A Fast Anti-Money Laundering Detection Method Based on Transaction Graph

By using a graph neural network based on location information in anti-money laundering detection, the transaction map is constructed and feature aggregation is solved, and the problem of the existing technology being difficult to monitor dynamic transaction maps in real time and fully evaluate social network relationships is achieved, and more efficient anti-money laundering detection is achieved.

CN114372803BActive Publication Date: 2025-06-03TONGJI UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111528301.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-12-14
Publication Date
2025-06-03
Estimated Expiration
2041-12-14

AI Technical Summary

Technical Problem

Existing anti-money laundering detection technologies are difficult to monitor dynamic transaction maps in real time, and focus on analyzing a single node or a single transaction, making it difficult to fully evaluate the impact of potential social network relationships in the transaction map on risks.

Method used

The graph neural network based on location information is used to build a transaction graph, aggregate node and full graph features, use the graph attention model to predict the high-risk situation of transactions between nodes, and update the graph neural network through the historical transaction database to detect the propagation chain of money laundering transactions.

Benefits of technology

Real-time accurate monitoring of dynamic transaction maps is realized, potential social relationships in the transaction maps are discovered, and the accuracy and coverage of anti-money laundering detection are improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114372803B_ABST
    Figure CN114372803B_ABST
Patent Text Reader

Abstract

The present invention relates to a fast anti-money laundering detection method based on a transaction graph, specifically including: S1, obtaining transaction data streams and constructing a directed graph structure to form a transaction graph; S2, making a preliminary judgment on the transaction graph, if a hit occurs, the transaction is blocked, otherwise it is sent to a graph neural network based on location information; S3, performing feature learning according to the transaction characteristics of each node, and aggregating node features and global graph features; S4, predicting the transactions between nodes according to the node features and global graph features, if it is a high risk, it is judged by an expert and sent to the historical transaction database, if it is a low risk, the transaction result is recorded and sent to the historical transaction database; S5, the historical transaction database updates the network according to the transaction results. Compared with the prior art, the present invention has the advantages of fully considering the situation of transactions changing over time, improving the accuracy of transaction monitoring, discovering potential social relationships in the network, and improving the accuracy and coverage rate of anti-money laundering detection results, etc.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of transaction detection, and in particular to a fast anti-money laundering detection method based on a transaction graph. Background Art

[0002] For decades, money laundering has been an important criminal activity within financial computing systems. In today's technology-driven society, criminals are using all available means to launder the proceeds of their illegal activities. With the development of technology, the dynamic nature of information systems has reduced the effectiveness of existing money laundering detection mechanisms. The process of money laundering crimes has become more concealed, and money laundering methods have become more complex, intelligent, and gang-related, which has brought new problems and challenges to the traditional anti-money laundering supervision system.

[0003] Anomaly detection, as the primary goal of anti-money laundering supervision, has become a key topic of current research. Currently, the main challenge in detecting abnormal transactions is to construct effective rules and models from massive heterogeneous transaction data to make anti-money laundering detection more rapid and accurate, so as to achieve the purpose of effective financial market security supervision. To this end, breaking the traditional anti-money laundering supervision thinking and constructing an intelligent anti-money laundering supervision scheme based on data and using technologies such as artificial intelligence and big data analysis has become a trend. Through a literature search of existing technologies, it is found that anomaly detection in the context of anti-money laundering mostly focuses on the detection of single transactions or single nodes. For example, in the Chinese patent "A Detection Method and System for Money Laundering Transactions in Complex Related Transactions" (authorization number CN112508705A), it is proposed to establish a recurrent neural network model, collect multiple mutually related transaction data of unknown money laundering status, and input them into the trained recurrent neural network model in sequence to obtain a judgment result on whether it is money laundering. In the Chinese patent "An Intelligent Suspicious Transaction Monitoring Method Based on a Semi-Supervised Graph Neural Network" (authorization number CN110400220A), it is proposed to input a high-risk density fund transaction network and individual transaction characteristics of an account into the semi-supervised graph neural network. The semi-supervised graph neural network outputs the fund transaction risk probability of the account, and an account with a fund transaction risk probability higher than the first threshold is judged as a high money laundering risk account. Existing related research has made good progress in improving the accuracy of anomaly transaction detection, but there are still the following two major defects: First, due to the continuous dynamic change of the real-time transaction graph, the existing anti-money laundering detection methods based on graph neural networks cannot accurately monitor the dynamic transaction graph in real time. Second, due to the existing anti-money laundering schemes focusing on analyzing single nodes or single transactions, it is difficult to fully evaluate the impact of the associated relationship, that is, the potential social network relationship in the transaction graph, on the risk. Summary of the Invention

[0004] The object of the present invention is to provide a fast anti-money laundering detection method based on a transaction graph to overcome the deficiencies of the existing technologies mentioned above, which cannot accurately monitor the dynamic transaction graph in real time and focus on analyzing a single node or a single transaction.

[0005] The object of the present invention can be achieved by the following technical solutions:

[0006] A fast anti-money laundering detection method based on a transaction graph specifically includes the following steps:

[0007] S1. Obtain the transaction data streams of multiple accounts, and construct a directed graph structure according to the transaction data streams to form a transaction graph;

[0008] S2. Take the blacklist and money laundering rules as the benchmark to make a preliminary judgment on the transaction graph. If it hits, block the transaction; if it does not hit, send it to the graph neural network based on location information;

[0009] S3. The graph neural network based on location information performs feature learning according to the transaction features of each node in the transaction graph, updates the unlabeled transaction features, and aggregates the node features and the whole graph features;

[0010] S4. The graph attention model in the graph neural network predicts the transactions between nodes according to the node features and the whole graph features. If the prediction result is high-risk, send the transaction information to the anti-money laundering expert strategy center for expert discrimination, and send the feedback result to the historical transaction database; if the prediction result is low-risk, record the corresponding transaction result and send it to the historical transaction database;

[0011] S5. The historical transaction database updates the graph neural network according to the high-risk and low-risk transaction results, searches for the potential propagation chain of money laundering transactions, and thus detects multiple illegal nodes participating in the same money laundering case.

[0012] In the transaction graph, nodes represent users or merchants, and edges represent transactions.

[0013] In the transaction graph, the Elliptic dataset is used as the standard for collecting transaction features.

[0014] Furthermore, 166 features are collected for each transaction in the transaction graph, where 94 features are the local information of the transaction account, and the other 72 features are the transaction data statistically obtained by aggregating the transaction information one hop forward / backward from the central node as aggregation features.

[0015] Furthermore, the local information of the transaction account includes time step, transaction fee, number of inputs / outputs, output amount, and multiple total data, and the transaction data corresponding to the aggregation features includes maximum value, minimum value, and standard deviation.

[0016] The directed graph is G = ((V, M), E), where V = {v u1 , v u2 , v u3 ,..., v un} is a series of trading users, M = {v m1 , v m2 , v m3 ,..., v mn} is a series of merchants, and E = {e 1 , e 2 , e 3 ,..., e |E|} represents a series of transactions (when a transaction occurs between a user and a merchant, an edge is created between these two nodes).

[0017] The formula for updating the edge features in the graph neural network in step S5 is as follows:

[0018] e′ ij = NN(e ij , v i , m j , v g )

[0019] where e′ ij is the updated edge feature, NN represents a neural network with two fully connected layers and the activation function ReLu, e ij is the edge feature before update, v g is the feature vector corresponding to the directed graph G of the transaction graph, v i and m j are nodes in the directed graph, where v i ∈V, m j ∈M.

[0020] Furthermore, the edge feature e ij represents the edge between nodes i and j, and the corresponding feature vector includes the number of transactions and the transaction location.

[0021] The formula for updating the node features in the graph neural network in step S5 is as follows:

[0022]

[0023]

[0024] where v‘ ui and v‘ mi are the updated user node feature and merchant node feature, v ui and v mi are the user node feature and merchant node feature before update, Ni Represents all edges connected to node v i connected.

[0025] The formula for updating the feature vector of the directed graph G in the graph neural network in step S5 is as follows:

[0026]

[0027] where, is the updated feature vector of the directed graph G, is the mean of the feature vectors of all user nodes in the directed graph, is the mean of the feature vectors of all merchant nodes in the directed graph, is the mean of all edges in the directed graph.

[0028] The graph neural network based on location information includes a graph convolutional network based on the attention mechanism, which accepts as input, where χ is the edge feature constructed in the graph neural network, N 1 is the dimension of the time window, N 2 is the feature dimension of v f and v f is v‘ g 、v‘ ui 、v‘ mi 、e′ ij The concatenated feature vector obtained. That is, a feature vector v that combines transaction features, relationship features between graphs, etc. is constructed for each time window f .

[0029] Furthermore, a time attention layer is provided in the graph convolutional network. To better capture the patterns of transactions changing over time, the specific formula is as follows:

[0030]

[0031]

[0032] where, β t,j refers to the weight parameter of time window t, NN is a feed-forward network, W * is the parameter to be trained in this time attention network, λ 1 is a process parameter, and rept is the output result of each transaction in the graph convolutional network. Compared with the one-dimensional convolutional layer, the two-dimensional convolutional layer can better utilize the time information in the features. Therefore, a 2D convolutional layer and a 2D pooling layer are connected after the attention network.

[0033] Furthermore, a prediction layer is provided in the graph neural network based on location information. The output of the prediction layer is the fraud probability of the transaction. The prediction layer has a loss function L, and the specific formula is as follows:

[0034]

[0035] Among them, N is the number of nodes, and y i is the weight parameter, where λ 2 is the weight of positive and negative samples, and rept i is the feature vector of each transaction in structure 2), and detect(rept i ) is the prediction layer, which uses two layers of ReLu and one layer of sigmoid to complete the output of the prediction result and is trained using SGD.

[0036] Compared with the prior art, the present invention has the following beneficial effects:

[0037] 1. The present invention constructs features for the transaction situation of the knowledge graph in each time window in real time, fully considering the situation of transactions changing over time. Compared with the prior art that is difficult to capture real-time changing graph information, the present invention effectively improves the accuracy of transaction monitoring. Moreover, when using the model for real-world prediction, the historical high-risk data is recorded in the historical transaction database and fed back to the network in real time, enabling the network to be updated in a timely manner.

[0038] 2. The present invention designs a graph neural network based on location information, which aims to aggregate the feature relationships of nodes and the entire graph. Compared with the prior art that is difficult to capture potential relationship information in the graph, the present invention can discover potential social relationships in the network and improve the accuracy and coverage rate of anti-money laundering detection results. BRIEF DESCRIPTION OF THE DRAWINGS

[0039] Figure 1 is a schematic flowchart of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0040] The present invention will be described in detail below with reference to the accompanying drawings and specific embodiments. This embodiment is implemented on the premise of the technical solution of the present invention, and gives the detailed implementation method and specific operation process, but the protection scope of the present invention is not limited to the following embodiments.

[0041] Embodiment

[0042] As Figure 1 shown, a fast anti-money laundering detection method based on a transaction graph specifically includes the following steps:

[0043] S1. Obtain the transaction data streams of multiple accounts, and construct a directed graph structure according to the transaction data streams to form a transaction graph;

[0044] S2. Take the blacklist and money laundering rules as the benchmark to make a preliminary judgment on the transaction graph. If it hits, the transaction is blocked; if it does not hit, it is sent to the graph neural network based on location information;

[0045] S3. The graph neural network based on location information performs feature learning according to the transaction features of each node in the transaction graph, updates the unlabeled transaction features, and aggregates node features and global graph features;

[0046] S4. The graph attention model in the graph neural network predicts the transactions between nodes based on the node features and global graph features. If the prediction result is high-risk, the transaction information is sent to the anti-money laundering expert strategy center for expert judgment, and the feedback result is sent to the historical transaction database. If the prediction result is low-risk, the corresponding transaction result is recorded and sent to the historical transaction database;

[0047] S5. The historical transaction database updates the graph neural network according to the high-risk and low-risk transaction results, searches for potential propagation chains of money laundering transactions, and thus detects multiple illegal nodes involved in the same money laundering case.

[0048] Nodes in the transaction graph represent users or merchants, and edges represent transactions.

[0049] In the transaction graph, the Elliptic dataset is used as the standard for collecting transaction features.

[0050] Each transaction in the transaction graph collects 166 features, of which 94 features are local information of the transaction account, and the other 72 features are transaction data statistically obtained by aggregating transaction information one hop forward / backward from the central node as aggregation features.

[0051] The local information of the transaction account includes time step, transaction fee, number of inputs / outputs, output amount, and multiple total data. The transaction data corresponding to the aggregation features includes maximum value, minimum value, and standard deviation.

[0052] The directed graph is G = ((V, M), E), where V = {v u1 , v u2 , v u3 ,..., v un} is a series of transaction users, M = {v m1 , v m2 , v m3 ,..., v mn} is a series of merchants, and E = {e 1 , e 2 , e 3 ,..., e |E|} represents a series of transactions (when a transaction occurs between a user and a merchant, an edge is created between these two nodes).

[0053] The formula for updating the features of the edges in the graph neural network in step S5 is as follows:

[0054] e' ij = NN(e ij , v i , m j , v g )

[0055] Among them, e' ij is the feature of the updated edge, NN represents a neural network with two fully connected layers and the activation function ReLu, e ij is the feature of the edge before update, v g is the feature vector corresponding to the directed graph G of the transaction graph, v i and m j are nodes in the directed graph, where v i ∈ V, m j ∈ M.

[0056] The edge feature e ij represents the edge between nodes i and j, and the corresponding feature vector includes the number of transactions and the transaction location.

[0057] The formula for updating the features of nodes in the graph neural network in step S5 is as follows:

[0058]

[0059]

[0060] Among them, v' ui and v' mi are the updated user node feature and merchant node feature, v ui and v mi are the user node feature and merchant node feature before update, N i represents all the edges connected to node v i .

[0061] The formula for updating the feature vector of the directed graph G in the graph neural network in step S5 is as follows:

[0062]

[0063] Among them, is the updated feature vector of the directed graph G, is the mean value of all user node features in the directed graph, is the mean value of all merchant node features in the directed graph, is the mean value of all edges in the directed graph.

[0064] The graph neural network based on location information includes a graph convolutional network based on the attention mechanism, which accepts as input, where χ is the edge feature constructed in the graph neural network, N1 is the dimension of the time window, N 2 is v f the feature dimension of v f is v'g 、 v′ ui and v′ mi and e′ ij The concatenated feature vector. That is, a feature vector v that combines transaction features, relationship features between graphs, etc. is constructed for each time window f .

[0065] There is a time attention layer in the graph convolutional network. To better capture the patterns of transactions changing over time, the specific formula is as follows:

[0066]

[0067]

[0068] Among them, β t,j is the weight parameter of the time window t, NN is a feedforward network, W * is the parameter to be trained in this time attention network, λ 1 is a process parameter, and rept is the output result of each transaction in the graph convolutional network. Compared with the one-dimensional convolutional layer, the two-dimensional convolutional layer can better utilize the time information in the features. Therefore, a 2D convolutional layer and a 2D pooling layer are connected after the attention network.

[0069] There is a prediction layer in the graph neural network based on location information. The output of the prediction layer is the fraud probability of the transaction. The prediction layer has a loss function L, and the specific formula is as follows:

[0070]

[0071] Among them, N is the number of nodes, y i is the weight parameter, where λ 2 is the weight of positive and negative samples, rept i is the feature vector of each transaction in structure 2), detect(rept i ) is the prediction layer, which uses two layers of ReLu and one layer of sigmoid to complete the output of the prediction result and is trained using SGD.

[0072] In this embodiment, the detection of anti-money laundering has two steps: pre-admission and post-event monitoring. At pre-admission, the blacklist and money laundering rules are used as the benchmark to judge the fraudulence of transaction orders. If it is a high-risk transaction, the transaction is directly blocked. Post-event monitoring refers to using an algorithm model that predicts the money laundering probability to predict the risk of transactions, and transactions with a high likelihood of money laundering are referred to experts for further judgment.

[0073] In specific implementation, the transaction data in the transaction graph arrives in the form of a distributed queue, and pre-admission is performed on it. The GAT network is used for prediction, and a memory database is used to record this historical transaction data. If the prediction result shows that the order is a high-risk money laundering transaction, it is handed over to an expert for judgment, and the judgment result is returned to the historical database. The data in the historical database can play a role in offline update. On the one hand, it can act on the GAT network to enable the network to be updated in real time. On the other hand, it can also help improve the pre-admission rules.

[0074] In addition, it should be noted that for the specific embodiments described in this specification, the names taken may be different. The above content described in this specification is only an example of the structure of the present invention. Any equivalent changes or simple changes made according to the structure, features, and principles conceived by the present invention are included in the protection scope of the present invention. Those skilled in the art of the present invention can make various modifications, supplements, or use similar methods to the described specific examples, as long as they do not deviate from the structure of the present invention or exceed the scope defined by this claim book, they should fall within the protection scope of the present invention.

Claims

1. A fast anti-money laundering detection method based on a transaction graph, characterized in that, it specifically includes the following steps: S1. Obtain the transaction data streams of multiple accounts, and construct a directed graph structure according to the transaction data streams to form a transaction graph; S2. Use the blacklist and money laundering rules as a benchmark to make a preliminary judgment on the transaction graph. If it hits, block the transaction. If it does not hit, send it to the graph neural network based on location information; S3. The graph neural network based on location information performs feature learning according to the transaction characteristics of each node in the transaction graph, updates the unlabeled transaction characteristics, and aggregates node features and global graph features; S4. The graph attention model in the graph neural network predicts the transactions between nodes according to the node features and global graph features. If the prediction result is high-risk, send the transaction information to the anti-money laundering expert strategy center for expert discrimination, and send the feedback result to the historical transaction database. If the prediction result is low-risk, record the corresponding transaction result and send it to the historical transaction database; S5. The historical transaction database updates the graph neural network according to the high-risk and low-risk transaction results, searches for the potential propagation chain of money laundering transactions, and thus detects multiple illegal nodes participating in the same money laundering case.

2. The fast anti-money laundering detection method based on a transaction graph according to claim 1, characterized in that, nodes in the transaction graph represent users or merchants, and edges represent transactions.

3. The fast anti-money laundering detection method based on a transaction graph according to claim 2, characterized in that, 166 features are collected for each transaction in the transaction graph, where 94 features are local information of the transaction account, and the other 72 features are transaction data statistically aggregated from one-hop forward / backward transaction information of the central node as aggregation features.

4. The fast anti-money laundering detection method based on a transaction graph according to claim 3, characterized in that, the local information of the transaction account includes time step, transaction fee, number of inputs / outputs, output amount, and multiple total data, and the transaction data corresponding to the aggregation features includes maximum value, minimum value, and standard deviation.

5. The fast anti-money laundering detection method based on a transaction graph according to claim 1, characterized in that, the formula for updating the features of the edges in the graph neural network in step S5 is as follows: e′ ij = NN(e ij , v i , m j , v g ) Among them, e' ij is the feature of the updated edge. NN represents a neural network with two fully connected layers and the activation function ReLu. e ij is the feature of the edge before update, v g is the feature vector corresponding to the directed graph G of the transaction graph, v i and m j are nodes in the directed graph, where v i ∈V, m j ∈M, V = {v u1 , v u2 , v u3 , …, v un} is a series of trading users, and M = {v m1 , v m2 , v m3 , …, v mn} is a series of merchants.

6. The fast anti-money laundering detection method based on a transaction graph according to claim 5, characterized in that, the formula for updating the features of the nodes in the graph neural network in step S5 is as follows: Among them, v ‘ ui and v ‘ mi are the updated user node features and merchant node features, and v ui and v mi are the user node features and merchant node features before update. N i represents all the edges connected to the node v i connected.

7. The fast anti-money laundering detection method based on a transaction graph according to claim 6, characterized in that, the formula for updating the feature vector of the directed graph G in the graph neural network in step S5 is as follows: Among them, v g ‘ is the eigenvector of the updated directed graph G, is the mean of the feature of all user nodes in the directed graph, is the mean of the feature of all merchant nodes in the directed graph, is the mean of all edges in the directed graph.

8. The fast anti-money laundering detection method based on a transaction graph according to claim 7, characterized in that, The graph neural network based on location information includes a graph convolutional network based on the attention mechanism, which accepts as input, where χ is the edge feature constructed in the graph neural network, and N 1 is the dimension of the time window, and N 2 is the feature dimension of v f , and v f is v′ g , v′ ui , v′ mi , e i ′ j is the feature vector obtained after concatenation.

9. The fast anti-money laundering detection method based on a transaction graph according to claim 8, characterized in that, a time attention layer is provided in the graph convolutional network, and the specific formula is as follows: Among them, β t refers to the weight parameter of the time window t, NN is a feedforward network, and W n are the parameters to be trained by this time attention network, λ 1 is a process parameter, and rept is the output result of each transaction in the graph convolutional network.

Citation Information

Patent Citations

  • Intelligent suspicious transaction monitoring method based on semi-supervised graph neural network

    CN110400220A

  • Method and system for detecting money laundering transactions in complex associated transactions

    CN112508705A