Transaction batch deduction anomaly detection method and system, terminal device and storage medium
By filtering out anomalies in multi-merchant transaction batches and calculating real-time transaction volume weights, combined with initial dispersion filtering and weight threshold comparison, the problem of high false alarm rate and complex detection in existing technologies is solved, achieving efficient and accurate anomaly detection.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- WEBANK (CHINA)
- Filing Date
- 2021-12-16
- Publication Date
- 2026-05-22
AI Technical Summary
Existing technologies have a high false alarm rate and complex detection process in multi-vendor transaction batch deduction anomaly detection, making it impossible to efficiently detect anomalies while meeting accuracy requirements.
By acquiring transaction volumes from multiple merchants, anomalies to be identified are filtered out using initial dispersion filtering rules. The weight of real-time batch deduction transaction volume in merchant groups is calculated and compared with pre-calculated weight thresholds to determine anomaly detection results. Combined with initial and re-inspections, a small amount of historical data is used for precise monitoring.
It achieves improved detection efficiency, reduced false alarms, and enhanced accuracy and efficiency of anomaly detection while meeting the requirements of accurate monitoring of transaction batch deduction anomalies.
Smart Images

Figure CN114202423B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of financial technology (Fintech), and in particular to an anomaly detection method, system, terminal device, and computer storage medium for transaction batch deduction. Background Technology
[0002] With the development of computer technology, more and more technologies are being applied in the financial field. The traditional financial industry is gradually transforming into financial technology. However, due to the requirements of security, real-time performance and stability in the financial industry, higher demands are also being placed on technology.
[0003] Currently, in the process of batch deduction of transactions for multiple merchants (timed tasks uniformly count and deduct transactions of merchants within a certain period of time), banks usually conduct continuous monitoring of the transaction volume of the payment application channel at the minute-by-minute time granularity so as to issue timely alarms when batch deduction anomalies are detected in real time.
[0004] In monitoring batch deductions for multi-merchant transactions, the industry typically employs two methods: setting thresholds and using prediction algorithms to detect anomalies and issue alerts. However, while setting thresholds can accurately trigger alerts for anomalies, it also generates a significant number of false alarms. This means that even when the transaction volume exceeds the threshold, the monitoring system may still trigger an alarm if the transaction volume is within the normal range. On the other hand, while prediction algorithms can reduce false alarms to some extent, they require extensive historical data to predict real-time transaction volumes. This not only consumes considerable storage space but also necessitates manual filtering of outliers from the historical data; otherwise, the prediction accuracy will be greatly reduced. Furthermore, this method requires retraining the prediction algorithm when adding new merchants, making the entire process of detecting batch deduction anomalies extremely complex.
[0005] In summary, how to improve the efficiency of detecting batch deduction anomalies while ensuring accurate monitoring of such anomalies is a technical problem that the industry urgently needs to solve. Summary of the Invention
[0006] The main objective of this invention is to provide a method, system, terminal device, and computer storage medium for detecting anomalies in transaction batch deductions. This invention aims to solve the technical problems of existing anomaly detection methods having high false alarm rates or complex detection processes, which fail to meet accuracy requirements while enabling simple and efficient detection of transaction volume anomalies. The invention aims to improve the efficiency of detecting batch deduction anomalies while ensuring accurate monitoring of transaction batch deduction anomalies.
[0007] To achieve the above objectives, the present invention provides an anomaly detection method for batch transaction deductions. This method is applied to detect anomalies in batch transaction deductions for multiple merchants and includes the following steps:
[0008] Obtain the transaction volume of the multi-merchant group according to the deduction cycle, and filter out the anomalies to be confirmed based on the transaction volume and the initial dispersion filtering rules.
[0009] Calculate the real-time batch deduction transaction volume weight of the multi-merchant in the target merchant group corresponding to the anomaly point;
[0010] The real-time batch deduction transaction volume weight is compared with the corresponding batch deduction transaction volume weight threshold of each of the multiple merchants in the target merchant group;
[0011] The anomaly detection result of the anomaly point is determined based on the comparison result between the real-time batch deduction transaction volume weight and the batch deduction transaction volume weight threshold, wherein the anomaly detection result includes: anomaly occurrence and false alarm occurrence.
[0012] Furthermore, to achieve the above objectives, the present invention also provides an anomaly detection device for transaction deductions. This device is used to detect anomalies in transaction deductions for multiple merchants. The anomaly detection device includes:
[0013] The initial inspection module is used to obtain the transaction volume of the multi-merchant deduction according to the deduction cycle, and to filter out the anomalies to be confirmed based on the transaction volume and the initial dispersion filtering rules.
[0014] The weight calculation module is used to calculate the real-time batch deduction transaction volume weight of the multiple merchants within the target merchant group corresponding to the anomaly point;
[0015] The comparison module is used to compare the real-time batch deduction transaction volume weight with the corresponding batch deduction transaction volume weight threshold of each of the multiple merchants in the target merchant group;
[0016] The re-inspection module is used to determine the anomaly detection result of the anomaly point based on the comparison result between the real-time batch deduction transaction volume weight and the batch deduction transaction volume weight threshold. The anomaly detection result includes: anomaly occurrence and false alarm occurrence.
[0017] In this invention, each functional module of the transaction batch deduction anomaly detection device implements the steps of the transaction batch deduction anomaly detection method as described above during operation.
[0018] In addition, to achieve the above objectives, the present invention also provides a terminal device, the terminal device comprising: a memory, a processor, and a transaction batch deduction anomaly detection program stored in the memory and executable on the processor, wherein the transaction batch deduction anomaly detection program, when executed by the processor, implements the steps of the transaction batch deduction anomaly detection method as described above.
[0019] In addition, to achieve the above objectives, the present invention also provides a computer storage medium storing an anomaly detection program for transaction batch deductions, wherein the anomaly detection program for transaction batch deductions, when executed by a processor, implements the steps of the anomaly detection method for transaction batch deductions as described above.
[0020] In addition, to achieve the above objectives, the present invention also provides a computer program product, which includes a computer program that, when executed by a processor, implements the steps of the abnormal detection method for transaction batch deduction as described above.
[0021] This invention provides a method, apparatus, terminal device, computer storage medium, and computer program product for detecting anomalies in batch transaction deductions. When detecting anomalies in batch transactions involving multiple merchants, the method involves acquiring the transaction volume of each merchant according to a deduction cycle, and filtering out anomalies to be confirmed based on the transaction volume and an initial dispersion filtering rule. The method calculates the real-time deduction transaction volume weight of each merchant in the target merchant group corresponding to the anomaly point. It then compares the real-time deduction transaction volume weight with the corresponding deduction transaction volume weight threshold for each merchant in the target merchant group. Finally, it determines the anomaly detection result based on the comparison result, where the anomaly detection result includes: anomaly occurrence and false alarm occurrence.
[0022] When performing anomaly detection for batch deductions of transactions from multiple merchants, this invention first obtains the transaction volume of each merchant according to the deduction cycle. Based on this transaction volume and an initial dispersion filtering rule, it filters out anomalies in the time series corresponding to the batch deductions of each merchant. Then, it calculates the real-time batch deduction transaction volume weight of each merchant in the target merchant group corresponding to the anomaly point. Next, it compares the real-time batch deduction transaction volume weight with the batch deduction transaction volume weight threshold of each merchant in the target merchant group to obtain the comparison result. Finally, based on the comparison result, it determines whether the anomaly detection result of the anomaly point is a genuine anomaly or a detection error alarm.
[0023] Compared to traditional methods for detecting anomalies in batch deductions for transactions, this invention first filters out potential anomalies based on initial dispersion filtering rules. Then, it independently calculates the real-time batch deduction transaction volume weights of multiple merchants within merchant groups. By comparing these weights with pre-calculated weight thresholds, the accurate anomaly detection result is finally determined. This allows for the individual detection of abnormal behavior at the time of batch deduction for two adjacent transaction volumes through intelligent grouping of multiple merchants. Combining "initial inspection" and "re-inspection," it can easily and efficiently detect anomalies using a small amount of historical data to calculate weight thresholds, while also accurately identifying anomalies and issuing alerts. This achieves the technical effect of improving the efficiency of batch deduction anomaly detection while meeting the requirements of accurate monitoring of transaction batch deduction anomalies. Attached Figure Description
[0024] Figure 1 This is a schematic diagram of the device structure of the terminal device hardware operating environment involved in the embodiments of the present invention;
[0025] Figure 2 This is a flowchart illustrating an embodiment of the abnormal detection method for transaction batch deduction of the present invention;
[0026] Figure 3 This is a schematic diagram illustrating an application scenario of an embodiment of the abnormal detection method for transaction batch deduction of the present invention;
[0027] Figure 4 This is a graph showing the transaction volume of multiple merchants involved in an embodiment of the abnormal detection method for batch deduction of transactions according to the present invention.
[0028] Figure 5 This is a functional module diagram of an embodiment of the abnormal detection device for transaction batch deduction of the present invention.
[0029] The realization of the objective, functional features and advantages of the present invention will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. Detailed Implementation
[0030] It should be understood that the specific embodiments described herein are merely illustrative of the invention and are not intended to limit the invention.
[0031] Reference Figure 1 , Figure 1 This is a schematic diagram of the hardware operating environment of the terminal device involved in the embodiments of the present invention.
[0032] The terminal device in this embodiment of the invention can be a terminal device configured to perform anomaly detection on transaction batch deductions for multiple merchants. The terminal device can be a server, smartphone, PC (Personal Computer), tablet computer, portable computer, etc.
[0033] like Figure 1 As shown, the terminal device may include: a processor 1001, such as a CPU; a communication bus 1002; a user interface 1003; a network interface 1004; and a memory 1005. The communication bus 1002 is used to enable communication between these components. The user interface 1003 may include a display screen and an input unit such as a keyboard; optionally, the user interface 1003 may also include a standard wired interface or a wireless interface. The network interface 1004 may optionally include a standard wired interface or a wireless interface (such as a Wi-Fi interface). The memory 1005 may be high-speed RAM or non-volatile memory, such as a disk drive. Optionally, the memory 1005 may also be a storage device independent of the aforementioned processor 1001.
[0034] Those skilled in the art will understand that Figure 1 The terminal device structure shown does not constitute a limitation on the terminal device and may include more or fewer components than shown, or combine certain components, or have different component arrangements.
[0035] like Figure 1 As shown, the memory 1005, which serves as a computer storage medium, may include an operating system, a network communication module, a user interface module, and an anomaly detection program for transaction batch deductions.
[0036] exist Figure 1 In the terminal shown, the network interface 1004 is mainly used to connect to the backend server and communicate data with the backend server; the user interface 1003 is mainly used to connect to the client and communicate data with the client; and the processor 1001 can be used to call the transaction batch deduction anomaly detection program stored in the memory 1005 and execute the following embodiments of the transaction batch deduction anomaly detection method.
[0037] Based on the above hardware structure, various embodiments of the abnormal detection method for transaction batch deduction of the present invention are proposed.
[0038] It should be noted that, currently, in the process of batch deduction of transactions for multiple merchants (timed tasks uniformly count and deduct funds from merchants' transactions within a certain period of time), banks usually continuously monitor the transaction volume of the payment application channel at the minute-by-minute time granularity so as to issue timely alerts when batch deduction anomalies are detected in real time.
[0039] In monitoring batch deductions for multi-merchant transactions, the industry typically employs two methods: setting thresholds and using prediction algorithms to detect anomalies and issue alerts. However, while setting thresholds can accurately trigger alerts for anomalies, it also generates a significant number of false alarms. This means that even when the transaction volume exceeds the threshold, the monitoring system may still trigger an alarm if the transaction volume is within the normal range. On the other hand, while prediction algorithms can reduce false alarms to some extent, they require extensive historical data to predict real-time transaction volumes. This not only consumes considerable storage space but also necessitates manual filtering of outliers from the historical data; otherwise, the prediction accuracy will be greatly reduced. Furthermore, this method requires retraining the prediction algorithm when adding new merchants, making the entire process of detecting batch deduction anomalies extremely complex.
[0040] In summary, how to improve the efficiency of detecting batch deduction anomalies while ensuring accurate monitoring of such anomalies is a technical problem that the industry urgently needs to solve.
[0041] To address the above-mentioned issues, this invention provides a method for detecting anomalies in transaction batch deductions. Please refer to... Figure 2 , Figure 2 This is a flowchart illustrating a first embodiment of the transaction batch deduction anomaly detection method of the present invention. In this embodiment, the transaction batch deduction anomaly detection method is applied to the terminal device configured to perform anomaly detection on transaction batch deductions for multiple merchants. It should be noted that although the logical order is shown in the flowchart, in some cases, the steps shown or described may be performed in a different order than that shown here.
[0042] The anomaly detection method for transaction batch deduction of this invention includes:
[0043] Step S10: Obtain the transaction volume of the multi-merchant deduction according to the deduction cycle, and filter out the anomalies to be confirmed according to the transaction volume and the initial dispersion filtering rules.
[0044] It should be noted that, in this embodiment, the initial dispersion filtering rule is to use the transaction volume of multiple merchants performing batch deductions, specifically represented by a curve graph, to preliminarily screen out potentially abnormal batch deduction behaviors for further confirmation based on the dispersion of the error curves between the transaction volume sequences. Anomalies are the time points in the time series formed by multiple merchants performing batch deductions according to the batch deduction cycle where the transaction volume is abnormal.
[0045] In the process of anomaly detection for batch deductions of transactions from multiple merchants, the terminal device first obtains the transaction volume of each merchant according to the set batch deduction cycle. Then, the terminal device calculates the degree of dispersion of the error curves between the transaction volume sequences corresponding to the transaction volumes of each merchant according to the initial dispersion filtering rules, and initially filters out the anomalies to be confirmed from the time series corresponding to the batch deductions of transactions from each merchant according to the set batch deduction cycle.
[0046] Furthermore, the deduction periods used by multiple merchants for transaction deductions can be the same or different. The specific transaction volume obtained by the terminal device based on each merchant's deduction period can be as follows: Figure 4 As shown in the graph, during working hours and non-working hours, due to the different transaction volumes of each merchant in different time periods, the deduction time initiated by the payment application for the transaction volume within that time period is also different (i.e., each merchant deducts transactions according to different deduction cycles). In addition, the indicator curve will increase sharply when the merchant deducts transactions, so the transaction volume at the minute-level granularity of the payment application channel will show a sudden increase and decrease pattern as monitored by the bank.
[0047] Specifically, the terminal device obtains such as Figure 4 The diagram shows the transaction volume of multiple merchants, each according to a pre-defined deduction cycle, processed by the payment application. Then, the diagram calculates the dispersion of the error curve between the transaction volume sequence e1 of the largest deduction cycle K1 and the transaction volume sequence e2 of the previous large deduction cycle K2. This filters out anomalies that indicate potential abnormalities in the transaction volume of one or more merchants for a given deduction cycle at a specific time point. Specifically, if the dispersion of the error curve between the transaction volume sequences of multiple merchants processed according to their respective deduction cycles exceeds a preset threshold at a certain time point, then that time point is considered an anomaly where the deduction transaction volume may be abnormal.
[0048] It should be noted that in this embodiment, since the variance of a sequence can represent the degree of dispersion of the sequence: the larger the variance, the greater the fluctuation of the sequence. Therefore, if the variance of an error sequence is relatively large, the alarm threshold for the error should be set relatively high. Based on this characteristic, the terminal device takes a continuous K-minute error sequence (where K is the value of the maximum deduction cycle) from the time series corresponding to the transaction deductions of multiple merchants according to their respective deduction cycles, and divides the error sequence into two sequences: e1 and e2. Therefore, if the difference between the means of the two sequences is greater than a multiple of λ (λ is the debugging parameter) of the variance of the e1 sequence, the terminal device determines that the time point corresponding to the error sequence in the entire time series may be an anomaly point where the transaction volume of the merchant's deduction is abnormal.
[0049] Step S20: Calculate the real-time batch deduction transaction volume weight of the multi-merchant in the target merchant group corresponding to the anomaly point;
[0050] After initially screening out the anomalies to be confirmed, the terminal device further calculates the real-time batch deduction transaction volume weight of each merchant in the target merchant group corresponding to the anomaly.
[0051] Specifically, the terminal device first obtains the total transaction volume deducted by each merchant within the deduction period corresponding to the target merchant group. Then, for each merchant, it first confirms whether the merchant exists in the target merchant group corresponding to the anomaly point. If confirmed, it further obtains the transaction volume deducted by the merchant within the deduction period corresponding to the target merchant group. The real-time deduction transaction volume weight of the merchant in the target merchant group is obtained by dividing the transaction volume by the total transaction volume mentioned above.
[0052] It should be noted that, in this embodiment, after the terminal device initially filters out the anomalies to be confirmed from the time series corresponding to the transaction batch deductions of the multiple merchants according to the batch deduction period based on the transaction volume represented by the curve and the above-mentioned initial dispersion filtering rules, it further confirms the anomalies based on the filtering conditions of the weight threshold.
[0053] Furthermore, the terminal device pre-groups the multiple merchants according to their respective transaction deduction cycles, resulting in multiple merchant groups. These merchant groups correspond to specific time points in the transaction deduction time series. After initially identifying anomalies, the terminal device determines the target merchant group corresponding to the anomaly based on the one-to-one correspondence between the anomaly and the merchant groups. It then further calculates the real-time deduction transaction volume weight for each merchant within that target merchant group.
[0054] In one feasible embodiment, the abnormal detection method for transaction batch deduction of the present invention may further include:
[0055] Step S50: Determine the deduction period for each of the multiple merchants, and perform grouping operations on the multiple merchants according to the deduction period to obtain merchant groups corresponding to the deduction period. The same merchant group contains multiple different merchants, and the same merchant belongs to different merchant groups at the same time.
[0056] In this embodiment, please refer to the following: Figure 3In the illustrated application scenario, before detecting potential anomalies in the payment application's batch deduction of transactions from multiple merchants, the terminal device pre-determines the deduction cycle for each of the multiple merchants and intelligently groups them according to this cycle. This divides the multiple merchants into multiple merchant groups, each corresponding to a specific deduction cycle. Each of these merchant groups contains multiple merchants, and the same merchant may appear in different groups simultaneously. For better understanding, an example is provided below:
[0057] Merchant A starts deducting fees at 00:01 and deducts fees once every 30 minutes, while Merchant B starts deducting fees at 01:01 and deducts fees once every 60 minutes. Thus, Merchant A will appear in groups 1, 31, 61, 91, 121, 151, 181, ..., 1381, and 1411, grouped according to the time sequence of the transaction deductions. Merchant B will appear in groups 1, 61, 121, 181, ..., 1381, grouped according to the time sequence of the transaction deductions (it can be observed that at least Merchant A and Merchant B exist simultaneously in these groups).
[0058] Furthermore, in a feasible embodiment, step S50 above may include:
[0059] Step S501: Obtain the first deduction time point and the second deduction time point when each of the multiple merchants performs two consecutive batch deductions for transactions;
[0060] Step S502: Calculate the deduction cycle for each of the multiple merchants' transactions based on the first deduction time point and the second deduction time point.
[0061] In the process of intelligently grouping multiple merchants, the terminal device first determines the deduction cycle for each merchant's transaction. That is, for each merchant, the terminal device sequentially obtains the first deduction time point and the second batch time point when the merchant conducts two consecutive transaction deductions. Then, the terminal device subtracts the first deduction time point from the second batch deduction time point to calculate the deduction cycle for the merchant's transaction.
[0062] Step 503: Determine the common deduction time points among the deduction time points of each of the multiple merchants according to the deduction cycle, wherein the number of the common deduction time points is greater than or equal to one.
[0063] Step 504: Divide the multiple merchants corresponding to the same batch deduction time point into the same merchant group.
[0064] After calculating the deduction cycle for each merchant by using the deduction time points of each merchant's two consecutive transactions, the terminal device further detects the deduction time points of each merchant's transactions according to their respective deduction cycles. Then, it identifies one or more identical deduction time points among these multiple deduction time points. The terminal device then directly classifies the merchants whose transaction deduction time points overlap with the one or more identical deduction time points into a merchant group corresponding to each identical deduction cycle.
[0065] It should be noted that in this embodiment, since each merchant among the multiple merchants has a different size, the deduction period K for each merchant's transaction deduction is also different (the deduction period for a single merchant is constant). For example, a merchant with a large number of transactions will have more deductions per day, and the smaller the period K, the more intensive the transaction deductions performed by the payment application on that merchant. Each merchant will deduct at least once a day, so the terminal device groups the multiple merchants according to the time sequence of the payment application's transaction deductions per minute, that is: the first minute is the first group, the Xth minute is the Xth group (group X), so there can be a maximum of X = 60 * 24 = 1440 groups per day.
[0066] Specifically, the time series for the payment application to deduct transactions from each merchant in a certain minute is assumed to be as follows:
[0067] Merchant 1: (a, K[1]+a, 2K[1]+a,…, nK[1]+a)
[0068] Merchant 2: (b, K[2]+b, 2K[2]+b, ..., nK[2]+b)
[0069] Merchant 3: (c, K[3]+c, 2K[3]+c, ..., nK[3]+c)
[0070] …
[0071] Merchant N: (n, 2K[N], 3K[N], ..., (n+1)K[N])
[0072] For example:
[0073] Merchant A starts deducting fees at 00:01 and deducts fees once every 30 minutes. The time sequence corresponding to Merchant A's transaction deductions is: 1m, 31m, 61m, 91m, 121m, 151m, 181m, ..., 1381m, 1411m. Since Merchant A deducts fees every 30 minutes, the deduction period K used by Merchant A is 30.
[0074] Merchant B starts deducting fees at 01:01 and deducts fees once every 60 minutes. The time sequence corresponding to Merchant B's transaction deductions is: 61m, 121m, 181m, ..., 1381m. Since Merchant B deducts fees every 60 minutes, the deduction period K used by Merchant B is 60.
[0075] After the terminal device determines the deduction period K for each merchant according to the above process, it can count all merchants participating in the first minute of deduction each day as the first group, and all merchants participating in the second minute of deduction each day as the second group, and so on to obtain a total of X groups.
[0076] Because different merchants may share the same deduction time period within their respective deduction cycles—meaning that nK[N]+n in the time series corresponding to transaction deductions for different merchants may specifically equal a certain minute—then these different merchants are grouped into the same merchant group. For example, Merchant A and Merchant B are grouped into the same merchant group at 61m, 121m, 181m, ..., 1381m. Furthermore, due to the different deduction periods K, a single merchant can exist in different merchant groups.
[0077] It should be noted that in this embodiment, if the terminal device divides the number of groups for multiple merchants into fewer groups, the number of merchants in each group will be more, and the transaction volume weight ratio of each merchant will be more stable. Based on this, the terminal device sorts the batch deduction period k of each merchant in order of size to obtain the batch deduction period sequence (K[1], K[2], K[3], ..., K[N]), and the maximum value of this sequence, MAX K[N], is the minimum value of the group X of the merchant grouping above, that is: X = MAX K[N].
[0078] Based on the aforementioned grouping operation of multiple merchants by the terminal device, a specific example is proposed for the terminal device to calculate the real-time batch deduction transaction volume weight of each merchant in the merchant group:
[0079] If Merchant A completes the batch deduction in the first minute, then Merchant A belongs to Group 1. If Merchant A completes the batch deduction in the second minute, then Merchant A also belongs to Group 2. That is, if Merchant A completes the batch deduction in the nth minute, then it belongs to Group n. Thus, the formula for calculating the real-time batch deduction transaction volume weight of each merchant in each merchant group is: Q[X]=P[A] / (P[A]+P[B]+…+P[N]), where P is the batch deduction transaction volume in a certain minute.
[0080] Step S30: Compare the real-time batch deduction transaction volume weight with the corresponding batch deduction transaction volume weight threshold of each of the multiple merchants in the target merchant group;
[0081] After calculating the real-time batch deduction transaction volume weight of each merchant in the target merchant group corresponding to the anomaly point, the terminal device further compares the real-time batch deduction transaction volume weight of each merchant with the corresponding batch deduction transaction volume weight threshold of that merchant in the target merchant group.
[0082] It should be noted that, in this embodiment, after the terminal device obtains X merchant groups through the above-mentioned grouping operation for multiple merchants, the terminal device further calculates the batch deduction transaction volume weight threshold of each of the multiple merchants in each merchant group.
[0083] Furthermore, in a feasible embodiment, the anomaly detection method for transaction batch deduction of the present invention may further include:
[0084] Step S60: Train the model according to the preset segmented threshold function to calculate the batch deduction transaction volume weight threshold of each of the multiple merchants in the merchant group.
[0085] In this embodiment, the preset segmented threshold function is specifically: f(x) = Σα.|Xi-Xj|. Here, i and j are positive integers, Xi and Xj are the weight percentages of merchant A's batch deduction transaction volume at the deduction time point within n days, relative to the total batch deduction transaction volume of all merchants in the same merchant group at that time point, and |Xi-Xj| is the weight threshold range for any two days. Therefore, the terminal device can train the batch deduction transaction volume weight threshold for merchant A in the same merchant group at the same deduction time point by summing all weight threshold ranges and multiplying by the automatic adjustment coefficient α (0 < α <= 1). Based on this, for any merchant group, the terminal device will only judge the merchant's batch deduction at that time as abnormal if |Q1-Q2| > f(x), given the current actual weight value Q1 and the historical average weight value Q2.
[0086] In this embodiment, compared to the existing technology that sets a threshold and immediately triggers an alarm once the batch deduction transaction volume exceeds the threshold, this embodiment calculates the batch deduction transaction volume weight threshold for each merchant within a merchant group through model training. Therefore, during the monitoring of batch deduction transactions, by comparing the real-time batch deduction transaction volume weight of each merchant with its respective batch deduction transaction volume weight threshold in the target merchant group, it ultimately determines whether an anomaly has actually occurred or a false alarm has been triggered. This effectively avoids false alarms caused by threshold-based alarms in existing technologies, achieving accurate monitoring of batch deduction anomalies. Furthermore, this embodiment incorporates an automatic adjustment coefficient to determine the batch deduction transaction volume weight threshold, enabling dynamic adjustment of the threshold. Compared to the industry practice of setting fixed thresholds, this further improves the accuracy of monitoring.
[0087] Step S40: Determine the anomaly detection result of the anomaly point based on the comparison result between the real-time batch deduction transaction volume weight and the batch deduction transaction volume weight threshold. The anomaly detection result includes: anomaly occurrence and false alarm occurrence.
[0088] After the terminal device sequentially compares the real-time batch deduction transaction volume weight of each merchant with the corresponding batch deduction transaction volume weight threshold of that merchant within the target merchant group, and obtains the corresponding comparison result, if the comparison result shows that the real-time batch deduction transaction volume weight of a certain merchant is a relatively stable value relative to the batch deduction transaction volume weight threshold of that merchant, the terminal device determines that the transaction batch deduction of that merchant at the abnormal point is normal. Thus, when it is determined that the transaction batch deduction of all merchants within the target merchant group at the abnormal point is normal, the anomaly detection result of the abnormal point is determined to be a false alarm. Alternatively, if it is determined that the transaction batch deduction of any merchant within the target merchant group at the abnormal point is not normal, the anomaly detection result of the abnormal point is determined to be an anomaly, and the transaction volume of the merchant at this time is determined to be the specific abnormal transaction volume.
[0089] It should be noted that, in this embodiment, after the terminal device calculates the real-time batch deduction transaction volume weight Q of each merchant in the target merchant group corresponding to the anomaly point based on the above process, it confirms the anomaly by detecting the change in the value of the weight Q. That is, when Q[A] = 0, i.e. P[A] = 0, the terminal device determines that the batch deduction of merchant A is abnormal at this time. When Q[X] is a relatively stable value relative to the batch deduction transaction volume weight threshold, the terminal device determines that the batch deduction of each merchant is normal at this time. In addition, when the Q[X] of multiple merchants is an unstable value relative to the batch deduction transaction volume weight threshold, the terminal device further determines whether a certain merchant in the merchant group corresponding to the anomaly point has promotion or other issues to be verified, in order to determine whether the batch deduction is abnormal at this time.
[0090] Furthermore, in a feasible embodiment, after determining the anomaly detection result of the abnormal point in step S40 above based on the comparison result of the real-time batch deduction transaction volume weight and the batch deduction transaction volume weight threshold, the anomaly detection method for batch deduction transactions of the present invention may further include:
[0091] Step S70: When the comparison result shows that the weight of the real-time batch deduction transaction volume exceeds the weight threshold of the batch deduction transaction volume, a preset weight adjustment coefficient is obtained.
[0092] It should be noted that in this embodiment, the preset weight adjustment system is the automatic adjustment coefficient α (0 < α <= 1) in the above piecewise threshold function f(x). The terminal device can obtain the historical weight proportion range of each merchant in its group through the historical normal batch deduction transaction volume and the adjustment of the automatic adjustment coefficient α, and then determine the abnormality. Among them, the selection of the reference value of the coefficient α is related to the historical data T of the merchant at the same moment on different days. Specifically, it can be obtained by the formula: α = 1 / (T - 1)!. Based on this formula, it can be seen that: the more historical data T, the smaller the value of α, and the more constant the value range of the function f(x) (because f(x) tends to a certain extreme value).
[0093] After the terminal device compares the real-time batch deduction transaction volume weight of each merchant with the batch deduction transaction volume weight threshold of the merchant in the target merchant group in turn to obtain the corresponding comparison result, if the comparison result shows that the real-time batch deduction transaction volume weight of a certain merchant is greater than the batch deduction transaction volume weight threshold relative to the batch deduction transaction volume weight threshold of the merchant, the terminal device will obtain the above weight adjustment coefficient α.
[0094] Step S80, customize the alarm for the abnormal point according to the real-time batch deduction transaction volume weight and the weight adjustment coefficient.
[0095] After the terminal device obtains the weight adjustment coefficient, it calculates based on the real-time batch deduction transaction volume weight of each merchant in the current target merchant group and the weight adjustment coefficient. When the calculated result still exceeds the corresponding threshold range, it determines that the batch deduction of the merchant's transaction at the current abnormal point is abnormal, so as to realize the customized alarm for this abnormality.
[0096] Specifically, for example, assume that the real-time batch deduction transaction volume weights of merchant A for the first minute in the corresponding time series of transaction batch deductions for n consecutive days calculated by the terminal device are as follows:
[0097] Merchant A's weight percentage in the first minute of the 1st day (%) 15 Merchant A's weight percentage in the first minute of the 2nd (%) 16 Merchant A's weight percentage in the first minute of the 3rd day (%) 17 Merchant A's weight percentage in the first minute of the 4th (%) 14 Merchant A's weight percentage in the first minute of the 5th (%) 15 Merchant A's weight percentage in the first minute of the 6th (%) 17 Merchant A's weight percentage in the first minute of the 7th (%) 18 … Xi,Xj
[0098] The terminal device takes the historical data of merchant A in the previous 3 days and calculates α = 1 / (3 - 1)! = 1 / 3. Thus, the piecewise threshold function f(x) = [|15 - 16| + |16 - 18| + |15 - 18|] / 3 = 1.33, and the average weight Q2 = 16.33. In this way, the batch deduction transaction volume weight threshold Q1 of merchant A in the corresponding merchant group at the first minute should be: 15 < Q1 < 17.66. Therefore, if the current value Q1 is not within this range, the terminal device will define the batch deduction of merchant A's transaction at the current abnormal point as abnormal.
[0099] Similarly, the terminal device calculates the historical data of Merchant A in the previous 7 days and obtains α = 1 / (7 - 1)! = 1 / 21 = 0.0476. Thus, the piecewise threshold function f(x) = [|15 - 16| + |16 - 18| + … + |17 - 15|] / 21 = 36 / 21 = 1.71, and the average weight Q2 = 16. In this way, the threshold Q1 of the batch deduction transaction volume weight of Merchant A in the corresponding merchant group at the 1st minute should be calculated as: 14.29 < Q1 < 17.71. Then, since the current weight value on the 7th day is 18, which is not within the range of 14.29 to 17.71, the terminal device will determine that the batch deduction of Merchant A at the 1st minute on the 7th day is abnormal.
[0100] In addition, if the terminal device determines that the current weight value 18 on the 7th day is a normal value during the batch deduction process, it can be adjusted through the α value. For example, by increasing a step size to adapt and modify the coefficient α to the optimal value, that is, f(x) = 36α, the average weight Q2 = 16, and based on Q1, when the current weight value is selected as 18, the optimal value of α for adaptation and adjustment is equal to 0.5.
[0101] In this embodiment, by adjusting the α value of the system, it can confirm and report an alarm when it is not within |Xi - Xj|. And, of course, the terminal device can also select the optimal α value through the machine algorithm training model to determine the optimal range of the real-time weight value, and then achieve precise customized alarm for abnormal points and exclude false alarms.
[0102] In this embodiment, during the process of the terminal device performing abnormal detection on the transaction batch deductions of multiple merchants, it first obtains the transaction volumes of each of these multiple merchants for batch deductions according to the set batch deduction cycle, and based on this transaction volume and the initial dispersion filtering rule, preliminarily screens out the abnormal points to be confirmed from the time series corresponding to the transaction batch deductions of each of these multiple merchants according to this batch deduction cycle. After that, the terminal device further confirms the abnormal points based on the filtering condition of the weight threshold. That is, the terminal device calculates the real-time batch deduction transaction volume weights of each of the multiple merchants in the corresponding target merchant group at the abnormal point one by one, and successively compares the real-time batch deduction transaction volume weight of each merchant with the threshold of the batch deduction transaction volume weight of this merchant in this target merchant group. In this way, if the comparison result shows that the real-time batch deduction transaction volume weight of a certain merchant is a relatively stable value compared to the threshold of the batch deduction transaction volume weight of this merchant, the terminal device determines that the transaction batch deduction of this merchant at the abnormal point is normal. Thus, when it is determined that the transaction batch deductions of all merchants in this target merchant group at this abnormal point are normal, it is determined that the abnormal detection result of this abnormal point is a false alarm. Or, if it is determined that the transaction batch deduction of any merchant in this target merchant group at this abnormal point is not normal, it is determined that the abnormal detection result of this abnormal point is an abnormality, and the transaction volume of this merchant for batch deduction at this time is determined as the specific abnormal transaction volume.
[0103] Compared to traditional methods for detecting anomalies in batch deductions for transactions, this invention first filters out potential anomalies based on initial dispersion filtering rules. Then, it independently calculates the real-time batch deduction transaction volume weights of multiple merchants within merchant groups. By comparing these weights with pre-calculated weight thresholds, the accurate anomaly detection result is finally determined. This allows for the individual detection of abnormal behavior at the time of batch deduction for two adjacent transaction volumes through intelligent grouping of multiple merchants. Combining "initial inspection" and "re-inspection," it can easily and efficiently detect anomalies using a small amount of historical data to calculate weight thresholds, while also accurately identifying anomalies and issuing alerts. This achieves the technical effect of improving the efficiency of batch deduction anomaly detection while meeting the requirements of accurate monitoring of transaction batch deduction anomalies.
[0104] Based on the first embodiment of the transaction deduction anomaly detection method of the present invention described above, a second embodiment of the transaction deduction anomaly detection method of the present invention is proposed. The main difference between the second embodiment of the transaction deduction anomaly detection method of the present invention and the first embodiment is that, in this embodiment, the transaction deduction anomaly detection method of the present invention may further include:
[0105] Step S1: Obtain the first batch of deduction periods for transactions of the proposed new merchants;
[0106] Step S2: Detect the first target period that is the same as the first batch deduction period in the batch deduction period corresponding to each of the merchant groups;
[0107] Step S3: Add the proposed new merchants to the merchant group corresponding to the first target period, wherein the number of merchants in the first target period and the number of merchant groups corresponding to the first target period are the same and greater than or equal to one.
[0108] Step S4: Calculate the new batch deduction transaction volume weight threshold for each of the multiple merchants, including the proposed new merchants, within the merchant group corresponding to the first target period.
[0109] In this embodiment, after the terminal device performs intelligent grouping operations on multiple merchants to obtain the aforementioned X merchant groups, it can further dynamically add newly added merchants as proposed new merchants to the corresponding merchant groups in real time. After adding the proposed new merchants to the corresponding merchant groups, it further recalculates the batch deduction transaction volume weight threshold for each merchant in the merchant group.
[0110] In addition, in a feasible embodiment, the terminal device first still automatically enters the corresponding merchant group according to the first batch deduction time point t of the to-be-added merchant. For example, if t1 is the 1st minute and it enters the 1st group, then for the nth minute, it correspondingly joins the nth group. After that, the terminal device further calculates the batch deduction period k = t2 - t1 according to the second batch deduction time point t2 of the to-be-added merchant, and then compares the k value with the maximum period MAX K[N] of the merchants. If k > MAX K[N], the grouping is the kth group; or, if k < MAX K[N], it follows the original grouping, that is, for the above-mentioned nth minute, it correspondingly joins the nth group.
[0111] Furthermore, in this embodiment, the abnormal detection method for transaction batch deduction of the present invention may further include:
[0112] Step S4, obtaining the second batch deduction period for the to-be-deleted merchant to perform transaction batch deduction, and deleting the second batch deduction period in the batch deduction periods corresponding to each of the merchant groups;
[0113] Step S5, performing grouping operations on the other merchants in the multi-merchants except the to-be-deleted merchant according to the batch deduction periods after deleting the second batch deduction period to obtain new merchant groups;
[0114] Step S6, calculating the batch deduction trading volume weight thresholds of the other merchants within the new merchant groups respectively.
[0115] In this embodiment, in addition to further dynamically adding the newly added merchants to the corresponding merchant groups in real time as the to-be-added merchants, the terminal device can also dynamically delete the to-be-deleted merchants that need to be served from the already divided merchant groups in real time. After deleting the to-be-deleted merchant from the corresponding merchant group, it further recalculates the batch deduction trading volume weight thresholds of each merchant in the merchant group.
[0116] Specifically, for example, when the terminal device needs to delete the to-be-deleted merchant from one or more already divided merchant groups, it first determines the second batch deduction period K of the to-be-deleted merchant, then deletes the second batch deduction period K from the batch deduction period sequence (K[1], K[2], K[3],..., K[N]) corresponding to the batch deduction periods of all merchants, and re-obtains the MAX K[N] in the remaining batch deduction periods after deleting the second batch deduction period K from the batch deduction period sequence. Then, based on the MAX K[N], the grouping X is defined according to the process of the above step S50, and then the batch deduction trading volume weight thresholds of each of the multiple merchants in each new merchant group are recalculated according to the process of the above step S60.
[0117] In addition, after deleting the merchant to be deleted from the corresponding merchant group, the terminal device further deletes the historical batch deduction data of the merchant to be deleted in the previous batch deduction cycle.
[0118] In this embodiment, the terminal device dynamically adds or deletes merchants for the service. It only needs to recalculate the new weight threshold based on the segmented threshold function. Unlike the traditional method, which requires retraining the preset algorithm after each merchant update, this simplifies the anomaly detection process when updating merchants and further improves the efficiency of batch deduction anomaly detection.
[0119] Furthermore, the present invention also provides an anomaly detection device for transaction deductions. This anomaly detection system for transaction deductions is applied to detect anomalies in transaction deductions for multiple merchants. Please refer to... Figure 5 , Figure 5 This is a functional module diagram of an embodiment of the abnormal detection device for transaction batch deduction of the present invention. Figure 5 As shown, the abnormal detection device for transaction batch deduction of the present invention includes:
[0120] The initial inspection module 10 is used to obtain the transaction volume of the multi-merchant deduction according to the deduction cycle, and to filter out the abnormal points to be confirmed according to the transaction volume and the initial dispersion filtering rules.
[0121] The weight calculation module 20 is used to calculate the real-time batch deduction transaction volume weight of the multi-merchant in the target merchant group corresponding to the anomaly point;
[0122] The comparison module 30 is used to compare the real-time batch deduction transaction volume weight with the corresponding batch deduction transaction volume weight threshold of each of the multiple merchants in the target merchant group;
[0123] The re-inspection module 40 is used to determine the anomaly detection result of the anomaly point based on the comparison result between the real-time batch deduction transaction volume weight and the batch deduction transaction volume weight threshold. The anomaly detection result includes: anomaly occurrence and false alarm occurrence.
[0124] Furthermore, the abnormal detection device for transaction batch deduction of the present invention further includes:
[0125] The intelligent grouping module is used to determine the deduction period for each of the multiple merchants, and to perform grouping operations on the multiple merchants according to the deduction period to obtain merchant groups corresponding to the deduction period. The same merchant group contains multiple different merchants, and the same merchant belongs to different merchant groups at the same time.
[0126] Furthermore, the intelligent grouping module includes:
[0127] The time point acquisition unit is used to acquire the first deduction time point and the second deduction time point when the multiple merchants each made two consecutive batch deductions for transactions.
[0128] The cycle calculation unit is used to calculate the batch deduction cycle for each of the multiple merchants' transactions based on the corresponding first batch deduction time point and the second batch deduction time point.
[0129] The determining unit is configured to determine the same deduction time point among the deduction time nodes of each of the multiple merchants according to the deduction cycle, wherein the number of the same deduction time points is greater than or equal to one.
[0130] The grouping unit is used to divide multiple merchants corresponding to the same batch deduction time point into the same merchant group.
[0131] Furthermore, the abnormal detection device for transaction batch deduction of the present invention further includes:
[0132] The threshold calculation module is used to train the model according to the preset segmented threshold function to calculate the batch deduction transaction volume weight threshold of each of the multiple merchants in the merchant group.
[0133] Furthermore, the anomaly detection device for transaction deduction of the present invention also includes a merchant update module, which includes:
[0134] The first cycle acquisition unit is used to acquire the first batch of deduction cycles for transactions of the proposed new merchants.
[0135] The detection unit is used to detect the first target period that is the same as the first batch deduction period in the batch deduction period corresponding to each of the merchant groups;
[0136] A merchant addition unit is used to add the proposed new merchant to the merchant group corresponding to the first target period, wherein the number of the first target period and the merchant group corresponding to the first target period are the same and greater than or equal to one.
[0137] The first threshold calculation unit is used to calculate the new batch deduction transaction volume weight threshold for each of the multiple merchants, including the proposed new merchants, within the merchant group corresponding to the first target period.
[0138] Furthermore, the merchant update module also includes:
[0139] The second cycle acquisition unit is used to acquire the second batch deduction cycle of the transaction batch deduction of the merchant to be deleted, and delete the second batch deduction cycle in the batch deduction cycle corresponding to each of the merchant groups.
[0140] The merchant deletion unit is used to perform grouping operations on the merchants other than the merchant to be deleted among the multiple merchants according to each batch deduction cycle after the deletion of the second batch deduction cycle to obtain new merchant groups.
[0141] The second threshold calculation unit is used to calculate the batch deduction transaction volume weight threshold for each of the other merchants in the new merchant group.
[0142] Furthermore, the abnormal detection device for transaction batch deduction of the present invention further includes:
[0143] The self-adjustment module is used to obtain a preset weight adjustment coefficient when the comparison result shows that the weight of the real-time batch deduction transaction volume exceeds the weight threshold of the batch deduction transaction volume.
[0144] A customized alarm module is used to provide customized alarms for the anomalies based on the real-time batch deduction transaction volume weight and the weight adjustment coefficient.
[0145] The functions of each module in the above-mentioned abnormal detection device for transaction batch deduction correspond to the steps in the above-mentioned abnormal detection method embodiment for transaction batch deduction, and their functions and implementation processes will not be described in detail here.
[0146] The present invention also provides a computer storage medium storing an anomaly detection program for transaction batch deductions, wherein the anomaly detection program for transaction batch deductions, when executed by a processor, implements the steps of the anomaly detection method for transaction batch deductions as described in any of the above embodiments.
[0147] The specific embodiments of the computer storage medium of the present invention are basically the same as the embodiments of the above-described abnormal detection method for transaction batch deduction, and will not be described in detail here.
[0148] The present invention also provides a computer program product, the computer program product comprising a computer program, which, when executed by a processor, implements the steps of the abnormal detection method for transaction batch deduction as described in any of the above embodiments.
[0149] The specific embodiments of the computer program product of the present invention are basically the same as the embodiments of the above-mentioned abnormal detection method for transaction batch deduction, and will not be described in detail here.
[0150] The above are merely preferred embodiments of the present invention and do not limit the scope of the patent. Any equivalent structural or procedural transformations made based on the description and drawings of the present invention, or direct or indirect applications in other related technical fields, are similarly included within the scope of patent protection of the present invention.
Claims
1. A method for detecting anomalies in transaction batch deductions, characterized in that, The anomaly detection method for batch transaction deductions is applied to detect anomalies in batch transaction deductions for multiple merchants. The anomaly detection method for batch transaction deductions includes the following steps: Obtain the transaction volume of the multi-merchant group according to the deduction cycle, and filter out the anomalies to be confirmed based on the transaction volume and the initial dispersion filtering rules. Calculate the real-time batch deduction transaction volume weight of the multi-merchant in the target merchant group corresponding to the anomaly point; The real-time batch deduction transaction volume weight is compared with the corresponding batch deduction transaction volume weight threshold of each of the multiple merchants in the target merchant group; The anomaly detection result of the anomaly point is determined based on the comparison result between the real-time batch deduction transaction volume weight and the batch deduction transaction volume weight threshold, wherein the anomaly detection result includes: anomaly occurrence and false alarm occurrence; The batch deduction transaction volume weight threshold is determined in the following ways, including: Obtain the first batch of deduction periods for transactions of the proposed new merchants; Detect the first target period that is the same as the first batch deduction period in the batch deduction period corresponding to each of the merchant groups; The proposed new merchants are added to the merchant group corresponding to the first target period, wherein the number of the first target period and the number of the merchant group corresponding to the first target period are the same and greater than or equal to one. Calculate the new batch deduction transaction volume weight threshold for each of the multiple merchants, including the proposed new merchants, within the merchant group corresponding to the first target period; or... Obtain the second batch deduction period for transactions of the merchant to be deleted, and delete the second batch deduction period in the corresponding batch deduction period of each of the merchant groups. Based on the deduction cycles after deleting the second batch, new merchant groups are obtained by grouping the other merchants in the multi-merchant group, excluding the merchants to be deleted. Calculate the batch deduction transaction volume weight threshold for each of the other merchants in the new merchant group.
2. The abnormal detection method for transaction batch deduction as described in claim 1, characterized in that, The method for detecting anomalies in transaction batch deductions also includes the following steps: The deduction period for each of the multiple merchants is determined, and the multiple merchants are grouped according to the deduction period to obtain merchant groups corresponding to the deduction period. The same merchant group contains multiple different merchants, and the same merchant belongs to different merchant groups at the same time.
3. The abnormal detection method for transaction batch deduction as described in claim 2, characterized in that, The step of determining the deduction period for each of the multiple merchants, and grouping the multiple merchants according to the deduction period to obtain merchant groups corresponding to the deduction period, includes: Obtain the first and second deduction timestamps of each of the multiple merchants when they each make two consecutive batch deductions for transactions. The deduction cycle for each of the multiple merchants' transactions is calculated based on the corresponding deduction time points of the first and second batches. Based on the deduction cycle, the common deduction time points among the deduction time points of each of the multiple merchants are determined, wherein the number of the common deduction time points is greater than or equal to one. Multiple merchants corresponding to the same batch deduction time point are grouped into the same merchant group.
4. The anomaly detection method for transaction batch deduction as described in any one of claims 1 to 3, characterized in that, After the step of determining the anomaly detection result of the anomaly point based on the comparison result of the real-time batch deduction transaction volume weight and the batch deduction transaction volume weight threshold, the method further includes: When the comparison result shows that the weight of the real-time batch deduction transaction volume exceeds the weight threshold of the batch deduction transaction volume, a preset weight adjustment coefficient is obtained; Customized alerts are generated for the anomalies based on the real-time batch deduction transaction volume weight and the weight adjustment coefficient.
5. An anomaly detection device for transaction batch deduction, characterized in that, The transaction batch deduction anomaly detection device is used to detect anomalies in transaction batch deductions for multiple merchants. The transaction batch deduction anomaly detection device includes: The initial inspection module is used to obtain the transaction volume of the multi-merchant deduction according to the deduction cycle, and to filter out the anomalies to be confirmed based on the transaction volume and the initial dispersion filtering rules. The weight calculation module is used to calculate the real-time batch deduction transaction volume weight of the multiple merchants within the target merchant group corresponding to the anomaly point; The comparison module is used to compare the real-time batch deduction transaction volume weight with the corresponding batch deduction transaction volume weight threshold of each of the multiple merchants in the target merchant group; The re-inspection module is used to determine the anomaly detection result of the anomaly point based on the comparison result between the real-time batch deduction transaction volume weight and the batch deduction transaction volume weight threshold, wherein the anomaly detection result includes: anomaly occurrence and false alarm occurrence; The threshold calculation module is used to obtain the first batch of deduction periods for transactions of newly added merchants; Detect the first target period that is the same as the first batch deduction period in the batch deduction period corresponding to each of the merchant groups; The proposed new merchants are added to the merchant group corresponding to the first target period, wherein the number of the first target period and the number of the merchant group corresponding to the first target period are the same and greater than or equal to one. Calculate the new batch deduction transaction volume weight threshold for each of the multiple merchants, including the proposed new merchants, within the merchant group corresponding to the first target period; or... Obtain the second batch deduction period for transactions of the merchant to be deleted, and delete the second batch deduction period in the corresponding batch deduction period of each of the merchant groups. Based on the deduction cycles after deleting the second batch, new merchant groups are obtained by grouping the other merchants in the multi-merchant group, excluding the merchants to be deleted. Calculate the batch deduction transaction volume weight threshold for each of the other merchants in the new merchant group.
6. A terminal device, characterized in that, The terminal device includes: a memory, a processor, and a transaction batch deduction anomaly detection program stored in the memory and executable on the processor. When the transaction batch deduction anomaly detection program is executed by the processor, it implements the steps of the transaction batch deduction anomaly detection method as described in any one of claims 1 to 4.
7. A computer storage medium, characterized in that, The computer storage medium stores an anomaly detection program for transaction batch deductions. When the anomaly detection program for transaction batch deductions is executed by the processor, it implements the steps of the anomaly detection method for transaction batch deductions as described in any one of claims 1 to 4.