Digital asset anti-money laundering research and judgment method based on block chain

By extracting fund transaction data and performing feature analysis based on blockchain technology, identifying abnormal transaction patterns and high-risk users, the hidden problem of money laundering activities in digital asset transactions is solved, and efficient anti-money laundering monitoring is achieved.

CN120219084AInactive Publication Date: 2025-06-27JIANGSU BURO INFORMATION TECH CO LTD
View PDF 0 Cites 3 Cited by

Patent Information

Application Number
CN202510332943.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-20
Publication Date
2025-06-27
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The anonymity and decentralized nature of digital assets make it difficult to track the source of users and transactions, resulting in money laundering activities being hidden and undetected in time.

Method used

Based on blockchain technology, capital transaction data is obtained, abnormal transaction patterns are identified through feature extraction and local outlier factor technology, risk assessment and user clustering are carried out, abnormal monitoring models are deployed to track the capital transaction flow path of high-risk users and trigger early warnings.

Benefits of technology

Effectively identify and distinguish between normal transactions and abnormal transactions, improve the accuracy and efficiency of the anti-money laundering monitoring system, and promptly discover and prevent money laundering risks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120219084A_ABST
    Figure CN120219084A_ABST
Patent Text Reader

Abstract

The invention discloses a digital asset anti-money laundering research and judgment method based on a block chain, and relates to the technical field of data processing, and the method comprises the steps: obtaining fund transaction data based on a block chain technology, carrying out the feature extraction of the fund transaction data, and recognizing an abnormal transaction mode associated with money laundering; risk assessment is carried out on the initiating user and the receiving user in the abnormal transaction mode, and high-risk users are clustered to the same group according to a risk assessment result; and tracking a fund transaction flow path of the high-risk users in the same group, deploying an anomaly monitoring model on the fund transaction flow path, and when the anomaly monitoring model monitors a money laundering behavior, triggering early warning according to a preset rule. According to the anti-money laundering monitoring system, the efficiency and accuracy of the anti-money laundering monitoring system can be remarkably improved by performing risk assessment on the initiating user and the receiving user in the abnormal transaction mode and clustering the high-risk users to the same group.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data processing, and more specifically, to a method for anti-money laundering research and judgment of digital assets based on blockchain. Background Art

[0002] Digital assets refer to assets that exist in digital form and have value. They are usually stored, transferred, and managed through digital technologies and cryptographic algorithms. Anti-money laundering (AML) refers to a series of laws, policies, and measures taken by financial institutions and other relevant entities to prevent illegal fund transfers, concealment, or conversion through the financial system. Money laundering refers to the process of transforming illegally obtained funds into seemingly legal funds or assets through a series of complex financial operations to conceal their illegal origin.

[0003] Digital assets have a high degree of anonymity and decentralization characteristics, which makes it difficult to trace the origin of users and transactions. For example, when using virtual assets, the participants in a transaction only conduct transactions based on addresses, without involving real identities, and although the transaction records on the blockchain are public, they usually lack sufficient information to identify the traders. Due to the lack of identity information, it is impossible to effectively identify and verify high-risk users, especially when these users operate with hidden identities or through multiple anonymous accounts, it is very difficult to trace the ultimate destination of the funds or the hidden asset flow path, resulting in the concealment of money laundering activities and the inability to detect them in a timely manner.

[0004] Regarding the problems in the related art, no effective solutions have been proposed yet. Summary of the Invention

[0005] Regarding the problems in the related art, the present invention proposes a method for anti-money laundering research and judgment of digital assets based on blockchain to overcome the above-mentioned technical problems existing in the existing related technologies.

[0006] To this end, the specific technical solution adopted by the present invention is as follows: A method for anti-money laundering research and judgment of digital assets based on blockchain, the method comprising: Obtaining fund transaction data based on blockchain technology, extracting features from the fund transaction data, and identifying abnormal transaction patterns associated with money laundering; Conducting risk assessments on the initiating users and receiving users in the abnormal transaction patterns respectively, and clustering high-risk users into the same group according to the risk assessment results; Tracking the fund transaction flow path of high-risk users in the same group, and deploying an abnormal monitoring model on the fund transaction flow path. When the abnormal monitoring model detects money laundering behavior, an alarm is triggered according to the preset rules; Among them, obtaining fund transaction data based on blockchain technology and extracting features from the fund transaction data includes: Collect fund transaction data using blockchain technology and preprocess the fund transaction data; Extract the key features of the preprocessed fund transaction data and calculate the outliers of the key features using the Local Outlier Factor technique; Compare the outlier calculation result with a preset threshold. If the outlier calculation result is greater than or equal to the preset threshold, it indicates that the key feature is a normal transaction feature; otherwise, it is an abnormal transaction feature; Tracking the fund transaction flow path of high-risk users in the same group includes: Obtain the fund transaction flow path initiated by high-risk users, traverse the fund transaction flow path using the breadth-first search algorithm, and track the flow of funds from the source to the end.

[0007] Preferably, identifying abnormal transaction patterns associated with money laundering includes: Construct a time series analysis model based on abnormal transaction features and use the time series analysis model to identify abnormal transaction patterns in the fund transaction data.

[0008] Preferably, extracting the key features of the preprocessed fund transaction data and calculating the outliers of the key features using the Local Outlier Factor technique includes: Extract the key features of the preprocessed fund transaction data. The key features include transaction amount, transaction frequency, and transaction time interval; Perform sliding window difference processing on the key features, filter out the duplicate key features in the difference processing, and obtain the deduplicated difference sequence; Calculate the Local Outlier Factor of the deduplicated difference sequence based on the repetition degree of the duplicate key features in all features, and set a threshold according to the Local Outlier Factor; Select all key features in the deduplicated difference sequence that are greater than the threshold, and mark the mutation points in the difference sequence based on the selected key features to obtain a marked vector; Analyze the change trend between adjacent mutation points in the marked vector, identify the misdetected points in the mutation points, and use the mutation points after filtering the misdetected points as the outliers of the key features.

[0009] Preferably, performing sliding window difference processing on the key features, filtering out the duplicate key features in the difference processing, and obtaining the deduplicated difference sequence includes: Establish a sliding window for selecting subsets of consecutive fund transaction data and determine the time range of the key features through the sliding window; Calculate the change amount of each key feature within the sliding window, and obtain the difference of each key feature according to the difference between adjacent key features; Combine the exponential perturbation method to perform perturbation processing on each difference in the difference sequence to ensure that the intensity of the perturbation meets the difference requirements; After differential perturbation, duplicate key eigenvalues in the differential sequence are removed to obtain a differential sequence after perturbation processing and duplicate removal.

[0010] Preferably, risk assessments are respectively performed on the initiating user and the receiving user in the abnormal transaction pattern, and high-risk users are clustered into the same group according to the risk assessment results, including: Taking the initiating user and the receiving user in the abnormal transaction pattern as nodes, and the transaction between the initiating user and the receiving user as an edge, defining the weight of the edge according to the transaction amount and transaction frequency, and generating a graph transaction network; Converting the graph transaction network into an adjacency matrix, and decomposing the adjacency matrix into a user feature matrix and a transaction feature matrix; Calculating the risk degrees of the initiating user and the receiving user in the abnormal transaction pattern, and identifying high-risk users in the user feature matrix and the transaction feature matrix based on the calculation results of the risk degrees; Using a graph clustering algorithm to cluster high-risk users into the same group.

[0011] Preferably, converting the graph transaction network into an adjacency matrix, and decomposing the adjacency matrix into a user feature matrix and a transaction feature matrix includes: Generating an adjacency matrix based on the nodes and edges in the graph transaction network, constructing an adjacency vector according to the adjacency matrix, and forming a library matrix from the adjacency vectors; Decomposing the library matrix into two non-negative matrices, and initializing the random values of the elements in the non-negative matrices; Based on the update method of gradient descent, continuously adjusting the minimization loss function of the non-negative matrices, and aiming at the decomposition error of the minimization loss function during the gradient descent process; Obtaining a regularization formula according to the minimization loss function and the Frobenius norm, and iteratively calculating and updating the values of the non-negative matrices; When the maximum number of iterations of the non-negative matrices meets the preset requirements, taking the updated two non-negative matrices as the user feature matrix and the transaction feature matrix.

[0012] Preferably, deploying an abnormal monitoring model on the fund transaction flow path, and triggering an alarm according to preset rules when the abnormal monitoring model detects money laundering behavior, including: Constructing an abnormal monitoring model according to the flow situation of funds, deploying the abnormal monitoring model on each fund transaction flow path, and monitoring the abnormality of the fund transaction flow path in real time; When the abnormal monitoring model detects money laundering behavior, triggering an alarm according to the preset rules to send an instruction to notify the anti-money laundering team to intervene.

[0013] Preferably, using the breadth-first search algorithm to traverse the fund transaction flow path and track the flow situation of funds from the source to the end, including: Perform a breadth-first search on the starting point of the fund transaction flow path, calculate the longest distances from the starting point value to the rest of the transaction nodes, and store the longest distances in the first array; Perform a breadth-first search on the fund transaction flow path from the ending point, find the longest distances from the ending point to the rest of the transaction nodes, and store the longest distances in the second array; Perform correlation analysis on the first array and the second array respectively to obtain the fund flow situation of the key fund transaction flow path.

[0014] Preferably, the expression of the regularization formula is: ; In the formula, represents minimizing the loss function; A represents the original matrix; W , H represent non-negative matrices decomposed from the library matrix; F represents the Frobenius norm; represents the regularization term.

[0015] Preferably, the calculation formula of the local outlier factor is: ; In the formula, represents the local outlier factor value of the j th key feature within the k -neighborhood; represents the neighborhood set containing the j th neighbor of the k th key feature; T j represents the weight value of the j th key feature; represents the j th key feature's local density within the k -neighborhood; Y j represents the set of neighbor key features.

[0016] The beneficial effects of the present invention are as follows: 1. The present invention obtains fund transaction data based on blockchain technology and performs feature extraction, which can effectively identify abnormal transaction patterns related to money laundering. By extracting key features and using the local outlier factor technology to calculate outliers, it helps to discover potential abnormal transaction behaviors. Comparing the outlier calculation results with a preset threshold can accurately distinguish normal transactions and abnormal transactions, and can further explore the time patterns in transaction patterns, providing effective support for the identification of money laundering behaviors, thereby improving the accuracy and efficiency of the anti-money laundering monitoring system.

[0017] 2. By conducting risk assessments on the initiating users and receiving users in abnormal transaction patterns and clustering high-risk users into the same group, the present invention can significantly improve the efficiency and accuracy of the anti-money laundering monitoring system. Based on the calculated risk levels, risk assessments are performed on the initiating users and receiving users, and high-risk users are identified, which helps to lock in potential money laundering behaviors in advance. At the same time, the graph clustering algorithm is used to group high-risk users in the same group, thereby achieving centralized monitoring of high-risk groups, further improving the monitoring accuracy, promptly detecting abnormal behaviors and taking corresponding measures, and effectively preventing money laundering risks.

[0018] 3. By tracking the fund transaction flow paths of high-risk users in the same group, the present invention can effectively monitor potential money laundering behaviors. Using the breadth-first search algorithm to traverse the fund transaction flow paths and comprehensively track from the source to the end of the funds, it can clearly depict the flow of funds among users. It can not only promptly detect abnormal patterns in the fund flow but also capture potential risk behaviors based on the fund flow trajectory, thereby accurately locating the fund flow paths of high-risk users and improving the accuracy and response speed of the anti-money laundering monitoring system. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.

[0020] Figure 1 is a flowchart of a method for anti-money laundering analysis and judgment of digital assets based on blockchain according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0021] To further illustrate the embodiments, the present invention provides drawings. These drawings are part of the disclosure of the present invention, mainly used to illustrate the embodiments, and can be used in conjunction with the relevant descriptions in the specification to explain the operating principles of the embodiments. With reference to these contents, those of ordinary skill in the art should be able to understand other possible implementation manners and the advantages of the present invention.

[0022] According to an embodiment of the present invention, a method for anti-money laundering analysis and judgment of digital assets based on blockchain is provided.

[0023] Now, the present invention will be further described in combination with the drawings and specific implementation manners. As Figure 1 shown, the method for anti-money laundering analysis and judgment of digital assets based on blockchain according to an embodiment of the present invention includes: S1. Obtain fund transaction data based on blockchain technology, extract features from the fund transaction data, and identify abnormal transaction patterns associated with money laundering.

[0024] Among them, obtaining fund transaction data based on blockchain technology, extracting features from the fund transaction data, and identifying abnormal transaction patterns associated with money laundering include: Collect fund transaction data using blockchain technology and preprocess the fund transaction data.

[0025] It should be noted that collecting fund transaction data using blockchain technology and preprocessing the fund transaction data include: Step 1. Data collection: One of the core advantages of blockchain technology is its data transparency and immutability. Through the public ledger interface of the blockchain (such as the API interfaces of Bitcoin, Ethereum, etc.), all transaction records on the chain can be obtained. The steps of data collection are as follows: Select a blockchain network: First, it is necessary to determine the blockchain network to be used, such as Bitcoin, Ethereum, or other blockchain networks that support smart contracts. The choice of this step determines the subsequent method of obtaining data.

[0026] Obtain transaction data: Blockchain explorer: Use a blockchain explorer (such as Etherscan, Blockchain.info) to obtain transaction data. These tools provide API interfaces that can regularly obtain transaction information related to a specific address or obtain transaction data for all blocks.

[0027] Blockchain node: Deploy a blockchain node to directly interact with the blockchain network and obtain the latest transaction data on the blockchain. Through the RPC (Remote Procedure Call) interface, such as web3.js of Ethereum, it is possible to directly interact with the data on the chain.

[0028] Data collection: Transaction data includes but is not limited to the following: Transaction ID (Transaction Hash); Transaction timestamp (Timestamp); Sender address (Sender Address); Receiver address (Receiver Address); Transaction amount (Transaction Amount); Transaction fee (Transaction Fee); Transaction status (such as confirmation status); Step 2. Data cleaning: The purpose of data cleaning is to process the collected original transaction data to make it cleaner, more structured, and further usable for feature extraction and analysis. The specific steps include: Removing redundant data: Filter some duplicate transaction records, invalid transactions, or test data. In particular, some historical test transactions or redundant data generated by the system should be deleted.

[0029] Standardizing the time format: The timestamps of blockchain data are usually Unix timestamps (i.e., the number of seconds since January 1, 1970), so it is necessary to convert them into a readable time format (such as YYYY-MM-DD HH:MM:SS) for subsequent analysis.

[0030] Standardization: There may be case issues or multiple representations for the sending address and receiving address in the blockchain (for example, Ethereum addresses have a "0x" prefix), so it is necessary to unify the address format to ensure its consistency.

[0031] Outlier detection: For the collected transaction amounts, it is necessary to check whether there are outliers (such as negative amounts, extremely large amounts, etc.), and mark or remove them.

[0032] Step 3. Filling in missing values: In actual operations, there may be some missing values in the collected transaction data. The methods for filling in missing values can be selected according to specific scenarios, including: Mean / median filling: For numerical features (such as transaction amounts, transaction fees, etc.), the mean or median can be used to fill in the missing data.

[0033] Filling with previous / next values: For time series data, the previous valid data or the next valid data is used to fill in the missing values. Especially in transaction data, if the timestamps of some transactions are missing, the timestamps of neighboring transactions can be used for filling.

[0034] Interpolation method: Use linear interpolation or other interpolation methods to fill in the missing numerical values, especially when there are missing values in transaction frequency data and time interval data Extract the key features of the preprocessed fund transaction data, and use the Local Outlier Factor technique to calculate the outliers of the key features.

[0035] Among them, extracting the key features of the preprocessed fund transaction data and using the Local Outlier Factor technique to calculate the outliers of the key features includes: Extract the key features of the preprocessed fund transaction data. The key features include transaction amount, transaction frequency, and transaction time interval; Perform sliding window difference processing on the key features, filter the duplicate key features in the difference processing, and obtain the de-duplicated difference sequence.

[0036] Among them, perform sliding window difference processing on the key features, filter the repeated key features in the difference processing, and the de-duplicated difference sequence obtained includes: Establish a sliding window for selecting a subset of consecutive fund transaction data, and determine the time range of the key features through the sliding window; Calculate the change amount of each key feature within the sliding window, and obtain the difference of each key feature according to the difference between adjacent key features; Combine the exponential perturbation method to perform perturbation processing on each difference in the difference sequence to ensure that the intensity of the perturbation meets the difference requirements; After the difference perturbation, remove the repeated key feature values in the difference sequence to obtain the difference sequence after perturbation processing and de-duplication.

[0037] Based on the repetition degree of the repeated key features in all the features, calculate the local outlier factor of the de-duplicated difference sequence, and set a threshold according to the local outlier factor.

[0038] Among them, the calculation formula of the local outlier factor is: ; In the formula, represents the local outlier factor value of the j th key feature in the k -neighborhood; represents the neighborhood set containing the j th key feature and its k neighbors; T j represents the weight value of the j th key feature; represents the j th key feature's local density in the k -neighborhood; Y j represents the set of neighbor key features.

[0039] Screen all key features in the de-duplicated difference sequence that are greater than the threshold, and mark the mutation points in the difference sequence based on the screened key features to obtain a marking vector; Analyze the change trend between adjacent mutation points in the marking vector, identify the mis-detected points in the mutation points, and use the mutation points after filtering the mis-detected points as the outlier points of the key features.

[0040] Compare the outlier point calculation result with the preset threshold. If the outlier point calculation result is greater than or equal to the preset threshold, it means that the key feature is a normal transaction feature; otherwise, it is an abnormal transaction feature; Construct a time series analysis model based on abnormal transaction characteristics, and use the time series analysis model to identify abnormal transaction patterns in fund transaction data.

[0041] To facilitate the understanding of the above technical solutions of the present invention, the following will detail the acquisition of fund transaction data based on blockchain technology in the actual process of the present invention, the extraction of features from the fund transaction data, and the identification of abnormal transaction patterns associated with money laundering: Step 1. Blockchain data collection and preprocessing: Data collection: Use the public ledger interface of the blockchain and combine with the APIs of major trading platforms to obtain fund transaction data, which mainly includes basic information such as transaction amount, transaction time, initiating user, receiving user, etc.

[0042] Step 2. Extract key features: In the preprocessed fund transaction data, extract key features for further analysis. These features include: Transaction amount: Reflects the scale of fund flow.

[0043] Transaction frequency: Reflects the number of transactions per unit time and can be used to identify whether the transactions are abnormally frequent.

[0044] Transaction time interval: Reflects the time distance between transactions and can reveal whether the transactions occur within a short period of time or whether there are abnormal transaction intervals.

[0045] Example of feature extraction: Assume that transaction data for a period of time is collected, including transaction information between multiple users. For each transaction, extract its amount, occurrence time, and the time difference from the previous transaction.

[0046] Step 3. Sliding window differential processing: To reduce the time dependence in transaction data and improve the flexibility of feature analysis, a sliding window method is used for differential processing.

[0047] Establish a sliding window: According to the timestamps of the fund transaction data, set a sliding window of a fixed size (for example, a time span of one day or one week). The sliding window will continuously slide in chronological order, move a certain period of time each time, and perform differential calculations on the transaction data within each window.

[0048] Differential calculation: Within each sliding window, calculate the change amounts of the transaction amount, transaction frequency, and transaction time interval. Specifically, for each pair of adjacent transactions within each window, calculate the amount difference, frequency difference, and time interval difference to obtain the differential values of each key feature.

[0049] Assume that the time span of the sliding window is one day, and there are 5 transactions within the window with amounts of 100, 120, 110, 130, and 140 respectively. Calculate the amount difference values as follows: 120 - 100 = 20; 110 - 120 = -10; 130 - 110 = 20; 140 - 130 = 10; For the transaction frequency and time interval, similar difference calculations are also performed.

[0050] Step Four: Exponential perturbation processing: To reduce the noise in the difference values and improve the stability of the features, an exponential perturbation method is used to process the difference sequence.

[0051] Exponential perturbation: Apply the exponential function to each difference value for perturbation, and the perturbation intensity can be adjusted according to actual needs.

[0052] Assume the difference value is 20, the perturbation intensity λ = 0.1, and the random value is 0.5. Then the perturbed value is: disturbedvalue = 20 × e0.1×0.5 ≈ 20 × 1.05127 ≈ 21.0254; Step Five: Duplicate removal processing: Perform duplicate removal on the difference sequence after perturbation processing to remove duplicate key feature values.

[0053] Duplicate removal method: Use data structures such as hash tables or sets to store each difference value and automatically remove duplicate values.

[0054] Assume the difference value sequence after perturbation processing is [21.0254, -10.5, 20.0, 10.5, 21.0254]. The sequence after duplicate removal will become [21.0254, -10.5, 20.0, 10.5].

[0055] Step Six: Local Outlier Factor (LOF) calculation: Based on the difference sequence after duplicate removal, calculate the Local Outlier Factor (LOF) of each key feature and set a threshold.

[0056] LOF calculation: For each data point p, calculate the reachable distance between each neighbor in its k-nearest neighbor set and p, and further evaluate the local density of p. By comparing the local density of p with the local density of its k-nearest neighbors, the LOF value of p is calculated using the above formula for the local outlier factor.

[0057] Threshold setting: According to the actual application requirements, set an LOF threshold, usually 1. Points with an LOF value greater than 1 are considered outliers.

[0058] LOF Calculation Example: Suppose there is a deduplicated difference sequence [21.0254, -10.5, 20.0, 10.5]. Calculate the LOF value for each point. If the LOF value is greater than 1, it indicates that the point is an outlier.

[0059] Step 7: Mutation Point Marking and False Detection Point Filtering: Mark the mutation points in the deduplicated difference sequence and analyze the change trend between adjacent mutation points in the marking vector to identify false detection points.

[0060] Mutation Point Marking: Select the key features with LOF values greater than the threshold and mark them as mutation points.

[0061] It should be noted that suppose there is a set of key features after difference processing, denoted as X = {X1, X2,..., X n}, and their corresponding Local Outlier Factor (LOF) values are LOF(1), LOF(2),..., LOF(n).

[0062] Set a threshold θ , and when the local outlier factor value is greater than this threshold, mark it as a mutation point.

[0063] Mutation Point Marking Formula: ; In the formula, M represents the mutation point marking value; LOF represents the local outlier factor; j represents the feature index, θ represents the preset threshold. When the j value of the data point LOF is greater than the threshold, it indicates that the data point is a mutation point; otherwise, mark it as 0, indicating that the data point is normal.

[0064] For example, if the set LOF threshold θ = 3.0, then mark according to the mutation point marking formula: For data point 1: LOF(1) = 2.5 < 3.0, mark as 0 (non-mutation point); For data point 2: LOF(2) = 3.0 = 3.0, mark as 0 (non-mutation point); For data point 3: LOF(3) = 1.8 < 3.0, mark as 0 (non-mutation point); For data point 4: LOF(4) = 4.5 > 3.0, mark as 1 (mutation point); For data point 5: LOF(5) = 1.2 < 3.0, mark as 0 (non-mutation point); False detection point identification: Analyze the change trend between adjacent mutation points in the marked vector. If the change trend between mutation points does not conform to the actual logic (for example, mutation points frequently appear in a short period), these points are considered false detection points and are filtered out.

[0065] Example of mutation point marking and false detection point identification: Assume the marked vector is [1, 0, 1, 1], indicating that the 1st, 3rd, and 4th points are mutation points. Analyze the change trend between adjacent mutation points and find that the change between the 3rd and 4th points does not conform to the actual logic. Therefore, the 4th point is identified as a false detection point, and the finally retained mutation points are [1, 0, 1, 0].

[0066] Step Eight: Abnormal transaction feature and time series analysis: Use the mutation points after filtering false detection points as outliers of key features, and further construct a time series analysis model to identify abnormal transaction patterns in the fund transaction data.

[0067] Time series analysis model: Use time series analysis models such as ARIMA and LSTM to model the transaction data and identify the abnormal patterns therein.

[0068] Abnormal pattern identification: Predict the future transaction trend through the model. If there is a significant deviation between the actual transaction data and the predicted value, it indicates that there may be an abnormal transaction.

[0069] Model the transaction data and predict the transaction amount for the next week. If the actual transaction amount differs greatly from the predicted value, for example, the actual amount is 150 while the predicted value is 100, it indicates that this transaction may be abnormal.

[0070] S2. Conduct risk assessments on the initiating users and receiving users in the abnormal transaction patterns respectively, and cluster high-risk users into the same group according to the risk assessment results.

[0071] Among them, conducting risk assessments on the initiating users and receiving users in the abnormal transaction patterns respectively, and clustering high-risk users into the same group according to the risk assessment results includes: Take the initiating users and receiving users in the abnormal transaction patterns as nodes, and the transactions between the initiating users and receiving users as edges. Define the weights of the edges according to the transaction amount and transaction frequency to generate a graph transaction network; Convert the graph transaction network into an adjacency matrix, and decompose the adjacency matrix into a user feature matrix and a transaction feature matrix.

[0072] Among them, converting the graph transaction network into an adjacency matrix, and decomposing the adjacency matrix into a user feature matrix and a transaction feature matrix includes: Generate an adjacency matrix based on the nodes and edges in the graph transaction network, construct an adjacency vector according to the adjacency matrix, and form a library matrix from the adjacency vectors; Decompose the library matrix into two sets of non - negative matrices, and initialize the random values of the elements in the non - negative matrices; Based on the update method of gradient descent, continuously adjust the loss function to be minimized for the non - negative matrices, and in the process of gradient descent, according to the goal of decomposing the error of the loss function to be minimized; Obtain the regularization formula according to the loss function to be minimized and the Frobenius norm, and iterate and calculate to update the values of the non - negative matrices.

[0073] Among them, the expression of the regularization formula is: ; In the formula, represents the loss function to be minimized; A represents the original matrix; W 、 H represent the non - negative matrices decomposed from the library matrix; F represents the Frobenius norm; represents the regularization term.

[0074] When the maximum number of iterations of the non - negative matrices meets the preset requirements, use the updated two sets of non - negative matrices as the user feature matrix and the transaction feature matrix.

[0075] Calculate the risk levels of the initiating users and receiving users in the abnormal transaction patterns, and identify the high - risk users in the user feature matrix and the transaction feature matrix based on the calculation results of the risk levels; Use the graph clustering algorithm to cluster the high - risk users into the same group.

[0076] To facilitate the understanding of the above - mentioned technical solution of the present invention, the following will detail the risk assessment of the initiating users and receiving users in the abnormal transaction patterns respectively in the actual process of the present invention, and clustering the high - risk users into the same group according to the risk assessment results: Step 1: Construct a graph transaction network: Construct a graph transaction network based on the initiating users and receiving users in the abnormal transaction patterns. Each node in the graph represents a user, and the transaction between the initiating user and the receiving user is used as an edge, and the weight of the edge is defined according to the transaction amount and transaction frequency.

[0077] For example, the transaction records of multiple users, each transaction includes information such as the initiating user, the receiving user, and the transaction amount. Regard each user as a node and each transaction as an edge. The values of the transaction amount and transaction frequency will be used as the weights of the edges. For example, if two transactions occur frequently, the weight of the edge is larger, indicating that the capital flow between them is more active; if the transaction amount is larger, the weight of the edge is also larger.

[0078] Suppose there are the following transactions among users A, B, C, and D: A→B, with an amount of 100 and a transaction frequency of 5 times; B→C, with an amount of 150 and a transaction frequency of 3 times; C→D, with an amount of 200 and a transaction frequency of 2 times; A→C, with an amount of 50 and a transaction frequency of 1 time; Based on these transaction records, construct a graph with A, B, C, and D as nodes, and the transaction amount and frequency define the edge weights between them.

[0079] Step 2: Generation and Decomposition of the Adjacency Matrix: After the graph transaction network is constructed, it is next necessary to convert it into an adjacency matrix. The adjacency matrix is used to describe the relationships between nodes, and the edge weights between each pair of nodes are represented in the matrix.

[0080] Generate an adjacency matrix based on the nodes and edges in the graph, where each element of the matrix represents the weight between nodes; further construct adjacency vectors based on the adjacency matrix, and these vectors form the library matrix.

[0081] Generation of the library matrix: Based on the adjacency matrix, construct a library matrix composed of adjacency vectors. Each row represents a node, and the elements of the vector represent the relationship between this node and other nodes.

[0082] Step 3: Non - negative Matrix Factorization (NMF): The purpose of non - negative matrix factorization is to decompose the adjacency matrix into two non - negative matrices, representing the user feature matrix and the transaction feature matrix respectively. This can reveal the potential patterns between users and transactions.

[0083] The core of non - negative matrix factorization is to continuously adjust the non - negative matrices through optimization methods such as gradient descent until the loss function is minimized, including: Initialize two non - negative matrices W (user feature matrix) and H (transaction feature matrix), and their elements are randomly initialized.

[0084] Use the gradient descent method to optimize W and H, and gradually obtain the optimal solution through the process of minimizing the loss function.

[0085] Prevent overfitting through regularization techniques (such as the Frobenius norm) to ensure that the matrix factorization can find appropriate patterns.

[0086] The initial adjacency matrix: A is a 4x4 matrix. Through matrix factorization methods, two matrices W and H are generated, where: W represents the characteristics of each user, describing the user's behavioral characteristics. H represents the characteristics of transactions, describing the specific situation of each transaction. By iteratively optimizing these matrices, A≈W×H, and finally the characteristics of each user and transaction are obtained.

[0087] Step Four: Risk Degree Calculation: The calculation of the risk degree is a key step in risk assessment of users. By analyzing the user's behavioral characteristics (such as transaction frequency, transaction amount, etc.), the risk degree of each user is calculated.

[0088] Based on the user characteristic matrix and transaction characteristic matrix that have been decomposed, the risk degree of each user is calculated.

[0089] Perform a weighted sum of the transaction frequency and amount of each user. Based on historical transaction behaviors, transaction counterparts, transaction frequency, etc., comprehensively evaluate the risk level of each user.

[0090] For example, if a user has transacted with multiple users, with a large transaction amount and high transaction frequency, the calculated risk degree may be high.

[0091] The transaction frequency and amount between user B and C are low, and the risk degree is low.

[0092] Step Five: Identify High-Risk Users: Based on the calculation results of the risk degree, identify high-risk users. Generally, users with a high risk degree are considered to have a higher potential risk and may be involved in money laundering activities.

[0093] Sort all users in descending order of risk degree, set a threshold, and users exceeding this threshold are regarded as high-risk users. Other behavioral characteristics or rules can be combined for screening.

[0094] For example, the risk degree of user A is 0.85, the risk degree of user B is 0.65, and the risk degree of user C is 0.45. If the threshold is set at 0.7, then user A is marked as a high-risk user, and B and C are low-risk users.

[0095] Step Six: Graph Clustering Algorithm: After identifying high-risk users, use the graph clustering algorithm to cluster these users into the same group. This step is for facilitating subsequent monitoring and analysis to identify interrelated high-risk users.

[0096] Use graph clustering algorithms (such as spectral clustering, K-means, etc.) to cluster high-risk users. Based on characteristics such as transaction frequency, amount, and time interval between users, group high-risk users together to help the anti-money laundering system focus on specific high-risk groups for more in-depth analysis.

[0097] For example, using the spectral clustering algorithm, according to the transaction frequency and amount between users A, B, and C, users A and B are clustered into one category, and user C is classified separately. In this way, the anti-money laundering system can give priority to monitoring the behaviors of the two high-risk users, A and B.

[0098] S3. Trace the fund transaction flow paths of high-risk users in the same group, and deploy an anomaly monitoring model on the fund transaction flow paths. When the anomaly monitoring model detects money laundering behavior, trigger an alarm according to the preset rules; Among them, tracing the fund transaction flow paths of high-risk users in the same group, deploying an anomaly monitoring model on the fund transaction flow paths, and when the anomaly monitoring model detects money laundering behavior, triggering an alarm according to the preset rules includes: Obtain the fund transaction flow paths initiated by high-risk users, use the breadth-first search algorithm to traverse the fund transaction flow paths, and trace the flow of funds from the source to the end.

[0099] Among them, using the breadth-first search algorithm to traverse the fund transaction flow paths and tracing the flow of funds from the source to the end includes: Conduct a breadth-first search on the starting point of the fund transaction flow path, calculate the longest distance from the starting point value to the rest of the transaction nodes, and store the longest distance in the first array; Conduct a breadth-first search on the fund transaction flow path from the ending point, find out the longest distance from the ending point to the rest of the transaction nodes, and store the longest distance in the second array; Conduct a correlation analysis on the first array and the second array respectively to obtain the fund flow conditions of the key fund transaction flow paths.

[0100] Construct an anomaly monitoring model based on the fund flow conditions, and deploy the anomaly monitoring model on each fund transaction flow path to monitor the anomalies of the fund transaction flow paths in real time; When the anomaly monitoring model detects money laundering behavior, trigger an alarm according to the preset rules to send an instruction to notify the anti-money laundering team to intervene.

[0101] To facilitate the understanding of the above technical solutions of the present invention, the following will elaborate on tracing the fund transaction flow paths of high-risk users in the same group in the actual process of the present invention, deploying an anomaly monitoring model on the fund transaction flow paths, and triggering an alarm according to the preset rules when the anomaly monitoring model detects money laundering behavior: Step 1. Obtain the fund transaction flow paths initiated by high-risk users: First, it is necessary to identify and obtain all the transaction records initiated by high-risk users within a certain time range and trace the path of their fund flow. These paths are the processes by which funds flow from the initiating users to the receiving users. Each transaction connects the nodes before and after, forming a path.

[0102] Through the identified list of high-risk users, obtain all the transaction data initiated by these users within a certain time period. Transaction data usually includes the initiating user, the receiving user, the transaction amount, the transaction time, etc.

[0103] Record each transaction and trace the path of fund flow from the initiating user to the receiving user. These transaction paths can be regarded as the edges in a graph, where each user is a node, each transaction is an edge, and the transaction amount and frequency, etc. can be used as the weights of the edges.

[0104] Sort the transactions in combination with the timestamp to ensure that the fund flow paths are arranged in chronological order.

[0105] Suppose there is a high-risk user A who initiated 5 transactions, flowing to users B, C, D, E, and F respectively. Trace the transaction flow paths from A to these users to obtain a fund flow graph.

[0106] Step 2: Use the breadth-first search algorithm to traverse the fund transaction flow paths: The breadth-first search (BFS) algorithm is a classic algorithm in graph theory for traversing the nodes in a graph. Use the BFS algorithm to traverse the fund transaction flow paths, trace the flow of funds from the source to the end, and ensure that the flow paths of each transaction can be completely recorded.

[0107] Conduct breadth-first search from the starting point: Select the source node in the fund flow path, use the BFS algorithm to traverse the source node, calculate the longest distances from the source node to the remaining transaction nodes, and store these distances in the first array, so as to help understand the flow range of funds starting from the source.

[0108] Conduct breadth-first search from the ending point: Similarly, start the BFS search from the end node of the fund flow path, calculate the longest distances from the end point to other transaction nodes, and store these values in the second array. This can trace the flow paths of funds from the end back to other nodes.

[0109] Conduct correlation analysis: Conduct correlation analysis on the data in these two arrays to find out the key nodes and their connection relationships in the fund flow paths. The transaction flows of these key nodes can help identify abnormal patterns and potential money laundering behaviors.

[0110] Assume the fund flow path is from A→B→C→D→E→F. First, perform a BFS search on A and record the maximum distances from A to other nodes. Then, perform a BFS search on F and record the maximum distances from F to other nodes. Through the correlation analysis of these two arrays, it is possible to determine which trading nodes are crucial for the fund flow path.

[0111] Step 3: Construct an anomaly monitoring model based on the fund flow situation: After tracing the fund flow path and conducting correlation analysis, the next step is to construct an anomaly monitoring model. The monitoring model is used to real-time monitor the anomaly of the fund flow path, especially for detecting possible money laundering behaviors.

[0112] Construct trading features: Extract key features from each fund flow path, such as transaction amount, transaction frequency, transaction time interval, transfer levels of transactions, etc. These features will help determine whether there are anomalies in the fund flow.

[0113] Model selection: Traditional machine learning models (such as decision trees, random forests, etc.) or deep learning-based models (such as LSTM, neural networks, etc.) can be selected. These models can learn the patterns of normal trading behaviors based on historical data and detect abnormal transactions that do not conform to the normal patterns during real-time monitoring.

[0114] Anomaly detection: According to the preset rules and model outputs, real-time detect whether there are abnormal behaviors. Usually, these rules include: Abnormal transaction amounts that exceed the historical trading patterns.

[0115] High-frequency transactions within a short period, which may be involved in money laundering behaviors.

[0116] The funds are dispersed or aggregated through multiple user accounts, forming a complex trading network.

[0117] Training and optimization: The model needs to be trained with historical data, mark normal and abnormal trading behaviors, and continuously optimize the model performance.

[0118] For a fund flow path A→B→C→D→E→F, construct a monitoring model based on the above trading features. The model finds that the transaction amount from C to D is abnormal and there are frequent small-value transaction transfers, which conform to the characteristics of money laundering behaviors. The monitoring model marks it as an abnormal path.

[0119] Step 4: Early warning trigger mechanism: When the anomaly monitoring model detects money laundering behaviors in the fund flow path, trigger an early warning according to the preset rules. The early warning mechanism needs to be able to promptly notify the anti-money laundering team for intervention and handling.

[0120] Set warning rules: Set warning thresholds according to the characteristics of money laundering behavior (such as abnormal transaction amounts, excessive frequencies, capital rotation, etc.). For example, if a user conducts more than 5 transactions with an amount greater than 10,000 within a short period of time, a warning will be triggered.

[0121] Warning notification: Once the model detects an abnormal capital flow path, it will automatically trigger a warning according to the preset rules and send a notification to the anti-money laundering team. The content of the notification includes the detailed information of the abnormal path, the users and amounts that may be involved, etc.

[0122] Automated processing: In some cases, the anti-money laundering system can be integrated with other security systems (such as transaction suspension, account freezing, etc.) for automated intervention.

[0123] The monitoring model found that user A conducted multiple small transactions through multiple accounts such as B, C, and D within a short period of time, triggering the preset money laundering detection rules. The system immediately sent a warning to the anti-money laundering team, stating the capital flow path, transaction amounts, and the accounts that may be involved. The team can conduct subsequent investigations based on this information.

[0124] Step Five: Data and Results: For example, a dataset containing 5,000 transactions from 200 users. Through the above steps, the monitoring system found 10 capital flow paths suspected of money laundering behavior. After further analysis, 7 of these paths were confirmed to be actual money laundering activities. The results show that by tracking capital flow paths and using an abnormal monitoring model, money laundering behavior can be accurately identified in most cases, and a warning can be triggered in a timely manner to notify the anti-money laundering team for intervention.

[0125] In summary, by means of the above technical solutions of the present invention, the present invention obtains fund transaction data based on blockchain technology and performs feature extraction, which can effectively identify abnormal transaction patterns related to money laundering. By extracting key features and using the local outlier factor technology to calculate outliers, it helps to discover potential abnormal transaction behaviors. Comparing the outlier calculation results with a preset threshold can accurately distinguish normal transactions from abnormal transactions, and can further explore the time rules in transaction patterns, providing effective support for the identification of money laundering behaviors, thereby improving the accuracy and efficiency of the anti-money laundering monitoring system. The present invention can significantly improve the efficiency and accuracy of the anti-money laundering monitoring system by conducting risk assessments on the initiating users and receiving users in abnormal transaction patterns and clustering high-risk users into the same group. Based on the risk degree calculation results, risk assessments are conducted on the initiating users and receiving users, and high-risk users are identified, which helps to lock in potential money laundering behaviors in advance. At the same time, the graph clustering algorithm is used to gather high-risk users in the same group, thereby realizing centralized monitoring of high-risk groups, further improving the monitoring accuracy, promptly discovering abnormal behaviors and taking corresponding measures, and effectively preventing money laundering risks. The present invention can effectively monitor potential money laundering behaviors by tracking the fund transaction flow paths of high-risk users in the same group. Using the breadth-first search algorithm to traverse the fund transaction flow paths and comprehensively track from the source to the end of the funds can clearly depict the flow of funds among users. It can not only promptly discover abnormal patterns in the fund flow but also capture potential risk behaviors according to the fund flow trajectory, thereby accurately positioning the fund flow paths of high-risk users and improving the accuracy and response speed of the anti-money laundering monitoring system.

[0126] The above are only the preferred embodiments of the present invention and are not intended to limit the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present invention shall be included in the protection scope of the present invention.

Claims

1. A digital asset anti-money laundering research and judgment method based on blockchain, characterized in that: The method includes: Obtain fund transaction data based on blockchain technology, extract features from fund transaction data, and identify abnormal transaction patterns associated with money laundering; Conduct risk assessments on initiating users and receiving users in abnormal transaction patterns, and cluster high-risk users into the same group based on risk assessment results; Track the capital transaction flow paths of high-risk users in the same group, and deploy anomaly monitoring models on the capital transaction flow paths. When the anomaly monitoring model detects money laundering behavior, it triggers an early warning according to the preset rules; The method of obtaining fund transaction data based on blockchain technology and extracting features from the fund transaction data includes: Use blockchain technology to collect fund transaction data and pre-process the fund transaction data; Extract the key features of the preprocessed fund transaction data and calculate the outliers of the key features using the local outlier factor technique; Compare the outlier calculation result with the preset threshold. If the outlier calculation result is greater than or equal to the preset threshold, it means that the key feature is a normal transaction feature. Otherwise, it is an abnormal transaction feature. Tracking the fund transaction flow path of high-risk users in the same group includes: Obtain the fund transaction flow path initiated by high-risk users, use the breadth-first search algorithm to traverse the fund transaction flow path, and track the flow of funds from the source to the end point.

2. According to a blockchain-based digital asset anti-money laundering research and judgment method according to claim 1, it is characterized in that: The identification of abnormal transaction patterns associated with money laundering includes: A time series analysis model is constructed based on abnormal transaction characteristics, and the time series analysis model is used to identify abnormal transaction patterns in fund transaction data.

3. According to the blockchain-based digital asset anti-money laundering research and judgment method of claim 1, it is characterized by: The extracting of key features of the pre-processed fund transaction data and calculating outliers of the key features using the local outlier factor technology include: Extracting key features of the preprocessed fund transaction data, wherein the key features include transaction amount, transaction frequency, and transaction time interval; Perform sliding window difference processing on key features, filter out repeated key features in the difference processing, and obtain a deduplicated difference sequence; Based on the repetition of all features accounted for by repeated key features, the local outlier factor of the difference sequence after deduplication is calculated, and the threshold is set according to the local outlier factor; Filter all key features greater than the threshold in the differential sequence after deduplication, and mark the mutation points in the differential sequence based on the filtered key features to obtain a marking vector; The changing trend between adjacent mutation points in the marker vector is analyzed, the false positive points in the mutation points are identified, and the mutation points after filtering the false positive points are taken as outliers of the key features.

4. According to the blockchain-based digital asset anti-money laundering research and judgment method of claim 3, it is characterized in that: The sliding window difference processing is performed on the key features, and repeated key features in the difference processing are filtered out to obtain a difference sequence after deduplication, which includes: Establish a sliding window for selecting a subset of continuous fund transaction data, and determine the time range of key features through the sliding window; Calculate the change of each key feature in the sliding window, and obtain the difference of each key feature based on the difference between adjacent key features; Combine the exponential perturbation method to perturb each difference in the difference sequence to ensure that the intensity of the perturbation meets the difference requirements; After the differential perturbation, the repeated key eigenvalues ​​in the differential sequence are removed to obtain a differential sequence after perturbation and deduplication.

5. According to a blockchain-based digital asset anti-money laundering research and judgment method according to claim 1, it is characterized in that: The risk assessment of the initiating user and the receiving user in the abnormal transaction mode is respectively performed, and the high-risk users are clustered into the same group according to the risk assessment results, including: The initiating user and the receiving user in the abnormal transaction mode are taken as nodes, and the transaction between the initiating user and the receiving user is taken as an edge. The weight of the edge is defined according to the transaction amount and transaction frequency to generate a graph transaction network. Convert the graph transaction network into an adjacency matrix, and decompose the adjacency matrix into a user feature matrix and a transaction feature matrix; Calculate the risk of the initiating user and the receiving user in the abnormal transaction mode, and identify high-risk users in the user feature matrix and the transaction feature matrix based on the risk calculation results; Graph clustering algorithm is used to cluster high-risk users into the same group.

6. According to the blockchain-based digital asset anti-money laundering research and judgment method of claim 5, it is characterized in that: The step of converting the graph transaction network into an adjacency matrix and decomposing the adjacency matrix into a user feature matrix and a transaction feature matrix comprises: Generate an adjacency matrix based on the nodes and edges in the graph transaction network, and construct an adjacency vector based on the adjacency matrix, and form a library matrix from the adjacency vectors; Decompose the library matrix into two sets of non-negative matrices, and initialize the random values ​​of the elements in the non-negative matrices; Based on the gradient descent update method, the minimization loss function of the non-negative matrix is ​​continuously adjusted, and the error goal is decomposed according to the minimization loss function during the gradient descent process; The regularization formula is obtained by minimizing the loss function and the Frobenius norm, and the value of the non-negative matrix is ​​updated iteratively and calculated; When the maximum number of iterations of the non-negative matrix meets the preset requirements, the two updated sets of non-negative matrices are used as the user feature matrix and the transaction feature matrix.

7. According to a blockchain-based digital asset anti-money laundering research and judgment method according to claim 1, it is characterized in that: The abnormal monitoring model is deployed on the capital transaction flow path. When the abnormal monitoring model detects money laundering behavior, an early warning is triggered according to preset rules, including: Build an abnormal monitoring model based on the flow of funds, and deploy the abnormal monitoring model on each fund transaction flow path to monitor the abnormality of the fund transaction flow path in real time; When the abnormal monitoring model detects money laundering behavior, an early warning is triggered according to the preset rules to send instructions to notify the anti-money laundering team to intervene.

8. According to a blockchain-based digital asset anti-money laundering research and judgment method as described in claim 1, it is characterized in that: The use of a breadth-first search algorithm to traverse the capital transaction flow path and track the flow of funds from the source to the destination includes: Perform a breadth-first search on the starting point of the capital transaction flow path, calculate the longest distance between the starting point and the remaining transaction nodes, and store the longest distance in the first array; Perform a breadth-first search on the capital transaction flow path from the end point to find the longest distance from the end point to the remaining transaction nodes, and store the longest distance in the second array; The first array and the second array are respectively subjected to correlation analysis to obtain the capital flow situation of the key capital transaction flow path.

9. According to claim 6, a blockchain-based digital asset anti-money laundering research and judgment method is characterized in that: The regularization formula is expressed as: ; In the formula, Represents the minimization loss function; A represents the original matrix; W , H represents the non-negative matrix factorized by the library matrix; F represents the Frobenius norm; represents the regularization term.

10. According to a blockchain-based digital asset anti-money laundering research and judgment method according to claim 3, it is characterized in that: The calculation formula of the local outlier factor is: ; In the formula, Indicates j The key features are k -Local outlier factor value within the neighborhood; Indicates that it contains j Key features k The neighborhood set of neighbors; T j Indicates j The weight of the key features; Indicates j The key features are k - local density within the neighborhood; Y j Represents a set of neighbor key features.

Citation Information

Cited By

  • Digital transaction method and system based on block chain

    CN120851868A

  • Integration link resonance early warning method and early warning device

    CN121724683A

  • Integral link resonance early warning method and early warning device

    CN121724683B