Transaction behavior identification method, device, equipment, storage medium and program product
By employing a hybrid architecture combining self-attention mechanisms and bidirectional long short-term memory networks, the problem of insufficient local temporal dependence and global feature correlation in transaction data modeling in existing technologies is solved. This enables high-precision, low-false-prone detection of abnormal transaction behavior, improving the model's adaptability and transparency.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- INDUSTRIAL AND COMMERCIAL BANK OF CHINA
- Filing Date
- 2026-03-12
- Publication Date
- 2026-07-07
AI Technical Summary
Existing technologies struggle to simultaneously account for both the local temporal dependence and global feature correlation of transaction data, resulting in limited ability to identify complex and abnormal transaction behavior patterns. Furthermore, they suffer from issues such as insufficient model performance, inadequate ability to handle high-dimensional nonlinear data, class imbalance, poor model interpretability, and weak adaptability to sudden events.
A hybrid architecture combining self-attention mechanism and bidirectional long short-term memory network is adopted. The self-attention mechanism captures global features, which are then input into the bidirectional time series modeling module to extract local time dependencies, generate bidirectional hidden states, and perform classification processing to identify abnormal transaction behavior.
It significantly improves the ability to identify covert abnormal transaction behaviors, achieves high-precision and low-false-probability abnormal transaction behavior detection, enhances the model's ability to perceive sparse abnormal transaction behavior samples, and has dynamic adaptability and interpretability.
Smart Images

Figure CN122347428A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the fields of artificial intelligence and financial technology, and in particular to a method, apparatus, device, storage medium and program product for identifying transaction behavior. Background Technology
[0002] In modern financial systems, with the rapid development of internet finance, electronic transactions have become a core channel for users' daily consumption. However, the diversification and complexity of transaction data have also given rise to new types of abnormal transaction behaviors, such as fraudulent account transactions and unusually large transfers. These abnormal transaction behaviors are often highly concealed, making them difficult to identify using traditional rule-based detection methods, leading to huge economic losses and reputational risks for financial institutions.
[0003] In existing technologies, rule-based detection methods struggle to simultaneously consider both the local temporal dependencies and global feature correlations of transaction data, resulting in limited ability to identify complex and abnormal transaction behavior patterns. Traditional methods rely on manual feature engineering, which is prone to insufficient feature extraction or model overfitting when processing high-dimensional, nonlinear, and multimodal transaction data. Therefore, existing technologies still have significant shortcomings in terms of model performance, data adaptability, real-time performance, and interpretability, making it difficult to meet the demands of financial scenarios for high accuracy, low false alarm rates, and strong robustness, and hindering the identification of novel abnormal transaction behaviors. Summary of the Invention
[0004] This application provides a transaction behavior identification method, apparatus, device, storage medium, and program product to solve the technical problem that the prior art is unable to identify new abnormal transaction behaviors.
[0005] Firstly, this application provides a method for identifying transaction behavior, including:
[0006] Obtain time series data corresponding to the transaction behavior. The time series data includes transaction feature vectors for several time steps.
[0007] By using a self-attention mechanism, features are extracted from the transaction feature vector to generate global features, which contain global dependencies.
[0008] The global features are input into the bidirectional time series modeling module, and the local temporal dependencies of the global features are extracted through forward and backward sequence modeling to generate bidirectional hidden states.
[0009] The bidirectional hidden states are classified to obtain the probability of abnormality in transaction behavior.
[0010] Secondly, this application provides a transaction behavior identification device, comprising:
[0011] The data acquisition module is used to acquire time series data corresponding to transaction behavior. The time series data includes transaction feature vectors for several time steps.
[0012] The feature extraction module is used to extract features from the transaction feature vector through a self-attention mechanism to generate global features, which contain global dependencies.
[0013] The state generation module is used to input global features into the bidirectional time series modeling module, extract the local time dependencies of global features through forward and backward sequence modeling, and generate bidirectional hidden states.
[0014] The classification processing module is used to classify the bidirectional hidden states and obtain the probability of abnormality in the transaction behavior.
[0015] Thirdly, this application provides an electronic device, including: a processor and a memory communicatively connected to the processor;
[0016] The memory stores the instructions that the computer executes;
[0017] The processor executes computer-executable instructions stored in memory to implement any of the methods of the first aspect.
[0018] Fourthly, this application provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, are used to implement the method of any one of the first aspects.
[0019] Fifthly, this application provides a computer program product, including a computer program that, when executed by a processor, implements the method of any one of the first aspects.
[0020] The transaction behavior recognition method, apparatus, device, storage medium, and program products provided in this application solve the performance bottleneck of single models in modeling local temporal dependencies and global feature correlations by combining a self-attention mechanism and a bidirectional long short-term memory network. The self-attention mechanism captures global patterns across time steps by dynamically calculating the weights of each time step in the transaction sequence, while the bidirectional long short-term memory network accurately extracts local temporal dependencies within short periods through forward and backward sequence modeling. The collaborative mechanism enables the model to simultaneously perceive the local features and global patterns of complex abnormal transaction behaviors, thereby significantly improving the ability to identify hidden abnormal transaction behaviors. The hybrid architecture enhances the model's ability to perceive sparse abnormal transaction behavior samples through feature complementarity, solving the performance deficiency problem caused by the single model in traditional methods, and ultimately achieving high-precision and low-false-positive-rate abnormal transaction behavior detection results. Attached Figure Description
[0021] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.
[0022] Figure 1 This is a schematic diagram for detecting abnormal transaction behavior.
[0023] Figure 2 A flowchart illustrating a transaction behavior identification method provided in an embodiment of this application;
[0024] Figure 3 This is a schematic diagram of the structure of a transaction behavior recognition device provided in an embodiment of this application;
[0025] Figure 4 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application.
[0026] The accompanying drawings illustrate specific embodiments of this application, which will be described in more detail below. These drawings and descriptions are not intended to limit the scope of the concept in any way, but rather to illustrate the concept of this application to those skilled in the art through reference to particular embodiments. Detailed Implementation
[0027] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.
[0028] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, storage, use, processing, transmission, provision, disclosure, and application of the relevant data all comply with the relevant laws, regulations, and standards of the relevant countries and regions, have taken necessary confidentiality measures, do not violate public order and good morals, and provide corresponding operation access points for users to choose to authorize or refuse.
[0029] Furthermore, the technical solution involved in this application, which involves big data analysis of user information (including but not limited to personal biometrics, identity data, consumption data, asset data, electronic terminal operation data, etc.) and the use of artificial intelligence technology for automated decision-making, and makes decisions that have a significant impact on personal rights based on the results of automated decision-making, provides users with corresponding operation entry points for users to choose to agree to or reject the results of automated decision-making; if the user chooses to reject, the process will proceed to the expert decision-making process.
[0030] It should be noted that the transaction behavior recognition method, device, equipment, storage medium and program product provided in this application can be used in the fields of artificial intelligence and financial technology, as well as in any field other than artificial intelligence and financial technology. The application fields of the transaction behavior recognition method, device, equipment, storage medium and program product in this application are not limited.
[0031] This application specifically targets the detection of abnormal transaction behavior in financial transactions, specifically deployed in real-time abnormal transaction behavior detection systems of banks, platforms, or financial institutions. With the rapid development of internet finance, electronic transactions have become an indispensable part of the modern financial system. Users complete various operations through mobile devices, online platforms, or smart terminals, resulting in transaction data characterized by high frequency, high dimensionality, non-linearity, and strong time-series dependence. However, the problem of abnormal transaction behavior has also intensified: on the one hand, abnormal transaction behavior is becoming increasingly covert, for example, circumventing traditional rule detection through cross-account linked operations and small-amount exploratory transactions; on the other hand, abnormal transaction behavior patterns are constantly evolving, such as using AI to generate fake transaction data and targeted attacks against specific user groups, making it difficult for existing detection methods to respond in a timely manner.
[0032] In existing technologies, abnormal transaction behavior detection mainly relies on two types of methods: traditional rule engines and machine learning / deep learning models. Figure 1 This is a diagram illustrating the detection of abnormal transaction behavior, such as... Figure 1 As shown, abnormal transaction behavior detection can include: 1. Traditional rule engines: detection based on preset transaction rules (such as transaction amount thresholds, abnormal geographical location, transaction frequency limits, etc.). 2. Traditional machine learning models: such as decision trees, support vector machines, random forests, etc. These models classify transactions by manually extracting features (such as transaction amount, time interval, device fingerprints, etc.).
[0033] However, existing technologies suffer from the following drawbacks: 1. Insufficient model performance: Existing single models struggle to simultaneously consider both the local temporal dependencies and global feature correlations of transaction data, resulting in limited ability to identify complex abnormal transaction behavior patterns. 2. Insufficient ability to handle high-dimensional nonlinear data: Traditional methods rely on manual feature engineering, while deep learning models are prone to insufficient feature extraction or overfitting when processing high-dimensional, nonlinear, and multimodal transaction data. 3. Class imbalance: The proportion of abnormal transaction behavior samples is extremely low (usually <1%), causing model training to favor the majority class, resulting in a high false negative rate and difficulty in effectively identifying sparse abnormal transaction behavior. 4. Poor model interpretability: The black-box nature of deep learning models makes it difficult to meet the requirements of financial regulation for model transparency and compliance, affecting practical deployment. 5. Weak adaptability to sudden events: Existing models lack dynamic adaptability to sudden changes in transaction behavior caused by sudden events, making it difficult to capture new abnormal transaction behavior patterns in a timely manner. 6. High model integration complexity: The training and deployment costs of hybrid models are high, and the collaborative efficiency between sub-models is difficult to optimize, leading to performance bottlenecks in practical applications.
[0034] The transaction behavior recognition method, apparatus, device, storage medium, and program products provided in this application construct a deep learning framework capable of simultaneously capturing the local temporal dependencies and global feature correlations of transaction data through a hybrid architecture that integrates Long Short-Term Memory (LSTM) networks and deep learning models. It utilizes the bidirectional sequence modeling capabilities of LTM networks to extract temporal patterns of transaction behavior, while simultaneously capturing global dependencies across time steps through the self-attention mechanism of deep learning models. This overcomes the shortcomings of single models in long-distance dependency modeling, local feature extraction, and parallel computing efficiency, aiming to solve the aforementioned technical problems of existing technologies.
[0035] The technical solution of this application and how the technical solution of this application solves the above-mentioned technical problems are described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments. The embodiments of this application will now be described with reference to the accompanying drawings.
[0036] Figure 2 This is a flowchart illustrating a transaction behavior identification method provided in an embodiment of this application, as shown below. Figure 2 As shown, the method includes:
[0037] S201. Obtain the time series data corresponding to the transaction behavior.
[0038] In this embodiment of the application, the time series data includes transaction feature vectors for several time steps.
[0039] In one example, the time series data corresponding to a transaction can include multi-dimensional features such as transaction amount, timestamp, and user identity information.
[0040] S202. Through the self-attention mechanism, feature extraction is performed on the transaction feature vector to generate global features.
[0041] In this embodiment of the application, global features include global dependencies.
[0042] In one example, a self-attention mechanism is used to calculate the correlation between time steps in the sequence, generating a global feature representation. For instance, an anomalous amount at a certain time step in time series data may be strongly correlated with abrupt changes in geographical location at subsequent time steps. The self-attention mechanism captures this global pattern through dynamic weight allocation. Specifically, the self-attention mechanism is a feature extraction method that dynamically calculates the correlation between elements in the sequence to assign weights. For example, the amounts and geographical location features at different time steps in time series data are used to generate a global feature representation through weight calculation.
[0043] S203. Input the global features into the bidirectional time series modeling module, extract the local time dependencies of the global features through forward and backward sequence modeling, and generate bidirectional hidden states.
[0044] In one example, global features are input into a bidirectional long short-term memory network to extract local temporal dependencies from both forward and backward time steps. For instance, forward sequence modeling captures anomalous spikes in transaction frequency, while backward sequence modeling identifies patterns of consecutive small, exploratory transactions. Bidirectional time series modeling is a neural network structure that simultaneously captures forward and backward dependencies in time series through both forward and backward sequence modeling. For example, anomalous behavior at transaction time t might be related to transaction patterns at t-1 and t+1.
[0045] S204. Classify the two-way hidden states to obtain the probability of abnormality in the transaction behavior.
[0046] In one example, the hidden state is mapped to either abnormal or non-abnormal transaction behavior categories, typically achieved through a fully connected layer and an activation function. For instance, the hidden state is mapped to a probability value in the [0,1] interval using a sigmoid function.
[0047] In one implementation scenario, time-series data is input into a deep learning model encoder. A self-attention mechanism is used to calculate the correlation between different time steps, and a feedforward neural network is used for feature mapping. For example, for a transaction sequence... The self-attention mechanism calculates each time step The weights of other time steps are used to generate a global feature representation. This is used for subsequent time series modeling. The self-attention mechanism dynamically assigns weights to capture global dependencies by calculating the correlation between each element and other elements in the time series data. For example, transaction time... The monetary characteristics may be related to The geographical location features are strongly correlated. Feedforward neural networks, multi-layered networks composed of linear transformations and non-linear activation functions, are used to perform non-linear mappings of features. For example, they can map the normalized value of transaction amounts to the hidden layer space. Through the collaborative processing of self-attention mechanisms and feedforward neural networks, deep learning model encoders can extract global patterns across time steps from transaction data, enhancing the model's ability to perceive complex and abnormal transaction behaviors.
[0048] The global features Z output by the deep learning model encoder are input into a bidirectional long short-term memory network to extract local temporal dependencies from both the forward and backward time steps. For example, for a global feature sequence... Forward Long Short-Term Memory (LSTM) network computes forward hidden states. Reverse Long Short-Term Memory Network (RSM) computes backward hidden states Ultimately, it merges into a two-way hidden state. Two-way hidden state It incorporates local time dependencies for classification, obtaining the probability of anomalies in trading behavior. A bidirectional long short-term memory network is used to model forward and backward sequences, simultaneously capturing the forward and backward dependencies of the time series. For example, abnormal behavior at trading time t may be related to trading patterns at both t-1 and t+1. Hidden states ( This represents the output of the Long Short-Term Memory (LSTM) network at each time step, containing the temporal characteristics and historical information of the current moment. For example, This represents the cumulative time series pattern from t=1 to t. Bidirectional Long Short-Term Memory (LSTM) networks, through forward and reverse sequence modeling, can more comprehensively extract local temporal dependencies in transaction data, enhancing the model's ability to detect short-cycle abnormal trading behavior.
[0049] For example, after standardization, transaction data is input into a deep learning model encoder, where global features are extracted using a self-attention mechanism and a feedforward neural network. These global features are then input into a bidirectional long short-term memory network, which models local temporal dependencies from both forward and backward time steps. The bidirectional hidden states are classified through fully connected layers, outputting the probability of anomalies in the transaction behavior. The deep learning model is responsible for capturing global patterns across time steps (such as anomalous correlations in long-term transaction behavior), while the bidirectional long short-term memory network focuses on local temporal dependencies (such as patterns in consecutive small-amount exploratory transactions). Together, they optimize the model's ability to identify complex and anomalous transaction behaviors.
[0050] In another implementation scenario, a method for detecting abnormal transaction behavior is proposed by combining a deep learning model encoder and a long short-term memory network model. First, a deep learning model encoder is used to extract global features from the input time-series data. These encoded global features are then input into the long short-term memory network to learn the temporal characteristics of the data more deeply. Finally, a discriminative model is used to classify abnormal transaction behavior.
[0051] Use the time series data corresponding to the transaction behavior as a time series. , of which each It is a d-dimensional feature vector representing the transaction information at time step t. The time series dataset is encoded using a deep learning model. The basic structure of the deep learning model encoder consists of multiple encoding layers, each containing a self-attention mechanism and a feedforward neural network. The self-attention mechanism is calculated as follows:
[0052] Self Attention(x) = Decoder(Encoder(x)), where Encoder() compresses the input time-series data X into a low-dimensional representation; Decoder() recovers the features of the time-series data and maps them to the target space. Through this mechanism, deep learning models can capture the dependencies between different time steps in the input sequence.
[0053] After calculating self-attention at each layer, the time series data is further transformed by a feedforward neural network:
[0054] Z = FFN(x) = MLP(x), where MLP() is a linear layer that requires feature mapping. After processing by a multi-layer deep learning model encoder, global features are obtained. The global features contain long-distance dependencies between time steps in the input sequence.
[0055] The global features Z encoded by the deep learning model are input into a Long Short-Term Memory (LSTM) network, which can extract temporal dependencies from bidirectional sequences. The state update formula for the LTM network is as follows:
[0056]
[0057]
[0058] in, and Let represent the forward hidden state and the backward hidden state of the Long Short-Term Memory network at time step t, respectively. and These represent the forward and backward memory cell states, respectively. By combining information from these two directions, a bidirectional hidden state is obtained, which is used to capture temporal patterns in transaction behavior.
[0059] After the output of the Long Short-Term Memory network, the bidirectional hidden states are classified through a fully connected layer. Assume... This is the last bidirectional hidden state of the Long Short-Term Memory (LSTM) network. It is input into a fully connected layer for discrimination, and the output is the abnormal transaction behavior detection prediction result: Where σ is the sigmoid activation function, and These are the weight matrix and bias term of the fully connected layer, respectively. This indicates whether the time series data at time step t represents abnormal trading behavior.
[0060] The model uses binary cross-entropy loss as its loss function, calculated as follows:
[0061]
[0062] Where N is the number of samples, It's a real label. This is a predicted value. By minimizing the loss function, the model can continuously optimize its parameters to achieve higher accuracy in detecting abnormal trading behavior. By combining deep learning models and long short-term memory network models, it can effectively capture global information and temporal dependencies in time series data, improving the performance of abnormal trading behavior detection. It not only performs well when handling complex, long-span trading data, but also significantly improves the accuracy of abnormal trading behavior detection and reduces false positives.
[0063] For example, the abnormal transaction behavior detection dataset used consists of black samples derived from abnormal transaction behavior data, matched with recent transaction records; and white samples, randomly selected customer transaction records. Each transaction in the dataset contains multiple features, such as transaction amount, transaction time, and cardholder identity information. The relatively low proportion of abnormal transactions in the dataset leads to a significant class imbalance problem. Abnormal transactions account for less than 1% of total transactions. This imbalance may cause traditional classification methods to favor the majority class, thus affecting model performance. To address this issue, oversampling and undersampling techniques are applied during data preprocessing to reduce the negative impact of class imbalance and ensure a more balanced proportion of abnormal transactions in the training data.
[0064] During model training, the data is divided into a training set and a test set. The training set is used to train the model, while the test set is used to test its performance. Cross-validation is employed to enhance the model's generalization ability. This method evaluates various combinations of the training and test sets, ensuring the stability and effectiveness of the proposed model. Considering the high dimensionality of the dataset and its inclusion of time-series information, the data is standardized before being input into the model. This step ensures that the numerical ranges of different features are similar, preventing differences in feature scale from affecting model training.
[0065] Several commonly used metrics were employed, including accuracy (ACC), F1 score, AUC (area under the curve), and recall. These metrics comprehensively describe the model's classification performance, especially in scenarios involving imbalanced classes. Experimental results show that the model based on a Long Short-Term Memory (LSTM) network combined with a deep learning model outperforms all other comparative models on all evaluation metrics. This demonstrates that the combination of LSTM and deep learning provides a powerful advantage in capturing temporal features and global information, enabling it to better detect anomalous trading activity, particularly in the context of imbalanced datasets.
[0066] In another implementation scenario, heterogeneous features such as user behavior data (e.g., device fingerprints, IP addresses, browser types), geographic location information, and social network association data are introduced on top of time-series data to construct a multimodal input framework. A deep learning model encoder performs cross-modal attention fusion on the multimodal data; for example, transaction amounts and device fingerprint features are interacted through a cross-attention mechanism to extract potential cross-modal correlations.
[0067] By introducing multimodal data, the model can more comprehensively capture indirect clues of abnormal transaction behavior (such as multiple abnormal transactions initiated by the same device within a short period of time, sudden changes in geographical location, etc.), making up for the limitations of single transaction features. The introduction of cross-modal attention mechanism further enhances the model's ability to perceive implicit correlations between heterogeneous features. For example, by co-analyzing device fingerprint anomalies and sudden increases in transaction amounts, the accuracy of identifying covert abnormal transaction behavior can be improved.
[0068] In another implementation scenario, a dynamic weight adjustment module is introduced into the self-attention mechanism of the deep learning model to dynamically allocate attention resources based on the feature distribution of real-time transaction data. For example, in scenarios with a sudden increase in transaction amount, the self-attention weights will automatically increase the attention given to the transaction amount feature; in scenarios with abnormal geographical locations, attention will be preferentially allocated to geographical location features. Dynamic weight adjustment is achieved through a learnable gating network, which dynamically adjusts the distribution of attention weights based on the characteristics of the input features (such as variance and entropy).
[0069] This allows the model to flexibly adjust feature focus based on dynamic changes in the transaction scenario. For example, in high-frequency, small-amount exploratory transaction scenarios, it prioritizes capturing abnormal patterns in time intervals and transaction frequency, while in large-amount transfer scenarios, it strengthens the analysis of account correlation and geographical location. This adaptability significantly improves the model's ability to adapt to changing and abnormal transaction behavior patterns, while reducing the consumption of redundant computing resources.
[0070] In another implementation scenario, to address the computational complexity issue of deep learning models in long sequence processing, a lightweight architecture optimization scheme is proposed: (1) a local attention mechanism is adopted, calculating only the attention weights of adjacent time steps to reduce computational load; (2) a channel pruning technique is introduced to dynamically remove redundant feature dimensions based on feature importance; (3) a knowledge distillation technique is used to compress the model size through teacher-student model transfer learning. For example, the self-attention matrix of the original deep learning model is reduced from O( The complexity is reduced to O(n) or O(n log n).
[0071] Through lightweight optimization, the model significantly reduces computational resource consumption while maintaining high accuracy, enabling the real-time abnormal transaction behavior detection system to be deployed on edge devices or low-power servers. For example, local attention mechanisms can reduce the computational overhead of long-sequence transaction data, channel pruning can accelerate the feature extraction process, and knowledge distillation can improve the deployment efficiency of the model, thereby meeting the stringent requirements of financial scenarios for low latency and high throughput.
[0072] In another implementation scenario, an online incremental learning framework is constructed to enable the model to continuously receive new transaction data and dynamically update parameters after deployment. Specifically, this includes: (1) using a sliding time window mechanism to retain only the transaction data from the most recent N days as training samples; (2) introducing a sample importance weighting strategy to assign higher weights to new abnormal transaction behavior samples (such as abnormal patterns caused by sudden events); and (3) adopting a federated learning architecture to collaboratively update model parameters from multiple distributed data sources to avoid single-point data bias. For example, in scenarios of sudden changes in transaction behavior, the model can quickly adapt to new small-amount, high-frequency transaction patterns.
[0073] This enables the model to dynamically adapt, capturing the evolution of abnormal transaction patterns in real time, such as quickly adjusting detection rules in the event of new types of fraudulent transactions or abnormal transactions in supply chain finance. The combination of sliding windows and federated learning also ensures a balance between data privacy protection and global generalization ability, thereby enhancing the model's ability to defend against unknown abnormal transaction behaviors.
[0074] In another implementation scenario, an interpretability enhancement module is introduced at the model output stage to achieve visual analysis of risk features through the following techniques: (1) generating a heatmap of key features of the transaction sequence using the attention weights of the deep learning model, such as highlighting the timestamp or amount of abnormal transactions; (2) quantifying the contribution of each feature to the probability of abnormal transaction behavior; and (3) constructing a risk feature knowledge graph to map the abnormal transaction behavior patterns detected by the model to predefined risk labels. For example, the correlation between a sudden change in the geographical location of a transaction and an abnormal device fingerprint can be intuitively displayed through the heatmap.
[0075] This significantly improves the transparency and compliance of the model, enabling staff to intuitively understand the model's decision-making logic. For example, feature heatmaps can quickly locate key clues to abnormal trading behavior, and risk tag knowledge graphs can assist in manual review, thereby reducing false positive rates.
[0076] The transaction behavior recognition method provided in this embodiment solves the performance bottleneck of single models in modeling local temporal dependencies and global feature correlations by combining a self-attention mechanism and a bidirectional long short-term memory network. The self-attention mechanism captures global patterns across time steps by dynamically calculating the weights of each time step in the transaction sequence, while the bidirectional long short-term memory network accurately extracts local temporal dependencies within short periods through forward and backward sequence modeling. The collaborative mechanism enables the model to simultaneously perceive the local features and global patterns of complex abnormal transaction behaviors, thereby significantly improving the ability to identify hidden abnormal transaction behaviors. The hybrid architecture enhances the model's ability to perceive sparse abnormal transaction behavior samples through feature complementarity, solving the performance deficiency problem caused by the single model in traditional methods, and ultimately achieving high-precision and low-false-positive-rate abnormal transaction behavior detection results.
[0077] Optionally, the self-attention weights of each time step in the time series data are calculated using a self-attention mechanism to generate initial global features; then, the initial global features are nonlinearly mapped using a feedforward neural network to generate global features.
[0078] In one example, the correlation between time steps in the transaction sequence is calculated using self-attention weights to generate initial global features. For example, transaction time... The amount and Geographical locations may form strong correlations through weighted calculations. A feedforward neural network performs a non-linear mapping on the global feature representation; for example, using fully connected layers and the ReLU activation function to transform features to the hidden space, outputting the encoded global features. The self-attention weights are dynamically assigned by calculating the correlation between each element in the time series data and other elements to capture global dependencies. For example, transaction times... The monetary characteristics may be related to There is a strong correlation between the geographical location features. A feedforward neural network, a multi-layered network composed of linear transformations and non-linear activation functions, is used to perform non-linear mapping of global features. For example, it maps the normalized value of transaction amounts to the hidden layer space.
[0079] By combining self-attention weights with a feedforward neural network, the model's ability to perceive global patterns across time steps in trading data is enhanced. Self-attention weights can dynamically identify long-term anomalies in capital flows, while the feedforward neural network improves the expressive power of features through nonlinear mapping, thereby improving the accuracy of identifying complex and abnormal trading behaviors.
[0080] Optionally, the initial global features are nonlinearly mapped using a feedforward neural network to generate global features, including: performing a linear transformation on the initial global features to generate intermediate features; and processing the intermediate features using a nonlinear activation function to generate global features.
[0081] In one example, a weighted sum of the global feature representations is performed using a linear transformation to generate intermediate features. These intermediate features are then processed using a non-linear activation function, such as setting negative values to zero to enhance sparsity, ultimately outputting the encoded global features. The linear transformation involves linearly combining the input features with a weight matrix and a bias term. For example, the normalized transaction amount is weighted and summed with a timestamp feature. The non-linear activation function introduces non-linear characteristics to enhance the model's expressive power.
[0082] By combining linear transformations and nonlinear activation functions, the model's ability to model nonlinear features in transaction data is enhanced. Linear transformations can extract the linear correlation between transaction amount and timestamp, while nonlinear activation functions improve the discriminative power of features by introducing sparsity, thereby further optimizing the accuracy of abnormal transaction behavior detection.
[0083] Optionally, in classifying the bidirectional hidden states to obtain the probability of abnormal trading behavior, the method further includes: oversampling the time series data to generate synthetic abnormal trading behavior samples; and enhancing the features of the abnormal trading behavior samples through a self-attention mechanism to generate enhanced global features.
[0084] In one example, abnormal transaction behavior samples in the original financial transaction data are oversampled to generate new abnormal transaction behavior samples. A self-attention mechanism is then used to enhance the features of the synthesized abnormal transaction behavior samples, such as calculating the correlation weights between transaction amount and geographical location, and outputting the enhanced global features. Oversampling increases the number of minority class samples through synthesis techniques, for example, by generating new abnormal transaction behavior samples through interpolation. Feature enhancement strengthens the feature correlations between samples through the attention mechanism, for example, assigning higher weights to the transaction amount and geographical location features of the synthesized abnormal transaction behavior samples.
[0085] By employing a combined approach of oversampling and feature enhancement, the negative impact of class imbalance in transaction data on model training is mitigated. The generation of synthetic anomalous transaction behavior samples expands the training dataset, while feature enhancement strengthens the model's learning ability on sparse anomalous transaction behavior samples through an attention mechanism, thereby significantly reducing the false negative rate and improving the model's robustness.
[0086] Optionally, the method also includes: selecting time series data from a preset sliding time window up to the current date as training samples; and using federated learning technology to collaboratively update model parameters from multiple distributed data sources.
[0087] In one example, a sliding window mechanism is used to select transaction data from the most recent N days as training samples. Federated learning techniques are used to collaboratively update model parameters from multiple distributed data sources (such as different banks or platforms), for example, by sharing model gradients through encrypted communication to improve global generalization ability. The sliding window retains only the transaction data from the most recent N days, ensuring the model is trained on the latest data. For example, transaction records from the most recent 30 days might be retained. Federated learning uses distributed data sources to collaboratively update model parameters, avoiding single-point data bias. For example, the model can be jointly trained from transaction data from multiple banks.
[0088] By combining a sliding time window with federated learning, the model's adaptability to dynamic and abnormal trading patterns is enhanced. The sliding window ensures that the model is always trained on the latest trading data, while federated learning avoids single-point data bias through collaborative updates of multi-source data, thereby significantly improving the model's ability to detect new types of abnormal trading behaviors.
[0089] Optionally, the self-attention weights of each time step in the time series data are calculated to generate initial global features, specifically including at least one of the following: calculating the first cross-attention weights of transaction amount and geographic location features in the time series data; calculating the second cross-attention weights of transaction time interval and device fingerprint features in the time series data.
[0090] In one example, cross-attention weights are used to calculate the correlation between different modal features (such as transaction amount and geographic location, transaction time interval and device fingerprint). For instance, dynamic weight allocation can be used to identify patterns of the same device initiating multiple abnormal transactions within a short period. The cross-attention weights are dynamically assigned by calculating the correlation between different modal features. For example, transaction amount and geographic location may form a strong correlation through cross-attention.
[0091] By calculating cross-attention weights, the model's ability to perceive the correlation between multimodal heterogeneous features is enhanced. Cross-account fund flow anomalies are identified through cross-attention of transaction amount and geographical location, thereby improving the accuracy of identifying concealed abnormal transaction behaviors.
[0092] Optionally, the cross-attention weights of transaction amount and geographic location features in time series data are calculated, including: performing a linear transformation on transaction amount and geographic location features through a preset weight matrix to generate associated features; and normalizing the associated features to obtain the first cross-attention weights.
[0093] In one example, a linear transformation is performed on transaction amount and geographic location features using a learnable weight matrix to generate associated features. These associated features are then normalized, and a first cross-attention weight is calculated to quantify the correlation between them. The learnable weight matrix is a parameter matrix optimized through training, used to perform the linear transformation on the input features. For example, it maps transaction amount and geographic location features to a hidden layer space. The normalization process includes standardizing the features to improve computational stability. For example, it normalizes the weight values to the [0,1] interval.
[0094] By synergistically optimizing the learnable weight matrix and normalization, the model's accuracy in modeling multimodal feature correlations is improved. The learnable weight matrix can dynamically adjust the mapping relationship between transaction amount and geographical location, while normalization ensures the stability of weight values, thereby further enhancing the ability to identify covert and abnormal transaction behaviors.
[0095] Optionally, the method also includes: continuously receiving updated time series data and dynamically updating model parameters through an online incremental learning framework; and generating heatmaps of key features corresponding to transaction behavior through an interpretability enhancement module.
[0096] In one example, an online incremental learning framework continuously receives new transaction data and dynamically updates the model parameters. For example, a sliding window mechanism is used to train the model using only the most recent N days' transaction data. Simultaneously, an interpretability enhancement module generates heatmaps of key features of the transaction sequences, such as highlighting key clues of abnormal transaction behavior using attention weights. Here, online incremental learning involves dynamically updating model parameters by continuously receiving new data. For example, a sliding window mechanism is used to train the model using only the most recent transaction data. Interpretability enhancements include increasing the transparency of model decisions through visualization. For example, a heatmap can be used to highlight the timestamps or amounts of abnormal transactions.
[0097] Through the collaborative processing of online incremental learning and interpretability enhancement, dynamic optimization and transparency of the abnormal transaction behavior detection system are achieved. Online incremental learning ensures that the model can adapt to new and common transaction behavior patterns in real time, while the interpretability enhancement module visually displays the key characteristics of common transaction behavior through heatmaps, thereby improving the system's real-time performance, robustness, and compliance.
[0098] Figure 3 This is a schematic diagram of the structure of a transaction behavior recognition device provided in an embodiment of this application, as shown below. Figure 3 As shown, the transaction behavior identification device 30 provided in this embodiment includes:
[0099] The data acquisition module 301 is used to acquire time series data corresponding to the transaction behavior. The time series data includes transaction feature vectors for several time steps.
[0100] The feature extraction module 302 is used to extract features from the transaction feature vector through a self-attention mechanism to generate global features, which contain global dependencies.
[0101] The state generation module 303 is used to input global features into the bidirectional time series modeling module, extract the local time dependencies of global features through forward and backward sequence modeling, and generate bidirectional hidden states.
[0102] The classification processing module 304 is used to classify the bidirectional hidden state to obtain the probability of abnormality in the transaction behavior.
[0103] In one possible implementation, the feature extraction module 302 is specifically used to: calculate the self-attention weights of each time step in the time series data through a self-attention mechanism to generate initial global features; and perform nonlinear mapping on the initial global features through a feedforward neural network to generate global features.
[0104] In one possible implementation, the feature extraction module 302 is further specifically used to: perform a linear transformation on the initial global features to generate intermediate features; and perform nonlinear activation function processing on the intermediate features to generate global features.
[0105] In one possible implementation, the transaction behavior recognition device is further specifically used to: oversample time series data to generate synthetic abnormal transaction behavior samples; and enhance the features of the abnormal transaction behavior samples through a self-attention mechanism to generate enhanced global features.
[0106] In one possible implementation, the transaction behavior recognition device is further configured to: select time series data from a preset sliding time window prior to the current date as training samples; and use federated learning technology to collaboratively update model parameters from multiple distributed data sources.
[0107] In one possible implementation, the feature extraction module 302 is further specifically used to: calculate the first cross-attention weight between transaction amount and geographic location feature in time series data; and calculate the second cross-attention weight between transaction time interval and device fingerprint feature in time series data.
[0108] In one possible implementation, the feature extraction module 302 is further specifically used to: perform a linear transformation on the transaction amount and geographical location features through a preset weight matrix to generate associated features; and normalize the associated features to obtain the first cross-attention weights.
[0109] In one possible implementation, the transaction behavior recognition device is further configured to: continuously receive updated time-series data and dynamically update model parameters through an online incremental learning framework; and generate a heatmap of key features corresponding to the transaction behavior through an interpretability enhancement module.
[0110] The transaction behavior identification device provided in this embodiment can execute the method provided in the above method embodiment. Its implementation principle and technical effect are similar, and will not be described in detail here.
[0111] Figure 4 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Figure 4 As shown, the electronic device 40 may include a memory 401 and a processor 402. Optionally, the electronic device may also include a transceiver 403, wherein the memory 401 and the processor 402 communicate with each other; for example, the memory 401, the processor 402 and the transceiver 403 may communicate via a communication bus 404, the memory 401 is used to store a computer program, and the processor 402 executes the computer program to implement the method of the above embodiments.
[0112] Optionally, the aforementioned processor can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), etc. The general-purpose processor can be a microprocessor or any conventional processor. The steps in the method embodiments disclosed in this application can be directly implemented by a hardware processor, or implemented by a combination of hardware and software modules within the processor.
[0113] This application also provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, implement the methods in any of the above method embodiments.
[0114] This application also provides a computer program product, including a computer program that, when executed by a processor, implements the methods in any of the above method embodiments.
[0115] All or part of the steps in the above method embodiments can be implemented by hardware related to program instructions. The aforementioned program can be stored in a readable memory. When the program is executed, it performs the steps of the above method embodiments; and the aforementioned memory (storage medium) includes: read-only memory (ROM), RAM, flash memory, hard disk, solid-state drive, magnetic tape, floppy disk, optical disk, and any combination thereof.
[0116] This application describes embodiments with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It should be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processing unit of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processing unit of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0117] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0118] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0119] Obviously, those skilled in the art can make various modifications and variations to the embodiments of this application without departing from the spirit and scope of this application. Therefore, if these modifications and variations to the embodiments of this application fall within the scope of the claims of this application and their equivalents, this application also intends to include these modifications and variations.
[0120] In this application, the term "comprising" and its variations can refer to non-limiting inclusion; the term "or" and its variations can refer to "and / or". The terms "first", "second", etc., in this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. In this application, "multiple" refers to two or more. "And / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, and B existing alone. The character " / " generally indicates that the preceding and following related objects have an "or" relationship.
[0121] It should be noted that, for the sake of simplicity, the foregoing method embodiments are all described as a series of actions. However, those skilled in the art should understand that this application is not limited to the described order of actions, as some steps may be performed in other orders or simultaneously according to this application. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are all optional embodiments, and the actions and modules involved are not necessarily essential to this application.
[0122] It should be further noted that although the steps in the flowchart are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowchart may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these sub-steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the sub-steps or stages of other steps.
[0123] It should be understood that the above-described device embodiments are merely illustrative, and the device of this application can also be implemented in other ways. For example, the division of units / modules in the above embodiments is only a logical functional division, and there may be other division methods in actual implementation. For example, multiple units, modules, or components may be combined, or integrated into another system, or some features may be ignored or not executed.
[0124] Furthermore, unless otherwise specified, the functional units / modules in the various embodiments of this application can be integrated into one unit / module, or each unit / module can exist physically separately, or two or more units / modules can be integrated together. The integrated units / modules described above can be implemented in hardware or as software program modules.
[0125] When integrated units / modules are implemented in hardware, the hardware can be digital circuits, analog circuits, etc. The physical implementation of the hardware structure includes, but is not limited to, transistors, memristors, etc. Unless otherwise specified, the processor can be any suitable hardware processor, such as a CPU, GPU, FPGA, DSP, and ASIC, etc. Unless otherwise specified, the storage unit can be any suitable magnetic or magneto-optical storage medium, such as Resistive Random Access Memory (RRAM), Dynamic Random Access Memory (DRAM), Static Random Access Memory (SRAM), Enhanced Dynamic Random Access Memory (EDRAM), High-Bandwidth Memory (HBM), Hybrid Memory Cube (HMC), etc.
[0126] If the integrated unit / module is implemented as a software program module and sold or used as an independent product, it can be stored in a computer-readable storage device (CMD). Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a memory and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this application. The aforementioned memory includes various media capable of storing program code, such as a USB flash drive, read-only memory (ROM), random access memory (RAM), portable hard drive, magnetic disk, or optical disk.
[0127] In the above embodiments, the descriptions of each embodiment have their own emphasis. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments. The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as the combination of these technical features does not contradict each other, it should be considered within the scope of this specification.
[0128] Other embodiments of this application will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of this application that follow the general principles of this application and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of this application are indicated by the following claims.
[0129] It should be understood that this application is not limited to the precise structure described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of this application is limited only by the appended claims.
Claims
1. A method for identifying transaction behavior, characterized in that, The method includes: Obtain time series data corresponding to the transaction behavior, wherein the time series data includes transaction feature vectors for several time steps; The transaction feature vector is used to extract features through a self-attention mechanism to generate global features, which contain global dependencies. The global features are input into the bidirectional time series modeling module, and the local time dependencies of the global features are extracted through forward and backward sequence modeling to generate bidirectional hidden states. The bidirectional hidden states are classified to obtain the probability of anomalies in the transaction behavior.
2. The method according to claim 1, characterized in that, The step of extracting features from the transaction feature vector using a self-attention mechanism to generate global features includes: The self-attention mechanism is used to calculate the self-attention weights at each time step in the time series data to generate initial global features. The initial global features are nonlinearly mapped using a feedforward neural network to generate the global features.
3. The method according to claim 2, characterized in that, The step of generating the global features by performing a nonlinear mapping on the initial global features using a feedforward neural network includes: The initial global features are linearly transformed to generate intermediate features; The intermediate features are processed by a non-linear activation function to generate the global features.
4. The method according to claim 1, characterized in that, The method further includes classifying the bidirectional hidden states to obtain the probability that the transaction behavior is abnormal, and obtaining the probability of an anomaly. The time series data is oversampled to generate synthetic abnormal transaction behavior samples; The abnormal transaction behavior samples are enhanced using a self-attention mechanism to generate enhanced global features.
5. The method according to claim 1, characterized in that, The method further includes: Based on a preset sliding time window, time series data from a preset sliding window prior to the current date are selected as training samples; Federated learning technology is used to collaboratively update model parameters from multiple distributed data sources.
6. The method according to claim 2, characterized in that, The calculation of the self-attention weights at each time step in the time series data to generate initial global features specifically includes at least one of the following: Calculate the first cross-attention weight between transaction amount and geographic location features in the time series data; Calculate the second cross-attention weight between the transaction time interval and the device fingerprint feature in the time series data.
7. The method according to claim 6, characterized in that, The calculation of the cross-attention weights between transaction amounts and geographic location features in the time series data includes: By performing a linear transformation between the transaction amount and the geographical location features using a preset weight matrix, correlation features are generated. The associated features are normalized to obtain the first cross-attention weight.
8. The method according to claim 7, characterized in that, The method further includes: The online incremental learning framework continuously receives updated time series data and dynamically updates the model parameters. The interpretability enhancement module generates a heatmap of key features corresponding to the transaction behavior.
9. A transaction behavior identification device, characterized in that, The device includes: The data acquisition module is used to acquire time series data corresponding to transaction behavior, wherein the time series data includes transaction feature vectors for several time steps; The feature extraction module is used to extract features from the transaction feature vector through a self-attention mechanism to generate global features, which contain global dependencies. The state generation module is used to input the global features into the bidirectional time series modeling module, extract the local time dependencies of the global features through forward and backward sequence modeling, and generate bidirectional hidden states. The classification processing module is used to classify the bidirectional hidden state to obtain the probability of an anomaly in the transaction behavior.
10. An electronic device, characterized in that, include: A processor, and a memory communicatively connected to the processor; The memory stores computer-executed instructions; The processor executes computer execution instructions stored in the memory to implement the method as described in any one of claims 1 to 8.
11. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the method as described in any one of claims 1 to 8.
12. A computer program product, characterized in that, Includes a computer program that, when executed by a processor, implements the method of any one of claims 1 to 8.