A suspicious transaction monitoring method, apparatus, device and storage medium
By acquiring transaction customer data and utilizing target models and graph mining techniques, the probability of suspicious transactions is automatically calculated, solving the problem of low efficiency in manual monitoring in existing technologies and achieving efficient and accurate monitoring of suspicious transactions.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- SHANGHAI PUDONG DEVELOPMENT BANK
- Filing Date
- 2022-10-25
- Publication Date
- 2026-04-17
AI Technical Summary
Existing methods for monitoring suspicious transactions rely on human experience, resulting in low efficiency and high costs, and are unable to effectively address the professional and technological characteristics of suspicious transactions.
By acquiring transaction customer data, including transaction records, related information, and terminal device addresses, the probability of suspicious transactions is automatically calculated using a target model. Combined with graph mining and graph pattern matching technologies, a suspicious transaction network graph is constructed, and pattern matching and feature analysis are performed to improve monitoring efficiency and accuracy.
It has achieved automated monitoring of suspicious transactions, improving monitoring efficiency and accuracy, enabling rapid identification of suspicious transactions and issuing early warnings, and reducing labor costs.
Smart Images

Figure CN115619411B_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present invention relate to the field of financial technology, and in particular to a method, apparatus, device and storage medium for monitoring suspicious transactions. Background Technology
[0002] In recent years, suspicious transactions have intensified rapidly, and the methods of suspicious transactions are becoming increasingly professional, technological, and geographically extended, which places higher demands on financial institutions to monitor suspicious transactions.
[0003] Existing methods for monitoring suspicious transactions typically involve developers monitoring transactions based on their personal experience, which is costly and inefficient. Summary of the Invention
[0004] This invention provides a method, apparatus, device, and storage medium for monitoring suspicious transactions, which can automatically monitor suspicious transactions and improve the efficiency and accuracy of suspicious transaction monitoring.
[0005] According to one aspect of the present invention, a method for monitoring suspicious transactions is provided, comprising:
[0006] Acquire transaction customer data, wherein the transaction customer data includes: transaction records corresponding to the transaction customer, associated information of the transaction customer, and terminal device address corresponding to the transaction customer;
[0007] The transaction customer data is input into the target model to obtain the target suspicious transaction probability corresponding to the transaction customer.
[0008] According to another aspect of the present invention, a suspicious transaction monitoring device is provided, the suspicious transaction monitoring device comprising:
[0009] The data acquisition module is used to acquire transaction customer data, wherein the transaction customer data includes: transaction records corresponding to the transaction customer, association information of the transaction customer, and terminal device address corresponding to the transaction customer;
[0010] The suspicious transaction probability determination module is used to input the transaction customer data into the target model to obtain the target suspicious transaction probability corresponding to the transaction customer.
[0011] According to another aspect of the present invention, an electronic device is provided, the electronic device comprising:
[0012] At least one processor; and
[0013] A memory communicatively connected to the at least one processor; wherein,
[0014] The memory stores a computer program that can be executed by the at least one processor, which enables the at least one processor to perform the suspicious transaction monitoring method according to any embodiment of the present invention.
[0015] According to another aspect of the present invention, a computer-readable storage medium is provided, the computer-readable storage medium storing computer instructions for causing a processor to execute and implement the suspicious transaction monitoring method according to any embodiment of the present invention.
[0016] This invention, through acquiring transaction customer data, including transaction records, associated information, and terminal device addresses, and inputting this data into a target model, yields the probability of a target suspicious transaction for that customer. This enables automatic monitoring of suspicious transactions, improving the efficiency and accuracy of suspicious transaction monitoring.
[0017] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of the present invention, nor is it intended to limit the scope of the invention. Other features of the invention will become readily apparent from the following description. Attached Figure Description
[0018] To more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings used in the embodiments will be briefly introduced below. It should be understood that the following drawings only show some embodiments of the present invention and should not be regarded as a limitation on the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.
[0019] Figure 1 This is a flowchart of a suspicious transaction monitoring method according to an embodiment of the present invention;
[0020] Figure 2 This is a schematic diagram of a portion of the transaction network map in an embodiment of the present invention;
[0021] Figure 3 This is a schematic diagram of the service network structure in an embodiment of the present invention;
[0022] Figure 4 This is a schematic diagram of the core network structure in an embodiment of the present invention;
[0023] Figure 5 This is a flowchart of another suspicious transaction monitoring method in an embodiment of the present invention;
[0024] Figure 6 This is a schematic diagram of the structure of a suspicious transaction monitoring device according to an embodiment of the present invention;
[0025] Figure 7 This is a schematic diagram of the structure of an electronic device according to an embodiment of the present invention. Detailed Implementation
[0026] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.
[0027] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0028] Example 1
[0029] Figure 1 This is a flowchart illustrating a suspicious transaction monitoring method provided in an embodiment of the present invention. This embodiment is applicable to suspicious transaction monitoring. The method can be executed by the suspicious transaction monitoring device in this embodiment, which can be implemented in software and / or hardware, such as... Figure 1 As shown, the method specifically includes the following steps:
[0030] S110, Obtain transaction customer data, wherein the transaction customer data includes: transaction records corresponding to the transaction customer, associated information of the transaction customer, and terminal device address corresponding to the transaction customer.
[0031] The associated information of the transaction customers includes at least one of the following: relatives, corporate legal persons, public-to-private transfers, and mutual guarantees.
[0032] The terminal device address corresponding to the transaction customer includes: IP and / or MAC.
[0033] The transaction customer data also includes: basic information of the transaction customer. This basic information includes: the transaction customer's name, customer status, identity information, business scope information, identification information, risk status, account type, warning status, whether it is an internal or external bank account, account opening time, account closing time, and at least one of the following:
[0034] Specifically, the methods for obtaining transaction customer data can be as follows: Obtain historical data, remove invalid but valid transaction data from the historical data, and thus obtain the transaction customer data. For example, one could obtain historical data, and then use relevant business rules such as transaction amount, number of transactions, and type, along with the model rules of the connected graph algorithm, to remove invalid but valid transaction data, thereby obtaining the transaction customer data. Performing graph pattern matching based on the transaction customer data obtained in the above manner can effectively improve the efficiency of graph pattern matching.
[0035] In a specific example, if transaction customer data is missing, then that transaction customer data will be removed. If the transaction customer data is an isolated node, meaning it has no relation to anything, then that transaction customer data will be removed.
[0036] S120, Input the transaction customer data into the target model to obtain the target suspicious transaction probability corresponding to the transaction customer.
[0037] The target model includes a first model and / or a graph mining model.
[0038] Specifically, the method for inputting the transaction customer data into the target model to obtain the target suspicious transaction probability corresponding to the transaction customer can be as follows: construct a suspicious transaction network graph based on the transaction customer data; perform pattern matching based on graph pattern rules and the suspicious transaction network graph to obtain suspicious transaction customers; input the transaction customer data corresponding to the suspicious transaction customers into the target model to obtain the target suspicious transaction probability corresponding to the suspicious transaction customers.
[0039] Optionally, the transaction customer data is input into the target model to obtain the target suspicious transaction probability corresponding to the transaction customer, including:
[0040] Construct a network graph of suspicious transactions based on the aforementioned customer data;
[0041] Suspicious transaction customers are identified by performing pattern matching based on graph pattern rules and the aforementioned suspicious transaction network graph.
[0042] Input the transaction customer data corresponding to the suspicious transaction customer into the target model to obtain the target suspicious transaction probability corresponding to the suspicious transaction customer.
[0043] Specifically, the method for constructing a suspicious transaction network graph based on the transaction customer data can be as follows: determine customer information based on transaction flow; determine entities based on customer information; determine the relationship between entities based on the association information of transaction customers; determine attribute information based on transaction flow and the association information of transaction customers; and construct a suspicious transaction network graph based on the entities, the relationship between entities, and the attribute information.
[0044] The graph pattern rules may include: multiple inflows and concentrated outflows; inflow counterparties originating from across the country; inflow amounts being multiples of 100 yuan or ending with specific digits; a large number of transactions; a high proportion of non-counter transactions; transactions occurring throughout the day; a high proportion of transactions occurring late at night; and alphanumeric combinations in transaction remarks. The graph pattern rules may also include: few and relatively fixed trading counterparties; large transaction amounts; transactions with suspicious customers. The graph pattern rules may also include: transaction amounts exceeding a set threshold. The graph pattern rules may also include: the presence of filtered account characteristics: multiple inflows followed by multiple outflows on the same day, abnormal surges in fund flow, short account opening time, and a high proportion of ATM and POS machine transactions. The graph pattern rules may also include: accounts opened within the last six months, with inflows and outflows roughly equal, and the cumulative amount exceeding a threshold. The graph pattern rules may also include: the amount received is greater than a threshold, the single amount is an integer multiple of 10,000 yuan, and the following remarks: investment, investment funds, loan, repayment, small balance after quick in-and-out, scattered transfers in, concentrated transfers out; personal account: the legal representative of the investment company or his / her close relatives; corporate account: numerous individual counterparties. The graph pattern rules may also include: fixed transaction time, and overlap between counterparties and receiving accounts.
[0045] Specifically, the method of inputting transaction customer data corresponding to suspicious transaction customers into the target model to obtain the target suspicious transaction probability for each suspicious transaction customer can be as follows: Generate target feature indicators based on the transaction customer data corresponding to the suspicious transaction customers; input the target feature indicators into a first model to obtain the target suspicious transaction probability for each suspicious transaction customer. Alternatively, the method can be as follows: Determine the out-degree and in-degree features corresponding to the suspicious transaction customers based on the suspicious transaction network graph; input the out-degree and in-degree features corresponding to the suspicious transaction customers into a graph mining model to obtain the target suspicious transaction probability for each suspicious transaction customer. Another method can be as follows: Filter the suspicious transaction customers according to a blacklist to obtain target suspicious transaction customers; obtain the target features corresponding to the target suspicious transaction customers; segment the target features based on segmentation rules; determine the target suspicious transaction probability for each suspicious transaction customer based on the WOE value corresponding to the segmented target features. The method for obtaining the target suspicious transaction probability by inputting the transaction customer data corresponding to the suspicious transaction customer into the target model can be as follows: Generate a target feature index based on the transaction customer data corresponding to the suspicious transaction customer; input the target feature index into a first model to obtain a first suspicious transaction probability corresponding to the suspicious transaction customer, wherein the first model is obtained by iteratively training a neural network model using a target sample set, the target sample set including: transaction customer data corresponding to the transaction customer sample and the first suspicious transaction probability corresponding to the transaction customer sample; determine the out-degree and in-degree features corresponding to the suspicious transaction customer based on the suspicious transaction network graph; input the out-degree and in-degree features corresponding to the suspicious transaction customer into a graph mining model to obtain a second suspicious transaction probability corresponding to the suspicious transaction customer; and determine the target suspicious transaction probability based on the first suspicious transaction probability and the second suspicious transaction probability.Another way to obtain the target suspicious transaction probability of a suspicious transaction customer by inputting the transaction customer data corresponding to the suspicious transaction customer into the target model is as follows: Generate a target feature index based on the transaction customer data corresponding to the suspicious transaction customer; input the target feature index into a first model to obtain a first suspicious transaction probability corresponding to the suspicious transaction customer, wherein the first model is obtained by iteratively training a neural network model using a target sample set, the target sample set including: transaction customer data corresponding to the transaction customer sample and the first suspicious transaction probability corresponding to the transaction customer sample; filter the suspicious transaction customers according to a blacklist to obtain target suspicious transaction customers; obtain the target features corresponding to the target suspicious transaction customers; segment the target features based on segmentation rules; determine a third suspicious transaction probability corresponding to the suspicious transaction customer based on the WOE value corresponding to the segmented target features; and determine the target suspicious transaction probability based on the first suspicious transaction probability and the third suspicious transaction probability. Another way to obtain the target suspicious transaction probability of a suspicious transaction customer by inputting the transaction customer data corresponding to the suspicious transaction customer into the target model is as follows: determine the out-degree and in-degree features corresponding to the suspicious transaction customer based on the suspicious transaction network graph; input the out-degree and in-degree features corresponding to the suspicious transaction customer into the graph mining model to obtain the second suspicious transaction probability corresponding to the suspicious transaction customer; filter the suspicious transaction customers according to the blacklist to obtain the target suspicious transaction customers; obtain the target features corresponding to the target suspicious transaction customers; segment the target features based on the segmentation rules; determine the third suspicious transaction probability corresponding to the suspicious transaction customer based on the WOE value corresponding to the segmented target features; and determine the target suspicious transaction probability based on the second suspicious transaction probability and the third suspicious transaction probability.
[0046] Optionally, the target model includes: a first model and a graph mining model;
[0047] Accordingly, the transaction customer data corresponding to the suspicious transaction customer is input into the target model to obtain the target suspicious transaction probability corresponding to the suspicious transaction customer, including:
[0048] Target feature indicators are generated based on the transaction customer data corresponding to the suspicious transaction customers;
[0049] The target feature index is input into the first model to obtain the first suspicious transaction probability corresponding to the suspicious transaction customer. The first model is obtained by iteratively training a neural network model through a target sample set. The target sample set includes: transaction customer data corresponding to the transaction customer sample and the first suspicious transaction probability corresponding to the transaction customer sample.
[0050] Based on the suspicious transaction network graph, determine the out-degree and in-degree characteristics of the suspicious transaction customers;
[0051] Input the out-degree and in-degree features of suspicious transaction customers into the graph mining model to obtain the second suspicious transaction probability of the suspicious transaction customer;
[0052] The suspicious transaction customers are screened based on the blacklist to obtain the target suspicious transaction customers;
[0053] Obtain the target characteristics corresponding to the target suspicious transaction customer;
[0054] The target features are segmented based on segmentation rules;
[0055] The probability of a third suspicious transaction is determined based on the WOE value corresponding to the segmented target features;
[0056] The target suspicious transaction probability is determined based on the first suspicious transaction probability, the second suspicious transaction probability, and the third suspicious transaction probability.
[0057] Specifically, suspicious transaction customers are screened based on the blacklist to obtain target suspicious transaction customers. This can be done by labeling suspicious samples, specifically by combining manual verification with blacklist verification.
[0058] In a specific example, the process involves obtaining graph pattern matching results, labeling suspicious samples, performing feature engineering on the labeled suspicious samples, and then performing a Word of the Exchange (WOE) transformation after feature engineering. Based on the WOE transformation result, the probability of the third suspicious transaction corresponding to the suspicious transaction customer is determined. The labeling of suspicious samples can be done through a combination of manual verification and blacklisting. The feature engineering of labeled suspicious samples can be performed by first constructing scoring features, then filtering the scoring features, binning continuous variables, adjusting the binning results by experts, and mapping the original data to the bins. The WOE transformation can be performed by calculating the segmented distribution ratio of features in the complete list, calculating the segmented distribution ratio of features in the suspicious list, calculating the segmented WOE value, and standardizing the WOE value.
[0059] Optionally, a suspicious transaction network graph is constructed based on the transaction customer data, including:
[0060] Determine customer information based on transaction records;
[0061] Identify entities based on customer information;
[0062] Determine the relationships between entities based on the associated information of the transacting clients;
[0063] Attribute information is determined based on transaction records and associated information of transaction clients;
[0064] A suspicious transaction network graph is constructed based on the entities, the relationships between entities, and attribute information.
[0065] Specifically, the entity types in the suspicious transaction network graph include: accounts, customers, addresses, devices, and telephones. Account-type entities have the following attributes: basic information and account opening / closing status. Basic information includes: account type (corporate / personal), alert status (yes / no), and whether it's within or outside the bank. Account opening / closing status includes: account opening time, account closing time, and the opening institution. Customer-type entities have the following attributes: basic information, identification information, and risk status. Basic information includes: customer name, customer status, whether it's within or outside the bank, corporate / personal, identity information, occupation, and business scope. Identification information includes: identification type, identification number, identification start date, and identification expiration date. Risk status includes: the customer's suspicious transaction risk level, whether it has received a suspicious transaction alert, and the number of suspicious transaction reports submitted. Address-type entities have the following attributes: registered address and personal address. Device-type entities have "none" attributes, and telephone-type entities have "none" attributes. Relationships between entities include: account ownership, transaction ownership, telephone ownership, address ownership, device ownership, company relationship, and kinship relationship. The attribute corresponding to account ownership is "None"; the attribute corresponding to transaction ownership is the specific transaction amount; the attribute corresponding to telephone number ownership is "None"; the attribute corresponding to address ownership is "None"; the attribute corresponding to device ownership is "None"; the attribute corresponding to company relationship is "None"; and the attribute corresponding to kinship relationship can be children, spouse, etc. For example... Figure 2 As shown, Figure 2 This is a partial transaction network graph. Figure 2 This includes: private customer entities, corporate customer entities, account entities, telephone entities, device number entities, and address entities. The relationships between these entities include: account ownership, transactions, kinship, corporate legal person, telephone ownership, device number ownership, and address ownership.
[0066] Optionally, pattern matching is performed based on graph pattern rules and the suspicious transaction network graph to obtain suspicious transaction customers, including:
[0067] Obtain at least one business network structure corresponding to at least one suspicious transaction scenario;
[0068] Generate graph pattern rules based on the at least one business network structure;
[0069] Suspicious transaction customers are identified by pattern matching based on graph pattern rules and the aforementioned suspicious transaction network graph.
[0070] One suspicious transaction scenario can correspond to at least one business network structure.
[0071] Specifically, the method for generating graph pattern rules based on the at least one business network structure can be as follows: generate graph pattern rules corresponding to each business network structure based on each business network structure.
[0072] Specifically, the method for obtaining suspicious transaction customers by performing pattern matching based on graph pattern rules and the suspicious transaction network graph can be as follows: input the graph pattern rules and the suspicious transaction network graph into the pattern matching model to obtain at least one sub-network graph that matches the graph pattern rules in the graph pattern rules; and determine the suspicious transaction customers based on the at least one sub-network graph.
[0073] In a specific example Figure 3 For business network structure, such as Figure 3 The agent accounts in the business network structure shown have the following characteristics: multiple inflows and centralized outflows; inflow counterparties are from all over the country; inflow amounts are multiples of 100 yuan or end with specific digits; a large number of transactions; a high proportion of non-counter transactions; transactions occur throughout the day; a high proportion of late-night transactions; and transaction remarks are a combination of letters and numbers. The aggregation accounts, on the other hand, have the following characteristics: few and relatively fixed counterparties; large transaction amounts; and transactions with suspicious customers. According to... Figure 3 The business network structure shown yields... Figure 4 The core network structure shown is based on Figure 4 The core network structure shown determines the graph pattern rules.
[0074] Optionally, pattern matching is performed based on graph pattern rules and the suspicious transaction network graph to obtain suspicious transaction customers, including:
[0075] Input the graph pattern rules and the suspicious transaction network graph into the pattern matching model to obtain at least one sub-network graph that matches the graph pattern rules in the graph pattern rules;
[0076] Suspicious transaction customers are identified based on at least one sub-network graph.
[0077] The sub-network graph is a part of the suspicious transaction network graph.
[0078] Specifically, the method of inputting the graph pattern rules and the suspicious transaction network graph into the pattern matching model to obtain at least one sub-network graph that matches the graph pattern rules in the graph pattern rules can be as follows: input each graph pattern rule and the suspicious transaction network graph into the pattern matching model to obtain at least one sub-network graph that matches the graph pattern rules in each graph pattern rule.
[0079] Optional, also includes:
[0080] If correction information is received from the user, the parameters in the graph pattern rule are adjusted according to the correction information to obtain the updated graph pattern rule.
[0081] The corrective information can be feedback results, which can be feedback results obtained by business personnel from reviewing suspicious transaction customers, combining business experience and black samples.
[0082] It should be noted that if correction information is received from the user, the parameters in the graph pattern rules are adjusted according to the correction information input by the user to construct graph pattern rules that conform to the customer's business scenario.
[0083] In a specific example, this invention proposes a suspicious transaction monitoring method based on graph pattern matching and graph mining algorithms. It proposes a suspicious transaction monitoring method combining graph rules and graph models, comprehensively improving monitoring accuracy by integrating the transaction behavior and correlation information of samples in the model. Utilizing a comprehensive anti-money laundering heterogeneous graph, the core network is extracted to construct complex graph patterns of 4-5 layers or more. Pattern matching is then performed to construct graph pattern rules, which are input into a graph model (GCN, graph representation learning, graph embedding) for model training and prediction, improving risk monitoring and identification effectiveness. Employing "graph technology—knowledge graph" technology, the complex relationships between transactions, legal entities, and equity of enterprises and individuals are mined. Through customer relationship insights and abnormal correlation structure mining, abnormal graph structure patterns matching suspicious transaction characteristics are quickly discovered, suspicious account groups are identified, and anti-suspicious transaction gangs are identified, achieving intelligent data screening and analysis.
[0084] like Figure 5 As shown, the implementation steps of this method are as follows:
[0085] Step 1:
[0086] Data preparation. The transaction flow, relationships, and terminal device addresses required by the model are processed. Invalid and normal transaction data are removed by using relevant business rules such as transaction amount, number of transactions, and type, as well as model rules of the connected graph algorithm. This effectively improves the efficiency of graph pattern matching, saves resources, and increases accuracy.
[0087] Step 2:
[0088] Knowledge graph construction. The data obtained in step 1 is subjected to knowledge graph-related information extraction. The structured data is extracted into point and edge files required for graph construction. Knowledge graph-related information extraction includes entity extraction, relationship extraction, and attribute extraction, obtaining entity, entity relationship, and attribute information of transaction customer data. Based on traditional transaction relationships, multi-dimensional relationships such as account, customer, address, device, and telephone number are introduced to construct a comprehensive suspicious transaction network graph.
[0089] Step 3:
[0090] Core network extraction. Based on the People's Bank of China's guidelines and industry cases, combined with the knowledge of business experts, the core network structure of different scenarios is extracted, and graph pattern rules are constructed. The graph pattern rules are specifically subgraphs composed of specific network structures and related features. The related features cover node features, relationship features, and network features.
[0091] Step 4:
[0092] Pattern matching. Based on the graph pattern rules extracted in step 3, a pattern matching algorithm is used to scan the comprehensive suspicious transaction network graph constructed in step 2, find subnetworks with similar structures to the core network, and output suspicious transaction customers;
[0093] Step 5:
[0094] Input the transaction customer data corresponding to the suspicious transaction customer into the target model to obtain the target suspicious transaction probability corresponding to the suspicious transaction customer:
[0095] First, target feature indicators are constructed using the customer's basic personal information and the basic characteristics of anti-money laundering market processing. The basic characteristics include abnormal transactions, large transactions, and cross-border transactions. The target feature indicators are then input into the first model to obtain the first suspicious transaction probability corresponding to the suspicious transaction customer.
[0096] Secondly, by processing secondary graph indicators through the comprehensive suspicious network graph, including but not limited to out-degree and in-degree features, the out-degree and in-degree features corresponding to suspicious transaction customers are input into the graph mining model to obtain the second suspicious transaction probability corresponding to the suspicious transaction customers.
[0097] Third, the suspicious transaction customers are screened according to the blacklist to obtain target suspicious transaction customers; the target features corresponding to the target suspicious transaction customers are obtained; the target features are segmented according to the segmentation rules; and the third suspicious transaction probability corresponding to the suspicious transaction customer is determined according to the WOE value corresponding to the segmented target features.
[0098] Step 6:
[0099] The target suspicious transaction probability is determined based on the first suspicious transaction probability, the second suspicious transaction probability, and the third suspicious transaction probability. The weights of the three probabilities are continuously adjusted, the target suspicious transaction probability is output, and the TOPN is selected for reporting and early warning.
[0100] Step 7:
[0101] Threshold adjustment. Suspicious subnets are reviewed, and based on business experience and black sample performance, core network structure parameters are adjusted to construct a network structure and thresholds that conform to the customer's business scenario.
[0102] The technical solution of this embodiment obtains transaction customer data, which includes: transaction records corresponding to the transaction customer, association information of the transaction customer, and terminal device address corresponding to the transaction customer; inputs the transaction customer data into a target model to obtain the target suspicious transaction probability corresponding to the transaction customer, which can automatically monitor suspicious transactions and improve the efficiency and accuracy of suspicious transaction monitoring.
[0103] Example 2
[0104] Figure 6 This is a schematic diagram of a suspicious transaction monitoring device provided in an embodiment of the present invention. This embodiment is applicable to suspicious transaction monitoring. The device can be implemented using software and / or hardware, and can be integrated into any device that provides suspicious transaction monitoring functionality, such as… Figure 6 As shown, the suspicious transaction monitoring device specifically includes: a data acquisition module 210 and a suspicious transaction probability determination module 220.
[0105] The data acquisition module is used to acquire transaction customer data, which includes: transaction records corresponding to the transaction customer, associated information of the transaction customer, and terminal device address corresponding to the transaction customer.
[0106] The suspicious transaction probability determination module is used to input the transaction customer data into the target model to obtain the target suspicious transaction probability corresponding to the transaction customer.
[0107] The above-described products can perform the methods provided in any embodiment of the present invention, and have the corresponding functional modules and beneficial effects for performing the methods.
[0108] The technical solution of this embodiment obtains transaction customer data, which includes: transaction records corresponding to the transaction customer, association information of the transaction customer, and terminal device address corresponding to the transaction customer; inputs the transaction customer data into a target model to obtain the target suspicious transaction probability corresponding to the transaction customer, which can automatically monitor suspicious transactions and improve the efficiency and accuracy of suspicious transaction monitoring.
[0109] Example 3
[0110] Figure 7A schematic diagram of an electronic device 10 that can be used to implement embodiments of the present invention is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices (e.g., helmets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the invention described and / or claimed herein.
[0111] like Figure 7 As shown, the electronic device 10 includes at least one processor 11 and a memory, such as a read-only memory (ROM) 12 or a random access memory (RAM) 13, communicatively connected to the at least one processor 11. The memory stores computer programs executable by the at least one processor. The processor 11 can perform various appropriate actions and processes based on the computer program stored in the ROM 12 or loaded from storage unit 18 into the RAM 13. The RAM 13 may also store various programs and data required for the operation of the electronic device 10. The processor 11, ROM 12, and RAM 13 are interconnected via a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.
[0112] Multiple components in electronic device 10 are connected to I / O interface 15, including: input unit 16, such as keyboard, mouse, etc.; output unit 17, such as various types of displays, speakers, etc.; storage unit 18, such as disk, optical disk, etc.; and communication unit 19, such as network card, modem, wireless transceiver, etc. Communication unit 19 allows electronic device 10 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.
[0113] Processor 11 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of processor 11 include, but are not limited to, central processing unit (CPU), graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, digital signal processors (DSPs), and any suitable processor, controller, microcontroller, etc. Processor 11 performs the various methods and processes described above, such as suspicious transaction monitoring methods.
[0114] In some embodiments, the suspicious transaction monitoring method may be implemented as a computer program tangibly contained in a computer-readable storage medium, such as storage unit 18. In some embodiments, part or all of the computer program may be loaded and / or installed on electronic device 10 via ROM 12 and / or communication unit 19. When the computer program is loaded into RAM 13 and executed by processor 11, one or more steps of the suspicious transaction monitoring method described above may be performed. Alternatively, in other embodiments, processor 11 may be configured to perform the suspicious transaction monitoring method by any other suitable means (e.g., by means of firmware).
[0115] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), payload-programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.
[0116] Computer programs used to implement the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when executed by the processor, the computer programs cause the functions / operations specified in the flowcharts and / or block diagrams to be performed. The computer programs may be executed entirely on a machine, partially on a machine, or as a standalone software package, partially on a machine and partially on a remote machine, or entirely on a remote machine or server.
[0117] In the context of this invention, a computer-readable storage medium can be a tangible medium that may contain or store a computer program for use by or in conjunction with an instruction execution system, apparatus, or device. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination thereof. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.
[0118] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).
[0119] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or computing systems that include middleware components (e.g., application servers), or computing systems that include frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., communication networks). Examples of communication networks include local area networks (LANs), wide area networks (WANs), blockchain networks, and the Internet.
[0120] A computing system can include clients and servers. Clients and servers are generally located far apart and typically interact through communication networks. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or cloud host, which is a hosting product within the cloud computing service system to address the shortcomings of traditional physical hosts and VPS services, such as high management difficulty and weak business scalability.
[0121] It should be understood that the various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps described in this invention can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution of this invention can be achieved, and no limitation is imposed herein.
[0122] The specific embodiments described above do not constitute a limitation on the scope of protection of this invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this invention should be included within the scope of protection of this invention.
Claims
1. A method for monitoring suspicious transactions, characterized in that, include: Acquire transaction customer data, wherein the transaction customer data includes: transaction records corresponding to the transaction customer, associated information of the transaction customer, and terminal device address corresponding to the transaction customer; Input the transaction customer data into the target model to obtain the target suspicious transaction probability corresponding to the transaction customer; Inputting the transaction customer data into the target model yields the target suspicious transaction probability corresponding to the transaction customer, including: Construct a network graph of suspicious transactions based on the aforementioned customer data; Suspicious transaction customers are identified by performing pattern matching based on graph pattern rules and the aforementioned suspicious transaction network graph. Input the transaction customer data corresponding to the suspicious transaction customer into the target model to obtain the target suspicious transaction probability corresponding to the suspicious transaction customer; The target model includes: a first model and a graph mining model; Accordingly, the transaction customer data corresponding to the suspicious transaction customer is input into the target model to obtain the target suspicious transaction probability corresponding to the suspicious transaction customer, including: Target feature indicators are generated based on the transaction customer data corresponding to the suspicious transaction customers; The target feature index is input into the first model to obtain the first suspicious transaction probability corresponding to the suspicious transaction customer. The first model is obtained by iteratively training a neural network model through a target sample set. The target sample set includes: transaction customer data corresponding to the transaction customer sample and the first suspicious transaction probability corresponding to the transaction customer sample. Based on the suspicious transaction network graph, determine the out-degree and in-degree characteristics of the suspicious transaction customers; Input the out-degree and in-degree features of suspicious transaction customers into the graph mining model to obtain the second suspicious transaction probability of the suspicious transaction customer; The suspicious transaction customers are screened based on the blacklist to obtain the target suspicious transaction customers; Obtain the target characteristics corresponding to the target suspicious transaction customer; The target features are segmented based on segmentation rules; The probability of a third suspicious transaction is determined based on the WOE value corresponding to the segmented target features; The target suspicious transaction probability is determined based on the first suspicious transaction probability, the second suspicious transaction probability, and the third suspicious transaction probability.
2. The method according to claim 1, characterized in that, Constructing a suspicious transaction network graph based on the aforementioned transaction customer data, including: Determine customer information based on transaction records; Identify entities based on customer information; Determine the relationships between entities based on the associated information of the transacting clients; Attribute information is determined based on transaction records and associated information of transaction clients; A suspicious transaction network graph is constructed based on the entities, the relationships between entities, and attribute information.
3. The method according to claim 1, characterized in that, Based on the graph pattern rules and the aforementioned suspicious transaction network graph, pattern matching is performed to identify suspicious transaction customers, including: Obtain at least one business network structure corresponding to at least one suspicious transaction scenario; Generate graph pattern rules based on the at least one business network structure; Suspicious transaction customers are identified by pattern matching based on graph pattern rules and the aforementioned suspicious transaction network graph.
4. The method according to claim 3, characterized in that, Based on the graph pattern rules and the aforementioned suspicious transaction network graph, pattern matching is performed to identify suspicious transaction customers, including: Input the graph pattern rules and the suspicious transaction network graph into the pattern matching model to obtain at least one sub-network graph that matches the graph pattern rules in the graph pattern rules; Suspicious transaction customers are identified based on at least one sub-network graph.
5. The method according to claim 3, characterized in that, Also includes: If correction information is received from the user, the parameters in the graph pattern rule are adjusted according to the correction information to obtain the updated graph pattern rule.
6. A suspicious transaction monitoring device, characterized in that, include: The data acquisition module is used to acquire transaction customer data, wherein the transaction customer data includes: transaction records corresponding to the transaction customer, association information of the transaction customer, and terminal device address corresponding to the transaction customer; The suspicious transaction probability determination module is used to input the transaction customer data into the target model to obtain the target suspicious transaction probability corresponding to the transaction customer. The process of inputting the transaction customer data into the target model to obtain the target suspicious transaction probability corresponding to the transaction customer includes: Construct a network graph of suspicious transactions based on the aforementioned customer data; Suspicious transaction customers are identified by performing pattern matching based on graph pattern rules and the aforementioned suspicious transaction network graph. Input the transaction customer data corresponding to the suspicious transaction customer into the target model to obtain the target suspicious transaction probability corresponding to the suspicious transaction customer; The target model includes: a first model and a graph mining model; Accordingly, the transaction customer data corresponding to the suspicious transaction customer is input into the target model to obtain the target suspicious transaction probability corresponding to the suspicious transaction customer, including: Target feature indicators are generated based on the transaction customer data corresponding to the suspicious transaction customers; The target feature index is input into the first model to obtain the first suspicious transaction probability corresponding to the suspicious transaction customer. The first model is obtained by iteratively training a neural network model through a target sample set. The target sample set includes: transaction customer data corresponding to the transaction customer sample and the first suspicious transaction probability corresponding to the transaction customer sample. Based on the suspicious transaction network graph, determine the out-degree and in-degree characteristics of the suspicious transaction customers; Input the out-degree and in-degree features of suspicious transaction customers into the graph mining model to obtain the second suspicious transaction probability of the suspicious transaction customer; The suspicious transaction customers are screened based on the blacklist to obtain the target suspicious transaction customers; Obtain the target characteristics corresponding to the target suspicious transaction customer; The target features are segmented based on segmentation rules; The probability of a third suspicious transaction is determined based on the WOE value corresponding to the segmented target features; The target suspicious transaction probability is determined based on the first suspicious transaction probability, the second suspicious transaction probability, and the third suspicious transaction probability.
7. An electronic device, characterized in that, The electronic device includes: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that can be executed by the at least one processor, the computer program being executed by the at least one processor to enable the at least one processor to perform the suspicious transaction monitoring method according to any one of claims 1-5.
8. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions that, when executed by a processor, implement the suspicious transaction monitoring method according to any one of claims 1-5.
Citation Information
Patent Citations
Suspicious account transaction confirmation method and device based on knowledge graph technology
CN110033279A
Method and system for enterprise risk prediction
CN111178614A