A method for detecting fraud in transaction flow data
By constructing transaction flow charts and using relevant Isin machines for community discovery, the shortcomings of traditional methods in identifying unknown fraud are solved, efficient and flexible fraud detection is achieved, and transaction security and response capabilities are improved.
Patent Information
- Application Number
- CN202410484456.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2024-04-12
- Filing Date
- 2024-04-22
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2044-04-22
AI Technical Summary
Existing fraud detection methods are difficult to identify new fraudulent behaviors with unknown patterns, and traditional community discovers that algorithms are insufficient in accuracy and practicality in large-scale transaction networks, and cannot effectively identify complex fraud patterns.
Quantum computing technology based on coherent Isin machine is adopted to construct transaction flow charts and optimize the module degree function, and to use coherent Isin machine or quantum annealer to perform community discovery, and to evaluate community risks in combination with the account's external fraud points and fraud labels to achieve fraud detection.
It can accurately identify high-risk communities in complex networks, support real-time processing, and has high flexibility and scalability, improves the accuracy and response speed of fraud detection, and ensures the security and reliability of the transaction environment.
Smart Images

Figure CN118365331B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of big data analysis, and relates to a fraud detection method, in particular to a fraud detection method for transaction flow data. Background Art
[0002] In transactions, identifying and preventing fraudulent activities is an important measure to ensure transaction security. With the development of technology and the explosion of electronic transaction volume, traditional fraud detection methods have become difficult to cope with increasingly complex fraud means, especially in real-time identification and prevention.
[0003] Although there are various fraud detection methods on the market, most fraud detection methods rely on the analysis of known fraud cases and pattern recognition, and it is difficult to identify newly emerging fraud behaviors with unknown patterns. Moreover, they all rely on static, rule-based analysis methods, lacking flexibility and scalability, and it is difficult to adapt to the rapid changes in transaction behaviors and fraud means.
[0004] In addition, classical community detection algorithms, such as the Louvain algorithm, may find communities with poor connection quality or generate a large number of small communities when dealing with large-scale transaction networks, which reduces the accuracy and practicality of fraud warnings. Moreover, classical community detection algorithms are heuristic search algorithms, and the performance of their solutions is poor, which leads to poor performance when dealing with data related to unknown patterns, and thus unable to identify fraud behavior patterns that have not been defined.
[0005] Therefore, in view of the above-mentioned defects existing in the prior art, it is necessary to develop a new fraud detection method for transaction flow data. Summary of the Invention
[0006] In order to overcome the defects of the prior art, the present invention proposes a fraud detection method for transaction flow data, which can identify potential high-risk accounts or high-risk transactions, thereby effectively warning against fraud and money laundering behaviors.
[0007] In order to achieve the above object, the present invention provides the following technical solutions:
[0008] A fraud detection method for transaction flow data, characterized by comprising the following steps:
[0009] Extract corresponding transaction flow data according to the transaction behavior of the user, and the transaction flow data includes the account and each transaction generated by the account;
[0010] Convert the transaction flow data into a transaction flow graph, wherein each account is regarded as a node in the transaction flow graph, and each transaction between two accounts is regarded as an edge between two nodes in the transaction flow graph;
[0011] Construct a modularity function for measuring community discovery based on the transaction flow graph;
[0012] Optimize with the goal of maximizing the modularity function, and find the optimal solution through an iterative method to obtain the community discovery result;
[0013] Evaluate the fraud risk of each community according to the community discovery result to achieve fraud detection.
[0014] Preferably, when optimizing with the goal of maximizing the modularity function and finding the optimal solution through an iterative method to obtain the community discovery result, first transform the modularity function into a QUBO model, and then solve the QUBO model through a coherent Ising machine or a quantum annealing machine to obtain the community discovery result.
[0015] Preferably, the constructed modularity function for measuring community discovery is:
[0016]
[0017] In the formula, Q is the modularity, which is the total number of edges in the community minus the expected number of edges generated by the nodes within the community; A vw represents the connection between node v and node w in the transaction flow graph, A vw =1 indicates that node v and node w are connected, A vw =0 indicates that node v and node w are not connected; m is the total number of edges in the transaction flow graph, c v represents the community to which node v is assigned, c w represents the community to which node w is assigned, and use δ(c v , c w ) = 1 to indicate that c v = c w , that is, it indicates that node v and node w are divided into the same community c, and δ(c v , c w ) = 0 indicates that node v and node w are not divided into the same community c; k v represents the degree of node v, which is the number of edges connected to node v, where, k w represents the degree of node w, which is the number of edges connected to node w, where,
[0018] Preferably, the QUBO model is:
[0019]
[0020] In the formula, x vc and x wc are binary decision variables, x vc= 1 indicates that node v is assigned to community c, x vc = 0 indicates that node v is not assigned to community c, x wc = 1 indicates that node w is assigned to community c, x wc = 0 indicates that node w is not assigned to community c; M is the penalty coefficient.
[0021] Preferably, M is determined empirically such that M is at least one order of magnitude larger than the magnitude.
[0022] Preferably, when evaluating the fraud risk of each community according to the community discovery result, the fraud scores of all accounts in each community are calculated by combining the external fraud scores of each account in each community, so as to evaluate the fraud risk of each community.
[0023] Preferably, when evaluating the fraud risk of each community according to the community discovery result, the proportion of fraud accounts in each community is calculated by combining the fraud labels of each account in each community, so as to evaluate the fraud risk of each community.
[0024] In addition, the present invention also provides a fraud detection device for transaction flow data, which is characterized by including:
[0025] at least one processor; and
[0026] at least one memory storing a computer program;
[0027] wherein, when the computer program is executed by the at least one processor, the fraud detection device for transaction flow data executes the steps of the fraud detection method for transaction flow data as described above.
[0028] Finally, the present invention also provides a computer-readable storage medium storing a computer program, wherein the computer program realizes the steps of the fraud detection method for transaction flow data as described above when executed by a processor.
[0029] Compared with the prior art, the fraud detection method for transaction flow data of the present invention has one or more of the following beneficial technical effects:
[0030] 1. The present invention applies the quantum computing technology based on the coherent Ising machine to the community discovery of transaction flow data for fraud detection, which not only opens up a new application path of quantum computing in the transaction field, but also provides a brand-new and efficient solution for fraud detection in transaction flow data.
[0031] 2. By leveraging the powerful computing capabilities of the coherent Ising machine, the present invention can deeply analyze the complex network structure formed by transaction flow data, effectively identify and partition the community structure hidden in the huge data, and accurately identify high-risk communities even in networks with complex or sparse connections. This complex network analysis ability is unmatched by traditional community discovery methods, providing institutions with a more powerful tool to identify and prevent potential fraud risks.
[0032] 3. The present invention supports real-time processing of transaction flow data, allowing institutions to promptly identify and respond to potential fraud behaviors. In addition, it has the ability to find high-risk transactions closely related to fraudulent transactions, enabling more accurate positioning of the occurrence points of fraud behaviors, thereby taking effective measures to prevent the expansion of losses, significantly enhancing the initiative and effectiveness of the institution's anti-fraud strategy, and ensuring the security and reliability of the transaction environment.
[0033] 4. The design of the present invention takes into account the rapid changes in transaction behaviors and fraud means, so it has extremely high flexibility and scalability. This means that as the market develops and new fraud means emerge, the present invention can easily adapt and upgrade to maintain its long-term effectiveness in the anti-fraud strategy. BRIEF DESCRIPTION OF THE DRAWINGS
[0034] Figure 1 is a flowchart of the fraud detection method for transaction flow data of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0035] Before detailing any embodiment of the present invention, it should be understood that in its application, the present invention is not limited to the construction and arrangement details of the components described in the following description or illustrated in the following drawings. The present invention is capable of having other embodiments and can be practiced or carried out in various ways. Additionally, it should be understood that the wording and terms used herein are for the purpose of description and should not be considered restrictive. As used herein, "including" or "having" and their variants are intended to cover the items listed hereinafter and their equivalents as well as additional items. Unless otherwise specified or limited, the terms "mounted", "connected", "supported", and "coupled" and their variants are used widely and cover direct mounting and indirect mounting, connection, support, and coupling. In addition, "connected" and "coupled" are not limited to physical or mechanical connection or coupling.
[0036] Also, in the disclosure of the present invention, the term "a" should be understood as "at least one" or "one or more". That is, in one embodiment, the number of an element can be one, while in other embodiments, the number of the element can be multiple. The term "a" should not be construed as a limitation on the number.
[0037] With the development of technology and the explosion of electronic transaction volumes, traditional fraud detection methods have become difficult to cope with increasingly sophisticated fraud means, especially in real-time identification and prevention. Therefore, in order to meet the requirements of quickly and accurately identifying and predicting potential fraud risks in transaction flows, the present invention adopts quantum computing technology based on a Coherent Ising Machine (CIM) to develop a community discovery algorithm. This algorithm utilizes the efficient parallel processing ability of quantum computing and the special quantum hardware attributes of the Coherent Ising Machine, and can quickly partition a network composed of a certain scale of transaction flows. Based on fraud transactions or fraud accounts in the community, potential high-risk accounts or high-risk transactions can be identified, thereby effectively warning against fraud and money laundering behaviors.
[0038] Figure 1 The flowchart of the fraud detection method for transaction flow data of the present invention is shown. As Figure 1 shown, the fraud detection method for transaction flow data of the present invention includes the following steps:
[0039] 1. Extract corresponding transaction flow data according to the user's transaction behavior.
[0040] Since fraud behaviors are ultimately related to economic interests, the community discovery method based on transaction flow data is particularly important in anti-fraud algorithms. The present invention first extracts corresponding transaction flow data according to the user's transaction behavior, and the transaction flow data includes accounts and each transaction generated by the accounts.
[0041] 2. Convert the transaction flow data into a transaction flow graph.
[0042] In the transaction flow graph, each account is regarded as a node in the transaction flow graph, and each transaction between two accounts is regarded as an edge between two nodes in the transaction flow graph. By analyzing the entire transaction flow data, with all accounts as nodes and all transactions as edges, a complete transaction network graph can be constructed.
[0043] Preferably, the edge has a weight. The weight can be determined based on the amount of the transaction or other attributes of the transaction.
[0044] For example, there are two accounts, namely account A and account B. Then account A and account B are the nodes of the transaction flow graph. If account A transfers money to account B once, a directed edge is established between account A and account B. The direction of this edge is from account A to account B, and its weight can be determined based on the transfer amount. The larger the transfer amount, the greater the weight.
[0045] 3. Construct a modularity function for measuring community discovery based on the transaction flow graph.
[0046] Community discovery, also known as community detection, aims to discover groups of nodes with close connections in a complex network structure. These nodes are tightly interconnected structurally, while having weaker connections with other nodes. Through community discovery, functional modules, social circles, information dissemination groups, etc. in the complex network structure can be identified, thus helping to understand the organizational structure of the complex network, revealing the relationships between nodes, and gaining insights and applications from them.
[0047] Fraud detection in the trading field also efficiently extracts hidden information from a complex network structure (i.e., the transaction flow graph), that is, detects abnormal transactions between different accounts from a large amount of transaction data. This problem also involves extracting network entity relationships and belongs to a type of community discovery problem.
[0048] Therefore, by performing community discovery based on the transaction flow graph, groups of closely connected accounts can be found, that is, groups of accounts that often conduct transactions, thus facilitating subsequent detection of abnormal transactions between different accounts.
[0049] Modularity can be used to measure the quality of community partitioning. If there are more edges within the partitioned communities and fewer edges between communities, the value of modularity is higher, indicating a better community partition. Therefore, the community discovery problem can be transformed into the problem of maximizing the modularity of the transaction flow graph.
[0050] In the present invention, an adjacency matrix A is first defined, which is used to represent the connections between nodes (i.e., accounts) in the transaction flow graph. Among them, A vw represents the connection between node v and node w in the transaction flow graph. A vw = 1 indicates that node v and node w are connected, and A vw = 0 indicates that node v and node w are not connected; m is defined as the total number of edges in the transaction flow graph (the total number of edges after removing duplicate edges).
[0051] The basic idea of community discovery based on modularity is to utilize the property that there are relatively more edges within a community. Assume that the transaction flow graph is partitioned into different communities, and c v represents the community c to which node v is assigned, c w represents the community c to which node w is assigned. Using δ(c v , c w ) = 1 to indicate c v = c w , that is, it indicates that node v and node w are partitioned into the same community c. Using δ(c v , c w ) = 0 to indicate that node v and node w are not partitioned into the same community c, then the probability that an edge falls within a community c (i.e., the two connected nodes are in the same community) can be expressed as:
[0052]
[0053] For this probability, the value is maximized if all nodes in the transaction flow graph are assigned to a community. Therefore, using this metric alone cannot measure the effect of community partitioning. Other metrics need to be combined. This other metric should be able to reflect the expected number of connections in a random community partitioning. To this end, first define the degree \(k\) of node \(v\) v , which is the number of edges connected to node \(v\), and define the degree \(k\) of node \(w\) w , which is the number of edges connected to node \(w\). Among them,
[0054] It can be seen that the probability that node \(w\) is connected to any one node is Now node \(v\) has degree \(k\) v , so in the case of a random network, the expected number of edges between node \(v\) and node \(w\) is That is to say, within a community, the larger the better.
[0055] In summary, the modularity function for measuring community discovery can be defined as:
[0056]
[0057] That is, \(Q\) is the modularity, which is the total number of edges in the community minus the expected number of edges generated by the nodes in the community. The total number of edges in the community is the sum of the edges of all nodes in the community. And, in the present invention, dividing by the total number of edges \(2m\) can be understood as the proportion of the number of edges.
[0058] Fourth, optimize with the goal of maximizing the modularity function, and find the optimal solution through an iterative method to obtain the community discovery result.
[0059] The CIM simulator and real machine can be used to find the optimal solution to obtain the community discovery result.
[0060] However, considering that the number of accounts and communities in the transaction flow data is relatively large, it is difficult to solve using conventional solution methods. Therefore, in the present invention, the classical community discovery algorithm Louvain can be used to obtain the community discovery result, or the modularity function can be transformed into a QUBO model and a coherent Ising machine or a quantum annealing machine can be used to find the optimal solution to obtain the community discovery result.
[0061] Among them, transforming the modularity function into a QUBO model and using a coherent Ising machine or a quantum annealing machine to find the optimal solution to obtain the community discovery result specifically includes:
[0062] First, convert the modularity function into a QUBO model and define binary decision variables x vc and x wc such that x vc = 1 means that node v is assigned to community c, and x vc = 0 means that node v is not assigned to community c. Also, x wc = 1 means that node w is assigned to community c, and x wc = 0 means that node w is not assigned to community c. The modularity of community c can be expressed as:
[0063]
[0064] Since a node can only be assigned to one community, for any node v, the constraint is:
[0065]
[0066] Written as a QUBO model:
[0067]
[0068] where M is a penalty coefficient. Here, M is determined empirically. If it is too small, it has no penalty effect, and if it is too large, it violates the norm. In the present invention, M is set such that M is at least one order of magnitude larger than the magnitude of .
[0069] Specifically, when all nodes are only divided into two communities, no additional constraints are required, and the above QUBO model can be further simplified to the following form:
[0070]
[0071] Second, solve the QUBO model using a coherent Ising machine or a quantum annealing machine to obtain the community discovery result.
[0072] The described QUBO model is applicable to be solved by a Coherent Ising Machine (CIM) or a quantum annealer. Taking the CIM based on a Degenerate Optical Parametric Oscillator (DOPO) as an example for the implementation and solution of the physical machine, this is a hybrid quantum computing system composed of an optical part and an electrical part. The optical part includes a laser, an amplifier, a Periodically Poled Lithium Niobate (PPLN) crystal, and an optical fiber loop. The laser is a femtosecond pulsed fiber laser, equipped with an amplifier system. The amplified laser first undergoes a frequency doubling process using the PPLN crystal. The frequency-doubled laser is used as a pump source to synchronously pump the PPLN crystal in an optical fiber loop to form a degenerate optical parametric oscillation, and there can be hundreds of oscillation pulses existing simultaneously in the optical fiber loop. The electrical part includes a Field Programmable Gate Array (FPGA), AD / DA (digital-to-analog / analog-to-digital conversion), and a phase detection part. The laser output from the optical fiber loop and the fundamental frequency laser are measured by a phase detector, and the phase of the output light can be tested. The FPGA is used in combination with high-speed AD / DA for the measurement and feedback control of optical pulses.
[0073] Different from classical computers running on semiconductor integrated circuits, CIM uses laser pulses in optical fibers as qubits for computing. In DOPO, the pump light incident on the nonlinear optical crystal splits into two beams of light. The polarization directions of the two beams of light are the same, the frequency is half of the pump light, and they are in a squeezed state, which can be used as a qubit. Gradually increasing the power of the pump light, when it exceeds the oscillation threshold, the generated light becomes a coherent state, and the phase of the light is divided into two states (phase 0 state and π state). At this time, the phase can be correspondingly set to ±1 of the spin to solve the optimization problem.
[0074] By solving through a coherent Ising machine or a quantum annealer, a set of solutions is obtained to minimize the objective value H. This set of solutions is a set of 0, 1 variables, in the form of [0, 0, 1, 1, 0, 0, 0, 1, 0,...]. The number of elements in this list is the product of the number of accounts in the transaction flow diagram and the number of divided communities. The 1 in the solution indicates that the account is divided into the corresponding community, and 0 indicates that the account is not divided into the corresponding community.
[0075] For example, if a transaction flow graph consisting of 10 nodes (i.e., accounts) is divided into 3 communities, then the 1st to 3rd bits in the variable combination represent the community belonging of node 1, the 4th to 6th bits represent the community belonging of node 2, and so on. In the returned result, such as [0, 0, 1, 1, 0, 0, ……], since the 1st to 3rd bits are 0, 0, 1, it means that node 1 belongs to the 3rd community; the 4th to 6th bits are 1, 0, 0, which means that node 2 belongs to the 1st community (1 represents belonging to the community, 0 represents not belonging to the community). Thus, by using a coherent Ising machine or a quantum annealing machine, the rapid division of the communities to which the nodes belong can be achieved.
[0076] 5. Evaluate the fraud risk of each community according to the community discovery result to achieve fraud detection.
[0077] With the community discovery result, existing evaluation methods can be used to evaluate the fraud risk of each community to achieve fraud detection.
[0078] In the present invention, when evaluating the fraud risk of each community according to the community discovery result, the external fraud scores of each account in each community (wherein the external fraud scores of each account are quantitatively marked for each account by a bank system, etc. and are known) can be combined to calculate the fraud score of all accounts within each community (that is, adding up the external fraud scores of all accounts within each community to obtain the fraud score of the community), and the fraud risk of each community is evaluated based on the community fraud score. For example, a community with a fraud score greater than 70 is regarded as a high-risk fraud community, a community with a fraud score less than 10 is regarded as a low-risk fraud community, and a community with a fraud score between 70 and 10 is regarded as a medium-risk fraud community. It should be noted that the magnitude of the community fraud score used to evaluate the fraud risk of each community depends on the accuracy of community discovery and can be adjusted as needed.
[0079] Of course, when evaluating the fraud risk of each community according to the community discovery result, the fraud labels of each account in each community (wherein the fraud labels of each account are marked for each account by a bank system, etc. and are known) can also be combined to calculate the proportion of fraud-related accounts within each community (for example, there are 10 accounts in a community, among which 4 accounts are marked with fraud labels, then the proportion of fraud-related accounts is 40%). The fraud risk of each community is evaluated based on the proportion of fraud-related accounts. For example, a community with a proportion of fraud-related accounts greater than 50% is regarded as a high-risk fraud community, a community with a proportion of fraud-related accounts less than 10% is regarded as a low-risk fraud community, and a community with a proportion of fraud-related accounts between 50% and 10% is regarded as a medium-risk fraud community. Similarly, it should be noted that the magnitude of the proportion of fraud-related accounts used to evaluate the fraud risk of each community depends on the accuracy of community discovery and can be adjusted as needed.
[0080] In addition, the present invention also provides a fraud detection device for transaction flow data, which includes:
[0081] at least one processor; and
[0082] at least one memory storing a computer program;
[0083] wherein, when the computer program is executed by the at least one processor, the fraud detection device for transaction flow data executes the steps of the fraud detection method for transaction flow data as described above.
[0084] Finally, the present invention also provides a computer-readable storage medium storing a computer program, wherein the computer program, when executed by a processor, implements the steps of the fraud detection method for transaction flow data as described above.
[0085] For the first time, the present invention applies the quantum computing technology based on the coherent Ising machine to the community discovery of transaction flow data for anti-fraud analysis. This innovation not only opens up a new application path for quantum computing in the transaction field, but also provides a brand-new and efficient solution for anti-fraud in transaction flow data. At the same time, by utilizing the powerful computing ability of the coherent Ising machine, the present invention can deeply analyze the complex network structure formed by transaction flows, effectively identify and partition the community structure hidden in the huge data, and accurately identify high-risk communities even in networks with complex or sparse connections. This complex network analysis ability is difficult to match by traditional community discovery methods, providing a more powerful tool for institutions to identify and prevent potential fraud risks. Moreover, the present invention supports real-time processing of transaction flow data, which is crucial for institutions as it allows them to promptly identify and respond to potential fraud behaviors. In addition, the present invention has the ability to find high-risk transactions closely related to fraudulent transactions intensively, which means that the occurrence points of fraud behaviors can be more accurately located, so as to take effective measures to prevent the expansion of losses. This ability significantly enhances the initiative and effectiveness of the institution's anti-fraud strategy, ensuring the security and reliability of the transaction environment. Finally, the design of the present invention takes into account the rapid changes in transaction behaviors and fraud means, so it has extremely high flexibility and scalability, which means that with the development of the market and the emergence of new fraud means, the present invention can easily adapt and upgrade to maintain its long-term effectiveness in the anti-fraud strategy.
[0086] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit the protection scope of the present invention. Those skilled in the art can modify or equivalently replace the technical solutions of the present invention according to the idea of the present invention, without departing from the essence and scope of the technical solutions of the present invention.
Claims
1. A method for detecting fraud in transaction flow data, characterized in that, Including the following steps: Extracting corresponding transaction flow data according to the user's transaction behavior, where the transaction flow data includes accounts and each transaction generated by the accounts; Converting the transaction flow data into a transaction flow graph, where each account is regarded as a node in the transaction flow graph, and each transaction between two accounts is regarded as an edge between two nodes in the transaction flow graph; Constructing a modularity function for measuring community discovery based on the transaction flow graph; Optimizing with the goal of maximizing the modularity function, and finding the optimal solution through an iterative method to obtain the community discovery result; Evaluating the fraud risk of each community according to the community discovery result to achieve fraud detection; When optimizing with the goal of maximizing the modularity function and finding the optimal solution through an iterative method to obtain the community discovery result, first convert the modularity function into a QUBO model, and then solve the QUBO model through a coherent Ising machine or a quantum annealing machine to obtain the community discovery result; The constructed modularity function for measuring community discovery is: Where Q is the modularity, which is the total number of edges in the community minus the expected number of edges generated by the nodes within the community; A vw represents the connection between node v and node w in the transaction flow graph, A vw = 1 indicates that node v and node w are connected, A vw = 0 indicates that node v and node w are not connected; m is the total number of edges in the transaction flow graph, c v represents the community to which node v is assigned, c w represents the community to which node w is assigned. Use δ(c v , c w ) = 1 to indicate that c v = c w , that is, it indicates that node v and node w are partitioned into the same community c. δ(c v , c w ) = 0 indicates that node v and node w are not partitioned into the same community c; k v represents the degree of node v, which is the number of edges connected to node v. Among them, k w represents the degree of node w, which is the number of edges connected to node w. Among them, The QUBO model is: where x vc and x wc are binary decision variables, x vc = 1 indicates that node v is assigned to community c, x vc = 0 indicates that node v is not assigned to community c, x wc = 1 indicates that node w is assigned to community c, x wc = 0 indicates that node w is not assigned to community c; M is the penalty coefficient; M is determined empirically such that M is at least an order of magnitude larger than in size; Among them, a node can only be assigned to one community, and the following constraints apply to any node v:
2. The fraud detection method for transaction flow data according to claim 1, wherein When evaluating the fraud risk of each community according to the community discovery result, calculate the fraud scores of all accounts in each community by combining the external fraud scores of each account in the community, so as to evaluate the fraud risk of each community.
3. The transaction flow data fraud detection method according to claim 1, characterized in that When evaluating the fraud risk of each community according to the community discovery result, calculate the proportion of fraud accounts in each community by combining the fraud labels of each account in the community, so as to evaluate the fraud risk of each community.
4. A transaction flow data fraud detection device, characterized in that, Including: At least one processor; And At least one memory storing a computer program; Wherein, when the computer program is executed by the at least one processor, the transaction flow data fraud detection device is enabled to execute the steps of the transaction flow data fraud detection method according to any one of claims 1-3.
5. A computer-readable storage medium storing a computer program, wherein, The computer program, when executed by a processor, implements the steps of the transaction flow data fraud detection method according to any one of claims 1-3.
Citation Information
Patent Citations
Logistic regression model establishing method and device
CN116522126A
Construction method of user group prediction model and user group prediction method
CN117668375A