Transaction behavior anomaly detection method and device and processor
By applying the transaction prediction model of the tree-enhanced pin Bayesian algorithm in financial transactions, the problem of low accuracy of transaction behavior abnormality detection is solved, more efficient and reliable transaction monitoring is achieved, and financial risks are reduced.
Patent Information
- Application Number
- CN202411974459.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-30
- Publication Date
- 2025-05-06
AI Technical Summary
The accuracy of abnormal detection of transaction behavior in the prior art is low, and the transaction abnormality cannot be effectively identified, making it difficult to prevent financial risks.
By obtaining transaction data sets, a tree-enhanced naive Bayes algorithm is used to establish a transaction prediction model, analyze the dependencies between transaction data, predict transaction results, and perform abnormal detection based on the prediction results.
It improves the accuracy of abnormal detection of transaction behavior, enhances the system's adaptability and self-optimization capabilities, provides more reliable and efficient transaction monitoring methods, and reduces financial risks.
Smart Images

Figure CN119939453A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of financial technology, and specifically, to a method, device and processor for detecting anomalies in transaction behaviors. Background Art
[0002] At present, payment transaction prediction and analysis is an important application in e-commerce, finance and other fields. Transaction prediction is based on historical transaction data and predicts transaction information in a certain period of time in the future, providing a basis for optimizing financial resource allocation, improving service quality, and preventing financial risks. With the rapid development of mobile payment and online payment, the amount of transaction data has increased exponentially, and the complexity and dynamic characteristics of transaction data are obvious. Relevant statistical analysis methods are difficult to meet the needs when dealing with transaction prediction problems.
[0003] In the related technologies, the conditional entropy algorithm is an important method for transaction prediction. Its main disadvantages are: it has high requirements for data continuity, while transaction data has jumps in time; it is sensitive to outliers, which can easily lead to deviations in prediction results; and the prediction model based on conditional entropy lacks interpretability for user needs. In summary, the related technologies still have the technical problem of low accuracy in detecting anomalies in transaction behaviors.
[0004] Currently, no effective solution has been proposed to the technical problem of low accuracy in detecting anomalies in transaction behaviors in related technologies. Summary of the invention
[0005] The main purpose of the present application is to provide a method, device and processor for detecting anomalies in transaction behaviors, so as to solve the technical problem of low accuracy in detecting anomalies in transaction behaviors in related technologies.
[0006] In order to achieve the above-mentioned purpose, according to one aspect of the present application, a method for detecting anomalies in transaction behaviors is provided. The method comprises: obtaining a transaction data set corresponding to the transaction behavior to be detected for anomalies, wherein the transaction data set includes transaction data of different dimensions generated when executing the transaction behavior; using a transaction prediction model, predicting the transaction result corresponding to the transaction behavior to obtain a prediction result, wherein the prediction result is used to indicate whether the transaction result corresponding to the transaction behavior is in a successful state or a failed state, and the transaction prediction model is used to analyze the dependency relationship between different transaction data in the transaction data set; based on the prediction result, detecting the transaction behavior to obtain a detection result, wherein the detection result is used to indicate whether the transaction behavior is in an abnormal state or a normal state.
[0007] Optionally, the method further includes: obtaining transaction data samples, and using the transaction data samples and a tree-enhanced naive Bayes algorithm to establish a transaction prediction model.
[0008] Optionally, obtaining a transaction data sample includes: obtaining an initial transaction data sample for a historical period, wherein the initial transaction data sample is generated when executing historical transaction behaviors within the historical period; performing consistency processing on the initial transaction data sample to obtain a processed initial transaction data sample, wherein the accuracy of the processed initial transaction data sample is higher than the accuracy of the processed initial transaction data sample; performing invalid value and missing value processing on the processed initial transaction data sample to obtain a transaction data sample.
[0009] Optionally, a transaction prediction model is established using transaction data samples and a tree-enhanced naive Bayes algorithm, including: analyzing the transaction data samples using a tree-enhanced naive Bayes algorithm to determine the conditional mutual information between the transaction data samples, wherein the conditional mutual information is used to represent the dependency relationship between the transaction data samples; constructing a tree model using the transaction data samples as nodes and the conditional mutual information as edges; and establishing a transaction prediction model based on the tree model.
[0010] Optionally, the tree model satisfies the following conditions: in the tree model, nodes corresponding to each transaction data sample are connected; in the tree model, the number of edges is the smallest; in the tree model, the sum of the lengths of the edges is the largest.
[0011] Optionally, the prediction result is probability information, wherein a transaction prediction model is used to predict a transaction result corresponding to the transaction behavior to obtain a prediction result, including: inputting a transaction data set into the transaction prediction model, using the transaction prediction model to determine dependencies, and based on the dependencies, constructing a tree model corresponding to the transaction data set; based on the tree model, determining probability information, wherein the probability information is used to indicate the probability of the transaction result being in a success state or a failure state.
[0012] Optionally, based on the tree model, determining the probability information includes: in response to the probability information being success probability information and the success probability information exceeding the probability information threshold, determining that the transaction result is in a success state, or the success probability information does not exceed the probability information threshold, determining that the transaction result is in a failure state; in response to the probability information being failure probability information and the failure probability information exceeds the probability information threshold, determining that the transaction result is in a failure state, or the failure probability information threshold does not exceed the probability information threshold, determining that the transaction result is in a success state.
[0013] Optionally, based on the prediction result, the transaction behavior is detected to obtain a detection result, including: in response to the prediction result being different from the actual result, determining that the detection result is that the transaction behavior is in an abnormal state; in response to the prediction result being the same as the actual result, determining that the detection result is that the transaction behavior is in a normal state; the method also includes: in response to the detection result being that the transaction behavior is in an abnormal state, processing the abnormal state to restore the transaction behavior to a normal state.
[0014] In order to achieve the above-mentioned purpose, according to another aspect of the present application, a device for detecting anomalies in transaction behaviors is provided. The device comprises: an acquisition unit, used to acquire a transaction data set corresponding to the transaction behavior to be detected for anomalies, wherein the transaction data set includes transaction data of different dimensions generated when executing the transaction behavior; a prediction unit, used to predict the transaction result corresponding to the transaction behavior using a transaction prediction model, and obtain a prediction result, wherein the prediction result is used to indicate whether the transaction result corresponding to the transaction behavior is in a successful state or a failed state, wherein the transaction prediction model is used to analyze the dependency relationship between different transaction data in the transaction data set; a detection unit, used to detect the transaction behavior based on the prediction result, and obtain a detection result, wherein the detection result is used to indicate whether the transaction behavior is in an abnormal state or a normal state.
[0015] According to another aspect of the embodiment of the present application, a processor is further provided. The processor is used to run a program, wherein when the program is run by the processor, the method for detecting anomalies in transaction behaviors in the embodiment of the present application is executed.
[0016] According to another aspect of an embodiment of the present application, an electronic device is also provided, including: a memory storing an executable program; and a processor for running the program, wherein when the program is running, the method for detecting anomalies in transaction behaviors in various embodiments of the present application is executed.
[0017] According to another aspect of the embodiment of the present application, a computer-readable storage medium is provided, which includes a stored program, wherein when the program is executed, the device where the computer-readable storage medium is located is controlled to execute the method for detecting abnormal transaction behavior in the embodiment of the present application.
[0018] According to another aspect of an embodiment of the present application, a computer program product is also provided, which includes a computer program, wherein when the computer program is executed by a processor, the method for detecting anomalies in transaction behaviors in the embodiment of the present application is implemented.
[0019] In an embodiment of the present application, if it is necessary to detect whether a transaction behavior is in an abnormal state, a transaction data set corresponding to the transaction behavior to be detected can be obtained. The transaction prediction model can be used to analyze the dependencies between the transaction data in the transaction data set to predict whether the transaction result is a success state or a failure state. Thus, the transaction behavior can be detected based on the prediction result to obtain the detection result. In this embodiment, the problem of low accuracy in detecting abnormal transaction behaviors is effectively solved through deep dependency analysis, probability prediction, dynamic threshold adjustment, real-time feedback, abnormal follow-up processing and automatic learning strategy. These methods not only improve the real-time and accuracy of detection, but also enhance the adaptability and self-optimization capabilities of the system, providing financial institutions with more reliable and efficient means of transaction monitoring. The technical problem of low accuracy in detecting abnormal transaction behaviors in the related technology is solved, and the technical effect of improving the accuracy of detecting abnormal transaction behaviors is achieved. BRIEF DESCRIPTION OF THE DRAWINGS
[0020] The drawings constituting a part of the present application are used to provide a further understanding of the present application. The illustrative embodiments and descriptions of the present application are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:
[0021] Figure 1 A hardware structure block diagram of a computer terminal for implementing an abnormality detection method for transaction behavior is shown;
[0022] Figure 2 is a flow chart of a method for detecting anomalies in transaction behavior according to an embodiment of the present application;
[0023] Figure 3 It is a flowchart of a transaction abnormality early warning monitoring method based on a tree enhanced naive Bayes algorithm provided in an embodiment of the present application;
[0024] Figure 4 is a schematic diagram of a transaction behavior anomaly detection device provided according to an embodiment of the present application;
[0025] Figure 5 It is a structural block diagram of an electronic device according to an embodiment of the present application. DETAILED DESCRIPTION
[0026] In order to enable those skilled in the art to better understand the solution of the present application, the technical solution in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of the present application.
[0027] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchangeable where appropriate, so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device comprising a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0028] It should be noted that the collected information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for display, data for analysis, etc.) involved in this application are information and data authorized by the user or fully authorized by all parties, and the collection, storage, use, processing, transmission, provision, disclosure and application of relevant data are in compliance with relevant laws, regulations and standards, necessary confidentiality measures are taken, and public order and good customs are not violated, and corresponding operation entrances are provided for users to choose to authorize or refuse. For example, an interface is set up between this system and relevant users or institutions to provide users with corresponding operation entrances for users to choose to agree or refuse the results of automated decision-making; if the user chooses to refuse, the expert decision-making process will be entered.
[0029] Example 1
[0030] According to an embodiment of the present application, a method embodiment of abnormal detection of transaction behavior is also provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.
[0031] The method embodiment provided in the first embodiment of the present application can be executed in a mobile terminal, a computer terminal or a similar computing device. Figure 1 The hardware structure block diagram of a computer terminal (or mobile device) for implementing an abnormality detection method for transaction behavior is shown. Figure 1As shown, the computer terminal 10 (or mobile device) may include one or more (102a, 102b, ..., 102n are used to illustrate) processors 102 (the processor 102 may include but is not limited to a processing device such as a microprocessor MCU or a programmable logic device FPGA), a memory 104 for storing data, and a transmission device 106 for communication functions. In addition, it may also include: a display, an input / output interface (I / O interface), a universal serial bus (USB) port (which may be included as one of the ports of the BUS bus), a network interface, a power supply and / or a camera. It can be understood by those skilled in the art that Figure 1 The structure shown is only for illustration and does not limit the structure of the above electronic device. Figure 1 More or fewer components as shown, or with Figure 1 Different configurations are shown.
[0032] It should be noted that the one or more processors 102 and / or other data processing circuits described above may generally be referred to herein as "data processing circuits". The data processing circuits may be embodied in whole or in part as software, hardware, firmware, or any other combination thereof. In addition, the data processing circuit may be a single independent processing module, or may be incorporated in whole or in part into any of the other components in the computer terminal 10 (or mobile device). As described in the embodiments of the present application, the data processing circuit acts as a processor control (e.g., selection of a variable resistor terminal path connected to an interface).
[0033] The memory 104 can be used to store software programs and modules of application software, such as program instructions / data storage devices corresponding to the abnormality detection method of transaction behavior in the embodiment of the present application. The processor 102 executes various functional applications and data processing by running the software programs and modules stored in the memory 104, that is, the abnormality detection method of transaction behavior described above is realized. The memory 104 may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some examples, the memory 104 may further include a memory remotely arranged relative to the processor 102, and these remote memories may be connected to the computer terminal 10 via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0034] The transmission device 106 is used to receive or send data via a network. The specific example of the above network may include a wireless network provided by a communication provider of the computer terminal 10. In one example, the transmission device 106 includes a network adapter (Network Interface Controller, NIC), which can be connected to other network devices through a base station so as to communicate with the Internet. In one example, the transmission device 106 can be a radio frequency (RF) module, which is used to communicate with the Internet wirelessly.
[0035] The display may be, for example, a touch screen liquid crystal display (LCD) that enables a user to interact with a user interface of the computer terminal 10 (or mobile device).
[0036] Under the above operating environment, this application provides Figure 2 Anomaly detection method for trading behavior shown. Figure 2 is a flow chart of a method for detecting anomalies in transaction behavior according to an embodiment of the present application. Figure 2 As shown, the method may include the following steps:
[0037] Step S201, obtaining a transaction data set corresponding to the transaction behavior to be detected for anomalies.
[0038] In step S201 of the embodiment of the present application, transaction behavior may refer to various types of transaction activities occurring in the bank payment system. Transaction behavior is the core of daily bank operations, which not only involves the flow of funds, but may also include complex business logic and multiple operations of the participating parties. The transaction data set includes transaction data of different dimensions generated when executing transaction behaviors. The transaction data may be bank payment transaction data. The transaction data set contains data of multiple dimensions generated when executing transaction behaviors. This is only for illustration and no specific limitation is made. The transaction data set is the basis for training and prediction of anomaly detection algorithms. By collecting and organizing these data, a deep understanding of normal transaction behaviors can be established, thereby more accurately identifying abnormal transactions.
[0039] In this embodiment, if it is necessary to detect whether a transaction behavior is in an abnormal state, a transaction data set corresponding to the transaction behavior to be detected for abnormality may be obtained.
[0040] Optionally, collect relevant data of all transactions to be detected from various channels and logs of the bank payment system. The accuracy and comprehensiveness of data collection directly affect the effect of subsequent analysis. After obtaining the transaction data set, data cleaning and preprocessing can be performed to eliminate the impact of invalid values, default values and abnormal data to ensure the quality of the data set. This step may include data consistency checks, format normalization, and outlier removal.
[0041] Optionally, the processed transaction data is integrated into a unified data set for algorithm processing. Data integration may involve data normalization, feature engineering, etc. to improve the efficiency of model training and the accuracy of prediction. Prepare the integrated data set into the format of model input, which usually includes steps such as feature selection and data segmentation (training set, validation set, test set), providing a basis for subsequent model training and anomaly detection.
[0042] In the embodiment of the present application, by executing the above steps, the quality and applicability of the transaction data set used for anomaly detection are ensured, providing a solid data foundation for subsequent analysis and model training. This step is crucial to the entire anomaly detection process because it directly affects the accuracy and efficiency of anomaly detection. With high-quality data sets, more accurate models can be trained to effectively identify and warn of abnormal transaction behaviors, thereby improving the risk prevention and control capabilities of financial institutions.
[0043] Step S202: using the transaction prediction model, predicting the transaction result corresponding to the transaction behavior to obtain a prediction result.
[0044] In step S202 of the embodiment of the present application, the prediction result is used to indicate that the transaction result corresponding to the transaction behavior is in a successful state or a failed state, and the transaction prediction model is used to analyze the dependency between different transaction data in the transaction data set. The transaction prediction model can be a model established by the Tree-Augmented Naive Bayes (TAN) algorithm. The TAN algorithm is an improved naive Bayes classifier that not only considers the independence assumption between features and targets, but also captures the interdependence between features by constructing a tree structure. In the scenario of transaction anomaly detection, the TAN algorithm can learn the dependency model between different transaction data based on historical transaction data, so as to more accurately predict the possibility of transaction results. The transaction result refers to the final state of feedback after the transaction behavior is completed, which is usually expressed as "success" or "failure". In normal transaction behavior, the transaction result should be successful, that is, the funds are successfully transferred from the debit account to the credit account, and all operations comply with business rules and expectations. Abnormal transaction behavior may lead to transaction failure or other unexpected results, such as funds not arriving, repeated transactions, and inconsistent transaction amounts.
[0045] Optionally, the prediction result is a judgment of the possibility of the transaction result output by the transaction prediction model based on the data set of the transaction behavior to be detected. In the scenario of the TAN algorithm, the prediction result is usually given in the form of probability, indicating the probability that the transaction result corresponding to the transaction behavior is in a "successful" or "failed" state. If the transaction prediction model believes that the probability of the transaction result corresponding to the transaction behavior being in a "successful" state is high, the prediction result is "success"; otherwise, the prediction result is "failure".
[0046] In this embodiment, after obtaining the transaction data set corresponding to the transaction behavior to be detected for anomalies, the transaction prediction model can be used to analyze the dependency relationship between transaction data of different dimensions in the transaction data set, and predict the transaction results corresponding to the transaction behavior to obtain the prediction results.
[0047] Optionally, after the transaction data set is collected and preprocessed, the data is input into a trained TAN transaction prediction model, which uses the learned dependencies between transaction data to analyze and infer new transaction data.
[0048] Optionally, the probability of each transaction result (success or failure) can be calculated within the transaction prediction model. For example, it can be calculated using a probability formula based on a tree structure based on nodes (transaction data features) and edges (dependencies between features). After obtaining the "success" and "failure" probabilities of the predicted results, the model will compare these probabilities with preset thresholds. If the predicted "success" probability exceeds the threshold of the success state, the transaction prediction model will mark the transaction result as a "success" state; if the predicted "failure" probability exceeds the threshold of the failure state, it will be marked as a "failure" state.
[0049] Optionally, the transaction prediction model outputs a status result, that is, the predicted transaction result is "successful" or "failed". This status output will be used as a basis for judging whether the transaction behavior is abnormal in subsequent steps.
[0050] In the embodiments of the present application, through the above embodiments, the transaction prediction model can provide a prediction of the transaction results based on the feature analysis of the transaction data set, thereby providing a quantitative judgment basis for transaction anomaly detection. This step is the key to the entire anomaly detection process, and it takes advantage of the TAN algorithm to more accurately identify potential abnormal transactions, providing strong technical support for risk control of bank payment systems.
[0051] Step S203: Based on the prediction result, the transaction behavior is detected to obtain the detection result.
[0052] In step S203 of the embodiment of the present application, the detection result is used to indicate whether the transaction behavior is in an abnormal state or a normal state. The detection result can be a sign that the transaction behavior is in an "abnormal state" or a "normal state". The judgment of this state is based on the prediction result output by the transaction prediction model, that is, the model's predicted probability of the transaction result (success or failure). If there is a significant difference between the predicted result and the actual transaction result, or the predicted failure probability exceeds the abnormal threshold (the preset standard for judging abnormal transactions), the transaction behavior will be marked as "abnormal state"; conversely, if the predicted result is consistent with the actual result, or the predicted failure probability is lower than the abnormal threshold, the transaction behavior will be marked as "normal state".
[0053] In this embodiment, after predicting the prediction result using the transaction prediction model, the transaction behavior can be detected based on the prediction result to obtain the detection result.
[0054] Optionally, the prediction model outputs a prediction result, i.e., the probability that the transaction result corresponding to the transaction behavior is in the "success" or "failure" state. The prediction result can be compared with the actual transaction result. If it is a real-time detection system, the actual transaction result is usually an immediate feedback of the current transaction behavior.
[0055] Optionally, based on the comparison results, the system will determine whether the predicted failure probability exceeds the preset abnormal threshold. This threshold is set based on business needs and risk assessment to distinguish normal transaction behavior from potential abnormal transaction behavior.
[0056] Optionally, if the predicted failure probability exceeds the abnormal threshold, or the predicted result is inconsistent with the actual transaction result (for example, the model predicts failure but the actual transaction is successful, or the model predicts success but the actual transaction fails), the transaction behavior will be marked as "abnormal state". Conversely, if the predicted failure probability is lower than the abnormal threshold, and the predicted result is consistent with the actual result, the transaction behavior will be marked as "normal state".
[0057] Optionally, for transaction behaviors marked as "abnormal status", subsequent abnormal handling processes can be triggered. This may include suspending transactions, starting manual review, recording abnormal behavior characteristics, adjusting monitoring strategies, etc. The specific operations depend on the preset abnormal handling rules and strategies.
[0058] In the embodiment of the present application, based on the output of the transaction prediction model, the transaction behavior can be detected in real time or near real time, potential abnormal transaction behavior can be identified in time, and responses can be made according to business needs and security policies. This process strengthens the risk control ability of the bank payment system, helps to protect the financial security of financial institutions and customers, while reducing the cost and false alarm rate of manual monitoring and improving the efficiency and accuracy of abnormal detection.
[0059] In step S201 to step S203 of the embodiment of the present application, if it is necessary to detect whether the transaction behavior is in an abnormal state, the transaction data set corresponding to the transaction behavior to be detected can be obtained. The transaction prediction model can be used to analyze the dependencies between the transaction data in the transaction data set to predict whether the transaction result is a success state or a failure state. Thus, the transaction behavior can be detected based on the prediction result to obtain the detection result. In this embodiment, the problem of low accuracy in detecting abnormal transaction behavior is effectively solved through deep dependency analysis, probability prediction, dynamic threshold adjustment, real-time feedback, abnormal follow-up processing and automatic learning strategy. These methods not only improve the real-time and accuracy of detection, but also enhance the adaptability and self-optimization ability of the system, providing financial institutions with more reliable and efficient transaction monitoring means. The technical problem of low accuracy in detecting abnormal transaction behavior in the related technology is solved, and the technical effect of improving the accuracy of detecting abnormal transaction behavior is achieved.
[0060] The above method of this embodiment is further introduced below.
[0061] As an optional implementation mode, the method also includes: obtaining transaction data samples, and using the transaction data samples and adopting a tree-enhanced naive Bayes algorithm to establish a transaction prediction model.
[0062] In this embodiment, a transaction data sample may be obtained, and a transaction prediction model may be established using the transaction data sample and the TAN algorithm. The transaction data sample may be a large transaction attribute data sample.
[0063] Optionally, the step of obtaining transaction data samples and establishing a transaction prediction model using the TAN algorithm is the core of the model training stage in the embodiment of the present application. This stage provides a basis for subsequent transaction behavior anomaly detection.
[0064] Optionally, a large amount of transaction data is extracted from the historical records of the bank's payment system as samples. This data should cover different types of transactions, different time periods, different user groups, and instances of normal and abnormal transactions to ensure the comprehensiveness and accuracy of model training. The collected raw transaction data is preprocessed, including data cleaning (removing invalid values and default values), feature engineering (extracting and constructing features that are helpful for prediction), and data balancing (dealing with class imbalance problems and ensuring that the ratio of normal and abnormal transaction data is appropriate). This step is crucial to improving the predictive performance of the model.
[0065] Optionally, a transaction prediction model is established using the TAN algorithm using transaction data samples. In the preprocessed data set, features related to transaction results (success or failure) are selected to analyze the interdependencies between features. The TAN algorithm can measure the strength of dependency by calculating the conditional mutual information (CMI) between features, which is the basis for model construction. The TAN algorithm is used to construct a maximum weighted spanning tree between the features of the transaction data. The nodes in the tree represent transaction features, the weights of the edges are determined by the CMI between the features, and the structure of the tree reflects the dependencies and information flows between the features. The above steps can capture the complex patterns hidden in the transaction data and improve the accuracy of the model.
[0066] Optionally, based on the constructed weighted spanning tree, a training dataset is used to train the model to learn the probabilistic mapping from input features to trading outcomes (success or failure). Parameters are adjusted during model training to optimize the match between the predicted results and the actual results. After the model training is completed, the model is preliminarily validated using the validation set to evaluate its prediction accuracy and generalization ability. Based on the validation results, it may be necessary to adjust the model parameters, feature selection, or data preprocessing strategies to further optimize the model performance. The validated and optimized trading prediction model can be deployed in a production environment for real-time or near real-time detection of trading behavior anomalies. The model needs to be updated regularly to adapt to changes in trading behavior and new abnormal patterns.
[0067] Optionally, the TAN algorithm can capture the dependencies between features by constructing a tree model, which is ignored in the traditional naive Bayes algorithm. This feature of the TAN algorithm is very suitable for transaction anomaly detection, because the mutual influence between features in transaction data is often very complex. The establishment of the model should not be a one-time process, but requires a continuous iteration and optimization process. As new data accumulates, the model should be updated regularly to ensure that it can adapt to new transaction trends and abnormal patterns. Through the above embodiments, a transaction prediction model based on the TAN algorithm can be established, which can analyze the complex dependencies in transaction data, predict transaction results, and thus effectively detect transaction anomalies. The transaction prediction model not only improves the accuracy of detection, but also reduces the reliance on manual rules, making anomaly detection more intelligent and efficient.
[0068] As an optional implementation method, obtaining a transaction data sample includes: obtaining an initial transaction data sample for a historical period, wherein the initial transaction data sample is generated when executing historical transaction behaviors within the historical period; performing consistency processing on the initial transaction data sample to obtain a processed initial transaction data sample, wherein the accuracy of the processed initial transaction data sample is higher than the accuracy of the processed initial transaction data sample; performing invalid value and missing value processing on the processed initial transaction data sample to obtain a transaction data sample.
[0069] In this embodiment, in the process of obtaining the transaction data sample, the initial transaction data sample of the historical period can be obtained. The initial transaction data sample can be processed for consistency to obtain the processed initial transaction data sample. The processed initial transaction data sample can be processed for invalid values and missing values to obtain the transaction data sample. The initial transaction data sample can be a transaction attribute big data sample. The transaction data sample can be a standard data result set.
[0070] Optionally, this optional implementation method of obtaining transaction data samples is intended to improve the accuracy and effectiveness of model training data through data preprocessing, thereby providing a more reliable basis for abnormal transaction detection.
[0071] Optionally, select one or more historical periods to extract data from the transaction records of the bank payment system to form an initial transaction data sample. These data samples should contain relevant transaction data generated when executing historical transaction behaviors. Ensure that the collected samples are representative, covering various types of transactions and normal and abnormal transaction behaviors, so that the model can learn comprehensive transaction characteristics and patterns. Check whether the data in the initial transaction data sample meets the preset business logic and data format requirements, for example, the transaction amount should not be negative, the account number format should be correct, and the transaction summary should be a non-empty string. Correct or mark the data that does not conform to the logic or format to ensure the consistency of all data in format. For example, replace the erroneous format account number with a special mark, and adjust the negative transaction amount to a value within a reasonable range. Through consistency processing, low-quality or erroneous data can be converted into a unified and easy-to-process form, improving the accuracy and reliability of the data set, thereby improving the performance of the subsequent transaction prediction model.
[0072] Optionally, invalid and missing value processing is performed on the processed initial transaction data sample. For invalid value processing, invalid values in the transaction data sample are identified and processed, such as empty strings, null, "NaN", etc. These values often do not provide valid information and may even interfere with model training. Invalid values are replaced with a predefined default value or filled by interpolation, prediction, etc. For missing value processing, missing values in the transaction data sample are processed, which may be caused by errors or omissions in the data collection process. There are many ways to process missing values, such as filling with the median, mean, mode, or using other relevant features for predictive filling. The specific method depends on the characteristics of the missing values and the characteristics of the data set.
[0073] Optionally, through the above processing, invalid values and missing values in the transaction data sample are effectively processed, which improves the integrity of the data and reduces the risk of model performance degradation due to data quality issues. Through the above steps, the obtained transaction data sample has higher accuracy and completeness, providing high-quality input for the training of the transaction prediction model based on the TAN algorithm, thereby ensuring that the model can more accurately learn the complex associations between transaction data and improve the accuracy and efficiency of transaction anomaly detection.
[0074] In the embodiment of the present application, the above process emphasizes the importance of data preprocessing, and the quality of data directly affects the performance of the model. By performing consistency processing and missing value processing on historical transaction data, the quality of the data set can be significantly improved, thereby improving the accuracy and reliability of the model. In actual applications, the data preprocessing step may need to be customized according to the specific business needs of the bank and the characteristics of the transaction data to achieve the desired effect.
[0075] As an optional implementation method, a transaction prediction model is established using transaction data samples and a tree-enhanced naive Bayes algorithm, including: using a tree-enhanced naive Bayes algorithm to analyze the transaction data samples to determine the conditional mutual information between the transaction data samples, wherein the conditional mutual information is used to represent the dependency relationship between the transaction data samples; constructing a tree model with the transaction data samples as nodes and the conditional mutual information as edges; and establishing a transaction prediction model based on the tree model.
[0076] In this embodiment, in the process of using transaction data samples and TAN algorithm to establish a transaction prediction model, TAN can be used to analyze the transaction data samples to determine the conditional mutual information between the transaction data samples. A tree model can be constructed with transaction data samples as nodes and conditional mutual information as edges. A transaction prediction model is established based on the tree model. Among them, conditional mutual information (CMI for short) is a statistic that measures the amount of information shared between two random variables given another random variable. Mathematically, conditional mutual information I(X; Y|Z) represents the expected value of the mutual information between random variables X and Y under the condition of a known random variable Z, reflecting the degree of mutual dependence between X and Y under the constraint of Z. In an embodiment of the present application, CMI can be used to represent the dependency relationship between transaction data samples.
[0077] Optionally, in this optional implementation method of using TAN to establish a transaction prediction model, by calculating the conditional mutual information between transaction data samples, a tree model is constructed to reflect the dependency relationship between features, and finally a transaction prediction model is established based on the tree model.
[0078] Optionally, conditional mutual information (CMI) is used in the TAN algorithm to measure the degree of dependence between two features (variables) given another variable. To calculate the CMI between each pair of features, statistical methods or estimation techniques, such as entropy-based methods, can be used. The calculated CMI value can be used to understand the mutual dependence between the various transaction data features. A high CMI value means that the two features still maintain a high level of information sharing given other features, indicating that there is a strong dependence or correlation between them.
[0079] Optionally, in the process of constructing a tree model with transaction data samples as nodes and conditional mutual information as edges, each feature in the processed transaction data sample is regarded as a node in the tree model. Using the calculated CMI value as the weight of the edge, a tree model is constructed, which connects all feature nodes and follows the characteristics of the tree structure: no loops and a minimum number of edges connecting all nodes. The TAN algorithm determines the connection mode of the edges through a maximum weighted spanning tree algorithm (such as the Chow-Liu algorithm) to reflect the dependencies between features. The construction of the tree model may include the optimization of the model structure to ensure a balance between the complexity of the model and the prediction performance. For example, the tree can be pruned to remove feature connections that have little impact on the prediction results, thereby simplifying the model structure and improving operating efficiency.
[0080] Optionally, in the process of building a transaction prediction model based on a tree model, the principle of a naive Bayes classifier can be used based on the constructed tree model, but on this basis, the dependencies between features are taken into account to calculate the conditional probabilities between features. This will be used to predict the probability of transaction results (success or failure) in new transaction data. Use the known transaction results (success or failure) in the transaction data sample to train the model parameters, that is, the probability of each feature appearing under different conditions. The training process may use techniques such as maximum likelihood estimation or Bayesian estimation. Once the model training is completed, new transaction data can be input into the model, and the conditional probabilities calculated by the model are used to predict the possible results of the new transaction. The prediction logic will include all the dependencies represented by the feature nodes and edges. After the model training is completed, the prediction performance of the model can be evaluated using an independent test data set, including indicators such as accuracy and recall. Based on the evaluation results, the model may need to be adjusted and optimized to improve its performance in abnormal transaction detection.
[0081] For example, based on the collected transaction data samples, the conditional mutual information (CMI), i.e. the degree of mutual dependence, between two attributes is calculated. (Because the sample data is constantly increasing, in order to ensure the accuracy of the model, the model should be re-established regularly using the latest samples):
[0082]
[0083] Among them, I(x i x j |y) can be used to represent CMI; x i and x j Represents two different attributes respectively.
[0084] In the embodiment of the present application, through the above steps, the transaction prediction model established by the TAN algorithm can more accurately capture the complex dependencies between transaction data features, thereby providing higher accuracy in predicting new transaction results, which is particularly important for detecting abnormal transaction behaviors. The TAN algorithm constructs a tree model that can reflect the dependencies between features, which is more adaptable to the complexity of transaction data and improves the efficiency and reliability of anomaly detection compared to the naive Bayes classifier of the related technology.
[0085] As an optional implementation method, the tree model satisfies the following conditions: in the tree model, the nodes corresponding to each transaction data sample are connected; in the tree model, the number of edges is the smallest; in the tree model, the sum of the edge lengths is the largest.
[0086] In this embodiment, the tree model can satisfy the following conditions: In the tree model, nodes corresponding to each transaction data sample can be connected. In the tree model, the number of edges is the smallest. In the tree model, the sum of the lengths of the edges is the largest.
[0087] Optionally, in the process of constructing a transaction prediction model using the tree-augmented naive Bayes algorithm (TAN), the design of the tree model needs to meet specific conditions to ensure its effectiveness and efficiency.
[0088] Optionally, in the tree model constructed by the TAN algorithm, the features of each transaction data sample are regarded as a node. For example, a transaction sample may contain features such as transaction-related information, which correspond to different nodes in the tree. The design of the tree model requires that all nodes are connected, which means that there should be no isolated nodes in the tree and each feature should be connected to other features in some way. This connectivity ensures that the model can comprehensively consider the role of all transaction features in prediction, not just isolated single features. Under the requirement of full connectivity, the number of edges of the tree model constructed by the TAN algorithm should be as small as possible. This is achieved by finding a minimum spanning tree. The minimum spanning tree refers to a tree structure connecting all nodes in a weighted undirected graph, with the sum of the weights of all its edges being the smallest. The construction of the minimum spanning tree reduces the redundancy of feature edges in the model and avoids too many meaningless edges, which helps to improve the interpretability and running efficiency of the model. In the complex network of transaction data, the minimum spanning tree can highlight the feature dependencies that have the greatest impact on the prediction results.
[0089] Optionally, in the TAN algorithm, the length (weight) of the edge is determined by the conditional mutual information (CMI) between the features of the transaction data sample. The larger the CMI value, the stronger the dependency between the two features. The constructed tree model should be a maximum weighted spanning tree, that is, a tree with the largest sum of the conditional mutual information (weights) of all edges. This ensures that the model can capture the most important dependencies in the transaction data, thereby providing higher accuracy and reliability when predicting transaction anomalies. The maximum weighted spanning tree connects all nodes while ensuring that the sum of the weights of the edges is maximized, that is, the dependencies between the features are maximized. This helps to improve the performance of the transaction prediction model, enabling it to more accurately identify potential abnormal patterns when processing complex transaction data.
[0090] In summary, the tree model constructed by the TAN algorithm not only connects all nodes in the transaction data sample, but also optimizes the model structure and reduces redundant edges through the construction of the minimum spanning tree and the maximum weighted spanning tree, while maximizing the sum of the edge weights (conditional mutual information), thereby ensuring that the model can effectively capture and utilize the most important feature dependencies in the transaction data when performing transaction abnormality early warning monitoring, improving the accuracy of prediction and the efficiency of system operation. This model design method is particularly important in complex and changeable bank payment transaction scenarios, and can better adapt to the dynamics and complexity of transaction data.
[0091] As an optional implementation method, the prediction result is probability information, wherein, step S202, using a transaction prediction model, predicts the transaction result corresponding to the transaction behavior to obtain a prediction result, including: inputting a transaction data set into the transaction prediction model, using the transaction prediction model to determine the dependency relationship, and based on the dependency relationship, constructing a tree model corresponding to the transaction data set; based on the tree model, determining probability information, wherein the probability information is used to indicate the probability of the transaction result being in a successful state or a failed state.
[0092] In this embodiment, in the process of using the transaction prediction model to predict the transaction result corresponding to the transaction behavior, the transaction data set can be input into the transaction prediction model, the transaction prediction model is used to determine the dependency relationship, and based on the dependency relationship, a tree model corresponding to the transaction data set is constructed. Based on the tree model, probability information is determined. Among them, the prediction result can be probability information. Probability information can be used to indicate the probability of the transaction result being in a successful state or a failed state, and in the embodiment of the present application, it can be simply referred to as probability.
[0093] Optionally, TAN is used to predict transaction results. The above optional implementation method describes in detail how to input the transaction data set into the model, use the model to determine the dependencies between features, build a specific tree model, and finally output the success or failure probability of the transaction result based on the model.
[0094] Optionally, the transaction dataset to be predicted is input into the trained transaction prediction model in a standard format. The dataset should contain the same features as when the model was trained. Ensure that the input transaction dataset matches the input format of the model. Data preprocessing, such as standardization, normalization, feature encoding, etc., may be required so that the model can correctly interpret and use the input data.
[0095] Optionally, the transaction prediction model is used to determine the dependencies, and based on the dependencies, a tree model corresponding to the transaction data set is constructed. The transaction prediction model is based on the TAN algorithm, and the dependencies between transaction data features have been determined through CMI calculation. During the prediction process, the model uses these pre-established dependencies to analyze the features in the transaction data set. For the input transaction data set, the model applies the previously constructed tree model structure, that is, the tree representation of the dependencies. Each node represents a transaction feature, and the edge represents the dependency between features. Through the tree model, the relationship between features can be analyzed more effectively and the accuracy of the prediction can be improved.
[0096] Optionally, probability information is determined based on a tree model. In the TAN model, the probability of success or failure of a transaction result is calculated based on the feature dependencies and conditional probabilities in the tree model. Based on the input transaction data, the model uses the conditional probabilities between features along the tree path to gradually calculate the probability of a transaction result being in a successful or failed state. The model outputs two probability values, representing the probability of a successful transaction and the probability of a failed transaction. The sum of these two probability values equals 1, which intuitively reflects the model's prediction and confidence in the transaction result. According to the set threshold, if the probability of a transaction failure exceeds the preset threshold, the model will mark the transaction as a possible anomaly, requiring further investigation or early warning measures. Conversely, if the probability of a successful transaction is high, the model considers the transaction normal.
[0097] In summary, the above optional implementation method utilizes the characteristics of the TAN algorithm, and determines the dependencies between features by constructing a tree model corresponding to the transaction data set. Based on these dependencies and conditional probabilities, the model can output the probability of success or failure of the transaction result, that is, probability information, which provides a quantitative decision-making basis for transaction anomaly warning. This method not only improves the accuracy of the prediction, but also provides the transaction monitoring system with real-time anomaly detection capabilities, which can provide timely warnings when anomalies occur in transactions, reducing potential losses and risks.
[0098] Optionally, the transaction attributes are passed into the classification model, and the probability of occurrence of the calculated result (success / failure) is calculated. The calculation formula for the probability (probability information) is as follows:
[0099]
[0100] Among them, x1~x n It is used to represent different transaction attributes, and n can be used to represent the number of transaction attributes.
[0101] As an optional implementation method, based on the tree model, determining probability information includes: in response to the probability information being success probability information and the success probability information exceeding the probability information threshold, determining that the transaction result is in a success state, or the success probability information does not exceed the probability information threshold, determining that the transaction result is in a failure state; in response to the probability information being failure probability information and the failure probability information exceeding the probability information threshold, determining that the transaction result is in a failure state, or the failure probability information threshold does not exceed the probability information threshold, determining that the transaction result is in a success state.
[0102] In this embodiment, in the process of determining the probability information based on the tree model, if the probability information is success probability information, and the success probability information exceeds the probability information threshold, it is determined that the transaction result is in a successful state. If the success probability information does not exceed the probability information threshold, it is determined that the transaction result is in a failed state. If the probability information is failure probability information, and the failure probability information exceeds the probability information threshold, it can be determined that the transaction result is in a failed state. If the failure probability information threshold does not exceed the probability information threshold, it can be determined that the transaction result is in a successful state.
[0103] Optionally, in the transaction prediction based on the tree model, the step of determining the transaction result is accomplished by analyzing the success and failure probability information and comparing them with a preset probability information threshold.
[0104] Optionally, in response to the probability information being success probability information, and the success probability information exceeding the probability information threshold, it is determined that the transaction result is in a successful state. The transaction prediction model calculates the probability information of a successful transaction through the conditional probability in the tree model based on the input transaction data set. The calculated success probability information is compared with the preset probability information threshold. The threshold can be set based on historical data and business needs, usually in the range of 50%-100%, and the specific value depends on the tolerance for false positives and false negatives. If the success probability information exceeds the probability information threshold, the model marks the transaction as being in a successful state, that is, the model believes that the transaction is normal, without abnormalities, and can be completed as expected.
[0105] Optionally, in response to the probability information being failure probability information, and the failure probability information exceeding the probability information threshold, it is determined that the transaction result is in a failed state. Similarly, the model can also calculate the probability information of transaction failure, that is, the probability of an abnormal transaction. Compare the failure probability information with a preset threshold. Similar to the threshold setting of the success probability, the failure probability threshold is usually set lower to reduce the possibility of missing abnormal transactions. If the failure probability information exceeds the preset threshold, the model marks the transaction as being in a failed state, that is, the transaction may be abnormal and further investigation or early warning measures are required.
[0106] Optionally, if the success / failure probability information does not exceed the probability information threshold, it is determined that the transaction result is in the opposite state. If the success probability information does not exceed the preset threshold, or the failure probability information does not exceed the preset threshold, this means that the model's confidence in the transaction state is not high enough, which may be due to the large difference between the feature value of the input data and the data distribution during model training, or other uncertain factors. In the case where the success probability information does not reach the threshold, the model will assume that the transaction result is in a failed state, and if the failure probability information does not reach the threshold, the transaction result is assumed to be a successful state. This processing method is based on the assumption that when the model confidence is insufficient, a more conservative strategy is adopted, tending to mark transactions as possibly abnormal or normal to reduce false positives and false negatives.
[0107] In the embodiment of the present application, the above steps ensure that the transaction prediction model based on the TAN algorithm can automatically judge and mark the transaction results according to the probability information and the preset threshold, thereby realizing automated and efficient abnormal warning in bank payment transaction monitoring. By adjusting the probability information threshold, the sensitivity and accuracy of the warning can be balanced to adapt to different business scenarios and risk control needs.
[0108] It is worth noting that the setting of the above thresholds needs to be optimized according to the actual business situation and model performance. Too high or too low thresholds may lead to a decrease in the efficiency and accuracy of the early warning mechanism. In practical applications, it may be necessary to find a suitable threshold through repeated testing and adjustment to ensure the timeliness and accuracy of transaction abnormality warnings. For example, set a prediction result threshold (50%-100%). If the success / failure probability exceeds the set threshold, the prediction result will be recorded as success / failure. Otherwise, the current transaction will not be processed.
[0109] As an optional implementation manner, step S203, based on the prediction result, detects the transaction behavior to obtain a detection result, including: in response to the prediction result being different from the actual result, determining that the detection result is that the transaction behavior is in an abnormal state; in response to the prediction result being the same as the actual result, determining that the detection result is that the transaction behavior is in a normal state; the method also includes: in response to the detection result being that the transaction behavior is in an abnormal state, processing the abnormal state to restore the transaction behavior to a normal state.
[0110] In this embodiment, if the transaction behavior is successfully detected based on the prediction result, if the prediction result is different from the actual result, it can be said that the detection result is that the transaction behavior is in an abnormal state. On the contrary, if the prediction result is the same as the actual result, it can be said that the detection result is that the transaction behavior is in a normal state. If the detection result is that the transaction behavior is in an abnormal state, the abnormal state can be processed to make the transaction behavior in a normal state.
[0111] Optionally, in the TAN-based transaction abnormality early warning monitoring method, detecting the transaction behavior based on the prediction result and obtaining the detection result is one of the key steps.
[0112] Optionally, based on the input transaction data, the predicted transaction results (probability of success or failure) are output and compared with the actual transaction results. If the predicted results do not match the actual transaction results, for example, the model predicts that the transaction will fail, but the actual transaction is successful, or the model predicts that the transaction will be successful, but the actual transaction fails, this indicates that an abnormality may have occurred in the system. In the context of transaction monitoring, such a difference usually indicates that there are potential risks or errors in the transaction. When the predicted results are consistent with the actual transaction results, that is, the model's prediction is consistent with the actual occurrence of the transaction, this usually indicates that the transaction behavior is in a normal state and no unexpected abnormalities or errors have occurred.
[0113] Optionally, once the model detects that the transaction behavior is in an abnormal state, that is, the predicted result is inconsistent with the actual result, the monitoring system will initiate the exception handling process. This may include but is not limited to: immediately suspending the transaction, initiating manual review, restarting or repairing the system, adjusting monitoring parameters, etc. The specific measures depend on the type and severity of the exception. The purpose of the exception handling process is to minimize the risks brought by transaction anomalies, such as preventing capital loss, maintaining trust between the two parties in the transaction, and ensuring the stable operation of the system. This may require coordination between multiple departments or systems related to the transaction to quickly identify and respond to abnormal situations. After handling the exception, the monitoring system should conduct subsequent follow-up and analysis to determine the root cause of the exception and evaluate the effectiveness of the exception handling measures. This helps to optimize the model and monitoring mechanism and reduce the occurrence of abnormal situations in the future.
[0114] In summary, in the transaction anomaly early warning monitoring method based on the TAN algorithm, by comparing the predicted results with the actual transaction results, it is possible to automatically determine whether the transaction behavior is in an abnormal state. When an anomaly is detected, the system will take a series of measures to restore the normal state of the transaction, and at the same time conduct a detailed analysis of the anomaly to continuously optimize the transaction monitoring system. This closed-loop detection and response mechanism is essential to ensure the security and reliability of the bank payment system, especially when dealing with large and complex transaction data, to detect and correct anomalies in a timely manner, and reduce potential monitoring impacts and economic losses.
[0115] In an embodiment of the present application, if it is necessary to detect whether a transaction behavior is in an abnormal state, a transaction data set corresponding to the transaction behavior to be detected can be obtained. The transaction prediction model can be used to analyze the dependencies between the transaction data in the transaction data set to predict whether the transaction result is a success state or a failure state. Thus, the transaction behavior can be detected based on the prediction result to obtain the detection result. In this embodiment, the problem of low accuracy in detecting abnormal transaction behaviors is effectively solved through deep dependency analysis, probability prediction, dynamic threshold adjustment, real-time feedback, abnormal follow-up processing and automatic learning strategy. These methods not only improve the real-time and accuracy of detection, but also enhance the adaptability and self-optimization capabilities of the system, providing financial institutions with more reliable and efficient means of transaction monitoring. The technical problem of low accuracy in detecting abnormal transaction behaviors in the related technology is solved, and the technical effect of improving the accuracy of detecting abnormal transaction behaviors is achieved.
[0116] The technical solution of the embodiment of the present application is illustrated below in conjunction with preferred implementation modes.
[0117] At present, when a bank payment system or a bank conducts a payment transaction, it is possible that anomalies in hardware, software, or network may lead to transaction failure, slowness, loss, account inconsistency, and other abnormalities. Currently, early warning can be provided by configuring monitoring based on expert rules.
[0118] However, the following problems still exist in the related technologies: monitoring based on experience configuration cannot fully cover newly added abnormal types; if there are many transaction branches, many customers, and complex logic, comprehensive monitoring needs to be configured, which requires a lot of labor cost investment; the current monitoring configuration needs to be adjusted in time with the adjustment and addition of transaction logic, and the scalability is poor. Therefore, there is still a technical problem of low accuracy in abnormal detection of transaction behavior in the related technologies.
[0119] In order to solve the above technical problems, the embodiment of the present application proposes a transaction anomaly early warning monitoring method based on the TAN algorithm. One part of the content is to verify the basic information based on external data, and the second part is to verify the correct data of the existing system based on the artificial intelligence algorithm. The third part is for actual use. The system can automatically predict the results of bank payment transactions, and judge whether the system has abnormalities by comparing with the actual payment results, which improves the accuracy of abnormal monitoring and reduces the cost of manual maintenance monitoring. The technical problem of low accuracy of abnormal detection of transaction behavior in related technologies is solved, and the technical effect of improving the accuracy of abnormal detection of transaction behavior is achieved.
[0120] Figure 3 is a flowchart of a transaction abnormality early warning monitoring method based on a tree enhanced naive Bayes algorithm provided in an embodiment of the present application, such as Figure 3 As shown, the method may include the following steps:
[0121] Step S301, input transaction attribute big data sample.
[0122] In this embodiment, big data samples of core transaction elements related to bank payment transactions are collected.
[0123] Step S302: Perform consistency check.
[0124] In this embodiment, the transaction elements are checked for consistency, and those that are illogical, out of the normal range, or contradictory, which can be discovered by the transaction itself, are replaced with a unified value of failure.
[0125] Step S303, perform invalid value and missing value processing.
[0126] In this embodiment, invalid values and missing values of transaction elements, such as "", null, and space, are uniformly processed as default values.
[0127] Step S304, outputting a standard data result set.
[0128] In this embodiment, after the above consistency check, invalid value and missing value processing, a standard data result set for the model to be established, that is, a data sample, can be obtained.
[0129] Step S305, calculating the CMI between transaction attributes according to the samples.
[0130] In this embodiment, based on the collected transaction data samples, the conditional mutual information CMI between two attributes, that is, the degree of mutual dependence, is calculated. (Because the sample data is constantly increasing, in order to ensure the accuracy of the model, the model should be re-established regularly using the latest samples):
[0131]
[0132] Among them, I(x i x j |y) can be used to represent CMI; x i and x j Represents two different attributes respectively.
[0133] Step S306: draw a maximum weighted spanning tree.
[0134] In this embodiment, a tree graph is formed with each attribute as a node and CMI as an edge, and the maximum weighted spanning tree of this graph is found according to the following rules: being able to connect all nodes, using the least number of edges, and having the maximum sum of edge lengths (CMI).
[0135] Optionally, the node connection relationship is set to be directed, that is, from the parent node to the child node. The first attribute can be set as the root node, and the root node determines the direction of the edge.
[0136] Step S307, obtaining a transaction result probability formula.
[0137] In this embodiment, a new transaction is added, and the transaction attributes are passed into the classification model, and the probability of occurrence of the calculated result (success / failure) is calculated as follows:
[0138]
[0139] Among them, x1~x n It is used to represent different transaction attributes, and n can be used to represent the number of transaction attributes.
[0140] Optionally, a prediction result threshold (50%-100%) is set. If the success / failure probability exceeds the set threshold, the prediction result is recorded as success / failure, otherwise the current transaction is not processed.
[0141] Step S308, setting up a post-warning processing mechanism.
[0142] In this embodiment, a subsequent early warning mechanism is set up to provide personalized early warnings for major customers, key transactions, regions, transaction volumes, and other dimensions.
[0143] Step S309, adding a new transaction input.
[0144] In this embodiment, after a new transaction is added, data cleaning is performed first.
[0145] Step S310: The model calculates the result probability. If the probability exceeds a threshold, it is recorded as a prediction result.
[0146] In this embodiment, the cleaned standard data is imported into the model to obtain the prediction result of the current transaction.
[0147] Step S311, comparing the predicted result with the actual result.
[0148] In this embodiment, the predicted result is compared with the actual transaction result. If they are consistent, step S313 is executed; if they are inconsistent, step S312 is executed.
[0149] Step S312, executing the subsequent processing mechanism.
[0150] In this embodiment, the predicted result is compared with the actual transaction result, and if there is any inconsistency, it is processed according to the subsequent processing mechanism of the personalized setting.
[0151] Step S313, end.
[0152] In this embodiment, the predicted result is compared with the actual transaction result, and if they are consistent, the process is skipped.
[0153] In an embodiment of the present application, a transaction anomaly early warning monitoring method based on the TAN algorithm is provided, which can automatically predict the results of bank payment transactions through the system, and determine whether the system has an abnormality by comparing it with the actual payment results, thereby improving the accuracy of abnormality monitoring and reducing the cost of manual maintenance monitoring.
[0154] It should be noted that the steps shown in the flowcharts of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and that, although a logical order is shown in the flowcharts, in some cases, the steps shown or described can be executed in an order different from that shown here.
[0155] Example 2
[0156] The embodiment of the present application also provides a transaction behavior anomaly detection device. It should be noted that the transaction behavior anomaly detection device of the embodiment of the present application can be used to execute the transaction behavior anomaly detection method provided in the embodiment of the present application. The transaction behavior anomaly detection device provided in the embodiment of the present application is introduced below.
[0157] According to an embodiment of the present application, a device for implementing the above-mentioned transaction behavior anomaly detection method is also provided. Figure 4 is a schematic diagram of an abnormality detection device for transaction behavior provided in an embodiment of the present application, such as Figure 4 As shown, the transaction behavior anomaly detection device 400 includes: an acquisition unit 402, a prediction unit 404 and a detection unit 406.
[0158] The acquisition unit 402 is used to acquire a transaction data set corresponding to the transaction behavior to be detected for anomalies, wherein the transaction data set includes transaction data of different dimensions generated when the transaction behavior is executed.
[0159] The prediction unit 404 is used to use the transaction prediction model to predict the transaction result corresponding to the transaction behavior to obtain a prediction result, wherein the prediction result is used to indicate whether the transaction result corresponding to the transaction behavior is in a success state or a failure state, wherein the transaction prediction model is used to analyze the dependency relationship between different transaction data in the transaction data set.
[0160] The detection unit 406 is used to detect the transaction behavior based on the prediction result to obtain a detection result, wherein the detection result is used to indicate whether the transaction behavior is in an abnormal state or a normal state.
[0161] The abnormality detection device for transaction behavior provided in the embodiment of the present application obtains a transaction data set corresponding to the transaction behavior to be abnormally detected by the acquisition unit 402, wherein the transaction data set includes transaction data of different dimensions generated when executing the transaction behavior; the transaction result corresponding to the transaction behavior is predicted by the prediction unit 404 using the transaction prediction model to obtain a prediction result, wherein the prediction result is used to indicate that the transaction result corresponding to the transaction behavior is in a successful state or a failed state, wherein the transaction prediction model is used to analyze the dependency relationship between different transaction data in the transaction data set; the transaction behavior is detected by the detection unit 406 based on the prediction result to obtain a detection result, wherein the detection result is used to indicate that the transaction behavior is in an abnormal state or a normal state, thereby solving the technical problem of low accuracy of abnormality detection of transaction behavior in the related art. Thus, the technical effect of improving the accuracy of abnormality detection of transaction behavior is achieved.
[0162] It should be noted that the acquisition unit 402, prediction unit 404 and detection unit 406 correspond to steps S201 to S203 in Example 1, and the three modules and corresponding steps implement the same examples and application scenarios, but are not limited to the contents disclosed in the above-mentioned Example 1. It should be noted that the above-mentioned modules or units may be hardware components or software components stored in a memory (e.g., memory 104) and processed by one or more processors (e.g., processors 102a, 102b, ..., 102n), and the above-mentioned modules may also be part of the device and may be run in the computer terminal 10 provided in Example 1.
[0163] Example 3
[0164] An embodiment of the present application may provide an electronic device, Figure 5 is a structural block diagram of an electronic device according to an embodiment of the present application. Figure 5 As shown, the electronic device may include: one or more ( Figure 5(only one is shown) processor 502, memory 504, storage controller, and peripheral interface, wherein the peripheral interface is connected to the radio frequency module, audio module and display.
[0165] Among them, the memory can be used to store software programs and modules, such as program instructions / modules corresponding to the methods and devices in the embodiments of the present application, and the processor executes various functional applications and data processing by running the software programs and modules stored in the memory, that is, realizing the above-mentioned method. The memory may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory may further include a memory remotely arranged relative to the processor, and these remote memories may be connected to the terminal via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0166] The processor can call the information and application stored in the memory through the transmission device to perform the following steps: obtain a transaction data set corresponding to the transaction behavior to be detected for abnormality, wherein the transaction data set includes transaction data of different dimensions generated when the transaction behavior is executed; use a transaction prediction model to predict the transaction result corresponding to the transaction behavior to obtain a prediction result, wherein the prediction result is used to indicate that the transaction result corresponding to the transaction behavior is in a success state or a failure state, and the transaction prediction model is used to analyze the dependency between different transaction data in the transaction data set; based on the prediction result, detect the transaction behavior to obtain a detection result, wherein the detection result is used to indicate that the transaction behavior is in an abnormal state or a normal state.
[0167] The processor can also call the information and application programs stored in the memory through the transmission device to perform the following steps: obtain transaction data samples, and use the transaction data samples to adopt a tree-enhanced naive Bayes algorithm to establish a transaction prediction model.
[0168] The processor can also call the information and application programs stored in the memory through the transmission device to perform the following steps: obtain an initial transaction data sample for a historical period, wherein the initial transaction data sample is generated when historical transaction behaviors are executed within the historical period; perform consistency processing on the initial transaction data sample to obtain a processed initial transaction data sample, wherein the accuracy of the processed initial transaction data sample is higher than the accuracy of the processed initial transaction data sample; perform invalid value and missing value processing on the processed initial transaction data sample to obtain a transaction data sample.
[0169] The processor can also call the information and application programs stored in the memory through the transmission device to perform the following steps: use the tree-enhanced naive Bayes algorithm to analyze the transaction data samples to determine the conditional mutual information between the transaction data samples, wherein the conditional mutual information is used to represent the dependency relationship between the transaction data samples; construct a tree model with the transaction data samples as nodes and the conditional mutual information as edges; and establish a transaction prediction model based on the tree model.
[0170] The processor can also call the information and application programs stored in the memory through the transmission device to perform the following steps: input the transaction data set into the transaction prediction model, use the transaction prediction model to determine the dependency relationship, and build a tree model corresponding to the transaction data set based on the dependency relationship; based on the tree model, determine the probability information, wherein the probability information is used to indicate the probability of the transaction result being in a successful state or a failed state.
[0171] The processor can also call the information and application stored in the memory through the transmission device to perform the following steps: in response to the probability information being success probability information and the success probability information exceeding the probability information threshold, determining that the transaction result is in a success state, or the success probability information does not exceed the probability information threshold, determining that the transaction result is in a failure state; in response to the probability information being failure probability information and the failure probability information exceeds the probability information threshold, determining that the transaction result is in a failure state, or the failure probability information threshold does not exceed the probability information threshold, determining that the transaction result is in a success state.
[0172] The processor can also call the information and application stored in the memory through the transmission device to perform the following steps: in response to the prediction result being different from the actual result, determining that the detection result is that the transaction behavior is in an abnormal state; in response to the prediction result being the same as the actual result, determining that the detection result is that the transaction behavior is in a normal state; in response to the detection result being that the transaction behavior is in an abnormal state, processing the abnormal state to restore the transaction behavior to a normal state.
[0173] By using the embodiment of the present application, if it is necessary to detect whether the transaction behavior is in an abnormal state, the transaction data set corresponding to the transaction behavior to be detected can be obtained. The transaction prediction model can be used to analyze the dependencies between the transaction data in the transaction data set to predict whether the transaction result is a success state or a failure state. Thus, the transaction behavior can be detected based on the prediction result to obtain the detection result. In this embodiment, the problem of low accuracy of abnormal detection of transaction behavior is effectively solved through deep dependency analysis, probability prediction, dynamic threshold adjustment, real-time feedback, abnormal follow-up processing and automatic learning strategy. These methods not only improve the real-time and accuracy of detection, but also enhance the adaptability and self-optimization ability of the system, providing financial institutions with more reliable and efficient transaction monitoring means. The technical problem of low accuracy of abnormal detection of transaction behavior in the related technology is solved, and the technical effect of improving the accuracy of abnormal detection of transaction behavior is achieved.
[0174] It can be understood by those skilled in the art that Figure 5 The structure shown is for illustration only, and the electronic device may also be a smart phone (such as an Android phone, an iOS phone, etc.), a tablet computer, a PDA, a mobile Internet device (Mobile Internet Devices, MID), a PAD, or other terminal devices. Figure 5 The structure of the electronic device is not limited. Figure 5 More or fewer components (such as network interfaces, display devices, etc.) shown in, or having Figure 5 Different configurations are shown.
[0175] A person of ordinary skill in the art can understand that all or part of the steps in the various methods of the above embodiments can be completed by instructing the hardware related to the terminal device through a program, and the program can be stored in a computer-readable storage medium, and the storage medium may include: a flash drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, etc.
[0176] Example 4
[0177] The embodiment of the present application further provides a storage medium. Optionally, in this embodiment, the storage medium can be used to store the program code executed by the transaction behavior anomaly detection method provided in the first embodiment.
[0178] Optionally, in this embodiment, the above storage medium may be located in any computer terminal in a computer terminal group in a computer network, or in any mobile terminal in a mobile terminal group.
[0179] The present application also provides a computer program product, which, when executed on a data processing device, is suitable for executing the program steps of the method for detecting anomalies in transaction behavior.
[0180] The serial numbers of the above-mentioned embodiments of the present application are for description only and do not represent the advantages or disadvantages of the embodiments.
[0181] In the above embodiments of the present application, the description of each embodiment has its own emphasis. For parts that are not described in detail in a certain embodiment, please refer to the relevant description of other embodiments.
[0182] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are only schematic. For example, the division of the units is only a logical function division. There may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of units or modules, which can be electrical or other forms.
[0183] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0184] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of software functional units.
[0185] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions to enable a computer device (which can be a personal computer, a server or a network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: U disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), mobile hard disk, disk or optical disk and other media that can store program codes.
[0186] The above is only a preferred implementation of the present application. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present application. These improvements and modifications should also be regarded as the scope of protection of the present application.
Claims
1. A method for detecting anomalies in transaction behavior, characterized in that: include: Acquire a transaction data set corresponding to the transaction behavior to be detected for anomaly, wherein the transaction data set includes transaction data of different dimensions generated when the transaction behavior is executed; Using a transaction prediction model, predicting the transaction result corresponding to the transaction behavior to obtain a prediction result, wherein the prediction result is used to indicate whether the transaction result corresponding to the transaction behavior is in a success state or a failure state, and the transaction prediction model is used to analyze the dependency relationship between different transaction data in the transaction data set; Based on the prediction result, the transaction behavior is detected to obtain a detection result, wherein the detection result is used to indicate whether the transaction behavior is in an abnormal state or a normal state.
2. The method according to claim 1, characterized in that The method further comprises: Acquire transaction data samples, and use the transaction data samples to establish the transaction prediction model using a tree-enhanced naive Bayes algorithm.
3. The method according to claim 2, characterized in that Get a sample of transaction data, including: Acquire an initial transaction data sample of a historical period, wherein the initial transaction data sample is generated when a historical transaction behavior is executed within the historical period; Performing consistency processing on the initial transaction data sample to obtain a processed initial transaction data sample, wherein the accuracy of the processed initial transaction data sample is higher than the accuracy of the processed initial transaction data sample; Invalid values and missing values are processed on the processed initial transaction data sample to obtain the transaction data sample.
4. The method according to claim 2, characterized in that: Using the transaction data sample and adopting the tree-enhanced naive Bayes algorithm, the transaction prediction model is established, including: The transaction data samples are analyzed using the tree enhanced naive Bayes algorithm to determine conditional mutual information between the transaction data samples, wherein the conditional mutual information is used to represent the dependency relationship between the transaction data samples; Constructing a tree model with the transaction data samples as nodes and the conditional mutual information as edges; Based on the tree model, the transaction prediction model is established.
5. The method according to claim 4, characterized in that The tree model meets the following conditions: In the tree model, connecting the nodes corresponding to the transaction data samples; In the tree model, the number of edges is minimal; In the tree model, the sum of the lengths of the edges is the largest.
6. The method according to claim 1, characterized in that The prediction result is probability information, wherein the transaction result corresponding to the transaction behavior is predicted using a transaction prediction model to obtain a prediction result, including: Inputting the transaction data set into the transaction prediction model, determining the dependency relationship using the transaction prediction model, and constructing a tree model corresponding to the transaction data set based on the dependency relationship; Based on the tree model, the probability information is determined, wherein the probability information is used to indicate the probability of the transaction result being in the success state or the failure state.
7. The method according to claim 6, characterized in that Determining the probability information based on the tree model includes: In response to the probability information being success probability information and the success probability information exceeding a probability information threshold, determining that the transaction result is in the success state, or the success probability information not exceeding the probability information threshold, determining that the transaction result is in the failure state; In response to the probability information being failure probability information and the failure probability information exceeding the probability information threshold, it is determined that the transaction result is in the failure state, or the failure probability information threshold does not exceed the probability information threshold, it is determined that the transaction result is in the success state.
8. The method according to claim 7, characterized in that Based on the prediction result, the transaction behavior is detected to obtain a detection result, including: In response to the prediction result being different from the actual result, determining that the detection result is that the transaction behavior is in the abnormal state; In response to the prediction result being the same as the actual result, determining that the detection result is that the transaction behavior is in the normal state; The method further includes: in response to the detection result that the transaction behavior is in the abnormal state, processing the abnormal state to make the transaction behavior in the normal state.
9. A transaction behavior anomaly detection device, characterized in that: include: An acquisition unit, configured to acquire a transaction data set corresponding to the transaction behavior to be detected for abnormality, wherein the transaction data set includes transaction data of different dimensions generated when the transaction behavior is executed; A prediction unit, used to predict the transaction result corresponding to the transaction behavior by using a transaction prediction model to obtain a prediction result, wherein the prediction result is used to indicate whether the transaction result corresponding to the transaction behavior is in a success state or a failure state, wherein the transaction prediction model is used to analyze the dependency relationship between different transaction data in the transaction data set; A detection unit is used to detect the transaction behavior based on the prediction result to obtain a detection result, wherein the detection result is used to indicate whether the transaction behavior is in an abnormal state or a normal state.
10. A processor, characterized in that: The processor is used to run a program, wherein the program, when run by the processor, executes the method for detecting anomalies in transaction behaviors as described in any one of claims 1 to 8.