Fraud detection method and system based on graph neural network and decoupled representation learning

CN116805245BActive Publication Date: 2026-09-29SHANGHAI UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310768577.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-06-27
Publication Date
2026-09-29
Estimated Expiration
2043-06-27

AI Technical Summary

Technical Problem

[0004]目前欺诈检测方法主要是采用专家经验规则或者机器学习方法,但是这些忽略了账户之间的关系,这些缺陷将在很大程度上影响欺诈检测的全面性以及精确性

Benefits of technology

[0028]本发明通过图神经网络建模欺诈场景中的图结构数据,运用解耦表示学习以及辅助的重构模块与对比学习模块,为欺诈类与正常类学习到了可以区别的特征表示,能更加有效地应对欺诈场景中的伪装问题,提高检测准确性。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116805245B_ABST
    Figure CN116805245B_ABST
Patent Text Reader

Abstract

The application discloses a fraud detection method and system based on a graph neural network and decoupled representation learning, relates to the fields of fraud detection and deep learning, and comprises the following steps: inputting graph structure data corresponding to current transaction scene data into a fraud detection model to determine a fraudulent account in the current transaction scene data; wherein, the fraud neural network is trained by using graph structure data corresponding to a fraud transaction scene data set and a comprehensive loss function, so that the trained fraud neural network is obtained; the fraud neural network comprises a GCN encoding module, a GCN decoding module and a classifier; the fraud detection model comprises the trained GCN encoding module and the trained classifier; and the comprehensive loss function is composed of a reconstruction loss subfunction, a classification loss subfunction, a maximum entropy loss subfunction and a contrastive learning loss subfunction. The application is used for solving the problem of disguise in fraud detection and improving detection accuracy.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the fields of fraud detection and deep learning, and in particular to a fraud detection method and system based on graph neural networks and decoupled representation learning. Background Technology

[0002] In the era of big data, online transactions are becoming increasingly frequent, including some illegal transactions involving malicious attacks and phishing. Therefore, it is necessary to detect illegal transactions based on their characteristics to prevent huge losses.

[0003] Transaction data refers to directed transactions between numerous trading accounts. Due to scams, malware, and other malicious software, some fraudulent transactions occur within trading networks. Therefore, we detect accounts involved in fraudulent transactions based on the account's own information and the transaction relationships between accounts.

[0004] Current fraud detection methods mainly rely on expert experience rules or machine learning methods, but these ignore the relationships between accounts. These shortcomings will greatly affect the comprehensiveness and accuracy of fraud detection. Summary of the Invention

[0005] The purpose of this invention is to provide a fraud detection method and system based on graph neural networks and decoupled representation learning, which can solve the spoofing problem faced in fraud detection, reduce the noise interference caused by spoofing, expand the inter-class distance in the feature space, and destroy the similarity between normal class features and fraudulent class features caused by spoofing.

[0006] To achieve the above objectives, the present invention provides the following solution:

[0007] This invention provides a fraud detection method based on graph neural networks and decoupled representation learning, comprising:

[0008] Obtain current transaction scenario data; the current transaction scenario data includes multiple account entities and attribute information of each account entity; the attribute information includes the account entity's registration time, the number of logins within a set time period, and the account entity's transaction information within the set time period; the transaction information includes transaction frequency, total transaction amount, and the amount of the last transaction;

[0009] The current transaction scenario data is processed to obtain the current graph structure data corresponding to the current transaction scenario data; the current graph structure data includes the graph's adjacency matrix and node feature matrix;

[0010] The current graph structure data is input into the fraud detection model to identify fraudulent accounts in the current transaction scenario data;

[0011] The process of determining the fraud detection model is as follows:

[0012] Using graph structure data corresponding to the fraud transaction scenario dataset and a comprehensive loss function, the fraud neural network is trained to obtain a well-trained fraud neural network.

[0013] The fraudulent transaction scenario dataset includes multiple transaction scenario sample data; the transaction scenario sample data includes multiple account entities and sample information for each account entity; the sample information includes attribute information and tag information; the tag information is either a fraudulent account or a legitimate account;

[0014] The graph structure data corresponding to the fraud transaction scenario dataset includes the graph's adjacency matrix, node feature matrix, and node label list;

[0015] The fraud neural network includes a GCN encoding module, a GCN decoding module, and a classifier; the fraud detection model includes a trained GCN encoding module and a trained classifier; the GCN encoding module includes at least a GCN encoder; the GCN decoding module includes at least a GCN decoder.

[0016] The comprehensive loss function consists of a reconstruction loss subfunction, a classification loss subfunction, a maximum entropy loss subfunction, and a contrastive learning loss subfunction. The reconstruction loss subfunction calculates the loss between the node feature matrix in the graph structure data and the reconstructed node feature matrix output by the GCN decoder. The maximum entropy loss subfunction calculates the maximum entropy loss of the content vector. The classification loss subfunction calculates the classification loss of the style vector. The content vector and the style vector are vectors obtained by partitioning the latent space features of the nodes output by the GCN encoder. The contrastive learning loss subfunction calculates the contrastive loss based on positive and negative node pairs. The positive and negative node pairs include positive node pairs and negative node pairs. The positive node pairs are node pairs composed of similar nodes, and the negative node pairs are node pairs composed of dissimilar nodes.

[0017] This invention also provides a fraud detection system based on graph neural networks and decoupled representation learning, comprising:

[0018] The data acquisition module is used to acquire current transaction scenario data; the current transaction scenario data includes multiple account entities and attribute information of each account entity; the attribute information includes the account entity registration time, the number of logins within a set time period, and the transaction information within the set time period; the transaction information includes transaction frequency, total transaction amount, and the amount of the last transaction;

[0019] The graph structure data determination module is used to process the current transaction scenario data to obtain the current graph structure data corresponding to the current transaction scenario data; the current graph structure data includes the adjacency matrix and node feature matrix of the graph;

[0020] The detection module is used to input the current graph structure data into the fraud detection model to identify fraudulent accounts in the current transaction scenario data;

[0021] The process of determining the fraud detection model is as follows:

[0022] Using graph structure data corresponding to the fraud transaction scenario dataset and a comprehensive loss function, the fraud neural network is trained to obtain a well-trained fraud neural network.

[0023] The fraudulent transaction scenario dataset includes multiple transaction scenario sample data; the transaction scenario sample data includes multiple account entities and sample information for each account entity; the sample information includes attribute information and tag information; the tag information is either a fraudulent account or a legitimate account;

[0024] The graph structure data corresponding to the fraud transaction scenario dataset includes the graph's adjacency matrix, node feature matrix, and node label list;

[0025] The fraud neural network includes a GCN encoding module, a GCN decoding module, and a classifier; the fraud detection model includes a trained GCN encoding module and a trained classifier; the GCN encoding module includes at least a GCN encoder; the GCN decoding module includes at least a GCN decoder.

[0026] The comprehensive loss function consists of a reconstruction loss subfunction, a classification loss subfunction, a maximum entropy loss subfunction, and a contrastive learning loss subfunction. The reconstruction loss subfunction calculates the loss between the node feature matrix in the graph structure data and the reconstructed node feature matrix output by the GCN decoder. The maximum entropy loss subfunction calculates the maximum entropy loss of the content vector. The classification loss subfunction calculates the classification loss of the style vector. The content vector and the style vector are vectors obtained by partitioning the latent space features of the nodes output by the GCN encoder. The contrastive learning loss subfunction calculates the contrastive loss based on positive and negative node pairs. The positive and negative node pairs include positive node pairs and negative node pairs. The positive node pairs are node pairs composed of similar nodes, and the negative node pairs are node pairs composed of dissimilar nodes.

[0027] According to specific embodiments provided by the present invention, the present invention discloses the following technical effects:

[0028] This invention models graph structure data in fraud scenarios using graph neural networks. By employing decoupled representation learning and auxiliary reconstruction and contrastive learning modules, it learns distinguishable feature representations for fraudulent and normal classes, which can more effectively address the spoofing problem in fraud scenarios and improve detection accuracy. Attached Figure Description

[0029] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0030] Figure 1 This is a flowchart illustrating the fraud detection method based on graph neural networks and decoupled representation learning provided in an embodiment of the present invention.

[0031] Figure 2 This is a flowchart illustrating the fraud detection model determination method based on graph neural networks and decoupled representation learning provided in an embodiment of the present invention.

[0032] Figure 3 A schematic diagram illustrating the network structure determination for a fraud detection model based on graph neural networks and decoupled representation learning, provided in an embodiment of the present invention.

[0033] Figure 4 A schematic diagram illustrating the fraud scenario camouflage problem provided in an embodiment of the present invention;

[0034] Figure 5 This is an example diagram of the detection stage of the fraud detection method based on graph neural networks and decoupled representation learning provided in an embodiment of the present invention;

[0035] Figure 6 This is a schematic diagram of the fraud detection method based on graph neural networks and decoupled representation learning provided in an embodiment of the present invention. Detailed Implementation

[0036] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0037] To make the above-mentioned objects, features and advantages of the present invention more apparent and understandable, the present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments.

[0038] The purpose of fraud detection is to accurately and efficiently identify fraudsters and reduce social losses. Typically, account entities are defined as nodes, and the transaction interactions between account entities are considered edges, thus modeling the real-world scenario as a graph. Therefore, fraud detection can be transformed into a node classification problem within the graph, that is, identifying nodes as fraudulent or legitimate.

[0039] Graph Neural Networks (GNNs) represent a central node by aggregating information from its neighbors, performing well on graph-structured data. However, deception by fraudsters can break the consistency assumption of GNNs: neighboring nodes possess similar feature representations and belong to the same class as the central node. For example... Figure 4 As shown, the forms of spoofing include: interacting with normal users to make oneself appear normal (environmental inconsistency spoofing) or interacting with completely unrelated accounts (characteristic inconsistency spoofing) to confuse the public.

[0040] Decoupled representation learning can separate multiple physical dimensions of features for use in downstream tasks. When fraudsters impersonate others, they generate a large number of unimportant neighbor nodes. If these noisy features can be extracted, it could potentially improve detection performance. By using feature decoupling, the latent space features of nodes obtained by the GCN encoder can be split into two parts. A loss function can be designed to force one part to contain only noisy features and no information indicating whether fraud exists, while the other part serves as the input to the classifier.

[0041] In summary, the decoupled representation learning and contrastive learning method provided by this invention can be used to solve the spoofing problem faced in fraud detection, reduce noise interference caused by spoofing, expand the inter-class distance in the feature space, and destroy the similarity between normal class features and fraudulent class features caused by spoofing. Therefore, this invention provides a fraud detection method and system based on graph neural networks and decoupled representation learning, which can be applied to the detection of fraudulent methods modeled in graph structure data, such as malicious review detection in product review graphs, and gambling / fraudulent transactions in payment transaction networks.

[0042] To make the above-mentioned objects, features and advantages of the present invention more apparent and understandable, the present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments.

[0043] Example 1

[0044] This embodiment provides a fraud detection method based on graph neural networks and decoupled representation learning. It utilizes a branch of graph convolutional network (GCN) in graph neural network (GNN) to mine data from transaction scenarios such as financial product sales, credit card applications, loans, and transfers in banks, and discovers fraudulent activities. This provides security for banking operations and is suitable for improving the anti-fraud management platform of the banking industry, further enhancing the level of fraud prevention and control.

[0045] This embodiment first models and obtains graph structure data, then uses decoupled representation learning and other auxiliary modules to train a classifier, and finally classifies the samples to be detected.

[0046] This embodiment mainly includes the following aspects:

[0047] First, a reconstruction module is used to learn edge weights and alleviate the problem of environmental inconsistency. Second, a decoupling module is used to separate noise caused by feature inconsistency in the feature space. Third, a contrastive learning module is used to enhance the learning of node features by constructing positive and negative node pairs.

[0048] like Figure 1 As shown in the figure, this embodiment provides a fraud detection method based on graph neural networks and decoupled representation learning, which includes the following steps:

[0049] Step 100: Obtain current transaction scenario data; the current transaction scenario data includes multiple account entities and attribute information of each account entity; the attribute information includes the account entity registration time, the number of logins within a set time period, and the transaction information within the set time period; the transaction information includes transaction frequency, total transaction amount, and the amount of the last transaction.

[0050] Step 200: Process the current transaction scenario data to obtain the current graph structure data corresponding to the current transaction scenario data; the current graph structure data includes the graph's adjacency matrix and node feature matrix.

[0051] In this embodiment, step 200 specifically includes:

[0052] For the current transaction scenario data, PyG or NetworkX tools are used to determine the current graph structure data corresponding to the current transaction scenario data, with account entities as nodes and the transaction interaction between two account entities as edges.

[0053] Step 300: Input the current graph structure data into the fraud detection model to identify fraudulent accounts in the current transaction scenario data. The number of fraudulent accounts in the current transaction scenario data can be 0, 1, or more.

[0054] The process of determining the fraud detection model is as follows:

[0055] The fraud neural network is trained using graph structure data corresponding to the fraud transaction scenario dataset and a comprehensive loss function.

[0056] The fraudulent transaction scenario dataset includes multiple transaction scenario sample data; the transaction scenario sample data includes multiple account entities and sample information for each account entity; the sample information includes attribute information and label information; the label information is either a fraudulent account or a legitimate account; the graph structure data corresponding to the fraudulent transaction scenario dataset includes the graph's adjacency matrix, node feature matrix, and node label list. The node label list is determined based on the label information; the fraud neural network includes a GCN encoding module, a GCN decoding module, and a classifier; the fraud detection model includes a trained GCN encoding module and a trained classifier; the GCN encoding module includes at least a GCN encoder; the GCN decoding module includes at least a GCN decoder.

[0057] The comprehensive loss function consists of a reconstruction loss subfunction, a classification loss subfunction, a maximum entropy loss subfunction, and a contrastive learning loss subfunction. The reconstruction loss subfunction calculates the loss between the node feature matrix in the graph structure data and the reconstructed node feature matrix output by the GCN decoder. The maximum entropy loss subfunction calculates the maximum entropy loss of the content vector. The classification loss subfunction calculates the classification loss of the style vector. The content vector and the style vector are vectors obtained by partitioning the latent space features of the nodes output by the GCN encoder. The contrastive learning loss subfunction calculates the contrastive loss based on positive and negative node pairs. The positive and negative node pairs include positive node pairs and negative node pairs. The positive node pairs are node pairs composed of similar nodes, and the negative node pairs are node pairs composed of dissimilar nodes.

[0058] Furthermore, the GCN encoding module also includes an edge learner and a feature divider; the edge learner is used to calculate the edge weights between any two nodes; the GCN encoder is used to calculate the latent space features of the nodes based on the node feature matrix and the edge weights; the feature divider is used to divide the latent space features of the nodes into two parts on an average scale according to the feature dimension, namely a content vector and a style vector; wherein, the content vector is a fraud-irrelevant feature; and the style vector is a fraud-related feature.

[0059] The GCN decoding module further includes a positive and negative node pair determination unit; the GCN decoder is used to determine the reconstructed node feature matrix based on the edge weights and the node latent space features output by the GCN encoder; the positive and negative node pair determination unit is used to determine positive and negative node pairs based on the style vector and similarity algorithm output by the feature divider.

[0060] Example 2

[0061] This embodiment provides a method for determining a fraud detection model based on graph neural networks and decoupled representation learning, to further illustrate the process of determining the fraud detection model described in Embodiment 1. Figure 2 and Figure 3 As shown, the method includes the following 9 steps:

[0062] Step 1: Obtain the fraud transaction scenario dataset and process it into a graph structure using tools such as PyG and NetworkX. This fraud transaction scenario dataset is the same as the one described in Example 1, and will not be elaborated upon further here.

[0063] The specific process is as follows: After obtaining the fraud transaction scenario dataset, the required fraud graph structure data is obtained using PyG tools, with account entities as nodes and the transaction interaction between two account entities as edges. This is the graph structure data corresponding to the fraud transaction scenario dataset described in Example 1.

[0064] Step 2: Calculate the edge weights between each pair of nodes using an edge learner. The specific process is as follows:

[0065] Based on the node features obtained from the graph structure data, a transformation f(i, j) is used to calculate the edge weight between two nodes. Here, the edge weight W... e The calculation formula is as follows:

[0066]

[0067] In the formula, e represents the weight of the edge connecting node i and node j in the l-th layer. ij Let represent the edge connecting node i and node j, and let sigmoid represent the activation function. This represents the feature of node i obtained in the (l-1)th layer. This represents the feature of node j obtained in the (l-1)th layer.

[0068] Therefore, the latent space feature matrix Z of the nodes in layer 0 (0) The calculation is as follows:

[0069] Z (0) =σ(W T X+b) (2).

[0070] In the formula, σ represents the activation function, W and b represent the linear transformation parameters, X represents the node feature matrix in the graph structure data, which has n*d dimensions, where n represents the number of nodes and d represents the node feature dimension; through linear transformation, the node feature matrix is ​​transformed into Z(0), which has a dimension of n*k; T represents the transpose.

[0071] Step 3: Using the GCN encoder and edge weights, obtain the latent space features of the nodes.

[0072] The specific process is as follows: Based on the latent space features of the 0th layer nodes calculated in step 2, the latent space features Z of the 1st layer nodes encoded using the GCN encoder can be obtained. (l) The calculation formula is as follows:

[0073]

[0074]

[0075]

[0076] Where D is the degree matrix, θ is the edge weight of the l-th layer, and is the adjacency matrix of the graph in the graph structure data obtained by adding self-loops through the identity matrix I; θ is the weight parameter to be learned, and its dimension is k*k. It is the degree matrix of the l-th layer used for the Laplace transform.

[0077] Step 4: Using the GCN decoder and edge weights, reconstruct the node feature matrix and calculate the reconstruction loss. The specific process is as follows:

[0078] To ensure that the learned edge weights are beneficial for representing node features, the learned edge weights are added to the GCN encoder and GCN decoder to reconstruct the attributes of the nodes in the graph. The formula for calculating the latent space feature matrix obtained above is the working process of the GCN encoder. It can now be simply expressed as:

[0079] Z = encoder(X) (6).

[0080] Similarly, the GCN decoder is represented as:

[0081]

[0082] in, This represents the reconstructed node feature matrix.

[0083] Therefore, we can establish the reconstruction loss, i.e., use the mean squared error loss (MSE), as follows:

[0084]

[0085] Step 5: Divide the latent space features of a node into two parts—a style vector and a content vector. The content vector represents fraud-irrelevant features, while the style vector represents fraud-related features. Specifically, let z be the latent space feature of node i. i It is divided into two parts on average according to the feature dimension—content vector and style vector, denoted as and respectively.

[0086] Step 6: Calculate the maximum entropy loss of the content vector. The specific process is as follows:

[0087] The required conditions include: (i) its information can indeed characterize the node features of the original graph (i.e., graph structure data); and (ii) it does not contain features related to fraud. After the above reconstruction operation, the latent space features of the nodes can be restored, thus satisfying condition (i). Therefore, to minimize the amount of classification-related information and fraud-related features it contains, we maximize the entropy H, calculated as follows:

[0088]

[0089] H = -∑ t∈labels p t log p t (10).

[0090] in, Indicates use The predicted fraud probability, W class and b class These are the weight matrix and bias values ​​of the classifier. In the formula (10) for calculating entropy H, p t This represents the probability of predicting the label as t, where t belongs to the set of labels and can be either normal or fraudulent.

[0091] Step 7: Calculate the classification loss function for the style vectors. Specifically, use the style vectors used to detect fraud. Applying to the cross-entropy loss function L CE The calculation formula is as follows:

[0092]

[0093]

[0094] in, Indicates use The predicted fraud probability, y i ∈{0,1} represents the sample label.

[0095] Step 8: Construct positive and negative node pairs and calculate the contrastive loss based on the positive and negative node pairs. The specific process is as follows: Given a node v...i Within its sample batch, find the set of k nodes that are most similar to it based on cosine similarity. The set of the k least similar nodes Given the style vector matrix of the b-th batch Then its similarity matrix S b It can be calculated using the following formula:

[0096]

[0097]

[0098] node v i Create positive node pairs symmetrically with each similar node; otherwise, use node v. i and This constructs negative node pairs. In this embodiment, we aim for positive sample pairs to represent samples of the same class (closer), while negative samples to represent samples of different classes (more distant). After the classifier, this should manifest as positive sample pairs having similar anomaly probabilities, and negative sample pairs having more distant anomaly probabilities. The contrastive learning loss L... cl The calculation is as follows:

[0099]

[0100]

[0101] in, This represents the anomaly score of node j. Let W, z, and b be the union of the sets of similar nodes and dissimilar nodes of node i to which node j belongs ((16) the remaining W, z, and b have been mentioned above). (k is the same as k in step 8 above). Let m represent the set of similar nodes to node i. Similarly, p in (17) is calculated from (16).

[0102] Step 9: Add the reconstruction loss, maximum entropy loss, classification loss, and contrastive loss to calculate the total loss. If the training reaches the iteration limit or converges, the fraud detection method is complete; otherwise, update all network parameters and restart from step 2.

[0103] The specific process is as follows: The overall loss of the model includes four components: maximum entropy loss H, classification loss L... CE Reconstruction loss L rec Comparison of learning loss L cl Therefore, the overall loss is calculated as follows:

[0104] L = H + L CE +L rec+L cl (18).

[0105] Experimental Description and Results: The datasets used were the Amazon dataset, Elliptic dataset, and T-Finance dataset described in Table 1, with a training set to test set ratio of 2:8. The proportions of anomalous nodes in the three datasets were 6.87%, 9.76%, and 4.58%, respectively. Table 1 shows the comparison results of different models on the test set. The metric used for testing was F1, which comprehensively measures the performance of the detection models. GCN aggregates the neighbors of a node in the spatial domain and then directly classifies them; GraphSage selects a sampling method and fixes the number of neighbors when aggregating neighbor information for batch training; GAT uses an attention mechanism in the process of aggregating neighbors; CARE-GCN uses reinforcement learning to adjust the threshold and select the neighbors to be aggregated when a node is aggregating neighbors; FRAUDRE aggregates neighbors with different relationships for a node separately, and also applies an imbalanced loss function to alleviate the classification imbalance problem; PC-GCN uses a sampling and selection strategy, selects training samples based on node importance, downsamples normal samples and oversamples abnormal samples when aggregating neighbors; AMNet uses dual filters to capture the features of normal and abnormal node frequency bands respectively, and finally uses an attention mechanism for aggregation; BWGCN implements filters for multiple frequency bands based on beta kernel functions to better handle the features of abnormal frequency bands. This embodiment uses graph neural networks to model the graph structure data in fraud scenarios, and uses decoupled representation learning and reconstruction modules and contrastive learning modules to learn distinguishable feature representations for fraud and normal classes, thereby performing fraud classification tasks. As can be seen, the method in this embodiment achieved the highest F1 score on all three datasets, exceeding the other best-performing methods by 1.94 percentage points, 11.81 percentage points, and 3.88 percentage points, respectively.

[0106] Table 1 Test Results

[0107]

[0108]

[0109] An example: Taking the testing phase of the T-Fiance dataset scenario as an example, such as... Figure 5 As shown, in a transaction network centered on account node 1, several neighboring account nodes 2-5 have transaction relationships with it. The attributes of the nodes include the account's registration time, recent login frequency, transaction frequency, and transaction amount, etc. To determine whether node 1 is fraudulent, this example inputs the graph into the fraud detection model designed in this invention, specifically:

[0110] ① Use tools such as PyG and NetworkX to process the data into the form required by the model, including node feature matrices, adjacency lists, and node label lists.

[0111] ② Use attribute reconstruction methods to learn an edge weight learner, calculating the edge weights between each pair of nodes. For example... Figure 5 As shown, the calculated edge weights between node 1 and nodes 2-5 are 0.1, 0.1, 0.1, and 0.7.

[0112] ③ Using the GCN encoder and combining edge weights, the latent space features of node 1 are aggregated.

[0113] ④ The latent space features of node 1 are content vector and style vector. The style vector is input into the classifier to obtain the detection result, i.e. whether node 1 is a fraudulent user.

[0114] Example 3

[0115] In order to implement the method corresponding to Embodiment 1 above and achieve the corresponding functions and technical effects, a fraud detection system based on graph neural networks and decoupled representation learning is provided below.

[0116] like Figure 6 As shown, this fraud detection system based on graph neural networks and decoupled representation learning includes:

[0117] The data acquisition module 601 is used to acquire current transaction scenario data; the current transaction scenario data includes multiple account entities and attribute information of each account entity; the attribute information includes the account entity registration time, the number of logins within a set time period of the account entity, and the transaction information within the set time period of the account entity; the transaction information includes transaction frequency, total transaction amount, and last transaction amount.

[0118] The graph structure data determination module 602 is used to process the current transaction scenario data to obtain the current graph structure data corresponding to the current transaction scenario data; the current graph structure data includes the adjacency matrix and node feature matrix of the graph.

[0119] The detection module 603 is used to input the current graph structure data into the fraud detection model to identify fraudulent accounts in the current transaction scenario data.

[0120] The process of determining the fraud detection model is as follows:

[0121] The fraud neural network is trained using graph structure data corresponding to the fraud transaction scenario dataset and a comprehensive loss function.

[0122] The fraudulent transaction scenario dataset includes multiple transaction scenario sample data; the transaction scenario sample data includes multiple account entities and sample information for each account entity; the sample information includes attribute information and label information; the label information is either a fraudulent account or a legitimate account; the graph structure data corresponding to the fraudulent transaction scenario dataset includes the graph's adjacency matrix, node feature matrix, and node label list; the fraud neural network includes a GCN encoding module, a GCN decoding module, and a classifier; the fraud detection model includes a trained GCN encoding module and a trained classifier; the GCN encoding module includes at least a GCN encoder; the GCN decoding module includes at least a GCN decoder; the comprehensive loss function is a reconstruction loss sub-function. The system comprises a classification loss subfunction, a maximum entropy loss subfunction, and a contrastive learning loss subfunction. The reconstruction loss subfunction calculates the loss between the node feature matrix in the graph structure data and the reconstructed node feature matrix output by the GCN decoder. The maximum entropy loss subfunction calculates the maximum entropy loss of the content vector. The classification loss subfunction calculates the classification loss of the style vector. The content vector and the style vector are vectors obtained by partitioning the latent space features of the nodes output by the GCN encoder. The contrastive learning loss subfunction calculates the contrastive loss based on positive and negative node pairs. Positive node pairs consist of pairs of similar nodes, and negative node pairs consist of pairs of dissimilar nodes.

[0123] Example 4

[0124] This invention provides an electronic device including a memory and a processor. The memory stores a computer program, and the processor runs the computer program to enable the electronic device to perform the fraud detection method based on graph neural networks and decoupled representation learning as described in Embodiment 1.

[0125] Alternatively, the aforementioned electronic device may be a server.

[0126] In addition, embodiments of the present invention also provide a computer-readable storage medium storing a computer program that, when executed by a processor, implements the fraud detection method based on graph neural networks and decoupled representation learning of Embodiment 1.

[0127] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on its differences from other embodiments. Similar or identical parts between embodiments can be referred to interchangeably. For the systems disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the descriptions are relatively simple; relevant parts can be referred to the method section.

[0128] This document uses specific examples to illustrate the principles and implementation methods of the present invention. The descriptions of the above embodiments are only for the purpose of helping to understand the method and core ideas of the present invention. Furthermore, those skilled in the art will recognize that, based on the ideas of the present invention, there will be changes in the specific implementation methods and application scope. Therefore, the content of this specification should not be construed as a limitation of the present invention.

Claims

1. A fraud detection method based on graph neural networks and decoupled representation learning, characterized in that, include: Obtain current transaction scenario data; the current transaction scenario data includes multiple account entities and attribute information of each account entity; The attribute information includes the account entity's registration time, the number of logins within a specified time period, and the account entity's transaction information within the specified time period; the transaction information includes transaction frequency, total transaction amount, and the amount of the last transaction. The current transaction scenario data is processed to obtain the current graph structure data corresponding to the current transaction scenario data; the current graph structure data includes the graph's adjacency matrix and node feature matrix; The current graph structure data is input into the fraud detection model to identify fraudulent accounts in the current transaction scenario data; The process of determining the fraud detection model is as follows: Using graph structure data corresponding to the fraud transaction scenario dataset and a comprehensive loss function, the fraud neural network is trained to obtain a well-trained fraud neural network. The fraudulent transaction scenario dataset includes multiple transaction scenario sample data; the transaction scenario sample data includes multiple account entities and sample information for each account entity; the sample information includes attribute information and tag information; the tag information is either a fraudulent account or a legitimate account; The graph structure data corresponding to the fraud transaction scenario dataset includes the graph's adjacency matrix, node feature matrix, and node label list; The fraud neural network includes a GCN encoding module, a GCN decoding module, and a classifier; the fraud detection model includes a trained GCN encoding module and a trained classifier; the GCN encoding module includes at least a GCN encoder, a side learner, and a feature segmenter; the GCN decoding module includes at least a GCN decoder and a positive / negative node pair determination unit; The comprehensive loss function consists of a reconstruction loss subfunction, a classification loss subfunction, a maximum entropy loss subfunction, and a contrastive learning loss subfunction. The reconstruction loss subfunction calculates the loss between the node feature matrix in the graph structure data and the reconstructed node feature matrix output by the GCN decoder. The maximum entropy loss subfunction calculates the maximum entropy loss of the content vector. The classification loss subfunction calculates the classification loss of the style vector. The content vector and the style vector are vectors obtained by partitioning the latent space features of the nodes output by the GCN encoder. The contrastive learning loss subfunction calculates the contrastive loss based on positive and negative node pairs. The positive and negative node pairs include positive node pairs and negative node pairs. The positive node pairs are node pairs composed of similar nodes, and the negative node pairs are node pairs composed of dissimilar nodes.

2. The fraud detection method based on graph neural networks and decoupled representation learning according to claim 1, characterized in that, The current transaction scenario data is processed to obtain the current graph structure data corresponding to the current transaction scenario data, specifically including: For the current transaction scenario data, PyG or NetworkX tools are used to determine the current graph structure data corresponding to the current transaction scenario data, with account entities as nodes and the transaction interaction between two account entities as edges.

3. The fraud detection method based on graph neural networks and decoupled representation learning according to claim 1, characterized in that, The edge learner is used to calculate the edge weights between any two nodes; The GCN encoder is used to calculate the latent space features of nodes based on the node feature matrix and edge weights; The feature divider is used to divide the latent space features of a node into two parts on an average basis according to the feature dimension: a content vector and a style vector. The content vector consists of fraud-irrelevant features, and the style vector consists of fraud-related features.

4. The fraud detection method based on graph neural networks and decoupled representation learning according to claim 3, characterized in that, The GCN decoder is used to determine the reconstructed node feature matrix based on the edge weights and the node latent space features output by the GCN encoder. The positive and negative node pair determination unit is used to determine positive and negative node pairs based on the style vector output by the feature segmenter and the similarity algorithm.

5. The fraud detection method based on graph neural networks and decoupled representation learning according to claim 1, characterized in that, The reconstruction loss function is: ; Among them, L rec Indicates the reconstruction loss. This represents the reconstructed node feature matrix. X This represents the node feature matrix.

6. The fraud detection method based on graph neural networks and decoupled representation learning according to claim 1, characterized in that, The classification loss function is: ; ; in, Indicates the use of style vectors The predicted fraud probability W class , b class These represent the weight matrix and bias values ​​of the classifier, respectively. ∈{0,1} represents the sample label; L CE This represents the classification loss.

7. The fraud detection method based on graph neural networks and decoupled representation learning according to claim 1, characterized in that, The maximum entropy loss function is: ; ; in, Indicates the use of content vectors The predicted fraud probability W class , b class These represent the weight matrix and bias values ​​of the classifier, respectively. H This represents the maximum entropy loss. p t Indicates the predicted label is t The probability, t It belongs to the label set and can be classified as either normal or fraudulent.

8. The fraud detection method based on graph neural networks and decoupled representation learning according to claim 1, characterized in that, The contrastive learning loss function is: ; ; in, Indicates the use of style vectors The predicted anomaly score, v j ∈ Let j be the union of the sets of similar nodes and the sets of dissimilar nodes belonging to node i. W class , b class L represents the weight matrix and bias values ​​of the classifier, respectively; cl This represents the learning loss from comparison.

9. The fraud detection method based on graph neural networks and decoupled representation learning according to claim 1, characterized in that, The comprehensive loss function is: ; in, H This represents the maximum entropy loss. L CE L represents the classification loss. rec L represents the reconstruction loss. cl This represents the learning loss compared to the comparison.

10. A fraud detection system based on graph neural networks and decoupled representation learning, characterized in that, include: The data acquisition module is used to acquire current transaction scenario data; the current transaction scenario data includes multiple account entities and attribute information of each account entity; The attribute information includes the account entity's registration time, the number of logins within a specified time period, and the account entity's transaction information within the specified time period; the transaction information includes transaction frequency, total transaction amount, and the amount of the last transaction. The graph structure data determination module is used to process the current transaction scenario data to obtain the current graph structure data corresponding to the current transaction scenario data; the current graph structure data includes the adjacency matrix and node feature matrix of the graph; The detection module is used to input the current graph structure data into the fraud detection model to identify fraudulent accounts in the current transaction scenario data; The process of determining the fraud detection model is as follows: Using graph structure data corresponding to the fraud transaction scenario dataset and a comprehensive loss function, the fraud neural network is trained to obtain a well-trained fraud neural network. The fraudulent transaction scenario dataset includes multiple transaction scenario sample data; the transaction scenario sample data includes multiple account entities and sample information for each account entity; the sample information includes attribute information and tag information; the tag information is either a fraudulent account or a legitimate account; The graph structure data corresponding to the fraud transaction scenario dataset includes the graph's adjacency matrix, node feature matrix, and node label list; The fraud neural network includes a GCN encoding module, a GCN decoding module, and a classifier; the fraud detection model includes a trained GCN encoding module and a trained classifier; the GCN encoding module includes at least a GCN encoder, a side learner, and a feature segmenter; the GCN decoding module includes at least a GCN decoder and a positive / negative node pair determination unit; The comprehensive loss function consists of a reconstruction loss subfunction, a classification loss subfunction, a maximum entropy loss subfunction, and a contrastive learning loss subfunction. The reconstruction loss subfunction calculates the loss between the node feature matrix in the graph structure data and the reconstructed node feature matrix output by the GCN decoder. The maximum entropy loss subfunction calculates the maximum entropy loss of the content vector. The classification loss subfunction calculates the classification loss of the style vector. The content vector and the style vector are vectors obtained by partitioning the latent space features of the nodes output by the GCN encoder. The contrastive learning loss subfunction calculates the contrastive loss based on positive and negative node pairs. The positive and negative node pairs include positive node pairs and negative node pairs. The positive node pairs are node pairs composed of similar nodes, and the negative node pairs are node pairs composed of dissimilar nodes.

Citation Information

Patent Citations

  • System and method for machine learning based detection of fraud

    CA3108609A1

  • Systems and methods for automated fraud detection

    CA3133445A1