Business auditing fusion auditing system based on big data

The integrated audit system of industry audits built through big data technology solves the problem of identifying complex transaction models and cross-platform capital flows in decentralized financial transactions, realizes efficient and real-time risk monitoring and report generation, and improves transaction security and transparency.

CN120297977AActive Publication Date: 2025-07-11BEIJING XINGHUO MINGZHI TECHNOLOGY CO LTD

Patent Information

Application Number
CN202510354495.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-25
Publication Date
2025-07-11
Estimated Expiration
2045-03-25

AI Technical Summary

Technical Problem

The existing audit methods are difficult to identify complex transaction patterns and track cross-platform capital flows in decentralized financial transactions, and lack effective risk identification and regulatory means, resulting in insufficient risk spread and transaction security.

Method used

The integrated audit system based on big data is adopted to achieve accurate identification and dynamic monitoring of high-risk transactions through data collection and preprocessing, standardized feature extraction, transaction link analysis and comprehensive risk scoring, combined with real-time streaming data processing, multi-scale time series alignment and reinforcement learning.

Benefits of technology

It improves the security and transparency of decentralized financial transactions, reduces the false alarm rate, enhances audit efficiency and risk identification capabilities, and can conduct real-time and dynamic audits in an environment of high concurrency, cross-platform, and multi-smart contract interaction.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120297977A_ABST
    Figure CN120297977A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of financial auditing, and particularly discloses a business auditing fusion auditing system based on big data, which comprises a data acquisition and preprocessing module, a standardized feature extraction module, a transaction link analysis module, a risk comprehensive score calculation module and an intelligent auditing report generation module. Compared with the prior art, the technical problem that high-risk transactions and abnormal fund flow cannot be accurately identified in the prior art due to dependence on static rule matching and manual auditing, especially under the conditions of transaction data cross-platform, account identity hiding and transaction path complexity in a decentralized transaction environment is solved. According to the method, efficient, real-time and dynamic financial industry auditing is realized through real-time streaming data processing, multi-scale time sequence alignment, transaction path risk propagation analysis and reinforcement learning optimization risk scoring.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of financial auditing, and in particular, relates to an industry-audit fusion audit based on big data. Background Art

[0002] At present, the decentralized financial industry is developing rapidly, and its openness and permissionless characteristics have promoted the globalization of financial transactions. However, the existing audit methods have many shortcomings when facing the decentralized financial industry, mainly reflected in: decentralized transactions, lack of effective audit supervision means; high-frequency transactions and smart contract operations increase the difficulty of auditing; traditional audit methods have limited ability to identify complex transaction patterns; cross-platform transaction behaviors are difficult to track, leading to risk diffusion; in addition, due to the lack of effective risk control measures on some decentralized trading platforms, attackers create new accounts in batches to conduct abnormal transactions. The existing audit system is difficult to accurately identify these risky accounts due to insufficient data correlation. Therefore, there is an urgent need for an intelligent audit method that can operate efficiently in a decentralized financial environment, identify complex transaction patterns, track cross-platform fund flows, and automatically generate audit reports, thereby improving the security, compliance and transparency of DeFi transactions. The present invention provides an industry-audit fusion audit method based on big data, which combines real-time stream data processing, dynamic feature optimization, reinforcement learning risk assessment and transaction path analysis. Even in a complex transaction environment with high concurrency, cross-platform, and multi-smart contract interaction, it can still achieve accurate decentralized financial transaction audits, improve the detection capability of high-risk transactions, reduce false alarm rates, and improve audit efficiency, thereby meeting the needs of decentralized financial industry audits for real-time, dynamic, and intelligent audits. Summary of the invention

[0003] In view of the above-mentioned technical deficiencies, the purpose of the present invention is to propose an industry-audit fusion audit system and method based on big data, aiming to solve the technical problem that the existing technology relies on static rule matching and manual review, especially in a decentralized trading environment, where transaction data is cross-platform, account identity is hidden, and transaction paths are complex. The existing technology cannot accurately identify high-risk transactions and abnormal capital flows.

[0004] In order to solve the above technical problems, the present invention adopts the following technical solutions: The present invention provides an audit system based on big data and integrating business and audit, including:

[0005] The data collection and preprocessing module is used to collect decentralized financial industry audit data. It uses Apache Kafka and Flink to process the real-time data stream of decentralized financial industry audit data and remove abnormal data to obtain preprocessed financial industry audit data.

[0006] The standardized feature extraction module is used to process the pre-processed financial industry audit data using the multi-scale time series alignment method and perform double-standard normalization to obtain the financial industry audit feature matrix;

[0007] The transaction link analysis module is used to construct a multi-dimensional transaction network based on the financial industry review feature matrix, calculate the transaction pattern similarity based on the multi-dimensional transaction network and combine it with cross-platform pattern matching analysis to obtain risky transaction groups; and obtain transaction path risk data by performing path detection on risky transaction groups;

[0008] A comprehensive risk score calculation module is used to obtain transaction data, account behavior data and capital flow data on the path according to the transaction path risk data, and calculate the comprehensive risk score;

[0009] The intelligent audit report generation module is used to generate explainable audit reports based on comprehensive risk scores combined with semantic analysis.

[0010] Preferably, in the data collection and preprocessing module, the decentralized financial industry audit data includes transaction data, account behavior data and capital flow data; transaction data includes transaction amount, transaction time, counterparty and transaction type; account behavior data includes user login frequency, device change and IP change records; capital flow data includes account capital inflow and account capital outflow.

[0011] Preferably, in the data collection and preprocessing module, in the step of using Apache Kafka and Flink to process the real-time data stream of decentralized financial industry audit data and remove abnormal data, the step of removing abnormal data specifically includes:

[0012] Apache Kafka and Flink are used to process the real-time data stream of decentralized financial industry review data to obtain the abnormal transaction feature vector Z of decentralized financial industry review data;

[0013] According to the abnormal transaction feature vector Z and the decentralized financial industry audit data X t , the variational autoencoder method is used to calculate the probability P of abnormal data;

[0014] Set the abnormal data probability threshold ∈ th , if P(X t )<∈ th , then remove X t .

[0015] Preferably, in the standardized feature extraction module, the step of using the multi-scale time series alignment method to process the pre-processed financial industry audit data adopts the formula:

[0016]

[0017] Among them, is the smoothed financial industry audit data for the i-th transaction at time point j; X i,t * is the financial industry audit data for the i-th transaction at time t; w t is the trading volume weighted factor; α is the time decay coefficient, used to control the impact of forward transactions on the current financial industry audit data; T is a preset time window; exp(·) is the exponential function;

[0018] The steps of double-standard normalization processing specifically include: for the transaction data in the preprocessed financial industry audit data, Z-score standardization processing is adopted; for the account behavior data in the preprocessed financial industry audit data, Min-Max normalization processing is adopted.

[0019] Preferably, in the transaction link analysis module, the steps of constructing a multi-dimensional transaction network based on the financial industry audit feature matrix specifically include: introducing the financial industry audit feature matrix M = {W1, W2,..., W n} generated by the standardized feature extraction module, where W p is the dynamic feature weight of the p-th transaction feature in the financial industry audit feature matrix, and n is the total number of transaction features; constructing a multi-dimensional transaction network G based on the financial industry audit feature matrix M: G = (V, E), E e,r = f(X e ', X r ', M), where G is the multi-dimensional transaction network; V is the account node; E e,r is the transaction path between the e-th transaction and the r-th transaction; X e ', X r ' are the transaction data and account behavior data in the financial industry audit data normalized by the standardized feature extraction module.

[0020] Preferably, in the transaction link analysis module, the steps of calculating the transaction pattern similarity based on the multi-dimensional transaction network and combining cross-platform pattern matching analysis to obtain the risk transaction group specifically include:

[0021] Calculating the mean value of the financial industry audit features and the variance of the financial industry audit features according to the financial industry audit feature matrix M, and calculating the transaction pattern similarity S i ; Among them, W p is the preset dynamic feature weight corresponding to the financial industry audit data, and X' p is the financial industry audit feature value corresponding to the p-th transaction feature;

[0022] Using the dynamic feature weight W pAfter weighting the financial industry audit feature matrix M, use the cross-platform transaction mode matching to calculate the abnormal mode score: Among them, Q is the abnormal mode score, and A e,r is the path weight of the transaction path between the e-th transaction and the r-th transaction in the multi-dimensional transaction network G;

[0023] Set a preset abnormal mode score threshold, and set the transactions with abnormal mode scores greater than the abnormal mode score threshold as the risk transaction group;

[0024] The steps of obtaining the transaction path risk data by performing path detection on the risk transaction group specifically include: introducing a constrained risk propagation coefficient exp(-βd e,r ) to calculate the suspicious fund flow path and obtain the transaction path risk data: R path = Σ e,r A e,r ·exp(-βd e,r )·Q i , where R path is the transaction path risk data, d e,r is the length of the transaction path, β is the risk propagation coefficient weight control factor, and exp(·) is the exponential function.

[0025] Preferably, in the risk comprehensive score calculation module, the steps of obtaining the transaction data, account behavior data, and fund flow data on the path according to the transaction path risk data and calculating the risk comprehensive score specifically include:

[0026] Screen out high-risk paths based on the transaction path risk data;

[0027] Extract the detailed transaction data on the path according to the high-risk path, including transaction data, account behavior data, and fund flow data;

[0028] Calculate the transaction amount abnormal score, transaction frequency abnormal score, account behavior abnormal score, and fund flow abnormal score according to the transaction data, account behavior data, and fund flow data;

[0029] Adopt the weighted comprehensive scoring method to calculate the risk comprehensive score of the path; define the risk warning threshold, and trigger the warning mechanism according to the risk comprehensive score and the risk warning threshold, including: low risk: continue to monitor, no immediate processing required; medium risk: mark the account and include it in the key attention transaction list; high risk: trigger abnormal transaction interception.

[0030] The beneficial effect of the present invention is that compared with the prior art that relies on static rule matching and manual review, especially in a decentralized trading environment, where transaction data is cross-platform, account identities are hidden, and transaction paths are complex, the prior art cannot accurately identify high-risk transactions and abnormal capital flows. The present invention achieves efficient, real-time, and dynamic financial industry auditing through real-time stream data processing, multi-scale time series alignment, transaction path risk propagation analysis, and reinforcement learning to optimize risk scoring. BRIEF DESCRIPTION OF THE DRAWINGS

[0031] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.

[0032] Figure 1 A module schematic diagram of a business-audit fusion audit system based on big data provided by the present invention.

[0033] Figure 2 A schematic diagram of the equipment of an industry-audit fusion audit system based on big data provided by the present invention. DETAILED DESCRIPTION

[0034] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0035] Embodiment 1: Figure 1 As shown, it is a module schematic diagram of a business-audit fusion audit system based on big data provided by the present invention, and an implementation example of the business-audit fusion audit system based on big data provided by the present invention is proposed.

[0036] In an embodiment, the business-audit fusion audit system based on big data includes:

[0037] The data collection and preprocessing module is used to collect decentralized financial industry audit data. It uses Apache Kafka and Flink to process the real-time data stream of decentralized financial industry audit data and remove abnormal data to obtain preprocessed financial industry audit data.

[0038] It should be noted that in the data collection and preprocessing module, in the steps of processing the real-time data stream of decentralized financial audit data and removing abnormal data using Apache Kafka and Flink, the steps of removing abnormal data specifically include: processing the real-time data stream of decentralized financial audit data using Apache Kafka and Flink to obtain the abnormal transaction feature vector Z of the decentralized financial audit data; according to the abnormal transaction feature vector Z and the decentralized financial audit data X t , calculating the probability P of abnormal data using the variational autoencoder method; setting the threshold ∈ th , if P(X t ) < ∈ th , then remove X t .

[0039] It should be understood that by introducing the variational autoencoder method (VAE), this method can accurately discover and remove abnormal data in a large-scale real-time data stream, ensuring the accuracy of subsequent data processing. This method calculates the anomaly score for each transaction and determines whether the transaction is an abnormal transaction based on this score, thereby effectively removing those abnormal data that may cause errors. By using Apache Kafka and Flink for real-time processing of the data stream, the system can ensure real-time response to large-scale decentralized financial data, and the anomaly detection using VAE can ensure that the removed data has high accuracy, thus avoiding the impact of incorrect data on subsequent audit results.

[0040] For example, in actual operation, when some transaction data such as the transaction amount is abnormal or the transaction frequency is too high, VAE will calculate the anomaly score of the transaction and decide whether to remove these data according to the set threshold. For example, in a certain experiment, the system detected frequent large-amount transfer transactions in real time, and their anomaly scores were much higher than the threshold, so they were marked as abnormal data and removed, thus ensuring the accuracy of system processing.

[0041] The standardized feature extraction module is used to process the preprocessed financial audit data using the multi-scale time series alignment method and perform double-standard normalization processing to obtain the financial audit feature matrix;

[0042] It should be noted that in the standardized feature extraction module, the steps of processing the preprocessed financial audit data using the multi-scale time series alignment method use the formula:

[0043]

[0044] where is the preprocessed financial audit data smoothed at time point j for the i-th transaction; X i,t *Financial industry audit data for the i-th transaction at time t; w t is the trading volume weighted factor; α is the time decay coefficient used to control the impact of forward transactions on the current financial industry audit data; T is a preset time window; exp(·) is the exponential function;

[0045] Since financial transaction data may have different time distributions (such as second-level, minute-level, hour-level), this formula can ensure that all transaction data is converted to the same time scale.

[0046] The steps of double-standard normalization processing specifically include: for the transaction data in the preprocessed financial industry audit data, Z-score standardization processing is adopted; for the account behavior data in the preprocessed financial industry audit data, Min-Max normalization processing is adopted.

[0047] It can be understood that the introduction of the multi-scale time series alignment method ensures the effective alignment of data at different time scales. Especially in decentralized financial industry audits, due to the different data collection time granularities of different transaction types, this method ensures that all transaction data can be calculated and analyzed on the same time axis, avoiding the problem of feature distortion caused by time dimension mismatch. The adoption of the double-standard normalization strategy enables the reasonable standardization of transaction data and account behavior data in different feature spaces, improves the distribution consistency of data on different types of features, and thus enhances the adaptability and generalization ability of the model.

[0048] For example, in a certain experimental environment, the system processes the transaction data of a certain DeFi platform in the past 30 days and finds that when the multi-scale time series alignment method is not adopted, due to the inconsistent time granularity of the data, the recognition accuracy of some transaction patterns is lower than 70%. After adopting this method, the recognition accuracy of transaction patterns is increased to 88%. At the same time, after using Z-score standardization to process the transaction amount, the detection ability of abnormal amount transactions is increased by 25%, and Min-Max normalization improves the recognition accuracy of account behavior patterns by 18%. These experimental results show that the present invention optimizes the data at multiple levels through the standardized feature extraction module, improves the interpretability of financial industry audit data and the model learning ability, and provides a solid foundation for subsequent transaction pattern analysis and risk assessment.

[0049] The transaction link analysis module is used to construct a multi-dimensional transaction network based on the financial industry audit feature matrix, calculate the transaction pattern similarity according to the multi-dimensional transaction network and combine cross-platform pattern matching analysis to obtain a risk transaction group; by performing path detection on the risk transaction group, risk data of the transaction path is obtained;

[0050] It should be noted that in the transaction link analysis module, the steps of constructing a multi-dimensional transaction network based on the financial industry audit feature matrix specifically include: introducing the financial industry audit feature matrix M = {W1, W2, …, W n} generated by the standardized feature extraction module, where W p is the dynamic feature weight of the p-th transaction feature in the financial industry audit feature matrix, and n is the total number of transaction features; constructing a multi-dimensional transaction network G based on the financial industry audit feature matrix M: G = (V, E), E e,r = f(X e ', X r ', M), where G is the multi-dimensional transaction network; V is the account node; E e,r is the transaction path between the e-th transaction and the r-th transaction; X e ', X r ' are the transaction data and account behavior data in the financial industry audit data normalized by the standardized feature extraction module.

[0051] In the transaction link analysis module, the steps of calculating the transaction pattern similarity based on the multi-dimensional transaction network and combining cross-platform pattern matching analysis to obtain the risk transaction group specifically include:

[0052] Calculating the mean value and variance of the financial industry audit features according to the financial industry audit feature matrix M, and calculating the transaction pattern similarity S i according to the mean value μ and variance σ of the financial industry audit features; where W p is the preset dynamic feature weight corresponding to the financial industry audit data, and X' p is the financial industry audit feature value corresponding to the p-th transaction feature;

[0053] After weighting the financial industry audit feature matrix M using the dynamic feature weight W p , calculating the abnormal pattern score using cross-platform transaction pattern matching: where Q is the abnormal pattern score, and A e,r is the path weight of the transaction path between the e-th transaction and the r-th transaction in the multi-dimensional transaction network G;

[0054] Presetting an abnormal pattern score threshold, and setting the transactions with an abnormal pattern score greater than the abnormal pattern score threshold as the risk transaction group;

[0055] The steps of obtaining the transaction path risk data by performing path detection on the risk transaction group specifically include: introducing a constrained risk propagation coefficient exp(-βd e,r ) to calculate the suspicious fund flow path and obtain the transaction path risk data: R path = Σ e,r Ae,r ·exp(-βd e,r )·Q i , where R path is the transaction path risk data, d e,r is the length of the transaction path, β is the risk propagation coefficient weight control factor, and exp(·) is the exponential function.

[0056] It can be understood that the construction of a multi-dimensional transaction network can effectively discover hidden transaction patterns. Especially in the scenario of cross-platform transactions, through the weighted optimization of the financial industry audit feature matrix, the transaction patterns on different platforms can be uniformly modeled and compared, thereby improving the accuracy of cross-platform transaction pattern matching. In addition, calculating the similarity of transaction patterns can effectively screen out accounts with highly similar transaction behaviors, and combined with transaction path risk detection, it can further track the transaction flow of suspicious accounts and identify potential risk transaction groups.

[0057] It should be understood that by adopting cross-platform pattern matching (CTPM) and transaction path risk analysis (CRPE), abnormal fund flow patterns hidden in transaction paths can be identified, avoiding the static analysis of isolated transactions in traditional transaction audit methods, and ensuring the dynamic monitoring ability of transaction risks. In addition, by optimizing the risk calculation in the transaction network through the dynamic feature weighting method, the influence of different types of transactions in the model can be adaptively adjusted, ensuring the stability and interpretability of the analysis results.

[0058] For example, in a certain experimental environment, the system analyzes the transaction data of a certain DeFi platform in the past 60 days and finds that the transaction patterns between a certain group of accounts are highly similar, and the fund flow frequently jumps between multiple DeFi platforms. Through multi-dimensional transaction network analysis, the system calculates that the similarity score of the transaction patterns of these accounts is as high as 92%, and the risk score of the fund flow path is calculated to be 87% through transaction path analysis. Subsequently, the system uses cross-platform pattern matching to find that there is an 85% similarity between this risk transaction group and a known money laundering account. Finally, the system successfully identifies this hidden risk transaction network. The experimental results show that the transaction link analysis method provided by the present invention can accurately identify high-risk transaction groups, improve the cross-platform risk detection ability, and enhance the transaction path tracking effect, thereby effectively improving the accuracy of decentralized finance audit.

[0059] A risk comprehensive scoring calculation module, configured to obtain transaction data, account behavior data, and fund flow data on the path according to the transaction path risk data, and calculate a risk comprehensive score;

[0060] It should be noted that in the risk comprehensive scoring calculation module, the steps of obtaining transaction data, account behavior data, and fund flow data on the path according to the transaction path risk data and calculating the risk comprehensive score specifically include:

[0061] Screen out high-risk paths based on the transaction path risk data;

[0062] Extract the detailed transaction data on the path according to the high-risk path, including transaction data, account behavior data, and fund flow data;

[0063] Calculate the abnormal transaction amount score, abnormal transaction frequency score, abnormal account behavior score, and abnormal fund flow score according to the transaction data, account behavior data, and fund flow data;

[0064] Adopt the weighted comprehensive scoring method to calculate the risk comprehensive score of the path; define the risk warning threshold, and trigger the warning mechanism according to the risk comprehensive score and the risk warning threshold, including: low risk: continue to monitor, no immediate processing required; medium risk: mark the account and include it in the key attention transaction list; high risk: trigger abnormal transaction interception.

[0065] It should be noted that the high-risk path is to screen out the high-risk transaction link from the transaction path risk data. The screening standard is based on the risk propagation score of the path, which is calculated by weighting the risks of all transactions on the path. The screening process includes: calculating the average risk score and standard deviation of all transaction paths, and then setting a risk threshold; if the risk score of a certain transaction path exceeds the threshold, then this path is considered a high-risk path and enters the next in-depth analysis.

[0066] For the screened high-risk paths, extract the involved transaction data, account behavior data, and fund flow data, and calculate the following four types of abnormal scores respectively:

[0067] Abnormal transaction amount score: Judge whether the amount of a certain transaction significantly deviates from the historical average. If the amount is much higher than the average transaction amount, it is considered an abnormal transaction.

[0068] Abnormal transaction frequency score: Calculate the transaction frequency of the account within a unit time. If the account conducts transactions frequently in a short period of time, it may indicate that it is involved in arbitrage, money laundering, or other high-risk behaviors.

[0069] Abnormal account behavior score: Analyze the behavior pattern of the account, including the device replacement frequency, IP address change, etc. If the account frequently switches the login device in a short period of time, it may indicate that it is trying to evade audit tracking.

[0070] Abnormal fund flow score: Analyze the fund inflow and outflow pattern of the account. If there is a large amount of fund inflow into the account in a short period of time and then it is immediately split and transferred out, it may be a typical feature of money laundering behavior.

[0071] It is understandable that the comprehensive risk scoring calculation module ensures that the risk assessment is not based on a single transaction feature through multi-dimensional anomaly detection, but comprehensively considers multiple dimensions such as transaction amount, transaction frequency, account behavior, and fund flow, so as to provide a more accurate risk score. In addition, the introduction of the dynamic risk threshold optimization mechanism enables the system to adaptively adjust with the changes in the market environment, reduce the false alarm rate, and improve the recognition rate of high-risk transactions.

[0072] It should be understood that the use of the risk calculation method at the transaction path level can analyze the transaction link risks in the decentralized financial industry audit more comprehensively compared with the traditional method based on the risk score of a single transaction. Especially when the funds flow through multiple accounts, multiple trading platforms, or are automatically executed by smart contracts, this method can effectively identify potential risk transactions in complex transaction chains. In addition, the weighted comprehensive scoring method combined with reinforcement learning to optimize the threshold makes the risk assessment more accurate and adaptable to market changes.

[0073] For example, in a risk monitoring experiment on a certain DeFi trading platform, the system analyzed the risks of 500,000 transactions in the past 90 days. The experiment found that without using the risk scoring at the transaction path level, the system only detected 75% of the high-risk transactions and had a false alarm rate of 15%. After using the comprehensive risk scoring calculation method of the present invention, the system successfully identified 92% of the high-risk transactions, and the false alarm rate was reduced to 5%. Further analysis found that the system can accurately identify the behavior of a certain account to conduct covert fund transfers among multiple DeFi platforms, and through the analysis of path risk propagation, it discovered the abnormal fund flow pattern behind it. This shows that the comprehensive risk scoring calculation method of the present invention can effectively improve the risk recognition ability of the decentralized financial industry audit, reduce the false alarm rate, and improve the overall audit efficiency of the system.

[0074] The intelligent audit report generation module is used to generate an interpretable audit report according to the comprehensive risk score combined with semantic analysis.

[0075] It should be noted that semantic analysis can perform natural language processing (NLP) on the report content to ensure that the generated report is concise and easy to understand, and can clearly explain the risk score and potential risk transaction behaviors.

[0076] It should be understood that the design of this module is to improve the transparency and efficiency of auditing. Especially in the decentralized financial auditing environment, a large amount of data and complex transaction patterns make traditional auditing methods unable to meet the real-time and efficient requirements. By introducing semantic analysis, high-dimensional data can be converted into concise written reports, enabling financial regulators to more quickly understand complex risk assessment results and make decisions. In addition, this module also has adaptability. As transaction patterns continue to change, it can automatically optimize the report template and content structure to adapt to new auditing needs.

[0077] For example, the intelligent audit report generation module performs natural language processing (NLP) on the report content to ensure that the generated report is concise and easy to understand, clearly explaining the risk score and potential risk transaction behaviors. After NLP processing, the following types of report content are generated: Risk level description: Automatically classified as low risk, medium risk, and high risk according to the risk score, with a concise description of each category. For example, Key abnormal transaction behaviors: List key abnormal factors such as abnormal fund flows, abnormal transaction amounts, and frequent transaction behaviors, and explain them; Risk source: Clearly indicate the main source of the risk (such as a certain account, counterparty, fund flow, etc.); Generate a complete audit report: Organize all analysis results into a structured audit report, including: Risk score: Provide the comprehensive risk score of the path; Report summary: Briefly summarize the risk status of the current transaction path; Detailed analysis: For each high-risk path, list the main factors affecting the risk score and explain them; Audit recommendations: Provide further suggestions or warning information, such as whether manual review of certain transactions is required, whether the account should be included in the monitoring, etc.

[0078] Embodiment 2: In addition, the present invention also provides a big data-based industry-audit integrated auditing device. Please refer to Figure 2, An audit device for integrating business and audit based on big data includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein, the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute a system for integrating business and audit based on big data in the first embodiment above. An audit device for integrating business and audit based on big data in the embodiments of the present invention may include, but is not limited to, mobile terminals such as mobile phones, laptop computers, digital broadcast receivers, PDAs (Personal Digital Assistants), PADs (Portable Application Descriptions: tablet computers), PMPs (Portable Media Players), in-vehicle terminals (such as in-vehicle navigation terminals), etc., and fixed terminals such as digital TVs, desktop computers, etc. An audit device for integrating business and audit based on big data is merely an example and should not impose any limitations on the functions and usage scope of the embodiments of the present invention. An audit device for integrating business and audit based on big data may include a processing device 1001 (such as a central processing unit, a graphics processing unit, etc.), which may perform various appropriate actions and processes according to a program stored in a read-only memory (ROM: Read Only Memory) 1002 or a program loaded from a storage device 1003 into a random access memory (RAM: Random Access Memory) 1004. In the RAM 1004, various programs and data required for the operation of an audit device for integrating business and audit based on big data are also stored. The processing device 1001, the ROM 1002, and the RAM 1004 are connected to each other through a bus 1005. An input / output (I / O) interface 1006 is also connected to the bus. Generally, the following systems may be connected to the I / O interface 1006: an input device 1007 including, for example, a touch screen, a touchpad, a keyboard, a mouse, an image sensor, a microphone, an accelerometer, a gyroscope, etc.; an output device 1008 including, for example, a liquid crystal display (LCD: Liquid Crystal Display), a speaker, a vibrator, etc.; a storage device 1003 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 1009. The communication device 1009 may allow an audit device for integrating business and audit based on big data to communicate with other devices wirelessly or wiredly to exchange data. Although an audit device for integrating business and audit based on big data with various systems is shown in the figure, it should be understood that it is not required to implement or have all the shown systems. More or fewer systems may be alternatively implemented or had.

[0079] In particular, according to the embodiments disclosed by the present invention, the processes described above with reference to the system diagrams can be implemented as computer software programs. For example, the embodiments disclosed by the present invention include a computer program product that includes a computer program carried on a computer-readable medium. In such an embodiment, the computer program can be downloaded and installed from a network via a communication device, or installed from a storage device 1003, or installed from a ROM 1002. When the computer program is executed by a processing device 1001, the above-described functions defined in the system of the embodiments disclosed by the present invention are performed.

[0080] It should be understood that the various parts of the present invention can be implemented by hardware, software, firmware, or a combination thereof. In the description of the above embodiments, specific features, structures, materials, or characteristics can be combined in a suitable manner in any one or more embodiments or examples.

[0081] Obviously, those skilled in the art can make various modifications and variations to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations of the present invention fall within the scope of the claims of the present invention and their equivalent technologies, the present invention also intends to include these modifications and variations.

Claims

1. A big data-based audit system integrating business and audit, characterized in that the system Including: A data collection and preprocessing module, which is used to collect decentralized financial industry audit data, process the real-time data stream of decentralized financial industry audit data by using Apache Kafka and Flink, and eliminate abnormal data, so as to obtain preprocessed financial industry audit data; A standardized feature extraction module, which is used to process the preprocessed financial industry audit data by using the multi-scale time series alignment method and perform double-standard normalization processing to obtain a financial industry audit feature matrix; A transaction link analysis module, which is used to construct a multi-dimensional transaction network based on the financial industry audit feature matrix, calculate the transaction pattern similarity according to the multi-dimensional transaction network, and combine cross-platform pattern matching analysis to obtain a risk transaction group; by performing path detection on the risk transaction group, transaction path risk data is obtained; A risk comprehensive scoring calculation module, which is used to obtain transaction data, account behavior data, and fund flow data on the path according to the transaction path risk data, and calculate the risk comprehensive score; An intelligent audit report generation module, which is used to generate an interpretable audit report according to the risk comprehensive score combined with semantic analysis.

2. A big-data-based business-audit integration audit system according to claim 1, characterized in that, In the data collection and preprocessing module, the decentralized financial industry audit data includes transaction data, account behavior data, and fund flow data; the transaction data includes transaction amount, transaction time, transaction counterparty, and transaction type; the account behavior data includes user login frequency, device change, and IP change records; the fund flow data includes account fund inflow and account fund outflow.

3. A big data-based industry-audit integration audit system according to claim 1, characterized in that, In the data collection and preprocessing module, in the step of processing the real-time data stream of decentralized financial industry audit data by using Apache Kafka and Flink and eliminating abnormal data, the step of eliminating abnormal data specifically includes: Processing the real-time data stream of decentralized financial industry audit data by using Apache Kafka and Flink to obtain an abnormal transaction feature vector Z of the decentralized financial industry audit data; Based on the abnormal transaction feature vector Z and the decentralized financial industry audit data X t , the variational auto-encoding method is used to calculate the probability P of abnormal data; Set the abnormal data probability threshold ∈ th , if P(X t ) < ∈ th , then eliminate X t .

4. A big data-based industry-audit integrated audit system according to claim 1, characterized in that In the standardized feature extraction module, the step of processing the preprocessed financial industry audit data by using the multi-scale time series alignment method adopts the formula: Among them, is the smoothed financial industry audit data for the i-th transaction at time point j; X i,t * is the financial industry audit data for the i-th transaction at time t; w t is the trading volume weighted factor; α is the time decay coefficient used to control the impact of forward transactions on the current financial industry audit data; T is a preset time window; exp(·) is the exponential function; The steps of double-standard normalization processing specifically include: for the transaction data in the preprocessed financial industry audit data, Z-score standardization processing is adopted; for the account behavior data in the preprocessed financial industry audit data, Min-Max normalization processing is adopted.

5. A big data-based industry-audit integrated audit system as claimed in claim 1, characterized in that, In the transaction link analysis module, the steps of constructing a multi-dimensional transaction network based on the financial industry audit feature matrix specifically include: introducing the financial industry audit feature matrix M = {W1, W2, …, W n}, where W p is the dynamic feature weight of the p-th transaction feature in the financial industry audit feature matrix, and n is the total number of transaction features; constructing a multi-dimensional transaction network G based on the financial industry audit feature matrix M: G = (V, E), E e,r = f(X e ', X r ', M), where G is the multi-dimensional transaction network; V is the account node; E e,r is the transaction path between the e-th transaction and the r-th transaction; X e ', X r ' are the transaction data and account behavior data in the financial industry audit data normalized by the standardized feature extraction module.

6. A big data-based industry-audit integration audit system according to claim 5, characterized in that, In the transaction link analysis module, the steps of calculating the transaction pattern similarity according to the multi-dimensional transaction network and combining cross-platform pattern matching analysis to obtain a risk transaction group specifically include: Calculate the mean and variance of the financial industry audit features based on the financial industry audit feature matrix M, and calculate the transaction pattern similarity S based on the mean μ and variance σ of the financial industry audit features i ; where W p is the dynamic feature weight corresponding to the preset financial industry audit data, and X' p is the financial industry audit feature value corresponding to the p-th transaction feature; Using the dynamic feature weight W p After weighting the financial industry audit feature matrix M, use cross-platform transaction mode matching to calculate the abnormal mode score: where Q is the abnormal mode score, and A e,r is the path weight of the transaction path between the e-th transaction and the r-th transaction in the multi-dimensional transaction network G; Presetting an abnormal pattern score threshold, and setting the transactions with abnormal pattern scores greater than the abnormal pattern score threshold as risk transaction groups; The steps of obtaining transaction path risk data by performing path detection on the risk trading group specifically include: introducing a constrained risk propagation coefficient exp(-βd e,r ) calculating the path of suspicious fund flow to obtain transaction path risk data: R path = ∑ e,r A e,r ·exp(-βd e,r )·Q i , where R path is the transaction path risk data, d e,r is the length of the transaction path, β is the risk propagation coefficient weight control factor, and exp(·) is the exponential function.

7. A big data-based industry-audit integration audit system according to claim 1, characterized in that, In the risk comprehensive scoring calculation module, the steps of obtaining transaction data, account behavior data, and fund flow data on the path according to the transaction path risk data and calculating the risk comprehensive score specifically include: Screening out high-risk paths based on the transaction path risk data; Extracting detailed transaction data on the path according to the high-risk path, including transaction data, account behavior data, and fund flow data; Calculate the abnormal transaction amount score, abnormal transaction frequency score, abnormal account behavior score, and abnormal fund flow score based on transaction data, account behavior data, and fund flow data; Use the weighted comprehensive scoring method to calculate the comprehensive risk score of the path; define the risk warning threshold, and trigger the warning mechanism according to the comprehensive risk score and the risk warning threshold, including: low risk: continue to monitor, no immediate processing required; medium risk: mark the account and include it in the key transaction list for attention; high risk: trigger abnormal transaction interception.

Citation Information

Patent Citations

  • Large-scale financial risk early warning method, device and equipment based on deep learning

    CN115965485A

  • Financial service link dyeing method and system for test risk prevention

    CN116126685A

  • Financial account risk early warning method and system based on big data

    CN118779774A

  • Real-time transaction monitoring and analysis system and method of financial big data platform

    CN119067780A

  • Risk control early warning method and system based on bank flow analysis

    CN119273441A

Cited By

  • Financial data intelligent management method and system

    CN120580083A