Transaction fraud risk prediction method and system based on user behavior logic

By constructing a graph neural differential equation model based on user behavior logic, the problem of difficult to predict transaction fraud risks in the prior art when the timestamp accuracy and completeness are insufficient, and higher prediction accuracy and long-term risk capture capabilities are achieved.

CN119991133AInactive Publication Date: 2025-05-13北京嘉华铭品牌策划有限公司

Patent Information

Application Number
CN202510450007.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-11
Publication Date
2025-05-13
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The prior art is difficult to accurately predict transaction fraud risks in the absence of time stamp accuracy and completeness, and traditional models cannot effectively capture the correlation patterns between long-term data.

Method used

By constructing a graph neural differential equation model based on user behavior logic, a logical adjacency matrix is ​​generated, and virtual dynamic parameters are defined to continuously evolve the state of the event node, a steady-state node state matrix is ​​obtained, and a global risk feature vector is generated through global feature aggregation, and finally, whether the transaction is fraud is determined based on the risk score.

Benefits of technology

This method can accurately judge transaction fraud risks in the absence of timestamps or confusion, improve the prediction accuracy of the model, and capture the latent risks of long-term cycles.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119991133A_ABST
    Figure CN119991133A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of fraud transaction detection, and discloses a transaction fraud risk prediction method and system based on user behavior logic, and the method comprises the steps: generating a logic adjacency matrix according to a user behavior sequence; the user behavior sequence comprises a plurality of event nodes; constructing a graph neural differential equation based on the logic adjacency matrix, and defining virtual kinetic parameters to perform continuous evolution on node states of all event nodes to obtain a steady-state node state matrix of all event nodes; performing global feature aggregation on the steady-state node state matrix to generate a global risk feature vector, and mapping according to the global risk feature vector to obtain a risk score; and judging whether the user behavior sequence is a fraudulent transaction according to the risk score and a fraudulent threshold. According to the method, the transaction fraud risk can be predicted under the condition that the accuracy and integrity of the timestamp are insufficient, and the prediction accuracy of the model is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of fraudulent transaction detection, and in particular relates to a transaction fraud risk prediction method and system based on user behavior logic. Background Art

[0002] As the global digitalization process accelerates, financial behaviors such as mobile payments, cross-border transactions, and instant settlements are growing explosively. At the same time, user behavior data presents multi-source heterogeneous characteristics (such as cross-device logins and online and offline mixed transactions). Traditional methods based on fixed rules or single-dimensional time series modeling are no longer able to cope with complex and changing fraud patterns.

[0003] Existing technologies usually use time-dependent models such as LSTM, GRU, and Transformer, which rely on timestamps to build sequence dependencies and capture time patterns through self-attention or loop structures. When user behaviors come from multiple platforms (such as APP, web pages, and offline devices), system clock asynchrony will lead to timestamp conflicts. In addition, existing models are limited to fixed time windows and cannot capture correlation patterns between long-period data, which in turn causes a decrease in prediction accuracy. Alternatively, rule engines are used to manually define hard-coded rules and directly trigger decisions through logical judgments. However, rule-based transaction interception has poor flexibility and cannot dynamically evaluate complex behavior patterns.

[0004] Therefore, there is an urgent need to develop a transaction fraud risk prediction method and system based on user behavior logic. Summary of the invention

[0005] In order to solve the above technical problems, the present invention provides a transaction fraud risk prediction method and system based on user behavior logic, which can predict transaction fraud risks when the timestamp accuracy and completeness are insufficient, thereby improving the prediction accuracy of the model.

[0006] The present invention provides a transaction fraud risk prediction method based on user behavior logic, the method comprising the following steps:

[0007] S1. Generate a logical adjacency matrix based on the user behavior sequence; the user behavior sequence includes multiple event nodes;

[0008] S2. Construct a graph neural differential equation based on the logical adjacency matrix, define virtual dynamic parameters to continuously evolve the node states of all event nodes, and obtain the steady-state node state matrix of all event nodes;

[0009] S3, performing global feature aggregation on the steady-state node state matrix to generate a global risk feature vector, and obtaining a risk score according to the global risk feature vector mapping;

[0010] S4. Determine whether the user behavior sequence is a fraudulent transaction based on the risk score and the fraud threshold.

[0011] Furthermore, in S1, generating a logical adjacency matrix according to the user behavior sequence includes:

[0012] S11. Define the logical association strength between different event nodes according to preset business rules;

[0013] S12. Obtain a logical adjacency matrix based on the user behavior sequence and the logical association strength between different event nodes.

[0014] Furthermore, in S11, defining the logical association strength between different event nodes according to the preset business rules includes:

[0015] When the first event node is a necessary prerequisite for the second event node, the logical association strength between the first event node and the second event node is defined as a first fixed value;

[0016] Otherwise, the logical association strength between the first event node and the second event node is defined as a second fixed value.

[0017] Furthermore, in S2, a graph neural differential equation is constructed based on the logical adjacency matrix, and virtual dynamic parameters are defined to continuously evolve the node states of all event nodes, and the steady-state node state matrix of all event nodes is obtained, including:

[0018] S21, calculating the initial state vector of each event node to obtain the initial node state matrix;

[0019] S22, defining virtual dynamic parameters, and constructing a state evolution equation according to the logical adjacency matrix and the virtual dynamic parameters;

[0020] S23. Using a differential equation solver, the state evolution equation is solved according to the initial node state matrix and the virtual dynamics parameters to obtain a steady-state node state matrix.

[0021] Furthermore, in S22, the state evolution equation is expressed as follows:

[0022] ;

[0023] Among them, τ is the virtual dynamics parameter, which represents the logical depth, h v (τ) represents the state matrix of the event node v when the logical depth is τ, ReLU represents the nonlinear activation function, LayerNorm represents the layer normalization operation, N(v) represents the set of neighbor nodes of the event node v, and A uv represents the logical association strength between event node u and event node v in the logical adjacency matrix, W g Represents the graph convolution weight matrix.

[0024] Further, in S23, a differential equation solver is used to solve the state evolution equation according to the initial node state matrix and the virtual dynamics parameters, and the steady-state node state matrix is ​​obtained, including:

[0025] ;

[0026] Among them, H(T) represents the steady-state node state matrix, ODESolver represents the differential equation solver, H(τ) represents the state matrix of all event nodes when the logical depth is τ, H0 represents the initial node state matrix, and T represents the termination value of the virtual dynamics parameter.

[0027] Furthermore, in S3, global feature aggregation is performed on the steady-state node state matrix to generate a global risk feature vector. The risk score obtained according to the global risk feature vector mapping includes:

[0028] S31. Calculate the attention weight of each event node according to the steady-state node state matrix;

[0029] S32, performing weighted summation according to the attention weight and the steady-state node state matrix to obtain a global risk feature vector;

[0030] S33. Map the global risk feature vector through a multi-layer perceptron to obtain a risk score.

[0031] Furthermore, in S31, the calculation formula of the attention weight of the event node is as follows:

[0032] ;

[0033] Among them, α v represents the attention weight of event node v, softmax represents the normalized weight operation, W a represents the attention weight parameter, Represents the transposed matrix of the attention weight parameters, h v (T) represents the steady-state node state matrix of event node v.

[0034] Furthermore, in S32, the calculation formula of the global risk feature vector is as follows:

[0035] ;

[0036] Among them, h global represents the global risk feature vector, and n represents the total number of event nodes.

[0037] The present invention also provides a transaction fraud risk prediction system based on user behavior logic, which is used to execute the transaction fraud risk prediction method based on user behavior logic, and is characterized in that the system includes the following modules:

[0038] An adjacency matrix building module is used to generate a logical adjacency matrix according to a user behavior sequence; the user behavior sequence includes multiple event nodes;

[0039] The node state calculation module is connected to the adjacency matrix construction module and is used to construct a graph neural differential equation based on the logical adjacency matrix, define virtual dynamic parameters to continuously evolve the node states of all event nodes, and obtain the steady-state node state matrix of all event nodes;

[0040] The risk score prediction module is connected to the node state calculation module and is used to perform global feature aggregation on the steady-state node state matrix to generate a global risk feature vector, and obtain a risk score based on the global risk feature vector mapping;

[0041] The output module is connected to the risk score prediction module and is used to determine whether the user behavior sequence is a fraudulent transaction based on the risk score and the fraud threshold.

[0042] The embodiments of the present invention have the following technical effects:

[0043] The present invention constructs a logical relationship diagram according to the user's behavioral logic and replaces the physical timeline with a logical topology. The system accurately identifies unconventional links such as reverse operations and cross-platform behavior splicing through mandatory logical constraints and adaptive association discovery between events, and gets rid of the dependence on linear time series. Even if the timestamp is missing or confused, it can still judge the anomaly based on the behavioral logic. Virtual dynamic parameters are constructed according to the logical depth of the user's behavior. According to the continuous evolution mechanism of the virtual parameters, the discrete event sequence can be upgraded to the logical space, so that the latent risks in the user behavior that span a long period of time can also be captured, further improving the prediction accuracy of the model. BRIEF DESCRIPTION OF THE DRAWINGS

[0044] In order to more clearly illustrate the specific implementation methods of the present invention or the technical solutions in the prior art, the drawings required for use in the specific implementation methods or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are some implementation methods of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.

[0045] Figure 1 is a flow chart of a transaction fraud risk prediction method based on user behavior logic provided by an embodiment of the present invention;

[0046] Figure 2 It is a logical adjacency matrix heat map provided by an embodiment of the present invention;

[0047] Figure 3 is an influence diagram of a virtual dynamic parameter τ provided by an embodiment of the present invention;

[0048] Figure 4 This is a performance comparison diagram of the present invention and a traditional timing model provided by an embodiment of the present invention;

[0049] Figure 5 It is a structural diagram of a transaction fraud risk prediction system based on user behavior logic provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0050] In order to make the purpose, technical solution and advantages of the present invention clearer, the technical solution of the present invention will be described clearly and completely below. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work belong to the scope of protection of the present invention.

[0051] The embodiment of the present invention provides a transaction fraud risk prediction method based on user behavior logic. Figure 1 is a flowchart of a transaction fraud risk prediction method based on user behavior logic provided by an embodiment of the present invention, see Figure 1 , the method comprises the following steps:

[0052] S1. Generate a logical adjacency matrix based on the user behavior sequence.

[0053] Among them, the user behavior sequence contains multiple event nodes, each event node contains attributes such as operation type, timestamp, device information, etc.; the operation type may include, for example, login, card binding, payment, password change, etc.

[0054] The generation of the logical adjacency matrix needs to consider the business logic relationship between events, for example, some operations must follow a specific order or dependency conditions. To build a graph structure, discrete events must first be converted into graph nodes, and then the weights of the edges are defined according to preset rules. Unlike traditional graph construction methods that only rely on co-occurrence frequency or temporal proximity, this embodiment replaces the physical timeline with a logical topology.

[0055] In some embodiments, S1 includes the following sub-steps:

[0056] S11. Define the logical association strength between different event nodes according to preset business rules.

[0057] In some embodiments, the preset business rules can be derived from the analysis of known fraud cases and the experience summary of risk control experts. For example, in the payment scenario, the identity authentication event must occur before the fund operation. This strong dependency is reflected in the special assignment of logical association strength. When there is a necessary condition relationship between two events, the association strength is set to a higher value to enhance the information transmission weight; otherwise, a lower value or zero value is assigned. This rule-driven adjacency matrix construction method retains the flexibility of the data-driven model and combines the prior constraints of domain knowledge.

[0058] In some embodiments, defining the logical association strength between different event nodes according to preset business rules may include:

[0059] When the first event node u is a necessary prerequisite for the second event node v, the logical association strength between the first event node and the second event node is defined as a first fixed value;

[0060] Otherwise, the logical association strength between the first event node and the second event node is defined as a second fixed value.

[0061] For example, the first fixed value may be set to 1, and the second fixed value may be set to 0, then the logical association strength A between different event nodes is uv Defined as:

[0062] .

[0063] In some embodiments, the definition method of the logical association strength between different event nodes may be further divided, for example:

[0064] When the first event node u is a necessary prerequisite for the second event node v, the logical association strength between the first event node and the second event node is defined as a first fixed value 1;

[0065] When the first event node u and the second event node v have a precondition relationship but are not a necessary precondition, the logical association strength between the first event node and the second event node is defined as a second fixed value of 0.5;

[0066] In other cases, the logical association strength between the first event node and the second event node is defined as a third fixed value of 0:

[0067] .

[0068] S12. Obtain a logical adjacency matrix based on the user behavior sequence and the logical association strength between different event nodes.

[0069] Figure 2is a logic adjacency matrix heat map provided by an embodiment of the present invention. According to the definition method of further dividing the logical association strength between different event nodes, assuming that the event nodes in the user behavior sequence include login, card binding, payment, and login password modification, the logical association strength between different event nodes is as follows: Figure 2 Through this structured processing, the originally disordered event sequence is transformed into a graph structure with semantic meaning, providing a topological basis for subsequent graph neural network processing.

[0070] S2. Construct a graph neural differential equation based on the logical adjacency matrix, define virtual dynamic parameters to continuously evolve the node states of all event nodes, and obtain the steady-state node state matrix of all event nodes.

[0071] The graph neural differential equation draws on the idea of ​​continuous dynamical systems and simulates the process of information propagation between event nodes by introducing virtual dynamical parameters. In the initial state, the feature vector of each node only contains its own attribute information; as the dynamical parameters advance, the node state is continuously updated through the connection relationship defined by the adjacency matrix, and finally converges to a steady state. This continuous evolution mechanism can capture complex nonlinear relationships between events, such as fraud patterns spanning multiple steps. The steady-state node state matrix contains not only the original event features, but also global risk information transmitted through the graph structure.

[0072] In some embodiments, S2 may include the following sub-steps:

[0073] S21. Calculate the initial state vector of each event node to obtain the initial node state matrix.

[0074] The calculation formula for initializing the event node is as follows:

[0075] ;

[0076] in, represents the initial state vector of event node v, Represents the embedding function of an event node v, which is used to map event types to vectors.

[0077] According to the initial state vectors of all event nodes, the initial node state matrix H0=[ , , ..., ].

[0078] The initial state vector is generated by processing the original event features using an embedding layer. The attributes of each event node are normalized and input into a fully connected network to generate a low-dimensional dense vector. This method can map heterogeneous features into a unified semantic space, retaining key risk signals while reducing the risk of dimensionality disaster.

[0079] S22. Define virtual dynamic parameters, and construct the state evolution equation according to the logical adjacency matrix and the virtual dynamic parameters.

[0080] In some embodiments, the state evolution equation is expressed as follows:

[0081] ;

[0082] Among them, τ is a virtual dynamic parameter, which indicates the logical depth. The continuous change of the virtual dynamic parameter τ simulates the multi-scale characteristics of risk propagation. Shallow evolution (small τ value) mainly captures local event correlation, while deep evolution (large τ value) reveals complex patterns across event chains. v (τ) represents the state matrix of the event node v when the logical depth is τ, ReLU represents the nonlinear activation function, LayerNorm represents the layer normalization operation, and the layer normalization operation can avoid gradient explosion, N(v) represents the set of neighbor nodes of the event node v, and A uv represents the logical association strength between event node u and event node v in the logical adjacency matrix, W g Represents the graph convolution weight matrix.

[0083] Figure 3 is an influence diagram of a virtual dynamic parameter τ provided in an embodiment of the present invention, see Figure 3 , showing the correlation between the virtual dynamic parameter τ and the node state change rate. The horizontal axis represents the virtual time parameter τ, with values ​​increasing gradually from 1.00 to 10.00; the vertical axis quantifies the dynamic change rate of the node state, ranging from 0 to 16 scales; as the value of τ increases, the node state change rate shows a significant positive growth relationship, indicating that the regulation of τ directly controls the dynamic intensity of system evolution. The increase of τ expands the logical depth of node state evolution, allowing the system to capture more complex interaction patterns in the continuous time domain. Compared with the traditional discrete iterative method, this method can adaptively adjust the intensity and scope of information propagation.

[0084] The introduction of virtual dynamic parameters breaks through the layer limit of traditional GNN. By iteratively converting discrete graph convolution layers into a continuous dynamic system, the model can adaptively determine the depth of information propagation. The ReLU activation function in the state evolution equation ensures the extraction of nonlinear features, while the layer normalization operation maintains the gradient stability and avoids the numerical divergence problem during the deep evolution process.

[0085] S23. Using a differential equation solver, the state evolution equation is solved according to the initial node state matrix and the virtual dynamics parameters to obtain a steady-state node state matrix.

[0086] Specifically, the calculation formula is as follows:

[0087] ;

[0088] Wherein, H(T) represents the steady-state node state matrix, ODESolver represents the differential equation solver (exemplarily, the solver type can adopt the Runge-Kutta method), which gradually calculates the state evolution of each event node from τ=0 to τ=T, H(τ) represents the state matrix of all event nodes when the logical depth is τ, H0 represents the initial node state matrix, T represents the termination value of the virtual dynamics parameter, T can be set according to the actual situation, such as by cross-validation optimization, and exemplarily, T can be set to 5.

[0089] S3. Perform global feature aggregation on the steady-state node state matrix to generate a global risk feature vector, and obtain a risk score based on the global risk feature vector mapping.

[0090] The global feature aggregation stage uses the attention mechanism to dynamically measure the contribution of each event node to fraud determination. Since different events have different importance in risk identification, for example, abnormal login behavior may be more risk-indicative than regular browsing, the attention weight can adaptively adjust the aggregation strategy. The weighted summed global vector is input into the multi-layer perceptron for nonlinear transformation, mapping the high-dimensional features into scalar risk scores.

[0091] In some embodiments, S3 includes the following sub-steps:

[0092] S31. Calculate the attention weight of each event node according to the steady-state node state matrix.

[0093] In some embodiments, the calculation formula of the attention weight of the event node is as follows:

[0094] ;

[0095] Among them, α v represents the attention weight of event node v, softmax represents the normalized weight operation, W a represents the attention weight parameter, Represents the transposed matrix of the attention weight parameters, h v (T) represents the steady-state node state matrix of the event node v, and the steady-state node state matrix h v (T) not only contains the attribute characteristics of the event node itself, but also encodes its contextual relationship in the behavior sequence, which enables the attention mechanism to identify risk events with spatiotemporal abnormal patterns, such as different types of operations continuously initiated by the same account on devices in different locations. The mining of such spatiotemporal correlation features significantly improves the model's ability to detect complex fraud strategies.

[0096] S32. Perform weighted summation based on the attention weight and the steady-state node state matrix to obtain a global risk feature vector.

[0097] In some embodiments, the calculation formula of the global risk feature vector is as follows:

[0098] ;

[0099] Among them, h global represents the global risk feature vector, and n represents the total number of event nodes.

[0100] S33. Map the global risk feature vector through a multi-layer perceptron to obtain a risk score.

[0101] In some embodiments, the risk score is calculated as follows:

[0102] ;

[0103] Among them, W f represents the weight of the fully connected layer, b represents the bias term, s represents the risk score, and sigmoid is used to compress the output to the (0,1) interval, which represents the fraud probability.

[0104] S4. Determine whether the user behavior sequence is a fraudulent transaction based on the risk score and the fraud threshold.

[0105] The setting of the fraud threshold can be combined with historical data distribution and business needs, and a reasonable dividing point can be determined by balancing the false alarm rate and the missed alarm rate; if the risk score is greater than or equal to the fraud threshold, the user behavior sequence is judged to be a fraudulent transaction; if the risk score is less than the fraud threshold, the user behavior sequence is judged to be a normal transaction.

[0106] In some embodiments, when the training data is insufficient and the model prediction effect is not accurate enough, the model score (risk score) obtained in S3 and the business rules can be combined to make a hybrid decision, which specifically includes the following operations:

[0107] Sa. Assume that the business rule set includes but is not limited to the following business rules:

[0108] If the payment is made without binding the card, the corresponding risk score is the first;

[0109] Large amount transfers on new devices (e.g. new device login and transfer amount > 50,000 yuan) will correspond to the second risk score;

[0110] High-frequency sensitive operations (such as changing a password and performing a transfer within 5 minutes) correspond to the third risk score.

[0111] Sb, business rule risk score calculation formula is as follows:

[0112] ;

[0113] Among them, s rule represents the risk score of the business rule, k represents the kth business rule, K represents the total number of business rules, and w k represents the weight parameter of the kth business rule, R k Represents the risk score of the kth business rule.

[0114] Sc. Calculate the hybrid risk score based on the risk score output by the S3 model and the business rule risk score. The calculation formula is as follows:

[0115] ;

[0116] Among them, s final represents the hybrid risk score, γ represents the dynamic weight parameter, and its value is [0,1]. For example, the initial weight of γ can be set to 0.7 and adaptively adjusted according to the actual situation.

[0117] Sd, determines whether the user behavior sequence is a fraudulent transaction based on the hybrid risk score and fraud threshold.

[0118] Among them, the fraud threshold can be set by the following method:

[0119] ;

[0120] Among them, s thre represents the fraud threshold, s0 represents the basic threshold, which can be set to 0.5 for example and adjusted dynamically according to the actual situation, s t Represents the risk coefficient corresponding to time period t.

[0121] For example, the risk coefficient ∈ [0, 1] is used to quantify the relative level of fraud risk in a specific time period, for example:

[0122] During the night time period (1:00-5:00 a.m.), due to the reduction of manual review, there may be batch fraud transactions, and the risk factor can be set to 0.6;

[0123] During the holiday shopping peak, due to the surge in transaction volume, there may be fraudulent transactions implemented by fake holiday promotions, and the risk factor can be set to 0.8;

[0124] During the system maintenance window, due to the temporary reduction of security protection, there may be fraudulent transactions that bypass risk control, and the risk factor can be set to 0.5;

[0125] The specific time period and the corresponding risk factor can be set according to actual conditions, including but not limited to the above situations.

[0126] Providing guaranteed decisions through the rule engine can improve prediction accuracy, while providing initial decision-making capabilities and covering edge cases. Edge cases are low-frequency, unconventional but high-impact situations, such as new fraud methods and business rule conflicts (for example, duplicate payments for the same order due to network delays). The rule engine can quickly supplement decision rules for edge cases and reduce the need for model iteration.

[0127] The technical effect of the present invention is further verified through experiments.

[0128] Figure 4 is a performance comparison chart of the present invention and the traditional timing model, see Figure 4 , intuitively comparing the performance of the present invention with two traditional time series models, LSTM and Transformer, in three core performance dimensions (chaos tolerance, long-term modeling capability, and computational efficiency). The horizontal axis represents the three models, and the vertical axis uses a normalized scoring system from 0 to 1. The blue, orange, and green bar graphs correspond to the chaos tolerance, long-term modeling capability, and computational efficiency indicators, respectively.

[0129] In terms of chaos tolerance, the present invention (0.93) significantly surpasses Transformer (0.61) and LSTM (0.44), thanks to its architecture design based on graph neural differential equations. Unlike traditional models that rely on temporal position encoding, the present invention captures the logical dependencies between events through virtual dynamic parameters τ, so that the node state evolution is not affected by the disorder of physical timestamps. For example, when the user behavior sequence shows a complex pattern of alternating device switching and payment operations, the model can still accurately identify the risk transmission path across events.

[0130] In terms of long-term modeling capabilities, both the present invention and Transformer show a high level of scores, far exceeding LSTM's 0.3. This is due to the advantages of both in processing long-term dependencies: the present invention achieves infinite-step information propagation through continuous differential equations, breaking through the layer limit of traditional GNN; Transformer uses the self-attention mechanism to capture global correlations.

[0131] However, the present invention has made further breakthroughs in the dimension of computational efficiency. Its core lies in the optimized calculation of sparse graph structures by the differential equation solver, which significantly reduces resource consumption compared to the quadratic complexity of Transformer.

[0132] The overall trend of the three sets of data reveals that the present invention, while maintaining long-term modeling capabilities, has achieved a leap-forward improvement in two key indicators, disordered data processing and computing resource utilization, through the combination of graph structure modeling and continuous power systems. It is suitable for complex behavior pattern detection such as multi-device jumps and asynchronous operations.

[0133] The present invention constructs a logical relationship diagram according to the user's behavioral logic and replaces the physical timeline with a logical topology. The system accurately identifies unconventional links such as reverse operations and cross-platform behavior splicing through mandatory logical constraints and adaptive association discovery between events, and gets rid of the dependence on linear time series. Even if the timestamp is missing or confused, it can still judge the anomaly based on the behavioral logic. Virtual dynamic parameters are constructed according to the logical depth of the user's behavior. According to the continuous evolution mechanism of the virtual parameters, the discrete event sequence can be upgraded to the logical space, so that the latent risks in the user behavior that span a long period of time can also be captured. The entire process transforms the discrete event sequence into a dynamic system in a continuous space, and realizes the hierarchical extraction of risk features through end-to-end learning, further improving the prediction accuracy of the model.

[0134] The embodiment of the present invention also provides a transaction fraud risk prediction system based on user behavior logic, which is used to execute the transaction fraud risk prediction method based on user behavior logic. Figure 5 is a schematic diagram of the structure of a transaction fraud risk prediction system based on user behavior logic provided by an embodiment of the present invention, see Figure 5 , the system includes the following modules:

[0135] An adjacency matrix building module is used to generate a logical adjacency matrix according to a user behavior sequence; the user behavior sequence includes multiple event nodes;

[0136] The node state calculation module is connected to the adjacency matrix construction module and is used to construct a graph neural differential equation based on the logical adjacency matrix, define virtual dynamic parameters to continuously evolve the node states of all event nodes, and obtain the steady-state node state matrix of all event nodes;

[0137] The risk score prediction module is connected to the node state calculation module and is used to perform global feature aggregation on the steady-state node state matrix to generate a global risk feature vector, and obtain a risk score based on the global risk feature vector mapping;

[0138] The output module is connected to the risk score prediction module and is used to determine whether the user behavior sequence is a fraudulent transaction based on the risk score and the fraud threshold.

[0139] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or replace some or all of the technical features therein by equivalents. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the technical solutions of the embodiments of the present invention.

Claims

1. A transaction fraud risk prediction method based on user behavior logic, characterized in that: The method comprises the following steps: S1. Generate a logical adjacency matrix according to a user behavior sequence; the user behavior sequence includes multiple event nodes; S2. Constructing a graph neural differential equation based on the logical adjacency matrix, defining virtual dynamic parameters to continuously evolve the node states of all event nodes, and obtaining a steady-state node state matrix of all event nodes; S3, performing global feature aggregation on the steady-state node state matrix to generate a global risk feature vector, and obtaining a risk score according to the global risk feature vector mapping; S4. Determine whether the user behavior sequence is a fraudulent transaction based on the risk score and the fraud threshold.

2. The transaction fraud risk prediction method based on user behavior logic according to claim 1 is characterized in that: In S1, generating a logical adjacency matrix according to the user behavior sequence includes: S11. Define the logical association strength between different event nodes according to preset business rules; S12. Obtain a logical adjacency matrix based on the user behavior sequence and the logical association strength between different event nodes.

3. The transaction fraud risk prediction method based on user behavior logic according to claim 2 is characterized in that: In S11, defining the logical association strength between different event nodes according to the preset business rules includes: When the first event node is a necessary prerequisite for the second event node, the logical association strength between the first event node and the second event node is defined as a first fixed value; Otherwise, the logical association strength between the first event node and the second event node is defined as a second fixed value.

4. The transaction fraud risk prediction method based on user behavior logic according to claim 1 is characterized in that: In S2, a graph neural differential equation is constructed based on the logical adjacency matrix, and virtual dynamic parameters are defined to continuously evolve the node states of all event nodes, and the steady-state node state matrix of all event nodes is obtained, including: S21, calculating the initial state vector of each event node to obtain the initial node state matrix; S22, defining virtual dynamic parameters, and constructing a state evolution equation according to the logical adjacency matrix and the virtual dynamic parameters; S23. Using a differential equation solver to solve the state evolution equation according to the initial node state matrix and the virtual dynamics parameters, to obtain the steady-state node state matrix.

5. The transaction fraud risk prediction method based on user behavior logic according to claim 4 is characterized in that: In S22, the state evolution equation is expressed as follows: ; Among them, τ is the virtual dynamics parameter, which represents the logical depth, h v (τ) represents the state matrix of the event node v when the logical depth is τ, ReLU represents the nonlinear activation function, LayerNorm represents the layer normalization operation, N(v) represents the set of neighbor nodes of the event node v, and A uv represents the logical association strength between event node u and event node v in the logical adjacency matrix, W g Represents the graph convolution weight matrix.

6. The transaction fraud risk prediction method based on user behavior logic according to claim 5 is characterized in that: In S23, using a differential equation solver to solve the state evolution equation according to the initial node state matrix and the virtual dynamics parameters to obtain the steady-state node state matrix includes: ; Among them, H(T) represents the steady-state node state matrix, ODESolver represents the differential equation solver, H(τ) represents the state matrix of all event nodes when the logical depth is τ, H0 represents the initial node state matrix, and T represents the termination value of the virtual dynamics parameter.

7. The transaction fraud risk prediction method based on user behavior logic according to claim 1 is characterized in that: In S3, performing global feature aggregation on the steady-state node state matrix to generate a global risk feature vector, and obtaining a risk score according to the global risk feature vector mapping includes: S31, calculating the attention weight of each event node according to the steady-state node state matrix; S32, performing weighted summation according to the attention weight and the steady-state node state matrix to obtain the global risk feature vector; S33. Map the global risk feature vector through a multi-layer perceptron to obtain a risk score.

8. The transaction fraud risk prediction method based on user behavior logic according to claim 7 is characterized in that: In S31, the calculation formula of the attention weight of the event node is as follows: ; Among them, α v represents the attention weight of event node v, softmax represents the normalized weight operation, W a represents the attention weight parameter, Represents the transposed matrix of the attention weight parameters, h v (T) represents the steady-state node state matrix of event node v.

9. The transaction fraud risk prediction method based on user behavior logic according to claim 8 is characterized in that: In S32, the calculation formula of the global risk feature vector is as follows: ; Among them, h global represents the global risk feature vector, and n represents the total number of event nodes.

10. A transaction fraud risk prediction system based on user behavior logic, used to execute the transaction fraud risk prediction method based on user behavior logic according to any one of claims 1 to 9, characterized in that: The system includes the following modules: An adjacency matrix construction module, used to generate a logical adjacency matrix according to a user behavior sequence; the user behavior sequence includes a plurality of event nodes; A node state calculation module, connected to the adjacency matrix construction module, is used to construct a graph neural differential equation based on the logical adjacency matrix, define virtual dynamic parameters to continuously evolve the node states of all event nodes, and obtain a steady-state node state matrix of all event nodes; A risk score prediction module, connected to the node state calculation module, is used to perform global feature aggregation on the steady-state node state matrix to generate a global risk feature vector, and obtain a risk score according to the global risk feature vector mapping; The output module is connected to the risk score prediction module and is used to determine whether the user behavior sequence is a fraudulent transaction based on the risk score and the fraud threshold.

Citation Information

Patent Citations

  • Dynamic graph fraud detection method based on Transform causal chain

    CN116579848A

  • Method and device for detecting fraudulent account

    CN117993914A

  • Risk-embedded multi-relational graph fraud detection method

    CN118096162A

  • Business risk prediction method and system based on big data analysis

    CN118469298A

  • Anti-fraud detection dynamic graph model construction method and system based on layered attention

    CN119006155A

Cited By

  • ETC fraud detection method

    CN120493249A