Cooperative fraud number detection method and system based on graph neural network

Through the collaborative fraud number detection method based on graph neural network, heterogeneous graphs are constructed using historical communication data, communities and collaborative information, the problem of fraud number identification in complex scenarios is solved, high-precision and fast response fraud detection is achieved, and anti-fraud capabilities are improved.

CN120111136AActive Publication Date: 2025-06-06北京九栖科技有限责任公司

Patent Information

Application Number
CN202510304688.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-14
Publication Date
2025-06-06
Estimated Expiration
2045-03-14

AI Technical Summary

Technical Problem

The prior art is difficult to effectively identify fraud numbers in complex scenarios, and the pattern characteristics of traditional static behavior pattern analysis methods are poor, making it difficult to adapt to the rapid changes in fraud methods.

Method used

A collaborative fraud number detection method based on graph neural network is adopted. By obtaining the historical communication data of the target mobile phone number, the original features and interactive features are extracted, and a heterogeneous graph is constructed based on community information and collaborative information, the graph neural network model is input to obtain comprehensive node features, and the fraud number prediction is finally carried out.

Benefits of technology

Effective identification of fraud numbers in complex scenarios improves the accuracy and response speed of fraud detection, improves anti-fraud capabilities, and can identify new fraud models, achieving an effective crackdown on telecom fraud behavior.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120111136A_ABST
    Figure CN120111136A_ABST
Patent Text Reader

Abstract

The invention discloses a cooperative fraud number detection method and system based on a graph neural network, and relates to the technical field of information security, and the method comprises the steps: obtaining historical communication data of a target mobile phone number; obtaining an original feature and an interaction feature of each number based on the historical communication data; community information and cooperation information of the target mobile phone number are obtained through screening based on historical communication data; integrating the original features, the interaction features, the community information and the collaborative information to obtain a heterogeneous graph; inputting the heterogeneous graph into a graph neural network model to obtain neighbor node features, community node features and time sequence node features; fusing the neighbor node features, the community node features and the time sequence node features to obtain comprehensive node features; and inputting the comprehensive node features into a classification layer to obtain a prediction result. The fraud number is effectively identified in a complex scene, the accuracy and response speed of fraud detection are improved, and the anti-fraud capability is further improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security technology, and more specifically to a collaborative fraud number detection method and system based on graph neural network. Background Art

[0002] At present, with the rapid development of the Internet, more and more users are pouring into this emerging entertainment and social field. However, this has also attracted a large number of criminals, who fabricate false information through phone calls, text messages and various application software, commit fraud, and induce victims to make payments or transfers, causing property losses and credibility crises. In recent years, in order to reduce telecommunications fraud, various fraud detection models have also emerged. For example, semi-supervised static probability graph models FFD, FRAUDER, PC_GNN, RIO_GNN and other classifier-based algorithms, as well as sequence-based methods such as HAINt-LSTM, NHA-LSTM, BiDyn, CORE-DGNN, etc.

[0003] Traditional static behavior pattern analysis methods can mine a wealth of fraud behavior patterns and effectively distinguish between fraud and normal user behavior patterns. However, the stability of its pattern characteristics is poor, and the fraud behavior pattern library needs to be updated at any time according to the latest telecommunications network fraud data, which makes it difficult to adapt to the impact of rapid changes in fraud methods.

[0004] Therefore, how to effectively identify fraudulent numbers in complex scenarios and improve the accuracy and response speed of fraud detection is an urgent problem that technical personnel in this field need to solve. Summary of the invention

[0005] In view of this, the present invention provides a collaborative fraud number detection method and system based on graph neural network, which can effectively identify fraud numbers in complex scenarios, improve the accuracy and response speed of fraud detection, and thus enhance anti-fraud capabilities.

[0006] In order to achieve the above object, the present invention adopts the following technical solution:

[0007] A collaborative fraud number detection method based on graph neural network, comprising:

[0008] Obtain historical communication data of the target mobile phone number;

[0009] Acquire original features and interactive features of each number based on the historical communication data;

[0010] Filter and obtain the community information and collaborative information of the target mobile phone number based on the historical communication data;

[0011] Obtaining a heterogeneous graph based on the integration of the original features, the interactive features, the community information and the collaborative information;

[0012] Based on the heterogeneous graph input into the graph neural network model, the neighbor node features, community node features and time series node features are obtained;

[0013] Obtaining a comprehensive node feature based on the fusion of the neighbor node feature, the community node feature and the time series node feature;

[0014] Based on the comprehensive node features, the features are input to the classification layer to obtain prediction results.

[0015] Preferably, the community information acquisition method is:

[0016] Determine whether the communication behavior is on a working day or a holiday based on the historical communication data, and obtain a determination result;

[0017] Obtaining the behavioral difference characteristics between the working day and the holiday based on the judgment result;

[0018] Acquire the call behavior characteristics of the target mobile phone number at different times of the day based on the historical communication data;

[0019] The community information is generated based on the behavior difference characteristics and the call behavior characteristics.

[0020] Preferably, the collaborative information acquisition method is:

[0021] Based on the historical communication data, obtain timestamps and location information of multiple user numbers that have communicated with the target mobile phone number;

[0022] Obtaining a time interval based on the timestamp;

[0023] Acquire a cross-region dialing mode based on the location information;

[0024] Based on the time interval and the cross-regional dialing pattern recognition, a collaborative crime feature is obtained;

[0025] The collaborative information between the user numbers is obtained based on the collaborative crime feature extraction.

[0026] Preferably, the heterogeneous graph construction method is:

[0027] Acquire all user numbers that communicate with the target mobile phone number based on the historical communication data;

[0028] Based on the target mobile phone number and the user number as nodes;

[0029] Obtaining a community label based on the community information;

[0030] Based on the community label and the original feature as node attributes, they are bound to the corresponding node to obtain an information node;

[0031] Generate a call link graph and a text message link graph based on the interactive relationship between all the information nodes;

[0032] Based on the interaction feature, the collaboration information and the community information as edge features, they are respectively bound to the call link graph and the SMS link graph to obtain a first link graph and a second link graph accordingly;

[0033] The heterogeneous graph is obtained by integrating the information nodes, the first link graph and the second link graph.

[0034] Preferably, obtaining a community label based on the community information specifically includes:

[0035] Based on the encoding of the community information in the time dimension:

[0036] The working days and holidays are represented by 2-bit binary to obtain a first dimension code;

[0037] Different time periods in a day are represented by 5 bits of binary to obtain the second dimension encoding;

[0038] A multi-dimensional code is obtained based on the first dimensional code and the second dimensional code as the community label.

[0039] Preferably, the graph neural network model includes a multi-frequency collaborative neural network, a self-attention temporal convolutional network and a multi-frequency processing module;

[0040] The heterogeneous graph is sequentially input into the multi-frequency collaborative neural network and the multi-frequency processing module to obtain the neighbor node features and the community node features;

[0041] The heterogeneous graph is input into the self-attention temporal convolutional network to obtain temporal node features.

[0042] Preferably, the method for obtaining community node features is:

[0043] Dividing all the information nodes into corresponding communities based on the time dimension information of the heterogeneous graph;

[0044] Clustering is performed based on the nodes in the community, and the cluster center node is selected as the single community feature of the current community;

[0045] The community node feature is obtained based on the aggregation of all the single community node features.

[0046] Preferably, the method for acquiring neighbor node features is:

[0047] Based on any information node in the heterogeneous graph as the current central node;

[0048] Selecting all neighbor nodes that are cooperatively connected with the central node based on the cooperative information;

[0049] Based on the similarity between the central node and the neighboring nodes, a plurality of neighboring nodes greater than a threshold are screened and obtained as screening nodes;

[0050] Generate neighbor node weights based on the screening nodes;

[0051] An initial neighbor feature of the central node is obtained based on the edge features of the central node and the neighbor nodes and the original features of the neighbor nodes;

[0052] Based on the neighbor node weights and the initial neighbor features, obtaining updated neighbor features;

[0053] The neighbor node feature is obtained by aggregating the first link graph and the second link graph based on the updated neighbor feature.

[0054] Preferably, the method for acquiring the time series node features is:

[0055] Constructing a time series based on each information node in the heterogeneous graph;

[0056] Extracting node features of the central node at the lth layer based on the time series;

[0057] Perform a maximum pooling operation based on the node features to obtain the hierarchical features at the lth layer and t time steps;

[0058] Perform a maximum pooling operation based on the hierarchical features to obtain global features;

[0059] Obtaining an initial attention score of the central node based on the global feature and normalizing it to obtain a final attention weight;

[0060] The temporal node feature is obtained based on the fusion of the final attention weight, the hierarchical feature and the global feature.

[0061] A collaborative fraud number detection system based on graph neural network, comprising: a data acquisition module, a data feature extraction module, a heterogeneous graph construction module, a node feature acquisition module and a prediction result output module;

[0062] The data acquisition module is used to acquire the historical communication data of the target mobile phone number;

[0063] The data feature extraction module is used to obtain the original features and interactive features of each number based on the historical communication data; and to filter and obtain the community information and collaborative information of the target mobile phone number based on the historical communication data;

[0064] The heterogeneous graph construction module is used to integrate the original features, the interactive features, the community information and the collaborative information to obtain a heterogeneous graph;

[0065] The node feature acquisition module is used to obtain neighbor node features, community node features and time series node features based on the heterogeneous graph input to the graph neural network model; and obtain the comprehensive node features based on the fusion of the neighbor node features, the community node features and the time series node features;

[0066] The prediction result output module is used to obtain the prediction result based on the comprehensive node feature input to the classification layer.

[0067] It can be seen from the above technical solutions that compared with the prior art, the present invention discloses a collaborative fraud number detection method and system based on graph neural network. The present invention constructs a multi-level heterogeneous graph data structure by combining multi-dimensional data such as time information, call and text message records, community information, collaborative information, etc., and detects and identifies them through a collaborative multi-frequency graph neural network model. It can effectively identify fraud numbers in complex scenarios and improve anti-fraud capabilities; the present invention identifies the communication behavior of fraud numbers and the types of fraud calls through comprehensive utilization of basic feature data, thereby effectively improving the detection capabilities of telecommunications fraud; the present invention can identify new fraud models through in-depth analysis of fraudulent behaviors, thereby effectively combating telecommunications fraud and protecting the safety and interests of users. BRIEF DESCRIPTION OF THE DRAWINGS

[0068] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without paying creative work.

[0069] Figure 1 A flow chart of a collaborative fraud number detection method based on graph neural network provided by the present invention.

[0070] Figure 2 This is a flow chart of the heterogeneous graph construction method provided by the present invention.

[0071] Figure 3 This is a schematic diagram of the graph neural network model structure provided by the present invention.

[0072] Figure 4 A schematic diagram of the structure of a collaborative fraud number detection system based on graph neural network provided by the present invention. DETAILED DESCRIPTION

[0073] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0074] Example 1

[0075] like Figure 1 As shown, the embodiment of the present invention discloses a collaborative fraud number detection method based on a graph neural network, comprising:

[0076] Obtain historical communication data of the target mobile phone number;

[0077] Obtaining original features and interactive features of each number based on historical communication data;

[0078] Filter and obtain the community information and collaborative information of the target mobile phone number based on historical communication data;

[0079] A heterogeneous graph is obtained by integrating original features, interactive features, community information and collaborative information;

[0080] Based on the heterogeneous graph input into the graph neural network model, the neighbor node features, community node features and time series node features are obtained;

[0081] Comprehensive node features are obtained by fusing neighbor node features, community node features and time series node features;

[0082] Based on the comprehensive node features, the features are input to the classification layer to obtain the prediction results.

[0083] Example 2

[0084] The embodiment of the present invention discloses a collaborative fraud number detection method based on a graph neural network, comprising:

[0085] Get the historical communication data of the target mobile number.

[0086] Preferably, the call records and text message records of the target mobile phone number from major operators are obtained, including the communication data of the day and within 30 days as the historical communication data.

[0087] The original features and interaction features of each number are obtained based on historical communication data.

[0088] Preferably, detailed information of relevant numbers is extracted based on historical communication data, and basic information of these numbers and their call or SMS counterpart numbers on the same day is recorded in the number screening table to generate a call table and a SMS table accordingly. The call table contains key fields such as timestamp, calling and called provinces, and the SMS table contains key fields such as sending time, sending and receiving end numbers, etc.

[0089] Preferably, the original features and interactive features of each number are extracted based on the call table and the SMS table; wherein the original features include: call features such as the number of calls, the total number of calls, the average call duration, the active call time period, SMS features such as the number of SMS sent, the number of SMS received, and monthly frequency features such as the number of active days in a month, the number of active cities, etc.; the interactive features include: the mutual dial rate and the mutual call time ratio.

[0090] The community information and collaborative information of the target mobile phone number are obtained based on the historical communication data.

[0091] Preferably, the community information acquisition method is:

[0092] Based on historical communication data, determine whether the communication behavior is on a weekday or a holiday, and obtain a judgment result;

[0093] Based on the judgment results, the behavioral difference characteristics between weekdays and holidays are obtained;

[0094] Based on historical communication data, the call behavior characteristics of the target mobile phone number at different times of the day (such as early morning, morning, afternoon, and evening) are obtained;

[0095] Generate community information based on behavioral difference characteristics and call behavior characteristics.

[0096] Preferably, community information is formed based on time information such as date, time, weekdays / holidays, etc., wherein in this example, "community" is defined as a set of numbers divided according to time and the like.

[0097] Preferably, the collaborative information acquisition method is:

[0098] Obtaining timestamps and location information of multiple user numbers that have communicated with the target mobile phone number based on historical communication data;

[0099] Get time interval based on timestamp;

[0100] Obtain cross-regional dialing patterns based on location information;

[0101] Based on time interval and cross-regional dialing pattern recognition, collaborative crime characteristics are obtained;

[0102] The collaborative information between user numbers is obtained based on the collaborative crime feature extraction.

[0103] Preferably, in collaborative fraud, the time intervals between the calls made by the fraudsters are usually short. By analyzing these timestamps, the short time intervals between the fraudsters and the cross-regional calling patterns can be extracted, from which signs of collaborative crimes can be identified, and collaborative information between user numbers can be extracted.

[0104] Preferably, this embodiment assists in detecting potential abnormal behavior patterns by analyzing time dimensions such as years, months, and days. By identifying numbers that are frequently active during specific time periods, the ability to warn of potential fraudulent behavior can be effectively improved. And considering the existence of collaborative fraud, that is, multiple numbers jointly commit fraud against the same victim. For example, one member may be responsible for making extensive phone calls to find potential victims, while another member further induces victims who have already taken the bait. The social structure of such behavior changes rapidly over time, resulting in significant differences in the behavior patterns of scammers and ordinary users. Based on this, this embodiment screens out collaborative information by analyzing the relationship between the calling (sending) number and the called (receiving) number to identify collaborative fraud.

[0105] A heterogeneous graph is obtained based on the integration of original features, interactive features, community information and collaborative information.

[0106] Preferably, Figure 2 As shown, the heterogeneous graph construction method is:

[0107] Obtain all user numbers that communicate with the target mobile phone number based on historical communication data;

[0108] Based on the target mobile phone number and user number as nodes;

[0109] Obtain community labels based on community information;

[0110] Based on the community labels and original features as node attributes, they are bound to the corresponding nodes to obtain information nodes;

[0111] Generate call link graph and SMS link graph based on the interaction relationship between all information nodes;

[0112] Based on the interaction features, the collaborative information and the community information as edge features, they are respectively bound to the call link graph and the SMS link graph, and the first link graph and the second link graph are obtained accordingly;

[0113] Based on the information nodes, the first link graph and the second link graph are integrated to obtain a heterogeneous graph.

[0114] Preferably, obtaining a community label based on community information specifically includes:

[0115] Encoding based on community information in the time dimension:

[0116] Working days and holidays are represented by 2-bit binary (e.g., 01 represents working days) to obtain the first dimension code;

[0117] Different time periods in a day are represented by 5-bit binary (e.g., 00100 represents 8:00-12:00 in the morning) to obtain the second dimension code;

[0118] Based on the first dimension coding and the second dimension coding, the multi-dimensional coding is obtained as the unique community label, which clearly identifies the behavioral characteristics of each node in the time dimension.

[0119] Preferably, a call link graph is generated based on the call data, and a text message link graph is generated based on the text message data, reflecting different types of node interactions.

[0120] Preferably, the heterogeneous graph includes a single node type (telephone node) and multiple edge types (call edge, text message edge).

[0121] Preferably, a heterogeneous graph is generated every day as a graph dataset required for subsequent model training.

[0122] Based on the heterogeneous graph input into the graph neural network model, neighbor node features, community node features and time series node features are obtained.

[0123] Preferably, Figure 3 As shown, the graph neural network model includes a multi-frequency collaborative neural network, a self-attention temporal convolutional network, and a multi-frequency processing module;

[0124] The heterogeneous graph is sequentially input into the multi-frequency collaborative neural network and the multi-frequency processing module to obtain the neighbor node features and community node features;

[0125] The heterogeneous graph is input into the self-attention temporal convolutional network to obtain the temporal node features.

[0126] Preferably, the graph neural network model is trained based on a graph data set composed of heterogeneous graphs to obtain a trained graph neural network model.

[0127] Preferably, before model training, the whole graph is converted into a local graph for training and testing, in order to improve the training efficiency and processing power of the model. Local graph training can reduce computational complexity and enable the model to focus on a smaller range of node relationships, thereby more accurately capturing local structural features and relationships. This method can help reduce memory usage and speed up the training process while improving the learning effect of local graph features. That is, the entire graph is divided into multiple batches, each batch is an independent local subgraph, and for each local subgraph, the model is trained and evaluated independently, and the model parameters are updated to be globally shared.

[0128] Preferably, the loss function used in the training process is:

[0129]

[0130] Among them, V represents the set of central nodes, y v represents the true label of the central node v, σ represents the activation function, z v =h' v Represents the final embedding obtained by the central node v.

[0131] Preferably, the method for obtaining community node features is:

[0132] Divide all information nodes into corresponding communities based on the time dimension information of the heterogeneous graph;

[0133] Clustering is performed based on the nodes in the community, and the cluster center node is selected as the single community feature of the current community;

[0134] Based on the aggregation of all individual community node features, community node features are obtained.

[0135] Preferably, this embodiment uses K-Means algorithm for clustering.

[0136] Preferably, a single community feature h v,w for:

[0137] h v,w =RELU(Mean AGG(h v',w ):v'∈N' w );

[0138] Among them, RELU represents the activation function, Mean AGG represents the average node aggregation function, and N' w A collection of nodes representing the communities generated by the aggregation.

[0139] Preferably, the community node feature h com for:

[0140] h com =AGG(⊕h v,w );

[0141] Among them, AGG represents the aggregation function, and w represents different community information labels.

[0142] Preferably, the neighbor node feature acquisition method is:

[0143] Based on any information node in the heterogeneous graph as the current central node;

[0144] Based on the collaborative information, all neighbor nodes that are collaboratively connected to the central node are preferentially selected;

[0145] Based on the similarity between the central node and the neighboring nodes, multiple neighboring nodes with a value greater than a threshold are screened and obtained as screening nodes;

[0146] Based on all the nodes screened out above (including neighbor nodes that are collaboratively connected to the central node and nodes whose similarity is greater than a threshold), the weights of the neighbor nodes are generated;

[0147] The initial neighbor features of the central node are updated based on the edge features of the central node and the neighbor nodes and the original features of the neighbor nodes;

[0148] Based on the neighbor node weights and the initial neighbor features, the updated neighbor features are obtained;

[0149] The neighbor node features are obtained by aggregating the first link graph and the second link graph based on the updated neighbor features.

[0150] Preferably, in this embodiment, the Manhattan distance between the central node and the neighboring nodes is calculated as the similarity D(v,v'):

[0151]

[0152] Among them, tanh represents a nonlinear activation function, FCN represents a fully connected network, and h v represents the original features of the central node v, h v' Represents the original features of the neighbor node v'.

[0153] Preferably, in this implementation, the central node is downsampled, and the K neighbor nodes closest to the central node are screened out based on similarity through a TOP-K downsampling algorithm.

[0154] Preferably, considering that wavelet transform is used to generate node features, it can not only capture the similarity of nodes in the subgraph, but also capture their differences, thus having better neighborhood flexibility. Therefore, in each relationship edge, wavelet transform is used to further update the node features. Beta distribution is selected as the graph kernel function to generate the weight W of the neighbor node features. p,q :

[0155]

[0156] Where p and q are the shape parameters of the Beta distribution, p+q=C, C is a constant, B(p,q) represents the Beta function for normalization, λ represents the eigenvalue, I represents a unit matrix, and W p,q =(W 0,C ,W 1,C-1 ...,W C,0 ).

[0157] Preferably, the initial neighbor feature h' of the central node is updated based on the edge features of the central node and the neighbor nodes and the original features of the neighbor nodes. r,adj :

[0158] h' r,adj =FCN(d v,v’,r *h v',r );

[0159] Among them, FCN represents the activation function, d v,v’,r is the edge feature (such as mutual call rate, coordination information, etc.) between the central node v and the neighbor node v' under the relationship r, r∈(0,R), in this example, R=2.

[0160] Preferably, based on the neighbor node weight W p,q and initial neighbor feature h' r,adj , get the updated neighbor feature h r,adj :

[0161] h r,adj =AGG(W p,q *h' r,adj )=AGG(W i,C-i *h' r,adj :i∈(0,C));

[0162] Among them, the index i is used to represent the filtering process under different waveform kernels.

[0163] Preferably, based on the updated neighbor feature, the neighbor node feature h is generated by aggregating the first link graph and the second link graph. adj :

[0164] h adj =AGG(h r,adj :r∈(0,R))).

[0165] Preferably, the method for acquiring time series node features is:

[0166] Build a time series based on each information node in the heterogeneous graph;

[0167] Extract node features of the central node at the lth layer based on the time series;

[0168] Perform the maximum pooling operation based on the node features to obtain the hierarchical features at the lth layer and t time steps;

[0169] Perform maximum pooling operation based on hierarchical features to obtain global features;

[0170] Based on the global features, the initial attention score of the central node is obtained and normalized to obtain the final attention weight;

[0171] Based on the final attention weight, hierarchical features and global features, the temporal node features are obtained.

[0172] Preferably, for each node, a time series is constructed for each node based on the heterogeneous graph, and these time series contain the features generated every day in a month. The time series modeling of these features through the time series convolutional network can effectively capture the time change characteristics of the node.

[0173] Preferably, in order to prevent time leakage, the TCN network uses a one-dimensional full convolutional network and causal convolution, and uses zero-length padding based on the input time series. And one-dimensional full convolution kernel Extract the node features of the central node at the lth layer:

[0174]

[0175] Among them, f (l-1) represents the convolution kernel of the l-1th layer, f (l-1) (i) represents the convolution kernel f (l-1) The i-th element of , d represents the dilation factor, k represents the size of the filter, * represents the convolution calculation, s represents the time step, and t represents the time point. The length of is equal to T, t∈(0,T).

[0176] Preferably, in order to further improve the model's learning of global and local temporal features, maximum pooling is used to aggregate features based on the temporal convolution module. The maximum pooling operation is used to select the most significant feature values ​​in the time dimension to avoid missing important information.

[0177] Preferably, the embedding representation of each time step s is calculated by point-by-point accumulation Get After that, the maximum pooling operation is performed. For each pair of input and Compare the two elements one by one and select the maximum value as output This operation halves the feature length of each layer, gradually compresses the sequence length, and forms a multi-scale feature representation:

[0178]

[0179] Among them, L is the maximum number of layers, Max_pool represents the maximum pooling operation, and They represent the local features obtained at two different time points, 2t+1 and 2t, after the l-th layer of temporal convolution. At this time, Length is Preserve the most significant local features of the node.

[0180] Preferably, for the last layer The total sequence length is T / 2 L Perform a global maximum pooling operation to extract Capture global information and obtain global features

[0181]

[0182] in, Representation level features The final level features are obtained after layer-by-layer maximum pooling.

[0183] Preferably, a self-attention module is added to extract long-term and short-term features from the time series data of the node. It can dynamically adjust the importance weight of the feature according to the time dimension. Especially in the process of node aggregation to form the final embedding, the self-attention mechanism can effectively collect the embedded features scattered in time and ensure the trade-off between local and global information.

[0184] Preferably, the initial attention score of the central node is obtained based on the global features and normalized to obtain the final attention weight:

[0185] Initial attention score

[0186]

[0187] Among them, W represents the weight matrix, b represents the bias vector, q represents the shared attention vector, in, Representation level features The final level features obtained after layer-by-layer maximum pooling processing, Indicates that for the last layer The total sequence length is T / 2 L The final global features are obtained after performing the global maximum pooling operation.

[0188] Preferably, the initial attention score is calculated by the softmax function Normalize and get the final attention weight of the central node v

[0189]

[0190] in,

[0191] Preferably, based on the final attention weight, hierarchical features and global features fusion, the temporal node feature h is obtained tcn :

[0192]

[0193] in, Representation level features The final level features obtained after layer-by-layer maximum pooling processing, Indicates that for the last layer The total sequence length is T / 2 L The final global features are obtained after performing the global maximum pooling operation.

[0194] Comprehensive node features are obtained by fusing neighbor node features, community node features and time series node features.

[0195] Preferably, the comprehensive node feature h' v Specifically:

[0196] h' v =h v +W 1 *h com +W 2 *AGG(h adj )+W 3 *h tcn ;

[0197] Among them, W 1 , W 2 and W 3 Both represent the set of learnable parameters, h v represents the original features of the central node v, h adj represents the neighbor node embedding of the central node v, h com represents the community node embedding of the central node v, h tcn Represents the temporal node embedding of the central node v.

[0198] Based on the comprehensive node features, the features are input to the classification layer to obtain the prediction results.

[0199] Preferably, the method further includes evaluating the model performance based on the test data, generating a prediction report through incremental learning, and selecting whether to retain the model as the latest model.

[0200] Preferably, after completing the preliminary machine learning model training, this example uses test data to conduct an in-depth evaluation of the model's recognition results. The purpose of this process is to ensure its accuracy and effectiveness by verifying the performance of the model in actual applications. The specific operation is to input the constructed heterogeneous graph into the trained graph neural network model to identify fraudulent numbers, and to regularly output the predicted blacklist by setting a threshold. This method can not only evaluate the performance of the model in identifying fraudulent behavior, but also continuously optimize the model through incremental learning to improve its adaptability in a dynamic environment.

[0201] Preferably, by generating a prediction report, this example can fully understand the actual effect of the model. Use the trained model to test, calculate its recall and precision, and decide whether to use it as the latest standard model. The advantage of doing so is to ensure that the model used can accurately respond to actual problems and continue to improve as data and needs change, thereby providing more reliable fraud detection services.

[0202] Example 3

[0203] like Figure 4 As shown, a collaborative fraud number detection system based on graph neural network includes: a data acquisition module, a data feature extraction module, a heterogeneous graph construction module, a node feature acquisition module and a prediction result output module;

[0204] A data acquisition module, used to obtain historical communication data of the target mobile phone number;

[0205] The data feature extraction module is used to obtain the original features and interactive features of each number based on the historical communication data; the community information and collaborative information of the target mobile phone number are obtained based on the historical communication data;

[0206] Heterogeneous graph construction module, used to integrate heterogeneous graphs based on original features, interactive features, community information and collaborative information;

[0207] The node feature acquisition module is used to obtain neighbor node features, community node features and time series node features based on heterogeneous graph input into the graph neural network model; the comprehensive node features are obtained by fusing the neighbor node features, community node features and time series node features;

[0208] The prediction result output module is used to obtain the prediction result based on the comprehensive node feature input to the classification layer.

[0209] Preferably, the functional implementation of each module in this embodiment corresponds to the above method steps one by one, and will not be repeated here.

[0210] Preferably, a user interface module is also included to display the prediction results in a table or graphical form, including fraudulent numbers, prediction probabilities and related information; the module provides a user feedback function, allowing users to mark false positives or false negatives to ensure the accuracy of the prediction. In addition, the system supports regular manual intervention to respond to emerging fraud patterns and prevent system performance degradation over time, thereby ensuring the long-term effective operation of the system.

[0211] Example 4

[0212] Based on the same inventive concept, the present invention also provides a computer device, including a processor, a communication interface, a memory and a communication bus, wherein the processor, the communication interface and the memory communicate with each other via the communication bus;

[0213] Memory, used to store computer programs;

[0214] The processor, when used to execute the program stored in the memory, can implement a collaborative fraud number detection method based on a graph neural network as in Example 1 or 2.

[0215] The electronic device may include: a processor, a communication interface, a memory, and a communication bus, wherein the processor, the communication interface, and the memory communicate with each other via the communication bus. The processor may call the logic instructions in the memory to execute a collaborative fraud number detection method based on a graph neural network in Embodiment 1 or 2.

[0216] In addition, the logic instructions in the above-mentioned memory can be implemented in the form of software functional units and can be stored in a computer-readable storage medium when sold or used as an independent product. Based on such an understanding, the technical solution of the present invention is essentially or the part that contributes to the prior art or the part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the methods of each embodiment of the present invention. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), disk or optical disk and other media that can store program codes.

[0217] In this specification, each embodiment is described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts between the embodiments can be referred to each other. For the device disclosed in the embodiment, since it corresponds to the method disclosed in the embodiment, the description is relatively simple, and the relevant parts can be referred to the method part.

[0218] The above description of the disclosed embodiments enables one skilled in the art to implement or use the present invention. Various modifications to these embodiments will be apparent to one skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention will not be limited to the embodiments shown herein, but rather to the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A collaborative fraud number detection method based on graph neural network, characterized in that: include: Obtain historical communication data of the target mobile phone number; Acquire original features and interactive features of each number based on the historical communication data; Filter and obtain the community information and collaborative information of the target mobile phone number based on the historical communication data; Obtaining a heterogeneous graph based on the integration of the original features, the interactive features, the community information and the collaborative information; Based on the heterogeneous graph input into the graph neural network model, the neighbor node features, community node features and time series node features are obtained; Obtaining a comprehensive node feature based on the fusion of the neighbor node feature, the community node feature and the time series node feature; Based on the comprehensive node features, the features are input to the classification layer to obtain prediction results.

2. According to the collaborative fraud number detection method based on graph neural network according to claim 1, it is characterized in that: The community information acquisition method is: Determine whether the communication behavior is on a working day or a holiday based on the historical communication data, and obtain a determination result; Obtaining the behavioral difference characteristics between the working day and the holiday based on the judgment result; Acquire the call behavior characteristics of the target mobile phone number at different times of the day based on the historical communication data; The community information is generated based on the behavior difference characteristics and the call behavior characteristics.

3. A collaborative fraud number detection method based on graph neural network according to claim 2, characterized in that: The collaborative information acquisition method is: Based on the historical communication data, obtain timestamps and location information of multiple user numbers that have communicated with the target mobile phone number; Obtaining a time interval based on the timestamp; Acquire a cross-region dialing mode based on the location information; Based on the time interval and the cross-regional dialing pattern recognition, a collaborative crime feature is obtained; The collaborative information between the user numbers is obtained based on the collaborative crime feature extraction.

4. A collaborative fraud number detection method based on graph neural network according to claim 3, characterized in that: The heterogeneous graph construction method is: Acquire all user numbers that communicate with the target mobile phone number based on the historical communication data; Based on the target mobile phone number and the user number as nodes; Obtaining a community label based on the community information; Based on the community label and the original feature as node attributes, they are bound to the corresponding node to obtain an information node; Generate a call link graph and a text message link graph based on the interactive relationship between all the information nodes; Based on the interaction feature, the collaboration information and the community information as edge features, they are respectively bound to the call link graph and the SMS link graph to obtain a first link graph and a second link graph accordingly; The heterogeneous graph is obtained by integrating the information nodes, the first link graph and the second link graph.

5. A collaborative fraud number detection method based on graph neural network according to claim 4, characterized in that: The community label is obtained based on the community information, specifically including: Based on the encoding of the community information in the time dimension: The working days and holidays are represented by 2-bit binary to obtain a first dimension code; Different time periods in a day are represented by 5 bits of binary to obtain the second dimension encoding; A multi-dimensional code is obtained based on the first dimensional code and the second dimensional code as the community label.

6. A collaborative fraud number detection method based on graph neural network according to claim 5, characterized in that: The graph neural network model includes a multi-frequency collaborative neural network, a self-attention temporal convolutional network and a multi-frequency processing module; The heterogeneous graph is sequentially input into the multi-frequency collaborative neural network and the multi-frequency processing module to obtain the neighbor node features and the community node features; The heterogeneous graph is input into the self-attention temporal convolutional network to obtain temporal node features.

7. A collaborative fraud number detection method based on graph neural network according to claim 6, characterized in that: The method for obtaining community node features is: Dividing all the information nodes into corresponding communities based on the time dimension information of the heterogeneous graph; Clustering is performed based on the nodes in the community, and the cluster center node is selected as the single community feature of the current community; The community node feature is obtained based on the aggregation of all the single community node features.

8. A collaborative fraud number detection method based on graph neural network according to claim 7, characterized in that: The neighbor node feature acquisition method is: Based on any information node in the heterogeneous graph as the current central node; Selecting all neighbor nodes that are cooperatively connected with the central node based on the cooperative information; Based on the similarity between the central node and the neighboring nodes, a plurality of neighboring nodes greater than a threshold are screened and obtained as screening nodes; Generate neighbor node weights based on the screening nodes; An initial neighbor feature of the central node is obtained based on the edge features of the central node and the neighbor nodes and the original features of the neighbor nodes; Based on the neighbor node weights and the initial neighbor features, obtaining updated neighbor features; The neighbor node feature is obtained by aggregating the first link graph and the second link graph based on the updated neighbor feature.

9. A collaborative fraud number detection method based on graph neural network according to claim 8, characterized in that: The method for acquiring the time series node features is as follows: Constructing a time series based on each information node in the heterogeneous graph; Extracting node features of the central node at the lth layer based on the time series; Perform a maximum pooling operation based on the node features to obtain the hierarchical features at the lth layer and t time steps; Perform a maximum pooling operation based on the hierarchical features to obtain global features; Based on the global feature, an initial attention score of the central node is obtained and normalized to obtain a final attention weight; The temporal node feature is obtained based on the fusion of the final attention weight, the hierarchical feature and the global feature.

10. A collaborative fraud number detection system based on graph neural network, applied to a collaborative fraud number detection method based on graph neural network as claimed in any one of claims 1 to 9, characterized in that: include: Data acquisition module, data feature extraction module, heterogeneous graph construction module, node feature acquisition module and prediction result output module; The data acquisition module is used to acquire the historical communication data of the target mobile phone number; The data feature extraction module is used to obtain the original features and interactive features of each number based on the historical communication data; Filter and obtain the community information and collaborative information of the target mobile phone number based on the historical communication data; The heterogeneous graph construction module is used to integrate the original features, the interactive features, the community information and the collaborative information to obtain a heterogeneous graph; The node feature acquisition module is used to obtain neighbor node features, community node features and time series node features based on the heterogeneous graph input into the graph neural network model; Obtaining a comprehensive node feature based on the fusion of the neighbor node feature, the community node feature and the time series node feature; The prediction result output module is used to obtain the prediction result based on the comprehensive node feature input to the classification layer.

Citation Information

Patent Citations

  • Fraud number identification method based on graph embedding

    CN110177179A

  • Fraud number identification method based on space-time diagram

    CN111726460A

  • Telecommunication fraud security federal detection method fusing homogeneous graph and bipartite graph

    CN114693317A

  • Telecommunication fraud detection method and device and storage medium

    CN114827352A

  • Method and system for identifying fraud user in call network by using human-in-loop graph neural network, and storage medium

    CN115034305A

Cited By

  • Fraud early warning method and device based on called communication

    CN120812170A

  • Trusted crowd analysis method and system, electronic equipment and storage medium

    CN121706021A