Artificial Intelligence-Based Method and System for Identifying Risk Behaviors in the Capital Chain
The method uses a combination of estimation and focus positioning networks to enhance the accuracy of financial chain risk identification, reducing inefficiencies and inaccuracies in manual analysis.
Patent Information
- Application Number
- CN202411106044.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-08-13
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2044-08-13
AI Technical Summary
Traditional capital chain risk identification methods rely on manual analysis, are inefficient and difficult to accurately identify potential risk points.
A capital chain risk behavior identification model based on artificial intelligence is built, including the first estimation network, the second estimation network and the focus positioning network. By performing pattern analysis of the capital chain interaction behavior data, the potential risk interaction path is identified, and the key nodes and regions are accurately positioned through the focus positioning network, and the second estimation network is used for detailed analysis, and finally the updated risk interaction path is generated and loaded into the message queue of the risk control server.
It improves the accuracy of capital chain risk identification, reduces false alarms and missed reports, realizes automated analysis, and provides real-time and dynamic risk control data support, which is suitable for capital chain risk identification in different industries and scenarios.
Smart Images

Figure CN118886997B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer technology. Specifically, it relates to a method and system for identifying risk behaviors in the capital chain based on artificial intelligence. Background Art
[0002] In the financial field, the security and stability of the capital chain are the cornerstones of enterprise operation and development. However, with the increasing complexity and frequency of financial transactions, the identification and prevention of risk behaviors in the capital chain have become particularly important. Traditional methods for identifying capital chain risks mainly rely on manual analysis, which is not only inefficient but also difficult to accurately identify potential risk points. Therefore, there is an urgent need to develop an efficient and accurate method for identifying risk behaviors in the capital chain. Summary of the Invention
[0003] In view of the problems mentioned above, in combination with the first aspect of this application, embodiments of this application provide a method for identifying risk behaviors in the capital chain based on artificial intelligence, which is implemented through a risk behavior identification model for the capital chain. The risk behavior identification model for the capital chain includes a first estimation network, a second estimation network, and a focus positioning network. The method includes:
[0004] Loading the session network structure data of the capital chain interaction behavior data into the first estimation network to determine the estimated risk interaction path of the capital chain interaction behavior data;
[0005] Generating, according to the focus positioning network, focus nodes corresponding to the estimated risk interaction path and determining the focus area where each focus node is located; the focus nodes reflect the context nodes of the estimated risk interaction path on the capital chain interaction behavior data, and at least part of the focus area includes the penetration path interval of the estimated risk interaction path;
[0006] Loading the session network structure data of the capital chain interaction behavior data and the context nodes corresponding to the focus area in the capital chain interaction behavior data into the second estimation network to generate an updated estimated risk interaction path; the focus area corresponding to the updated estimated risk interaction path includes an updated penetration path interval;
[0007] Loading the updated estimated risk interaction path into the message queue of the risk control server to determine the risk behavior identification data of the capital chain interaction behavior data.
[0008] In a possible implementation manner of the first aspect, the generating, according to the focus positioning network, focus nodes corresponding to the estimated risk interaction path and determining the focus area where each focus node is located includes:
[0009] Determine the focusing node parameter values corresponding to the estimated risk interaction path according to the focusing positioning network;
[0010] Traverse the estimated risk interaction path and perform focusing node matching according to the focusing node parameter values to generate the focusing nodes corresponding to the estimated risk interaction path;
[0011] Respectively use the focusing nodes as reference nodes of the focusing area to determine the focusing area where each focusing node is located.
[0012] In a possible implementation manner of the first aspect, the determining the focusing node parameter values corresponding to the estimated risk interaction path according to the focusing positioning network includes:
[0013] According to the focusing positioning network, determine the focusing node parameter values corresponding to the estimated risk interaction path based on the cost value of the estimated risk interaction path, where the focusing node parameter values are proportional to the cost value.
[0014] In a possible implementation manner of the first aspect, the first estimation network includes a first multi-layer perceptron;
[0015] The loading the session network structure data of the fund chain interaction behavior data into the first estimation network to determine the estimated risk interaction path of the fund chain interaction behavior data includes:
[0016] Perform pattern analysis on the session network structure data of the fund chain interaction behavior data according to the first multi-layer perceptron to estimate X potential risk links and the risk labels of each potential risk link; X is an integer greater than 0;
[0017] Based on the risk path features of the X potential risk links and the risk labels of each potential risk link, determine the estimated risk interaction path of the fund chain interaction behavior data from the potential risk links.
[0018] In a possible implementation manner of the first aspect, the second estimation network includes a second multi-layer perceptron;
[0019] The loading the session network structure data of the fund chain interaction behavior data and the context nodes corresponding to the focusing area in the fund chain interaction behavior data into the second estimation network to generate an updated estimated risk interaction path includes:
[0020] Map the context nodes corresponding to the focusing area in the fund chain interaction behavior data onto the session network structure data of the fund chain interaction behavior data to determine the penetration path features of the penetration path interval within the focusing area;
[0021] Based on the penetration path characteristics, update the penetration path interval within the focused area based on the second multi-layer perceptron to generate the updated estimated risk interaction path.
[0022] In a possible implementation manner of the first aspect, the step of updating the penetration path interval within the focused area based on the second multi-layer perceptron according to the penetration path characteristics to generate the updated estimated risk interaction path includes:
[0023] Based on the penetration path characteristics, update the penetration path interval within the focused area based on the second multi-layer perceptron to generate the estimated risk operation trajectory within each focused area and the labeled knowledge points of each estimated risk operation trajectory;
[0024] Based on the labeled knowledge points of the estimated risk operation trajectory within each focused area, extract the updated penetration path interval from each estimated risk operation trajectory to generate the updated estimated risk interaction path.
[0025] In a possible implementation manner of the first aspect, the method further includes:
[0026] According to the second multi-layer perceptron, determine the risk attention node of the estimated risk operation trajectory within each focused area, the trajectory cost value of the estimated risk operation trajectory, and the deviation degree of the estimated risk operation trajectory relative to the reference path interval of the estimated risk interaction path;
[0027] According to the risk attention node, the trajectory cost value, and the deviation degree of the estimated risk operation trajectory, determine the path state description of the estimated risk operation trajectory within each focused area; the path state description reflects the specific risk state mode of the estimated risk operation trajectory.
[0028] In a possible implementation manner of the first aspect, the step of loading the updated estimated risk interaction path into the message queue of the risk control server to determine the risk behavior recognition data of the fund chain interaction behavior data includes:
[0029] Based on the path state description of the updated penetration path interval, determine the risk attention node of the updated penetration path interval;
[0030] According to the order of the focused areas corresponding to the updated estimated risk interaction path, load the set of risk attention nodes of the updated penetration path interval within the focused area into the message queue of the risk control server to generate the risk behavior recognition data of the fund chain interaction behavior data.
[0031] In a possible implementation of the first aspect, the method further includes:
[0032] Loading the session network structure data of the template fund chain interaction behavior data into the first estimation network to determine the estimated risk interaction path of the template fund chain interaction behavior data; the template fund chain interaction behavior data carries the risk interaction path;
[0033] Generating, according to the focusing positioning network, a focusing node corresponding to the estimated risk interaction path and determining a focusing area where each focusing node is located; the focusing node reflects a context node of the estimated risk interaction path on the template fund chain interaction behavior data, and at least a part of the penetration path interval of the estimated risk interaction path is included in the focusing area;
[0034] Loading the session network structure data of the template fund chain interaction behavior data and the context nodes corresponding to the focusing area in the template fund chain interaction behavior data into the second estimation network to generate an updated estimated risk interaction path;
[0035] Determining a first model error parameter according to the risk interaction path and the potential risk link; the potential risk link is estimated by the first estimation network;
[0036] Determining a second model error parameter based on the penetration path interval in the focusing area corresponding to the estimated risk interaction path and the updated penetration path interval in the focusing area of the updated estimated risk interaction path;
[0037] Determining a model error parameter according to the first model error parameter and the second model error parameter, and optimizing the parameters of the fund chain risk behavior recognition model according to the model error parameter.
[0038] In another aspect, an embodiment of the present application further provides an artificial intelligence-based fund chain risk behavior recognition system, including a processor and a machine-readable storage medium, the machine-readable storage medium is connected to the processor, the machine-readable storage medium is used to store programs, instructions or codes, and the processor is used to execute the programs, instructions or codes in the machine-readable storage medium to implement the above method.
[0039] Based on the above aspects, the embodiments of the present application achieve precise risk identification and assessment of capital chain interaction behavior data by constructing a capital chain risk behavior identification model including a first estimation network, a second estimation network, and a focused positioning network. First, the first estimation network is used to estimate potential risk interaction paths from complex capital chain interaction behavior data. Subsequently, the focused positioning network precisely locates the key focused nodes and their corresponding focused regions on these paths. Further, the second estimation network is used to refine the analysis of the risks within the focused regions, generating updated estimated risk interaction paths. Finally, the updated risk path data is loaded into the message queue of the risk control server, providing timely and accurate data support for risk management and control.
[0040] Therefore, by combining the use of a two-level estimation network and a focused positioning network, potential risk points in the capital chain can be identified more precisely, reducing false alarms and missed reports, and improving the accuracy of risk identification. The use of artificial intelligence technology to automatically analyze capital chain interaction behavior data greatly reduces the degree of manual participation and improves the efficiency of risk identification. Loading the updated risk path data into the message queue of the risk control server in real time provides real-time and dynamic data support for risk control decisions, helping enterprises to take risk prevention and control measures in a timely manner. This method is applicable to the risk identification of capital chains in different industries and scenarios, and has strong versatility and adaptability. BRIEF DESCRIPTION OF THE DRAWINGS
[0041] Figure 1 is a schematic flowchart of the execution process of the capital chain risk behavior identification method based on artificial intelligence provided by the embodiments of the present application.
[0042] Figure 2 is a schematic diagram of the hardware architecture of the capital chain risk behavior identification system based on artificial intelligence provided by the embodiments of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0043] The following specifically describes the present application in conjunction with the accompanying drawings of the specification. Figure 1 is a schematic flowchart of the capital chain risk behavior identification method based on artificial intelligence provided by an embodiment of the present application. The capital chain risk behavior identification method is implemented through a capital chain risk behavior identification model, and the capital chain risk behavior identification model includes a first estimation network, a second estimation network, and a focused positioning network. The following details the capital chain risk behavior identification method based on artificial intelligence.
[0044] Step S110, loading the session network structure data of the capital chain interaction behavior data into the first estimation network to determine the estimated risk interaction path of the capital chain interaction behavior data.
[0045] Specifically, the capital chain interaction behavior data refers to the data that records a series of activities such as capital flows, transfers, transactions, etc. It usually contains key information such as the information of both parties to the transaction, the transaction time, the transaction amount, etc., and reflects the flow of funds between different entities. For example, assume a bank records the transfer data between its customers, including that transferor A transfers 1000 yuan to payee B at XX:XX on XX / XX / XX. These data are part of the capital chain interaction behavior data and are used to analyze the pattern and risk of capital flow.
[0046] The session network structure data is a data structure that organizes the capital chain interaction behavior data in the form of a network diagram. In this network diagram, nodes represent transaction entities (such as individuals, companies, etc.), and edges represent transaction behaviors (such as transfers, transactions, etc.). In this way, the flow path and relationship of funds between different entities can be intuitively displayed. Continuing with the above example, the bank can convert the transfer data into session network structure data. In this network diagram, A and B are nodes representing two transaction entities; the edge from A to B represents the behavior of A transferring money to B. If there are other transfer behaviors, these behaviors will also be represented as edges in the network diagram.
[0047] The first estimation network is a trained deep learning model used to estimate potential risk links in the session network structure data. It can automatically learn and identify risk patterns in the capital chain interaction behavior and output potential risk interaction paths. For example, the bank uses the first estimation network to analyze the capital chain interaction behavior data of its customers. By inputting the session network structure data, the model can estimate which transaction paths have potential risks, such as frequent large - amount transfers, transactions with high - risk entities, etc.
[0048] The estimated risk interaction path is the result output by the first estimation network, indicating the transaction paths that may have risks in the capital chain interaction behavior data. These paths are composed of a series of connected edges and nodes, reflecting the high - risk areas of capital flow. For example, under the analysis of the first estimation network, the bank finds that the transfer path from A to B intersects with multiple high - risk entities and the transfer amount is large. Therefore, this path is identified as one of the estimated risk interaction paths.
[0049] That is to say, in this embodiment, the server receives a batch of capital chain interaction behavior data, which records activities such as capital transfers and transactions between different users. The server first extracts the session network structure of these capital chain interaction behavior data to form a complex session network structure data. In the session network structure data, nodes represent users or transaction entities, and edges represent capital flows.
[0050] Next, the server loads this session network structure data into the first estimation network. The first estimation network is a trained deep learning model that can estimate potential risk links in the session network structure data. After analysis, the first estimation network outputs several estimated risk interaction paths, which are represented as a series of connected edges and nodes in the session network structure data and are considered to have a relatively high risk.
[0051] Step S120: According to the focusing and positioning network, generate focusing nodes corresponding to the estimated risk interaction paths, and determine the focusing regions where each of the focusing nodes is located. The focusing nodes reflect the context nodes of the estimated risk interaction paths in the fund chain interaction behavior data, and at least part of the penetration path intervals of the estimated risk interaction paths are included in the focusing regions.
[0052] Specifically, the focusing and positioning network is a network model for identifying key nodes, which can find important focusing nodes for each estimated risk interaction path and is crucial for understanding the risk nature of the entire path. For example, when the focusing and positioning network analyzes an estimated risk interaction path and finds that node A appears frequently in this path and interacts with multiple high-risk entities. Therefore, node A is identified as one of the focusing nodes.
[0053] The focusing nodes are the key nodes determined by the focusing and positioning network, which reflect the context nodes of the estimated risk interaction paths in the fund chain interaction behavior data. The focusing region is a subgraph centered on the focusing node, including the focusing node and its surrounding nodes and edges, and is used to further analyze the specific situation of the risk. Taking node A as an example, the focusing region includes other nodes (such as B, C, etc.) that directly interact with node A and the edges between them. This region contains the key part of the estimated risk interaction path and is used to deeply analyze the risk situation of node A.
[0054] That is to say, in this embodiment, after determining the estimated risk interaction paths, the server then uses the focusing and positioning network to further analyze these paths. The role of the focusing and positioning network is to find the key focusing nodes for each estimated risk interaction path.
[0055] The server inputs the risk interaction paths into the focusing and positioning network. The focusing and positioning network determines several focusing nodes by calculating the importance and context relationships of the nodes on each path. These focusing nodes are the key nodes on the path and are crucial for understanding the risk nature of the entire path.
[0056] Subsequently, the server determines a focused area for each focused node. The focused area is a subgraph in the session network structure data, which includes the focused node and its surrounding nodes and edges. These focused areas at least partially contain the penetration path intervals of the estimated risk interaction paths, that is, the abnormal or risky parts that may exist in the fund flow.
[0057] Step S130: Load the session network structure data of the fund chain interaction behavior data and the focused area into the second estimation network corresponding to the context nodes in the fund chain interaction behavior data to generate an updated estimated risk interaction path. The updated penetration path interval is included in the focused area corresponding to the estimated risk interaction path.
[0058] Specifically, the second estimation network is a more refined risk assessment model, which is used to update and correct the estimated risk interaction path output by the first estimation network. It uses the context information in the focused area to more accurately identify risk points and outputs an updated estimated risk interaction path. For example, under the analysis of the second estimation network, the bank finds that certain transaction behaviors in the focused area have higher risks. Therefore, the original estimated risk interaction path is updated and optimized, and a more accurate risk interaction path is output.
[0059] The updated estimated risk interaction path is the result output by the second estimation network, which represents the risk interaction path determined after more refined analysis in the fund chain interaction behavior data, and more accurately reflects the real risk situation in the fund flow. For example, under the analysis of the second estimation network, the bank finds that in addition to the transfer path from A to B, the transfer path from A to C also has high risks. Therefore, this new path is added to the updated estimated risk interaction path.
[0060] Thus, in this embodiment, the server now determines the session network structure data of the fund chain interaction behavior data and the focused area determined by the focused positioning network. Next, the server loads these data into the second estimation network.
[0061] The second estimation network is a more refined risk assessment model, which uses the context information in the focused area to update and correct the previous estimated risk interaction path. By analyzing the characteristics of the nodes and edges in the focused area, as well as their positions and relationships in the entire network, the second estimation network generates an updated estimated risk interaction path, which more accurately reflects the real risk situation in the fund chain interaction behavior. In particular, the updated estimated risk interaction path includes new penetration path intervals, which indicate more specific and accurate risk points in the fund flow.
[0062] Step S140: Load the updated estimated risk interaction path into the message queue of the risk control server, and determine the risk behavior identification data of the fund chain interaction behavior data.
[0063] The message queue of the risk control server is a buffer for processing a large amount of data, which is used to ensure the orderly processing and transmission of data. The server loads the updated estimated risk interaction path into the message queue so that the risk control system can obtain this data in real time for further risk control and processing. For example, a bank loads the updated estimated risk interaction path into the message queue of the risk control server. The risk control system retrieves these path data from the queue and performs real-time risk monitoring and implementation of prevention and control measures based on the risk information therein.
[0064] That is, finally, the server needs to convert the updated estimated risk interaction path into specific risk behavior identification data. To this end, the server loads these estimated risk interaction paths into the message queue of the risk control server. The message queue is a buffer for processing a large amount of data, which can ensure the orderly processing and transmission of data. By putting the updated risk interaction path into the message queue, the server can further analyze and process these paths according to the priority and order.
[0065] Finally, the server retrieves the estimated risk interaction path from the message queue and determines the risk behavior identification data of each estimated risk interaction path. These data include the specific information of the estimated risk interaction path, the risk level, the users and trading entities involved, etc., providing an important basis for subsequent risk control decisions.
[0066] Based on the above steps, the embodiment of the present application realizes the accurate risk identification and assessment of the fund chain interaction behavior data by constructing a fund chain risk behavior identification model including a first estimation network, a second estimation network and a focusing and positioning network. First, use the first estimation network to estimate the potential risk interaction path from the complex fund chain interaction behavior data. Subsequently, use the focusing and positioning network to accurately locate the key focusing nodes and their focusing areas on these paths. Further, use the second estimation network to refine the analysis of the risks in the focusing area to generate the updated estimated risk interaction path. Finally, load the updated risk path data into the message queue of the risk control server to provide timely and accurate data support for risk management and control.
[0067] Thus, by the combined use of the two - level estimation network and the focusing and positioning network, potential risk points in the capital chain can be identified more precisely, reducing false alarms and missed reports, and improving the accuracy of risk identification. The use of artificial intelligence technology to automatically analyze the capital chain interaction behavior data greatly reduces the degree of manual participation and improves the efficiency of risk identification. Loading the updated risk path data into the message queue of the risk control server in real - time provides real - time and dynamic data support for risk control decisions, helping enterprises to take risk prevention and control measures in a timely manner. This method is applicable to the risk identification of capital chains in different industries and scenarios, and has strong generality and adaptability.
[0068] In a possible implementation manner, step S120 includes:
[0069] Step S121, according to the focusing and positioning network, determine the focusing node parameter values corresponding to the estimated risk interaction paths.
[0070] In this embodiment, after the server determines the estimated risk interaction paths, these paths are input into the focusing and positioning network. The focusing and positioning network contains a series of complex algorithms and models, and these models are trained to identify the nodes that play key roles in the network.
[0071] For each estimated risk interaction path, the focusing and positioning network analyzes each node on the path and calculates a focusing node parameter value for each node according to factors such as the node's connectivity, centrality, and interaction frequency with other nodes. This focusing node parameter value reflects the importance of the node in the risk interaction path.
[0072] Step S122, traverse the estimated risk interaction paths and perform focusing node matching according to the focusing node parameter values to generate the focusing nodes corresponding to the estimated risk interaction paths.
[0073] The server will then "traverse" along each estimated risk interaction path, that is, check one by one according to the connection order of the nodes on the path. During the traversal process, the server will match and screen the nodes according to the previously calculated focusing node parameter values.
[0074] Specifically, the server will set a threshold. Only when the focusing node parameter value of a node exceeds this threshold will the node be identified as a focusing node. In this way, the server can select the most important several nodes from each estimated risk interaction path as the focusing nodes of this path.
[0075] Step S123, respectively use the focusing nodes as the reference nodes of the focusing regions to determine the focusing regions where each focusing node is located.
[0076] Once the focused nodes are determined, the server further determines the focused areas where each focused node is located. A focused area is a subgraph centered on the focused node, including the nodes and edges within a certain range around it.
[0077] To determine the scope of the focused area, the server considers various factors, such as the connection strength between nodes, the length of the path, and the position of the focused node in the network, etc. By integrating these factors, the server can delimit a reasonable scope so that the focused area contains other nodes and edges closely related to the focused node without being too large to lose the meaning of focusing.
[0078] Finally, the server determines a corresponding focused area for each focused node, and these areas will be the key objects of concern for subsequent risk analysis and processing. In this way, the server can more accurately identify and respond to potential risks in the capital chain interaction behavior.
[0079] In a possible implementation manner, step S121 includes: based on the focused positioning network, determining the focused node parameter value corresponding to the estimated risk interaction path according to the cost value of the estimated risk interaction path, where the focused node parameter value is proportional to the cost value.
[0080] In the risk analysis process of the server, after the estimated risk interaction paths have been determined through the first estimation network, the next step is to use the focused positioning network to determine the key nodes on these paths, that is, the focused nodes. And an important basis for determining these focused nodes is the cost value of the path.
[0081] First, the server calculates the cost value of each estimated risk interaction path, which is comprehensively calculated based on multiple factors such as the risk level of each node on the path, the interaction frequency between nodes, and the historical risk records. The higher the cost value, the greater the risk on this path.
[0082] Next, the server inputs these estimated risk interaction paths and their corresponding cost values into the focused positioning network. The focused positioning network contains complex algorithms that can determine the focused node parameter value of each node on the path according to the cost value of the path.
[0083] This focused node parameter value is proportional to the cost value of the path. That is to say, if the cost value of a path is very high, then the focused node parameter value obtained by the nodes on this path will also be relatively high. This is because a path with a high cost value means a high risk and needs more attention, so the nodes on it are more likely to become key risk points, that is, focused nodes.
[0084] In this way, the server can accurately identify the key nodes on the risk interaction path, providing strong support for subsequent risk prevention and control work. For example, for nodes with relatively high focus node parameter values, the server can strengthen monitoring to timely discover and handle potential risk events.
[0085] In one possible implementation manner, the first estimation network includes a first multi-layer perceptron.
[0086] Step S110 includes:
[0087] Step S111, perform pattern analysis on the session network structure data of the fund chain interaction behavior data according to the first multi-layer perceptron, estimate X potential risk links, and the risk label of each potential risk link. Wherein X is an integer greater than 0.
[0088] Step S112, based on the risk path features of the X potential risk links and the risk label of each potential risk link, determine the estimated risk interaction path of the fund chain interaction behavior data from the potential risk links.
[0089] In this embodiment, the server first loads the session network structure data of the fund chain interaction behavior data into the first estimation network. This session network structure data includes various detailed information such as various fund flow records, information of both trading parties, trading time, trading amount, etc. This session network structure data is organized in the form of a network structure, where nodes represent trading entities and edges represent trading behaviors.
[0090] Next, the server uses the first multi-layer perceptron (a deep learning model) to perform pattern analysis on this session network structure data. The multi-layer perceptron can capture the deep patterns and associations in the data through its complex network structure and non-linear activation function.
[0091] During the pattern analysis process, the multi-layer perceptron will automatically learn and identify potential risk patterns in the fund chain interaction behavior. These risk patterns can include abnormal fund flow frequencies, amounts, trading counterparts, etc.
[0092] Based on the results of the pattern analysis, the server can estimate X potential risk links. Each potential risk link represents a potentially problematic part of the fund chain, such as certain specific combinations of trading counterparts, trading amount ranges, or trading frequencies, etc.
[0093] Meanwhile, the multi-layer perceptron also assigns a risk label to each potential risk link. This risk label is a quantitative metric used to represent the risk level of the potential risk link. For example, a high-risk link may be labeled "red", a medium-risk link "yellow", and a low-risk link "green".
[0094] Finally, based on the risk path features and risk labels of these X potential risk links, the server determines the estimated risk interaction paths of the fund chain interaction behavior data. This process may involve further analysis and screening of the risk path features, such as considering factors like the transaction amount, transaction frequency, and stability of the trading counterpart in the path.
[0095] The determined estimated risk interaction paths are the parts of the fund chain interaction that the server deems to have a relatively high risk, and these parts may require further review or monitoring. In this way, the server can help enterprises promptly detect and prevent potential fund chain risks.
[0096] Generally speaking, this process is an automated risk assessment and identification process that relies on the analysis and learning of a large amount of fund chain interaction behavior data by a deep learning model to accurately identify potential risk points.
[0097] In a possible implementation manner, the second estimation network includes a second multi-layer perceptron.
[0098] Step S130 includes:
[0099] Step S131, mapping the context nodes corresponding to the focused area in the fund chain interaction behavior data to the session network structure data of the fund chain interaction behavior data, and determining the penetration path features of the penetration path interval within the focused area.
[0100] Step S132, based on the penetration path features, updating the penetration path interval within the focused area based on the second multi-layer perceptron to generate the updated estimated risk interaction path.
[0101] In this embodiment, the server first maps the context nodes corresponding to the focused area in the fund chain interaction behavior data to the session network structure data of the fund chain interaction behavior data. This process can be understood as marking the area of special concern, that is, the focused area, in the complex network diagram.
[0102] Specifically, if the fund chain interaction behavior data constitutes a huge network graph, where each node represents an entity (such as a company, an individual, etc.) and each edge represents a fund interaction behavior, then the server will find the nodes corresponding to the focused area in this network graph and mark out these nodes and their surrounding context nodes (i.e., other nodes directly or indirectly connected to these nodes).
[0103] For example, assume that the server is analyzing a fund chain interaction network involving multiple companies. In this network, several companies are marked as the focused area due to their recent abnormal transaction behaviors. The server will highlight or specially mark these companies and other companies (context nodes) that have had recent fund transactions on the network graph.
[0104] Next, the server will analyze these marked nodes and edges to determine the penetration path characteristics of the penetration path interval within the focused area. The penetration path characteristics can include the frequency of fund flow, the amount of money, the degree of association between the trading parties, etc. These factors may all affect the risk of fund penetration.
[0105] For example, within the already marked focused area, the server discovers that the fund flow between two certain companies is extremely frequent and the amount is huge. At the same time, these two companies also have close fund transactions with many other companies. These characteristics constitute the penetration path characteristics between these two companies, indicating that these two companies can be key nodes for fund penetration.
[0106] Finally, the server will update the penetration path interval within the focused area using the second multi-layer perceptron based on these penetration path characteristics. The second multi-layer perceptron is a deep learning model that can automatically learn and adjust network parameters according to the input feature data to more accurately predict risks.
[0107] In this step, the server will use the penetration path characteristics as input data and process and analyze them through the second multi-layer perceptron. The model will update the prediction of the fund penetration risk within the focused area based on these feature data and generate an updated estimated risk interaction path.
[0108] For example, the server inputs the previously analyzed penetration path characteristics into the second multi-layer perceptron. After learning and calculation, the model outputs an updated estimated risk interaction path. On this path, the two companies previously marked as key nodes are still in high-risk positions, but the model also predicts several other possible risk points, including several other companies that have close fund transactions with these two companies. In this way, the server obtains a more comprehensive and accurate prediction result of the risk interaction path.
[0109] In a possible implementation manner, step S132 includes:
[0110] Step S1321: According to the penetration path features, update the penetration path intervals within the focused area based on the second multi-layer perceptron, generate the estimated risk operation trajectories within each focused area, and the label knowledge points of each estimated risk operation trajectory.
[0111] Step S1322: Based on the label knowledge points of the estimated risk operation trajectories within each focused area, extract the updated penetration path intervals from each of the estimated risk operation trajectories to generate the updated estimated risk interaction paths.
[0112] In this embodiment, the server first updates the penetration path intervals within the focused area according to the previously determined penetration path features using the second multi-layer perceptron. The core of this step is to train and infer the deep learning model through the second multi-layer perceptron based on the specific attributes of the penetration path, such as the frequency of fund flow, the amount of money, the counterparty of the transaction, etc.
[0113] For example, assume that in a complex fund chain network, the server has identified a focused area suspected of having risky operations. This area contains multiple fund flow paths, and the server now needs to update its understanding of the risk based on the features of these paths.
[0114] The server inputs the penetration features of each path, such as an unusually high transaction frequency and an unusually large transaction amount, into the second multi-layer perceptron. Through the internal calculation of the model, the server obtains the risk assessment results of each path, and these results form the estimated risk operation trajectories within the focused area. At the same time, the model also generates label knowledge points for each trajectory, and these labels can include "high-frequency trading", "large-amount transfer", etc., to identify the main risk features of the trajectory.
[0115] After obtaining the estimated risk operation trajectories and their label knowledge points within each focused area, the server will further analyze these trajectories and extract the updated penetration path intervals from them. These intervals are the specific fund flow paths that the server believes have a higher risk.
[0116] For example, continuing the scenario of the previous step, the server now has a series of estimated risk operation trajectories with risk labels. Next, the server will analyze these trajectories, especially those marked as high-risk, such as the trajectories labeled with "high-frequency trading" and "large-amount transfer".
[0117] Through analysis, the server discovers that certain specific fund flow paths frequently appear in these high-risk trajectories, and these paths are the updated penetration path intervals. The server integrates these intervals to form an updated estimated risk interaction path graph, which not only includes the previously known risk paths but also new risk paths discovered through the analysis of the deep learning model.
[0118] In this way, the server completes the update of the risk interaction paths within the focused area, providing more accurate and comprehensive data support for subsequent risk prevention and control and supervision.
[0119] In a possible implementation manner, the method further includes:
[0120] Step A110, according to the second multi-layer perceptron, determine the risk attention nodes of the estimated risk operation trajectories within each focused area, the trajectory cost values of the estimated risk operation trajectories, and the deviation degrees of the estimated risk operation trajectories relative to the benchmark path intervals of the estimated risk interaction paths.
[0121] Step A120, according to the risk attention nodes, the trajectory cost values, and the deviation degrees of the estimated risk operation trajectories, determine the path state descriptions of the estimated risk operation trajectories within each focused area. The path state descriptions reflect the specific risk state patterns of the estimated risk operation trajectories.
[0122] In this embodiment, the server will conduct a more in-depth analysis of the estimated risk operation trajectories within each focused area according to the output results of the second multi-layer perceptron. This step mainly includes determining three key indicators: risk attention nodes, trajectory cost values, and deviation degrees.
[0123] Risk attention nodes are the points with higher risks in the estimated risk operation trajectories, which can be the key links of fund transfer or the starting points of abnormal transactions. The server identifies these risk attention nodes by analyzing the transaction data in the trajectories, the connection relationships between nodes, and the fund flow patterns.
[0124] The trajectory cost value is a quantitative indicator used to measure the risk degree of the entire estimated risk operation trajectory. The server will comprehensively consider multiple factors such as the transaction amount, frequency, and historical behaviors of the nodes involved in the estimated risk operation trajectory to calculate the cost value. The higher the cost value, the greater the potential risk of the trajectory.
[0125] The deviation is used to measure the degree of deviation of the estimated risk operation trajectory from the benchmark path interval of the estimated risk interaction path. The server calculates the deviation by comparing the differences between the trajectory and the benchmark path in terms of structure, capital flow pattern, etc. A large deviation means that the trajectory has a significant difference from the conventional capital flow pattern, which may hide higher risks.
[0126] For example, in a complex financial network, the server is analyzing a specific focus area where there are multiple estimated risk operation trajectories. For one of the trajectories, the server identifies several risk attention nodes, which are important hubs for capital transfer and have shown abnormal capital flows recently. At the same time, the server calculates that the cost value of this trajectory is relatively high, indicating that its overall risk level cannot be ignored. In addition, by comparing the deviation of this trajectory from the benchmark path, the server finds that it has significant differences from the conventional path in terms of the frequency and pattern of capital flow.
[0127] After collecting information such as risk attention nodes, trajectory cost values, and deviations, the server will comprehensively consider these metrics to determine the path status description of the estimated risk operation trajectories in each focus area. This description aims to reflect the specific risk status pattern of the trajectories and provide intuitive and comprehensive risk assessment results for risk managers.
[0128] Continuing with the scenario from the previous step, the server generates a path status description for that specific estimated risk operation trajectory based on the information collected. The description clearly indicates the location and nature of the risk attention nodes, the overall risk level of the trajectory (reflected by the cost value), and the degree of deviation of the trajectory from the conventional path. Such a description helps risk managers quickly understand the risk situation of the trajectory and thus take targeted prevention and control measures. For example, they may decide to conduct more rigorous monitoring of these risk attention nodes or conduct a more in-depth investigation of the capital flows involved in the entire trajectory.
[0129] In one possible implementation manner, step S140 includes:
[0130] Step S141, determining the risk attention nodes of the updated penetration path interval based on the path status description of the updated penetration path interval.
[0131] Step S142, according to the order of the focus areas corresponding to the updated estimated risk interaction path, loading the set of risk attention nodes of the updated penetration path interval in the focus area into the message queue of the risk control server to generate the risk behavior recognition data of the capital chain interaction behavior data.
[0132] In this embodiment, after the server has completed the update of the estimated risk interaction path and the path status description, it will determine the risk attention nodes in the updated penetration path interval based on these status descriptions. These nodes are the key points that exhibit abnormal or high-risk behaviors during the fund interaction process, and can be the starting point, ending point, or key transfer station of abnormal fund flows.
[0133] For example, assume that in a complex fund chain network, the server has updated an estimated risk interaction path through a multi-layer perceptron model and generated a detailed path status description for this path. In these descriptions, the server discovers that certain nodes have significant abnormalities in terms of fund flow frequency, amount size, or counterparty, etc. These abnormal nodes are marked as risk attention nodes because they can be potential risk sources or key links for risk amplification.
[0134] After determining the risk attention nodes, the server will organize and sort these node sets according to the order of the focused areas they belong to. Subsequently, the server will load these ordered risk attention node sets into the message queue of the risk control server. The purpose of this step is to transmit the latest risk identification results to the risk control system so that it can take corresponding risk control measures in real time.
[0135] For example, continuing with the scenario in the previous step, after the server identifies the risk attention nodes, it will sort and organize them according to the focused areas they belong to. For instance, if a certain focused area contains multiple risk attention nodes, these nodes will be grouped into the same set. Subsequently, the server will load these risk attention node sets into the message queue of the risk control server in the order of the focused areas. In this way, the risk control system can quickly respond based on these latest risk identification data, such as conducting real-time monitoring of high-risk nodes, restricting their trading behaviors, or triggering further risk assessment processes.
[0136] Through the above steps, the server can transmit the risk behavior identification data in the fund chain interaction behavior data to the risk control system in real time, thereby effectively improving the timeliness and accuracy of risk prevention and control.
[0137] In a possible implementation manner, the method further includes:
[0138] Step S101, loading the session network structure data of the template fund chain interaction behavior data into the first estimation network to determine the estimated risk interaction path of the template fund chain interaction behavior data. The template fund chain interaction behavior data carries a risk interaction path.
[0139] In this embodiment, the server first loads the session network structure data of the template fund chain interaction behavior data into the first estimation network. The template fund chain interaction behavior data is preset and carries known risk interaction paths, which are used as reference standards to train and optimize the model.
[0140] For example, assume there is a standard financial transaction template that contains a series of known risk transaction behaviors. The server will input the transaction network structure data in this template fund chain interaction behavior data into the first estimation network. Through the calculation and processing of the network, the estimated risk interaction path of this template fund chain is obtained.
[0141] Step S102: Generate focus nodes corresponding to the estimated risk interaction path according to the focus positioning network, and determine the focus areas where each focus node is located. The focus nodes reflect the context nodes of the estimated risk interaction path on the template fund chain interaction behavior data, and at least part of the focus areas include the penetration path intervals of the estimated risk interaction path.
[0142] Next, the server will use the focus positioning network to generate corresponding focus nodes for the estimated risk interaction path obtained in the previous step. These focus nodes reflect the context nodes of the estimated risk interaction path on the template fund chain interaction behavior data, that is, the key nodes closely related to the risk path. At the same time, the server will also determine the focus areas where each focus node is located, and at least part of these areas include the penetration path intervals of the estimated risk interaction path.
[0143] For example, in the estimated risk interaction path of the template fund chain interaction behavior data, the server identifies several key transaction nodes through the focus positioning network. These nodes are considered important links in risk interaction. The server further determines the focus areas where these nodes are located. These areas can be dense areas of fund transfer or frequent areas of abnormal transactions.
[0144] Step S103: Load the session network structure data of the template fund chain interaction behavior data and the context nodes corresponding to the focus areas in the template fund chain interaction behavior data into the second estimation network to generate an updated estimated risk interaction path.
[0145] Subsequently, the server will load the session network structure data of the template fund chain interaction behavior data and the context nodes corresponding to the focus areas determined in the previous step into the second estimation network together. Through the calculation and processing of the second estimation network, the server will obtain an updated estimated risk interaction path.
[0146] For example, after obtaining the focused area and its context nodes, the server inputs this data into the second estimation network. Through the deep learning and calculations of the network, the server obtains a more accurate and refined risk interaction path, which is updated and optimized based on the original one.
[0147] Step S104: Determine a first model error parameter according to the risk interaction path and the potential risk link. The potential risk link is estimated by the first estimation network.
[0148] Next, the server will determine a first model error parameter according to the original risk interaction path and the potential risk link estimated by the first estimation network. This first model error parameter reflects the accuracy of the first estimation network in predicting the risk link.
[0149] For example, the server conducts a comparative analysis of the original risk interaction path and the potential risk link predicted by the first estimation network, and determines the first model error parameter by calculating the difference between the two. This first model error parameter helps the server understand the performance of the first estimation network in risk prediction.
[0150] Step S105: Determine a second model error parameter based on the penetration path interval within the focused area corresponding to the estimated risk interaction path and the updated penetration path interval within the focused area of the updated estimated risk interaction path.
[0151] Then, the server will determine a second model error parameter based on the penetration path interval within the focused area corresponding to the original estimated risk interaction path and the updated penetration path interval within the focused area of the updated estimated risk interaction path. This parameter reflects the accuracy of the second estimation network in updating the risk interaction path.
[0152] For example, the server conducts a comparative analysis of the original penetration path interval and the updated penetration path interval, and determines the second model error parameter by calculating the difference between the two. This second model error parameter helps the server understand the performance of the second estimation network in risk path update.
[0153] Step S106: Determine a model error parameter according to the first model error parameter and the second model error parameter, and optimize the parameters of the capital chain risk behavior recognition model according to the model error parameter.
[0154] Finally, the server determines the overall model error parameter based on the first model error parameter and the second model error parameter, which comprehensively considers the performance of the first estimation network and the second estimation network. The server optimizes the parameters of the capital chain risk behavior identification model according to this model error parameter to improve the accuracy of the model in risk identification and prediction.
[0155] For example, after comprehensively analyzing the first model error parameter and the second model error parameter, the server obtains the overall model error parameter. According to this model error parameter, the server conducts targeted parameter optimization and adjustment on the capital chain risk behavior identification model to improve its performance in future risk identification and prediction tasks.
[0156] Figure 2 The hardware structure diagram of the artificial intelligence-based capital chain risk behavior identification system 100 provided by the embodiments of the present application for implementing the above artificial intelligence-based capital chain risk behavior identification method is shown. As Figure 2 shown, the artificial intelligence-based capital chain risk behavior identification system 100 may include a processor 110, a machine-readable storage medium 120, a bus 130, and a communication unit 140.
[0157] In a possible design, the artificial intelligence-based capital chain risk behavior identification system 100 can be a single server or a server group. The server group can be centralized or distributed (for example, the artificial intelligence-based capital chain risk behavior identification system 100 can be a distributed system). In some embodiments, the artificial intelligence-based capital chain risk behavior identification system 100 can be local or remote. For example, the artificial intelligence-based capital chain risk behavior identification system 100 can access the information and / or data stored in the machine-readable storage medium 120 via a network. Again, for example, the artificial intelligence-based capital chain risk behavior identification system 100 can be directly connected to the machine-readable storage medium 120 to access the stored information and / or data. In some embodiments, the artificial intelligence-based capital chain risk behavior identification system 100 can be implemented on the artificial intelligence-based capital chain risk behavior identification system. Only by way of example, the artificial intelligence-based capital chain risk behavior identification system can include a private cloud, a public cloud, a hybrid cloud, a community cloud, a distributed cloud, an internal cloud, a multi-layer cloud, etc. or any combination thereof.
[0158] The machine-readable storage medium 120 may store data and / or instructions. In some embodiments, the machine-readable storage medium 120 may store data obtained from an external terminal. In some embodiments, the machine-readable storage medium 120 may store data and / or instructions for the artificial intelligence-based fund chain risk behavior identification system 100 to execute or use to complete the exemplary methods described in this application.
[0159] In a specific implementation process, one or more processors 110 execute the computer-executable instructions stored in the machine-readable storage medium 120, so that the processors 110 can execute the artificial intelligence-based fund chain risk behavior identification method in the above method embodiments. The processors 110, the machine-readable storage medium 120, and the communication unit 140 are connected through a bus 130. The processors 110 can be used to control the sending and receiving actions of the communication unit 140.
[0160] For the specific implementation process of the processors 110, reference may be made to the various method embodiments executed by the artificial intelligence-based fund chain risk behavior identification system 100 described above. Their implementation principles and technical effects are similar, and will not be elaborated here in this embodiment.
[0161] In addition, an embodiment of this application also provides a readable storage medium, in which computer-executable instructions are preset. When a processor executes the computer-executable instructions, the artificial intelligence-based fund chain risk behavior identification method described above is implemented.
[0162] It should be noted that, in order to simplify the description of this application disclosure and thus help the understanding of one or more invention embodiments, in the foregoing description of the embodiments of this application, sometimes multiple features are merged into one embodiment, drawing, or description thereof.
Claims
1. An artificial intelligence-based method for identifying risk behaviors in the capital chain, characterized in that, Implemented through a fund chain risk behavior identification model, the fund chain risk behavior identification model includes a first estimation network, a second estimation network, and a focusing and positioning network; the method includes: Loading the session network structure data of the fund chain interaction behavior data into the first estimation network to determine the estimated risk interaction path of the fund chain interaction behavior data. The fund chain interaction behavior data refers to the data recording fund flows, transfers, and transaction activities, including information about both parties to the transaction, transaction time, and transaction amount information, reflecting the flow of funds between different entities; Generating, according to the focusing and positioning network, the focusing nodes corresponding to the estimated risk interaction path and determining the focusing area where each focusing node is located; the focusing nodes reflect the context nodes of the estimated risk interaction path on the fund chain interaction behavior data, and at least part of the penetration path interval of the estimated risk interaction path is included in the focusing area; Loading the session network structure data of the fund chain interaction behavior data and the context nodes corresponding to the focusing area in the fund chain interaction behavior data into the second estimation network to generate an updated estimated risk interaction path; the updated penetration path interval is included in the focusing area corresponding to the updated estimated risk interaction path; Loading the updated estimated risk interaction path into the message queue of the risk control server to determine the risk behavior identification data of the fund chain interaction behavior data; The generating, according to the focusing and positioning network, the focusing nodes corresponding to the estimated risk interaction path and determining the focusing area where each focusing node is located includes: Determining the focusing node parameter values corresponding to the estimated risk interaction path according to the focusing and positioning network; Traversing the estimated risk interaction path and performing focusing node matching according to the focusing node parameter values to generate the focusing nodes corresponding to the estimated risk interaction path; Respectively using the focusing nodes as the reference nodes of the focusing area to determine the focusing area where each focusing node is located.
2. The method for identifying risk behaviors of the capital chain based on artificial intelligence according to claim 1, wherein, The determining, according to the focusing and positioning network, the focusing node parameter values corresponding to the estimated risk interaction path includes: Determining the focusing node parameter values corresponding to the estimated risk interaction path according to the focusing and positioning network based on the cost value of the estimated risk interaction path, where the focusing node parameter values are proportional to the cost value.
3. The method for identifying risk behaviors of the capital chain based on artificial intelligence according to any one of claims 1-2, characterized in that The first estimation network includes a first multi-layer perceptron; The loading the session network structure data of the fund chain interaction behavior data into the first estimation network to determine the estimated risk interaction path of the fund chain interaction behavior data includes: Performing pattern analysis on the session network structure data of the fund chain interaction behavior data according to the first multi-layer perceptron to estimate X potential risk links and the risk labels of each potential risk link; X is an integer greater than 0; Based on the risk path characteristics of the X potential risk links and the risk tags of each of the potential risk links, determine the estimated risk interaction path of the fund chain interaction behavior data from the potential risk links.
4. The method for identifying risk behaviors of the capital chain based on artificial intelligence according to any one of claims 1-2, characterized in that, The second estimation network includes a second multi-layer perceptron; Loading the session network structure data of the fund chain interaction behavior data and the focused area into the context nodes corresponding to the fund chain interaction behavior data in the second estimation network to generate an updated estimated risk interaction path includes: Map the context nodes corresponding to the focused area in the fund chain interaction behavior data onto the session network structure data of the fund chain interaction behavior data to determine the penetration path characteristics of the penetration path interval within the focused area; Based on the penetration path characteristics, update the penetration path interval within the focused area based on the second multi-layer perceptron to generate the updated estimated risk interaction path.
5. The method for identifying risk behaviors of the capital chain based on artificial intelligence according to claim 4, wherein, The updating the penetration path interval within the focused area based on the second multi-layer perceptron according to the penetration path characteristics to generate the updated estimated risk interaction path includes: Based on the penetration path characteristics, update the penetration path interval within the focused area based on the second multi-layer perceptron to generate an estimated risk operation trajectory within each focused area and label knowledge points of each estimated risk operation trajectory; Based on the label knowledge points of the estimated risk operation trajectories within each focused area, extract updated penetration path intervals from each of the estimated risk operation trajectories to generate the updated estimated risk interaction path.
6. The method for identifying risk behaviors of the capital chain based on artificial intelligence according to claim 4, characterized in that, The method further includes: Based on the second multi-layer perceptron, determine the risk attention nodes of the estimated risk operation trajectories within each focused area, the trajectory cost values of the estimated risk operation trajectories, and the deviation degrees of the estimated risk operation trajectories from the reference path interval of the estimated risk interaction path; Based on the risk attention nodes, the trajectory cost values, and the deviation degrees of the estimated risk operation trajectories, determine the path state description of the estimated risk operation trajectories within each focused area; the path state description reflects the specific risk state mode of the estimated risk operation trajectories.
7. The method for identifying risk behaviors of the capital chain based on artificial intelligence according to claim 6, wherein Loading the updated estimated risk interaction path into the message queue of the risk control server to determine the risk behavior identification data of the fund chain interaction behavior data includes: Based on the path state description of the updated penetration path interval, determine the risk attention nodes of the updated penetration path interval; According to the order of the focused areas corresponding to the updated estimated risk interaction path, load the set of risk attention nodes of the updated penetration path interval within the focused area into the message queue of the risk control server to generate the risk behavior identification data of the fund chain interaction behavior data.
8. The method for identifying risk behaviors of the capital chain based on artificial intelligence according to claim 1, characterized in that, The method further includes: Load the session network structure data of the template fund chain interaction behavior data into the first estimation network, and determine the estimated risk interaction path of the template fund chain interaction behavior data; the template fund chain interaction behavior data carries the risk interaction path. Generate, according to the focusing positioning network, the focusing nodes corresponding to the estimated risk interaction path, and determine the focusing areas where each of the focusing nodes is located; the focusing nodes reflect the context nodes of the estimated risk interaction path on the template fund chain interaction behavior data, and at least part of the focusing areas include the penetration path intervals of the estimated risk interaction path. Load the session network structure data of the template fund chain interaction behavior data and the context nodes corresponding to the focusing areas in the template fund chain interaction behavior data into the second estimation network to generate an updated estimated risk interaction path. Determine the first model error parameter according to the risk interaction path and the potential risk link; the potential risk link is estimated by the first estimation network. Determine the second model error parameter based on the penetration path interval within the focusing area corresponding to the estimated risk interaction path and the updated penetration path interval within the focusing area of the updated estimated risk interaction path. Determine the model error parameter according to the first model error parameter and the second model error parameter, and optimize the parameters of the fund chain risk behavior recognition model according to the model error parameter.
9. An artificial intelligence-based risk behavior identification system for the capital chain, characterized in that, The artificial intelligence-based fund chain risk behavior recognition system includes a processor and a memory, the memory is connected to the processor, the memory is used to store programs, instructions or codes, and the processor is used to execute the programs, instructions or codes in the memory to implement the artificial intelligence-based fund chain risk behavior recognition method according to any one of claims 1-8 above.
Citation Information
Patent Citations
Risk identification method and device
CN109003089A
Transaction risk identification method, device and system
CN113487427A