Fraudulent transaction detection model construction method and system based on graph data enhancement

By combining data augmentation technology and graph induction network methods, the problems of data imbalance and abnormal samples neglect in abnormal detection and fraud transaction identification in the financial field are solved, and higher detection accuracy is achieved.

CN120047151AInactive Publication Date: 2025-05-27JIMEI UNIV
View PDF 8 Cites 0 Cited by

Patent Information

Application Number
CN202510115244.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-24
Publication Date
2025-05-27
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

In the abnormal detection and fraudulent transaction identification in the financial field, the existing technology faces the problems of data imbalance and neglect of abnormal samples, which leads to the model's bias towards most classes during training, making it difficult to effectively learn the characteristics of abnormal transactions, affecting the detection accuracy.

Method used

Using a method combining data augmentation technology and graph induction network, the model can better capture the characteristics of a few types of abnormal transactions by generating synthetic data. The specific steps include collecting user transaction data, building a first-order transaction subgraph, calculating hidden layer features, using condition generation adversarial networks to enhance data, and performing secondary training on the graph summary network to improve detection accuracy.

Benefits of technology

It effectively solves the problems of data imbalance and neglect of abnormal samples, significantly improves the overall performance of abnormal transaction detection, and improves detection accuracy.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120047151A_ABST
    Figure CN120047151A_ABST
Patent Text Reader

Abstract

The invention provides a fraudulent transaction detection model construction method and system based on graph data enhancement. The method comprises the steps of collecting existing user transaction data and performing aggregation calculation to obtain a transaction statistical feature vector; collecting historical transaction records of two transaction parties in the same time window, extracting historical transaction characteristics, and constructing a first-order transaction sub-graph with first-order neighbors of the two transaction parties; calculating hidden layer features of two transaction parties and neighbor nodes based on historical transaction features, and combining the hidden layer features of the two transaction parties and the hidden layer features of the neighbor nodes by using a weight and an activation function of a graph induction network to obtain hidden layer features of the transaction features; inputting hidden layer features of the transaction features and features of the first-order transaction sub-graph into a hidden layer condition generation adversarial network to obtain simulated historical transaction statistical features; and performing secondary training on the graph induction network by using a cross entropy loss function to obtain a trained graph induction network, and inputting transaction data of the to-be-detected user into the graph induction network to complete fraudulent transaction detection.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of anomaly detection and fraudulent transaction identification based on deep learning, and in particular to a method for constructing a fraudulent transaction detection model based on graph data enhancement. Background Art

[0002] In the financial sector, anomaly detection and identification of fraudulent transactions are critical tasks to protect institutions and consumers from huge financial losses. These tasks usually involve the use of a variety of analytical techniques, including statistical analysis, rule-based systems, and machine learning models. Through these techniques, a model of normal transaction behavior can be built based on historical data, and behaviors that are significantly different from the model can be identified and marked as potential fraud or anomalies.

[0003] Graph networks are playing an increasingly important role in anomaly detection and fraudulent transaction identification due to their unique ability to process and analyze relational data. Graph networks can grasp the complex dependencies between financial transactions by learning the feature representations of nodes and their interconnections in the graph. However, there are two major challenges in practical applications: data imbalance and neglect of abnormal samples. The data imbalance problem refers to the fact that normal transaction data far outweighs fraudulent transaction data, causing the model to be biased towards the majority class during training. In addition, due to data skew, the model often ignores abnormal transaction samples, making it difficult to effectively learn their features, thus affecting detection accuracy. Representatives of this type of method include CN108596630A "Fraudulent transaction identification method, system and storage medium based on deep learning" disclosed by China Merchants Bank, CN113506109A "Fraudulent transaction identification method and device" disclosed by Industrial and Commercial Bank of China, CN108428132B "Fraudulent transaction identification method, device, server and storage medium" authorized by Alibaba, CN108428132B "Fraudulent transaction identification method, device, server and storage medium" authorized by Innovation Advanced Technology Co., Ltd., CN118070141B "Anti-fraud transaction identification method and system based on artificial intelligence" authorized by Chengdu Lechaoren Technology Co., Ltd., and CN111105241B "A method for identifying fraud in credit card transactions" authorized by Zhejiang Gongshang University. Summary of the invention

[0004] In view of the above problems, the present invention proposes a method combining data enhancement technology and graph induction network to improve the accuracy of abnormal transaction detection, which specifically includes:

[0005] Step S1: Collect existing user transaction data, and perform statistical calculations on the user transaction data to obtain a transaction statistical feature vector;

[0006] Step S2: according to the selected preset time window, historical transaction records of both parties in the same time window are collected, and then historical transaction features of the historical transaction records are extracted; a first-order transaction subgraph is constructed based on the historical transaction features of both parties and the historical transaction features of the first-order neighbor nodes of the two parties in the same time window;

[0007] Step S3, based on the historical transaction features, calculating the hidden features of the transaction parties and the hidden features of the first-order neighbor nodes, and combining the hidden features of the transaction parties and the hidden features of the first-order neighbor nodes using the weights and activation function of the graph induction neural network to obtain the hidden features of the transaction features;

[0008] Step S4: construct a hidden layer conditional generative adversarial network based on the conditional generative adversarial network loss function and input the hidden layer features of the transaction features and the features of the first-order transaction subgraph into the hidden layer conditional generative adversarial network to obtain simulated historical transaction statistical features;

[0009] Step S5: Based on the simulated historical transaction statistical features, the graph induction network is trained twice using a cross entropy loss function to obtain a trained graph induction network, and the transaction data of the user to be detected is input into the graph induction network to complete fraudulent transaction detection.

[0010] Optionally, in step S1, the first-order transaction subgraph includes the paying account, the receiving account, the first-order neighbors of the paying account, i.e., the account that has direct transactions with the paying account, the first-order neighbors of the receiving account, i.e., the account that has direct transactions with the receiving account, the first-order neighbors of the paying neighbor account and the first-order neighbors of the receiving neighbor account.

[0011] Optionally, in step S3, the calculation process of the hidden layer features of the neighboring nodes includes:

[0012]

[0013] in, is the statistical feature vector of the i-th transaction between the transaction neighbor nodes of the two parties in the time window T, h i is the hidden feature vector obtained from the i-th transaction of the neighbor node, c i is the auxiliary vector and LSTM(·) is the aggregation function.

[0014] Optionally, in step S3, the hidden features h of the transaction features are obtained by combining the hidden features of the transaction parties and the hidden features of the neighboring nodes using the weights and activation functions of the graph induction network:

[0015] Input the transaction statistical feature vector of the payer and the payee of the neighbor node into the hidden layer feature calculation formula of step S3 to obtain and based on h in and h out Calculate the hidden features h of transaction features:

[0016]

[0017] Among them, σ is the activation function, W is the weight, is the hidden layer feature of the neighbor node recipient within the time window T, is the hidden layer feature of the payer of the neighbor node in the time window T, h in is the hidden feature of the payer, h out is the hidden feature of the payee.

[0018] The present invention also discloses a fraudulent transaction detection model construction system based on graph data enhancement, the system comprising:

[0019] A data collection and preprocessing module, used to collect existing user transaction data, perform statistical calculations on the user transaction data to obtain a transaction statistical feature vector;

[0020] A transaction subgraph generation module is used to collect historical transaction records of both parties in the same time window according to a selected preset time window, extract historical transaction features of the historical transaction records, and construct a first-order transaction subgraph based on the historical transaction features of both parties and the historical transaction features of the first-order neighbor nodes of the two parties in the same time window;

[0021] A hidden layer feature calculation module, used to calculate the hidden layer features of the transaction parties and the hidden layer features of the first-order neighbor nodes based on the historical transaction features, and to combine the hidden layer features of the transaction parties and the hidden layer features of the first-order neighbor nodes using the weights and activation functions of the graph induction neural network to obtain the hidden layer features of the transaction features;

[0022] A simulated historical transaction statistical feature generation module is used to construct a hidden layer conditional generative adversarial network based on a conditional generative adversarial network loss function and input the hidden layer features of the transaction features and the features of the first-order transaction subgraph into the hidden layer conditional generative adversarial network to obtain simulated historical transaction statistical features;

[0023] The fraudulent transaction detection module is used to perform secondary training on the graph induction network based on the simulated historical transaction statistical features using a cross entropy loss function to obtain a trained graph induction network, input the transaction data of the user to be detected into the graph induction network, and complete fraudulent transaction detection.

[0024] Optionally, in the data collection and preprocessing module, the first-order transaction subgraph includes the paying account, the receiving account, the first-order neighbors of the paying account, i.e., the account that has direct transactions with the paying account, the first-order neighbors of the receiving account, i.e., the account that has direct transactions with the receiving account, the first-order neighbors of the paying neighbor account and the first-order neighbors of the receiving neighbor account.

[0025] Optionally, in the hidden layer feature calculation module, the calculation process of the hidden layer features of the neighboring nodes includes:

[0026]

[0027] in, is the statistical feature vector of the ith transaction between the transaction neighbors of the two transaction parties within the time window T, h i is the hidden vector corresponding to the i-th transaction of the neighbor node, c i is the auxiliary vector and LSTM(·) is the aggregation function.

[0028] Optionally, in the hidden layer feature calculation module, the hidden layer features of the transaction parties and the hidden layer features of the neighboring nodes are combined using the weights and activation functions of the graph induction network to obtain the hidden layer features h of the transaction features, which are specifically:

[0029] The transaction statistical feature vector of the payer and the payee of the neighboring node is input into the hidden layer feature calculation formula of the hidden layer feature calculation module to obtain and based on h in and h out Calculate the hidden features h of transaction features:

[0030]

[0031] Among them, σ is the activation function, W is the weight, is the hidden layer feature of the neighbor node recipient within the time window T, is the hidden layer feature of the payer of the neighbor node in the time window T, h in is the hidden feature of the payer, h out is the hidden feature of the payee.

[0032] Compared with the prior art, the present invention has the following beneficial effects:

[0033] The present invention uses data enhancement technology to generate synthetic data to balance the category distribution, helping the model to better capture the characteristics of the minority class (i.e., abnormal transactions). At the same time, the graph induction network uses its powerful recognition ability of complex relationships and patterns to obtain the transaction relationship of the account and capture possible illegal patterns, further improving the detection accuracy. It can effectively solve the problems of data imbalance and abnormal sample neglect in graph network applications, and significantly improve the overall performance of abnormal transaction detection. BRIEF DESCRIPTION OF THE DRAWINGS

[0034] In order to more clearly illustrate the technical solution of the present invention, the following briefly introduces the drawings required for use in the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative labor.

[0035] Figure 1 This is a schematic diagram of a transaction subgraph according to an embodiment of the present invention;

[0036] Figure 2 A schematic diagram of generating sub-graph simulation data for an embodiment of the present invention;

[0037] Figure 3 A method step diagram of a method combining data enhancement technology and graph induction network according to an embodiment of the present invention;

[0038] Figure 4 This is an example diagram of the transaction subgraph network data dimension according to an embodiment of the present invention;

[0039] Figure 5 Schematic diagram of the network architecture of the conditional adversarial network according to an embodiment of the present invention. DETAILED DESCRIPTION

[0040] In order to make the above-mentioned objects, features and advantages of the present invention more obvious and easy to understand, the present invention is further described in detail below with reference to the accompanying drawings and specific embodiments.

[0041] The meanings of the relevant terms used in the present invention are as follows:

[0042] User transaction data: current transaction accounts and amounts;

[0043] Transaction statistical feature vector: transaction statistical information calculated by both parties based on the time window;

[0044] Historical transaction records: query the database to see what other accounts the current trading account traded with within the time window;

[0045] Generator target: Statistical feature vector of historical transactions between two parties, used for graph network training.

[0046] Embodiment 1

[0047] A method that combines data augmentation techniques and graph induction networks, such as Figure 3 As shown, the method includes:

[0048] Step S1: Collect existing user transaction data, and perform statistical calculations on the user transaction data to obtain a transaction statistical feature vector.

[0049] First, use a database that can efficiently store and query transaction data, including key fields such as user ID, transaction time, transaction amount, and transaction type. Through an online trading platform or financial management system, when a user completes a transaction, the relevant data is recorded in a database including but not limited to Mysql, redis, etc., ensuring that all necessary information is included to support subsequent analysis.

[0050] By determining the time window (such as monthly, weekly, etc.), the transaction data within the corresponding time period is extracted from the database. The data of each user is aggregated and calculated to obtain statistical indicators such as total transaction amount, number of transactions, average transaction amount, etc., and the transaction statistical feature vectors of both parties are constructed based on these statistical results.

[0051] Before an account transaction occurs, four time windows can be used to analyze the user's transaction behavior: 1 month, 1 week, 1 day, and 1 hour. For each time window, we extract the user's transaction data from the database and calculate statistical indicators such as total transaction amount, number of transactions, average transaction amount, maximum and minimum transaction amount, standard deviation of transaction amount, and average transaction interval time.

[0052] For example, within a one-month window, we found that a certain user made 50 transactions with a total transaction amount of 5,000, so the average transaction amount is 100, and the maximum, minimum and standard deviation of the user's transaction amount are obtained based on the details. In addition, transaction time information can also be obtained, such as an average transaction every 15 hours, and this transaction is 4 hours away from the last transaction. Based on these statistical results, a transaction statistical feature vector for each user is constructed. These features can be shown in the form of Table 1:

[0053] Table 1

[0054]

[0055] The statistical features of the account transaction features obtained in step 1 can be divided into two types: collection and payment. Therefore, before the transaction occurs, the statistical feature dimensions of accounts A and B in a period of time are 8+8, where the first dimension is the amount of the transaction, and the 8 dimensions represent the statistical features of collection and payment respectively.

[0056] When four time windows (1 month, 1 week, 1 day, 1 hour) are set according to step 1, the statistical characteristics of an account are (8+8)*4=64 dimensions.

[0057] Step S2: According to the selected preset time window, collect the historical transaction records of the two transaction parties in the same time window and extract the historical transaction features of the historical transaction records; and construct a first-order transaction subgraph based on the historical transaction features of the two transaction parties and the historical transaction features of the first-order neighbor nodes of the two transaction parties in the same time window.

[0058] In the process of constructing a transaction subgraph, we first need to select an appropriate time window T to collect the historical transaction records of both parties (nodes A and B). Then, within the time window T, collect all nodes that have transactions with nodes A and B and their transaction information. Based on these collected data, the results of module one are used to obtain the transaction statistical feature vectors of each node involved, including transaction information such as transfer amount, transaction amount mean, transaction amount variance, transaction time variance, and time since the last transaction. Finally, the transaction statistical characteristics and network structure information are obtained directly through query, and a transaction subgraph covering nodes A and B is generated. The subgraph includes first-order neighboring nodes. The specific steps are as follows:

[0059] Using the database and calculation method of module 1, we can obtain the transaction characteristics of accounts A and B before the transaction occurs with a total time window T, and obtain their first-order neighbors to construct a first-order transaction subgraph as follows: Figure 1 shown.

[0060] In the present invention, the first-order transaction subgraph is used for the following reasons: 1) the first-order neighbors have less time complexity. 2) since the account characteristics include the collection and payment characteristics, part of the second-order neighbor information is included.

[0061] Through the database in step 1, query the transaction object account set S of both parties in the time window T (T can also be set to 1 month) A , S B , and obtain S again according to the time window T A , S B The transaction set S A1 , S B2 , and calculate the statistical characteristics of Table 1. Calculate the transaction characteristics according to Table 1. In summary, the approximate calculation scope and data dimensions of this transaction are as follows Figure 4 shown.

[0062] Step S3: based on the historical transaction features, calculate the hidden features of the transaction parties and the hidden features of the first-order neighbor nodes, and use the weights and activation function of the graph induction neural network to combine the hidden features of the transaction parties and the hidden features of the first-order neighbor nodes to obtain the hidden features of the transaction features.

[0063] The graph induction network is used to extract transaction features. The graph induction algorithm updates the feature representation of nodes by aggregating the neighbor transaction information of the receiving and paying nodes using the aggregation function LSTM. For each transaction i, based on the historical transaction features x calculated by its neighbor nodes in module 1 and the previous hidden layer aggregation features, Calculate the current hidden layer aggregation features

[0064]

[0065] here It is the transaction statistical feature vector of the transaction neighbors collected within the time window T, sorted from far to near by transaction time to highlight the timing of transactions. The hidden layer features h of all neighbor nodes are obtained i c and the hidden features h of both parties i and h j (payer and payee), these features will be combined through the fully connected layer, and the weight W and activation function σ are used to obtain the hidden feature representation of the transaction features:

[0066]

[0067] This final hidden layer feature h will be used as the condition of the conditional generative adversarial network and the input of the hidden layer simulation generation algorithm to generate the corresponding account subgraph for data enhancement. In this way, on the one hand, the transaction information of neighboring nodes can be aggregated, and on the other hand, LSTM can aggregate neighboring nodes according to transaction time, which is in line with the timeliness of transactions.

[0068] For each transaction record i, query the neighbors S of transaction accounts A and B within the T time window of i A , S B The transaction statistics feature vector Sort the transactions by time from far to near, and use LSTM to extract the hidden features of neighbor nodes.

[0069] Take payer A as an example, assuming The length of is m, m can be calculated according to the transaction length in the draw time window T of the corresponding data set in step 1, and the hidden layer features are extracted as follows.

[0070]

[0071] in, is the statistical feature of the i-th transaction between the transaction neighbor nodes of the two parties in the time window T, h i is the hidden feature vector obtained from the i-th transaction of the neighbor node, c iis the auxiliary vector and LSTM(·) is the aggregation function.

[0072] Similarly, similar calculations are performed on the payee B to obtain the corresponding hidden layer features.

[0073] If the hidden features of the payer and the payee are represented by the superscripts in and out, and are substituted into formula (3), the hidden features of the neighbor nodes are obtained: After that, the hidden features h of the two parties are in and h out Perform full connection, using weight W k And the activation function σ obtains the hidden feature representation of the transaction feature, as shown in the following formula:

[0074]

[0075] Among them, σ is the activation function, W is the weight, is the hidden layer feature of the neighbor node recipient within the time window T, is the hidden layer feature of the payer of the neighbor node in the time window T, h in is the hidden feature of the payer, h out is the hidden feature of the payee.

[0076] During the back propagation process, fraud samples can be labeled according to user feedback or reports, so as to train the corresponding hidden data in the hidden features h of the transaction features.

[0077] Step S4: construct a hidden layer conditional generative adversarial network based on the conditional generative adversarial network loss function and input the hidden layer features of the transaction features and the features of the first-order transaction subgraph into the hidden layer conditional generative adversarial network to obtain simulated historical transaction statistical features.

[0078] According to the hidden layer data and subgraph data of the fraudulent transaction, the conditional generative adversarial network is trained, and the simulated data generated by the generator G is used as the result of data enhancement. This embodiment proposes to use the conditional generative adversarial network as a data enhancement method. The correspondence between the minority class samples and the simulated data can be more accurately defined. Using formula (5) as the input of the conditional generative adversarial network, the conditional generative adversarial network loss function is as shown in formula (5):

[0079] l cGAN(G,D) =E h,x [logD(h,sg)]+E h,z [log(1-D(h,G(h,z)))] (5)

[0080] Among them, sg represents the aggregated features of historical transactions of transaction accounts connected to neighbors, D represents the discriminator, and G represents the generator. The flowchart of the hidden layer conditional generative adversarial network is as follows: Figure 2 .

[0081] Use the conditional generative adversarial network loss function to build a conditional generative adversarial network.

[0082] exist Figure 2 In , the transaction subgraph may include a payer or payee subgraph, and the transaction statistical feature vector represents the transaction aggregation feature of the payer's historical transaction node. The generator G generates the subgraph transaction aggregation feature based on the hidden feature h, and the discriminator D makes a judgment based on the simulated transaction statistical feature vector sg' and the real transaction statistical feature vector sg. The generator G uses the hidden feature h as input, and the output of the generator G is calculated in the following way:

[0083] sg'=G(h sys ) (6)

[0084] Among them, h sys It is the system hidden layer interpolation feature obtained from the graph induction network model. According to the distribution of nodes in the hidden layer, it combines SMOTE and other interpolation methods (including but not limited to SMOTE, MWMOTE, etc.) to generate data. In order to ensure that the generated data is associated with specific minority class samples, the present invention uses the hidden layer features of the nodes and the transaction subgraph features as conditional inputs.

[0085] Ignore the noise z, use h as the input of the generator, train the conditional generative adversarial network, and the conditional adversarial network design is as follows Figure 5 As shown in the figure, 16, 32, and 2 represent the hidden layer data dimensions, 64 represents the aggregated features calculated in step 2, and m represents the neighbor length preset in step 3. Figure 5 The network setting is to train the generator G and the discriminator D with h as the condition and sg as the generation target.

[0086] Step S5: Based on the simulated historical transaction statistical features, the graph induction network is trained twice using a cross entropy loss function to obtain a trained graph induction network, and the transaction data of the user to be detected is input into the graph induction network to complete fraudulent transaction detection.

[0087] According to the SMOTE simulation data algorithm, the hidden layer simulation vector is determined to generate the corresponding simulation subgraph. The hidden layer calculation method based on SMOTE is as follows.

[0088] h sys =h dd +r*(h dn -h dd ),0≤r≤1 (7)

[0089] Among them, h dd represents the virtual fraud hidden data sample corresponding to the fraudulent transaction, h dn Indicates hdd The virtual fraud hidden layer data samples of neighbors. r represents a random number, h sys Represents the generated hidden layer simulation data. The number of generated data can be set as a multiple of the number of fraud samples, such as 1, 2, ..., 10, etc. The transaction subgraph is generated according to the generator G trained in step 4.

[0090] sg=G(h) (8)

[0091] Use the Euclidean distance of hidden layer nodes to determine the corresponding samples in the hidden layer space according to the following formula.

[0092]

[0093] Among them, h v represents fraud samples with similar distance in the latent space, h sys The generated subgraph is g sys ={x Node , sg}, the central node is Node, and the neighbor historical transaction statistical features are sg. According to the retrained graph induction network model, fraudulent transactions are judged. The original data and the added subgraph are used to enhance the data g sys Retraining graph induction networks.

[0094] After retraining, before each transaction occurs, use step S1 to calculate the statistical features and use step S2 to calculate the transaction subgraph to determine whether it is fraudulent.

[0095] Embodiment 2

[0096] A system combining data augmentation technology and graph induction network, the system comprising:

[0097] The data collection and preprocessing module is used to collect existing user transaction data and perform statistical calculations on the user transaction data to obtain transaction statistical feature vectors.

[0098] First, use a database that can efficiently store and query transaction data, including key fields such as user ID, transaction time, transaction amount, and transaction type. Through an online trading platform or financial management system, when a user completes a transaction, the relevant data is recorded in a database including but not limited to Mysql, redis, etc., ensuring that all necessary information is included to support subsequent analysis.

[0099] By determining the time window (such as monthly, weekly, etc.), the transaction data within the corresponding time period is extracted from the database. The data of each user is aggregated and calculated to obtain statistical indicators such as total transaction amount, number of transactions, average transaction amount, etc., and the transaction statistical feature vectors of both parties are constructed based on these statistical results.

[0100] Before an account transaction occurs, four time windows can be used to analyze the user's transaction behavior: 1 month, 1 week, 1 day, and 1 hour. For each time window, we extract the user's transaction data from the database and calculate statistical indicators such as total transaction amount, number of transactions, average transaction amount, maximum and minimum transaction amount, standard deviation of transaction amount, and average transaction interval time.

[0101] For example, within a one-month window, we found that a certain user made 50 transactions with a total transaction amount of 5,000, so the average transaction amount is 100, and the maximum, minimum and standard deviation of the user's transaction amount are obtained based on the details. In addition, transaction time information can also be obtained, such as an average transaction every 15 hours, and this transaction is 4 hours away from the last transaction. Based on these statistical results, a transaction statistical feature vector for each user is constructed. These features can be shown in the form of Table 2:

[0102] Table 2

[0103]

[0104] The statistical features of the account transaction features obtained can be divided into two types: collection and payment. Therefore, before the transaction occurs, the statistical feature dimensions of accounts A and B in a period of time are 8+8, where the first dimension is the amount of the transaction, and the 8 dimensions represent the statistical features of collection and payment respectively.

[0105] When four time windows (1 month, 1 week, 1 day, 1 hour) are set, the statistical characteristics of an account are (8+8)*4=64 dimensions.

[0106] The transaction subgraph generation module is used to collect the historical transaction records of the two transaction parties in the same time window according to the selected preset time window, extract the historical transaction features of the historical transaction records, and construct a first-order transaction subgraph based on the historical transaction features of the two transaction parties and the historical transaction features of the first-order neighbor nodes of the two transaction parties in the same time window.

[0107] In the process of constructing a transaction subgraph, we first need to select an appropriate time window T to collect the historical transaction records of both parties (nodes A and B). Then, within the time window T, collect all nodes that have transactions with nodes A and B and their transaction information. Based on these collected data, the results of module one are used to obtain the transaction statistical feature vectors of each node involved, including transaction information such as transfer amount, transaction amount mean, transaction amount variance, transaction time variance, and time since the last transaction. Finally, the transaction statistical characteristics and network structure information are obtained directly through query, and a transaction subgraph covering nodes A and B is generated. The subgraph includes first-order neighboring nodes. The specific steps are as follows:

[0108] Using the database and calculation method of module 1, we can obtain the transaction characteristics of accounts A and B before the transaction occurs with a total time window T, and obtain their first-order neighbors to construct a first-order transaction subgraph as follows: Figure 1 shown.

[0109] In the present invention, the first-order transaction subgraph is used for the following reasons: 1) the first-order neighbors have less time complexity. 2) since the account characteristics include the collection and payment characteristics, part of the second-order neighbor information is included.

[0110] Through the database in step 1, query the transaction object account set S of both parties in the time window T (T can also be set to 1 month) A , S B , and again obtain S according to the time window T A , S B The transaction set S A1 , S B2 , and calculate the statistical characteristics of Table 2. Calculate the transaction characteristics according to Table 2. In summary, the approximate calculation scope and data dimensions of this transaction are as follows Figure 4 shown.

[0111] The hidden layer feature calculation module is used to calculate the hidden layer features of the transaction parties and the hidden layer features of the first-order neighbor nodes based on the historical transaction features, and use the weights and activation functions of the graph induction neural network to combine the hidden layer features of the transaction parties and the hidden layer features of the first-order neighbor nodes to obtain the hidden layer features of the transaction features.

[0112] The graph induction network is used to extract transaction features. The graph induction algorithm updates the feature representation of nodes by aggregating the neighbor transaction information of the receiving and paying nodes using the aggregation function LSTM. For each transaction i, based on the historical transaction features x calculated by its neighbor nodes in module 1 and the previous hidden layer aggregation features, Calculate the current hidden layer aggregation features

[0113]

[0114] here It is the transaction statistical feature vector of the transaction neighbors collected within the time window T, sorted from far to near by transaction time to highlight the timing of transactions. The hidden layer features h of all neighbor nodes are obtained i c and the hidden features h of the two parties i and h j (payer and payee), these features will be combined through the fully connected layer, and the weight W and activation function σ are used to obtain the hidden feature representation of the transaction features:

[0115]

[0116] This final hidden layer feature h will be used as the condition of the conditional generative adversarial network and the input of the hidden layer simulation generation algorithm to generate the corresponding account subgraph for data enhancement. In this way, on the one hand, the transaction information of neighboring nodes can be aggregated, and on the other hand, LSTM can aggregate neighboring nodes according to transaction time, which is in line with the timeliness of transactions.

[0117] For each transaction record i, query the neighbors S of transaction accounts A and B within the T time window of i A , S B The transaction statistics feature vector Sort the transactions by time from far to near, and use LSTM to extract the hidden features of neighbor nodes.

[0118] Take payer A as an example, assuming The length of is m, m can be calculated according to the transaction length in the draw time window T of the corresponding data set in step 1, and the hidden layer features are extracted as follows.

[0119]

[0120] in, is the statistical feature vector of the i-th transaction between the transaction neighbor nodes of the two parties in the time window T, h i is the hidden feature vector obtained from the i-th transaction of the neighbor node, c i is the auxiliary vector and LSTM(·) is the aggregation function.

[0121] Similarly, similar calculations are performed on the payee B to obtain the corresponding hidden layer features.

[0122] If the hidden features of the payer and the payee are represented by the superscripts in and out, and are substituted into formula (12), the hidden features of the neighbor nodes are obtained: After that, the hidden features h of the two parties are in and h out Perform full connection, using weight W k And the activation function σ obtains the hidden feature representation of the transaction feature, as shown in the following formula:

[0123]

[0124] Among them, σ is the activation function, W is the weight, is the hidden layer feature of the neighbor node recipient within the time window T, is the hidden layer feature of the payer of the neighbor node in the time window T, h in is the hidden feature of the payer, h out is the hidden feature of the payee.

[0125] During the back propagation process, fraud samples can be labeled according to user feedback or reports, so as to train the corresponding hidden data in the hidden features h of the transaction features.

[0126] The simulated historical transaction statistical feature generation module is used to construct a hidden layer conditional generative adversarial network based on the conditional generative adversarial network loss function and input the hidden layer features of the transaction features and the features of the first-order transaction subgraph into the hidden layer conditional generative adversarial network to obtain simulated historical transaction statistical features.

[0127] According to the hidden layer data and subgraph data of the fraudulent transaction, the conditional generative adversarial network is trained, and the simulated data generated by the generator G is used as the result of data enhancement. This embodiment proposes to use the conditional generative adversarial network as a data enhancement method. The correspondence between the minority class samples and the simulated data can be more accurately defined. Using formula (14) as the input of the conditional generative adversarial network, the conditional generative adversarial network loss function is as shown in formula (14):

[0128] l cGAN(G,D) =E h,x [logD(h,sg)]+E h,z [log(1-D(h,G(h,z)))] (14)

[0129] Among them, sg represents the aggregated features of historical transactions of transaction accounts connected to neighbors, D represents the discriminator, and G represents the generator. The flowchart of the hidden layer conditional generative adversarial network is as follows: Figure 2 .

[0130] Use the conditional generative adversarial network loss function to build a conditional generative adversarial network.

[0131] exist Figure 2 In the example, the transaction subgraph may include a payer or payee subgraph, and the transaction statistical feature vector represents the aggregated transaction feature of the payer's historical transaction node. The generator G generates the subgraph transaction aggregate feature based on the hidden feature h, and the discriminator D makes a judgment based on the simulated transaction statistical feature vector sg' and the real transaction statistical feature vector sg. The generator G uses the hidden feature h as input, and the output of the generator G corresponding to the hidden feature h using real data is calculated by formula (15), corresponding to the interpolation feature h sys The data enhancement output of is calculated by formula (16):

[0132] sg=G(h) (15)

[0133] sg'=G(h sys ) (16)

[0134] Among them, h sysIt is the system hidden layer interpolation feature obtained from the graph induction network model. According to the distribution of nodes in the hidden layer, it combines SMOTE and other interpolation methods (including but not limited to SMOTE, MWMOTE, etc.) to generate data. In order to ensure that the generated data is associated with specific minority class samples, the present invention uses the hidden layer features of the nodes and the transaction subgraph features as conditional inputs.

[0135] Ignore the noise z, use h as the input of the generator, train the conditional generative adversarial network, and the conditional adversarial network design is as follows Figure 5 As shown in the figure, 16, 32, and 2 represent the hidden layer data dimensions, 64 represents the aggregated features calculated by the transaction subgraph generation module, and m represents the neighbor length preset by the hidden layer feature calculation module. Figure 5 The network setting is to train the generator G and the discriminator D with h as the condition and sg as the generation target.

[0136] The fraudulent transaction detection module is used to perform secondary training on the graph induction network based on the simulated historical transaction statistical features using a cross entropy loss function to obtain a trained graph induction network, input the transaction data of the user to be detected into the graph induction network, and complete fraudulent transaction detection.

[0137] According to the SMOTE simulation data algorithm, the hidden layer simulation vector is determined to generate the corresponding simulation subgraph. The hidden layer calculation method based on SMOTE is as follows.

[0138] h sys =h dd +r*(h dn -h dd ),0≤r≤1 (17)

[0139] Among them, h dd represents the virtual fraud hidden data sample corresponding to the fraudulent transaction, h dn Indicates h dd The virtual fraud hidden layer data samples of neighbors. r represents a random number, h sys Represents the generated hidden layer simulation data. The number of generated data can be set as a multiple of the number of fraud samples, such as 1, 2, ..., 10, etc. The transaction subgraph is generated according to the generator G trained in step 4.

[0140] sg'=G(h sys ) (18)

[0141] Use the Euclidean distance of hidden layer nodes to determine the corresponding samples in the hidden layer space according to the following formula.

[0142]

[0143] Among them, h vrepresents fraud samples with similar distance in the latent space, h sys The generated subgraph is g sys ={x Node , sg}, the central node is Node, and the neighbor historical transaction statistical features are sg. According to the retrained graph induction network model, fraudulent transactions are judged. The original data and the added subgraph are used to enhance the data g sys Retraining graph induction networks.

[0144] After retraining, before each transaction occurs, the data collection and preprocessing module is used to calculate statistical features, and the transaction subgraph generation module is used to calculate the transaction subgraph to determine whether it is fraudulent.

[0145] The embodiments described above are only descriptions of the preferred embodiments of the present invention and are not intended to limit the scope of the present invention. Without departing from the design spirit of the present invention, various modifications and improvements made to the technical solutions of the present invention by ordinary technicians in this field should all fall within the protection scope determined by the claims of the present invention.

Claims

1. A method for constructing a fraudulent transaction detection model based on graph data enhancement, characterized in that: Methods include: Step S1: Collect existing user transaction data, and perform statistical calculations on the user transaction data to obtain a transaction statistical feature vector; Step S2: according to the selected preset time window, historical transaction records of both parties in the same time window are collected, and then historical transaction features of the historical transaction records are extracted; a first-order transaction subgraph is constructed based on the historical transaction features of both parties and the historical transaction features of the first-order neighbor nodes of the two parties in the same time window; Step S3, based on the historical transaction features, calculating the hidden features of the transaction parties and the hidden features of the first-order neighbor nodes, and combining the hidden features of the transaction parties and the hidden features of the first-order neighbor nodes using the weights and activation function of the graph induction neural network to obtain the hidden features of the transaction features; Step S4: construct a hidden layer conditional generative adversarial network based on the conditional generative adversarial network loss function and input the hidden layer features of the transaction features and the features of the first-order transaction subgraph into the hidden layer conditional generative adversarial network to obtain simulated historical transaction statistical features; Step S5: Based on the simulated historical transaction statistical features, the graph induction network is trained twice using a cross entropy loss function to obtain a trained graph induction network, and the transaction data of the user to be detected is input into the graph induction network to complete fraudulent transaction detection.

2. The method for constructing a fraudulent transaction detection model based on graph data enhancement according to claim 1, characterized in that: In step S1, the first-order transaction subgraph includes the paying account, the receiving account, the first-order neighbors of the paying account, i.e., the account that has direct transactions with the paying account, the first-order neighbors of the receiving account, i.e., the account that has direct transactions with the receiving account, the first-order neighbors of the paying neighbor account and the first-order neighbors of the receiving neighbor account.

3. The method for constructing a fraudulent transaction detection model based on graph data enhancement according to claim 1, characterized in that: In step S3, the calculation process of the hidden layer features of the neighboring nodes includes: in, is the statistical feature vector of the i-th transaction between the transaction neighbor nodes of the two parties in the time window T, h i is the hidden feature vector obtained from the i-th transaction of the neighbor node, c i is the auxiliary vector and LSTM(·) is the aggregation function.

4. The method for constructing a fraudulent transaction detection model based on graph data enhancement according to claim 3, characterized in that: In step S3, the hidden features h of the transaction features are obtained by combining the hidden features of the transaction parties and the hidden features of the neighboring nodes using the weights and activation functions of the graph induction network: Input the transaction statistical feature vector of the payer and the payee of the neighbor node into the hidden layer feature calculation formula of step S3 to obtain and based on h i n and h out Calculate the hidden features h of transaction features: Among them, σ is the activation function, W is the weight, is the hidden layer feature of the neighbor node recipient within the time window T, is the hidden layer feature of the payer of the neighbor node in the time window T, h in is the hidden feature of the payer, h out is the hidden feature of the payee.

5. A fraudulent transaction detection model construction system based on graph data enhancement, the system is used to implement the fraudulent transaction detection model construction method according to any one of claims 1 to 4, characterized in that: The system includes: A data collection and preprocessing module, used to collect existing user transaction data, perform statistical calculations on the user transaction data to obtain a transaction statistical feature vector; A transaction subgraph generation module is used to collect historical transaction records of both parties in the same time window according to a selected preset time window, extract historical transaction features of the historical transaction records, and construct a first-order transaction subgraph based on the historical transaction features of both parties and the historical transaction features of the first-order neighbor nodes of the two parties in the same time window; A hidden layer feature calculation module, used to calculate the hidden layer features of the transaction parties and the hidden layer features of the first-order neighbor nodes based on the historical transaction features, and to combine the hidden layer features of the transaction parties and the hidden layer features of the first-order neighbor nodes using the weights and activation functions of the graph induction neural network to obtain the hidden layer features of the transaction features; A simulated historical transaction statistical feature generation module is used to construct a hidden layer conditional generative adversarial network based on a conditional generative adversarial network loss function and input the hidden layer features of the transaction features and the features of the first-order transaction subgraph into the hidden layer conditional generative adversarial network to obtain simulated historical transaction statistical features; The fraudulent transaction detection module is used to perform secondary training on the graph induction network based on the simulated historical transaction statistical features using a cross entropy loss function to obtain a trained graph induction network, input the transaction data of the user to be detected into the graph induction network, and complete fraudulent transaction detection.

6. The fraud transaction detection model construction system based on graph data enhancement according to claim 5, characterized in that: In the data collection and preprocessing module, the first-order transaction subgraph includes the paying account, the receiving account, the first-order neighbors of the paying account, that is, the accounts that have direct transactions with the paying account, the first-order neighbors of the receiving account, that is, the accounts that have direct transactions with the receiving account, the first-order neighbors of the paying neighbor account and the first-order neighbors of the receiving neighbor account.

7. The fraud transaction detection model construction system based on graph data enhancement according to claim 5, characterized in that: In the hidden layer feature calculation module, the calculation process of the hidden layer features of the neighboring nodes includes: in, is the statistical feature vector of the ith transaction between the transaction neighbors of the two transaction parties within the time window T, h i is the hidden vector corresponding to the i-th transaction of the neighbor node, c i is the auxiliary vector and LSTM(·) is the aggregation function.

8. The fraud transaction detection model construction system based on graph data enhancement according to claim 5, characterized in that: In the hidden layer feature calculation module, the hidden layer features of the transaction parties and the hidden layer features of the neighboring nodes are combined using the weights and activation functions of the graph induction network to obtain the hidden layer features h of the transaction features, which are specifically: The transaction statistical feature vector of the payer and the payee of the neighboring node is input into the hidden layer feature calculation formula of the hidden layer feature calculation module to obtain and based on h i n and h out Calculate the hidden features h of transaction features: Among them, σ is the activation function, W is the weight, is the hidden layer feature of the neighbor node recipient within the time window T, is the hidden layer feature of the payer of the neighbor node in the time window T, h in is the hidden feature of the payer, h out is the hidden feature of the payee.

Citation Information

Patent Citations

  • Fraudulent transaction identification methods, devices, servers, and storage media

    CN108428132B

  • Deep learning-based fraud transaction identification method, system and storage medium

    CN108596630A

  • A method for identifying fraud in credit card transactions

    CN111105241B

  • Fraudulent transaction identification method and device

    CN113506109A

  • Anti-fraud transaction identification method and system based on artificial intelligence

    CN118070141B