Abnormal node detection method and device and electronic equipment

By combining the evaluation system of structural similarity and semantic similarity, the introduction of knowledge transfer and residual graph encoder methods is solved, and the problem of low detection accuracy of abnormal nodes in limited supervision scenarios is achieved, achieving more efficient and accurate abnormal detection effects.

CN119961823APending Publication Date: 2025-05-09WEBANK (CHINA) +1
View PDF 0 Cites 3 Cited by

Patent Information

Application Number
CN202510022406.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-07
Publication Date
2025-05-09

AI Technical Summary

Technical Problem

The existing technology has the problem of low accuracy in abnormal node detection in limited supervision scenarios, especially in the fields of financial fraud detection and network security monitoring. Labeled data are scarce and of different quality, resulting in poor detection results.

Method used

Through a dual-track evaluation system that integrates structural similarity and semantic similarity, a reference data set similar to the target data set is selected, a knowledge transfer mechanism is introduced, and a reference data set with rich labels is used to enhance model training on the target data set with limited labels. At the same time, the residual graph encoder is used to perform multi-hop residual learning on the graph neural network, capture the multi-hop affinity mode, and dynamically learn and predict the degree of anomalies of nodes through the context attention anomaly scoring module.

Benefits of technology

It improves the accuracy and robustness of abnormal detection, can effectively identify abnormal nodes when tags are scarce, and improves the detection effect in areas such as financial fraud detection and network security monitoring.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119961823A_ABST
    Figure CN119961823A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses an abnormal node detection method and device and electronic equipment, and the method comprises the steps: constructing a transaction data set according to a user transaction record in a database; obtaining a reference data set matched with the transaction data set based on the structural similarity and the semantic similarity; performing feature splicing on the transaction data set and the reference data set to obtain a target training matrix; performing residual learning on the graph neural network according to the target training matrix to obtain a node embedding matrix; performing anomaly scoring on the node embedding matrix based on context attention to obtain an anomaly classification result of the nodes; according to the method, a small number of normal samples are utilized to dynamically learn and predict the abnormal degree of other nodes in the reasoning stage, so that efficient anomaly detection is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of data monitoring technology; specifically, to an abnormal node detection method, device and electronic equipment. Background Art

[0002] With the rapid development of the global financial market and the widespread application of Internet technology, abnormal financial activities have become increasingly covert and complex, threatening not only the stability of the financial system, but also posing a serious threat to the social and economic order.

[0003] In order to meet the challenge of abnormal activities, existing technologies attempt to improve the accuracy of anomaly detection by constructing risk control knowledge graphs, combining depth-first search and manual rules. This method uses historical transaction data to generate risk control knowledge graphs, and performs depth-first search through node and path features in the graph to automatically generate new risk control rules. However, this method relies on manually constructed rules and is difficult to achieve cross-domain knowledge transfer. At the same time, although time series feature extraction models and heterogeneous graph neural network methods are used to improve the accuracy of abnormal activity recognition, these methods still face the problem of poor detection results in limited supervision environments. They require sufficient labeled data for model training. In actual application scenarios, labeled data is often scarce and of varying quality, which limits the broad accuracy of traditional methods.

[0004] It can be seen that the relevant technology has the problem of low accuracy in abnormal node detection under limited supervision scenarios. Summary of the invention

[0005] To solve the above technical problems, the embodiments of the present application provide a method, device and electronic device for detecting abnormal nodes, which solve the problem of low accuracy of abnormal node detection in limited supervision scenarios in related technologies.

[0006] According to one aspect of an embodiment of the present application, a method for detecting abnormal nodes is provided, the method comprising: constructing a transaction data set based on user transaction records in a database; acquiring a reference data set matching the transaction data set based on structural similarity and semantic similarity; performing feature concatenation on the transaction data set and the reference data set to obtain a target training matrix; performing residual learning on a graph neural network based on the target training matrix to obtain a node embedding matrix; and performing abnormal scoring on the node embedding matrix based on contextual attention to obtain an abnormal classification result of the node.

[0007] Optionally, obtaining a reference data set matching the transaction data set based on structural similarity and semantic similarity includes: obtaining the degree values ​​of all nodes in the transaction data set and all candidate reference data sets; obtaining the degree value distribution corresponding to each data set based on the frequency of occurrence of each degree value; calculating the first structural similarity between the transaction data set and each candidate reference data set based on the degree value distribution corresponding to each data set; obtaining a candidate data set that is structurally similar to the transaction data set based on the first structural similarity; and performing semantic analysis on the node information in each candidate data set to obtain a parameter data set matching the transaction data set.

[0008] Optionally, based on the first structural similarity, obtaining and acquiring a candidate data set that is structurally similar to the transaction data set includes: obtaining all connected components in the transaction data set and all candidate reference data sets; obtaining a connected component size distribution corresponding to each data set based on the number of nodes in each connected component; calculating a second structural similarity between the transaction data set and each candidate reference data set based on the connected component size distribution corresponding to each data set; and acquiring a candidate data set that is structurally similar to the transaction data set based on the first structural similarity and the second structural similarity.

[0009] Optionally, feature concatenation is performed on the transaction data set and the reference data set to obtain a target training matrix, including: converting the transaction data set and the reference data set into feature matrices respectively; performing feature projection on different feature matrices to obtain feature vectors of multiple preset dimensions; sorting features according to a smoothing parameter of each feature vector; and concatenating the sorted target matrix and the reference matrix to obtain a target training matrix.

[0010] Optionally, the smoothing parameter calculation expression for each eigenvector is:

[0011]

[0012] Among them, s k represents the smoothing parameter of the kth feature, E is the edge set of the graph, and x ik and x jk They are node v i and v j The value of the kth feature.

[0013] Optionally, when residual learning is performed on the graph neural network according to the target training matrix, a node embedding matrix is ​​obtained, including: performing multi-hop propagation on the target training matrix to obtain a feature matrix after propagation; performing a shared transformation on the target training matrix and the feature matrix after propagation to obtain a feature fusion matrix; obtaining a residual matrix after the current iteration by calculating the difference between the current feature fusion matrix and the feature fusion matrix after the previous iteration; and aggregating the residual matrices after all iterations to obtain a node embedding matrix.

[0014] Optionally, the node embedding matrix is ​​scored for abnormality based on contextual attention to obtain an abnormal classification result of the node, including: dividing the node embedding matrix into a context node embedding matrix and a query node embedding matrix; fusing the context node embedding matrix into the query node embedding matrix to generate a reconstructed embedding of the query node; obtaining a drift distance between an original embedding representation and a reconstructed embedding representation of the query node according to the query node embedding matrix; and obtaining an abnormal classification result of the node according to the drift distance.

[0015] Optionally, the context node embedding matrix is ​​fused into the query node embedding matrix to generate a reconstructed embedding of the query node, including: linearly transforming the context node embedding matrix and the query node embedding matrix according to a weight matrix to generate a query matrix and a key matrix; generating an attention weight matrix by calculating the dot product between the query matrix and the key matrix; and generating a reconstructed embedding of the query node through the attention weight matrix and the context node embedding matrix.

[0016] According to one aspect of an embodiment of the present application, an abnormal node detection device is provided, the device comprising: a transaction data set construction module, used to construct a transaction data set according to user transaction records in a database; a reference data set acquisition module, used to acquire a reference data set matching the transaction data set based on structural similarity and semantic similarity; a feature splicing module, used to perform feature splicing on the transaction data set and the reference data set to obtain a target training matrix; a residual learning module, used to perform residual learning on a graph neural network according to the target training matrix to obtain a node embedding matrix; an anomaly scoring module, used to perform anomaly scoring on the node embedding matrix based on contextual attention to obtain an abnormal classification result of the node.

[0017] According to one aspect of an embodiment of the present application, a computer-readable medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the abnormal node detection method in the above technical solution is implemented.

[0018] According to one aspect of an embodiment of the present application, an electronic device is provided, comprising: a processor; and a memory for storing executable instructions of the processor; wherein the processor is configured to execute the executable instructions so that the electronic device implements the abnormal node detection method in the above technical solution.

[0019] According to one aspect of an embodiment of the present application, a computer program product is provided, including a computer program, and when the computer program is executed by a processor, the abnormal node detection method in the above technical solution is implemented.

[0020] The technical solution provided by this application includes at least the following beneficial effects:

[0021] This application uses a dual-track evaluation system of integrated structural similarity and semantic similarity to select a reference data set that is similar to the target data set, aiming to enhance the model training on the target data set with limited labels by introducing a knowledge transfer mechanism and utilizing a reference data set with rich labels, thereby improving the accuracy and robustness of anomaly detection. Furthermore, by performing residual learning on the graph neural network using a matrix obtained by feature concatenating the transaction data set and the reference data set, multi-hop affinity patterns can be captured, providing rich and comprehensive information, thereby improving the accuracy of anomaly detection. In addition, this application utilizes a small number of normal samples to dynamically learn and predict the degree of abnormality of other nodes in the reasoning stage, thereby achieving efficient anomaly detection. BRIEF DESCRIPTION OF THE DRAWINGS

[0022] The drawings herein are incorporated into the specification and constitute a part of the specification, showing embodiments consistent with the present application, and together with the specification, are used to explain the principles of the present application. Obviously, the drawings described below are only some embodiments of the present application, and for those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative work. In the drawings:

[0023] Figure 1 The figure is a flow chart of an abnormal node detection method provided in an embodiment of the present application;

[0024] Figure 2 The figure is a schematic diagram of the structure of a transaction data set provided in an embodiment of the present application;

[0025] Figure 3 Shown Figure 1 An exemplary flow chart of step S30 in FIG.

[0026] Figure 4 Shown Figure 1 An exemplary flow chart of step S40 in FIG.

[0027] Figure 5Shown Figure 1 An exemplary flow chart of step S50 in FIG.

[0028] Figure 6 The figure is a schematic diagram of the structure of an abnormal node detection device provided in an embodiment of the present application;

[0029] Figure 7 A schematic diagram of the structure of a computer system suitable for implementing an electronic device of an embodiment of the present application is shown. DETAILED DESCRIPTION

[0030] Here, exemplary embodiments will be described in detail, examples of which are shown in the accompanying drawings. When the following description refers to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The implementations described in the following exemplary embodiments do not represent all implementations consistent with the present application. Instead, they are only examples of devices and methods consistent with some aspects of the present application as detailed in the attached claims.

[0031] The block diagrams shown in the accompanying drawings are merely functional entities and do not necessarily correspond to physically independent entities. That is, these functional entities may be implemented in software form, or in one or more hardware modules or integrated circuits, or in different networks and / or processor devices and / or microcontroller devices.

[0032] The flowcharts shown in the accompanying drawings are only exemplary and do not necessarily include all the contents and operations / steps, nor must they be executed in the order described. For example, some operations / steps can be decomposed, and some operations / steps can be combined or partially combined, so the actual execution order may change according to actual conditions.

[0033] It should also be noted that the "multiple" mentioned in this application refers to two or more than two. "And / or" describes the association relationship of the associated objects, indicating that there can be three relationships. For example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone. The character " / " generally indicates that the previous and next associated objects are in an "or" relationship.

[0034] Figure 1 FIG. 1 is a flow chart of an abnormal node detection method provided in an embodiment of the present application; Figure 1 As shown, the method specifically comprises the following steps:

[0035] Step S10: construct a transaction data set based on user transaction records in the database.

[0036] It should be noted that this embodiment constructs a corresponding transaction graph based on the bank's transaction records in order to more effectively and intuitively identify potential abnormal accounts and abnormal activities. The original data of the user transaction records comes from the bank's SQL database; the specific extraction steps include:

[0037] 1. Data extraction and preprocessing: Extract data that is helpful for constructing transaction graphs from the bank's SQL database, and perform preprocessing operations such as data cleaning and data completion. The purpose is to prepare for the subsequent construction of high-quality bank transaction graphs; specifically, the following operations are included:

[0038] (1) Data source location: Identify which tables in the SQL database contain data related to the construction of the transaction graph, including but not limited to transaction flow tables, account information tables, IP address management tables, etc.

[0039] (2) Data query and extraction: Use SQL query statements, such as "SELECT account_id, transaction_amount, transaction_time FROM transactions_table;" to obtain transaction data from the transaction flow table. At the same time, use statements such as "SELECT account_id, open_date, ip_address FROM accounts_table;" to obtain account-related data from the account basic information table.

[0040] (3) Data cleaning: Use natural language processing, entity resolution and other related technologies to delete duplicate records in the data, complete incomplete information of some accounts, and repair conflicting information.

[0041] (4) Data standardization: For some numerical attributes, such as account opening timestamps, standardization techniques (such as Z-score standardization or Min-Max scaling) are applied to make them comparable; at the same time, for some categorical attributes, such as transaction types, one-hot encoding is used to convert them into numerical form to prepare for subsequent graph neural network calculations.

[0042] 2. Construct a transaction graph: Use the data obtained in the previous step to construct a transaction graph and obtain a transaction dataset in the form of a graph structure. The graph structure consists of the following two parts:

[0043] (1) Node: An account is a node in the graph. In addition to the basic account ID, each node also includes a series of attributes such as account balance, account opening date, last login IP address, and common transaction patterns.

[0044] (2) Edge: When a transaction occurs, an edge is created between two account nodes. The weight of the edge is determined by the transaction amount, and the weight is adjusted based on the transaction frequency.

[0045] Figure 2 FIG. 1 is a schematic diagram of a transaction data set structure provided in an embodiment of the present application; Figure 2 As shown in the figure, the transaction graph in this example includes three accounts, and the node of each account stores the basic information of the account, such as account opening date, login IP address, etc. The weight on the edge represents the amount of the transfer. In this example, account 1 transferred 10,000 yuan and 20,000 yuan to account 2 and account 3 respectively; at the same time, account 2 transferred 25,000 yuan to account 3.

[0046] Step S20: Acquire a reference data set that matches the transaction data set based on the structural similarity and the semantic similarity.

[0047] In one embodiment, a reference data set matching the transaction data set is obtained based on structural similarity and semantic similarity, including: obtaining the degree values ​​of all nodes in the transaction data set and all candidate reference data sets; obtaining the degree value distribution corresponding to each data set according to the frequency of occurrence of each degree value; calculating the first structural similarity between the transaction data set and each candidate reference data set according to the degree value distribution corresponding to each data set; obtaining a candidate data set that is structurally similar to the transaction data set according to the first structural similarity; and performing semantic analysis on the node information in each candidate data set to obtain a parameter data set matching the transaction data set.

[0048] In another embodiment, obtaining and acquiring a candidate data set that is structurally similar to the transaction data set based on the first structural similarity includes: acquiring all connected components in the transaction data set and all candidate reference data sets; obtaining a connected component size distribution corresponding to each data set based on the number of nodes in each connected component; calculating a second structural similarity between the transaction data set and each candidate reference data set based on the connected component size distribution corresponding to each data set; and obtaining a candidate data set that is structurally similar to the transaction data set based on the first structural similarity and the second structural similarity.

[0049] It should be noted that in today's data science field, anomaly detection in the face of limited labels is a challenging task, especially in the fields of financial fraud detection and network security monitoring. When data labels are scarce, traditional supervised learning models often find it difficult to achieve ideal detection results. Therefore, this embodiment proposes an innovative method, which introduces a knowledge transfer mechanism and uses a reference data set with rich labels to enhance model training on a target data set with limited labels, thereby improving the accuracy and robustness of anomaly detection. The core of this method is to cleverly extract valuable knowledge from the reference data set and migrate it to the target data set to improve the model performance on the target domain.

[0050] In order to achieve this goal, we first need to find a reference data set that is similar to the target data set. The key lies in how to quantify the similarity between the two data sets. Based on this, this embodiment adopts a dual-track evaluation system that integrates structural similarity and semantic similarity for evaluation; among them, structural similarity refers to the degree of similarity between two graph data sets in topological structure, which can be measured by calculating the statistical characteristics of the graph, including average degree, clustering coefficient, shortest path length distribution, etc. Semantic similarity involves a deeper understanding of the data content, not only focusing on the surface form of the data, but also emphasizing the meaning behind the data and the logical relationship between the data; in this embodiment, this deep semantic information is captured by using natural language processing technology and graph neural networks.

[0051] Specifically, in terms of calculating structural similarity, it is necessary to analyze the global statistical features of the target dataset and the candidate reference dataset, such as node degree distribution, size distribution of connected components, etc., and compare the differences between the features. Specifically: First, calculate the degree of all nodes in each graph, and count the frequency of each degree value to form a degree distribution; then, use statistical methods (such as Kolmogorov-Smirnov test, Kullback-Leibler divergence, or Jensen-Shannon divergence) to evaluate the similarity of the two degree distributions. Similarly, by identifying all connected components in the graph and counting the number of nodes in each component, the size distribution of the connected components can be obtained, and then the similarity of the two distributions can be compared using the same statistical method. This process can usually be done efficiently with the help of the NetworkX library in Python to complete the graph processing and analysis work. If the two datasets have a high degree of match in these statistical characteristics, they are considered to be similar at the structural level. Next, in order to further confirm whether the selection of the reference dataset is reasonable, it is necessary to further examine the similarity of the two datasets at the semantic level.

[0052] On this basis, natural language processing technology is used to perform semantic analysis on the node information in the data set. In this step, various types of unstructured data may be encountered, such as text, images, etc. For text data, word embedding technology can be used to convert text into vector form, and then the similarity between texts can be measured by calculating the distance between these vectors; for image data, convolutional neural networks can be used to extract its feature representation, and then the similarity between images can be evaluated by the distance of feature vectors. In addition, graph neural networks are also used to capture the complex relationships between nodes in the data set. Through multiple rounds of message passing mechanisms, each node can not only obtain its own information, but also perceive the characteristics of its neighboring nodes, thereby forming a richer node representation.

[0053] Finally, structural similarity and semantic similarity are combined as a comprehensive indicator to guide the selection of reference datasets. Datasets that are highly consistent with the target dataset in both structure and semantics will be selected as reference datasets. Next, in the model training phase, the selected reference dataset is input into the graph neural network together with the target dataset for joint training. In this process, the rich label information in the reference dataset helps the model learn a more comprehensive feature expression capability, which is then transferred to the target dataset through the knowledge transfer mechanism, thereby improving the generalization ability and detection accuracy of the model in the target domain. For example, in the financial field, there are many blockchain datasets, transfer datasets, etc. in public data. The scenarios of these datasets are similar to those of abnormal activities, so they can be used as reference datasets in abnormal node detection tasks.

[0054] Step S30: perform feature concatenation on the transaction data set and the reference data set to obtain a target training matrix.

[0055] It should be noted that feature alignment is a key step in graph anomaly detection tasks, especially when dealing with graph datasets from different fields. The goal of feature alignment is to unify the features of different datasets into a common and sensitive space so that the model can effectively capture and identify abnormal patterns.

[0056] In the real world, the feature dimensions and meanings of graph datasets may be very different. For example, features in citation networks usually include text information and meta information of papers, while features in social networks may include user profile information. These differences make it difficult to directly input features from different datasets into the same model. Therefore, feature alignment becomes a key step to solve this problem. By aligning the features of different datasets, the model can better understand and process diverse graph data, thereby improving the accuracy and generalization ability of anomaly detection. First, the graph data of the reference dataset and the target dataset must be converted into a feature matrix. The process of initializing a graph data into a feature matrix involves converting the nodes and their attributes in the graph into a matrix in numerical form to facilitate subsequent machine learning or data analysis tasks. First, determine the features of each node in the graph. These features can be the attributes of the node itself (for example, the personal information of the account represented by the node, etc.), or they can be features extracted from the graph structure (for example, the degree, centrality, etc. of the node). Next, create a feature vector for each node, where each element corresponds to a specific feature value. The feature vectors of all nodes are combined to form a feature matrix, where each row represents a node and each column represents a feature. If some nodes are missing some eigenvalues, the completeness and consistency of the feature matrix can be ensured by filling them with default values ​​(such as zero).

[0057] Step S40: Perform residual learning on the graph neural network according to the target training matrix to obtain a node embedding matrix.

[0058] In graph neural networks, residual graph encoders are an important technique for learning node embeddings to capture abnormal patterns in graph data. Traditional graph neural network methods usually have low-pass filtering characteristics and are difficult to capture high-frequency and heterogeneous abnormal patterns. To address these problems, this application proposes a residual graph encoder that can effectively learn high-order affinity and heterogeneity information through a multi-hop residual aggregation scheme.

[0059] In order to overcome the limitations of traditional graph neural networks, this embodiment designs a residual graph encoder. By introducing residual operations, the encoder can capture multi-hop affinity patterns and provide rich and comprehensive information, thereby improving the accuracy of anomaly detection. Specifically, the residual graph encoder has the following advantages: (1) Emphasis on the difference between a node and its neighbors: The residual operation enables the model to explicitly model the difference between a node and its neighbors, rather than just focusing on the semantic information of the node itself. This difference information is very important for detecting abnormal patterns; (2) High-pass filtering characteristics: The residual operation is equivalent to high-pass filtering of the graph data, helping the model capture high-frequency signals and local heterogeneity information; (3) Multi-hop affinity: Through the multi-hop residual aggregation scheme, the model can capture higher-order affinity patterns, thereby better understanding the complex structure in the graph data.

[0060] Step S50: perform anomaly scoring on the node embedding matrix based on contextual attention to obtain anomaly classification results of the nodes.

[0061] It should be noted that in the graph anomaly detection task, accurately identifying abnormal nodes is a very challenging problem, especially when the labeled data is limited. Traditional anomaly detection methods usually rely on a large amount of labeled data for supervised learning, but in practical applications, labeled data is often very scarce. In order to solve this problem, this application proposes a context-based attention anomaly scoring module. This module dynamically learns and predicts the degree of abnormality of other nodes in the reasoning stage by using a small number of normal samples (called context nodes), thereby achieving efficient anomaly detection. The core idea of ​​the contextual attention anomaly scoring module is to reconstruct the embedding representation of the query node using a small number of normal samples (context nodes) through the contextual attention mechanism. Specifically, the module fuses the embedding representation of the context node into the embedding representation of the query node through the cross-attention block, and then evaluates the degree of abnormality of the node by calculating the drift distance between the original embedding representation and the reconstructed embedding representation. The larger the drift distance, the more likely the node is an abnormal node.

[0062] In summary, the present application integrates a dual-track evaluation system of structural similarity and semantic similarity to select a reference data set that is similar to the target data set, aiming to enhance the model training on the target data set with limited labels by introducing a knowledge transfer mechanism and utilizing a reference data set with rich labels, thereby improving the accuracy and robustness of anomaly detection; further, by performing residual learning on the graph neural network using the matrix after feature concatenation of the transaction data set and the reference data set, it is possible to capture multi-hop affinity patterns and provide rich and comprehensive information, thereby improving the accuracy of anomaly detection; in addition, the present application utilizes a small number of normal samples to dynamically learn and predict the degree of abnormality of other nodes in the reasoning stage, thereby achieving efficient anomaly detection.

[0063] In one embodiment, if Figure 3 As shown, the transaction dataset and the reference dataset are feature concatenated to obtain the target training matrix, which specifically includes the following steps:

[0064] Step S310: Convert the transaction data set and the reference data set into feature matrices respectively.

[0065] It should be noted that the process of initializing a dataset into a feature matrix involves converting the nodes and their attributes in the graph into a matrix in numerical form to facilitate subsequent machine learning or data analysis tasks. First, determine the features of each node in the graph. The feature can be an attribute of the node itself (for example, the personal information of the account represented by the node, etc.), or a feature extracted from the graph structure (for example, the degree and centrality of the node); next, create a feature vector for each node, in which each element corresponds to a specific feature value; then, combine the feature vectors of all nodes to form a feature matrix, in which each row represents a node and each column represents a feature. If some nodes lack certain feature values, the integrity and consistency of the feature matrix can be ensured by filling in default values ​​(such as zero).

[0066] Step S320: Perform feature projection on different feature matrices to obtain feature vectors of multiple preset dimensions.

[0067] It should be noted that feature projection is to unify the feature dimensions of different data sets into a common space; specifically, given a feature matrix where n (o) It is the dataset D (i) The number of nodes in d (i) is the feature dimension. Feature projection is achieved through a linear mapping, and the specific mapping relationship is shown in formula (1):

[0068]

[0069] in, is the feature matrix after projection, d u is a predefined projection dimension that applies to all datasets. is a dataset-specific linear projection weight matrix. To maintain the generality of the model, the weight matrix W (i) It can be defined by principal component analysis. For example, assuming that the feature matrix of the original reference data set is five-dimensional, that is, each node v corresponds to a five-dimensional vector [v1, V2, V3, V4, v5], where v i is called the value of v on the i-th feature. If you want to project the feature matrix into three-dimensional space, you need a linear projection weight matrix W with five rows and three columns, as follows

[0070]

[0071] For node v, the feature vector after projection becomes:

[0072] [v1w 11 +…+v5w 51 ,v1w 21 +…+v5w25 ,v1w 31 +…+v5w 35 ].

[0073] Step S330: sort the features according to the smoothing parameter of each feature vector.

[0074] It should be noted that the features are sorted according to their smoothing parameters in the graph signal. k represents the degree of change of the kth feature between connected nodes. Specifically, a lower s k A value of s indicates that the feature varies less between connected nodes, corresponding to a low-frequency graph signal; conversely, a higher s k A value of 0 indicates that the feature varies greatly between connected nodes, corresponding to high-frequency graph signals. The smoothing parameter s k It can be calculated by the following formula (2):

[0075]

[0076] Among them, s k represents the smoothing parameter of the kth feature, E is the edge set of the graph, and X ik and X jk They are node v i and v j The value of the kth feature.

[0077] By sorting the features by smoothing parameters, the features can be rearranged so that the features with lower smoothing parameters are at the front, which are usually more sensitive to anomaly detection. Specifically, given the feature matrix after projection By smoothing parameter s k Rearrange the feature dimensions in descending order. Suppose there is a graph with three nodes v1, v2, v3 and two edges (v1, v2), (v2, v3). The three-dimensional feature matrix obtained after projection is:

[0078]

[0079] For the first dimension, its smoothness is (|2-4|+|4-6|) / (2×2)=1. Similarly, the smoothness of the second and third dimensions can be calculated to be 0.5 and 1.5 respectively. The order of smoothness from small to large is: second dimension, first dimension, third dimension. The new feature matrix obtained after rearrangement is:

[0080]

[0081] Therefore, for all datasets, the first column of the feature matrix is ​​always the feature with the lowest smoothing parameter, while the features with higher smoothing parameters are arranged at the back; the feature alignment module not only helps to unify the feature space of different datasets, but also improves the model's sensitivity to abnormal patterns. By sorting the features by smoothing parameters, the model can more effectively capture high-frequency graph signals and heterogeneous information, thereby enhancing its anomaly detection ability in complex graph structures; in addition, the introduction of the smooth feature alignment module enables the model to quickly adapt to new datasets without retraining or fine-tuning, which greatly improves the generalization ability of the model.

[0082] Step S340: concatenate the sorted target matrix and the reference matrix to obtain a target training matrix.

[0083] It should be noted that since all reference data sets and target data sets have been unified into the same dimension, all matrices will be concatenated to obtain one matrix. Assuming there are three data sets with 5, 6 and 7 nodes respectively, which are unified into three-dimensional space in the projection operation, then at the end of step three, these three matrices will be concatenated into a matrix with 18 rows and 3 columns. Rows 1 to 5 represent the first data set, and so on. Subsequent operations are all based on this concatenated matrix.

[0084] In another embodiment, Figure 4 As shown in the figure, when residual learning is performed on the graph neural network according to the target training matrix, the node embedding matrix is ​​obtained, which specifically includes the following steps:

[0085] Step S410: Perform multi-hop propagation on the target training matrix to obtain a propagated feature matrix.

[0086] This embodiment uses a residual graph encoder to perform feature learning of a graph neural network, that is, residual learning of the graph neural network is performed according to the target training matrix. The process of the residual graph encoder is as follows: The input of the residual graph encoder is the target training matrix X after feature alignment and splicing. ′ First, multi-hop propagation is performed on the target training matrix to capture the high-order relationships between nodes. Specifically, the propagation process can be expressed as:

[0087]

[0088] Among them, X [l] is the propagation feature matrix after the first iteration, is the normalized adjacency matrix, X [0] =X ′is the initial target training matrix. Through multiple iterations, the model is able to gradually capture the high-order relationships between nodes, thereby better understanding the complex structures in the graph data. In the task of detecting abnormal activities, multi-hop propagation can help the model capture the multi-level transaction relationships between accounts. For example, an account may trade with another account through multiple intermediary accounts, and these complex transaction paths are often one of the characteristics of abnormal activities. Through multi-hop propagation, the model can effectively identify these complex transaction paths, thereby improving the detection ability of money laundering activities. In addition, multi-hop propagation can also help the model discover hidden abnormal patterns that may be ignored in single-hop propagation.

[0089] Step S420: performing a shared transformation on the target training matrix and the propagated feature matrix to obtain a feature fusion matrix.

[0090] It should be noted that after multi-hop propagation, the model performs a shared MLP transformation on the original target training matrix and the propagated features to map them to the same representation space. Specifically, the transformation process can be expressed as: [l] =MLP(X [l] )l=0,1,2,…,L.

[0091] Among them, Z [l] is the transformed feature matrix after the first iteration, and MLP is a multi-layer perceptron. By sharing MLP, the model can ensure that features after different iterations are compared in the same representation space. Sharing MLP transformation helps to unify features at different levels into a common representation space, thereby improving the expressiveness of the model. In the task of detecting abnormal activities, features at different levels may contain different information, such as basic account information, transaction amount, transaction frequency, etc. By sharing MLP transformation, the model can fuse these different levels of features together to more fully understand the behavior patterns of accounts.

[0092] Step S430: Obtain a residual matrix after the current iteration by calculating the difference between the current feature fusion matrix and the feature fusion matrix after the previous iteration.

[0093] It should be noted that the residual operation is the core part of the residual graph encoder. By calculating the difference between the feature matrices after different iterations, the model can capture the difference information between a node and its neighbors. Specifically, the residual matrix R [l] It can be expressed as: R [l] =Z [l] -Z [0] ; where l =

[0094] 1,2,…,L,R [l] is the residual matrix after the first iteration, Z [0]is the transformation result of the initial feature matrix. By calculating the residual matrix, the model can explicitly model the differences between a node and its neighbors. The residual operation is crucial for anomaly detection tasks because it can capture the difference information between a node and its neighbors. In practical applications, abnormal accounts often exhibit significantly different behavior patterns from normal accounts; for example, an abnormal account may frequently conduct small transactions, while normal accounts mainly conduct large transactions. Through the residual operation, the model can capture these difference information and thus more accurately identify abnormal accounts; in addition, the residual operation can also help the model filter out noise and irrelevant features, thereby improving the accuracy of anomaly detection.

[0095] Step S440: Aggregate all the iterated residual matrices to obtain a node embedding matrix.

[0096] It should be noted that the model aggregates all residual matrices to form the final embedding of the node. Specifically, the final embedding matrix H can be expressed as:

[0097] H=Aggr(R [1] ,R [2] ,…,R [L] )

[0098] Among them, Aggr represents the matrix aggregation operation. By performing aggregation operations on the multi-hop residual matrix, the model can obtain node embeddings that contain rich information, thereby improving the accuracy of anomaly detection; the final embedding matrix H contains the information of the multi-hop residual matrix, which can comprehensively reflect the characteristics of the node and its relationship with its neighbors. The final embedding matrix can be used in the downstream anomaly scoring module to help the model more accurately predict the degree of abnormality of the node. For example, by calculating the weights of each feature in the final embedding matrix, the model can identify which features are most important for anomaly detection. In addition, the final embedding matrix can also be used for visual analysis to help financial analysts better understand the behavior patterns of accounts and thus assist in decision-making.

[0099] In another embodiment, Figure 4 As shown in the figure, the node embedding matrix is ​​scored abnormally based on the contextual attention to obtain the abnormal classification result of the node, which specifically includes the following steps:

[0100] Step S510: divide the node embedding matrix into a context node embedding matrix and a query node embedding matrix.

[0101] Specifically, given a graph G = (V, E, X), the nodes are divided into context nodes and query nodes. Usually, the context nodes are a small number of randomly selected known normal nodes, while the query nodes are all the nodes that need to be detected for anomalies.

[0102] Through the residual graph encoder in the above step, the target training matrix X in the graph is converted into a node embedding matrix H, and the node embedding matrix H is divided into the context node embedding matrix H k and the query node embedding matrix H q . In this embodiment, the context nodes can be known normal accounts whose behavior patterns are considered normal. By selecting these normal accounts as context nodes, the model can better understand the behavior patterns of normal accounts, thereby more accurately identifying abnormal accounts. Query nodes are all accounts that need to be detected for anomalies. By dividing all accounts into query nodes, the model can dynamically evaluate the degree of abnormality of each account in the inference phase, thereby achieving comprehensive anomaly detection. The node embeddings generated by the residual graph encoder can capture the complex relationships between nodes and their neighbors, which is crucial for identifying complex transaction patterns in abnormal activities. For example, an account may trade with another account through multiple intermediary accounts, and these complex transaction paths are often one of the characteristics of abnormal activities. Dividing the node embedding matrix into a context node embedding matrix and a query node embedding matrix helps the model dynamically evaluate the degree of abnormality of each query node in the inference phase. In this way, the model can make full use of known normal account information to more accurately identify abnormal accounts.

[0103] Step S520: merge the context node embedding matrix into the query node embedding matrix to generate a reconstructed embedding of the query node.

[0104] In one embodiment, the context node embedding matrix is ​​fused into the query node embedding matrix to generate a reconstructed embedding of the query node, specifically including: performing a linear transformation on the context node embedding matrix and the query node embedding matrix according to a weight matrix to generate a query matrix and a key matrix; generating an attention weight matrix by calculating the dot product between the query matrix and the key matrix; and generating a reconstructed embedding of the query node through the attention weight matrix and the context node embedding matrix.

[0105] It should be noted that after obtaining the above node embedding matrix, the context node is embedded into the matrix H through the cross attention block. k Fusion into the query node embedding matrix H q In order to reconstruct the embedding representation of the query node. Specifically:

[0106] In the process of attention calculation, the query matrix Q and key matrix K are generated by linear transformation. The specific transformation formula is: Q = H q W q , K=H k W k , where W q and W kis a learnable weight matrix that transforms the embedding representations of query nodes and context nodes.

[0107] After obtaining the above query matrix and key matrix, the attention weight matrix can be generated by calculating the dot product between the query matrix and the key matrix:

[0108]

[0109] Among them, A is the attention weight matrix, which represents the attention allocation of the query node to the context node.

[0110] Furthermore, the reconstructed embedding representation of the query node is generated through the attention weight matrix and the context node embedding matrix:

[0111] H′ q =AH k

[0112] Generating the query matrix and key matrix through linear transformation helps the model capture the similarities and differences between the query node and the context node. In this embodiment, this step can help the model identify which accounts have similar behavior patterns to normal accounts and which accounts have significantly different behavior patterns from normal accounts; by calculating the attention weight matrix, the model can dynamically allocate the attention of the query node to the context node; in addition, through the attention mechanism, the model can more accurately identify these abnormal patterns, and generate a reconstructed embedding representation of the query node through the attention weight matrix and the context node embedding matrix, which helps the model evaluate the abnormality of the query node.

[0113] Step S530: Obtain a drift distance between an original embedding representation and a reconstructed embedding representation of the query node according to the query node embedding matrix.

[0114] In this embodiment, the drift distance between the original embedding representation and the reconstructed embedding representation of the query node is calculated, and the drift distance can be used as the abnormality score of the node. Specifically, for a node v i , and its drift distance can be expressed as:

[0115] f(v i )=d(H qi ,H ′ qi )=1-cos(H qi ,H ′ qi )

[0116] where cos is the cosine similarity between the two embedding representations.

[0117] Step S540: Obtain an abnormal classification result of the node according to the drift distance.

[0118] It should be noted that for a node, the larger its drift distance is, the more likely it is to be an abnormal node. By calculating the drift distance between the original embedding representation and the reconstructed embedding representation of the query node, the model can evaluate the degree of abnormality of the query node. Specifically, the drift distance of normal accounts is usually small, while the drift distance of abnormal accounts is usually large. In this embodiment, this step can help financial analysts better understand the behavior patterns of accounts, thereby assisting decision-making; for example, by calculating the drift distance of each account, the model can identify which accounts have behavior patterns that are significantly different from normal accounts, thereby more accurately identifying potential abnormal activities.

[0119] In summary, the technical solution provided by this application has at least the following beneficial effects:

[0120] 1. This application proposes an innovative dataset screening method, which aims to enhance the model training on the target dataset with limited labels by introducing a knowledge transfer mechanism and using a reference dataset with rich labels, thereby improving the accuracy and robustness of anomaly detection. In the fields of financial fraud detection, network security monitoring, etc., anomaly detection in the face of limited labels is a challenging task. Traditional supervised learning models often find it difficult to achieve ideal detection results in this case, because the lack of sufficient labeled data will lead to overfitting or insufficient generalization of the model. In order to solve this problem, this application adopts a dual-track evaluation system that combines structural similarity and semantic similarity to select reference datasets. Structural similarity refers to the degree of similarity between two graph datasets in topological structure, which can be measured by calculating some statistical properties of the graph, such as average degree, clustering coefficient, shortest path length distribution, etc. Semantic similarity involves a deeper understanding of the data content, not just the surface form of the data, but also emphasizes the meaning behind the data and the logical relationship between the data. In this application, natural language processing technology and graph neural networks are used to capture this deep semantic information.

[0121] 2. In graph neural networks, traditional models usually have low-pass filtering characteristics, which makes it difficult to capture high-frequency and heterogeneous abnormal patterns. In order to solve these problems, this application proposes a residual graph encoder, which can effectively learn high-order affinity and heterogeneous information through a multi-hop residual aggregation scheme. When processing graph data, traditional graph neural network methods can often only capture local relationships between nodes, while ignoring broader contextual information. This leads to poor performance of the model when processing complex graph structures, especially in scenarios involving multi-level transaction relationships. By introducing residual operations, the encoder can capture multi-hop affinity patterns and provide rich and comprehensive information, thereby improving the accuracy of anomaly detection. Specifically, the residual graph encoder has the following advantages: First, it can emphasize the difference between a node and its neighbors. The residual operation enables the model to explicitly model the difference between a node and its neighbors, rather than just focusing on the semantic information of the node itself. This difference information is very important for detecting abnormal patterns. Second, the residual operation is equivalent to high-pass filtering of the graph data, helping the model capture high-frequency signals and local heterogeneous information. This is particularly important for identifying abnormal accounts, because abnormal accounts often exhibit behavior patterns that are significantly different from normal accounts. For example, an abnormal account may frequently conduct small transactions, while a normal account mainly conducts large transactions. Through residual operations, the model can capture these differences and identify abnormal accounts more accurately. In addition, residual operations can also help the model filter out noise and irrelevant features, improving the accuracy of anomaly detection.

[0122] 3. In the task of graph anomaly detection, accurately identifying abnormal nodes is a very challenging problem, especially when there is limited labeled data. Traditional anomaly detection methods usually rely on a large amount of labeled data for supervised learning, but in practical applications, labeled data is often very scarce. To solve this problem, this application proposes a context-based attention anomaly scoring module. This module dynamically learns and predicts the degree of abnormality of other nodes in the reasoning stage by utilizing a small number of normal samples (called context nodes), thereby achieving efficient anomaly detection. The core idea of ​​the contextual attention anomaly scoring module is to reconstruct the embedding representation of the query node using a small number of normal samples (context nodes) through the contextual attention mechanism. Specifically, the module fuses the embedding representation of the context node into the embedding representation of the query node through a cross-attention block, and then evaluates the degree of abnormality of the node by calculating the drift distance between the original embedding representation and the reconstructed embedding representation. The larger the drift distance, the more likely the node is an abnormal node.

[0123] Figure 6 FIG. 1 is a schematic diagram of the structure of an abnormal node detection device provided in an embodiment of the present application; Figure 6 As shown, the device comprises:

[0124] A transaction data set construction module 610 is used to construct a transaction data set according to user transaction records in a database;

[0125] A reference data set acquisition module 620, configured to acquire a reference data set matching the transaction data set based on structural similarity and semantic similarity;

[0126] A feature concatenation module 630 is used to concatenate features of the transaction dataset and the reference dataset to obtain a target training matrix;

[0127] A residual learning module 640 is used to perform residual learning on the graph neural network according to the target training matrix to obtain a node embedding matrix;

[0128] The anomaly scoring module 650 is used to perform anomaly scoring on the node embedding matrix based on contextual attention to obtain an anomaly classification result of the node.

[0129] Figure 7 A schematic diagram of the structure of a computer system suitable for implementing an electronic device of an embodiment of the present application is shown.

[0130] It should be noted that Figure 7 The computer system 1000 of the electronic device shown is only an example and should not bring any limitation to the functions and scope of use of the embodiments of the present application.

[0131] like Figure 7 As shown, the computer system 1000 includes a central processing unit (CPU) 1001, which can perform various appropriate actions and processes according to the program stored in the read-only memory (ROM) 1002 or the program loaded from the storage part 1008 to the random access memory (RAM) 1003, such as executing the method described in the above embodiment. In the RAM 1003, various programs and data required for system operation are also stored. The CPU 1001, the ROM 1002 and the RAM 1003 are connected to each other through the bus 1004. The input / output (I / O) interface 1005 is also connected to the bus 1004.

[0132] The following components are connected to the I / O interface 1005: an input section 1006 including a keyboard, a mouse, etc.; an output section 1007 including a cathode ray tube (CRT), a liquid crystal display (LCD), etc., and a speaker, etc.; a storage section 1008 including a hard disk, etc.; and a communication section 1009 including a network interface card such as a LAN (Local Area Network) card, a modem, etc. The communication section 1009 performs communication processing via a network such as the Internet. A drive 1010 is also connected to the I / O interface 1005 as needed. A removable medium 1011, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 1010 as needed so that a computer program read therefrom is installed into the storage section 1008 as needed.

[0133] In particular, according to an embodiment of the present application, the process described above with reference to the flowchart can be implemented as a computer software program. For example, an embodiment of the present application includes a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program includes a computer program for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from a network through a communication section 1009, and / or installed from a removable medium 1011. When the computer program is executed by a central processing unit (CPU) 1001, various functions defined in the system of the present application are executed.

[0134] It should be noted that the computer-readable medium shown in the embodiment of the present application can be a computer-readable signal medium or a computer-readable storage medium or any combination of the above two. The computer-readable storage medium can be, for example, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or device, or any combination of the above. More specific examples of computer-readable storage media can include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM), a flash memory, an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present application, a computer-readable storage medium can be any tangible medium containing or storing a program, which can be used by an instruction execution system, device or device or used in combination with it. In the present application, a computer-readable signal medium can include a data signal propagated in a baseband or as a part of a carrier wave, wherein a computer-readable computer program is carried. Such propagated data signals may take a variety of forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. Computer-readable signal media may also be any computer-readable medium other than computer-readable storage media, which may send, propagate, or transmit programs for use by or in conjunction with an instruction execution system, apparatus, or device. The computer program contained on the computer-readable medium may be transmitted using any appropriate medium, including but not limited to: wireless, wired, etc., or any suitable combination of the above.

[0135] The flowchart and block diagram in the accompanying drawings illustrate the possible architecture, functions and operations of the system, method and computer program product according to various embodiments of the present application. Wherein, each box in the flowchart or block diagram can represent a module, a program segment, or a part of the code, and the above-mentioned module, program segment, or a part of the code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a different order from the order marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram or flowchart, and the combination of boxes in the block diagram or flowchart can be implemented with a dedicated hardware-based system that performs a specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.

[0136] The units involved in the embodiments described in this application may be implemented by software or hardware, and the units described may also be set in a processor. The names of these units do not, in some cases, constitute limitations on the units themselves.

[0137] The above content is only a preferred exemplary embodiment of the present application and is not intended to limit the implementation scheme of the present application. A person skilled in the art can easily make corresponding changes or modifications based on the main concept and spirit of the present application. Therefore, the scope of protection of the present application shall be based on the scope of protection required by the claims.

Claims

1. A method for detecting abnormal nodes, characterized in that: The method comprises: Construct a transaction data set based on user transaction records in the database; Acquire a reference data set matching the transaction data set based on structural similarity and semantic similarity; Concatenate the transaction dataset and the reference dataset to obtain the target training matrix; Perform residual learning on the graph neural network according to the target training matrix to obtain the node embedding matrix; The node embedding matrix is ​​scored for anomaly based on contextual attention to obtain the anomaly classification result of the node.

2. The method according to claim 1, characterized in that Acquiring a reference data set matching the transaction data set based on structural similarity and semantic similarity, including: Obtaining the degree values ​​of all nodes in the transaction dataset and all candidate reference datasets; According to the frequency of occurrence of each degree value, the degree value distribution corresponding to each data set is obtained; Calculating a first structural similarity between the transaction dataset and each candidate reference dataset according to the degree value distribution corresponding to each dataset; According to the first structural similarity, obtaining a candidate data set that is similar in structure to the transaction data set; Perform semantic analysis on the node information in each candidate data set to obtain a parameter data set that matches the transaction data set.

3. The method according to claim 2, characterized in that Acquiring a candidate data set that is structurally similar to the transaction data set according to the first structural similarity includes: Obtaining all connected components in the transaction dataset and all candidate reference datasets; According to the number of nodes in each connected component, the connected component size distribution corresponding to each data set is obtained; Calculating a second structural similarity between the transaction dataset and each candidate reference dataset according to the connected component size distribution corresponding to each dataset; A candidate data set that is similar in structure to the transaction data set is acquired according to the first structural similarity and the second structural similarity.

4. The method according to claim 1, characterized in that: The transaction dataset and the reference dataset are concatenated to obtain the target training matrix, including: Convert the transaction dataset and reference dataset into feature matrices respectively; Perform feature projection on different feature matrices to obtain feature vectors of multiple preset dimensions; Sort features according to the smoothing parameter of each eigenvector; The sorted target matrix and reference matrix are concatenated to obtain the target training matrix.

5. The method according to claim 4, characterized in that The smoothing parameter calculation expression for each eigenvector is: Among them, s k represents the smoothing parameter of the kth feature, E is the edge set of the graph, and x ik and x jk They are node v i and v j The value of the kth feature.

6. The method according to claim 1, characterized in that When residual learning is performed on the graph neural network according to the target training matrix, the node embedding matrix is ​​obtained, including: Perform multi-hop propagation on the target training matrix to obtain the propagated feature matrix; Perform a shared transformation on the target training matrix and the propagated feature matrix to obtain a feature fusion matrix; By calculating the difference between the current feature fusion matrix and the feature fusion matrix after the previous iteration, the residual matrix after the current iteration is obtained; All the residual matrices after iterations are aggregated to obtain the node embedding matrix.

7. The method according to any one of claims 1 to 6, characterized in that: Based on the contextual attention, the node embedding matrix is ​​scored abnormally to obtain the abnormal classification results of the node, including: Divide the node embedding matrix into a context node embedding matrix and a query node embedding matrix; fusing the context node embedding matrix into the query node embedding matrix to generate a reconstructed embedding of the query node; According to the query node embedding matrix, obtaining a drift distance between an original embedding representation and a reconstructed embedding representation of the query node; An abnormal classification result of the node is obtained according to the drift distance.

8. The method according to claim 7, characterized in that Fusion of the context node embedding matrix into the query node embedding matrix to generate a reconstructed embedding of the query node includes: Performing linear transformation on the context node embedding matrix and the query node embedding matrix according to the weight matrix to generate a query matrix and a key matrix; Generate the attention weight matrix by calculating the dot product between the query matrix and the key matrix; The reconstructed embedding of the query node is generated through the attention weight matrix and the context node embedding matrix.

9. An abnormal node detection device, characterized in that: The device comprises: A transaction data set construction module is used to construct a transaction data set based on user transaction records in a database; A reference data set acquisition module, used to acquire a reference data set matching the transaction data set based on structural similarity and semantic similarity; The feature concatenation module is used to concatenate the transaction dataset and the reference dataset to obtain the target training matrix; The residual learning module is used to perform residual learning on the graph neural network according to the target training matrix to obtain the node embedding matrix; The anomaly scoring module is used to perform anomaly scoring on the node embedding matrix based on contextual attention to obtain the anomaly classification result of the node.

10. An electronic device, characterized in that: include: processor; and a memory for storing executable instructions of the processor; wherein the processor is configured to execute the executable instructions to enable the electronic device to implement the abnormal node detection method as described in any one of claims 1 to 8.

Citation Information

Cited By

  • Transaction chain abnormal node identification method based on knowledge graph enhancement

    CN120234582A

  • Feature processing method and device of transaction anomaly detection model and electronic equipment

    CN121030298A

  • Data maintenance system and method based on distributed material boxing and tagging system

    CN121786044A