Financial transaction anti-fraud system based on artificial intelligence
Through the anti-fraud system of financial transactions based on artificial intelligence, templates are generated, knowledge graphs are constructed and knowledge graphs are carried out and in-depth analysis is solved, and the problems of inaccurate feature extraction and low recognition efficiency in the existing technology are achieved, and efficient anti-fraud detection of complex financial transaction scenarios is achieved.
Patent Information
- Application Number
- CN202510764584.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-10
- Publication Date
- 2025-07-08
- Estimated Expiration
- 2045-06-10
AI Technical Summary
The existing anti-fraud methods for financial transactions are not high in data quality, inaccurate feature extraction, and poor generalization capabilities of model, resulting in unsatisfactory identification results and low query efficiency, making it difficult to deal with complex and diverse financial transaction scenarios.
Adopt the anti-fraud system of financial transactions based on artificial intelligence, generate anti-fraud templates through the generation module, build a knowledge graph, obtain user transaction data, extract features and query the knowledge graph to determine anti-fraud information, and use association rule learning and named entity recognition technology for in-depth analysis.
It improves the accuracy and identification efficiency of feature extraction, significantly improves the detection ability of advanced attacks such as gang fraud and complex cash outs, realizes the transformation from manual experience to data intelligence, and improves the adaptability and operation and maintenance efficiency of anti-fraud rules.
Smart Images

Figure CN120278722A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of financial transaction anti-fraud, and particularly relates to an artificial intelligence-based financial transaction anti-fraud system. Background Art
[0002] With the rapid development of fintech and the continuous expansion of the space for financial transaction services, financial transaction behaviors have become increasingly complex and diverse, and at the same time, the risk of fraud has increased. Traditional anti-fraud means often rely on manual review and rule judgment, and it is difficult to cope with large-scale and high-frequency modern financial transaction scenarios. Therefore, how to effectively identify and prevent fraud behaviors in financial transactions and ensure the healthy and stable development of the financial market has become an urgent problem to be solved in the current financial industry. However, when dealing with financial transaction data, existing anti-fraud transaction identification methods often face problems such as low data quality, inaccurate feature extraction, and weak model generalization ability, resulting in unsatisfactory identification effects. At the same time, when determining anti-fraud information based on the extracted features, the query efficiency is low and the identification efficiency is low. Summary of the Invention
[0003] The present invention aims to solve at least one of the technical problems in the above technologies to some extent. For this purpose, the object of the present invention is to propose an artificial intelligence-based financial transaction anti-fraud system to improve the accuracy of feature extraction and, when determining anti-fraud information based on the extracted features, improve the identification efficiency and identification effect.
[0004] To achieve the above object, an embodiment of the present invention proposes an artificial intelligence-based financial transaction anti-fraud system, including: A generation module, configured to generate a financial transaction anti-fraud template; A construction module, configured to construct a knowledge graph based on the financial transaction anti-fraud template; An acquisition module, configured to acquire financial transaction data of a user; A first extraction module, configured to extract features from the financial transaction data to obtain transaction features; A first determination module, configured to query the knowledge graph according to the transaction features to determine financial transaction anti-fraud information.
[0005] According to some embodiments of the present invention, the generation module includes: A second determination module, configured to formulate an anti-fraud strategy based on fraud data in a fraud database and determine an anti-fraud rule according to the formulated anti-fraud strategy; the anti-fraud rule includes a rule for scoring, a rule for weights, a rule for danger levels, and a rule for strategy flows; A configuration module, configured to configure the operating conditions of the anti-fraud rule, and after the configuration is completed, configure the execution order of the anti-fraud rule to obtain a configuration result; wherein, the execution order includes sequential execution and traversal execution; A test module, configured to obtain sample data, perform a logical test on the configuration result, and determine a financial transaction anti-fraud template according to the test result.
[0006] According to some embodiments of the present invention, a construction module includes: A second extraction module, configured to extract anti-fraud features of a financial transaction anti-fraud template; A third determination module, configured to determine label information of a financial transaction anti-fraud template according to the anti-fraud features; An integration module, configured to perform data integration on each financial transaction anti-fraud template based on the label information, and construct a knowledge graph based on the integration result.
[0007] According to some embodiments of the present invention, the second extraction module includes: An aggregation module, configured to: Classify and aggregate based on the functional features of the anti-fraud behavior constituent elements included in the financial transaction anti-fraud template to form the basic functional categories of the anti-fraud behavior constituent elements as the functional layer; Classify and aggregate based on the interaction features of the anti-fraud behavior constituent elements included in the financial transaction anti-fraud template to form the basic association categories of the anti-fraud behavior constituent elements as the association layer; Classify and aggregate based on the data features of the anti-fraud behavior constituent elements included in the financial transaction anti-fraud template to form the basic logical categories of the anti-fraud behavior constituent elements as the logical layer; A fourth determination module, configured to generate a data analysis model according to the functional layer, the association layer, and the logical layer, determine the types of entities involved in the data analysis model and the corresponding attributes, and determine user behavior features, device environment features, transaction network features, and time series features based on the types of entities and the corresponding attributes; and form anti-fraud features based on the user behavior features, device environment features, transaction network features, and time series features.
[0008] According to some embodiments of the present invention, the user behavior features include transaction patterns, account operations, and risk associations; the device environment features include device fingerprints, network environments, and emulator detections; the transaction network features include fund flows, relationship networks, and address features; and the time series features include behavior time sequences and event intervals.
[0009] According to some embodiments of the present invention, the transaction patterns include the discreteness of transaction amounts, the proportion of night transactions, and the number of high-frequency small-amount exploratory transactions; The account operations include the login failure rate, the password modification frequency, and the number of emergency contact changes; The risk associations include the number of associated account fraud labels, the number of blacklist device matches, and the proportion of high-risk merchant transactions; The device fingerprint includes the number of times the device ID has changed and the entropy value of the canvas fingerprint; The network environment includes the proxy IP score and the WiFi base station switching rate; The emulator detection includes the number of emulator feature hits; The fund flow includes the score of the fund transfer station and the depth of the fund closed-loop; The relationship network includes the community fraud density and the shortest path to the black node; The address feature includes the frequency of change of the receiving address and the distance between the IP and the GPS; The behavior time series includes the entropy of the login time distribution and the interval from registration to the first transaction; The event interval includes the interquartile range ratio of the transaction interval and the number of transaction bursts within 5 minutes.
[0010] According to some embodiments of the present invention, the first extraction module includes: The fifth determination module is used for: Generating a transaction link based on financial transaction data, determining the attention weight coefficient between nodes in the transaction link for each time period, and performing normalization processing on the attention weight coefficient to obtain a normalized attention weight coefficient; Generating node structure features based on the normalized attention weight coefficient by graph attention weighted aggregation of adjacent node features; Capturing the behavior pattern of nodes in the time dimension in the transaction link, extracting time series statistical features, and determining node time series features based on Transformer encoding of time series dependencies; The splicing module is used to splice the node structure features and the node time series features, and adaptively adjust the contribution degrees of the two types of features based on the gating mechanism to obtain transaction features.
[0011] According to some embodiments of the present invention, the first determination module includes: The first detection module is used to detect entity features for transaction features by using named entity recognition technology; The second detection module is used for: Detecting the corresponding target entity in the knowledge graph according to the entity features through entity linking; Determining the subgraph information of the target entity in the knowledge graph, and determining financial transaction anti-fraud information according to the subgraph information.
[0012] According to some embodiments of the present invention, the second detection module determines the subgraph information of the target entity in the knowledge graph through the shortest path algorithm.
[0013] According to some embodiments of the present invention, the second detection module determines the subgraph information of the target entity in the knowledge graph, including: Determine the size of the recognition sliding window in the knowledge graph based on the number of target entities, and slide based on the recognition sliding window to obtain a number of sliding images; Determine the central pixel point of the sliding image; calculate the centralized coordinates of each pixel point in the sliding image relative to the central pixel point; Determine the gradient direction of each pixel point in the sliding image; Among them, is the gradient direction of the pixel point; is the horizontal gradient value; is the vertical gradient value; Rotate the centralized coordinates by angle according to the gradient direction of the pixel point to obtain coordinates aligned with the edge direction; Establish the neighborhood relationship between other pixel points and the central pixel point according to the coordinates aligned with the edge direction; Determine the associated local according to the neighborhood relationship, fuse the associated local, and determine the subgraph information of the target entity in the knowledge graph.
[0014] The present invention proposes an anti-fraud system for financial transactions based on artificial intelligence, which improves the accuracy of feature extraction and, when determining anti-fraud information based on the extracted features, improves the recognition efficiency and recognition effect.
[0015] Other features and advantages of the present invention will be described in the following specification, and some of them will become obvious from the specification or be understood by implementing the present invention. The objectives and other advantages of the present invention can be achieved and obtained through the structures specifically pointed out in the written specification and the drawings.
[0016] The technical solutions of the present invention will be further described in detail below through the drawings and embodiments. Description of the Drawings
[0017] The drawings are used to provide a further understanding of the present invention, and constitute a part of the specification. Together with the embodiments of the present invention, they are used to explain the present invention and do not constitute a limitation to the present invention. In the drawings: Figure 1 is a block diagram of an anti-fraud system for financial transactions based on artificial intelligence according to an embodiment of the present invention; Figure 2 is a block diagram of a generation module according to an embodiment of the present invention; Figure 3 is a block diagram of a construction module according to an embodiment of the present invention. Detailed Embodiments
[0018] The preferred embodiments of the present invention will be described below with reference to the accompanying drawings. It should be understood that the preferred embodiments described herein are only for the purpose of illustrating and explaining the present invention, and are not intended to limit the present invention.
[0019] As Figure 1 shown, an anti-fraud system for financial transactions based on artificial intelligence is proposed in an embodiment of the present invention, including: A generation module for generating an anti-fraud template for financial transactions; A construction module for constructing a knowledge graph based on the anti-fraud template for financial transactions; An acquisition module for acquiring the financial transaction data of a user; A first extraction module for extracting features from the financial transaction data to obtain transaction features; A first determination module for querying the knowledge graph according to the transaction features to determine the anti-fraud information for financial transactions.
[0020] The working principle of the above technical solution: The generation module is used to generate an anti-fraud template for financial transactions based on the fraud data in the fraud database; the construction module is used to convert the anti-fraud template for financial transactions into a structured knowledge representation, that is, a knowledge graph. The financial transaction data of the user includes real-time transaction flows, historical databases, and external data (such as device fingerprint databases, IP reputation databases). The first extraction module is used to extract features from the financial transaction data to obtain transaction features; query the knowledge graph according to the transaction features to determine the anti-fraud information for financial transactions.
[0021] The beneficial effects of the above technical solution: An anti-fraud template for financial transactions is generated based on the fraud data in the fraud database to realize the collation of static rules, and then a knowledge graph is constructed, forming a leap in dynamic graph reasoning, significantly improving the detection ability for advanced attacks such as group fraud and complex cash-out. The accuracy of feature extraction is improved. When determining the anti-fraud information based on the extracted features, query the knowledge graph to determine the anti-fraud information for financial transactions, improving the recognition efficiency and recognition effect.
[0022] As Figure 2 shown, according to some embodiments of the present invention, the generation module includes: A second determination module for formulating an anti-fraud strategy based on the fraud data in the fraud database and determining anti-fraud rules according to the formulated anti-fraud strategy; the anti-fraud rules include rules for scoring, rules for weights, rules for danger levels, and rules for strategy flows; A configuration module for configuring the operating conditions of the anti-fraud rules, and after the configuration is completed, configuring the execution order of the anti-fraud rules to obtain a configuration result; wherein, the execution order includes sequential execution and traversal execution; A test module, which is used to obtain sample data, conduct a logical test on the configuration result, and determine a financial transaction anti-fraud template according to the test result.
[0023] The working principle of the above technical solution: Use association rule learning (such as the Apriori algorithm) to discover frequent fraud patterns. Example: Frequent item set {large amount transfer, new device login, night transaction} → Generate combined rules. Scoring rule: Cumulative risk score (such as a single transaction amount > 100,000 adds 50 points). Weight rule: Weights for different feature dimensions (such as the weight of device fingerprint matching is 30%). Danger level: Dynamic threshold division (such as a total score > 80 is high risk). Policy flow: The execution order of rules (such as first checking the device fingerprint, then verifying the geographical location). Configure the running conditions of the anti-fraud rules, including condition types: time window (such as within the past 5 minutes), data source (such as only checking third-party payment channels); use the Drools rule engine to dynamically configure rule conditions. Configure the execution order of the anti-fraud rules to obtain the configuration result; among them, the execution order includes sequential execution and traversal execution; Sequential execution: Strictly execute according to the rule definition order (applicable to strongly dependent rules). Traversal execution: Aggregate the results after parallel execution of all rules (applicable to independent rules). The test module determines sample data, including positive samples (known fraud transactions), negative samples (normal transactions), and boundary samples (such as the amount = 100,000); conduct a logical test on the configuration result based on the sample data, including unit testing to verify the triggering logic of a single rule; and integration testing to verify the execution result of the rule flow. Through coverage analysis, ensure that the rules cover more than 95% of historical fraud cases, and determine the financial transaction anti-fraud template according to the test result.
[0024] The beneficial effect of the above technical solution: The generation module can realize the transformation from manual experience-driven to data intelligence-driven, significantly improving the adaptability and operation and maintenance efficiency of anti-fraud rules.
[0025] As Figure 3 shown, according to some embodiments of the present invention, the construction module includes: A second extraction module, which is used to extract anti-fraud features of the financial transaction anti-fraud template; A third determination module, which is used to determine the label information of the financial transaction anti-fraud template according to the anti-fraud features; An integration module, which is used to perform data integration on each financial transaction anti-fraud template based on the label information, and construct a knowledge graph based on the integration result.
[0026] Working principle of the above technical solution: The second extraction module extracts quantifiable and computable features from the anti-fraud template, providing a data basis for subsequent knowledge graph construction. The third determination module assigns semantic labels to the template based on the anti-fraud features to support subsequent graph query and reasoning. The label information includes risk type labels (such as money laundering, cash-out, card skimming, gang fraud), risk level labels (such as high risk, medium risk, low risk, normal), and pattern labels (such as capital circulation, intensive two-way transfer, rapid splitting, etc.). When determining the label information of the financial transaction anti-fraud template according to the anti-fraud features, XGBoost / LightGBM is used to predict the labels. The integration module integrates the template data into a structured knowledge graph based on the label information to support complex fraud pattern reasoning. Data integration of each financial transaction anti-fraud template based on the label information includes: classifying the financial transaction anti-fraud templates with the same label information to obtain several classification sets; defining node types and edge relationships for each classification set, generating a graph structure based on the graph computing engine, and performing attribute annotation on the graph structure to obtain the knowledge graph. The node types include entity nodes: user, account, device, IP, merchant, bank card; event nodes: transaction, login, password modification, cash withdrawal. The edge relationships include explicit relationships: transaction (transfer, payment), device login, common contact; implicit relationships: IP co-occurrence (logging in to different accounts with the same IP), geographical location clustering (multiple accounts frequently appearing in the same base station). The attribute annotation includes node attributes: user credit rating, device fingerprint uniqueness score; edge attributes: transaction amount, login time difference, IP geographical location distance.
[0027] Beneficial effects of the above technical solution: Data integration of each financial transaction anti-fraud template based on the label information realizes the leap from single-point rule defense to networked correlation analysis, constructs a comprehensive knowledge graph, and is convenient for effectively coping with increasingly complex gang-based and professional fraud attacks.
[0028] According to some embodiments of the present invention, the second extraction module includes: An aggregation module for: Classifying and aggregating the functional features of the anti-fraud behavior constituent elements included in the financial transaction anti-fraud template to form the basic functional categories of the anti-fraud behavior constituent elements as the functional layer; Classifying and aggregating the interaction features of the anti-fraud behavior constituent elements included in the financial transaction anti-fraud template to form the basic association categories of the anti-fraud behavior constituent elements as the association layer; Classifying and aggregating the data features of the anti-fraud behavior constituent elements included in the financial transaction anti-fraud template to form the basic logical categories of the anti-fraud behavior constituent elements as the logical layer; A fourth determination module, configured to generate a data analysis model based on a function layer, an association layer, and a logic layer, determine the types of entities involved in the data analysis model and the corresponding attributes, and determine user behavior characteristics, device environment characteristics, transaction network characteristics, and time series characteristics based on the types of entities and the corresponding attributes; and form anti-fraud characteristics based on the user behavior characteristics, device environment characteristics, transaction network characteristics, and time series characteristics.
[0029] The working principle of the above technical solution: The aggregation module is responsible for performing multi-dimensional classification and aggregation on the anti-fraud behavior constituent elements in the financial transaction anti-fraud template to form different levels of function categories, association categories, and logic categories. Based on the function characteristics of the anti-fraud behavior constituent elements, the anti-fraud behavior constituent elements with similar or related function characteristics are classified and aggregated to form the basic function categories of the anti-fraud behavior constituent elements, which serve as the function layer. These categories reflect the commonalities and differences in the functions of anti-fraud behaviors. Based on the interaction characteristics of the anti-fraud behavior constituent elements, the interaction relationships between the anti-fraud behavior constituent elements are analyzed, and the elements with close interaction relationships are classified and aggregated to form the basic association categories of the anti-fraud behavior constituent elements, which serve as the association layer. These categories reveal the patterns and rules in the interactions of anti-fraud behaviors. Based on the data characteristics of the anti-fraud behavior constituent elements, according to the data logical relationships of the anti-fraud behavior constituent elements, such as causal relationships, conditional relationships, etc., classification and aggregation are performed to form the basic logic categories of the anti-fraud behavior constituent elements, which serve as the logic layer. These categories reflect the internal connections of anti-fraud behaviors in data logic. The fourth determination module constructs a data analysis model based on the function layer, association layer, and logic layer generated by the aggregation module, and extracts key user behavior characteristics, device environment characteristics, transaction network characteristics, and time series characteristics therefrom to form a comprehensive anti-fraud characteristic system. Based on the function layer, association layer, and logic layer, by combining the information of these three layers, a comprehensive data analysis model is constructed, which can comprehensively reflect all aspects of anti-fraud behaviors. In the data analysis model, the types of entities involved (such as users, devices, transactions, etc.) and the corresponding attributes (such as user IDs, device IPs, transaction amounts, etc.) are identified and determined. User behavior characteristics, device environment characteristics, transaction network characteristics, and time series characteristics are determined based on the types of entities and the corresponding attributes.
[0030] The beneficial effects of the above technical solution: A data analysis model is generated based on the function layer, association layer, and logic layer, the types of entities involved in the data analysis model and the corresponding attributes are determined, and thus the anti-fraud characteristics are accurately determined.
[0031] According to some embodiments of the present invention, the user behavior characteristics include transaction patterns, account operations, and risk associations; the device environment characteristics include device fingerprints, network environments, and emulator detections; the transaction network characteristics include fund flows, relationship networks, and address characteristics; and the time series characteristics include behavior time sequences and event intervals.
[0032] According to some embodiments of the present invention, the transaction patterns include the dispersion of transaction amounts, the proportion of night transactions, and the number of high-frequency small-amount exploratory transactions; The account operations include the login failure rate, the password modification frequency, and the number of emergency contact changes; The risk associations include the number of associated account fraud tags, the number of blacklist device matches, and the proportion of high-risk merchant transactions; The device fingerprints include the number of device ID changes and the canvas fingerprint entropy value; The network environments include the proxy IP score and the WiFi base station switching rate; The emulator detections include the number of emulator feature hits; The fund flows include the fund transfer station score and the fund closed-loop depth; The relationship networks include the community fraud density and the shortest path to black nodes; The address characteristics include the frequency of receiving address changes and the distance between the IP and GPS; The behavior time sequences include the entropy of login time distribution and the interval from registration to the first transaction; The event intervals include the interquartile range ratio of transaction intervals and the number of transaction bursts within 5 minutes.
[0033] According to some embodiments of the present invention, the first extraction module includes: The fifth determination module is used for: Generating a transaction link based on financial transaction data, determining the attention weight coefficients between nodes in the transaction link for each time period, and performing normalization processing on the attention weight coefficients to obtain normalized attention weight coefficients; Generating node structure features by aggregating adjacent node features based on the normalized attention weight coefficients using graph attention; Capturing the behavior patterns of nodes in the transaction link in the time dimension, extracting time series statistical features, and determining node time series features based on Transformer encoding of time series dependencies; The splicing module is used for splicing the node structure features and the node time series features, and adaptively adjusting the contribution degrees of the two types of features based on a gating mechanism to obtain transaction features.
[0034] Working principle of the above technical solution: Based on the transaction records in financial transaction data, a transaction link is constructed to represent each node involved in the transaction process (such as users, merchants, payment platforms, etc.) and their interaction relationships. Analyze the interaction intensity between nodes in the transaction link for each time period, and calculate the attention weight coefficient between nodes to reflect the importance or correlation degree of different nodes in the transaction process. Normalize the calculated attention weight coefficient to ensure that the sum of all weight coefficients is 1, obtaining the normalized attention weight coefficient for subsequent feature aggregation and comparison. Based on the method of graph attention weighted aggregation of neighboring node features, use the normalized attention weight coefficient to weight-aggregate the features of neighboring nodes to generate the structural features of each node. These structural features reflect the position, role of the node in the transaction link, and its interaction pattern with other nodes. Capture the behavioral patterns of nodes in the time dimension in the transaction link, such as transaction frequency, change in transaction amount, etc., to reflect the temporal behavioral characteristics of nodes. Based on the captured behavioral patterns, extract temporal statistical features, such as mean, variance, maximum value, minimum value, etc., to quantify the temporal behavior of nodes. Use the Transformer model to encode the temporal statistical features to capture the temporal dependence relationship between features and further determine the temporal features of nodes. These temporal features reflect the dynamic changes of nodes in the time series. Concatenate the node structural features and node temporal features to form a more comprehensive feature vector to comprehensively reflect the structural and temporal characteristics of nodes in the transaction process. Introduce a gating mechanism (such as the gating structure in gated recurrent unit GRU, long short-term memory network LSTM, or custom gating logic), and adaptively adjust the contribution degrees of node structural features and node temporal features according to different parts in the feature vector. In this way, the proportion of the two types of features in the final transaction features can be dynamically balanced according to the actual transaction scenario and requirements.
[0035] Beneficial effects of the above technical solution: The fifth determination module is responsible for extracting key structural features and temporal features from financial transaction data, providing a basis for subsequent anti-fraud analysis. The concatenation module is responsible for concatenating the node structural features and node temporal features generated by the fifth determination module, and adaptively adjusting the contribution degrees of the two types of features through a gating mechanism, finally obtaining transaction features. These features integrate the structural and temporal characteristics of nodes, can more comprehensively reflect the key information in the transaction process, and improve the accuracy of transaction features.
[0036] According to some embodiments of the present invention, the first determination module includes: The first detection module is used to detect entity features for transaction features by using named entity recognition technology; The second detection module is used for: Detect the corresponding target entity in the knowledge graph according to the entity features through entity linking; Determine the subgraph information of the target entity in the knowledge graph, and determine the financial transaction anti-fraud information according to the subgraph information.
[0037] The working principle of the above technical solution: The first detection module uses the Named Entity Recognition (NER) technology to carefully scan the transaction features, accurately locate and extract the entity features therein. The list of entity features identified and extracted from the transaction features provides the basic data for subsequent association analysis in the knowledge graph. Accurately locate the key entities in the transaction features, providing a clear target for subsequent knowledge graph query and analysis. Reduce the interference of invalid information and improve the efficiency and accuracy of anti-fraud analysis. The second detection module conducts in-depth association analysis in the knowledge graph based on the entity features extracted by the first detection module, and mines the anti-fraud information in financial transactions through entity linking and the shortest path algorithm. According to the entity features extracted by the first detection module, entity linking is performed in the knowledge graph, that is, the target entities matching these entity features are found. Establish the association between the transaction features and the entities in the knowledge graph, laying the foundation for subsequent subgraph information extraction and anti-fraud analysis. The shortest path algorithm (such as the Dijkstra algorithm) is used to determine the shortest path between the target entity and other related entities in the knowledge graph. Determine the subgraph information of the target entity in the knowledge graph, including the entities directly connected to the target entity, the relationships, and the shortest paths between them, etc. The subgraph information reflects the position, role of the target entity in the knowledge graph, and its association with other entities. Combining the domain knowledge and rules of financial transaction anti-fraud, deeply analyze the subgraph information, and mine the possible fraud patterns, abnormal associations or risk signals therein. Determine the financial transaction anti-fraud information, such as fraud risk level, suspected fraud entities, fraud behavior patterns, etc., and give corresponding handling measures.
[0038] The beneficial effects of the above technical solution: The first determination module aims to accurately mine and extract the anti-fraud information in financial transactions by deeply analyzing the transaction features, combining the named entity recognition and knowledge graph technologies. This module consists of two core detection modules: the first detection module is responsible for the recognition of entity features, and the second detection module conducts in-depth mining in the knowledge graph based on the entity features. Through the association analysis of the knowledge graph, discover the complex relationships and potential risks hidden in the transaction features. Use the shortest path algorithm to efficiently extract the key subgraph information, improving the efficiency and accuracy of anti-fraud analysis. Provide comprehensive and in-depth information support for financial transaction anti-fraud, and help financial institutions effectively prevent and combat fraud behavior.
[0039] According to some embodiments of the present invention, the second detection module determines the subgraph information of the target entity in the knowledge graph, including: Determine the size of the recognition sliding window in the knowledge graph based on the number of target entities, and slide based on the recognition sliding window to obtain several sliding images; Determine the central pixel point of the sliding image; calculate the centralized coordinates of each pixel point in the sliding image relative to the central pixel point; Determine the gradient direction of each pixel point in the sliding image; Among them, is the gradient direction of the pixel point; is the horizontal gradient value; is the vertical gradient value; According to the gradient direction of the pixel point, rotate the centralized coordinates by an angle to obtain coordinates aligned with the edge direction; According to the coordinates aligned with the edge direction, establish the neighborhood relationship between other pixel points and the central pixel point; Determine the associated local area according to the neighborhood relationship, fuse the associated local area, and determine the sub-graph information of the target entity in the knowledge graph.
[0040] The working principle of the above technical solution: Query the preset quantity-size comparison table based on the number of target entities to determine the corresponding size of the recognition sliding window. If the number of target entities is small, select a smaller sliding window to finely capture local information. If the number of target entities is large, select a larger sliding window to cover more entities. Slide the window on the visual representation of the knowledge graph (such as an image or a graph structure), each time sliding by a step size (usually 1 pixel or 1 node). After each slide, extract the sub-graph or image patch covered by the current window, which is called a "sliding image".
[0041] Among them, ( ) are the coordinates aligned with the edge direction; ( ) are the centralized coordinates of the pixel point relative to the central pixel point; The coordinates aligned with the edge direction reflect the relative position of the pixel point in the edge direction. Compare the modulus of the coordinates aligned with the edge direction with a preset threshold. When it is determined that the modulus is less than the preset threshold, it means that the pixel point and the central pixel point belong to the same neighborhood. Determine the associated local area according to the neighborhood relationship, fuse the associated local area, and determine the sub-graph information of the target entity in the knowledge graph.
[0042] Advantages of the above technical solution: By establishing a sliding window, a central coordinate, a gradient direction rotation, and a neighborhood relationship, local structures and association information of a target entity can be extracted from the visual representation of the knowledge graph, facilitating the accurate determination of subgraph information of the target entity in the knowledge graph.
[0043] Obviously, those skilled in the art can make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations of the present invention fall within the scope of the claims of the present invention and its equivalent technologies, the present invention is also intended to include these modifications and variations.
Claims
1. An anti-fraud system for financial transactions based on artificial intelligence, characterized in that, Including: A generation module, configured to generate a financial transaction anti-fraud template; A construction module, configured to construct a knowledge graph based on the financial transaction anti-fraud template; An acquisition module, configured to acquire the financial transaction data of a user; A first extraction module, configured to perform feature extraction on the financial transaction data to obtain transaction features; A first determination module, configured to query the knowledge graph according to the transaction features and determine financial transaction anti-fraud information.
2. The anti-fraud system for financial transactions based on artificial intelligence according to claim 1, characterized in that, The generation module includes: A second determination module, configured to formulate an anti-fraud strategy based on the fraud data in the fraud database and determine anti-fraud rules according to the formulated anti-fraud strategy; the anti-fraud rules include rules for scoring, rules for weights, rules for risk levels, and rules for policy flows; A configuration module, configured to configure the operating conditions of the anti-fraud rules, and after the configuration is completed, configure the execution order of the anti-fraud rules to obtain a configuration result; wherein, the execution order includes sequential execution and traversal execution; A testing module, configured to acquire sample data and perform a logical test on the configuration result, and determine a financial transaction anti-fraud template according to the test result.
3. The anti-fraud system for financial transactions based on artificial intelligence according to claim 1, characterized in that, The construction module includes: A second extraction module, configured to extract anti-fraud features of the financial transaction anti-fraud template; A third determination module, configured to determine label information of the financial transaction anti-fraud template according to the anti-fraud features; An integration module, configured to perform data integration on each financial transaction anti-fraud template based on the label information and construct a knowledge graph based on the integration result.
4. The anti-fraud system for financial transactions based on artificial intelligence according to claim 3, characterized in that, The second extraction module includes: An aggregation module, configured to: Classify and aggregate the functional features of the anti-fraud behavior constituent elements included in the financial transaction anti-fraud template to form the basic functional categories of the anti-fraud behavior constituent elements as the functional layer; Classify and aggregate the interaction features of the anti-fraud behavior constituent elements included in the financial transaction anti-fraud template to form the basic association categories of the anti-fraud behavior constituent elements as the association layer; Classify and aggregate the data features of the anti-fraud behavior constituent elements included in the financial transaction anti-fraud template to form the basic logical categories of the anti-fraud behavior constituent elements as the logical layer; A fourth determination module, configured to generate a data analysis model according to the functional layer, the association layer, and the logical layer, determine the types of entities involved in the data analysis model and the corresponding attributes, and determine user behavior features, device environment features, transaction network features, and time series features based on the types of entities and the corresponding attributes; the anti-fraud features are constituted by the user behavior features, the device environment features, the transaction network features, and the time series features.
5. The anti-fraud system for financial transactions based on artificial intelligence according to claim 4, wherein The user behavior features include transaction patterns, account operations, and risk associations; the device environment features include device fingerprints, network environments, and simulator detections; the transaction network features include fund flows, relationship networks, and address features; the time series features include behavior time sequences and event intervals.
6. The anti-fraud system for financial transactions based on artificial intelligence according to claim 5, wherein, The transaction patterns include transaction amount dispersion, proportion of night transactions, and number of high-frequency small-amount probing transactions; The account operations include login failure rate, password modification frequency, and number of emergency contact changes; The risk associations include the number of fraud labels of associated accounts, the number of blacklist device matches, and the proportion of high-risk merchant transactions. The device fingerprint includes the number of device ID changes and the canvas fingerprint entropy value; The network environment includes the proxy IP score and the WiFi base station switching rate; The emulator detection includes the number of emulator feature hits; The fund flow includes the fund transfer station score and the fund closed-loop depth; The relationship network includes the community fraud density and the shortest path to the black node; The address feature includes the frequency of receiving address changes and the distance between the IP and GPS; The behavior time series includes the entropy of the login time distribution and the interval from registration to the first transaction; The event interval includes the interquartile range ratio of the transaction interval and the number of transaction bursts within 5 minutes.
7. The anti-fraud system for financial transactions based on artificial intelligence according to claim 1, characterized in that, The first extraction module includes: The fifth determination module is used for: Generating a transaction link based on the financial transaction data, determining the attention weight coefficient between nodes in the transaction link for each time period, and normalizing the attention weight coefficient to obtain the normalized attention weight coefficient; Generating node structure features based on the normalized attention weight coefficient by graph attention weighted aggregation of neighbor features; Capturing the behavior pattern of nodes in the transaction link in the time dimension, extracting time series statistical features, and determining the node time series features based on Transformer encoding of time series dependencies; The splicing module is used to splice the node structure features and the node time series features, and adaptively adjust the contribution degrees of the two types of features based on the gating mechanism to obtain the transaction features.
8. The anti-fraud system for financial transactions based on artificial intelligence according to claim 1, wherein, The first determination module includes: The first detection module is used to detect entity features for the transaction features using named entity recognition technology; The second detection module is used for: Detecting the corresponding target entity in the knowledge graph according to the entity features through entity linking; Determining the subgraph information of the target entity in the knowledge graph, and determining the financial transaction anti-fraud information according to the subgraph information.
9. The anti-fraud system for financial transactions based on artificial intelligence according to claim 8, characterized in that, The second detection module determines the subgraph information of the target entity in the knowledge graph through the shortest path algorithm.
10. The anti-fraud system for financial transactions based on artificial intelligence according to claim 8, wherein The second detection module determines the subgraph information of the target entity in the knowledge graph, including: Determining the size of the recognition sliding window in the knowledge graph based on the number of target entities, and sliding based on the recognition sliding window to obtain a number of sliding images; Determining the central pixel point of the sliding image; calculating the centered coordinates of each pixel point in the sliding image relative to the central pixel point; Determining the gradient direction of each pixel point in the sliding image; Among them, is the gradient direction of the pixel point; is the horizontal gradient value; is the vertical gradient value; Rotate the centered coordinates according to the gradient direction of the pixel points by an angle to obtain coordinates aligned with the edge direction; Establishing the neighborhood relationship between other pixel points and the central pixel point according to the coordinates aligned with the edge direction; Determining the associated local area according to the neighborhood relationship, fusing the associated local area, and determining the subgraph information of the target entity in the knowledge graph.
Citation Information
Patent Citations
A risk gang identification method and device
CN109949046A
System and method for realizing intelligent early warning of fraudulent transactions
CN110148001A
Anti-fraud method based on big data support
CN112506983A
Insurance anti-gang fraud method based on graph rule engine
CN114862605A
Fraud gang identification system based on transaction knowledge graph
CN116151967A