Artificial intelligence risk level supervision system
By introducing link abnormality identification, behavioral pattern mapping, path clustering evaluation and level tag correction modules into the artificial intelligence risk level supervision system, the problem that existing systems cannot effectively respond to link dynamics and complex evolution of risk propagation paths is solved, and more efficient and flexible risk identification and evaluation is achieved, improving the timeliness and accuracy of regulatory measures.
Patent Information
- Application Number
- CN202510550677.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-29
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2045-04-29
AI Technical Summary
The existing AI risk level regulatory system cannot effectively respond to the complex evolution of link dynamics and risk propagation paths, resulting in a lack of timeliness and flexibility in identification results, difficulty in identifying cases where numbers are duplicated but behavioral performance is significantly different, and lack of dynamic calibration mechanisms, resulting in lagging regulatory measures.
The link abnormality identification module identifies and detects spatial position transition nodes, filters the node trajectory with transition frequency exceeding the set threshold, and establishes a node link abnormality map; the behavior pattern mapping module extracts abnormal node numbers and behavior identifiers, associates the behavior deviation sequences in the traffic instruction nodes, and collects and processes the overlapping numbered data sequences to establish a cross-mark behavior set; the path clustering evaluation module detects the trigger paths in the illegal operation sequence, records and maps the violation judgment nodes, and builds a risk path aggregation map; the level tag correction module locates the rule execution chain consistent with the illustrated path in the intelligent supervision platform, extracts the current marking level, and compares it with the standard path level in the supervision risk registration template to generate a level mapping calibration table.
It realizes accurate capture of link dynamics and risk propagation paths, improves the timeliness and flexibility of identification results, enhances the consistency processing capability of multi-source behavior data, significantly improves the perceived granularity of the risk level assessment system for subtle changes, and improves the concentration and coherence of high-risk link identification.
Smart Images

Figure CN120069567A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of artificial intelligence technology, and particularly to an artificial intelligence risk level supervision system. Background Art
[0002] The field of artificial intelligence technology involves analyzing, reasoning, and decision-making processes for massive data by constructing human-like intelligent systems. Its core contents include sub-technologies such as machine learning, natural language processing, computer vision, knowledge graphs, and intelligent control. The research in this technical field involves data collection and preprocessing, model training and optimization, feature extraction and classification, language understanding and generation, etc., aiming to enable computing systems to have the ability of automatic recognition, judgment, and execution of complex tasks. The development of artificial intelligence has been widely applied in multiple industries such as transportation, healthcare, finance, and manufacturing, promoting its in-depth integration in automation, personalized services, and intelligent auxiliary decision-making.
[0003] Among them, the artificial intelligence risk level supervision system refers to a system used to identify, classify, and supervise different risks existing in the application process of artificial intelligence. It mainly targets technical matters such as ethical risks, security hazards, algorithmic biases, and data compliance issues caused by artificial intelligence in actual deployment and operation. By constructing a risk factor identification rule set, risk level standards are set.
[0004] The processing mechanism of the existing technology in artificial intelligence risk level supervision mainly relies on the rule judgment method under a predefined condition set. This static rule matching and analysis path are fixed, and it is unable to effectively cope with the link dynamics and complex evolution of risk propagation paths during operation, resulting in the lack of timeliness and flexibility of the identification results. In scenarios involving multi-node behavior intersections, the existing technology is difficult to achieve the collection and annotation processing of numbered overlapping data, resulting in the inability to effectively capture the cross-node conduction mode of abnormal behaviors. For example, during the high-frequency instruction transmission process, if there are cases where the numbers are repeated but the behavior performances are significantly different, the traditional system cannot identify the potential deviation aggregation phenomenon. In the risk level judgment link, the current solution fails to form a feedback loop for the setting and update of the level. When there is a long-term inconsistency between the standard level and the actual link level, no dynamic calibration mechanism is provided, resulting in lagging supervision measures and insufficient risk regulation capabilities. The existing technology lacks a tracking mechanism for the level change trend in multi-stage processes, and it is easy to ignore the early warning signals of the gradually rising level in high-risk paths, thus unable to achieve early intervention in potential concentrated risk areas and reducing the overall supervision's control ability over the risk evolution path. Summary of the Invention
[0005] The purpose of the present invention is to solve the deficiencies existing in the prior art and propose an artificial intelligence risk level supervision system.
[0006] To achieve the above object, the present invention adopts the following technical solutions: An artificial intelligence risk level supervision system includes: Based on the time records and positioning coordinates in the transmission link of the financial supervision node, the link anomaly identification module identifies and detects the nodes with spatial position transitions through the time series data stream, screens the node trajectories with transition frequencies exceeding the set threshold, and establishes a node link anomaly map; The behavior pattern mapping module calls the node link anomaly map, extracts the abnormal node numbers and behavior identifiers in the map, associates the behavior deviation sequences in the traffic instruction nodes, and performs aggregation processing on the overlapping numbered data sequences to establish a cross-marked behavior set; The path clustering and evaluation module calls the cross-marked behavior set, detects the trigger paths in the illegal operation sequences, records and maps the illegal judgment nodes, forms a mapping block according to the frequency, and constructs a risk path aggregation graph; The level label correction module calls the risk path aggregation graph, locates the rule execution chain in the intelligent supervision platform that is consistent with the illustrated path, extracts the current marked level, compares it with the standard path level in the supervision risk registration template, and adjusts and classifies the chains with inconsistent levels to generate a level mapping calibration table.
[0007] As a further solution of the present invention, the node link anomaly map includes the transition node number, the transition frequency threshold, the spatial position change characteristics, the link stability parameter, and the time series offset index. The cross-marked behavior set includes the abnormal node number, the behavior deviation label, the overlapping behavior sequence, the behavior feature index, and the cross-identification mark. The risk path aggregation graph includes the illegal path number, the frequency statistics block, the risk node grouping, the path level identifier, and the aggregated link label. The level mapping calibration table includes the rule execution chain number, the current level label, the standard level benchmark, the level deviation value, and the correction classification mark.
[0008] As a further solution of the present invention, the link anomaly identification module includes: The time trajectory extraction sub-module identifies the time difference and coordinate difference between consecutive records based on the time records and positioning coordinates in the transmission link of the financial supervision node, screens the record intervals that meet the time jump threshold and the spatial jump threshold conditions, and generates a node time position trajectory sequence; The transition node screening sub-module counts the transition frequencies of the nodes in different time periods based on the node time position trajectory sequence, determines whether they exceed the transition frequency threshold, screens the corresponding nodes and records the transition time period and the spatial change amount, and obtains the change rate of the high-frequency transition nodes; The link map construction sub-module calls the change rate of the high-frequency transition nodes, identifies the link structure of the transition nodes, determines the connection relationship and the transition order, formulates a timing structure according to the transition time period and sets the edge weight, and establishes a node link anomaly map.
[0009] As a further solution of the present invention, the behavior pattern mapping module includes: The node anomaly recognition sub-module calls the node link anomaly atlas, extracts the node numbers and status identifiers, filters the numbers with status mutations and path offsets, analyzes the amplitude of the status mutation and the intensity of the path change, and obtains the node anomaly intensity value; The behavior deviation aggregation sub-module, according to the node anomaly intensity value, associates the labeled behavior deviation sequences in the instruction nodes, filters the numbers that coincide with the deviation sequences in the number sequence, extracts the deviation classifications, performs aggregation and classification, and uses the formula: ; Calculate the number deviation aggregation value, merge and classify according to the numerical range, and obtain the deviation aggregation value; Wherein, represents the number deviation aggregation value, is the density of the th type of abnormal number, is the amplitude of the status mutation of the th type of abnormal number, is the path offset intensity of the th type of abnormal number, is the number of occurrences of the abnormal number during the monitoring period, is the starting identifier of the th deviation entry in the traffic instruction, is the th termination identifier of the deviation entry, is the total number of traffic instruction deviation entries, is the number of types of abnormal numbers; The cross-mark recognition sub-module, based on the deviation aggregation value, compares the numbers with the deviation category labels, extracts the co-occurring node pairs in the mapping sequence, analyzes the overlapping feature intervals and behavior differences between the numbers, and establishes a cross-mark behavior set.
[0010] As a further solution of the present invention, the path clustering evaluation module includes: The cross-mark analysis sub-module calls the cross-mark behavior set, extracts the behavior label groups within the path, detects the cross structure of the behavior labels through the combination of the path position value and the label type, calculates the cross frequency and the position offset value, divides the path behavior clusters according to the offset position, and obtains the path behavior cluster frequency value; The violation node mapping sub-module calls the path behavior cluster frequency value, filters the nodes with a conflict rate higher than the behavior threshold, re-codes according to the node numbers and frequencies, and generates a standard mapping node set; The risk path aggregation sub-module aggregates the associated path node structures according to the standard mapping node set, identifies the node operation sequence number, position sequence and trigger signal value, and uses the formula: ; Calculate the path structure correlation index, perform block sorting, count the number of paths covered by the block and the node ratio, and construct a risk path aggregation graph; Among them, represents the path structure correlation index, is the node operation sequence consistency value of the th path, is the trigger signal difference value of the th path, is the operation sequence overlap value of the th path, is the number of mapped nodes of the th path, is the sum of the trigger signal strengths of all nodes of the th path, is the offset behavior mapping strength adjustment factor of the th path, is the node sequence conflict compensation factor of the th path, is the total number of paths.
[0011] As a further solution of the present invention, the level label correction module includes: The risk chain identification sub-module calls the risk path aggregation graph, compares the node order and logic of the illustrated path with the regulatory platform rule chain, identifies the risk chains with structural consistency exceeding the threshold, and generates an artificial intelligence risk path chain set; The level deviation judgment sub-module extracts the chain level label according to the artificial intelligence risk path chain set, calls the standard level value of the corresponding path in the regulatory risk registration template, judges the corresponding positions of the two in the level sequence and analyzes the differences, and generates an AI risk level deviation value; The label mapping adjustment sub-module selects the chains with level deviation exceeding the threshold according to the AI risk level deviation value, extracts the level label, risk event frequency, node inference coupling strength and path conflict number, and uses the formula: ; Calculate the AI risk label correction amplitude, and perform mapping reconstruction with the current level label value, identify the label mapping relationship, and generate a level mapping calibration table; Among them, represents the AI risk label correction amplitude, represents the current level label value, represents the standard level value, represents the triggering frequency of risk events, represents the inference coupling strength, represents the deviation value of the AI risk level, represents the number of path conflicts.
[0012] As a further solution of the present invention, the system further includes a segmented level tracking module: The segmented level tracking module calls the level mapping calibration table, marks the corresponding risk level values of the link triggering instructions in the multi-stage process, identifies the distribution trend of the level changes in the instruction conduction path, screens the continuously increasing level chains as the risk concentration links, and outputs the segmented risk level supervision path set; The segmented risk level supervision path set includes the stage risk level, the level change trajectory, the link concentration section, the continuous increase flag, and the instruction conduction path mapping.
[0013] As a further solution of the present invention, the segmented level tracking module includes: The level mapping marking sub-module calls the level mapping calibration table, identifies the link number, triggering time, and response time in the process path, extracts the original level value and compares the mapped level items, selects the corresponding value, and generates a risk level mapping value set; The level trend identification sub-module, based on the risk level mapping value set, sorts the link number sequence and the response time sequence by number, identifies the difference between adjacent values and judges the positive and negative, marks the growth nodes, extracts the continuous positive difference sequence, records the link number, the total difference, and the number of nodes, eliminates the low-frequency change segments, and generates the increasing trend sequence quantity; The chain screening and aggregation sub-module, according to the increasing trend sequence quantity, extracts the high-frequency increasing path segments, identifies the start and end numbers, calculates the cumulative increase and the increase rate, screens the path segments with a rate exceeding the reference value, and obtains the segmented risk level supervision path set.
[0014] Compared with the prior art, the advantages and positive effects of the present invention are as follows: In the present invention, through the linkage analysis of time records and positioning coordinates in the transmission link of financial supervision nodes, spatial transition nodes are quickly detected in the time series structure of data streams, and an abnormal trajectory screening mechanism is formed by setting thresholds with transition frequencies, enhancing the precise capture ability of link change behaviors and improving the spatial perception depth of dynamic abnormal nodes. Combining transition feature extraction and trajectory behavior classification can focus on the atypical changes in the evolution of node behaviors, and construct a cross-behavior structure based on numbered overlap aggregation, effectively enhancing the consistency processing ability of multi-source behavior data in abnormal identification. In the process of clustering and mapping the trigger paths of illegal operation sequences, mapping blocks are divided through the frequency dimension to form a multi-angle quantitative description method for risk paths, broadening the graph expression ability of illegal events and the node positioning accuracy. Based on the comparison and analysis of the current level and template level of the execution chain, a correction feedback path for level differences is formed, significantly improving the perception granularity of the risk level assessment system for subtle changes. Using the level variation trend in the multi-stage process as the link screening basis, continuous increasing paths are screened as key links for output, realizing the serial extraction of the risk distribution trend and enhancing the concentration and coherence of high-risk link identification. The overall process constructs a closed-loop mechanism from data stream perception, behavior recognition, path classification, level comparison to trend tracking, enabling the detection, analysis, and evaluation of risk links to have highly structured and hierarchically controllable capabilities. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] Figure 1 is the system flow chart of the present invention; Figure 2 is the flow chart of the link anomaly identification module in the present invention; Figure 3 is the flow chart of the behavior pattern mapping module in the present invention; Figure 4 is the flow chart of the path clustering and evaluation module in the present invention; Figure 5 is the flow chart of the level label correction module in the present invention; Figure 6 is the flow chart of the segmented level tracking module in the present invention. DETAILED DESCRIPTION OF THE INVENTION
[0016] In order to make the objectives, technical solutions and advantages of the present invention clearer, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.
[0017] In the description of the present invention, it should be understood that the orientation or positional relationship indicated by terms such as "length", "width", "upper", "lower", "front", "rear", "left", "right", "vertical", "horizontal", "top", "bottom", "inner", "outer", etc. is based on the orientation or positional relationship shown in the drawings. It is only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore should not be construed as a limitation to the present invention. In addition, in the description of the present invention, "a plurality of" means two or more, unless otherwise specifically defined.
[0018] Please refer to Figure 1 , an artificial intelligence risk level supervision system includes: The link anomaly identification module, based on the time records and positioning coordinates in the financial supervision node transmission link, identifies and detects the spatial position transition nodes through the time series data stream, screens the node trajectories with the transition frequency exceeding the set threshold, and establishes a node link anomaly map; The behavior pattern mapping module calls the node link anomaly map, extracts the abnormal node numbers and behavior identifiers in the map, associates the behavior deviation sequences in the traffic instruction nodes, and performs a collection process on the overlapping numbered data sequences to establish a cross-marked behavior set; The path clustering and evaluation module calls the cross-marked behavior set, detects the trigger paths in the illegal operation sequences, records and maps the illegal judgment nodes, forms a mapping block according to the frequency, and constructs a risk path aggregation map; The level label correction module calls the risk path aggregation map, locates the rule execution chain in the intelligent supervision platform that is consistent with the illustrated path, extracts the current marked level, and compares it with the standard path level in the supervision risk registration template, and adjusts and classifies the chains with inconsistent levels to generate a level mapping calibration table; The segmented level tracking module calls the level mapping calibration table, marks the risk level corresponding values of the link trigger instructions in the multi-stage process, identifies the distribution trend of the level changes in the instruction transmission path, screens the chains with continuously increasing levels as the risk concentration links, and outputs the segmented risk level supervision path set.
[0019] The node link anomaly map includes transition node number, transition frequency threshold, spatial position change characteristics, link stability parameters, and time series offset indicators. The cross-marking behavior set includes abnormal node number, behavior deviation label, overlapping behavior sequence, behavior feature index, and cross-identification label. The risk path aggregation map includes violation path number, frequency statistics block, risk node grouping, path level identification, and aggregation link label. The level mapping calibration table includes the rule execution chain number, current level label, standard level benchmark, level deviation value, and correction classification mark. The segmented risk level supervision path set includes stage risk level, level change trajectory, link concentration section, continuous incremental identification, and instruction conduction path mapping.
[0020] See also Figure 2 , the link change identification module includes: The time trajectory extraction submodule identifies the time difference and coordinate difference between consecutive records based on the time records and positioning coordinates in the transmission link of the financial regulatory node, selects the record interval that meets the time jump threshold and space jump threshold conditions, and generates the node time position trajectory sequence; First, the time record and location coordinates of the financial regulatory node are obtained. This process involves collecting data from multiple monitoring points. For example, in a transaction, each transaction node such as a bank's ATM, online trading platform, etc. is regarded as a regulatory node. The time and geographical location coordinates of each transaction are recorded in real time to monitor whether the transaction behavior is normal. At this time, a time jump threshold and a space jump threshold are set. For example, the time threshold is set to 30 seconds and the space threshold is set to 100 meters. Only when the recorded time difference and position difference exceed the threshold at the same time, it is considered a valid jump. This setting helps to exclude normal time and space fluctuations and ensure that only truly abnormal behaviors are marked and recorded. Then the records are screened out, and the time and location information is extracted to form a sequence. The sequence shows the movement trajectory of each node in time and space. Through this sequence, it is possible to further analyze whether the node's activities are abnormal. For example, an ATM appears multiple times in a short period of time at two points that are extremely far apart in geographical location, indicating fraud. Finally, a node time and location trajectory sequence is generated, providing regulators with an intuitive method to observe and evaluate the abnormality of node behavior.
[0021] The transition node screening submodule counts the transition frequency of nodes in differentiated time periods based on the node time position trajectory sequence, determines whether it exceeds the transition frequency threshold, screens the corresponding nodes and records the transition time period and spatial changes, and obtains the change rate of high-frequency transition nodes; Statistically analyze the position transition frequencies of each node in different time periods and compare them with the set transition frequency threshold. For example, in financial supervision, if the transition frequency of a supervision node exceeds 10 times within one hour, it indicates that there is an anomaly in this node. In this process, it is first necessary to divide the data in the time-position trajectory sequence into time periods. For example, divide a day into 24 hours, with each hour as a monitoring unit, and then statistically analyze the transition frequencies within each monitoring unit. The frequency data is then compared with the transition frequency threshold. The threshold is set based on historical data analysis. For example, it is set by analyzing the average transition frequencies of all nodes in the past year. If the transition frequency of a certain node is significantly higher than this average value, it is marked as an anomaly. After screening out the abnormal nodes, record the transition time period and the spatial change amount to provide data support for further analysis. Finally, obtain the high-frequency transition node change rate, which is a quantitative description of the node behavior and provides a basis for subsequent risk assessment and early warning; Table 1: Example data of node transition frequencies ; As shown in Table 1, Table 1 lists the transition frequencies of two nodes in different time periods. From the data, it can be observed that the transition frequencies of node B in the 1-2 hour and 2-3 hour periods exceed the set threshold (10 times), indicating that there is abnormal behavior in node B.
[0022] The link map construction sub-module calls the high-frequency transition node change rate to identify the link structure of the transition nodes, determine the connection relationship and transition order, formulate a time sequence structure according to the transition time period and set the edge weights to establish a node link anomaly map; Use the high-frequency transition node change rate to identify the abnormal nodes in the link structure, determine the connection relationship and transition order, call the transition node change rate data, and analyze the relationship between the nodes in terms of time and space. For example, if a node frequently jumps from location A to location B and then back to A within a short period of time, this frequent round-trip transition behavior indicates potential risks. Determine the connection relationship between the nodes through the data, and then construct a time series graph according to the time period of node transition. This graph not only shows the connections between the nodes but also marks the intensity and order of the transitions. The transition intensity can be calculated by the product of the transition frequency and the transition distance. Assign a weight value to each connection. The setting of the weight value is also based on historical data. For example, the weight value can be set by analyzing the relationship between the link intensity and the event influence in past events. Connections with high weights represent more important or more abnormal transition behaviors. Finally, establish a node link anomaly map to intuitively reveal the key abnormal nodes and their dynamic relationships in the entire supervision network, providing an important visual aid for the decision-making of the supervision department.
[0023] Please refer to Figure 3 , the behavior pattern mapping module includes: The node movement identification sub-module calls the node link movement atlas, extracts the node numbers and status identifiers, filters the numbers with status mutations and path offsets, analyzes the amplitude of status mutations and the intensity of path changes, and obtains the node movement intensity value; In the process of monitoring financial risks, for example, the trading nodes of financial institutions exhibit unusual behaviors due to abnormal internal data processing or rapid changes in the external environment. The behaviors include abnormal trading volumes or trading patterns. By real-time monitoring of trading data, such abnormal behaviors can be quickly identified. In a specific implementation example, if a certain trading node frequently executes a large number of high-risk transactions that do not conform to the historical pattern within a short period of time, the node will be automatically marked as high-risk. The judgment is based on a comprehensive analysis of trading frequency, amount, and historical data. By calculating the change rate of the trading volume of the node and the deviation degree of the trading pattern, a comprehensive risk index, that is, the node movement intensity value, can be generated. This value will be used for further risk assessment and early warning, helping financial institutions adjust their risk management strategies, thereby preventing potential financial crises and allowing financial institutions to take measures before the risks occur, such as adjusting trading strategies and strengthening monitoring measures.
[0024] The behavior deviation aggregation sub-module, according to the node movement intensity value, associates the labeled behavior deviation sequences in the instruction nodes, filters the numbers that coincide with the deviation sequences in the number sequence, extracts the deviation classifications, and performs aggregation and classification. Using the formula: ; Calculate the number deviation aggregation value, merge and classify according to the numerical interval, and obtain the deviation aggregation value; Among them, represents the number deviation aggregation value, is the density of the th type of abnormal number, is the amplitude of the status mutation of the th type of abnormal number, is the path offset intensity of the th type of abnormal number, is the number of occurrences of the abnormal number within the monitoring period, is the starting identifier of the th deviation entry in the traffic instruction, is the th termination identifier of the deviation entry, is the total number of traffic instruction deviation entries, is the number of types of abnormal numbers; The aggregated value of number deviation refers to the result of collecting and counting the data sequences with overlapping numbers in the behavior deviation sequence. The indicator quantifies the density and intensity of behavior deviation by calculating factors such as the occurrence times, state mutation amplitude, and path deviation intensity of different numbers within the monitoring period. The core objective is to identify the numbers with significant behavior deviations at different time points and evaluate the risk level of abnormal behaviors through aggregated information; In the financial scenario under the artificial intelligence risk level supervision system, identify, classify, and measure the numbers with abnormal behaviors in the trading nodes to achieve the quantitative identification of potential financial risk factors. Taking the financial securities market as an example, if a certain type of stock shows continuous abnormal trading behaviors during the non-announcement period, the supervision can call the abnormal trading numbers marked in the node movement intensity value and compare them with the historical violation trading behavior sequences in the financial behavior deviation annotation. After screening out the overlapping numbers, conduct aggregated statistics on their trading characteristics; : The aggregated value of number deviation, which represents the deviation intensity evaluation indicator for abnormal numbers after aggregation, with the unit of "trading behavior deviation points" (dimensionless); : The density of the -th type of abnormal number, representing the frequency of abnormal behaviors of this number per unit time, with the unit of "times / hour", obtained by counting the frequency of a certain type of number marked as "abnormal trading" in the AI monitoring system within a unit hour. If a number is recorded as 5 abnormal times from 10:00 to 11:00 in the morning, then : The state mutation amplitude of the -th type of abnormal number, indicating the deviation degree of the trading state (such as buy-sell ratio, net trading volume) of this number from the historical mean, with the unit of "%", calculated by the deviation degree of the buy-sell ratio of this number during the detection time period. For example, if the historical buy-sell ratio is 1.0 and the current one is 1.6, then : The path deviation intensity of the -th type of abnormal number, referring to the mutation degree of the trading mode of this number on the capital flow path, with the unit of "number of changed paths", defined as the increment of the number of trading path changes of this number per unit time compared with the historical average. For example, changing from the conventional 3 paths to 7 paths, then : The number of occurrences of the abnormal number within the monitoring period (dimensionless), recording the total number of occurrences of the number within the monitoring period. For example, if a number appears 12 times, then ; 、 : Respectively the The start and end time points of deviation items, in "minutes", are the time markers for recording the start and end of each deviation behavior. For example, if a deviation behavior starts at 9:00 and ends at 9:07, the corresponding values are 540 and 547 (minutes); : The total number of traffic instruction deviation items (dimensionless); : The number of abnormal number types (dimensionless); All indicators are processed through unit conversion to ensure a unified dimension, 、 、 and uniformly enter the molecular layer for normalization of the unit; A numerical calculation example is as follows: Let , ,and the assignments of each parameter are as follows: , , , , , ; , , , , , ; Substitute into the calculation: The first part: ; The second part: ; The final result: ; In the current detection cycle, the aggregated behavior deviation numbers show a comprehensive deviation intensity of 32.17 in multiple dimensions such as transaction frequency and status deviation. If the preset deviation reference value is 25, it indicates that the behavior of this number has a risk of exceeding the standard deviation and should be included in the AI risk level supervision list and undergo cross-deviation verification processing; By jointly using multi-dimensional indicators such as transaction deviation density, state mutation amplitude, and path deviation, the aggregation result of deviation behaviors has both time intensity, frequency density, and transaction path complexity, improving the comprehensive accuracy and adaptability of identifying abnormal behaviors in the financial market.
[0025] Based on the deviation aggregation value, the cross-mark identification sub-module compares the numbers with the deviation category labels, extracts the co-occurring node pairs in the mapping sequence, analyzes the overlapping feature intervals and behavior differences between the numbers, and establishes a cross-mark behavior set; Identify and analyze cross - risks and behavioral correlations in the market, applicable to environments dealing with complex financial products and large amounts of transaction data. For example, when regulatory agencies need to assess the correlation risks between multiple financial markets or various financial products, cross - marking generation can analyze the trading behavior deviations between different markets or products. Through in - depth analysis of the aggregated magnitudes of behavioral deviations, potential paths of risk contagion can be identified, such as a financial crisis spreading from one market to another. Generate a behavioral correlation map to show the relationship of behavioral deviations between different markets or products. This map helps regulatory agencies understand the interdependence between markets and potential risk contagion points. Through analysis, generate a cross - marking behavior set, providing a visual way to help regulatory agencies monitor and manage financial risks at the global level, thus effectively improving the response ability and early - warning mechanism for systemic risks.
[0026] Please refer to Figure 4 , the path clustering evaluation module includes: The cross - marking analysis sub - module calls the cross - marking behavior set, extracts the behavior label groups within the path, detects the cross - structure of behavior labels through the combination of path position values and label types, calculates the cross - frequency and position offset values, divides the path behavior clusters according to the offset positions, and obtains the path behavior cluster frequency values; In financial risk assessment, the extraction of behavior label groups can effectively identify potential risk behaviors. Through the combination of path position values and label types, the cross - structure of behavior labels shows the inter - relationships between different behaviors, which is particularly important in identifying complex financial transaction fraud. Calculating the cross - frequency and position offset values is completed through numerical analysis. For example, by comparing the trading paths of different customers to find abnormal intersection points, dividing the path behavior clusters according to the offset positions makes the formation of each behavior cluster have a clear statistical basis for risk level determination. Obtaining the path behavior cluster frequency values is obtained through set operations in statistical analysis, specifically calculating the frequency of specific behavior patterns, providing a method for regulatory agencies to quantify risks.
[0027] The violation node mapping sub - module calls the path behavior cluster frequency values, filters out the nodes with a conflict rate higher than the behavior threshold, re - codes them according to the node numbers and frequencies, and generates a standard mapping node set; In a practical application in financial risk management, frequency values are used to identify high-risk cases and obtain the set of nodes within the path cluster. The screening of nodes is based on a threshold. For example, the frequency value is set as a certain percentage upper limit to identify customers with abnormal behaviors. The identification of nodes with a conflict rate higher than the behavior threshold is determined through specific calculation formulas. For example, a frequency value higher than twice the average is considered high-risk. The recoded nodes are not only digitized but also include their location information in the network, such as the reordering of node numbers. The processing process is all for simplifying subsequent risk assessment operations and generating a standard mapped node set. The generation of the set is completed through an optimized data processing flow, such as integrating and optimizing node information through data mining techniques.
[0028] Based on the standard mapped node set, the risk path aggregation sub-module aggregates the associated path node structures, identifies the node operation sequence numbers, location sequences, and trigger signal values, and uses the formula: ; Calculate the path structure correlation degree index, perform block sorting, count the number of paths covered by the block and the node ratio, and construct a risk path aggregation graph; Among them, represents the path structure correlation degree index, is the node operation sequence consistency value of the th path, is the trigger signal difference value of the th path, is the operation sequence overlap value of the th path, is the number of mapped nodes of the th path, is the sum of the trigger signal intensities of all nodes in the th path, is the offset behavior mapping intensity adjustment factor of the th path, is the node sequence conflict compensation factor of the th path, is the total number of paths; The path structure correlation degree index is used to evaluate the correlation degree between the node operation sequence and the trigger signal in the violation path. By calculating factors such as the node operation sequence consistency, trigger signal difference, and overlap of the operation sequence in the path, the correlation degree of the path is obtained, which further helps to identify potential risk paths and nodes. The calculation of this index can reveal the cross and complexity of behaviors in the path, thereby quantifying the intensity of risk propagation; Aggregate association path node structure. In financial risk assessment, first obtain the node operation sequence number, position sequence, and trigger signal value. The data is obtained through real-time monitoring and data analysis. Construct three participating items: the consistency value between paths, the signal difference, and the operation overlap value. The process involves complex data processing techniques, such as using statistical analysis to determine which paths have high-risk characteristics; The specific meanings and acquisition processes of each parameter are as follows: : The consistency value of the node operation sequence of the x-th path, obtained by calculating the consistency ratio between the behaviors of each node in the path and the standard behavior model. For example, if there are 10 node behaviors in a path and 9 of them conform to the standard behavior model, then ; and : Represent the trigger signal difference and operation sequence overlap value of the x-th path respectively. The trigger signal difference can be calculated by measuring the standard deviation of the trigger signals between nodes. The operation sequence overlap value is obtained by calculating the overlap degree of operations within the time window. For example, if the standard deviation of the trigger signals between nodes is 20, then , if 50% of the operations overlap in time, then ; : The number of mapped nodes of the x-th path, that is, the total number of nodes included in this path; : The sum of the trigger signal intensities of all nodes in the x-th path, which is the sum of the trigger signal intensities of all nodes within this path; and : Are the offset behavior mapping intensity adjustment factor and node sequence conflict compensation factor of the x-th path respectively. The factors are obtained based on historical data analysis. For example, if a path is offset due to a specific type of behavior, a higher value is assigned. If conflicts in the node sequence occur frequently, then the value will be increased to reflect this; Example of substituting specific values for calculation: Suppose there are the following parameter values: , , , , , , , (total number of paths); Calculation process: ; This calculation demonstrates how to solve the risk level indicator through a formula using specific numerical parameters , which is a relatively small value, indicating that in this case, the risk level is relatively low. This calculation method can help financial institutions evaluate and manage risks in actual operations.
[0029] Please refer to Figure 5 , the level label correction module includes: The risk chain identification sub-module calls the risk path aggregation graph, compares the node order and logic of the illustrated path with the rule chain of the regulatory platform, identifies the risk chains whose structural consistency exceeds the threshold, and generates an artificial intelligence risk path chain set; By comparing the structure and logic of the illustrated path with the rule execution chain in the regulatory platform through intelligent algorithms, the risk chains with matching structures are identified, ensuring that each risk chain is obtained through the consistency comparison of the node sequence. The comparison process involves checking the attributes and connection logic of each node to ensure complete coincidence with the chain in the regulatory platform. For example, for a certain financial transaction path, check whether each link of its transaction chain is executed according to regulatory requirements. If a node logic mismatch is found, it is marked as a risk node, and then the chain structure is optimized through the node comparison algorithm to enhance the pertinence and effectiveness of supervision. Finally, an artificial intelligence risk path chain set is generated, and this set will be used as the basis for subsequent risk level adjustment.
[0030] The level deviation judgment sub-module extracts the chain level labels according to the artificial intelligence risk path chain set, calls the standard level values of the corresponding paths in the regulatory risk registration template, judges their corresponding positions in the level sequence and analyzes the differences, and generates an AI risk level deviation value; Extract the current level label of each chain, call the standard level defined in the regulatory risk registration template using the data analysis model, calculate the deviation between the current marked level and the standard level by comparing the sequence position relationship, for example, when dealing with the AI risk of specific financial services, if the current level of a chain is medium risk and the standard level is high risk, then calculate the deviation value as a one-level difference. This calculation process not only considers the base difference of the levels but also involves the probability of risk occurrence and potential impact to ensure the accuracy of risk assessment, thereby generating an AI risk level deviation value. This deviation value is a key parameter for adjusting the supervision strategy.
[0031] The label mapping adjustment sub-module selects the chains with level deviations exceeding the threshold according to the AI risk level deviation value, extracts the level labels, risk event frequencies, node inference coupling strengths, and path conflict numbers, and uses the formula: ; Calculate the AI risk label correction amplitude, and perform mapping reconstruction with the current level label value, identify the label mapping relationship, and generate a level mapping calibration table; Among them, represents the correction amplitude of the AI risk label, represents the current level label value, represents the standard level value, represents the risk event trigger frequency, represents the inference coupling strength, represents the AI risk level deviation value, represents the number of path conflicts; The correction amplitude of the AI risk label is the result of adjusting according to the deviation between the risk label generated by the AI system on the path and the standard risk template. This amplitude is a correction value calculated by comprehensively considering multi-dimensional factors such as path trigger frequency, inference coupling strength, and number of path conflicts, and is used to adjust and optimize the risk assessment label to ensure that the classification and monitoring of risks can be more accurate; For risk chains where the level deviation exceeds the judgment threshold, an adjustment operation of the risk level label needs to be performed. According to the AI risk level deviation value, the chain objects that exceed the preset deviation limit (such as the set level 3 deviation threshold) are screened out, and their current marked levels are extracted and the standard levels in the supervision template , the level label is a numerical level score, and the range is set from 1 to 5 points. The larger the value, the higher the risk level. Specifically, for example: 1 is low risk, 3 is medium risk, and 5 is high risk. Assuming that the current level of chain A is 4 and the corresponding standard level is 2, then there is , ; Subsequently, collect the risk event trigger records of this chain in the past 7 days, and count the frequency as , such as if the risk trigger identified within this chain is 6 times, that is , and analyze the logical reasoning dependence degree between key nodes in the path to quantify the inference coupling strength , use the normalization coefficient to convert the call frequency and dependence structure between nodes into strength values, set as continuous values between 0 and 10. If there is a high-frequency call relationship and strong data dependence within this path, the inference coupling strength is set to be relatively high. For example ; Obtain that the current chain deviation is level 3 from the previously generated AI risk level deviation value, so there is , and identify and count the data conflicts caused by this path during operation. For example, if the number of processing exceptions caused by inconsistent model versions is counted as 2 times, then , substitute the above data into the formula: ; The obtained risk level correction amplitude is 1.4967. This value indicates that the original level label needs to be increased by approximately 1.5 levels. If the original label level is 4, it should be adjusted to approximately 5.5 levels after correction. Considering that the label upper limit is set to 5, it is set to the highest level 5. Finally, this result is entered into the artificial intelligence risk level label calibration table. All parameters in the above calculation process have been dimensionally unified. For example, the level difference is expressed in level points, the event frequency and the number of conflicts are dimensionless integer values, and the coupling strength is included in the unified evaluation range (0 - 10) after normalization processing. By introducing the square root mechanism of the inference strength and the event frequency, the coupling response to multi-dimensional risk characteristics is more sensitive, effectively reflecting the dynamic risk degree in the chain operation. This result indicates that there is a deviation between the current level of Chain A and the actual risk, and the level label needs to be increased. The adjusted result can be further used as the trigger condition for the regulatory intervention rule.
[0032] Please refer to Figure 6 , the segmented level tracking module includes: The level mapping marking sub-module calls the level mapping calibration table, identifies the link number, trigger time, and response time in the process path, extracts the original level value, compares the mapped level items, selects the corresponding value, and generates a risk level mapping value set; By calling the link number, trigger time, and response time in the process path, this is to ensure that the activity records of each process link can be accurately matched with the risk level mapping items in the level mapping calibration table. The key execution actions in this process include data matching and re-evaluation of the risk level. By matching the link number with the corresponding item in the mapping calibration table, the original level value of the corresponding link is extracted, and then the risk levels are compared to select the mapped level with the highest matching degree. For example, if the original risk level of a certain process link is level 3, according to the corresponding level 3 risk in the mapping table, the new risk assessment is medium risk. At this time, medium risk will be selected as the final risk level of this link. Through a series of operations, a risk level mapping value set is finally generated. This result set contains the risk levels adjusted according to the latest risk assessment criteria for each link, providing basic data for the next risk analysis.
[0033] The level trend identification sub-module, based on the risk level mapping value set, sorts the link number sequence and the response time sequence by number, identifies the differences between adjacent values and determines their positive or negative signs, marks the growth nodes, extracts the continuous positive difference sequence, records the link number, the total difference, and the number of nodes, eliminates the low-frequency change segments, and generates the number of increasing trend sequences; Call link number sequence and its response time sequence, sort the level mapping values in the order of the numbers, and perform difference calculation. The key execution actions include difference analysis and trend marking. For example, if the level mapping values of two consecutive links are level 2 and level 3 respectively, and the calculated difference is 1, it indicates an increasing trend in the risk level. This marking of positive differences helps to identify the upward trend of the risk level. Count all the links with consecutive positive differences, record the link number sequence, total difference amount, and number of nodes. Screen out those low-frequency change segments and only retain the high-frequency continuously increasing sequences. Through the processing process, generate the number of increasing trend sequences. This number reflects that during the entire monitoring period, the upward trend of the risk level is obvious, which is an important basis for further analyzing and preventing potential risks.
[0034] The chain screening and aggregation sub-module extracts high-frequency increasing path segments according to the number of increasing trend sequences, identifies the start and end numbers, calculates the cumulative increase and increase rate, and screens out the path segments with a rate exceeding the benchmark value to obtain the segmented risk level supervision path set; Screen and aggregate the chains according to the number of increasing trend sequences. The execution process includes the extraction of path segments and risk focusing. Extract the start and end numbers of each link from the high-frequency increasing path segments, and calculate the cumulative increase and increase rate of the path segment levels. The key execution actions are comparative analysis and risk screening. For example, if the cumulative increase value of a certain path segment is 5 and the increase rate is 0.5, compare the values with the set benchmark value of the risk level change rate, and screen out those path segments higher than the benchmark value. Through the screening process, obtain the segmented risk level supervision path set. This result set shows the key paths where the risk level rises concentratedly during the entire monitoring period, providing specific operation targets and risk concentration areas for risk management.
[0035] The above is only the preferred embodiment of the present invention, and it is not intended to limit the present invention in other forms. Any person skilled in the art may use the disclosed technical content to make changes or modifications into equivalent embodiments with equivalent changes and apply them to other fields. However, as long as it does not depart from the technical solution content of the present invention, any simple modification, equivalent change, and modification made to the above embodiments based on the technical essence of the present invention still fall within the protection scope of the technical solution of the present invention.
Claims
1. An artificial intelligence risk level supervision system, characterized in that: The system comprises: The link change identification module is based on the time record and positioning coordinates in the transmission link of the financial regulatory node. Through the time series data stream, it identifies and detects the spatial position transition nodes, screens the node trajectories whose transition frequency exceeds the set threshold, and establishes the node link change map; The behavior pattern mapping module calls the node link abnormality map, extracts the abnormal node number and behavior identifier in the map, associates the behavior deviation sequence in the traffic instruction node, and collects and processes the data sequence of overlapping numbers to establish a cross-marked behavior set; The path clustering assessment module calls the cross-marking behavior set, detects the trigger path in the illegal operation sequence, records and maps the illegal judgment nodes, forms mapping blocks according to the frequency, and constructs a risk path aggregation graph; The grade label correction module calls the risk path aggregation diagram, locates the rule execution chain in the intelligent supervision platform that is consistent with the diagram path, extracts the current marking level, and compares it with the standard path level in the supervision risk registration template, adjusts and classifies the chains that do not match the level, and generates a grade mapping calibration table.
2. The artificial intelligence risk level supervision system according to claim 1 is characterized in that: The node link anomaly map includes transition node numbers, transition frequency thresholds, spatial position change characteristics, link stability parameters, and time series offset indicators. The cross-marking behavior set includes abnormal node numbers, behavior deviation labels, overlapping behavior sequences, behavior feature indexes, and cross-identification labels. The risk path aggregation map includes violation path numbers, frequency statistics blocks, risk node groups, path level identifiers, and aggregation link labels. The level mapping calibration table includes rule execution chain numbers, current level labels, standard level benchmarks, level deviation values, and corrected classification labels.
3. The artificial intelligence risk level supervision system according to claim 1 is characterized in that: The link change identification module includes: The time trajectory extraction submodule identifies the time difference and coordinate difference between consecutive records based on the time records and positioning coordinates in the transmission link of the financial regulatory node, selects the record interval that meets the time jump threshold and space jump threshold conditions, and generates the node time position trajectory sequence; The transition node screening submodule counts the transition frequency of the node in the differentiated time period based on the node time position trajectory sequence, determines whether it exceeds the transition frequency threshold, screens the corresponding nodes and records the transition time period and spatial variation, and obtains the change rate of high-frequency transition nodes; The link graph construction submodule calls the high-frequency transition node change rate, identifies the transition node link structure, determines the connection relationship and transition sequence, formulates the timing structure and sets the edge weight according to the transition time period, and establishes the node link change graph.
4. The artificial intelligence risk level supervision system according to claim 3 is characterized in that: The behavior pattern mapping module includes: The node change identification submodule calls the node link change graph, extracts the node number and state identifier, screens the numbers with state mutation and path deviation, analyzes the state mutation amplitude and path change intensity, and obtains the node change intensity value; The behavior deviation aggregation submodule associates the behavior deviation sequence marked in the instruction node according to the node change intensity value, selects the numbers in the number sequence that overlap with the deviation sequence, extracts the deviation classification, and aggregates and classifies it using the formula: ; Calculate the number deviation aggregate value, merge and classify according to the numerical interval, and obtain the deviation aggregation value; in, Represents the number deviation aggregate value, For the The density of the exception class number, For the The state mutation amplitude of the class exception number, For the Path deviation strength of class exception number, Exception number The number of occurrences during the monitoring period, For traffic instructions The starting identifier of the deviation entry, For the The end mark of the deviation entry, is the total number of traffic instruction deviation entries, is the number of abnormal number types; The cross-mark identification submodule compares the number and the deviation category label based on the deviation collection value, extracts the co-occurring node pairs in the mapping sequence, analyzes the overlapping feature intervals and behavior differences between the numbers, and establishes a cross-mark behavior set.
5. The artificial intelligence risk level supervision system according to claim 4 is characterized in that: The path clustering evaluation module includes: The cross-mark analysis submodule calls the cross-mark behavior set, extracts the behavior label group in the path, detects the behavior label cross structure through the combination of the path position value and the label type, calculates the cross frequency and position offset value, divides the path behavior cluster according to the offset position, and obtains the path behavior cluster frequency value; The illegal node mapping submodule calls the path behavior cluster frequency value, screens the nodes whose conflict rate is higher than the behavior threshold, recodes them according to the node number and frequency, and generates a standard mapping node set; The risk path aggregation submodule aggregates the associated path node structure according to the standard mapping node set, identifies the node operation sequence number, position sequence and trigger signal value, and adopts the formula: ; Calculate the path structure correlation index, sort the blocks, count the number of paths covered by the blocks and the proportion of nodes, and build a risk path aggregation graph; in, represents the path structure correlation index, For the The node operation sequence consistency value of the path, For the The trigger signal difference of the path, For the The operation sequence overlap value of the path, For the The number of mapped nodes of the path, For the The sum of the trigger signal strengths of all nodes on the path, For the The offset behavior of the path maps to the intensity adjustment factor, For the Path node sequence conflict compensation factor, is the total number of paths.
6. The artificial intelligence risk level supervision system according to claim 5 is characterized in that: The level label correction module includes: The risk chain identification submodule calls the risk path aggregation diagram, compares the node sequence and logic of the diagram path with the regulatory platform rule chain, identifies the risk chain whose structural consistency exceeds the threshold, and generates an artificial intelligence risk path chain set; The grade deviation judgment submodule extracts the chain grade label according to the artificial intelligence risk path chain set, calls the standard grade value of the corresponding path in the regulatory risk registration template, determines the corresponding positions of the two in the grade sequence and analyzes the differences, and generates the AI risk grade deviation value; The label mapping adjustment submodule selects the chains with level deviation exceeding the threshold value according to the AI risk level deviation value, extracts the level label, risk event frequency, node reasoning coupling strength and path conflict number, and uses the formula: ; Calculate the AI risk label correction range, and reconstruct the mapping with the current level label value, identify the label mapping relationship, and generate a level mapping calibration table; in, Indicates the AI risk label correction range, Represents the current level label value, Represents the standard grade value, Represents the frequency of risk event triggering, represents the strength of inference coupling, Represents the AI risk level deviation value, Represents the number of path conflicts.
7. The artificial intelligence risk level supervision system according to claim 1 is characterized in that: The system also includes a segment level tracking module: The segmented level tracking module calls the level mapping calibration table, marks the corresponding value of the risk level of the link triggering instruction in the multi-stage process, identifies the distribution trend of the level change in the instruction transmission path, selects the chain of continuous level increase as the risk concentration link, and outputs the segmented risk level supervision path set; The segmented risk level supervision path set includes staged risk levels, level change trajectories, link concentration sections, continuous incremental identification, and instruction conduction path mapping.
8. The artificial intelligence risk level supervision system according to claim 7 is characterized in that: The segment level tracking module includes: The level mapping marking submodule calls the level mapping calibration table, identifies the link number, trigger time and response time in the process path, extracts the original level value and compares the mapping level item, selects the corresponding value, and generates a risk level mapping value set; The level trend identification submodule, based on the risk level mapping value set, sorts the link number sequence and the response time sequence by number, identifies the difference between adjacent values and determines whether it is positive or negative, marks the growth node, extracts the continuous positive difference sequence, records the link number, the total difference and the number of nodes, removes the low-frequency change segment, and generates the number of increasing trend sequences; The chain screening aggregation submodule extracts high-frequency increasing path segments according to the number of increasing trend sequences, identifies the start and end numbers, calculates the cumulative increase and the increase rate, screens the path segments whose rates exceed the benchmark value, and obtains the segmented risk level supervision path set.
Citation Information
Patent Citations
Unmanned intelligent inspection equipment cooperative scheduling method and system in photovoltaic power generation scene
CN119358998A
Financial transaction anomaly detection and risk assessment method and device based on artificial intelligence
CN119693111A
Financial data security management system and method thereof
CN119848882A
Cited By
Data management method and system based on artificial intelligence
CN120316106A
A data governance method and system based on artificial intelligence
CN120316106B
Smart park monitoring method and system based on end-to-end cooperation
CN120378459A
An intelligent park monitoring method and system based on end-to-end cooperation
CN120378459B
Malicious deletion traceability method of distributed file system based on block chain
CN120386768A