A real-time transaction risk detection and intelligent interception method, system and storage medium based on multi-dimensional data
The method addresses inefficiencies in determining privacy protection budgets and real-time risk monitoring by iteratively adjusting parameters and using feature extraction networks to enhance neural network training and risk detection accuracy in multi-dimensional data analysis.
Patent Information
- Application Number
- CN202510314929.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-18
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2045-03-18
AI Technical Summary
In the prior art, it is difficult to accurately determine whether the privacy protection budget parameters of differential privacy computing can meet the requirements of neural network training, and it is difficult to conduct real-time risk detection and interception of graph neural networks. The data preprocessing in the existing methods is complicated, resulting in insufficient data utilization.
By acquiring cubes, differential privacy processing is performed using the initial privacy protection budget parameters, feature extraction network extracts features, adjusts privacy protection budget parameters, iteratively trains graph neural networks, and builds multi-dimensional graph neural networks for risk detection and interception.
It improves the training efficiency of neural networks, ensures data security, enhances the accuracy of risk detection and interception, and overcomes the shortcomings in the prior art.
Smart Images

Figure CN119850217B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical fields of data processing, bank risk prevention and control, and artificial intelligence, and particularly relates to a real-time transaction risk detection and intelligent interception method, system, and storage medium based on multi-dimensional data. Background Art
[0002] In the prior art, artificial intelligence has been used for risk detection and interception. To reduce the risk of data privacy leakage during the training of neural network models, differential privacy calculation has been introduced. However, in the prior art, it is difficult to accurately determine whether the privacy protection budget parameter of differential privacy calculation meets the requirements of neural network training, that is, whether the data after differential privacy calculation can meet the training requirements of the neural network. Moreover, the method for determining the privacy protection budget parameter is too complex and has a long iteration cycle.
[0003] In addition, there are also methods in the prior art for risk detection and interception using graph neural networks. However, the graph construction method in the prior art organizes data with users as nodes, that is, various historical data are composed into a data vector as the historical data of a user. In this way, the collected historical data needs to be preprocessed into user data first, and some other collected historical data cannot be used. Moreover, it is difficult for the trained graph neural network to perform real-time monitoring and interception of risks based on the obtained partial real-time data. Summary of the Invention
[0004] In view of one or more of the above technical defects in the prior art, the present invention proposes the following technical solutions.
[0005] A real-time transaction risk detection and intelligent interception method based on multi-dimensional data, the method comprising:
[0006] An acquisition step of acquiring a historical multi-dimensional data set related to transactions, the historical multi-dimensional data set including: historical transaction behavior data, historical user portrait data, historical environmental dynamic data, and historical cross-industry joint defense data;
[0007] A processing step of performing differential privacy processing on the data in the historical multi-dimensional data set using an initial privacy protection budget parameter ε to obtain a processed differential privacy historical multi-dimensional data set;
[0008] A training step of using a feature extraction network to extract features from the differential privacy historical multi-dimensional data to obtain a training sample feature set, and training a graph neural network based on the training sample feature set to obtain a trained first transaction detection model;
[0009] Adjustment step: Use the test sample set to test the first transaction detection model to obtain the first test result. If the error of the first test result is greater than or equal to the first threshold, adjust the initial privacy protection budget parameter based on the error to obtain the adjusted privacy protection budget parameter ε′.
[0010] Iteration step: Use the adjusted ε′ to replace ε, and then repeat the processing step, training step, and adjustment step until the error of the first test result is less than the first threshold to obtain the second transaction detection model.
[0011] Interception step: After the obtained real-time transaction multi-dimensional data is input into the feature extraction network, real-time transaction data features are obtained. Input the real-time transaction data features into the second transaction detection model to obtain a transaction risk index. If the transaction risk index is greater than the first threshold, intercept the transaction in real time.
[0012] Preferably, the operation of adjusting the initial privacy protection budget parameter based on the error to obtain the adjusted privacy protection budget parameter ε′ is as follows:
[0013] Obtain the number N1 of historical transaction behavior data, the number N2 of historical user portrait data, the number N3 of historical environmental dynamic data, and the number N4 of historical cross-industry joint defense data in the historical multi-dimensional dataset.
[0014] Use k times the error as the clustering distance, and use a clustering algorithm to cluster N1 pieces of historical transaction behavior data, N2 pieces of historical user portrait data, N3 pieces of historical environmental dynamic data, and N4 pieces of historical cross-industry joint defense data, respectively obtaining the number of clusters n1 of historical transaction behavior data, the number of clusters n2 of historical user portrait data, the number of clusters n3 of historical environmental dynamic data, and the number of clusters n4 of historical cross-industry joint defense data.
[0015] The calculation method of the adjusted privacy protection budget parameter ε′ is:
[0016] ,
[0017] where is the error, and k≥1.
[0018] Preferably, the feature extraction network is VGG or ResNet.
[0019] Preferably, the transaction behavior data includes: transaction time, transaction frequency, geographical location, and device fingerprint; the user portrait data includes: historical behavior patterns, credit scores, and social network relevance; the environmental dynamic data includes: network latency, device abnormal status, and real-time public opinion events; the cross-industry joint defense data includes: security cooperation data with communication and e-commerce platforms.
[0020] Preferably, the graph formation method used by the graph neural network is as follows: taking transaction behavior, user profile, environmental dynamics, and industry characteristics as nodes of the graph. If the geographical location in the transaction behavior is less than a second threshold from the location in the device abnormal state or the location of the real-time public opinion event in the environmental dynamics, there is an edge between the transaction behavior node and the environmental dynamics node. If the geographical location in the transaction behavior is less than a third threshold from the security collaboration data related to communication and e-commerce platforms in the cross-industry joint defense data, there is an edge between the transaction behavior node and the industry characteristics node. If the location in the device abnormal state or the location of the real-time public opinion event in the environmental dynamics is less than a fourth threshold from the security collaboration data related to communication and e-commerce platforms in the cross-industry joint defense data, there is an edge between the environmental dynamics node and the industry characteristics node, and the edges between the user profile node and the transaction behavior node, environmental dynamics node, and industry characteristics node are determined based on the social network relevance in the user profile.
[0021] The present invention also proposes a real-time transaction risk detection and intelligent interception system based on multi-dimensional data, and the system includes:
[0022] An acquisition unit, which acquires a historical multi-dimensional data set related to transactions, and the historical multi-dimensional data set includes: historical transaction behavior data, historical user profile data, historical environmental dynamics data, and historical cross-industry joint defense data;
[0023] A processing unit, which performs differential privacy processing on the data in the historical multi-dimensional data set using an initial privacy protection budget parameter ε to obtain a processed differential privacy historical multi-dimensional data set;
[0024] A training unit, which uses a feature extraction network to extract features from the differential privacy historical multi-dimensional data to obtain a training sample feature set, and trains a graph neural network based on the training sample feature set to obtain a trained first transaction detection model;
[0025] An adjustment unit, which uses a test sample set to test the first transaction detection model to obtain a first test result. If the error of the first test result is greater than or equal to a first threshold, the initial privacy protection budget parameter is adjusted based on the error to obtain an adjusted privacy protection budget parameter ε';
[0026] An iteration unit, which uses the adjusted ε' to replace the ε and then repeats the operations of the processing unit, training unit, and adjustment unit until the error of the first test result is less than the first threshold, and obtains a second transaction detection model;
[0027] The interception unit obtains real-time transaction multi-dimensional data. After inputting it into the feature extraction network, real-time transaction data features are obtained. The real-time transaction data features are input into the second transaction detection model to obtain a transaction risk index. If the transaction risk index is greater than the first threshold, the transaction is intercepted in real time.
[0028] Preferably, the operation of adjusting the initial privacy protection budget parameter based on the error to obtain the adjusted privacy protection budget parameter ε' is as follows:
[0029] Obtain the quantity N1 of historical transaction behavior data, the quantity N2 of historical user portrait data, the quantity N3 of historical environmental dynamic data, and the quantity N4 of historical cross-industry joint defense data in the historical multi-dimensional dataset;
[0030] Use k times the error as the clustering distance and adopt a clustering algorithm to cluster N1 pieces of historical transaction behavior data, N2 pieces of historical user portrait data, N3 pieces of historical environmental dynamic data, and N4 pieces of historical cross-industry joint defense data, respectively obtaining the number of clusters n1 of historical transaction behavior data, the number of clusters n2 of historical user portrait data, the number of clusters n3 of historical environmental dynamic data, and the number of clusters n4 of historical cross-industry joint defense data;
[0031] The calculation method of the adjusted privacy protection budget parameter ε' is:
[0032] ,
[0033] where is the error, and k≥1.
[0034] Preferably, the feature extraction network is VGG or ResNet.
[0035] Preferably, the transaction behavior data includes: transaction time, transaction frequency, geographical location, and device fingerprint; the user portrait data includes: historical behavior patterns, credit scores, and social network relevance; the environmental dynamic data includes: network latency, device abnormal status, and real-time public opinion events; the cross-industry joint defense data includes: security collaboration data with communication and e-commerce platforms.
[0036] Preferably, the formation method of the graph used by the graph neural network is as follows: taking transaction behavior, user profile, environmental dynamics, and industry characteristics as the nodes of the graph. If the geographical location in the transaction behavior is less than the second threshold with the location in the device abnormal state in the environmental dynamics or the location of the real-time public opinion event, there is an edge between the transaction behavior node and the environmental dynamics node. If the geographical location in the transaction behavior is less than the third threshold with the security collaboration data related to communication and e-commerce platforms in the cross-industry joint defense data, there is an edge between the transaction behavior node and the industry characteristics node. If the location in the device abnormal state in the environmental dynamics or the location of the real-time public opinion event is less than the fourth threshold with the security collaboration data related to communication and e-commerce platforms in the cross-industry joint defense data, there is an edge between the environmental dynamics node and the industry characteristics node. And the edges between the user profile node and the transaction behavior node, the environmental dynamics node, and the industry characteristics node are determined based on the social network relevance in the user profile.
[0037] The present invention also proposes a computer-readable storage medium, on which computer program code is stored, and when the computer program code is executed by a computer, the method described in any one of the above is executed.
[0038] The technical effects of the present invention are as follows: A real-time transaction risk detection and intelligent interception method, system and storage medium based on multi-dimensional data of the present invention. The method includes: an acquisition step S101 of acquiring a historical multi-dimensional data set related to transactions, where the historical multi-dimensional data set includes: historical transaction behavior data, historical user portrait data, historical environmental dynamic data, and historical cross-industry joint defense data; a processing step S102 of performing differential privacy processing on the data in the historical multi-dimensional data set using an initial privacy protection budget parameter ε to obtain a processed differential privacy historical multi-dimensional data set; a training step S103 of using a feature extraction network to extract features from the differential privacy historical multi-dimensional data to obtain a training sample feature set, and training a graph neural network based on the training sample feature set to obtain a trained first transaction detection model; an adjustment step S104 of testing the first transaction detection model using a test sample set to obtain a first test result. If the error of the first test result is greater than or equal to a first threshold, the initial privacy protection budget parameter is adjusted based on the error to obtain an adjusted privacy protection budget parameter ε'; an iteration step S105 of replacing ε with the adjusted ε' and then repeating the processing step S102, the training step S103, and the adjustment step S104 until the error of the first test result is less than the first threshold to obtain a second transaction detection model; an interception step S106 of inputting the obtained real-time transaction multi-dimensional data into a feature extraction network to obtain real-time transaction data features, inputting the real-time transaction data features into the second transaction detection model to obtain a transaction risk index. If the transaction risk index is greater than the first threshold, the transaction is intercepted in real time. The present invention obtains a first test result by testing the first transaction detection model using a test sample set. If the error of the first test result is greater than or equal to the first threshold, the initial privacy protection budget parameter is adjusted based on the error to obtain an adjusted privacy protection budget parameter ε', that is, in the present invention, an adjustment of the initial privacy protection budget parameter based on the test error is set. After repeated iterations until the error of the first test result is less than the first threshold, a second transaction detection model is obtained, that is, the privacy protection budget parameter that can meet the requirements of neural network training in differential privacy calculation is obtained relatively quickly, improving the training efficiency of the model and ensuring data security. Another innovation point of the present invention is that features are first extracted using a feature extraction network, and then the extracted features are used as feature values of the graph neural network for calculation, improving the running efficiency of the graph neural network and overcoming the defects in the prior art.The present invention innovatively proposes a method of constructing a graph neural network. Instead of using users as nodes for graph construction, it constructs the graph based on the types of data obtained. The graph neural network constructed in this way can detect and intercept risks from multiple dimensions such as transaction behavior, user portraits, environmental dynamic data, and historical cross-industry joint defense data. As a result, the trained transaction detection model can perform risk detection and interception as long as it obtains more than one type of data among transaction behavior, user portraits, environmental dynamic data, and historical cross-industry joint defense data, improving the accuracy and reliability of risk detection and interception. BRIEF DESCRIPTION OF THE DRAWINGS
[0039] Other features, objects, and advantages of the present application will become more apparent by reading the detailed description of the non-limiting embodiments with reference to the following drawings.
[0040] Figure 1 is a flowchart of a real-time transaction risk detection and intelligent interception method based on multi-dimensional data according to an embodiment of the present invention.
[0041] Figure 2 is a structural diagram of a real-time transaction risk detection and intelligent interception system based on multi-dimensional data according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0042] The present application will be further described in detail below with reference to the drawings and embodiments. It can be understood that the specific embodiments described herein are only used to explain the related invention and are not intended to limit the invention. Additionally, it should be noted that for the sake of description, only parts related to the relevant invention are shown in the drawings.
[0043] It should be noted that, without conflict, the embodiments in the present application and the features in the embodiments can be combined with each other. The present application will be described in detail below with reference to the drawings and embodiments.
[0044] Figure 1 A real-time transaction risk detection and intelligent interception method based on multi-dimensional data according to the present invention is shown. The method includes:
[0045] An acquisition step S101 of acquiring a historical multi-dimensional data set related to transactions, where the historical multi-dimensional data set includes: historical transaction behavior data, historical user portrait data, historical environmental dynamic data, and historical cross-industry joint defense data;
[0046] A processing step S102 of performing differential privacy processing on the data in the historical multi-dimensional data set using an initial privacy protection budget parameter ε to obtain a processed differential privacy historical multi-dimensional data set;
[0047] Training step S103: Use the feature extraction network to extract features from the differentially private historical multi-dimensional data to obtain a training sample feature set, and train the graph neural network based on the training sample feature set to obtain a trained first transaction detection model;
[0048] Adjustment step S104: Use the test sample set to test the first transaction detection model to obtain a first test result. If the error of the first test result is greater than or equal to the first threshold, adjust the initial privacy protection budget parameter based on the error to obtain an adjusted privacy protection budget parameter ε';
[0049] Iteration step S105: Replace ε with the adjusted ε' and repeat the processing step S102, training step S103, and adjustment step S104 until the error of the first test result is less than the first threshold to obtain a second transaction detection model;
[0050] Interception step S106: Input the obtained real-time transaction multi-dimensional data into the feature extraction network to obtain real-time transaction data features, input the real-time transaction data features into the second transaction detection model to obtain a transaction risk index. If the transaction risk index is greater than the first threshold, intercept the transaction in real time.
[0051] An important inventive concept of the present invention is reflected in: In order to address the risk of data privacy leakage during the training of the neural network model, differential privacy calculation is introduced. However, it is difficult to accurately determine the privacy protection budget parameter in the prior art, that is, whether the data after differential privacy calculation can meet the training requirements of the neural network. In the present invention, the first transaction detection model is tested using the test sample set to obtain a first test result. If the error of the first test result is greater than or equal to the first threshold, the initial privacy protection budget parameter is adjusted based on the error to obtain an adjusted privacy protection budget parameter ε'. That is, in the present invention, an adjustment of the initial privacy protection budget parameter based on the test error is set. After repeated iteration until the error of the first test result is less than the first threshold, a second transaction detection model is obtained. That is, the privacy protection budget parameter that can meet the requirements of neural network training in differential privacy calculation is obtained relatively quickly, improving the training efficiency of the model and ensuring data security. Another innovation point of the present invention is: First, use the feature extraction network to extract features, and then use the extracted features as the feature values of the graph neural network for calculation, improving the operation efficiency of the graph neural network and overcoming the defects in the prior art.
[0052] In one embodiment, the operation of adjusting the initial privacy protection budget parameter based on the error to obtain an adjusted privacy protection budget parameter ε' is as follows:
[0053] Obtain the quantity N1 of historical transaction behavior data, the quantity N2 of historical user portrait data, the quantity N3 of historical environmental dynamic data, and the quantity N4 of historical cross-industry joint defense data in the historical multi-dimensional dataset;
[0054] Use k times the error as the clustering distance and adopt a clustering algorithm to cluster N1 pieces of historical transaction behavior data, N2 pieces of historical user portrait data, N3 pieces of historical environmental dynamic data, and N4 pieces of historical cross-industry joint defense data, respectively obtaining the number of clusters n1 of historical transaction behavior data, the number of clusters n2 of historical user portrait data, the number of clusters n3 of historical environmental dynamic data, and the number of clusters n4 of historical cross-industry joint defense data;
[0055] The calculation method of the adjusted privacy protection budget parameter ε′ is:
[0056] ,
[0057] where is the error, k ≥ 1, and N1, N2, N3, N4 are all integers greater than 10, and n1, n2, n3, n4 are also integers.
[0058] Since k times the error is used as the clustering distance, if the error is large, then the clustering distance is also large, resulting in a smaller number of clusters obtained by clustering, and is also a decreasing function, so that decreases rapidly, ensuring that the subsequent generated differential privacy historical multi-dimensional data can quickly reduce the error. Through actual testing, generally, iterating 5 - 10 times can generate differential privacy historical multi-dimensional data that meets the requirements, improving the training efficiency of the neural network model. That is, the present invention innovatively constructs a privacy protection budget parameter based on the relationship between the test error and the training data. Since this application involves transaction risk detection and real-time interception, generally, the data characteristics of risky transactions and normal transactions are different. The characteristics of normal and abnormal transactions can be reflected by clustering various historical data. Therefore, k times the error is used as the clustering distance. If the error is large, then the clustering distance is also large, resulting in a smaller number of clusters obtained by clustering, and is also a decreasing function, so that decreases rapidly, thus obtaining a privacy protection budget parameter that meets the requirements for neural network training. This is an important embodiment of the invention point of the present invention. Generally, in practical applications, the value of k is taken between 5 - 20, which depends on the requirements for the accuracy of the neural network.
[0059] In the present invention, the feature extraction network is VGG or ResNet. Of course, other feature extraction networks etc. can also be used.
[0060] In one embodiment, the transaction behavior data includes: transaction time, transaction frequency, geographical location, and device fingerprint; the user profile data includes: historical behavior patterns, credit scores, and social network relevance; the environmental dynamic data includes: network latency, device abnormal status, and real-time public opinion events; the cross-industry joint defense data includes: security collaboration data with communication and e-commerce platforms. In the present invention, various types of data related to transaction risks are comprehensively used to comprehensively judge transaction risks, improving the accuracy of risk detection and interception.
[0061] In one embodiment, the formation method of the graph used by the graph neural network is as follows: using transaction behavior, user profile, environmental dynamics, and industry characteristics as nodes of the graph. If the geographical location in the transaction behavior is less than a second threshold from the location in the device abnormal status or the location of the real-time public opinion event in the environmental dynamics, then there is an edge between the transaction behavior node and the environmental dynamics node. If the geographical location in the transaction behavior is less than a third threshold from the security collaboration data with communication and e-commerce platforms in the cross-industry joint defense data, then there is an edge between the transaction behavior node and the industry characteristics node. If the location in the device abnormal status or the location of the real-time public opinion event in the environmental dynamics is less than a fourth threshold from the security collaboration data with communication and e-commerce platforms in the cross-industry joint defense data, then there is an edge between the environmental dynamics node and the industry characteristics node. And based on the social network relevance in the user profile, the edges between the user profile node and the transaction behavior node, the environmental dynamics node, and the industry characteristics node are determined.
[0062] In the present invention, the method of constructing the graph in this way can solve the problem that the historical quantities in the background art are inconsistent, resulting in only the data with the smallest quantity being used as samples in the neural network training. That is, the traditional training method can only use MIN(N1, N2, N3, N4) data among the quantity N1 of historical transaction behavior data, the quantity N2 of historical user portrait data, the quantity N3 of historical environmental dynamic data, and the quantity N4 of historical cross-industry joint defense data to form training samples after alignment for training. That is, the traditional training method organizes data with users as nodes, that is, various historical data are combined into a data vector as the historical data of a user. In this way, the collected historical data needs to be preprocessed into user data first, and some other collected historical data cannot be used. The present invention innovatively proposes that the graph construction method of the graph neural network does not construct the graph with users as nodes, but constructs the graph according to the obtained data types. The graph neural network constructed in this way can detect and intercept risks from multiple dimensions such as transaction behavior, user portrait, environmental dynamic data, and historical cross-industry joint defense data. Thus, the trained transaction detection model can perform risk detection and interception as long as it obtains more than one type of data among transaction behavior, user portrait, environmental dynamic data, and historical cross-industry joint defense data, improving the accuracy and reliability of risk detection and interception. For example, this graph neural network can detect the following risks based only on one of transaction behavior, user portrait, and environmental dynamic data. If an account initiates large transfers in Beijing and Chongqing within 2 minutes, the system can combine the distance between the two places and traffic data to determine the risk of physical inaccessibility. This is another important inventive concept of the present invention.
[0063] In the present invention, the data features extracted by the feature extraction network are used as the feature values of the nodes of the graph neural network. If there is an edge between two nodes, the weight of the edge is set to 1, which improves the operation efficiency of the graph neural network and overcomes the defects in the prior art.
[0064] Figure 2 Fig. shows a real-time transaction risk detection and intelligent interception system based on multi-dimensional data of the present invention, including:
[0065] An acquisition unit 201 for acquiring a historical multi-dimensional data set related to transactions, where the historical multi-dimensional data set includes: historical transaction behavior data, historical user portrait data, historical environmental dynamic data, and historical cross-industry joint defense data;
[0066] A processing unit 202 for performing differential privacy processing on the data in the historical multi-dimensional data set using an initial privacy protection budget parameter ε to obtain a processed differential privacy historical multi-dimensional data set;
[0067] The training unit 203 uses a feature extraction network to extract features from the differential privacy historical multi-dimensional data to obtain a training sample feature set, and trains a graph neural network based on the training sample feature set to obtain a trained first transaction detection model;
[0068] The adjustment unit 204 uses a test sample set to test the first transaction detection model to obtain a first test result. If the error of the first test result is greater than or equal to a first threshold, the initial privacy protection budget parameter is adjusted based on the error to obtain an adjusted privacy protection budget parameter ε';
[0069] The iteration unit 205 uses the adjusted ε' to replace ε and then repeats the operations of the processing unit 202, the training unit 203, and the adjustment unit 204 until the error of the first test result is less than the first threshold, obtaining a second transaction detection model;
[0070] The interception unit 206 obtains real-time transaction data features after inputting the obtained real-time transaction multi-dimensional data into the feature extraction network, inputs the real-time transaction data features into the second transaction detection model to obtain a transaction risk index, and if the transaction risk index is greater than the first threshold, intercepts the transaction in real time.
[0071] An important inventive concept of the present invention is reflected in: in order to reduce the risk of data privacy leakage during the training of a neural network model, differential privacy calculation is introduced. However, it is difficult to accurately determine the privacy protection budget parameter in the prior art, that is, whether the data after differential privacy calculation can meet the training requirements of the neural network. In the present invention, a first test result is obtained by using a test sample set to test the first transaction detection model. If the error of the first test result is greater than or equal to a first threshold, the initial privacy protection budget parameter is adjusted based on the error to obtain an adjusted privacy protection budget parameter ε', that is, in the present invention, an adjustment of the initial privacy protection budget parameter based on the test error is set. After repeated iterations until the error of the first test result is less than the first threshold, a second transaction detection model is obtained, that is, the privacy protection budget parameter that can meet the requirements of neural network training in differential privacy calculation is obtained relatively quickly, improving the training efficiency of the model and ensuring data security. Another innovation point of the present invention is: first, a feature extraction network is used to extract features, and then the extracted features are used as the feature values of the graph neural network for calculation, improving the operation efficiency of the graph neural network and overcoming the defects in the prior art.
[0072] In one embodiment, the operation of adjusting the initial privacy protection budget parameter based on the error to obtain an adjusted privacy protection budget parameter ε' is:
[0073] Obtain the quantity N1 of historical transaction behavior data, the quantity N2 of historical user profile data, the quantity N3 of historical environmental dynamic data, and the quantity N4 of historical cross-industry joint defense data in the historical multi-dimensional dataset;
[0074] Use k times the error as the clustering distance and adopt a clustering algorithm to cluster N1 pieces of historical transaction behavior data, N2 pieces of historical user profile data, N3 pieces of historical environmental dynamic data, and N4 pieces of historical cross-industry joint defense data, respectively obtaining the number of clusters n1 of historical transaction behavior data, the number of clusters n2 of historical user profile data, the number of clusters n3 of historical environmental dynamic data, and the number of clusters n4 of historical cross-industry joint defense data;
[0075] The calculation method of the adjusted privacy protection budget parameter ε′ is:
[0076] ,
[0077] where, is the error, k ≥ 1, and N1, N2, N3, N4 are all integers greater than 10, and n1, n2, n3, n4 are also all integers.
[0078] Since k times the error is used as the clustering distance, if the error is large, then the clustering distance is also large, resulting in a smaller number of clusters obtained by clustering, and is also a decreasing function, thus making rapidly decrease, ensuring that the subsequent generated differentially private historical multi-dimensional data can quickly reduce the error. Through actual testing, generally, iterating 5 - 10 times can generate differentially private historical multi-dimensional data that meets the requirements, improving the training efficiency of the neural network model. That is, the present invention innovatively constructs a privacy protection budget parameter based on the relationship between the test error and the training data. Since this application involves transaction risk detection and real-time interception, generally speaking, the data characteristics of risky transactions and normal transactions are different. The characteristics of normal and abnormal transactions can be reflected by clustering various historical data. Thus, k times the error is used as the clustering distance. If the error is large, then the clustering distance is also large, resulting in a smaller number of clusters obtained by clustering, and is also a decreasing function, thus making rapidly decrease, thereby obtaining a privacy protection budget parameter that meets the requirements for neural network training. This is an important embodiment of the present invention. Generally speaking, in practical applications, the value of k is taken between 5 - 20, which depends on the requirements for the accuracy of the neural network.
[0079] In the present invention, the feature extraction network is VGG or ResNet. Of course, other feature extraction networks, etc., can also be used.
[0080] In one embodiment, the transaction behavior data includes: transaction time, transaction frequency, geographical location, and device fingerprint; the user profile data includes: historical behavior patterns, credit scores, and social network relevance; the environmental dynamic data includes: network latency, device abnormal status, and real-time public opinion events; the cross-industry joint defense data includes: security collaboration data with communication and e-commerce platforms. In the present invention, various types of data related to transaction risks are comprehensively used to comprehensively judge transaction risks, improving the accuracy of risk detection and interception.
[0081] In one embodiment, the graph formation method used by the graph neural network is as follows: taking transaction behavior, user profile, environmental dynamics, and industry characteristics as the nodes of the graph. If the geographical location in the transaction behavior is less than a second threshold from the location in the device abnormal status or the location of the real-time public opinion event in the environmental dynamics, then there is an edge between the transaction behavior node and the environmental dynamics node. If the geographical location in the transaction behavior is less than a third threshold from the security collaboration data with communication and e-commerce platforms in the cross-industry joint defense data, then there is an edge between the transaction behavior node and the industry characteristics node. If the location in the device abnormal status or the location of the real-time public opinion event in the environmental dynamics is less than a fourth threshold from the security collaboration data with communication and e-commerce platforms in the cross-industry joint defense data, then there is an edge between the environmental dynamics node and the industry characteristics node. And based on the social network relevance in the user profile, the edges between the user profile node and the transaction behavior node, environmental dynamics node, and industry characteristics node are determined.
[0082] In the present invention, this way of constructing the graph can solve the problem in the background technology where the historical quantities are inconsistent, resulting in only the data with the smallest quantity being used as samples in neural network training. That is, the traditional training method can only use MIN(N1, N2, N3, N4) data among the quantity N1 of historical transaction behavior data, the quantity N2 of historical user profile data, the quantity N3 of historical environmental dynamic data, and the quantity N4 of historical cross-industry joint defense data after alignment to form training samples for training. That is, the traditional training method organizes data with users as nodes, that is, various types of historical data are combined into a data vector as the historical data of a user. In this way, the collected historical data needs to be preprocessed into user data first, and some other collected historical data cannot be used. The present invention innovatively proposes a graph construction method for the graph neural network that does not use users as nodes for graph construction, but constructs the graph according to the types of data obtained. The graph neural network constructed in this way can detect and intercept risks from multiple dimensions such as transaction behavior, user profile, environmental dynamic data, and historical cross-industry joint defense data. Thus, the trained transaction detection model can perform risk detection and interception as long as it obtains more than one type of data among transaction behavior, user profile, environmental dynamic data, and historical cross-industry joint defense data, improving the accuracy and reliability of risk detection and interception. This is another important inventive concept of the present invention.
[0083] In the present invention, each data feature extracted by the feature extraction network is used as the feature value of each node of the graph neural network. If there is an edge between two nodes, the weight of the edge is set to 1, which improves the operation efficiency of the graph neural network and overcomes the defects in the prior art.
[0084] For the convenience of description, the above system is described by dividing it into various units according to functions. Of course, when implementing the present application, the functions of each unit can be implemented in the same or multiple software and / or hardware.
[0085] From the description of the above embodiments, those skilled in the art can clearly understand that the present application can be implemented by means of software plus a necessary general hardware platform. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art can be embodied in the form of a software product. This computer software product can be stored in a storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the system described in each embodiment or some parts of the embodiments of the present application.
[0086] Finally, it should be noted that the above embodiments are only used to illustrate rather than limit the technical solution of the present invention. Although the present invention has been described in detail with reference to the above embodiments, those of ordinary skill in the art should understand that the present invention can still be modified or equivalently replaced, and any modification or partial replacement without departing from the spirit and scope of the present invention shall be covered by the scope of the claims of the present invention.
Claims
1. A real-time transaction risk detection and intelligent interception method based on multi-dimensional data, characterized in that The method includes: An acquisition step of acquiring a historical multi-dimensional dataset related to transactions, where the historical multi-dimensional dataset includes: historical transaction behavior data, historical user portrait data, historical environmental dynamic data, and historical cross-industry joint defense data; A processing step of performing differential privacy processing on the data in the historical multi-dimensional dataset using an initial privacy protection budget parameter ε to obtain a processed differential privacy historical multi-dimensional dataset; A training step of using a feature extraction network to extract features from the differential privacy historical multi-dimensional data to obtain a training sample feature set, and training a graph neural network based on the training sample feature set to obtain a trained first transaction detection model; An adjustment step of using a test sample set to test the first transaction detection model to obtain a first test result. If the error of the first test result is greater than or equal to a first threshold, then adjusting the initial privacy protection budget parameter based on the error to obtain an adjusted privacy protection budget parameter ε'; An iteration step of using the adjusted ε' to replace ε and then repeating the processing step, the training step, and the adjustment step until the error of the first test result is less than the first threshold to obtain a second transaction detection model; An interception step of inputting the obtained real-time transaction multi-dimensional data into the feature extraction network to obtain real-time transaction data features, inputting the real-time transaction data features into the second transaction detection model to obtain a transaction risk index, and if the transaction risk index is greater than the first threshold, then performing real-time interception on the transaction; Wherein, the operation of adjusting the initial privacy protection budget parameter based on the error to obtain the adjusted privacy protection budget parameter ε' is: Obtaining the quantity N1 of historical transaction behavior data, the quantity N2 of historical user portrait data, the quantity N3 of historical environmental dynamic data, and the quantity N4 of historical cross-industry joint defense data in the historical multi-dimensional dataset; Using k times the error as the clustering distance and adopting a clustering algorithm to cluster N1 pieces of historical transaction behavior data, N2 pieces of historical user portrait data, N3 pieces of historical environmental dynamic data, and N4 pieces of historical cross-industry joint defense data to respectively obtain the number of clusters n1 of historical transaction behavior data, the number of clusters n2 of historical user portrait data, the number of clusters n3 of historical environmental dynamic data, and the number of clusters n4 of historical cross-industry joint defense data; The calculation method of the adjusted privacy protection budget parameter ε' is: Where err is the error, and the value of k ranges from 5 to 20.
2. The method according to claim 1, characterized in that The feature extraction network is VGG or ResNet.
3. The method according to claim 2, wherein The transaction behavior data includes: transaction time, transaction frequency, geographical location, and device fingerprint; the user portrait data includes: historical behavior patterns, credit scores, and social network correlations; the environmental dynamic data includes: network latency, device abnormal states, and real-time public opinion events; the cross-industry joint defense data includes: security collaboration data with communication and e-commerce platforms.
4. The method according to claim 3, wherein The formation method of the graph used by the graph neural network is as follows: taking transaction behavior, user portrait, environmental dynamics, and industry characteristics as the nodes of the graph. If the geographical location in the transaction behavior is less than the second threshold with the location in the device abnormal state in the environmental dynamics or the location of the real-time public opinion event, there is an edge between the transaction behavior node and the environmental dynamics node. If the geographical location in the transaction behavior is less than the third threshold with the security collaboration data related to communication and e-commerce platforms in the cross-industry joint defense data, there is an edge between the transaction behavior node and the industry characteristics node. If the location in the device abnormal state in the environmental dynamics or the location of the real-time public opinion event is less than the fourth threshold with the security collaboration data related to communication and e-commerce platforms in the cross-industry joint defense data, there is an edge between the environmental dynamics node and the industry characteristics node, and the edges between the user portrait node and the transaction behavior node, environmental dynamics node, and industry characteristics node are determined based on the social network relevance in the user portrait.
5. A real-time transaction risk detection and intelligent interception device based on multi-dimensional data, characterized in that, The device includes: an acquisition unit that acquires a historical multi-dimensional data set related to transactions, where the historical multi-dimensional data set includes: historical transaction behavior data, historical user portrait data, historical environmental dynamics data, and historical cross-industry joint defense data; a processing unit that performs differential privacy processing on the data in the historical multi-dimensional data set using an initial privacy protection budget parameter ε to obtain a processed differential privacy historical multi-dimensional data set; a training unit that uses a feature extraction network to extract features from the differential privacy historical multi-dimensional data to obtain a training sample feature set, and trains a graph neural network based on the training sample feature set to obtain a trained first transaction detection model; an adjustment unit that tests the first transaction detection model using a test sample set to obtain a first test result. If the error of the first test result is greater than or equal to the first threshold, the initial privacy protection budget parameter is adjusted based on the error to obtain an adjusted privacy protection budget parameter ε'; an iteration unit that repeats the operations of the processing unit, training unit, and adjustment unit using the adjusted ε' to replace ε until the error of the first test result is less than the first threshold, to obtain a second transaction detection model; an interception unit that inputs the obtained real-time transaction multi-dimensional data into the feature extraction network to obtain real-time transaction data features, inputs the real-time transaction data features into the second transaction detection model to obtain a transaction risk index, and if the transaction risk index is greater than the first threshold, intercepts the transaction in real time; wherein, the operation of adjusting the initial privacy protection budget parameter based on the error to obtain the adjusted privacy protection budget parameter ε' is: acquiring the quantity N1 of historical transaction behavior data, the quantity N2 of historical user portrait data, the quantity N3 of historical environmental dynamics data, and the quantity N4 of historical cross-industry joint defense data in the historical multi-dimensional data set; Using k times the said error as the clustering distance, cluster the N1 historical transaction behavior data, N2 historical user portrait data, N3 historical environmental dynamic data, and N4 historical cross-industry joint defense data by using a clustering algorithm, and respectively obtain the number of clusters n1 of the historical transaction behavior data, the number of clusters n2 of the historical user portrait data, the number of clusters n3 of the historical environmental dynamic data, and the number of clusters n4 of the historical cross-industry joint defense data; The calculation method of the adjusted privacy protection budget parameter ε′ is: where err is the said error, and the value of k ranges from 5 to 20.
6. The device according to claim 5, characterized in that The feature extraction network is VGG or ResNet.
7. The device according to claim 6, characterized in that The transaction behavior data includes: transaction time, transaction frequency, geographical location, and device fingerprint; the user portrait data includes: historical behavior pattern, credit score, and social network relevance; the environmental dynamic data includes: network latency, device abnormal state, and real-time public opinion event; the cross-industry joint defense data includes: security collaboration data with communication and e-commerce platforms.
8. A computer-readable storage medium, on which computer program code is stored, and when the computer program code is executed by a computer, the method according to any one of claims 1-4 above is executed.
Citation Information
Patent Citations
Telecommunication fraud identification model training method and device, equipment and storage medium
CN118296348A
Large model training method, medium and system based on differential privacy mechanism
CN119494408A