Transaction index anomaly detection method and device based on index threshold, and electronic equipment

By combining fixed threshold and year-on-year threshold anomaly detection strategies, the thresholds are dynamically adjusted to adapt to different business scenarios, solving the false alarm and false negative problems of traditional fixed threshold detection methods and achieving higher accuracy and stability in transaction monitoring.

CN119722314BActive Publication Date: 2025-11-11INDUSTRIAL AND COMMERCIAL BANK OF CHINA
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411792300.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-06
Publication Date
2025-11-11
Estimated Expiration
2044-12-06

AI Technical Summary

Technical Problem

Traditional fixed-threshold anomaly detection methods cannot adapt to the diverse business scenarios of different partners, leading to false alarms, missed alarms, and frequent alarms, which affects the accuracy and effectiveness of transaction monitoring.

Method used

A transaction indicator anomaly detection method based on indicator thresholds is adopted, which combines a fixed threshold anomaly detection strategy and a year-on-year threshold anomaly detection strategy. By analyzing real-time indicator data and comparing it with preset thresholds or historical data, the thresholds are dynamically adjusted to adapt to different business scenarios.

Benefits of technology

It improves the accuracy and timeliness of transaction anomaly detection, reduces false alarms and missed alarms, and enhances the stability and security of transactions between financial institutions and their partners.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119722314B_ABST
    Figure CN119722314B_ABST
Patent Text Reader

Abstract

This invention discloses a method, device, and electronic device for detecting anomalies in trading indicators based on indicator thresholds, relating to the field of financial technology. The method includes: collecting financial trading data according to an indicator anomaly detection strategy selected by the business end; sending the indicator anomaly detection strategy and financial trading data to a trading anomaly detection model; the trading anomaly detection model analyzing the real-time indicator data values ​​corresponding to each financial trading indicator against a preset fixed threshold, or analyzing the increase or decrease ratio of the indicator data values ​​against a corresponding preset percentage threshold to obtain a trading anomaly detection result; and triggering a threshold adjustment notification to the business end when preset anomaly detection switch and threshold adjustment requirements are met, receiving the threshold adjustment parameters fed back from the business end, and feeding them back to the trading anomaly detection model. This invention solves the technical problem of fixed threshold anomaly detection mechanisms in related technologies, which are prone to false alarms and have low accuracy.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of financial technology or other related fields, and more specifically, to a method, apparatus, and electronic device for detecting anomalies in trading indicators based on indicator thresholds. Background Technology

[0002] With the digital transformation of the financial industry and the widespread use of API (Application Programming Interface) services, monitoring between financial institutions and external partners via API interfaces has become increasingly important. The number of partners accessing API services is growing rapidly, and each partner has different business scenarios and transaction characteristics. This makes it difficult for a single fixed-threshold anomaly detection mechanism to meet the personalized needs of all partners. For example, fixed-threshold anomaly detection may generate false positives during peak business periods for some partners, while missing anomalies during off-peak periods, which seriously affects the accuracy and effectiveness of transaction monitoring.

[0003] Traditional fixed-threshold anomaly detection methods monitor metrics based on preset thresholds. This "one-size-fits-all" strategy cannot adapt to the differences in business scenarios among different partners. That is, all partner transactions were based on a single fixed threshold, and the anomaly alarms could not truly reflect the transaction metrics of each partner. Furthermore, because the single alarm threshold could not be personalized to adapt to the actual business anomalies of each partner, it caused problems such as false alarms, missed alarms, and frequent alarms.

[0004] Fixed-threshold anomaly detection mechanisms have limitations, particularly their inflexibility and inaccuracy when handling diverse business scenarios across different partners. Specifically, this invention proposes a transaction anomaly detection method with customizable thresholds. By introducing both fixed-threshold and year-over-year threshold anomaly detection strategies, it aims to overcome the limitations of a single fixed threshold, improve the accuracy and timeliness of transaction anomaly detection, reduce false positives and false negatives, and ultimately enhance the stability and security of transactions between financial institutions and their partners.

[0005] As the business expands and the number of partners integrating with the API service grows, each partner's transaction curves differ. The original abnormal fluctuation alarms based on a single fixed threshold can no longer reflect the true business situation of different partners. Previously, all partner transactions were based on a single fixed threshold, and its abnormal alarms failed to accurately reflect each partner's transaction metrics. Furthermore, because the single alarm threshold could not be personalized to adapt to the actual business anomalies of each partner, it resulted in false alarms, missed alarms, and frequent alarms.

[0006] There is currently no effective solution to the above problems. Summary of the Invention

[0007] This invention provides a method, apparatus, and electronic device for detecting anomalies in trading indicators based on indicator thresholds, in order to at least solve the technical problems of fixed threshold anomaly detection mechanisms in related technologies, which are prone to false alarms and have low accuracy.

[0008] To achieve the above objectives, according to one aspect of this application, a method for detecting anomalies in trading indicators based on indicator thresholds is provided, comprising: receiving an indicator anomaly detection strategy selected by a business terminal, wherein the indicator anomaly detection strategy includes: a fixed threshold anomaly detection strategy and a year-on-year threshold anomaly detection strategy, wherein the fixed threshold anomaly detection strategy refers to a strategy that compares the real-time indicator data value corresponding to each financial trading indicator with a preset fixed threshold corresponding to the financial trading indicator, and the year-on-year threshold anomaly detection strategy refers to a strategy that compares the sum of trading data of the financial trading indicator in the current time period with the sum of trading data in the same time period in a specified historical period, and compares the calculated increase or decrease ratio with a preset percentage threshold corresponding to the financial trading indicator; and collecting data on the current time period based on the selected indicator anomaly detection strategy. The system collects financial transaction data and sends the anomaly detection strategy and the financial transaction data to a transaction anomaly detection model. The model analyzes the real-time indicator data values ​​of each financial transaction indicator against their corresponding preset fixed thresholds, or analyzes the percentage increase or decrease of each financial transaction indicator's data value against its corresponding preset percentage threshold, to obtain transaction anomaly detection results. If the transaction anomaly detection results meet the preset anomaly detection switch and threshold adjustment requirements, a threshold adjustment notification is triggered to the business terminal. Upon receiving the threshold adjustment notification, the business terminal analyzes the transaction indicators whose thresholds need adjustment and the target threshold parameters based on the real-time transaction monitoring curve to obtain threshold adjustment parameters. The business terminal receives the threshold adjustment parameters fed back from the business terminal and feeds them back to the transaction anomaly detection model.

[0009] Optionally, when the transaction anomaly detection model executes the fixed threshold anomaly detection strategy, it includes: triggering a first type of alarm when the real-time indicator data value of the fixed threshold anomaly detection strategy is lower than a first preset fixed threshold, or when the real-time indicator data value of the fixed threshold anomaly detection strategy is higher than a second preset fixed threshold, wherein the second preset fixed threshold is greater than the first preset fixed threshold; triggering a second type of alarm when the cumulative number of the first type of alarms within a preset time period reaches a first type of alarm cumulative threshold; and triggering a threshold adjustment notification when the cumulative number of the second type of alarms within a preset time period reaches a second type of alarm cumulative threshold.

[0010] Optionally, when executing the year-on-year threshold anomaly detection strategy, the transaction anomaly detection model includes: obtaining the first sum of transaction data for the financial transaction indicator within the current time period, and extracting the second sum of transaction data for the same historical time period corresponding to the current time period within a first historical specified time period and the third sum of transaction data for the same historical time period within a second historical specified time period from the transaction database; calculating the increase ratio or decrease ratio based on the first sum of transaction data, the second sum of transaction data, and the third sum of transaction data; triggering a first type of alarm for an indicator increase when both the increase ratio and the decrease ratio are greater than 0, and the increase ratio is greater than a first preset percentage threshold, and the decrease ratio is greater than a second preset percentage threshold; or triggering a first type of alarm for an indicator decrease when both the increase ratio and the decrease ratio are less than 0, and the absolute value of the increase ratio is greater than a first preset percentage threshold, and the absolute value of the decrease ratio is greater than a second preset percentage threshold.

[0011] Optionally, when the transaction anomaly detection model executes the year-on-year threshold anomaly detection strategy, it further includes: triggering a second type of alarm when the number of first type alarms with the indicator rising reaches the first type of alarm cumulative threshold within a preset time period, or when the number of first type alarms with the indicator falling reaches the first type of alarm cumulative threshold within a preset time period; and triggering a threshold adjustment notification when the number of second type alarms reaches the second type of alarm cumulative threshold within a preset time period.

[0012] Optionally, after receiving the threshold adjustment parameters, the transaction anomaly detection model further includes: obtaining the partner identifier corresponding to the business end, and extracting the financial transaction indicators and partner business scenarios associated with the partner identifier; and updating the preset fixed threshold, preset percentage threshold, detection frequency, detection duration, alarm accumulation threshold, and comparison symbol stored in the transaction anomaly detection model based on all the extracted financial transaction indicators and partner business scenarios.

[0013] Optionally, before receiving the anomaly detection strategy selected by the business terminal, the method further includes: the business terminal configuring the preset fixed threshold and the corresponding comparison operator based on historical transaction data, the tolerance range of each financial transaction indicator and the business scenario of the partner, and configuring the preset percentage threshold and the corresponding comparison operator.

[0014] Optionally, the financial transaction metrics include at least one of the following: transaction volume, success rate, and time consumption, wherein the transaction volume is the number of financial transactions that occur within the current time period, the success rate represents the percentage of successful transactions, and the time consumption represents the average processing time for each transaction.

[0015] According to another aspect of the present invention, a transaction indicator anomaly detection device based on indicator thresholds is also provided, comprising: a detection strategy receiving unit, configured to receive an indicator anomaly detection strategy selected by a business terminal, wherein the indicator anomaly detection strategy includes: a fixed threshold anomaly detection strategy and a year-on-year threshold anomaly detection strategy, wherein the fixed threshold anomaly detection strategy refers to a strategy that compares the real-time indicator data value corresponding to each financial transaction indicator with a preset fixed threshold corresponding to the financial transaction indicator, and the year-on-year threshold anomaly detection strategy refers to a strategy that compares the sum of transaction data of the financial transaction indicator in the current time period with the sum of transaction data in the same time period in a historical specified time period, and compares the calculated increase ratio or decrease ratio with a preset percentage threshold corresponding to the financial transaction indicator; and a model analysis unit, configured to collect financial transaction data of the current time period according to the selected indicator anomaly detection strategy. The system uses data processing and sends the anomaly detection strategy and financial transaction data to a transaction anomaly detection model. The model analyzes the real-time data values ​​of each financial transaction indicator against a preset fixed threshold, or analyzes the percentage increase or decrease of each financial transaction indicator against a preset percentage threshold to obtain the transaction anomaly detection result. A threshold adjustment unit is used to trigger a threshold adjustment notification to the business terminal when the transaction anomaly detection result meets preset anomaly detection switch and threshold adjustment requirements. After receiving the threshold adjustment notification, the business terminal analyzes the transaction indicators whose thresholds need to be adjusted and the target threshold parameters based on the real-time transaction monitoring curve to obtain the threshold adjustment parameters. A threshold feedback unit is used to receive the threshold adjustment parameters fed back by the business terminal and feed them back to the transaction anomaly detection model.

[0016] Optionally, the transaction anomaly detection model in the transaction indicator anomaly detection device based on indicator thresholds, when executing a fixed threshold anomaly detection strategy, includes: a first triggering unit, configured to trigger a first type of alarm when the real-time indicator data value of the fixed threshold anomaly detection strategy is lower than a first preset fixed threshold, or when the real-time indicator data value of the fixed threshold anomaly detection strategy is higher than a second preset fixed threshold, wherein the second preset fixed threshold is greater than the first preset fixed threshold; a second triggering unit, configured to trigger a second type of alarm when the cumulative number of the first type of alarms within a preset time period reaches a first type of alarm cumulative threshold; and a third triggering unit, configured to trigger a threshold adjustment notification when the cumulative number of the second type of alarms within a preset time period reaches a second type of alarm cumulative threshold.

[0017] Optionally, the transaction anomaly detection model in the transaction indicator anomaly detection device based on indicator thresholds, when executing the year-on-year threshold anomaly detection strategy, includes: a data summation acquisition unit, used to acquire the first transaction data summation of the financial transaction indicator within the current time period, and extract the second transaction data summation of the same historical time period corresponding to the current time period within the first historical specified time period and the third transaction data summation of the same historical time period within the second historical specified time period from the transaction database; a calculation unit, used to calculate the increase ratio or decrease ratio based on the first transaction data summation, the second transaction data summation, and the third transaction data summation; and a fourth triggering unit, used to trigger a first type of alarm for indicator increase when both the increase ratio and the decrease ratio are greater than 0, and the increase ratio is greater than a first preset percentage threshold, and the decrease ratio is greater than a second preset percentage threshold; or, when both the increase ratio and the decrease ratio are less than 0, and the absolute value of the increase ratio is greater than a first preset percentage threshold, and the absolute value of the decrease ratio is greater than a second preset percentage threshold, triggering a first type of alarm for indicator decrease.

[0018] Optionally, when the transaction anomaly detection model in the transaction indicator anomaly detection device based on indicator thresholds executes the year-on-year threshold anomaly detection strategy, it further includes: a fifth triggering unit, used to trigger a second type of alarm when the number of first type of alarms for an increase in the indicator reaches the first type of alarm cumulative threshold within a preset time period, or when the number of first type of alarms for a decrease in the indicator reaches the first type of alarm cumulative threshold within a preset time period; and a sixth triggering unit, used to trigger a threshold adjustment notification when the number of second type of alarms reaches the second type of alarm cumulative threshold within a preset time period.

[0019] Optionally, the transaction indicator anomaly detection device based on indicator thresholds further includes: a partner identifier acquisition unit, used to acquire the partner identifier corresponding to the business end after the transaction anomaly detection model receives the threshold adjustment parameters, and extract the financial transaction indicators and partner business scenarios associated with the partner identifier; and a parameter update unit, used to update the preset fixed threshold, preset percentage threshold, detection frequency, detection duration, alarm accumulation threshold, and comparison symbol stored in the transaction anomaly detection model based on all the extracted financial transaction indicators and partner business scenarios.

[0020] Optionally, the transaction indicator anomaly detection device based on indicator thresholds further includes: a threshold configuration unit, used to configure the preset fixed threshold and corresponding comparison operator by the business terminal according to historical transaction data, the tolerance range of each financial transaction indicator and the business scenario of the partner before receiving the indicator anomaly detection strategy selected by the business terminal, and to configure the preset percentage threshold and corresponding comparison operator.

[0021] Optionally, the financial transaction metrics include at least one of the following: transaction volume, success rate, and time consumption, wherein the transaction volume is the number of financial transactions that occur within the current time period, the success rate represents the percentage of successful transactions, and the time consumption represents the average processing time for each transaction.

[0022] According to another aspect of the present invention, a computer-readable storage medium is also provided, the computer-readable storage medium including a stored computer program, wherein, when the computer program is executed, it controls the device where the computer-readable storage medium is located to execute the above-described transaction indicator anomaly detection method based on indicator threshold.

[0023] According to another aspect of the present invention, an electronic device is also provided, including one or more processors and a memory, the memory being used to store one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors cause the one or more processors to implement the above-described method for detecting abnormal trading indicators based on indicator thresholds.

[0024] According to another aspect of the present invention, a computer program product is also provided, including a computer program that, when executed by a processor, implements the steps of the above-described method for detecting anomalies in trading indicators based on indicator thresholds.

[0025] In this disclosure, the system first receives the indicator anomaly detection strategy selected by the business end. Then, based on the selected indicator anomaly detection strategy, it collects financial transaction data for the current time period and sends the indicator anomaly detection strategy and financial transaction data to the transaction anomaly detection model. The transaction anomaly detection model analyzes the real-time indicator data values ​​corresponding to each financial transaction indicator and their corresponding preset fixed thresholds, or analyzes the increase or decrease ratio of the indicator data values ​​of each financial transaction indicator and their corresponding preset percentage thresholds to obtain the transaction anomaly detection results. If the transaction anomaly detection results meet the preset anomaly detection switch and threshold adjustment requirements, a threshold adjustment notification is triggered to the business end. After receiving the threshold adjustment notification, the business end analyzes the transaction indicators whose thresholds need to be adjusted and the target threshold parameters based on the real-time transaction monitoring curve to obtain the threshold adjustment parameters. It then receives the threshold adjustment parameters fed back by the business end and feeds the threshold adjustment parameters back to the transaction anomaly detection model.

[0026] Based on the above-mentioned information, when a large number of alarms or false alarms are detected, a threshold adjustment notification will be triggered. The business side can analyze the business situation based on the real-time transaction monitoring curve and flexibly adjust various threshold parameters to ensure the accuracy of the transaction monitoring strategy. This can solve the technical problem that fixed threshold anomaly detection mechanisms in related technologies are prone to false alarms and have low accuracy. Attached Figure Description

[0027] The accompanying drawings, which are included to provide a further understanding of the invention and form part of this application, illustrate exemplary embodiments of the invention and, together with their description, serve to explain the invention and do not constitute an undue limitation thereof. In the drawings:

[0028] Figure 1 A hardware structure block diagram of a computer terminal (or mobile device) for implementing a trading indicator anomaly detection method based on indicator thresholds is shown.

[0029] Figure 2 This is a flowchart of an optional trading indicator anomaly detection method based on indicator threshold according to an embodiment of the present invention;

[0030] Figure 3 This is a flowchart of another optional transaction anomaly detection method based on indicator thresholds according to an embodiment of the present invention;

[0031] Figure 4 This is a schematic diagram of an optional trading indicator anomaly detection device based on indicator threshold according to an embodiment of the present invention;

[0032] Figure 5 This is a structural block diagram of an electronic device according to an embodiment of this application. Detailed Implementation

[0033] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.

[0034] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0035] It should be noted that the trading indicator anomaly detection method and device based on indicator thresholds in this disclosure can be used in the fintech field to achieve customizable thresholds for trading indicator anomaly detection based on fintech, and can also be used in any field other than fintech to achieve customizable thresholds for trading indicator anomaly detection based on fintech. This disclosure does not limit the application field of the trading indicator anomaly detection method and device based on indicator thresholds.

[0036] It should be noted that the information collected in this public disclosure (including but not limited to equipment information, partner information, user equipment information, and user personal information) and data (including but not limited to data used for analysis, stored data, and displayed data) are information and data authorized by users or fully authorized by all parties. Furthermore, the collection, storage, use, processing, transmission, provision, disclosure, and application of this data comply with the relevant laws, regulations, and standards of the relevant regions, necessary confidentiality measures have been taken, and it does not violate public order and good morals. Corresponding operation entry points are provided for users to choose to authorize or refuse. For example, this system has interfaces with relevant users or organizations. Before obtaining relevant information, a request to obtain the information needs to be sent to the aforementioned users or organizations through the interface, and the relevant information is obtained only after receiving consent from the aforementioned users or organizations.

[0037] It should be noted that in this disclosure, customer information is collected and analyzed, and users are provided with corresponding operation entry points to choose whether to agree to or reject the automated decision results; if the user chooses to reject, the process will proceed to the expert decision-making process.

[0038] The following embodiments of the present invention can be applied to various systems / applications / devices for detecting anomalies in trading indicators based on indicator thresholds. The present invention proposes a trading indicator anomaly detection method with customizable thresholds. By introducing a fixed threshold anomaly detection strategy and a year-on-year threshold anomaly detection strategy, it aims to overcome the limitations of a single fixed threshold, improve the accuracy and timeliness of trading anomaly detection, reduce false positives and false negatives, and thereby enhance the stability and security of transactions between financial institutions and their partners.

[0039] Under the fixed threshold anomaly detection strategy, this invention solves the problem that a single fixed threshold cannot adapt to the monitoring of transaction indicators in different business scenarios. By flexibly configuring detection parameters, including detection frequency, detection duration, alarm accumulation threshold, etc., on the business side according to historical transaction data and business needs, the accuracy of anomaly detection is ensured.

[0040] Under the year-on-year threshold anomaly detection strategy, this invention solves the problem of false alarms and false negatives in fixed threshold anomaly detection caused by large fluctuations in indicators such as trading volume at different times. By performing year-on-year analysis with trading data from the same historical period, a more reasonable threshold is used for anomaly detection, thereby improving the accuracy and reliability of the detection results.

[0041] The present invention will now be described in detail with reference to various embodiments.

[0042] Example 1

[0043] According to an embodiment of the present invention, an embodiment of a trading indicator anomaly detection method based on indicator thresholds is provided. It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Furthermore, although a logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in a different order than that shown here.

[0044] The method for detecting abnormal trading indicators based on indicator thresholds provided in Embodiment 1 of this application can be executed on a mobile terminal, computer terminal, or similar computing device. Figure 1 A hardware block diagram of a computer terminal (or mobile device) for implementing a trading indicator anomaly detection method based on indicator thresholds is shown. Figure 1 As shown, computer terminal 10 (or mobile device) may include one or more ( Figure 1 The processor 102 (which may include, but is not limited to, a microprocessor MCU (Microcontroller Unit) or a programmable logic device FPGA (Field Programmable Gate Array)) is illustrated using 102a, 102b, ..., 102n. It also includes a memory 104 for storing data and a transmission device 106 for communication functions. In addition, it may include: a display, an input / output interface (I / O interface), a Universal Serial Bus (USB) port (which may be included as one of the ports of a BUS bus), a network interface, a power supply, and / or a camera. Those skilled in the art will understand that... Figure 1 The structure shown is for illustrative purposes only and does not limit the structure of the aforementioned electronic device. For example, computer terminal 10 may also include... Figure 1 The more or fewer components shown, or having the same Figure 1 The different configurations shown.

[0045] It should be noted that the aforementioned one or more processors 102 and / or other data processing circuits are generally referred to herein as "data processing circuits". These data processing circuits may be embodied, in whole or in part, in software, hardware, firmware, or any other combination thereof. Furthermore, the data processing circuits may be a single, independent processing module, or may be integrated, in whole or in part, into any other element within the computer terminal 10 (or mobile device). As involved in the embodiments of this application, the data processing circuits serve as a processor control mechanism (e.g., selection of a variable resistor termination path connected to an interface).

[0046] The memory 104 can be used to store software programs and modules of application software, such as the program instructions / data storage device corresponding to the transaction indicator anomaly detection method based on indicator thresholds in this embodiment. The processor 102 executes various functional applications and data processing by running the software programs and modules stored in the memory 104, thereby realizing the aforementioned transaction indicator anomaly detection method based on indicator thresholds. The memory 104 may include high-speed random access memory, and may also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 104 may further include memory remotely located relative to the processor 102, and these remote memories can be connected to the computer terminal 10 via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.

[0047] The transmission device 106 is used to receive or send data via a network. Specific examples of the network described above may include a wireless network provided by the communication provider of the computer terminal 10. In one example, the transmission device 106 includes a Network Interface Controller (NIC), which can connect to other network devices via a base station to communicate with the Internet. In another example, the transmission device 106 may be a Radio Frequency (RF) module, used for wireless communication with the Internet.

[0048] The display can be, for example, a touchscreen liquid crystal display (LCD), which allows the user to interact with the user interface of the computer terminal 10 (or mobile device).

[0049] Under the above operating environment, the present invention provides, as follows: Figure 2 The method shown is a trading indicator anomaly detection method based on indicator thresholds. Figure 2 This is a flowchart of an optional trading indicator anomaly detection method based on indicator thresholds according to an embodiment of the present invention.

[0050] This invention proposes an alarm model with customizable thresholds for financial transaction monitoring indicators such as transaction volume, success rate, and time consumption. It provides two detection schemes: fixed threshold anomaly detection and year-on-year threshold anomaly detection, which are adapted to the monitoring capabilities of indicators with different characteristics. At the same time, the on / off switch and threshold parameters of the detection model can be manually adjusted and take effect in real time, which can effectively adapt to the differentiated business scenarios of partners.

[0051] It should be noted that the transaction indicator anomaly detection method of this application is applicable to diverse business scenarios of API interface transaction monitoring between financial institutions and their partners, such as financial transaction volume monitoring scenarios, transaction success rate monitoring scenarios, transaction time monitoring scenarios, real-time transaction risk control scenarios, and dynamic adjustment scenarios of transaction monitoring. In the financial transaction volume monitoring scenario, such as in retail payments, online lending, and insurance quoting, financial transaction volume exhibits significant fluctuations due to factors such as time, location, and holidays. For example, subway QR code payments see much higher transaction volumes during peak hours than during off-peak hours, while online insurance sales may significantly decrease during holidays. Through the year-on-year threshold anomaly detection strategy of this invention, the system can automatically compare the transaction volume of the current period with the transaction volume of the same historical period (e.g., 1 day ago, 7 days ago), calculate the percentage increase or decrease, and compare it with a preset percentage threshold, thereby accurately identifying periods of abnormal transaction volume fluctuations and reducing false alarms and missed alarms. For transaction success rate monitoring scenarios, such as in credit card applications, bank-enterprise cooperation, and cross-border transactions, the transaction success rate is affected not only by system performance but also by user behavior, the stability of partner services, and other factors. Using the fixed threshold anomaly detection strategy of this invention, the business side can set a reasonable success rate threshold. When the real-time transaction success rate is lower or higher than this threshold, the system automatically triggers an alarm, helping financial institutions quickly identify potential risks, such as partner system failures or fraudulent activities. For transaction time monitoring scenarios, such as high-frequency trading and real-time payments, transaction processing time has a significant impact on user experience and system performance. Anomalies in processing time may be caused by network latency, system bottlenecks, or increased partner response time. The fixed threshold anomaly detection strategy of this invention can monitor transaction time indicators in real time. Once a timeout exceeding a preset threshold is detected, an alarm is immediately triggered, enabling the technical team to quickly locate and resolve the problem, avoiding continuous negative impacts on business operations. For real-time transaction risk control scenarios, such as in the financial sector, timely identification and control of transaction risks are crucial, especially for high-risk scenarios such as large transactions and suspicious transactions. Through the transaction indicator anomaly detection method of this invention, financial institutions can monitor transaction data in real time. Once an anomaly is detected, immediate risk assessment and control measures are implemented, such as suspending transactions or increasing manual review, thereby effectively preventing risks. For scenarios involving dynamic adjustments to transaction monitoring, the transaction environment and business needs of financial institutions change over time, and fixed anomaly detection strategies may gradually lose their effectiveness. This invention provides a threshold adjustment mechanism. When the system detects a large number of alarms or false alarms, it will trigger a threshold adjustment notification. Business personnel can analyze the business situation based on real-time transaction monitoring curves and flexibly adjust various threshold parameters to ensure the continuous applicability and accuracy of transaction monitoring strategies.

[0052] like Figure 2As shown, the trading indicator anomaly detection method based on indicator thresholds includes the following steps:

[0053] It should be noted that before the system officially starts anomaly detection, the business side (such as the risk control department of a financial institution) needs to set the most suitable anomaly detection strategy parameters based on historical transaction data, business volatility characteristics, and the specific business scenarios of the partners. Optionally, before receiving the anomaly detection strategy selected by the business side, the business side can configure preset fixed thresholds and corresponding comparison operators based on historical transaction data, the tolerance range of each financial transaction indicator, and the business scenarios of the partners, as well as preset percentage thresholds and corresponding comparison operators.

[0054] Business personnel will conduct in-depth analysis of transaction data over a period of time to identify normal fluctuation ranges and abnormal patterns in indicators such as transaction volume, success rate, and time consumption. For example, by analyzing the transaction success rate, it may be found that fluctuations between 98% and 100% are within the normal range, while a success rate below 98% may indicate system problems or fraudulent activities.

[0055] When setting tolerance ranges for metrics, based on historical data analysis, the business side will set a tolerance range for each monitored metric. This range reflects the acceptable level of metric fluctuation for the business. For example, for transaction time, if the average time is 100 milliseconds, a tolerance range of ±20% might be set, meaning fluctuations between 80 and 120 milliseconds are considered normal. When configuring preset fixed thresholds and comparison operators, business personnel configure a preset fixed threshold and corresponding comparison operator (such as "less than" or "greater than") for each metric based on the analysis results. For example, for transaction success rate, the preset fixed threshold might be set to 98%, and the comparison operator to "less than," meaning any success rate below 98% will trigger an alarm. The preset fixed threshold for transaction time might be set to 120 milliseconds, and the comparison operator to "greater than," meaning a time exceeding 120 milliseconds will be marked as abnormal. When configuring preset percentage thresholds and comparison operators, for metrics such as transaction volume, when business personnel use a year-on-year threshold anomaly detection strategy, a preset percentage threshold and corresponding comparison operator need to be set. For example, the threshold for a year-on-year increase or decrease in trading volume may be set to 20%, and the comparison operator is also "greater than" or "less than", which means that an increase or decrease of more than 20% in trading volume compared with the same period in history will trigger anomaly detection.

[0056] By configuring thresholds and comparison operators, we can ensure that the anomaly detection strategy can be adapted to the business scenarios of our partners, reduce false alarms and false negatives, and improve detection efficiency and accuracy.

[0057] It should also be noted that this invention can be applied to the transaction anomaly detection system of financial institutions. The transaction anomaly detection system pre-deploys a transaction anomaly detection model and an alarm notification module. The transaction anomaly detection model and the anomaly detection module will analyze the data according to the pre-set strategies and thresholds, while the alarm notification module is responsible for sending alarm notifications to business personnel in a timely manner when an anomaly is detected.

[0058] Step S201: Receive the anomaly detection strategy selected by the business terminal.

[0059] The anomaly detection strategies include: a fixed threshold anomaly detection strategy and a year-on-year threshold anomaly detection strategy. The fixed threshold anomaly detection strategy compares the real-time indicator data value of each financial trading indicator with the preset fixed threshold corresponding to the financial trading indicator. The year-on-year threshold anomaly detection strategy compares the sum of the trading data of the financial trading indicator in the current time period with the sum of the trading data of the same period in the historical specified time period, and compares the calculated increase or decrease ratio with the preset percentage threshold corresponding to the financial trading indicator.

[0060] When the business side selects anomaly detection strategies from the user interface (e.g., web portal, mobile application, or dedicated management tool), the system first presents a strategy selection interface, listing fixed threshold anomaly detection strategies and year-on-year threshold anomaly detection strategies. The business side can choose the most suitable detection strategy based on the current partner's business characteristics and historical transaction data. When selecting a fixed threshold anomaly detection strategy, the business side needs to set a stable threshold that reflects normal trading activity based on historical statistics of monitored metrics (such as transaction success rate, transaction volume, and transaction time). For example, the success rate threshold might be set to 95%, the transaction volume threshold might be based on twice the average daily transaction volume, and the transaction time threshold might be based on 1.5 times the average transaction time. When selecting a year-on-year threshold anomaly detection strategy, business personnel need to set the historical comparison period and the year-on-year date (e.g., 1 day ago or 7 days ago), and set a reasonable percentage threshold based on business volatility, such as a threshold for a transaction volume increase or decrease exceeding 20%.

[0061] It should be noted that the financial transaction indicators mentioned in this embodiment include at least one of the following: transaction volume, success rate, and time consumption. Transaction volume refers to the number of financial transactions occurring within the current time period, reflecting the activity level of transactions over a certain period. For financial institutions, abnormal fluctuations in transaction volume often indicate potential business risks or opportunities. For example, a sudden and significant drop in transaction volume may mean user churn or system failure, while an abnormal increase in transaction volume may indicate the success of financial promotion activities or the existence of abnormal transaction behavior. Success rate, representing the percentage of successful transactions, is an important indicator for measuring the health and quality of the transaction system. A stable success rate means efficient operation of the transaction system, while a sudden drop in success rate may indicate system performance problems or an increase in fraudulent activities. For example, a decrease in the credit card payment success rate may indicate credit card information theft or a payment system malfunction. Time taken represents the average processing time for each transaction, reflecting the efficiency of transaction processing. Long processing times may lead to a decline in user experience or even transaction failure. An abnormal increase in processing time may indicate a system bottleneck or external service delay, which needs to be quickly located and resolved. For example, in a payment gateway, if the average processing time for each transaction suddenly increases, it may mean that the gateway server's processing capacity is insufficient and needs to be expanded or optimized.

[0062] Anomaly detection in financial transaction metrics plays a crucial role in maintaining the operational stability and user trust of financial institutions. By monitoring these metrics in real time and responding swiftly when anomalies occur, financial institutions can effectively mitigate risks and ensure the normal operation of their businesses. Furthermore, due to the flexibility of the anomaly detection strategy, the system can adapt to the business characteristics of different partners, ensuring the personalization and precision of the monitoring strategy.

[0063] Step S202: Based on the selected indicator anomaly detection strategy, collect financial transaction data for the current time period, and send the indicator anomaly detection strategy and financial transaction data to the transaction anomaly detection model. The transaction anomaly detection model analyzes the real-time indicator data values ​​corresponding to each financial transaction indicator and the corresponding preset fixed threshold, or analyzes the increase or decrease ratio of the indicator data values ​​of each financial transaction indicator and the corresponding preset percentage threshold to obtain the transaction anomaly detection result.

[0064] After selecting the detection strategy and configuring the thresholds on the business side, the system begins collecting financial transaction data for the current time period in real time. For the fixed threshold anomaly detection strategy, the system compares the real-time data value of each monitoring indicator with the preset fixed threshold. If a data value deviates from the threshold, it indicates a potential anomaly, and the system generates a corresponding anomaly detection result. For the year-on-year threshold anomaly detection strategy, the system calculates the sum of transaction data for the monitored indicators within the current time period and compares it with the sum of transaction data for the same period in a historical specified time frame. It calculates the percentage increase or decrease; if the percentage exceeds a preset percentage threshold, it is also considered an anomaly, and a transaction anomaly detection result is generated. The transaction anomaly detection result, along with the detection strategy and financial transaction data, is sent to the transaction anomaly detection model, which then makes further analysis and judgments based on this information.

[0065] It should be noted that for each indicator, the transaction anomaly detection model checks whether its data value is lower than a first preset fixed threshold or higher than a second preset fixed threshold. Optionally, when executing the fixed threshold anomaly detection strategy, the transaction anomaly detection model includes: triggering a first type of alarm when the real-time indicator data value of the fixed threshold anomaly detection strategy is lower than the first preset fixed threshold, or when the real-time indicator data value of the fixed threshold anomaly detection strategy is higher than the second preset fixed threshold, wherein the second preset fixed threshold is greater than the first preset fixed threshold; triggering a second type of alarm when the cumulative number of first type of alarms within a preset time period reaches the first type of alarm cumulative threshold; and triggering a threshold adjustment notification when the cumulative number of second type of alarms within a preset time period reaches the second type of alarm cumulative threshold.

[0066] For example, for the transaction success rate metric, if its real-time data value is lower than a preset 98% (first preset fixed threshold), or if the real-time data value of the time taken metric is higher than a preset 150 milliseconds (second preset fixed threshold), the model will immediately trigger a first type of alarm. It is worth noting that the second preset fixed threshold is usually higher than the first preset fixed threshold to ensure that the model can distinguish between abnormally low and abnormally high metric values.

[0067] In this embodiment, the model records the number of times the first type of alarm (which can be understood as a normal alarm notification) is triggered. If, within a preset time period, such as one hour, the cumulative number of triggers of the first type of alarm reaches the first type of alarm cumulative threshold, for example, five times, the model will escalate the alarm level and trigger the second type of alarm (which can be understood as a critical alarm notification). The second type of alarm typically represents the persistence of abnormal metrics, indicating that there may be a more serious problem that requires immediate action. If the second type of alarm continues to trigger within a preset time period, accumulating to the second type of alarm cumulative threshold, for example, three times, the model will automatically trigger a threshold adjustment notification. This indicates that the current detection strategy may no longer be suitable for the current business scenario, and business personnel need to re-evaluate and adjust the preset fixed threshold to ensure that subsequent anomaly detection is more accurate and effective.

[0068] Optionally, when executing the year-on-year threshold anomaly detection strategy, the transaction anomaly detection model includes: obtaining the first sum of transaction data for financial transaction indicators within the current time period, and extracting the second sum of transaction data for the same historical time period within the first historical specified time period and the third sum of transaction data for the same historical time period within the second historical specified time period from the transaction database; calculating the increase ratio or decrease ratio based on the first sum of transaction data, the second sum of transaction data, and the third sum of transaction data; triggering a first type of alarm for an indicator increase when both the increase ratio and the decrease ratio are greater than 0, and the increase ratio is greater than a first preset percentage threshold, and the decrease ratio is greater than a second preset percentage threshold; or triggering a first type of alarm for an indicator decrease when both the increase ratio and the decrease ratio are less than 0, and the absolute value of the increase ratio is greater than a first preset percentage threshold, and the absolute value of the decrease ratio is greater than a second preset percentage threshold.

[0069] The transaction anomaly detection model collects the total financial transaction data for the current time period in real time, and simultaneously extracts the total transaction data for the same time period from two historical periods (e.g., 1 day ago and 7 days ago) from the historical database. For example, for the transaction volume indicator, the model calculates the total transaction volume for the current time period (in this embodiment, the first total transaction data can be set as A1), and extracts the total transaction volume for the same time period 1 day ago (in this embodiment, the second total transaction data can be set as A2), and the total transaction volume for the same time period 7 days ago (in this embodiment, the third total transaction data can be set as A3). Then, based on the current total transaction data and the historical total transaction data, the transaction anomaly detection model calculates the increase ratio C1 = (A1-A2) / A2 and the decrease ratio C2 = (A1-A3) / A3 of the transaction volume. These two ratios reflect the degree of fluctuation of the current transaction volume compared to the same historical period, which helps to determine whether the transaction volume is abnormal.

[0070] Optionally, when executing the year-on-year threshold anomaly detection strategy, the transaction anomaly detection model further includes: triggering a second type of alarm when the number of first-type alarms with an upward indicator reaches the first type of alarm cumulative threshold within a preset time period, or when the number of first-type alarms with a downward indicator reaches the first type of alarm cumulative threshold within a preset time period; and triggering a threshold adjustment notification when the number of second-type alarms reaches the second type of alarm cumulative threshold within a preset time period.

[0071] The trading anomaly detection model checks whether the calculated increase percentage C1 and decrease percentage C2 meet preset percentage thresholds. If both C1 and C2 are greater than 0, and C1 is greater than the first preset percentage threshold (e.g., 5%), and C2 is greater than the second preset percentage threshold (e.g., 5%), the model will trigger a first-type alarm for an increase in the indicators. Similarly, if both C1 and C2 are less than 0, and the absolute value of C1 is greater than the first preset percentage threshold, and the absolute value of C2 is greater than the second preset percentage threshold, the model will trigger a first-type alarm for a decrease in the indicators. This indicates that the current trading volume fluctuation exceeds the historical normal range and there may be an anomaly. Similar to the fixed threshold anomaly detection strategy, the trading anomaly detection model records the number of times the first-type alarm is triggered. If the cumulative number of first-type alarm triggers reaches the first-type alarm cumulative threshold (e.g., 5 times) within a preset time period, the model will escalate the alarm level and trigger a second-type alarm, prompting business personnel to pay attention to the continuous abnormal fluctuations. If the second type of alarm continues to be triggered within a preset time period and accumulates to the second type of alarm cumulative threshold (e.g., 3 times), the model will automatically trigger a threshold adjustment notification, prompting the business side to reassess the percentage threshold of year-on-year detection in order to better adapt to the current business fluctuations and market environment.

[0072] Step S203: If the transaction anomaly detection result meets the preset anomaly detection switch and threshold adjustment requirements, a threshold adjustment notification is triggered to the business end. After receiving the threshold adjustment notification, the business end analyzes the transaction indicators whose thresholds need to be adjusted and the target threshold parameters based on the real-time transaction monitoring curve to obtain the threshold adjustment parameters.

[0073] Here, after analyzing all transaction data, the transaction anomaly detection model determines whether to trigger a threshold adjustment notification based on preset anomaly detection switches and threshold adjustment rules. If the detection results repeatedly reach or exceed the cumulative threshold for severe alarms, or if the frequency of false alarms / missed alarms is higher than the preset value, the model will recognize that the current detection strategy and thresholds may no longer be suitable for the current business scenario, and will trigger a threshold adjustment notification.

[0074] It's important to note that threshold adjustment notifications are sent to the business side. Upon receiving the notification, the business side will retrieve a real-time transaction monitoring graph and analyze the current business situation by observing the curve's trend. The graph displays the changing trends of various monitoring indicators over time, as well as a comparison with preset detection thresholds, helping the business side determine which indicators need adjustment, and the magnitude and direction of the adjustment. Based on the analysis results, the business side determines the threshold values ​​of the indicators that need adjustment and the target threshold parameters, generating threshold adjustment parameters.

[0075] Step S204: Receive the threshold adjustment parameters from the business side and feed them back to the transaction anomaly detection model.

[0076] After generating threshold adjustment parameters, the business side feeds these parameters back to the transaction anomaly detection model via a system-provided interface. Upon receiving the new threshold adjustment parameters, the transaction anomaly detection model immediately updates its internal detection strategies and threshold settings to reflect the latest analysis results and adjustment decisions from business personnel. This update process is real-time, ensuring that the new threshold parameters take effect immediately, thus quickly adapting to current business fluctuations and risk situations, and improving the accuracy and timeliness of anomaly detection. After the model update is complete, the new detection strategies and thresholds continue to be used for real-time monitoring of transaction data, forming a closed-loop transaction anomaly detection and adjustment mechanism.

[0077] Through the above steps, the system first receives the anomaly detection strategy selected by the business end. Then, based on the selected strategy, it collects financial transaction data for the current time period and sends the anomaly detection strategy and financial transaction data to the transaction anomaly detection model. The model analyzes the real-time data values ​​of each financial transaction indicator against their corresponding preset fixed thresholds, or analyzes the percentage increase or decrease of each indicator's data value against its corresponding preset percentage threshold to obtain the anomaly detection result. If the anomaly detection result meets the preset anomaly detection switch and threshold adjustment requirements, a threshold adjustment notification is triggered to the business end. Upon receiving the threshold adjustment notification, the business end analyzes the transaction indicators whose thresholds need adjustment and the target threshold parameters based on the real-time transaction monitoring curve to obtain the threshold adjustment parameters. It then receives the threshold adjustment parameters from the business end and feeds them back to the transaction anomaly detection model. In this embodiment, a threshold adjustment notification is triggered when a large number of alarms or false alarms are detected. The business end can analyze the business situation based on the real-time transaction monitoring curve and flexibly adjust various threshold parameters to ensure the accuracy of the transaction monitoring strategy. This solves the technical problem of fixed threshold anomaly detection mechanisms in related technologies, which are prone to false alarms and have low accuracy.

[0078] Optionally, after receiving the threshold adjustment parameters, the transaction anomaly detection model further includes: obtaining the partner identifier corresponding to the business end, and extracting the financial transaction indicators and partner business scenarios associated with the partner identifier; based on all extracted financial transaction indicators and partner business scenarios, updating the preset fixed threshold, preset percentage threshold, detection frequency, detection duration, alarm cumulative threshold, and comparison symbol stored in the transaction anomaly detection model.

[0079] When the transaction anomaly detection model receives threshold adjustment parameters from the business side, it performs a series of update and optimization operations to ensure that its detection strategy can adapt to business development and market changes in real time and accurately. First, the model extracts the corresponding partner identifier from the threshold adjustment notification. This identifier is crucial information linking the partner and financial institution for transaction monitoring and anomaly detection. Next, based on the partner identifier, the model extracts all financial transaction indicator data related to that partner from the system database, including but not limited to transaction volume, success rate, and time consumption, as well as the partner's business scenario information, such as business type, peak transaction periods, and the impact of holidays.

[0080] Different anomaly detection strategies require different parameter adjustments. For metrics employing a fixed threshold anomaly detection strategy, the model updates its internally stored preset fixed thresholds based on the new thresholds provided by business personnel in the threshold adjustment parameters. For example, if business personnel adjust the transaction success rate threshold, the model will update the fixed threshold for transaction success rate to reflect the latest business risk tolerance. For metrics employing a year-on-year threshold anomaly detection strategy, the model updates its internally stored preset percentage thresholds based on the threshold adjustment parameters provided by business personnel. For example, if business personnel adjust the percentage threshold for year-on-year increase in transaction volume based on market changes, the model will update the corresponding percentage threshold to ensure the accuracy and timeliness of year-on-year detection.

[0081] Threshold adjustment parameters may include adjustments to the detection frequency and detection duration. The detection frequency determines the cycle in which the model samples indicator data and detects anomalies, while the detection duration affects the statistical range of the data. The model will adjust its data collection and analysis cycle based on these parameters to more accurately reflect the real-time status of the current business.

[0082] The transaction anomaly detection model can also adjust parameters based on thresholds set by the business side, updating the cumulative thresholds for both Type I and Type II alarms, as well as comparison operators related to threshold detection (such as "less than" and "greater than"). This helps the model more accurately determine when to escalate from Type I to Type II alarms and when to trigger threshold adjustment notifications, thereby optimizing the alarm triggering mechanism and reducing false positives and false negatives.

[0083] After updating the above parameters, the transaction anomaly detection model re-evaluates and optimizes its overall detection strategy based on the new partner's business scenarios and indicator thresholds. This includes adjusting the data processing algorithm and optimizing the data storage structure to improve the efficiency and accuracy of anomaly detection. Furthermore, the transaction anomaly detection model can flexibly switch between fixed threshold anomaly detection and year-on-year threshold anomaly detection strategies according to business needs, adapting to different types of indicator monitoring requirements.

[0084] The following describes in detail another optional implementation method.

[0085] The purpose of this invention is to implement an alarm model with customizable thresholds for transaction monitoring indicators such as transaction volume, success rate, and time consumption. This model can effectively adapt to different API product service scenarios, identify abnormal transaction situations of specific partners and interfaces, and help business personnel to perceive, identify, and handle potential risks in a timely manner from massive amounts of data.

[0086] Figure 3 This is a flowchart of another optional transaction anomaly detection method based on indicator thresholds according to an embodiment of the present invention, such as... Figure 3 As shown, it includes:

[0087] S1: Initialize and configure alarm switches and thresholds.

[0088] When using the transaction anomaly detection system for the first time, the business side needs to configure alarm switches and thresholds for various monitoring indicators based on historical transaction data and specific requirements. This includes configuring the overall anomaly detection switch, fixed threshold detection switch, year-on-year detection switch, detection frequency, detection duration, detection threshold and comparison symbol, year-on-year date, cumulative threshold for ordinary alarms, and cumulative threshold for critical alarms, etc.

[0089] The anomaly detection model deployed in the transaction anomaly detection system is pre-set with a set of default thresholds. These default values ​​are based on industry standards and internal specifications, ensuring that the system can still operate and provide basic anomaly detection functions without manual intervention. However, to adapt to more specific and complex business scenarios, the business side can personalize the detection strategy according to actual transaction data and metric tolerance requirements. For example, for the success rate metric, a fixed threshold detection strategy can be set, configuring the detection frequency, detection duration, detection threshold (e.g., 95%), and comparison operator (e.g., "less than"). For the transaction volume metric, the business side may prefer to set a year-on-year threshold detection strategy to accommodate fluctuations in transaction volume over time, holidays, and other factors. Both detection schemes support parallel execution based on the business side's configuration, and the alarm information will clearly distinguish whether the alarm is triggered by the fixed threshold or the year-on-year threshold detection strategy, facilitating the business side to quickly locate the problem.

[0090] The business side can choose fixed threshold detection or year-on-year threshold detection, or both, based on the characteristics of the indicator to be detected. When both are selected, the two detection schemes will be executed in parallel according to their respective logics without interfering with each other. The text content of the abnormal alarm will distinguish which detection scheme issued the alarm, making it convenient for the business side to differentiate.

[0091] like Figure 3 As shown, after the anomaly detection model is deployed, the transaction flow data of the partner can be collected in real time, and the data values ​​corresponding to each financial transaction indicator can be extracted. These financial transaction indicators include: transaction volume, success rate, and time consumption. Then, it will confirm whether to enable anomaly detection and provide the business side / partner with anomaly detection options. If so, the partner / business side needs to choose whether to select a fixed threshold detection strategy or a year-on-year threshold detection strategy, and then perform anomaly detection analysis and threshold adjustment according to the corresponding threshold.

[0092] S2: Fixed threshold anomaly detection analysis.

[0093] 1) The anomaly detection model obtains the detection frequency V set in advance by the business side (for example, V=1 means that the average value of the indicator is calculated once every 1 minute).

[0094] 2) The anomaly detection model obtains the detection duration D pre-set by the business side (for example, D=10 means that each detection obtains the indicator data of the most recent 10 minutes and calculates the average value of the indicator within this duration).

[0095] 3) The anomaly detection model obtains the detection threshold T and comparison operator pre-set by the business side (for example, T=95, the comparison operator is "less than", which means that if the success rate of each detection is less than 95%, a normal alarm notification will be triggered).

[0096] 4) The anomaly detection model obtains the pre-set cumulative threshold N1 for ordinary alarms on the business side (for example, N1=5 means that if an ordinary alarm is triggered 5 times consecutively, a critical alarm notification will be triggered).

[0097] 5) The anomaly detection model obtains the critical alarm cumulative threshold N2 pre-set by the business side (for example, N2=3 means that if a critical alarm is reached 3 times consecutively, a threshold adjustment notification will be triggered).

[0098] 6) After receiving the threshold adjustment notification, the business side will check the real-time monitoring curve to analyze the business situation and manually determine whether the threshold parameters need to be adjusted and how to adjust them.

[0099] 7) The anomaly detection model obtains the adjusted threshold parameters and performs anomaly detection analysis based on the new thresholds.

[0100] S3: Anomaly detection analysis of year-on-year threshold.

[0101] For monitoring metrics like transaction volume, which fluctuate significantly across different time periods (for example, during Singles' Day, the number of shopping transactions made using financial institutions at night is much higher than the same period on other days; similarly, the number of transactions using financial institutions' apps to scan and pay for subway fares during morning and evening rush hours is much higher than at other times), fixed threshold anomaly detection can lead to false alarms and missed alarms. It is recommended to use year-on-year threshold anomaly detection analysis. When performing year-on-year threshold detection, the system will take the total number or average value of the metrics within the detection period and compare it to the threshold. Occasionally, missing or abnormal transaction data will not significantly affect the accuracy of the alarms. After the business side sets the threshold parameters according to its actual business situation in step S1, the anomaly detection analysis is implemented as follows:

[0102] 1) The anomaly detection model obtains the detection frequency V set in advance by the business side (for example, V=1 means that the sum of the indicator data is calculated once every 1 minute).

[0103] 2) The anomaly detection model obtains the detection duration D pre-set by the business side (for example, D=10 means that each detection obtains the indicator data of the most recent 10 minutes and calculates the sum of the indicator data within this duration, denoted as A1).

[0104] 3) The anomaly detection model obtains the same-year date DAY1 pre-set by the business side (for example, DAY1=1 means that each detection obtains the indicator data of the same period 1 day ago and calculates the sum of the indicator data within this period, denoted as A2).

[0105] 4) The anomaly detection model obtains the same-year date DAY2 pre-set by the business side (for example, DAY1=7 means that each detection obtains the indicator data of the same period 7 days ago and calculates the sum of the indicator data within this period, denoted as A3).

[0106] 5) The anomaly detection model obtains the detection threshold T set in advance by the business side. According to the formula (A1-A2) / A2=C1, (A1-A3) / A3=C2, C1 represents the percentage increase / decrease in the transaction volume of the current period compared with the transaction volume of the same period of DAY1, and C2 is the same.

[0107] When C1>0 and C2>0 and C1>T and C2>percentage threshold T, it means that the trading volume in the current period has increased compared to the trading volume in the same period of DAY1 and DAY2, and the increase exceeds the percentage threshold T, thus triggering a normal alarm notification for the indicator increase.

[0108] If C1<0 and C2<0 and |C1|>T and |C2|>T, it means that the trading volume in the current period has decreased compared to the trading volume in the same period of DAY1 and DAY2, and the decrease exceeds the percentage threshold T, then a normal alarm notification for the indicator decrease is triggered.

[0109] 6) The anomaly detection model obtains the pre-set cumulative threshold N1 for ordinary alarms on the business side (for example, N1=5 means that if the number of rising / falling ordinary alarms reaches 5 consecutive times, a critical alarm notification will be triggered).

[0110] 7) The anomaly detection model obtains the critical alarm cumulative threshold N2 pre-set by the business side (for example, N2=3 means that if a critical alarm is reached 3 times consecutively, a threshold adjustment notification will be triggered).

[0111] 8) After receiving the threshold adjustment notification, the business side will check the real-time monitoring curve to analyze the business situation and manually determine whether the threshold parameters need to be adjusted and how to adjust them.

[0112] 9) The anomaly detection model obtains the adjusted threshold parameters and performs anomaly detection analysis based on the new thresholds.

[0113] Through the above implementation methods, a refined risk control capability for detecting anomalies in trading indicators is achieved. Two detection schemes are provided: fixed threshold anomaly detection and year-on-year threshold anomaly detection. These adapt to monitoring anomalies of different natures, enabling the trading anomaly detection model to more accurately and efficiently monitor and detect various anomalies in financial transactions. This not only improves the risk control capabilities of financial institutions but also enhances adaptability to different partners' business scenarios, reducing the risk of false positives and false negatives. It provides strong technical support for the transaction security and business development of financial institutions. Furthermore, the model's alarm mechanism and threshold adjustment function allow the system to continuously optimize its detection strategy, better responding to ever-changing market environments and business needs.

[0114] The following is a detailed description with reference to another embodiment.

[0115] Example 2

[0116] The transaction indicator anomaly detection device based on indicator threshold provided in this embodiment includes multiple implementation units, each of which corresponds to the implementation steps in the above embodiment one. Its specific implementation method and beneficial effects can be referred to the foregoing method embodiment, and will not be repeated here.

[0117] Figure 4 This is a schematic diagram of an optional trading indicator anomaly detection device based on indicator thresholds according to an embodiment of the present invention, as shown below. Figure 4As shown, the trading indicator anomaly detection device based on indicator thresholds may include: a detection strategy receiving unit 41, a model analysis unit 41, a threshold adjustment unit 43, and a threshold feedback unit 44.

[0118] The detection strategy receiving unit 41 is used to receive the indicator anomaly detection strategy selected by the business end. The indicator anomaly detection strategy includes a fixed threshold anomaly detection strategy and a year-on-year threshold anomaly detection strategy. The fixed threshold anomaly detection strategy is a strategy that compares the real-time indicator data value corresponding to each financial transaction indicator with the preset fixed threshold corresponding to the financial transaction indicator. The year-on-year threshold anomaly detection strategy is a strategy that compares the sum of the transaction data of the financial transaction indicator in the current time period with the sum of the transaction data of the same period in the historical specified time period, and compares the calculated increase or decrease ratio with the preset percentage threshold corresponding to the financial transaction indicator.

[0119] The model analysis unit 41 is used to collect financial transaction data for the current time period according to the selected indicator anomaly detection strategy, and send the indicator anomaly detection strategy and financial transaction data to the transaction anomaly detection model. The transaction anomaly detection model analyzes the real-time indicator data value corresponding to each financial transaction indicator and the corresponding preset fixed threshold, or analyzes the increase or decrease ratio of the indicator data value of each financial transaction indicator and the corresponding preset percentage threshold to obtain the transaction anomaly detection result.

[0120] The threshold adjustment unit 43 is used to trigger a threshold adjustment notification to the business end when the transaction anomaly detection result meets the preset anomaly detection switch and threshold adjustment requirements. After receiving the threshold adjustment notification, the business end analyzes the transaction indicators whose thresholds need to be adjusted and the target threshold parameters based on the real-time transaction monitoring curve to obtain the threshold adjustment parameters.

[0121] The threshold feedback unit 44 is used to receive the threshold adjustment parameters fed back from the business side and feed the threshold adjustment parameters back to the transaction anomaly detection model.

[0122] The aforementioned transaction indicator anomaly detection device based on indicator thresholds can receive the indicator anomaly detection strategy selected by the business end through the detection strategy receiving unit 41. Then, the model analysis unit 42 collects financial transaction data for the current time period according to the selected indicator anomaly detection strategy and sends the indicator anomaly detection strategy and financial transaction data to the transaction anomaly detection model. The transaction anomaly detection model analyzes the real-time indicator data value corresponding to each financial transaction indicator and the corresponding preset fixed threshold, or analyzes the increase or decrease ratio of the indicator data value of each financial transaction indicator and the corresponding preset percentage threshold to obtain the transaction anomaly detection result. Then, the threshold adjustment unit 43 triggers a threshold adjustment notification to the business end when the transaction anomaly detection result meets the preset anomaly detection switch and threshold adjustment requirements. After receiving the threshold adjustment notification, the business end analyzes the transaction indicators whose indicator thresholds need to be adjusted and the target threshold parameters according to the real-time transaction monitoring curve to obtain the threshold adjustment parameters. Then, the threshold feedback unit 44 receives the threshold adjustment parameters fed back by the business end and feeds the threshold adjustment parameters back to the transaction anomaly detection model. In this embodiment, when a large number of alarms or false alarms are detected, a threshold adjustment notification is triggered. The business side can analyze the business situation based on the real-time transaction monitoring curve and flexibly adjust various threshold parameters to ensure the accuracy of the transaction monitoring strategy. This can solve the technical problem of fixed threshold anomaly detection mechanisms in related technologies, which are prone to false alarms and have low accuracy.

[0123] Optionally, the transaction anomaly detection model in the transaction indicator anomaly detection device based on indicator thresholds includes the following components when executing a fixed threshold anomaly detection strategy: a first triggering unit, configured to trigger a first type of alarm when the real-time indicator data value of the fixed threshold anomaly detection strategy is lower than a first preset fixed threshold, or when the real-time indicator data value of the fixed threshold anomaly detection strategy is higher than a second preset fixed threshold, wherein the second preset fixed threshold is greater than the first preset fixed threshold; a second triggering unit, configured to trigger a second type of alarm when the cumulative number of first type of alarms within a preset time period reaches a first type of alarm cumulative threshold; and a third triggering unit, configured to trigger a threshold adjustment notification when the cumulative number of second type of alarms within a preset time period reaches a second type of alarm cumulative threshold.

[0124] Optionally, the transaction anomaly detection model in the transaction indicator anomaly detection device based on indicator thresholds, when executing the year-on-year threshold anomaly detection strategy, includes: a data summation acquisition unit, used to acquire the first transaction data summation of financial transaction indicators within the current time period, and extract the second transaction data summation of the same historical time period corresponding to the current time period within the first historical specified time period and the third transaction data summation of the same historical time period within the second historical specified time period from the transaction database; a calculation unit, used to calculate the increase ratio or decrease ratio based on the first transaction data summation, the second transaction data summation, and the third transaction data summation; and a fourth triggering unit, used to trigger a first type of alarm for indicator increase when both the increase ratio and the decrease ratio are greater than 0, and the increase ratio is greater than a first preset percentage threshold, and the decrease ratio is greater than a second preset percentage threshold; or, when both the increase ratio and the decrease ratio are less than 0, and the absolute value of the increase ratio is greater than a first preset percentage threshold, and the absolute value of the decrease ratio is greater than a second preset percentage threshold, triggering a first type of alarm for indicator decrease.

[0125] Optionally, when the transaction anomaly detection model in the transaction indicator anomaly detection device based on indicator thresholds executes the year-on-year threshold anomaly detection strategy, it further includes: a fifth triggering unit, used to trigger a second type of alarm when the number of first type alarms with an increase in the indicator reaches the first type of alarm cumulative threshold within a preset time period, or when the number of first type alarms with a decrease in the indicator reaches the first type of alarm cumulative threshold within a preset time period; and a sixth triggering unit, used to trigger a threshold adjustment notification when the number of second type alarms reaches the second type of alarm cumulative threshold within a preset time period.

[0126] Optionally, the transaction indicator anomaly detection device based on indicator thresholds further includes: a partner identifier acquisition unit, used to acquire the partner identifier corresponding to the business end after the transaction anomaly detection model receives the threshold adjustment parameters, and extract the financial transaction indicators and partner business scenarios associated with the partner identifier; and a parameter update unit, used to update the preset fixed threshold, preset percentage threshold, detection frequency, detection duration, alarm cumulative threshold, and comparison symbol stored in the transaction anomaly detection model based on all extracted financial transaction indicators and partner business scenarios.

[0127] Optionally, the transaction indicator anomaly detection device based on indicator thresholds further includes: a threshold configuration unit, used to configure a preset fixed threshold and corresponding comparison operator by the business end based on historical transaction data, the tolerance range of each financial transaction indicator and the business scenario of the partner before receiving the indicator anomaly detection strategy selected by the business end, and to configure a preset percentage threshold and corresponding comparison operator.

[0128] Optionally, financial transaction metrics include at least one of the following: transaction volume, success rate, and time taken, wherein transaction volume is the number of financial transactions that occur in the current time period, success rate represents the percentage of successful transactions, and time taken represents the average processing time for each transaction.

[0129] The aforementioned transaction indicator anomaly detection device based on indicator thresholds may further include a processor and a memory. The detection strategy receiving unit 41, model analysis unit 41, threshold adjustment unit 43, threshold feedback unit 44, etc., are all stored in the memory as program units, and the processor executes the aforementioned program units stored in the memory to realize the corresponding functions.

[0130] The aforementioned processor contains a kernel, which retrieves the corresponding program units from memory. One or more kernels can be configured, and adjusting kernel parameters can implement trading fluctuation alerts based on financial trading indicator thresholds.

[0131] The aforementioned memory may include non-permanent memory in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM, and the memory includes at least one memory chip.

[0132] Example 3

[0133] Embodiments of this application may provide an electronic device. Figure 5 This is a structural block diagram of an electronic device according to an embodiment of this application. Figure 5 As shown, the electronic device may include: one or more ( Figure 5 Only one of the components is shown: processor 502, memory 504, memory controller, and peripheral interface, wherein the peripheral interface is connected to the radio frequency module, audio module, and display.

[0134] The memory can be used to store software programs and modules, such as the program instructions / modules corresponding to the trading indicator anomaly detection method and apparatus based on indicator thresholds in this application embodiment. The processor executes various functional applications and data processing by running the software programs and modules stored in the memory, thereby realizing the aforementioned trading indicator anomaly detection method based on indicator thresholds. The memory may include high-speed random access memory, and may also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory may further include memory remotely located relative to the processor, and these remote memories can be connected to the terminal via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.

[0135] The processor can access information and applications stored in memory via a transmission device to execute the following steps: receiving an anomaly detection strategy selected by the business terminal, wherein the anomaly detection strategy includes: a fixed threshold anomaly detection strategy and a year-on-year threshold anomaly detection strategy. The fixed threshold anomaly detection strategy compares the real-time indicator data value corresponding to each financial transaction indicator with a preset fixed threshold corresponding to the financial transaction indicator. The year-on-year threshold anomaly detection strategy compares the sum of transaction data of the financial transaction indicator in the current time period with the sum of transaction data in the same period in the historical specified time period, and compares the calculated increase or decrease ratio with a preset percentage threshold corresponding to the financial transaction indicator; and collecting financial transaction data for the current time period according to the selected anomaly detection strategy. The system sends data, along with the indicator anomaly detection strategy and financial transaction data, to the transaction anomaly detection model. The model analyzes the real-time indicator data values ​​of each financial transaction indicator against their corresponding preset fixed thresholds, or analyzes the percentage increase or decrease of each financial transaction indicator's data value against its corresponding preset percentage threshold, to obtain the transaction anomaly detection result. If the transaction anomaly detection result meets the preset anomaly detection switch and threshold adjustment requirements, a threshold adjustment notification is triggered to the business end. Upon receiving the threshold adjustment notification, the business end analyzes the transaction indicators whose thresholds need adjustment and the target threshold parameters based on the real-time transaction monitoring curve, obtaining the threshold adjustment parameters. The system then receives the threshold adjustment parameters from the business end and feeds them back to the transaction anomaly detection model.

[0136] The processor can also call the information and application stored in the memory through the transmission device to perform the following steps: When the transaction anomaly detection model executes the fixed threshold anomaly detection strategy, if the real-time indicator data value of the fixed threshold anomaly detection strategy is lower than the first preset fixed threshold, or if the real-time indicator data value of the fixed threshold anomaly detection strategy is higher than the second preset fixed threshold, a first type of alarm is triggered, wherein the second preset fixed threshold is greater than the first preset fixed threshold; when the number of first type alarms accumulates to the first type of alarm accumulation threshold within a preset time period, a second type of alarm is triggered; when the number of second type alarms accumulates to the second type of alarm accumulation threshold within a preset time period, a threshold adjustment notification is triggered.

[0137] The processor can also call the information and application stored in the memory through the transmission device to perform the following steps: When the transaction anomaly detection model executes the year-on-year threshold anomaly detection strategy, it obtains the first sum of transaction data of financial transaction indicators within the current time period, and extracts the second sum of transaction data of the same historical time period corresponding to the current time period within the first historical specified time period in the transaction database, and the third sum of transaction data of the same historical time period within the second historical specified time period; based on the first sum of transaction data, the second sum of transaction data, and the third sum of transaction data, it calculates the increase ratio or decrease ratio; when both the increase ratio and the decrease ratio are greater than 0, and the increase ratio is greater than the first preset percentage threshold, and the decrease ratio is greater than the second preset percentage threshold, it triggers the first type of alarm for an indicator increase; or, when both the increase ratio and the decrease ratio are less than 0, and the absolute value of the increase ratio is greater than the first preset percentage threshold, and the absolute value of the decrease ratio is greater than the second preset percentage threshold, it triggers the first type of alarm for an indicator decrease.

[0138] The processor can also call the information and application stored in the memory through the transmission device to perform the following steps: When the transaction anomaly detection model executes the year-on-year threshold anomaly detection strategy, if the number of first-type alarms with an upward indicator reaches the first-type alarm cumulative threshold within a preset time period, or if the number of first-type alarms with a downward indicator reaches the first-type alarm cumulative threshold within a preset time period, a second-type alarm is triggered; if the number of second-type alarms reaches the second-type alarm cumulative threshold within a preset time period, a threshold adjustment notification is triggered.

[0139] The processor can also call the information and application stored in the memory through the transmission device to perform the following steps: After receiving the threshold adjustment parameters, the transaction anomaly detection model obtains the partner identifier corresponding to the business end, and extracts the financial transaction indicators and partner business scenarios associated with the partner identifier; based on all the extracted financial transaction indicators and partner business scenarios, it updates the preset fixed threshold, preset percentage threshold, detection frequency, detection duration, alarm cumulative threshold, and comparison symbol stored in the transaction anomaly detection model.

[0140] The processor can also call the information and application stored in the memory through the transmission device to perform the following steps: Before receiving the indicator anomaly detection strategy selected by the business end, the business end configures the preset fixed threshold and the corresponding comparison operator based on historical transaction data, the tolerance range of each financial transaction indicator and the business scenario of the partner, and configures the preset percentage threshold and the corresponding comparison operator.

[0141] The processor can also call the information and application stored in the memory through the transmission device to perform the following steps: financial transaction indicators include at least one of the following: transaction volume, success rate, and time consumption, wherein the transaction volume is the number of financial transactions that occur in the current time period, the success rate is the percentage of successful transactions, and the time consumption is the average processing time of each transaction.

[0142] This application provides a solution for detecting financial transaction anomalies based on indicator thresholds. By triggering threshold adjustment notifications when a large number of alarms or false alarms are detected, the business side can analyze the business situation based on real-time transaction monitoring curves and flexibly adjust various threshold parameters to ensure the accuracy of the transaction monitoring strategy.

[0143] Those skilled in the art will understand that Figure 5 The structure shown is for illustrative purposes only. Electronic devices can also be smartphones, tablets, handheld computers, mobile internet devices (MIDs), PADs, and other terminal devices. Figure 5 This does not limit the structure of the aforementioned electronic device. For example, electronic devices may also include components that are more... Figure 5 The more or fewer components shown (such as network interfaces, display devices, etc.), or having the same Figure 5 The different configurations shown.

[0144] Those skilled in the art will understand that all or part of the steps in the various indicator threshold-based abnormal transaction indicator detection methods in the above embodiments can be implemented by a program instructing the hardware of the terminal device. The program can be stored in a computer-readable storage medium, which may include: flash drive, read-only memory (ROM), random access memory (RAM), disk or optical disk, etc.

[0145] Example 4

[0146] Embodiments of this application also provide a storage medium. Optionally, in this embodiment, the storage medium can be used to store the program code executed by the trading indicator anomaly detection method based on indicator thresholds provided in Embodiment 1.

[0147] According to another aspect of the present invention, a computer-readable storage medium is also provided, the computer-readable storage medium including a stored computer program, wherein, when the computer program is running, it controls the device where the computer-readable storage medium is located to execute any of the above-described transaction indicator anomaly detection methods based on indicator thresholds in Embodiment 1.

[0148] Optionally, in this embodiment, the storage medium may be located in any computer terminal in a group of computer terminals in a computer network, or in any mobile terminal in a group of mobile terminals.

[0149] This application also provides a computer program product, including a computer program that, when executed by a processor, implements the steps of the trading indicator anomaly detection method based on indicator thresholds described in various embodiments of this application.

[0150] This application also provides a computer program product, including a non-volatile computer-readable storage medium storing a computer program, which, when executed by a processor, implements the steps of the transaction indicator anomaly detection method based on indicator thresholds described in various embodiments of this application.

[0151] The sequence numbers of the above embodiments of the present invention are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.

[0152] In the above embodiments of the present invention, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments.

[0153] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. The device embodiments described above are merely illustrative; for example, the division of units can be a logical functional division, and in actual implementation, there may be other division methods. For instance, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the displayed or discussed mutual coupling, direct coupling, or communication connection may be through some interfaces; the indirect coupling or communication connection between units or modules may be electrical or other forms.

[0154] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0155] Furthermore, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0156] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, read-only memory (ROM), random access memory (RAM), portable hard drives, magnetic disks, or optical disks.

[0157] The above description is only a preferred embodiment of the present invention. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principle of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.

Claims

1. A method for detecting anomalies in trading indicators based on indicator thresholds, characterized in that, include: The system receives an anomaly detection strategy selected by the business terminal. The anomaly detection strategy includes a fixed threshold anomaly detection strategy and a year-on-year threshold anomaly detection strategy. The fixed threshold anomaly detection strategy compares the real-time indicator data value corresponding to each financial transaction indicator with the preset fixed threshold corresponding to the financial transaction indicator. The year-on-year threshold anomaly detection strategy compares the sum of the transaction data of the financial transaction indicator in the current time period with the sum of the transaction data in the same period in the historical specified time period, and compares the calculated increase or decrease ratio with the preset percentage threshold corresponding to the financial transaction indicator. Based on the selected indicator anomaly detection strategy, financial transaction data for the current time period is collected, and the indicator anomaly detection strategy and the financial transaction data are sent to the transaction anomaly detection model. The transaction anomaly detection model analyzes the real-time indicator data value corresponding to each financial transaction indicator and the corresponding preset fixed threshold, or analyzes the increase or decrease ratio of the indicator data value of each financial transaction indicator and the corresponding preset percentage threshold to obtain the transaction anomaly detection result. If the transaction anomaly detection result meets the preset anomaly detection switch and threshold adjustment requirements, a threshold adjustment notification is triggered to the business terminal. After receiving the threshold adjustment notification, the business terminal analyzes the transaction indicators whose thresholds need to be adjusted and the target threshold parameters based on the real-time transaction monitoring curve to obtain the threshold adjustment parameters. Receive the threshold adjustment parameters fed back by the business terminal, and feed the threshold adjustment parameters back to the transaction anomaly detection model; The transaction anomaly detection model, when executing a fixed threshold anomaly detection strategy, includes: triggering a first type of alarm when the real-time indicator data value of the fixed threshold anomaly detection strategy is lower than a first preset fixed threshold, or when the real-time indicator data value of the fixed threshold anomaly detection strategy is higher than a second preset fixed threshold, wherein the second preset fixed threshold is greater than the first preset fixed threshold; triggering a second type of alarm when the cumulative number of the first type of alarms within a preset time period reaches a first type of alarm cumulative threshold; and triggering a threshold adjustment notification when the cumulative number of the second type of alarms within a preset time period reaches a second type of alarm cumulative threshold. When executing the year-on-year threshold anomaly detection strategy, the transaction anomaly detection model includes: obtaining the first sum of transaction data for the financial transaction indicator within the current time period, and extracting the second sum of transaction data for the same historical time period corresponding to the current time period within a first historical specified time period and the third sum of transaction data for the same historical time period within a second historical specified time period from the transaction database; calculating the increase ratio or decrease ratio based on the first sum of transaction data, the second sum of transaction data, and the third sum of transaction data; triggering a first type of alarm for an indicator increase when both the increase ratio and the decrease ratio are greater than 0, and the increase ratio is greater than a first preset percentage threshold, and the decrease ratio is greater than a second preset percentage threshold; or triggering a first type of alarm for an indicator decrease when both the increase ratio and the decrease ratio are less than 0, and the absolute value of the increase ratio is greater than a first preset percentage threshold, and the absolute value of the decrease ratio is greater than a second preset percentage threshold. When the transaction anomaly detection model executes the year-on-year threshold anomaly detection strategy, it further includes: triggering a second type of alarm when the number of first type alarms for an increase in the indicator reaches the first type of alarm cumulative threshold within a preset time period, or when the number of first type alarms for a decrease in the indicator reaches the first type of alarm cumulative threshold within a preset time period; and triggering a threshold adjustment notification when the number of second type alarms reaches the second type of alarm cumulative threshold within a preset time period.

2. The trading indicator anomaly detection method according to claim 1, characterized in that, After receiving the threshold adjustment parameter, the transaction anomaly detection model further includes: Obtain the partner identifier corresponding to the business terminal, and extract the financial transaction indicators and partner business scenarios associated with the partner identifier; Based on all the extracted financial transaction indicators and partner business scenarios, update the preset fixed threshold, preset percentage threshold, detection frequency, detection duration, alarm cumulative threshold, and comparison symbol stored in the transaction anomaly detection model.

3. The method for detecting anomalies in trading indicators according to claim 1, characterized in that, Before receiving the anomaly detection strategy selected by the business side, it also includes: The business unit configures the preset fixed threshold and corresponding comparison operator based on historical transaction data, the tolerance range of various financial transaction indicators, and the business scenarios of the partners, and also configures the preset percentage threshold and corresponding comparison operator.

4. The method for detecting anomalies in trading indicators according to any one of claims 1 to 3, characterized in that, The financial transaction metrics include at least one of the following: transaction volume, success rate, and time consumption, wherein the transaction volume is the number of financial transactions that occur within the current time period, the success rate represents the percentage of successful transactions, and the time consumption represents the average processing time for each transaction.

5. A device for detecting anomalies in trading indicators based on indicator thresholds, characterized in that, include: The detection strategy receiving unit is used to receive the indicator anomaly detection strategy selected by the business end. The indicator anomaly detection strategy includes a fixed threshold anomaly detection strategy and a year-on-year threshold anomaly detection strategy. The fixed threshold anomaly detection strategy is a strategy that compares the real-time indicator data value corresponding to each financial transaction indicator with the preset fixed threshold corresponding to the financial transaction indicator. The year-on-year threshold anomaly detection strategy is a strategy that compares the sum of the transaction data of the financial transaction indicator in the current time period with the sum of the transaction data of the same time period in the past specified time period, and compares the calculated increase ratio or decrease ratio with the preset percentage threshold corresponding to the financial transaction indicator. The model analysis unit is used to collect financial transaction data for the current time period according to the selected indicator anomaly detection strategy, and send the indicator anomaly detection strategy and the financial transaction data to the transaction anomaly detection model. The transaction anomaly detection model analyzes the real-time indicator data value corresponding to each financial transaction indicator and the corresponding preset fixed threshold, or analyzes the increase or decrease ratio of the indicator data value of each financial transaction indicator and the corresponding preset percentage threshold to obtain the transaction anomaly detection result. The threshold adjustment unit is used to trigger a threshold adjustment notification to the business terminal when the transaction anomaly detection result meets the preset anomaly detection switch and threshold adjustment requirements. After receiving the threshold adjustment notification, the business terminal analyzes the transaction indicators whose thresholds need to be adjusted and the target threshold parameters based on the real-time transaction monitoring curve to obtain the threshold adjustment parameters. A threshold feedback unit is used to receive threshold adjustment parameters fed back by the business terminal and feed the threshold adjustment parameters back to the transaction anomaly detection model; The transaction anomaly detection model in the threshold-based transaction indicator anomaly detection device, when executing a fixed threshold anomaly detection strategy, includes: a first triggering unit, configured to trigger a first type of alarm when the real-time indicator data value of the fixed threshold anomaly detection strategy is lower than a first preset fixed threshold, or when the real-time indicator data value of the fixed threshold anomaly detection strategy is higher than a second preset fixed threshold, wherein the second preset fixed threshold is greater than the first preset fixed threshold; a second triggering unit, configured to trigger a second type of alarm when the cumulative number of the first type of alarms within a preset time period reaches a first type of alarm cumulative threshold; and a third triggering unit, configured to trigger a threshold adjustment notification when the cumulative number of the second type of alarms within a preset time period reaches a second type of alarm cumulative threshold. The transaction anomaly detection model in the transaction indicator anomaly detection device based on indicator thresholds, when executing the year-on-year threshold anomaly detection strategy, includes: a data summation acquisition unit, used to acquire the first transaction data summation of the financial transaction indicator within the current time period, and extract the second transaction data summation of the same historical time period corresponding to the current time period within the first historical specified time period and the third transaction data summation of the same historical time period within the second historical specified time period from the transaction database; a calculation unit, used to calculate the increase ratio or decrease ratio based on the first transaction data summation, the second transaction data summation, and the third transaction data summation; and a fourth triggering unit, used to trigger a first type of alarm for indicator increase when both the increase ratio and the decrease ratio are greater than 0, and the increase ratio is greater than a first preset percentage threshold, and the decrease ratio is greater than a second preset percentage threshold; or, when both the increase ratio and the decrease ratio are less than 0, and the absolute value of the increase ratio is greater than a first preset percentage threshold, and the absolute value of the decrease ratio is greater than a second preset percentage threshold, triggering a first type of alarm for indicator decrease; The transaction anomaly detection model in the transaction indicator anomaly detection device based on indicator thresholds further includes, when executing the year-on-year threshold anomaly detection strategy: a fifth triggering unit, used to trigger a second type of alarm when the number of first type of alarms for an increase in the indicator reaches the first type of alarm cumulative threshold within a preset time period, or when the number of first type of alarms for a decrease in the indicator reaches the first type of alarm cumulative threshold within a preset time period; and a sixth triggering unit, used to trigger a threshold adjustment notification when the number of second type of alarms reaches the second type of alarm cumulative threshold within a preset time period.

6. An electronic device, characterized in that, It includes one or more processors and a memory, the memory being used to store one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors cause the one or more processors to implement the trading indicator anomaly detection method based on indicator thresholds as described in any one of claims 1 to 4.

7. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by the processor, it implements the steps of the trading indicator anomaly detection method based on indicator thresholds as described in any one of claims 1 to 4.

Citation Information

Patent Citations

  • Abnormity detection method, device and equipment

    CN110874674A

  • Business transaction monitoring alarm system, method and device, and storage medium

    CN116433347A