Anti-run-score real-time monitoring and control method and system

By building a global account transaction graph network and applying an enhanced graph attention network, the problem of difficulty in real-time monitoring and early warning of running score fraud in the existing technology is solved, and efficient identification and early warning of running score behavior is achieved.

CN118657600BActive Publication Date: 2025-07-01BEIJING MODEL ONLINE TECH CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202410561077.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-05-08
Publication Date
2025-07-01
Estimated Expiration
2044-05-08

AI Technical Summary

Technical Problem

It is difficult for existing technology to effectively monitor and early warning of scoring fraud in financial violations in real time, especially when faced with changing money laundering methods and complex financial products.

Method used

By obtaining real-time payment data from multiple payment platforms, data preprocessing and fusion are carried out, a global account transaction graph network is built, and a enhanced graph attention network is used to identify risk nodes.

Benefits of technology

It realizes efficient identification and early warning of running points, improves the dynamic adaptability and efficiency of the monitoring system, and can detect potential abnormal or risky behaviors earlier.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118657600B_ABST
    Figure CN118657600B_ABST
Patent Text Reader

Abstract

An embodiment of the present invention provides an anti-money laundering real-time monitoring and control method and system, which relates to the field of intelligent early warning technology. The method includes: for each payment platform interface, obtaining the platform real-time payment data corresponding to the payment platform interface; performing data preprocessing on the real-time payment data of each platform, and fusing the preprocessed platform payment data of each platform according to account information to determine the corresponding cross-platform real-time payment data of the account; determining the corresponding account payment time series data; updating the global account transaction graph network based on the account payment time series data of each account; inputting the global account transaction graph network into a preset money laundering behavior recognition model to identify risk nodes, and the money laundering behavior recognition model uses an enhanced graph attention network. Thus, a cross-platform real-time payment data view is constructed, realizing cross-platform data fusion and dynamic monitoring, which helps to discover potential money laundering risk behaviors earlier.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of intelligent early warning, and in particular, to an anti-money laundering real-time monitoring and control method and system. Background Art

[0002] With the rapid development of the digital economy, while financial technology brings convenience, it also gives rise to illegal activities such as money laundering through money laundering. At present, although a variety of regulatory technologies are applied to prevent money laundering, there are still loopholes and it is difficult to achieve real-time and effective monitoring and early warning.

[0003] "Money laundering" is a common financial illegal activity, which refers to using credit cards or other payment tools to conduct false transactions to transfer and launder illegal funds. Although regulatory agencies and financial institutions in various countries have deployed a variety of monitoring and prevention systems, the current monitoring systems mostly rely on traditional rule matching technologies, lack dynamic adaptability, and are difficult to cope with changing money laundering methods. Specifically, most systems rely on preset rules to detect abnormal transactions, which are not only inefficient in dealing with new money laundering methods, but also difficult to quickly adapt to complex financial products and services. In particular, money launderers constantly change their methods or use multiple payment platforms for money laundering, making it difficult for existing rule engines to update in time to capture rapidly evolving money laundering fraud patterns.

[0004] In response to the above problems, the industry has not yet proposed a better technical solution. Summary of the Invention

[0005] The present invention provides an anti-money laundering real-time monitoring and control method and system, which is used to at least solve the problem that in the current related technologies, it is difficult for the system to effectively capture rapidly evolving money laundering fraud behaviors relying on preset rules.

[0006] In a first aspect, an embodiment of the present invention provides an anti-run-score real-time monitoring and control method, including: for each payment platform interface, obtaining the platform real-time payment data corresponding to the payment platform interface; the platform real-time payment data all includes account information, transaction amount, transaction time, and transaction counterparty account information; preprocessing the platform real-time payment data for each, and fusing the preprocessed platform payment data for each according to the account information to determine the corresponding cross-platform real-time payment data for the account; for each of the cross-platform real-time payment data for the account, combining the cross-platform real-time payment data for the account with the cross-platform historical payment data set of the corresponding account information in a historical preset time period to determine the corresponding account payment time series data; based on each of the account payment time series data, updating the global account transaction graph network; each node in the global account graph network is respectively used to represent the corresponding account information, and each edge connection is a directed edge, pointing from the payer account information to the payee account information; the edge connection attributes include: transaction amount, transaction time, and the average transaction cycle between both parties; the node attributes include: account type, account registration time, account location, and account transaction frequency; inputting the global account transaction graph network into a preset run-score behavior recognition model to identify at least one risk node to be subject to account control in the global account transaction graph network; the run-score behavior recognition model adopts an enhanced graph attention network, and the enhanced graph attention network includes a cascaded time encoding layer, a deep graph attention layer, and an anomaly detection layer; the time encoding layer is used to encode the associated time encodings corresponding to the time information in each edge connection in the global account transaction graph network; the deep graph attention layer is used to calculate the attention coefficients between each node and its adjacent nodes in the global account transaction graph network according to the initial node features of each node and the associated time encoding, and update the corresponding first node features weighted according to the attention coefficients to obtain the corresponding attention node features; the anomaly detection layer is used to respectively identify the risk behavior patterns of each attention node feature, so as to screen risk nodes from each node accordingly.

[0007] Second aspect, an embodiment of the present invention provides an anti-money laundering real-time monitoring and control system, including: a data acquisition unit configured to acquire, for each payment platform interface, the platform real-time payment data corresponding to the payment platform interface; the platform real-time payment data all includes account information, transaction amount, transaction time, and transaction counterparty account information; a data fusion unit configured to perform data preprocessing on each of the platform real-time payment data and fuse each preprocessed platform payment data according to the account information to determine the corresponding cross-platform real-time payment data of the account; a time series data determination unit configured to, for each of the cross-platform real-time payment data of the account, combine the cross-platform real-time payment data of the account with the cross-platform historical payment data set of the corresponding account information in a historical preset time period to determine the corresponding account payment time series data; a graph network update unit configured to update the global account transaction graph network based on each of the account payment time series data; each node in the global account graph network is respectively used to represent the corresponding account information, and each edge connection is a directed edge, pointing from the payer account information to the payee account information; the edge connection attributes include: transaction amount, transaction time, and the average transaction cycle between both parties; the node attributes include: account type, account registration time, account belonging location, and account transaction frequency; a money laundering behavior recognition unit configured to input the global account transaction graph network into a preset money laundering behavior recognition model to identify at least one risk node to be subject to account control in the global account transaction graph network; the money laundering behavior recognition model uses an enhanced graph attention network, and the enhanced graph attention network includes a cascaded time encoding layer, a deep graph attention layer, and an anomaly detection layer; the time encoding layer is used to encode the associated time encodings corresponding to the time information in each edge connection in the global account transaction graph network; the deep graph attention layer is used to calculate the attention coefficients between each node and its adjacent nodes in the global account transaction graph network according to the initial node features of each node and the associated time encoding, and weight-update the corresponding first node features according to the attention coefficients to obtain the corresponding attention node features; the anomaly detection layer is used to respectively identify the risk behavior patterns of each attention node feature to correspondingly screen risk nodes from each node.

[0008] Third aspect, an electronic device is provided, which includes: at least one processor, and a memory communicatively connected to the at least one processor, wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the steps of the anti-money laundering real-time monitoring and control method according to any embodiment of the present invention.

[0009] Fourthly, an embodiment of the present invention provides a storage medium, on which a computer program is stored, characterized in that when the program is executed by a processor, the steps of the anti-score-running real-time monitoring and control method according to any embodiment of the present invention are implemented.

[0010] Fifthly, an embodiment of the present invention provides a computer program product, including a computer program / instructions, and when the computer program / instructions are executed by a processor, the steps of the anti-score-running real-time monitoring and control method according to any embodiment of the present invention are implemented.

[0011] The beneficial effects of the embodiments of the present invention are as follows:

[0012] (1) By acquiring and preprocessing the real-time payment data of multiple payment platforms and fusing them according to account information, a cross-platform real-time payment data view can be constructed, which not only improves the overall view of score-running activities, can reflect the real-time transaction behavior patterns of accounts, realizes cross-platform data fusion and dynamic monitoring, helps to detect potential abnormal or risky behaviors earlier, and thus realizes more effective real-time monitoring and early warning.

[0013] (2) Through the system architecture design provided by this technical solution, it is allowed to easily integrate new payment platforms and account information, and supports the monitoring system to maintain high efficiency and effectiveness when expanding into new markets or new products.

[0014] (3) In the general architecture provided by this technical solution, by adopting an enhanced graph attention network, an integrated time encoding layer and a deep graph attention layer, the model can not only consider the static attributes of nodes, but also dynamically evaluate the abnormality degree of transaction behaviors according to factors such as transaction time and frequency. In particular, the time encoding layer encodes the time when the transaction occurs, enabling the model to have better recognition efficiency for time-sensitive score-running behaviors, thereby enhancing the recognition ability for abnormal behaviors.

[0015] (4) As new transaction data is continuously input, the global account transaction graph network will be continuously updated, enabling the monitoring system to dynamically adapt to new transaction patterns and potential score-running strategies, providing strong adaptability and being able to adaptively counter the changing techniques of score-runners.

[0016] (5) Through the anomaly detection layer, by analyzing the behavior patterns based on the attention node features corresponding to each account information, risk nodes with high-risk potential and corresponding risk account information can be screened out, providing a basis for further targeted risk control management and evaluation of risk accounts.

[0017] Through the comprehensive anti-money laundering real-time monitoring and control system provided by this technical solution, the monitoring ability of money laundering behavior in complex financial products and services can be significantly improved. Especially when dealing with new money laundering means and changing money laundering methods, this solution demonstrates higher efficiency and adaptability, not only meeting regulatory requirements but also enhancing the overall security and trust of the financial system. Brief Description of the Drawings

[0018] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0019] Figure 1 Shows a flowchart of an example of the anti-money laundering real-time monitoring and control method according to an embodiment of the present invention;

[0020] Figure 2 Shows a structural block diagram of an example of the money laundering behavior recognition model according to an embodiment of the present invention;

[0021] Figure 3 Shows a structural block diagram of an example of the anti-money laundering real-time monitoring and control system according to an embodiment of the present invention;

[0022] Figure 4 Is a schematic structural diagram of an embodiment of the electronic device of the present invention. Detailed Embodiments

[0023] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.

[0024] In the technical solution of the present invention, for the processing of the collection, storage, use, processing, transmission, provision, and disclosure of user personal information, etc., it all complies with the provisions of relevant laws and regulations and does not violate public order and good customs.

[0025] Figure 1 Shows a flowchart of an example of the anti-money laundering real-time monitoring and control method according to an embodiment of the present invention.

[0026] Regarding the execution entity of the method in the embodiments of the present invention, it can be any controller or processor with computing or processing capabilities. In order to address the problems existing in the current financial monitoring system, especially the lack of real-time and effective monitoring and early warning for money laundering through running points, an innovative real-time monitoring and control method for anti-money laundering through running points is proposed. More specifically, in the context of the business service scenario of real-time monitoring and control for anti-money laundering through running points, the execution entity can be a transaction risk control platform. By comprehensively utilizing the real-time payment data of multiple payment platforms, constructing a global account transaction graph network, and applying an enhanced graph attention network, efficient identification and early warning of money laundering through running points are achieved. In some examples, it can be integrated and configured in an electronic device or terminal in a software, hardware, or software-hardware combination manner, and the types of terminals or electronic devices can be diverse, such as mobile phones, tablets, or desktop computers, etc.

[0027] As Figure 1 shown, in step S110, for each payment platform interface, obtain the platform real-time payment data corresponding to the payment platform interface.

[0028] More specifically, first clarify the types of financial payment platforms for which data needs to be collected, such as bank systems, Alipay, WeChat Pay, etc., and then integrate the API interfaces of each financial payment platform to ensure that transaction data can be obtained in real time. In some embodiments, the system collects real-time payment data from each payment platform through API calls. The platform real-time payment data all includes account information, transaction amount, transaction time, and transaction counterparty account information. These data are protected by a secure transmission protocol (such as SSL / TLS) to ensure data security and integrity during the collection process.

[0029] Thus, by collecting the real-time payment data of each platform, it helps to capture timely money laundering through running points behavior, and can greatly improve the timeliness and accuracy of subsequent analysis.

[0030] In step S120, perform data preprocessing on the real-time payment data of each platform, and fuse the preprocessed platform payment data according to the account information to determine the corresponding cross-platform real-time payment data of the account.

[0031] More specifically, perform format standardization processing on the payment data collected from each platform to ensure that all data has the same data format and measurement standard before fusion. For example, the date and time format is unified to ISO 8601, and the currency unit is unified, etc. In addition, it is also necessary to perform cleaning operations on the collected platform real-time payment data to eliminate or correct incomplete, incorrect, or irrelevant records in each dataset, such as invalid transaction times, abnormal transaction amounts, etc.

[0032] Furthermore, the account information of the same user on different platforms is matched through text matching technology or clustering algorithms (which can handle possible spelling mistakes and aliases), and then the matched account data is fused to form a single cross-platform payment data, avoiding data duplication and information loss.

[0033] Thus, through data preprocessing and fusion, the availability and consistency of the data are improved, making subsequent analysis more accurate and effective. The fused data helps to reveal the transaction behaviors and patterns of a single account across different platforms, which is particularly important for identifying complex money laundering behavior patterns. In addition, through the system architecture design provided in this embodiment, it is allowed to easily integrate new payment platforms and account information, supporting the monitoring system to remain efficient and effective when expanding into new markets or new products.

[0034] It should be noted that the data formats or encryption types of different financial payment platforms are not interoperable. Therefore, during the data preprocessing of the real-time payment data of each platform, attention should also be paid to decrypting the data into a unified data type for subsequent data fusion.

[0035] In some examples of the embodiments of the present invention, for the real-time payment data of each platform, determine the target data encryption format corresponding to the platform payment data, query the payment format blockchain based on the target data encryption format to obtain the corresponding target data decryption format, and decrypt the real-time payment data of the platform based on the target data decryption format. Subsequently, fuse the decrypted real-time payment data of each platform according to the account information to obtain the corresponding cross-platform real-time payment data of the account.

[0036] In the embodiments of the present invention, the payment format blockchain uses the nodes in its network to jointly maintain and verify a distributed ledger containing data encryption formats and their corresponding data decryption formats. By storing the data encryption formats and their corresponding decryption formats on the payment format blockchain, the security and transparency of the decryption process are ensured. In this way, using the immutability of the blockchain, it can prevent the decryption key and process from being modified or accessed without authorization. In addition, using the consensus mechanism of the blockchain, it can ensure that all nodes reach an agreement on the stored encryption and decryption formats, thus guaranteeing the consistency of the data during the decryption process. Thereby, the security and efficiency of the payment system are enhanced, and a powerful data management and compliance tool is also provided for payment service providers, while improving the reliability of the service and the trust of users.

[0037] In step S130, for the cross-platform real-time payment data of each account, combine the cross-platform real-time payment data of the account with the cross-platform historical payment data set of the corresponding account information in a historical preset time period to determine the corresponding account payment time series data.

[0038] More specifically, the cross-platform real-time payment data of each account is combined with its historical payment data within a historical preset time period (for example, one week or 10 days, etc., and can be adjusted according to business needs) to construct account payment time-series data, so that it not only pays attention to the latest account transaction information but also attaches importance to the past transaction history of the account.

[0039] Thus, by constructing the payment time-series data, the model can use historical behavior patterns to analyze the abnormality of current behaviors. Based on time-series analysis, it can effectively identify periodic money laundering patterns and long-term abnormal behavior trends, enhancing the ability to predict potential risks.

[0040] In step S140, based on the payment time-series data of each account, the global account transaction graph network is updated.

[0041] Here, each node in the global account graph network is used to represent the corresponding account information respectively, and each edge connection is a directed edge, pointing from the payer account information to the payee account information; the edge connection attributes include: transaction amount, transaction time, and the average transaction cycle between the two parties, and the node attributes include: account type, account registration time, account location, and account transaction frequency.

[0042] It should be noted that the global account transaction graph network is continuously updated based on the input of platform real-time payment data to continuously and dynamically reflect the latest transaction status and account relationships under the global account system, ensuring the timeliness of information.

[0043] Thus, by constructing the global account transaction graph network, it provides a data basis for complex network analysis, making it possible to use graph theory methods to identify potential risk nodes and money laundering patterns.

[0044] In step S150, the global account transaction graph network is input into a preset money laundering behavior recognition model to identify at least one risk node in the global account transaction graph network that needs to be subject to account control.

[0045] In some embodiments, the money laundering behavior recognition model can adopt various non-restrictive deep learning models to automatically learn and identify complex money laundering patterns from a large amount of data. When processing the global account transaction graph network, it uses a graph attention network to analyze the transaction patterns of each account and identify risk account nodes. Thus, it can automatically and efficiently identify and mark the accounts that participate in or may participate in money laundering, improving the dynamic adaptability of the monitoring system, being able to cope with various money laundering means, and providing a powerful risk management tool for financial institutions.

[0046] Figure 2 Shows a structural block diagram of an example of the money laundering behavior recognition model according to an embodiment of the present invention.

[0047] AsFigure 2 As shown in Figure 2 , the running score behavior recognition model 200 adopts an enhanced graph attention network, which includes a cascaded time encoding layer 210, a deep graph attention layer 220, and an anomaly detection layer 230.

[0048] The time encoding layer 210 is used to encode the associated time encodings corresponding to the time information in each edge connection in the global account transaction graph network.

[0049] Since running score behaviors often occur more frequently or abnormally in specific time patterns (for example, a sudden increase in transaction frequency at night), by configuring the time encoding layer 210, the model can effectively capture and understand transaction time information, and can effectively identify running score behaviors. The time encoding can map this time dynamics into the features of nodes and edges, making it easier for the model to understand and analyze time series data, and helping to identify complex patterns that use time changes for fraud, such as periodic running scores.

[0050] The deep graph attention layer 220 is used to calculate the attention coefficients between each node and its adjacent nodes in the global account transaction graph network according to the initial node features and associated time encodings of each node, and weight-update the corresponding first node features according to the attention coefficients to obtain the corresponding attention node features.

[0051] Here, the deep graph attention layer 220 can adopt a multi-layer structure, that is, use multiple cascaded graph attention layers. Through the graph attention layer, the model not only learns the features of nodes, but also dynamically adjusts the influence of neighbor nodes according to the importance of transactions and time context. Thus, important node-to-node relationships can be accurately identified and emphasized, which is beneficial to revealing non-explicit associations hidden in large amounts of data.

[0052] The anomaly detection layer 230 is used to respectively identify the risk behavior patterns of each attention node feature, so as to screen out risk nodes from each node accordingly.

[0053] In some embodiments, the anomaly detection layer can adopt a fully connected layer with a non-linear activation function or other algorithms. By focusing on identifying and classifying node features that exhibit potential risk behavior patterns, the anomaly detection layer effectively screens out high-risk nodes from the global network. Thus, by real-time analyzing the behavior patterns of each node, a fast response mechanism is provided, which can timely discover and mark accounts that may be involved in running scores, providing support for subsequent risk control and prevention measures.

[0054] Through the innovative architecture design of the running score behavior recognition model provided by the embodiments of the present invention, not only can the accuracy and efficiency of recognition be improved, but also potential risks can be warned in advance through in-depth analysis of time and relationships, thereby protecting and enhancing the reputation and security of the entire payment platform, making it have extremely high application value in the current environment of frequent digital payments and high security requirements.

[0055] Furthermore, the embodiments of the present invention also provide a more specific and novel structural design of the model layer. The disclosure of its content is intended to enable readers to better understand the technical concept of the present invention, and should not be regarded as a limitation to the present invention.

[0056] In some examples of the embodiments of the present invention, the time encoding layer is used to encode the time information in each edge connection of the global account transaction graph network to determine the corresponding associated time encoding:

[0057] TE(t, 2p) = sin(t / 10000 2p / d )), Equation (1)

[0058] TE(t, 2p + 1) = cos(t / 10000 2p / d )), Equation (2)

[0059] In the formula, t represents the time information in the edge connection; d represents the total number of vector dimensions of the associated time encoding; m represents the vector dimension index, p ∈ [1, d / 2 - 1]; TE(t, 2p) and TE(t, 2p + 1) respectively represent the vector elements at the even and odd positions of the associated time encoding.

[0060] In the embodiments of the present invention, a series of sine and cosine functions are used to encode the time information, enabling it to relatively smoothly process the time information while maintaining the comparability between different timestamps. Each dimension of time is encoded by sine and cosine functions with different frequencies, thereby not only being able to capture the absolute position of time but also retaining the information of time intervals, enabling the model to capture the continuity and periodicity of time.

[0061] In some examples of the embodiments of the present invention, the deep graph attention layer includes multiple cascaded graph attention layers;

[0062] The graph attention layer is used to calculate the attention coefficient α between each pair of adjacent nodes i and j in the global account transaction graph network ij :

[0063]

[0064] In the formula, ‖ represents the concatenation of vectors; h i and h jrespectively represent the node features of nodes i and j; a represents a learnable weight vector; W represents a linear transformation weight matrix; TE(t ij ) represents the associated time encoding of edge (i,j); LeakyReLU represents a non-linear activation function; represents the set of neighbor nodes of node i.

[0065] According to the attention coefficient α ij weightedly update the node features of node i:

[0066]

[0067] where σ represents an activation function, and h′ i represents the attention-weighted node features output by the graph attention layer for node i.

[0068] It should be noted that the same W is used in the calculation of the attention coefficient and the node feature update formula, which ensures that all feature transformations are carried out in a unified feature space, helps the model learn how to effectively allocate attention weights according to the transformed features, and accordingly updates the features of each node. Thus, the consistency and simplicity of the model are maintained, while ensuring that all node features are processed in a unified manner, so that the learned model parameters can be universal throughout the network, and also helps to reduce the complexity of the model and improve the computational efficiency.

[0069] Furthermore, a deep attention mechanism network is formed by stacking multiple layers. In the multi-layer network, the output h′ of each layer i can be used as the input feature h of the next layer i , and through the hierarchical structure design, the model can learn more complex relationships between nodes, while maintaining sensitivity to important features and the ability to respond to different time points.

[0070] Compared with the basic GAT model, the TGAT (Temporal Graph Attention Network) provided by the embodiments of the present invention not only considers the static relationship between nodes in the attention mechanism, but also introduces dynamic factors such as transaction time, so that the attention allocation can be adjusted according to time changes.

[0071] It should be noted that as time goes by, the transaction patterns in the payment network may change, and TGAT can flexibly respond to these changes based on its dynamic attention mechanism, maintaining the efficiency and accuracy of the model in various situations. On the other hand, by observing how the model adjusts the attention weights according to time changes, researchers can better understand the decision-making process of the model and its recognition logic for risk behaviors, increasing the interpretability of the model.

[0072] In some examples of the embodiments of the present invention, the anomaly detection layer is used to calculate the running score anomaly scores respectively corresponding to each attention node feature by using the Isolation Forest algorithm, and the running score anomaly scores are used to screen risk nodes:

[0073] score(i) = path_length(i) / c(n), Equation (5)

[0074]

[0075]

[0076]

[0077] In the formula, score(i) represents the running score anomaly score corresponding to node i; path_length(i) represents the average path length at which node i is isolated; n represents the total number of all nodes in the global account transaction graph network, and c(n) represents the average path length of all nodes in the global account transaction graph network; represents the attention node feature output by the depth graph attention layer for node i; m q represents the number of data points in the child node after the qth split of H(m q ); c(m q ) represents the average path length corresponding to m q ; e represents the number of edges passed before reaching the leaf node for the split of node i; γ is the Euler-Mascheroni constant, which is approximately equal to 0.5772156649.

[0078] It should be noted that the Isolation Forest algorithm is a tree-based model, and its basic idea is to randomly select a feature, then randomly select a split value of this feature to split the data, and repeat until each data point is "isolated". Since abnormal data usually behaves differently from most data points in the feature space, it is easier to be isolated.

[0079] Through the above calculation method, the Isolation Forest algorithm can effectively estimate the anomaly degree of each node, where a shorter path length usually indicates a higher running score anomaly score or anomaly possibility.

[0080] More specifically, during the construction of each decision tree, features are randomly selected from the features of the data. For the selected feature, a value is randomly chosen between the maximum and minimum values as the splitting point. Then, the dataset is split using the splitting point, and this process is recursively repeated until the dataset can no longer be split. Subsequently, the anomaly score is obtained based on the depth at which the data points are isolated. Generally, normal data points require more splits to be isolated, while anomaly points are quickly isolated. Therefore, the Isolation Forest outputs the anomaly scores for each account node in the global account transaction graph network respectively, and these scores can be further used to label potential high-risk accounts.

[0081] Furthermore, when an abnormal account transaction behavior is identified, the system can quickly respond to potential money laundering behaviors, such as suspending account operations, requiring additional verification, or notifying relevant regulatory authorities and other risk control and supervision measures to effectively prevent possible fraud and financial crime behaviors.

[0082] In the embodiment of the present invention, the anomaly detection layer adopts an innovative structural design, integrating the Isolation Forest algorithm to identify potential money laundering behaviors. Based on the fact that the Isolation Forest algorithm is suitable for processing high-dimensional data and can automatically identify abnormal patterns in the data without relying on external labels, it can effectively distinguish normal account behaviors from abnormal account behaviors. In addition, the Isolation Forest algorithm constructs multiple trees and evaluates anomalies from multiple perspectives, which helps to reduce false positives and false negatives, thereby improving the accuracy of the risk detection results and enhancing the trust and security of the entire payment system.

[0083] In some examples of the embodiment of the present invention, the money laundering behavior recognition model adopts the following comprehensive loss function L:

[0084] L = μ·L class + β·L anom + λ·L temp , Equation (9)

[0085]

[0086]

[0087]

[0088] In the formula, L class represents the classification loss term, L anom represents the anomaly detection loss, L temp represents the time continuity loss term, μ, β, λ respectively represent the weight coefficients corresponding to the respective loss terms; N represents the total number of samples in the data sample set; y i represents the true label of the i-th sample, is the probability predicted by the model as running score; P represents the actual probability distribution of running score behavior and non-running score behavior, Q represents the probability distribution of running score behavior and non-running score behavior predicted by the model based on the input data; χ represents the set of all possible behavior categories, and x represents a specific behavior category; KL(P‖Q) represents the KL divergence between the probability distributions P and Q; T represents the total length of the time series corresponding to the sample, and t represents the serial number of the time point in the time series; represents the probability of running score behavior predicted by the model output at time point t, represents the Euclidean norm of the difference in the model prediction output between time points t and t + 1.

[0089] In the embodiment of the present invention, the cross-entropy loss is used as the basic classification loss L class , to achieve better processing of the binary classification problem (running score vs non-running score). A loss term L based on the difference between the model prediction distribution and the label distribution is introduced anom , and the Kullback-Leibler Divergence is used to enhance the model's ability to capture abnormal patterns. In addition, considering that running score behavior generally has the characteristic of time continuity (such as frequent transactions in a short period of time), a time continuity loss term L temp is designed to evaluate the sensitivity of the model to time series anomalies. Thus, by combining the classification loss, anomaly detection loss, and time continuity loss, the model can be optimized from multiple perspectives to make it more sensitive to complex running score behavior patterns. In particular, through the time continuity loss, the model is trained to identify abnormal patterns in the time series. Since the model focuses on time continuity and the identification of abnormal patterns, it is very beneficial to the early warning risk analysis of real-time payment data. Therefore, it can quickly identify and trigger an alarm at the initial stage of running score behavior, thereby supporting real-time risk management and decision-making.

[0090] In some embodiments, by adjusting the weights μ, β, λ of the three losses, the balance of the model's sensitivity to different types of data during training can be flexibly controlled, which helps the model maintain good performance in different data sets and the ever-changing real-world environment. In particular, adding the anomaly detection loss and time continuity loss on the basis of the standard classification loss term enables the model to not only learn the surface features of label data, but also deeply learn the internal structure and time dynamics of the data, thereby improving the generalization ability of the model.

[0091] The anti-running score real-time monitoring and control system provided by the present invention will be described below. The anti-running score real-time monitoring and control system described below can be mutually referred to the anti-running score real-time monitoring and control method described above.

[0092] Figure 3A structural block diagram showing an example of an anti-money laundering real-time monitoring and control system according to an embodiment of the present invention is shown.

[0093] As Figure 3 shown, the anti-money laundering real-time monitoring and control system 300 includes a data acquisition unit 310, a data fusion unit 320, a time-series data determination unit 330, a graph network update unit 340, and a money laundering behavior identification unit 350.

[0094] The data acquisition unit 310 is configured to obtain, for each payment platform interface, the platform real-time payment data corresponding to the payment platform interface; the platform real-time payment data all includes account information, transaction amount, transaction time, and transaction counterparty account information.

[0095] The data fusion unit 320 is configured to perform data preprocessing on each of the platform real-time payment data, and fuse each preprocessed platform payment data according to the account information to determine the corresponding cross-platform real-time payment data of the account.

[0096] The time-series data determination unit 330 is configured to, for each of the cross-platform real-time payment data of the account, combine the cross-platform real-time payment data of the account with the cross-platform historical payment data set of the corresponding account information in a preset historical time period to determine the corresponding account payment time-series data.

[0097] The graph network update unit 340 is configured to update the global account transaction graph network based on each of the account payment time-series data; each node in the global account graph network is respectively used to represent the corresponding account information, and each edge connection is a directed edge, pointing from the payer account information to the payee account information; the edge connection attributes include: transaction amount, transaction time, and the average transaction cycle between both parties; the node attributes include: account type, account registration time, account location, and account transaction frequency.

[0098] The money laundering behavior identification unit 350 is configured to input the global account transaction graph network into a preset money laundering behavior identification model to identify at least one risk node to be subject to account control in the global account transaction graph network.

[0099] The money laundering behavior identification model adopts an enhanced graph attention network, and the enhanced graph attention network includes a cascaded time encoding layer, a deep graph attention layer, and an anomaly detection layer.

[0100] The time encoding layer is used to encode the associated time encodings respectively corresponding to the time information in each edge connection in the global account transaction graph network.

[0101] The depth map attention layer is used to calculate the attention coefficients between each node and its adjacent nodes in the global account transaction graph network according to the initial node features of each node and the associated time encoding, and update the corresponding first node features by weighting according to the attention coefficients, so as to obtain the corresponding attention node features.

[0102] The anomaly detection layer is used to respectively identify the risk behavior patterns of each attention node feature, so as to screen out risk nodes from each node accordingly.

[0103] It should be noted that for the foregoing method embodiments, for the sake of simple description, they are all expressed as a series of actions combined. However, those skilled in the art should know that the present invention is not limited by the described action sequence, because according to the present invention, certain steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily essential to the present invention. In the above embodiments, the descriptions of each embodiment have their own emphases. For the parts not detailed in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.

[0104] Figure 4 is a schematic hardware structure diagram of an electronic device for executing the anti-money laundering real-time monitoring and control method provided by another embodiment of the present invention. As Figure 4 shown, the device includes:

[0105] One or more processors 410 and a memory 420, Figure 4 Taking one processor 410 as an example in

[0106] The device for executing the anti-money laundering real-time monitoring and control method may further include: an input device 430 and an output device 440.

[0107] The processor 410, the memory 420, the input device 430, and the output device 440 may be connected through a bus or other means, Figure 4 Taking connection through a bus as an example in

[0108] The memory 420, as a non-volatile computer-readable storage medium, can be used to store non-volatile software programs, non-volatile computer-executable programs, and modules, such as the program instructions / modules corresponding to the anti-money laundering real-time monitoring and control method in the embodiments of the present invention. The processor 410 executes various functional applications and data processing of the server by running the non-volatile software programs, instructions, and modules stored in the memory 420, that is, implements the anti-money laundering real-time monitoring and control method in the above method embodiments.

[0109] The memory 420 may include a program storage area and a data storage area. The program storage area may store an operating system and application programs required for at least one function. The data storage area may store data created according to the use of the electronic device and the like. In addition, the memory 420 may include a high-speed random access memory and may also include non-volatile memory, such as at least one magnetic disk storage device, a flash memory device, or other non-volatile solid-state storage devices. In some embodiments, the memory 420 may optionally include a memory remotely disposed relative to the processor 410, and these remote memories may be connected to the electronic device through a network. Examples of the above networks include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0110] The input device 430 may receive input digital or character information and generate signals related to user settings and function controls of the electronic device. The output device 440 may include a display device such as a display screen.

[0111] The one or more modules are stored in the memory 420 and, when executed by the one or more processors 410, execute the anti-score-running real-time monitoring and control method in any of the above method embodiments.

[0112] The above product may execute the anti-score-running real-time monitoring and control method provided by the embodiments of the present invention, and has functional modules and beneficial effects corresponding to the execution method. For technical details not described in detail in this embodiment, reference may be made to the method provided by the embodiments of the present invention.

[0113] The electronic device in the embodiments of the present invention exists in various forms, including but not limited to:

[0114] (1) Mobile communication devices: These devices are characterized by having mobile communication functions and mainly aim to provide voice and data communication. Such terminals include: smart phones, multimedia phones, functional phones, and low-end phones, etc.

[0115] (2) Ultra-mobile personal computer devices: These devices belong to the category of personal computers, have computing and processing functions, and generally also have the characteristic of mobile Internet access. Such terminals include: PDAs, MIDs, and UMPC devices, etc.

[0116] (3) Portable entertainment devices: These devices can display and play multimedia content. Such devices include: audio and video players, handheld game consoles, e-books, and smart toys and portable in-vehicle navigation devices.

[0117] (4) Other airborne electronic devices with data interaction functions, such as in-vehicle device installed on a vehicle.

[0118] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0119] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a general hardware platform, and of course, it can also be implemented by hardware. Based on this understanding, the essence of the above technical solution, or the part that contributes to the related technology, can be embodied in the form of a software product. The computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to enable a computer device (which can be a personal computer, server, or network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.

[0120] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A real-time monitoring and control method for anti-running points, comprising: For each payment platform interface, obtain the platform real-time payment data corresponding to the payment platform interface; the platform real-time payment data includes account information, transaction amount, transaction time and transaction counterparty account information; Preprocess the real-time payment data of each platform, and merge the preprocessed platform payment data according to the account information to determine the corresponding cross-platform real-time payment data of the account; the cross-platform real-time payment data of the account is used to reveal the transaction behavior and pattern of a single account between different platforms; For each of the cross-platform real-time payment data of the account, the cross-platform real-time payment data of the account is combined with a data set of cross-platform historical payment data of the account of the corresponding account information in a preset historical time period to determine the corresponding account payment time series data; Based on the payment time series data of each of the accounts, a global account transaction graph network is updated; each node in the global account transaction graph network is used to represent the corresponding account information, and each edge connection is a directed edge, pointing from the payer's account information to the payee's account information; the edge connection attributes include: transaction amount, transaction time and average transaction cycle of both parties; the node attributes include: account type, account registration time, account location and account transaction frequency; The global account transaction graph network is input into a preset running behavior recognition model to identify at least one risk node to be subject to account control in the global account transaction graph network; the running behavior recognition model adopts an enhanced graph attention network, which includes a cascaded time encoding layer, a deep graph attention layer, and an anomaly detection layer; The time coding layer is used to encode the associated time codes corresponding to the time information in each edge connection in the global account transaction graph network; The deep graph attention layer is used to calculate the attention coefficient between each node and the adjacent nodes in the global account transaction graph network according to the initial node features of each node and the associated time code, and perform weighted update on the corresponding first node features according to the attention coefficient to obtain the corresponding attention node features; The anomaly detection layer is used to identify the risk behavior patterns of the characteristics of each attention node respectively, so as to filter the risk nodes from each node accordingly; The time coding layer is used to encode the time information in each edge connection in the global account transaction graph network to determine the corresponding associated time coding: TE(t,2p)=sin(t / 10000 2p / d ) TE(t,2p+1)=cos(t / 10000 2p / d ) Where t represents the time information in the edge connection; d represents the total number of vector dimensions associated with the time code; p represents the vector dimension index, p∈[1,d / 2-1]; TE(t,2p) and TE(t,2p+1) represent the vector elements at the even and odd positions of the associated time code, respectively; Wherein, the deep graph attention layer comprises a plurality of cascaded graph attention layers; The graph attention layer is used to calculate the attention coefficient α between each pair of adjacent nodes i and j in the global account transaction graph network ij : In the formula, ‖ represents the concatenation of vectors; h i and h j denote the node features of nodes i and j respectively; a denotes a learnable weight vector; W denotes a linear transformation weight matrix; TE(t ij ) represents the associative temporal encoding of edge (i, j); LeakyReLU represents the nonlinear activation function; Represents the set of neighbor nodes of node i; According to the attention coefficient α ij Perform weighted update on the node features of node i: In the formula, σ represents the activation function, h i ′ represents the attention-weighted node feature output by the graph attention layer for node i; The anomaly detection layer is used to calculate the running score anomaly scores corresponding to the features of each attention node using the isolation forest algorithm, and the running score anomaly scores are used to screen risk nodes: score(i)=path_length(i) / c(n) In the formula, score(i) represents the abnormal score of the running score corresponding to node i; path_length(i) represents the average path length of node i being isolated; n represents the total number of all nodes in the global account transaction graph network, and c(n) represents the average path length of all nodes in the global account transaction graph network; represents the attention node feature output by the deep graph attention layer for node i; m q Indicates that for h(m q ) after the qth split, the number of data points in the child node; c(m q ) indicates that for m q The corresponding average path length; e represents the number of edges passed before reaching the leaf node for the segmentation of node i; γ is the Euler-Mascheroni constant; The running behavior recognition model adopts the following comprehensive loss function L: L=μ·L class +β·L anom +λ·L temp Where, L class represents the classification loss term, L anom represents the anomaly detection loss, L temp represents the time continuity loss term, μ, β, λ represent the weight coefficients corresponding to the corresponding loss terms; N represents the total number of samples in the data sample set; y i represents the true label of the i-th sample, is the probability of the model predicting a run; P represents the actual probability distribution of run and non-run behaviors, and Q represents the probability distribution of run and non-run behaviors predicted by the model based on the input data; represents the set of all possible behavior categories, x represents a specific behavior category; KL(P‖Q) represents the KL divergence between probability distributions P and Q; T represents the total length of the time series corresponding to the sample, and t represents the serial number of the time point in the time series; represents the probability of the running behavior output by the model prediction at time point t, Represents the Euclidean norm of the difference in model prediction output between time points t and t+1.

2. The method according to claim 1, wherein: The method of preprocessing the real-time payment data of each platform and fusing the preprocessed payment data of each platform according to the account information to determine the corresponding cross-platform real-time payment data of the account includes: For each of the platform real-time payment data, determine the target data encryption format corresponding to the platform payment data, query the payment format blockchain based on the target data encryption format to obtain the corresponding target data decryption format, and decrypt the platform real-time payment data based on the target data decryption format; the payment format blockchain uses the nodes in its network to jointly maintain and verify the distributed ledger containing the data encryption format and its corresponding data decryption format; The decrypted real-time payment data of each platform is integrated according to the account information to obtain the corresponding account cross-platform real-time payment data.

3. A real-time monitoring and control system for anti-runaway, used to implement the real-time monitoring and control method for anti-runaway as claimed in claim 1 or 2; The system includes: The data acquisition unit is configured to acquire the platform real-time payment data corresponding to each payment platform interface; the platform real-time payment data includes account information, transaction amount, transaction time and transaction counterparty account information; A data fusion unit is configured to pre-process the real-time payment data of each platform, and fuse the pre-processed platform payment data according to the account information to determine the corresponding account cross-platform real-time payment data; A time series data determination unit is configured to combine, for each of the account cross-platform real-time payment data, the account cross-platform real-time payment data with a data set of account cross-platform historical payment data of the corresponding account information in a preset historical time period to determine the corresponding account payment time series data; The graph network updating unit is configured to update the global account transaction graph network based on the payment time series data of each of the accounts; each node in the global account transaction graph network is used to represent the corresponding account information, and each edge connection is a directed edge, pointing from the payer's account information to the payee's account information; the edge connection attributes include: transaction amount, transaction time and average transaction cycle of both parties; the node attributes include: account type, account registration time, account location and account transaction frequency; A running behavior identification unit is configured to input the global account transaction graph network into a preset running behavior identification model to identify at least one risk node to be subject to account control in the global account transaction graph network; the running behavior identification model adopts an enhanced graph attention network, and the enhanced graph attention network includes a cascaded time encoding layer, a deep graph attention layer, and an anomaly detection layer; The time coding layer is used to encode the associated time codes corresponding to the time information in each edge connection in the global account transaction graph network; The deep graph attention layer is used to calculate the attention coefficient between each node and the adjacent nodes in the global account transaction graph network according to the initial node features of each node and the associated time code, and perform weighted update on the corresponding first node features according to the attention coefficient to obtain the corresponding attention node features; The anomaly detection layer is used to respectively identify the risk behavior patterns of the characteristics of each attention node, so as to filter out risky nodes from each node accordingly.

4. A storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the steps of the method according to claim 1 or 2 are implemented.

5. A computer program product comprising a computer program / instructions, characterized in that When the computer program / instructions are executed by a processor, the steps of the method according to any one of claims 1 or 2 are implemented.

Citation Information

Patent Citations

  • Supervisory blockchain system and method

    CN107483198A

  • Network training method, abnormal transaction behavior identification method and device, and medium

    CN112435122A

  • Systems and methods for Anti-money laundering analysis

    CN113348480A

  • Credit risk enterprise identification method and device based on graph neural network

    CN116091208A

  • Method for detecting Ethereum malicious account through graph attention neural network based on time sequence transaction relation

    CN116506140A