Bank staff behavior anomaly detection method and device based on behavior sequence and medium

By integrating multi-source data and a behavioral analysis hub, and utilizing semantic mapping and risk assessment technologies, the problem of isolated behavior detection and lack of semantic correlation within banks has been solved, enabling real-time monitoring and efficient anomaly detection of bank personnel behavior.

CN122365237APending Publication Date: 2026-07-10BEIJING ZHONGAN FENGYUAN TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610414733.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-03-31
Publication Date
2026-07-10

AI Technical Summary

Technical Problem

Existing internal security systems in banks are unable to effectively monitor and identify high-risk behaviors of bank personnel, and suffer from isolated behavior detection and a lack of semantic correlation.

Method used

By deploying a behavior analysis hub, integrating data sources such as access control controllers, bastion hosts, business servers, and smart cameras, key attribute features are extracted using message queues and various parsing templates. Data is then cleaned and standardized, and a behavior code string is generated by combining a semantic mapping rule base. Path deviation and time sequence deviation are assessed to generate a comprehensive risk score to identify abnormal behavior.

Benefits of technology

It enables real-time monitoring and analysis of bank personnel behavior, improves the efficiency and accuracy of anomaly detection, reduces false alarm rates, ensures data consistency and availability, and can promptly detect potential security threats and violations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122365237A_ABST
    Figure CN122365237A_ABST
Patent Text Reader

Abstract

This invention discloses a behavior anomaly detection method for bank personnel based on behavioral sequences, belonging to the field of behavior anomaly monitoring technology. It addresses the technical problems of existing methods for comprehensively monitoring and identifying high-risk behavioral characteristics of bank employees, which suffer from isolated behavior detection and a lack of semantic association. The method includes: parsing and aligning multi-source heterogeneous data collected from various data sources; performing common baseline analysis of group behavior under standard behavioral sequences on the behavioral path data of bank personnel to obtain standard role behavior baselines; performing semantic code mapping processing on behavioral metadata related to real-time behavior serialization to obtain semantically annotated real-time behavior code strings; performing dual evaluation calculations on the real-time behavior code strings based on path deviation and temporal deviation to obtain a comprehensive risk score; and automatically fixing the evidence chain of high-risk associated behavioral sequences with outliers in the comprehensive risk score to generate anomaly behavior detection results.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of abnormal behavior monitoring, and in particular to methods, equipment and media for detecting abnormal behavior of bank personnel based on behavioral sequences. Background Technology

[0002] With societal development, the financial industry has also grown rapidly. Within the banking sector, the conduct of bank personnel has become increasingly crucial. In particular, crimes committed by bank insiders, due to their high degree of secrecy and authority, often result in significant financial and reputational losses for the bank. Currently, banks primarily rely on fragmented security monitoring systems (such as access control card swipe records, surveillance videos, and business operation logs) for post-incident investigations.

[0003] However, traditional security systems only monitor single, isolated behaviors (e.g., a late-night card swipe alarm, a large transaction record). Internal crimes, however, often consist of a series of actions that appear compliant individually but are highly suspicious when viewed in sequence (e.g., appearing in unauthorized areas outside of working hours + using a computer left unlocked by someone else + querying low-frequency customer information).

[0004] Furthermore, existing systems only record data and cannot transform behavioral data into behavioral units with semantic features, let alone analyze the logical relationships and temporal connections between behaviors. In addition, traditional rule engines can only discover known attack patterns and cannot detect unknown and complex potential threats through behavioral pattern deviations.

[0005] Therefore, there is an urgent need for a method that can accurately identify high-risk behaviors that deviate from the normal roles of bank personnel, thereby solving the problems of isolated behavior detection and lack of semantic relevance in existing technologies. Summary of the Invention

[0006] This application provides a method, device, and medium for detecting abnormal behavior of bank personnel based on behavioral sequences, which addresses the following technical problem: the high-risk behavioral characteristics of existing bank employees are difficult to comprehensively monitor and identify, resulting in isolated behavior detection and a lack of semantic association.

[0007] The embodiments of this application adopt the following technical solutions: On one hand, this application provides a method for detecting abnormal behavior of bank personnel based on behavioral sequences, including: controlling the data channel access between a security monitoring computer deploying a behavior analysis center and data acquisition devices in the bank via a message queue, and collecting corresponding multiple data sources; wherein, the data acquisition devices include: access control controllers, bastion hosts, business servers, and smart cameras; based on defined field extraction rules, log key information matched by regular expressions, and structured data output by edge computing nodes, pre-configuring access control data parsing templates, business log parsing templates, and video analysis data parsing templates respectively; and extracting key attribute features from the multiple data sources using the multiple parsing templates to obtain initial parsed data; wherein, The key attribute features extracted by the access control data parsing template include at least: timestamp, personnel ID, access control point, and entry / exit marker; the key attribute features extracted by the business log parsing template include at least: timestamp, operator ID, operation type, target account, and operation result; the key attribute features extracted by the video analysis data parsing template include at least: timestamp, personnel ID, behavior tag, and confidence level; the timestamp of the initial parsed data is compared with the local NTP time, and based on the comparison result, the initial parsed data is aligned and calibrated under time synchronization; the initial parsed data after data cleaning and filtering is standardized, encapsulated, and cached to obtain the behavior metadata; and the behavior metadata is pushed to a high-performance message queue.

[0008] This application's embodiments, through real-time monitoring and analysis of bank personnel behavior, can promptly detect and prevent potential security threats and violations. It can also leverage message queues and a combination of multiple data sources to quickly and effectively collect and analyze data, improving the efficiency of anomaly detection. Furthermore, it can integrate multi-source data from access control controllers, bastion hosts, business servers, and smart cameras, providing more comprehensive behavioral analysis and improving detection accuracy. Using pre-configured parsing templates, key attribute features can be automatically extracted, reducing the workload of manual data processing and improving efficiency. Simultaneously, NTP time synchronization technology ensures the time accuracy of all data, which is crucial for analyzing abnormal behavior of bank personnel. Moreover, data cleaning, filtering, and standardization ensure data consistency and availability, facilitating subsequent analysis and decision-making. Finally, through precise data extraction and analysis, false alarm rates can be reduced, avoiding unnecessary alarms and interference.

[0009] In one feasible implementation, based on the behavioral attribute sequences of different personnel positions, a common baseline analysis of group behavior under standard behavioral sequences is performed on the behavioral path data of bank personnel to obtain the standard role behavior baseline for each personnel position. Specifically, this includes: mapping the latest organizational structure and personnel position information through the bank's human resources system to obtain a position-personnel mapping table; wherein the mapping attribute sequence of the position-personnel mapping table includes: personnel ID, name, position code, and position name; based on the personnel ID, all historical behavioral metadata of bank personnel is collected, and based on timestamps, a personal historical behavioral sequence for each bank personnel is generated; high-frequency behavioral subsequences in the personal historical behavioral sequence are mined based on a minimum support threshold to obtain several high-frequency behavioral paths for each bank personnel; and based on the high-frequency behavioral paths, a position behavior pattern feature sequence is generated; wherein, the high-frequency behavioral paths... This involves defining behavioral characteristic paths for bank personnel under high support levels. The behavioral attribute sequence includes: the mapping attribute sequence, the individual's historical behavioral sequence, and the job-specific behavioral pattern characteristic sequence. The behavioral attribute sequence undergoes industry evaluation processing based on relevant standard behavioral sequences. If the behavioral attribute sequence belongs to the standard behavioral sequence, the behavioral path for each employee's job within the behavioral attribute sequence is divided into a node list of relevant behavioral nodes. For each behavioral node, a time tolerance interval and path occurrence probability are configured. Each behavioral node includes a behavioral type and specific attributes. The time tolerance interval is a time tolerance window calculated based on historical distribution. The path occurrence probability is the path's support level within the job. Based on the behavioral node characteristics, time tolerance interval characteristics, and path occurrence probability characteristics in the behavioral attribute sequence, a standard role behavioral baseline is generated to quantify the behavioral sequence of each employee's job.

[0010] This application's embodiments, by analyzing the behavioral attribute sequences of personnel in different positions, can establish personalized behavioral baselines, thereby more accurately identifying the standard behavioral patterns of each position. Furthermore, by analyzing the characteristic sequences of job behavioral patterns, typical behavioral paths for each position can be identified, aiding in understanding and predicting employee behavior in their respective roles. Comparing actual behavior with standard baselines makes it easier to detect abnormal behavior, thus promptly identifying potential risks or violations. Moreover, through the analysis of behavioral path data, banks can strengthen security monitoring and prevent internal fraud and operational risks. Simultaneously, by quantifying the behavioral sequences of each personnel position, risk assessment and management can be conducted more effectively. Additionally, analyzing job behavioral baselines can help banks better plan human resources and optimize staffing.

[0011] In one feasible implementation, the behavioral metadata is processed using a semantic mapping rule base to perform semantic code mapping for real-time behavioral serialization, resulting in a semantically annotated real-time behavioral code string. Specifically, this includes: extracting the behavioral metadata from a high-performance message queue and configuring a behavioral sliding window for each person; wherein the behavioral sliding window stores the real-time behavioral metadata for each person; updating the storage of the latest behavioral metadata in the behavioral sliding window; and using the semantic mapping rule base to perform semantic code mapping on the current behavioral metadata in each person's behavioral sliding window, including: mapping access control points in the current behavioral metadata to area types and generating area codes; wherein the area types include at least: cash area, non-cash area, and computer room area. The system includes: 1) mapping the business operation type in the current behavior metadata to an operation category and generating an operation code; wherein the business operation type includes at least: small withdrawal, large transfer, and querying dormant accounts; 2) mapping the behavior tags output by video analysis in the current behavior metadata to status codes and generating behavior tag codes; wherein the behavior tags include at least: leaving the post, multiple people watching, and obstructing the camera; 3) automatically generating time period tags from the timestamps in the current behavior metadata and generating time period codes; 4) mapping each piece of behavior metadata in the current behavior sliding window according to the semantic code mapping rules to obtain several semantic unit codes; 5) performing time-series concatenation of all the semantic unit codes to obtain the real-time behavior code string for each person in the current behavior sliding window.

[0012] This application's embodiments achieve a standardized representation of behavioral sequences by converting behavioral metadata into semantic code strings, facilitating subsequent processing and analysis. Real-time behavioral serialization enables the system to track and analyze personnel behavior in real time, which is crucial for rapid response and early warning. Furthermore, through a semantic mapping rule base, the system can map specific behavioral data into more abstract semantic information, such as region type, operation category, and status code, improving data understandability. It can also simplify complex behavioral metadata into semantic code strings, reducing data processing complexity and improving system efficiency.

[0013] In one feasible implementation, based on the standard role behavior baseline, a dual evaluation calculation is performed on the real-time behavior code string under the conditions of path deviation and temporal deviation to obtain the comprehensive risk score under the current bank personnel behavior sequence. Specifically, this includes: determining the corresponding standard role behavior baseline based on the job code of the real-time behavior code string; if no corresponding standard role behavior baseline exists for the job code of the real-time behavior code string, then the default job behavior baseline is determined as the standard role behavior baseline for the current job code; comparing and pre-annotating each high-frequency path in the real-time behavior code string with the standard role behavior baseline; and calculating the real-time sequence of the annotated real-time behavior code string and each high-frequency path based on the editing cost between each behavior code in the semantic code and dynamic programming. The minimum edit distance between baseline paths; selecting the minimum edit distance among all baseline paths, and obtaining a path deviation score representing the path deviation based on the real-time sequence length of the real-time behavior code string; wherein, the higher the value of the path deviation score, the more severe the path deviation; calculating the temporal deviation for the behavior attribute sequence in the behavior sliding window for each behavior node in the real-time behavior code string, obtaining a temporal deviation score; wherein, the behavior sliding window is the expected behavior sliding window corresponding to the real-time behavior code string under the standard role behavior baseline; weighting and summing the path deviation score and the temporal deviation score to obtain the comprehensive risk score; wherein, the weighting coefficient is configured based on business requirements.

[0014] This application's embodiments, by calculating path deviation and temporal deviation, enable the system to quantify the risk of bank personnel behavior sequences, providing data support for risk management. Furthermore, by comparing pre-labeled data and calculating minimum edit distance, anomalies in the behavior sequences can be accurately located, facilitating the rapid identification of potential risky behaviors. Combining this with a comparison of standard role behavior baselines and real-time behavior sequences can identify whether employee behavior patterns conform to expectations, thereby identifying abnormal patterns. Moreover, the application of dynamic programming algorithms allows risk assessments to be updated in real-time over time, adapting to constantly changing behavior patterns. Simultaneously, weighting coefficients can be configured according to business needs, making risk scores more aligned with the requirements of actual business scenarios.

[0015] In one feasible implementation, based on each behavior node in the real-time behavior code string, the temporal deviation of the behavior attribute sequence in the behavior sliding window is calculated to obtain a temporal deviation score. Specifically, this includes: aligning the real-time sequence in the real-time behavior code string with the best-matching baseline path, wherein the best-matching baseline path is the path corresponding to the minimum edit distance; checking and determining whether the timestamp of the real-time behavior sequence in the behavior attribute sequence falls within the time tolerance interval of the current behavior node based on each aligned behavior node, and obtaining a judgment result; if the judgment result is a positive result, counting the number of time-out behavior nodes and calculating the cumulative timeout time; normalizing the number of behavior nodes and the cumulative timeout time to obtain the temporal deviation score representing the temporal deviation.

[0016] In one feasible implementation, the high-risk associated behavior sequences related to outliers in the comprehensive risk score are subjected to automatic evidence chain fixing processing to obtain abnormal behavior detection results. Specifically, this includes: classifying the comprehensive risk score into risk levels based on a preset risk threshold range to obtain risk level results; wherein the risk level results include: low risk, medium risk, and high risk; the comprehensive risk scores corresponding to the medium risk and high risk are the outliers; marking and recording the abnormal bank personnel information corresponding to the comprehensive risk scores containing the outliers, and recording the behavior sliding window and comprehensive risk score corresponding to the abnormal bank personnel. The system retrieves and processes data on behavioral deviation types and causes to generate abnormal behavior warning information for the abnormal bank personnel. It identifies the behavioral sliding window in the abnormal behavior warning information as the abnormal behavior sliding window and extracts the abnormal behavior metadata from it. The abnormal behavior metadata is then packaged and uploaded to an anti-tampering database. The abnormal behavior compressed file and the abnormal behavior warning information are stored together, and an evidence chain ID is generated. Based on the evidence chain ID, the abnormal behavior compressed file, and the abnormal behavior warning information, the abnormal behavior detection result is generated.

[0017] This application's embodiments automatically classify risk levels by pre-setting risk thresholds, enabling rapid identification and response to high-risk behaviors and improving the speed of reaction to abnormal events. Furthermore, it categorizes risks into low, medium, and high risks, making risk assessment results more intuitive and easier to understand. It automatically establishes a chain of evidence for abnormal behavior, ensuring the integrity and immutability of the evidence, which is crucial for subsequent investigations and evidence collection. It can also record detailed information about abnormal bank personnel, including behavioral sliding windows, comprehensive risk scores, types of behavioral deviations, and reasons, providing comprehensive data support for subsequent analysis. It can generate abnormal behavior warning information, promptly notifying relevant personnel to intervene and prevent potential risk events from occurring. Simultaneously, by storing compressed files of abnormal behavior and warning information in a linked manner, it ensures the integrity and traceability of the evidence chain.

[0018] In one feasible implementation, after automatically fixing the evidence chain of high-risk associated behavior sequences related to outliers in the comprehensive risk score to obtain abnormal behavior detection results, the method further includes: extracting behavioral sequence features, spatiotemporal features, resource access features, and personnel attribute features related to abnormal bank personnel from the abnormal behavior detection results, and generating multi-dimensional key features; mapping the multi-dimensional key features to a fixed-length binary hash code using a locality-sensitive hashing algorithm to obtain a behavioral semantic fingerprint; storing and associating the behavioral semantic fingerprint with the evidence chain ID, abnormal behavior compressed file, and abnormal behavior early warning information in the abnormal behavior detection results, and storing the associated data packet in a risk case database.

[0019] Secondly, embodiments of this application also provide a bank personnel behavior anomaly detection device based on behavior sequence, the device comprising: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, so that the at least one processor can execute a bank personnel behavior anomaly detection method based on behavior sequence as described in any of the above embodiments.

[0020] Thirdly, embodiments of this application also provide a non-volatile computer storage medium, which is a non-volatile computer-readable storage medium storing at least one program. Each program includes instructions, which, when executed by a terminal, cause the terminal to execute a method for detecting abnormal behavior of bank personnel based on behavioral sequences as described in any of the above embodiments.

[0021] This application provides a method for detecting abnormal behavior of bank personnel based on behavioral sequences. Compared with the prior art, this application has the following beneficial technical effects: 1. By monitoring and analyzing the behavior of bank personnel in real time, potential security threats and violations can be detected and prevented in a timely manner.

[0022] 2. By combining message queues with multiple data sources, data can be collected and analyzed quickly and effectively, improving the efficiency of anomaly detection.

[0023] 3. Integrating multi-source data from access controllers, bastion hosts, business servers, and smart cameras can provide more comprehensive behavior analysis and improve detection accuracy.

[0024] 4. With pre-configured parsing templates, key attribute features can be extracted automatically, reducing the workload of manual data processing and improving efficiency.

[0025] 5. By using NTP time synchronization technology, we can ensure the time accuracy of all data, which is crucial for analyzing abnormal behavior of bank personnel.

[0026] 6. Data cleaning, filtering, and standardization processes can ensure data consistency and availability, facilitating subsequent analysis and decision-making.

[0027] 7. Through precise data extraction and analysis, false alarm rates can be reduced, and unnecessary alarms and interference can be avoided. Attached Figure Description

[0028] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort. In the drawings: Figure 1 A flowchart of a method for detecting abnormal behavior of bank personnel based on behavioral sequences is provided in this application embodiment; Figure 2 This is a schematic diagram of the structure of a bank employee behavior anomaly detection device based on behavior sequence, provided in an embodiment of this application. Detailed Implementation

[0029] To enable those skilled in the art to better understand the technical solutions in this application, the technical solutions in the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this specification, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of this application.

[0030] It should be noted that this embodiment was deployed and implemented in a commercial bank. First, a security monitoring computer is configured as the behavior analysis hub. This computer establishes data connections with various security subsystems of the bank via a network. These subsystems include access control systems, core business system log servers, and intelligent video analytics systems. Data generated by all subsystems is aggregated in real time to the behavior analysis hub through an internal message queue, thereby enabling unified data analysis and detection, ultimately generating abnormal behavior detection results for detecting behavioral sequences of bank personnel.

[0031] This application provides a method for detecting abnormal behavior of bank personnel based on behavioral sequences, such as... Figure 1 As shown, the method for detecting abnormal behavior of bank personnel based on behavioral sequences specifically includes steps S101-S105: S101. By deploying a security monitoring computer in the behavior analysis center, the system performs multi-source heterogeneous data parsing and alignment processing on the collected data from various data sources to obtain behavioral metadata about bank personnel.

[0032] Specifically, the first step is to use a message queue to connect the security monitoring computer, which is deploying the behavior analysis hub, with the data acquisition devices in the bank, and to collect data from various data sources. These data acquisition devices include access controllers, bastion hosts, business servers, and smart cameras.

[0033] In one embodiment, a security monitoring computer can be deployed as a behavior analysis hub, which establishes connections with data sources such as access control controllers, bastion hosts / business servers, and smart cameras through message queues (such as Kafka).

[0034] Furthermore, based on the defined field extraction rules, the key log information matched by regular expressions, and the structured data output by the edge computing nodes, pre-configure access control data parsing templates, business log parsing templates, and video analysis data parsing templates respectively.

[0035] In one embodiment, for an access control system, the original card swipe record is typically a single line of text containing the swipe time, card number, access point number, and direction of entry / exit. The data acquisition service extracts this key information based on preset regular expressions or field locations, forming a structured record that includes personnel identification, event time, location information, and action type. For core business system logs, each operation log records information such as operator number, transaction time, transaction code, and operation account. The acquisition service extracts fields such as operator identification, time, operation type, and target account from these. Simultaneously, edge computing nodes are used to perform real-time analysis of the monitoring footage. When a specific behavior is detected, a structured data entry containing time, personnel identification, behavior tag, and confidence level is output. This allows for the configuration of corresponding access control data parsing templates, business log parsing templates, and video analytics data parsing templates.

[0036] Furthermore, it is necessary to combine multiple parsing templates to extract key attribute features from various data sources to obtain initial parsed data. Specifically, the key attribute features extracted by the access control data parsing template should at least include: timestamp, personnel ID, access control location, and entry / exit markers; the key attribute features extracted by the business log parsing template should at least include: timestamp, operator ID, operation type, target account, and operation result; and the key attribute features extracted by the video analytics data parsing template should at least include: timestamp, personnel ID, behavior tags, and confidence level.

[0037] Furthermore, the timestamp of the initial parsed data is compared with the local NTP time, and based on the comparison result, the initial parsed data undergoes alignment calibration under time synchronization. Finally, the cleaned and filtered initial parsed data is standardized, encapsulated, and cached to obtain behavioral metadata, which is then pushed to a high-performance message queue.

[0038] In one embodiment, because the clocks of various data acquisition devices may differ, when the acquisition service receives each piece of raw data, it compares the timestamp carried by the data with the standard time synchronized by the behavior analysis center from the network time protocol server. If the difference exceeds a preset threshold (e.g., 5 seconds), the original timestamp is replaced with the standard time, and a calibration mark is recorded in the data, while the original timestamp is retained for auditing. This step ensures the accuracy of subsequent time series analysis.

[0039] In one embodiment, each piece of data, after being processed by deduplication, noise removal, and irrelevant data filtering, is encapsulated into a uniform format to obtain behavioral metadata. Each piece of behavioral metadata contains the following core fields: employee ID, event timestamp, data source (e.g., access control, business logs, video), specific location or operation type, operation object, and a globally unique event number. The encapsulated behavioral metadata is pushed to a high-performance message queue for temporary storage, awaiting real-time consumption in subsequent steps.

[0040] S102. Based on the behavioral attribute sequences of different personnel positions, conduct a common baseline analysis of group behavior under the standard behavioral sequence on the behavioral path data of bank personnel to obtain the standard role behavior baseline for each personnel position.

[0041] Specifically, the bank's human resources system is first used to map the latest organizational structure with personnel job information, resulting in a job-person mapping table. The mapping attribute sequence in the job-person mapping table includes: personnel ID, name, job code, and job name.

[0042] In one embodiment, the behavior analysis center retrieves the latest organizational structure data from the bank's human resources system daily, generating a table mapping personnel to positions (position-person mapping table). This table records the department and specific position name of each employee, such as "cash teller," "corporate account manager," and "operations engineer." This position-person mapping table is stored in a relational database and updated regularly.

[0043] Furthermore, based on the personnel ID, all historical behavioral metadata of bank personnel is collected, and based on the timestamp, a personal historical behavioral sequence for each bank personnel is generated. Then, high-frequency behavioral subsequences in the personal historical behavioral sequence are processed using a minimum support threshold to obtain several high-frequency behavioral paths for each bank personnel. Based on these high-frequency behavioral paths, a job-specific behavioral pattern feature sequence is generated. The high-frequency behavioral paths are the behavioral feature paths of bank personnel with high support. In other words, the behavioral attribute sequence includes: a mapping attribute sequence, a personal historical behavioral sequence, and a job-specific behavioral pattern feature sequence.

[0044] In one embodiment, behavioral metadata of all personnel over the past six months can also be extracted from the data warehouse. For each personnel, their behavioral metadata is arranged chronologically to form a personal historical behavioral sequence. These sequences reflect the personnel's work trajectory over a period of time. Furthermore, for each position, the personal historical behavioral sequences of all personnel under that position are collected. High-frequency behavioral sub-sequences can be extracted using GSP or PrefixSpan. The specific process can be as follows: First, set a minimum support threshold (e.g., 30%), meaning that the proportion of the sub-sequence appearing among personnel in that position is not less than 30%. The mining results yield several high-frequency behavioral paths. For example, for the "cash teller" position, these include: 1) Path 1: [Access control - enter the branch, access control - enter the cash area, business system - sign in, cash box check-in] (support 85%); 2) Path 2: [Access control - enter the branch, access control - enter the cash area, business system - sign in, business system - initial daily reconciliation] (support 70%). At the same time, the statistical distribution of each behavior node in each path relative to the start time of the day (such as 0:00) is recorded, including the mean and standard deviation, for subsequent time series deviation calculation.

[0045] Furthermore, the behavioral attribute sequences are processed for industry assessment under relevant standard behavioral sequences: If the behavioral attribute sequence belongs to a standard behavioral sequence, then the behavioral path for each employee's position in the behavioral attribute sequence is divided into a node list of relevant behavioral nodes. Based on each behavioral node, a time tolerance interval and a path occurrence probability are configured. Each behavioral node includes a behavioral type and specific attributes; the time tolerance interval is a time tolerance window calculated based on historical distribution; and the path occurrence probability is the path's support level within the position.

[0046] In one embodiment, the behavioral attribute sequence from the high-frequency path set mined above is used as the "standard behavioral path" for the position. For each path, a unique identifier is first determined; then, a list of behavioral nodes is established, each node containing a behavioral type (e.g., access control card swiping) and specific attributes (e.g., location area); then, a time tolerance interval is calculated, that is, for each node, a time tolerance window is calculated based on historical distribution. For example, if the mean μ of the node "Business System - Check-in" is 8:50 and the standard deviation σ is 5 minutes, then the time tolerance window can be set to [μ-2σ, μ+2σ] = [8:40, 9:00]. Finally, the probability of path occurrence is configured, i.e., the support of the path in the position, which can be used for weighted calculations in subsequent steps. Finally, the above information is stored in the position baseline database, indexed by the position code, for quick retrieval during real-time detection.

[0047] Furthermore, based on the behavioral node features, time tolerance interval features, and path occurrence probability features in the behavioral attribute sequence, a standard role behavior baseline is generated to quantify the job behavior sequence of each person.

[0048] S103. Using the semantic mapping rule base, the behavior metadata is processed by semantic code mapping related to real-time behavior serialization to obtain the semantically annotated real-time behavior code string.

[0049] Specifically, firstly, behavioral metadata is extracted from the high-performance message queue, and a behavioral sliding window is configured for each person. This behavioral sliding window stores the real-time behavioral metadata for each person. Then, the behavior sliding window is updated with the latest behavioral metadata.

[0050] In one embodiment, a behavior sliding window needs to be maintained for each on-duty employee, combining behavioral metadata from the real-time consumption message queue. The window size is set to 2 hours, and the sliding step is set to 15 minutes. Specifically, a Redis sorted set (ZSet) can be used to store the behavioral metadata within each employee's current behavior sliding window, using timestamps as fractions to ensure order. When new behavioral metadata arrives, it is added to the corresponding employee's ZSet. For example, the update mechanism removes old data with timestamps earlier than "current time - 2 hours," ensuring the window always contains behavior from the most recent 2 hours. Simultaneously, an analysis of the employee's window data is triggered every 15 minutes.

[0051] Furthermore, through a semantic mapping rule base, the current behavior metadata in each person's behavior sliding window is mapped to semantic codes. The semantic code mapping rules mainly include: 1) Map the access control points in the current behavior metadata to area types and generate area codes. The area types include at least: cash area, non-cash area, computer room area, and office area.

[0052] 2) Map the business operation type in the current behavior metadata to the operation category and generate an operation code; the business operation type includes at least: small withdrawal, large transfer and query dormant account.

[0053] 3) Map the behavior tags output from the video analysis in the current behavior metadata to status codes, and generate behavior tag codes. Behavior tags must include at least: leaving one's post, multiple people watching, and obstructing the camera.

[0054] 4) Automatically generate time period labels and time period codes from the timestamps in the current behavior metadata.

[0055] In one embodiment, a configurable semantic mapping rule base needs to be established first to map fields in the original behavioral metadata to abstract semantic codes. Specifically, this includes: 1) Area codes: mapping access control points to area types (e.g., "cash zone," "non-cash zone," "computer room," "office area"); for example, point D102 corresponds to "cash zone" and is mapped to A01, and point D205 corresponds to "computer room" and is mapped to A02. 2) Operation codes: mapping business operation types to operation categories; for example, transaction code "1001" (small withdrawal) is mapped to B01. “2005” (large transfer) is mapped to B02, and “3001” (query dormant account) is mapped to B03. 3) Behavior tag code: The behavior tags output by video analysis are mapped to status codes. For example, “off-duty” is mapped to C01, “multiple people watching” is mapped to C02, and “obstructing camera” is mapped to C03. 4) Time period code: Time period tags are automatically generated based on timestamps. For example, “working hours (9:00-18:00)” is mapped to T01, “non-working hours” is mapped to T02, and “late night (0:00-6:00)” is mapped to T03.

[0056] Furthermore, based on the semantic code mapping rules described above, each piece of behavior metadata in the current behavior sliding window is mapped one by one to obtain several semantic unit codes. Finally, all semantic unit codes are concatenated in time to obtain the real-time behavior code string for each person in the current behavior sliding window.

[0057] In one embodiment, for each piece of behavior metadata within the current behavior sliding window, the above mapping rules are applied sequentially to generate a semantic unit code. For example, a card swipe record can be mapped to A01|T02 (representing a non-working-hour behavior in the cash area). All unit codes are concatenated in chronological order to obtain the behavior code string for the person's current window, such as: A01|T02→B03|T02→C02|T02. Simultaneously, a pointer to the original behavior metadata corresponding to each semantic unit code is retained for subsequent traceability.

[0058] S104. Based on the standard role behavior baseline, perform dual evaluation calculations on the real-time behavior code string under the relevant path deviation and time sequence deviation to obtain the comprehensive risk score under the current bank personnel behavior sequence.

[0059] Specifically, the standard role behavior baseline is first determined based on the job code of the real-time behavior code string. If no corresponding standard role behavior baseline exists for the job code of the real-time behavior code string, the default job behavior baseline is determined as the standard role behavior baseline for the current job code. That is, the corresponding standard role behavior baseline can be loaded from the job baseline library according to the current employee's job code. If the employee's job is not in the library (e.g., a newly created job), the default baseline is temporarily used or the detection is skipped.

[0060] Furthermore, the real-time behavior code string is pre-annotated by comparing it with each high-frequency path in the standard role behavior baseline. Then, based on the edit cost between each behavior code in the semantic code and using dynamic programming, the minimum edit distance between the real-time sequence of the annotated real-time behavior code string and each baseline path is calculated. The minimum edit distance among all baseline paths is then selected, and based on the real-time sequence length of the real-time behavior code string, a path deviation score representing the path deviation degree is obtained. A higher path deviation score indicates a more severe path deviation.

[0061] In one embodiment, the real-time action code string is compared with each high-frequency path in the standard role action baseline. An improved edit distance algorithm can be used to calculate the minimum edit distance, which is then normalized to a path deviation score (0~1). That is, the edit cost between action codes is first defined; for example, the replacement cost of the same region code but different opcodes is lower, while the replacement cost of different region codes (crossing different sensitive regions) is higher. Then, dynamic programming is used to calculate the minimum edit distance between the real-time sequence and each baseline path. Finally, the minimum edit distance among all baseline paths is selected and divided by the real-time sequence length to obtain the path deviation score P_score. A higher score indicates a more severe path deviation; for example, if the real-time sequence is A01|T02→B03|T02, and there is a high-frequency path in the baseline A01|T01→B01|T01, the edit distance is larger due to different time period codes (T02 and T01) and different opcodes (B03 and B01), resulting in a higher P_score.

[0062] Furthermore, based on each behavior node in the real-time behavior code string, the temporal deviation of the behavior attribute sequence within the behavior sliding window needs to be calculated to obtain a temporal deviation score. Here, the behavior sliding window is the expected behavior sliding window corresponding to the real-time behavior code string under the standard role behavior baseline.

[0063] As a feasible implementation, the real-time sequence in the real-time action code string needs to be aligned with the best-matching baseline path, where the best-matching baseline path is the path corresponding to the minimum edit distance. Then, for each aligned action node, it is checked and determined whether the timestamp of the real-time action sequence in the action attribute sequence falls within the time tolerance interval of the current action node, and a judgment result is obtained. If the judgment result is positive, the number of timed-out action nodes is counted, and the cumulative timeout time is calculated. Finally, the number of action nodes and the cumulative timeout time are normalized to obtain a time deviation score representing the time deviation degree.

[0064] In one embodiment, during the timing deviation calculation, for each behavior node in the real-time behavior code string, the expected time window of its corresponding node in the standard role behavior baseline is found. That is, firstly, the real-time sequence in the real-time behavior code string is aligned with the best-matching baseline path (i.e., the path corresponding to the minimum edit distance in the path deviation calculation above). Then, for each aligned node, it is checked whether the timestamp of the real-time behavior falls within the time tolerance interval of that node. Afterwards, the number of timeout nodes is counted, and the cumulative timeout time is calculated, finally normalized to a timing deviation score T_score. For example, the percentage of timeout nodes can be used as the T_score.

[0065] Furthermore, the path deviation score and the time sequence deviation score are weighted and summed to obtain the comprehensive risk score. The weighting coefficients are configured based on business requirements.

[0066] In one embodiment, the path deviation and time sequence deviation are weighted and summed to obtain a comprehensive risk score: Risk = α * P_score + β * T_score. The weights α and β can be configured according to business needs. For example, the weight of β can be increased for non-working periods, as time anomalies are often more suspicious than path anomalies. The weights can be optimized through training with historical data or dynamically adjusted. Furthermore, a dynamic threshold mechanism can be used to avoid false positives or false negatives caused by fixed thresholds. The threshold can be set based on the risk score distribution within a historical window, for example, taking the 95th percentile of the risk scores of all personnel in the past week as the current threshold. When Risk > the current threshold, the behavioral sequence is determined to be a high-risk associated behavioral sequence, and the risk score and triggering conditions are recorded.

[0067] S105. Automatically fix the evidence chain of high-risk associated behavior sequences with outliers in the comprehensive risk score to generate abnormal behavior detection results.

[0068] Specifically, the comprehensive risk score is first classified into risk levels using a preset risk threshold range to obtain risk level results. These risk level results include: low risk, medium risk, and high risk; the comprehensive risk scores corresponding to medium and high risk are outliers.

[0069] In one embodiment, risks can be divided into three levels based on the comprehensive risk score: (1) High risk (Risk≥0.8): Real-time alarms are triggered immediately and pushed to the risk control screen and duty mobile phone. (2) Medium risk (0.5≤Risk<0.8): Email notification is sent to the security team and audit logs are recorded. (3) Low risk (Risk<0.5): Only logs are recorded for post-event analysis.

[0070] Furthermore, the abnormal bank personnel information corresponding to the outlier comprehensive risk scores is marked and recorded. The data of the abnormal bank personnel's behavior sliding window, comprehensive risk score, and behavior deviation type and reason are then retrieved and processed to generate abnormal behavior warning information for these personnel. For example, the behavior deviation type and reason could be: path deviation mainly due to unauthorized areas, and time sequence deviation due to late-night operations. The abnormal bank personnel are represented by the abnormal behavior metadata in the corresponding behavior sliding window.

[0071] Furthermore, it is necessary to identify the sliding window in the abnormal behavior warning information as the abnormal behavior sliding window and extract the abnormal behavior metadata from it. Then, the abnormal behavior metadata is packaged and the compressed abnormal behavior file is uploaded to the anti-tampering database.

[0072] Furthermore, the compressed file containing the abnormal behavior and the abnormal behavior warning information are stored together, and an evidence chain ID is generated. Finally, based on the evidence chain ID, the compressed file containing the abnormal behavior, and the abnormal behavior warning information, the abnormal behavior detection result is generated.

[0073] In one embodiment, it is necessary to automatically extract all original behavioral data (i.e., abnormal behavior metadata, which may include: original access control records, original business logs, video clip file paths, etc.) corresponding to bank personnel within the identified abnormal behavior sliding window, and then package them into a ZIP file. The SHA-256 hash value of this file is calculated, and the hash value is uploaded to a blockchain for evidence storage or stored in a tamper-proof database to ensure the evidence is irrefutable. Finally, the abnormal behavior compressed file and abnormal behavior warning information are associated and stored, and a unique evidence ID is generated for subsequent retrieval. Based on the data recorded above, the abnormal behavior detection result for the current bank personnel is generated.

[0074] As a feasible implementation method, after obtaining the above-mentioned abnormal behavior detection results, the behavioral sequence features, spatiotemporal features, resource access features, and personnel attribute features of the abnormal bank personnel are extracted from the abnormal behavior detection results, and multi-dimensional key features are generated. Then, the multi-dimensional key features are mapped to a fixed-length binary hash code using the Locality Sensitive Hashing (LSH) algorithm to obtain the behavioral semantic fingerprint. Finally, the behavioral semantic fingerprint is stored and associated with the evidence chain ID, abnormal behavior compressed file, and abnormal behavior early warning information in the abnormal behavior detection results, and the associated data package is stored in the risk case database.

[0075] In one embodiment, the behavioral sequence feature involves extracting consecutive behavioral unit code combinations from the behavioral code string, preserving their sequential relationship, and generating a fixed-length sequence code. The spatiotemporal feature extracts quantitative characteristics such as the time period (e.g., early morning, holidays), location (e.g., high-sensitivity areas, cross-regional movement), and duration of the behavior. The resource access feature extracts the type of target resource involved in the operation (e.g., dormant accounts, large-amount accounts, core system configurations), access frequency, and data volume. The personnel attribute feature hides specific identity information while retaining non-sensitive attributes such as job category, rank, and years of service for subsequent correlation analysis.

[0076] In one embodiment, the Locality Sensitive Hash (LSH) algorithm can be used to map the extracted multidimensional features into a fixed-length binary hash code, i.e., a behavioral semantic fingerprint. This behavioral semantic fingerprint has an extremely low probability of different behavioral sequences generating the same fingerprint (which can be controlled through hash collisions); it ensures that fingerprints generated by similar behavioral sequences are close in Hamming space, facilitating rapid retrieval; and it prevents the original behavioral data from being deduced from the fingerprint, maximizing privacy protection. Finally, the behavioral semantic fingerprint is stored in association with the evidence chain ID, the abnormal behavior compressed file, and the abnormal behavior warning information from the abnormal behavior detection results, and is stored in a risk case database. This risk case database, indexed by the behavioral semantic fingerprint, supports efficient approximate nearest neighbor retrieval.

[0077] In addition, this application also provides a device for detecting abnormal behavior of bank personnel based on behavioral sequences, such as... Figure 2 As shown, the bank employee behavior anomaly detection device 200 based on behavioral sequences specifically includes: At least one processor 201; and a memory 202 communicatively connected to the at least one processor 201; wherein the memory 202 stores instructions executable by the at least one processor 201 to enable the at least one processor 201 to execute: By deploying a security monitoring computer at the behavior analysis center, the collected data from various data sources is parsed and aligned to obtain behavioral metadata about bank personnel. Based on the behavioral attribute sequences of different personnel positions, a common baseline analysis of group behavior under standard behavioral sequences was conducted on the behavioral path data of bank personnel to obtain the standard role behavior baseline for each personnel position. By using a semantic mapping rule base, the behavioral metadata is processed with semantic code mapping related to real-time behavioral serialization to obtain semantically annotated real-time behavioral code strings. Based on the standard role behavior baseline, the real-time behavior code string is subjected to dual evaluation calculations on path deviation and time sequence deviation to obtain the comprehensive risk score under the current bank personnel behavior sequence. The evidence chain of high-risk associated behavior sequences with outliers in the comprehensive risk score is automatically fixed to generate abnormal behavior detection results.

[0078] This application's embodiments, through real-time monitoring and analysis of bank personnel behavior, can promptly detect and prevent potential security threats and violations. It can also leverage message queues and a combination of multiple data sources to quickly and effectively collect and analyze data, improving the efficiency of anomaly detection. Furthermore, it can integrate multi-source data from access control controllers, bastion hosts, business servers, and smart cameras, providing more comprehensive behavioral analysis and improving detection accuracy. Using pre-configured parsing templates, key attribute features can be automatically extracted, reducing the workload of manual data processing and improving efficiency. Simultaneously, NTP time synchronization technology ensures the time accuracy of all data, which is crucial for analyzing abnormal behavior of bank personnel. Moreover, data cleaning, filtering, and standardization ensure data consistency and availability, facilitating subsequent analysis and decision-making. Finally, through precise data extraction and analysis, false alarm rates can be reduced, avoiding unnecessary alarms and interference.

[0079] The various embodiments in this application are described in a progressive manner. Similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, the device and medium embodiments are basically similar to the method embodiments, so the description is relatively simple; relevant parts can be referred to the description of the method embodiments.

[0080] The devices and media provided in this application are one-to-one with the methods. Therefore, the devices and media also have similar beneficial technical effects as their corresponding methods. Since the beneficial technical effects of the methods have been described in detail above, the beneficial technical effects of the devices and media will not be repeated here.

[0081] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0082] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0083] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0084] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0085] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.

[0086] Memory may include non-persistent storage in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of computer-readable media.

[0087] Computer-readable media includes both permanent and non-permanent, removable and non-removable media that can store information using any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.

[0088] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitation, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0089] The above description is merely an embodiment of this application and is not intended to limit the scope of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of this specification.

Claims

1. A method for detecting abnormal behavior of bank personnel based on behavioral sequences, characterized in that, The method includes: By deploying a security monitoring computer at the behavior analysis center, the collected data from various data sources is parsed and aligned to obtain behavioral metadata about bank personnel. Based on the behavioral attribute sequences of different personnel positions, a common baseline analysis of group behavior under standard behavioral sequences was conducted on the behavioral path data of bank personnel to obtain the standard role behavior baseline for each personnel position. The behavior metadata is processed by semantic code mapping related to real-time behavior serialization using a semantic mapping rule base to obtain a semantically annotated real-time behavior code string. Based on the standard role behavior baseline, the real-time behavior code string is subjected to dual evaluation calculations on path deviation and time sequence deviation to obtain the comprehensive risk score under the current bank personnel behavior sequence. The high-risk associated behavior sequences with outliers in the comprehensive risk score are automatically fixed with evidence chains to generate abnormal behavior detection results.

2. The method for detecting abnormal behavior of bank personnel based on behavioral sequences according to claim 1, characterized in that, By deploying a security monitoring computer at the behavior analysis center, the system analyzes and aligns heterogeneous data from various data sources to obtain behavioral metadata about bank personnel, specifically including: The security monitoring computer, which is deployed as a behavior analysis hub, is connected to the data acquisition equipment in the bank via a message queue to control the data channel and collect data from various data sources. The data acquisition equipment includes access controllers, bastion hosts, business servers, and smart cameras. Based on defined field extraction rules, log key information matched by regular expressions, and structured data output by edge computing nodes, pre-configured access control data parsing templates, business log parsing templates, and video analysis data parsing templates are respectively configured. Using various parsing templates, key attribute features are extracted from the various data sources to obtain initial parsed data. Specifically, the key attribute features extracted by the access control data parsing template include at least: timestamp, personnel ID, access control point, and entry / exit marker; the key attribute features extracted by the business log parsing template include at least: timestamp, operator ID, operation type, target account, and operation result; and the key attribute features extracted by the video analytics data parsing template include at least: timestamp, personnel ID, behavior tag, and confidence level. The timestamp of the initial parsed data is compared with the local NTP time, and based on the comparison result, the initial parsed data is aligned and calibrated under time synchronization. The initial parsed data after data cleaning and filtering is standardized, encapsulated, and cached to obtain the behavioral metadata; and the behavioral metadata is pushed to a high-performance message queue.

3. The method for detecting abnormal behavior of bank personnel based on behavioral sequences according to claim 1, characterized in that, Based on the behavioral attribute sequences of different personnel positions, a common baseline analysis of group behavior under standard behavioral sequences was conducted on the behavioral path data of bank personnel to obtain the standard role behavior baseline for each personnel position, specifically including: The latest organizational structure and personnel job information are mapped through the bank's human resources system to obtain a job-person mapping table. The mapping attribute sequence of the job-person mapping table includes: personnel ID, name, job code, and job name. Based on the personnel ID, collect all historical behavior metadata of the bank personnel, and generate a personal historical behavior sequence for each bank personnel based on the timestamp; The high-frequency behavior subsequences in the individual's historical behavior sequence are mined based on the minimum support threshold to obtain several high-frequency behavior paths for each bank employee; and based on the high-frequency behavior paths, a job behavior pattern feature sequence is generated; wherein, the high-frequency behavior paths are the behavior feature paths of bank employees under high support. The behavioral attribute sequence includes: the mapping attribute sequence, the personal historical behavior sequence, and the job behavior pattern feature sequence; The behavioral attribute sequence is then subjected to industry assessment processing based on relevant standard behavioral sequences. If the behavioral attribute sequence belongs to the standard behavioral sequence, then the behavioral path of each person's position in the behavioral attribute sequence is divided into a node list of relevant behavioral nodes, and a time tolerance interval and path occurrence probability are configured based on each behavioral node; wherein, each behavioral node includes a behavioral type and a specific attribute; the time tolerance interval is a time tolerance window calculated based on historical distribution; and the path occurrence probability is the support of the path in the position. Based on the behavioral node features, time tolerance interval features, and path occurrence probability features in the behavioral attribute sequence, a standard role behavior baseline is generated to quantify the job behavior sequence of each person.

4. The method for detecting abnormal behavior of bank personnel based on behavioral sequences according to claim 1, characterized in that, Using a semantic mapping rule base, the behavioral metadata is processed by semantic code mapping related to real-time behavioral serialization to obtain semantically annotated real-time behavioral code strings, specifically including: Extract the behavior metadata from the high-performance message queue and configure a behavior sliding window for each person; wherein, the behavior sliding window is used to store the real-time behavior metadata of each person; The behavior sliding window is updated with the latest behavior metadata. Using a semantic mapping rule base, the current behavior metadata in each person's behavior sliding window is mapped to semantic codes, including: Map the access control points in the current behavior metadata to area types and generate area codes; wherein, the area types include at least: cash area, non-cash area, computer room area, and office area; Map the business operation type in the current behavior metadata to the operation category and generate an operation code; wherein the business operation type includes at least: small withdrawal, large transfer and query dormant account; The behavior tags output from the video analysis in the current behavior metadata are mapped to status codes, and behavior tag codes are generated; wherein, the behavior tags include at least: leaving the post, multiple people watching, and obstructing the camera; Automatically generate time period labels and time period codes from the timestamps in the current behavior metadata; Based on the mapping rules of the semantic code, each piece of behavior metadata in the current behavior sliding window is mapped one by one to obtain several semantic unit codes; All the semantic unit codes are concatenated in a time sequence to obtain the real-time behavior code string for each person in the current behavior sliding window.

5. The method for detecting abnormal behavior of bank personnel based on behavioral sequences according to claim 1, characterized in that, Based on the aforementioned standard role behavior baseline, the real-time behavior code string undergoes dual evaluation calculations based on path deviation and time sequence deviation to obtain a comprehensive risk score for the current bank personnel behavior sequence, specifically including: Based on the job code of the real-time behavior code string, the corresponding standard role behavior baseline is determined; if the job code of the real-time behavior code string does not have a corresponding standard role behavior baseline, the default job behavior baseline is determined as the standard role behavior baseline of the current job code. The real-time behavior code string is compared and pre-annotated with each high-frequency path in the standard role behavior baseline; Based on the edit cost between each action code in the semantic code, and using dynamic programming, calculate the minimum edit distance between the real-time sequence of the annotated real-time action code string and each baseline path; The minimum edit distance among all the baseline paths is selected, and a path deviation score representing the path deviation is obtained based on the real-time sequence length of the real-time action code string; wherein, the higher the value of the path deviation score, the more severe the path deviation. Based on each behavior node in the real-time behavior code string, the temporal deviation is calculated for the behavior attribute sequence in the behavior sliding window to obtain a temporal deviation score; wherein, the behavior sliding window is the expected behavior sliding window corresponding to the real-time behavior code string under the standard role behavior baseline; The path deviation score and the time sequence deviation score are weighted and summed to obtain the comprehensive risk score; wherein the weighting coefficient is configured based on business requirements.

6. The method for detecting abnormal behavior of bank personnel based on behavioral sequences according to claim 5, characterized in that, Based on each behavior node in the real-time behavior code string, the temporal deviation is calculated for the behavior attribute sequence in the behavior sliding window to obtain a temporal deviation score, specifically including: Align the real-time sequence in the real-time behavior code string with the best matching baseline path, wherein the best matching baseline path is the path corresponding to the minimum edit distance; Based on each aligned behavior node, check and determine whether the timestamp of the real-time behavior sequence in the behavior attribute sequence falls within the time tolerance interval of the current behavior node, and obtain the judgment result. If the judgment result is positive, then count the number of timeout behavior nodes and calculate the cumulative timeout time; The number of behavior nodes and the cumulative timeout time are normalized to obtain the time deviation score, which represents the time deviation.

7. The method for detecting abnormal behavior of bank personnel based on behavioral sequences according to claim 1, characterized in that, The high-risk associated behavior sequences with outliers in the comprehensive risk score are subjected to automatic evidence chain fixing processing to obtain the abnormal behavior detection results, specifically including: The comprehensive risk score is divided into risk levels based on a preset risk threshold range to obtain risk level results; wherein, the risk level results include: low risk, medium risk, and high risk; the comprehensive risk scores corresponding to the medium risk and the high risk are the outliers; The abnormal bank personnel information corresponding to the comprehensive risk score with the outlier value is marked and recorded. The behavior sliding window, comprehensive risk score, behavior deviation type and reason corresponding to the abnormal bank personnel are processed by data retrieval to generate abnormal behavior warning information about the abnormal bank personnel. The behavior sliding window in the abnormal behavior warning information is identified as the abnormal behavior sliding window, and the abnormal behavior metadata in the abnormal behavior sliding window is extracted. The abnormal behavior metadata is packaged and processed, and the packaged abnormal behavior compressed file is uploaded to the anti-tampering database; The abnormal behavior compressed file and the abnormal behavior early warning information are stored together and an evidence chain ID is generated. The abnormal behavior detection result is generated based on the evidence chain ID, the abnormal behavior compressed file, and the abnormal behavior warning information.

8. The method for detecting abnormal behavior of bank personnel based on behavioral sequences according to claim 1, characterized in that, After automatically fixing the evidence chain of high-risk associated behavior sequences related to outliers in the comprehensive risk score to obtain the outlier detection results, the method further includes: Extract behavioral sequence features, spatiotemporal features, resource access features, and personnel attribute features of abnormal bank personnel from the abnormal behavior detection results, and generate multidimensional key features; The multidimensional key features are mapped to a fixed-length binary hash code using the locality-sensitive hashing algorithm, thus obtaining a behavioral semantic fingerprint. The behavioral semantic fingerprint is stored and associated with the evidence chain ID, abnormal behavior compressed file, and abnormal behavior early warning information in the abnormal behavior detection result, and the associated data package is stored in the risk case library.

9. A device for detecting abnormal behavior of bank personnel based on behavioral sequences, characterized in that, The device includes: At least one processor; and, A memory communicatively connected to the at least one processor; wherein, The memory stores instructions executable by the at least one processor to enable the at least one processor to perform the bank employee behavior anomaly detection method based on behavioral sequences according to any one of claims 1-8.

10. A non-volatile computer storage medium, characterized in that, The storage medium is a non-volatile computer-readable storage medium that stores at least one program, each program including instructions that, when executed by a terminal, cause the terminal to perform the bank personnel behavior anomaly detection method based on behavioral sequences according to any one of claims 1-8.