Financial fraud detection method based on deep embedding technology
Through the financial fraud detection method based on deep embedded technology, the problem that the existing technology cannot adapt to the dynamic changes in the financial network in a timely manner is solved, and rapid response and high-accuracy detection of fraud are achieved.
Patent Information
- Application Number
- CN202510553231.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-29
- Publication Date
- 2025-05-30
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The existing technology cannot adapt to the dynamic changes in financial networks in a timely manner, resulting in delayed response to fraudulent behavior in high-frequency trading environments. In the dynamically changing networks, fraudulent transactions account for a minority, resulting in imbalance in transaction data and limited accuracy of model prediction.
The financial fraud detection method based on deep embedding technology is adopted to generate the adjusted network through weighted random undersampling, and the low-dimensional vectorization representation is performed using random walk and group embedding technology, and the network data flow is dynamically updated through the reservoir sampling method to identify abnormal edges and nodes in real time.
It realizes rapid response to dynamic changes in financial networks, reduces storage and computing costs, and improves the real-time and accuracy of fraud detection.
Smart Images

Figure CN120070062A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of anomaly detection, and specifically to a financial fraud detection method based on deep embedding technology. Background Art
[0002] The main task of financial fraud detection is to prevent non-compliant transactions. Banks at home and abroad mainly rely on expert experience in traditional anti-fraud management and formulate inspection rules manually based on business experience. However, such methods cannot comprehensively cover fraud behaviors in actual application scenarios, and expert rules are difficult to keep up with the update of fraud means. Machine learning methods train appropriate models by learning historical data to predict unknown problems and have been widely used in the anti-fraud field in recent years. According to the label situation of the training data, existing work can be classified into three categories: fraud detection based on supervised learning (SL), unsupervised learning (UL), and semi-supervised learning (SSL). Supervised methods rely on historical transaction data, analyze fraud patterns from it, and classify newly conducted transactions by training a model.
[0003] The prior art usually defines two typical sample distribution patterns, determines the distribution pattern by extracting the distribution features of the samples, and probabilistically selects and enhances samples under a probability distribution function according to the determined pattern. Specifically, it includes the following steps: Step S1: In deep embedding clustering DEC, feature selection and feature extraction are performed. Feature selection amplifies the distribution features of clustering, and feature extraction is achieved through an autoencoder; Step S2: In the DEC-SeDA framework, scaling of time series and selective data augmentation are performed. The scaling of the time series is performed at an equal ratio in each dimension, and samples are selectively selected for data augmentation to amplify the features that are more conducive to clustering.
[0004] However, existing technologies are often limited by their inherent static architectures and cannot effectively capture the rapidly changing characteristics in financial networks. The deficiencies of these technologies mainly stem from their lack of adaptation mechanisms for real-time changes in network structures, resulting in the inability to update models in a timely manner to reflect the latest risk patterns and fraud behaviors. Especially in high-frequency trading environments, such deficiencies may lead to response delays to fraud, thereby increasing financial risks. At the same time, in dynamically changing networks, fraudulent transactions only account for a small portion, leading to a serious imbalance in transaction data. The model is more inclined to predict the majority class during prediction. In addition, there is a lot of noise information and the scarcity of labels, resulting in weak guiding signals for feature learning. Since most data lacks complete labels, the noise information will also interfere with the training of the model. Under the dual influence of label scarcity and the prevalence of noise information, the accuracy of the model in capturing the characteristics of benign and fraudulent behaviors is limited, thereby leading to less than ideal detection performance. And existing technologies lack a rapid response mechanism to network changes. When dealing with network structure changes, it often requires recalculating the representation of the entire network, which is time-consuming and costly, limiting their effectiveness in real-time monitoring and predicting financial fraud. Summary of the Invention
[0005] The present invention aims to at least solve one of the technical problems existing in the prior art; for this purpose, the present invention proposes a financial fraud detection method based on deep embedding technology to solve the problems that the prior art cannot be applied to dynamically changing networks in a timely manner or has a high maintenance cost.
[0006] To achieve the above object, the present invention provides a financial fraud detection method based on deep embedding technology, including the following steps: S1: Perform weighted random undersampling on the initial network based on node label types and the number of neighbors to generate an adjusted network; S2: The adjusted network generates network walk sequences through a random walk strategy, and uses population embedding technology to perform low-dimensional vector representation on the nodes in each network walk sequence; S3: To ensure that the population embedding technology can efficiently reflect the latest structural changes in the network, a reservoir sampling method is also used to process the network data stream to achieve dynamic update of the network walk sequences; S4: Based on the nodes with low-dimensional vector representation, deploy a clustering-based anomaly detection algorithm to incrementally and real-time identify abnormal edges and nodes in the adjusted network; both abnormal edges and nodes represent the existence of fraud risks; The initial network changes over time.
[0007] Furthermore: The specific steps of S1 are as follows: S1-1: Construct a multi-relational undirected graph based on the initial network; S1-2: For any node in the multi-relational undirected graph, define corresponding sampling weights according to its category, where the categories include: fraud category and benign category; S1-3: Combine the information on the number of first-order neighbors of the nodes to calculate the final sampling probabilities of all nodes; S1-4: Sample an initially given time-varying network according to the sampling probabilities of all nodes to generate an adjusted network.
[0008] Furthermore: The specific method of S1-4 is as follows: S1-4-1: Perform inverse probability greedy sampling on the nodes according to the sampling probabilities, with low-probability nodes being preferentially retained. The specific method is as follows: Maintain two counters. The first counter counts the number of fraud-category nodes, and the second counter counts the number of normal-category nodes; Select nodes according to the sampling probabilities of all nodes. Traverse the sorted nodes one by one, and retrieve the nodes whose labels satisfy any one of the two conditions. The two conditions are: belonging to the fraud-category nodes and the number of fraud-category nodes being less than the product of the target proportion of fraud-category nodes and the total sample size; belonging to the normal-category nodes and the number of normal-category nodes being less than the product of the target proportion of normal-category nodes and the total sample size; Add the nodes that meet the conditions to , which is the vertex set spanning from timestamp 1 to timestamp t included in the adjusted network, and update the counters; S1-4-2: Perform edge sampling to update the set of streaming edges received from timestamp 1 to timestamp t. The method is as follows: Extract all the edges in the multi-relational undirected graph with the relationship type r, where r ∈ R and R represents the connected relationships in the multi-relational undirected graph; Filter the valid edges: Only retain the edges whose two endpoints are in to form an edge subset; Then merge the edge subsets of all relationship types to obtain the edge set of the adjusted network, and generate the adjusted network from the edge set.
[0009] Furthermore: The specific steps of S2 are as follows: S2-1: Decompose the adjusted network into a set of network walks, where each network walk contains a series of vertices selected by random walk; S2-2: Introduce the population embedding algorithm to learn the low-dimensional vectorized representation of each input network walk; S2-3: Encode the edges in the network walk into low-dimensional vectors, specifically calculated by the element-wise product of the embedding vectors of the two nodes of the edge.
[0010] Furthermore: The specific method of S2-2 is: S2-2-1: For each vertex in each input network walk, construct a one-hot encoded input vector; S2-2-2: For each input vector, perform forward propagation through the deep autoencoder and calculate the output of the hidden layer; S2-2-3: Calculate the total loss function based on the output of the hidden layer; S2-2-4: Calculate the partial derivatives of the total loss function with respect to the weights and biases, specifically as follows: Introduce the hidden layer error term and the output layer error term, consider the group embedding loss, calculate the partial derivatives of the weights and biases; use the gradient descent method to update the weights and biases; S2-2-5: Repeat S2-2-2, S2-2-3, S2-2-4 until one of the conditions of the maximum number of iterations or loss convergence is met; S2-2-6: Output the low-dimensional embedding vectors of each network node; Thus, the network nodes in each network walk are successfully represented in a low-dimensional vectorized manner.
[0011] Furthermore: The specific method of S3 is as follows: For any vertex in the adjusted network; Maintain a vertex repository of size for each vertex, determined by the network walk sequence; The vertex repository corresponding to each vertex consists of the neighbor vertices of that vertex; When a new neighbor vertex is sampled for the current vertex, update the vertex repository corresponding to the current vertex accordingly; After the updated vertex reaches the storage repository of the corresponding vertex, network walks that need to be updated accordingly will be generated; the set of newly added network walks is and the set of deleted network walks is ; Use the updated set of network walks to continue training the model in a warm start manner.
[0012] Furthermore: The rule for updating the vertex repository corresponding to the current vertex is specifically as follows: Obtain the update probability based on the degree of the current vertex, and then add new neighbor vertices according to the update probability to update the vertex repository accordingly.
[0013] Furthermore: The specific method of S4 is as follows: S4-1: Divide the network into k clusters according to the vertices and corresponding edges included in the adjusted network, and find the clustering center of each cluster; Calculate the distances between the cluster centers of each cluster and all existing cluster centers. S4-2: When new vertices flow in, use streaming k-means clustering to update the cluster centers accordingly. S4-3: Calculate the anomaly scores of the embedded vectors of the nodes and edges corresponding to the new vertices after learning representation processing, that is, calculate the minimum Euclidean distance between the embedded vector of any item of the new node or edge and all cluster centers. Determine whether this distance exceeds a predefined threshold: if yes, it is considered that the newly added node or edge is abnormal and there is a fraud risk; if no, it is considered that the newly added node or edge is normal.
[0014] Furthermore: The counter terminates counting when any of the following two conditions is met: The number of fraud nodes in the adjusted network is equal to times the total number of nodes; The number of benign nodes in the adjusted network is equal to times the total number of nodes; is the preset target proportion of fraud nodes; is the preset target proportion of normal nodes.
[0015] The beneficial effects of the present invention are: (1) Using reservoir sampling to process large-scale data streams, while maintaining the representativeness of samples, significantly reducing storage and computing costs.
[0016] (2) Group embedding captures local neighborhood information in the network and maps it to coordinates in a multi-dimensional space, providing an effective low-dimensional representation for subsequent network analysis tasks, such as anomaly detection and community discovery.
[0017] (3) Clustering technology helps to discover the inherent structure and patterns in the data, provides support for further analysis and decision-making, identifies abnormal nodes or edges that do not belong to any existing clusters, and thus realizes real-time fraud detection in dynamic financial networks. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] In order to more clearly illustrate the technical solutions in the embodiments of the present invention and the prior art, the following will briefly introduce the drawings required for description in the embodiments and the prior art. Obviously, the drawings in the following description are only some embodiments recorded in the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0019] Figure 1 is the method flow chart of the present invention; Figure 2Schematic diagram of updating the vertex repository by the reservoir sampling method provided by a specific embodiment of the present invention. Detailed implementation manners
[0020] In order to make the objectives, technical solutions and advantages of the present invention clearer and more understandable, the present invention will be described and illustrated below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments provided by the present invention without making creative efforts belong to the scope of protection of the present invention.
[0021] Obviously, the accompanying drawings in the following description are only some examples or embodiments of the present invention. For those of ordinary skill in the art, the present invention can also be applied to other similar scenarios based on these drawings without making creative efforts.
[0022] In addition, it can also be understood that although the efforts made in this development process may be complex and lengthy, for those of ordinary skill in the art related to the content disclosed by the present invention, some design, manufacturing or production changes based on the technical content disclosed by the present invention are only conventional technical means and should not be understood as the content disclosed by the present invention being insufficient.
[0023] If there is no special description, all embodiments and optional embodiments of the present invention can be combined with each other to form new technical solutions.
[0024] Please refer to Figure 1 , the method flowchart of the present invention, which includes the following steps: S1: Initially, a time-varying network is given, and weighted random undersampling is performed based on the node label type and the number of neighbors to generate an adjusted network; S2: The adjusted network generates a network walk sequence through a random walk strategy, and uses the population embedding technology to perform low-dimensional vector representation on the network nodes in each network walk sequence; S3: The reservoir sampling method is used to process the network data stream to realize the dynamic update of the network walk sequence; S4: Based on the network nodes with low-dimensional vector representation, a clustering-based anomaly detection algorithm is deployed to incrementally and real-time identify the abnormal edges and nodes in the adjusted network.
[0025] Specifically: The specific steps of S1 are as follows: S1-1 For the initially given time-varying network, a multi-relational undirected graph is constructed, denoted as ; S1-2: For any node in the multi-relational undirected graph , define the corresponding sampling weight according to its category , where the categories include: fraud category and benign category; S1-3: Combine the information on the number of first-order neighbors of the node to calculate the final sampling probability of the node ; ; S1-4: Sample an initially given time-varying network according to the sampling probability to generate an adjusted network .
[0026] The method of sampling an initially given time-varying network according to the sampling probability is as follows: S1-4-1: Conduct inverse probability greedy sampling on the nodes according to the sampling probability , and preferentially retain the nodes with low probabilities. The specific method is as follows: Maintain two counters and , count the number of fraud nodes, count the number of normal nodes; Select nodes in ascending order of , and traverse the sorted nodes one by one , and retrieve the nodes whose labels meet any one of the two conditions. The two conditions are: fraud category and , normal category and ; Add the nodes that meet the conditions to , and update the counters, where: is the target proportion of fraud nodes, is the target proportion of normal nodes, and K is the preset total sample size; until the target ratio is met or the preset total sample size is reached; After sampling, it is also necessary to meet one of the following two conditions: the number of fraud nodes in the adjusted network is equal to times the total number of nodes; the number of benign nodes in the adjusted network is equal to times the total number of nodes; That is, the category ratio constraint: and ; S1-4-2: Then conduct edge sampling and update , and the method is: For each relationship type , only retain the two endpoints of the edge in The edges, and the corresponding edge subset is ; among them, represents the edges with both endpoints in ; represents all the edges in that belong to the relationship type; Then, the edge subsets of all relationship types are merged into , and an adjusted network is generated according to the edge set.
[0027] The specific steps of S2 are as follows: S2-1: Decompose the adjusted network into a set of network walks, where each network walk contains a series of vertices selected by random walk; S2-2: Introduce a population embedding algorithm to learn the low-dimensional vectorized representation of each input network walk ; S2-3: Encode the edges in the network walk into low-dimensional vectors: for each edge , its encoding vector is calculated through the element-wise product of the embedding vectors of node and node , where nodes and are both determined according to the network nodes with low-dimensional vectorized representation in S2-2.
[0028] The specific method of S2-2 is: S2-2-1: For each vertex p in each input network walk , construct a one-hot encoded input vector , where n is the total number of vertices in each input network walk; S2-2-2: For each input vector , perform forward propagation through a deep autoencoder to calculate the output of the hidden layer; S2-2-3: Calculate the total loss function according to the output of the hidden layer; Among them, represents the population embedding loss; represents the reconstruction error; represents the sparsity constraint; represents the weight decay; represents the reconstruction error weight used to ensure that the network embedding can better reconstruct an initially given time-varying network structure; The reconstruction error weight that represents the case of penalizing the activation values of the hidden layer neurons deviating from the preset sparsity P through KL divergence, thereby maintaining the sparsity of the embedding; The reconstruction error weight that represents preventing overfitting and restricting the model complexity by penalizing the norm of the weight matrix; S2-2-4: Backpropagation and parameter update, that is, calculating the partial derivatives of the total loss function with respect to the weights and biases as follows: Introduce the hidden layer error term and the output layer error term , consider the group embedding loss, and calculate the partial derivatives of the weights and biases ; Update the weights and biases using the gradient descent method: ; ; S2-2-5: Repeat S2-2-2, S2-2-3, S2-2-4 until the maximum number of iterations is reached or the loss converges; S2-2-6: Output the low-dimensional embedding vectors of each network node; thus, each network node in each network walk is successfully represented in a low-dimensional vector form.
[0029] The specific method of S3 is as follows: For any vertex (denoted as m) in the adjusted network , maintain a vertex repository for each vertex m, and the size of the vertex repository is , determined by the network walk sequence, and the value can be 1, 2,..., n. The vertices in the vertex repository are replaced by the sampled vertices with the changing sampling timestamps and the newly sampled neighbor vertices at different timestamps, as shown in ; When a new vertex is sampled, update the vertex repository. When a vertex (and the corresponding edge of the vertex) is added to the vertex repository, the update rule is as follows: Update the vertex and the degree of m: , ; For each item (vertex) in the vertex repository , replace the old item with the new item with a probability of 1 / ; the probability of retaining the old item is 1 - 1 / ; For each item in the vertex repository , replace the old item with the new item with a probability of 1 / ; the probability of retaining the old item is 1 - 1 / ; For the specific sampling replacement process, please refer to Figure 2 , the schematic diagram of updating the vertex repository for the reservoir sampling method provided by the present invention. When adding an edge ( , , ) at the timestamp , are the two endpoints of the edge, which are simplified as numbers 1, 2,... in the figure), it can be seen that the neighbors of point are and , and its degree is 2 (the degree is directly determined by the number of lines extending from this point, updated vertex = 2 + 1). Therefore, will be added with a probability of 1 / 3, and will be added with a probability of 1 / 3, so as to update the repositories corresponding to vertex and vertex .
[0030] In the figure, the size of the vertex repository is 3, and the vertex repositories corresponding to each vertex at the timestamp are respectively: ( , , ), ( , , ), ( , , ), ( , , ). It can be seen the update change of the vertex repositories from the timestamp to ; For example, for vertex , during the process from the timestamp to , the selected neighbor nodes are reduced, is disconnected from , and the vertex repository corresponding to the moment updates the original to any one of and (since is not sampled in the initial vertex repository, does not participate in the update process); For example, for vertex , at the timestamp to during the process of a new connection relationship is and there is a certain probability of adding it.
[0031] After the updated vertex reaches the corresponding vertex repository, a network walk that needs to be updated accordingly will be generated; a new set of network walks is and the set of deleted network walks is ; Use the updated set of network walks to continue training the model in a warm start manner.
[0032] The specific method of S4 is as follows: S4-1: Divide the network into k clusters according to the vertices and corresponding edges included in the adjusted network, and find the clustering center of each cluster; Calculate the distance between the clustering center of each cluster and all existing clustering centers Distance = , c ∈ C, where is the learned representation of each vertex and edge; represents the Euclidean distance; c is the clustering center of any cluster; S4-2: When new vertices flow in, use streaming k-means clustering to update the clustering center accordingly; S4-3: Calculate the anomaly score of the embedding vectors of the nodes and edges corresponding to the new vertices after being processed by the learned representation , that is, calculate the minimum Euclidean distance between the embedding vector of any new node or edge and all clustering centers; Judge whether this distance exceeds a predefined threshold: if yes, it is considered that the newly added node or edge is abnormal; if no, it is considered that the newly added node or edge is normal.
[0033] The above has given a very detailed application description of one or more embodiments of the present invention, but the content described is only a specific example of the present invention and cannot be considered as limiting the scope of implementation of the present invention. Any other methods and changes proposed based on the content of the present invention shall fall within the scope of patent protection of the present invention.
Claims
1. A financial fraud detection method based on deep embedding technology, characterized in that: The steps include: S1: Perform weighted random undersampling on the initial network based on node label type and number of neighbors to generate an adjusted network; S2: The adjusted network generates a network walk sequence through a random walk strategy, and uses group embedding technology to perform low-dimensional vector representation of the nodes in each network walk sequence; S3: Use the reservoir sampling method to process the network data stream and dynamically update the network walk sequence; S4: Based on the low-dimensional vectorized representation of the nodes, a clustering-based anomaly detection algorithm is deployed to incrementally identify abnormal edges and nodes in the adjusted network in real time; abnormal edges and nodes both represent fraud risks; The initial network changes over time.
2. According to claim 1, a financial fraud detection method based on deep embedding technology is characterized in that: The specific steps of S1 are as follows: S1-1: Construct a multi-relation undirected graph based on the initial network; S1-2: For any node in the multi-relation undirected graph, define the corresponding sampling weight according to its category, which includes: fraud and benign; S1-3: Combine the first-order neighbor number information of the node to calculate the final sampling probability of all nodes; S1-4: Sample an initially given time-varying network according to the sampling probabilities of all nodes to generate an adjusted network.
3. A financial fraud detection method based on deep embedding technology according to claim 2, characterized in that: The specific method of S1-4 is as follows: S1-4-1: Perform inverse probability greedy sampling on nodes according to sampling probability, and keep low probability nodes first. The specific method is as follows: Maintain two counters, the first counter counts the number of fraud nodes, and the second counter counts the number of normal nodes; Select nodes according to the sampling probability of all nodes, traverse the sorted nodes one by one, and retrieve nodes whose labels meet any of the two conditions: they belong to fraud nodes, and the number of fraud nodes is less than the product of the target proportion of fraud nodes and the total sample size; Belong to normal class nodes, and the number of normal class nodes is less than the product of the target proportion of normal class nodes and the total sample size; Add nodes that meet the conditions , The set of vertices from timestamp 1 to timestamp t included in the adjusted network, and the counter is updated; S1-4-2: Perform edge sampling and update the set of streaming edges received from timestamp 1 to timestamp t. The method is: Extract all edges corresponding to the relation type r in the multi-relation undirected graph, r∈R, where R represents the connectivity relation in the multi-relation undirected graph; Filter valid edges: only keep the two endpoints of the edge The edges of , constitute the edge subset; Then, edge subsets of all relationship types are merged to obtain the edge set of the adjusted network, and the adjusted network is generated from the edge set.
4. The financial fraud detection method based on deep embedding technology according to claim 1 is characterized in that: The specific steps of S2 are as follows: S2-1: Decompose the adjusted network into a set of network walks, where each network walk contains a series of vertices selected by a random walk; S2-2: Introduce a group embedding algorithm to learn a low-dimensional vector representation of each input network walk; S2-3: Encode the edges in the network walk into low-dimensional vectors, which are calculated by the element-by-element product of the embedding vectors of the two nodes of the edge.
5. A financial fraud detection method based on deep embedding technology according to claim 4, characterized in that: The specific method of S2-2 is: S2-2-1: For each vertex in each input network walk, construct a one-hot encoded input vector; S2-2-2: For each input vector, forward propagate through the deep autoencoder to calculate the output of the hidden layer; S2-2-3: Calculate the total loss function based on the output of the hidden layer; S2-2-4: Calculate the partial derivatives of the total loss function with respect to weights and biases as follows: Introduce hidden layer error terms and output layer error terms, consider group embedding loss, calculate partial derivatives of weights and biases; use gradient descent method to update weights and biases; S2-2-5: Repeat S2-2-2, S2-2-3, and S2-2-4 until one of the conditions of maximum number of iterations or loss convergence is met; S2-2-6: Output the low-dimensional embedding vector of each network node; Therefore, each network node in the network walk is successfully represented by low-dimensional vectorization.
6. The financial fraud detection method based on deep embedding technology according to claim 1 is characterized in that: The specific method of S3 is: For any vertex in the adjusted network; Maintain a size of The Vertex Repository, Determined by the network walk sequence; The vertex repository corresponding to each vertex consists of the neighboring vertices of the vertex; When the current vertex samples a new neighbor vertex, the vertex storage corresponding to the current vertex is updated accordingly; After the updated vertex reaches the repository of the corresponding vertex, a network walk that needs to be updated accordingly will be generated; the newly added network walk set is , the deleted network walk set is ; Use the updated network walk set Continue training the model in warm start mode.
7. A financial fraud detection method based on deep embedding technology according to claim 6, characterized in that: The specific rules for updating the vertex repository corresponding to the current vertex are: The update probability is obtained according to the degree of the current vertex, and then new neighbor vertices are added according to the update probability, thereby updating the vertex repository.
8. The financial fraud detection method based on deep embedding technology according to claim 1 is characterized in that: The specific method of S4 is: S4-1: Divide the network into k clusters according to the vertices and corresponding edges contained in the adjusted network, and find the cluster center of each cluster; Calculate the distance between the cluster center of each cluster and all existing cluster centers; S4-2: When new vertices flow in, streaming k-means clustering is used to update the cluster centers accordingly; S4-3: Calculate the anomaly score of the embedding vectors of the nodes and edges corresponding to the new vertex after the learned representation processing, that is, calculate the minimum Euclidean distance between the embedding vector of any new node or edge and all cluster centers; Determine whether this distance exceeds a predefined threshold: if yes, the newly added node or edge is considered abnormal and there is a risk of fraud; if no, the newly added node or edge is considered normal.
9. The financial fraud detection method based on deep embedding technology according to claim 3 is characterized in that: The counter stops counting when any one of the following two conditions is met: The number of fraudulent nodes in the adjusted network is equal to the total number of nodes times; The number of benign nodes in the adjusted network is equal to the total number of nodes times; The preset fraud node target ratio; It is the preset target ratio of normal nodes.