Low-frequency transaction anomaly detection method and device, equipment and medium
By constructing a trading volume sequence and judging the low-frequency trading status, dynamically adjusting the low-frequency duration threshold, the problems of low-frequency trading volume detection are solved, and efficient low-frequency trading abnormality detection is achieved.
Patent Information
- Application Number
- CN202510122656.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-26
- Publication Date
- 2025-05-27
AI Technical Summary
The detection accuracy of low-frequency trading volume is low, making it difficult to accurately distinguish between normal fluctuations and abnormal fluctuations, and has poor adaptability, so it is impossible to flexibly adapt to changes in high-frequency and low-frequency trading volumes.
By constructing a trading volume sequence, we can determine whether the current trading time point is in a low-frequency trading state, and determine the low-frequency duration threshold based on the historical low-frequency duration of the target historical trading time point, and dynamically adjust the threshold to improve detection accuracy.
The accuracy of low-frequency trading anomaly detection has been improved, the ability to detect low-frequency trading anomaly is improved, and the adaptability of the model has been enhanced.
Smart Images

Figure CN120046072A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of financial transaction monitoring, and particularly to a method, device, equipment and medium for detecting anomalies in low-frequency transactions. Background Art
[0002] With the continuous development of the financial market, detecting anomalies in low-frequency transactions has become an important technical problem in the monitoring systems of financial institutions. Low-frequency transactions usually refer to data with relatively small trading volumes occurring within a specific time interval. Therefore, traditional anomaly detection methods often fail to effectively identify potential anomalies in low-frequency trading volumes. Most existing anomaly detection technologies are based on real-time data streams and high-frequency trading data, lacking effective modeling and detection means for the time-series data of low-frequency trading volumes, resulting in some anomalies not being discovered in a timely manner.
[0003] Specific technical problems include: low detection accuracy of low-frequency trading volumes: The data of low-frequency trading volumes is unevenly distributed in the time series, and the sparsity makes it difficult for traditional methods to accurately distinguish normal fluctuations from abnormal fluctuations, prone to a high false alarm rate. At the same time, due to the small fluctuations and long intervals of low-frequency trading volumes, anomalies may only manifest as small fluctuations or mutations, making it difficult to locate specific abnormal moments. And poor adaptability in detecting low-frequency trading volumes: High-frequency and low-frequency trading volumes in actual trading data are intertwined, and existing methods often cannot flexibly adapt to this change, resulting in the model being difficult to effectively handle complex trading volume fluctuation patterns and having poor adaptability. Summary of the Invention
[0004] The present invention provides a method, device, equipment and medium for detecting anomalies in low-frequency transactions to solve the problem of low accuracy in detecting anomalies in low-frequency transactions.
[0005] According to one aspect of the present invention, a method for detecting anomalies in low-frequency transactions is provided, including:
[0006] Obtaining historical trading volumes at multiple historical trading time points and the current trading volume at the current trading time point according to a preset trading volume acquisition time interval, and constructing a trading volume sequence;
[0007] Judging whether the current trading time point is in a low-frequency trading state according to the current trading volume;
[0008] If in a low-frequency trading state, determining the historical low-frequency duration at multiple target historical trading time points according to the trading volume sequence; wherein, the historical low-frequency duration is determined according to the low-frequency trading duration before the target historical trading time point;
[0009] Determining a low-frequency duration threshold according to the historical low-frequency durations at the multiple target historical trading time points;
[0010] Determine the current low-frequency duration corresponding to the current trading time point according to the trading volume sequence, and determine the low-frequency trading anomaly detection result of the current trading time point according to the comparison result between the current low-frequency duration and the low-frequency duration threshold.
[0011] According to another aspect of the present invention, there is provided a low-frequency trading anomaly detection device, including:
[0012] A trading volume determination module, configured to acquire the historical trading volumes of multiple historical trading time points and the current trading volume of the current trading time point at a preset trading volume acquisition time interval, and construct a trading volume sequence;
[0013] A low-frequency trading state judgment module, configured to judge whether the current trading time point is in a low-frequency trading state according to the current trading volume;
[0014] A historical low-frequency duration determination module, configured to, if in a low-frequency trading state, determine the historical low-frequency durations of multiple target historical trading time points according to the trading volume sequence; wherein, the historical low-frequency duration is determined according to the low-frequency trading duration before the target historical trading time point;
[0015] A low-frequency duration threshold determination module, configured to determine a low-frequency duration threshold according to the historical low-frequency durations of the multiple target historical trading time points;
[0016] An anomaly detection module, configured to determine the current low-frequency duration corresponding to the current trading time point according to the trading volume sequence, and determine the low-frequency trading anomaly detection result of the current trading time point according to the comparison result between the current low-frequency duration and the low-frequency duration threshold.
[0017] According to another aspect of the present invention, there is provided an electronic device, where the electronic device includes:
[0018] At least one processor; and
[0019] A memory communicatively connected to the at least one processor; wherein,
[0020] The memory stores a computer program executable by the at least one processor, and when the computer program is executed by the at least one processor, the at least one processor can execute the low-frequency trading anomaly detection method according to any embodiment of the present invention.
[0021] According to another aspect of the present invention, there is provided a computer-readable storage medium, where the computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to execute the low-frequency trading anomaly detection method according to any embodiment of the present invention when executed.
[0022] In the technical solution of the embodiment of the present invention, by determining the historical low-frequency duration corresponding to a plurality of target historical transaction time points corresponding to the current transaction time point in the low-frequency transaction state, and then determining the low-frequency duration threshold corresponding to the current transaction time point according to the historical low-frequency duration of the plurality of target historical transaction time points, and determining the low-frequency transaction anomaly detection result of the current transaction time point according to the comparison result between the current low-frequency duration corresponding to the current transaction time point and the low-frequency duration threshold, the dynamic adjustment of the low-frequency duration threshold along with the change of the current transaction time point is realized, and the accuracy of low-frequency transaction anomaly detection is improved.
[0023] It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present invention, nor is it used to limit the scope of the present invention. Other features of the present invention will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0024] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0025] Figure 1 is a flowchart of a low-frequency transaction anomaly detection method provided according to an embodiment of the present invention;
[0026] Figure 2 is a schematic diagram for determining the target historical transaction time point;
[0027] Figure 3 is a flowchart of another low-frequency transaction anomaly detection method provided according to an embodiment of the present invention;
[0028] Figure 4 is a flowchart of another low-frequency transaction anomaly detection method provided according to an embodiment of the present invention;
[0029] Figure 5 is a schematic structural diagram of a low-frequency transaction anomaly detection device provided according to an embodiment of the present invention;
[0030] Figure 6 is a schematic structural diagram of an electronic device for implementing the low-frequency transaction anomaly detection method of the embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0031] To enable those skilled in the art to better understand the solution of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0032] It should be noted that the terms "candidate", "target", etc. in the specification and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects, and do not have to be used to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device that includes a series of steps or units does not have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0033] Figure 1 A flowchart of a method for detecting abnormal low-frequency transactions is provided for an embodiment of the present invention. This embodiment is applicable to the situation of accurately monitoring abnormal low-frequency trading volumes. This method can be executed by a low-frequency trading anomaly detection device, which can be implemented in the form of hardware and / or software, and the low-frequency trading anomaly detection device can be configured in a server with computing capabilities. As Figure 1 shown, the method includes:
[0034] S110. Obtain the historical trading volumes at multiple historical trading time points and the current trading volume at the current trading time point according to a preset trading volume collection time interval, and construct a trading volume sequence.
[0035] Among them, the preset trading volume collection time interval refers to the preset trading volume statistical time interval, for example, one minute, that is, the time interval between two adjacent historical trading time points and between the current trading time point and the previous historical trading time point is the preset trading volume collection time interval.
[0036] Count the number of transactions generated within the time interval between the current transaction time point and the previous historical transaction time point as the current trading volume. Similarly, count the number of transactions generated within the time interval between each historical transaction time point and its corresponding previous historical transaction time point as the historical trading volume of that historical transaction time point. Sort the historical trading volumes of multiple historical transaction time points and the current trading volume at the current transaction time point in chronological order to construct a trading volume sequence.
[0037] Exemplarily, the trading volume sequence X consists of multiple transaction time points. Count the trading volume corresponding to each time point. The trading volume can be at granularities such as per hour, per minute, etc. Assume the length of the historical trading volume sequence X is d, then X = {x1, x2,..., xd}, the current trading volume is xd+1, xd is the historical trading volume of the previous historical transaction time point corresponding to the current transaction time point, and so on.
[0038] S120. Determine whether the current transaction time point is in a low-frequency trading state based on the current trading volume.
[0039] The low-frequency trading state means that the trading volume obtained within the time interval for collecting the trading volume corresponding to the current transaction time point is lower than the normal trading volume of the target user.
[0040] Specifically, determine the low-frequency trading volume threshold according to the normal trading volume of the target user within the preset trading volume collection time interval. If the current trading volume is less than this low-frequency trading volume threshold, it is determined that the current transaction point is in a low-frequency trading state, and it is necessary to further detect whether the current transaction point is in an abnormal low-frequency trading state. If the current trading volume is greater than or equal to this low-frequency trading volume threshold, it is determined that the current transaction point is in a non-low-frequency trading state, and continue to monitor the trading volume of the next transaction time point.
[0041] S130. If in a low-frequency trading state, determine the historical low-frequency duration of multiple target historical transaction time points according to the trading volume sequence.
[0042] Among them, the historical low-frequency duration is determined according to the duration of low-frequency trading before the target historical transaction time point.
[0043] If it is determined that the current transaction time point is in a low-frequency trading state, it is necessary to determine whether the low-frequency trading state at the current transaction time point is an abnormal state. Determine the corresponding target historical transaction time points with the same time characteristics according to the time characteristics of the current transaction time point, and determine the historical low-frequency duration of each target historical transaction time point according to the duration of being in a low-frequency trading state before the target historical transaction time point.
[0044] In a feasible embodiment, determining the historical low-frequency duration of multiple target historical transaction time points according to the trading volume sequence includes:
[0045] Determining a target time window corresponding to the current transaction time point within multiple historical cycles from multiple historical transaction time points according to a preset period and a preset window length;
[0046] Determining each historical transaction time point within the target time window as a target historical transaction time point;
[0047] Counting the continuous length of transaction time points in a low-frequency trading state before each target historical transaction time point according to the trading volume sequence, and determining the historical low-frequency duration of the target historical transaction time point according to the continuous length of the transaction time points.
[0048] Among them, the preset period is determined according to the period of the fluctuation law of the trading volume, such as one day or one week, etc. If the preset period is one day, it means that the same time points every day have similar trading rules. The preset window length is used to determine the number of selected target historical transaction time points, and can be determined according to the detection requirements of the user. For example, if the preset trading volume collection time interval is 1 minute, the preset window length is 5 minutes.
[0049] Selecting contemporaneous historical transaction time points as target historical transaction time points from multiple historical cycles according to the current transaction time point, where the number of selected historical cycles is determined according to the detection requirements of the user, and the specific value is not limited here. Specifically, as Figure 2 Shown in the schematic diagram for determining the target historical transaction time point, where t represents the current transaction time point in the current cycle, t1 is the first historical transaction time point corresponding to the current transaction time point in the previous historical cycle of the current cycle. Taking this first historical transaction time point as the time center, extending a preset window length forward and backward to obtain the target time window, that is, the time period from t1 - window to t1 + window is the target time window corresponding to the T - 1 historical cycle. Similarly, t2 is the second historical transaction time point corresponding to the current transaction time point in the first two historical cycles before the current cycle, and the time period from t2 - window to t2 + window is the target time window corresponding to the T - 2 historical cycle. tn is the nth historical transaction time point corresponding to the current transaction time point in the first n historical cycles before the current cycle, and the time period from tn - window to tn + window is the target time window corresponding to the T - N historical cycle. Taking the current transaction time point as the time center, extending a preset window length forward to obtain the target time window, that is, the time period from t - window to t is the target time window corresponding to the current T cycle.
[0050] Determine each historical transaction time point within all target time windows corresponding to the current T period to the T-N period as a target historical transaction time point. As Figure 2 shown, the historical transaction time points corresponding to the green part are target historical transaction time points.
[0051] Statistically count the consecutive length of transaction time points in the low-frequency trading state before each target historical transaction time point, and use this consecutive length of transaction time points as the historical low-frequency duration of this target historical transaction time point. Exemplarily, determine the adjacent historical transaction time points before t1, and determine whether the historical trading volume of this adjacent historical transaction time point is less than the low-frequency trading volume threshold. If it is less, continue to determine forward until it is determined that the historical trading volume of the historical transaction time point is greater than or equal to the low-frequency trading volume threshold. Take the number of adjacent consecutive historical transaction time points with historical trading volume less than the low-frequency trading volume threshold before t1 as the historical low-frequency duration of t1; if the historical trading volume of the adjacent historical transaction time point before t1 is greater than or equal to the low-frequency trading volume threshold, then determine that the historical low-frequency duration of t1 is 0. For example, determine the historical low-frequency duration sequence W = {w1, w2,..., wn} according to the historical low-frequency durations of all target historical transaction time points, where n = 2*window*N + N + window, and n is the number of target historical transaction time points.
[0052] S140. Determine the low-frequency duration threshold according to the historical low-frequency durations of multiple target historical transaction time points.
[0053] Determine the low-frequency duration threshold corresponding to the current transaction time point according to the historical low-frequency durations of multiple target historical transaction time points corresponding to the current transaction time point. Since the historical low-frequency durations of multiple target historical transaction time points are determined based on the current transaction time point, the low-frequency duration threshold determined according to the historical low-frequency durations of multiple target historical transaction time points can better reflect the low-frequency trading pattern of the current transaction time point and achieve dynamic adjustment of the low-frequency duration threshold.
[0054] Exemplarily, determine the low-frequency duration threshold according to the data statistical law of the historical low-frequency durations of multiple target historical transaction time points. For example, determine the low-frequency duration threshold according to the average value of the historical low-frequency durations of multiple target historical transaction time points.
[0055] In a feasible embodiment, S140 includes:
[0056] Construct a low-frequency trading continuous occurrence probability model according to the historical low-frequency durations of multiple target historical transaction time points;
[0057] Determine the low-frequency duration threshold according to the low-frequency trading continuous occurrence probability model.
[0058] Construct a low-frequency trading continuous occurrence probability model based on the historical low-frequency continuous durations at multiple target historical trading time points. The independent variable of the low-frequency trading continuous occurrence probability model is the low-frequency continuous duration at any trading time point, and the dependent variable is the low-frequency trading continuous occurrence probability corresponding to the low-frequency continuous duration at this trading time point. The low-frequency trading continuous occurrence probability model describes the occurrence probability and distribution characteristics of the low-frequency continuous duration in the historical low-frequency continuous durations. Determine the low-frequency continuous duration threshold corresponding to the current trading time point according to the occurrence probability and distribution characteristics. For example, determine the low-frequency trading continuous duration when the occurrence probability is a preset value according to the constructed low-frequency trading continuous occurrence probability model as the low-frequency continuous duration threshold.
[0059] S150. Determine the current low-frequency continuous duration corresponding to the current trading time point according to the trading volume sequence, and determine the low-frequency trading anomaly detection result at the current trading time point according to the comparison result between the current low-frequency continuous duration and the low-frequency continuous duration threshold.
[0060] Count the continuous length of the historical trading time points in the low-frequency trading state before the current trading time point, and use this continuous length of the historical trading time points as the current low-frequency continuous duration at the current trading time point. The determination method of the current low-frequency continuous duration is the same as that of the historical low-frequency continuous duration, and will not be elaborated here.
[0061] If the current low-frequency continuous duration at the current trading time point is greater than the low-frequency continuous duration threshold, determine that a low-frequency trading anomaly has occurred in the low-frequency trading anomaly detection result at the current trading time point; otherwise, determine that no low-frequency trading anomaly has occurred in the low-frequency trading anomaly detection result at the current trading time point, continue to detect the next trading time point, and determine the low-frequency continuous duration threshold corresponding to the next trading time point.
[0062] The technical solution of the embodiment of the present invention determines the historical low-frequency continuous durations of multiple target historical trading time points corresponding to the current trading time point in the low-frequency trading state, and then determines the low-frequency continuous duration threshold corresponding to the current trading time point according to the historical low-frequency continuous durations of multiple target historical trading time points. Determine the low-frequency trading anomaly detection result at the current trading time point according to the comparison result between the current low-frequency continuous duration corresponding to the current trading time point and the low-frequency continuous duration threshold, realizing dynamic adjustment of the low-frequency continuous duration threshold with the change of the current trading time point, and improving the accuracy of low-frequency trading anomaly detection.
[0063] Figure 3 It is a flowchart of another low-frequency trading anomaly detection method provided by the embodiment of the present invention. This embodiment further refines the step of dynamically determining the low-frequency continuous duration threshold in the above embodiment. As Figure 3 shown, this method includes:
[0064] S310. Obtain the historical trading volumes at multiple historical trading time points and the current trading volume at the current trading time point according to the preset trading volume collection time interval, and construct a trading volume sequence.
[0065] S320. Determine whether the current trading time point is in a low-frequency trading state according to the current trading volume.
[0066] S330. If it is in a low-frequency trading state, determine the historical low-frequency continuous durations at multiple target historical trading time points according to the trading volume sequence.
[0067] Among them, the historical low-frequency continuous duration is determined according to the low-frequency trading continuous duration before the target historical trading time point.
[0068] S340. Determine the target model from the candidate models according to the data characteristics of the historical low-frequency continuous durations at multiple target historical trading time points.
[0069] Construct a low-frequency trading continuous occurrence probability model for the historical low-frequency continuous durations at multiple target historical trading time points, which is used to describe the occurrence probability and its distribution characteristics of the low-frequency trading continuous window. The embodiments of the present invention are not limited to using a single probability distribution, but adopt candidate models of multiple distributions to better adapt to the heterogeneity and irregularity of low-frequency trading data. Among them, the candidate models include the Poisson distribution model and the Gamma distribution model. Different candidate models are applicable to historical low-frequency continuous durations with different data characteristics.
[0070] Assume that the historical low-frequency continuous durations at multiple target historical trading time points are sparse and random, and can be modeled by the Poisson distribution; assume that the historical low-frequency continuous durations at multiple target historical trading time points are positive random variables and have continuity, and can be modeled by the Gamma distribution. Determine the qualified target model from the Poisson distribution model and the Gamma distribution model according to the data characteristics of the historical low-frequency continuous durations at multiple target historical trading time points, which improves the accuracy of constructing the low-frequency trading continuous occurrence probability model according to the target model.
[0071] In a feasible embodiment, S340 includes:
[0072] Count the number of target historical trading time points with a historical low-frequency continuous duration value of 0 among the historical low-frequency continuous durations at multiple target historical trading time points;
[0073] If the number of target historical trading time points is greater than the first preset quantity threshold and the number of consecutive target historical trading time points with a historical low-frequency continuous duration value of 0 is less than the preset consecutive threshold, determine that the target model is the Poisson distribution model;
[0074] If the number of target historical transaction time points is less than or equal to the second preset quantity threshold, determine that the target model is a Gamma distribution model;
[0075] Otherwise, determine that the target models are a Poisson distribution model and a Gamma distribution model.
[0076] Count the number of target historical transaction time points with a value of 0 for the historical low-frequency duration among the historical low-frequency durations of multiple target historical transaction time points as the number of target historical transaction time points, and determine the maximum number of consecutive target historical transaction time points with a value of 0 for the historical low-frequency duration as the number of consecutive target historical transaction time points.
[0077] If the number of target historical transaction time points is greater than the first preset quantity threshold and the number of consecutive target historical transaction time points with a value of 0 for the historical low-frequency duration is less than the preset consecutive threshold, it means that there are many target historical transaction time points with a value of 0 for the historical low-frequency duration and they are not consecutive, that is, the historical low-frequency durations of multiple target historical transaction time points are sparse and random, then determine that the target model is a Poisson distribution model; if the number of target historical transaction time points is less than or equal to the second preset quantity threshold, it means that there are few target historical transaction time points with a value of 0 for the historical low-frequency duration, that is, the historical low-frequency durations of multiple target historical transaction time points are positive random variables and have continuity, determine that the target model is a Gamma distribution model; otherwise, determine that the target model is a mixed model of a Poisson distribution model and a Gamma distribution model. Exemplarily, the first preset quantity threshold, the preset consecutive threshold, and the second preset quantity threshold can be determined according to the number of target historical transaction time points. For example, the second preset quantity threshold can be 0, and the specific value is not limited in the embodiments of the present invention.
[0078] S350. Determine a low-frequency transaction continuous occurrence probability model according to the target model and the historical low-frequency durations of multiple target historical transaction time points.
[0079] If the target model is a Poisson distribution model, the low-frequency transaction continuous occurrence probability model is:
[0080]
[0081] where λ is the average number of occurrences of an event per unit time, and the specific value of λ is determined according to the simulation results of the target model based on the historical low-frequency durations of multiple target historical transaction time points.
[0082] If the target model is a Gamma distribution model, the low-frequency transaction continuous occurrence probability model is:
[0083]
[0084] Where, θ is the scale parameter, k is the shape parameter, Γ(k) is the Gamma function, and the specific values of the scale parameter and the shape parameter are determined according to the simulation results of the target model based on the historical low-frequency duration of multiple target historical transaction time points.
[0085] In a feasible embodiment, S350 includes:
[0086] If the target models are the Poisson distribution model and the Gamma distribution model, determine the model weights according to the number of target historical transaction time points;
[0087] Weight the Poisson distribution model and the Gamma distribution model according to the model weights to obtain a hybrid model;
[0088] Determine the low-frequency transaction continuous occurrence probability model according to the hybrid model and the historical low-frequency duration of multiple target historical transaction time points.
[0089] If the target models are the Poisson distribution model and the Gamma distribution model, the low-frequency transaction continuous occurrence probability model is:
[0090] P(X) = ω1P1(X) + ω2P2(X);
[0091] Where, P1(X) is the Poisson distribution, P2(X) is the Gamma distribution, ω1 and ω2 are the model weights, ω1 corresponding to the Poisson distribution model is the first model weight, and ω2 corresponding to the Gamma distribution model is the second model weight.
[0092] The values of the model weights are determined according to the number of target historical transaction time points with a historical low-frequency duration value of 0 in the historical low-frequency durations of multiple target historical transaction time points. The number of target historical transaction time points is positively related to the first model weight, that is, the larger the number of target historical transaction time points, the larger the value of the first model weight, and the values of the first model weight and the second model weight are 1. Exemplarily, a mapping relationship between the number of target historical transaction time points and the first model weight is established in advance, and this mapping relationship can be determined according to the statistical results of historical data and dynamically adjusted according to the feedback results of future data.
[0093] S360. Determine the low-frequency duration value corresponding to the preset confidence level in the low-frequency transaction continuous occurrence probability model, and determine the low-frequency duration value as the low-frequency duration threshold.
[0094] Based on the probability distribution of the historical low-frequency duration determined by the low-frequency trading continuous occurrence probability model, the low-frequency duration threshold is dynamically set for the real-time data stream at the current trading time point through the confidence interval of the probability distribution. Set a preset confidence level p, and find the critical value corresponding to the preset confidence level in the probability distribution as the low-frequency duration threshold Xanomaly. That is, P(X≤X anomaly ) = p. In the real-time trading data stream, once it is detected that the current low-frequency duration corresponding to the current trading time point is greater than the low-frequency duration threshold Xanomaly, it can be considered that a low-frequency trading anomaly has occurred at this time.
[0095] S370. Determine the current low-frequency duration corresponding to the current trading time point according to the trading volume sequence, and determine the low-frequency trading anomaly detection result at the current trading time point according to the comparison result between the current low-frequency duration and the low-frequency duration threshold.
[0096] The technical solution of the embodiment of the present invention constructs a low-frequency trading continuous occurrence probability model through the data characteristics of the historical low-frequency duration at multiple target historical trading time points, increases the adaptability of the model, and further improves the accuracy of determining the low-frequency duration threshold.
[0097] Figure 4 It is a flowchart of another low-frequency trading anomaly detection method provided by the embodiment of the present invention, which specifically includes:
[0098] S410. Determine the trading volume sequence.
[0099] Obtain the historical trading volumes at multiple historical trading time points and the current trading volume at the current trading time point according to the preset trading volume acquisition time interval, and construct a trading volume sequence.
[0100] S420. Judge the low-frequency trading state.
[0101] Judge whether the current trading time point is in the low-frequency trading state according to the current trading volume.
[0102] S430. Select historical data for the same period.
[0103] If in the low-frequency trading state, determine the target time window corresponding to the current trading time point within multiple historical periods from multiple historical trading time points according to the preset period and the preset window length; determine each historical trading time point within the target time window as the target historical trading time point as the historical data for the same period.
[0104] S440. Extract the low-frequency duration sequence.
[0105] Statistically analyze the continuous length of trading time points in the low-frequency trading state before each target historical trading time point according to the trading volume sequence, determine the historical low-frequency duration of the target historical trading time point according to the continuous length of the trading time point, and construct a low-frequency duration sequence according to the historical low-frequency durations of all target historical trading time points.
[0106] S450. Determine the low-frequency trading continuous occurrence probability model.
[0107] Determine the target model from the candidate models according to the data characteristics of the historical low-frequency durations of multiple target historical trading time points; wherein, the candidate models include a Poisson distribution model and a Gamma distribution model; determine the low-frequency trading continuous occurrence probability model according to the target model and the historical low-frequency durations of multiple target historical trading time points.
[0108] S460. Update the low-frequency duration threshold.
[0109] Determine the low-frequency duration value corresponding to the preset confidence level in the low-frequency trading continuous occurrence probability model, and determine the low-frequency duration value as the low-frequency duration threshold.
[0110] S470. Output the real-time low-frequency trading anomaly detection result.
[0111] Determine the current low-frequency duration corresponding to the current trading time point according to the trading volume sequence, and determine the low-frequency trading anomaly detection result of the current trading time point according to the comparison result between the current low-frequency duration and the low-frequency duration threshold.
[0112] The specific steps of this embodiment refer to the above-mentioned embodiment and will not be elaborated herein.
[0113] The embodiment of the present invention improves the accuracy of low-frequency trading anomaly detection and greatly enhances the adaptability of the probability model by combining probability distribution modeling with a flexible dynamic adjustment mechanism for the low-frequency duration threshold.
[0114] Figure 5 It is a structural schematic diagram of a low-frequency trading anomaly detection device provided by an embodiment of the present invention. As Figure 5 shown, the device includes:
[0115] A trading volume determination module 510, configured to obtain the historical trading volumes of multiple historical trading time points and the current trading volume of the current trading time point according to a preset trading volume acquisition time interval, and construct a trading volume sequence;
[0116] A low-frequency trading state judgment module 520, configured to judge whether the current trading time point is in a low-frequency trading state according to the current trading volume;
[0117] A historical low-frequency duration determination module 530, configured to, if in a low-frequency trading state, determine the historical low-frequency duration of multiple target historical trading time points according to the trading volume sequence; wherein, the historical low-frequency duration is determined according to the low-frequency trading duration before the target historical trading time point.
[0118] A low-frequency duration threshold determination module 540, configured to determine a low-frequency duration threshold according to the historical low-frequency durations of the multiple target historical trading time points.
[0119] An anomaly detection module 550, configured to determine the current low-frequency duration corresponding to the current trading time point according to the trading volume sequence, and determine the low-frequency trading anomaly detection result of the current trading time point according to the comparison result between the current low-frequency duration and the low-frequency duration threshold.
[0120] The technical solution of the embodiment of the present invention determines the historical low-frequency durations of multiple target historical trading time points corresponding to the current trading time point in a low-frequency trading state, and then determines the low-frequency duration threshold corresponding to the current trading time point according to the historical low-frequency durations of the multiple target historical trading time points. According to the comparison result between the current low-frequency duration corresponding to the current trading time point and the low-frequency duration threshold, the low-frequency trading anomaly detection result of the current trading time point is determined, realizing dynamic adjustment of the low-frequency duration threshold as the current trading time point changes, and improving the accuracy of low-frequency trading anomaly detection.
[0121] Optionally, the low-frequency duration threshold determination module includes:
[0122] A probability model construction unit, configured to construct a low-frequency trading continuous occurrence probability model according to the historical low-frequency durations of the multiple target historical trading time points.
[0123] A threshold determination unit, configured to determine a low-frequency duration threshold according to the low-frequency trading continuous occurrence probability model.
[0124] Optionally, the probability model construction unit includes:
[0125] A target model determination subunit, configured to determine a target model from candidate models according to the data characteristics of the historical low-frequency durations of the multiple target historical trading time points; wherein, the candidate models include a Poisson distribution model and a Gamma distribution model.
[0126] A probability model determination subunit, configured to determine the low-frequency trading continuous occurrence probability model according to the target model and the historical low-frequency durations of the multiple target historical trading time points.
[0127] Optionally, the target model determination subunit is specifically configured to:
[0128] Count the number of target historical transaction time points with a historical low-frequency duration value of 0 among the historical low-frequency durations of the multiple target historical transaction time points;
[0129] If the number of target historical transaction time points is greater than the first preset quantity threshold and the number of consecutive target historical transaction time points with a historical low-frequency duration value of 0 is less than the preset consecutive threshold, determine that the target model is a Poisson distribution model;
[0130] If the number of target historical transaction time points is less than or equal to the second preset quantity threshold, determine that the target model is a Gamma distribution model;
[0131] Otherwise, determine that the target model is a Poisson distribution model and a Gamma distribution model.
[0132] Optionally, the probability model determination subunit is specifically configured to:
[0133] If the target model is a Poisson distribution model and a Gamma distribution model, determine the model weights according to the number of target historical transaction time points;
[0134] Weight the Poisson distribution model and the Gamma distribution model according to the model weights to obtain a hybrid model;
[0135] Determine the low-frequency transaction continuous occurrence probability model according to the hybrid model and the historical low-frequency durations of the multiple target historical transaction time points.
[0136] Optionally, the threshold determination unit is specifically configured to:
[0137] Determine the low-frequency duration value corresponding to a preset confidence level in the low-frequency transaction continuous occurrence probability model, and determine the low-frequency duration value as the low-frequency duration threshold.
[0138] Optionally, the historical low-frequency duration determination module is specifically configured to:
[0139] Determine a target time window corresponding to the current transaction time point within multiple historical periods from the multiple historical transaction time points according to a preset period and a preset window length;
[0140] Determine each historical transaction time point within the target time window as a target historical transaction time point;
[0141] According to the trading volume sequence, count the continuous length of the transaction time points in the low-frequency trading state before each target historical transaction time point, and determine the historical low-frequency duration of the target historical transaction time point according to the continuous length of the transaction time points.
[0142] The low-frequency trading anomaly detection device provided by the embodiments of the present invention can execute the low-frequency trading anomaly detection method provided by any embodiment of the present invention, and has the corresponding functional modules and beneficial effects for executing the method.
[0143] In the technical solution of this application, the acquisition, storage, use, processing, etc. of data all comply with the relevant regulations of national laws and regulations, and do not violate public order and good customs.
[0144] According to an embodiment of the present disclosure, the present disclosure also provides an electronic device, a readable storage medium, and a computer program product.
[0145] Figure 6 FIG. shows a schematic structural diagram of an electronic device 10 that can be used to implement the embodiments of the present invention. The electronic device is intended to represent various forms of digital computers, such as, for example, a laptop computer, a desktop computer, a workbench, a personal digital assistant, a server, a blade server, a mainframe computer, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as, for example, a personal digital processor, a cellular phone, a smart phone, a wearable device (such as a helmet, glasses, a watch, etc.) and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the present invention described and / or claimed herein.
[0146] As Figure 6 shown, the electronic device 10 includes at least one processor 11, and a memory communicatively connected to the at least one processor 11, such as a read-only memory (ROM) 12, a random access memory (RAM) 13, etc. Among them, the memory stores a computer program executable by the at least one processor. The processor 11 can execute various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 12 or the computer program loaded from the storage unit 18 into the random access memory (RAM) 13. In the RAM 13, various programs and data required for the operation of the electronic device 10 can also be stored. The processor 11, the ROM 12, and the RAM 13 are connected to each other through a bus 14. The input / output (I / O) interface 15 is also connected to the bus 14.
[0147] A plurality of components in the electronic device 10 are connected to the I / O interface 15, including: an input unit 16, such as a keyboard, a mouse, etc.; an output unit 17, such as various types of displays, speakers, etc.; a storage unit 18, such as a magnetic disk, an optical disc, etc.; and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the electronic device 10 to exchange information / data with other devices through a computer network such as the Internet and / or various telecommunication networks.
[0148] The processor 11 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The processor 11 executes the various methods and processes described above, such as the low-frequency trading anomaly detection method.
[0149] In some embodiments, the low-frequency trading anomaly detection method can be implemented as a computer program tangibly embodied in a computer-readable storage medium, such as the storage unit 18. In some embodiments, part or all of the computer program can be loaded and / or installed onto the electronic device 10 via the ROM 12 and / or the communication unit 19. When the computer program is loaded into the RAM 13 and executed by the processor 11, one or more steps of the low-frequency trading anomaly detection method described above can be executed. Alternatively, in other embodiments, the processor 11 can be configured to execute the low-frequency trading anomaly detection method in any other suitable manner (e.g., by means of firmware).
[0150] Various embodiments of the systems and techniques described above in this document can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGA), application-specific integrated circuits (ASIC), application-specific standard products (ASSP), system-on-a-chip systems (SOC), complex programmable logic devices (CPLD), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include: being implemented in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which can be a dedicated or general-purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit the data and instructions to the storage system, the at least one input device, and the at least one output device.
[0151] The computer program for implementing the method of the present invention can be written in any combination of one or more programming languages. These computer programs can be provided to the processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when the computer program is executed by the processor, the functions / operations specified in the flowchart and / or block diagram are implemented. The computer program can be executed entirely on the machine, partially on the machine, as an independent software package partially on the machine and partially on a remote machine, or entirely on a remote machine or server.
[0152] In the context of the present invention, a computer-readable storage medium can be a tangible medium that can contain or store a computer program for use by or in connection with an instruction execution system, apparatus, or device. The computer-readable storage medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. Alternatively, the computer-readable storage medium can be a machine-readable signal medium. More specific examples of the machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0153] To provide for interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the electronic device. Other kinds of devices can also be used to provide for interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, speech input, or tactile input).
[0154] The systems and techniques described herein can be implemented in a computing system that includes backend components (such as, for example, a data server), or a computing system that includes middleware components (such as, for example, an application server), or a computing system that includes frontend components (such as, for example, a user computer having a graphical user interface or a web browser through which the user can interact with an implementation of the systems and techniques described herein), or a computing system that includes any combination of such backend components, middleware components, or frontend components. The components of the system can be interconnected by any form or medium of digital data communication (such as, for example, a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), a blockchain network, and the Internet.
[0155] A computing system may include a client and a server. The client and the server are generally far from each other and usually interact via a communication network. The relationship between the client and the server is created by computer programs running on respective computers and having a client-server relationship with each other. The server may be a cloud server, also known as a cloud computing server or a cloud host, which is a host product in the cloud computing service system, and solves the defects of difficult management and weak business scalability existing in traditional physical hosts and VPS services.
[0156] It should be understood that various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps described in the present invention can be executed in parallel, sequentially, or in a different order, as long as the desired results of the technical solution of the present invention can be achieved, and no limitation is made herein.
[0157] The above specific embodiments do not constitute a limitation on the protection scope of the present invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.
Claims
1. A method for detecting anomalies in low-frequency transactions, characterized in that: The method includes: Obtain the historical transaction volumes at multiple historical transaction time points and the current transaction volume at the current transaction time point according to the preset transaction volume collection time interval, and construct a transaction volume sequence; Determining whether the current trading time point is in a low-frequency trading state according to the current trading volume; If it is in a low-frequency trading state, the historical low-frequency duration of multiple target historical trading time points is determined according to the trading volume sequence; wherein the historical low-frequency duration is determined according to the low-frequency trading duration before the target historical trading time point; Determine a low frequency duration threshold according to the historical low frequency durations of the multiple target historical transaction time points; The current low-frequency duration corresponding to the current transaction time point is determined according to the transaction volume sequence, and the low-frequency transaction anomaly detection result at the current transaction time point is determined according to the comparison result between the current low-frequency duration and the low-frequency duration threshold.
2. The method according to claim 1, characterized in that Determining a low frequency duration threshold according to the historical low frequency durations of the multiple target historical transaction time points includes: Constructing a low-frequency transaction continuous occurrence probability model according to the historical low-frequency duration of the multiple target historical transaction time points; The low-frequency transaction duration threshold is determined according to the low-frequency transaction continuous occurrence probability model.
3. The method according to claim 2, characterized in that A low-frequency transaction continuous occurrence probability model is constructed according to the historical low-frequency duration of the multiple target historical transaction time points, including: Determine a target model from candidate models according to data characteristics of the historical low-frequency duration of the multiple target historical transaction time points; wherein the candidate models include a Poisson distribution model and a Gamma distribution model; A probability model for the continued occurrence of the low-frequency transactions is determined according to the target model and the historical low-frequency durations of the multiple target historical transaction time points.
4. The method according to claim 3, characterized in that Determining a target model from candidate models according to data features of historical low-frequency durations of the multiple target historical transaction time points includes: Counting the number of target historical transaction time points whose historical low frequency duration value is 0 among the historical low frequency durations of the multiple target historical transaction time points; If the number of target historical transaction time points is greater than a first preset number threshold and the number of consecutive target historical transaction time points whose value of the historical low-frequency duration is 0 is less than a preset continuous threshold, it is determined that the target model is a Poisson distribution model; If the target number of historical transaction time points is less than or equal to a second preset number threshold, determining that the target model is a Gamma distribution model; Otherwise, the target model is determined to be a Poisson distribution model and a Gamma distribution model.
5. The method according to claim 4, characterized in that Determining the low-frequency transaction continuous occurrence probability model according to the target model and the historical low-frequency durations of the multiple target historical transaction time points includes: If the target model is a Poisson distribution model or a Gamma distribution model, the model weight is determined according to the number of target historical transaction time points; The Poisson distribution model and the Gamma distribution model are weighted according to the model weight to obtain a mixed model; A probability model for the continued occurrence of low-frequency transactions is determined based on the hybrid model and the historical low-frequency durations of the multiple target historical transaction time points.
6. The method according to any one of claims 2 to 5, characterized in that: Determining the low-frequency transaction duration threshold according to the low-frequency transaction continuous occurrence probability model includes: Determine a low-frequency duration value corresponding to a preset confidence level in the probability model for continuous occurrence of low-frequency transactions, and determine the low-frequency duration value as the low-frequency duration threshold.
7. The method according to claim 1, characterized in that Determine the historical low frequency duration of multiple target historical transaction time points according to the transaction volume sequence, including: Determining, from the plurality of historical transaction time points, a target time window corresponding to the current transaction time point within a plurality of historical periods according to a preset period and a preset window length; Determining each historical transaction time point within the target time window as a target historical transaction time point; The continuous length of the transaction time points in the low-frequency transaction state before each target historical transaction time point is counted according to the transaction volume sequence, and the historical low-frequency duration of the target historical transaction time point is determined according to the continuous length of the transaction time points.
8. A low-frequency transaction anomaly detection device, characterized in that: The device includes: A transaction volume determination module, used to obtain the historical transaction volumes at multiple historical transaction time points and the current transaction volume at the current transaction time point according to a preset transaction volume collection time interval, and to construct a transaction volume sequence; A low-frequency trading state judgment module, used to judge whether the current trading time point is in a low-frequency trading state according to the current trading volume; A historical low frequency duration determination module is used to determine the historical low frequency duration of multiple target historical transaction time points according to the transaction volume sequence if the module is in a low frequency transaction state; wherein the historical low frequency duration is determined according to the low frequency transaction duration before the target historical transaction time point; A low frequency duration threshold determination module, used to determine a low frequency duration threshold according to the historical low frequency durations of the multiple target historical transaction time points; An anomaly detection module is used to determine the current low-frequency duration corresponding to the current transaction time point according to the transaction volume sequence, and determine the low-frequency transaction anomaly detection result at the current transaction time point according to the comparison result of the current low-frequency duration and the low-frequency duration threshold.
9. An electronic device, characterized in that: The electronic device comprises: at least one processor; and a memory communicatively connected to the at least one processor; wherein, The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the low-frequency transaction anomaly detection method according to any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the low-frequency transaction anomaly detection method according to any one of claims 1 to 7 when executed.