Continuous Financial Fraud Detection Method Based on Dynamic Feature Space Transformation

Through dynamic feature spatial transformation and dynamic adjustment of spherical decision-making boundaries, the problem of insufficient dependence and generalization capabilities of existing financial fraud detection methods on data annotation is solved, and efficient and robust financial fraud detection is achieved.

CN119863315BActive Publication Date: 2025-07-01SOUTHWESTERN UNIV OF FINANCE & ECONOMICS
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510349978.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-24
Publication Date
2025-07-01
Estimated Expiration
2045-03-24

AI Technical Summary

Technical Problem

The existing financial fraud detection methods rely on supervised learning to require a large amount of labeled data and lack generalization capabilities, or rely on unsupervised learning but are difficult to define normal transaction boundaries, which are susceptible to noise and outliers, resulting in high false positive rates.

Method used

The continuous financial fraud detection method based on dynamic feature spatial transformation is adopted, and financial fraud detection is carried out by obtaining the characteristics of the transaction sample, dynamically adjusting the target dimension of the random projection, calculating the center of mass and boundary range of the normal transaction sample, constructing the initial spherical decision-making boundary and dynamically adjusting its radius.

Benefits of technology

It improves the adaptability and generalization ability of the model, maintains good detection performance when data is sufficient and scarce, reduces interference from data noise and outliers, and significantly improves the accuracy and robustness of fraud detection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119863315B_ABST
    Figure CN119863315B_ABST
Patent Text Reader

Abstract

The present invention discloses a continuous financial fraud detection method based on dynamic feature space transformation, belonging to the technical field of financial fraud detection, including: obtaining the features of transaction samples; dynamically adjusting the target dimension of random projection according to the data volume to perform dynamic feature space transformation; constructing an adaptive spherical decision boundary, and adapting to new data through a centroid calculation and radius update mechanism; performing financial fraud detection according to the decision boundary. Through dynamic feature space transformation, when there is sufficient data, the feature space can be automatically expanded to capture more complex patterns; when the data is scarce, overfitting of the detection model can be avoided by compressing the feature space, improving the generalization ability of the model and maintaining good detection performance on new data. At the same time, updating the centroid of the normal transaction samples according to the newly added transaction samples and dynamically adjusting the radius of the spherical decision boundary can continuously adapt to the financial dynamic detection scenario, effectively reducing the interference of data noise and outliers.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of financial fraud detection, and particularly to a continuous financial fraud detection method based on dynamic feature space transformation. Background Art

[0002] In recent years, anomaly detection technology has been widely used in the field of financial fraud detection. The purpose of anomaly detection is to identify behaviors that do not conform to normal transaction patterns, which may imply fraud or other malicious activities. However, existing anomaly detection methods mostly rely on supervised learning, which requires a large number of labeled normal transaction and fraud transaction samples for training. Obtaining these labeled data is both time-consuming and expensive, and cannot cover all possible fraud types. In addition, when supervised learning models encounter new types of fraud behaviors, they are prone to overfitting, resulting in insufficient generalization ability of the models. To solve the problem of dependence on data annotation in supervised learning, unsupervised learning methods have been proposed. However, although unsupervised learning methods do not need to rely on labeled data, they lack a clear definition of the boundary of normal transactions and are easily interfered by data noise and outliers, resulting in a high false alarm rate. In addition, the data feature dimensions processed by unsupervised methods are fixed and difficult to dynamically adjust according to the data volume, resulting in insufficient generalization ability of the models and unable to maintain good performance on new data. Summary of the Invention

[0003] The purpose of the present invention is to overcome the problems of the prior art and provide a continuous financial fraud detection method based on dynamic feature space transformation.

[0004] The purpose of the present invention is achieved through the following technical solutions: A continuous financial fraud detection method based on dynamic feature space transformation, the method comprising the following steps:

[0005] Obtain the features of transaction samples, where the transaction samples include transaction note information, chat records, social media information, and historical transaction records;

[0006] Dynamically adjust the target dimension of random projection according to the data volume of the transaction samples, and then perform dynamic feature space transformation;

[0007] Calculate the centroid of all normal transaction samples; obtain the distance distribution of each normal transaction sample to the centroid, and then learn the boundary range of the normal transaction samples; calculate the average distribution range of the normal transaction samples, and construct an initial spherical decision boundary according to the average distribution range; update the centroid of the normal transaction samples according to the newly added transaction samples, and dynamically adjust the radius of the spherical decision boundary;

[0008] Perform financial fraud detection by determining whether the distance between the transaction sample to be detected and the centroid of the normal transaction samples is within the radius of the spherical decision boundary, and output the detection result.

[0009] In one example, obtaining the features of the transaction samples includes:

[0010] Extracting the features of image transaction samples using an image detection model, and / or extracting the features of text transaction samples according to a text detection model, and / or extracting the features of voice transaction samples according to a voice detection model.

[0011] In one example, before the step of dynamically adjusting the target dimension of the random projection according to the data volume of the transaction samples, it further includes:

[0012] Calculating the global distance matrix of all transaction samples and optimizing the distance relationship between samples using a distance-aware contrast loss function.

[0013] In one example, the expression of the distance-aware contrast loss function is:

[0014] ;

[0015] ;

[0016] Wherein, Represents the total distance-aware contrast loss of positive sample pairs; Represents the set of positive sample pairs, and the positive samples are normal transaction samples; Represents a positive sample pair The distance-aware loss between; Represents a positive sample pair The distance between; Represents the set of negative sample pairs, and the negative samples are potential fraud transaction samples; Represents a hyperparameter; Represents a positive sample And the negative sample The distance between; Represents a positive sample And the negative sample The distance between.

[0017] In one example, dynamically adjusting the target dimension of the random projection according to the data volume of the transaction samples, and then performing dynamic feature space transformation, includes:

[0018] Constructing a random projection matrix using orthogonal random projection, and the target dimension in the random projection matrix is dynamically adjusted according to the data volume of the transaction samples. If the data volume is greater than the threshold, the target dimension is increased; if the data volume is less than the threshold, the target dimension is decreased; if the data volume is equal to the threshold, the target dimension remains unchanged;

[0019] Mapping the features of the transaction samples to a new feature space according to the random projection matrix to achieve dynamic feature space transformation.

[0020] In one example, when constructing the initial spherical decision boundary, the spherical decision boundary loss function is used to balance the risks of misjudging normal transaction samples as fraud transaction samples and misjudging fraud transaction samples as normal transaction samples. The spherical decision boundary loss function has the following expression:

[0021] ;

[0022] where represents the total number of samples; is an indicator indicating whether the sample exceeds the spherical decision boundary; represents the feature representation of each transaction sample; is the centroid of the th sample; represents the th radius of the spherical decision boundary.

[0023] In one example, the update expression for the radius of the spherical decision boundary is:

[0024] ;

[0025] where represents the updated radius of the th spherical decision boundary; represents the radius of the th spherical decision boundary before update; represents the gradient of the decision boundary loss function with respect to the radius; represents the partial derivative.

[0026] In one example, for financial fraud detection by determining whether the distance between the transaction sample to be detected and the centroid of the normal transaction samples is within the radius of the spherical decision boundary, it includes:

[0027] If the distance between the transaction sample to be detected and the centroid of the normal transaction samples is less than or equal to the radius of the spherical decision boundary, output the detection result of normal transaction;

[0028] If the distance between the transaction sample to be detected and the centroid of the normal transaction samples is greater than the radius of the spherical decision boundary, output the detection result of abnormal transaction and trigger an alarm, and / or, conduct manual review and analysis and output the final detection result;

[0029] Update the samples with the detection result determined as normal transactions to the training dataset, and optimize the spherical decision boundary using the updated training dataset.

[0030] It should be further noted that the technical features corresponding to the above method examples can be combined or replaced with each other to form a new technical solution.

[0031] Compared with the prior art, the beneficial effects of the present invention are as follows:

[0032] 1. In one example, by dynamically adjusting the dimension of random projection according to the data volume, dynamic feature space transformation is realized, which can improve the adaptability of the model, that is: when the data is sufficient, the feature space is automatically expanded to capture more complex patterns, thereby improving the detection accuracy; when the data is scarce, overfitting of the detection model can be avoided by compressing the feature space, the generalization ability of the model is improved, good detection performance can be maintained on new data, and the robustness of the model is enhanced.

[0033] At the same time, by calculating the average distribution range of normal transaction samples, an initial spherical decision boundary is defined, which can ensure that most normal transaction samples are included within the decision boundary, and at the same time avoid the problem of increased false alarm rate caused by an overly large decision boundary; by updating the centroid of normal transaction samples according to newly added transaction samples and dynamically adjusting (expanding or shrinking) the radius of the spherical decision boundary, it can continuously adapt to the financial dynamic detection scenario and effectively reduce the interference of data noise and outliers.

[0034] 2. In one example, since financial fraud behaviors account for a relatively small proportion in transaction data, existing methods often have difficulty effectively identifying a small number of fraud transactions. The present invention optimizes the distance relationship between normal transactions and fraud transactions through a distance-aware contrastive learning method, minimizes the distance between positive sample pairs, and at the same time maximizes the distance between negative sample pairs, thereby optimizing the decision boundary between normal transaction samples and potential fraud transaction samples, enabling the model to still efficiently identify fraud behaviors when dealing with data imbalance problems, and significantly improving the detection accuracy of the model. BRIEF DESCRIPTION OF THE DRAWINGS

[0035] The following further details the specific embodiments of the present invention with reference to the drawings. The drawings described herein are used to provide a further understanding of the present application and form a part of the present application. The same reference numerals are used to represent the same or similar parts in these drawings. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation of the present application.

[0036] Figure 1 It is a flowchart of the method provided by an example of the present invention;

[0037] Figure 2 It is a flowchart of the method provided by a preferred example of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0038] The technical solution of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0039] In the description of the present invention, it should be noted that unless otherwise clearly defined and limited, the term "connection" should be understood in a broad sense. For example, it can be directly connected or indirectly connected through an intermediate medium. For those of ordinary skill in the art, the specific meaning of the above terms in the present invention can be understood according to specific situations.

[0040] In addition, the technical features involved in different embodiments of the present invention described below can be combined with each other as long as they do not conflict with each other.

[0041] In one example, as Figure 1 shown, a continuous financial fraud detection method based on dynamic feature space transformation, the method includes the following steps:

[0042] S1: Obtain the features of the transaction samples.

[0043] Among them, the transaction samples can be different types of financial transaction samples, such as text, images, voices, etc. Specifically, the transaction samples include transaction note information, chat records, social media information, and historical transaction records, etc. Specifically, the transaction samples include consumption records, bank loan records, securities trading records, etc., which can reflect transaction time, transaction location, transaction frequency, transaction account, etc. Preferably, before extracting the features of the transaction samples, data preprocessing can also be performed, such as data cleaning, data normalization processing, data augmentation processing, etc.

[0044] S2: Dynamically adjust the target dimension of the random projection according to the data volume of the transaction samples, and then perform dynamic feature space transformation.

[0045] Specifically, through dynamic feature space transformation, the dimension of the feature space can be automatically adjusted according to the data volume of the transaction samples. When the data is sufficient, the feature space is expanded to enhance the discrimination ability of the model; while when the data is less, the dimension reduction means is used to maintain the robustness of the model and avoid overfitting, so as to ensure that the model can maintain a stable performance under different data volume conditions.

[0046] S3: Calculate the centroid of all normal transaction samples; obtain the distance distribution of each normal transaction sample to the centroid, and then learn the boundary range of normal transaction samples; after determining the boundary range of normal transaction samples, calculate the average distribution range of normal transaction samples, and construct an initial spherical decision boundary based on the average distribution range; update the centroid of normal transaction samples according to the newly added transaction samples, and dynamically adjust the radius of the spherical decision boundary.

[0047] Among them, the centroid is used to represent the typical distribution of normal transaction samples, and can provide a basis for the subsequent construction of the decision boundary. The average distribution range is the average distance of each normal transaction sample to the centroid. By constructing an initial spherical decision boundary based on the average distribution range, it can ensure that most normal transaction samples can be included within the decision boundary, while avoiding the problem of increasing the false alarm rate caused by an overly large decision boundary. When new transaction samples are added, regularly analyze the latest normal transaction samples, update the centroid representing the normal transaction samples, and expand or shrink the radius of the spherical decision boundary, so that the decision boundary can continuously adapt to different transaction scenarios and effectively reduce the interference of data noise and outliers.

[0048] S4: Detect financial fraud by determining whether the distance between the transaction sample to be detected and the centroid of the normal transaction sample is within the radius of the spherical decision boundary, and output the detection result.

[0049] Specifically, when performing fraud detection, for the transaction sample to be detected, calculate its distance to the centroid of the normal transaction sample, and determine whether it belongs to a normal transaction based on the size of the distance and the radius of the spherical decision boundary. If the data point of the transaction sample to be detected falls within the boundary, that is: the distance between the transaction sample to be detected and the centroid of the normal transaction sample is less than or equal to the radius of the spherical decision boundary, it is a normal transaction, and the detection result of the normal transaction is output. If the data point of the transaction sample to be detected falls outside the boundary, that is: the distance between the transaction sample to be detected and the centroid of the normal transaction sample is greater than the radius of the spherical decision boundary, it may be a fraudulent transaction, and the detection result of the fraudulent transaction is output.

[0050] In an example, obtain the features of the transaction sample, including:

[0051] Use an image detection model to extract the features of image transaction samples, and / or extract the features of text transaction samples according to a text detection model, and / or extract the features of voice transaction samples according to a voice detection model.

[0052] Among them, the image detection model, text detection model, and speech detection model are all neural network models. The image detection model can be a convolutional neural network, a deep convolutional neural network, etc. The text detection model can be a BERT model, a Transformer model, etc. The speech detection model can be a recurrent neural network, etc. It is also possible to convert speech transaction samples into text information, and then extract the features of the transaction samples through the text detection model. Preferably, when the transaction samples are of different types, after obtaining the features of the transaction samples through different types of detection models, a multi-modal data fusion processing technology can be used to integrate information from different modalities, thereby improving the accuracy and robustness of transaction detection.

[0053] Optionally, when the data type of the transaction sample is text, text transaction samples from different sources are integrated to construct a multi-dimensional text data set to provide rich information support for subsequent fraud detection. In the present invention, all the transaction samples used are only normal transaction samples and do not include any fraud transaction samples, ensuring that the model is trained and predicted only based on normal transaction behaviors.

[0054] First, the BERT model is used to process and extract features from the transaction samples. The BERT model can capture the deep semantic information in the text through a bidirectional context encoding method and generate the context representation of each word. Suppose the input transaction sample is a word sequence , the BERT model first maps these words to a high-dimensional word vector space to obtain the embedding representation of each word:

[0055] [CLS, T 1 , T 2 , ⋯, T L ]∈ R (L + 1)×H ;

[0056] Among them, [CLS] represents a special classification marker used to summarize the semantic information of the entire sentence; represents the embedding representation of each marker in the sequence; represents the length of the sequence; represents the dimension of the embedding; represents the set of real numbers.

[0057] To solve the problem of the variable length of the BERT output sequence, the present invention uses a pooling operation for processing. Specifically, the mean pooling method can be used or the output of the [CLS] marker can be directly used as the representation of the text. Among them, the mean pooling operation is as follows:

[0058] ;

[0059] Among them, is the preliminary feature representation of the transaction sample, representing the overall semantic information of the text-based transaction sample. Represents the mean pooling operation; the mean pooling operation takes the average of the representations of all tokens to obtain a fixed-length text vector. A token is the basic unit of text data and can be a word or a character. In this way, the BERT model can effectively extract the semantic information of the text and provide high-quality features for subsequent fraud detection.

[0060] After generating the preliminary feature representation of the text, the present invention further optimizes the preliminary feature representation through a fully connected layer and a ReLU activation function. Specifically, the feature representation after linear transformation is:

[0061] ;

[0062] Among them, , is the weight matrix of the fully connected layer; , is the bias term; is the dimension of the output space; is the optimized feature representation.

[0063] To enhance the model's ability to distinguish different texts, the present invention adopts the cross-entropy loss function , which is used to reduce the difference between the normal transaction category and the actual label. The expression of the cross-entropy loss function is:

[0064] ;

[0065] Among them, is the total number of samples of normal transactions; represents the linear classifier; is the th classification score; is the true label of the sample; is the total number of categories.

[0066] In this example, by using the BERT model to extract sample features, it is possible to deeply understand the complex semantic relationships in transaction texts, especially when dealing with unstructured data such as transaction remarks and customer chat records, improving the ability to identify fraud behaviors.

[0067] In one example, before the step of dynamically adjusting the target dimension of random projection according to the data volume of the transaction sample, it further includes:

[0068] Calculate the global distance matrix of all transaction samples and optimize the distance relationship between samples using the distance-aware contrast loss function.

[0069] Specifically, metrics such as Euclidean distance, cosine similarity, or Mahalanobis distance can be used to calculate the distances between transaction samples, determine the similarity of each transaction sample in the high-dimensional feature space, and construct a global distance matrix of transaction samples. By calculating the relative distances between samples, it is possible to determine which transaction behaviors belong to typical normal transaction patterns and which transaction samples deviate from the normal transaction patterns, thus constructing an efficient foundation for fraud detection.

[0070] Furthermore, a distance-aware contrastive loss function is adopted to optimize the distance relationship between transaction samples, making the normal transaction samples more closely aggregated in the feature space, while keeping a large distance between abnormal transactions (fraudulent transactions) and normal transaction samples, thereby enhancing the model's recognition ability. During the training process, the model will learn an optimal feature representation, making the distribution of normal transactions more concentrated in the embedding space, while potential fraudulent transactions are more dispersed in this space due to their differences from normal transactions, thus improving the detection accuracy.

[0071] More specifically, calculating the global distance matrix of all transaction samples and adopting a distance-aware contrastive loss function to optimize the distance relationship between samples includes the following steps:

[0072] Construct a global distance matrix between transaction samples to achieve distance-aware contrastive learning. First, use the embedding representation output by the detection model to obtain the feature representation of each normal transaction sample. Then, calculate the Euclidean distance matrix between all samples, and the calculation formula is:

[0073] ;

[0074] where represents the distance between transaction sample and transaction sample .

[0075] During the training phase, the detection model only uses normal transaction samples for learning and does not use fraudulent transaction samples. On the one hand, this is because fraudulent samples are usually scarce and difficult to obtain. On the other hand, relying on normal transaction samples for model training can reduce the cost of data annotation and ensure the efficiency of the training process. In addition, by learning the distribution of normal behaviors in normal transaction samples, the model can effectively identify fraudulent behaviors that are significantly different from them.

[0076] Furthermore, by optimizing the distances between normal transaction samples, the model can ensure that the feature distances of similar samples are as small as possible, while the distances between different types of samples (i.e., normal transaction samples and potential fraud transaction samples) are as large as possible. Specifically, the loss function optimizes the decision boundary between normal transactions and potential fraud transactions by minimizing the distances between positive sample pairs and maximizing the distances between negative sample pairs. For all positive sample pairs , the distance-aware contrastive loss is defined as:

[0077] ;

[0078] where represents the total distance-aware contrastive loss of positive sample pairs; represents the set of positive sample pairs, and the positive samples are normal transaction samples; represents the positive sample pair The distance-aware loss between is expressed as:

[0079] ;

[0080] where represents the set of negative sample pairs, and the negative samples are potential fraud transaction samples; is a hyperparameter used to control the separation degree between normal transaction samples and fraud transaction samples; represents the positive sample and the negative sample The distance between; represents the positive sample and the negative sample The distance between. This loss function adopts a contrastive learning strategy to minimize , that is: make the distance between normal transaction samples as small as possible to make similar transactions closer; maximize and , that is: make the distance between normal transaction samples and fraud transaction samples as large as possible to improve the classification ability.

[0081] During the training process, the model optimizes this loss function, making normal transaction samples more concentrated in the feature space and fraud transaction samples relatively dispersed, thereby improving the detection accuracy of fraud transactions in the test phase.

[0082] Based on the optimization method of distance-aware contrastive learning, this example optimizes the distance relationship between samples, and the model can accurately distinguish normal transactions and potential fraud transactions, thereby improving the robustness and accuracy of fraud detection.

[0083] In one example, the target dimension of the random projection is dynamically adjusted according to the data volume of the transaction sample, and then dynamic feature space transformation is performed, including:

[0084] An orthogonal random projection is used to construct a random projection matrix. The target dimension in the random projection matrix is dynamically adjusted according to the data volume of the transaction sample. If the data volume is greater than the threshold, the target dimension is increased; if the data volume is less than the threshold, the target dimension is decreased; if the data volume is equal to the threshold, the target dimension remains unchanged;

[0085] The features of the transaction sample are mapped to a new feature space according to the random projection matrix, realizing dynamic feature space transformation.

[0086] Specifically, the detection model maps the input features. By using the RandomProjection technology, the input features are mapped to a new feature space, representing the transformation from the original feature space to the new feature space:

[0087] ;

[0088] Among them, is the transformed feature representation; , is the projection weight matrix, which follows a normal distribution, is the original dimension, is the dimension after projection; is the input feature, is the bias term.

[0089] The present invention uses Orthogonal Random Projection to construct a random projection matrix , ensuring that high-dimensional data is mapped to a low-dimensional space and the distance relationship between samples is maintained as much as possible. The specific generation rule of the random projection matrix is as follows:

[0090] ;

[0091] Among them, the normalization factor ensures the consistency of the feature scale after projection; represents the target dimension; , is a random Gaussian matrix, and its elements satisfy:

[0092] ;

[0093] Among them, represents the element in the matrix at the th row and the Denotes the standard normal distribution with a mean of 0 and a standard deviation of 1.

[0094] The dynamic feature space transformation of the present invention is not static but adaptively adjusted. During the training process, the dimension of the feature space is dynamically adjusted according to the amount of data, that is: the model will automatically decide whether to expand or compress the feature space, thereby improving the adaptability of the model, so as to ensure that the model can effectively process different data volume conditions. Specifically, when the data is sufficient, the model automatically expands the feature space to capture more complex patterns, ensuring that the discrimination ability can be improved when the data is sufficient; while when the data is scarce, the model compresses the feature space to avoid overfitting, maintaining the robustness of the model and avoiding the occurrence of overfitting phenomena.

[0095] Furthermore, the present invention sets a threshold as the standard for whether the data is sufficient and introduces a feature expansion factor :

[0096] ;

[0097] wherein, represents the total number of current samples. Then, according to dynamically adjust the dimension of the feature space:

[0098] ;

[0099] where: when (data is sufficient), , , that is, dimension increase, improving the model's representation ability for complex situations; when (data is insufficient), , , that is, dimension reduction, avoiding the situation of overfitting of the model; when , , keeping the original feature dimension unchanged.

[0100] Finally, the dynamic adjustment of the feature space is achieved through the following formula:

[0101] ;

[0102] wherein, represents the adaptive feature transformation function, which can automatically adjust the operation of the feature space according to the data sample size. Through this adaptive adjustment method, the model can always maintain high performance in different data environments.

[0103] In one example, step S3 constructs an initial spherical decision boundary and dynamically adjusts the radius of the spherical decision boundary, including the following sub-steps:

[0104] First, within the feature space, all normal transaction samples are processed to calculate the centroid of the normal transaction samples. The centroid is calculated by taking the weighted average of the feature vectors of all normal transaction samples, thereby obtaining a point representing the center of the distribution of normal transaction samples. Specifically, the centroid is calculated as follows:

[0105] ;

[0106] where is the set of normal transaction samples of class ; is the total number of samples in this class.

[0107] Using the calculated centroid , the distance from the normal transaction samples to the centroid is further analyzed to define an initial spherical decision boundary. The radius of the decision boundary is initially set according to the average distribution range of the normal transaction samples. This boundary needs to ensure that most normal transaction samples are within the boundary while avoiding over-expansion that leads to an increase in the false positive rate. The Euclidean distance from a normal transaction sample to the centroid not exceeding the radius of the decision boundary is calculated as follows:

[0108] ;

[0109] where represents, for each , used to quantify all elements in the set. In the process of constructing the spherical decision boundary, it is necessary to balance the internal risk and the external open space risk. The internal risk refers to the risk of misclassifying normal transaction samples as fraud transaction samples, and the external risk refers to the risk of misclassifying fraud transaction samples as normal transaction samples. This balance is achieved through the spherical decision boundary loss function, and the expression of the spherical decision boundary loss function is:

[0110] ;

[0111] where is the centroid of the th sample; represents the th radius of the spherical decision boundary; represents an indicator of whether the sample exceeds the spherical decision boundary, defined as follows:

[0112] ;

[0113] When new added transaction samples arrive, the centroid of normal transaction samples is updated regularly, and the radius of the decision boundary is recalculated based on the latest transaction samples. This process involves dynamic adjustment of the current radius to ensure that the decision boundary can adapt to different transaction scenarios. The radius update formula is as follows:

[0114] ;

[0115] Wherein, represents the radius of the updated th spherical decision boundary; represents the radius of the th spherical decision boundary before update; represents the learning rate; is the gradient of the decision boundary loss function with respect to the radius; represents the partial derivative. This process ensures that the decision boundary remains flexible and adaptable when facing new samples, and the calculation formula is as follows:

[0116] ;

[0117] Wherein, represents an indicator of whether the category of the sample is , used to filter samples belonging to a specific category; if , ; otherwise . Through the spherical decision boundary loss function, an appropriate decision boundary can be learned.

[0118] In an example, during the fraud transaction sample detection process, the model flexibly distinguishes normal transactions and potential fraud transactions by constructing and updating the spherical decision boundary. The data distribution in the financial market is usually dynamically changing, and the characteristics of normal transactions and fraud transactions may shift. Therefore, real-time and accurate classification is required. The present invention analyzes each transaction sample based on the previously learned spherical decision boundary. The radius and centroid of the decision boundary define the typical distribution of normal transactions. All normal transaction samples should be concentrated within the decision boundary in the feature space. That is, at this time, financial fraud detection is performed by determining whether the distance between the transaction sample to be detected and the centroid of the normal transaction samples is within the radius of the spherical decision boundary, including the following sub-steps:

[0119] If the distance between the transaction sample to be detected and the centroid of the normal transaction sample is less than or equal to the radius of the spherical decision boundary, it is considered that the transaction conforms to the normal mode, and the detection result of the normal transaction is output. At this time, further operations can also be carried out, including: ① recording transaction information; ② continuously enhancing the normal transaction sample dataset through this sample to improve the system's recognition ability of normal transaction features; ③ marking this transaction as a "passed" normal transaction.

[0120] If the distance between the transaction sample to be detected and the centroid of the normal transaction sample is greater than the radius of the spherical decision boundary, that is, the sample falls outside the decision boundary, the model determines that this transaction is an abnormal behavior, and the detection result of the abnormal transaction is output. At this time, further operations can also be carried out, including: ① marking this transaction as a potential fraud transaction and triggering an alarm; ② sending this transaction sample into the manual review system for manual analysis and processing; ③ updating the model according to the manual review result. If this transaction is confirmed to be a fraud transaction, the operation of terminating the transaction is carried out; if this transaction is confirmed to be a normal transaction, the model will incorporate this transaction sample into the training data to construct a more accurate decision boundary.

[0121] Financial fraud detection not only relies on static decision boundaries. In this example, continuous learning is also carried out through a dynamic update mechanism to adapt to emerging fraud behaviors in the financial market. Whenever new data is processed, especially when fraud behaviors are confirmed, the model will appropriately adjust the decision boundary according to the new sample information.

[0122] Combining the above examples, the preferred example of the present invention is obtained, as Figure 2 shown. At this time, the detection method includes the following steps:

[0123] S10: Obtain the features of the transaction sample;

[0124] S20: Calculate the global distance matrix of all transaction samples, and optimize the distance relationship between samples by using the distance-aware contrast loss function;

[0125] S30: Dynamically adjust the target dimension of the random projection according to the data volume of the transaction sample, and then perform dynamic feature space transformation;

[0126] S40: Construct an adaptive spherical decision boundary, and adapt to newly added transaction samples through centroid calculation and radius update mechanism;

[0127] S50: Determine whether the transaction is a fraud behavior according to the decision boundary and give a real-time warning.

[0128] In the process of financial fraud detection, the present invention first extracts the features of normal transaction samples through a detection model, and uses a contrastive loss function to optimize the distance relationship between samples, making normal transaction samples easy to aggregate and fraud transaction samples far away. In response to changes in the number of data samples, a dynamic feature space transformation is used to adjust the dimension of the feature space, enabling the feature space to adaptively adjust, ensuring enhanced model discrimination ability when data is sufficient and maintaining the robustness of the model when data is scarce. At the same time, an adaptive spherical decision boundary is constructed, and a centroid calculation and radius update mechanism are used to ensure that the detection model can flexibly respond to new data changes. In practical applications, this method classifies transactions through the decision boundary: if a sample is within the normal transaction boundary, it is determined to be a normal transaction; if it exceeds the boundary, it is used as a fraud transaction warning, and the model is updated in combination with the results of manual review to continuously optimize the detection ability.

[0129] In summary, the method of the present invention can classify financial transaction behaviors into normal transactions and potential fraud transactions. For potential fraud transactions, the method can effectively identify currently unlabeled new fraud behaviors, making up for the deficiencies of traditional methods in the face of unknown fraud types. This method can not only accurately identify fraud behaviors in financial transactions, but also effectively respond to changes in fraud means in a dynamic environment, with strong adaptability and robustness, and can provide more accurate and reliable fraud detection solutions for financial institutions, improving the fraud prevention ability of financial institutions. At the same time, the method of the present invention supports the dynamic update of the model, can adapt to new fraud behaviors, reduces the dependence on large-scale labeled data, and improves the timeliness and accuracy of detection.

[0130] The above specific embodiments are detailed descriptions of the present invention. It cannot be determined that the specific embodiments of the present invention are only limited to these descriptions. For those of ordinary skill in the technical field to which the present invention belongs, without departing from the concept of the present invention, several simple deductions and substitutions can still be made, and all should be regarded as belonging to the protection scope of the present invention.

Claims

1. A method for detecting persistent financial fraud based on dynamic feature space transformation, characterized in that: The following steps are involved: Obtaining features of transaction samples, including transaction notes, chat records, social media information, and historical transaction records; Dynamically adjust the target dimension of random projection according to the data volume of transaction samples, and then perform dynamic feature space transformation; Calculate the centroid of all normal transaction samples; Obtain the distance distribution from each normal transaction sample to the centroid, and then learn the boundary range of the normal transaction samples; calculate the average distribution range of the normal transaction samples, and construct the initial spherical decision boundary based on the average distribution range; update the centroid of the normal transaction samples according to the newly added transaction samples, and dynamically adjust the radius of the spherical decision boundary; When constructing the initial spherical decision boundary, the spherical decision boundary loss function is used to balance the risk of normal transaction samples being misjudged as fraudulent transaction samples and fraudulent transaction samples being misjudged as normal transaction samples. The expression is: ; in, represents the total number of samples; An indicator indicating whether the sample exceeds the spherical decision boundary; Represent the feature representation of each transaction sample; For the The centroid of the samples; Indicates The radius of the spherical decision boundary; The update expression of the radius of the spherical decision boundary is: ; in, Indicates The updated radius of the spherical decision boundary; Indicates The radius of the spherical decision boundary before updating; represents the gradient of the decision boundary loss function with respect to the radius; represents partial derivative; By judging whether the distance between the centroid of the transaction sample to be detected and the normal transaction sample is within the radius of the spherical decision boundary, financial fraud detection is performed and the detection result is output.

2. The method for detecting persistent financial fraud based on dynamic feature space transformation according to claim 1, characterized in that: The characteristics of obtaining transaction samples include: The features of the image transaction samples are extracted using an image detection model, and / or the features of the text transaction samples are extracted using a text detection model, and / or the features of the voice transaction samples are extracted using a voice detection model.

3. The method for detecting persistent financial fraud based on dynamic feature space transformation according to claim 1, characterized in that: Before the step of dynamically adjusting the target dimension of random projection according to the data volume of the transaction sample, the method further includes: The global distance matrix of all transaction samples is calculated, and the distance relationship between samples is optimized using the distance-aware contrast loss function.

4. The method for detecting persistent financial fraud based on dynamic feature space transformation according to claim 3 is characterized in that: The expression of the distance-aware contrast loss function is: ; ; in, represents the total distance-aware contrast loss of positive sample pairs; Represents a set of positive sample pairs, where positive samples are normal transaction samples; Represents a positive sample pair The distance between the perceived losses; Represents a positive sample pair The distance between represents a set of negative sample pairs, where negative samples are potential fraudulent transaction samples; represents a hyperparameter; Represents a positive sample With negative samples The distance between Represents a positive sample With negative samples The distance between.

5. The method for detecting persistent financial fraud based on dynamic feature space transformation according to claim 1, characterized in that: The method of dynamically adjusting the target dimension of random projection according to the data volume of the transaction sample and then performing dynamic feature space transformation includes: Orthogonal random projection is used to construct a random projection matrix. The target dimension in the random projection matrix is ​​dynamically adjusted according to the data volume of the transaction sample. If the data volume is greater than the threshold, the target dimension is increased in dimension; if the data volume is less than the threshold, the target dimension is decreased in dimension; if the data volume is equal to the threshold, the target dimension remains unchanged. The features of transaction samples are mapped to a new feature space according to the random projection matrix to achieve dynamic feature space transformation.

6. The method for detecting persistent financial fraud based on dynamic feature space transformation according to claim 1, characterized in that: The method of detecting financial fraud by judging whether the distance between the centroid of the transaction sample to be detected and the normal transaction sample is within the radius of the spherical decision boundary includes: If the distance between the centroid of the transaction sample to be detected and the normal transaction sample is less than or equal to the radius of the spherical decision boundary, the detection result of the normal transaction is output; If the distance between the centroid of the transaction sample to be detected and the normal transaction sample is greater than the radius of the spherical decision boundary, the detection result of the abnormal transaction is output and an alarm is triggered, and / or manual review and analysis are performed and the final detection result is output; The samples that are judged as normal transactions by the detection results are updated to the training data set, and the spherical decision boundary is optimized using the updated training data set.

Citation Information

Patent Citations

  • Three-decision unbalanced data oversampling method based on Spark big data platform

    CN106599935A

  • Local interpretation method of Internet-of-things intelligent model based on linear kernel SVM

    CN111639688A