score based on the node embedding features and the correlation strength; comparing the transaction suspiciousness score with a preset suspiciousness threshold, and triggering a transaction verification process when the transaction suspiciousness score exceeds the preset suspiciousness threshold; taking transaction features as environmental states, constructing a hierarchical verification means action space based on a knowledge graph, constructing a relationship edge set by calculating similarity measurement values and dependency relationship values between verification means nodes, realizing adaptive division of security levels according to dynamic security scores of the verification means nodes, calculating comprehensive utility values of verification combinations by node unit cost and associated conflict cost, constructing a reinforcement learning-based adaptive verification strategy generator, executing a verification combination output by the adaptive verification strategy generator, and obtaining a verification result; when the verification is passed, releasing the transaction, and when the verification is not passed, rejecting the transaction and pushing a risk reminder to the user.

[0023] In an optional implementation, constructing the user identifier, payment device and payee as nodes, and constructing payment behavior as edges to generate a transaction relationship graph comprises: constructing user identifier information as a first type of node, constructing payment device information as a second type of node, and constructing payee information as a third type of node; using transaction time, transaction amount and transaction type as payment behavior information, and constructing directed edges between the first type of node or the second type of node and the third type of node according to the payment behavior information, wherein the starting point of the directed edge is the node initiating payment, the end point of the directed edge is the node receiving payment, and the corresponding payment behavior information is labeled on the directed edge; ​A node adjacency matrix is constructed to represent the connection relationship between the first type of nodes, the second type of nodes and the third type of nodes, the rows and columns of the node adjacency matrix correspond to different types of nodes respectively, and the matrix elements represent whether there is a directed edge connection between nodes; an edge attribute matrix is constructed to store the payment behavior information on the directed edge, the edge attribute matrix has the same dimension as the node adjacency matrix, and the matrix elements record the transaction time, transaction amount and transaction type of the corresponding directed edge; and a topology structure of a transaction relationship graph is generated based on the node adjacency matrix and the edge attribute matrix.

[0024] The application provides a method for constructing a transaction relationship graph, which constructs user identification, payment devices and payees as nodes, and payment behavior as edges, to generate a transaction relationship graph for facilitating transaction data analysis and risk monitoring.

[0025] In the embodiment, first, the transaction data is preprocessed to extract user identification information, payment device information and payee information. The user identification information can include user ID, user name, ID number, etc.; the payment device information can include device ID, device type, device MAC address, etc.; and the payee information can include merchant ID, merchant name, merchant category, etc.

[0026] In constructing the transaction relationship graph, the user identification information is constructed as the first type of nodes, each user corresponds to a node, and the node attributes include user ID, user name and other information. For example, user Zhang corresponds to node attributes {user ID: "U001", user name: "Zhang"}; the payment device information is constructed as the second type of nodes, each payment device corresponds to a node, and the node attributes include device ID, device type and other information. For example, Zhang's mobile device corresponds to node attributes {device ID: "D001", device type: "smartphone", MAC address: "00:11:22:33:44:55"}; and the payee information is constructed as the third type of nodes, each payee corresponds to a node, and the node attributes include merchant ID, merchant name and other information. For example, a supermarket corresponds to node attributes {merchant ID: "M001", merchant name: "a supermarket", merchant category: "retail"}.

[0027] For each transaction, extract the transaction time, transaction amount, and transaction type as payment behavior information. A directed edge is constructed between the first type of node or the second type of node and the third type of node. The starting point of the directed edge is the node that initiates the payment, and the ending point of the directed edge is the node that receives the payment. The corresponding payment behavior information is labeled on the directed edge. For example, if Zhang uses his mobile phone to pay 100 yuan for daily necessities at a supermarket on July 10, 2023, at 10:30, a directed edge can be constructed between the user node "U001" or the device node "D001" and the merchant node "M001". The edge attribute is {transaction time: "2023-07-10 10:30:00", transaction amount: "100", transaction type: "daily necessities purchase"}.

[0028] To effectively store and process the transaction relationship graph, a node adjacency matrix is constructed to represent the connection relationship between the first type of node, the second type of node, and the third type of node. The rows and columns of the node adjacency matrix correspond to different types of nodes, and the matrix elements represent whether there is a directed edge connection between nodes. Assuming there are 3 user nodes (U001, U002, U003), 2 device nodes (D001, D002), and 4 merchant nodes (M001, M002, M003, M004), a 9x9 node adjacency matrix can be constructed. In this matrix, if there is a transaction relationship between user U001 and merchant M001, the element value at the corresponding position in the matrix is 1, otherwise it is 0.

[0029] At the same time, an edge attribute matrix is constructed to store the payment behavior information on the directed edge. The edge attribute matrix has the same dimensions as the node adjacency matrix, and the matrix elements record the transaction time, transaction amount, and transaction type of the corresponding directed edge. In the above 9x9 matrix, if there is a transaction between user U001 and merchant M001, the element value at the corresponding position in the matrix is the attribute information of the transaction, such as {transaction time: "2023-07-10 10:30:00", transaction amount: "100", transaction type: "daily necessities purchase"}.

[0030] When there are multiple transactions between the same pair of nodes, a transaction list can be stored in the corresponding element of the edge attribute matrix, and each transaction record contains the transaction time, transaction amount, and transaction type. For example, user U001 has multiple transactions at different times at a supermarket M001, and the corresponding edge attribute is the transaction record list: [{transaction time: "2023-07-10 10:30:00", transaction amount: "100", transaction type: "daily necessities purchase"}, {transaction time: "2023-07-15 16:45:00", transaction amount: "150", transaction type: "food purchase"}].

[0031] Based on the node adjacency matrix and the edge attribute matrix, the topology of the transaction relationship graph can be generated. By traversing the node adjacency matrix, the connection relationship between nodes is determined; through the edge attribute matrix, the transaction information on each edge is obtained. For example, the node adjacency matrix indicates that user U001 has a transaction relationship with merchants M001 and M002, while the edge attribute matrix provides detailed information of these transactions, including transaction time, amount and type.

[0032] To enhance the expression ability of the transaction relationship graph, the nodes and edges can be visualized. For example, different types of nodes can be represented by different shapes or colors: user nodes are represented by blue circles, device nodes are represented by green squares, and merchant nodes are represented by red triangles. The thickness of the edge can represent the size of the transaction amount, and the color of the edge can represent the difference of the transaction type. Through this visualization method, the structure and characteristics of the transaction network can be intuitively displayed.

[0033] By constructing the transaction relationship graph, the consumption patterns of users, the usage habits of devices, and the association relationships between merchants can be discovered. For example, if multiple users often use the same device to pay for the same merchant at the same time period, it indicates that there is an association between these users, or the device is shared by multiple people. These information has important value for risk control, marketing promotion and user portrait.

[0034] In an optional implementation, the association strength between nodes is modeled using a graph attention network, and an abnormal transaction association pattern is identified. The transaction suspiciousness score is calculated based on the node embedding features and the association strength, including: An initial feature vector is configured for a node in the transaction relationship graph, and the initial feature vector is input into a feature transformation matrix to obtain a transformed feature. The transformed features corresponding to adjacent nodes are spliced and input into an attention vector to generate an attention coefficient between the node pair. The attention coefficient is normalized to obtain an attention weight, and the node features are aggregated and updated based on the attention weight to obtain an attention feature of the node. The attention feature sequence of the user's historical transactions is extracted, the attention coefficient between the user-device nodes is multiplied by the negative exponential decay value of the transaction time interval to obtain the user-device association strength; the attention coefficient between the user-cashier nodes is weighted and summed with the logarithmic normalized value of the transaction amount to obtain the user-cashier association strength; the cosine similarity of the attention features between the device-cashier nodes is multiplied by the attention coefficient to obtain the device-cashier association strength; and the three kinds of association strength are spliced and input into a fully connected layer to obtain a multi-dimensional fusion feature vector. The difference between the correlation strength of the current transaction and the average correlation strength of the user historical transaction is calculated, and the difference is divided by the standard deviation to obtain a time sequence anomaly score; the structural anomaly score is obtained by calculating the probability distribution information entropy of the three correlation strengths; the time sequence anomaly score, the structural anomaly score and the multi-dimensional fusion feature vector are spliced and input into a three-layer fully connected network, and a transaction suspiciousness score is obtained through a Sigmoid function mapping.

[0035] The embodiment provides an abnormal transaction identification method based on a graph attention network, which models the correlation strength between nodes in a transaction relationship graph, identifies abnormal transaction correlation patterns, and calculates a transaction suspiciousness score.

[0036] In practical applications, a transaction relationship graph is first constructed, which includes user nodes, device nodes and payee nodes. Each node in the transaction relationship graph is configured with an initial feature vector. The initial features of a user node can include user age, registration duration, transaction frequency, etc.; the initial features of a device node can include device type, operating system version, number of installed applications, etc.; and the initial features of a payee node can include merchant category, registered capital, operation duration, etc. Taking a user node as an example, its initial feature vector can be represented as a vector of length 64, of which the first 10 dimensions represent user basic attributes and the last 54 dimensions represent user behavior features.

[0037] The above initial feature vector is input into a feature transformation matrix for linear transformation to obtain a transformed feature. The feature transformation matrix has a dimension of 64x32, and through the transformation, the initial feature is mapped from 64 dimensions to 32 dimensions. For adjacent node pairs, their transformed features are spliced to form a 64-dimensional vector, which is then input into an attention vector to generate attention coefficients between the node pairs. The attention vector has a dimension of 64, and by calculating the inner product of the spliced feature and the attention vector, a scalar value representing the importance of the association between the two nodes can be obtained.

[0038] The attention coefficients are normalized, and a softmax function is used to convert the attention coefficients from the same source node to each target node into attention weights with a sum of 1. Then, the node features are weighted and aggregated based on the attention weights, and are processed through a nonlinear activation function (such as ReLU) to obtain the attention features of the nodes. Through the iteration of multiple layers of graph attention networks, the node embedding representation fused with local structural information is finally obtained.

[0039] In the transaction relationship graph, the attention feature sequence formed by the user's historical transactions is extracted. For the user A's 10 historical transactions, a 32-dimensional attention feature vector is generated for each transaction, forming a 10x32 feature matrix. When calculating the association strength between the user-device nodes, the attention coefficients between the user-device nodes are multiplied by the negative exponential decay value of the transaction time interval and then summed. For example, the attention coefficients of the last 3 transactions of user A and device D1 are 0.8, 0.75, and 0.7, respectively, and the corresponding transaction time intervals are 1 day, 5 days, and 10 days, respectively. The time decay values are 0.905, 0.607, and 0.368, respectively. The calculated association strength is 0.8x0.905+0.75x0.607+0.7x0.368=1.272.

[0040] When calculating the association strength between the user-customer nodes, the attention coefficients between the user-customer nodes are weighted and summed with the log-normalized values of the transaction amounts. Assuming that the attention coefficients of the last 3 transactions of user A and merchant M1 are 0.6, 0.65, and 0.55, respectively, and the corresponding transaction amounts are 100 yuan, 200 yuan, and 500 yuan, respectively, the log-normalized values are 0.2, 0.3, and 0.5, respectively. The association strength is 0.6x0.2+0.65x0.3+0.55x0.5=0.5175.

[0041] When calculating the association strength between the device-customer nodes, the cosine similarity of the attention features between the device-customer nodes is multiplied by the attention coefficient. For example, the cosine similarity of the attention features between device D1 and merchant M1 is 0.85, and the attention coefficient is 0.7. The association strength is 0.85x0.7=0.595.

[0042] The three association strengths are concatenated into a vector [1.272, 0.5175, 0.595], which is input into a fully connected layer with an input dimension of 3 and an output dimension of 8 to obtain a multi-dimensional fusion feature vector.

[0043] The time series anomaly score is obtained by calculating the difference between the current transaction's association strength and the user's historical transaction association strength mean, and dividing the difference by the standard deviation. For example, the user A's historical transaction user-device association strength mean is 1.25, the standard deviation is 0.15, and the current transaction's association strength is 0.9. The time series anomaly score is (0.9-1.25) / 0.15=-2.33, indicating that the current transaction deviates significantly from the user's historical pattern of using the device.

[0044] The probability distribution information entropy of the three correlation strengths is calculated to obtain a structural anomaly score. For the transaction network of user A, if the entropy value of the user-device correlation strength is 0.8, the entropy value of the user-cashier correlation strength is 0.65, and the entropy value of the device-cashier correlation strength is 0.75, then the structural anomaly score is (0.8+0.65+0.75) / 3=0.73, and a higher entropy value indicates a complex transaction relationship structure and the presence of anomalies.

[0045] The time sequence anomaly score, the structural anomaly score, and the multi-dimensional fusion feature vector are spliced to form a 10-dimensional vector, which is input into a three-layer fully connected network. The input dimension of the first layer is 10, and the output dimension is 16; the input dimension of the second layer is 16, and the output dimension is 8; the input dimension of the third layer is 8, and the output dimension is 1. Finally, the output is mapped to between 0 and 1 through a Sigmoid function to obtain a score representing the suspicious degree of the transaction. If the score exceeds a preset threshold of 0.7, the transaction is determined to be suspicious, triggering a further risk review process.

[0046] Figure 2 For performance comparison and analysis of different technical solutions, the schematic diagram is as follows: As shown in the figure, in terms of accuracy, the application achieves a high-precision recognition ability of 95.3%, which is significantly better than the 85.7% of the traditional fixed configuration method and the 75.4% of the simple greedy algorithm, and embodies the excellent performance of the algorithm in identifying complex patterns. In the detection speed test, the application also performs well, leading the traditional fixed configuration method of 68.5% and the simple greedy algorithm of 62.7% with a high efficiency of 86.2%, proving that the optimized computing framework can effectively reduce processing delay. The most significant advantage is in the resource occupancy rate index, which requires only 35.6% of the system resources, far lower than the 67.3% of the traditional fixed configuration method and the 72.8% of the simple greedy algorithm, which can handle larger-scale data loads in actual deployment environments while reducing hardware costs.

[0047] In an optional implementation, the transaction features are taken as environment states, a hierarchical verification means action space is constructed based on a knowledge graph, a relationship edge set is constructed by calculating similarity measurement values and dependency relationship values between verification means nodes, adaptive division of security levels is realized according to dynamic security scores of the verification means nodes, and a comprehensive utility value of verification combination is calculated by node unit cost and associated conflict cost, including: The verification means knowledge graph is constructed, and the verification means knowledge graph includes a verification means node set and a relationship edge set; Based on the feature vector of the verification means node, the similarity measure value between nodes is obtained by weighting the cosine similarity of the feature vector and the overlap degree of the applicable scene set, and the dependency value is calculated based on the co-occurrence times of the verification means node in the historical verification data, and the similarity measure value and the dependency value are taken as the weight of the relationship edge set; According to the basic security score of the verification means node and the weight information of the relationship edge set, the dynamic security score of the verification means node is calculated by combining the historical performance score and the adaptability score of the verification means in different scenes, and the verification means node is dynamically divided into different security levels based on the dynamic security score; The cost budget constraint model is established for the verification means nodes of different security levels, the unit cost of the verification means node is calculated based on the resource consumption cost, and the conflict cost is calculated based on the conflict information between nodes obtained through the relationship edge set, and the unit cost and the conflict cost are integrated to obtain the combination utility value under the condition of meeting the budget constraint.

[0048] In this embodiment, the adaptive verification strategy for transaction security is realized by constructing a hierarchical verification means action space based on a knowledge graph. This method takes transaction features as environmental states, constructs a relationship edge set by calculating the similarity measure value and the dependency value between verification means nodes, and realizes adaptive division of security levels according to the dynamic security score of the verification means node, so as to calculate the comprehensive utility value of the verification combination through the unit cost of the node and the associated conflict cost.

[0049] When constructing the verification means knowledge graph, the verification means node set and the relationship edge set need to be defined. The verification means node set includes various verification methods, such as identity card OCR verification, face recognition, bank card four-element verification, mobile phone number three-element verification, etc. Each verification means node includes node ID, name, type, applicable scene set, basic security score, resource consumption cost and other attributes. For example, the attributes of the face recognition node include: node ID "KYC002", name "face recognition", type "identity verification", applicable scene set ["account opening verification", "large amount transfer", "sensitive operation confirmation"], basic security score 85 points, resource consumption cost 0.5 yuan per time.

[0050] To calculate the similarity measure value between the nodes of the verification means, first, the feature vector of each node is extracted. The feature vector is composed of multiple dimensions such as the technical type of the verification means, the verification dimension, the implementation method, etc. Taking the identity card OCR verification and face recognition as an example, their feature vectors are extracted respectively. The identity card OCR verification feature vector can be represented as identity verification class, image recognition technology, and static feature extraction; the face recognition feature vector can be represented as identity verification class, biometric technology, and dynamic feature extraction. By calculating the cosine similarity of the two feature vectors, the technical similarity is 0.6. At the same time, the overlap degree of the application scenario set of the two is calculated, such as both are applicable to the "account opening verification" scenario, and the scene overlap degree is 0.4. The technical similarity and the scene overlap degree are weighted and averaged according to the weight of 6:4, and the final similarity measure value between the nodes is 0.52.

[0051] The calculation of the dependency value is based on the statistical co-occurrence times of the verification means nodes based on historical verification data. For example, in 10,000 recorded transaction verifications, identity card OCR verification and face recognition co-occur 7,000 times, and their co-occurrence frequency is 0.7. Further, in these 7,000 co-occurrences, 6,300 times are first performing identity card OCR verification and then performing face recognition, accounting for 90% of the total number of co-occurrences, so the dependency value from identity card OCR verification to face recognition is 0.63 (i.e. 0.7 x 0.9). The similarity measure value and the dependency value are used as the weight of the relationship edge set to construct a complete verification means knowledge graph.

[0052] The calculation of the dynamic security score considers the basic security score of the verification means node, the weight information of the relationship edge set, the historical performance score, and the adaptability score. The historical performance score is calculated according to the accuracy, coverage, fraud interception rate, etc. of the verification means in the past period of time. Taking face recognition as an example, assuming that in the last 10,000 uses, the accurate recognition rate is 98% and the fraud interception rate is 95%, the historical performance score is calculated as 96.5 points. The adaptability score measures the adaptability of the verification means to the current transaction scenario, such as for the non-first login high-frequency small amount transfer scenario, the adaptability score of face recognition is 75 points. Combined with the basic security score of 85 points of face recognition and the weight information of the relationship edge associated with it, the dynamic security score of the face recognition node is calculated as 82.3 points.

[0053] Based on the dynamic security score, the verification means nodes are divided into different security levels. Assuming that the security level threshold is set as: 90 points or more for A level (high security), 80-90 points for B level (medium-high security), 70-80 points for C level (medium security), 60-70 points for D level (basic security), and 60 points or less for E level (low security). According to the dynamic security score of 82.3 points of the face recognition mentioned above, it is divided into B level security level.

[0054] A cost budget constraint model is established for the verification means nodes of different security levels. First, the unit cost of each verification means node is calculated, including technical resource consumption, time cost and user experience impact. Taking face recognition as an example, the resource consumption cost is 0.5 yuan per time, the average time consumption is 5 seconds, and the user experience impact score is medium (converted to a numerical value of 0.3), and the unit cost is 0.65.

[0055] The calculation of conflict cost is based on the conflict information between nodes obtained from the relationship edge set. For example, if both face recognition and voiceprint recognition are selected as biometric verification methods, the user's operation burden will increase, and the user experience will decrease. According to the conflict degree of 0.4 between the two nodes recorded in the relationship edge set, the conflict cost of using the combination of the two verification means is calculated to be 0.26.

[0056] When integrating the unit cost and the conflict cost, the budget constraint condition needs to be met. Assuming that the current transaction risk score is 75 points, and the verification cost budget set for this risk level is 1.5 yuan. For a feasible verification combination scheme: identity card OCR verification (unit cost 0.3) + face recognition (unit cost 0.65) + SMS verification code (unit cost 0.2), the total unit cost is 1.15 yuan, which meets the budget constraint. Considering that the total conflict cost between the three verification means is 0.15, the final comprehensive utility value of the verification combination is 1.3 (i.e. 1.15+0.15), which is lower than the budget upper limit of 1.5 yuan, so this verification combination scheme can be adopted.

[0057] Through the above detailed implementation steps, the hierarchical verification means action space based on the knowledge graph is constructed, and the optimal verification combination can be adaptively selected according to the transaction characteristics, which not only ensures the transaction security, but also controls the verification cost.

[0058] In an optional implementation, a cost budget constraint model is established for the verification means nodes of different security levels, the unit cost is calculated based on the resource consumption cost of the verification means nodes, and the conflict cost is calculated through the conflict information between nodes obtained from the relationship edge set. The unit cost and the conflict cost are integrated to obtain a combination utility value under the condition of meeting the budget constraint, including: The calculation resource consumption, memory resource consumption and time consumption of the verification means node are respectively assigned to corresponding weights and the weighted sum is calculated to obtain a unit resource cost. The security level cost coefficient is calculated according to the security level to which the verification means node belongs, and the unit resource cost is multiplied by the security level cost coefficient to obtain the node basic cost of each verification means node. The resource overlap degree is calculated by counting the proportion of the commonly used resources among the nodes in the total resources of the nodes, and the conflict intensity between the nodes is obtained by multiplying the resource overlap degree by a preset conflict weight. The conflict intensity is calculated for each pair of the selected nodes and accumulated to obtain the accumulated conflict cost. A global budget upper limit and hierarchical budget upper limits of different security levels are set as budget constraints, and it is determined whether the sum of the node base costs and the accumulated conflict cost meets the budget constraints. The security score, performance score and user experience score of each node that meets the budget constraints are calculated, and the corresponding weights are assigned to the security score, performance score and user experience score to obtain the node utility value. The combination utility value of the combination of the nodes is obtained by subtracting the accumulated conflict cost from the node utility value.

[0059] In a multi-security level verification method combination optimization system, a cost budget constraint model is established for different security level verification method nodes, and the implementation method of calculating the combination utility value based on the model can be described as follows: First, the verification graph data containing multiple verification method nodes and their relationship edges are received, and each verification method node has attribute parameters such as computing resource consumption, memory resource consumption and time consumption. For each verification method node, the unit cost is calculated based on its resource consumption, and the conflict information is obtained through the relationship edges between the nodes to calculate the conflict cost. The optimal combination is obtained under the condition of meeting the budget constraints.

[0060] For the unit resource cost calculation of the verification method node, the weight of the computing resource consumption is set to 0.4, the weight of the memory resource consumption is set to 0.3, and the weight of the time consumption is set to 0.3. Taking a face recognition verification method as an example, the computing resource consumption is 500 CPU units, the memory resource consumption is 200 MB, and the time consumption is 300 ms. The weighted unit resource cost is calculated as: 500x0.4+200x0.3+300x0.3=350 units. According to the security level to which the verification method belongs, the security level cost coefficient is determined. If the verification method belongs to the high security level, the security level cost coefficient is set to 1.5; if it belongs to the medium security level, the security level cost coefficient is set to 1.2; and if it belongs to the low security level, the security level cost coefficient is set to 1.0. Assuming that the face recognition belongs to the medium security level, the node base cost is: 350x1.2=420 units.

[0061] The conflict between the verification means nodes is evaluated. Taking face recognition and fingerprint recognition as examples, if both use image processing units and share 100 units of computing resources, and the total amount of computing resources of both is 600 units; share 50MB of memory resources, and the total amount of memory resources of both is 300MB; share 80ms of time resources, and the total amount of time resources of both is 500ms. The calculation resource overlap is 100 / 600=0.167, the memory resource overlap is 50 / 300=0.167, and the time resource overlap is 80 / 500=0.16. Set the calculation resource conflict weight to 0.5, the memory resource conflict weight to 0.3, and the time resource conflict weight to 0.2, then the conflict intensity between the two nodes is: 0.167×0.5+0.167×0.3+0.16×0.2=0.1655. If 5 verification means nodes have been selected, the conflict intensity between the 5 nodes needs to be calculated, and the cumulative conflict cost is 5.8 units.

[0062] The global budget upper limit is set to 2000 units, the high security level budget upper limit is 1000 units, the medium security level budget upper limit is 700 units, and the low security level budget upper limit is 300 units. Assuming that the sum of the node basic costs of the selected verification means nodes is 1500 units, the sum of the cumulative conflict costs is 200 units, and the total cost is 1700 units. The total cost is less than the global budget upper limit of 2000 units, and the costs of each security level are: high security level 800 units, medium security level 600 units, and low security level 100 units, which do not exceed the corresponding hierarchical budget upper limit, so the budget constraint condition is met.

[0063] For the verification means combination that meets the budget constraint condition, the utility value is further evaluated. Taking a fingerprint recognition verification means as an example, the security score is 85 points (full score 100 points), the performance score is 75 points, and the user experience score is 70 points. Set the security weight to 0.5, the performance weight to 0.3, and the user experience weight to 0.2, and the node utility value is calculated as: 85×0.5+75×0.3+70×0.2=79 points. Assuming that the cumulative conflict cost of the fingerprint recognition and other selected verification means is 2.5 points, the contribution of the combination utility value is: 79-2.5=76.5 points.

[0064] The combination utility value is calculated for all verification means combinations that meet the budget constraint, and the combination with the highest combination utility value is selected as the optimal verification combination. For example, combination A includes face recognition, fingerprint recognition, and password verification, with a combination utility value of 210 points; combination B includes face recognition, voiceprint recognition, and SMS verification, with a combination utility value of 195 points; and combination C includes iris recognition, fingerprint recognition, and dynamic password, with a combination utility value of 225 points. After comparison, combination C is selected as the optimal verification combination.

[0065] Through the above technical implementation, under the condition of meeting different security level budget constraints, the resource consumption, security, performance, and user experience of the verification means are comprehensively considered, and the conflict between the verification means is also considered, to obtain the optimal verification means combination, thereby improving security and user experience.

[0066] Figure 3 The following is a comparison diagram of verification combination utility values under different budget constraints: This diagram directly shows the utility value performance of three different verification means combination strategies under each budget constraint. The horizontal axis represents the budget constraint from 500 to 2600 cost units, and the vertical axis is the combination utility value (0-350). Different shapes are used to identify the three methods in the diagram: circles represent the present scheme (cost budget constraint model), squares represent the fixed combination scheme, and triangles represent the greedy selection scheme. From the trend, all methods show a diminishing marginal utility as the budget increases. The present scheme always maintains a significant leading advantage, with a utility value of 305 when the budget is 1700 units, which is an increase of 74.3% and 35.6% compared to the fixed combination scheme of 175 and the greedy selection scheme of 225, respectively. It is worth noting that when the budget exceeds 2000 units, the utility values of the three methods tend to grow flat, indicating that the combination of verification means has reached saturation. The advantage of the present scheme lies in its innovative establishment of a cost budget constraint model for multiple security level verification means, which comprehensively considers the unit resource cost, security level cost coefficient, conflict cost caused by resource overlap, and the security, performance, and user experience scores of each verification means. This all-around optimization method can maximize the overall utility of the verification combination under limited budget, providing a more efficient verification strategy selection scheme for practical application scenarios.

[0067] In an optional implementation, an adaptive verification strategy generator based on reinforcement learning is constructed, and the verification combination output by the adaptive verification strategy generator is executed to obtain a verification result, which includes: The transaction feature vector, user portrait feature vector, and scene context feature vector are spliced to form an environment state representation vector, which is linearly transformed by an encoding weight matrix and processed by an activation function to obtain a state code. According to the state code, a plurality of security level verification means sets are divided, the selection state of each verification means is composed into an action vector, the action vector is set with a total selection quantity constraint and a selection quantity constraint in different security levels, and a candidate verification means combination set satisfying the constraint condition is generated; The state code is input into an Actor network and a Critic network at the same time, the Actor network performs feature extraction on the state code through a multi-layer perception structure to generate a selection probability distribution of each combination of the candidate verification means combination set; the Critic network adopts a double-layer neural network structure, the first layer performs dimension reduction mapping on the state code, and the second layer outputs a state value evaluation score to obtain a value score corresponding to the current state code; According to the selection probability distribution, each combination of the candidate verification means combination set is sorted, and a verification means combination with the highest value score is selected as an optimal verification strategy output to obtain a verification result.

[0068] The embodiment provides a reinforcement learning-based adaptive verification strategy generation method, which dynamically generates an optimal verification strategy according to different states of a transaction environment by constructing an adaptive verification strategy generator, thereby improving transaction security and optimizing user experience.

[0069] In an actual application scenario, first, environment state information of a current transaction is acquired, including a transaction feature vector, a user portrait feature vector and a scene context feature vector. The transaction feature vector contains transaction amount, transaction time, transaction type and the like; the user portrait feature vector contains user historical behavior, credit score, transaction frequency and the like; and the scene context feature vector contains device information, IP address, geographic location and the like. For example, for a cross-region transfer transaction with an amount of 5000 yuan, the transaction feature vector [5000, 1, 3] (indicating the amount, type code and time period code) is acquired, the user portrait feature vector [85, 120, 4] (indicating the credit score, monthly transaction frequency and user level) is acquired, and the scene context feature vector [2, 0, 1] (indicating the device type, IP risk level and geographic location anomaly marker) is acquired.

[0070] The above three types of feature vectors are spliced to form an environment state representation vector, for example, [5000, 1, 3, 85, 120, 4, 2, 0, 1]. The vector is linearly transformed through a preset coding weight matrix, if the dimension of the environment state representation vector is 9 and the dimension of the coded state is 64, then the dimension of the coding weight matrix is 9*64. The result of linear transformation is processed through a ReLU activation function to obtain a state code. For example, after the initial environment state representation vector is processed through the coding weight matrix and the activation function, a 64-dimensional state code vector is obtained.

[0071] According to the state encoding vector, a set of verification means of multiple security levels is divided. In this embodiment, the verification means are divided into three security levels: low-level security verification (such as SMS verification code, fingerprint recognition), medium-level security verification (such as face recognition, secret question), and high-level security verification (such as video liveness detection, contact confirmation). Each security level contains multiple verification means, for example, low-level security verification contains 3 means, medium-level security verification contains 4 means, and high-level security verification contains 3 means, a total of 10 verification means. The selection state (0 means not selected, 1 means selected) of each verification means is composed into an action vector, for example, [0, 1, 0, 1, 0, 0, 0, 0, 1, 0] means that the 2nd, 4th and 9th verification means are selected.

[0072] The total selection number constraint and the selection number constraint within different security levels are set for the action vector. For example, the total selection number constraint is 2 to 4 verification means, at least 1 low-level security verification, at most 2 medium-level security verification, and at most 1 high-level security verification. Based on these constraints, a set of candidate verification means combinations that meet the conditions is generated. For the above 10 verification means and constraint conditions, the generated candidate combinations include: [1, 0, 0, 1, 0, 0, 0, 0, 0, 0], [1, 0, 0, 0, 1, 0, 0, 0, 1, 0], [0, 1, 0, 1, 0, 1, 0, 0, 0, 0], etc.

[0073] The state encoding is input into the Actor network and the Critic network at the same time. The Actor network adopts a multi-layer perceptron structure, including an input layer, two hidden layers and an output layer. The input layer receives a 64-dimensional state encoding; the first hidden layer contains 128 neurons and uses a ReLU activation function; the second hidden layer contains 64 neurons and uses a ReLU activation function; the output layer has a dimension equal to the number of candidate verification means combinations, and uses a Softmax activation function to generate a selection probability distribution of each combination. For example, if there are 20 candidate combinations, the output layer is a 20-dimensional vector representing the probability of selecting each combination.

[0074] The Critic network adopts a two-layer neural network structure, the first layer performs dimension reduction mapping on the 64-dimensional state encoding, contains 32 neurons, and uses a ReLU activation function; the second layer is a single neuron output layer, which directly outputs a state value evaluation score representing the value score of the current state. For example, for a given state encoding, the Critic network outputs a value score of 7.5.

[0075] According to the selection probability distribution output by the Actor network, each combination in the candidate verification method combination set is sorted. For example, the selection probability of combination A is 0.3, the selection probability of combination B is 0.25, and the selection probability of combination C is 0.2, and the sorting result is A > B > C. The verification method combination with the highest selection probability is selected as the optimal verification strategy output. In actual deployment, the exploration strategy is combined to randomly select a combination with a probability other than the highest probability to enhance the exploration ability.

[0076] The selected optimal verification strategy is executed, and the corresponding verification method combination is presented to the user, for example, "please complete the SMS verification code verification and face recognition". After the user completes the verification, the verification result is obtained, including whether the verification is passed, the user response time, the operation trajectory and other information. These results will be used as reward signals for reinforcement learning to update the Actor network and the Critic network, and to continuously optimize the verification strategy generation capability.

[0077] Through the above method, the optimal verification strategy can be dynamically generated according to the risk characteristics of different transaction scenarios, while ensuring transaction security, minimizing user operation burden and improving overall user experience.

[0078] The payment fraud real-time identification and disposal system based on machine learning in the embodiment of the application comprises: A first unit is configured to obtain a user identifier, extract historical payment device records and historical payee information of the user from a user historical behavior database based on the user identifier; A second unit is configured to construct the user identifier, the payment device and the payee as nodes, construct the payment behavior as edges, generate a transaction relationship graph, perform feature embedding on the nodes in the transaction relationship graph, model the association strength between the nodes by using a graph attention network, identify an abnormal transaction association mode, and calculate a transaction suspiciousness score based on the node embedding features and the association strength; A third unit is configured to compare the transaction suspiciousness score with a preset suspiciousness threshold, and trigger a transaction verification process when the transaction suspiciousness score exceeds the preset suspiciousness threshold; A fourth unit is configured to use transaction features as an environment state, construct a hierarchical verification method action space based on a knowledge graph, construct a relationship edge set by calculating similarity measurement values and dependency relationship values between verification method nodes, realize adaptive division of security levels according to dynamic security scores of the verification method nodes, calculate a comprehensive utility value of a verification combination by using node unit cost and associated conflict cost, construct a reinforcement learning-based adaptive verification strategy generator, execute a verification combination output by the adaptive verification strategy generator, and obtain a verification result; A fifth unit is configured to release the transaction when the verification is passed, and reject the transaction and push a risk reminder to the user when the verification is not passed.

[0079] In a third aspect, the present application provides an electronic device, comprising: a processor; a memory for storing processor-executable instructions; wherein the processor is configured to invoke the instructions stored in the memory to perform the method described above.

[0080] In a fourth aspect, the present application provides a computer-readable storage medium having stored thereon computer program instructions, which when executed by a processor, implement the method described above.

[0081] The present application can be a method, apparatus, system, and / or computer program product. Computer program products can include computer-readable storage media having computer-readable program instructions loaded thereon for performing various aspects of the present application.

[0082] Finally, it should be noted that: the above embodiments are only used to illustrate the technical solutions of the present application, and not to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand: it can still modify the technical solutions recorded in the foregoing embodiments, or make equivalent replacement for part or all of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the scope of the technical solutions of the embodiments of the present application.

Claims

1. A method for real-time identification and handling of payment fraud based on machine learning, characterized in that, include: Obtain the user identifier, and based on the user identifier, extract the user's historical payment device records and historical payee information from the user's historical behavior database; User identifiers, payment devices, and payees are constructed as nodes, and payment behaviors are constructed as edges to generate a transaction relationship graph; feature embedding is performed on the nodes in the transaction relationship graph; the association strength between nodes is modeled using a graph attention network to identify abnormal transaction association patterns, and transaction suspicion scores are calculated based on node embedding features and association strength. The transaction suspicion score is compared with a preset suspicion threshold. When the score exceeds the preset suspicion threshold, the transaction verification process is triggered. By treating transaction features as environmental states, a hierarchical verification action space is constructed based on a knowledge graph. A set of relational edges is built by calculating the similarity and dependency values ​​between verification method nodes. An adaptive classification of security levels is achieved based on the dynamic security scores of verification method nodes. The comprehensive utility value of the verification combination is calculated by the unit cost of nodes and the cost of association conflicts. An adaptive verification strategy generator based on reinforcement learning is constructed, and the verification combination output by the adaptive verification strategy generator is executed to obtain the verification result. The transaction is allowed when the verification is successful, and the transaction is rejected and a risk warning is sent to the user when the verification fails.

2. The method according to claim 1, characterized in that, By constructing user identifiers, payment devices, and payees as nodes, and payment actions as edges, a transaction relationship graph is generated, including: User identification information is constructed as the first type of node, payment device information is constructed as the second type of node, and payee information is constructed as the third type of node; Using transaction time, transaction amount, and transaction type as payment behavior information, directed edges are constructed between the first type of node or the second type of node and the third type of node based on the payment behavior information. The starting point of the directed edge is the node that initiates the payment, and the ending point of the directed edge is the node that receives the payment. The corresponding payment behavior information is marked on the directed edge. A node adjacency matrix is ​​constructed to represent the connection relationships between the first type of nodes, the second type of nodes, and the third type of nodes. The rows and columns of the node adjacency matrix correspond to different types of nodes, and the matrix elements indicate whether there are directed edges connecting the nodes. An edge attribute matrix is ​​constructed to store payment behavior information on the directed edges. The edge attribute matrix has the same dimension as the node adjacency matrix, and the matrix elements record the transaction time, transaction amount, and transaction type of the corresponding directed edge. A topological structure of the transaction relationship graph is generated based on the node adjacency matrix and the edge attribute matrix.

3. The method according to claim 1, characterized in that, Graph attention networks are used to model the strength of associations between nodes, identify abnormal transaction association patterns, and calculate transaction suspicion scores based on node embedding features and association strength, including: An initial feature vector is configured for each node in the transaction relationship graph. The initial feature vector is input into a feature transformation matrix to obtain transformed features. The transformed features corresponding to adjacent nodes are concatenated and input into an attention vector to generate attention coefficients between node pairs. The attention coefficients are normalized to obtain attention weights. The node features are aggregated and updated based on the attention weights to obtain the attention features of the nodes. The attention feature sequence of user's historical transactions is extracted. The user-device association strength is obtained by multiplying the attention coefficient between user-device nodes by the negative exponential decay value of the transaction time interval and summing the results. The user-payee association strength is obtained by weighted summing the attention coefficient between user-payee nodes by the log normalized value of the transaction amount. The device-payee association strength is obtained by multiplying the cosine similarity of the attention features between device-payee nodes by the attention coefficient. The three association strengths are concatenated and input into a fully connected layer to obtain a multidimensional fusion feature vector. The difference between the correlation strength of the current transaction and the average correlation strength of the user's historical transactions is calculated. The difference is divided by the standard deviation to obtain the temporal anomaly score. The information entropy of the probability distribution of the three correlation strengths is calculated to obtain the structural anomaly score. The temporal anomaly score, structural anomaly score and multidimensional fusion feature vector are concatenated and input into a three-layer fully connected network. The transaction suspicion score is obtained by mapping through the Sigmoid function.

4. The method according to claim 1, characterized in that, Treating transaction characteristics as environmental states, a hierarchical verification action space is constructed based on a knowledge graph. A set of relational edges is built by calculating similarity and dependency values ​​between verification method nodes. An adaptive classification of security levels is achieved based on the dynamic security scores of the verification method nodes. The comprehensive utility value of the verification combination is calculated using node unit cost and association conflict cost, including: Construct a knowledge graph of verification methods, wherein the knowledge graph of verification methods includes a set of verification method nodes and a set of relation edges; Based on the feature vectors of the verification method nodes, a similarity measure between nodes is obtained by weighting the cosine similarity of the feature vectors with the overlap of the applicable scenario set. At the same time, a dependency value is calculated based on the number of co-occurrences of the verification method nodes based on historical verification data. The similarity measure and the dependency value are used as the weights of the relation edge set. Based on the basic security score of the verification method node and the weight information of the relation edge set, combined with the historical performance score and adaptability score of the verification method in different scenarios, the dynamic security score of the verification method node is calculated, and the verification method node is dynamically divided into different security levels based on the dynamic security score. A cost budget constraint model is established for verification method nodes with different security levels. The unit cost is calculated based on the resource consumption cost of the verification method nodes. At the same time, the conflict cost is calculated through the conflict information between nodes obtained by the relation edge set. The unit cost and conflict cost are integrated and the combined utility value is obtained under the condition of satisfying the budget constraint.

5. The method according to claim 4, characterized in that, A cost budget constraint model is established for verification method nodes with different security levels. The unit cost is calculated based on the resource consumption cost of the verification method nodes. Simultaneously, the conflict cost is calculated using the inter-node conflict information obtained from the relational edge set. The unit cost and conflict cost are integrated, and a combined utility value is obtained under the condition of satisfying budget constraints, including: The computational resource consumption, memory resource consumption, and time consumption of the verification method node are assigned corresponding weights and the weighted sum is calculated to obtain the unit resource cost. The security level cost coefficient is calculated according to the security level to which the verification method node belongs. The unit resource cost is multiplied by the security level cost coefficient to obtain the node base cost of each verification method node. The computational resources, memory resources, and time resources used by the verification method nodes are statistically analyzed. The proportion of shared resources to the total resources of the nodes is calculated to obtain the resource overlap. The resource overlap is multiplied by a preset conflict weight to obtain the conflict intensity between the nodes. The conflict intensity is calculated for each selected verification method node and the cumulative conflict cost is obtained. Set a global budget cap and tiered budget caps for each security level as budget constraints, and determine whether the sum of the basic costs of the nodes and the sum of the cumulative conflict costs satisfy the budget constraints. For verification method nodes that meet the budget constraints, calculate their security score, performance score, and user experience score respectively. Assign corresponding weights to the security score, performance score, and user experience score respectively and calculate the weighted sum to obtain the node utility value. Subtract the accumulated conflict cost from the node utility value to obtain the combined utility value of the verification combination.

6. The method according to claim 1, characterized in that, Construct an adaptive verification policy generator based on reinforcement learning, execute the verification combination output by the adaptive verification policy generator, and obtain the verification results, including: The transaction feature vector, user profile feature vector, and scene context feature vector are acquired and concatenated to form an environment state representation vector. The environment state representation vector is then linearly transformed through an encoding weight matrix and processed by an activation function to obtain a state code. The verification method sets for multiple security levels are divided according to the state code. The selection state of each verification method is composed into an action vector. The overall selection quantity constraint and the selection quantity constraint within different security levels are set for the action vector to generate a set of candidate verification method combinations that meet the constraints. The state code is simultaneously input into the Actor network and the Critic network. The Actor network extracts features from the state code using a multilayer perceptron structure to generate the selection probability distribution of each combination in the candidate verification method combination set. The Critic network adopts a two-layer neural network structure. The first layer performs dimensionality reduction mapping on the state code, and the second layer outputs the state value evaluation score to obtain the value score corresponding to the current state code. The candidate verification method combination set is sorted according to the selection probability distribution, and the verification method combination with the highest value score is selected as the optimal verification strategy output to obtain the verification result.

7. A machine learning-based real-time payment fraud identification and handling system, used to implement the method as described in any one of claims 1-6, characterized in that, include: The first unit is used to obtain a user identifier and, based on the user identifier, extract the user's historical payment device records and historical payee information from the user's historical behavior database. The second unit is used to construct user identifiers, payment devices, and payees as nodes, and payment behaviors as edges to generate a transaction relationship graph; to embed features into the nodes in the transaction relationship graph; to model the correlation strength between nodes using a graph attention network, to identify abnormal transaction correlation patterns, and to calculate the transaction suspicion score based on node embedding features and correlation strength. The third unit is used to compare the transaction suspicion score with a preset suspicion threshold. When the score exceeds the preset suspicion threshold, the transaction verification process is triggered. The fourth unit is used to treat transaction features as environmental states, construct a hierarchical verification action space based on a knowledge graph, build a set of relational edges by calculating similarity and dependency values ​​between verification method nodes, achieve adaptive classification of security levels based on the dynamic security scores of verification method nodes, calculate the comprehensive utility value of verification combinations by node unit cost and association conflict cost, construct an adaptive verification strategy generator based on reinforcement learning, execute the verification combinations output by the adaptive verification strategy generator, and obtain verification results. The fifth unit is used to allow transactions when verification is successful, and to reject transactions and send risk warnings to users when verification fails.

8. An electronic device, characterized in that, include: processor; Memory used to store processor-executable instructions; The processor is configured to invoke instructions stored in the memory to execute the method according to any one of claims 1 to 6.

9. A computer-readable storage medium having computer program instructions stored thereon, characterized in that, When the computer program instructions are executed by the processor, they implement the method described in any one of claims 1 to 6.

Citation Information

Patent Citations

  • Fraud behavior detection method and device based on associated fraud perception

    CN116662982A

  • Transaction risk judgment method and device, equipment and storage medium

    CN116883000A

  • Anti-fraud transaction identification method and system based on artificial intelligence

    CN118070141A

  • Real-time anti-fraud detection system for digital financial transaction

    CN119090518A

  • Hidden high-risk group mining method and system based on heterogeneous graph attention network

    CN119202918A