Artificial intelligence based financial transaction anti-fraud system

By using an AI-based financial transaction anti-fraud system, templates are generated, knowledge graphs are constructed, and features are extracted, solving the problem of unsatisfactory recognition results in existing technologies and achieving efficient anti-fraud in financial transactions.

CN120278722BActive Publication Date: 2025-11-11SHENZHEN SED LOGIC BUSINESS EQUIP CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510764584.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-06-10
Publication Date
2025-11-11
Estimated Expiration
2045-06-10

AI Technical Summary

Technical Problem

Existing anti-fraud methods for financial transactions suffer from poor data quality, inaccurate feature extraction, and weak model generalization ability, resulting in unsatisfactory identification effects and low query efficiency, making it difficult to cope with complex and diverse modern financial transaction scenarios.

Method used

An AI-based financial transaction anti-fraud system is adopted. It generates anti-fraud templates through a generation module, constructs a knowledge graph, acquires financial transaction data, extracts features, and queries the knowledge graph to determine anti-fraud information. It also utilizes techniques such as association rule learning and graph attention weighted aggregation to improve the efficiency of feature extraction and recognition.

Benefits of technology

It significantly improves the detection capabilities for organized fraud and advanced attacks, enhances the accuracy and efficiency of feature extraction, and enables efficient identification of complex fraudulent activities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120278722B_ABST
    Figure CN120278722B_ABST
Patent Text Reader

Abstract

This invention discloses an artificial intelligence-based financial transaction anti-fraud system, comprising: a generation module for generating a financial transaction anti-fraud template; a construction module for constructing a knowledge graph based on the financial transaction anti-fraud template; an acquisition module for acquiring users' financial transaction data; a first extraction module for extracting features from the financial transaction data to obtain transaction features; and a first determination module for querying the knowledge graph based on the transaction features to determine financial transaction anti-fraud information. This improves the accuracy of feature extraction and enhances recognition efficiency and effectiveness when determining anti-fraud information based on extracted features.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of financial transaction anti-fraud technology, and in particular to an artificial intelligence-based financial transaction anti-fraud system. Background Technology

[0002] With the rapid development of fintech and the continuous expansion of financial transaction services, financial transactions are becoming increasingly complex and diverse, accompanied by an increase in fraud risks. Traditional anti-fraud methods often rely on manual review and rule-based judgment, which are insufficient to handle the large-scale, high-frequency scenarios of modern financial transactions. Therefore, how to effectively identify and prevent fraudulent activities in financial transactions and ensure the healthy and stable development of the financial market has become an urgent problem for the financial industry. However, existing anti-fraud transaction identification methods often face problems such as low data quality, inaccurate feature extraction, and weak model generalization ability when processing financial transaction data, resulting in unsatisfactory identification results. Furthermore, when determining anti-fraud information based on extracted features, query efficiency and identification efficiency are both low. Summary of the Invention

[0003] This invention aims to at least partially solve one of the technical problems in the aforementioned technologies. Therefore, the objective of this invention is to propose an artificial intelligence-based anti-fraud system for financial transactions, improving the accuracy of feature extraction and enhancing recognition efficiency and effectiveness when determining anti-fraud information based on extracted features.

[0004] To achieve the above objectives, embodiments of the present invention propose an artificial intelligence-based anti-fraud system for financial transactions, comprising:

[0005] The generation module is used to generate anti-fraud templates for financial transactions;

[0006] The building module is used to construct a knowledge graph based on financial transaction anti-fraud templates;

[0007] The acquisition module is used to acquire users' financial transaction data;

[0008] The first extraction module is used to extract features from financial transaction data to obtain transaction features;

[0009] The first determination module is used to query the knowledge graph based on transaction characteristics to determine anti-fraud information for financial transactions.

[0010] According to some embodiments of the present invention, the generation module includes:

[0011] The second determining module is used to formulate anti-fraud strategies based on fraud data in the fraud database, and to determine anti-fraud rules according to the formulated anti-fraud strategies; the anti-fraud rules include scoring rules, weighting rules, risk level rules, and strategy flow rules;

[0012] The configuration module is used to configure the running conditions of anti-fraud rules. After the configuration is completed, the execution order of the anti-fraud rules is configured to obtain the configuration result; wherein, the execution order includes sequential execution and traversal execution.

[0013] The testing module is used to acquire sample data, perform logical tests on the configuration results, and determine the anti-fraud template for financial transactions based on the test results.

[0014] According to some embodiments of the present invention, the building module includes:

[0015] The second extraction module is used to extract the anti-fraud features of the financial transaction anti-fraud template;

[0016] The third determination module is used to determine the label information of the financial transaction anti-fraud template based on anti-fraud characteristics;

[0017] The integration module is used to integrate data from various financial transaction anti-fraud templates based on tag information, and to build a knowledge graph based on the integration results.

[0018] According to some embodiments of the present invention, the second extraction module includes:

[0019] The aggregation module is used for:

[0020] Based on the functional characteristics of the anti-fraud behavior components included in the financial transaction anti-fraud template, the basic functional categories of the anti-fraud behavior components are classified and aggregated to form a functional layer.

[0021] Based on the interactive features of the anti-fraud behavior components included in the financial transaction anti-fraud template, the basic association categories of the anti-fraud behavior components are classified and aggregated to form an association layer.

[0022] Based on the data characteristics of the anti-fraud behavior components included in the financial transaction anti-fraud template, the basic logical categories of the anti-fraud behavior components are classified and aggregated to form a logical layer.

[0023] The fourth determination module is used to generate a data analysis model based on the functional layer, the association layer, and the logic layer, determine the types of entities involved in the data analysis model and their corresponding attributes, and determine user behavior characteristics, device environment characteristics, transaction network characteristics, and time series characteristics based on the types of entities and their corresponding attributes; and construct anti-fraud features based on user behavior characteristics, device environment characteristics, transaction network characteristics, and time series characteristics.

[0024] According to some embodiments of the present invention, the user behavior characteristics include transaction patterns, account operations, and risk associations; the device environment characteristics include device fingerprints, network environment, and simulator detection; the transaction network characteristics include fund flows, relationship networks, and address characteristics; and the time series characteristics include behavior sequence and event intervals.

[0025] According to some embodiments of the present invention, the transaction pattern includes transaction amount dispersion, nighttime transaction ratio, and number of high-frequency small-amount trial transactions;

[0026] Account operations include login failure rate, password change frequency, and number of emergency contact changes;

[0027] Risk correlation includes the number of fraud tags associated with related accounts, the number of blacklisted devices matched, and the proportion of transactions by high-risk merchants;

[0028] Device fingerprints include the number of device ID changes and the canvas fingerprint entropy value;

[0029] Network environment includes proxy IP rating and WiFi base station switching rate;

[0030] Simulator detection includes the number of simulator feature hits;

[0031] Fund flow includes fund transfer station rating and fund loop depth;

[0032] Relationship networks include community fraud density and the shortest path to black nodes;

[0033] Address characteristics include the frequency of delivery address changes and the distance between IP and GPS;

[0034] The behavioral time sequence includes the login time distribution entropy and the interval from registration to the first transaction;

[0035] Event intervals include the interquartile range of the transaction interval and the number of transaction bursts within 5 minutes.

[0036] According to some embodiments of the present invention, the first extraction module includes:

[0037] The fifth determining module is used for:

[0038] A transaction chain is generated based on financial transaction data. The attention weight coefficients between nodes in the transaction chain for each time period are determined, and the attention weight coefficients are normalized to obtain normalized attention weight coefficients.

[0039] Based on the normalized attention weight coefficients, the neighbor features are aggregated using graph attention weighting to generate node structure features;

[0040] Capture the behavioral patterns of nodes in the transaction chain in the time dimension, extract time-series statistical features, and determine the time-series features of nodes based on Transformer encoding of time-series dependencies;

[0041] The splicing module is used to splice the node structural features and node temporal features, and adaptively adjusts the contribution of the two types of features based on the gating mechanism to obtain the transaction features.

[0042] According to some embodiments of the present invention, the first determining module includes:

[0043] The first detection module is used to detect entity features based on transaction features using named entity recognition technology.

[0044] The second detection module is used for:

[0045] Detecting the corresponding target entity in the knowledge graph based on entity features and entity links;

[0046] Determine the subgraph information of the target entity in the knowledge graph, and determine the anti-fraud information for financial transactions based on the subgraph information.

[0047] According to some embodiments of the present invention, the second detection module determines the subgraph information of the target entity in the knowledge graph through the shortest path algorithm.

[0048] According to some embodiments of the present invention, the second detection module determines the subgraph information of the target entity in the knowledge graph, including:

[0049] The size of the recognition sliding window in the knowledge graph is determined based on the number of target entities, and the sliding window is slid to obtain several sliding images.

[0050] Determine the center pixel of the sliding image; calculate the centered coordinates of each pixel in the sliding image relative to the center pixel;

[0051] Determine the gradient direction for each pixel in the sliding image;

[0052]

[0053] in, The gradient direction of the pixel; This represents the horizontal gradient value; This represents the longitudinal gradient value;

[0054] Rotate the centered coordinates according to the gradient direction of the pixel. Angle, to obtain coordinates aligned with the edge direction;

[0055] Based on the coordinates aligned with the edge direction, establish the neighborhood relationship between other pixels and the center pixel;

[0056] Based on neighborhood relationships, related localities are identified, and these related localities are merged to determine the subgraph information of the target entity in the knowledge graph.

[0057] This invention proposes an artificial intelligence-based anti-fraud system for financial transactions, which improves the accuracy of feature extraction and enhances recognition efficiency and effectiveness when determining anti-fraud information based on extracted features.

[0058] Other features and advantages of the invention will be set forth in the following description, and will be apparent in part from the description, or may be learned by practicing the invention. The objects and other advantages of the invention may be realized and obtained by means of the structures particularly pointed out in the written description and the accompanying drawings.

[0059] The technical solution of the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. Attached Figure Description

[0060] The accompanying drawings are provided to further illustrate the invention and form part of the specification. They are used in conjunction with embodiments of the invention to explain the invention and do not constitute a limitation thereof. In the drawings:

[0061] Figure 1 This is a block diagram of an artificial intelligence-based anti-fraud system for financial transactions according to an embodiment of the present invention;

[0062] Figure 2 This is a block diagram of a generation module according to an embodiment of the present invention;

[0063] Figure 3 This is a block diagram of a construction module according to an embodiment of the present invention. Detailed Implementation

[0064] The preferred embodiments of the present invention will be described below with reference to the accompanying drawings. It should be understood that the preferred embodiments described herein are for illustration and explanation only and are not intended to limit the present invention.

[0065] like Figure 1 As shown in the figure, this invention proposes an artificial intelligence-based anti-fraud system for financial transactions, comprising:

[0066] The generation module is used to generate anti-fraud templates for financial transactions;

[0067] The building module is used to construct a knowledge graph based on financial transaction anti-fraud templates;

[0068] The acquisition module is used to acquire users' financial transaction data;

[0069] The first extraction module is used to extract features from financial transaction data to obtain transaction features;

[0070] The first determination module is used to query the knowledge graph based on transaction characteristics to determine anti-fraud information for financial transactions.

[0071] The working principle of the above technical solution is as follows: The generation module generates anti-fraud templates for financial transactions based on fraud data in the fraud database; the construction module transforms the anti-fraud templates into structured knowledge representations, i.e., a knowledge graph. User financial transaction data includes real-time transaction flows, historical databases, and external data (such as device fingerprint databases and IP reputation databases). The first extraction module extracts features from the financial transaction data to obtain transaction features; based on these transaction features, it queries the knowledge graph to determine anti-fraud information for financial transactions.

[0072] The beneficial effects of the above technical solution are as follows: It generates anti-fraud templates for financial transactions based on fraud data in a fraud database, organizes static rules, and constructs a knowledge graph, enabling dynamic graph reasoning and significantly improving the detection capabilities against advanced attacks such as organized fraud and complex cash-out schemes. It also improves the accuracy of feature extraction; when determining anti-fraud information based on extracted features, it queries the knowledge graph to determine the anti-fraud information for financial transactions, thereby improving recognition efficiency and effectiveness.

[0073] like Figure 2 As shown, according to some embodiments of the present invention, the generation module includes:

[0074] The second determining module is used to formulate anti-fraud strategies based on fraud data in the fraud database, and to determine anti-fraud rules according to the formulated anti-fraud strategies; the anti-fraud rules include scoring rules, weighting rules, risk level rules, and strategy flow rules;

[0075] The configuration module is used to configure the running conditions of anti-fraud rules. After the configuration is completed, the execution order of the anti-fraud rules is configured to obtain the configuration result; wherein, the execution order includes sequential execution and traversal execution.

[0076] The testing module is used to acquire sample data, perform logical tests on the configuration results, and determine the anti-fraud template for financial transactions based on the test results.

[0077] The working principle of the above technical solution is as follows: It uses association rule learning (such as the Apriori algorithm) to discover frequent fraud patterns. Example: Frequent itemset {large transfers, new device logins, nighttime transactions} → generates combined rules. Scoring rules: Cumulative risk score (e.g., adding 50 points for a single transaction amount > 100,000). Weighting rules: Weighting different feature dimensions (e.g., device fingerprint matching weight 30%). Risk level: Dynamic threshold division (e.g., total score > 80 is high risk). Policy flow: Rule execution order (e.g., checking device fingerprint first, then verifying geographical location). The operating conditions of the anti-fraud rules are configured, including condition type: time window (e.g., within the past 5 minutes), data source (e.g., only checking third-party payment channels); the Drools rule engine is used to dynamically configure rule conditions. The execution order of the anti-fraud rules is configured to obtain the configuration result; wherein, the execution order includes sequential execution and traversal execution; sequential execution: strictly following the rule definition order (applicable to strongly dependent rules). Traversal execution: executing all rules in parallel and then aggregating the results (applicable to independent rules). The testing module determines sample data, including positive samples (known fraudulent transactions), negative samples (normal transactions), and boundary samples (e.g., amount = 100,000). Based on the sample data, it performs logic testing through configuration results, including unit testing to verify the triggering logic of individual rules and integration testing to verify the execution results of the rule flow. Through coverage analysis, ensuring that the rules cover more than 95% of historical fraud cases, the financial transaction anti-fraud template is determined based on the test results.

[0078] The beneficial effects of the above technical solution are: the generation module can realize the transformation from human experience-driven to data intelligence-driven, which significantly improves the adaptability and operation and maintenance efficiency of anti-fraud rules.

[0079] like Figure 3 As shown, according to some embodiments of the present invention, the building module includes:

[0080] The second extraction module is used to extract the anti-fraud features of the financial transaction anti-fraud template;

[0081] The third determination module is used to determine the label information of the financial transaction anti-fraud template based on anti-fraud characteristics;

[0082] The integration module is used to integrate data from various financial transaction anti-fraud templates based on tag information, and to build a knowledge graph based on the integration results.

[0083] The working principle of the above technical solution is as follows: The second extraction module extracts quantifiable and computable features from the anti-fraud templates, providing a data foundation for subsequent knowledge graph construction. The third determination module assigns semantic labels to the templates based on the anti-fraud features, supporting subsequent graph querying and reasoning. Label information includes risk type labels (e.g., money laundering, cash-out, credit card fraud, gang fraud), risk level labels (e.g., high-risk, medium-risk, low-risk, normal), and pattern labels (e.g., fund circulation, intensive two-way transfers, rapid splitting, etc.). When determining the label information of financial transaction anti-fraud templates based on anti-fraud features, XGBoost / LightGBM is used to predict the labels. The integration module integrates the template data into a structured knowledge graph based on the label information, supporting reasoning about complex fraud patterns. Data integration of various financial transaction anti-fraud templates based on label information includes: classifying financial transaction anti-fraud templates with the same label information to obtain several classification sets; defining node types and edge relationships for each classification set; generating a graph structure based on a graph computing engine; and labeling attributes on the graph structure to obtain the knowledge graph. Node types include entity nodes: user, account, device, IP, merchant, bank card; event nodes: transaction, login, password change, withdrawal. Edge relationships include explicit relationships: transaction (transfer, payment), device login, mutual contact; implicit relationships: IP co-occurrence (same IP logging into different accounts), geographic location clustering (multiple accounts frequently appearing at the same base station). Attribute annotations include node attributes: user credit rating, device fingerprint uniqueness score; edge attributes: transaction amount, login time difference, IP geographic distance.

[0084] The beneficial effects of the above technical solution are: data integration of various financial transaction anti-fraud templates based on tag information, realizing a leap from single-point rule defense to networked correlation analysis, constructing a comprehensive knowledge graph, which facilitates effective response to increasingly complex gang-related and professional fraud attacks.

[0085] According to some embodiments of the present invention, the second extraction module includes:

[0086] The aggregation module is used for:

[0087] Based on the functional characteristics of the anti-fraud behavior components included in the financial transaction anti-fraud template, the basic functional categories of the anti-fraud behavior components are classified and aggregated to form a functional layer.

[0088] Based on the interactive features of the anti-fraud behavior components included in the financial transaction anti-fraud template, the basic association categories of the anti-fraud behavior components are classified and aggregated to form an association layer.

[0089] Based on the data characteristics of the anti-fraud behavior components included in the financial transaction anti-fraud template, the basic logical categories of the anti-fraud behavior components are classified and aggregated to form a logical layer.

[0090] The fourth determination module is used to generate a data analysis model based on the functional layer, the association layer, and the logic layer, determine the types of entities involved in the data analysis model and their corresponding attributes, and determine user behavior characteristics, device environment characteristics, transaction network characteristics, and time series characteristics based on the types of entities and their corresponding attributes; and construct anti-fraud features based on user behavior characteristics, device environment characteristics, transaction network characteristics, and time series characteristics.

[0091] The working principle of the above technical solution is as follows: The aggregation module is responsible for multi-dimensional classification and aggregation of the anti-fraud behavior components in the financial transaction anti-fraud template to form functional categories, association categories, and logical categories at different levels. Based on the functional characteristics of the anti-fraud behavior components, anti-fraud behavior components with similar or related functional characteristics are classified and aggregated to form basic functional categories of anti-fraud behavior components, serving as the functional layer. These categories reflect the commonalities and differences in the functions of anti-fraud behaviors. Based on the interaction characteristics of the anti-fraud behavior components, the interaction relationships between the anti-fraud behavior components are analyzed, and elements with close interaction relationships are classified and aggregated to form basic association categories of anti-fraud behavior components, serving as the association layer. These categories reveal the patterns and rules of anti-fraud behaviors in interaction. Based on the data characteristics of the anti-fraud behavior components, according to the data logical relationships of the anti-fraud behavior components, such as causal relationships and conditional relationships, classification and aggregation are performed to form basic logical categories of anti-fraud behavior components, serving as the logical layer. These categories reflect the inherent connections of anti-fraud behaviors in data logic. The fourth determination module, based on the functional, relational, and logical layers generated by the aggregation module, constructs a data analysis model and extracts key user behavior features, device environment features, transaction network features, and time series features to form a comprehensive anti-fraud feature system. Based on the functional, relational, and logical layers, and combining information from these three layers, a comprehensive data analysis model is built that can comprehensively reflect all aspects of anti-fraud behavior. In the data analysis model, the types of entities involved (such as users, devices, transactions, etc.) and their corresponding attributes (such as user ID, device IP, transaction amount, etc.) are identified and determined. User behavior features, device environment features, transaction network features, and time series features are determined based on the type of entity and its corresponding attributes.

[0092] The beneficial effects of the above technical solution are: generating a data analysis model based on the functional layer, the association layer, and the logic layer; determining the types of entities involved in the data analysis model and their corresponding attributes; and thus accurately determining anti-fraud features.

[0093] According to some embodiments of the present invention, the user behavior characteristics include transaction patterns, account operations, and risk associations; the device environment characteristics include device fingerprints, network environment, and simulator detection; the transaction network characteristics include fund flows, relationship networks, and address characteristics; and the time series characteristics include behavior sequence and event intervals.

[0094] According to some embodiments of the present invention, the transaction pattern includes transaction amount dispersion, nighttime transaction ratio, and number of high-frequency small-amount trial transactions;

[0095] Account operations include login failure rate, password change frequency, and number of emergency contact changes;

[0096] Risk correlation includes the number of fraud tags associated with related accounts, the number of blacklisted devices matched, and the proportion of transactions by high-risk merchants;

[0097] Device fingerprints include the number of device ID changes and the canvas fingerprint entropy value;

[0098] Network environment includes proxy IP rating and WiFi base station switching rate;

[0099] Simulator detection includes the number of simulator feature hits;

[0100] Fund flow includes fund transfer station rating and fund loop depth;

[0101] Relationship networks include community fraud density and the shortest path to black nodes;

[0102] Address characteristics include the frequency of delivery address changes and the distance between IP and GPS;

[0103] The behavioral time sequence includes the login time distribution entropy and the interval from registration to the first transaction;

[0104] Event intervals include the interquartile range of the transaction interval and the number of transaction bursts within 5 minutes.

[0105] According to some embodiments of the present invention, the first extraction module includes:

[0106] The fifth determining module is used for:

[0107] A transaction chain is generated based on financial transaction data. The attention weight coefficients between nodes in the transaction chain for each time period are determined, and the attention weight coefficients are normalized to obtain normalized attention weight coefficients.

[0108] Based on the normalized attention weight coefficients, the neighbor features are aggregated using graph attention weighting to generate node structure features;

[0109] Capture the behavioral patterns of nodes in the transaction chain in the time dimension, extract time-series statistical features, and determine the time-series features of nodes based on Transformer encoding of time-series dependencies;

[0110] The splicing module is used to splice the node structural features and node temporal features, and adaptively adjusts the contribution of the two types of features based on the gating mechanism to obtain the transaction features.

[0111] The working principle of the above technical solution is as follows: Based on transaction records in financial transaction data, a transaction chain is constructed to represent the various nodes involved in the transaction process (such as users, merchants, payment platforms, etc.) and their interaction relationships. The interaction intensity between nodes in the transaction chain within each time period is analyzed, and attention weight coefficients between nodes are calculated to reflect the importance or correlation of different nodes in the transaction process. The calculated attention weight coefficients are normalized to ensure that the sum of all weight coefficients is 1, resulting in normalized attention weight coefficients for subsequent feature aggregation and comparison. Based on a graph attention-weighted aggregation method for neighboring node features, the normalized attention weight coefficients are used to weight and aggregate the features of neighboring nodes, generating structural features for each node. These structural features reflect the node's position, role, and interaction patterns with other nodes in the transaction chain. The behavioral patterns of nodes in the transaction chain over time, such as transaction frequency and changes in transaction amount, are captured to reflect the temporal behavioral characteristics of the nodes. Based on the captured behavioral patterns, temporal statistical features, such as mean, variance, maximum, and minimum values, are extracted to quantify the temporal behavior of the nodes. The Transformer model is used to encode temporal statistical features, capturing the temporal dependencies between features to further determine the temporal characteristics of nodes. These temporal features reflect the dynamic changes of nodes over time. Node structural features and temporal features are concatenated to form a more comprehensive feature vector, comprehensively reflecting the structural and temporal characteristics of nodes during the transaction process. A gating mechanism (such as a gated recurrent unit (GRU), the gating structure in a long short-term memory (LSTM) network, or a custom gating logic) is introduced to adaptively adjust the contribution of node structural features and node temporal features based on different parts of the feature vector. This allows for a dynamic balance of the weight of the two types of features in the final transaction features according to the actual transaction scenario and requirements.

[0112] The beneficial effects of the above technical solution are as follows: The fifth determination module is responsible for extracting key structural and temporal features from financial transaction data, providing a foundation for subsequent anti-fraud analysis. The splicing module is responsible for splicing the node structural and temporal features generated by the fifth determination module, and adaptively adjusting the contribution of the two types of features through a gating mechanism to finally obtain the transaction features. These features integrate the structural and temporal characteristics of the nodes, which can more comprehensively reflect the key information in the transaction process and improve the accuracy of the transaction features.

[0113] According to some embodiments of the present invention, the first determining module includes:

[0114] The first detection module is used to detect entity features based on transaction features using named entity recognition technology.

[0115] The second detection module is used for:

[0116] Detecting the corresponding target entity in the knowledge graph based on entity features and entity links;

[0117] Determine the subgraph information of the target entity in the knowledge graph, and determine the anti-fraud information for financial transactions based on the subgraph information.

[0118] The working principle of the above technical solution is as follows: The first detection module utilizes Named Entity Recognition (NER) technology to meticulously scan transaction features, accurately locate and extract entity features. The list of entity features identified and extracted from transaction features provides foundational data for subsequent association analysis in the knowledge graph. Accurately locating key entities within transaction features provides clear targets for subsequent knowledge graph queries and analysis. This reduces interference from invalid information and improves the efficiency and accuracy of anti-fraud analysis. The second detection module, based on the entity features extracted by the first detection module, conducts deep association analysis in the knowledge graph, mining anti-fraud information in financial transactions through entity linking and shortest path algorithms. Based on the entity features extracted by the first detection module, entity links are established in the knowledge graph, i.e., target entities matching these entity features are found. This establishes associations between transaction features and entities in the knowledge graph, laying the foundation for subsequent subgraph information extraction and anti-fraud analysis. Shortest path algorithms (such as Dijkstra's algorithm) are used to determine the shortest path between the target entity and other related entities in the knowledge graph. This involves identifying the target entity's subgraph information within the knowledge graph, including directly connected entities, relationships, and the shortest paths between them. This subgraph information reflects the target entity's position, role, and relationships with other entities within the knowledge graph. By combining domain knowledge and rules for financial transaction fraud prevention, this subgraph information is analyzed in depth to uncover potential fraud patterns, abnormal correlations, or risk signals. Finally, it identifies financial transaction fraud prevention information, such as fraud risk levels, suspected fraudulent entities, and fraudulent behavior patterns, and proposes corresponding handling measures.

[0119] The beneficial effects of the above technical solution are as follows: The first detection module aims to accurately mine and extract anti-fraud information in financial transactions by deeply analyzing transaction characteristics and combining named entity recognition and knowledge graph technology. This module consists of two core detection modules: the first detection module is responsible for identifying entity features, while the second detection module conducts in-depth mining in the knowledge graph based on these entity features. Through association analysis of the knowledge graph, complex relationships and potential risks hidden in transaction characteristics are discovered. The shortest path algorithm is used to efficiently extract key subgraph information, improving the efficiency and accuracy of anti-fraud analysis. This provides comprehensive and in-depth information support for anti-fraud in financial transactions, helping financial institutions effectively prevent and combat fraudulent activities.

[0120] According to some embodiments of the present invention, the second detection module determines the subgraph information of the target entity in the knowledge graph, including:

[0121] The size of the recognition sliding window in the knowledge graph is determined based on the number of target entities, and the sliding window is slid to obtain several sliding images.

[0122] Determine the center pixel of the sliding image; calculate the centered coordinates of each pixel in the sliding image relative to the center pixel;

[0123] Determine the gradient direction for each pixel in the sliding image;

[0124]

[0125] in, The gradient direction of the pixel; This represents the horizontal gradient value; This represents the longitudinal gradient value;

[0126] Rotate the centered coordinates according to the gradient direction of the pixel. Angle, to obtain coordinates aligned with the edge direction;

[0127] Based on the coordinates aligned with the edge direction, establish the neighborhood relationship between other pixels and the center pixel;

[0128] Based on neighborhood relationships, related localities are identified, and these related localities are merged to determine the subgraph information of the target entity in the knowledge graph.

[0129] The working principle of the above technical solution is as follows: Based on the number of target entities, a preset quantity-size lookup table is consulted to determine the size of the corresponding recognition sliding window. If the number of target entities is small, a smaller sliding window is selected to capture local information in detail. If the number of target entities is large, a larger sliding window is selected to cover more entities. The window slides on the visual representation of the knowledge graph (such as an image or graph structure), sliding one step at a time (usually 1 pixel or 1 node). After each slide, the subgraph or image patch covered by the current window is extracted, called the "sliding image".

[0130]

[0131]

[0132] in,( ) are coordinates aligned with the edge direction; () represents the centered coordinates of a pixel relative to the center pixel;

[0133] The coordinates aligned with the edge direction reflect the relative position of the pixel in that direction. The magnitude of these coordinates is compared to a preset threshold. If the magnitude is less than the threshold, the pixel and the center pixel belong to the same neighborhood. Related local units are determined based on these neighborhood relationships, and these units are then fused to determine the subgraph information of the target entity within the knowledge graph.

[0134] The beneficial effects of the above technical solution are as follows: by using sliding windows, centered coordinates, gradient direction rotation, and neighborhood relationship establishment, the local structure and association information of the target entity can be extracted from the visual representation of the knowledge graph, which facilitates the accurate determination of the target entity's subgraph information in the knowledge graph.

[0135] Obviously, those skilled in the art can make various modifications and variations to this invention without departing from its spirit and scope. Therefore, if these modifications and variations fall within the scope of the claims of this invention and their equivalents, this invention also intends to include these modifications and variations.

Claims

1. An artificial intelligence-based anti-fraud system for financial transactions, characterized in that, include: The generation module is used to generate anti-fraud templates for financial transactions; The building module is used to construct a knowledge graph based on financial transaction anti-fraud templates; The acquisition module is used to acquire users' financial transaction data; The first extraction module is used to extract features from financial transaction data to obtain transaction features; The first determination module is used to query the knowledge graph based on transaction characteristics to determine anti-fraud information for financial transactions; The generation module includes: The second determining module is used to formulate anti-fraud strategies based on fraud data in the fraud database, and to determine anti-fraud rules according to the formulated anti-fraud strategies; the anti-fraud rules include scoring rules, weighting rules, risk level rules, and strategy flow rules; The configuration module is used to configure the running conditions of anti-fraud rules. After the configuration is completed, the execution order of the anti-fraud rules is configured to obtain the configuration result; wherein, the execution order includes sequential execution and traversal execution. The testing module is used to acquire sample data, perform logical tests on the configuration results, and determine the anti-fraud template for financial transactions based on the test results. Build modules, including: The second extraction module is used to extract the anti-fraud features of the financial transaction anti-fraud template; The third determination module is used to determine the label information of the financial transaction anti-fraud template based on anti-fraud characteristics; The integration module is used to integrate data from various financial transaction anti-fraud templates based on tag information and to build a knowledge graph based on the integration results. The second extraction module includes: The aggregation module is used for: Based on the functional characteristics of the anti-fraud behavior components included in the financial transaction anti-fraud template, the basic functional categories of the anti-fraud behavior components are classified and aggregated to form a functional layer. Based on the interactive features of the anti-fraud behavior components included in the financial transaction anti-fraud template, the basic association categories of the anti-fraud behavior components are classified and aggregated to form an association layer. Based on the data characteristics of the anti-fraud behavior components included in the financial transaction anti-fraud template, the basic logical categories of the anti-fraud behavior components are classified and aggregated to form a logical layer. The fourth determination module is used to generate a data analysis model based on the functional layer, the association layer, and the logic layer, determine the types of entities involved in the data analysis model and their corresponding attributes, and determine user behavior characteristics, device environment characteristics, transaction network characteristics, and time series characteristics based on the types of entities and their corresponding attributes; and construct anti-fraud features based on user behavior characteristics, device environment characteristics, transaction network characteristics, and time series characteristics.

2. The AI-based financial transaction anti-fraud system as described in claim 1, characterized in that, The user behavior characteristics include transaction patterns, account operations, and risk associations; the device environment characteristics include device fingerprints, network environment, and simulator detection; the transaction network characteristics include fund flows, relationship networks, and address characteristics; and the time series characteristics include behavior sequence and event intervals.

3. The AI-based financial transaction anti-fraud system as described in claim 2, characterized in that, Trading patterns include the dispersion of trading amount, the proportion of nighttime trading, and the number of high-frequency, small-amount exploratory trades; Account operations include login failure rate, password change frequency, and number of emergency contact changes; Risk correlation includes the number of fraud tags associated with related accounts, the number of blacklisted devices matched, and the proportion of transactions by high-risk merchants; Device fingerprints include the number of device ID changes and the canvas fingerprint entropy value; Network environment includes proxy IP rating and WiFi base station switching rate; Simulator detection includes the number of simulator feature hits; Fund flow includes fund transfer station rating and fund loop depth; Relationship networks include community fraud density and the shortest path to black nodes; Address characteristics include the frequency of delivery address changes and the distance between IP and GPS; The behavioral time sequence includes the login time distribution entropy and the interval from registration to the first transaction; Event intervals include the interquartile range of the transaction interval and the number of transaction bursts within 5 minutes.

4. The AI-based financial transaction anti-fraud system as described in claim 1, characterized in that, The first extraction module includes: The fifth determining module is used for: A transaction chain is generated based on financial transaction data. The attention weight coefficients between nodes in the transaction chain for each time period are determined, and the attention weight coefficients are normalized to obtain normalized attention weight coefficients. Based on the normalized attention weight coefficients, the neighbor features are aggregated using graph attention weighting to generate node structure features; Capture the behavioral patterns of nodes in the transaction chain in the time dimension, extract time-series statistical features, and determine the time-series features of nodes based on Transformer encoding of time-series dependencies; The splicing module is used to splice the node structural features and node temporal features, and adaptively adjusts the contribution of the two types of features based on the gating mechanism to obtain the transaction features.

5. The AI-based financial transaction anti-fraud system as described in claim 1, characterized in that, The first determining module includes: The first detection module is used to detect entity features based on transaction features using named entity recognition technology. The second detection module is used for: Detecting the corresponding target entity in the knowledge graph based on entity features and entity links; Determine the subgraph information of the target entity in the knowledge graph, and determine the anti-fraud information for financial transactions based on the subgraph information.

6. The AI-based financial transaction anti-fraud system as described in claim 5, characterized in that, The second detection module uses the shortest path algorithm to determine the subgraph information of the target entity in the knowledge graph.

7. The AI-based financial transaction anti-fraud system as described in claim 5, characterized in that, The second detection module determines the subgraph information of the target entity in the knowledge graph, including: The size of the recognition sliding window in the knowledge graph is determined based on the number of target entities, and the sliding window is slid to obtain several sliding images. Determine the center pixel of the sliding image; calculate the centered coordinates of each pixel in the sliding image relative to the center pixel; Determine the gradient direction for each pixel in the sliding image; in, The gradient direction of the pixel; This represents the horizontal gradient value; This represents the longitudinal gradient value; Rotate the centered coordinates according to the gradient direction of the pixel. Angle, to obtain coordinates aligned with the edge direction; Based on the coordinates aligned with the edge direction, establish the neighborhood relationship between other pixels and the center pixel; Based on neighborhood relationships, related localities are identified, and these related localities are merged to determine the subgraph information of the target entity in the knowledge graph.

Citation Information

Patent Citations

  • Anti-fraud method based on big data support

    CN112506983A