Abnormal data detection method and device, equipment, medium and program product
By constructing a dynamic graph of trading activities and extracting the characteristics of trading accounts, and using deep learning models to process these features, the problem of abnormal behavior detection in trading data is solved, and more efficient and accurate identification of fraud is achieved.
Patent Information
- Application Number
- CN202510188983.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-20
- Publication Date
- 2025-05-16
AI Technical Summary
How to automatically, quickly and accurately detect abnormal behaviors in transaction data and identify fraudulent activities, challenges to regulators.
By constructing a dynamic graph of trading activities, the spatial and temporal characteristics of the trading account are extracted, and the graph convolutional neural network and self-attention mechanism are used for processing, and vector representation is generated to determine abnormal transaction data.
It improves the accuracy and efficiency of abnormal data detection, can capture the complexity and dynamics of trading behavior more accurately, and enhances the risk control capabilities of the trading system.
Smart Images

Figure CN120013669A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the fields of financial technology and big data technology, and specifically to an abnormal data detection method, device, equipment, medium and program product. Background Art
[0002] Financial fraud refers to the act of obtaining financial benefits through dishonest means, which not only disrupts the order of the financial market, but also damages social and economic development, and may contribute to the spread of other illegal and criminal activities. With the popularization of the Internet and online payments, many fraudulent activities have shifted from traditional offline to online, which has brought huge challenges to regulators. Compared with normal transaction data, the transaction data generated by fraudulent activities in transaction activities often show abnormalities and have different data characteristics. Therefore, how to automatically, quickly and accurately detect these abnormal transaction data, so as to identify the corresponding fraudulent behavior, has become an urgent problem that needs to be solved. Summary of the invention
[0003] In view of the above problems, the present disclosure provides an abnormal data detection method, apparatus, device, medium and program product for improving the accuracy and efficiency of abnormal data detection.
[0004] According to a first aspect of the present disclosure, there is provided an abnormal data detection method, comprising: constructing a dynamic graph of the transaction activity based on the transaction data in the transaction activity, the dynamic graph representing the change of the transaction relationship between the transaction accounts over time; extracting the spatial features and temporal features of each transaction account in the dynamic graph, the spatial features representing the transaction behavior characteristics of the transaction account in the transaction activity, and the temporal features representing the behavior change law of the transaction account; adding and aggregating the spatial features and temporal features of each transaction account by row elements to obtain a vector representation of the corresponding transaction account; and determining the abnormal transaction data in the transaction activity according to the vector representation.
[0005] According to an embodiment of the present disclosure, a dynamic graph of transaction activities is constructed based on transaction data in transaction activities, including: constructing static graphs of different time periods based on the transaction data, wherein each static graph shares the same node set and has an independent edge set, the nodes in the node set represent transaction accounts, and the edges in the edge set represent transaction relationships between transaction accounts; and concatenating the static graphs into a dynamic graph in chronological order.
[0006] According to an embodiment of the present disclosure, the spatial features and temporal features of each transaction account in the dynamic graph are extracted, including: using a graph convolutional neural network layer to process each static graph in the dynamic graph to generate the spatial features of each node; using an adjacency coding layer based on a self-attention mechanism to process the dynamic graph to generate the temporal features of each node.
[0007] According to an embodiment of the present disclosure, a graph convolutional neural network layer is used to process each static graph in a dynamic graph to generate spatial features of each node, including: symmetric normalization of the adjacency matrix of each static graph; based on the normalized adjacency matrix, a graph convolutional neural network layer is used to perform feature propagation and linear transformation on the nodes of the static graph to generate a final node representation of the static graph; the final node representation is input into a bidirectional long short-term memory network neural unit to obtain a forward long short-term memory network output vector and a backward long short-term memory network output vector; the forward long short-term memory network output vector and the backward long short-term memory network output vector are concatenated and classified to obtain the spatial features of the node.
[0008] According to an embodiment of the present disclosure, an adjacency coding layer based on a self-attention mechanism is used to process a dynamic graph to generate a temporal feature of each node, including: mapping each column of the full-period space feature matrix of the node to a representation space of a query, a key, and a value through a linear transformation, the full-period space feature matrix containing feature information of the node at different time steps; based on the representation space of the query, the key, and the value, calculating the attention weight between each node, and scaling and normalizing the attention weight to obtain an attention weight matrix; using the attention weight matrix to perform weighted summation on the value matrix of each node to obtain the temporal feature of each node.
[0009] According to an embodiment of the present disclosure, before extracting the spatial features and temporal features of each transaction account in the dynamic graph, the method further includes: dimensionalizing the initial features of each node in the static graph.
[0010] According to an embodiment of the present disclosure, abnormal transaction data in transaction activities is determined based on vector representation, including: inputting the vector representation into a binary classifier, determining the account abnormality score of each transaction account, and when the account abnormality score exceeds a preset threshold, determining the transaction data of the corresponding transaction account as abnormal transaction data.
[0011] According to an embodiment of the present disclosure, constructing a dynamic graph of transaction activities based on transaction data in transaction activities also includes: performing data cleaning on transaction data collected in transaction activities; and constructing a dynamic graph of transaction activities based on the cleansed transaction data.
[0012] A second aspect of the present disclosure provides an abnormal data detection device, including: a construction module, which is used to construct a dynamic graph of transaction activities based on transaction data in transaction activities, and the dynamic graph represents the changes in transaction relationships between transaction accounts over time; an extraction module, which is used to extract spatial features and temporal features of each transaction account in the dynamic graph, the spatial features represent the transaction behavior characteristics of the transaction account in the transaction activities, and the temporal features represent the behavior change rules of the transaction account; an aggregation module, which is used to perform row-by-row element addition and aggregation on the spatial features and temporal features of each transaction account to obtain a vector representation of the corresponding transaction account; and a determination module, which is used to determine the abnormal transaction data in the transaction activities according to the vector representation.
[0013] A third aspect of the present disclosure provides an electronic device, comprising: one or more processors; and a memory for storing one or more computer programs, wherein the one or more processors execute the one or more computer programs to implement the steps of the above method.
[0014] The fourth aspect of the present disclosure further provides a computer-readable storage medium having a computer program or instructions stored thereon, which implements the steps of the above method when the above computer program or instructions are executed by a processor.
[0015] The fifth aspect of the present disclosure further provides a computer program product, including a computer program or instructions, which implement the steps of the above method when the above computer program or instructions are executed by a processor.
[0016] According to the abnormal data detection method, device, equipment, medium and program product disclosed in the present invention, by constructing the transaction data into a dynamic graph that is convenient for the detection model to process, the spatial and temporal characteristics of the transaction account are extracted from it, and the vector representation of the transaction account is aggregated to determine the abnormal transaction data in the transaction activity, so that abnormal behavior in the transaction activity, such as fraudulent behavior, can be identified. The abnormal data detection method can be automatically executed by a computer program to realize the automation of abnormal data detection, thereby improving the detection efficiency and greatly reducing the workload of manual detection. The dynamic graph model used in the abnormal data detection method can not only accurately express the connection between data, but also efficiently model the spatiotemporal characteristics of account transactions, aggregate the spatiotemporal characteristics of the transaction account, enhance the representation ability of the node, effectively capture the complexity and dynamics of the transaction behavior, thereby improving the detection accuracy of abnormal data in the transaction activity, and improving the risk management and control capabilities of the transaction system. By constructing a dynamic graph to detect abnormal data, the amount of data calculation can also be reduced, and the data detection processing efficiency and data detection accuracy can be improved. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] The above contents and other objects, features and advantages of the present disclosure will become more apparent through the following description of the embodiments of the present disclosure with reference to the accompanying drawings, in which:
[0018] Figure 1 The application scenario diagram of the abnormal data detection method, apparatus, device, medium and program product according to the embodiments of the present disclosure is schematically shown;
[0019] Figure 2 A flowchart of an abnormal data detection method according to an embodiment of the present disclosure is schematically shown;
[0020] Figure 3 A flowchart of an abnormal data detection method according to another embodiment of the present disclosure is schematically shown;
[0021] Figure 4 A structural block diagram of an abnormal data detection device according to an embodiment of the present disclosure is schematically shown; and
[0022] Figure 5 A block diagram of an electronic device suitable for implementing the abnormal data detection method according to an embodiment of the present disclosure is schematically shown. DETAILED DESCRIPTION
[0023] Hereinafter, embodiments of the present disclosure will be described with reference to the accompanying drawings. However, it should be understood that these descriptions are exemplary only and are not intended to limit the scope of the present disclosure. In the following detailed description, for ease of explanation, many specific details are set forth to provide a comprehensive understanding of the embodiments of the present disclosure. However, it is apparent that one or more embodiments may also be implemented without these specific details. In addition, in the following description, descriptions of known structures and technologies are omitted to avoid unnecessary confusion of the concepts of the present disclosure.
[0024] The terms used herein are only for describing specific embodiments and are not intended to limit the present disclosure. The terms "comprise", "include", etc. used herein indicate the existence of features, steps, operations and / or components, but do not exclude the existence or addition of one or more other features, steps, operations or components.
[0025] All terms (including technical and scientific terms) used herein have the meanings commonly understood by those skilled in the art unless otherwise defined. It should be noted that the terms used herein should be interpreted as having a meaning consistent with the context of this specification and should not be interpreted in an idealized or overly rigid manner.
[0026] When using expressions such as "at least one of A, B, and C, etc.", they should generally be interpreted according to the meaning of the expression commonly understood by those skilled in the art (for example, "a system having at least one of A, B, and C" should include but is not limited to a system having A alone, B alone, C alone, A and B, A and C, B and C, and / or A, B, C, etc.).
[0027] In the technical solution of the present disclosure, the user information (including but not limited to user personal information, user image information, user device information, such as location information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved are all information and data authorized by the user or fully authorized by all parties, and the collection, storage, use, processing, transmission, provision, disclosure and application of the relevant data comply with relevant laws, regulations and standards, take necessary confidentiality measures, do not violate public order and good morals, and provide corresponding operation entrances for users to choose to authorize or refuse.
[0028] In the scenario of using personal information for automated decision-making, the methods, devices, and systems provided by the embodiments of the present disclosure provide users with corresponding operation portals for users to choose to agree or reject the automated decision-making results; if the user chooses to reject, the expert decision-making process will be entered. The expression "automated decision-making" here refers to the activity of automatically analyzing and evaluating a person's behavioral habits, interests and hobbies, or economic, health, credit status, etc. through computer programs, and making decisions. The expression "expert decision-making" here refers to the activity of making decisions by people who specialize in a certain field, have specialized experience, knowledge and skills, and have reached a certain level of professionalism.
[0029] Graph neural networks are deep learning models that can effectively utilize the interactive relationships in static graph structures. Graph neural networks have been widely used in the field of fraud detection. However, traditional static graph algorithms cannot capture the temporal correlation in account transactions well. In a financial transaction network with accounts as nodes and transactions between accounts as edges, the structure of the graph will change over time. Therefore, static graph neural networks can no longer meet the new needs of financial fraud detection.
[0030] In view of this, an embodiment of the present disclosure provides an abnormal data detection method, including: constructing a dynamic graph of transaction activities based on transaction data in transaction activities, the dynamic graph characterizing the changes in transaction relationships between transaction accounts over time; extracting spatial features and temporal features of each transaction account in the dynamic graph, the spatial features characterizing the transaction behavior characteristics of the transaction account in the transaction activities, and the temporal features characterizing the behavioral change patterns of the transaction accounts; adding and aggregating the spatial features and temporal features of each transaction account by row elements to obtain a vector representation of the corresponding transaction account; and determining abnormal transaction data in the transaction activities based on the vector representation.
[0031] Figure 1 The application scenario diagram of the abnormal data detection method, apparatus, device, medium and program product according to the embodiments of the present disclosure is schematically shown.
[0032] like Figure 1As shown, the application scenario 100 according to this embodiment may include a first terminal device 101, a second terminal device 102, a third terminal device 103, a network 104, and a server 105. The network 104 is used to provide a medium for a communication link between the first terminal device 101, the second terminal device 102, the third terminal device 103, and the server 105. The network 104 may include various connection types, such as wired, wireless communication links, or optical fiber cables, etc.
[0033] The user can use the first terminal device 101, the second terminal device 102, and the third terminal device 103 to interact with the server 105 through the network 104 to receive or send messages, etc. Various communication client applications can be installed on the first terminal device 101, the second terminal device 102, and the third terminal device 103, such as shopping applications, web browser applications, search applications, instant messaging tools, email clients, social platform software, etc. (only for example).
[0034] The first terminal device 101, the second terminal device 102, and the third terminal device 103 may be various electronic devices having display screens and supporting web browsing, including but not limited to smart phones, tablet computers, laptop computers, desktop computers, and the like.
[0035] The server 105 may be a server that provides various services, such as a background management server (only as an example) that provides support for websites browsed by users using the first terminal device 101, the second terminal device 102, and the third terminal device 103. The background management server may analyze and process the received data such as user requests, and feed back the processing results (such as web pages, information, or data obtained or generated according to user requests) to the terminal device.
[0036] It should be noted that the abnormal data detection method provided in the embodiment of the present disclosure can generally be executed by the server 105. Accordingly, the abnormal data detection device provided in the embodiment of the present disclosure can generally be set in the server 105. The abnormal data detection method provided in the embodiment of the present disclosure can also be executed by a server or server cluster that is different from the server 105 and can communicate with the first terminal device 101, the second terminal device 102, the third terminal device 103 and / or the server 105. Accordingly, the abnormal data detection device provided in the embodiment of the present disclosure can also be set in a server or server cluster that is different from the server 105 and can communicate with the first terminal device 101, the second terminal device 102, the third terminal device 103 and / or the server 105.
[0037] It should be understood that Figure 1The number of terminal devices, networks and servers in the embodiment is only for illustration. Any number of terminal devices, networks and servers may be provided according to implementation requirements.
[0038] The following will be based on Figure 1 The scene described by Figure 2~Figure 3 The abnormal data detection method of the disclosed embodiment is described in detail.
[0039] Figure 2 The flowchart of the abnormal data detection method according to the embodiment of the present disclosure is schematically shown.
[0040] like Figure 2 As shown, the abnormal data detection method of this embodiment includes operations S210 to S240, and the transaction processing method can be executed by the server 105.
[0041] In operation S210, a dynamic graph of the transaction activity is constructed based on the transaction data in the transaction activity, and the dynamic graph represents changes in the transaction relationship between the transaction accounts over time.
[0042] As an example, transaction activities can be transfers, payments, and other transaction activities in the financial or e-commerce fields, and transaction data can be account information of each transaction account in the transaction activity, transaction relationships between transaction accounts, transaction amounts, etc. These transaction accounts may have different transaction relationships and transaction amounts in different time periods, and dynamic graphs can represent the changes in each transaction account and its transaction relationship through a graph structure that changes over time.
[0043] In operation S220, the spatial features and temporal features of each trading account in the dynamic graph are extracted, the spatial features represent the trading behavior characteristics of the trading account in the trading activities, and the temporal features represent the behavior change rules of the trading account.
[0044] Spatial features can characterize the behavioral characteristics of trading accounts in trading activities, such as the number of transactions of an account, the characteristics of neighboring nodes, the distribution of transaction amounts, etc. Temporal features can characterize the changing patterns and trends of the behavior of trading accounts over time, such as the changes in transaction frequency, the trend of transaction amounts, the time interval between transactions, etc. The dynamic graph can be input into a pre-trained model to extract spatial and temporal features. The process of extracting features from the model will be further explained later.
[0045] In operation S230, the spatial features and the temporal features of each transaction account are aggregated by adding row-by-row elements to obtain a vector representation of the corresponding transaction account.
[0046] For example, spatial features can be represented as a vector [f1, f2, f3], and temporal features can be represented as a vector [t1, t2, t3]. The aggregated vector can be represented as [f1+t1, f2+t2, f3+t3], which combines spatial and temporal behavior features.
[0047] In operation S240, abnormal transaction data in the transaction activity is determined according to the vector representation.
[0048] Based on the vector representation of transaction accounts, for example, machine learning or statistical methods can be used to detect abnormal data. Abnormal data indicates that there are abnormal transactions in trading activities, such as high-frequency large-value transactions, sudden behavioral changes, transactions with abnormal accounts, etc. Abnormal transactions can also be some transaction fraud.
[0049] By constructing transaction data into a dynamic graph that is easy for the detection model to process, the spatial and temporal features of the transaction account are extracted and aggregated into a vector representation of the transaction account, thereby determining abnormal transaction data in the transaction activity, such as fraud in the transaction activity. The dynamic graph model can not only accurately express the connection between data, but also efficiently model the spatiotemporal features of account transactions. Aggregating the spatiotemporal features of the transaction account can enhance the representation ability of the node and effectively capture the complexity and dynamics of the transaction behavior, thereby improving the detection accuracy of abnormal data in the transaction activity and improving the risk management and control capabilities of the transaction system. It can be applied to scenarios such as financial risk control and anti-fraud.
[0050] On the basis of the above embodiments, based on the transaction data in the transaction activities, constructing a dynamic graph of the transaction activities may include: based on the transaction data, constructing static graphs of different time periods, wherein each static graph shares the same node set and has an independent edge set, the nodes in the node set represent transaction accounts, and the edges in the edge set represent transaction relationships between the transaction accounts; and concatenating the static graphs into a dynamic graph in chronological order.
[0051] Each static graph shares the same set of nodes, and the nodes represent transaction accounts. For example, node A can represent account A, and node B can represent account B. Each static graph has an independent set of edges, and the edges represent the transaction relationship between transaction accounts. For example, if account A transfers money to account B within a certain time period, an edge pointing from node A to node B is added to the corresponding static graph, and the edge weight can represent the transaction amount or the number of transactions. The transaction data is divided according to the time period, and each time period corresponds to a static graph. For example, it can be divided by day, and a static graph is generated for each day's transaction data. The generated static graphs are connected in chronological order to form a dynamic graph. Each static graph represents a time slice in the dynamic graph. The nodes and edges in the dynamic graph remain unchanged in different time slices or are updated according to changes in transaction data. The dynamic graph is a graph sequence consisting of a series of static heterogeneous graph snapshots, which can be expressed as follows:
[0052]
[0053] in Indicates the total number of timestamps, Static graphs representing different time periods, Represents a collection of nodes. Represents a set of edges. By constructing a dynamic graph of transaction activities, we can not only preserve the spatiotemporal characteristics of transaction data, but also provide richer analysis dimensions, which helps to deeply understand the dynamic behavior of the transaction network, thereby supporting more accurate decision-making and prediction.
[0054] Based on the above embodiment, extracting the spatial features and temporal features of each transaction account in the dynamic graph may include: using a graph convolutional neural network layer to process each static graph in the dynamic graph to generate the spatial features of each node; using an adjacency coding layer based on a self-attention mechanism to process the dynamic graph to generate the temporal features of each node.
[0055] Graph Convolutional Networks (GCN) is a deep learning model for graph structured data that can capture the relationship between nodes and their neighbors. For each static graph, the GCN layer can generate spatial features of each node by aggregating information from neighboring nodes, such as transaction patterns between accounts. After being processed by the GCN layer, each node generates a new feature vector representing its spatial features. The self-attention mechanism can capture the changing relationship of node features in dynamic graphs over time, such as the evolution of account transaction behavior. Through the self-attention mechanism, the importance of node features in different time slices can be calculated to generate time features. The introduction of time features can enable the model to better detect abnormal behavior, such as a sudden increase in the transaction frequency of an account. In this embodiment, the combination of the GCN layer and the self-attention mechanism enables the model to simultaneously capture the spatial and temporal features of nodes in the dynamic graph, thereby more comprehensively describing the behavior of the nodes. This method has significant advantages in dynamic graph analysis tasks and can support more accurate anomaly detection, behavior prediction, and pattern recognition.
[0056] In some embodiments, before extracting the spatial features and temporal features of each transaction account in the dynamic graph, the initial features of each node in the static graph may be dimensionally unified.
[0057] For example, in a financial transaction graph, nodes may represent different types of entities (such as individual users, enterprises, merchants, etc.), and each type of node may have different characteristics. In order to facilitate the unified processing of these different types of nodes in the graph, their initial characteristics can be mapped to the same dimensional space through a mapping matrix. Dimensional unification can be performed according to the following formula:
[0058]
[0059] where x v represents the initial features of node v, Represents a trainable mapping matrix.
[0060] On the basis of the above embodiment, a graph convolutional neural network layer is used to process each static graph in the dynamic graph to generate the spatial features of each node, which may include: symmetric normalization of the adjacency matrix of each static graph; based on the normalized adjacency matrix, a graph convolutional neural network layer is used to perform feature propagation and linear transformation on the nodes of the static graph to generate the final node representation of the static graph; the final node representation is input into a bidirectional long short-term memory network neural unit to obtain a forward long short-term memory network output vector and a backward long short-term memory network output vector; the forward long short-term memory network output vector and the backward long short-term memory network output vector are concatenated and classified to obtain the spatial features of the node.
[0061] In this embodiment, the normalization formula can be expressed as follows:
[0062]
[0063] Among them, A t represents the adjacency matrix of the static graph, I represents the identity matrix, and D t Indicates A t +I diagonal matrix. Each layer of graph convolutional neural network can generate node hidden representation , where |V| represents the number of nodes in the node set V, D k The node representation dimension of the k-th layer network. The hidden representation of each layer node can be obtained by the following formula:
[0064]
[0065] Each graph convolutional neural network layer has an independent trainable matrix , the first layer hidden representation of the node It is initialized and concatenated by node features.
[0066] This embodiment can be used in various static images Assume a K-layer graph convolutional neural network, and the K+1-th layer node represents The final representation of the static graph is fed into the BiLSTM neural unit. The node representation will be used as the t-th time sequence input in the BiLSTM sequence.
[0067]
[0068]
[0069]
[0070] in and They represent the vector representation of the last time series of the forward LSTM and the backward LSTM respectively, [·;·] represents the vector concatenation operation, and the softmax function is used to normalize the attention weights. Represents the concatenated vector, which is the vector representation of the spatial features of the node.
[0071] In this embodiment, symmetric normalization can make the graph convolutional neural network more stable and efficient during feature propagation, avoiding gradient explosion or vanishing problems. Bidirectional LSTM can capture the dependencies of node features in the time dimension, while considering forward and backward time information. By concatenating the forward and backward LSTM output vectors, the spatial features of the nodes can simultaneously contain local structural information and time evolution information. This embodiment can generate node spatial features containing local structure and time dependency by symmetric normalization of the adjacency matrix of the static graph, and combining the GCN layer and bidirectional LSTM, supporting more accurate node classification, anomaly detection and prediction tasks.
[0072] On the basis of the above embodiment, the dynamic graph is processed by an adjacency coding layer based on a self-attention mechanism, and the generation of the time feature of each node may include: mapping each column of the full-period space feature matrix of the node to the representation space of the query, key and value through a linear transformation, and the full-period space feature matrix contains the feature information of the node at different time steps; based on the representation space of the query, key and value, calculating the attention weight between each node, and scaling and normalizing the attention weight to obtain the attention weight matrix; using the attention weight matrix to perform weighted summation on the value matrix of each node to obtain the time feature of each node.
[0073] The full-period spatial feature matrix can contain feature information of nodes at different time steps. In this embodiment, the adjacency coding layer based on the self-attention mechanism can first construct a full-period spatial feature matrix about node v , the matrix construction formula can be expressed as:
[0074]
[0075] in, Represents the difference between node v at timestamp t and node v j The relationship weight.
[0076] The node features are encoded by the self-attention mechanism, and each column of the matrix can be mapped to the representation space of query, key and value through linear transformation. The formula can be expressed as follows:
[0077]
[0078] in, Denote the linear transformation matrices for query, key, and value, respectively. Q, K, and V denote the representation matrices for query, key, and value, respectively.
[0079] Then the attention weights between all nodes can be calculated in matrix form and scaled and normalized. The formula can be expressed as follows:
[0080]
[0081]
[0082] in, represents the interaction strength between nodes, Each row represents the attention distribution of the current node to other nodes, and d represents the dimension of the key vector. The softmax function is used to normalize the attention weights.
[0083] Then use the attention weight matrix α to perform weighted summation on the value matrix V to obtain the context representation of each node, that is, the temporal feature of each node:
[0084]
[0085] In this embodiment, the temporal features of the nodes can be generated by performing linear transformation on the full-cycle spatial feature matrix and calculating the self-attention mechanism. This method can capture the global dependencies of the nodes throughout the time period and dynamically assign the importance of different time steps, thereby more flexibly modeling the evolution of node features. At the same time, the self-attention mechanism can calculate the relationship between nodes in parallel, avoiding the recursive calculation of sequence models such as RNN, and improving the calculation efficiency.
[0086] The outputs of the graph convolutional neural network layer and the self-attention based neighbor encoder layer can be aggregated by row-by-row element summation to obtain the vector representation of the node. The vector representation of the node v can be obtained by the following formula:
[0087]
[0088] Among them, Z v represents the vector representation of node v, represents the spatial feature representation of node v, Represents the temporal feature representation of node v.
[0089] Based on the above embodiment, determining abnormal transaction data in transaction activities according to the vector representation may include: inputting the vector representation into a binary classifier, determining the account abnormality score of each transaction account, and when the account abnormality score exceeds a preset threshold, determining the transaction data of the corresponding transaction account as abnormal transaction data.
[0090] The binary classifier has high computational efficiency and can quickly process large-scale transaction data, and is suitable for real-time or near-real-time anomaly detection. As an example, the binary classifier can be one of logistic regression, support vector machine, neural network, etc., and the corresponding anomaly score can be calculated based on the obtained vector representation through the binary classifier. Taking logistic regression as a binary classifier as an example, its formula can be expressed as:
[0091]
[0092] Among them, y represents the calculated abnormal score, W p represents the weight vector, b p represents the bias term, σ represents the sigmoid function, which can map the output to [0, 1].
[0093] For example, there are three trading accounts {A, B, C}, and the calculated anomaly scores are 0.85, 0.45, and 0.92, respectively. According to the preset threshold, determine which accounts have anomaly scores exceeding the threshold, and mark their transaction data as abnormal transaction data. For example, the threshold is set to 0.8. Since the anomaly scores of accounts A and C are both greater than the threshold, they are marked as abnormal, that is, the transaction data of accounts A and C are determined to be abnormal transaction data. It should be emphasized that the preset threshold can be reasonably set or dynamically adjusted as needed to flexibly respond to anomaly detection tasks in different scenarios. The present disclosure does not limit the specific value of the threshold.
[0094] By inputting the feature vector of the transaction account into the binary classifier, calculating the abnormal score of the account, and determining the abnormal transaction data according to the preset threshold, efficient and accurate anomaly detection can be achieved. This method can automatically complete the anomaly detection task, reduce manual intervention, and improve work efficiency.
[0095] As a usage scenario, when an abnormal transaction is set as a fraudulent transaction, the above method can be used to quickly lock the fraudulent account and intercept the fraudulent transfer by freezing the account, etc. It can be understood that this method is not only applicable to anomaly detection of financial transaction data, but can also be extended to other fields, such as network security, social network analysis, etc.
[0096] According to an embodiment of the present disclosure, constructing a dynamic graph of transaction activities based on transaction data in transaction activities also includes: performing data cleaning on transaction data collected in transaction activities; and constructing a dynamic graph of transaction activities based on the cleansed transaction data.
[0097] Data cleaning may include, for example, invalid item filtering, missing value processing, data conversion, data normalization, etc., which will be further described in the following embodiments. Data cleaning may convert the collected initial data into the input required by the model to improve the accuracy and efficiency of data processing.
[0098] Figure 3 A flowchart of an abnormal data detection method according to another embodiment of the present disclosure is schematically shown.
[0099] like Figure 3As shown, in this embodiment, data collection can be performed first. Taking the processing of transaction data in financial transactions as an example, the basic information of the account owner can be collected from the bank data platform, and the information dimensions include but are not limited to customer number, gender, age, marital status, industry, unit type, number of accounts held, region, etc.; basic account information includes but is not limited to bank card number, holder, account balance, account type, account status (normal, frozen, reported lost), account level, account opening bank, account opening region, currency, transaction frequency, average transaction amount, average monthly assets, average annual assets, etc.; basic transaction information includes but is not limited to transfer amount, transfer time, initiating transfer account information, receiving transfer account information, transfer bank, transfer region, etc.
[0100] Next, the collected data can be preprocessed. Invalid item filtering: Data with missing core data such as customer code and transfer amount is considered invalid, and the row will be deleted directly during the data cleaning stage. Missing value processing: Missing fields such as the gender and age of the head of the household can be filled in according to the ID number, and missing fields such as the transaction bank and transaction area can be filled in according to the account opening bank and account opening area. Missing values such as the average transaction amount, average monthly assets, and average annual assets can be filled in according to the account balance and account historical transaction data. Data transformation: For discrete eigenvalues such as gender, account type, and account status, unique hot encoding is used. This method encodes by mapping categorical values to integer values and representing these integer values as binary vectors. Data normalization: For continuous eigenvalues such as account balances, average monthly assets, average annual assets, and transfer amounts, the Z-score method can be used for standardization so that such eigenvalues are evenly distributed on both sides of 0. The calculation formula is as follows: , where μ represents the column mean of the eigenvalue and σ represents the column standard deviation of the eigenvalue.
[0101] Next, a dynamic graph is constructed based on the cleaned transaction data. The process of constructing a dynamic graph has been described in detail in the previous article and will not be repeated here.
[0102] Next, the model is trained. The model may include a graph convolutional neural network layer, an adjacency coding layer based on a self-attention mechanism, and a feature aggregation layer. The graph convolutional neural network layer and the adjacency coding layer based on a self-attention mechanism are used to extract spatial features and temporal features from the input dynamic graph, and the feature aggregation layer is used to aggregate spatial features and temporal features into a vector representation of the node. For the relevant content of extracting features and aggregating features, please refer to the previous text and will not be repeated here. As an example, the cross entropy loss function can be used to train the model.
[0103] Finally, the model is predicted. The trained model is used to predict the anomaly score of the account, and the abnormal trading accounts in the trading activities are determined based on the relationship between the anomaly score and the preset threshold.
[0104] This embodiment provides a financial fraud detection model based on dynamic graphs. The model algorithm aggregates the spatiotemporal features of nodes from the graph neural network layer and the neighbor coding layer based on the self-attention mechanism, respectively, to enhance the representation ability of account nodes. Compared with other models, this dynamic graph model can not only express the connection between data more accurately, but also efficiently model the temporal characteristics of account transactions, thereby improving the accuracy and generalization ability of the model. In financial fraud detection, it can effectively improve the accuracy and recall rate of fraud detection, and provide ideas for safeguarding the rights and interests of customers and the stability of the financial market.
[0105] Based on the above abnormal data detection method, the present disclosure also provides an abnormal data detection device. Figure 4 The device is described in detail.
[0106] Figure 4 The structure block diagram of the abnormal data detection device according to the embodiment of the present disclosure is schematically shown.
[0107] like Figure 4 As shown, the abnormal data detection device 400 of this embodiment includes a construction module 410 , an extraction module 420 and an aggregation module 430 .
[0108] The construction module 410 is used to construct a dynamic graph of the transaction activity based on the transaction data in the transaction activity, and the dynamic graph represents the change of the transaction relationship between the transaction accounts over time. In one embodiment, the construction module 410 can be used to perform the operation S210 described above, which will not be repeated here.
[0109] The extraction module 420 is used to extract the spatial features and temporal features of each trading account in the dynamic graph, the spatial features represent the trading behavior characteristics of the trading account in the trading activities, and the temporal features represent the behavior change rules of the trading account. In one embodiment, the extraction module 420 can be used to perform the operation S220 described above, which will not be repeated here.
[0110] Aggregation module 430 is used to aggregate the spatial features and temporal features of each transaction account by row-by-row element addition to obtain a vector representation of the corresponding transaction account. In one embodiment, aggregation module 430 can be used to perform operation S230 described above, which will not be described in detail here.
[0111] The determination module 440 is used to determine abnormal transaction data in the transaction activity according to the vector representation. In one embodiment, the determination module 440 can be used to perform the operation S240 described above, which will not be described in detail here.
[0112] According to an embodiment of the present disclosure, the construction module 410 can also be used to construct static graphs of different time periods based on transaction data, wherein each static graph shares the same set of nodes and has an independent set of edges, the nodes in the node set represent transaction accounts, and the edges in the edge set represent transaction relationships between transaction accounts; the static graphs are connected in chronological order into a dynamic graph.
[0113] According to an embodiment of the present disclosure, the extraction module 420 may further include a first generation module and a second generation module. The first generation module is used to process each static graph in the dynamic graph using a graph convolutional neural network layer to generate spatial features of each node; the second generation module is used to process the dynamic graph using an adjacency coding layer based on a self-attention mechanism to generate temporal features of each node.
[0114] According to an embodiment of the present disclosure, the first generation module can also be used to perform symmetric normalization processing on the adjacency matrix of each static graph; based on the normalized adjacency matrix, a graph convolutional neural network layer is used to perform feature propagation and linear transformation on the nodes of the static graph to generate the final node representation of the static graph; the final node representation is input into a bidirectional long short-term memory network neural unit to obtain a forward long short-term memory network output vector and a backward long short-term memory network output vector; the forward long short-term memory network output vector and the backward long short-term memory network output vector are concatenated and classified to obtain the spatial features of the node.
[0115] According to an embodiment of the present disclosure, the second generation module can also be used to map each column of the full-period space feature matrix of the node to the representation space of query, key and value through a linear transformation, and the full-period space feature matrix contains the feature information of the node at different time steps; based on the representation space of query, key and value, the attention weight between each node is calculated, and the attention weight is scaled and normalized to obtain the attention weight matrix; the attention weight matrix is used to perform weighted summation on the value matrix of each node to obtain the time feature of each node.
[0116] According to an embodiment of the present disclosure, the extraction module 420 may also be used to unify the dimensions of the initial features of each node in the static graph before extracting the spatial features and temporal features of each transaction account in the dynamic graph.
[0117] According to an embodiment of the present disclosure, the determination module 440 can also be used to input the vector representation into a binary classifier to determine the account anomaly score of each transaction account, and when the account anomaly score exceeds a preset threshold, the transaction data of the corresponding transaction account is determined as abnormal transaction data.
[0118] According to an embodiment of the present disclosure, the construction module 410 may also be used to clean the transaction data collected in the transaction activities; and to construct a dynamic graph of the transaction activities based on the cleansed transaction data.
[0119] According to an embodiment of the present disclosure, any multiple modules of the construction module 410, the extraction module 420, the aggregation module 430 and the determination module 440 can be combined into one module for implementation, or any one of the modules can be split into multiple modules. Alternatively, at least part of the functions of one or more of these modules can be combined with at least part of the functions of other modules and implemented in one module. According to an embodiment of the present disclosure, at least one of the construction module 410, the extraction module 420, the aggregation module 430 and the determination module 440 can be at least partially implemented as a hardware circuit, such as a field programmable gate array (FPGA), a programmable logic array (PLA), a system on a chip, a system on a substrate, a system on a package, an application-specific integrated circuit (ASIC), or can be implemented by hardware or firmware such as any other reasonable way of integrating or packaging the circuit, or implemented in any one of the three implementation methods of software, hardware and firmware or in any appropriate combination of any of them. Alternatively, at least one of the construction module 410, the extraction module 420, the aggregation module 430 and the determination module 440 can be at least partially implemented as a computer program module, and when the computer program module is run, the corresponding function can be performed.
[0120] Figure 5 A block diagram of an electronic device suitable for implementing the abnormal data detection method according to an embodiment of the present disclosure is schematically shown.
[0121] like Figure 5 As shown, the electronic device 500 according to an embodiment of the present disclosure includes a processor 501, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 502 or a program loaded from a storage part 508 to a random access memory (RAM) 503. The processor 501 may include, for example, a general-purpose microprocessor (such as a CPU), an instruction set processor and / or a related chipset and / or a special-purpose microprocessor (for example, an application-specific integrated circuit (ASIC)), etc. The processor 501 may also include an onboard memory for caching purposes. The processor 501 may include a single processing unit or multiple processing units for performing different actions of the method flow according to an embodiment of the present disclosure.
[0122] In RAM 503, various programs and data required for the operation of electronic device 500 are stored. Processor 501, ROM 502 and RAM 503 are connected to each other via bus 504. Processor 501 performs various operations of the method flow according to the embodiment of the present disclosure by executing the program in ROM 502 and / or RAM 503. It should be noted that the program can also be stored in one or more memories other than ROM 502 and RAM 503. Processor 501 can also perform various operations of the method flow according to the embodiment of the present disclosure by executing the program stored in one or more memories.
[0123] According to an embodiment of the present disclosure, the electronic device 500 may further include an input / output (I / O) interface 505, which is also connected to the bus 504. The electronic device 500 may further include one or more of the following components connected to the input / output (I / O) interface 505: an input portion 506 including a keyboard, a mouse, etc.; an output portion 507 including a cathode ray tube (CRT), a liquid crystal display (LCD), etc., and a speaker, etc.; a storage portion 508 including a hard disk, etc.; and a communication portion 509 including a network interface card such as a LAN card, a modem, etc. The communication portion 509 performs communication processing via a network such as the Internet. A drive 510 is also connected to the input / output (I / O) interface 505 as needed. A removable medium 511, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 510 as needed, so that a computer program read therefrom is installed into the storage portion 508 as needed.
[0124] The present disclosure also provides a computer-readable storage medium, which may be included in the device / apparatus / system described in the above embodiments; or may exist independently without being assembled into the device / apparatus / system. The above computer-readable storage medium carries one or more programs, and when the above one or more programs are executed, the method according to the embodiment of the present disclosure is implemented.
[0125] According to an embodiment of the present disclosure, the computer-readable storage medium may be a non-volatile computer-readable storage medium, for example, it may include but is not limited to: a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof. In the present disclosure, a computer-readable storage medium may be any tangible medium containing or storing a program, which may be used by or in combination with an instruction execution system, an apparatus or a device. For example, according to an embodiment of the present disclosure, the computer-readable storage medium may include the ROM 502 and / or RAM 503 described above and / or one or more memories other than ROM 502 and RAM 503.
[0126] The embodiment of the present disclosure also includes a computer program product, which includes a computer program, and the computer program contains program code for executing the method shown in the flowchart. When the computer program product is run in a computer system, the program code is used to enable the computer system to implement the abnormal data detection method provided by the embodiment of the present disclosure.
[0127] The above functions defined in the system / device of the embodiment of the present disclosure are performed when the computer program is executed by the processor 501. According to the embodiment of the present disclosure, the system, device, module, unit, etc. described above can be implemented by a computer program module.
[0128] In one embodiment, the computer program may rely on tangible storage media such as optical storage devices, magnetic storage devices, etc. In another embodiment, the computer program may also be transmitted and distributed in the form of signals on a network medium, and downloaded and installed through the communication part 509, and / or installed from the removable medium 511. The program code contained in the computer program may be transmitted using any appropriate network medium, including but not limited to: wireless, wired, etc., or any suitable combination of the above.
[0129] In such an embodiment, the computer program can be downloaded and installed from the network through the communication part 509, and / or installed from the removable medium 511. When the computer program is executed by the processor 501, the above functions defined in the system of the embodiment of the present disclosure are performed. According to the embodiment of the present disclosure, the system, device, means, module, unit, etc. described above can be implemented by a computer program module.
[0130] According to an embodiment of the present disclosure, the program code for executing the computer program provided by the embodiment of the present disclosure can be written in any combination of one or more programming languages. Specifically, these computing programs can be implemented using high-level process and / or object-oriented programming languages, and / or assembly / machine languages. Programming languages include, but are not limited to, Java, C++, python, "C" language or similar programming languages. The program code can be executed entirely on the user computing device, partially on the user device, partially on the remote computing device, or entirely on the remote computing device or server. In the case of a remote computing device, the remote computing device can be connected to the user computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computing device (for example, using an Internet service provider to connect through the Internet).
[0131] The flow charts and block diagrams in the accompanying drawings illustrate the possible architecture, functions and operations of the systems, methods and computer program products according to various embodiments of the present disclosure. In this regard, each box in the flow chart or block diagram can represent a module, a program segment, or a part of a code, and the above-mentioned module, program segment, or a part of a code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a different order from the order marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram or flow chart, and the combination of the boxes in the block diagram or flow chart can be implemented with a dedicated hardware-based system that performs a specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.
[0132] It will be appreciated by those skilled in the art that the features described in the various embodiments of the present disclosure may be combined and / or combined in a variety of ways, even if such combinations or combinations are not explicitly described in the present disclosure. In particular, without departing from the spirit and teachings of the present disclosure, the features described in the various embodiments of the present disclosure may be combined and / or combined in a variety of ways. All of these combinations and / or combinations fall within the scope of the present disclosure.
[0133] The embodiments of the present disclosure are described above. However, these embodiments are only for illustrative purposes and are not intended to limit the scope of the present disclosure. Although the embodiments are described above, this does not mean that the measures in the various embodiments cannot be used in combination to advantage. Without departing from the scope of the present disclosure, those skilled in the art may make a variety of substitutions and modifications, which should all fall within the scope of the present disclosure.
Claims
1. A method for detecting abnormal data, characterized in that: include: Based on the transaction data in the transaction activity, construct a dynamic graph of the transaction activity, wherein the dynamic graph represents the change of the transaction relationship between the transaction accounts over time; Extracting the spatial features and temporal features of each of the trading accounts in the dynamic graph, wherein the spatial features represent the trading behavior characteristics of the trading account in the trading activity, and the temporal features represent the behavior change rules of the trading account; The spatial feature and the temporal feature of each of the transaction accounts are aggregated by adding row-by-row elements to obtain a vector representation of the corresponding transaction account; Abnormal transaction data in the transaction activity is determined based on the vector representation.
2. The abnormal data detection method according to claim 1, characterized in that: The step of constructing a dynamic graph of the transaction activity based on the transaction data in the transaction activity includes: Based on the transaction data, static graphs of different time periods are constructed, wherein each of the static graphs shares the same node set and has an independent edge set, the nodes in the node set represent the transaction accounts, and the edges in the edge set represent the transaction relationships between the transaction accounts; The static images are connected in chronological order to form the dynamic image.
3. The abnormal data detection method according to claim 2, characterized in that: The extracting of the spatial features and temporal features of each of the transaction accounts in the dynamic graph comprises: Using a graph convolutional neural network layer to process each of the static graphs in the dynamic graph to generate the spatial features of each of the nodes; The dynamic graph is processed using an adjacency coding layer based on a self-attention mechanism to generate the temporal features of each of the nodes.
4. The abnormal data detection method according to claim 3, characterized in that: The step of using a graph convolutional neural network layer to process each of the static graphs in the dynamic graph to generate the spatial features of each of the nodes includes: Performing symmetric normalization processing on the adjacency matrix of each of the static graphs; Based on the normalized adjacency matrix, the graph convolutional neural network layer is used to perform feature propagation and linear transformation on the nodes of the static graph to generate a final node representation of the static graph; Input the final node representation into a bidirectional long short-term memory network neural unit to obtain a forward long short-term memory network output vector and a backward long short-term memory network output vector; The forward long short-term memory network output vector and the backward long short-term memory network output vector are concatenated and classified to obtain the spatial feature of the node.
5. The abnormal data detection method according to claim 3, characterized in that: The process of processing the dynamic graph by using an adjacency coding layer based on a self-attention mechanism to generate the temporal feature of each node includes: Mapping each column of the full-periodic spatial feature matrix of the node to a representation space of a query, a key, and a value through a linear transformation, wherein the full-periodic spatial feature matrix includes feature information of the node at different time steps; Based on the representation space of the query, key and value, calculate the attention weight between each of the nodes, and scale and normalize the attention weight to obtain an attention weight matrix; The attention weight matrix is used to perform weighted summation on the value matrix of each node to obtain the time feature of each node.
6. The abnormal data detection method according to claim 3, characterized in that: Before extracting the spatial features and temporal features of each of the transaction accounts in the dynamic graph, the method further includes: The initial features of each of the nodes in the static graph are dimensionally unified.
7. The abnormal data detection method according to claim 1, characterized in that: The determining, according to the vector representation, abnormal transaction data in the transaction activity includes: The vector representation is input into a binary classifier to determine an account abnormality score for each of the transaction accounts, and when the account abnormality score exceeds a preset threshold, the transaction data of the corresponding transaction account is determined as the abnormal transaction data.
8. The abnormal data detection method according to claim 1 or 2, characterized in that: The constructing the dynamic graph of the transaction activity based on the transaction data in the transaction activity also includes: Performing data cleaning on the transaction data collected in the transaction activities; Based on the cleaned transaction data, a dynamic graph of the transaction activity is constructed.
9. An abnormal data detection device, characterized in that: The device comprises: A construction module, for constructing a dynamic graph of the transaction activity based on the transaction data in the transaction activity, wherein the dynamic graph represents the change of the transaction relationship between the transaction accounts over time; An extraction module, configured to extract spatial features and temporal features of each of the trading accounts in the dynamic graph, wherein the spatial features represent the trading behavior characteristics of the trading account in the trading activity, and the temporal features represent the behavior change rules of the trading account; an aggregation module, configured to perform row-by-row element summation on the spatial features and the temporal features of each of the transaction accounts to obtain a vector representation of the corresponding transaction account; and A determination module is used to determine abnormal transaction data in the transaction activity according to the vector representation.
10. An electronic device comprising: one or more processors; a memory for storing one or more computer programs, It is characterized in that the one or more processors execute the one or more computer programs to implement the steps of the method according to any one of claims 1 to 8.
11. A computer-readable storage medium having a computer program or instruction stored thereon, characterized in that: When the computer program or instruction is executed by a processor, the steps of the method according to any one of claims 1 to 8 are implemented.
12. A computer program product comprising a computer program or instructions, characterized in that When the computer program or instruction is executed by a processor, the steps of the method according to any one of claims 1 to 8 are implemented.