Abnormal transaction customer detection method and device, and computer program product

Through the combination of the dual clustering proximity model and the approximate nearest neighbor algorithm, the problem of misjudging normal customers in existing abnormal transaction detection is solved, and efficient and accurate identification and disposal of abnormal transaction customers is achieved.

CN120297981APending Publication Date: 2025-07-11中国邮政储蓄银行股份有限公司
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510437174.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-08
Publication Date
2025-07-11

AI Technical Summary

Technical Problem

When the existing anomaly transaction detection system discovers suspicious transaction customers who frequently have similar behaviors, it fails to effectively consider the regular behavior of some normal customers, resulting in low accuracy of misjudgment and detection results. At the same time, the deep neural network model is intensive to calculate, high training cost, and long processing time.

Method used

The dual clustering neighbor model is used to combine the approximate nearest neighbor algorithm to mine the local mode of transaction characteristics through the dual clustering algorithm, calculate the variance and support degree to filter out abnormal customers, and use the ANN algorithm for iterative training to identify potential abnormal trading customers.

Benefits of technology

It improves the accuracy of abnormal transaction detection, reduces the misjudgment rate of normal customers, reduces the demand for computing resources, and realizes efficient identification and disposal of abnormal transaction customers.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120297981A_ABST
    Figure CN120297981A_ABST
Patent Text Reader

Abstract

The invention provides an abnormal transaction customer detection method and apparatus, and a computer program product. The method comprises the steps of obtaining effective data transaction matrixes corresponding to all target customers; inputting the effective data transaction matrix into a bi-clustering proximity model, and performing anomaly detection on the effective data transaction matrix by using the bi-clustering proximity model to obtain all abnormal transaction clients; and executing corresponding exception handling strategies for all the exceptional transaction clients. According to the method and the device, the problem that the accuracy of an abnormal detection result is relatively low due to a misjudged scene caused by the fact that frequent suspicious transaction clients with similar behaviors are mined without considering regular behaviors of part of normal clients is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of abnormal customer detection, and in particular to an abnormal transaction customer detection method, an abnormal transaction customer detection device and a computer program product. Background Art

[0002] With the development of economy and the advancement of technology, the emergence of online banking and the rise of online payment services have led to a spurt in the volume of transactions based on bank card accounts. Under the massive transaction data, there are always some illegal and irregular transaction behaviors hidden. With the enrichment of transaction forms, the means and patterns of these illegal transactions have become more complex and more secretive. Therefore, abnormal transaction detection has become particularly important. However, the problems and defects of the current abnormal transaction detection system mainly include the following aspects:

[0003] (1) The current abnormal transaction detection method mines out suspicious transaction customers with frequent similar behaviors, but does not consider the situation where some normal customers’ regular behaviors lead to misjudgment. For example, in the banking system, the misjudgment of the daily transaction behavior of normal customers causes the card to be frozen, and the normal transaction customer must go to the branch to unfreeze it. Therefore, the detection result is not accurate enough.

[0004] (2) The current method of abnormal transaction detection based on deep neural network model, because neural network is computationally intensive, will cause the overall processing time of the detection system to be too long. In addition, the abnormal transaction detection algorithm based on neural network also has other characteristics such as high training cost, many training parameters, and high data quality requirements.

[0005] (3) Current methods for detecting abnormal transactions invest little in processing sensitive customer transaction data. Summary of the invention

[0006] The main purpose of the present application is to provide an abnormal transaction customer detection method, an abnormal transaction customer detection device and a computer program product, so as to at least solve the problem in the prior art of mining out suspicious transaction customers who frequently have similar behaviors, but not considering the regular behaviors of some normal customers that may lead to misjudgment and result in low accuracy of abnormal detection results.

[0007] In order to achieve the above object, according to one aspect of the present application, a method for detecting abnormal transaction customers is provided, comprising: obtaining a valid data transaction matrix corresponding to all target customers, wherein the element X of the valid data transaction matrix is NrNcIt represents the eigenvalue of the Nc-th transaction feature of the Nr-th target customer, and the transaction features at least include transaction amount, transaction frequency, transaction time, and credit rating; input the effective data transaction matrix into the biclustering proximity model to perform anomaly detection on the effective data transaction matrix by using the biclustering proximity model, so as to obtain all abnormal transaction customers. The biclustering proximity model is a convergence model obtained by using the biclustering algorithm to mine the sample data transaction matrix to obtain biclusters, calculating the variance and support of each bicluster to perform anomaly marking on the target customers to obtain potential abnormal customers, and then using the approximate nearest neighbor algorithm to perform anomaly detection on the potential abnormal customers for iterative training. The support represents the coverage degree of the bicluster in the effective data transaction matrix; execute corresponding anomaly handling strategies for all the abnormal transaction customers, and the anomaly handling strategies at least include freezing the bank funds of the abnormal transaction customers.

[0008] Optionally, obtaining the effective data transaction matrix corresponding to all target customers includes: obtaining the target customer transaction data corresponding to all target customers, where the target customer transaction data includes the transaction features and the eigenvalues corresponding to the transaction features; constructing a data transaction matrix according to all the target customers and the corresponding target customer transaction data, where the rows of the data transaction matrix represent the target customers, the columns of the data transaction matrix represent the transaction features of the target customers, and the elements of the data transaction matrix represent the eigenvalues of the target customers with respect to the transaction features; performing data processing on the data transaction matrix to obtain the effective data transaction matrix, and the data processing at least includes data cleaning processing, data desensitization processing, data normalization processing, and unbalanced data processing.

[0009] Optionally, performing data processing on the data transaction matrix to obtain the effective data transaction matrix includes: performing data cleaning on the data transaction matrix to obtain a cleaned data matrix; performing data desensitization processing on the cleaned data by using the MD5 algorithm to obtain desensitized data; performing normalization processing on the desensitized data to obtain normalized data; using the SMOTE algorithm to process the unbalanced data in the normalized data to obtain the effective data transaction matrix.

[0010] Optionally, input the valid data transaction matrix into a biclustering proximity model to perform anomaly detection on the valid data transaction matrix using the biclustering proximity model, and output all abnormal transaction customers, including: input the valid data transaction matrix into the biclustering submodel in the biclustering proximity model to perform clustering processing on each column of the valid data transaction matrix using a hierarchical clustering method to generate at least one biclustering seed, where the biclustering seed is a column in the valid data transaction matrix, and the biclustering submodel is a convergent model obtained by iteratively training a predetermined model using a biclustering algorithm; expand and merge the biclustering seed with columns in the valid data transaction matrix other than the column where the biclustering seed is located to generate a biclustering set, where the biclustering set is a set formed by multiple biclusterings, and the biclustering is a submatrix in the valid data transaction matrix; calculate the variance and support of each biclustering in the biclustering set; screen the biclusterings with a variance less than a variance threshold and a support greater than a support threshold; calculate the anomaly score values of all the screened biclusterings based on statistical deviation, and determine the target customers corresponding to the biclusterings with an anomaly score value greater than a score threshold as the potential abnormal customers; input the transaction features corresponding to the potential abnormal customers into the approximate nearest neighbor submodel in the biclustering proximity model for anomaly detection, and output all the abnormal transaction customers, where the approximate nearest neighbor submodel includes an input layer, multiple hidden layers, and an output layer.

[0011] Optionally, performing clustering processing on each column of the valid data transaction matrix using a hierarchical clustering method to generate biclustering seeds includes: taking each element in the valid data transaction matrix as an initial cluster; a first calculation step of calculating the distance between any two initial clusters in a target column to obtain a plurality of first cluster distances, where the target column is any column in the valid data transaction matrix that has not been clustered; a merging step of merging the two initial clusters with the smallest first cluster distance into a current cluster set; a second calculation step of recalculating the clustering between the current cluster set and other clusters in the target column to obtain a plurality of second cluster distances, where the other clusters are all clusters in the target column except the current cluster set; a determination step of determining the similarity between two initial clusters in the current cluster set based on the smallest second cluster distance; taking the current cluster set as an initial cluster, and sequentially repeating the first calculation step, the merging step, the second calculation step, and the determination step until all the initial clusters are merged into a biclustering cluster set or the similarity corresponding to all the current cluster sets is greater than a hierarchical clustering threshold; determining the biclustering cluster set or all the current cluster sets as the biclustering seeds.

[0012] Optionally, expand and merge the biclustering seed with the columns in the effective data transaction matrix other than the column where the biclustering seed is located to generate a biclustering set, including: an addition step of adding the current column to the current biclustering seed to obtain an extended submatrix, where the current column is any column in the effective data transaction matrix other than the column where the current biclustering seed is located and participating in the calculation for the first time, and the current biclustering seed is any one of the biclustering seeds; a third calculation step of calculating the mean squared residue score of the extended submatrix according to the first formula, where the first formula is MSRS(x) represents the mean squared residue score, x represents the extended submatrix, R represents the number of rows of the extended submatrix, C represents the number of columns of the extended submatrix, and x ij represents the actual value of the element in the i-th row and j-th column of the extended submatrix, represents the predicted value in the i-th row and j-th column of the extended submatrix; a merging step of, when the mean squared residue score is less than a set threshold, merging the current column with the current biclustering seed and determining the current column as an extended biclustering seed; a repetition step of sequentially repeating the addition step, the third calculation step, and the merging step at least once until all columns have participated in the calculation to obtain all the extended biclustering seeds corresponding to the current biclustering seed, and at the same time, the current biclustering seed and all the extended biclustering seeds form a biclustering; in the case of multiple biclustering seeds, updating the current biclustering seed and sequentially repeating the addition step, the third calculation step, the merging step, and the repetition step at least once until all the biclustering seeds are completed in expansion to obtain the extended biclustering seeds corresponding to each biclustering seed and all the biclusterings; removing the duplicate biclusterings and determining the remaining all biclusterings as the biclustering set.

[0013] Optionally, before calculating the mean squared residue score of the extended submatrix according to the first formula, the method further includes: calculating the overall mean of the extended submatrix according to the second formula, where the second formula is μ1 represents the overall mean; calculating the row effect corresponding to each row in the biclustering submatrix according to the third formula, where the third formula is α i represents the row effect of the i-th row in the extended submatrix; calculating the column effect corresponding to each column in the extended submatrix according to the fourth formula, where the fourth formula is β j represents the column effect of the j-th column in the extended submatrix; adding the overall mean, the row effect corresponding to the i-th row, and the column effect corresponding to the j-th column to obtain the predicted value of the element in the i-th row and j-th column.

[0014] Optionally, calculating the variance and support degree corresponding to each bicluster in the bicluster set includes: a fourth calculation step of calculating the mean value of the current bicluster according to the fifth formula, where the current bicluster is any bicluster to be calculated in the bicluster set, and the fifth formula is μ2 represents the mean value, and A pq represents the element in the p-th row and q-th column of the current bicluster, n represents the number of rows of the current bicluster, and m represents the number of columns of the current bicluster; a fifth calculation step of substituting the mean value into the sixth formula to calculate the variance corresponding to the current bicluster, and the sixth formula is σ1 2 represents the variance corresponding to the current bicluster; a sixth calculation step of calculating the product between the first ratio and the second ratio to obtain the support degree corresponding to the current bicluster, where the first ratio is the ratio of the number of rows of the current bicluster to the number of rows of the effective data transaction matrix, and the second ratio is the ratio of the number of columns of the current bicluster to the number of columns of the effective data transaction matrix; updating the current bicluster, and sequentially repeating the fourth calculation step, the fifth calculation step, and the sixth calculation step at least once until the variances and support degrees corresponding to all the biclusters in the bicluster set are obtained.

[0015] According to another aspect of the present application, there is provided an abnormal transaction customer detection device, and the device includes: an acquisition unit configured to acquire an effective data transaction matrix corresponding to all target customers, where the element X of the effective data transaction matrix NrNc represents the eigenvalue of the Nc-th transaction feature of the Nr-th target customer; an abnormal detection unit configured to input the effective data transaction matrix into a bicluster proximity model to perform abnormal detection on the effective data transaction matrix by using the bicluster proximity model to obtain all abnormal transaction customers, where the bicluster proximity model is a convergent model obtained by using a bicluster algorithm to mine biclusters from a sample data transaction matrix, calculating the variance and support degree of each bicluster, and performing abnormal marking on the target customers to obtain potential abnormal customers, and then using an approximate nearest neighbor algorithm to perform abnormal detection on the potential abnormal customers and iteratively training, and the support degree characterizes the coverage degree of the bicluster in the effective data transaction matrix; an abnormal handling unit configured to execute corresponding abnormal handling strategies on all the abnormal transaction customers, and the abnormal handling strategies at least include freezing the bank funds of the abnormal transaction customers.

[0016] According to still another aspect of the present application, there is provided a computer program product including computer instructions, and when the computer instructions are executed by a processor, any one of the above methods is implemented.

[0017] Applying the technical solution of the present application in the method for detecting abnormal transaction customers, first, obtain the valid data transaction matrix corresponding to all target customers. The element X of the above-mentioned valid data transaction matrix NrNc represents the eigenvalue of the Nc-th transaction feature of the Nr-th above-mentioned target customer. The above-mentioned transaction features at least include transaction amount, transaction frequency, transaction time, and credit rating. Then, input the above-mentioned valid data transaction matrix into the bi-clustering proximity model to perform abnormal detection on the above-mentioned valid data transaction matrix by using the above-mentioned bi-clustering proximity model, and obtain all abnormal transaction customers. The above-mentioned bi-clustering proximity model is a convergence model obtained by using the bi-clustering algorithm to mine bi-clusters from the sample data transaction matrix, calculating the variance and support degree of each above-mentioned bi-cluster to perform abnormal marking on the above-mentioned target customers to obtain potential abnormal customers, and using the approximate nearest neighbor algorithm to perform abnormal detection on the above-mentioned potential abnormal customers and iteratively training. The above-mentioned support degree represents the coverage degree of the above-mentioned bi-cluster in the above-mentioned valid data transaction matrix. Finally, execute corresponding abnormal handling strategies for all the above-mentioned abnormal transaction customers. The above-mentioned abnormal handling strategies at least include freezing the bank funds of the above-mentioned abnormal transaction customers. The present application combines the bi-clustering algorithm and the ANN algorithm to construct a bi-clustering proximity model. In the bi-clustering proximity model, the bi-clustering algorithm is used to mine bi-clusters with row-column consistency local patterns, calculate the variance and support degree of all bi-clusters, screen the bi-clusters that meet the conditions based on the variance and support degree, mark the corresponding target customers, and then use the approximate nearest neighbor algorithm to detect abnormal transaction customers for the marked target customers to obtain the final abnormal transaction customers, and execute corresponding abnormal handling strategies. The present application solves the problem that frequent suspicious transaction customers with similar behaviors are mined, but the regular behaviors of some normal customers are not considered, resulting in misjudgment and low accuracy of abnormal detection results. Brief Description of the Drawings

[0018] Figure 1 Shows a hardware structure block diagram of a mobile terminal for executing a method for detecting abnormal transaction customers provided in an embodiment of the present application;

[0019] Figure 2 Shows a flowchart of a method for detecting abnormal transaction customers provided in an embodiment of the present application;

[0020] Figure 3 Shows an operation process diagram of a bi-clustering proximity model provided in an embodiment of the present application;

[0021] Figure 4 Shows a construction flowchart of a bi-clustering proximity model provided in an embodiment of the present application;

[0022] Figure 5Shows a data pre - processing flow chart provided according to an embodiment of the present application;

[0023] Figure 6 Shows a bi - clustering algorithm flow chart provided according to an embodiment of the present application;

[0024] Figure 7 Shows an extended bi - clustering seed flow chart provided according to an embodiment of the present application;

[0025] Figure 8 Shows a structural block diagram of an abnormal transaction customer detection device provided according to an embodiment of the present application.

[0026] Among them, the above - mentioned drawings include the following reference numerals:

[0027] 102, processor; 104, memory; 106, transmission device; 108, input / output device. Detailed implementation manners

[0028] It should be noted that, without conflict, the embodiments in the present application and the features in the embodiments may be combined with each other. The present application will be described in detail below with reference to the drawings and in combination with the embodiments.

[0029] In order to enable those skilled in the art to better understand the solution of the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.

[0030] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above - mentioned drawings are used to distinguish similar objects, and do not necessarily need to be used to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances, so as to implement the embodiments of the present application described here. In addition, the terms "include" and "have" and any variations thereof are intended to cover non - exclusive inclusion. For example, a process, method, system, product or device including a series of steps or units does not necessarily need to be limited to those clearly listed steps or units, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.

[0031] For the convenience of description, some nouns or terms related to the embodiments of the present application are described below:

[0032] Biclustering is a new clustering method developed based on traditional clustering methods. It can perform clustering operations simultaneously in the row and column directions of a data matrix, clustering data objects that show consistency in certain attributes into classes, and realizing the extraction of specific information in the data matrix.

[0033] ANN algorithm: The Approximate Nearest Neighbor (ANN) algorithm is an algorithm that allows a small amount of error during the search process of nearest neighbor calculation. In the case of large-scale data, it can achieve excellent accuracy in a short time.

[0034] As introduced in the background technology, the current methods for detecting abnormal transactions in the prior art excavate suspicious transaction customers with frequent similar behaviors, without considering the regular behaviors of some normal customers that may lead to misjudgment. For example, in a banking system, misjudging the daily transaction behaviors of normal customers, resulting in the card being frozen, and normal transaction customers having to go to the branch to unfreeze it. Therefore, the detection results are not accurate enough. To solve the problem in the prior art that suspicious transaction customers with frequent similar behaviors are excavated without considering the regular behaviors of some normal customers that may lead to misjudgment, resulting in a low accuracy of abnormal detection results, the embodiments of the present application provide a method for detecting abnormal transaction customers, a device for detecting abnormal transaction customers, and a computer program product.

[0035] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention.

[0036] The method embodiments provided in the embodiments of the present application can be executed on a mobile terminal, a computer terminal, or a similar computing device. Taking running on a mobile terminal as an example, Figure 1 is a hardware structure block diagram of a mobile terminal for a method of detecting abnormal transaction customers in an embodiment of the present invention. As Figure 1 shown, the mobile terminal may include one or more ( Figure 1 only one is shown in Figure 1 a processor 102 (the processor 102 may include, but is not limited to, a processing device such as a microprocessor MCU or a programmable logic device FPGA) and a memory 104 for storing data. Among them, the above mobile terminal may further include a transmission device 106 for communication functions and an input / output device 108. Those of ordinary skill in the art can understand that Figure 1 the structure shown in Figure 1 is only schematic and does not limit the structure of the above mobile terminal. For example, the mobile terminal may further include more or fewer components than

[0037] The memory 104 can be used to store computer programs, for example, software programs of application software and sub-modules, such as the computer program corresponding to the abnormal transaction customer detection method in the embodiments of the present invention. The processor 102 executes various functional applications and data processing by running the computer program stored in the memory 104, that is, implements the above-mentioned method. The memory 104 may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memories, or other non-volatile solid-state memories. In some instances, the memory 104 may further include a memory remotely disposed relative to the processor 102, and these remote memories can be connected to the mobile terminal through a network. Examples of the above-mentioned network include but are not limited to the Internet, enterprise intranets, local area networks, mobile communication networks, and combinations thereof. The transmission device 106 is used to receive or send data via a network. Specific examples of the above-mentioned network may include a wireless network provided by a communication provider of the mobile terminal. In one instance, the transmission device 106 includes a network adapter (Network Interface Controller, abbreviated as NIC), which can be connected to other network devices through a base station and thus can communicate with the Internet. In one instance, the transmission device 106 may be a radio frequency (RF) sub-module, which is used to communicate with the Internet wirelessly.

[0038] In this embodiment, an abnormal transaction customer detection method running on a mobile terminal, a computer terminal, or a similar computing device is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.

[0039] Figure 2 It is a flowchart of the abnormal transaction customer detection method according to the embodiments of the present application. As Figure 2 shown, the method includes the following steps:

[0040] Step S201, obtain the effective data transaction matrix corresponding to all target customers. The element X of the above-mentioned effective data transaction matrix NrNc represents the eigenvalue of the Nc-th transaction feature of the Nr-th above-mentioned target customer. The above-mentioned transaction features at least include transaction amount, transaction frequency, transaction time, and credit rating.

[0041] Specifically, Figure 3 shows a running process diagram of a biclustering proximity model provided by the embodiments of the present application. As Figure 3As shown, the first stage is the data preparation stage, so it is necessary to construct a data matrix: construct the customer transaction data into a matrix X with N rows and M columns N×M , where the rows represent customers and the columns represent transaction characteristics (such as transaction amount, transaction frequency, transaction time, etc.), and the elements in X N×M are X NrNc .

[0042] Step S202: Input the above valid data transaction matrix into the biclustering proximity model to use the above biclustering proximity model to perform anomaly detection on the above valid data transaction matrix, and obtain all abnormal transaction customers. The above biclustering proximity model is a convergence model obtained by using the biclustering algorithm to mine the sample data transaction matrix to obtain biclusters, calculating the variance and support of each above bicluster to perform anomaly marking on the above target customers to obtain potential abnormal customers, and using the approximate nearest neighbor algorithm to perform anomaly detection on the above potential abnormal customers and iteratively training. The above support represents the coverage degree of the above bicluster in the above valid data transaction matrix.

[0043] Specifically, take the valid data transaction matrix as the input and send it to the previously trained biclustering proximity model. This model is trained through the following process: First, use an improved biclustering algorithm to deeply mine the sample data transaction matrix to find local patterns (biclusters) with characteristic linkage consistency. Subsequently, calculate the variance and support of each bicluster, and based on this, perform preliminary anomaly marking on the target customers to screen out potential abnormal customers. Finally, use the approximate nearest neighbor algorithm (ANN) to perform further anomaly detection on these potential abnormal customers, and through multiple iterative trainings, make the model reach a convergence state, forming a machine learning model that can accurately identify abnormal transactions. Through the biclustering proximity model, abnormal patterns outside normal transaction behaviors can be identified, and these patterns are often difficult to capture through a single feature or traditional clustering methods. With the calculation of variance and support, the model can more finely distinguish abnormal transactions from normal transactions and reduce the false alarm rate for normal customers. The adoption of the ANN algorithm enables the model to remain efficient when dealing with large-scale data sets and reduces the demand for computing resources.

[0044] More specifically, a biclustering algorithm is used to analyze the valid data transaction matrix to find local patterns (biclusters). A novel and effective biclustering algorithm proposed by the present invention is used to mine row-column consistent patterns. Compared with the results of ordinary clustering, the clustering results obtained by the biclustering algorithm have more specific meanings because they cluster both rows and columns simultaneously, and obtain consistent behavior patterns on a certain set of attributes. The biclusters mined by the present invention have consistent behavior patterns of customer transaction feature linkage. The biclustering algorithm will output some sub-matrices (i.e., local combinations of customers and transaction features), and these sub-matrices may contain abnormal patterns. It is necessary to mark the abnormal patterns and then determine potential abnormal customers. The local patterns extracted by the biclustering algorithm are used as input features, combined with the original transaction data, to perform anomaly detection to determine the final abnormal transaction customers.

[0045] Step S203: Execute corresponding abnormal handling strategies for all the above-mentioned abnormal transaction customers. The above-mentioned abnormal handling strategies at least include freezing the bank funds of the above-mentioned abnormal transaction customers.

[0046] Specifically, once abnormal transaction customers are identified through the biclustering proximity model, the next step is to take appropriate handling strategies for these customers. The handling strategies mainly include freezing the bank funds of the abnormal transaction customers to prevent further illegal activities. At the same time, the system may also notify the risk management department or the legal department to conduct manual reviews or legal procedures on these accounts marked as abnormal. In short, the entire anomaly detection process starts from data integration, mines biclustering patterns with consistent feature linkages, combines variance and support to screen out abnormal transaction customers, and finally takes handling measures such as freezing accounts to form a complete mechanism for detecting and processing abnormal transaction customers. This can not only improve the accuracy of detection, reduce interference to normal customers, but also maintain the efficient operation of the system under limited resources, achieving a balance between financial security and user experience.

[0047] In this embodiment, first, obtain the valid data transaction matrix corresponding to all target customers. The element X of the above-mentioned valid data transaction matrix NrNcDenote the eigenvalue of the Nc-th transaction feature of the Nr-th above-mentioned target customer, where the above-mentioned transaction features at least include transaction amount, transaction frequency, transaction time, and credit rating; then, input the above-mentioned valid data transaction matrix into the biclustering proximity model to use the above-mentioned biclustering proximity model to perform anomaly detection on the above-mentioned valid data transaction matrix to obtain all abnormal transaction customers. The above-mentioned biclustering proximity model is a convergence model obtained by using the biclustering algorithm to mine biclusters from the sample data transaction matrix, calculating the variance and support degree of each above-mentioned bicluster to mark the above-mentioned target customers as potential abnormal customers, and using the approximate nearest neighbor algorithm to perform anomaly detection on the above-mentioned potential abnormal customers and iteratively training. The above-mentioned support degree represents the coverage degree of the above-mentioned bicluster in the above-mentioned valid data transaction matrix; finally, execute corresponding anomaly handling strategies for all the above-mentioned abnormal transaction customers. The above-mentioned anomaly handling strategies at least include freezing the bank funds of the above-mentioned abnormal transaction customers. This application constructs a biclustering proximity model by combining the biclustering algorithm and the ANN algorithm. In the biclustering proximity model, the biclustering algorithm is used to mine biclusters with row-column consistency local patterns, calculate the variance and support degree of all biclusters, screen biclusters that meet the conditions based on the variance and support degree, mark the corresponding target customers, and then use the approximate nearest neighbor algorithm to detect abnormal transaction customers for the marked target customers to obtain the final abnormal transaction customers and execute corresponding anomaly handling strategies. This application solves the problem that the accuracy of the anomaly detection result is relatively low due to the situation that suspicious transaction customers with frequent and similar behaviors are mined, but the regular behaviors of some normal customers are not considered and misjudgment occurs.

[0048] In order to enable those skilled in the art to more clearly understand the technical solution of this application, the implementation process of the abnormal transaction customer detection method of this application will be described in detail below in conjunction with specific embodiments.

[0049] In an optional implementation manner, in order to improve the quality of customer data to improve the detection accuracy of the biclustering proximity model, the above step S201 includes:

[0050] Step S2011, obtain the target customer transaction data corresponding to all target customers, where the above target customer transaction data includes the above transaction features and the above eigenvalues corresponding to the above transaction features;

[0051] Step S2012, construct a data transaction matrix according to all the above target customers and the corresponding above target customer transaction data. The rows of the above data transaction matrix represent the above target customers, the columns of the above data transaction matrix represent the above transaction features of the above target customers, and the elements of the above data transaction matrix represent the above eigenvalues of the above target customers with respect to the above transaction features;

[0052] In step S2013, data processing is performed on the above data transaction matrix to obtain the above valid data transaction matrix. The data processing at least includes data cleaning, data desensitization, data normalization, and imbalanced data processing.

[0053] In the above embodiment, the customer transaction data of all customers is constructed into a matrix (i.e., the above data transaction matrix), where the rows represent customers and the columns represent transaction characteristics (such as transaction amount, transaction frequency, transaction time, etc.). For each transaction characteristic of each customer, a corresponding specific value, i.e., a feature value, will be assigned. Collecting complete transaction data is the basis for subsequent analysis. Ensuring that the system grasps all relevant transaction information of the target customers can analyze customer behavior more comprehensively. The collected target customer transaction data is organized into a data transaction matrix. The rows of the matrix represent each target customer, the columns represent different transaction characteristics, and each element in the matrix represents the specific value of the customer on a certain transaction characteristic. For example, the first row of the matrix may represent the first target customer, and the value under the "transaction amount" column is the feature value of the customer's transaction amount. Converting the original data into a structured matrix form facilitates subsequent processing using the biclustering proximity model. After constructing the data transaction matrix, the next step is to perform a series of data preprocessing on the matrix to obtain a higher-quality valid data transaction matrix. The preprocessing includes: Data cleaning: Removing or correcting obviously incorrect or unreasonable data, such as extremely high transaction amounts or missing values. Data desensitization: Using the MD5 algorithm or other privacy protection technologies to process sensitive information (such as customer IDs, account details, etc.), retaining the analysis value of the data while protecting customer privacy. Data normalization: Ensuring the comparability of different features on the numerical scale through min-max normalization or Z-score standardization, etc. Imbalanced data processing: Using oversampling (such as the SMOTE algorithm) or undersampling and other means to balance the ratio of normal transactions to abnormal transactions and improve the training effect of the model. Data cleaning and normalization processing can reduce noise and make the model training more robust; imbalanced data processing avoids the model being overly biased towards the majority class and improves the accuracy of anomaly detection. Data desensitization ensures that customer sensitive information will not be leaked during the analysis process, meeting the requirements of data security and privacy protection regulations. The preprocessed valid data transaction matrix is more conducive to the understanding and learning of the model, helping to improve the training efficiency and detection accuracy of the biclustering proximity model.

[0054] In order to improve the security of privacy protection and data class imbalance, in an optional implementation manner, the above step S2013 includes:

[0055] Step S20131, perform data cleaning on the above data transaction matrix to obtain a cleaned data matrix;

[0056] Step S20132: Perform data desensitization processing on the above-mentioned cleaned data using the MD5 algorithm to obtain desensitized data;

[0057] Step S20133: Perform normalization processing on the above-mentioned desensitized data to obtain normalized data;

[0058] Step S20134: Use the SMOTE algorithm to process the imbalanced data in the above-mentioned normalized data to obtain the above-mentioned valid data transaction matrix.

[0059] In the above embodiment, as Figure 5 shown, data cleaning is performed on the data transaction matrix, and the MD5 algorithm is used to decrypt sensitive data, that is, the sensitive data is processed into a meaningless string to avoid the leakage of sensitive information when using the data. Features with a large number of missing values are processed. If the missing amount of a certain feature is too large, it is directly discarded; if the proportion of missing values is small, it is filled with the median. Of course, other data can also be used for filling, such as the mode. Then, the min-max normalization algorithm is applied to normalize the data, and finally the SMOTE algorithm is used to process the imbalanced data. Through data cleaning processing, such as removing missing values, outliers, and duplicate data, the integrity and consistency of the data are ensured. Data desensitization processing, such as using the MD5 algorithm, protects customer privacy and avoids the risk of sensitive information leakage. Data normalization processing brings different-dimensional transaction features to the same scale, which is beneficial to subsequent clustering analysis. Imbalanced data processing balances the proportion of positive and negative samples through the SMOTE algorithm, prevents the model from being biased towards majority-class predictions, and improves the accuracy of abnormal transaction detection. The combination of these data preprocessing steps solves problems such as low quality of original transaction data, insufficient privacy protection, and class imbalance, provides a high-quality data basis for subsequent abnormal detection, and ensures the effectiveness and security of the entire risk control process.

[0060] In order to effectively solve the situation of misjudging normal customers, in an optional implementation manner, the above-mentioned step S202 includes:

[0061] Step S2021: Input the above-mentioned valid data transaction matrix into the biclustering sub-model in the above-mentioned biclustering proximity model to perform clustering processing on each column of the above-mentioned valid data transaction matrix using the hierarchical clustering method, generating at least one biclustering seed, where the biclustering seed is a column in the above-mentioned valid data transaction matrix, and the biclustering sub-model is a convergent model obtained by iteratively training a predetermined model using the biclustering algorithm;

[0062] Step S2022: Expand and merge the above-mentioned biclustering seeds with the columns in the above-mentioned valid data transaction matrix except the column where the above-mentioned biclustering seeds are located to generate a biclustering set. The above-mentioned biclustering set is a set formed by multiple biclusters, and the above-mentioned bicluster is a submatrix in the above-mentioned valid data transaction matrix;

[0063] Step S2023: Calculate the variance and support degree corresponding to each of the above-mentioned biclusters in the above-mentioned biclustering set;

[0064] Step S2024: Filter out the above-mentioned biclusters whose variance is less than the variance threshold and whose support degree is greater than the support degree threshold;

[0065] Step S2025: Calculate the anomaly score values of all the filtered above-mentioned biclusters based on statistical deviation, and determine the above-mentioned target customers corresponding to the above-mentioned biclusters with anomaly score values greater than the score threshold as the above-mentioned potential abnormal customers;

[0066] Step S2026: Input the above-mentioned transaction characteristics corresponding to the above-mentioned potential abnormal customers into the approximate nearest neighbor submodel in the above-mentioned biclustering proximity model for anomaly detection, and output all the above-mentioned abnormal transaction customers. The above-mentioned approximate nearest neighbor submodel includes an input layer, multiple hidden layers, and an output layer.

[0067] In the above embodiment, the improved biclustering algorithm is applied to the customer transaction matrix to mine the consistent behavior pattern biclusters. As Figure 4As shown in the figure, the improved biclustering algorithm is divided into two steps: the first step is to generate initial biclustering seeds by applying agglomerative hierarchical clustering (HC) in each column of the matrix; the second step is to expand and merge the biclustering seeds generated in the first step along the column direction to form a biclustering, and obtain a biclustering set. Through the improved biclustering algorithm, a biclustering result (i.e., a biclustering set) is obtained. Variance is an index to measure the volatility of data and can be used to evaluate the significance of biclustering. The smaller the variance, the more consistent the data within the biclustering. Support is the coverage degree of the biclustering in the dataset, which can be measured by calculating the proportion of rows and columns in the biclustering in the effective data transaction matrix. Set thresholds according to variance and support, and screen out qualified biclusters. For example, screen out biclusters with variance less than a certain threshold and support greater than a certain threshold. Calculate the anomaly score value for each screened bicluster based on statistical deviation, and mark the customers in the submatrix with a higher anomaly score value as potential abnormal customers. Finally, use the approximate nearest neighbor submodel (ANN algorithm model) to further detect potential abnormal customers to determine the final abnormal transaction customers. The ANN model includes an input layer (for receiving biclustering features), multiple hidden layers (for extracting and processing complex features), and an output layer (for predicting the anomaly probability). Through training, the model can distinguish normal and abnormal transaction patterns. After inputting the potential abnormal customer data into the model, the output is the probability that the customer belongs to an abnormal transaction, so as to mark and identify abnormal transaction customers. It solves the situation in the current commonly used abnormal transaction detection methods that frequent suspicious transaction customers with similar behaviors are mined, but the regular behaviors of some normal customers are not considered and they are misjudged, effectively solving the situation of misjudging normal customers and improving the accuracy of the detection results.

[0068] It should be noted that the anomaly score values of all the above-mentioned screened biclusters are calculated based on statistical deviation, including: calculating the global mean of the effective data transaction matrix according to the seventh formula, and the above-mentioned seventh formula is μ3 represents the above-mentioned global mean, N represents the total number of rows of the above-mentioned effective data transaction matrix, and M represents the total number of columns of the above-mentioned effective data transaction matrix; calculate the global variance of the effective data transaction matrix according to the eighth formula, and the above-mentioned eighth formula is σ2 2 represents the above-mentioned global variance. The variance (global variance) of the effective data transaction matrix is used to measure the dispersion degree of all elements in the effective data transaction matrix. The variance calculation of the bicluster is similar to that of the effective data transaction matrix, but only for the elements within the bicluster. Calculate the mean of each of the above-mentioned biclusters according to the above-mentioned fifth formula; substitute the mean of each of the above-mentioned biclusters into the above-mentioned sixth formula to calculate the variance of the above-mentioned bicluster correspondingly; calculate the ratio between the variance of the above-mentioned bicluster and the above-mentioned global variance to obtain the above-mentioned anomaly score value, that is σ12 is the variance of the above biclustering.

[0069] It should also be noted that an ANN model is designed to learn the behavior patterns of normal and abnormal customers.

[0070] The ANN model includes: 1. Input layer: The input features are the local pattern features extracted by biclustering (i.e., the transaction features corresponding to potential abnormal customers).

[0071] 2. Hidden layer: Multiple hidden layers are designed and the ReLU activation function is used.

[0072] Number of layers: 1 - 3 hidden layers are selected according to the data complexity.

[0073] Number of nodes: The number of nodes in each hidden layer can be selected as 32, 64, 128, etc., and is specifically adjusted according to experiments.

[0074] Activation function: The ReLU (Rectified Linear Unit) activation function is used.

[0075] 3. Output layer: The Sigmoid function is used to output the anomaly probability.

[0076] (1) Number of nodes: 1 node (for handling binary classification problems).

[0077] (2) Activation function: The Sigmoid activation function is used, and the formula is: The output range is [0, 1], and f(t) represents the anomaly probability of the transaction feature t corresponding to the potential abnormal customer.

[0078] 4. The binary cross - entropy loss function (Binary Cross - Entropy Loss) is used to calculate the loss value, and the formula is: where y i is the true label, is the predicted probability

[0079] 5. Optimizer: The Adam optimizer is used, and the learning rate is set to 0.001.

[0080] The core of Adam is:

[0081] Calculate the first - order moment estimate (momentum) of the gradient: The exponential weighted moving average of the gradient is used to accelerate convergence.

[0082] m t = β1·m t-1 +(1 - β1)·g t

[0083] Second - order moment estimation of computing gradient (adaptive learning rate): Use the exponentially weighted moving average of the squared gradient to adjust the learning rate. v t = β2·v t-1 +(1 - β2)·g t 2

[0084] (3) Bias correction: Since the moment estimation at the initial moment tends to be 0, Adam corrects the estimated value through bias correction.

[0085]

[0086] (4) Update parameters:

[0087]

[0088] where g t is the gradient at the current time step, m t and v t are the first - order moment and second - order moment estimations of the gradient respectively, β1 and β2 are hyperparameters, usually taking values β1 = 0.9, β2 = 0.999, η is the learning rate. ∈ is a very small constant (such as 10 -8 ), used to prevent division - by - zero errors.

[0089] 6. Evaluation metrics:

[0090] Accuracy: The proportion of correctly classified.

[0091] Precision: The proportion of actually abnormal among the predicted abnormal customers.

[0092] Recall: The proportion of actually abnormal customers that are correctly predicted.

[0093] F1 - score: The harmonic mean of precision and recall.

[0094] In order to calculate the biclustering seeds reflecting local behavior patterns, in an optional implementation manner, the above - mentioned step S2021 includes:

[0095] Step S20211, taking each element in the above - mentioned valid data transaction matrix as an initial cluster;

[0096] Step S20212, the first calculation step, calculating the distance between any two initial clusters in the target column, obtaining a plurality of first - cluster distances, where the target column is any column in the above - mentioned valid data transaction matrix that has not been clustered;

[0097] Step S20213, the merging step, merging the two initial clusters with the smallest first - cluster distance into the current cluster set;

[0098] Step S20214, the second calculation step, recalculate the clustering between the above-mentioned current cluster set and other clusters in the above-mentioned target column to obtain a plurality of second cluster distances, where the above-mentioned other clusters are all clusters in the above-mentioned target column except the above-mentioned current cluster set;

[0099] Step S20215, the determination step, determine the similarity between two of the above-mentioned initial clusters in the above-mentioned current cluster set by taking the smallest of the above-mentioned second cluster distances;

[0100] Step S20216, take the above-mentioned current cluster set as one of the above-mentioned initial clusters, and repeat the above-mentioned first calculation step, the above-mentioned merging step, the above-mentioned second calculation step, and the above-mentioned determination step in sequence until all the above-mentioned initial clusters are merged into a bicluster set or the similarity corresponding to all the above-mentioned current cluster sets is greater than the hierarchical clustering threshold;

[0101] Step S20217, determine the above-mentioned bicluster set or all the above-mentioned current cluster sets as the above-mentioned bicluster seeds.

[0102] In the above embodiment, the specific implementation process of the improved biclustering algorithm is as Figure 6 shown. In the first step, the agglomerative hierarchical clustering algorithm is applied to each column of the matrix. The specific method is: for the input matrix X, that is, the effective data transaction matrix, for each column k Nc (Nc = 1, 2,..., M), first regard each data element as an initial cluster. Therefore, for column k Nc there are Nc data objects to be clustered, and the size of its distance matrix is M×M. The basic idea of the agglomerative hierarchical clustering algorithm based on the minimum distance is:

[0103] (1) Merge the clusters with the smallest Euclidean distance d(Nr, Nc), that is, the two closest clusters, into a new cluster (i.e., the above-mentioned current cluster set);

[0104] (2) Select the minimum distance value between the new cluster and other clusters as the similarity between the two clusters, that is, recalculate the distance d(Nr, Nc) between the new cluster and other clusters;

[0105] (3) Repeat steps (2) and (3) until all initial clusters are merged into one cluster or the inter-cluster distance (similarity) of the current cluster set exceeds a pre-set threshold Thc. The inter-cluster distance is an important concept in clustering analysis and is used to measure the separation degree between different clusters. The calculation method of the inter-cluster distance: the distance between the centroids (center points) of two clusters.

[0106] (4) Agglomerative hierarchical clustering based on the minimum distance merges similar data elements into a cluster. Therefore, the clusters obtained by the hierarchical clustering algorithm are regarded as bicluster seeds. In other words, for a column, the clustering obtained by the hierarchical clustering method serves as the bicluster seeds of the biclustering, and then the columns are subsequently extended to expand the bicluster seeds and obtain the biclustering.

[0107] Overall, the above steps implement an independent clustering process for each column in the effective data transaction matrix, forming bicluster seeds that reflect local behavior patterns. This not only helps to uncover the commonalities among customer groups in a single transaction feature but also lays a foundation for the subsequent expansion and merging of cross-column patterns (i.e., biclustering).

[0108] In order to effectively expand and merge bicluster seeds to form a set of biclusters covering the combinations of customers and transaction features in the effective data transaction matrix, in an optional implementation manner, the above step S2022 includes:

[0109] Step S20221, addition step, add the current column to the current bicluster seed to obtain an extended submatrix. The above current column is any column other than the column where the current bicluster seed is located in the above effective data transaction matrix and participates in the calculation for the first time. The above current bicluster seed is any one of the above bicluster seeds;

[0110] Step S20222, third calculation step, calculate the mean squared residue score of the above extended submatrix according to the first formula. The above first formula is MSRS(x) represents the above mean squared residue score, x represents the above extended submatrix, R represents the number of rows of the above extended submatrix, C represents the number of columns of the above extended submatrix, x ij represents the actual value of the element in the i-th row and j-th column of the above extended submatrix, represents the predicted value in the i-th row and j-th column of the above extended submatrix;

[0111] Step S20223, merging step, in the case where the above mean squared residue score is less than the set threshold, merge the above current column with the above current bicluster seed and determine the above current column as the extended bicluster seed;

[0112] Step S20224, repetition step, sequentially repeat the above addition step, the above third calculation step, and the above merging step at least once until all columns have participated in the calculation to obtain all the above extended bicluster seeds corresponding to the above current bicluster seed. At the same time, the above current bicluster seed and all the above extended bicluster seeds form a bicluster;

[0113] Step S20225, in the case of having multiple such biclustering seeds, update the current biclustering seeds, and sequentially repeat the above adding step, the above calculating step, the above merging step, and the above repeating step at least once until all the above biclustering seeds are completed in expansion, so as to obtain the above expanded biclustering seeds corresponding to each of the above biclustering seeds and all the above biclusterings;

[0114] Step S20226, remove the duplicate above biclusterings, and determine the remaining all the above biclusterings as the above biclustering set.

[0115] In the above embodiment, Figure 7 it shows the process of forming a biclustering set from expanded biclustering seeds. As Figure 7 shown, for a biclustering seed s_bic clustered from the Nc-th (Nc = 1, 2,..., M) column in the HC_Set set (the set formed by all biclustering seeds), s_bic = (Nr, CNc), if the mean square residue score (MSRS(x), which may be represented by 1sd in Figure 7 is small and less than a preset threshold δ for the matrix (expanded sub-matrix) formed after adding the biclustering seed s_bic with a certain column 1 (1 ≠ Nc), then merge the biclustering seed s_bic with the first column, and loop this process to add new columns to the biclustering seed until all the biclustering seeds are expanded to the maximum. The expanded biclustering seeds are all regarded as the final biclustering results, and the biclusterings are saved in the Bic_set set (the set formed by all biclusterings). After this step, the Bic_Set set contains the final biclustering output, and each biclustering can be represented as A(n, m), where In addition, for two or more identical biclusters, i.e., when the row and column sets of the biclusters are the same, the duplicate biclusters need to be deleted, and only one of the biclusters is retained to ensure the uniqueness of the bicluster results in the Bic_Set set. Calculating the Mean Squared Residual Score (MSRS) of the matrix is a key step in bicluster analysis, which is used to measure the consistency between rows and columns in the extended submatrix. The smaller the value of MSRS, the higher the consistency of the extended submatrix, and the stronger the relationship between rows and columns. The quality of biclusters is controlled by setting a threshold δ. Moreover, due to the uneven sizes of bicluster results and the too small number of clustering rows, the determination of the feature selection pattern is random. Therefore, the present invention stipulates that an effective feature selection rule should include at least 5 rows, i.e., 5 transaction features. This means that in the customer transaction matrix, there are at least 5 feature combinations indicating consistent or similar behaviors. Through the above process, bicluster seeds can be effectively extended and merged to form a bicluster set covering customer and transaction feature combinations in the effective data transaction matrix. These biclusters can not only reflect local behavior patterns, but also ensure the effectiveness and non-repetitiveness of local patterns through deduplication and consistency-based screening, providing a high-quality basis for subsequent anomaly scoring and abnormal customer identification.

[0116] In order to calculate the predicted value, in an optional implementation manner, before the above step S20222, the method further includes:

[0117] Step S301, calculating the overall mean of the above extended submatrix according to the second formula, and the second formula is μ represents the above overall mean;

[0118] Step S302, calculating the row effect corresponding to each of the above rows in the above bicluster submatrix according to the third formula, and the third formula is αi represents the above row effect of the i-th row in the above extended submatrix;

[0119] Step S303, calculating the column effect corresponding to each of the above columns in the above extended submatrix according to the fourth formula, and the fourth formula is β j represents the above column effect of the j-th column in the above extended submatrix;

[0120] Step S304, adding the above overall mean, the above row effect corresponding to the i-th row, and the above column effect corresponding to the j-th column to obtain the above predicted value of the i-th row and j-th column.

[0121] In the above embodiment, in bicluster analysis, the predicted value is usually calculated by the following formula: where μ1 is the overall mean of the extended submatrix, ɑi To expand the row effect of the \(i\)-th row of the extended sub-matrix (representing the deviation of the row mean from the overall mean), \(\beta\) j is the column effect of the \(j\)-th column of the extended sub-matrix (representing the deviation of the column mean from the overall mean). Overall, steps S301 to S304 construct a model for predicting and evaluating the consistency of customer behavior in local patterns within the extended sub-matrix. By calculating the overall mean, row effects, and column effects, as well as the predicted values generated based on these values, it is possible to more accurately identify which local patterns of customer behavior deviate from expectations, thus contributing to the detection of abnormal transactions.

[0122] To effectively screen out biclusters that do not meet the criteria, in an optional implementation manner, the above step S2023 includes:[[]]

[0123] Step S20231, the fourth calculation step, calculates the mean of the current bicluster according to the fifth formula. The above current bicluster is any one of the biclusters to be calculated in the above bicluster set. The above fifth formula is \(\mu_2\) represents the above mean, \(A\) pq represents the element in the \(p\)-th row and \(q\)-th column of the above current bicluster, \(n\) represents the number of rows of the above current bicluster, and \(m\) represents the number of columns of the above current bicluster;

[0124] Step S20232, the fifth calculation step, substitutes the above mean into the sixth formula to calculate the above variance corresponding to the above current bicluster. The above sixth formula is \(\sigma_1\) 2 represents the above variance corresponding to the above current bicluster;

[0125] Step S20233, the sixth calculation step, calculates the product between the first ratio and the second ratio to obtain the above support degree corresponding to the above current bicluster. The above first ratio is the ratio between the number of rows of the above current bicluster and the number of rows of the above valid data transaction matrix, and the above second ratio is the ratio between the number of columns of the above current bicluster and the number of columns of the above valid data transaction matrix;

[0126] Step S20234, updates the above current bicluster, and sequentially repeats the above fourth calculation step, the above fifth calculation step, and the above sixth calculation step at least once until the above variances and the above support degrees corresponding to all the above biclusters in the above bicluster set are obtained.

[0127] In the above embodiments, the biclustering set is obtained through the improved biclustering algorithm. Variance is an index to measure data volatility and can be used to evaluate the significance of biclustering. Support is the coverage of a biclustering in the dataset and can be measured by calculating the proportion of rows and columns in the biclustering. For each candidate biclustering, calculate the variance of the internal data. The smaller the variance, the more consistent the data within the biclustering. (1) The calculation formula of biclustering variance is as follows: First, calculate the mean of the biclustering: Then calculate the variance of the biclustering: Support calculation: Support is the coverage of a biclustering in the dataset. It can be measured by calculating the proportion of rows and columns in the biclustering. Support can be defined as: The above steps are used to complete the calculation of variance and support for all biclusterings. The calculation of variance and support provides a quantitative basis for subsequent biclustering screening. By setting appropriate thresholds, biclusterings that do not meet the standards can be effectively screened out, improving the accuracy and efficiency of anomaly detection, reducing the probability of false alarms, and improving the performance of the detection system.

[0128] It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. And although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.

[0129] The embodiment of the present application also provides an abnormal transaction customer detection device. It should be noted that the abnormal transaction customer detection device of the embodiment of the present application can be used to execute the abnormal transaction customer detection method provided by the embodiment of the present application. This device is used to implement the above embodiments and preferred implementation manners, and those that have been described will not be repeated. As used hereinafter, the term "sub-module" can be a combination of software and / or hardware that can achieve a predetermined function. Although the devices described in the following embodiments are preferably implemented in software, implementation in hardware, or a combination of software and hardware is also possible and contemplated.

[0130] The abnormal transaction customer detection device provided by the embodiment of the present application is introduced below.

[0131] Figure 8 is a structural block diagram of the abnormal transaction customer detection device according to the embodiment of the present application. As Figure 8 shown, the device includes:

[0132] An acquisition unit 10, configured to acquire a valid data transaction matrix corresponding to all target customers. The element X of the above valid data transaction matrix NrNc represents the eigenvalue of the Nc-th transaction feature of the Nr-th above target customer. The above transaction features at least include transaction amount, transaction frequency, transaction time, and credit rating.

[0133] Specifically, Figure 3 FIG. shows a running process diagram of a biclustering proximity model provided by an embodiment of the present application, as Figure 3 shown. The first stage is the data preparation stage, so it is necessary to construct a data matrix: construct the customer transaction data into a matrix X with N rows and M columns N×M , where the rows represent customers and the columns represent transaction features (such as transaction amount, transaction frequency, transaction time, etc.), and the elements in X N×M are X NrNc .

[0134] Anomaly detection unit 20 is configured to input the above-mentioned valid data transaction matrix into the biclustering proximity model to perform anomaly detection on the above-mentioned valid data transaction matrix by using the above-mentioned biclustering proximity model, so as to obtain all abnormal transaction customers. The above-mentioned biclustering proximity model is a convergence model obtained by using a biclustering algorithm to mine the sample data transaction matrix to obtain biclusters, calculating the variance and support degree of each above-mentioned bicluster to perform anomaly marking on the above-mentioned target customers to obtain potential abnormal customers, and using the approximate nearest neighbor algorithm to perform anomaly detection on the above-mentioned potential abnormal customers and iteratively training. The above-mentioned support degree represents the coverage degree of the above-mentioned bicluster in the above-mentioned valid data transaction matrix.

[0135] Specifically, take the valid data transaction matrix as the input and feed it into the previously trained biclustering proximity model. This model is trained through the following process: First, use an improved biclustering algorithm to deeply mine the sample data transaction matrix to find local patterns (biclusters) with characteristic linkage consistency. Subsequently, calculate the variance and support degree of each bicluster, and based on this, perform preliminary anomaly marking on the target customers to screen out potential abnormal customers. Finally, use the approximate nearest neighbor algorithm (ANN) to perform further anomaly detection on these potential abnormal customers, and through multiple iterative trainings, make the model reach a convergence state, forming a machine learning model that can accurately identify abnormal transactions. Through the biclustering proximity model, abnormal patterns outside normal transaction behaviors can be identified, and these patterns are often difficult to capture by single features or traditional clustering methods. By calculating the variance and support degree, the model can more finely distinguish abnormal transactions from normal transactions and reduce the false alarm rate for normal customers. The adoption of the ANN algorithm enables the model to remain efficient when dealing with large-scale data sets and reduces the demand for computing resources.

[0136] More specifically, a biclustering algorithm is used to analyze the valid data transaction matrix to find local patterns (biclusters). A novel and effective biclustering algorithm proposed by the present invention is used to mine row-column consistent patterns. Compared with ordinary clustering results, the clustering results obtained by the biclustering algorithm have more specific meanings because they cluster both rows and columns simultaneously, and obtain a consistent behavior pattern on a certain set of attributes. The biclusters mined by the present invention have a consistent behavior pattern of customer transaction feature linkage. The biclustering algorithm will output some submatrices (i.e., local combinations of customers and transaction features), and these submatrices may contain abnormal patterns. It is necessary to mark the abnormal patterns to determine potential abnormal customers. The local patterns extracted by the biclustering algorithm are used as input features, combined with the original transaction data, for anomaly detection to determine the final abnormal transaction customers.

[0137] An anomaly handling unit 30 is configured to execute corresponding anomaly handling strategies for all the above-mentioned abnormal transaction customers. The above-mentioned anomaly handling strategies at least include freezing the bank funds of the above-mentioned abnormal transaction customers.

[0138] Specifically, once abnormal transaction customers are identified through the biclustering proximity model, the next step is to adopt appropriate handling strategies for these customers. The handling strategies mainly include freezing the bank funds of the abnormal transaction customers to prevent further illegal activities. At the same time, the system may also notify the risk management department or the legal department to conduct manual review or legal procedures on these accounts marked as abnormal. In short, the entire anomaly detection process starts from data integration, mines biclustering patterns with consistent feature linkages, combines variance and support to screen out abnormal transaction customers, and finally takes handling measures such as freezing accounts to form a complete mechanism for detecting and handling abnormal transaction customers. This can not only improve the detection accuracy, reduce the interference to normal customers, but also maintain the efficient operation of the system under limited resources, achieving a balance between financial security and user experience.

[0139] In this embodiment, by combining the biclustering algorithm and the ANN algorithm, a biclustering proximity model is constructed. In the biclustering proximity model, the biclustering algorithm is used to mine biclusters of row-column consistent local patterns, and the variance and support of all biclusters are calculated. Based on the variance and support, biclusters that meet the conditions are screened out, and their corresponding target customers are marked. Then, the approximate nearest neighbor algorithm is used to detect abnormal transaction customers among the marked target customers to obtain the final abnormal transaction customers, and corresponding anomaly handling strategies are executed. This application solves the problem that frequent suspicious transaction customers with similar behaviors are mined, but the regular behaviors of some normal customers are not considered, resulting in a lower accuracy of anomaly detection results due to misjudgment.

[0140] In order to improve the quality of customer data to improve the detection accuracy of the biclustering proximity model, in an optional implementation manner, the above-mentioned acquisition unit includes:

[0141] An acquisition module for acquiring target customer transaction data corresponding to all target customers, where the target customer transaction data includes the above-mentioned transaction features and the above-mentioned feature values corresponding to the above-mentioned transaction features;

[0142] A construction module for constructing a data transaction matrix based on all the above-mentioned target customers and the corresponding target customer transaction data, where the rows of the data transaction matrix represent the above-mentioned target customers, the columns of the data transaction matrix represent the above-mentioned transaction features of the target customers, and the elements of the data transaction matrix represent the above-mentioned feature values of the target customers regarding the above-mentioned transaction features;

[0143] A data processing module for performing data processing on the above-mentioned data transaction matrix to obtain the above-mentioned effective data transaction matrix, where the data processing at least includes data cleaning processing, data desensitization processing, data normalization processing, and unbalanced data processing.

[0144] In an optional implementation manner, in order to improve the security of privacy protection and data class imbalance, the above-mentioned data processing module includes:

[0145] A data cleaning sub-module for performing data cleaning on the above-mentioned data transaction matrix to obtain a cleaned data matrix;

[0146] A data desensitization sub-module for performing data desensitization processing on the above-mentioned cleaned data by using the MD5 algorithm to obtain desensitized data;

[0147] A normalization sub-module for performing normalization processing on the above-mentioned desensitized data to obtain normalized data;

[0148] An unbalanced processing sub-module for processing unbalanced data in the above-mentioned normalized data by using the SMOTE algorithm to obtain the above-mentioned effective data transaction matrix.

[0149] In an optional implementation manner, in order to effectively solve the situation of misjudging normal customers, the above-mentioned anomaly detection unit includes:

[0150] A clustering module for inputting the above-mentioned effective data transaction matrix into a bi-clustering sub-model in the above-mentioned bi-clustering proximity model, so as to perform clustering processing on each column of the above-mentioned effective data transaction matrix by using a hierarchical clustering method by the above-mentioned bi-clustering sub-model to generate at least one bi-clustering seed, where the bi-clustering seed is a column in the above-mentioned effective data transaction matrix, and the above-mentioned bi-clustering sub-model is a convergent model obtained by iteratively training a predetermined model by using a bi-clustering algorithm;

[0151] Column expansion module, used to expand and merge the above bicluster seeds with the columns in the above valid data transaction matrix except the column where the above bicluster seeds are located, to generate a bicluster set, the above bicluster set is a set formed by multiple biclusters, and the above bicluster is a submatrix in the above valid data transaction matrix;

[0152] Calculation module, used to calculate the variance and support degree corresponding to each of the above biclusters in the above bicluster set;

[0153] Screening module, used to screen the above biclusters whose variance is less than the variance threshold and whose support degree is greater than the support degree threshold;

[0154] Determination module, used to calculate the anomaly score value of all the screened above biclusters based on statistical deviation, and determine the above target customers corresponding to the above biclusters whose anomaly score value is greater than the score threshold as the above potential abnormal customers;

[0155] Anomaly detection module, used to input the above transaction characteristics corresponding to the above potential abnormal customers into the approximate nearest neighbor submodel in the above bicluster proximity model for anomaly detection, and output all the above abnormal transaction customers, the above approximate nearest neighbor submodel includes an input layer, multiple hidden layers and an output layer.

[0156] It should be noted that the determination module includes a first calculation sub-module, a second calculation sub-module, a third calculation sub-module, a fourth calculation sub-module and a fifth calculation sub-module. Among them, the first calculation sub-module is used to calculate the global mean of the valid data transaction matrix according to the seventh formula, and the above seventh formula is μ3 represents the above global mean, N represents the number of rows of the above valid data transaction matrix, and M represents the number of columns of the above valid data transaction matrix; the second calculation sub-module is used to calculate the global variance of the valid data transaction matrix according to the eighth formula, and the above eighth formula is σ2 2 represents the above global variance, and the variance (global variance) of the valid data transaction matrix is used to measure the dispersion degree of all elements in the valid data transaction matrix. The variance calculation of the bicluster is similar to that of the valid data transaction matrix, but only for the elements within the bicluster. The third calculation sub-module is used to calculate the mean of each of the above biclusters according to the above fifth formula; the fourth calculation sub-module is used to substitute the mean of each of the above biclusters into the above sixth formula to calculate the variance of the above bicluster correspondingly; the fifth calculation sub-module is used to calculate the ratio between the variance of the above bicluster and the above global variance to obtain the above anomaly score value, that is σ1 2 is the variance of the above bicluster.

[0157] It should also be noted that an ANN model is designed to learn the behavior patterns of normal customers and abnormal customers.

[0158] The ANN model includes: 1. Input layer: The input features are the local pattern features extracted by bi-clustering (i.e., the transaction features corresponding to potential abnormal customers).

[0159] 2. Hidden layer: Design multiple hidden layers and use the ReLU activation function.

[0160] Number of layers: Select 1 - 3 hidden layers according to the data complexity.

[0161] Number of nodes: The number of nodes in each hidden layer can be selected as 32, 64, 128, etc., and adjusted specifically according to experiments.

[0162] Activation function: Use the ReLU (Rectified Linear Unit) activation function.

[0163] 3. Output layer: Use the Sigmoid function to output the anomaly probability.

[0164] (1) Number of nodes: 1 node (for handling binary classification problems).

[0165] (2) Activation function: Use the Sigmoid activation function, and the formula is: The output range is [0, 1], and f(t) represents the anomaly probability of the transaction feature t corresponding to the potential abnormal customer.

[0166] 4. Use the Binary Cross-Entropy Loss function to calculate the loss value, and the formula is: where, y i is the true label, is the predicted probability

[0167] 5. Optimizer: Use the Adam optimizer, and set the learning rate to 0.001.

[0168] The core of Adam is:

[0169] Calculate the first moment estimate (momentum) of the gradient: Use the exponentially weighted moving average of the gradient to accelerate convergence.

[0170] m t = β1·m t-1 +(1 - β1)·g t

[0171] Calculate the second moment estimate (adaptive learning rate) of the gradient: Use the exponentially weighted moving average of the squared gradient to adjust the learning rate. v t = β2·v t-1 +(1 - β2)·g t 2

[0172] (3) Deviation correction: Since the moment estimation at the initial moment tends to 0, Adam corrects the estimated value through deviation correction.

[0173]

[0174] (4) Update parameters:

[0175]

[0176] where g t is the gradient at the current time step, m t and v t are the first-order moment and second-order moment estimations of the gradient respectively, β1 and β2 are hyperparameters, usually taking values of β1 = 0.9 and β2 = 0.999, η is the learning rate. ∈ is a very small constant (such as 10 -8 ) to prevent division-by-zero errors.

[0177] 6. Evaluation metrics:

[0178] Accuracy: The proportion of correct classifications.

[0179] Precision: The proportion of actually abnormal customers among those predicted as abnormal.

[0180] Recall: The proportion of actually abnormal customers correctly predicted.

[0181] F1 score: The harmonic mean of precision and recall.

[0182] To calculate the biclustering seeds reflecting local behavior patterns, in an optional implementation manner, the above clustering module includes:

[0183] A setting sub-module for taking each element in the above effective data transaction matrix as an initial cluster;

[0184] A sixth calculation sub-module for performing a first calculation step to calculate the distance between any two initial clusters in the target column, obtaining a plurality of first cluster distances, where the target column is any column in the above effective data transaction matrix that has not been clustered;

[0185] A merging sub-module for performing a merging step to merge the two initial clusters with the smallest first cluster distance into the current cluster set;

[0186] A seventh calculation sub-module for performing a second calculation step to recalculate the clustering between the current cluster set and other clusters in the target column, obtaining a plurality of second cluster distances, where the other clusters are all clusters in the target column except the current cluster set;

[0187] The first determination sub-module is used to execute the determination step of determining the similarity between two of the above initial clusters in the current cluster set by using the smallest of the above second cluster distances.

[0188] The first repetition sub-module is used to take the current cluster set as one of the above initial clusters, and sequentially repeat the above first calculation step, the above merging step, the above second calculation step, and the above determination step until all the above initial clusters are merged into a bicluster set or the similarity corresponding to all the above current cluster sets is greater than the hierarchical clustering threshold.

[0189] The second determination sub-module is used to determine the above bicluster set or all the above current cluster sets as the above bicluster seeds.

[0190] In order to effectively expand and merge bicluster seeds to form a bicluster set covering the combination of customer and transaction features in the effective data transaction matrix, in an optional implementation manner, the above expansion module includes:

[0191] The adding sub-module is used to execute the adding step of adding the current column to the current bicluster seed to obtain an extended sub-matrix, where the current column is any column other than the column where the current bicluster seed is located in the above effective data transaction matrix and participates in the calculation for the first time, and the current bicluster seed is any one of the above bicluster seeds.

[0192] The eighth calculation sub-module is used to execute the third calculation step of calculating the mean square residue score of the above extended sub-matrix according to the first formula, where the first formula is MSRS(x) represents the above mean square residue score, x represents the above extended sub-matrix, R represents the number of rows of the above extended sub-matrix, C represents the number of columns of the above extended sub-matrix, x ij represents the actual value of the element in the i-th row and j-th column of the above extended sub-matrix, represents the predicted value of the i-th row and j-th column in the above extended sub-matrix;

[0193] The merging sub-module is used to execute the merging step of merging the current column with the current bicluster seed and determining the current column as the extended bicluster seed when the above mean square residue score is less than the set threshold.

[0194] The second repetition sub-module is used to execute the repetition step of sequentially repeating the above adding step, the above third calculation step, and the above merging step at least once until all columns have participated in the calculation to obtain all the above extended bicluster seeds corresponding to the current bicluster seed, and at the same time, the current bicluster seed and all the above extended bicluster seeds form a bicluster.

[0195] The third repeating sub-module, in the case of having multiple above-mentioned biclustering seeds, updates the above-mentioned current biclustering seeds, and sequentially repeats the above-mentioned adding step, the above-mentioned calculating step, the above-mentioned merging step, and the above-mentioned repeating step at least once until all the above-mentioned biclustering seeds are completed in expansion, to obtain the above-mentioned expanded biclustering seeds corresponding to each of the above-mentioned biclustering seeds and all the above-mentioned biclusterings;

[0196] The third determining sub-module is configured to remove duplicate above-mentioned biclusterings, and determine the remaining all above-mentioned biclusterings as the above-mentioned biclustering set.

[0197] In order to calculate a predicted value, in an optional implementation manner, the apparatus further includes:

[0198] The first calculating unit is configured to calculate the overall mean value of the above-mentioned expanded sub-matrix according to a second formula before calculating the mean squared residue score of the above-mentioned expanded sub-matrix according to a first formula, and the second formula is μ represents the above-mentioned overall mean value;

[0199] The second calculating unit is configured to calculate the row effect corresponding to each of the above-mentioned rows in the above-mentioned biclustering sub-matrix according to a third formula, and the third formula is α i represents the above-mentioned row effect of the i-th row in the above-mentioned expanded sub-matrix;

[0200] The third calculating unit is configured to calculate the column effect corresponding to each of the above-mentioned columns in the above-mentioned expanded sub-matrix according to a fourth formula, and the fourth formula is β j represents the above-mentioned column effect of the j-th column in the above-mentioned expanded sub-matrix;

[0201] The fourth calculating unit is configured to add the above-mentioned overall mean value, the above-mentioned row effect corresponding to the i-th row, and the above-mentioned column effect corresponding to the j-th column to obtain the above-mentioned predicted value of the i-th row and j-th column.

[0202] In order to effectively screen out biclusterings that do not meet the standards, in an optional implementation manner, the above-mentioned calculating module includes:

[0203] The ninth calculating sub-module is configured to execute a fourth calculating step, and calculate the mean value of the current biclustering according to a fifth formula, where the current biclustering is any one of the above-mentioned biclusterings to be calculated in the above-mentioned biclustering set, and the fifth formula is μ2 represents the above-mentioned mean value, A pq represents the element of the p-th row and q-th column in the above-mentioned current biclustering, n represents the number of rows of the above-mentioned current biclustering, and m represents the number of columns of the above-mentioned current biclustering;

[0204] The tenth calculation sub-module is used to execute the fifth calculation step, substitute the above mean value into the sixth formula to calculate the above variance corresponding to the current bicluster, and the sixth formula is σ1 2 represents the above variance corresponding to the current bicluster;

[0205] The eleventh calculation sub-module is used to execute the sixth calculation step, calculate the product between the first ratio and the second ratio, and obtain the above support degree corresponding to the current bicluster. The first ratio is the ratio between the number of rows of the current bicluster and the number of rows of the effective data transaction matrix, and the second ratio is the ratio between the number of columns of the current bicluster and the number of columns of the effective data transaction matrix;

[0206] The fourth repetition sub-module is used to update the above current bicluster, and sequentially repeat the above fourth calculation step, the above fifth calculation step, and the above sixth calculation step at least once until the above variances and the above support degrees corresponding to all the above biclusters in the bicluster set are obtained.

[0207] The above abnormal transaction customer detection device includes a processor and a memory. The above acquisition unit, abnormal detection unit, and abnormal handling unit are all stored in the memory as program units, and the processor executes the above program units stored in the memory to implement corresponding functions. The above sub-modules are all located in the same processor; or, the above each sub-module is located in different processors in any combination form.

[0208] The processor contains a kernel, and the kernel retrieves the corresponding program unit from the memory. One or more kernels can be set. By adjusting the kernel parameters, the problem of low accuracy of the abnormal detection result caused by the situation that frequently suspicious transaction customers with similar behaviors are mined out without considering the regular behaviors of some normal customers and being misjudged can be solved.

[0209] The memory may include non-permanent memory in computer-readable media, forms such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash memory (flash RAM), and the memory includes at least one storage chip.

[0210] An embodiment of the present invention provides a computer-readable storage medium. The above computer-readable storage medium includes a stored program. Among them, when the above program runs, it controls the device where the above computer-readable storage medium is located to execute the above abnormal transaction customer detection method.

[0211] An embodiment of the present invention provides a processor. The above processor is used to run a program. Among them, when the above program runs, it executes the above abnormal transaction customer detection method.

[0212] An embodiment of the present invention provides an abnormal transaction customer detection system. The abnormal transaction customer detection system includes a processor, a memory, and a program stored on the memory and executable on the processor. When the processor executes the program, at least the following steps are implemented:

[0213] Step S201: Obtain a valid data transaction matrix corresponding to all target customers. The element X of the valid data transaction matrix NrNc represents the eigenvalue of the Nc-th transaction feature of the Nr-th target customer. The transaction features at least include transaction amount, transaction frequency, transaction time, and credit rating;

[0214] Step S202: Input the valid data transaction matrix into a biclustering proximity model to perform anomaly detection on the valid data transaction matrix by using the biclustering proximity model, and obtain all abnormal transaction customers. The biclustering proximity model is a convergent model obtained by using a biclustering algorithm to mine a biclustering from a sample data transaction matrix, calculating the variance and support degree of each biclustering to perform anomaly marking on the target customers to obtain potential abnormal customers, and using an approximate nearest neighbor algorithm to perform anomaly detection on the potential abnormal customers for iterative training. The support degree represents the coverage degree of the biclustering in the valid data transaction matrix;

[0215] Step S203: Execute corresponding anomaly handling strategies for all the abnormal transaction customers. The anomaly handling strategies at least include freezing the bank funds of the abnormal transaction customers.

[0216] The present application also provides a computer program product, which when executed on a data processing device, is adapted to execute a program initialized with at least the following method steps:

[0217] Step S201: Obtain a valid data transaction matrix corresponding to all target customers. The element X of the valid data transaction matrix NrNc represents the eigenvalue of the Nc-th transaction feature of the Nr-th target customer. The transaction features at least include transaction amount, transaction frequency, transaction time, and credit rating;

[0218] Step S202: Input the valid data transaction matrix into a biclustering proximity model to perform anomaly detection on the valid data transaction matrix by using the biclustering proximity model, and obtain all abnormal transaction customers. The biclustering proximity model is a convergent model obtained by using a biclustering algorithm to mine a biclustering from a sample data transaction matrix, calculating the variance and support degree of each biclustering to perform anomaly marking on the target customers to obtain potential abnormal customers, and using an approximate nearest neighbor algorithm to perform anomaly detection on the potential abnormal customers for iterative training. The support degree represents the coverage degree of the biclustering in the valid data transaction matrix;

[0219] Step S203: Execute corresponding exception handling strategies for all the above-mentioned customers with abnormal transactions. The above-mentioned exception handling strategies shall at least include freezing the bank funds of the above-mentioned customers with abnormal transactions.

[0220] Obviously, those skilled in the art should understand that the various sub-modules or steps of the present invention described above can be implemented by a general-purpose computing device. They can be concentrated on a single computing device or distributed over a network composed of multiple computing devices. They can be implemented by program codes executable by the computing device. Thus, they can be stored in a storage device and executed by the computing device. And in some cases, the steps shown or described herein can be executed in a different order, or they can be separately fabricated into individual integrated circuit sub-modules, or multiple sub-modules or steps among them can be fabricated into a single integrated circuit sub-module for implementation. In this way, the present invention is not limited to any specific combination of hardware and software.

[0221] Those skilled in the art should understand that the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memories, CD-ROMs, optical memories, etc.) containing computer-usable program codes.

[0222] The present application is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to the embodiments of the present application. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and the combination of flows and / or blocks in the flowcharts and / or block diagrams, can be realized by computer program instructions. These computer program instructions can be provided to the processors of general-purpose computers, special-purpose computers, embedded processors, or other programmable data processing devices to generate a machine, such that the instructions executed by the processors of the computer or other programmable data processing devices generate means for realizing the functions specified in Figure 1 one or more flows and / or blocks Figure 1 one or more blocks.

[0223] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory generate a manufactured article including instruction means for realizing the functions specified in Figure 1 one or more flows and / or blocks Figure 1 one or more blocks.

[0224] These computer program instructions can also be loaded onto a computer or other programmable data processing device, so that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide for implementing the process Figure 1 a process or multiple processes and / or blocks Figure 1 steps for the functions specified in a block or multiple blocks.

[0225] In a typical configuration, a computing device includes one or more processors (CPUs), an input / output interface, a network interface, and memory.

[0226] The memory may include non-permanent memory in the form of computer-readable media, random access memory (RAM), and / or non-volatile memory such as read-only memory (ROM) or flash memory (flash RAM). The memory is an example of computer-readable media.

[0227] Computer-readable media includes permanent and non-permanent, removable and non-removable media that can store information by any method or technology. The information can be computer-readable instructions, data structures, sub-modules of a program, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassette tapes, magnetic disk storage or other magnetic storage devices, or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer-readable media does not include transitory computer-readable media such as modulated data signals and carrier waves.

[0228] It should also be noted that the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or also includes elements inherent to such process, method, commodity or device. Without further limitation, an element defined by the statement "including one..." does not exclude the existence of another identical element in the process, method, commodity or device including the element.

[0229] From the above description, it can be seen that the above embodiments of the present application achieve the following technical effects:

[0230] 1), The abnormal transaction customer detection method of the present application constructs a biclustering proximity model by combining the biclustering algorithm and the ANN algorithm. In the biclustering proximity model, the biclustering algorithm is used to mine the biclustering of row-column consistency local patterns, and the variance and support of all biclusterings are calculated. Eligible biclusterings are screened based on the variance and support, and the corresponding target customers are marked. Then, the approximate nearest neighbor algorithm is used to detect abnormal transaction customers among the marked target customers, and the final abnormal transaction customers are obtained, and the corresponding abnormal handling strategies are executed. The present application solves the problem that the accuracy of abnormal detection results is relatively low due to the situation where suspicious transaction customers with frequent similar behaviors are mined, but the regular behaviors of some normal customers are not considered and thus misjudged.

[0231] 2), The abnormal transaction customer detection device of the present application constructs a biclustering proximity model by combining the biclustering algorithm and the ANN algorithm. In the biclustering proximity model, the biclustering algorithm is used to mine the biclustering of row-column consistency local patterns, and the variance and support of all biclusterings are calculated. Eligible biclusterings are screened based on the variance and support, and the corresponding target customers are marked. Then, the approximate nearest neighbor algorithm is used to detect abnormal transaction customers among the marked target customers, and the final abnormal transaction customers are obtained, and the corresponding abnormal handling strategies are executed. The present application solves the problem that the accuracy of abnormal detection results is relatively low due to the situation where suspicious transaction customers with frequent similar behaviors are mined, but the regular behaviors of some normal customers are not considered and thus misjudged.

[0232] The above are only the preferred embodiments of the present application and are not used to limit the present application. For those skilled in the art, various changes and modifications can be made to the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included within the protection scope of the present application.

Claims

1. A method for detecting abnormal trading customers, characterized in that, Including: Obtain the valid data transaction matrix corresponding to all target customers, where the element X of the valid data transaction matrix NrNc represents the eigenvalue of the Nc-th transaction feature of the Nr-th target customer, and the transaction features at least include transaction amount, transaction frequency, transaction time, and credit rating; Input the valid data transaction matrix into the biclustering proximity model to use the biclustering proximity model to perform anomaly detection on the valid data transaction matrix, obtaining all abnormal transaction customers. The biclustering proximity model is a convergence model obtained by using the biclustering algorithm to mine biclusters from the sample data transaction matrix, calculating the variance and support degree of each bicluster to perform anomaly marking on the target customers to obtain potential abnormal customers, and using the approximate nearest neighbor algorithm to perform anomaly detection on the potential abnormal customers for iterative training. The support degree represents the coverage degree of the bicluster in the valid data transaction matrix; Execute corresponding anomaly handling strategies for all the abnormal transaction customers. The anomaly handling strategies at least include freezing the bank funds of the abnormal transaction customers.

2. The method according to claim 1, wherein Obtain the valid data transaction matrix corresponding to all target customers, including: Obtain the target customer transaction data corresponding to all target customers. The target customer transaction data includes the transaction features and the feature values corresponding to the transaction features; Construct a data transaction matrix according to all the target customers and the corresponding target customer transaction data. The rows of the data transaction matrix represent the target customers, the columns of the data transaction matrix represent the transaction features of the target customers, and the elements of the data transaction matrix represent the feature values of the target customers regarding the transaction features; Perform data processing on the data transaction matrix to obtain the valid data transaction matrix. The data processing at least includes data cleaning processing, data desensitization processing, data normalization processing, and unbalanced data processing.

3. The method according to claim 2, characterized in that, Perform data processing on the data transaction matrix to obtain the valid data transaction matrix, including: Perform data cleaning on the data transaction matrix to obtain a cleaned data matrix; Use the MD5 algorithm to perform data desensitization processing on the cleaned data to obtain desensitized data; Perform normalization processing on the desensitized data to obtain normalized data; Use the SMOTE algorithm to process the unbalanced data in the normalized data to obtain the valid data transaction matrix.

4. The method according to claim 1, characterized in that, Input the valid data transaction matrix into the biclustering proximity model to use the biclustering proximity model to perform anomaly detection on the valid data transaction matrix, and output all abnormal transaction customers, including: Input the valid data transaction matrix into the biclustering submodel in the biclustering proximity model to use the biclustering submodel to perform clustering processing on each column of the valid data transaction matrix by using the hierarchical clustering method, generating at least one bicluster seed. The bicluster seed is a column in the valid data transaction matrix. The biclustering submodel is a convergence model obtained by using the biclustering algorithm to perform iterative training on a predetermined model; Expand and merge the bicluster seed with the columns in the valid data transaction matrix other than the column where the bicluster seed is located to generate a bicluster set. The bicluster set is a set formed by multiple biclusters. The bicluster is a submatrix in the valid data transaction matrix; Calculate the variance and support degree corresponding to each bicluster in the bicluster set; Filter out the biclusters whose variance is less than the variance threshold and whose support degree is greater than the support degree threshold; Calculate the anomaly score values of all the filtered biclusters based on statistical deviation, and determine the target customers corresponding to the biclusters with anomaly score values greater than the score threshold as the potential abnormal customers; Input the transaction features corresponding to the potential abnormal customers into the approximate nearest neighbor sub-model in the bicluster proximity model for anomaly detection, and output all the abnormal transaction customers. The approximate nearest neighbor sub-model includes an input layer, multiple hidden layers, and an output layer.

5. The method according to claim 4, wherein Perform clustering processing on each column of the effective data transaction matrix using the hierarchical clustering method to generate bicluster seeds, including: Take each element in the effective data transaction matrix as an initial cluster; The first calculation step: Calculate the distance between any two initial clusters in the target column to obtain multiple first cluster distances. The target column is any column in the effective data transaction matrix that has not been clustered; The merging step: Merge the two initial clusters with the smallest first cluster distance into the current cluster set; The second calculation step: Recalculate the clustering between the current cluster set and other clusters in the target column to obtain multiple second cluster distances. The other clusters are all the clusters in the target column except the current cluster set; The determination step: Determine the similarity between the two initial clusters in the current cluster set based on the smallest second cluster distance; Take the current cluster set as an initial cluster, and sequentially repeat the first calculation step, the merging step, the second calculation step, and the determination step until all the initial clusters are merged into a bicluster set or the similarity corresponding to all the current cluster sets is greater than the hierarchical clustering threshold; Determine the bicluster set or all the current cluster sets as the bicluster seeds.

6. The method according to claim 4, characterized in that, Expand and merge the bicluster seeds with the columns in the effective data transaction matrix other than the column where the bicluster seeds are located to generate a bicluster set, including: The adding step: Add the current column to the current bicluster seed to obtain an extended sub-matrix. The current column is any column in the effective data transaction matrix other than the column where the current bicluster seed is located and participating in the calculation for the first time. The current bicluster seed is any one of the bicluster seeds; The third calculation step is to calculate the mean square residue score of the extended sub-matrix according to the first formula, and the first formula is MSRS(x) represents the mean square residue score, x represents the extended sub-matrix, R represents the number of rows of the extended sub-matrix, C represents the number of columns of the extended sub-matrix, and x ij represents the actual value of the element in the i-th row and j-th column of the extended sub-matrix, represents the predicted value of the i-th row and j-th column in the extended sub-matrix; The merging step: In the case where the mean squared residue score value is less than the set threshold, merge the current column with the current bicluster seed and determine the current column as the extended bicluster seed; The repeating step: Sequentially repeat the adding step, the third calculation step, and the merging step at least once until all columns have participated in the calculation to obtain all the extended bicluster seeds corresponding to the current bicluster seed. At the same time, the current bicluster seed and all the extended bicluster seeds form a bicluster. In the case of having multiple such biclustering seeds, update the current biclustering seeds, and sequentially repeat the addition step, the third calculation step, the merging step, and the repeating step at least once until the expansion of all the biclustering seeds is completed, so as to obtain the expanded biclustering seeds corresponding to each of the biclustering seeds and all the biclusterings; Remove the duplicate biclusterings, and determine all the remaining biclusterings as the biclustering set.

7. The method according to claim 6, wherein Before calculating the mean squared residue score of the expanded submatrix according to the first formula, the method further includes: Calculate the overall mean of the extended submatrix according to the second formula, where the second formula is μ1 represents the overall mean; Calculate the row effects corresponding to each row in the biclustering submatrix according to the third formula, where the third formula is α i represents the row effect of the i-th row in the extended submatrix; Calculate the column effects corresponding to each column in the extended sub - matrix according to the fourth formula, where the fourth formula is β j represents the column effect of the j - th column in the extended sub - matrix; Add the overall mean, the row effect corresponding to the i-th row, and the column effect corresponding to the j-th column to obtain the predicted value of the i-th row and the j-th column.

8. The method according to claim 4, characterized in that, Calculate the variance and support degree corresponding to each biclustering in the biclustering set, including: The fourth calculation step is to calculate the mean of the current bicluster according to the fifth formula, where the current bicluster is any bicluster to be calculated in the bicluster set, and the fifth formula is μ2 represents the mean, and A pq represents the element in the p-th row and q-th column of the current bicluster, n represents the number of rows of the current bicluster, and m represents the number of columns of the current bicluster; The fifth calculation step is to substitute the mean value into the sixth formula to calculate the variance corresponding to the current bicluster, and the sixth formula is σ1 2 represents the variance corresponding to the current bicluster; A sixth calculation step of calculating the product between a first ratio and a second ratio to obtain the support degree corresponding to the current biclustering, where the first ratio is the ratio between the number of rows of the current biclustering and the number of rows of the effective data transaction matrix, and the second ratio is the ratio between the number of columns of the current biclustering and the number of columns of the effective data transaction matrix; Update the current biclustering, and sequentially repeat the fourth calculation step, the fifth calculation step, and the sixth calculation step at least once until the variances and the support degrees corresponding to all the biclusterings in the biclustering set are obtained.

9. An abnormal transaction customer detection device, characterized in that, The device includes: An acquisition unit for acquiring a valid data transaction matrix corresponding to all target customers, where an element X of the valid data transaction matrix NrNc represents an eigenvalue of the Nc-th transaction feature of the Nr-th target customer; An anomaly detection unit, configured to input the effective data transaction matrix into a biclustering proximity model to perform anomaly detection on the effective data transaction matrix by using the biclustering proximity model, so as to obtain all the abnormal transaction customers. The biclustering proximity model is a convergence model obtained by mining biclusterings from a sample data transaction matrix by using a biclustering algorithm, calculating the variance and support degree of each biclustering, performing anomaly marking on the target customers to obtain potential abnormal customers, and iteratively training by using an approximate nearest neighbor algorithm for anomaly detection on the potential abnormal customers. The support degree represents the coverage degree of the biclustering in the effective data transaction matrix; An anomaly handling unit, configured to execute corresponding anomaly handling strategies on all the abnormal transaction customers, and the anomaly handling strategies at least include freezing the bank funds of the abnormal transaction customers.

10. A computer program product comprising computer instructions, characterized in that, The computer instructions, when executed by a processor, implement the method according to any one of claims 1 to 8.