Transaction Fraud Behavior Detection Method and System Based on Graph Neural Network
By adopting a graph-based neural network method in transaction fraud detection, a heterogeneous graph and using dynamic weighting mechanism is constructed, combined with reinforcement learning and a hierarchical attention network, the problem of difficulty in identifying complex transaction fraud in the existing technology is solved, and higher recognition accuracy and intelligent transaction security protection are achieved.
Patent Information
- Application Number
- CN202510452542.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-11
- Publication Date
- 2025-06-20
- Estimated Expiration
- 2045-04-11
AI Technical Summary
The prior art is difficult to effectively detect and identify complex transaction fraud behaviors, especially multi-hop association risks across devices and IPs, and failure to deeply understand the dynamic evolution characteristics of transaction behaviors.
Using a transaction fraud detection method based on graph neural network, by constructing a heterogeneous graph structure, multi-dimensional entities such as users, merchants, and devices are included in the unified analysis framework, and the time sensitivity of trading nodes is quantified in combination with a dynamic weighting mechanism. Use reinforcement learning agents to generate high-risk metapaths and achieve multi-path feature fusion through hierarchical attention networks.
It significantly improves the ability to identify complex fraud behaviors, improves the accuracy of identification of transaction fraud behaviors, and provides an intelligent solution for transaction security protection.
Smart Images

Figure CN119963204B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of transaction fraud detection, and particularly to a method and system for detecting transaction fraud behaviors based on a graph neural network. Background Art
[0002] In the context of the rapid development of the digital economy, transaction fraud has become one of the core risks threatening the healthy development of the business ecosystem. An effective fraud detection mechanism can minimize losses for all parties by early warning of abnormal transactions and blocking the fund transfer link. Meanwhile, the accumulated fraud pattern data can provide decision-making support for optimizing risk control strategies and improving the security authentication system, forming a virtuous cycle of risk prevention and control.
[0003] Currently, the mainstream detection technologies can be divided into three categories: expert systems based on rule engines, classification models based on traditional machine learning, and analysis methods based on simple graph structures. The rule engine intercepts risks by setting hard thresholds (such as the upper limit of the number of daily transactions) or black and white list mechanisms. Although it can quickly respond to known fraud patterns, the rule maintenance cost increases sharply when facing evolving fraud means, and the false alarm rate is relatively high. Traditional machine learning models (such as random forests, gradient boosting trees) learn feature patterns from historical data, but limited by the model architecture, it is difficult to effectively process the temporal correlations and complex network relationships in transaction data. Although the graph neural network technology that has emerged in recent years can capture some correlation features, existing methods mostly adopt fixed paths or shallow attention mechanisms. For example, only the simple path of "user - transaction - merchant" is analyzed, and it is impossible to deeply mine the multi-hop association risks across devices and IPs. More critically, existing technologies lack the ability to model the dynamic evolution characteristics of transaction behaviors. For example, the temporal changes in user activity and the dynamic fluctuations in merchant reputation are not incorporated into the weight calculation, resulting in a lag in the detection of periodic fraud, progressive card skimming and other behaviors.
[0004] Therefore, there is an urgent need for a method and system for detecting transaction fraud behaviors based on a graph neural network, which can improve the recognition accuracy of transaction fraud behaviors and provide an intelligent solution for transaction security protection. Summary of the Invention
[0005] In order to solve the above technical problems, the present invention provides a method and system for detecting transaction fraud behaviors based on a graph neural network, which can improve the recognition accuracy of transaction fraud behaviors and provide an intelligent solution for transaction security protection.
[0006] The present invention provides a method for detecting transaction fraud behaviors based on a graph neural network, including the following steps:
[0007] S1. Obtain user data, transaction data, and merchant data of a trading platform, and generate a heterogeneous graph including transaction nodes, user nodes, commodity nodes, merchant nodes, device nodes, and IP address nodes;
[0008] S2. Calculate the dynamic weights of each transaction node according to the transaction data;
[0009] S3. According to the heterogeneous graph, generate a set of high-risk meta-paths through a reinforcement learning agent; the set of high-risk meta-paths includes the association paths between transaction nodes and other types of nodes;
[0010] S4. According to the dynamic weights of each transaction node and the transaction data, update the embedding representation of each transaction node through a temporal graph network;
[0011] S5. According to the set of high-risk meta-paths and the characteristics of each type of node, obtain the meta-path embedding representation through a hierarchical attention network;
[0012] S6. Fuse the embedding representation of each transaction node and the meta-path embedding representation to predict the fraud probability of the transaction node;
[0013] S7. Mark the transaction nodes with a fraud probability greater than or equal to the fraud threshold as fraudulent transactions.
[0014] Further, in S2, when calculating the dynamic weights of each transaction node according to the transaction data, the calculation formula is as follows:
[0015] ;
[0016] where, ω T represents the dynamic weight of the T-th transaction node, Δt represents the difference between the current time and the transaction timestamp, c represents the coupon usage flag, a represents the payment amount, A u represents the user activity, r represents the historical complaint rate of the merchant, and α represents the time decay coefficient.
[0017] Further, the calculation formula for the user activity is as follows:
[0018] ;
[0019] where, k represents the k-th transaction associated with the user, n represents the total number of transactions associated with the user, a k represents the payment amount of the k-th transaction, and Δt k represents the difference between the current time and the transaction timestamp of the k-th transaction.
[0020] Further, in S3, generating a set of high-risk meta-paths according to the heterogeneous graph through a reinforcement learning agent includes:
[0021] S31. Define the state space of the reinforcement learning agent as the current meta-path, the action space as the node type to be expanded based on the current meta-path, and the reward function as the weighted sum of the proportion of fraud samples in the path and the transaction weight;
[0022] S32. Explore paths in the heterogeneous graph through the reinforcement learning agent, and retain the paths with the cumulative reward value exceeding the preset threshold to obtain the high-risk meta-path set.
[0023] Further, in S31, the calculation formula of the reward function is as follows:
[0024] ;
[0025] Among them, R represents the reward value of the meta-path, N fraud represents the number of fraud samples in the meta-path, N total represents the total number of samples in the meta-path, λ represents the weight coefficient, T represents the T-th transaction node, p represents the meta-path in the high-risk meta-path set, ω T represents the dynamic weight of the T-th transaction node.
[0026] Further, in S4, updating the embedding representation of each transaction node through the temporal graph network according to the dynamic weights and transaction data of each transaction node includes:
[0027] S41. Extract features according to the transaction timestamps corresponding to each transaction node in the transaction data to generate the transaction cycle features of each transaction node;
[0028] S42. Input the dynamic weights and corresponding transaction cycle features of each transaction node into the temporal graph network to update the embedding representation of each transaction node.
[0029] Further, in S41, extracting features according to the transaction timestamps corresponding to each transaction node in the transaction data to generate the transaction cycle features of each transaction node includes:
[0030] Convert the transaction timestamps in the transaction data to hours;
[0031] Calculate the transaction cycle features of each node according to the converted transaction timestamps and the cycle encoding function;
[0032] The calculation formula of the cycle encoding function is as follows:
[0033] ;
[0034] Among them, represents the transaction cycle feature of the T-th transaction node, and t' represents the converted transaction timestamp.
[0035] Further, in S6, fusing the embedding representation of each transaction node and the meta-path embedding representation to predict the fraud probability of the transaction node includes:
[0036] S61. Concatenate the meta-path embedding representation with the embedding representations of each transaction node, and input them into a multi-layer perceptron to obtain the final embedding representation of each transaction node;
[0037] S62. According to the final embedding representation, calculate the fraud probability of the transaction node through the Sigmoid function.
[0038] Furthermore, in S62, the fraud probability of the transaction node is calculated through the Sigmoid function, and the calculation formula is as follows:
[0039] ;
[0040] where y T represents the fraud probability of the T-th transaction node, σ represents the Sigmoid function, w represents the weight vector, and h T final represents the final embedding representation of the T-th transaction node, and b represents the bias term.
[0041] The present invention also provides a transaction fraud behavior detection system based on a graph neural network for executing the transaction fraud behavior detection method based on a graph neural network described in any one of the above, and the system includes the following modules:
[0042] Heterogeneous graph construction module, which is used to obtain user data, transaction data, and merchant data of a transaction platform, and generate a heterogeneous graph including transaction nodes, user nodes, commodity nodes, merchant nodes, device nodes, and IP address nodes;
[0043] Dynamic weight calculation module, connected to the heterogeneous graph construction module, and used to calculate the dynamic weights of each transaction node according to the transaction data;
[0044] Meta-path discovery module, connected to the heterogeneous graph construction module, and used to generate a set of high-risk meta-paths through a reinforcement learning agent according to the heterogeneous graph; the set of high-risk meta-paths includes the association paths between transaction nodes and other types of nodes;
[0045] Node embedding module, connected to the dynamic weight calculation module, and used to update the embedding representations of each transaction node through a temporal graph network according to the dynamic weights of each transaction node and the transaction data;
[0046] Meta-path embedding module, connected to the meta-path discovery module, and used to obtain the meta-path embedding representation through a hierarchical attention network according to the set of high-risk meta-paths and the characteristics of each type of node;
[0047] Fraud probability prediction module, connected to the node embedding module and the meta-path embedding module, and used to fuse the embedding representations of each transaction node and the meta-path embedding representation to predict the fraud probability of the transaction node;
[0048] An output module, connected to the fraud probability prediction module, is configured to mark a transaction node with a fraud probability greater than or equal to a fraud threshold as a fraudulent transaction.
[0049] The embodiments of the present invention have the following technical effects:
[0050] In this solution, by constructing a heterogeneous graph structure, multi-dimensional entities such as users, merchants, and devices are incorporated into a unified analysis framework. Combining a dynamic weight mechanism to quantify dynamic characteristics such as the time sensitivity of transaction nodes and user activity, it breaks through the dependence on static characteristics in traditional methods. In addition, this solution explores a set of high-risk meta-paths through a reinforcement learning agent, and combines a hierarchical attention network to achieve multi-path feature fusion, which can automatically discover cross-entity fraud links such as "abnormal device - newly registered user - highly complained merchant", significantly improving the ability to identify complex fraud behaviors. The transaction node embeddings generated by the temporal graph network carry dynamic behavior characteristics, while the meta-path embeddings encode cross-entity association patterns. The concatenation operation of the two establishes a complementary relationship while retaining their respective information advantages, enabling the system to improve the recognition accuracy of transaction fraud behaviors and providing an intelligent solution for transaction security protection. Description of the Drawings
[0051] In order to more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the following will briefly introduce the drawings required for the description of the specific embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0052] Figure 1 is a flowchart of a method for detecting transaction fraud behaviors based on a graph neural network provided by an embodiment of the present invention;
[0053] Figure 2 is a schematic diagram of the process of discovering high-risk meta-paths provided by an embodiment of the present invention;
[0054] Figure 3 is a schematic diagram of the periodic encoding of a transaction timestamp provided by an embodiment of the present invention;
[0055] Figure 4 is a histogram of the distribution of transaction fraud probabilities provided by an embodiment of the present invention;
[0056] Figure 5 is a schematic diagram of the structure of a system for detecting transaction fraud behaviors based on a graph neural network provided by an embodiment of the present invention. Detailed Embodiments
[0057] To make the objectives, technical solutions, and advantages of the present invention clearer, the technical solutions of the present invention will be described clearly and completely below. Apparently, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the scope protected by the present invention.
[0058] The present invention proposes a method for detecting transaction fraud behavior based on a graph neural network. Figure 1 It is a flowchart of the method for detecting transaction fraud behavior based on a graph neural network provided by an embodiment of the present invention. Refer to Figure 1 , and specifically includes:
[0059] S1. Obtain user data, transaction data, and merchant data of a trading platform, and generate a heterogeneous graph including transaction nodes, user nodes, commodity nodes, merchant nodes, device nodes, and IP address nodes.
[0060] In some embodiments, the user data may include: user ID, device ID, login IP address, etc.; the transaction data may include: transaction ID, commodity category, commodity ID, transaction timestamp t0, payment amount a, coupon usage flag c, etc.; the merchant data may include: merchant ID, merchant registration time, merchant historical complaint rate r, etc.
[0061] Define the node types in the heterogeneous graph to include transaction nodes (T), user nodes (U), commodity nodes (P), merchant nodes (S), device nodes (D), and IP address nodes (IP); define the edge types may include but are not limited to: purchase edge (U→T), transaction edge (T→P), supply edge (S→P), login edge (U→D / IP), etc.
[0062] Construct a heterogeneous graph structure through multi-source data integration. Entities such as users, merchants, and commodities in the trading platform are abstracted into different types of nodes, and the transaction behavior is used as the central node to establish connections with other entities. For example, a single transaction node will be associated with the user node that initiates the payment, the merchant node that provides the commodity, the terminal device node used, and the IP address node at the time of the transaction. This multi-dimensional connection relationship provides a topological basis for subsequent analysis.
[0063] S2. Calculate the dynamic weights of each transaction node according to the transaction data.
[0064] In some embodiments, the calculation formula for the dynamic weights of each transaction node is as follows:
[0065] ;
[0066] where ω TRepresents the dynamic weight of the T-th transaction node, Δt represents the difference between the current time and the transaction timestamp, c represents the coupon usage flag, a represents the payment amount, and A u Represents user activity, r represents the historical merchant complaint rate, and α represents the time decay coefficient.
[0067] Among them, is the time decay factor. The risk weight of the transaction node is dynamically adjusted through the time decay factor. The decay coefficient for recent transactions (such as within 1 hour) approaches 1, retaining the complete risk signal; while the weight of historical transactions (such as 3 days ago) decreases exponentially to avoid interference from outdated data in model judgment. For example, a user's high-frequency transaction at 3 am has a very high weight when it occurs, but its weight may decay to less than 5% of the initial value after 72 hours.
[0068] The coupon usage flag c is used to mark abnormal promotional activities, so that high-amount discount transactions (when a is relatively large) obtain a higher risk weight; the historical merchant complaint rate r is used to indicate an increase in the weight of transactions associated with merchants with a high complaint rate. By integrating features such as coupon usage, payment amount, user behavior, and merchant reputation, the dynamic weight screens out transactions that need to be monitored key points, improving the detection accuracy.
[0069] Furthermore, the calculation formula for user activity is as follows:
[0070] ;
[0071] Among them, k represents the k-th transaction associated with the user, n represents the total number of transactions associated with the user, and a k represents the payment amount of the k-th transaction, and Δt k represents the difference between the current time and the transaction timestamp of the k-th transaction.
[0072] User activity is used to describe the spatio-temporal regularity of user transaction behavior. By calculating user activity, the intensity and density of a user's historical transactions can be quantified, such as high-frequency low-amount users, low-frequency high-amount users, etc. When the activity suddenly changes, it may indicate that there are abnormal behaviors or the account has been stolen. Using user activity as one of the core parameters of the dynamic weight can improve the detection of complex fraud patterns while reducing the probability of misjudging normal user behaviors.
[0073] S3. According to the heterogeneous graph, generate a set of high-risk meta-paths through a reinforcement learning agent.
[0074] Among them, the set of high-risk meta-paths contains the association paths between transaction nodes and other types of nodes.
[0075] In some embodiments, S3 includes the following sub-steps:
[0076] S31. Define the state space of the reinforcement learning agent as the current meta-path, the action space as the node type extended based on the current meta-path, and the reward function as the weighted sum of the proportion of fraud samples in the path and the transaction weight.
[0077] Figure 2 It is a schematic diagram of the process for discovering high-risk meta-paths provided by an embodiment of the present invention. Refer to Figure 2 , the state space is the currently constructed meta-path sequence. For example, the initial state is a single transaction node path T1, and the initial state space only contains the transaction node T1. The action space is to extend new node types based on the type of the end node of the current meta-path. For example, if the current meta-path is transaction → user, the extendable actions include but are not limited to: user → device, user → IP address, etc. When extending new node types, it is preferred to extend to the high-reward direction. After extending a new node type to the end of the current meta-path, the meta-path sequence in the state space is also updated accordingly until the preset maximum path length is reached.
[0078] In this embodiment, the calculation formula of the reward function is as follows:
[0079] ;
[0080] where, R represents the reward value of the meta-path, N fraud represents the number of fraud samples in the meta-path. The fraud sample refers to the transaction data record marked as having fraud behavior. N total represents the total number of samples in the meta-path, λ represents the weight coefficient, T represents the T-th transaction node, p represents the meta-path in the high-risk meta-path set, and ω T represents the dynamic weight of the T-th transaction node.
[0081] S32. Use the reinforcement learning agent to explore paths in the heterogeneous graph, and retain the paths whose cumulative reward value exceeds the preset threshold to obtain the high-risk meta-path set.
[0082] Calculate the reward value of each path. If the reward value is greater than the preset threshold, retain the path in the high-risk meta-path set P. This mechanism effectively balances the pattern coverage and the calculation efficiency, can not only discover complex fraud links across entities, but also avoid blindly searching in the infinite path space.
[0083] S4. Update the embedding representation of each transaction node through the temporal graph network according to the dynamic weight of each transaction node and the transaction data.
[0084] In some embodiments, S4 includes the following sub-steps:
[0085] S41. Extract features according to the transaction timestamps corresponding to each transaction node in the transaction data to generate the transaction cycle features of each transaction node.
[0086] Figure 3 It is a schematic diagram of the periodic encoding of the trading timestamp provided by an embodiment of the present invention. Refer to Figure 3 , S41 specifically includes:
[0087] Convert the trading timestamp in the trading data into hours;
[0088] For example, the timestamp "2023-10-01 15:30:00" corresponds to t = 15.5.
[0089] Calculate the trading cycle characteristics of each node according to the converted trading timestamp and the periodic encoding function;
[0090] The calculation formula of the periodic encoding function is as follows:
[0091] ;
[0092] Among them, represents the trading cycle characteristic of the T-th trading node, t' represents the converted trading timestamp, and 24 represents 24 hours a day.
[0093] Exemplarily, if t = 3 (3 am), the trading cycle characteristic of the trading node is:
[0094] .
[0095] Refer to Figure 3 , the timestamp of each trading node is converted into a periodic encoding with an hourly granularity, and the phase characteristics of the sine and cosine functions are used to capture the trading pattern fluctuations within the daily cycle. The combination input of the dynamic weight and the cycle characteristic enables the graph neural network to distinguish the importance differences of trading behaviors in different time periods when aggregating neighborhood information. For example, an abnormal large transaction in the early morning period will be given higher attention compared to a regular transaction during normal hours. This time-series-aware embedding update mechanism significantly enhances the model's ability to capture the instantaneous characteristics of fraud behaviors.
[0096] S42. Input the dynamic weights and corresponding trading cycle characteristics of each trading node into the time-series graph network to update the embedding representations of each trading node.
[0097] Specifically, according to the dynamic weights and corresponding trading cycle characteristics of each trading node, input them into the time-series graph network to obtain the maintenance memory state of each trading node:
[0098] ;
[0099] Among them, m T represents the maintenance memory state of the T-th trading node, m T (t)Denote the maintenance memory state of the $T$-th transaction node at the $t$-th time step, $f$ T Denote the basic features of the $T$-th transaction node (such as amount, commodity category, etc.).
[0100] Weighted aggregation of the neighbor nodes of the transaction node according to time proximity:
[0101] ;
[0102] where $h$ N(T) Denote the aggregation result, $N(T)$ denote the set of neighbor nodes of the transaction node $T$, $T'\in N(T)$ denote other transaction nodes associated with the neighbor node, $T'$ denote other transaction nodes, $m$ T’ Denote the maintenance memory state of the transaction node $T'$, $t_0$ denote the transaction timestamp of the transaction node $T$, $t_0'$ denote the transaction timestamp of the transaction node $T'$, $\beta$ denote the time decay intensity adjustment factor.
[0103] Obtain the updated embedding representation of the transaction node according to the node's own memory and the neighbor aggregation result:
[0104] ;
[0105] where $h$ T TGN Denote the updated embedding representation of the transaction node $T$, $\|$ denote vector concatenation, MLP denote the multi-layer perceptron, which is used to implement the non-linear transformation.
[0106] S5. According to the high-risk meta-path set and the features of each type of node, obtain the meta-path embedding representation through the hierarchical attention network.
[0107] The specific process is as follows:
[0108] Input the high-risk meta-path set and the features of each type of node (such as the dynamic weight $\omega$ of the transaction node T , the transaction cycle feature , the payment amount $a$, etc.) into the hierarchical attention network to obtain the node-level attention and the path-level attention:
[0109] ;
[0110] where Denote the attention weight of the node $v$ in the meta-path $p$, $h$ u Denote the original feature vector of the node $u$, $h$ v' Denote the original feature vector of the node $v'$, $W$ p Denote the node feature transformation matrix of the meta-path $p$, $a$ p Denote the node-level attention vector of the meta-path $p$, $\tau$ denote the activation function, Denote the set of neighbor nodes directly connected to node v in the meta-path p, and v' represents the central node in the meta-path p (i.e., the transaction node T).
[0111] ;
[0112] ;
[0113] Among them, denotes the path-level attention weight of the meta-path p, denotes the node-level aggregated feature vector of the meta-path p, denotes the set of all nodes on the meta-path p, q represents the path-level attention vector, M represents the path feature transformation matrix, b represents the bias term, tanh represents the hyperbolic tangent activation function, and p' represents each meta-path in the high-risk meta-path set P.
[0114] Obtain the meta-path embedding based on the path-level attention weight and the node-level aggregated feature vector:
[0115] ;
[0116] Among them, denotes the meta-path embedding.
[0117] For each high-risk meta-path in the hierarchical attention network, the network first analyzes the contribution degree of different types of entity features at the node level, and then evaluates the global importance of different meta-paths at the path level. Those path patterns that frequently appear in known fraud cases will obtain higher attention weights. This double-layer attention mechanism not only retains the semantic information of the meta-path but also realizes the dynamic weighted aggregation of risk features.
[0118] S6. Combine the embedding representations of each transaction node and the meta-path embedding representation to predict the fraud probability of the transaction node.
[0119] In some embodiments, S6 includes the following sub-steps:
[0120] S61. Concatenate the meta-path embedding representation with the embedding representations of each transaction node and input them into a multi-layer perceptron to obtain the final embedding representation of each transaction node.
[0121] The concatenation operation is as follows:
[0122] ;
[0123] where h T final denotes the final embedding representation of the T-th transaction node.
[0124] S62. Calculate the fraud probability of the transaction node through the Sigmoid function based on the final embedding representation.
[0125] In this embodiment, the calculation formula for the fraud probability of the transaction node is as follows:
[0126] ;
[0127] where y T represents the fraud probability of the T-th transaction node, σ represents the Sigmoid function, w represents the weight vector, and h T final represents the final embedding representation of the T-th transaction node, and b represents the bias term.
[0128] The final fraud probability prediction is achieved through the deep fusion of the feature space. The transaction node embeddings generated by the temporal graph network carry dynamic behavior features, while the meta-path embeddings encode cross-entity association patterns. The concatenation operation of the two establishes a complementary relationship while retaining their respective information advantages. The multi-layer perceptron mines the synergistic effect of these two features through non-linear transformation, and finally maps the high-dimensional features to fraud probability values through the Sigmoid function. During the entire model training process, the synergistic effect of the dynamic weight mechanism and the attention mechanism enables the system to adaptively adjust the sensitivity to different risk signals. For example, during the intensive trading period of the promotion season, it automatically increases the monitoring intensity for abnormal device associations, while during normal periods, it pays more attention to the mutation patterns of user behavior.
[0129] S7. Mark the transaction nodes with fraud probability greater than or equal to the fraud threshold as fraudulent transactions.
[0130] Exemplarily, Figure 4 is a histogram of the distribution of transaction fraud probabilities provided by an embodiment of the present invention. Refer to Figure 4 . The blue color represents normal transactions, and the fraud probability is mainly concentrated in the range of 0 to 0.3, accounting for 90%; the yellow color represents suspicious transactions, and the fraud probability is mainly distributed in the range of 0.3 to 0.8, accounting for 7%; the red color represents fraudulent transactions, and the fraud probability is mainly concentrated in the range of 0.8 to 1, accounting for 3%. In addition, in this embodiment, thresholds are set at 0.6 and 0.85 for the fraud probability respectively. Among them, 0.6 is the suspicious threshold, and 0.85 is the fraud threshold. When the fraud probability of a transaction < 0.6, no manual review is triggered; when 0.6 ≤ the fraud probability of a transaction < 0.85, a manual re-review is triggered; when the fraud probability of a transaction ≥ 0.85, it is automatically intercepted and marked as a fraudulent transaction.
[0131] This solution constructs a heterogeneous graph structure, incorporates multi-dimensional entities such as users, merchants, and devices into a unified analysis framework, and combines a dynamic weight mechanism to quantify dynamic characteristics such as the time sensitivity of transaction nodes and user activity, breaking through the dependence on static characteristics of traditional methods. In addition, this solution explores a set of high-risk meta-paths through a reinforcement learning agent, and combines a hierarchical attention network to achieve multi-path feature fusion, which can automatically discover cross-entity fraud links such as "abnormal device - newly registered user - highly complained merchant", significantly improving the ability to identify complex fraud behaviors. The transaction node embeddings generated by the temporal graph network carry dynamic behavior characteristics, while the meta-path embeddings encode cross-entity association patterns. The concatenation operation of the two establishes a complementary relationship while retaining their respective information advantages, enabling the system to improve the recognition accuracy of transaction fraud behaviors and providing an intelligent solution for transaction security protection.
[0132] Figure 5 It is a schematic structural diagram of a transaction fraud behavior detection system based on a graph neural network provided by an embodiment of the present invention. This system is used to execute the transaction fraud behavior detection method based on a graph neural network described in the above embodiment, as Figure 5 shown. The system includes the following modules:
[0133] A heterogeneous graph construction module, which is used to obtain user data, transaction data, and merchant data of a trading platform, and generate a heterogeneous graph including transaction nodes, user nodes, commodity nodes, merchant nodes, device nodes, and IP address nodes;
[0134] A dynamic weight calculation module, which is connected to the heterogeneous graph construction module and is used to calculate the dynamic weights of each transaction node according to the transaction data;
[0135] A meta-path discovery module, which is connected to the heterogeneous graph construction module and is used to generate a set of high-risk meta-paths through a reinforcement learning agent according to the heterogeneous graph; the set of high-risk meta-paths includes association paths between transaction nodes and other types of nodes;
[0136] A node embedding module, which is connected to the dynamic weight calculation module and is used to update the embedding representation of each transaction node through a temporal graph network according to the dynamic weights of each transaction node and the transaction data;
[0137] A meta-path embedding module, which is connected to the meta-path discovery module and is used to obtain the meta-path embedding representation through a hierarchical attention network according to the set of high-risk meta-paths and the characteristics of each type of node;
[0138] A fraud probability prediction module, which is connected to the node embedding module and the meta-path embedding module and is used to fuse the embedding representation of each transaction node and the meta-path embedding representation to predict the fraud probability of the transaction node;
[0139] An output module, connected to the fraud probability prediction module, is configured to mark the transaction nodes with a fraud probability greater than or equal to the fraud threshold as fraudulent transactions.
[0140] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them. Although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some or all of the technical features. These modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the technical solutions of the embodiments of the present invention.
Claims
1. A transaction fraud detection method based on graph neural network, characterized in that: The steps include: S1. Obtain user data, transaction data and merchant data of the trading platform, and generate a heterogeneous graph including transaction nodes, user nodes, commodity nodes, merchant nodes, device nodes and IP address nodes; S2. Calculate the dynamic weight of each transaction node according to the transaction data; The calculation formula of the dynamic weight is as follows: ; Among them, ω T represents the dynamic weight of the Tth transaction node, Δt represents the difference between the current time and the transaction timestamp, c represents the coupon usage identifier, a represents the payment amount, and A u represents user activity, r represents the merchant's historical complaint rate, and α represents the time decay coefficient; The calculation formula of the user activity is as follows: ; Where k represents the kth transaction associated with the user, n represents the total number of transactions associated with the user, and a k represents the payment amount of the kth transaction, Δt k Indicates the difference between the current time and the transaction timestamp of the kth transaction; S3. Generate a high-risk meta-path set through a reinforcement learning agent according to the heterogeneous graph; the high-risk meta-path set includes associated paths between transaction nodes and other types of nodes; S4. updating the embedded representation of each transaction node through a time-series graph network according to the dynamic weight of each transaction node and the transaction data; S5. Based on the high-risk meta-path set and the characteristics of each type of node, the meta-path embedding representation is obtained through a hierarchical attention network; S6. Fusing the embedding representation of each transaction node with the meta-path embedding representation to predict the fraud probability of the transaction node; S7. Mark the transaction nodes whose fraud probability is greater than or equal to the fraud threshold as fraud transactions.
2. The transaction fraud detection method based on graph neural network according to claim 1 is characterized in that: In S3, generating a high-risk meta-path set by a reinforcement learning agent according to the heterogeneous graph includes: S31. Define the state space of the reinforcement learning agent as the current meta-path, the action space as the node type expanded based on the current meta-path, and the reward function as the weighted sum of the proportion of fraudulent samples in the path and the transaction weight; S32. Explore paths in the heterogeneous graph through the reinforcement learning agent, and retain paths whose cumulative reward values exceed a preset threshold to obtain a high-risk meta-path set.
3. The transaction fraud detection method based on graph neural network according to claim 2 is characterized in that: In S31, the calculation formula of the reward function is as follows: ; Among them, R represents the reward value of the meta-path, N fraud represents the number of fraud samples in the meta-path, N total represents the total number of samples in the meta-path, λ represents the weight coefficient, T represents the Tth transaction node, p represents the meta-path in the high-risk meta-path set, ω T Indicates the dynamic weight of the Tth transaction node.
4. The transaction fraud detection method based on graph neural network according to claim 1 is characterized in that: In S4, updating the embedded representation of each transaction node through a time-series graph network according to the dynamic weight of each transaction node and the transaction data includes: S41, extracting features according to the transaction timestamps corresponding to each transaction node in the transaction data to generate transaction cycle features of each transaction node; S42: Input the dynamic weight of each transaction node and the corresponding transaction cycle characteristics into the timing graph network, and update the embedded representation of each transaction node.
5. The transaction fraud detection method based on graph neural network according to claim 4 is characterized in that: In S41, feature extraction is performed according to the transaction timestamp corresponding to each transaction node in the transaction data to generate the transaction cycle feature of each transaction node, including: Convert the transaction timestamp in the transaction data into hour units; Calculate the transaction cycle characteristics of each node based on the converted transaction timestamp and cycle encoding function; The calculation formula of the periodic encoding function is as follows: ; in, represents the transaction cycle characteristics of the Tth transaction node, and t' represents the converted transaction timestamp.
6. The transaction fraud detection method based on graph neural network according to claim 1 is characterized in that: In S6, the embedded representation of each transaction node is integrated with the meta-path embedded representation to predict the fraud probability of the transaction node, including: S61, concatenating the meta-path embedding representation with the embedding representation of each transaction node, and inputting the result into a multi-layer perceptron to obtain a final embedding representation of each transaction node; S62. Calculate the fraud probability of the transaction node by using a Sigmoid function according to the final embedded representation.
7. The transaction fraud detection method based on graph neural network according to claim 6 is characterized in that: In S62, the fraud probability of the transaction node is calculated by the Sigmoid function, and the calculation formula is as follows: ; Among them, y T represents the fraud probability of the Tth transaction node, σ represents the Sigmoid function, w represents the weight vector, and h T final represents the final embedding representation of the Tth transaction node, and b represents the bias term.
8. A transaction fraud detection system based on graph neural network, used to implement the transaction fraud detection method based on graph neural network according to any one of claims 1 to 7, characterized in that: The system includes the following modules: A heterogeneous graph construction module is used to obtain user data, transaction data and merchant data of the trading platform and generate a heterogeneous graph containing transaction nodes, user nodes, commodity nodes, merchant nodes, device nodes and IP address nodes; A dynamic weight calculation module, connected to the heterogeneous graph construction module, for calculating the dynamic weight of each transaction node according to the transaction data; A meta-path discovery module, connected to the heterogeneous graph construction module, for generating a set of high-risk meta-paths through a reinforcement learning agent according to the heterogeneous graph; The high-risk meta-path set includes associated paths between transaction nodes and other types of nodes; A node embedding module, connected to the dynamic weight calculation module, for updating the embedding representation of each transaction node through a time-series graph network according to the dynamic weight of each transaction node and the transaction data; A meta-path embedding module, connected to the meta-path discovery module, for obtaining a meta-path embedding representation through a hierarchical attention network according to the high-risk meta-path set and the characteristics of each type of node; A fraud probability prediction module, connected to the node embedding module and the meta-path embedding module, for fusing the embedding representation of each transaction node with the meta-path embedding representation to predict the fraud probability of the transaction node; The output module is connected to the fraud probability prediction module and is used to mark the transaction nodes whose fraud probability is greater than or equal to the fraud threshold as fraud transactions.
Citation Information
Patent Citations
Medical insurance fraud detection algorithm and system based on multilayer attention mechanism graph neural network
CN114463141A
Trade process digital optimization method and system
CN119740876A