Payment Fraud Detection Method and Related Devices Based on Behavioral Pattern Analysis and Multimodal Authentication

By adopting behavioral pattern analysis and multimodal authentication methods in mobile payment, the problems of low security and privacy leakage of mobile payment are solved, and higher security and privacy protection are achieved.

CN119904239BActive Publication Date: 2025-05-27EPAY GLOBAL PAYMENT CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510382787.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-28
Publication Date
2025-05-27
Estimated Expiration
2045-03-28

AI Technical Summary

Technical Problem

The existing mobile payment technology has low security problems in security verification, and it is difficult to effectively manage user privacy data, resulting in privacy leakage.

Method used

Payment fraud detection methods based on behavioral pattern analysis and multimodal identity verification are adopted to collect users' behavioral data and biological data in real time, encrypt and process and destroy them, and risk analysis and verification are used using spatio-temporal graph convolutional network and multimodal identity verification strategy.

Benefits of technology

Improves security in the mobile payment process, prevents payment fraud, and effectively protects users' privacy data to avoid leakage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119904239B_ABST
    Figure CN119904239B_ABST
Patent Text Reader

Abstract

Embodiments of the present invention relate to the field of transaction security technologies, and disclose a payment fraud detection method based on behavior pattern analysis and multi-modal identity authentication. The method includes: when receiving a transaction request from a user, collecting the user's current original behavior data in real time according to the transaction request; respectively encrypting the user's current original behavior data and the transaction request in real time to obtain the encrypted current behavior data and the encrypted transaction request, and at the same time destroying the user's current original behavior data and the transaction request; analyzing the behavior risk level using a behavior analysis model; according to the behavior risk level, collecting the user's current original biological data, encrypting the user's current original biological data, and destroying the current original biological data, and using a target verification strategy to verify the encrypted current biological data to obtain a verification result; according to the verification result, determining whether there is payment fraud. Embodiments of the present invention achieve the effects of payment security and privacy protection.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present invention relate to the technical field of foreign exchange scheduling, and in particular to a payment fraud detection method, device, computer device and readable storage medium based on behavior pattern analysis and multi-modal identity authentication. Background Art

[0002] Currently, mobile payment is becoming more and more common. Since there is no need to use physical media during payment verification, it brings great convenience to users. This also poses great challenges to the security verification in the mobile payment process. However, the existing mobile payment still has security vulnerabilities, and there is no very effective management method for the user's privacy data during the verification process, making it easy to leak security privacy and further reducing the security of mobile payment. Summary of the Invention

[0003] In view of the above problems, the embodiments of the present invention provide a payment fraud detection method, device, computer device and readable storage medium based on behavior pattern analysis and multi-modal identity authentication, which are used to solve the problems of low security of security verification during the payment process and user privacy leakage existing in the prior art.

[0004] According to one aspect of the embodiments of the present invention, a payment fraud detection method based on behavior pattern analysis and multi-modal identity authentication is provided. The method includes:

[0005] When receiving a transaction request from a user, real-time collect the user's current original behavior data according to the transaction request; the transaction request includes a user identifier, current transaction information and current physical information; the user's current original behavior data at least includes a touch screen sliding trajectory, a device holding posture and input rhythm information;

[0006] After respectively encrypting the user's current original behavior data and the transaction request in real time by using a preset first encryption algorithm, obtain the encrypted current behavior data and the encrypted transaction request, and at the same time destroy the user's current original behavior data and the transaction request;

[0007] Analyze according to the encrypted current behavior data and the transaction request by using a behavior analysis model to obtain a behavior risk degree; the behavior analysis model is obtained by a third-party storage end training a spatio-temporal graph convolutional network according to user historical behavior information and historical transaction information; the user historical behavior information is obtained by encrypting the user's original historical behavior information by using a preset first encryption algorithm;

[0008] According to the behavioral risk degree, collect the user's current original biological data, encrypt the user's current original biological data using a preset second encryption algorithm, destroy the current original biological data, and verify the encrypted current biological data using a target verification strategy to obtain a verification result; the target verification strategy is one of the multi-modal identity verification strategies;

[0009] Determine whether there is payment fraud according to the verification result.

[0010] In an alternative manner, the first encryption algorithm includes a position offset algorithm and differential privacy calculation; the current physical information includes current device information and current geographical location information; after respectively and real-time encrypting the user's current original behavior data and the transaction request using the preset first encryption algorithm, the encrypted current behavior data and the encrypted transaction request are obtained, and at the same time, the user's current original behavior data and the transaction request are destroyed, including:

[0011] After performing position offset calculation on the current geographical location information according to the position offset algorithm, the offset current geographical location information is obtained;

[0012] Perform differential privacy calculation on the user's current original behavior data to obtain the encrypted current behavior data.

[0013] In an alternative manner, before predicting at least one recommended exchange plan according to the first foreign exchange request, the current exchange rate fluctuation information, and the historical foreign exchange data when the waiting duration exceeds a preset duration threshold, the method further includes:

[0014] Obtain historical foreign exchange data; the historical foreign exchange data includes the amount of the historical foreign exchange request, the exchange rate, the historical foreign exchange request time, the request quantity at the historical foreign exchange request time, the historical mutual exchange waiting duration corresponding to the historical foreign exchange request, and information on whether the exchange is successful;

[0015] Input the historical foreign exchange data into a preset time series prediction model for training to obtain an exchange duration prediction model;

[0016] Obtain historical exchange rate data; the historical exchange rate data includes historical exchange rate fluctuation information, historical macroeconomic data, and historical foreign exchange data;

[0017] Input the historical exchange rate data into a deep learning model for training to obtain a trained best exchange timing prediction model.

[0018] In an alternative approach, the spatio-temporal convolutional network is an STGCN model; the STGCN model includes a spatio-temporal convolutional block with two temporal convolutional layers sandwiching a spatial graph convolutional layer and a fully connected layer; the process of inputting the encrypted touchscreen sliding trajectory, encrypted device holding posture, encrypted input rhythm information, historical transaction requests, and corresponding behavioral risk degree labels into the spatio-temporal convolutional network for training to obtain a trained behavioral analysis model includes:

[0019] Map the encrypted touchscreen sliding trajectory, encrypted device holding posture, and encrypted input rhythm information at each time point into node features respectively, and represent the spatial relationship between the user's historical behavior information through an adjacency matrix;

[0020] Use the offset historical geographical location information in the historical transaction request as a node feature, and represent the spatial relationship between transactions through an adjacency matrix;

[0021] Extract features through the temporal convolutional layer and the spatial graph convolutional layer respectively, and output a risk prediction value through the fully connected layer;

[0022] Calculate the loss function based on the risk prediction value and the behavioral risk degree label, and adjust the parameters of the STGCN model according to the loss function, and continue iterative training to obtain the trained behavioral analysis model.

[0023] In an alternative approach, the multi-modal authentication strategy includes a first authentication strategy, a second authentication strategy, and a third authentication strategy; the encrypted current original biometric data of the user at least includes current encrypted fingerprint data, current encrypted liveness detection information, and current encrypted voiceprint data; the preset thresholds include a preset first threshold and a preset second threshold; the process of collecting the user's current original biometric data according to the behavioral risk degree, encrypting the user's current original biometric data using a preset second encryption algorithm, destroying the current original biometric data, and verifying the encrypted current biometric data using a target authentication strategy to obtain a verification result includes:

[0024] Obtain the standard user encrypted biometric data encrypted using the preset second encryption algorithm from the third-party storage; the standard user encrypted biometric data at least includes standard encrypted fingerprint data, standard encrypted voiceprint data, and standard encrypted liveness detection information;

[0025] When the behavioral risk degree is lower than the first threshold, verify according to the first authentication strategy; the first authentication strategy is to compare the current encrypted fingerprint data with the standard encrypted fingerprint data to obtain a verification result;

[0026] When the behavior risk level is higher than a preset first threshold and lower than a preset second threshold, verification is performed according to a second verification strategy; the second verification strategy is to perform verification based on any two of the current encrypted fingerprint data, the current liveness detection encrypted information, or the current voiceprint encrypted data to obtain a verification result;

[0027] When the behavior risk level is higher than the second threshold, verification is performed according to a third verification strategy to obtain a verification result; the third verification strategy is to perform verification on the current encrypted fingerprint data, the current liveness detection encrypted information, and the current voiceprint encrypted data respectively to obtain a verification result.

[0028] In an optional manner, after determining whether there is payment fraud according to the verification result, the method includes:

[0029] When it is determined that there is payment fraud, the transaction payment is stopped, and the result of the failed transaction is prompted to the user.

[0030] According to another aspect of the embodiments of the present invention, there is provided a payment fraud detection device based on behavior pattern analysis and multi-modal identity verification, including:

[0031] An acquisition module, configured to, when receiving a transaction request from a user, acquire the user's current original behavior data in real time according to the transaction request; the transaction request includes a user identifier, current transaction information, and current physical information; the user's current original behavior data at least includes a touch screen sliding trajectory, a device holding posture, and input rhythm information;

[0032] An encryption and destruction module, configured to respectively perform encryption processing on the user's current original behavior data and the transaction request in real time using a preset first encryption algorithm to obtain encrypted current behavior data and an encrypted transaction request, and at the same time destroy the user's current original behavior data and the transaction request;

[0033] A risk level calculation module, configured to analyze the encrypted current behavior data and the transaction request using a behavior analysis model to obtain a behavior risk level; the behavior analysis model is obtained by a third-party storage end training a spatio-temporal graph convolutional network according to user historical behavior information and historical transaction information; the user historical behavior information is obtained by encrypting the user's original historical behavior information using a preset first encryption algorithm;

[0034] A multi-modal verification module, configured to, according to the behavior risk level, acquire the user's current original biological data, encrypt the user's current original biological data using a preset second encryption algorithm, destroy the current original biological data, and perform verification on the encrypted current biological data using a target verification strategy to obtain a verification result; the target verification strategy is one of the multi-modal identity verification strategies;

[0035] A determination module, configured to determine whether there is payment fraud according to the verification result.

[0036] According to another aspect of the embodiments of the present invention, there is provided a computer device, including: a processor, a memory, a communication interface, and a communication bus, and the processor, the memory, and the communication interface complete mutual communication through the communication bus;

[0037] The memory is used to store at least one executable instruction, and the executable instruction causes the processor to execute the operations of the payment fraud detection method based on behavior pattern analysis and multi-modal authentication.

[0038] According to still another aspect of the embodiments of the present invention, there is provided a computer-readable storage medium, in which at least one executable instruction is stored, and when the executable instruction runs on a computer device, the computer device is caused to execute the operations of the payment fraud detection method based on behavior pattern analysis and multi-modal authentication.

[0039] In the embodiments of the present invention, when a transaction request of a user is received, the current original behavior data of the user is collected in real time according to the transaction request. After respectively encrypting the current original behavior data of the user and the transaction request in real time by using a preset first encryption algorithm, the encrypted current behavior data and the encrypted transaction request are obtained, and at the same time, the current original behavior data of the user and the transaction request are destroyed; the encrypted current behavior data and the transaction request are analyzed by using a behavior analysis model to obtain a behavior risk degree; according to the behavior risk degree, the current original biometric data of the user is collected and the current original biometric data of the user is encrypted by using a preset second encryption algorithm, and the current original biometric data is destroyed, and a target verification strategy is used to verify the encrypted current biometric data to obtain a verification result; according to the verification result, it is determined whether there is payment fraud. Among them, by encrypting various types of user data in each link, destroying the original sensitive data, and storing the sensitive data encrypted in a third-party storage end at the same time, it is possible to effectively perform security verification through multi-modal during the transaction payment process, and at the same time, it will not cause user privacy leakage due to excessive collection of user sensitive data.

[0040] The above description is only an overview of the technical solutions of the embodiments of the present invention. In order to be able to understand the technical means of the embodiments of the present invention more clearly, it can be implemented according to the content of the description. And in order to make the above and other purposes, features, and advantages of the embodiments of the present invention more obvious and understandable, the following specifically gives the specific implementation manners of the present invention. Description of the Drawings

[0041] The accompanying drawings are only used to illustrate the embodiments and are not considered as limiting the present invention. Moreover, throughout the drawings, the same reference numerals are used to represent the same components. In the drawings:

[0042] Figure 1 A flowchart showing the process of a payment fraud detection method based on behavior pattern analysis and multimodal authentication provided by an embodiment of the present invention is shown;

[0043] Figure 2 A schematic structural diagram of a payment fraud detection device based on behavior pattern analysis and multimodal authentication provided by an embodiment of the present invention is shown;

[0044] Figure 3 A schematic structural diagram of a computer device provided by an embodiment of the present invention is shown. Detailed Embodiments

[0045] The exemplary embodiments of the present invention will be described in more detail below with reference to the accompanying drawings. Although the exemplary embodiments of the present invention are shown in the drawings, it should be understood that the present invention can be implemented in various forms and should not be limited by the embodiments set forth herein.

[0046] Figure 1 A flowchart showing the payment fraud detection method based on behavior pattern analysis and multimodal authentication provided by an embodiment of the present invention is shown. This method is executed by a computer device. The computer device can be a distributed device. As Figure 1 shown, the method includes the following steps:

[0047] Step 110: When receiving a transaction request from a user, collect the user's current original behavior data in real time according to the transaction request.

[0048] In an embodiment of the present invention, when a user needs to make a payment, a transaction request is generated in real time according to the user identification, transaction amount, transaction merchant, and transaction time.

[0049] Among them, the transaction request includes user identification, current transaction information, and current physical information. Among them, the current transaction information includes transaction amount, transaction time, and transaction merchant. The user's current original behavior data at least includes touch screen sliding trajectory, device holding posture, and input rhythm information. Since different devices have different user operation habits, resulting in different operation behaviors, the current physical information may specifically include current device information and current geographical location information.

[0050] Step 120: After encrypting the user's current original behavior data and the transaction request respectively in real time using a preset first encryption algorithm, obtain the encrypted current behavior data and the encrypted transaction request, and at the same time destroy the user's current original behavior data and the transaction request.

[0051] Among them, the first encryption algorithm includes a position offset algorithm and differential privacy calculation; the current physical information includes current device information and current geographical location information.

[0052] In the embodiments of the present invention, after respectively encrypting the user's current original behavior data and the transaction request in real time using a preset first encryption algorithm, the encrypted current behavior data and the encrypted transaction request are obtained, and at the same time, the user's current original behavior data and the transaction request are destroyed. Specifically, it includes:

[0053] Step 1201: Perform position offset calculation on the current geographical location information according to the position offset algorithm to obtain the offset current geographical location information. Among them, the position offset algorithm uses spherical trigonometry formulas to calculate the new latitude and longitude. Specifically, obtain the longitude and latitude information in the current geographical location information.

[0054] Among them, R is the radius of the earth, is the azimuth angle, θ_rad = θ × π / 180, and the value of the current latitude lat after radian conversion is: lat rad = lat ×π / 180. Calculate the new latitude through the following method : , where lat is the current latitude, is the latitude increment, and d is the offset distance; is the value after converting the angle to radians.

[0055] . Among them, the new longitude is calculated as: , where, lon is the longitude increment. .

[0056] In the embodiments of the present invention, in this way, the longitude and latitude offset is more accurate. Among them, the third-party storage end also stores historical geographical location information, which is encrypted in the same way as above. Thus, the encryption methods of the two are the same, so that even after encryption, it does not affect the comparison and analysis.

[0057] Step 1202: Perform differential privacy calculation on the user's current original behavior data to obtain the encrypted current behavior data. Among them, in the embodiments of the present invention, the differential privacy algorithm is respectively used to encrypt the touch screen sliding trajectory, device holding posture, and input rhythm information in the user's current original behavior data to obtain the encrypted current touch screen sliding trajectory, encrypted current device holding posture, and encrypted current input rhythm information. Specifically, differential privacy calculation can use the Laplace mechanism for encryption.

[0058] Step 130: Analyze using a behavior analysis model based on the encrypted current behavior data and the transaction request to obtain a behavior risk level.

[0059] Among them, the behavior analysis model is obtained by a third-party storage end training a spatio-temporal graph convolutional network based on user historical behavior information and historical transaction information. The user historical behavior information is obtained by encrypting the user's original historical behavior information using a preset first encryption algorithm.

[0060] In an embodiment of the present invention, the behavior analysis model is trained based on a spatio-temporal convolutional network, and the spatio-temporal convolutional network can be an STGCN model. The STGCN model includes a spatio-temporal convolutional block and a fully connected layer with two temporal convolutional layers sandwiching a spatial graph convolutional layer. Among them, before analyzing using the behavior analysis model based on the encrypted current behavior data and the transaction request to obtain a behavior risk level, it is first necessary to train the behavior analysis model. Specifically, it includes the following steps:

[0061] Step 001: The third-party storage end respectively uses a differential privacy algorithm to encrypt the historical touch screen sliding trajectory, historical device holding posture, and historical input rhythm information in the historical transaction request to obtain the encrypted touch screen sliding trajectory, encrypted device holding posture, and encrypted input rhythm information.

[0062] Among them, the differential privacy algorithm used by the third-party storage end is the same as the process of encrypting the user's current original behavior data described above, and will not be elaborated here.

[0063] Step 002: The third-party storage end performs position offset calculation on the historical geographical location information according to the position offset algorithm to obtain the offset historical geographical location information.

[0064] Among them, the process of the third-party storage end calculating the geographical location information in the transaction request according to the position offset algorithm is the same, and will not be elaborated here.

[0065] Step 003: The third-party storage end inputs the encrypted touch screen sliding trajectory, encrypted device holding posture, encrypted input rhythm information, historical transaction request, and corresponding behavior risk level labels into the spatio-temporal convolutional network for training to obtain a trained behavior analysis model.

[0066] Among them, the encrypted touch - screen sliding trajectory, encrypted device - holding posture, and encrypted input rhythm information at each time point are respectively mapped to node features, and the spatial relationship between the user's historical behavior information is represented by an adjacency matrix. Specifically, first, data pre - processing and graph - structure construction are carried out: convert historical behavior information and historical transaction information into a format suitable for the STGCN model. For example, for the touch - screen sliding trajectory, record the sliding coordinate points (x, y) in chronological order to form time - series data. For the device - holding posture, record sensor data such as acceleration and gyroscope and arrange them in chronological order. For the information input rhythm, record the timestamps of key - press or sliding events to form a time - series. For historical transaction information, record transaction amount, transaction time, transaction location (latitude and longitude), etc., and arrange them in chronological order. After pre - processing is completed, a graph structure is constructed. Among them, the behavior or transaction event at each time point is used as a node, and edges are constructed according to spatio - temporal relationships. For example, for temporal adjacency, an edge is established between behaviors or transactions at adjacent time points. For spatial adjacency, an edge is established between transactions or behaviors with similar geographical locations. Among them, the adjacency matrix represents the connection relationship between nodes and is used for spatial graph convolution. For spatial graph convolution, the role of the spatial graph convolution layer is to extract spatial features from the graph structure and capture the spatial relationship between nodes. The STGCN model extracts spatio - temporal features by alternately using spatial graph convolution and temporal convolution. Therefore, the offset historical geographical location information in the historical transaction request is used as a node feature, and the spatial relationship between transactions is represented by an adjacency matrix. Features are extracted through the temporal convolution layer and the spatial graph convolution layer respectively, and the risk prediction value is output through a fully - connected layer. According to the risk prediction value and the behavior risk - degree label, a loss function is calculated, and the parameters of the STGCN model are adjusted according to the loss function, and iterative training is continued to obtain the trained behavior analysis model. Among them, since encrypted data needs to be trained, in order to improve training efficiency, the embodiments of the present invention train the STGCN model based on the CrypTen framework.

[0067] After the training is completed on the third - party storage end, the behavior analysis model is deployed to the behavior - pattern - analysis - and - multi - modal - identity - authentication - based payment fraud detection system of the embodiments of the present invention, so that historical behavior data, historical biological data, etc. can be not leaked.

[0068] Step 140: According to the behavior risk degree, collect the user's current original biological data, encrypt the user's current original biological data using a preset second encryption algorithm, destroy the current original biological data, and use a target verification strategy to verify the encrypted current biological data to obtain a verification result.

[0069] Among them, the target verification strategy is one of the multi-modal authentication strategies. The multi-modal authentication strategy includes a first verification strategy, a second verification strategy, and a third verification strategy. In an embodiment of the present invention, the encrypted current original biological data of the user at least includes current encrypted fingerprint data, current liveness detection encrypted information, and current voiceprint encrypted data; the preset thresholds include a preset first threshold and a preset second threshold. Among them, the second threshold is greater than the first threshold.

[0070] In an embodiment of the present invention, according to the behavior risk degree, the current original biological data of the user is collected, and the current original biological data of the user is encrypted using a preset second encryption algorithm, and the current original biological data is destroyed. The encrypted current biological data is verified using a target verification strategy to obtain a verification result, specifically including:

[0071] Obtain the standard encrypted biological data of the user encrypted using a preset second encryption algorithm from the third-party storage end; the standard encrypted biological data of the user at least includes standard encrypted fingerprint data, standard voiceprint encrypted data, and standard liveness detection encrypted information;

[0072] When the behavior risk degree is lower than the first threshold, verification is performed according to the first verification strategy; the first verification strategy is to compare the current encrypted fingerprint data with the standard encrypted fingerprint data to obtain a verification result. When the current encrypted fingerprint data is consistent with the standard encrypted fingerprint data, the verification result is verification passed.

[0073] When the behavior risk degree is higher than the preset first threshold and lower than the preset second threshold, verification is performed according to the second verification strategy. The second verification strategy is to verify according to any two of the current encrypted fingerprint data, the current liveness detection encrypted information, or the current voiceprint encrypted data to obtain a verification result. When verification fails according to any two of the current encrypted fingerprint data, the current liveness detection encrypted information, or the current voiceprint encrypted data, the verification result is verification failed. When both verifications pass, the verification result is verification passed.

[0074] When the behavior risk degree is higher than the second threshold, verification is performed according to the third verification strategy to obtain a verification result; the third verification strategy is to verify the current encrypted fingerprint data, the current liveness detection encrypted information, and the current voiceprint encrypted data respectively to obtain a verification result.

[0075] Step 150: Determine whether there is payment fraud according to the verification result.

[0076] Among them, when it is determined that there is payment fraud in the embodiments of the present invention, the transaction payment is stopped, and the result of the failed transaction is prompted to the user. In the embodiments of the present invention, after the transaction ends, user feedback is received, and according to the user feedback, the accuracy of the verification result is determined. The encrypted current behavior data and the encrypted transaction request are stored in a third-party storage end for further training of the behavior analysis model. And the encrypted current behavior data and the encrypted transaction request temporarily stored in the payment fraud detection system based on behavior pattern analysis and multi-modal authentication are deleted.

[0077] In the embodiments of the present invention, when a transaction request from a user is received, the user's current original behavior data is collected in real time according to the transaction request. After the user's current original behavior data and the transaction request are respectively encrypted in real time using a preset first encryption algorithm, the encrypted current behavior data and the encrypted transaction request are obtained, and at the same time, the user's current original behavior data and the transaction request are destroyed; the encrypted current behavior data and the transaction request are analyzed using a behavior analysis model to obtain a behavior risk degree; according to the behavior risk degree, the user's current original biological data is collected and the user's current original biological data is encrypted using a preset second encryption algorithm, and the current original biological data is destroyed, and a target verification strategy is used to verify the encrypted current biological data to obtain a verification result; according to the verification result, it is determined whether there is payment fraud. Among them, by encrypting various types of user data in each link, destroying the original sensitive data, and storing the sensitive data encrypted in a third-party storage end, it is possible to effectively perform security verification through multi-modal during the transaction payment process, and at the same time, it will not cause user privacy leakage due to excessive collection of user sensitive data.

[0078] Figure 2 The structural schematic diagram of the payment fraud detection device based on behavior pattern analysis and multi-modal authentication provided by the embodiments of the present invention is shown. As Figure 2 shown, the device 200 includes:

[0079] An acquisition module 210, configured to collect the user's current original behavior data in real time according to the transaction request when the transaction request from the user is received; the transaction request includes a user identifier, current transaction information, and current physical information; the user's current original behavior data includes at least a touch screen sliding trajectory, a device holding posture, and input rhythm information.

[0080] An encryption and destruction module 220, configured to respectively encrypt the user's current original behavior data and the transaction request in real time using a preset first encryption algorithm to obtain the encrypted current behavior data and the encrypted transaction request, and at the same time destroy the user's current original behavior data and the transaction request.

[0081] A risk degree calculation module 230, configured to analyze the encrypted current behavior data and the transaction request by using a behavior analysis model to obtain a behavior risk degree; the behavior analysis model is obtained by a third-party storage end training a spatio-temporal graph convolutional network according to user historical behavior information and historical transaction information; the user historical behavior information is obtained by encrypting the user's original historical behavior information by using a preset first encryption algorithm.

[0082] A multi-modal verification module 240, configured to collect the user's current original biological data according to the behavior risk degree, encrypt the user's current original biological data by using a preset second encryption algorithm, destroy the current original biological data, and verify the encrypted current biological data by using a target verification strategy to obtain a verification result; the target verification strategy is one of the multi-modal identity verification strategies.

[0083] A determination module 250, configured to determine whether there is payment fraud according to the verification result.

[0084] In an optional manner, the first encryption algorithm includes a position offset algorithm and differential privacy calculation; the current physical information includes current device information and current geographical location information; after respectively and real-time encrypting the user's current original behavior data and the transaction request by using the preset first encryption algorithm, the encrypted current behavior data and the encrypted transaction request are obtained, and at the same time, the user's current original behavior data and the transaction request are destroyed, including:

[0085] Performing position offset calculation on the current geographical location information according to the position offset algorithm to obtain the offset current geographical location information;

[0086] Performing differential privacy calculation on the user's current original behavior data to obtain the encrypted current behavior data.

[0087] In an optional manner, before predicting at least one recommended exchange plan by inputting the first foreign exchange request, the current exchange rate fluctuation information, and the historical foreign exchange data into an exchange plan model when the waiting duration exceeds a preset duration threshold, the method further includes:

[0088] Obtaining historical foreign exchange data; the historical foreign exchange data includes the amount of the historical foreign exchange request, the exchange rate, the historical foreign exchange request time, the request quantity at the historical foreign exchange request time, the historical mutual exchange waiting duration corresponding to the historical foreign exchange request, and information on whether the exchange is successful;

[0089] Inputting the historical foreign exchange data into a preset time series prediction model for training to obtain a mutual exchange duration prediction model;

[0090] Obtain historical exchange rate data; the historical exchange rate data includes historical exchange rate fluctuation information, historical macroeconomic data, and historical foreign exchange data;

[0091] Input the historical exchange rate data into a deep learning model for training to obtain a trained optimal exchange timing prediction model.

[0092] In an alternative approach, the spatio-temporal convolutional network is an STGCN model; the STGCN model includes a spatio-temporal convolutional block with two temporal convolutional layers sandwiching a spatial graph convolutional layer and a fully connected layer; the encrypted touch screen sliding trajectory, encrypted device holding posture, encrypted input rhythm information, historical transaction requests, and corresponding behavioral risk degree labels are input into the spatio-temporal convolutional network for training to obtain a trained behavioral analysis model, including:

[0093] Map the encrypted touch screen sliding trajectory, encrypted device holding posture, and encrypted input rhythm information at each time point into node features respectively, and represent the spatial relationship between the user's historical behavior information through an adjacency matrix;

[0094] Use the offset historical geographical location information in the historical transaction request as a node feature, and represent the spatial relationship between transactions through an adjacency matrix;

[0095] Extract features through the temporal convolutional layer and the spatial graph convolutional layer respectively, and output a risk prediction value through the fully connected layer;

[0096] Calculate the loss function based on the risk prediction value and the behavioral risk degree label, and adjust the parameters of the STGCN model according to the loss function, and continue iterative training to obtain the trained behavioral analysis model.

[0097] In an alternative approach, the multi-modal authentication strategy includes a first authentication strategy, a second authentication strategy, and a third authentication strategy; the encrypted current original biometric data of the user at least includes current encrypted fingerprint data, current encrypted liveness detection information, and current encrypted voiceprint data; the preset thresholds include a preset first threshold and a preset second threshold; according to the behavioral risk degree, collect the user's current original biometric data, encrypt the user's current original biometric data using a preset second encryption algorithm, destroy the current original biometric data, and use a target authentication strategy to verify the encrypted current biometric data to obtain a verification result, including:

[0098] Obtain the standard user encrypted biometric data encrypted using a preset second encryption algorithm from the third-party storage end; the standard user encrypted biometric data at least includes standard encrypted fingerprint data, standard encrypted voiceprint data, and standard encrypted liveness detection information;

[0099] When the behavior risk level is lower than the first threshold, verification is performed according to the first verification strategy; the first verification strategy is to compare the current encrypted fingerprint data with the standard encrypted fingerprint data to obtain a verification result;

[0100] When the behavior risk level is higher than the preset first threshold and lower than the preset second threshold, verification is performed according to the second verification strategy; the second verification strategy is to perform verification based on any two of the current encrypted fingerprint data, the current live detection encrypted information, or the current voiceprint encrypted data to obtain a verification result;

[0101] When the behavior risk level is higher than the second threshold, verification is performed according to the third verification strategy to obtain a verification result; the third verification strategy is to perform verification on the current encrypted fingerprint data, the current live detection encrypted information, and the current voiceprint encrypted data respectively to obtain a verification result.

[0102] In an alternative manner, after determining whether there is payment fraud according to the verification result, the method includes:

[0103] When it is determined that there is payment fraud, stop the transaction payment and prompt the user with the result of the failed transaction.

[0104] In an embodiment of the present invention, when receiving a transaction request from a user, the user's current original behavior data is collected in real time according to the transaction request. After respectively encrypting the user's current original behavior data and the transaction request in real time using a preset first encryption algorithm, the encrypted current behavior data and the encrypted transaction request are obtained, and at the same time, the user's current original behavior data and the transaction request are destroyed; the encrypted current behavior data and the transaction request are analyzed using a behavior analysis model to obtain a behavior risk level; according to the behavior risk level, the user's current original biological data is collected and the user's current original biological data is encrypted using a preset second encryption algorithm, and the current original biological data is destroyed. The encrypted current biological data is verified using a target verification strategy to obtain a verification result; according to the verification result, it is determined whether there is payment fraud. Among them, by encrypting various types of user data in each link, destroying the original sensitive data, and storing the sensitive data encrypted in a third-party storage end, it is possible to effectively perform security verification through multiple modalities during the transaction payment process, and at the same time, it will not cause user privacy leakage due to excessive collection of user sensitive data.

[0105] Figure 3 The structural schematic diagram of the computer device provided by the embodiment of the present invention is shown. The specific implementation of the computer device is not limited in the specific embodiment of the present invention.

[0106] Such as Figure 3As shown in the figure, the computer device may include: a processor 302, a communications interface 304, a memory 306, and a communication bus 308.

[0107] Among them: The processor 302, the communications interface 304, and the memory 306 communicate with each other through the communication bus 308. The communications interface 304 is used to communicate with network elements of other devices such as clients or other servers. The processor 302 is used to execute the program 310, and specifically can execute the relevant steps in the above embodiments of the method for detecting payment fraud based on behavior pattern analysis and multimodal authentication.

[0108] Specifically, the program 310 may include program code, and the program code includes computer-executable instructions.

[0109] The processor 302 may be a central processing unit CPU, or a specific integrated circuit ASIC (Application Specific Integrated Circuit), or one or more integrated circuits configured to implement the embodiments of the present invention. One or more processors included in the computer device may be of the same type of processor, such as one or more CPUs; or may be of different types of processors, such as one or more CPUs and one or more ASICs.

[0110] The memory 306 is used to store the program 310. The memory 306 may include high-speed RAM memory, and may also include non-volatile memory, such as at least one disk memory.

[0111] The program 310 can specifically be called by the processor 302 to cause the computer device to perform the following operations:

[0112] When receiving a transaction request from a user, real-time collect the user's current original behavior data according to the transaction request; the transaction request includes a user identifier, current transaction information, and current physical information; the user's current original behavior data at least includes a touch screen sliding trajectory, a device holding posture, and input rhythm information;

[0113] After respectively encrypting the user's current original behavior data and the transaction request in real time using a preset first encryption algorithm, obtain the encrypted current behavior data and the encrypted transaction request, and at the same time destroy the user's current original behavior data and the transaction request;

[0114] Analyze using a behavior analysis model based on the encrypted current behavior data and the transaction request to obtain a behavior risk level; the behavior analysis model is obtained by a third-party storage end training a spatio-temporal graph convolutional network based on user historical behavior information and historical transaction information; the user historical behavior information is obtained by encrypting the user's original historical behavior information using a preset first encryption algorithm;

[0115] According to the behavior risk level, collect the user's current original biometric data, encrypt the user's current original biometric data using a preset second encryption algorithm, destroy the current original biometric data, and use a target verification strategy to verify the encrypted current biometric data to obtain a verification result; the target verification strategy is one of the multimodal identity verification strategies;

[0116] Determine whether there is payment fraud according to the verification result.

[0117] In an optional manner, the first encryption algorithm includes a position offset algorithm and differential privacy calculation; the current physical information includes current device information and current geographical location information; after respectively and real-time encrypting the user's current original behavior data and the transaction request using the preset first encryption algorithm, the encrypted current behavior data and the encrypted transaction request are obtained, and at the same time, the user's current original behavior data and the transaction request are destroyed, including:

[0118] Perform a position offset calculation on the current geographical location information according to the position offset algorithm to obtain the offset current geographical location information;

[0119] Perform differential privacy calculation on the user's current original behavior data to obtain the encrypted current behavior data.

[0120] In an optional manner, before predicting at least one recommended exchange plan according to the first foreign exchange request, the current exchange rate fluctuation information, and the historical foreign exchange data by inputting them into an exchange plan model when the waiting duration exceeds a preset duration threshold, the method further includes:

[0121] Obtain historical foreign exchange data; the historical foreign exchange data includes the amount of the historical foreign exchange request, the exchange rate, the historical foreign exchange request time, the request quantity at the historical foreign exchange request time, the historical mutual exchange waiting duration corresponding to the historical foreign exchange request, and information on whether the exchange is successful;

[0122] Input the historical foreign exchange data into a preset time series prediction model for training to obtain a mutual exchange duration prediction model;

[0123] Obtain historical exchange rate data; the historical exchange rate data includes historical exchange rate fluctuation information, historical macroeconomic data, and historical foreign exchange data;

[0124] Input the historical exchange rate data into a deep learning model for training to obtain a trained optimal exchange timing prediction model.

[0125] In an alternative approach, the spatio-temporal convolutional network is an STGCN model; the STGCN model includes a spatio-temporal convolutional block with two temporal convolutional layers sandwiching a spatial graph convolutional layer and a fully connected layer; the encrypted touch screen sliding trajectory, encrypted device holding posture, encrypted input rhythm information, historical transaction requests, and corresponding behavior risk degree labels are input into the spatio-temporal convolutional network for training to obtain a trained behavior analysis model, including:

[0126] Map the encrypted touch screen sliding trajectory, encrypted device holding posture, and encrypted input rhythm information at each time point to node features respectively, and represent the spatial relationship between the user's historical behavior information through an adjacency matrix;

[0127] Use the offset historical geographical location information in the historical transaction request as a node feature, and represent the spatial relationship between transactions through an adjacency matrix;

[0128] Extract features through the temporal convolutional layer and the spatial graph convolutional layer respectively, and output a risk prediction value through the fully connected layer;

[0129] Calculate a loss function based on the risk prediction value and the behavior risk degree label, and adjust the parameters of the STGCN model according to the loss function, and continue iterative training to obtain the trained behavior analysis model.

[0130] In an alternative approach, the encrypted current original biometric data of the user at least includes current encrypted fingerprint data, current liveness detection encrypted information, and current voiceprint encrypted data; the preset thresholds include a preset first threshold and a preset second threshold; according to the behavior risk degree, collect the user's current original biometric data and encrypt the user's current original biometric data using a preset second encryption algorithm, and destroy the current original biometric data, and use a target verification strategy to verify the encrypted current biometric data to obtain a verification result, including:

[0131] Obtain the standard user encrypted biometric data encrypted using a preset second encryption algorithm from the third-party storage end; the standard user encrypted biometric data at least includes standard encrypted fingerprint data, standard voiceprint encrypted data, and standard liveness detection encrypted information;

[0132] When the behavior risk degree is lower than the first threshold, compare the current encrypted fingerprint data with the standard encrypted fingerprint data to obtain a verification result;

[0133] When the behavior risk level is higher than a preset first threshold and lower than a preset second threshold, verify according to any two of the current encrypted fingerprint data, the current live detection encrypted information, or the current voiceprint encrypted data to obtain a verification result;

[0134] When the behavior risk level is higher than the second threshold, verify the current encrypted fingerprint data, the current live detection encrypted information, and the current voiceprint encrypted data respectively to obtain a verification result.

[0135] In an optional manner, after determining whether there is payment fraud according to the verification result, the method includes:

[0136] When it is determined that there is payment fraud, stop the transaction payment and prompt the user with the result of the failed transaction. When receiving the user's transaction request, collect the user's current original behavior data in real time; the transaction request includes a user identifier, current transaction information, and current physical information; the user's current original behavior data at least includes a touch screen sliding trajectory, a device holding posture, and input rhythm information;

[0137] After encrypting the user's current original behavior data and the transaction request respectively using a preset first encryption algorithm in real time, obtain the encrypted current behavior data and the encrypted transaction request, and at the same time destroy the user's current original behavior data and the transaction request;

[0138] Analyze the encrypted current behavior data and the transaction request using a behavior analysis model to obtain a behavior risk level; the behavior analysis model is obtained by a third-party storage end training a spatio-temporal graph convolutional network according to the user's historical behavior information and historical transaction information; the user's historical behavior information is obtained by encrypting the user's original historical behavior information using a preset first encryption algorithm;

[0139] According to the behavior risk level, collect the user's current original biological data, encrypt the user's current original biological data using a preset second encryption algorithm, destroy the current original biological data, and verify the encrypted current biological data using a target verification strategy to obtain a verification result; the target verification strategy is one of the multi-modal identity verification strategies;

[0140] Determine whether there is payment fraud according to the verification result.

[0141] In an alternative approach, the first encryption algorithm includes a position offset algorithm and differential privacy calculation; the current physical information includes current device information and current geographical location information; after separately and real-time encrypting the user's current original behavior data and the transaction request using a preset first encryption algorithm, the encrypted current behavior data and the encrypted transaction request are obtained, and at the same time, the user's current original behavior data and the transaction request are destroyed, including:

[0142] After performing position offset calculation on the current geographical location information according to the position offset algorithm, the offset current geographical location information is obtained;

[0143] Perform differential privacy calculation on the user's current original behavior data to obtain the encrypted current behavior data.

[0144] In an alternative approach, before predicting at least one recommended exchange plan by inputting the first foreign exchange request, the current exchange rate fluctuation information, and the historical foreign exchange data into the exchange plan model when the waiting duration exceeds a preset duration threshold, the method further includes:

[0145] Obtain historical foreign exchange data; the historical foreign exchange data includes the amount of the historical foreign exchange request, the exchange rate, the historical foreign exchange request time, the request quantity at the historical foreign exchange request time, the historical mutual exchange waiting duration corresponding to the historical foreign exchange request, and information on whether the exchange was successful;

[0146] Input the historical foreign exchange data into a preset time series prediction model for training to obtain a mutual exchange duration prediction model;

[0147] Obtain historical exchange rate data; the historical exchange rate data includes historical exchange rate fluctuation information, historical macroeconomic data, and historical foreign exchange data;

[0148] Input the historical exchange rate data into a deep learning model for training to obtain a trained optimal exchange timing prediction model.

[0149] In an alternative approach, the spatio-temporal convolutional network is an STGCN model; the STGCN model includes a spatio-temporal convolutional block with two temporal convolutional layers sandwiching a spatial graph convolutional layer and a fully connected layer; inputting the encrypted touch screen sliding trajectory, the encrypted device holding posture, the encrypted input rhythm information, the historical transaction request, and the corresponding behavior risk degree label into the spatio-temporal convolutional network for training to obtain a trained behavior analysis model, including:

[0150] Map the encrypted touch screen sliding trajectory, the encrypted device holding posture, and the encrypted input rhythm information at each time point into node features respectively, and represent the spatial relationship between the user's historical behavior information through an adjacency matrix;

[0151] Use the offset historical geographical location information in the historical transaction request as node features, and represent the spatial relationship between transactions through an adjacency matrix;

[0152] Extract features through a temporal convolutional layer and a spatial graph convolutional layer respectively, and output a risk prediction value through a fully connected layer;

[0153] According to the risk prediction value and the behavior risk degree label, calculate the loss function, and adjust the parameters of the STGCN model according to the loss function, and continue iterative training to obtain the trained behavior analysis model.

[0154] In an alternative manner, the multi-modal authentication strategy includes a first authentication strategy, a second authentication strategy, and a third authentication strategy; the encrypted current original biometric data of the user at least includes current encrypted fingerprint data, current liveness detection encrypted information, and current voiceprint encrypted data; the preset thresholds include a preset first threshold and a preset second threshold; according to the behavior risk degree, collect the user's current original biometric data, encrypt the user's current original biometric data using a preset second encryption algorithm, and destroy the current original biometric data, and use a target authentication strategy to authenticate the encrypted current biometric data to obtain a verification result, including:

[0155] Obtain the standard user encrypted biometric data encrypted using a preset second encryption algorithm from the third-party storage end; the standard user encrypted biometric data at least includes standard encrypted fingerprint data, standard voiceprint encrypted data, and standard liveness detection encrypted information;

[0156] When the behavior risk degree is lower than the first threshold, verify according to the first verification strategy; the first verification strategy is to compare the current encrypted fingerprint data with the standard encrypted fingerprint data to obtain a verification result;

[0157] When the behavior risk degree is higher than the preset first threshold and lower than the preset second threshold, verify according to the second verification strategy; the second verification strategy is to verify according to any two of the current encrypted fingerprint data, the current liveness detection encrypted information, or the current voiceprint encrypted data to obtain a verification result;

[0158] When the behavior risk degree is higher than the second threshold, verify according to the third verification strategy to obtain a verification result; the third verification strategy is to verify the current encrypted fingerprint data, the current liveness detection encrypted information, and the current voiceprint encrypted data respectively to obtain a verification result.

[0159] In an alternative manner, after determining whether there is payment fraud according to the verification result, the method includes:

[0160] When it is determined that there is payment fraud, stop the transaction payment and prompt the user with the result of the failed transaction.

[0161] In an embodiment of the present invention, when a transaction request from a user is received, the user's current original behavior data is collected in real time according to the transaction request. After respectively encrypting the user's current original behavior data and the transaction request in real time using a preset first encryption algorithm, the encrypted current behavior data and the encrypted transaction request are obtained, and at the same time, the user's current original behavior data and the transaction request are destroyed; the encrypted current behavior data and the transaction request are analyzed using a behavior analysis model to obtain a behavior risk degree; according to the behavior risk degree, the user's current original biological data is collected and encrypted using a preset second encryption algorithm, and the current original biological data is destroyed, and a target verification strategy is used to verify the encrypted current biological data to obtain a verification result; according to the verification result, it is determined whether there is payment fraud. Among them, by encrypting various types of user data in each link, destroying the original sensitive data, and storing the sensitive data encrypted in a third-party storage end, it is possible to effectively perform security verification through multi-modal during the transaction payment process, and at the same time, it will not cause user privacy leakage due to excessive collection of user sensitive data.

[0162] An embodiment of the present invention provides a computer-readable storage medium, and the storage medium stores at least one executable instruction. When the executable instruction runs on a computer device, the computer device is caused to execute the method for detecting payment fraud based on behavior pattern analysis and multi-modal identity verification in any of the above method embodiments.

[0163] The executable instruction can specifically be used to cause the computer device to perform the following operations:

[0164] When a transaction request from a user is received, the user's current original behavior data is collected in real time according to the transaction request; the transaction request includes a user identifier, current transaction information, and current physical information; the user's current original behavior data at least includes a touch screen sliding trajectory, a device holding posture, and input rhythm information;

[0165] After respectively encrypting the user's current original behavior data and the transaction request in real time using a preset first encryption algorithm, the encrypted current behavior data and the encrypted transaction request are obtained, and at the same time, the user's current original behavior data and the transaction request are destroyed;

[0166] Analyze using a behavior analysis model based on the encrypted current behavior data and the transaction request to obtain a behavior risk level; the behavior analysis model is obtained by a third-party storage end training a spatio-temporal graph convolutional network based on user historical behavior information and historical transaction information; the user historical behavior information is obtained by encrypting the user's original historical behavior information using a preset first encryption algorithm;

[0167] According to the behavior risk level, collect the user's current original biometric data, encrypt the user's current original biometric data using a preset second encryption algorithm, destroy the current original biometric data, and verify the encrypted current biometric data using a target verification strategy to obtain a verification result; the target verification strategy is one of the multi-modal identity verification strategies;

[0168] Determine whether there is payment fraud according to the verification result.

[0169] In an optional manner, the first encryption algorithm includes a position offset algorithm and differential privacy calculation; the current physical information includes current device information and current geographical location information; after respectively and real-time encrypting the user's current original behavior data and the transaction request using the preset first encryption algorithm, the encrypted current behavior data and the encrypted transaction request are obtained, and at the same time, the user's current original behavior data and the transaction request are destroyed, including:

[0170] Perform a position offset calculation on the current geographical location information according to the position offset algorithm to obtain the offset current geographical location information;

[0171] Perform differential privacy calculation on the user's current original behavior data to obtain the encrypted current behavior data.

[0172] In an optional manner, before predicting at least one recommended exchange plan according to the first foreign exchange request, the current exchange rate fluctuation information, and the historical foreign exchange data by inputting them into an exchange plan model when the waiting duration exceeds a preset duration threshold, the method further includes:

[0173] Obtain historical foreign exchange data; the historical foreign exchange data includes the amount of the historical foreign exchange request, the exchange rate, the historical foreign exchange request time, the request quantity at the historical foreign exchange request time, the historical mutual exchange waiting duration corresponding to the historical foreign exchange request, and information on whether the exchange is successful;

[0174] Input the historical foreign exchange data into a preset time series prediction model for training to obtain a mutual exchange duration prediction model;

[0175] Obtain historical exchange rate data; the historical exchange rate data includes historical exchange rate fluctuation information, historical macroeconomic data, and historical foreign exchange data;

[0176] Input the historical exchange rate data into a deep learning model for training to obtain a trained optimal exchange timing prediction model.

[0177] In an alternative approach, the spatio-temporal convolutional network is an STGCN model; the STGCN model includes a spatio-temporal convolutional block with two temporal convolutional layers sandwiching a spatial graph convolutional layer and a fully connected layer; the encrypted touchscreen sliding trajectory, encrypted device holding posture, encrypted input rhythm information, historical transaction requests, and corresponding behavioral risk degree labels are input into the spatio-temporal convolutional network for training to obtain a trained behavioral analysis model, including:

[0178] Map the encrypted touchscreen sliding trajectory, encrypted device holding posture, and encrypted input rhythm information at each time point into node features respectively, and represent the spatial relationship between the user's historical behavior information through an adjacency matrix;

[0179] Use the offset historical geographical location information in the historical transaction request as a node feature, and represent the spatial relationship between transactions through an adjacency matrix;

[0180] Extract features through the temporal convolutional layer and the spatial graph convolutional layer respectively, and output a risk prediction value through the fully connected layer;

[0181] Calculate a loss function based on the risk prediction value and the behavioral risk degree label, and adjust the parameters of the STGCN model according to the loss function, and continue iterative training to obtain the trained behavioral analysis model.

[0182] In an alternative approach, the encrypted current original biological data of the user at least includes current encrypted fingerprint data, current encrypted liveness detection information, and current encrypted voiceprint data; the preset thresholds include a preset first threshold and a preset second threshold; according to the behavioral risk degree, collect the user's current original biological data and encrypt the user's current original biological data using a preset second encryption algorithm, and destroy the current original biological data, and use a target verification strategy to verify the encrypted current biological data to obtain a verification result, including:

[0183] Obtain the standard user encrypted biological data encrypted using a preset second encryption algorithm from the third-party storage end; the standard user encrypted biological data at least includes standard encrypted fingerprint data, standard encrypted voiceprint data, and standard encrypted liveness detection information;

[0184] When the behavioral risk degree is lower than the first threshold, compare the current encrypted fingerprint data with the standard encrypted fingerprint data to obtain a verification result;

[0185] When the behavior risk level is higher than a preset first threshold and lower than a preset second threshold, any two of the current encrypted fingerprint data, the current liveness detection encrypted information, or the current voiceprint encrypted data are used for verification to obtain a verification result;

[0186] When the behavior risk level is higher than the second threshold, the current encrypted fingerprint data, the current liveness detection encrypted information, and the current voiceprint encrypted data are respectively verified to obtain a verification result.

[0187] In an optional manner, after determining whether there is payment fraud according to the verification result, the method includes:

[0188] When it is determined that there is payment fraud, stop the transaction payment and prompt the user with the result of the failed transaction.

[0189] In an embodiment of the present invention, when receiving a transaction request from a user, the user's current original behavior data is collected in real time according to the transaction request. After respectively encrypting the user's current original behavior data and the transaction request with a preset first encryption algorithm in real time, the encrypted current behavior data and the encrypted transaction request are obtained, and at the same time, the user's current original behavior data and the transaction request are destroyed; the encrypted current behavior data and the transaction request are analyzed using a behavior analysis model to obtain a behavior risk level; according to the behavior risk level, the user's current original biological data is collected and encrypted with a preset second encryption algorithm, and the current original biological data is destroyed. The encrypted current biological data is verified using a target verification strategy to obtain a verification result; according to the verification result, it is determined whether there is payment fraud. Among them, by encrypting various types of user data in each link, destroying the original sensitive data, and storing the sensitive data encrypted in a third-party storage end, it is possible to effectively perform security verification through multi-modal during the transaction payment process, and at the same time, it will not cause user privacy leakage due to excessive collection of user sensitive data.

[0190] An embodiment of the present invention provides a payment fraud detection device based on behavior pattern analysis and multi-modal identity verification, which is used to execute the above-mentioned payment fraud detection method based on behavior pattern analysis and multi-modal identity verification.

[0191] An embodiment of the present invention provides a computer program, which can be called by a processor to enable a computer device to execute the payment fraud detection method based on behavior pattern analysis and multi-modal identity verification in any of the above method embodiments.

[0192] An embodiment of the present invention provides a computer program product. The computer program product includes a computer program stored on a computer-readable storage medium. The computer program includes program instructions. When the program instructions run on a computer, the computer is caused to execute the method for detecting payment fraud based on behavior pattern analysis and multi-modal authentication in any of the above method embodiments.

[0193] The algorithms or displays provided herein are not inherently related to any particular computer, virtual system, or other device. Various general-purpose systems can also be used in conjunction with the teachings based herein. The structure required to construct such systems will be apparent from the above description. In addition, the embodiments of the present invention are not directed to any particular programming language. It should be understood that the content of the present invention described herein can be implemented using various programming languages, and the description of the specific language above is for disclosing the best mode of the present invention.

[0194] In the specification provided herein, a large number of specific details are set forth. However, it can be understood that the embodiments of the present invention can be practiced without these specific details. In some instances, well-known methods, structures, and techniques have not been shown in detail so as not to obscure the understanding of this specification.

[0195] Similarly, it should be understood that, in order to streamline the present invention and assist in understanding one or more of the various inventive aspects, in the above description of the exemplary embodiments of the present invention, the various features of the embodiments of the present invention are sometimes grouped together into a single embodiment, figure, or description thereof. However, the disclosed method should not be construed as reflecting an intention that the claimed invention requires more features than are expressly recited in each claim.

[0196] Those skilled in the art can understand that the modules in the devices in the embodiments can be adaptively changed and disposed in one or more devices different from the embodiments. The modules or units or components in the embodiments can be combined into one module or unit or component, and can be divided into multiple sub-modules or sub-units or sub-components. Except that at least some of such features and / or processes or units are mutually exclusive, any combination can be adopted to combine all the features disclosed in this specification (including the accompanying claims, abstract, and drawings) and all the processes or units of any method or device so disclosed. Unless otherwise expressly stated, each feature disclosed in this specification (including the accompanying claims, abstract, and drawings) can be replaced by an alternative feature that provides the same, equivalent, or similar purpose.

[0197] It should be noted that the above embodiments illustrate the present invention rather than limit the present invention, and those skilled in the art can design alternative embodiments without departing from the scope of the appended claims. In the claims, any reference signs placed between parentheses shall not be construed as limiting the claim. The word "comprising" does not exclude the presence of elements or steps not listed in the claim. The word "a" or "an" preceding an element does not exclude the presence of a plurality of such elements. The present invention can be implemented by means of hardware including several different elements and by means of a suitably programmed computer. In the unit claims listing several devices, several of these devices may be embodied by the same item of hardware. The use of the words first, second, and third, etc. does not denote any order. These words can be interpreted as names. The steps in the above embodiments, unless otherwise specified, should not be construed as limiting the order of execution.

Claims

1. A payment fraud detection method based on behavioral pattern analysis and multimodal identity authentication, characterized in that: The method comprises: When receiving a transaction request from a user, the user's current original behavior data is collected in real time according to the transaction request; the transaction request includes a user identifier, current transaction information, and current physical information; the user's current original behavior data includes at least a touch screen sliding track, a device holding posture, and input rhythm information; After respectively encrypting the user's current original behavior data and the transaction request in real time using a preset first encryption algorithm, the encrypted current behavior data and the encrypted transaction request are obtained, and the user's current original behavior data and the transaction request are destroyed at the same time; The encrypted touch screen sliding trajectory, encrypted device holding posture and encrypted input rhythm information at each time point are mapped to node features respectively, and the spatial relationship between the user's historical behavior information is represented by the adjacency matrix; the offset historical geographic location information in the historical transaction request is used as the node feature, and the spatial relationship between transactions is represented by the adjacency matrix; the features are extracted by the temporal convolution layer and the spatial graph convolution layer of the STGCN model respectively, and the risk prediction value is output through the fully connected layer of the STGCN model; the loss function is calculated based on the risk prediction value and the behavior risk label, and the parameters of the STGCN model are adjusted according to the loss function, and the iterative training is continued to obtain a trained behavior analysis model; Analyze the encrypted current behavior data and the transaction request using a behavior analysis model to obtain a behavior risk level; According to the behavior risk, obtaining from a third-party storage terminal standard user encrypted biometric data encrypted by a preset second encryption algorithm; When the behavior risk is lower than the first threshold, verification is performed according to a first verification strategy; the first verification strategy is to compare the current encrypted fingerprint data with the standard encrypted fingerprint data to obtain a verification result; When the behavior risk is higher than a preset first threshold and lower than a preset second threshold, verification is performed according to a second verification strategy; the second verification strategy is to perform verification according to any two of the current encrypted fingerprint data, the current liveness detection encrypted information or the current voiceprint encrypted data to obtain a verification result; When the behavior risk is higher than the second threshold, verification is performed according to a third verification strategy to obtain a verification result; the third verification strategy is to verify the current encrypted fingerprint data, the current liveness detection encrypted information and the current voiceprint encrypted data respectively to obtain a verification result; Based on the verification result, determine whether payment fraud exists.

2. The method according to claim 1, characterized in that The first encryption algorithm includes a location shift algorithm and a differential privacy calculation; the current physical information includes current device information and current geographic location information; the current original behavior data of the user and the transaction request are encrypted in real time using a preset first encryption algorithm to obtain the encrypted current behavior data and the encrypted transaction request, and the current original behavior data of the user and the transaction request are destroyed at the same time, including: After calculating the position offset of the current geographical location information according to the position offset algorithm, the current geographical location information after offset is obtained; Perform differential privacy calculation on the user's current original behavior data to obtain encrypted current behavior data.

3. The method according to claim 2, characterized in that The current transaction information includes the transaction amount and transaction time; the user historical behavior information includes historical transaction requests, historical device information and historical geographic location information; before analyzing the encrypted current behavior data and the transaction request using a behavior analysis model to obtain the behavior risk, the method further includes: The third-party storage end uses a differential privacy algorithm to encrypt the historical touch screen sliding trajectory, the historical device holding posture, and the historical input rhythm information in the historical transaction request to obtain the encrypted touch screen sliding trajectory, the encrypted device holding posture, and the encrypted input rhythm information; The third-party storage end calculates the position offset of the historical geographical location information according to the position offset algorithm to obtain the historical geographical location information after offset; The third-party storage end inputs the encrypted touch screen sliding trajectory, encrypted device holding posture and encrypted input rhythm information, historical transaction requests and corresponding behavioral risk labels into the spatiotemporal convolutional network for training to obtain a trained behavior analysis model.

4. The method according to any one of claims 1 to 3, characterized in that: After determining whether payment fraud exists according to the verification result, the method includes: When payment fraud is determined, the transaction payment is stopped and the user is prompted with the result of transaction failure.

5. A payment fraud detection device based on behavioral pattern analysis and multimodal identity authentication, characterized in that: The device comprises: A collection module, for collecting the user's current original behavior data in real time according to the transaction request when receiving the transaction request from the user; the transaction request includes the user identification, current transaction information and current physical information; the user's current original behavior data includes at least the touch screen sliding track, device holding posture and input rhythm information; An encryption and destruction module, used to encrypt the current original behavior data of the user and the transaction request in real time using a preset first encryption algorithm to obtain the encrypted current behavior data and the encrypted transaction request, and to destroy the current original behavior data of the user and the transaction request at the same time; The risk calculation module is used to map the encrypted touch screen sliding trajectory, encrypted device holding posture and encrypted input rhythm information at each time point into node features, and represent the spatial relationship between the user's historical behavior information through the adjacency matrix; use the offset historical geographic location information in the historical transaction request as the node feature, and represent the spatial relationship between transactions through the adjacency matrix; extract features through the time convolution layer and the spatial graph convolution layer of the STGCN model, and output the risk prediction value through the fully connected layer of the STGCN model; calculate the loss function based on the risk prediction value and the behavior risk label, and adjust the parameters of the STGCN model according to the loss function, and continue to iterate the training to obtain a trained behavior analysis model; use the behavior analysis model to analyze the encrypted current behavior data and the transaction request to obtain the behavior risk; A multimodal verification module is used to obtain, from a third-party storage terminal, standard user encrypted biometric data encrypted by a preset second encryption algorithm according to the behavior risk; when the behavior risk is lower than a first threshold, verification is performed according to a first verification strategy; the first verification strategy is to compare the current encrypted fingerprint data with the standard encrypted fingerprint data to obtain a verification result; when the behavior risk is higher than the preset first threshold and lower than the preset second threshold, verification is performed according to a second verification strategy; the second verification strategy is to perform verification according to any two of the current encrypted fingerprint data, the current liveness detection encrypted information or the current voiceprint encrypted data to obtain a verification result; when the behavior risk is higher than the second threshold, verification is performed according to a third verification strategy to obtain a verification result; the third verification strategy is to respectively verify the current encrypted fingerprint data, the current liveness detection encrypted information and the current voiceprint encrypted data to obtain a verification result; The determination module is used to determine whether payment fraud exists according to the verification result.

6. The device according to claim 5, characterized in that The first encryption algorithm includes a location shift algorithm and a differential privacy calculation; the current physical information includes current device information and current geographic location information; the current original behavior data of the user and the transaction request are encrypted in real time using a preset first encryption algorithm to obtain the encrypted current behavior data and the encrypted transaction request, and the current original behavior data of the user and the transaction request are destroyed at the same time, including: After calculating the position offset of the current geographical location information according to the position offset algorithm, the current geographical location information after offset is obtained; Perform differential privacy calculation on the user's current original behavior data to obtain encrypted current behavior data.

7. A computer device, characterized in that: include: A processor, a memory, a communication interface and a communication bus, wherein the processor, the memory and the communication interface communicate with each other via the communication bus; The memory is used to store at least one executable instruction, and the executable instruction enables the processor to perform the operation of the payment fraud detection method based on behavioral pattern analysis and multimodal identity authentication as described in any one of claims 1-4.

8. A computer-readable storage medium, characterized in that: The storage medium stores at least one executable instruction, and when the executable instruction is executed on a computer device, the computer device executes the operation of the payment fraud detection method based on behavioral pattern analysis and multimodal identity authentication as described in any one of claims 1 to 4.

Citation Information

Patent Citations

  • Safe withdrawal method and system for automatic teller machine

    CN113223252A