Anti-money laundering detection method based on graph neural network
Through the feature-enhanced graph attention network (FEGAT) detection method based on graph neural network, the problems of inefficient anti-money laundering detection and limited recognition capabilities in the prior art are solved, and efficient identification and real-time monitoring of complex money laundering patterns are achieved, which is suitable for diversified financial scenarios.
Patent Information
- Application Number
- CN202510747896.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-06
- Publication Date
- 2025-07-04
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The existing technology relies on manual review in anti-money laundering detection, which is difficult to deal with complex and hidden money laundering models, and rules-based and machine learning methods ignore transaction network structure and spatiotemporal characteristics, resulting in limited recognition capabilities.
The anti-money laundering detection method based on graph neural network is adopted to construct bank transfer transaction data into a topological graph, and the feature enhancement graph attention network (FEGAT) is used for detection. The account and transaction characteristics are aggregated through the two-layer FEGAT network structure and attention mechanism, and combined with multi-time slice data analysis, money laundering behavior identification is carried out.
It significantly improves the recognition accuracy of money laundering behavior, reduces missed detection and misjudgment, can handle dynamic timing data, is suitable for real-time monitoring of large-scale transaction data, enhances the robustness of the model and the representation ability of complex transaction networks, and supports the detection needs of diversified financial scenarios.
Smart Images

Figure CN120258992A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of data processing, and particularly relates to an anti-money laundering detection method based on a graph neural network. Background Art
[0002] Traditional detection means need to consume a large amount of manpower and material resources to identify suspicious transactions from a vast amount of transactions, and are prone to interfering with normal financial activities, making financial institutions have concerns in anti-money laundering implementation; on the other hand, criminals' modus operandi are constantly renovated, and they use concealed methods such as splitting large transactions into multiple small transactions and using complex fund transfer channels to avoid detection, further increasing the difficulty of anti-money laundering.
[0003] Currently, the mainstream money laundering detection technology of financial institutions highly relies on manual review. However, manual review is easily interfered by human factors such as the experience, fatigue, and prejudice of reviewers, resulting in the omission or misjudgment of money laundering behaviors, and occupying a large amount of human resources with low detection efficiency. In addition, rule-based models are difficult to cope with the emerging new money laundering routines, further limiting their effectiveness.
[0004] The Risk Monitoring Service Center of China UnionPay Electronic Payment Research Institute adopts big data correlation tracing technology solutions and abnormal transaction community discovery solutions, which are respectively used for the reverse investigation of known cases and the active discovery of abnormal money laundering behaviors, and finally presents criminal groups in the form of subgraphs. Although this method has achieved certain results, there is still a problem of relatively large labor costs.
[0005] In view of the defects of traditional methods, machine learning technology is applied to the field of money laundering detection. For example, decision trees, support vector machines (SVMs), deep learning algorithms, etc. are used to construct money laundering detection models. Domestic scholars such as Dong Guang et al. proposed a money laundering detection algorithm based on improved minimum spanning tree clustering, Shen Jie et al. adopted decision tree algorithms, and Zheng Yingfei et al. proposed a human-machine coupling model for anti-money laundering monitoring systems and used random forest algorithms. These solutions mostly extract features for single transactions (such as transaction amounts, locations and occupations of both parties to the transaction, etc.), and then use models for classification. In the field of anti-money laundering detection of cryptocurrencies such as Bitcoin, Elliptic company has constructed the world's largest labeled transaction dataset, providing important support for researchers. Multiple research teams have effectively improved the detection ability of money laundering behaviors by applying technologies such as graph convolutional networks, self-supervised graph representation learning, graph neural networks, and graph substructure networks. However, the above-mentioned machine learning-based money laundering detection solutions are limited to the extraction and analysis of single transaction features, ignoring the key topological features contained in the transaction network structure, resulting in limited types of money laundering recognized, and rarely comprehensively considering the spatio-temporal characteristics of transactions, making it difficult to play a role in long-term and complex money laundering detection tasks, and being unable to cope with the increasingly concealed and dynamically changing money laundering patterns. Therefore, the present invention proposes an anti-money laundering detection method based on a graph neural network. Summary of the Invention
[0006] The purpose of the present invention is to provide an anti-money laundering detection method based on a graph neural network, aiming to solve the problems raised in the above-mentioned background technology.
[0007] The purpose of the present invention is achieved through the following technical solutions: An anti-money laundering detection method based on a graph neural network constructs a topological graph from bank transfer transaction data, with accounts as nodes and transactions as edges, and uses the FEGAT network to detect money laundering behavior. The specific steps are as follows: Step 1: Data preparation and input; Divide the bank transfer transaction data into two parts: account information data and transaction data, and divide the data labels according to time slices; Step 2: Node feature generation; Split the graph data according to the number of features on the edges, calculate the attention weights on each edge, perform node feature aggregation, and splice the aggregated node features in each dimension to obtain the output; Step 3: Construct a two-layer FEGAT network; Adopt a two-layer FEGAT network structure. The first layer of the FEGAT network uses a multi-head attention mechanism, and the second layer of the FEGAT network uses a single attention head. Update the two-layer FEGAT network through a formula, and the input edge features of the two-layer FEGAT network are the same; Step 4: Data statistics and normalization processing; Perform data statistics on the time slices input to the model, accumulate the node and edge features respectively, and then perform normalization processing on the node and edge features; the edge features are subjected to two normalization processes; Step 5: Classification output; The output data of the two-layer FEGAT network is input to the fully connected layer after the normalization processing in Step 4. Use an activation function to activate the output of the fully connected layer, and use the LogSoftmax function to convert the activated result into a probability distribution. Determine whether the account is involved in money laundering behavior by judging whether the probability exceeds the threshold, and complete the detection task.
[0008] Furthermore, the specific process of Step 1 is as follows: Divide the bank transfer transaction data into account information data and transaction data into two parts; the account information data , representing T the account information of N time slices, with D accounts under each time slice, and each account has its own dimensional features; the transaction data TTransaction information for each time slice, where each time slice is a N*N adjacency matrix, and the matrix elements are also e dimensional vectors, representing the transaction information between two nodes; The data label is divided by time slice, that is , and the value of the data label is 0 or 1; The input of the model within a single time slice is a sequence of length l , that is, at time t , the input account information data is , the input transaction data is , the data label is , and it is determined whether the account is involved in money laundering at this moment through a sequence of historical transaction data of length l .
[0009] Furthermore, the specific steps of step 2 are as follows: Step 21: Data preprocessing; After inputting the graph data, it is split according to the number of edge features, that is E types of features are split into E subgraphs, and the edge features of each subgraph are only 1-dimensional; Assume that the edge features have E dimensions, and the transaction data A is split into E N*N adjacency matrices, that is , the matrix structures are the same and the positions of non-zero values are the same; Step 22: Attention weight calculation and node feature aggregation; For each adjacency matrix, calculate the attention weight on each edge respectively, and apply the attention weight on each edge to node feature aggregation. Specifically, as shown in equations 1-3: Equation 1: ; Equation 2: ; Equation 3: ; In the equations, is the output of the th layer; is the activation function; is matrix concatenation operations; is the edge weight calculation function, and the detailed calculation is shown in Equation 2; is the output of the th layer; is the weight matrix; is node and node Edge weight calculation function between; Is an exponential function; Represents the attention network layer; Is the point in the e-th dimension And node The transaction data between, that is, the edge value between nodes; Is the attention coefficient; Is a vector; Is the transpose; Is the attention weight matrix, l Represents the l Layer, e Represents the e Dimensional edge feature.
[0010] Furthermore, in step 22, the specific process of attention weight calculation is as follows: First, perform a linear transformation on the features of the graph nodes, that is, multiply by the weight matrix , to obtain a new feature representation; Then calculate the node assignment weight matrix f , the specific process is as follows: For the calculation process of the weight between each two edges: first, splice the node features after feature transformation at both ends of the edge, and then multiply the spliced features by the attention weight matrix to obtain a new vector, multiply the obtained new vector by the vector to obtain the attention coefficient ; use the activation function to activate the attention coefficient , then scale it with the exponential function, and finally multiply by the eigenvalue of the edge under the dimension to obtain the e Dimensional i And j Weight between nodes; Perform the same calculation on all edges in the graph in the same way as calculating the weight between each two edges, and finally obtain the entire weight matrix f ; The specific process of node feature aggregation is: multiply the weight matrix f by the node features after feature transformation to aggregate the features of the neighbor nodes of the node with a certain weight; perform feature aggregation in other dimensions in the same way. After completing the feature aggregation in all dimensions, output E aggregated node features; splice the E aggregated node features to obtain the final output result.
[0011] Furthermore, in step 3, the update methods of the two-layer FEGAT network are shown in Equations 4 and 5: Equation 4: ; Equation 5: ; In the formula, is the output of the second layer; represents a matrix splicing operation; is the layer's graph convolutional layer; is the network output result; is a single-layer graph convolutional layer, and the input is and the transaction data graph .
[0012] Furthermore, the specific steps of step 4 are as follows: Step 41: Data statistics; For several time slices input into the model, perform statistical operations; for the node itself, accumulate its features in each time slice; for the edges between nodes, also accumulate their features to obtain the graph data for the overall time period; Step 42: Normalization processing; Node feature normalization: For node i , after calculating the sum of its features, divide all features by this sum of features so that the sum of the new features is 1; Equation 6: ; In the formula, is the normalized feature of node i relative to ; is the matrix the value at position ; N is the number of nodes; k is the matrix column index; is the matrix the value at position ; Edge feature normalization: Normalize each dimension of the edge features separately, and the formula is as follows: Equation 7: ; Equation 8: ; Equation 9: ; In the formula, is the normalized value at position in the matrix ; is the matrix the original value at position ; is the matrix the value at position value; is the new adjacency matrix; is the preliminary normalization result matrix; is the identity matrix; is the edge feature after final normalization; is the matrix at position original value; is the matrix at position original value.
[0013] Furthermore, the specific process of the edge feature normalization step is as follows: First, calculate the sum of the features of the edges starting from node i , then divide the corresponding features by the calculated feature sum to obtain an adjacency matrix with a diagonal of 0; Next, add the identity matrix I and the obtained adjacency matrix with a diagonal of 0 to get the new adjacency matrix ; After that, find the sum of the features of the corresponding edges starting from node i , and then divide each feature corresponding to the edges starting from node in by the calculated feature sum, so that the feature sum of each edge starting from node i becomes 1. i
[0014] Compared with the prior art, the beneficial effects of the present invention are as follows: Improve the accuracy of money laundering behavior recognition: The present invention significantly enhances the model's ability to recognize complex money laundering patterns and reduces missed detections and misjudgments by simultaneously aggregating account (node) features and transaction (edge) features and dynamically quantifying the importance of key transaction paths through the attention mechanism.
[0015] Effectively process dynamic time-series data: The present invention supports the analysis of multi-time-slice historical transaction data. Through time-slice sequence input and feature accumulation statistics, it can learn the modus operandi of criminals in the long term and identify hidden money laundering behaviors across time periods.
[0016] Enhance the representation ability of complex transaction networks: The present invention uses a feature-enhanced graph attention mechanism to fully extract heterogeneous information in the transaction network through edge feature splitting and multi-dimensional feature splicing, improving the model's processing effect on high-dimensional and unstructured data.
[0017] Improve detection efficiency and real-time performance: The present invention controls the computational complexity while ensuring the feature expression ability through an optimized two-layer network structure, meeting the real-time monitoring requirements of large-scale bank transaction data.
[0018] Enhance model robustness: Through the normalization of node and edge features, the present invention eliminates the data scale difference; the two-time normalization of edge features effectively avoids weight anomalies and improves the anti-interference ability of the model against noisy data.
[0019] Support diverse financial scenarios: The present invention supports the joint modeling of account features and transaction features and is applicable to the money laundering detection requirements of different types of transaction networks. Brief Description of the Drawings
[0020] Figure 1 It is a flowchart of the method of the present invention.
[0021] Figure 2 It is a structural diagram of a two-layer FEGAT network. Detailed Embodiment
[0022] For a clearer understanding of the technical features, objectives, and beneficial effects of the present invention, the technical solution of the present invention will be described in detail below, but it should not be construed as a limitation on the implementable scope of the present invention.
[0023] Bank transfer transactions can form a topological graph, with nodes being accounts and edges being transactions. Identifying money laundering crimes requires analyzing information such as the accounts themselves, the transaction counterparts of the accounts, and the transactions between accounts. For this reason, the present invention proposes an anti-money laundering detection method based on a graph neural network, called Feature Enhanced Graph Attention Network (FEGAT). Compared with conventional graph neural networks (GNNs), FEGAT can simultaneously and selectively aggregate account features and transaction features in a transaction network, thereby maximizing the extraction of information in the network and enhancing the feature expression of the model. The method includes the following steps (as Figure 1 shown): Step 1: Data preparation and input; Divide the bank transfer transaction data into account information data and transaction data in two parts. The account information data , representing T the account information of N time slices, with D accounts in each time slice, and each account having
[0024] its own -dimensional features. Its main features include the initial amount of the account, the number of other accounts with which the account transacts within this time slice, the number of transactions, the total amount of transactions, etc. T The transaction data N*Nadjacency matrix, but the elements in the matrix are also a e -dimensional vector, representing the transaction information between two nodes, such as the amount and the number of transactions. For the convenience of subsequent calculations, it is stipulated that this vector is either all zero or all non-zero. In addition, the data label is also divided by time slices, that is . Since this is a binary classification supervised learning task, the value of the data label is 0 or 1. Among them, represents the dimension of the data label is .
[0025] The input of the model within a single time slice is a sequence of length l . That is, at time t , the input account information data is , the input transaction data is , and the data label is . This is equivalent to judging whether the account is involved in money laundering at this moment through a historical transaction data sequence of length l .
[0026] Step 2: Node feature generation (single-layer FEGAT operation), the specific steps are as follows: Step 21: Data preprocessing; After inputting the graph data, it is split according to the number of edge features, that is E types of features are split into E subgraphs, and each subgraph has only 1-dimensional edge features. When aggregating the features of these subgraphs, the attention weight on each edge is multiplied by the feature value on that edge. After processing several subgraphs, all the node features are concatenated.
[0027] Assume that the edge feature has E dimensions, and the transaction data A is split into E adjacency matrices of N*N , that is . These matrix structures are the same and the positions of non-zero values are also the same.
[0028] Step 22: Attention weight calculation and node feature aggregation; For each adjacency matrix, calculate the attention weight on each edge respectively, and apply it to the node feature aggregation, as shown in equations 1-3 specifically: Equation 1: ; Equation 2: ; Equation 3: ; In the formula, is the Layer output; is the activation function; is a matrix concatenation operation; is the edge weight calculation function, and the detailed calculation is shown in Equation 2; is the layer output; is the weight matrix; is the edge weight calculation function between node and node ; is the exponential function; represents the attention network layer; is the transaction data between the point in the e-th dimension and node , that is, the edge value between nodes; is the attention coefficient; is a vector; is the transpose; is the attention weight matrix, l represents the l layer, e represents the e -dimensional edge feature.
[0029] (1) The specific process of calculating the attention weight is as follows: First, perform a linear transformation on the features of the graph nodes, that is, multiply by the weight matrix to obtain a new feature representation.
[0030] Then calculate the node assignment weight matrix f , and the specific process is as follows: For the calculation process of the weight between each two edges: first, concatenate the node features after feature transformation at both ends of the edge, and then multiply the concatenated features by the attention weight matrix to obtain a new vector. Multiply the obtained new vector by the vector to obtain the attention coefficient . Different from traditional graph neural networks, this method adds the operation of multiplying by the attention weight matrix to handle complex information and make the judgment of the importance of edges have a more complex decision logic. Use the activation function (such as the ReLU function) to activate the attention coefficient , then scale it with the exponential function, and finally multiply by the eigenvalue of the edge in this dimension to obtain the weight between the e -dimensional i and j nodes.
[0031] Calculate all the edges in the graph in the same way as calculating the weight between each two edges above, and finally obtain the entire weight matrixf 。
[0032] (2) The specific process of node feature aggregation is as follows: Multiply the weight matrix f with the node features after feature transformation to aggregate the features of the neighbor nodes of the node with a certain weight. At this time, the feature aggregation of this dimension is completed, and the same applies to other dimensions. Given that there are E dimensions of edge features, after completing the feature aggregation of all dimensions, E aggregated node features will be output. Concatenate the E aggregated node features to obtain the final output result.
[0033] Step 3: Construct a two-layer FEGAT network; The above is the structure of a single-layer FEGAT network. The present invention adopts a two-layer FEGAT network structure, as shown in Figure 2 . On the one hand, this structure can ensure an effective node aggregation effect, and on the other hand, it can avoid the over-smoothing problem to a certain extent. There are obvious differences between the two-layer neural network. The first-layer FEGAT uses the multi-head attention mechanism. Taking 5 attention heads as an example, each attention head will output a round of nodes, and then the 5 groups of outputs are concatenated as the input of the second-layer FEGAT, and the edge information between the nodes remains unchanged. The second-layer FEGAT only sets one attention head. Doing so can avoid the exponential growth of the feature dimension on the one hand, and on the other hand, it is because the output of the second-layer FEGAT usually needs to be input into a classifier (the classifier includes a fully connected layer).
[0034] Therefore, the update methods of the two-layer FEGAT network are shown in Equations 4 and 5: Equation 4: ; Equation 5: ; In the formula, is the output of the second layer; represents matrix concatenation operations; is the graph convolutional layer of the layer; is the network output result; is a single-layer graph convolutional layer, and the input is and the transaction data graph .
[0035] That is, in the first layer, there are H individual GNN layers. They receive the same input and each generate different outputs. These outputs are concatenated and become the input of the second-layer GNN. The same edge features are used for the inputs of the two-layer GNN, that is, the edge features do not change.
[0036] Step 4: Data Statistics and Normalization, the specific steps are as follows: Step 41: Data Statistics; For several time slices of the input model, data statistics will be performed on them to obtain graph data for an overall time period. The statistical method for this data is similar to sum pooling. For the nodes themselves, the features of the node within these time slices are accumulated, and then a normalization operation is used to make the sum of the features of each node equal to 1. For the edges between nodes, their features are also accumulated and then a normalization operation is applied to them.
[0037] Step 42: Normalization; The normalization method for the data is shown in Equations 6 - 9.
[0038] Node Feature Normalization: For node i , after calculating the sum of its features, all features are divided by this sum of features so that the sum of the new features is 1.
[0039] Equation 6: ; In the formula, is the feature of the normalized node i relative to ; is the value at position in matrix ; N is the number of nodes; k is the column index of the matrix; is matrix at position ; Edge Feature Normalization: Each dimension of the edge features is normalized separately, and the formula is as follows: Equation 7: ; Equation 8: ; Equation 9: ; In the formula, is the normalized value at position in matrix ; is the original value at position in matrix ; is the value at position in matrix ; is the new adjacency matrix; is the preliminary normalization result matrix; is the identity matrix; is the finally normalized edge feature; is a matrix at the position of the original value; is a matrix at the position of the original value.
[0040] The specific operation of edge feature normalization is as follows: First, calculate the sum of the features of the edges starting from node i and then divide the corresponding features by the sum of the features calculated in this step. After such an operation, an adjacency matrix with a diagonal of 0 is obtained. This is because there is no transfer operation from oneself to oneself, so there is no edge from oneself to oneself.
[0041] Next, add the identity matrix I and the obtained adjacency matrix with a diagonal of 0 to get a new adjacency matrix ; After that, perform the same normalization operation on (that is, calculate the sum of the features of the corresponding edges in i starting from node and then divide each feature corresponding to the edges starting from node in i by the sum of the features calculated in this step), so that the sum of the features of each edge (including the edge from oneself to oneself) starting from node i becomes 1.
[0042] The reason for performing the normalization operation twice is that the data range of the original edge features is often uncertain. If the normalization is directly performed after adding the identity matrix and the adjacency matrix, then in the obtained new matrix, the elements on the diagonal may be too large or too small. The ultimate consequence is that when the model performs feature aggregation, the weight of the node itself explodes or disappears, resulting in the loss of its own information or the information of neighboring nodes.
[0043] Step 5: Classification and output; The output data of the two-layer FEGAT network is directly input into the fully connected layer after being normalized in Step 4. The output dimension of the fully connected layer is the number of label types of the data. Then, the output of the fully connected layer is activated using an activation function, and the LogSoftmax function is used to convert the activated result into a probability distribution. Finally, the specific classification result is obtained. It is determined whether the account is involved in money laundering by judging whether the probability exceeds the threshold of 0.5, thus completing the entire money laundering detection task.
[0044] The following describes the specific implementation of the present invention in detail with reference to specific embodiments.
[0045] Example 1: In this example, AMLSim anti-money laundering data simulator from IBM Watson Laboratory is used to generate experimental data. For the convenience of the experiment, the amount of generated data is controlled. Among the entire transaction data, there are more than 12,000 accounts, of which about 700 accounts are suspected of money laundering. The time span of the transaction data is about 2 years. According to the occurrence dates of all transactions, it is divided into 340 time slices at an interval of two days. During this period, a total of about 150,000 transactions occurred, of which more than 600 transactions are suspected of money laundering crimes.
[0046] This example aims to conduct a comparative test on the performance of FEGAT and other graph neural network models. The data used in the test is the statistical data of all-time transaction data. To ensure the fairness of the comparison of each model, the same hyperparameters are used for the tested graph neural network models. The specific hyperparameter settings are as follows: the number of neurons in the middle layer neural network is uniformly 128; the number of model iterations is 1000; the activation function uses the ELU function with its alpha parameter being 1; the model dropout rate is 0.1; the initial learning rate is 0.001; the part involving attention uniformly uses 3 attention heads. In addition, each graph neural network model additionally uses the XGBoost model for the final classification task, and the relevant parameters of XGBoost are set as follows: step size 0.1; maximum depth 20; the subsample used to train the model accounts for 70% of the entire sample set; the proportion of randomly sampling features is 0.7. The comparative experimental results are shown in Table 1: Table 1 Comparative Experimental Results of FEGAT
[0047] Note: The bold numerical values in Table 1 represent the optimal values of each index, and the underlined numerical values represent the sub-optimal values of each index.
[0048] From the data in Table 1, it can be seen that FEGAT achieves a better balance between precision and recall and obtains the highest F1 scores, which are 0.6002 (without combining the XGBoost model) and 0.6226 (combining the XGBoost model) respectively. If only analyzing the graph neural network itself and combining with the performance of FEGAT in the experiment, it can be considered that FEGAT in the present invention successfully realizes the aggregation of graph node information.
[0049] The above is only the preferred implementation manner of the present invention. It should be noted that for those skilled in the art, without departing from the concept of the present invention, several deformations and improvements can still be made, which should also be regarded as the protection scope of the present invention, and these will not affect the implementation effect of the present invention and the practicality of the patent.
Claims
1. An anti-money laundering detection method based on graph neural network, characterized in that, Construct the bank transfer transaction data into a topological graph, with accounts as nodes and transactions as edges, and use the FEGAT network to detect money laundering behavior, which specifically includes the following steps: Step 1: Data preparation and input; Divide the bank transfer transaction data into two parts: account information data and transaction data, and divide the data labels according to time slices; Step 2: Node feature generation; Split the graph data according to the number of features on the edges, calculate the attention weights on each edge, perform node feature aggregation, and splice the node features aggregated in each dimension to obtain the output; Step 3: Construct a two-layer FEGAT network; Adopt a two-layer FEGAT network structure. The first-layer FEGAT network uses a multi-head attention mechanism, and the second-layer FEGAT network uses a single attention head. Update the two-layer FEGAT network through formulas, and the input edge features of the two-layer FEGAT network are the same; Step 4: Data statistics and normalization processing; Perform data statistics on the time slices input to the model, accumulate the node and edge features respectively, and then perform normalization processing on the node and edge features; the edge features are normalized twice; Step 5: Classification output; The output data of the two-layer FEGAT network is input to the fully connected layer after the normalization processing in Step 4. Use an activation function to activate the output of the fully connected layer, and use the LogSoftmax function to convert the activated result into a probability distribution. Determine whether the account is involved in money laundering behavior by judging whether the probability exceeds the threshold, and complete the detection task.
2. The anti-money laundering detection method based on a graph neural network according to claim 1, wherein, The specific process of the above Step 1 is as follows: Divide the bank transfer transaction data into account information data and transaction data into two parts; the account information data , representing T the account information of a time slice, with N accounts under each time slice, and each account has D dimensional features; Transaction data represents T transaction information for time slices, and each time slice is an N*N adjacency matrix, and the matrix elements are simultaneously e dimensional vectors, representing the transaction information between two nodes; the data label is divided by time slice, that is , and the value of the data label is 0 or 1; The input of the model within a single time slice is a sequence of length l , that is, at time t , the input account information data is , the input transaction data is , the data label is , and a historical transaction data sequence of length l is used to determine whether the account is involved in money laundering at this moment.
3. The anti-money laundering detection method based on graph neural network according to claim 1, wherein The specific steps of the above Step 2 are as follows: Step 21: Data preprocessing; After inputting the graph data, it is split according to the number of edge features, that is E types of features are split into E subgraphs, and the edge features of each subgraph are only 1-dimensional; Assume that the edge features have E dimensions, and the transaction data A is split into E adjacency matrices of N*N , that is, , with the same matrix structure and the same positions of non-zero values; Step 22: Attention weight calculation and node feature aggregation; For each adjacency matrix, calculate the attention weights on each edge respectively, and apply the attention weights on each edge to node feature aggregation, as shown in Formulas 1 to 3 specifically: Formula 1: ; Formula 2: ; Formula 3: ; In the formula, is the output of the th layer; is the activation function; is a matrix splicing operation; is the edge weight calculation function; is the output of the th layer; is the weight matrix; is the and node edge weight calculation function between; is the exponential function; represents the attention network layer; is the and node transaction data between, that is, the edge value between nodes; is the attention coefficient; is a vector; is the transpose; is the attention weight matrix, l represents the l th layer, e represents the e dimensional edge feature.
4. The anti-money laundering detection method based on graph neural network according to claim 3, characterized in that, In the above Step 22, the specific process of attention weight calculation is as follows: First, perform a linear transformation on the features of the graph nodes, that is, multiply by the weight matrix , to obtain a new feature representation; Then calculate the node allocation weight matrix f , and the specific process is as follows: The calculation process for the weight between each pair of edges is as follows: First, the node features after feature transformation at both ends of the edge are concatenated, and then the concatenated features are multiplied by the attention weight matrix to obtain a new vector. Multiply the obtained new vector by the vector to obtain the attention coefficient ; activate the attention coefficient using an activation function , then scale it using an exponential function, and finally multiply it by the eigenvalue of the feature under the dimension to obtain the weight between the e -dimensional i and j nodes; Perform the same calculation on all the edges in the graph according to the method of calculating the weight between every two edges, and finally obtain the entire weight matrix f ; The specific process of node feature aggregation is as follows: Multiply the weight matrix f by the node features after feature transformation to aggregate the features of the neighbor nodes of the node with a certain weight; perform feature aggregation for other dimensions in the same way. After completing the feature aggregation for all dimensions, output E aggregated node features; Concatenate E aggregated node features to obtain the final output result.
5. The anti-money laundering detection method based on graph neural network according to claim 1, wherein, In the above Step 3, the update methods of the two-layer FEGAT network are as shown in Formulas 4 and 5: Formula 4: ; Formula 5: ; Wherein, is the output of the second layer; represents a matrix splicing operation; is the graph convolutional layer of the is the network output result; is a single-layer graph convolutional layer, and the input is and the transaction data graph .
6. The anti-money laundering detection method based on graph neural network according to claim 1, wherein, The specific steps of the above Step 4 are as follows: Step 41: Data statistics; For several time slices input to the model, perform statistical operations; for the node itself, accumulate its features in each time slice; for the edges between nodes, also accumulate its features to obtain the graph data for the overall time period; Step 42: Normalization processing; Node feature normalization: For node i , after calculating the sum of its features, divide all features by the sum of features so that the sum of the new features is 1; Formula 6: ; Wherein, is the normalized node i relative to characteristics; is the matrix in the position value; N is the number of nodes; k is the matrix column index; is the matrix in the position value; Edge feature normalization: Normalize each dimension of the edge features respectively, and the formula is as follows: Formula 7: ; Formula 8: ; Formula 9: ; In the formula, is the normalization value at position in matrix ; is the original value at position in matrix ; is the value at position in matrix ; is the new adjacency matrix; is the preliminary normalization result matrix; is the identity matrix; is the edge feature after final normalization; is the original value at position in matrix ; is the original value at position in matrix .
7. The anti-money laundering detection method based on graph neural network according to claim 6, wherein, The specific process of the above edge feature normalization step is as follows: First, calculate the sum of the features of the edges starting from the node i and then divide the corresponding feature by the calculated feature sum to obtain an adjacency matrix with a diagonal of 0; Next, add the identity matrix I to the obtained adjacency matrix with a diagonal of 0 to obtain a new adjacency matrix ; After that, calculate the sum of the features of the corresponding edges in i starting from . Then, divide the feature of each edge starting from from node i by the calculated feature sum, so that the feature sum of each edge starting from i becomes 1.
Citation Information
Patent Citations
Anti-money laundering suspicious transaction data monitoring method and device
CN114238414A
Bank anti-money laundering monitoring method and system based on graph neural network
CN119809660A