Method and device for monitoring abnormal transactions, medium and program product
By obtaining multimodal transaction data, using streaming computing engine and machine learning model for real-time analysis, and dynamically updating the model, the adaptability and real-time problems of abnormal transaction detection in the existing technology are solved, and more efficient abnormal transaction identification and protection are achieved.
Patent Information
- Application Number
- CN202510741336.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-05
- Publication Date
- 2025-07-04
AI Technical Summary
The existing abnormal transaction detection scheme cannot adapt to changes in abnormal transaction behavior patterns, cannot effectively identify all abnormal transaction behaviors, poor real-time performance, difficult to identify and prevent abnormal transaction behaviors in a timely manner, and difficult to effectively protect the security of users' assets and information.
By acquiring multimodal transaction data, using a streaming computing engine for real-time data processing and analysis, dynamically selecting a matching streaming computing engine, combining machine learning models for exception recognition, and automatically iteratively update the model based on new transaction data.
It improves the accuracy and real-time nature of abnormal transaction identification, can adapt to changes in trading mode in a timely manner, optimize model performance, reduce obvious abnormal data interference, improve system efficiency and adaptability, and meet the real-time requirements of online trading systems.
Smart Images

Figure CN120258807A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of computer technology, and in particular to a method, device, computer-readable medium and computer program product for monitoring abnormal transactions. Background Art
[0002] With the rapid development of mobile payment technology, the forms of abnormal transactions are becoming more and more complex and diverse. In order to avoid the adverse consequences of abnormal transactions as much as possible, how to identify abnormal transactions has gradually become a research hotspot in the fields of theory and practice. At present, many online transaction systems have implemented abnormal transaction detection schemes, mainly including rule-based schemes and machine learning-based schemes. After the user initiates a transaction request, the transaction system will apply predefined rules for detection and identify suspicious transactions as potential abnormal transaction behaviors. At the same time, the transaction system will also input data into the machine learning model. The model performs pattern recognition by learning normal transaction behavior patterns and identifies transactions that are significantly different from these patterns. These transactions may also be regarded as abnormal transaction behaviors.
[0003] However, there are many problems with existing abnormal transaction detection solutions. Rule-based solutions mainly rely on predefined rules set manually. For example, a large number of transactions in a short period of time or a transaction amount far exceeding the average value may be identified as abnormal transaction behavior. However, these rules require manual adjustment, making it difficult to cover all abnormal transaction patterns and unable to adapt to changes in abnormal transaction behavior patterns. Although machine learning-based methods can learn normal transaction behavior patterns, model performance will be affected if the model structure and parameters are inappropriate, or if the training data is insufficient or inaccurate. In addition, some machine learning models require a lot of computing resources and time for training and prediction, which makes it difficult to meet the real-time requirements of online trading systems. The real-time nature of payments is crucial to online trading systems. If the system cannot identify and prevent abnormal transaction behaviors in a timely manner, users' funds and information will be at risk of loss.
[0004] To sum up, the existing abnormal transaction detection solutions cannot adapt to the changes in abnormal transaction behavior patterns, cannot effectively identify all abnormal transaction behaviors, have poor real-time performance, are difficult to identify and prevent abnormal transaction behaviors in a timely manner, and are difficult to effectively protect users' assets and information security. Summary of the invention
[0005] Multiple aspects of the present application provide a method, an apparatus, a computer-readable medium, and a computer program product for monitoring abnormal transactions.
[0006] In one aspect of the present application, a method for monitoring abnormal transactions is provided, wherein the method comprises: In response to a transaction monitoring trigger instruction, obtaining multimodal transaction data related to a target transaction; Dynamically select a streaming computing engine that matches the target transaction based on the type pattern information of the target transaction; Use the selected streaming computing engine to perform real-time data processing and analysis on the multimodal transaction data; Input the feature data processed by the streaming computing engine into the trained target model to obtain the anomaly recognition result output by the target model, where the target model is automatically iteratively updated based on new transaction data.
[0007] In one aspect of the present application, there is provided a device for monitoring abnormal transactions, where the device includes: A device for acquiring multimodal transaction data related to a target transaction in response to a transaction monitoring trigger instruction; A device for dynamically selecting a streaming computing engine that matches the target transaction based on the type pattern information of the target transaction; A device for using the selected streaming computing engine to perform real-time data processing and analysis on the multimodal transaction data; A device for inputting the feature data processed by the streaming computing engine into the trained target model to obtain the anomaly recognition result output by the target model, where the target model is automatically iteratively updated based on new transaction data.
[0008] In another aspect of the present application, there is provided an electronic device, where the electronic device includes: at least one processor; and a memory communicatively connected to the at least one processor; where the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the method of the embodiments of the present application.
[0009] In another aspect of the present application, there is provided a computer-readable storage medium, on which computer program instructions are stored, and the computer program instructions can be executed by a processor to implement the method of the embodiments of the present application.
[0010] In another aspect of the present application, there is provided a computer program product, including a computer program, and when the computer program is executed by a processor, it implements the method of the embodiments of the present application.
[0011] In the solution provided by the embodiments of the present application, by obtaining multimodal transaction data related to the target transaction to be detected and performing fusion processing on the feature information of each piece of data, the transaction behavior is comprehensively analyzed from multiple dimensions, which can more accurately capture the characteristics of abnormal transactions and effectively improve the accuracy of abnormal identification of the target transaction. The model of the embodiments of the present application is automatically iteratively updated based on new transaction data, can timely adapt to the changes in abnormal transaction patterns, continuously optimize the model performance, and further improve the accuracy and reliability of abnormal identification. After obtaining the multimodal transaction data, preliminary screening is carried out according to preset rules to filter out the data with obvious transaction anomalies, which improves the pertinence and efficiency of subsequent processing, avoids the interference of obvious abnormal data on the model, and helps to improve the overall identification effect. By using a streaming computing engine to perform real-time processing and analysis on the multimodal transaction data, abnormal transactions can be discovered in a timely manner, avoiding losses caused by delays and meeting the high requirements for real-time performance of online transaction systems. By dynamically selecting a matching streaming computing engine according to the type pattern information of the target transaction, the computing resources are more reasonably utilized, the overall processing efficiency of the system is improved, and the adaptability to different types of transactions is enhanced. BRIEF DESCRIPTION OF THE DRAWINGS
[0012] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings in the following description are some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0013] By reading the detailed description of the non-restrictive embodiments with reference to the following drawings, other features, objectives, and advantages of the present application will become more apparent: Figure 1 FIG. shows a schematic flowchart of a method for monitoring abnormal transactions provided by an embodiment of the present application; Figure 2 FIG. shows a schematic structural diagram of a device for monitoring abnormal transactions provided by an embodiment of the present application; Figure 3 FIG. shows a schematic structural diagram of a device suitable for implementing the solution in the embodiments of the present application.
[0014] The same or similar reference numerals in the drawings represent the same or similar components. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0015] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions in the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of this application. Obviously, the described embodiments are part of the embodiments of this application, rather than all of them. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in this application without creative efforts belong to the scope of protection of this application.
[0016] In a typical configuration of this application, both the terminal and the devices of the service network include one or more processors (CPUs), input / output interfaces, network interfaces, and memories.
[0017] The memory may include non-permanent memory in the computer-readable medium, random access memory (RAM), and / or non-volatile memory in the form of, for example, read-only memory (ROM) or flash RAM. The memory is an example of the computer-readable medium.
[0018] The computer-readable medium includes permanent and non-permanent, removable and non-removable media, and information storage can be implemented by any method or technology. The information can be computer program instructions, data structures, program modules, or other data. Examples of the computer storage medium include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory, or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD), or other optical storage, magnetic cassette tapes, magnetic tape disk storage, or other magnetic storage devices, or any other non-transmission medium that can be used to store information accessible by a computing device.
[0019] Figure 1 The flowchart shows a method for monitoring abnormal transactions provided by the embodiments of this application. The method at least includes steps S101, S102, S103, and S104.
[0020] In an actual scenario, the execution entity of this method can be an intelligent hardware device, or it can also be an application program running on the intelligent hardware device. The intelligent hardware device includes a user device or a network device. The user device includes, but is not limited to, various terminal devices such as a computer, a mobile phone, a tablet computer, a smart watch, a bracelet, etc., and the network device includes, but is not limited to, being implemented by a network host, a single network server, a set of multiple network servers, or a computer set based on cloud computing. Here, the cloud is composed of a large number of hosts or network servers based on cloud computing (Cloud Computing), where cloud computing is a type of distributed computing and consists of a virtual computer formed by a group of loosely coupled computer sets.
[0021] In some embodiments, the embodiments of the present application use a streaming computing engine to perform data analysis and processing.
[0022] Among them, the streaming computing engine (Streaming Compute Engine, SCE) is a computing framework for real-time processing of data streams. Common streaming computing engines include Apache Flink, Apache Spark Streaming, Apache Storm, etc.
[0023] Refer to Figure 1 , in step S101, in response to a transaction monitoring trigger instruction, multi-modal transaction data related to the target transaction is obtained.
[0024] Among them, the target transaction is a transaction for which it is necessary to determine whether a transaction anomaly has occurred.
[0025] Among them, the transaction monitoring trigger instruction is used to start the monitoring process of the target transaction to determine whether there is an abnormal risk in this transaction. The transaction monitoring trigger instruction is a signal generated by automatically detecting a specific transaction behavior or user operation, such as a user initiating a transaction request, multiple transactions occurring within a short time after the user logs in to the account, the user logging in to the account in a different location and initiating a transaction, etc.
[0026] Among them, the multi-modal transaction data includes data collected from multiple data sources, and the multi-modal data at least includes transaction data and user behavior data. Among them, the transaction data includes, but is not limited to: transaction amount; transaction timestamp, used to analyze the time regularity of transactions, accurate to seconds; transaction type identifier, such as online payment, offline card swiping, transfer, refund, etc.; transaction terminal device fingerprint information, including device model, operating system version, device ID, IP address, etc.; transaction location, which can be geographical location coordinates or merchant category, such as online shopping, ATM withdrawal, retail store, etc.; transaction channel, such as mobile payment platform, bank credit card, debit card, cash transaction, etc.; transaction recipient information, including the industry to which the recipient account belongs, account type, etc.; changes in the user's account balance before and after the transaction, etc.
[0027] The user behavior data includes, but is not limited to: the user's account-related information, such as registration time, registration location, device used during registration, etc.; the user's operation behavior during the transaction, such as click path, input speed, stay time, etc.; the usage habits of the user's device, such as the commonly used device model, operating system version, device usage frequency, etc.; the user's login behavior before and after the transaction, such as login time, login location, whether the login device is the same as the commonly used device, etc.; the interaction records between the user and the customer service during the transaction, such as voice conversations, text chat records, etc.; the image or video data of the user in the transaction scenario, such as the monitoring camera image of the offline transaction scenario, the interface screenshot of the user operating the device, etc.; the audio data generated by the user during the transaction, such as the ambient sound in the offline transaction scenario, etc.; the historical transaction behavior pattern of the user, such as the commonly used transaction amount range, transaction time period, transaction frequency, etc.
[0028] According to one embodiment, the method obtains transaction data from different systems and platforms. For example, it obtains transaction data from multiple systems such as the core transaction system, online banking system, mobile payment system, credit card system, etc. By obtaining data from these different systems in real time and performing standardization and integration processing, a complete transaction view can be formed, thereby more accurately identifying abnormal transactions.
[0029] According to one embodiment, the method obtains data in real time from multiple data sources through a streaming computing engine, such as database change logs, message queues, network data streams, sensor data, and file systems, etc. The streaming computing engine receives data from the configured data sources in a continuous manner. This process is usually asynchronous to ensure that data can be obtained in a timely manner without obvious delays.
[0030] It should be noted that the transaction data involved in the embodiments of this application are all obtained with the consent or permission of the relevant parties, and the collection, use, and processing of the relevant data need to comply with the relevant laws, regulations, and standards of the relevant countries and regions.
[0031] According to one embodiment, the method preprocesses the obtained multi-modal transaction data.
[0032] Among them, the preprocessing includes but is not limited to data cleaning, data standardization and normalization, data correction, data quality assessment, data storage, etc.
[0033] Among them, the preprocessing includes at least any one of the following: 1) Data cleaning: removing noise data, handling missing values, and correcting incorrect data; 2) Data conversion: converting the data into a format or type suitable for subsequent processing. For example, converting the time in string format to a datetime object, normalizing numerical data, etc., so that these data can be accurately used in subsequent calculations and analyses; 3) Data enrichment: supplementing and enriching the original data by combining external data sources. For example, when processing transaction data, the user ID in the transaction data can be associated with the user's detailed information (such as user level, historical transaction records, etc.) by calling an external user information database, so as to provide more dimensional data support for subsequent risk assessment and other processing.
[0034] Optionally, in the data collection process, the method uses multi-source heterogeneous data fusion collection technology to obtain data from different types and structures of data sources, and performs format unification and preprocessing to ensure the integrity and availability of the data.
[0035] According to one embodiment, the method selects multiple data for abnormal transaction identification from the obtained multi-modal transaction data based on the transaction type of the target transaction and a preset data screening criterion, where the data screening criterion is automatically updated according to new transaction patterns and risk characteristics.
[0036] Among them, the transaction type includes but is not limited to credit card payment, online transfer, cash purchase, etc.
[0037] Among them, the data screening criterion is used to indicate how to select the data for abnormal transaction identification. It includes but is not limited to relevant factors such as the size of the transaction amount, the time and frequency of the transaction occurrence, the geographical location of the transaction, and the historical transaction records of both parties to the transaction.
[0038] Specifically, the method first determines the transaction type to which the target transaction belongs. Then, according to the pre-set data screening criteria, multiple pieces of data closely related to abnormal transaction identification are selected from the obtained multimodal transaction data.
[0039] Among them, the method automatically updates the data screening criteria according to new transaction patterns and risk characteristics. Specifically, the method monitors and analyzes a large amount of transaction data in real time to capture new transaction patterns and corresponding risk characteristics. For example, with the development of fintech, new payment methods are emerging continuously, such as digital currency payment, biometric payment, etc. These new payment methods may bring new risk characteristics that lead to abnormal transactions. The method automatically identifies these new risk characteristics through machine learning algorithms and incorporates them into the data screening criteria.
[0040] Moreover, the method continuously evaluates and analyzes the existing transaction patterns to determine whether new risk characteristics that lead to abnormal transactions appear. For example, in the scenario of credit card payment, common risk characteristics may include an abnormally large transaction amount or an abnormally distant transaction location. However, with the continuous change of credit card usage scenarios, new risk characteristics such as high-frequency small transactions may also appear. The method identifies new risk characteristics and makes corresponding adjustments to the data screening criteria according to them, so as to strengthen the risk monitoring of small high-frequency transactions.
[0041] In addition, the method regularly evaluates the effectiveness of the data screening criteria and updates them according to new transaction data and risk information. For example, if a new fraud pattern is found in a certain region, it will immediately optimize the transaction data screening criteria related to that region and increase the monitoring intensity of transactions in that region. Through this dynamic update mechanism, it is possible to always maintain a high sensitivity to abnormal transactions, timely identify potential risks, and thus provide more reliable risk prevention and control means for financial institutions.
[0042] Continue to refer to the following Figure 1 for illustration. In step S102, based on the type pattern information of the target transaction, a streaming computing engine matching the target transaction is dynamically selected.
[0043] Among them, the type pattern information includes various information that can be used to indicate the transaction type and / or transaction mode of the target transaction. For example, the transaction type includes but is not limited to credit card consumption, cross-border payment, stock trading, virtual currency trading, etc.
[0044] Optionally, the selection basis for selecting a matching streaming computing engine includes but is not limited to the real-time requirement for data processing, the size of the data volume, the data complexity, and the availability of computing resources, etc.
[0045] For example, for high-frequency stock trading that requires real-time complex event processing, choose Apache Flink. For cross-border e-commerce payment scenarios that require fast processing of large-scale data, choose Apache Spark Streaming. For credit card consumption scenarios that require low-latency processing, choose Apache Storm.
[0046] In step S103, the selected streaming computing engine is used to perform real-time data processing and analysis on the multimodal transaction data.
[0047] According to one embodiment, step S103 further includes steps S1031 to 1033.
[0048] In step S1031, after obtaining the multimodal transaction data, the data is first preliminarily screened according to preset rules to filter out data with obvious transaction anomalies. For example, check simple and obvious anomaly features such as whether the transaction amount exceeds the set threshold and whether the transaction time is during non-normal business hours. This preliminary screening process can quickly filter out a large number of obviously normal transactions and some obvious abnormal transactions (such as amounts far exceeding the normal range), thereby reducing the amount of data to be processed subsequently and improving the overall efficiency.
[0049] Specifically, based on in-depth understanding and analysis of abnormal transaction characteristics, a series of event patterns and rules are defined. For example, for abnormal patterns such as frequent large-amount transactions within a short period of time, an account logging in and trading in multiple different regions, and associated transactions with known high-risk accounts, corresponding identification rules are set. These rules cover various dimensions of transaction characteristics and behavior characteristics, such as transaction frequency, transaction amount threshold, geographical distribution, transaction time interval, etc.
[0050] Moreover, the complex event processing function of the selected streaming computing engine is utilized, such as the Complex Event Processing (CEP) library in Flink, to perform pattern matching and analysis of abnormal transactions on the real-time data stream. Specific operations include windowing the data stream, aggregation calculation, correlation analysis, etc. The aim is to accurately identify the event sequences that conform to the preset abnormal transaction patterns.
[0051] Among them, the common window types in window processing include: Time Window: Data is divided based on a time range, such as every 30 seconds as a window. In real-time data analysis, metrics within each time window can be calculated, such as the trading volume per minute, the average transaction amount per hour, etc. Count Window: Windows are divided according to the quantity of data. For example, every 100 transaction records form a window. This type of window is suitable for scenarios that require statistics or analysis based on a fixed amount of data. Session Window: Windows are divided according to the activity intervals of data and are used to divide continuous activities into a session. For example, in user behavior analysis, the consecutive web browsing operations of a user are regarded as a session. If there are no new operations by the user within a certain period (such as 10 minutes), the session is considered to end. This type of window can be used to analyze metrics related to user stickiness, such as the session duration and the number of operations within a session.
[0052] Among them, the aggregation calculation is used to perform aggregation operations on the data within the window, such as sum, average, max, min, count, etc. In a financial scenario, the total transaction amount per second, the number of transaction records per minute, etc. can be calculated to monitor the real-time traffic and scale of transactions.
[0053] Among them, the correlation analysis is used to correlate data from different data sources to discover the relationships and patterns between the data. For example, in an e-commerce transaction scenario, transaction data is correlated with data such as the user's browsing history and search records to analyze the user's purchase behavior pattern and predict the user's purchase intention, etc.
[0054] Next, in step S1032, for the multimodal transaction data that still needs further analysis after preliminary screening, the streaming computing engine performs feature extraction processing to obtain transaction feature data corresponding to the target transaction. These feature data may include multi-dimensional information such as transaction frequency, transaction amount, transaction location, transaction time interval, transaction type, etc. The streaming computing engine utilizes its powerful real-time data processing capabilities to perform operations such as window processing and aggregation calculation on the data stream to accurately extract the required feature information.
[0055] Among them, the streaming computing engine performs real-time feature engineering to extract and transform features in real time during the data flow. For example, in the scenario of identifying abnormal trading in the stock market, machine learning models require a large number of real-time features to determine whether a transaction is abnormal, such as real-time price fluctuations of stocks, changes in trading volume, depth of buy and sell order books, etc. The streaming computing engine can process the stock trading data stream in real time, quickly extract these features, and input them into the machine learning model, enabling the model to make real-time predictions based on the latest market data and timely detect abnormal trading behaviors such as insider trading and market manipulation.
[0056] Next, in step S1033, the feature information corresponding to each item of data is fused to obtain the corresponding fused feature information.
[0057] Among them, the fusion processing methods include but are not limited to feature splicing, feature transformation, shared feature extractor, attention mechanism fusion, circulant matrix fusion, voting method, model fusion, multi-layer perceptron (MLP) fusion, and deep learning model fusion, etc.
[0058] Specifically, for various types of transaction data, such as structured transaction amounts, times, account information, etc., semi-structured transaction log data (such as JSON format data containing transaction device information, transaction geographical location coordinates, etc.), and unstructured data (such as chat records related to transactions, voice call content, etc.), the streaming computing engine processes these multi-source heterogeneous data in real time and fuses them.
[0059] For example, multi-modal data alignment is achieved through the Transformer architecture. Using its self-attention mechanism to calculate the importance weights between different features, it automatically focuses on the feature dimensions crucial for abnormal trading identification, thereby achieving deep fusion of features.
[0060] In step S104, the feature data processed by the streaming computing engine is input into the trained target model to obtain the abnormal identification result output by the target model, where the target model is automatically iteratively updated based on new transaction data.
[0061] Among them, the target model is a risk prediction model based on machine learning, which is used to calculate the probability of abnormal trading or identify the category of abnormal trading according to the input feature data and output the corresponding abnormal identification result.
[0062] Among them, the target model can be constructed using a variety of machine learning techniques. Optionally, the target model is constructed using a deep learning model and a multi-task learning model.
[0063] The target model is trained based on a large amount of historical transaction data, capable of learning complex feature relationships and abnormal patterns, thereby deeply analyzing the fused feature information to determine whether an abnormal transaction occurs. At the same time, the model will automatically iterate and update based on new transaction data during actual application to adapt to changes in transaction patterns and the emergence of new abnormal features.
[0064] Among them, the abnormal recognition result includes but is not limited to indicating whether a transaction anomaly occurs (for example, marked as "normal" or "abnormal"), the predicted probability value of a transaction anomaly occurring (for example, the probability value is a floating point number between 0 and 1, and the closer it is to 1, the greater the likelihood of a transaction anomaly), information on the type of transaction anomaly (for example, the anomaly type can be that the transaction amount is abnormally high or low, the transaction location is abnormal, or the transaction device is abnormal, etc.).
[0065] Specifically, in step S104, the feature data processed by the streaming computing engine is input into the trained target model for analysis and processing. The target model will calculate the probability of an abnormal transaction and identify the category of the abnormal transaction based on the input feature data, and output the corresponding abnormal recognition result.
[0066] Optionally, the method uses multiple abnormal pattern mining algorithms, such as isolation forest, LSTM time series prediction, graph neural network, and clustering algorithm, etc., to analyze and model the transaction data from different perspectives, so that the trained target model can mine potential abnormal patterns in the transaction data.
[0067] According to one embodiment, the method selects a matching model from multiple candidate models as the target model based on the type pattern information of the target transaction.
[0068] Specifically, the method selects a matching model from multiple candidate models as the target model according to the preset model matching rules. Among them, the preset model matching rules are a set of logical criteria that have been strictly verified and optimized through multiple rounds. Its core purpose is to accurately screen out the most suitable model for the target transaction among numerous candidate models.
[0069] During the matching process, the type pattern information of the target transaction is carefully disassembled first. These information may include multiple dimensions such as the transaction amount range, transaction frequency, transaction time point, credit ratings of both parties to the transaction, geographical features of the transaction, and business type of the transaction. For example, for a transaction involving cross-border payment, its type pattern information may include features such as a large transaction amount, a transaction time spanning different time zones of different countries, and both parties to the transaction belonging to enterprises in different countries; while for a small-value and high-frequency local retail transaction, its features may be manifested as a small amount, a high transaction frequency, and a transaction time concentrated in specific business activity periods, etc.
[0070] Next, the disassembled type pattern information is compared one by one with the features of the candidate models. Among them, the features of the candidate models are formed through the learning of a large number of sample data during the model training process, and each model has its unique advantages and applicable scenarios. For example, some models may have higher accuracy in processing large-value transactions and can accurately identify risk points in transactions; while others may show stronger stability in processing high-frequency transactions and can quickly respond to and process a large number of transaction requests.
[0071] Optionally, the method may also comprehensively consider multiple key factors. For example, the accuracy, stability, and adaptability of the model, etc., so that the finally selected target model can best meet the actual needs of the target transaction and can provide strong support from the perspectives of risk control, transaction efficiency, and user experience.
[0072] Optionally, the target model is included in a model library, and the model library contains multiple machine learning models that are specifically trained for different transaction types or transaction patterns. The method dynamically selects a machine learning model that matches the type pattern information of the target transaction from the model library as the target model based on the type pattern information of the target transaction. For example, for credit card consumption transactions, an isolation forest model based on user behavior is selected. For cross-border payment transactions, a supervised learning classification model based on geographical distribution and transaction frequency is selected. For virtual currency transactions, a graph neural network model based on the transaction network graph is selected.
[0073] According to one embodiment, the trained target model is integrated into the streaming computing process. Among them, the machine learning model includes but is not limited to a classification model trained by a supervised learning algorithm and an isolation forest model in an unsupervised learning algorithm. The classification model is used to identify normal and abnormal patterns in transaction data, and the isolation forest model focuses on detecting abnormal transaction instances that deviate from the normal pattern. After feature extraction of the real-time data, it is input into the model for prediction of whether there are abnormal transactions.
[0074] According to one embodiment, the method optimizes and improves the preset rules for preliminary data screening based on the abnormal recognition result output by the target model. Specifically, the abnormal recognition result output by the target model is fed back to the rule engine to help optimize and improve the preset rules for preliminary data screening in step S1031, realizing the co-evolution of rules and models, and further improving the accuracy and efficiency of abnormal transaction detection. Through continuous learning and optimization, the system can continuously adapt to new transaction patterns and abnormal features, improving the accuracy and efficiency of abnormal transaction detection.
[0075] According to one embodiment, the method further includes step S105.
[0076] In step S105, if it is determined that the target transaction is an abnormal transaction, warning processing is performed.
[0077] Among them, the warning processing includes various risk management measures for abnormal transactions. For example, warning signals are sent, accounts are frozen, and users are required to perform identity verification, etc.
[0078] Specifically, the method can determine whether the target transaction is an abnormal transaction during the process of the streaming computing engine preliminarily screening data according to preset rules, or determine whether the target transaction is an abnormal transaction based on the abnormal recognition result output by the target model.
[0079] Optionally, the method pre-sets corresponding warning strategies according to the risk levels and business impact degrees of different abnormal transaction types. For example, for high-risk abnormal transaction behaviors, real-time warning notifications are immediately sent to the business system and relevant regulatory agencies. For medium and low-risk abnormal transactions, such as possible operation errors or account theft risks, further analysis and verification are first carried out, and then it is decided whether to issue a warning according to the verification result.
[0080] Optionally, the warning strategy also includes a dynamic adjustment mechanism for warning thresholds. According to the business operation situation and data change trend, warning parameters are optimized in real time to improve the timeliness and accuracy of warnings.
[0081] Optionally, the method sends warning notifications to the devices where the relevant personnel of the abnormal transaction are located. Among them, the content of the warning notification at least includes key information such as the type of abnormal transaction, occurrence time, involved account, transaction amount, risk level, and preliminary analysis result, etc., so that the relevant personnel can quickly take countermeasures to reduce risk losses. Optionally, through diversified warning notification channels, it is ensured that the warning information can be conveyed to the relevant personnel and systems in a timely and accurate manner. The warning notification channels include but are not limited to text messages, emails, instant messaging tools, etc. Optionally, the method conducts a structured design on the content of the warning notification to ensure the integrity and readability of the information. The content of the warning notification at least includes key information such as the type of abnormal transaction, occurrence time, involved account, transaction amount, risk level, and preliminary analysis result, etc., so that the relevant personnel can quickly take countermeasures to reduce risk losses.
[0082] According to one embodiment, the method trains the target model through steps S106 to S108.
[0083] In step S106, target training data is obtained. Among them, the target training data includes multi-modal historical transaction data corresponding to multiple historical transactions and their annotation results.
[0084] Among them, the historical transaction data includes, but is not limited to: the specific timestamp of the historical transaction, which is used to analyze the time regularity of transactions; the transaction amount, covering various amount ranges, including large amounts, small amounts, and regular transaction amounts; the transaction location, which can be specific geographical location coordinates or the merchant category where the transaction occurs, such as online shopping, ATM withdrawals, retail stores, etc.; the transaction channel, such as mobile payment platforms, bank credit cards, debit cards, cash transactions, etc.; the network environment parameters at the time of the transaction, including network type and network latency, etc.; the device information used by the user, such as device model, operating system version, device ID, etc.; the information of the transaction recipient, such as the industry to which the recipient account belongs, account type, etc.; the change in the user's account balance before and after the transaction; the user's transaction behavior pattern, such as the user's usual transaction amount range, transaction time period, transaction frequency, etc.; the image data generated during the transaction, such as the monitoring camera images of the offline transaction scenario, the interface screenshots of the user operating the device, etc.; the audio data generated during the transaction, such as the voice conversations between the user and the customer service during the transaction, the environmental sounds in the offline transaction scenario, etc.; the context information of the transaction, such as whether the transaction is associated with a promotional activity, whether it is the first transaction of a newly registered user, etc.; the text data related to the transaction, such as transaction remarks, transaction description information, etc.
[0085] Optionally, by accessing multiple data sources related to transactions, such as transaction order databases, account basic information management systems, or fund flow record platforms, multi-dimensional historical transaction data can be obtained.
[0086] Among them, the annotation result includes, but is not limited to, information indicating whether a transaction anomaly occurs, the predicted probability value of the occurrence of a transaction anomaly, and the type of transaction anomaly.
[0087] According to one embodiment, in step S106, multi-modal historical transaction data is loaded and data preprocessing is performed. Then, the training sample data is annotated. Then, the annotated data set is divided into a training data set and a validation data set according to a certain ratio, and thus the quantitatively divided training data set is used as the target training data.
[0088] Among them, the preprocessing includes, but is not limited to, data cleaning, data standardization processing, data denoising, and format conversion.
[0089] Among them, the data cleaning includes removing missing values, duplicate values, and error data. For example, deleting records with missing transaction amounts or transaction times, correcting transaction timestamp errors, etc. Among them, the data is standardized. The data is standardized to make data of different dimensions comparable. For example, numerical data such as transaction amounts and user ages is normalized. Among them, data denoising is used to remove abnormal data points caused by equipment failures or network problems. Among them, data augmentation increases the diversity and quantity of data by synthesizing new data samples. For example, new abnormal transaction samples are generated by simulating fraudulent transactions. Among them, format conversion converts data from different sources into a unified format for subsequent processing.
[0090] Among them, the annotation content includes: category labels indicating whether a transaction is abnormal (such as "normal" or "abnormal"), probability values of transaction anomalies, specific types of transaction anomalies, context correlation labels of transactions (for example, whether it is associated with recent promotional activities, or whether it belongs to a high-risk transaction period), etc.
[0091] Among them, the data set is divided into a training set and a validation set to monitor the accuracy of the validation set to prevent the model from overfitting.
[0092] In step S107, an anomaly recognition result output by the target model based on the input historical transaction data is obtained.
[0093] According to one embodiment, the target model adopts a multi-layer neural network structure, integrates the Transformer architecture to process sequence data, and is used to capture dependency relationships and key feature information in transaction data. At the same time, it combines rich features extracted and constructed from the original historical transaction data, such as time features and behavior features such as transaction time and user behavior, as well as new features constructed through business knowledge and experience, such as the number of transactions in the recent period and the transaction frequency of a certain type of commodity. In addition, the target model also uses methods such as correlation analysis and chi-square test for feature selection to remove redundant and irrelevant features, so as to accurately capture feature information highly relevant to abnormal transactions.
[0094] Among them, the input layer of the target model can receive different types of historical transaction data, including multi-modal data such as text, images, and structured data. The middle layer of the target model can include multiple Transformer encoder and decoder modules, which are used to model the time series features of transaction data, learn the temporal patterns and change rules of normal transactions, and at the same time combine the advantages of other machine learning algorithms, such as the efficient processing of high-dimensional sparse data by the isolation forest algorithm, the capture of long-term dependencies by the LSTM time series prediction algorithm, the mining of complex associations between accounts by the graph neural network algorithm, and the clustering analysis of transaction data by the clustering algorithm, etc., to further enhance the ability to identify abnormal transaction patterns. The middle layer of the target model can also analyze in detail the differences in aspects such as the distribution of transaction time, the fluctuation of transaction amount, the change of transaction frequency, and the characteristics of participants for each transaction type, and form a specific and accurate event pattern description, so that the target model can accurately distinguish different types of abnormal transactions.
[0095] The output layer of the target model outputs the recognition results of abnormal transactions according to the task requirements, such as the probability that the transaction data belongs to an abnormal transaction, the corresponding type of abnormal transaction (such as false declaration, price manipulation, etc.) or the abnormal risk level, etc., so as to achieve the accurate recognition and classification of abnormal transactions. At the same time, the target model is automatically iteratively updated based on new transaction data, can timely adapt to the changes of abnormal transaction patterns, continuously optimize the model performance, and further improve the accuracy and reliability of abnormal recognition.
[0096] According to one embodiment, based on the type of abnormal transaction to be identified, a machine learning algorithm for model training is selected, so that the target model learns the feature differences between normal transactions and abnormal transactions.
[0097] Among them, the machine learning algorithm includes but is not limited to at least any one of the following: 1) Isolation forest algorithm: An ensemble learning algorithm based on decision trees. By randomly splitting the feature space to construct isolation trees, samples with shorter path lengths are more likely to be outliers. In view of the characteristics of high-dimensional and sparse financial transaction data, the isolation forest algorithm is optimized to make it have higher computational efficiency and memory utilization when processing large-scale transaction data, and at the same time improve the ability to identify complex abnormal patterns, and can quickly and accurately identify abnormal transactions that deviate greatly from normal transaction patterns; 2) LSTM time series prediction algorithm: Use the LSTM neural network to model the time series characteristics of transaction data, learn the time series patterns and change rules of normal transactions, predict the reasonable range and trend of subsequent transactions. When the actual transaction data deviates severely from the predicted value, such as the individual stock price suddenly deviating greatly from the predicted trend, or the transaction amount showing abnormal fluctuations in a short period of time, it is judged that there is an abnormal transaction behavior. Expand the LSTM network structure, add a multi-feature fusion module and an attention mechanism, so that the model can better capture the long-term dependence relationship and key feature information in transaction data, and improve the prediction accuracy and the sensitivity of anomaly detection; 3) Graph neural network algorithm: Model the trading accounts and related information as a graph structure, where nodes represent entities such as accounts and funds, and edges represent relationships such as transactions. Learn the embedding representations of nodes and graphs through the graph neural network, mine the complex associations and collaborative behaviors between accounts, and identify hidden abnormal trading networks. Innovatively introduce a multi-graph pooling mechanism and a dynamic graph update strategy, so that the model can maintain high computational performance when processing large-scale graph data, and can timely capture the dynamic changes in the relationships between accounts, enhancing the ability to detect hidden abnormal transactions; 4) Clustering algorithm: Use clustering algorithms such as K-Means and DBSCAN to perform clustering analysis on transaction data, classify similar transactions into one category. Normal transactions usually form larger clusters, while abnormal transactions may be located at the cluster edges or form small-scale independent clusters. By optimizing the clustering algorithm, such as improving the clustering center initialization method and introducing a density adaptive adjustment mechanism, etc., improve the accuracy and robustness of the clustering results, so as to achieve more effective identification of abnormal transactions.
[0098] For example, for high-frequency trading data, select the LSTM time series prediction algorithm. Since high-frequency trading has obvious time series characteristics, large data volume and rapid changes, LSTM can effectively capture the time dependence relationship and dynamic change patterns in trading data, and identify abnormal transactions that deviate significantly from the normal pattern by learning the time series characteristics of normal high-frequency transactions; for trading types with complex associations between trading accounts, select the graph neural network algorithm. This type of trading involves the fund flow and association behaviors between multiple accounts, and the graph neural network can model the trading accounts and related information as a graph structure, mine the hidden relationships and collaborative behaviors between accounts, and identify abnormal account association patterns.
[0099] Optionally, the method combines business requirements and data characteristics to select a suitable machine learning algorithm for model training, so that the target model learns the feature differences between normal transactions and abnormal transactions. After determining the selected algorithm, the method initializes the parameters of the model according to the selected algorithm.
[0100] In step S108, the target model is continuously updated according to the difference between the anomaly recognition result output by the target model and the actual anomaly recognition result of historical transactions until the difference meets a predetermined requirement. Specifically, through multiple iterative trainings, the loss between the anomaly recognition result obtained in each iteration and the actual anomaly recognition result is calculated, and the model parameters are updated based on the calculated loss.
[0101] Wherein, the predetermined requirement includes one or more conditions for determining whether the expected training effect is achieved.
[0102] Optionally, the predetermined requirement includes at least any one of the following conditions: the value of the loss function between the predicted emotion evaluation result and the actual emotion evaluation result of the sample object is lower than a preset threshold; the value of a predetermined performance index of the model reaches a preset threshold, and the performance index includes but is not limited to accuracy or recall rate, etc.; the number of iterations reaches a preset number threshold.
[0103] Optionally, the method calculates the gradient of the loss function with respect to the model parameters through the backpropagation algorithm, and uses an optimization algorithm to adjust the parameters to minimize the loss function.
[0104] According to an embodiment, a method of dynamic feature selection and weight adjustment is adopted. According to the real-time changes of transaction data and the feedback of the model, one or more most relevant features are automatically selected, and during the training process, the weights of the one or more features in the target model are adjusted. For example, based on a certain feature selection algorithm, combined with the time series characteristics of transaction data, feature evaluation and screening are performed regularly, and the feature weights in the model are updated according to the screening results. Since the trading patterns in the financial market are dynamically changing, the importance of different features for the recognition of abnormal transactions also varies at different times. This method can improve the adaptability and recognition performance of the model.
[0105] According to an embodiment, the streaming computing engine and the target model of the embodiments of the present application are co-optimized.
[0106] Specifically, if the dynamically selected streaming computing engine changes, the corresponding parameters of the target model are triggered to be adjusted to ensure the efficient cooperation between the target model and the streaming computing engine. For example, when switching from an engine for processing high-frequency trading data to a deep learning engine for processing complex pattern recognition, the corresponding model parameters are automatically optimized to improve the adaptability of the model to the data output of the new engine and enhance the accuracy and real-time performance of anomaly recognition. If the streaming computing engine detects new trading patterns or data feature changes, the corresponding parameters of the target model are triggered to be adjusted, and according to the data characteristics processed by the streaming computing engine, the key data for model training is adjusted accordingly. For example, during the trading peak period when the streaming computing engine processes a large amount of real-time trading data, when automatically updating the target model, the focus is on optimizing the features for the recognition ability of high-frequency trading anomalies. At the same time, using the real-time feedback data provided by the engine, the model parameters are quickly iterated to ensure that the target model can promptly adapt to the new trading environment and maintain a high-precision anomaly trading recognition effect.
[0107] According to one embodiment, the method uses the divided test set to evaluate the trained target model. Among them, the evaluation methods include but are not limited to accuracy, recall rate, and F1 score. Among them, the accuracy rate represents the proportion of correctly predicted abnormal transactions in all transactions predicted as abnormal transactions; the recall rate represents the proportion of abnormal transactions predicted by the model in all actual abnormal transactions; the F1 value is the harmonic mean of the accuracy rate and the recall rate. Optionally, the area under the AUC-ROC curve can also be calculated to evaluate the trained target model, and this indicator comprehensively considers the performance of the model at different thresholds.
[0108] According to the method of the present application, by obtaining multi-modal trading data related to the target transaction to be detected and fusing the feature information of each item of data, the trading behavior is comprehensively analyzed from multiple dimensions, and the characteristics of abnormal transactions can be captured more accurately, effectively improving the accuracy of anomaly recognition of the target transaction; the model of the embodiment of the present application is automatically iteratively updated based on new trading data, can promptly adapt to the changes in abnormal trading patterns, continuously optimize the model performance, and further improve the accuracy and reliability of anomaly recognition; after obtaining the multi-modal trading data, according to the preset rules for preliminary screening, the data with obvious trading anomalies is filtered out, improving the pertinence and efficiency of subsequent processing, avoiding the interference of obvious abnormal data on the model, and helping to improve the overall recognition effect; through the streaming computing engine for real-time processing and analysis of multi-modal trading data, abnormal transactions can be discovered in a timely manner, avoiding losses caused by delays, and meeting the high requirements for real-time performance of the online trading system; by dynamically selecting a matching streaming computing engine according to the type pattern information of the target transaction, the computing resources are more reasonably utilized, improving the overall processing efficiency of the system and enhancing the adaptability to different types of transactions.
[0109] Figure 2 The structural schematic diagram of a device for monitoring abnormal transactions provided by an embodiment of the present application is shown.
[0110] The device includes: a device for obtaining multimodal transaction data related to a target transaction in response to a transaction monitoring trigger instruction (hereinafter referred to as "data acquisition device 101"), a device for dynamically selecting a streaming computing engine matching the target transaction based on the type pattern information of the target transaction (hereinafter referred to as "engine selection device 102"), a device for performing real-time data processing and analysis on the multimodal transaction data using the selected streaming computing engine (hereinafter referred to as "data processing device 103"), and a device for inputting the feature data processed by the streaming computing engine into a trained target model to obtain an abnormal recognition result output by the target model (hereinafter referred to as "abnormal recognition device 104").
[0111] Referring to Figure 2 , in response to a transaction monitoring trigger instruction, the data acquisition device 101 obtains multimodal transaction data related to a target transaction.
[0112] Among them, the transaction monitoring trigger instruction, the target transaction, and the multimodal transaction data have been described in the foregoing, and will not be elaborated herein.
[0113] According to one embodiment, the data acquisition device 101 obtains transaction data from different systems and platforms. For example, it obtains transaction data from multiple systems such as a core transaction system, an online banking system, a mobile payment system, and a credit card system. By obtaining data from these different systems in real time and performing standardization and integration processing, a complete transaction view can be formed, thereby more accurately identifying abnormal transactions.
[0114] According to one embodiment, the data acquisition device 101 obtains data in real time from multiple data sources through a streaming computing engine, such as database change logs, message queues, network data streams, sensor data, and file systems. The streaming computing engine receives data from the configured data sources in a continuous manner. This process is usually asynchronous to ensure that data can be obtained in a timely manner without obvious delays.
[0115] It should be noted that the transaction data involved in the embodiments of the present application are all obtained with the consent or permission of the relevant parties, and the collection, use, and processing of the relevant data need to comply with the relevant laws, regulations, and standards of the relevant countries and regions.
[0116] According to one embodiment, the device preprocesses the obtained multimodal transaction data.
[0117] Among them, the method of the preprocessing has been described in the previous text and will not be elaborated here.
[0118] Optionally, during the data acquisition process, the device uses the multi-source heterogeneous data fusion acquisition technology to obtain data from data sources of different types and structures, and performs format unification and preprocessing to ensure the integrity and availability of the data.
[0119] According to one embodiment, the device selects multiple pieces of data for abnormal transaction identification from the obtained multi-modal transaction data based on the transaction type of the target transaction and the preset data screening criteria, wherein the data screening criteria are automatically updated according to the new transaction mode and risk characteristics.
[0120] Among them, the transaction type, the data screening criteria, and the method of selecting multiple pieces of data for abnormal transaction identification have been described in the previous text and will not be elaborated here.
[0121] The engine selection device 102 dynamically selects a streaming computing engine that matches the target transaction based on the type pattern information of the target transaction.
[0122] Among them, the type pattern information includes various information that can be used to indicate the transaction type and / or transaction mode of the target transaction. For example, the transaction type includes but is not limited to credit card consumption, cross-border payment, stock trading, virtual currency trading, etc.
[0123] Optionally, the selection basis for the engine selection device 102 to select a matching streaming computing engine includes but is not limited to the real-time requirement of data processing, the size of the data scale, the data complexity, and the availability of computing resources, etc.
[0124] The data processing device 103 uses the selected streaming computing engine to perform real-time data processing and analysis on the multi-modal transaction data.
[0125] According to one embodiment, the data processing device 103 further includes a data preliminary screening device, a feature extraction device, and a feature fusion device.
[0126] After obtaining the multi-modal transaction data, the data preliminary screening device preliminarily screens the data according to the preset rules to filter out the data with obvious transaction anomalies. The method for the data preliminary screening device to preliminarily screen the data has been described in the part of step S1031 in the previous text and will not be elaborated here.
[0127] Next, for the multi-modal transaction data that still needs further analysis after preliminary screening, the feature extraction device performs feature extraction processing on the streaming computing engine to obtain transaction feature data corresponding to the target transaction. Among them, the operation of the feature extraction device has been described in the part of step S1032 in the previous text and will not be elaborated here.
[0128] The feature fusion device fuses the feature information corresponding to each item of data to obtain the corresponding fused feature information.
[0129] Among them, the method of the fusion process has been described in the previous part of step S1033 and will not be elaborated here.
[0130] The anomaly recognition device 104 inputs the feature data processed by the streaming computing engine into the trained target model to obtain the anomaly recognition result output by the target model. Among them, the target model is automatically iteratively updated based on new transaction data.
[0131] Among them, the target model is a risk prediction model based on machine learning, which is used to calculate the probability of an abnormal transaction or identify the category of an abnormal transaction according to the input feature data, and output the corresponding anomaly recognition result.
[0132] Among them, the target model can be constructed using a variety of machine learning techniques. Optionally, the target model is constructed using a deep learning model and a multi-task learning model.
[0133] The target model is trained based on a large amount of historical transaction data, and can learn complex feature relationships and abnormal patterns, so as to deeply analyze the fused feature information and judge whether the target transaction is abnormal. At the same time, the model will be automatically iteratively updated based on new transaction data in actual applications to adapt to changes in transaction patterns and the emergence of new abnormal features.
[0134] Among them, the anomaly recognition result includes but is not limited to indicating whether a transaction anomaly occurs (for example, marked as "normal" or "abnormal"), the predicted probability value of a transaction anomaly occurring (for example, the probability value is a floating point number between 0 and 1, and the closer it is to 1, the greater the possibility of a transaction anomaly), information about the type of transaction anomaly (for example, the anomaly type can be that the transaction amount is abnormally high or low, the transaction location is abnormal, or the transaction device is abnormal, etc.).
[0135] Specifically, the anomaly recognition device 104 inputs the feature data processed by the streaming computing engine into the trained target model for analysis and processing. The target model will calculate the probability of an abnormal transaction and identify the category of an abnormal transaction according to the input feature data, and output the corresponding anomaly recognition result.
[0136] Optionally, the device uses a variety of abnormal pattern mining algorithms, such as isolation forest, LSTM time series prediction, graph neural network, and clustering algorithm, etc., to analyze and model the transaction data from different angles, so that the trained target model can mine potential abnormal patterns in the transaction data.
[0137] According to one embodiment, the device selects a matching model from multiple candidate models as the target model based on the type pattern information of the target transaction.
[0138] Among them, the method of selecting a matching model as the target model has been described above and will not be elaborated here.
[0139] Optionally, the target model is included in a model library, and the model library contains multiple machine learning models that are specifically trained for different transaction types or transaction patterns. The method dynamically selects a machine learning model that matches the type pattern information of the target transaction from the model library as the target model. For example, for credit card consumption transactions, an isolation forest model based on user behavior is selected. For cross-border payment transactions, a supervised learning classification model based on geographical distribution and transaction frequency is selected. For virtual currency transactions, a graph neural network model based on the transaction network graph is selected.
[0140] According to one embodiment, the trained target model is integrated into the streaming computing process. Among them, the machine learning model includes, but is not limited to, a classification model trained by a supervised learning algorithm and an isolation forest model in an unsupervised learning algorithm. The classification model is used to identify normal and abnormal patterns in transaction data, and the isolation forest model focuses on detecting abnormal transaction instances that deviate from the normal pattern. After feature extraction of real-time data, it is input into the model for predicting whether there are abnormal transactions.
[0141] According to one embodiment, the device optimizes and improves the preset rules for preliminary screening of data based on the abnormal recognition result output by the target model. Specifically, the abnormal recognition result output by the target model is fed back to the rule engine to help optimize and improve the preset rules for preliminary screening of data, realizing the co-evolution of rules and models, and further improving the accuracy and efficiency of abnormal transaction detection. Through continuous learning and optimization, the system can continuously adapt to new transaction patterns and abnormal features, improving the accuracy and efficiency of abnormal transaction detection.
[0142] According to one embodiment, the method further includes an early warning processing device.
[0143] If it is determined that the target transaction is an abnormal transaction, the early warning processing device performs early warning processing.
[0144] Among them, the method of performing early warning processing has been described above and will not be elaborated here.
[0145] According to one embodiment, the method trains the target model through the operations of a training data acquisition device, a model result acquisition device, and a model iterative update device.
[0146] The training data acquisition device acquires target training data. Among them, the target training data includes multimodal historical transaction data corresponding to multiple historical transactions and their annotation results.
[0147] Among them, the historical transaction data has been described above and will not be elaborated here.
[0148] Optionally, the training data acquisition device accesses various transaction-related data sources, such as transaction order databases, account basic information management systems, or fund flow record platforms, etc., to acquire multi-dimensional historical transaction data.
[0149] Among them, the annotation results include, but are not limited to, information indicating whether a transaction anomaly occurs, the predicted probability value of a transaction anomaly occurring, and the type of transaction anomaly.
[0150] According to one embodiment, the training data acquisition device loads multimodal historical transaction data and performs data preprocessing. Then, the training sample data is annotated. Then, the annotated data set is divided into a training data set and a validation data set according to a certain ratio, and the divided training data set is used as the target training data.
[0151] Among them, the preprocessing includes, but is not limited to, data cleaning, data standardization, data denoising, and format conversion. The specific operations of this preprocessing have been described above and will not be elaborated here.
[0152] Among them, the annotation content includes: the category label of whether the transaction is abnormal (such as "normal" or "abnormal"), the probability value of the transaction anomaly, the specific type of the transaction anomaly, the context association label of the transaction (for example, whether it is associated with a recent promotion activity, or whether it belongs to a high-risk transaction period), etc.
[0153] Among them, dividing the data set into a training set and a validation set can monitor the accuracy of the validation set to prevent the model from overfitting.
[0154] The model result acquisition device acquires the anomaly recognition result output by the target model based on the input historical transaction data.
[0155] According to one embodiment, the target model adopts a multi-layer neural network structure, integrates the Transformer architecture to process sequence data, and is used to capture the dependencies and key feature information in transaction data. At the same time, it combines rich features extracted and constructed from the original historical transaction data, such as time features and behavioral features like transaction time and user behavior, as well as new features constructed through business knowledge and experience, such as the number of transactions in the recent period and the transaction frequency of a certain type of commodity. In addition, the target model also uses methods such as correlation analysis and chi-square test for feature selection to remove redundant and irrelevant features, so as to accurately capture the feature information highly correlated with abnormal transactions.
[0156] Among them, the input layer of the target model can receive different types of historical transaction data, including multi-modal data such as text, images, and structured data. The middle layer of the target model can include multiple Transformer encoder and decoder modules, which are used to model the time series features of transaction data, learn the timing patterns and change rules of normal transactions, and at the same time combine the advantages of other machine learning algorithms, such as the efficient processing of high-dimensional sparse data by the isolation forest algorithm, the capture of long-term dependencies by the LSTM time series prediction algorithm, the mining of complex associations between accounts by the graph neural network algorithm, and the clustering analysis of transaction data by the clustering algorithm, etc., to further enhance the ability to identify abnormal transaction patterns. The middle layer of the target model can also analyze in detail the differences in aspects such as the distribution of transaction time, the fluctuation of transaction amount, the change of transaction frequency, and the characteristics of participants for each type of transaction, and form a specific and accurate event pattern description, so that the target model can accurately distinguish different types of abnormal transactions.
[0157] The output layer of the target model outputs the recognition results of abnormal transactions according to the task requirements, such as the probability that the transaction data belongs to an abnormal transaction, the corresponding type of abnormal transaction (such as false declaration, pumping and dumping stock prices, etc.) or the abnormal risk level, etc., so as to achieve the accurate recognition and classification of abnormal transactions. At the same time, the target model is automatically iteratively updated based on new transaction data, can timely adapt to the changes in abnormal transaction patterns, continuously optimize the model performance, and further improve the accuracy and reliability of abnormal recognition.
[0158] According to one embodiment, the device selects a machine learning algorithm for model training based on the type of abnormal transaction to be recognized, so that the target model learns the feature differences between normal transactions and abnormal transactions.
[0159] Among them, the machine learning algorithm and the method of selecting the machine learning algorithm for model training have been described above and will not be elaborated here.
[0160] The model iterative update device continuously updates the target model according to the difference between the anomaly recognition result output by the target model and the actual anomaly recognition result of historical transactions until the difference meets the predetermined requirements. Specifically, through multiple iterative trainings, the loss between the anomaly recognition result obtained in each iteration and the actual anomaly recognition result is calculated, and the model parameters are updated based on the calculated loss.
[0161] Among them, the predetermined requirements include one or more conditions for judging whether the expected training effect is achieved.
[0162] Optionally, the predetermined requirements include but are not limited to at least any one of the following conditions: the value of the loss function between the predicted emotion evaluation result and the actual emotion evaluation result of the sample object is lower than the preset threshold; the value of the predetermined performance index of the model reaches the preset threshold, and the performance index includes but is not limited to accuracy rate or recall rate, etc.; the number of iterations reaches the preset number threshold.
[0163] Optionally, the device calculates the gradient of the loss function with respect to the model parameters through the backpropagation algorithm and adjusts the parameters using an optimization algorithm to minimize the loss function.
[0164] According to one embodiment, the model iterative update device adopts a method of dynamic feature selection and weight adjustment. According to the real-time changes of transaction data and the feedback of the model, one or more most relevant features are automatically selected, and during the training process, the weights of the one or more features in the target model are adjusted. For example, based on a certain feature selection algorithm, combined with the time series characteristics of transaction data, feature evaluation and screening are carried out regularly, and the feature weights in the model are updated according to the screening results. Since the trading patterns in the financial market are dynamically changing, the importance of different features for the recognition of abnormal transactions will also vary at different times. This method can improve the adaptability and recognition performance of the model.
[0165] According to one embodiment, the streaming computing engine and the target model of the embodiments of the present application are co-optimized. Among them, the method of co-optimizing the streaming computing engine and the target model has been described above and will not be elaborated here.
[0166] According to one embodiment, the device uses the divided test set to evaluate the trained target model. Among them, the evaluation methods include but are not limited to accuracy rate, recall rate, and F1 score (F1 score). Among them, the accuracy rate represents the proportion of abnormal transactions predicted correctly by the model among all transactions predicted as abnormal; the recall rate represents the proportion of abnormal transactions predicted by the model among all actual abnormal transactions; the F1 value is the harmonic mean of the accuracy rate and the recall rate. Optionally, the area under the AUC-ROC curve can also be calculated to evaluate the trained target model, and this index comprehensively considers the performance of the model at different thresholds.
[0167] For the device according to the present application, by obtaining multi-modal transaction data related to a target transaction to be detected and performing fusion processing on the feature information of each piece of data, the transaction behavior can be comprehensively analyzed from multiple dimensions, and the characteristics of abnormal transactions can be captured more accurately, effectively improving the accuracy of abnormal identification of the target transaction; the model in the embodiments of the present application is automatically iteratively updated based on new transaction data, can timely adapt to changes in abnormal transaction patterns, continuously optimize the model performance, and further improve the accuracy and reliability of abnormal identification; after obtaining the multi-modal transaction data, preliminary screening is carried out according to preset rules to filter out data with obvious transaction anomalies, improving the pertinence and efficiency of subsequent processing, avoiding interference of obvious abnormal data on the model, and helping to improve the overall identification effect; by using a streaming computing engine to perform real-time processing and analysis on the multi-modal transaction data, abnormal transactions can be discovered in a timely manner, avoiding losses caused by delays, and meeting the high requirements for real-time performance of an online transaction system; by dynamically selecting a matching streaming computing engine according to the type pattern information of the target transaction, the computing resources can be more reasonably utilized, improving the overall processing efficiency of the system and enhancing the adaptability to different types of transactions.
[0168] Based on the same inventive concept, an electronic device is further provided in the embodiments of the present application. The method corresponding to the electronic device may be the method for monitoring abnormal transactions in the foregoing embodiments, and the principle of solving problems is similar to that of this method. The electronic device provided in the embodiments of the present application includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein, the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the methods and / or technical solutions of multiple foregoing embodiments of the present application.
[0169] The electronic device may be a user device, or a device formed by integrating a user device and a network device through a network, or may also be an application program running on the above devices. The user device includes, but is not limited to, various terminal devices such as a computer, a mobile phone, a tablet computer, a smart watch, a smart bracelet, etc. The network device includes, but is not limited to, being implemented such as a network host, a single network server, a set of multiple network servers, or a computer set based on cloud computing, and can be used to implement some processing functions when setting an alarm clock. Here, the cloud is composed of a large number of hosts or network servers based on cloud computing. Among them, cloud computing is a type of distributed computing and consists of a virtual computer composed of a group of loosely coupled computers.
[0170] Figure 3The structure of a device applicable to implement the method and / or technical solution in the embodiments of the present application is shown. The device 1200 includes a central processing unit (CPU, Central Processing Unit) 1201, which can perform various appropriate actions and processes according to the program stored in the read-only memory (ROM, Read Only Memory) 1202 or the program loaded from the storage section 1208 into the random access memory (RAM, Random Access Memory) 1203. In the RAM 1203, various programs and data required for system operation are also stored. The CPU 1201, ROM 1202, and RAM 1203 are connected to each other via a bus 1204. The input / output (I / O, Input / Output) interface 1205 is also connected to the bus 1204.
[0171] The following components are connected to the I / O interface 1205: an input section 1206 including a keyboard, a mouse, a touch screen, a microphone, an infrared sensor, etc.; an output section 1207 including such as a cathode ray tube (CRT, Cathode Ray Tube), a liquid crystal display (LCD, LiquidCrystal Display), an LED display, an OLED display, etc. and a speaker, etc.; a storage section 1208 including one or more computer-readable media such as a hard disk, an optical disc, a magnetic disk, a semiconductor memory, etc.; and a communication section 1209 including a network interface card such as a LAN (Local Area Network) card, a modem, etc. The communication section 1209 performs communication processing via a network such as the Internet.
[0172] In particular, the method and / or embodiments in the embodiments of the present application can be implemented as a computer software program. For example, the embodiments disclosed in the present application include a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program contains program codes for executing the method shown in the flowchart. When the computer program is executed by the central processing unit (CPU) 1201, the above functions defined in the method of the present application are executed.
[0173] Wherein, the program includes mobile phone programs (APP programs, mini programs, etc.), smart device programs, and smart devices include watches, bracelets, helmets, smart hardware devices, etc.
[0174] Another embodiment of the present application also provides a computer-readable storage medium, on which computer program instructions are stored, and the computer program instructions can be executed by a processor to implement the method and / or technical solution of any one or more of the foregoing embodiments of the present application.
[0175] Specifically, one or more combinations of computer-readable media may be employed in this embodiment. The computer-readable media may be a computer-readable signal medium or a computer-readable storage medium. The computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the foregoing. More specific examples (a non-exhaustive list) of the computer-readable storage medium include: an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing. In this document, the computer-readable storage medium may be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device.
[0176] The computer-readable signal medium may include a data signal propagated in a baseband or as part of a carrier wave, in which computer-readable program code is carried. Such a propagated data signal may take many forms, including - but not limited to - an electromagnetic signal, an optical signal, or any suitable combination of the foregoing. The computer-readable signal medium may also be any computer-readable medium other than a computer-readable storage medium, which can send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device.
[0177] The program code contained on the computer-readable medium may be transmitted using any appropriate medium, including - but not limited to - wireless, wireline, optical fiber cable, RF, and the like, or any suitable combination of the foregoing.
[0178] The computer program code for performing the operations of this application may be written in one or more programming languages or combinations thereof. The programming languages include object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code may execute entirely on the user's computer, partially on the user's computer, as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on the remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., through the Internet using an Internet service provider).
[0179] The flowcharts or block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of devices, methods, and computer program products according to various embodiments of the present application. In this regard, each block in the flowchart or block diagram may represent a module, a segment of a program, or a part of code that contains one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than that marked in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, as well as the combinations of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system that performs the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.
[0180] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the systems, devices, and units described above can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated herein.
[0181] In several embodiments provided in the present application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division, and there may be other division methods in actual implementation. For example, multiple units or page components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the couplings or direct couplings or communication connections shown or discussed among each other can be indirect couplings or communication connections through some interfaces, devices, or units, and can be in electrical, mechanical, or other forms.
[0182] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0183] In addition, the functional units in various embodiments of the present application can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above-mentioned integrated units can be implemented in the form of hardware or in the form of a combination of hardware and software functional units.
[0184] The integrated units implemented in the form of software functional units can be stored in a computer-readable storage medium. The above-mentioned software functional units stored in a storage medium include several instructions to enable a computer device (which may be a personal computer, a server, or a network device, etc.) or a processor to execute some steps of the methods described in various embodiments of the present application. The foregoing storage medium includes: various media that can store program codes, such as USB flash drives, mobile hard disks, read-only memories (ROM), random access memories (RAM), magnetic disks, or optical discs.
[0185] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of various embodiments of the present application.
[0186] In addition, obviously, the word "including" does not exclude other units or steps, and the singular does not exclude the plural. The multiple units or devices described in the device can also be implemented by one unit or device through software or hardware. The terms such as first and second are used to represent names and do not represent any specific order.
Claims
1. A method for monitoring abnormal transactions, wherein, The method includes: In response to a transaction monitoring trigger instruction, obtaining multimodal transaction data related to a target transaction; Based on the type pattern information of the target transaction, dynamically selecting a streaming computing engine that matches the target transaction; Using the selected streaming computing engine to perform real-time data processing and analysis on the multimodal transaction data; Inputting the feature data processed by the streaming computing engine into a trained target model to obtain an anomaly recognition result output by the target model, where the target model is automatically iteratively updated based on new transaction data.
2. The method according to claim 1, wherein The using the selected streaming computing engine to perform real-time data processing and analysis on the multimodal transaction data includes: After obtaining the multimodal transaction data, preliminarily screening the multimodal transaction data according to a preset rule to filter out data with obvious transaction anomalies; For the multimodal transaction data that still needs further analysis after preliminary screening, the streaming computing engine performs feature extraction processing to obtain transaction feature data corresponding to the target transaction; Performing fusion processing on the feature information corresponding to each item of data to obtain corresponding fusion feature information.
3. The method according to claim 2, wherein, The method further includes: Based on the anomaly recognition result output by the target model, optimizing and improving the preset rule for preliminary screening of data.
4. The method according to any one of claims 1 to 3, wherein, The method further includes: Based on the transaction type of the target transaction and a preset data screening criterion, selecting multiple items of data for anomaly transaction recognition from the obtained multimodal transaction data, where the data screening criterion is automatically updated according to new transaction patterns and risk characteristics.
5. The method according to claim 1, wherein The method further includes: Based on the type pattern information of the target transaction, selecting a matching model from multiple candidate models as the target model.
6. The method according to claim 5, wherein, The target model is included in a model library, and the model library contains multiple machine learning models that are specifically trained for different transaction types or transaction patterns. The selecting a matching model from multiple candidate models as the target model based on the type pattern information of the target transaction includes: Based on the type pattern information of the target transaction, dynamically selecting a machine learning model that matches the type pattern information of the target transaction from the model library as the target model.
7. The method according to any one of claims 1 to 3, wherein The method further includes: If it is determined that the target transaction is an abnormal transaction, performing a warning process.
8. The method according to claim 7, wherein, The method further includes: Obtaining target training data, where the target training data includes multimodal historical transaction data corresponding to multiple historical transactions and their annotation results; Obtaining an anomaly recognition result output by the target model based on the input historical transaction data; According to the difference between the anomaly recognition result output by the target model and the actual anomaly recognition result of the historical transaction, continuously updating the target model until the difference meets a predetermined requirement.
9. The method according to claim 7, wherein The method further includes: Adopting a method of dynamic feature selection and weight adjustment, and automatically selecting one or more most relevant features according to the real-time changes of transaction data and the feedback of the model; During the training process, adjusting the weights of the one or more features in the target model.
10. The method according to claim 7, wherein, The method selects at least one of the following machine learning algorithms for model training based on the type of abnormal transaction to be recognized, so that the target model learns the feature differences between normal transactions and abnormal transactions: Isolation Forest algorithm; LSTM time series prediction algorithm; Graph Neural Network algorithm; Clustering algorithm.
11. A device for monitoring abnormal transactions, wherein, The device includes: A device for obtaining multimodal transaction data related to a target transaction in response to a transaction monitoring trigger instruction; A device for dynamically selecting a streaming computing engine that matches the target transaction based on the type pattern information of the target transaction; A device for performing real-time data processing and analysis on the multimodal transaction data using the selected streaming computing engine; A device for inputting the feature data processed by the streaming computing engine into a trained target model to obtain an abnormal recognition result output by the target model, where the target model is automatically iteratively updated based on new transaction data.
12. An electronic device, the electronic device includes: At least one processor; And A memory communicatively connected to the at least one processor; wherein, The memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the method according to any one of claims 1 to 10.
13. A computer-readable medium, on which computer program instructions are stored, and the computer program instructions can be executed by a processor to implement the method according to any one of claims 1 to 10.
14. A computer program product, including a computer program, and when the computer program is executed by a processor, it implements the method according to any one of claims 1 to 10.
Citation Information
Patent Citations
Real-time anti-fraud data processing method and system based on streaming computing
CN112862009A
Streaming computing technology-based abnormal transaction identification method and system
CN115631046A
Method and device for detecting transaction data
CN116228429A
Novel multi-source real-time transaction quotation data receiving and processing method
CN117575791A
Abnormal transaction data identification method and device, storage medium and electronic equipment
CN117670359A
Cited By
Lithium ion battery anomaly detection method based on stream-oriented computation
CN120652312A
Online payment information reminding method and system
CN121034041A
Emission right transaction guiding method
CN121961497A
Abnormal recognition method and device, storage medium and electronic equipment
CN121981731A