Risk control method and system for financial association network, and electronic equipment
By performing graph modeling and graph computation on financial data, abnormal risk patterns in financial relationship networks are identified, solving the problems of untimely risk detection and inaccurate identification in existing technologies, and achieving efficient risk control of complex financial relationship networks.
Patent Information
- Application Number
- CN202610216105.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-02-14
- Publication Date
- 2026-05-15
AI Technical Summary
Existing financial risk control measures are insufficient to effectively identify and warn of covert, coordinated, and persistent fraudulent activities that rely on the structural characteristics of networks, resulting in delayed risk perception, inaccurate pattern recognition, and insufficient overall risk identification coverage and response timeliness.
Graph modeling is performed on multiple heterogeneous financial data sources to generate financial relationship attribute graphs. Graph computing algorithms such as community discovery, path discovery, and centrality calculation are used to identify abnormal risk graph patterns, generate risk warning information, and perform visualization rendering and interactive operations.
It enables global risk identification of financial networks, improves the timeliness and accuracy of risk identification, and can discover collaborative and hidden risks that traditional methods cannot capture, thereby improving the efficiency and depth of audits and investigations.
Smart Images

Figure CN122048554A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the technical field of financial risk management, and more specifically, to a risk control method, system, and electronic device for financial interconnected networks. Background Technology
[0002] In corporate financial activities, key processes such as procurement payments, expense reimbursements, and marketing expense settlements generally involve multiple stakeholders, multiple nodes, and multiple paths of fund movement, forming a complex and dynamically evolving financial network. This network not only reflects the linear flow of funds but also implies deeper relationships such as implicit collaboration, vested interests, and coordinated behavior among stakeholders. Some organized and systematic financial fraud is not carried out based on a single, explicit abnormal transaction, but rather is deeply embedded in and relies on this network, achieving concealment, decentralization, and structured cover-up of fraudulent intentions through cross-stakeholder, cross-cycle, and cross-business scenario collaborative operations.
[0003] Currently, mainstream financial risk prevention and control methods mainly include three categories: First, single-point compliance audit based on preset rules, which means that auditors or automated systems independently determine the authenticity, completeness, and compliance of a single transaction based on predetermined thresholds or logical conditions; second, individual behavior anomaly identification based on statistical models, which uses specific subjects (such as employees, suppliers, or departments) as the unit of analysis and identifies outliers that significantly deviate from the baseline pattern by modeling their historical behavior sequences; and third, relational query methods based on traditional relational databases (SQL), which mainly use table join operations at a limited level to mine shallow, static, explicit, and enumerable relationships.
[0004] However, the aforementioned technical methods typically use "transaction instances" or "isolated entities" as the basic analytical granularity, making it difficult to effectively identify and warn of covert, coordinated, and persistent fraudulent activities that rely on network structural characteristics. As a result, existing financial risk control systems suffer from lagging risk perception and inaccurate pattern recognition when facing complex interconnected networks. Overall risk identification coverage and response timeliness are significantly insufficient, posing a serious challenge to prevention and control effectiveness. Summary of the Invention
[0005] The purpose of this invention is to provide a risk control method, system, and electronic device for financial networks, so as to alleviate the technical problems of insufficient timeliness of risk detection and low accuracy of identification in the prior art.
[0006] In a first aspect, embodiments of the present invention provide a risk control method for financial relationship networks, comprising: performing graph modeling on financial entity and financial relationship data from multiple heterogeneous financial data sources to generate a financial relationship attribute graph; wherein the nodes of the financial relationship attribute graph are the financial entities and the edges are the financial relationships, and both the nodes and edges have types and attributes; determining an abnormal risk graph pattern based on the financial relationship attribute graph using a graph computation algorithm; wherein the graph computation algorithm includes: a community detection algorithm, a path detection algorithm, and / or a centrality calculation algorithm; and generating risk warning information based on the abnormal risk graph pattern; wherein the risk warning information includes the type of the abnormal risk graph pattern, the identification information of the corresponding nodes and edges, and a risk score.
[0007] In some optional implementations, the above method further includes: visually rendering the generated risk warning information and associated graph structure, and displaying it on a graph analysis interface; in response to a first operation instruction on a target node in the graph structure, obtaining and displaying detailed attribute information of the target node from the financial association attribute graph; and in response to a second operation instruction on a target node in the graph structure, obtaining and displaying a neighbor relationship network of a specified degree centered on the target node from the financial association attribute graph.
[0008] In some alternative implementations, the aforementioned financial entities include at least two of employees, suppliers, companies, bank accounts, and invoices; the aforementioned financial relationships include at least one of reimbursement, payment, invoicing, and account ownership.
[0009] In some alternative implementations, graph modeling and the generation of financial relationship attribute graphs can be performed by using a distributed graph computing engine to store and compute the aforementioned financial relationship attribute graphs.
[0010] In some optional implementations, graph computation algorithms are used to determine anomalous risk graph patterns, including: identifying closely related internal communities that characterize gang fraud using the community discovery algorithm described above; and / or identifying closed-loop transaction paths that characterize fund returns using the path discovery algorithm described above; and / or identifying key bridging nodes that characterize anomalous intermediaries using the centrality computation algorithm described above.
[0011] In some alternative implementations, the community detection algorithm mentioned above is either the Louvain algorithm or the label propagation algorithm; the centrality calculation algorithm mentioned above is either the PageRank algorithm or the betweenness centrality algorithm.
[0012] In some optional implementations, based on the aforementioned financial relationship attribute graph, anomaly risk graph patterns are determined using graph computation algorithms, including: applying one or more graph computation algorithms to the aforementioned financial relationship attribute graph to determine at least one anomaly risk graph pattern; wherein the application of one or more graph computation algorithms includes: periodically executing the aforementioned graph computation algorithms on the aforementioned financial relationship attribute graph in batch mode; and / or performing local graph pattern matching on the incrementally updated aforementioned financial relationship attribute graph in real-time mode.
[0013] Secondly, embodiments of the present invention provide a risk control system for a financial relationship network, comprising: a graph data processing module, used to perform graph modeling on financial entity and financial relationship data from multiple heterogeneous financial data sources to generate a financial relationship attribute graph; wherein the nodes of the financial relationship attribute graph are the financial entities and the edges are the financial relationships; a graph engine calculation module, used to determine an abnormal risk graph pattern based on the financial relationship attribute graph using a graph calculation algorithm; wherein the graph calculation algorithm includes: a community detection algorithm, a path detection algorithm, and / or a centrality calculation algorithm; and a risk warning generation module, used to generate risk warning information based on the abnormal risk graph pattern; wherein the risk warning information includes the type of the abnormal risk graph pattern, the identification information of the corresponding nodes and edges, and a risk score.
[0014] Thirdly, embodiments of the present invention provide an electronic device, including a memory and a processor, wherein the memory stores a computer program that can run on the processor, and the processor executes the computer program to implement the steps of any of the methods described in the first aspect.
[0015] Fourthly, embodiments of the present invention provide a computer-readable storage medium storing computer-executable instructions, which, when invoked and executed by a processor, cause the processor to perform the method described in any of the first aspects above.
[0016] This invention provides a risk control method, system, and electronic device for financial interconnected networks. The method includes: graph modeling financial entities and relationships from multiple heterogeneous financial data sources to generate a financial interconnected attribute graph where nodes and edges each have types and attributes; identifying abnormal risk graph patterns based on this graph using graph computation algorithms such as community detection, path detection, or centrality calculation; and generating risk warning information based on the identified patterns, including pattern type, unique identifiers of corresponding nodes and edges, and a risk score quantified based on graph structure features. This method upgrades the risk control paradigm from isolated transactions to interconnected networks, solving the technical problems of insufficient timeliness and low accuracy in risk detection in existing technologies, and improving the timeliness and accuracy of identifying systemic financial risks. Attached Figure Description
[0017] To more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings used in the embodiments of the present invention will be briefly introduced below. It should be understood that the following drawings only show some embodiments of the present invention and should not be regarded as a limitation on the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.
[0018] Figure 1 A flowchart illustrating a risk control method for a financial network provided in an embodiment of the present invention; Figure 2 A schematic diagram of the structure of a risk control system for a financial network provided in an embodiment of the present invention; Figure 3 A flowchart illustrating another risk control method for financially related networks provided in an embodiment of the present invention; Figure 4 This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present invention. Detailed Implementation
[0019] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the present invention will be clearly and completely described below in conjunction with the embodiments. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0020] Currently, mainstream financial risk control methods mainly include: single-point auditing based on preset rules, which involves manual or system-based compliance checks on individual transactions according to established standards; anomaly identification based on statistical models, which establishes benchmark models based on the historical behavior of specific entities to identify significant deviations; and traditional relational database queries, which analyze shallow explicit relationships through table joins at limited levels. These methods typically use individual transactions or independent entities as the unit of analysis, making it difficult to effectively identify coordinated fraudulent activities based on network structure characteristics. This leads to problems such as delayed identification and inaccurate positioning in existing risk control systems, posing a serious challenge to the overall effectiveness of risk prevention and control.
[0021] Based on this, the present invention provides a risk control method, system and electronic device for financial networks to solve the technical problems of insufficient timeliness of risk detection and low accuracy of identification in the prior art.
[0022] To facilitate understanding of this embodiment, a risk control method for a financial network disclosed in this invention will first be described in detail. (See also...) Figure 1The diagram illustrates a risk control method for a financial network, which can be executed by an electronic device and mainly includes the following steps S102 to S106: Step S102 involves performing graph modeling on financial entity and financial relationship data from multiple heterogeneous financial data sources to generate a financial association attribute graph.
[0023] In the financial relationship attribute graph, the nodes are financial entities and the edges are financial relationships. Both nodes and edges have types and attributes.
[0024] Heterogeneous financial data sources can be raw data from internal business systems such as ERP, HR, expense control, and SRM, as well as from external authoritative platforms such as industry and commerce, judiciary, and credit reporting. Before entering graph modeling, the entity identities (such as employees and suppliers) and interactive behaviors (such as reimbursement and payment) contained in these data have not yet been uniformly identified and structurally associated.
[0025] Graph modeling can be performed by: uniquely normalizing the entities in the original data and explicitly abstracting the identifiable business interactions between them as typed edges; thereby, isolated records scattered across various systems are organized into a connected graph structure with a unified ID space, traceable origin, and support for type filtering and attribute querying. This structure can be directly used as the input object for subsequent graph computation algorithms (step S104), ensuring that the communities, paths, or central nodes identified by the algorithm can all be traced back to specific data sources, entity instances, and relational contexts.
[0026] In one embodiment, the aforementioned financial entity may include at least two of the following: employees, suppliers, companies, bank accounts, and invoices; the aforementioned financial relationship may include at least one of the following: reimbursement, payment, invoicing, and account ownership.
[0027] In one embodiment, the method of graph modeling and generating a financial relationship attribute graph in step S102 above may include: storing and computing the financial relationship attribute graph using a distributed graph computing engine. Preferably, the distributed graph computing engine is Spark GraphX.
[0028] Step S104: Based on the financial relationship attribute graph, determine the abnormal risk graph pattern through graph computation algorithm; Graph computation algorithms can include community detection algorithms, path detection algorithms, and / or centrality calculation algorithms. Anomaly risk graph patterns can refer to subgraph configurations with interpretable risk control semantics explicitly carried by the graph structure's own topological features. Their existence itself represents a networked trace of a typical type of financial fraud. This pattern is not a threshold judgment result based on single-point data, but rather a quantitative identification result of global structural attributes such as inter-node connectivity, path closure, and locational hub function. Therefore, it can cover collaborative and hidden risks that traditional methods cannot capture.
[0029] In one embodiment, determining anomaly risk graph patterns using graph computation algorithms may include: identifying closely related internal communities that characterize gang fraud using community discovery algorithms; and / or identifying closed-loop transaction paths that characterize fund returns using path discovery algorithms; and / or identifying key bridging nodes that characterize anomalous intermediaries using centrality computation algorithms.
[0030] As a specific example, the community detection algorithm mentioned above can be the Louvain algorithm or the Label Propagation Algorithm (LPA); the centrality calculation algorithm mentioned above can be the PageRank algorithm or the betweenness centrality algorithm.
[0031] Specifically, the structured results output by each of the above algorithms (such as community partition sets, shortest closed-loop path sequences, and lists of highly central nodes) can be mapped to corresponding risk graph pattern instances and bound to their predefined detection strategies. For example, "the frequency of reimbursements between employees and a single supplier in a community exceeding the threshold" triggers a gang fraud strategy, and "the cumulative payment amount in a closed-loop path reaching the warning line" triggers a fund return strategy. This binding relationship ensures that the pattern type, node / edge identifier, and risk score contained in the risk warning information generated in step S106 all originate from the same graph structure analysis process, maintaining the integrity and verifiability of the technology chain.
[0032] In another embodiment, determining the abnormal risk graph pattern based on the financial association attribute graph using a graph computation algorithm may include: applying one or more graph computation algorithms to the financial association attribute graph to determine at least one abnormal risk graph pattern.
[0033] The application of one or more graph computation algorithms may include: periodically executing graph computation algorithms on financial association attribute graphs in batch mode; and / or performing local graph pattern matching on incrementally updated financial association attribute graphs in real-time mode.
[0034] Specifically, the batch processing mode outputs stable and high-confidence risk patterns for the entire graph structure, supporting periodic audits and model iterations; the real-time mode focuses on local structural disturbances caused by newly injected nodes / edges, reusing only existing calculation results and performing lightweight re-evaluation, thereby ensuring the timeliness of the S106 warning while maintaining consistency with the graph structure built in step S102. That is, regardless of the mode, the identified pattern instances carry the node identifiers, edge identifiers, and attribute snapshots from the original graph, ensuring that risk tracing is traceable and warnings are locatable.
[0035] Step S106: Generate risk warning information based on the abnormal risk map pattern; The risk warning information includes the type of abnormal risk graph pattern, the corresponding node and edge identification information, and the risk score.
[0036] The types of abnormal risk graph patterns can include structured subgraph categories with clear risk control semantics identified by the graph calculation algorithm in step S104, such as: closely related internal communities, closed-loop transaction paths, highly bridging intermediary nodes, etc. These types directly correspond to typical systemic risk forms such as gang fraud, fund loops, and abnormal intermediaries, ensuring that the warning results have business interpretability.
[0037] The identification information of the corresponding nodes and edges may include the unique node identifiers and edge identifiers defined in the financial association attribute graph constructed in step S102, which point to all entities and relationships contained in the specific pattern instance output in step S104 (such as 5 nodes and 4 payment edges in a certain fund loop path), thereby anchoring the abstract algorithm result to the real business object.
[0038] Risk scores can be quantified based on graph structure features. Specifically, the score is not calculated independently, but rather inherits and integrates the original structural indicators (such as edge density within the community, total path length and monetary weighting, and node betweenness centrality score) output by the algorithm in step S104. After normalization and policy weighting, the score is generated to ensure that the score corresponds strictly one-to-one with the pattern type and the nodes / edges involved, and can be dynamically recalculated as the graph structure is updated.
[0039] In another embodiment, the above method may further include: visually rendering the generated risk warning information and the associated graph structure, and displaying it on the graph analysis interface; in response to a first operation instruction on a target node in the graph structure, obtaining and displaying detailed attribute information of the target node from the financial association attribute graph; in response to a second operation instruction on a target node in the graph structure, obtaining and displaying a neighbor relationship network of a specified degree centered on the target node from the financial association attribute graph.
[0040] Specifically, the graph structure data, node / edge attributes, and highlighted areas upon which the visualization rendering relies all originate from the same financial relationship attribute graph constructed in step S102. All data invoked by interactive operations (viewing details, expanding neighbors) are obtained by querying the latest snapshot of the graph in real time using the node / edge identifiers carried in the alert information. Thus, alerts, visualization, and drill-down share the same graph data foundation, forming a closed-loop analysis chain of identification, presentation, and investigation. This enables risk control personnel to quickly focus from macro-level models to micro-level entities, effectively supporting root cause analysis and decision-making.
[0041] This invention provides a risk control method for financial interconnected networks. It involves graph modeling of financial entities and relationships from multiple heterogeneous financial data sources to generate a financial interconnected attribute graph where nodes and edges each have types and attributes. Based on this graph, and employing graph computation algorithms such as community detection, path discovery, or centrality calculation, abnormal risk graph patterns are identified. Risk warning information is generated based on the identified patterns, including pattern type, unique identifiers of corresponding nodes and edges, and a risk score quantified based on graph structure features. This method upgrades the risk control paradigm from isolated transactions to interconnected networks, solving the technical problems of insufficient timeliness and low accuracy in risk detection in existing technologies, and improving the timeliness and accuracy of identifying systemic financial risks.
[0042] Based on the same inventive concept, this invention also provides a risk control system for financial linkage networks, see [link to relevant documentation]. Figure 2 As shown, the system mainly includes the following parts: The graph data processing module 210 is used to perform graph modeling on financial entity and financial relationship data from multiple heterogeneous financial data sources to generate a financial relationship attribute graph; the nodes of the financial relationship attribute graph are financial entities, and the edges are financial relationships. Graph engine calculation module 220 is used to determine abnormal risk graph patterns based on financial relationship attribute graphs and through graph calculation algorithms; the graph calculation algorithms include: community detection algorithm, path detection algorithm and / or centrality calculation algorithm; The risk warning generation module 230 is used to generate risk warning information based on the abnormal risk graph pattern. The risk warning information includes the type of abnormal risk graph pattern, the corresponding node and edge identification information, and the risk score.
[0043] The risk control system for financially related networks provided in this embodiment of the invention can be specific hardware on a device or software or firmware installed on the device. The system provided in this embodiment of the invention has the same implementation principle and technical effects as the aforementioned method embodiments. For the sake of brevity, any parts not mentioned in the system embodiments can be referred to the corresponding content in the aforementioned method embodiments. Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, units, and processes described above can all be referred to the corresponding processes in the above method embodiments, and will not be repeated here.
[0044] This invention aims to address the fundamental problem that existing financial risk control technologies cannot effectively identify and analyze "relationship-based risks." Existing technologies analyze risks from the perspective of "transactions" or "individuals," lacking a systematic approach that examines all financial activities from a holistic perspective, focusing on "relationships." This results in the inability to detect advanced fraud patterns hidden within complex network structures. Therefore, the technical problem this invention aims to solve is: How can we construct a system capable of uniformly modeling a company's full and heterogeneous financial data into a large-scale relational graph, and automatically extracting predefined or unknown abnormal relational patterns from this graph using advanced graph computing technology? The system needs to have the following functions: 1) Effectively abstract different types of entities such as people, companies, accounts, and invoices, as well as their relationships such as transactions, reimbursements, and invoicing, into nodes and edges of a graph; 2) Utilize a distributed graph computing engine to efficiently execute complex graph algorithms, such as community detection, path search, and centrality calculation; 3) Define and automatically identify various typical financial risk graph patterns, such as fund loops, group fraud, and abnormal intermediaries; 4) Present the discovered risk patterns to risk control personnel in a visual manner and provide drill-down analysis capabilities to reveal systemic and organizational financial risks that are difficult for humans to detect.
[0045] To address the aforementioned technical problems, this invention proposes a method for mining abnormal patterns in financial relationship networks based on graph computing. The core of this method is to construct a property graph of all financial entities and their relationships, and then run a series of graph analysis algorithms on this graph to identify risks. The following detailed explanation is based on an application example of a risk control method for financial relationship networks provided by this invention.
[0046] See Figure 3 The flowchart shown illustrates another risk control method for financial linkage networks. This method mainly includes the following steps S302 to S308: Step S302: Construct a unified financial relationship graph.
[0047] This step is the core of transforming relational data into graph data, and the constructed financial relationship graph is the financial relationship attribute graph in the above embodiment. First, data sources are integrated. Using a data integration platform (such as an ETL tool), various entity and relationship data related to financial activities are extracted from multiple data sources such as ERP, expense control, HR, and business registration information. Then, this data is uniformly loaded into a graph database (such as Neo4j) or a distributed graph computing engine (such as Spark GraphX) to construct a large-scale attribute graph. In this graph, nodes (verticals) represent entities, such as employees, suppliers, companies, bank accounts, invoices, etc. Each node has its own type and attributes (such as employee name, supplier tax ID). Edges represent relationships between entities, such as "reimbursement," "payment," "invoice issuance," "account ownership," etc. Each edge can also have its own type and attributes (such as transaction amount, date).
[0048] Preferably, the data source may include: Financial system (ERP / expense control): retrieves expense reports, payment slips, accounting vouchers, etc., including information such as applicant, payee, amount, date, and invoice number.
[0049] Human Resources (HR) system: Obtains employee information, including name, department, position, date of employment, and even family relationships (used to identify conflicts of interest).
[0050] Supplier Management System (SRM): Obtains basic information about suppliers, including business registration information, bank accounts, and historical cooperation ratings.
[0051] External data: Obtain publicly available data such as business registration information (shareholders, executives) and lists of dishonest persons subject to enforcement through APIs or web crawlers.
[0052] Secondly, the specific implementation of graph modeling (Schema Design) can include defining the node labels and edge types of the graph. Preferably, node labels include: Employee, Supplier, Bank Account, Invoice, Company, etc. Edge types include: APPLIES_FOR (Employee -> Expense Report), PAY_TO (Payment Order -> Bank Account), ISSUED_BY (Invoice -> Supplier), HAS_ACCOUNT (Employee / Supplier -> Bank Account), IS_SHAREHOLDER_OF (Employee -> Company), etc.
[0053] Furthermore, specific implementation methods for ETL and graph data loading may include: writing ETL scripts (such as using Spark) to convert row data extracted from various source systems into graph vertex and edge set files.
[0054] For example, for a single expense report, at least one Employee node, one Supplier node, one Invoice node, and edges such as APPLIES_FOR and INVOICE_FOR between them will be generated. Each node and edge has rich attributes, such as the amount and date attributes of the edge. Finally, these node and edge set files are imported in batches into the target graph platform (e.g., using Neo4j's neo4j-admin import tool, or building GraphX's Graph objects).
[0055] Step S304: Determine the graph query and algorithm for abnormal association patterns.
[0056] On the constructed graph, a series of "graph patterns" are defined to identify potential financial risks. These patterns are identified by combining graph query languages (such as Cypher) and various graph computation algorithms. Typical risk patterns include: Circular Transfer: Using path discovery algorithms (such as shortest path, all paths), we find closed-loop paths where funds originate from an entity, pass through a series of intermediate entities, and ultimately flow back to that entity or its strongly related entities (such as its spouse's account).
[0057] Collusive fraud: This involves using community detection algorithms (such as LPA and Louvain) to identify "small groups" where internal business relationships are much closer than external ones. For example, multiple employees frequently submit expense reports to the same individual supplier.
[0058] Anomaly Brokers: These are nodes that play an unusually critical "bridge" role in a network, identified using centrality algorithms (such as PageRank and BetweennessCentrality). For example, a seemingly ordinary consulting firm might connect a large number of internal employees and external suppliers who would otherwise have no connection.
[0059] This step is crucial for transforming audit experience into computable logic.
[0060] Preferably, the query logic for fund loop detection is as follows: For each large payment (A)-[:PAY_TO]->(B), initiate a variable-length path query to find whether a path (B)-[:PAY_TO] exists. 1..5]->(C), and C has a strong association with A (e.g., (C)-[:HAS_ACCOUNT_OF]->(A) or C is an associated party of A).
[0061] Its algorithm implementation may include: In Neo4j, Cypher queries can be used to query MATCHp=(a)-[:PAY_TO Use `RETURNp` to find all funding loops. In GraphX, path tracing can be achieved through iterative Pregel messaging or multiple Join operations.
[0062] Preferably, the query logic for detecting group fraud is as follows: Construct a bipartite graph, with Employee nodes on one side and Supplier nodes on the other side, where edges represent reimbursement relationships. Then, search for "dense subgraphs" on this graph.
[0063] The algorithm implementation may include running community detection algorithms, such as Louvain Modularity or LabelPropagation Algorithm (LPA). These algorithms can automatically divide the nodes in the graph into different communities. If a community contains multiple Employees and a few (or even one) Suppliers, and the transaction edge density within the community is much higher than that between communities, it is a highly suspicious group.
[0064] Preferably, the query logic for abnormal intermediary detection is as follows: in a graph that contains all payment and transaction relationships, find those "bridge" nodes that connect many unrelated subgraphs.
[0065] The algorithm implementation may include calculating the betweenness centrality of each node in the graph. Betweenness centrality measures the number of times a node appears on the shortest path between all pairs of nodes in the network. A supplier or individual account that is not involved in core business activities, if its betweenness centrality score is abnormally high, is likely to be acting as a conduit for funds or a "front."
[0066] Preferably, various combination rules based on graph topology and node / edge attributes can also be defined, such as "one person with multiple accounts", "one account with multiple people", "abnormal transaction time late at night", and "supplier registration time too short to get a large order".
[0067] Step S306: Perform batch / real-time graph analysis and generate risk warnings.
[0068] The system can operate in two modes: Batch processing mode: Periodically (e.g., daily or weekly) run the mining algorithms for all the above risk patterns on the full graph to generate a comprehensive risk report.
[0069] Real-time / Near Real-time Mode: When a new transaction occurs, it is used as an incremental update to the graph. Then, local, small-scale graph pattern matching is performed only starting from the newly added nodes and edges to enable rapid response to new risks.
[0070] When any risk pattern is successfully matched, the system will generate a structured risk warning, which includes the type of the pattern, all the nodes and edges involved, and a quantified risk score.
[0071] This step involves the practical execution of the mining algorithm.
[0072] Preferably, the batch processing mode can be implemented by using scheduling tools such as Apache Airflow to create a daily DAG (Directed Acyclic Graph) task. This task first triggers incremental data synchronization from the business system to the data lake, then runs a Spark job to incrementally build or fully reconstruct the graph, followed by parallel execution of multiple GraphX algorithms (or sending batch query requests to Neo4j) to discover all defined risk patterns. Finally, all discovered risk instances, along with their risk scores (which can be calculated based on the severity of the pattern, the amount involved, etc.), are stored in a "risk warning database".
[0073] Preferably, the specific implementation of the real-time / near real-time mode can include: utilizing stream processing technologies (such as Flink or Kafka Streams). Transaction data streams from CDC are consumed in real time. When a new transaction (such as a new edge) is generated, it is updated immediately in the in-memory graph or graph database. Then, instead of performing global computation, a local graph query is triggered, for example, only checking whether the participants of the new transaction constitute a new loop or whether it significantly changes the tightness of a community. This approach has low latency but may not discover complex patterns that require a global perspective. In practice, a combination of both modes is usually used.
[0074] Step S308: Visualization and processing of risk warnings.
[0075] The generated risk alerts are presented on a visual graph analysis interface. Risk control personnel can intuitively see the marked abnormal network structures (such as highlighted fund return paths) and also perform interactive operations on the interface, such as drilling down to view the detailed attributes of any node or edge, expanding the N-degree neighbor relationships of a node, etc., to conduct in-depth root cause analysis. Based on the analysis results, risk control personnel can create formal audit cases or take corresponding risk disposal measures.
[0076] This step involves delivering the analysis results and human-computer interaction. Preferably, the specific implementation of this step may include the following process: First, build the visualization interface. Develop a web-based front-end application using a graph visualization library such as D3.js, Cytoscape.js, or G6. This interface will display a risk warning dashboard by default, listing the latest discovered anomaly patterns sorted by risk level.
[0077] Secondly, interactive exploration is conducted. When risk control personnel click on a specific alert item (such as "Detected a 5-node fund loop"), the interface will dynamically render that specific sub-graph.
[0078] Preferably, in a specific example, node / edge information can be displayed. Hovering the mouse over or clicking on any node or edge will bring up its detailed attribute information (such as employee department and position, transaction amount and date). Neighbor expansion can also be performed; for example, right-clicking a node and selecting "Expand First / Second Degree Relationship" dynamically loads and displays more of its neighboring nodes and relationships to explore a broader context. Path highlighting can also be implemented; for fund loops or critical paths, the system will automatically highlight them with different colors and animation effects. Timeline filtering can also be implemented; by providing a time slider, only transactions within a specific time range can be displayed to observe the dynamic evolution of the network structure.
[0079] Secondly, collaboration and handling. Based on the visualization analysis, risk control personnel can perform the following interactive actions: add notes and tags, such as labeling suspicious nodes or relationships with tags like "pending investigation" or "high risk"; create cases, such as packaging the current visualization analysis results along with relevant data into a new audit case with one click and assigning it to specific investigators; generate reports, such as exporting the analysis view as an image or PDF report.
[0080] In summary, this invention elevates the risk control perspective from isolated transactions and entities to a global relational network level, enabling the discovery of systemic and organizational risks hidden within complex relationships that are completely inaccessible to traditional methods. For advanced fraud schemes requiring multi-party collaboration and multi-step operations, such as organized fraud, fund loops, and illicit transfers of benefits, this invention, through graph analysis, clearly exposes their network structure characteristics, significantly enhancing the ability to detect advanced fraud. Furthermore, the visualized graph analysis interface makes complex relationships readily apparent, allowing auditors to conduct exploratory analysis within the graph, quickly locating core nodes and clarifying fund flows, thus improving the efficiency and depth of audits and investigations, and significantly enhancing the efficiency and depth of evidence collection. By solidifying audit experience into computable graph patterns and continuously uncovering new anomaly patterns, a constantly accumulating and evolving corporate financial risk control knowledge base is constructed.
[0081] Based on the same inventive concept, embodiments of the present invention also provide an electronic device, specifically, the electronic device includes a processor and a storage device; the storage device stores a computer program, and the computer program, when run by the processor, executes the method described in any of the above embodiments.
[0082] Figure 4 This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present invention. The electronic device 400 includes: a processor 410, a memory 420, a communication interface 430, and a bus 440. The memory 420 stores machine-readable instructions that can be executed by the processor 410. When the electronic device is running, the processor 410 communicates with the memory 420 through the bus 440. The processor 410 executes the machine-readable instructions to perform the steps of the method described above.
[0083] Specifically, the memory 420 and processor 410 can be general-purpose memory and processor, without any specific limitations. When the processor 410 runs the computer program stored in the memory 420, it can execute the above method.
[0084] Processor 410 may be an integrated circuit chip with signal processing capabilities. In implementation, each step of the above method can be completed by the integrated logic circuitry in the hardware of processor 410 or by instructions in software form. The processor 410 may be a general-purpose processor, including a Central Processing Unit (CPU), a Network Processor (NP), etc.; it may also be a Digital Signal Processor (DSP), an Application Specific Integrated Circuit (ASIC), a Field-Programmable Gate Array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. It can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this invention. The general-purpose processor may be a microprocessor or any conventional processor. The steps of the methods disclosed in the embodiments of this invention can be directly manifested as execution by a hardware decoding processor, or execution by a combination of hardware and software modules in the decoding processor. The software module can reside in a mature storage medium in the art, such as random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, or registers. This storage medium is located in memory 420, and processor 410 reads the information from memory 420 and, in conjunction with its hardware, completes the steps of the above method.
[0085] Corresponding to the above method, this embodiment of the invention also provides a computer-readable storage medium storing machine-executable instructions. When the computer-executable instructions are called and run by a processor, the computer-executable instructions cause the processor to perform the steps of the above method.
[0086] In the embodiments provided by this invention, it should be understood that the disclosed apparatus and method can be implemented in other ways. The apparatus embodiments described above are merely illustrative. For example, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. Furthermore, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Additionally, the displayed or discussed mutual couplings, direct couplings, or communication connections may be through some communication interfaces; indirect couplings or communication connections between devices or units may be electrical, mechanical, or other forms.
[0087] Furthermore, the units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0088] Furthermore, the functional modules in the various embodiments of the present invention can be integrated together to form an independent part, or each module can exist independently, or two or more modules can be integrated to form an independent part.
[0089] It should be noted that if the functionality is implemented as a software module and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this invention, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0090] In this document, relational terms such as first and second are used only to distinguish one entity or operation from another entity or operation, without necessarily requiring or implying any such actual relationship or order between these entities or operations.
[0091] The above description is merely an embodiment of the present invention and is not intended to limit the scope of protection of the present invention. For those skilled in the art, the present invention can have various modifications and variations. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.
Claims
1. A risk control method for financial linkage networks, characterized in that, include: Graph modeling is performed on financial entity and financial relationship data from multiple heterogeneous financial data sources to generate a financial association attribute graph; the nodes of the financial association attribute graph are the financial entities, and the edges are the financial relationships, and both the nodes and edges have types and attributes; Based on the aforementioned financial relationship attribute graph, anomaly risk graph patterns are determined using graph computation algorithms; the graph computation algorithms include: community detection algorithms, path detection algorithms, and / or centrality calculation algorithms. Based on the abnormal risk graph pattern, risk warning information is generated; the risk warning information includes the type of the abnormal risk graph pattern, the corresponding node and edge identification information, and the risk score.
2. The method according to claim 1, characterized in that, The method further includes: The generated risk warning information and associated graph structure are visualized and rendered, and displayed on the graph analysis interface; In response to a first operation instruction on a target node in the graph structure, detailed attribute information of the target node is obtained from and displayed in the financial association attribute graph; In response to a second operation instruction on a target node in the graph structure, a neighbor relationship network of a specified degree centered on the target node is obtained from the financial association attribute graph and displayed.
3. The method according to claim 1, characterized in that, The financial entity includes at least two of the following: employees, suppliers, companies, bank accounts, and invoices; the financial relationship includes at least one of the following: reimbursement, payment, invoicing, and account ownership.
4. The method according to claim 1, characterized in that, Methods for performing graph modeling and generating financial relationship attribute graphs include: using a distributed graph computing engine to store and compute the financial relationship attribute graphs.
5. The method according to claim 1, characterized in that, Anomaly risk graph patterns are determined using graph computation algorithms, including: The community discovery algorithm identifies closely related internal communities that characterize gang fraud. And / or, the path discovery algorithm identifies closed-loop transaction paths that characterize the return of funds; And / or, identify key bridging nodes that characterize anomalous mediators through the centrality computation algorithm.
6. The method according to claim 1, characterized in that, The community detection algorithm is the Louvain algorithm or the label propagation algorithm; the centrality calculation algorithm is the PageRank algorithm or the betweenness centrality algorithm.
7. The method according to claim 1, characterized in that, Based on the financial relationship attribute graph, an abnormal risk graph pattern is determined by a graph computation algorithm, including: applying one or more graph computation algorithms to the financial relationship attribute graph to determine at least one abnormal risk graph pattern; The application of one or more graph computation algorithms includes: periodically executing the graph computation algorithm on the financial association attribute graph in batch mode; and / or performing local graph pattern matching on the incrementally updated financial association attribute graph in real-time mode.
8. A risk control system for a financial network, characterized in that, include: The graph data processing module is used to perform graph modeling on financial entity and financial relationship data from multiple heterogeneous financial data sources, and generate financial relationship attribute graphs. The nodes of the financial relationship attribute graph are the financial entities, and the edges are the financial relationships. The graph engine calculation module is used to determine the abnormal risk graph pattern based on the financial relationship attribute graph through graph calculation algorithms; the graph calculation algorithms include: community detection algorithm, path detection algorithm and / or centrality calculation algorithm. The risk warning generation module is used to generate risk warning information based on the abnormal risk graph pattern; the risk warning information includes the type of the abnormal risk graph pattern, the corresponding node and edge identification information, and the risk score.
9. An electronic device comprising a memory and a processor, wherein the memory stores a computer program executable on the processor, characterized in that, When the processor executes the computer program, it implements the steps of the method described in any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions that, when invoked and executed by a processor, cause the processor to perform the method according to any one of claims 1 to 7.