A feature extraction method and device

By generating original sub-graphs for network data in the financial field, inserting noise and restoring graph features, generating feature heat maps and extracting key features, the problem of feature engineering of graph type data in the prior art is solved, and more efficient and interpretable feature extraction is achieved.

CN117874491BActive Publication Date: 2025-06-24WEBANK (CHINA) +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202311865341.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-12-29
Publication Date
2025-06-24
Estimated Expiration
2043-12-29

AI Technical Summary

Technical Problem

When the prior art performs feature engineering on large-scale network data in the financial field, it is difficult to effectively identify unknown features in the business, and the recognition efficiency is low, especially when processing graph type data, it lacks an effective feature capture method.

Method used

By generating M original sub-maps, noise is inserted for each sub-map and graph feature reduction is performed, reconstructed sub-maps are generated, and feature heat maps are generated using feature differences, thereby extracting key features and improving the interpretability of feature engineering.

Benefits of technology

Effective feature engineering for graph-type data is realized, the interpretability of feature engineering is improved, and key features can be extracted more accurately, thereby improving the performance and prediction accuracy of the model.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117874491B_ABST
    Figure CN117874491B_ABST
Patent Text Reader

Abstract

An embodiment of the present invention provides a feature extraction method and apparatus. The method includes generating M original subgraphs based on the acquired network data; the subgraph information of the original subgraphs includes vertices, edges, and graph features, and the graph features include K vertex features of each vertex and F edge features of each edge. Insert noise into the graph features of each original subgraph, and then restore the graph features to generate reconstructed subgraphs; generate a feature heat map according to the feature differences between the graph features of the original subgraphs and the graph features of the corresponding reconstructed subgraphs; extract H key features from the K vertex features and the F edge features according to the feature heat maps respectively corresponding to the M original subgraphs. Thereby, feature engineering for graph-type data is realized, and the interpretability of feature engineering is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Embodiments of the present invention relate to the field of financial technology (Fintech), and in particular, to a feature extraction method and apparatus. Background Art

[0002] With the development of computer technology, more and more technologies are applied in the financial field, and traditional finance is gradually transforming into financial technology (Fintech). However, due to the requirements of security and real-time nature in the financial industry, higher requirements are also imposed on technologies. In many scenarios, machine learning algorithms are needed to classify or calculate large-scale network data. However, before inputting the large-scale network data into the machine learning algorithm, the large-scale network data is first processed using feature engineering, and then the processed data is input into the machine learning algorithm.

[0003] In the prior art, a variety of feature engineering solutions are provided. In a feature engineering solution based on expert experience, the algorithm performs weighted scoring of features for each account according to features and business logics specified by human experience. When an account is hit by certain rules and identified as an abnormal account, the system gives an alarm. This solution highly depends on human participation and support from business experts, and is a reverse extraction idea from point to surface, which cannot identify features unknown in business, and the formulation and matching of rules also result in low recognition efficiency of this type of method. To improve the recognition efficiency, another feature engineering solution can be adopted, that is, using a feature dimensionality reduction algorithm based on a neural network to process data, and using the neural network to embed high-dimensional account features into a lower-dimensional vector space. However, the feature dimensionality reduction algorithm itself does not have interpretability, and it is difficult to determine which features lead to the generation of target samples. Moreover, the above two feature engineering solutions can only be applied to numerical type data, and do not fully consider graph type data in the transaction network, such as the topological structure of the graph, the out-degree and in-degree of each node, and the characteristics of transaction edges, lacking the capture of graph features, and unable to perform feature engineering on this type of graph data of network data. Summary of the Invention

[0004] Embodiments of the present invention provide a feature extraction method and apparatus to implement feature engineering for graph type data and improve the interpretability of feature engineering.

[0005] In a first aspect, an embodiment of the present invention provides a feature extraction method, which can be executed by a feature extraction device. The method includes: generating M original subgraphs based on network data, where the subgraph information of each original subgraph includes vertices, edges, and graph features, and the graph features include K vertex features of each vertex and F edge features of each edge, and both K and F are positive integers; for each of the M original subgraphs, perform: inserting first noise into the graph features of the original subgraph to generate a noisy subgraph; then, performing graph feature restoration on the noisy subgraph to generate a reconstructed subgraph corresponding to the original subgraph, and the graph features of the reconstructed subgraph include K vertex features of each vertex in the reconstructed subgraph and F edge features corresponding to each edge; generating a feature heat map corresponding to the original subgraph according to the feature difference between the graph features of the original subgraph and the graph features of the reconstructed subgraph corresponding to the original subgraph; extracting H key features from the K vertex features and F edge features according to the feature heat maps respectively corresponding to the M original subgraphs, where H is a positive integer and H is less than the sum of K and F.

[0006] In the above technical solution, based on network data, M original subgraphs can be extracted from the network data, with each of the M target accounts as the central vertex. The original subgraph corresponding to each target account is a transaction network centered around the target account, and the original subgraph includes rich vertex features and edge features, which can not only improve the quality of feature engineering but also enhance the interpretability of feature engineering. For each of the original subgraphs, noise is inserted and then restored to generate a reconstructed subgraph. By comparing the differences between the graph features of the original subgraph and the reconstructed subgraph, a feature heat map reflecting the differences before and after the features can be obtained. Then, according to the feature heat maps respectively corresponding to the M original subgraphs, a small number of key features are extracted from a large number of vertex features and edge features. These key features are more likely to be the most important features for distinguishing samples, enabling the subsequent model using these key features to achieve better model performance. Moreover, the above solution can perform feature engineering on graph-type data and improve the interpretability of feature engineering.

[0007] Optionally, the original subgraph is an N-order subgraph; generating M original subgraphs based on network data includes: for each of the M target accounts included in the network data, perform: based on the network data, with the target account as the central vertex, through N diffusion iterations, determining the account information associated with the target account as the neighbor vertices of the N-order subgraph corresponding to the target account, and taking the transaction information between the vertices in the N-order subgraph as the edges of the N-order subgraph corresponding to the target account; where the nth diffusion iteration is used to determine the nth-order vertices of the original subgraph.

[0008] In the above technical solution, the N-order subgraph can reflect the transaction network centered around the target account and can better capture global features.

[0009] Optionally, perform graph feature restoration on the noisy subgraph to generate a reconstructed subgraph corresponding to the original subgraph, including: inputting the noisy subgraph into a first graph neural network model to output a first predicted value corresponding to the first noise inserted in the noisy subgraph; the first graph neural network model is trained according to at least one first preset sample, and the first preset sample is a preset noisy subgraph with a preset noise value label; removing the first predicted value from the graph features of the noisy subgraph to obtain a reconstructed subgraph corresponding to the original subgraph.

[0010] In the above solution, by inserting noise into the original subgraph and then restoring the graph features to obtain a reconstructed subgraph, the principle that "normal behavioral features are easy to be restored, while features with abnormal behaviors are difficult to be restored" is utilized, so that the graph features that are difficult to be restored can be found, which is convenient for subsequent screening of key features.

[0011] Optionally, removing the first predicted value from the graph features of the noisy subgraph to obtain a reconstructed subgraph corresponding to the original subgraph includes: removing the first predicted value from the graph features of the noisy subgraph to obtain a first reconstructed subgraph corresponding to the original subgraph; inputting the first reconstructed subgraph into a second graph neural network model to predict the abnormal probability corresponding to the first reconstructed subgraph; the second graph neural network model is trained according to at least one second preset sample, and the second preset sample is a reconstructed subgraph corresponding to the first preset sample with a positive sample label or a negative sample label; determining a reconstructed subgraph corresponding to the original subgraph according to the abnormal probability corresponding to the first reconstructed subgraph.

[0012] Through the above technical solution, a more accurate reconstructed subgraph can be determined. After restoring the noisy subgraph, the abnormal probability of the first reconstructed subgraph is predicted, and the final reconstructed subgraph is determined according to the abnormal probability, so that normal features in the noisy subgraph are retained during the reconstruction process, while abnormal features are not easily restored.

[0013] Optionally, determining a reconstructed subgraph corresponding to the original subgraph according to the abnormal probability corresponding to the first reconstructed subgraph includes: if the abnormal probability corresponding to the first reconstructed subgraph is less than the probability threshold, determining the first reconstructed subgraph as the reconstructed subgraph corresponding to the original subgraph; or, if the abnormal probability corresponding to the first reconstructed subgraph is greater than or equal to the probability threshold, reversely correcting the first predicted value according to the abnormal probability corresponding to the first reconstructed subgraph to obtain a second predicted value; removing the second predicted value from the graph features of the noisy subgraph to obtain a reconstructed subgraph corresponding to the original subgraph.

[0014] Through the above technical solution, normal features can be retained, while abnormal features are not easily restored, so that there are differences between the reconstructed subgraph and the original subgraph in terms of abnormal features, that is, guiding the noisy subgraph to be reconstructed in a healthy direction.

[0015] Optionally, a feature heat map corresponding to the original sub-graph is generated according to the feature difference between the graph features of the original sub-graph and the reconstructed sub-graph, including: determining a first feature matrix corresponding to the graph features of the original sub-graph, and determining a second feature matrix corresponding to the graph features of the reconstructed sub-graph; performing a matrix subtraction operation on the first feature matrix and the second feature matrix to generate a feature heat map corresponding to the original sub-graph.

[0016] The feature heat map obtained through the above technical solution reflects the degree of difference of each graph feature, can provide an intuitive data basis for screening key features, and can help people understand which features are invalid features and which features are highly correlated with abnormal behaviors.

[0017] Optionally, according to the feature heat maps respectively corresponding to the M original sub-graphs, H key features are extracted from the K vertex features and F edge features, including: for each feature among the K vertex features and F edge features, perform: determining M difference values corresponding to each feature from the feature heat maps respectively corresponding to the M original sub-graphs; determining H key features from the K vertex features and F edge features according to the M difference values corresponding to each feature.

[0018] Through the above technical solution, the most critical H key features can be screened out from a large number of graph features, which can provide better model performance for the subsequent model using the key features, and improve the calculation speed and prediction accuracy of the model.

[0019] Optionally, before generating M original sub-graphs based on the network data, the method further includes: performing a preprocessing operation on the network data; wherein, the preprocessing operation includes at least one of the following processing operations: graph feature encoding; filling missing feature values; regularizing or normalizing numerical type data.

[0020] Through the above solution, the network data can have a unified data structure.

[0021] In a second aspect, an embodiment of the present invention further provides a feature extraction device, including:

[0022] A construction unit, configured to generate M original sub-graphs based on network data, where the sub-graph information of each original sub-graph includes vertices, edges, and graph features, and the graph features include K vertex features of each vertex in the original sub-graph and F edge features of each edge, and both K and F are positive integers;

[0023] A processing unit, which is configured to perform the following operations for each of the M original subgraphs: insert first noise into the graph features of the original subgraph to generate a noise subgraph; then, restore the graph features of the noise subgraph to generate a reconstructed subgraph corresponding to the original subgraph, where the graph features of the reconstructed subgraph include K vertex features of each vertex in the reconstructed subgraph and F edge features corresponding to each edge; generate a feature heat map corresponding to the original subgraph according to the feature difference between the graph features of the original subgraph and the graph features of the reconstructed subgraph corresponding to the original subgraph; and extract H key features from the K vertex features and the F edge features according to the feature heat maps respectively corresponding to the M original subgraphs, where H is a positive integer and H is less than the sum of K and F.

[0024] Optionally, the original subgraph is an N-order subgraph; the constructing unit is specifically configured to perform the following operations for each of the M target accounts: based on network data, with the target account as the central vertex, through N diffusion iterations, determine the account information associated with the target account as the neighbor vertices of the N-order subgraph corresponding to the target account, and use the transaction information between the vertices in the N-order subgraph as the edges of the N-order subgraph corresponding to the target account; where the nth diffusion iteration is used to determine the nth-order vertices of the original subgraph.

[0025] Optionally, the processing unit is specifically configured to: input the noise subgraph into a first graph neural network model, and output a first prediction value corresponding to the first noise inserted in the noise subgraph; the first graph neural network model is trained according to at least one first preset sample, and the first preset sample is a preset noise subgraph with a preset noise value label; and remove the first prediction value from the graph features of the noise subgraph to obtain a reconstructed subgraph corresponding to the original subgraph.

[0026] Optionally, the processing unit is specifically configured to: remove the first prediction value from the graph features of the noise subgraph to obtain a first reconstructed subgraph corresponding to the original subgraph; input the first reconstructed subgraph into a second graph neural network model to predict the anomaly probability corresponding to the first reconstructed subgraph; the second graph neural network model is trained according to at least one second preset sample, and the second preset sample is a reconstructed subgraph corresponding to the first preset sample with a positive sample label or a negative sample label; and determine a reconstructed subgraph corresponding to the original subgraph according to the anomaly probability corresponding to the first reconstructed subgraph.

[0027] Optionally, the processing unit is specifically configured to: if the anomaly probability corresponding to the first reconstructed subgraph is less than the probability threshold, determine the first reconstructed subgraph as the reconstructed subgraph corresponding to the original subgraph; or, if the anomaly probability corresponding to the first reconstructed subgraph is greater than or equal to the probability threshold, reverse-correct the first prediction value according to the anomaly probability corresponding to the first reconstructed subgraph to obtain a second prediction value; and remove the second prediction value from the graph features of the noise subgraph to obtain a reconstructed subgraph corresponding to the original subgraph.

[0028] Optionally, the processing unit is specifically configured to: determine a first feature matrix corresponding to the graph features of the original sub-graph, and determine a second feature matrix corresponding to the graph features of the reconstructed sub-graph; perform a matrix subtraction operation on the first feature matrix and the second feature matrix to generate a feature heat map corresponding to the original sub-graph.

[0029] Optionally, the processing unit is specifically configured to: for each of the K vertex features and F edge features, perform: determine M difference values corresponding to each feature from the feature heat maps respectively corresponding to the M original sub-graphs; determine H key features from the K vertex features and F edge features according to the M difference values corresponding to each feature.

[0030] Optionally, the processing unit is further configured to: perform a preprocessing operation on the network data; wherein, the preprocessing operation includes at least one of the following processing operations: graph feature encoding; missing feature value filling; regularizing or normalizing numerical type data.

[0031] In a third aspect, an embodiment of the present invention provides a computing device, including:

[0032] A memory for storing program instructions;

[0033] A processor for calling the program instructions stored in the memory and executing the feature extraction method according to the obtained program.

[0034] In a fourth aspect, an embodiment of the present invention provides a computer-readable storage medium, where the computer-readable storage medium stores computer-executable instructions, and the computer-executable instructions are used to cause a computer to execute the feature extraction method.

[0035] For the beneficial effects of the second aspect to the fourth aspect, reference may be made to the beneficial effects of the first aspect and any optional solution of the first aspect above, which will not be elaborated here. Description of the Drawings

[0036] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0037] Figure 1 It is a schematic diagram of a system architecture provided by an embodiment of the present invention;

[0038] Figure 2 It is a schematic flow chart of a feature extraction method provided by an embodiment of the present invention;

[0039] Figure 3A schematic diagram of network data provided by an embodiment of the present invention;

[0040] Figure 4 A schematic diagram of a third-order subgraph provided by an embodiment of the present invention;

[0041] Figure 5 A schematic diagram of a feature engineering method based on graph noise diffusion and reconstruction provided by an embodiment of the present invention;

[0042] Figure 6 A schematic diagram of the structure of a feature extraction device provided by an embodiment of the present invention. Detailed implementation manners

[0043] In order to make the objectives, technical solutions, and advantages of the present invention clearer, the present invention will be further described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without making creative efforts belong to the scope of protection of the present invention.

[0044] Figure 1 A system architecture provided by an embodiment of the present invention. As Figure 1 shown, the system architecture may be server 100, including a processor 110, a communication interface 120, and a memory 130.

[0045] Among them, the communication interface 120 is used to communicate with a terminal device, receive and transmit information transmitted by the terminal device, and implement communication.

[0046] The processor 110 is the control center of the server 100, connects various parts of the entire server 100 through various interfaces and lines, and executes various functions of the server 100 and processes data by running or executing software programs / modules stored in the memory 130 and calling data stored in the memory 130. Optionally, the processor 110 may include one or more processing units.

[0047] The memory 130 can be used to store software programs and modules. The processor 110 executes various function applications and data processing by running the software programs and modules stored in the memory 130. The memory 130 may mainly include a program storage area and a data storage area. Among them, the program storage area may store an operating system, application programs required for at least one function, etc.; the data storage area may store transaction data, etc. In addition, the memory 130 may include a high-speed random access memory, and may also include a non-volatile memory, such as at least one magnetic disk storage device, a flash memory device, or other volatile solid-state storage devices.

[0048] It should be noted that the aboveFigure 1 The structure shown is only an example, and the embodiments of the present invention are not limited thereto.

[0049] Based on the above description, Figure 2 exemplarily shows the flow of a feature extraction method provided by an embodiment of the present invention. This flow can be executed by a feature extraction device, which can be located in the server 100 as shown in Figure 1 or can be the server 100.

[0050] As Figure 2 shown, this flow specifically includes:

[0051] Step 201, obtain network data. The network data includes transaction information of L accounts and transaction information between accounts, where L is a positive integer.

[0052] Taking a bank as an example, transaction data can be stored in a data warehouse, such as a hive data warehouse. For example, information related to accounts registered in the bank is stored in the form of a bank account information table, and information related to the transaction behavior of any registered account with other accounts is stored in the form of a transaction table. In step 201, transaction information of all registered accounts can be obtained from the bank account information table and the transaction table as network data, or transaction information of some registered accounts can be obtained, such as transaction information of accounts that have transactions among all accounts, as network data. In the embodiments of this application, taking obtaining transaction information of L accounts as network data as an example for introduction.

[0053] Figure 3 Exemplarily shows a schematic diagram of a network data, as Figure 3 shown, this network data includes L vertices, which are account 1 to account L respectively. This network data also includes connection edges between the vertices that have transaction behaviors among the L vertices. For example, account 1 has transaction behaviors with account 2, account 3, account 7, and account 8 respectively. This network data includes the connection edge between account 1 and account 2, the connection edge (or called edge) between account 1 and account 3, the connection edge between account 1 and account 7, and the connection edge between account 1 and account 8. Also, for example, in addition to the transaction behavior with account 1, account 2 also has transaction behaviors with account 3 and account 4. This network data also includes the connection edge between account 2 and account 3 and the connection edge between account 2 and account 4. All the connection edges included in the network data are not listed one by one here. This network data also includes vertex features of each vertex and edge features of each connection edge.

[0054] Before constructing the graph structure data based on the obtained network data, it is necessary to further preprocess the network data. Since the number of features of each account vertex is huge, when fitting the graph structure data, not only the features of the account itself need to be considered, but also the features of its trading objects need to be aggregated. If the feature data in the original network data is directly used for graph neural network training, a large amount of redundant information will exceed the expressive ability of the graph neural network, thus limiting the prediction effect of the graph neural network model. To improve the quality of the graph structure data and enhance the model accuracy of the subsequent graph neural network when fitting the data and predicting the account credit risk, the redundant features in the graph features can be filtered through the graph feature importance ranking algorithm. For example, features such as the gender of the account opener and the bank where the account is opened can be filtered, and finally the most valuable core vertex features and edge features are retained, so that the subsequent graph neural network model using the data after feature filtering can obtain better model performance.

[0055] To improve the recognition accuracy and a certain degree of interpretability of the subsequent graph neural network. In the embodiments of the present application, before constructing the graph structure data based on the network data, preprocessing operations can be performed on the network data, and the preprocessing operations include but are not limited to at least one of the following processing operations: graph feature encoding; filling missing feature values; regularizing or normalizing numerical type data. For example, one-hot encoding is performed on the account opening location information, default values are filled for some missing feature values, or numerical type data is regularized and normalized, so as to ensure that the data structure is neat and unified.

[0056] Exemplarily, taking the current anti-money laundering business in banks as an example, it mainly includes three major types of indicators: vertex aggregation type indicators, transaction edge aggregation type indicators, and early warning indicators based on expert knowledge. It mainly monitors the following high-risk behaviors: cross-border transfers, large-value transfers, high-risk regions, the proportion of various types of transfer transactions, high-risk time periods, etc. The monitoring period is three months, which is consistent with the reporting period of risk users. In order to encode the above indicators into the initial feature vectors and then provide them to the graph neural network for representation learning, targeted feature encoding can be performed on the vertex features and edge features in the network data.

[0057] For different data types, the following means are mainly used for graph feature encoding:

[0058] Multi-category features (currency, region) are encoded using one-hot encoding 0100 0001;

[0059] Binary classification features (whether the account is closed) are encoded using 0-1 encoding;

[0060] Ratio features (large-value proportion) are processed using Min-Max to be between 0 and 1;

[0061] Numerical features (total amount / total number of transactions) are processed using Min-Max to be between 0 and 1.

[0062] The above method of feature encoding can be modified and optimized by customizing HQL.

[0063] In the embodiments of the present application, when preprocessing network data, it supports the extraction of custom vertex (account) features and edge features (transaction information), can be compatible with existing metric libraries, and customizes the selection of the account opening region, customer occupation, age, etc. of the account as vertex features. It also supports customizing the selection of transaction aggregation information between two accounts, such as the number of transfers within a certain period and the total transfer amount within a certain period, etc. as edge features. Thus, it can make full use of human experience and knowledge to select graph features, thereby strengthening the interpretability of the algorithm towards the business side, and at the same time, the flexible feature selection can also improve the accuracy of algorithm recognition.

[0064] After performing the preprocessing operation on the network data, based on the network data after the preprocessing operation, step 202 is executed.

[0065] Step 202, construct graph structure data based on the network data.

[0066] Among them, the graph structure data includes M original subgraphs corresponding to M target accounts that are respectively used as central vertices. The L accounts include M target accounts, and M is a positive integer less than or equal to L. In the embodiments of the present application, the value of M can be set according to actual needs and is not limited here.

[0067] In one example, for example, the network data includes 1000 accounts, and the constructed graph structure data includes 1000 original subgraphs. That is to say, each of the 1000 accounts in the network data is used as a central vertex, and 1000 original subgraphs are correspondingly generated.

[0068] In another example, for example, the network data includes 1000 accounts, and the constructed graph structure data includes 800 original subgraphs. That is to say, 800 accounts are selected from the network data as central vertices respectively, and 800 original subgraphs are correspondingly generated.

[0069] In the embodiments of the present application, the above original subgraph can be an N - order subgraph, where N is a positive integer.

[0070] In a possible implementation manner, the above step 202 can be implemented as follows: For each of the M target accounts, perform: Based on network data, with the target account as the central vertex, through N diffusion iterations, determine the account information associated with the target account as the neighbor vertices of the Nth-order subgraph corresponding to the target account, and use the transaction information between the vertices in the Nth-order subgraph as the edges of the Nth-order subgraph corresponding to the target account; where the nth diffusion iteration is used to determine the nth-order vertices of the original subgraph. The Nth-order subgraph can reflect the transaction network centered on the target account, can better capture global features, and thus accurately extract key features.

[0071] In the following, N is taken as 3 for illustration, that is, the Nth-order subgraph is a third-order subgraph. It should be understood that the value of N can be set according to actual needs and is not limited here.

[0072] Combined with Figure 3 the network data shown, the extraction of the third-order subgraph from the network data is introduced.

[0073] Exemplarily, taking Figure 3 the account 1 in the network data shown as the central vertex, extract the third-order subgraph corresponding to account 1 from the network data; take account 2 as the central vertex and extract the third-order subgraph corresponding to account 2 from the network data; take account 3 as the central vertex and extract the third-order subgraph corresponding to account 2 from the network data; ……, and so on, take account L as the central vertex and extract the third-order subgraph corresponding to account L from the network data.

[0074] In a possible implementation manner, the process of extracting the third-order subgraph corresponding to each account from the network data can be achieved by inputting the network data into the Pregel graph computing framework, and the Pregel graph computing framework supports the relevant processing and calculation of large-scale graph data on the Spark cluster. The extraction process is as follows: First, use HQL to extract the central vertex; secondly, label the central vertex, and this label can be used for the diffusion iteration of the label Message through the Pregel graph computing framework. In each iteration, the first-order neighbor vertices of the current vertex will be updated and labeled accordingly. After three rounds of iteration, the third-order subgraph can be obtained.

[0075] Next, based on Figure 3 the network data shown, the extraction of the third-order subgraph corresponding to account 1 is taken as an example for illustration.

[0076] Extract from Figure 3 the network data shown the third-order subgraph with account 1 as the central vertex, other vertices with direct or indirect transaction behaviors with the central vertex, and the transaction behaviors between each vertex as the connecting edges. Thus, as shown in Figure 4The third-order subgraph corresponding to the account 1 shown, which includes a central vertex, i.e., the account 1; this third-order subgraph also includes multiple other vertices that have direct or indirect transaction behaviors with the central vertex. For example, the account 2 and the account 3 are the first-order neighbor vertices obtained by the first diffusion iteration, the account 4 and the account 5 are the second-order neighbor vertices obtained by the second diffusion iteration, and the account 6 is the third-order neighbor vertex obtained by the third diffusion iteration.

[0077] In the embodiments of the present application, the subgraph information of the original subgraph corresponding to each target account includes vertices, edges, and graph features. Among them, the vertices include the accounts associated with the target account, the edges include the transaction information between the accounts, and the graph features include K vertex features of each vertex in the original subgraph and F edge features corresponding to each edge. Both K and F are positive integers. The vertex features are, for example, account type, place of account opening, account opening time, etc., and the edge features are, for example, transaction amount, number of transactions, etc. The account features and transaction features may also include other contents, and the present application does not limit this.

[0078] The graph structure data can be stored in the database in the form of a table. For example, the subgraph vertex table is used to store the vertex information and vertex features of each original subgraph with the central vertex as the primary key, and the specific format is shown in Table 1 below.

[0079] Table 1 Subgraph Vertex Table

[0080]

[0081]

[0082] Also, for example, the subgraph edge table is used to store all the edges and edge features (such as the attributes of the edges) between the vertices in the original subgraph. For example, all the edges and their attributes between the vertices involved in Table 1 are shown in Table 2 below.

[0083] Table 2 Subgraph Edge Table

[0084] Payer Number Payee Number Edge Attribute Vertex 1 Vertex 2 (Feature 1, Feature 2, Feature 3, Feature 4...) Vertex 1 Vertex 3 (Feature 1, Feature 2, Feature 3, Feature 4...) Vertex 2 Vertex 3 (Feature 1, Feature 2, Feature 3, Feature 4...) Vertex 2 Vertex 4 (Feature 1, Feature 2, Feature 3, Feature 4...)

[0085] In the embodiments of the present application, after obtaining the original subgraph with a certain account as the central vertex, the graph neural network model can be used to monitor and evaluate the whole of the original subgraph with this account as the central vertex. Compared with evaluating the single account information, it can better capture the global features.

[0086] The graph structure data constructed in the above step 202 still includes a large number of graph features. To further improve the quality of the graph structure data, the M original subgraphs can be further processed to screen out the key features, so that the model using this graph structure data later can obtain better model performance.

[0087] Therefore, the present application proposes a feature engineering method for noise diffusion and reconstruction based on graph-structured data, which screens the graph features in the graph-structured data. By continuously inserting random noise into the original subgraphs, they are transformed into a "chaotic state". Then, the principle that "normal behavioral features are easy to restore, while abnormal behavioral features are difficult to restore" is utilized. During the restoration process, a graph neural network is used to predict the previously inserted noise. Then, the chaotic noisy subgraph is restored to a normal reconstructed subgraph. Then, by comparing the graph features of the original graph with those of the reconstructed subgraph, the graph features that are difficult to restore are found. These graph features are considered more likely to be the key features for distinguishing positive and negative samples, that is, the features highly correlated with abnormal behaviors, thereby achieving the purpose of feature screening. Features that are not important for model prediction are deleted, that is, redundant information is removed, improving the computational speed of the model and the accuracy of the prediction results. This feature engineering can evaluate the importance of each feature from multiple perspectives, ensuring that the screened dataset contains all key information without redundant data. At the same time, it can provide relevant explanations to help business personnel understand why certain features are determined to be invalid features while the remaining features are identified as features highly correlated with abnormal behaviors.

[0088] The process of the feature engineering for noise diffusion and reconstruction based on graph data will be described below in conjunction with steps 203 to 205.

[0089] Step 203: For each of the M original subgraphs, insert first noise into the graph features of the original subgraph to generate a noisy subgraph.

[0090] Among them, the first noise can be random noise.

[0091] Exemplarily, a series of random noises that follow a normal distribution within a fixed range can be inserted into the original subgraph. For example, for the feature of the night trading frequency (5 times), a noise value (-0.67) can be randomly drawn from a normal distribution with a mean of 0 and a variance of 1, and this noise is added to the original trading frequency value. Through multiple insertions of the above-mentioned noise, a noisy subgraph is obtained. The features of each vertex and edge in the noisy subgraph will follow a normal distribution. Inserting noise that conforms to the normal distribution is to ensure that the authenticity of the original graph is not lost during the entire process of noise diffusion, so that it can be successfully restored by the denoising network during the restoration process.

[0092] Step 204: Restore the graph features of the noisy subgraph to generate a reconstructed subgraph corresponding to the original subgraph.

[0093] The graph features of the reconstructed subgraph include K vertex features of each vertex in the reconstructed subgraph and F edge features corresponding to each edge.

[0094] In an implementation that can achieve the above step 204, the noise subgraph is input into the first neural network model, and the first predicted value corresponding to the first noise inserted in the noise subgraph is output; the graph feature of the noise subgraph is removed from the first predicted value to obtain a reconstructed subgraph corresponding to the original subgraph. Among them, the first neural network model is trained according to at least one first preset sample, and the first preset sample is a preset noise subgraph with a preset noise value label.

[0095] Specifically, removing the noise prediction value from the graph feature of the noise subgraph to obtain a reconstructed subgraph corresponding to the original subgraph can be achieved through the following process:

[0096] S1, the graph feature of the noise subgraph is removed from the first predicted value to obtain a first reconstructed subgraph corresponding to the original subgraph.

[0097] S2, the first reconstructed subgraph is input into the second graph neural network model to predict the anomaly probability corresponding to the first reconstructed subgraph. Among them, the second graph neural network model is trained according to at least one second preset sample, and the second preset sample is a reconstructed subgraph corresponding to the first preset sample with a positive sample label or a negative sample label.

[0098] S3, according to the anomaly probability corresponding to the first reconstructed subgraph, determine the reconstructed subgraph corresponding to the original subgraph.

[0099] If the anomaly probability corresponding to the first reconstructed subgraph is less than the probability threshold, then the first reconstructed subgraph is determined as the reconstructed subgraph corresponding to the original subgraph.

[0100] If the anomaly probability corresponding to the first reconstructed subgraph is greater than or equal to the probability threshold, then according to the anomaly probability corresponding to the first reconstructed subgraph, the first predicted value is corrected backward to obtain a second predicted value; the graph feature of the noise subgraph is removed from the second predicted value to obtain a reconstructed subgraph corresponding to the original subgraph.

[0101] Exemplarily, such as Figure 5As shown, any original subgraph is selected from the graph structure data, and random noise is inserted into the graph features of the original subgraph to obtain a noisy subgraph. Then, the original subgraph with superimposed random noise is restored to a reconstructed subgraph with no abnormal features. This process involves two layers of neural networks, namely the first graph neural network model (such as a denoising network) and the second graph neural network model (such as a guiding classifier). Specifically, the noisy subgraph is input into the denoising network. The denoising network is a self-supervised neural network that predicts the predicted value corresponding to the previously inserted first noise through training. Then, based on this predicted value, the noise of the features corresponding to the noisy subgraph is removed to obtain an intermediate reconstructed subgraph. After that, the intermediate reconstructed subgraph and the suspicious label are input into the guiding classifier. The guiding classifier is a supervised neural network that is used to predict the abnormal probability of the subgraph and correct the features according to the probability to obtain the final reconstructed subgraph, that is, the reconstructed subgraph corresponding to the original subgraph.

[0102] In the embodiments of the present application, restoring the original subgraph with superimposed random noise to a reconstructed subgraph with no abnormal features may include the processing of two types of samples. First, for the noisy subgraph of the positive sample, since it has no abnormal features itself, only the noise needs to be predicted and restored in the direction of the original subgraph. Second, for the noisy subgraph of the negative sample, in addition to restoring the noise, it is also necessary to restore the abnormal features to the non-abnormal range according to the feature pattern learned from the positive sample to obtain a reconstructed subgraph with no abnormal features.

[0103] The denoising network is responsible for predicting the noise inserted during the graph noise diffusion process to ensure that the features in the subgraph will not be distorted during the restoration process. The process of predicting the noise is the process by which the graph neural network learns and fits the trading pattern of the normal subgraph. The denoising network adopts a self-supervised training method, that is, through the neural network training method, the input is the feature matrix of the graph, and the output is a predicted value of the noise. The prediction target is the amplitude of the previously inserted noise, that is, -0.67 in the above example. Through training, the denoising network can learn the trading pattern in the subgraph in this way, so as to be able to restore different original subgraphs in the subsequent process. At the same time, by pre-training the denoising network and retaining the training results, and migrating the trained model parameters to the guiding classifier neural network, the number of training iterations can be effectively reduced, training resources can be saved, and the accuracy of the prediction results can be improved.

[0104] The guiding classifier is a graph neural network responsible for correcting the abnormal features of the subgraph. Its input is the subgraph passed through the denoising network and its suspicious labels. During the restoration process of the noisy subgraph, if the suspicious label of the original subgraph is abnormal, the predicted value of the denoising network is corrected through the output probability of the guiding classifier, thereby guiding the noisy subgraph to be corrected towards the abnormal-free reconstructed subgraph. In this application, the features are not directly corrected because the features do not have uniformity and cannot be directly compared between different features. Therefore, it is chosen to superimpose noise values (with uniformity) on the features and judge the key features by correcting the noise values and comparing the differences before and after correction. For example, if the guiding classifier predicts that the current subgraph is a positive sample without money laundering behavior, then the output of the guiding classifier is 0, that is, the predicted noise value of the denoising network is not corrected. If the current subgraph is judged by the guiding classifier to be an abnormal money laundering network, the output is the probability 0.89 that the subgraph is an abnormal subgraph, and then correction is initiated. Suppose the predicted value of the denoising network is 0.67, then the finally corrected restored noise value is (1 - 0.89) * 0.67. Through this method, normal features can be retained, while abnormal features are not easily restored, so that the reconstructed subgraph and the original subgraph have differences in abnormal features, that is, guiding the noisy subgraph to be reconstructed in a "healthy" direction.

[0105] Step 205: Generate a feature heat map corresponding to the original subgraph according to the feature difference between the graph features of the original subgraph and the graph features of the reconstructed subgraph.

[0106] In an implementation that can implement the above step 205, determine the first feature matrix corresponding to the graph features of the original subgraph, determine the second feature matrix corresponding to the graph features of the reconstructed subgraph, perform matrix subtraction operation on the first feature matrix and the second feature matrix, and generate a feature heat map corresponding to the original subgraph. This feature heat map can represent the difference between the graph features in the original subgraph and the corresponding graph features in the reconstructed subgraph corresponding to the original subgraph. The greater the difference between the graph features in the original subgraph and the corresponding graph features in the reconstructed subgraph corresponding to the original subgraph, the higher the heat value. The key features in the original subgraph can be determined through the feature heat map.

[0107] Step 206: Extract H key features from the K vertex features and F edge features according to the feature heat maps respectively corresponding to the M original subgraphs, where H is a positive integer and H is less than the sum of K and F.

[0108] In an implementation that can achieve the above step 206, for each of the K vertex features and F edge features, where each feature here can be a vertex feature or an edge feature, perform: determine the difference value corresponding to the feature from the feature heatmaps respectively corresponding to the M original subgraphs, obtaining M difference values corresponding to the feature; according to the M difference values corresponding to each feature, determine H key features from the K vertex features and F edge features.

[0109] For example, for the M difference values corresponding to each feature, the final difference value corresponding to each feature can be determined by means of simple accumulation or weighted accumulation. Generally speaking, the smaller the final difference value, the lower the importance (or key) level, and the feature with the largest final difference value is the most important key feature. The feature heatmap can also provide corresponding explanations for experts.

[0110] In an example, the K vertex features and F edge features can be sorted according to the size of the final difference value, and the H features with larger final difference values are determined as key features.

[0111] In another example, it can also be to set a difference threshold, and the features with final difference values greater than the difference threshold are determined as key features.

[0112] Exemplarily, the key features can be applied to the scenario of identifying group money laundering. The H key features are the H features that are most critical for identifying money laundering behaviors. The extracted H key features can be input into an identification model for identifying group money laundering, so as to predict the risk index of group money laundering through the identification model. When the predicted risk index of group money laundering exceeds a certain threshold, a risk alarm is issued. Thereafter, relevant business experts are involved to conduct a manual investigation of the accounts involved in the subgraph. Thus, it supports real-time group money laundering risk prediction under a large amount of transaction data.

[0113] In the embodiments of the present application, from a complete transaction network, with an account as the central vertex, a raw transaction subgraph is first extracted. Each raw subgraph is an input sample of this model. These transaction subgraphs can be either positive samples or negative samples, that is, known suspicious groups. Finally, the key features obtained by accumulating all input samples are added up, and then the difference degrees of all features are sorted, and finally the features that can best represent the abnormal behavior of the samples are screened and retained.

[0114] The method provided by this application mainly has the following advantages: First is interpretability. Through comparison, a feature heat map reflecting the differences before and after features can be obtained, and then it can be determined which features are abnormal, resulting in this original sub - graph being identified as a money - laundering gang. Second, compared with traditional graph neural networks that need to learn on a graph with 200 million user vertices in its entirety, leading to very low training efficiency and being unable to adapt to large - scale transaction networks, in the embodiments of this application, learning can be performed on each original sub - graph one by one, with high computational efficiency.

[0115] It should be understood that this application is applicable to performing feature engineering on graph - type data, and the application scenario is not limited. For example, it is applied to performing feature engineering on transaction data in the anti - money - laundering scenario.

[0116] Based on the same technical concept, Figure 6 An exemplary illustration shows a feature extraction device provided by an embodiment of the present invention, and this device can execute the process of the feature extraction method.

[0117] As Figure 6 shown, the device includes:

[0118] An acquisition unit 601, configured to acquire network data, where the network data includes transaction information of L accounts and transaction information between accounts, and L is a positive integer;

[0119] A construction unit 602, configured to construct graph - structured data based on the network data; the graph - structured data includes M original sub - graphs corresponding to M target accounts that are respectively used as central vertices. The L accounts include M target accounts. The sub - graph information of each original sub - graph corresponding to a target account includes vertices, edges, and graph features. The vertices include accounts associated with the target account, the edges include transaction information between accounts, and the graph features include K vertex features of each vertex in the original sub - graph and F edge features corresponding to each edge. M is a positive integer less than or equal to L, and both K and F are positive integers.

[0120] A processing unit 603, configured to, for each of the M original sub - graphs: insert first noise into the graph features of the original sub - graph to generate a noisy sub - graph; then, perform graph - feature restoration on the noisy sub - graph to generate a reconstructed sub - graph corresponding to the original sub - graph. The graph features of the reconstructed sub - graph include K vertex features of each vertex in the reconstructed sub - graph and F edge features corresponding to each edge; generate a feature heat map corresponding to the original sub - graph according to the feature difference between the graph features of the original sub - graph and the graph features of the reconstructed sub - graph corresponding to the original sub - graph; extract H key features from the K vertex features and F edge features according to the feature heat maps respectively corresponding to the M original sub - graphs, where H is a positive integer and H is less than the sum of K and F.

[0121] Optionally, the building unit 602 is specifically configured for the original subgraph to be an N - order subgraph; specifically, the building unit is configured to: for each of the M target accounts, perform the following: based on the network data, with the target account as the central vertex, through N diffusion iterations, determine the account information associated with the target account as the neighbor vertices of the N - order subgraph corresponding to the target account, and use the transaction information between the vertices in the N - order subgraph as the edges of the N - order subgraph corresponding to the target account; where the nth diffusion iteration is used to determine the nth - order vertices of the original subgraph.

[0122] Optionally, the processing unit 603 is specifically configured to: input the noisy subgraph into the first graph neural network model to output the first prediction value corresponding to the first noise inserted in the noisy subgraph; the first graph neural network model is trained according to at least one first preset sample, and the first preset sample is a preset noisy subgraph with a preset noise value label; remove the first prediction value from the graph features of the noisy subgraph to obtain the reconstructed subgraph corresponding to the original subgraph.

[0123] Optionally, the processing unit 603 is further configured to: remove the first prediction value from the graph features of the noisy subgraph to obtain the first reconstructed subgraph corresponding to the original subgraph; input the first reconstructed subgraph into the second graph neural network model to predict the anomaly probability corresponding to the first reconstructed subgraph; the second graph neural network model is trained according to at least one second preset sample, and the second preset sample is the reconstructed subgraph corresponding to the first preset sample with a positive sample label or a negative sample label; determine the reconstructed subgraph corresponding to the original subgraph according to the anomaly probability corresponding to the first reconstructed subgraph.

[0124] Optionally, the processing unit 603 is specifically configured to: if the anomaly probability corresponding to the first reconstructed subgraph is less than the probability threshold, determine the first reconstructed subgraph as the reconstructed subgraph corresponding to the original subgraph; or, if the anomaly probability corresponding to the first reconstructed subgraph is greater than or equal to the probability threshold, reverse - correct the first prediction value according to the anomaly probability corresponding to the first reconstructed subgraph to obtain the second prediction value; remove the second prediction value from the graph features of the noisy subgraph to obtain the reconstructed subgraph corresponding to the original subgraph.

[0125] Optionally, the processing unit 603 is specifically configured to: determine the first feature matrix corresponding to the graph features of the original subgraph, and determine the second feature matrix corresponding to the graph features of the reconstructed subgraph; perform a matrix subtraction operation on the first feature matrix and the second feature matrix to generate the feature heat map corresponding to the original subgraph.

[0126] Optionally, the processing unit 603 is specifically configured to: for each of the K vertex features and F edge features, perform: determining M difference values corresponding to each feature from the feature heat maps respectively corresponding to the M original subgraphs; and determining H key features from the K vertex features and F edge features according to the M difference values corresponding to each feature.

[0127] Optionally, the processing unit 603 is further configured to: perform a preprocessing operation on the network data; wherein, the preprocessing operation includes at least one of the following processing operations: graph feature encoding; missing feature value filling; regularizing or normalizing numerical type data.

[0128] Based on the same technical concept, an embodiment of the present invention provides a computing device, including:

[0129] a memory for storing program instructions;

[0130] a processor for calling the program instructions stored in the memory and executing the feature extraction method according to the obtained program.

[0131] Based on the same technical concept, an embodiment of the present invention provides a computer-readable storage medium storing computer-executable instructions for causing a computer to execute the feature extraction method.

[0132] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, a system, or a computer program product. Therefore, the present invention can take the form of an all-hardware embodiment, an all-software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0133] The present invention is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to the present invention. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and the combination of flows and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to the processors of general-purpose computers, special-purpose computers, embedded processors, or other programmable data processing devices to generate a machine, such that the instructions executed by the processors of the computer or other programmable data processing devices generate means for realizing the functions specified in Figure 1 one or more flows or multiple flows and / or blocks Figure 1 one or more blocks or multiple blocks.

[0134] These computer program instructions may also be stored in a computer-readable memory that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer-readable memory produce an article of manufacture including instruction means embodying the function specified in the flowchart Figure 1 a flowchart or multiple flowcharts and / or block Figure 1 a block or multiple blocks.

[0135] These computer program instructions may also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process, whereby the instructions executed on the computer or other programmable apparatus provide steps for implementing the function specified in the flowchart Figure 1 a flowchart or multiple flowcharts and / or block Figure 1 a block or multiple blocks.

[0136] Although the preferred embodiments of the present invention have been described, additional changes and modifications can be made by those skilled in the art once they learn of the basic inventive concept. Therefore, the appended claims are intended to be construed to include the preferred embodiments as well as all changes and modifications falling within the scope of the present invention.

[0137] Obviously, those skilled in the art can make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations of the present invention fall within the scope of the claims of this application and their equivalent technologies, the present invention is also intended to include these modifications and variations.

Claims

1. A method for predicting abnormal account behaviors, characterized in that, Including: Based on network data, generate M original subgraphs with M target accounts as central vertices. The network data includes transaction information of multiple accounts and transaction information between accounts. The accounts are accounts registered in the bank. The transaction information of the accounts includes at least one of the following: account type, place of account opening, account opening time. The transaction information between accounts includes at least one of the following: number of transactions between accounts, transaction amount. The subgraph information of each original subgraph includes vertices, edges, and graph features. The graph features include K vertex features of each vertex and F edge features of each edge. The vertex features include at least one of the following: account type, place of account opening, account opening time. The edge features include at least one of the following: number of transactions between accounts, transaction amount. Both K and F are positive integers. For each of the M original subgraphs among the M original subgraphs, execute: Insert first noise into the graph features of the original subgraph to generate a noisy subgraph. The first noise is obtained by superimposing noise values on at least one of the K vertex features and / or F edges. Restore the graph features of the noisy subgraph to generate a reconstructed subgraph corresponding to the original subgraph. The graph features of the reconstructed subgraph include K vertex features of each vertex and F edge features corresponding to each edge. Among them, graph feature restoration is to use a graph neural network to predict the inserted first noise and then restore it to a reconstructed subgraph with no abnormal features. Generate a feature heatmap corresponding to the original subgraph according to the feature difference between the graph features of the original subgraph and the graph features of the reconstructed subgraph. Among them, the greater the feature difference, the higher the heat value. Extract H key features from the K vertex features and F edge features according to the feature heatmaps corresponding to the M original subgraphs respectively. H is a positive integer and H is less than the sum of K and F. The H key features are the H features with the largest heat values among the K vertex features and the F edge features. The H key features corresponding to each original subgraph are used to be input into an abnormal behavior recognition model to predict the risk index of account abnormal behavior in the original subgraph.

2. The method according to claim 1, wherein The original subgraph is an N-order subgraph. Generating M original subgraphs based on the network data includes: For each of the M target accounts included in the network data, execute: Based on the network data, with the target account as the central vertex, through N diffusion iterations, determine the account information associated with the target account as the neighbor vertices of the N-order subgraph corresponding to the target account, and use the transaction information between the vertices in the N-order subgraph as the edges of the N-order subgraph corresponding to the target account. Among them, the nth diffusion iteration is used to determine the nth-order vertices of the original subgraph.

3. The method according to claim 1 or 2, characterized in that, Restoring the graph features of the noisy subgraph to generate a reconstructed subgraph corresponding to the original subgraph includes: Input the noise sub - graph into the first graph neural network model to output the first prediction value corresponding to the first noise inserted in the noise sub - graph; the first graph neural network model is trained according to at least one first preset sample, and the first preset sample is a preset noise sub - graph with a preset noise value label; Remove the first prediction value from the graph features of the noise sub - graph to obtain a reconstructed sub - graph corresponding to the original sub - graph.

4. The method according to claim 3, characterized in that, The step of removing the first prediction value from the graph features of the noise sub - graph to obtain a reconstructed sub - graph corresponding to the original sub - graph includes: Remove the first prediction value from the graph features of the noise sub - graph to obtain a first reconstructed sub - graph corresponding to the original sub - graph; Input the first reconstructed sub - graph into the second graph neural network model to predict the anomaly probability corresponding to the first reconstructed sub - graph; the second graph neural network model is trained according to at least one second preset sample, and the second preset sample is a reconstructed sub - graph corresponding to the first preset sample with a positive sample label or a negative sample label; Determine the reconstructed sub - graph corresponding to the original sub - graph according to the anomaly probability corresponding to the first reconstructed sub - graph.

5. The method according to claim 4, wherein The step of determining the reconstructed sub - graph corresponding to the original sub - graph according to the anomaly probability corresponding to the first reconstructed sub - graph includes: If the anomaly probability corresponding to the first reconstructed sub - graph is less than the probability threshold, then determine the first reconstructed sub - graph as the reconstructed sub - graph corresponding to the original sub - graph; or, If the anomaly probability corresponding to the first reconstructed sub - graph is greater than or equal to the probability threshold, then reverse - correct the first prediction value according to the anomaly probability corresponding to the first reconstructed sub - graph to obtain a second prediction value; remove the second prediction value from the graph features of the noise sub - graph to obtain a reconstructed sub - graph corresponding to the original sub - graph.

6. The method according to claim 1 or 2, characterized in that, The step of generating a feature heat - map corresponding to the original sub - graph according to the feature difference between the graph features of the original sub - graph and the graph features of the reconstructed sub - graph includes: Determine a first feature matrix corresponding to the graph features of the original sub - graph; Determine a second feature matrix corresponding to the graph features of the reconstructed sub - graph; Perform a matrix subtraction operation on the first feature matrix and the second feature matrix to generate a feature heat - map corresponding to the original sub - graph.

7. The method according to claim 1 or 2, characterized in that The step of extracting H key features from the K vertex features and F edge features according to the feature heat - maps respectively corresponding to the M original sub - graphs includes: For each feature among the K vertex features and the F edge features, perform: Determine M difference values corresponding to each feature from the feature heat - maps respectively corresponding to the M original sub - graphs; Determine the H key features from the K vertex features and the F edge features according to the M difference values corresponding to each feature.

8. The method according to claim 1 or 2, characterized in that, Before generating M original sub - graphs based on the network data, the method further includes: Perform a pre - processing operation on the network data; Wherein, the pre - processing operation includes at least one of the following processing operations: graph feature encoding; filling in missing feature values; regularizing or normalizing numerical - type data.

9. A computing device, characterized in that, Includes: A memory for storing program instructions; A processor, configured to call program instructions stored in the memory and execute the method according to any one of claims 1 to 8 based on the obtained program.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions for causing a computer to execute the method according to any one of claims 1 to 8.

Citation Information

Patent Citations

  • Network model generation method and device, terminal and storage medium

    CN113420801A

  • Heterogeneous graph data node embedded feature extraction model training method, embedded feature extraction method and node classification method and device

    CN117272017A