Transaction fraud behavior detection method and system based on graph neural network
By constructing heterogeneous graphs and using dynamic weighting mechanisms, strengthening learning agents and hierarchical attention networks, the problem of difficulty in detecting complex transaction fraud in existing technologies is solved, and higher recognition accuracy and intelligent transaction security protection are achieved.
Patent Information
- Application Number
- CN202510452542.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-11
- Publication Date
- 2025-05-09
- Estimated Expiration
- 2045-04-11
AI Technical Summary
The prior art is difficult to effectively detect and identify complex transaction fraud behaviors, especially multi-hop association risks across devices and IPs, and failure to deeply understand the dynamic evolution characteristics of transaction behaviors.
By constructing heterogeneous graphs, users, merchants, devices and other entities are included in the unified analysis framework, and the time sensitivity and user activity of trading nodes are quantified in combination with dynamic weighting mechanisms. Use reinforcement learning agents to generate high-risk metapaths and achieve multi-path feature fusion through hierarchical attention networks. The timing chart network updates the transaction node embedding representation, which combines the transaction node and metapath embedding to predict the probability of fraud.
It significantly improves the ability to identify complex fraud behaviors, improves the accuracy of identification of transaction fraud behaviors, and provides an intelligent solution for transaction security protection.
Smart Images

Figure CN119963204A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of transaction fraud detection, and in particular to a transaction fraud behavior detection method and system based on graph neural network. Background Art
[0002] In the context of the rapid development of the digital economy, transaction fraud has become one of the core risks that threaten the healthy development of the business ecosystem. An effective fraud detection mechanism can minimize the losses of all parties by early warning of abnormal transactions and blocking the capital flow chain. At the same time, the accumulated fraud pattern data can provide decision-making support for optimizing risk control strategies and improving security certification systems, forming a virtuous cycle of risk prevention and control.
[0003] At present, the mainstream detection technologies can be divided into three categories: expert systems based on rule engines, classification models based on traditional machine learning, and analysis methods based on simple graph structures. The rule engine intercepts risks by setting hard thresholds (such as the upper limit of the number of transactions per day) or blacklist and whitelist mechanisms. Although it can quickly respond to known fraud patterns, the cost of rule maintenance increases dramatically when facing evolving fraud methods, and the false alarm rate is high. Traditional machine learning models (such as random forests and gradient boosting trees) learn feature rules through historical data, but are limited by the model architecture and cannot effectively handle the temporal associations and complex network relationships in transaction data. Although the graph neural network technology that has emerged in recent years can capture some correlation features, existing methods mostly use fixed paths or shallow attention mechanisms. For example, they only analyze the simple path of "user-transaction-merchant" and cannot deeply explore multi-hop correlation risks across devices and IPs. More importantly, existing technologies lack the ability to model the dynamic evolution characteristics of transaction behaviors. For example, they fail to include the temporal changes in user activity and the dynamic fluctuations in merchant reputation in weight calculations, resulting in delayed detection of periodic fraud, progressive fraud, and other behaviors.
[0004] Therefore, there is an urgent need for transaction fraud detection methods and systems based on graph neural networks, which can improve the recognition accuracy of transaction fraud and provide an intelligent solution for transaction security protection. Summary of the invention
[0005] In order to solve the above technical problems, the present invention provides a transaction fraud detection method and system based on graph neural network, which can improve the recognition accuracy of transaction fraud and provide an intelligent solution for transaction security protection.
[0006] The present invention provides a transaction fraud detection method based on graph neural network, comprising the following steps:
[0007] S1. Obtain user data, transaction data and merchant data of the trading platform, and generate a heterogeneous graph including transaction nodes, user nodes, commodity nodes, merchant nodes, device nodes and IP address nodes;
[0008] S2. Calculate the dynamic weight of each transaction node based on the transaction data;
[0009] S3. Generate a set of high-risk meta-paths through a reinforcement learning agent based on the heterogeneous graph; the set of high-risk meta-paths includes the associated paths between transaction nodes and other types of nodes;
[0010] S4. Update the embedded representation of each transaction node through the time-series graph network according to the dynamic weight and transaction data of each transaction node;
[0011] S5. Based on the high-risk meta-path set and the characteristics of each type of node, the meta-path embedding representation is obtained through a hierarchical attention network;
[0012] S6, integrating the embedding representation of each transaction node with the meta-path embedding representation to predict the fraud probability of the transaction node;
[0013] S7. Mark the transaction nodes whose fraud probability is greater than or equal to the fraud threshold as fraud transactions.
[0014] Furthermore, in S2, the dynamic weight of each transaction node is calculated based on the transaction data, and the calculation formula is as follows:
[0015] ;
[0016] Among them, ω T represents the dynamic weight of the Tth transaction node, Δt represents the difference between the current time and the transaction timestamp, c represents the coupon usage identifier, a represents the payment amount, and A u represents user activity, r represents the merchant’s historical complaint rate, and α represents the time decay coefficient.
[0017] Furthermore, the calculation formula for user activity is as follows:
[0018] ;
[0019] Where k represents the kth transaction associated with the user, n represents the total number of transactions associated with the user, and a k represents the payment amount of the kth transaction, Δt k Indicates the difference between the current time and the transaction timestamp of the kth transaction.
[0020] Furthermore, in S3, according to the heterogeneous graph, the set of high-risk meta-paths generated by the reinforcement learning agent includes:
[0021] S31. Define the state space of the reinforcement learning agent as the current meta-path, the action space as the node type expanded based on the current meta-path, and the reward function as the weighted sum of the proportion of fraudulent samples in the path and the transaction weight;
[0022] S32. Explore paths in the heterogeneous graph through a reinforcement learning agent, and retain paths whose cumulative reward values exceed a preset threshold to obtain a high-risk meta-path set.
[0023] Furthermore, in S31, the calculation formula of the reward function is as follows:
[0024] ;
[0025] Among them, R represents the reward value of the meta-path, N fraud represents the number of fraud samples in the meta-path, N total represents the total number of samples in the meta-path, λ represents the weight coefficient, T represents the Tth transaction node, p represents the meta-path in the high-risk meta-path set, ω T Indicates the dynamic weight of the Tth transaction node.
[0026] Furthermore, in S4, according to the dynamic weight and transaction data of each transaction node, updating the embedding representation of each transaction node through the time-series graph network includes:
[0027] S41, extracting features according to the transaction timestamps corresponding to each transaction node in the transaction data, and generating transaction cycle features of each transaction node;
[0028] S42: Input the dynamic weight of each transaction node and the corresponding transaction cycle characteristics into the timing graph network, and update the embedded representation of each transaction node.
[0029] Furthermore, in S41, feature extraction is performed according to the transaction timestamp corresponding to each transaction node in the transaction data to generate transaction cycle features of each transaction node, including:
[0030] Convert transaction timestamps in transaction data into hour units;
[0031] Calculate the transaction cycle characteristics of each node based on the converted transaction timestamp and cycle encoding function;
[0032] The calculation formula of the periodic encoding function is as follows:
[0033] ;
[0034] in, represents the transaction cycle characteristics of the Tth transaction node, and t' represents the converted transaction timestamp.
[0035] Furthermore, in S6, the embedding representation of each transaction node is integrated with the meta-path embedding representation to predict the fraud probability of the transaction node, including:
[0036] S61, concatenating the meta-path embedding representation with the embedding representation of each transaction node, and inputting the result into a multi-layer perceptron to obtain a final embedding representation of each transaction node;
[0037] S62. According to the final embedding representation, the fraud probability of the transaction node is calculated by using the Sigmoid function.
[0038] Furthermore, in S62, the fraud probability of the transaction node is calculated by the Sigmoid function, and the calculation formula is as follows:
[0039] ;
[0040] Among them, y T represents the fraud probability of the Tth transaction node, σ represents the Sigmoid function, w represents the weight vector, and h T final represents the final embedding representation of the Tth transaction node, and b represents the bias term.
[0041] The present invention also provides a transaction fraud behavior detection system based on graph neural network, which is used to execute any of the transaction fraud behavior detection methods based on graph neural network described above, and the system includes the following modules:
[0042] A heterogeneous graph construction module is used to obtain user data, transaction data and merchant data of the trading platform and generate a heterogeneous graph containing transaction nodes, user nodes, commodity nodes, merchant nodes, device nodes and IP address nodes;
[0043] The dynamic weight calculation module is connected to the heterogeneous graph construction module and is used to calculate the dynamic weight of each transaction node based on the transaction data;
[0044] The meta-path discovery module is connected to the heterogeneous graph construction module and is used to generate a high-risk meta-path set based on the heterogeneous graph through a reinforcement learning agent; the high-risk meta-path set includes the associated paths between transaction nodes and other types of nodes;
[0045] A node embedding module, connected to the dynamic weight calculation module, is used to update the embedding representation of each transaction node through a time-series graph network according to the dynamic weight and transaction data of each transaction node;
[0046] The meta-path embedding module is connected to the meta-path discovery module and is used to obtain the meta-path embedding representation through a hierarchical attention network based on the high-risk meta-path set and the characteristics of each type of node;
[0047] The fraud probability prediction module is connected with the node embedding module and the meta-path embedding module to fuse the embedding representation of each transaction node with the meta-path embedding representation to predict the fraud probability of the transaction node;
[0048] The output module is connected to the fraud probability prediction module and is used to mark the transaction nodes whose fraud probability is greater than or equal to the fraud threshold as fraud transactions.
[0049] The embodiments of the present invention have the following technical effects:
[0050] This solution builds a heterogeneous graph structure, incorporates multi-dimensional entities such as users, merchants, and devices into a unified analysis framework, and combines a dynamic weight mechanism to quantify dynamic features such as time sensitivity and user activity of transaction nodes, breaking through the traditional method's reliance on static features; in addition, this solution explores a set of high-risk meta-paths through reinforcement learning agents, and combines a hierarchical attention network to achieve multi-path feature fusion, which can automatically discover cross-entity fraud links such as "abnormal devices-new registered users-high-complaint merchants", significantly improving the ability to identify complex fraud behaviors; the transaction node embeddings generated by the time-series graph network carry dynamic behavioral features, and the meta-path embeddings encode cross-entity association patterns. The splicing operation of the two establishes a complementary relationship while retaining their respective information advantages, enabling the system to improve the recognition accuracy of transaction fraud behaviors and provide an intelligent solution for transaction security protection. BRIEF DESCRIPTION OF THE DRAWINGS
[0051] In order to more clearly illustrate the specific implementation methods of the present invention or the technical solutions in the prior art, the drawings required for use in the specific implementation methods or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are some implementation methods of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0052] Figure 1 is a flow chart of a transaction fraud detection method based on a graph neural network provided by an embodiment of the present invention;
[0053] Figure 2 It is a schematic diagram of a process of discovering a high-risk meta-path provided by an embodiment of the present invention;
[0054] Figure 3 It is a schematic diagram of a periodic coding of a transaction timestamp provided by an embodiment of the present invention;
[0055] Figure 4 is a transaction fraud probability distribution histogram provided by an embodiment of the present invention;
[0056] Figure 5 It is a structural diagram of a transaction fraud detection system based on graph neural network provided in an embodiment of the present invention. DETAILED DESCRIPTION
[0057] In order to make the purpose, technical solution and advantages of the present invention clearer, the technical solution of the present invention will be described clearly and completely below. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work belong to the scope of protection of the present invention.
[0058] This paper proposes a transaction fraud detection method based on graph neural network. Figure 1 is a flowchart of a transaction fraud detection method based on a graph neural network provided by an embodiment of the present invention, see Figure 1 , specifically including:
[0059] S1. Obtain user data, transaction data and merchant data of the trading platform, and generate a heterogeneous graph including transaction nodes, user nodes, product nodes, merchant nodes, device nodes and IP address nodes.
[0060] In some embodiments, user data may include: user ID, device ID, login IP address, etc.; transaction data may include: transaction ID, product category, product ID, transaction timestamp t0, payment amount a, coupon usage identifier c, etc.; merchant data may include: merchant ID, merchant registration time, merchant historical complaint rate r, etc.
[0061] The node types defined in the heterogeneous graph include transaction nodes (T), user nodes (U), product nodes (P), merchant nodes (S), device nodes (D) and IP address nodes (IP); the edge types defined may include but are not limited to: purchase edge (U→T), transaction edge (T→P), supply edge (S→P), login edge (U→D / IP), etc.
[0062] By integrating multi-source data to build a heterogeneous graph structure, entities such as users, merchants, and commodities in the trading platform are abstracted into different types of nodes, and the transaction behavior is used as a central node to establish connections with other entities. For example, a single transaction node will be associated with the user node that initiated the payment, the merchant node that provided the commodity, the terminal device node used, and the IP address node when the transaction occurred. This multi-dimensional connection relationship provides a topological basis for subsequent analysis.
[0063] S2. Calculate the dynamic weight of each transaction node based on the transaction data.
[0064] In some embodiments, the calculation formula of the dynamic weight of each transaction node is as follows:
[0065] ;
[0066] Among them, ω Trepresents the dynamic weight of the Tth transaction node, Δt represents the difference between the current time and the transaction timestamp, c represents the coupon usage identifier, a represents the payment amount, and A u represents user activity, r represents the merchant’s historical complaint rate, and α represents the time decay coefficient.
[0067] in, The time decay factor dynamically adjusts the risk weight of the transaction node through the time decay factor. The decay coefficient of recent transactions (such as within 1 hour) is close to 1, retaining the complete risk signal; while the weight of historical transactions (such as 3 days ago) decreases exponentially to avoid outdated data interfering with model judgment. For example, the weight of a user's high-frequency transaction at 3 a.m. is extremely high when it occurs, but after 72 hours, its weight may decay to less than 5% of the initial value.
[0068] The coupon usage identifier c is used to mark abnormal promotional activities, so that high-value preferential transactions (when a is large) receive higher risk weights; the merchant's historical complaint rate r is used to indicate that the weight of merchant-related transactions with high complaint rates should be increased. Integrating features such as coupon usage, payment amount, user behavior, and merchant reputation, dynamic weights are used to filter out transactions that need to be monitored, thereby improving detection accuracy.
[0069] Furthermore, the calculation formula for user activity is as follows:
[0070] ;
[0071] Where k represents the kth transaction associated with the user, n represents the total number of transactions associated with the user, and a k represents the payment amount of the kth transaction, Δt k Indicates the difference between the current time and the transaction timestamp of the kth transaction.
[0072] User activity is used to characterize the spatiotemporal regularity of user transaction behavior. By calculating user activity, the intensity and density of user historical transactions can be quantified, such as high-frequency low-amount users, low-frequency high-amount users, etc. When the activity changes suddenly, it may indicate that the account has abnormal behavior or has been stolen. Using user activity as one of the core parameters of dynamic weights can improve complex fraud models while reducing the probability of misjudgment of normal user behavior.
[0073] S3. Generate a set of high-risk meta-paths based on heterogeneous graphs through reinforcement learning agents.
[0074] Among them, the high-risk meta-path set includes the associated paths between transaction nodes and other types of nodes.
[0075] In some embodiments, S3 includes the following sub-steps:
[0076] S31. Define the state space of the reinforcement learning agent as the current meta-path, the action space as the node type expanded based on the current meta-path, and the reward function as the weighted sum of the proportion of fraudulent samples in the path and the transaction weight.
[0077] Figure 2 is a schematic diagram of a high-risk meta-path discovery process provided by an embodiment of the present invention, see Figure 2 , the state space is the currently constructed meta-path sequence. For example, the initial state is a single transaction node path T1, and the initial state space only contains transaction node T1. The action space is to expand new node types based on the node type at the end of the current meta-path. For example, if the current meta-path is transaction→user, the extensible actions include but are not limited to: user→device, user→IP address, etc. When expanding new node types, priority is given to expanding to high reward directions. After expanding new node types to the end of the current meta-path, the meta-path sequence in the state space is also updated until the preset maximum path length is reached.
[0078] In this embodiment, the calculation formula of the reward function is as follows:
[0079] ;
[0080] Among them, R represents the reward value of the meta-path, N fraud represents the number of fraud samples in the meta-path. Fraud samples refer to transaction data records marked as fraudulent. N total represents the total number of samples in the meta-path, λ represents the weight coefficient, T represents the Tth transaction node, p represents the meta-path in the high-risk meta-path set, ω T Indicates the dynamic weight of the Tth transaction node.
[0081] S32. Explore paths in the heterogeneous graph through a reinforcement learning agent, and retain paths whose cumulative reward values exceed a preset threshold to obtain a high-risk meta-path set.
[0082] The reward value of each path is calculated. If the reward value is greater than the preset threshold, the path is retained in the high-risk meta-path set P. This mechanism effectively balances pattern coverage and computational efficiency, and can not only discover complex fraud links across entities, but also avoid blind searches in infinite path space.
[0083] S4. According to the dynamic weight and transaction data of each transaction node, the embedded representation of each transaction node is updated through the time-series graph network.
[0084] In some embodiments, S4 includes the following sub-steps:
[0085] S41. Extract features according to the transaction timestamps corresponding to each transaction node in the transaction data to generate transaction cycle features of each transaction node.
[0086] Figure 3 is a schematic diagram of a periodic coding of a transaction timestamp provided by an embodiment of the present invention, see Figure 3 , S41 specifically includes:
[0087] Convert transaction timestamps in transaction data into hour units;
[0088] For example, the timestamp "2023-10-01 15:30:00" corresponds to t=15.5.
[0089] Calculate the transaction cycle characteristics of each node based on the converted transaction timestamp and cycle encoding function;
[0090] The calculation formula of the periodic encoding function is as follows:
[0091] ;
[0092] in, It represents the transaction cycle characteristics of the Tth transaction node, t' represents the converted transaction timestamp, and 24 represents 24 hours a day.
[0093] For example, if t=3 (3 am), the transaction cycle characteristics of the transaction node are:
[0094] .
[0095] See also Figure 3 , the timestamp of each transaction node is converted into a periodic code with hourly granularity, and the phase characteristics of the sine-cosine function are used to capture the fluctuations of transaction patterns within the daily cycle. The combined input of dynamic weights and periodic features enables the graph neural network to distinguish the importance differences of transaction behaviors in different time periods when aggregating neighborhood information. For example, abnormal large transactions in the early morning hours will be given higher attention than regular transactions during normal hours. This time-series-aware embedding update mechanism significantly enhances the model's ability to capture the instantaneous characteristics of fraudulent behavior.
[0096] S42: Input the dynamic weight of each transaction node and the corresponding transaction cycle characteristics into the timing graph network, and update the embedded representation of each transaction node.
[0097] Specifically, according to the dynamic weight of each transaction node and the corresponding transaction cycle characteristics, the timing graph network is input to obtain the maintenance memory state of each transaction node:
[0098] ;
[0099] Among them, m T Indicates the maintenance memory state of the Tth transaction node, m T (t)represents the maintenance memory state of the Tth transaction node at the tth time step, f T Indicates the basic features of the Tth transaction node (such as amount, product category, etc.).
[0100] The neighbor nodes of the transaction node are weighted and aggregated according to time proximity:
[0101] ;
[0102] Among them, h N(T) represents the aggregation result, N(T) represents the set of neighbor nodes of transaction node T, T'∈N(T) represents other transaction nodes associated with neighbor nodes, T' represents other transaction nodes, m T’ It represents the maintenance memory state of transaction node T', t0 represents the transaction timestamp of transaction node T, t0' represents the transaction timestamp of transaction node T', and β represents the time decay strength adjustment factor.
[0103] The updated embedding representation of the transaction node is obtained based on the node’s own memory and neighbor aggregation results:
[0104] ;
[0105] Among them, h T TGN represents the updated embedding representation of the transaction node T, || represents vector concatenation, and MLP represents a multi-layer perceptron, which is used to implement nonlinear transformation.
[0106] S5. Based on the high-risk meta-path set and the characteristics of each type of node, the meta-path embedding representation is obtained through a hierarchical attention network.
[0107] The specific process is as follows:
[0108] The high-risk meta-path set and the characteristics of each type of node (such as the dynamic weight ω of the transaction node) T , Trading cycle characteristics , payment amount a, etc.) are input into the hierarchical attention network to obtain node-level attention and path-level attention:
[0109] ;
[0110] in, represents the attention weight of node v in meta-path p, h u represents the original feature vector of node u, h v' represents the original feature vector of node v', W p Represents the node feature transformation matrix of the meta-path p, a p represents the node-level attention vector of meta-path p, τ represents the activation function, represents the set of neighbor nodes directly connected to node v in meta-path p, and v' represents the central node in meta-path p (i.e., transaction node T).
[0111] ;
[0112] ;
[0113] in, represents the path-level attention weight of meta-path p, represents the node-level aggregate feature vector of meta-path p, represents the set of all nodes on the meta-path p, q represents the path and attention vector, M represents the path feature transformation matrix, b represents the bias term, tanh represents the hyperbolic tangent activation function, and p' represents each meta-path in the high-risk meta-path set P.
[0114] The meta-path embedding is obtained based on the path-level attention weights and the node-level aggregated feature vectors:
[0115] ;
[0116] in, Represents a meta-path embedding.
[0117] For each high-risk meta-path, the hierarchical attention network first analyzes the contribution of different types of entity features at the node level, and then evaluates the global importance of different meta-paths at the path level. Those path patterns that frequently appear in known fraud cases will receive higher attention weights. This two-layer attention mechanism not only retains the semantic information of the meta-path, but also realizes the dynamic weighted aggregation of risk features.
[0118] S6. Fusion the embedding representation of each transaction node with the meta-path embedding representation to predict the fraud probability of the transaction node.
[0119] In some embodiments, S6 includes the following sub-steps:
[0120] S61. Concatenate the meta-path embedding representation with the embedding representation of each transaction node, and input the result into a multi-layer perceptron to obtain the final embedding representation of each transaction node.
[0121] The splicing operation is as follows:
[0122] ;
[0123] Among them, h T final Represents the final embedding representation of the T-th transaction node.
[0124] S62. According to the final embedding representation, the fraud probability of the transaction node is calculated by using the Sigmoid function.
[0125] In this embodiment, the calculation formula of the fraud probability of the transaction node is as follows:
[0126] ;
[0127] Among them, y T represents the fraud probability of the Tth transaction node, σ represents the Sigmoid function, w represents the weight vector, and h T final represents the final embedding representation of the Tth transaction node, and b represents the bias term.
[0128] The final fraud probability prediction is achieved through deep fusion of feature space. The transaction node embedding generated by the time-series graph network carries dynamic behavior features, and the meta-path embedding encodes the cross-entity association pattern. The splicing operation of the two establishes a complementary relationship while retaining their respective information advantages. The multi-layer perceptron mines the synergistic effect of these two features through nonlinear transformation, and finally maps the high-dimensional features to fraud probability values through the Sigmoid function. During the entire model training process, the synergy of the dynamic weight mechanism and the attention mechanism enables the system to adaptively adjust its sensitivity to different risk signals. For example, during the intensive transaction period of the promotion season, the monitoring intensity of abnormal device associations is automatically increased, while in normal times, more attention is paid to the mutation pattern of user behavior.
[0129] S7. Mark the transaction nodes whose fraud probability is greater than or equal to the fraud threshold as fraud transactions.
[0130] For example, Figure 4 is a transaction fraud probability distribution histogram provided by an embodiment of the present invention, see Figure 4 , blue indicates normal transactions, and the fraud probability is mainly concentrated in the range of 0~0.3, accounting for 90%; yellow indicates suspicious transactions, and the fraud probability is mainly distributed in the range of 0.3~0.8, accounting for 7%; red indicates fraudulent transactions, and the fraud probability is mainly concentrated in the range of 0.8~1, accounting for 3%. In addition, in this embodiment, thresholds are set at the fraud probability of 0.6 and 0.85, respectively, where 0.6 is the suspicious threshold and 0.85 is the fraud threshold. When the fraud probability of the transaction is less than 0.6, manual review is not triggered. When 0.6≤the fraud probability of the transaction is less than 0.85, manual review is triggered. When the fraud probability of the transaction is ≥0.85, it is automatically intercepted and marked as a fraudulent transaction.
[0131] This solution builds a heterogeneous graph structure, incorporates multi-dimensional entities such as users, merchants, and devices into a unified analysis framework, and combines a dynamic weight mechanism to quantify dynamic features such as time sensitivity and user activity of transaction nodes, breaking through the traditional method's reliance on static features; in addition, this solution explores a set of high-risk meta-paths through reinforcement learning agents, and combines a hierarchical attention network to achieve multi-path feature fusion, which can automatically discover cross-entity fraud links such as "abnormal devices-new registered users-high-complaint merchants", significantly improving the ability to identify complex fraud behaviors; the transaction node embeddings generated by the time-series graph network carry dynamic behavioral features, and the meta-path embeddings encode cross-entity association patterns. The splicing operation of the two establishes a complementary relationship while retaining their respective information advantages, enabling the system to improve the recognition accuracy of transaction fraud behaviors and provide an intelligent solution for transaction security protection.
[0132] Figure 5 is a schematic diagram of the structure of a transaction fraud behavior detection system based on a graph neural network provided in an embodiment of the present invention, and the system is used to execute the transaction fraud behavior detection method based on a graph neural network described in the above embodiment, such as Figure 5 As shown, the system includes the following modules:
[0133] A heterogeneous graph construction module is used to obtain user data, transaction data and merchant data of the trading platform and generate a heterogeneous graph containing transaction nodes, user nodes, commodity nodes, merchant nodes, device nodes and IP address nodes;
[0134] The dynamic weight calculation module is connected to the heterogeneous graph construction module and is used to calculate the dynamic weight of each transaction node based on the transaction data;
[0135] The meta-path discovery module is connected to the heterogeneous graph construction module and is used to generate a high-risk meta-path set based on the heterogeneous graph through a reinforcement learning agent; the high-risk meta-path set includes the associated paths between transaction nodes and other types of nodes;
[0136] A node embedding module, connected to the dynamic weight calculation module, is used to update the embedding representation of each transaction node through a time-series graph network according to the dynamic weight and transaction data of each transaction node;
[0137] The meta-path embedding module is connected to the meta-path discovery module and is used to obtain the meta-path embedding representation through a hierarchical attention network based on the high-risk meta-path set and the characteristics of each type of node;
[0138] The fraud probability prediction module is connected with the node embedding module and the meta-path embedding module to fuse the embedding representation of each transaction node with the meta-path embedding representation to predict the fraud probability of the transaction node;
[0139] The output module is connected to the fraud probability prediction module and is used to mark the transaction nodes whose fraud probability is greater than or equal to the fraud threshold as fraud transactions.
[0140] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or replace some or all of the technical features therein by equivalents. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the technical solutions of the embodiments of the present invention.
Claims
1. A transaction fraud detection method based on graph neural network, characterized in that: The steps include: S1. Obtain user data, transaction data and merchant data of the trading platform, and generate a heterogeneous graph including transaction nodes, user nodes, commodity nodes, merchant nodes, device nodes and IP address nodes; S2. Calculate the dynamic weight of each transaction node according to the transaction data; S3. generating a set of high-risk meta-paths through a reinforcement learning agent according to the heterogeneous graph; The high-risk meta-path set includes associated paths between transaction nodes and other types of nodes; S4. updating the embedded representation of each transaction node through a time-series graph network according to the dynamic weight of each transaction node and the transaction data; S5. Based on the high-risk meta-path set and the characteristics of each type of node, the meta-path embedding representation is obtained through a hierarchical attention network; S6. Fusing the embedding representation of each transaction node with the meta-path embedding representation to predict the fraud probability of the transaction node; S7. Mark the transaction nodes whose fraud probability is greater than or equal to the fraud threshold as fraud transactions.
2. The transaction fraud detection method based on graph neural network according to claim 1 is characterized in that: In S2, the dynamic weight of each transaction node is calculated according to the transaction data, and the calculation formula is as follows: ; Among them, ω T represents the dynamic weight of the Tth transaction node, Δt represents the difference between the current time and the transaction timestamp, c represents the coupon usage identifier, a represents the payment amount, and A u represents user activity, r represents the merchant’s historical complaint rate, and α represents the time decay coefficient.
3. The transaction fraud detection method based on graph neural network according to claim 2 is characterized in that: The calculation formula of the user activity is as follows: ; Where k represents the kth transaction associated with the user, n represents the total number of transactions associated with the user, and a k represents the payment amount of the kth transaction, Δt k Indicates the difference between the current time and the transaction timestamp of the kth transaction.
4. The transaction fraud detection method based on graph neural network according to claim 2 is characterized in that: In S3, generating a high-risk meta-path set by a reinforcement learning agent according to the heterogeneous graph includes: S31. Define the state space of the reinforcement learning agent as the current meta-path, the action space as the node type expanded based on the current meta-path, and the reward function as the weighted sum of the proportion of fraudulent samples in the path and the transaction weight; S32. Explore paths in the heterogeneous graph through the reinforcement learning agent, and retain paths whose cumulative reward values exceed a preset threshold to obtain a high-risk meta-path set.
5. The transaction fraud detection method based on graph neural network according to claim 4 is characterized in that: In S31, the calculation formula of the reward function is as follows: ; Among them, R represents the reward value of the meta-path, N fraud represents the number of fraud samples in the meta-path, N total represents the total number of samples in the meta-path, λ represents the weight coefficient, T represents the Tth transaction node, p represents the meta-path in the high-risk meta-path set, ω T Indicates the dynamic weight of the Tth transaction node.
6. The transaction fraud detection method based on graph neural network according to claim 1 is characterized in that: In S4, updating the embedded representation of each transaction node through a time-series graph network according to the dynamic weight of each transaction node and the transaction data includes: S41, extracting features according to the transaction timestamps corresponding to each transaction node in the transaction data to generate transaction cycle features of each transaction node; S42: Input the dynamic weight of each transaction node and the corresponding transaction cycle characteristics into the timing graph network, and update the embedded representation of each transaction node.
7. The transaction fraud detection method based on graph neural network according to claim 6 is characterized in that: In S41, feature extraction is performed according to the transaction timestamp corresponding to each transaction node in the transaction data to generate the transaction cycle feature of each transaction node, including: Convert the transaction timestamp in the transaction data into hour units; Calculate the transaction cycle characteristics of each node based on the converted transaction timestamp and cycle encoding function; The calculation formula of the periodic encoding function is as follows: ; in, represents the transaction cycle characteristics of the Tth transaction node, and t' represents the converted transaction timestamp.
8. The transaction fraud detection method based on graph neural network according to claim 1 is characterized in that: In S6, the embedded representation of each transaction node is integrated with the meta-path embedded representation to predict the fraud probability of the transaction node, including: S61, concatenating the meta-path embedding representation with the embedding representation of each transaction node, and inputting the result into a multi-layer perceptron to obtain a final embedding representation of each transaction node; S62. Calculate the fraud probability of the transaction node by using a Sigmoid function according to the final embedded representation.
9. The transaction fraud detection method based on graph neural network according to claim 8 is characterized in that: In S62, the fraud probability of the transaction node is calculated by the Sigmoid function, and the calculation formula is as follows: ; Among them, y T represents the fraud probability of the Tth transaction node, σ represents the Sigmoid function, w represents the weight vector, and h T final represents the final embedding representation of the Tth transaction node, and b represents the bias term.
10. A transaction fraud detection system based on graph neural network, used to implement the transaction fraud detection method based on graph neural network according to any one of claims 1 to 9, characterized in that: The system includes the following modules: A heterogeneous graph construction module is used to obtain user data, transaction data and merchant data of the trading platform and generate a heterogeneous graph containing transaction nodes, user nodes, commodity nodes, merchant nodes, device nodes and IP address nodes; A dynamic weight calculation module, connected to the heterogeneous graph construction module, for calculating the dynamic weight of each transaction node according to the transaction data; A meta-path discovery module, connected to the heterogeneous graph construction module, for generating a set of high-risk meta-paths through a reinforcement learning agent according to the heterogeneous graph; The high-risk meta-path set includes associated paths between transaction nodes and other types of nodes; A node embedding module, connected to the dynamic weight calculation module, for updating the embedding representation of each transaction node through a time-series graph network according to the dynamic weight of each transaction node and the transaction data; A meta-path embedding module, connected to the meta-path discovery module, for obtaining a meta-path embedding representation through a hierarchical attention network according to the high-risk meta-path set and the characteristics of each type of node; A fraud probability prediction module, connected to the node embedding module and the meta-path embedding module, for fusing the embedding representation of each transaction node with the meta-path embedding representation to predict the fraud probability of the transaction node; The output module is connected to the fraud probability prediction module and is used to mark the transaction nodes whose fraud probability is greater than or equal to the fraud threshold as fraud transactions.
Citation Information
Patent Citations
Medical insurance fraud detection algorithm and system based on multilayer attention mechanism graph neural network
CN114463141A
Power grid equipment operation state monitoring method based on multi-modal data joint representation and dynamic weight learning
CN117172413A
Intelligent financial market data analysis and factor mining method
CN118134654A
Fraudulent transaction risk monitoring method and device based on graph neural network, equipment and medium
CN119722106A
Trade process digital optimization method and system
CN119740876A
Cited By
Unmanned aerial vehicle sensor spoofing detection system based on MoE architecture
CN120722394A
Transaction abnormity monitoring system based on multi-source data collaborative analysis
CN120725684A
Financial product abnormal transaction detection method and system based on time-space diagram neural network
CN120822964A
Power market false behavior detection method, system and device, and storage medium
CN120931299A
Abnormal transaction real-time risk control system based on deep learning
CN122264930A