Banking system risk monitoring and early warning method and system based on artificial intelligence
By building an account trading network, the initial importance score is calculated and the importance is transmitted, the fund dispersion and path coordination are analyzed, suspicious accounts are identified, and differentiated monitoring rules are set, which solves the risk identification problems of multi-level account transfer and diversified transactions in the banking system, and improves the timeliness and accuracy of risk monitoring.
Patent Information
- Application Number
- CN202510496713.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-21
- Publication Date
- 2025-07-11
- Estimated Expiration
- 2045-04-21
AI Technical Summary
The existing bank system risk monitoring methods are difficult to effectively identify complex risk behaviors such as multi-level account transfer and diversified transactions, and the fixed rule model is difficult to adapt to new risk forms, resulting in frequent false alarms and missed reports.
Build an account trading network, extract transaction characteristics and calculate initial importance scores, transmit importance through transaction relationships between nodes, analyze fund dispersion and path coordination, identify suspicious accounts based on link position characteristics, and set up differentiated monitoring rules and dynamic adjustment mechanisms.
It improves the timeliness and accuracy of risk monitoring in the bank system, reduces the false alarm rate, and enhances the adaptability to new risk forms and the flexibility of risk prevention and control.
Smart Images

Figure CN120298091A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of data processing applicable to administrative, commercial, financial, management, supervision or prediction purposes, and particularly relates to a method and system for risk monitoring and early warning of a bank system based on artificial intelligence. Background Art
[0002] With the rapid development of fintech, the scale of banking business and the complexity of transactions have been continuously increasing, and risk events in bank systems occur frequently. To maintain financial order and ensure financial security, the monitoring and early warning of bank system risks have become increasingly important.
[0003] In related technologies, risk identification can be carried out by means of rule matching. By setting threshold rules for dimensions such as transaction amount, transaction frequency, and transaction time, transaction behaviors exceeding the thresholds are marked and manually verified. At the same time, some banks are also trying to introduce statistical analysis methods, establishing statistical models based on historical transaction data, and conducting statistical analysis and anomaly detection on the transaction behaviors of accounts.
[0004] However, due to the inability to effectively analyze the complex transaction correlation relationships between accounts, this method makes it difficult to detect risk behaviors that evade monitoring through multi-level account transfers, dispersed transactions, etc. At the same time, with the continuous innovation of criminals' modus operandi, fixed rule models are difficult to adapt to new risk patterns in a timely manner, resulting in some risk behaviors not being discovered and warned in a timely manner. Summary of the Invention
[0005] This application provides a method and system for risk monitoring and early warning of a bank system based on artificial intelligence, which is used to improve the timeliness of discovering risk behaviors in bank transactions.
[0006] In a first aspect, the present application provides a method for risk monitoring and early warning of a banking system based on artificial intelligence, which is applied to a risk monitoring and early warning system of a banking system. The method includes: constructing an account transaction network based on transaction data within a target time window, and extracting transaction characteristics of each account node in the account transaction network. The account transaction network takes each account as a node, and the transaction relationship between the accounts as a directed edge; obtaining the flow characteristics of the account fund income and expenditure ratio relationship, the time correlation degree characteristics between the account and the counterparty, and the business portfolio mode characteristics of the account, and calculating the initial importance score of the account according to the flow characteristics, the time correlation degree characteristics, and the business portfolio mode characteristics; performing importance transmission through the transaction relationship between nodes according to the initial importance score, and calculating the transmitted importance score; calculating the fund dispersion index and the path coordination index based on the previous transaction path of the target account in the account transaction network, and constructing the link position characteristics of the account according to the fund dispersion index and the path coordination index; calculating the final suspiciousness score of the account according to the transmitted importance score and the link position characteristics, and determining the account with the final suspiciousness score greater than the preset score threshold as a suspicious account; sending out a warning message according to the transmitted importance score of the suspicious account, the link position characteristics, and the structural position in the account transaction network.
[0007] In the above embodiment, by constructing an account transaction network and extracting transaction characteristics, combining the account fund flow, time correlation, and business model characteristics to calculate the initial importance score, and then performing importance transmission through the transaction relationship between nodes. The system effectively identifies hidden risk behaviors such as multi-level account transfer and decentralized transactions by analyzing the fund dispersion degree and path coordination degree of the previous transaction path of the target account, can better adapt to and discover new risk forms, and improves the timeliness and accuracy of risk monitoring.
[0008] Combined with some embodiments of the first aspect, in some embodiments, the step of performing importance transmission through the transaction relationship between nodes according to the initial importance score and calculating the transmitted importance score specifically includes: setting a transaction scale threshold and a time interval threshold, and screening the node pairs that meet the conditions in the account transaction network; obtaining the transaction amount ratio, time decay coefficient, and transaction time sequence correlation degree between the node pairs, and combining the initial importance score of the node with the transaction amount ratio, decay coefficient, and time sequence correlation degree to calculate the importance transmission value between nodes; performing iterative calculation on the account transaction network to obtain the transmitted importance score of each account node.
[0009] In the above embodiments, the trading scale and time interval threshold are set to screen node pairs, and factors such as the proportion of transaction amounts, time decay coefficient, and transaction timing correlation are comprehensively considered to calculate the importance transfer value. Through the iterative calculation process, the risk transfer process can more accurately reflect the association degree between accounts and the risk transfer path, so as to obtain a more accurate transfer importance score for each account node, providing a more reliable basis for subsequent risk assessment.
[0010] Combined with some embodiments of the first aspect, in some embodiments, the steps of calculating the fund dispersion index and the path coordination index based on the previous transaction path of the target account in the account trading network, and constructing the link position characteristics of the account according to the fund dispersion index and the path coordination index specifically include: performing backward tracing on the account trading network with the target account as the starting point to obtain the previous transaction path within a preset number of layers; calculating the fund dispersion index based on the fund transfer scale of the previous transaction path; analyzing the timing combination characteristics of the previous transaction path to obtain the path coordination index; constructing the link position characteristics of the account according to the fund dispersion index and the path coordination index.
[0011] In the above embodiments, backward tracing is performed on the target account to obtain the previous transaction path, the fund dispersion index is calculated by analyzing the fund transfer scale, and the path coordination index is obtained in combination with the timing combination characteristics of the path. This multi-level path analysis method enables the system to comprehensively grasp the characteristics of fund flow, effectively identify abnormal fund transfer paths, and deeply depict the risk characteristics of the account in the entire trading network through the construction of link position characteristics.
[0012] Combined with some embodiments of the first aspect, in some embodiments, the steps of sending a warning message according to the transfer importance score of the suspicious account, the link position characteristics, and the structural position in the account trading network specifically include: dividing the risk level of the suspicious account according to its transfer importance score, and setting high, medium, and low three-level warning thresholds; analyzing the role attributes of the suspicious account in the fund chain based on the link position characteristics of the suspicious account to determine whether the suspicious account is a fund aggregation node, a transfer node, or a dispersion node; if so, identifying the associated account group of the suspicious account and determining the transaction mode within the associated account group according to the structural position characteristics of the account trading network; generating a warning message including the basic information, risk level, position characteristics, role description, and associated account group information of the suspicious account.
[0013] In the above embodiments, the risk levels of suspicious accounts are classified and graded warning thresholds are set. Based on the link location characteristics, the role attributes of the accounts in the fund chain are analyzed, and the transaction patterns of the associated account groups are further identified. Through the multi-dimensional profiling analysis of suspicious accounts, complete warning information including basic information, risk levels, location characteristics, etc. is formed, realizing the accurate positioning and comprehensive characterization of risk accounts, and providing a more detailed and accurate warning basis for risk control.
[0014] In combination with some embodiments of the first aspect, in some embodiments, after the step of generating warning information including the basic information, risk level, location characteristics, role description, and associated account group information of the suspicious account, the method further includes: setting differentiated monitoring rules according to the risk level of the suspicious account, where the monitoring rules include the daily maximum transaction amount, the maximum single-transaction limit, and the upper limit of the cumulative number of transactions for high-risk accounts; when the current transaction behavior of the suspicious account triggers the monitoring rules, freezing the current transaction behavior and pushing an exception reminder to the target customer terminal.
[0015] In the above embodiments, setting differentiated monitoring rules according to the risk level of the suspicious account, including transaction amounts, limits, and upper limits of the number of times. When the account triggers the monitoring rules, the transaction is frozen in a timely manner and an exception reminder is pushed. The differentiated monitoring rules and real-time response mechanism enable the system to quickly take control measures after discovering risks, effectively blocking the continuation of abnormal transaction behaviors and reducing the risk of fund losses.
[0016] In combination with some embodiments of the first aspect, in some embodiments, after the step of sending warning information according to the transfer importance score, the link location characteristics, and the structural location in the account transaction network of the suspicious account, the method further includes: statistically analyzing the number of times the monitoring rules are triggered by the suspicious account within a preset time window; when the number of trigger times exceeds a preset threshold, raising the risk level of the suspicious account and adjusting the monitoring rule parameters; recording the trigger history of the monitoring rules and the results of manual handling.
[0017] In the above embodiments, statistically analyzing the number of times the suspicious account triggers the monitoring rules, dynamically adjusting the risk level and monitoring parameters when the number exceeds the preset threshold, and recording the trigger history and handling results. The dynamic risk level adjustment mechanism enhances the system's ability to identify persistent abnormal behaviors, enables the monitoring rules to be adjusted in a timely manner according to risk changes, and improves the flexibility and adaptability of risk prevention and control.
[0018] In combination with some embodiments of the first aspect, in some embodiments, after the step of recording the trigger history of the monitoring rule and the manual handling result, the method further includes: receiving a handling result mark of the warning information from the target customer terminal, calculating the accuracy rate and false alarm rate of the warning rule according to the handling result mark, where the handling result mark includes three types: real risk, false alarm, and to be observed; when the accuracy rate is lower than a preset accuracy rate threshold or the false alarm rate is higher than a preset false alarm rate threshold, adjusting the score threshold in the warning rule.
[0019] In the above embodiments, receiving the handling result mark of the warning information from the target customer terminal, calculating the accuracy rate and false alarm rate of the warning rule according to the marks of the three types of real risk, false alarm, and to be observed, and automatically adjusting the score threshold in the warning rule when the accuracy rate or false alarm rate exceeds the preset threshold. The adaptive adjustment mechanism of the warning rule enables the system to continuously optimize the warning threshold during operation, continuously improve the accuracy of the warning, and reduce the false alarm rate.
[0020] In a second aspect, an embodiment of the present application provides a bank system risk monitoring and warning system, which includes: one or more processors and a memory; the memory is coupled to the one or more processors, and the memory is used to store computer program code, and the computer program code includes computer instructions, and the one or more processors call the computer instructions to enable the bank system risk monitoring and warning system to execute the method described in the first aspect and any possible implementation manner in the first aspect.
[0021] In a third aspect, an embodiment of the present application provides a computer program product containing instructions, and when the above computer program product runs on a bank system risk monitoring and warning system, it enables the above bank system risk monitoring and warning system to execute the method described in the first aspect and any possible implementation manner in the first aspect.
[0022] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium including instructions, and when the above instructions run on a bank system risk monitoring and warning system, it enables the above bank system risk monitoring and warning system to execute the method described in the first aspect and any possible implementation manner in the first aspect.
[0023] It can be understood that the bank system risk monitoring and warning system provided in the second aspect above, the computer program product provided in the third aspect, and the computer storage medium provided in the fourth aspect are all used to execute the method provided in the embodiments of the present application. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects in the corresponding method, and will not be elaborated here.
[0024] One or more technical solutions provided in the embodiments of the present application have at least the following technical effects or advantages: 1. This application constructs an account transaction network, extracts transaction features, calculates an initial importance score by combining account fund flow, time correlation, and business model features, and then conducts importance propagation through inter-node transaction relationships. The system effectively identifies hidden risk behaviors such as multi-level account transfers and decentralized transactions by analyzing the fund dispersion degree and path coordination degree of the previous transaction paths of the target account, can better adapt to and detect new risk patterns, and improves the timeliness and accuracy of risk monitoring.
[0025] 2. This application screens node pairs by setting transaction scale and time interval thresholds, and calculates the importance propagation value by comprehensively considering factors such as the transaction amount ratio, time decay coefficient, and transaction time sequence correlation degree. Through the iterative calculation process, the risk propagation process more accurately reflects the association degree between accounts and the risk propagation path, so as to obtain a more accurate propagation importance score for each account node, providing a more reliable basis for subsequent risk assessment.
[0026] 3. This application obtains the previous transaction path by reverse tracing the target account, analyzes the fund transfer scale to calculate the fund dispersion degree index, and combines the time sequence combination features of the path to obtain the path coordination degree index. This multi-level path analysis method enables the system to comprehensively master the fund flow characteristics, effectively identify abnormal fund transfer paths, and deeply characterize the risk characteristics of the account in the entire transaction network through the construction of link position characteristics. BRIEF DESCRIPTION OF THE DRAWINGS
[0027] Figure 1 is a flowchart of a method for risk monitoring and early warning of a bank system based on artificial intelligence in an embodiment of this application; Figure 2 is another flowchart of a method for risk monitoring and early warning of a bank system based on artificial intelligence in an embodiment of this application; Figure 3 is a schematic structural diagram of an entity device of a bank system risk monitoring and early warning system in an embodiment of this application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0028] The terms used in the following embodiments of this application are only for the purpose of describing specific embodiments and are not intended to limit this application. As used in the specification of this application, the singular forms "a", "one", "the above", "the", and "this" are also intended to include the plural forms unless the context clearly indicates otherwise. It should also be understood that the term "and / or" used in this application refers to any or all possible combinations including one or more of the listed items.
[0029] Hereinafter, the terms "first" and "second" are for descriptive purposes only and should not be construed as implying or suggesting relative importance or implicitly specifying the quantity of the indicated technical features. Thus, features defined with "first" and "second" may explicitly or implicitly include one or more of such features. In the description of the embodiments of the present application, unless otherwise specified, the meaning of "a plurality" is two or more than two.
[0030] For ease of understanding, the application scenarios of the embodiments of the present application are introduced below.
[0031] In daily banking operations, the popularity of electronic payment and online transfer has led to a significant increase in the frequency and complexity of transactions. A typical case is that a merchant received a total of 157 payments through online banking within a week, with amounts ranging from 500 yuan to 3000 yuan. The transaction times were distributed at different times of the day, and the transaction locations were scattered in multiple cities. These funds were transferred through 3 to 4 intermediate accounts, and both the single-amount and time intervals were carefully designed, making it difficult for traditional transaction monitoring systems to determine whether it was a normal business transaction. Especially in cross-bank transactions, due to incomplete information, it is impossible to accurately identify potential risks simply relying on simple features such as transaction amount and frequency. Banks need to establish a monitoring method that can analyze transaction chains, identify fund flows, and evaluate the importance of nodes to accurately detect abnormal transaction behaviors hidden in normal operations.
[0032] Current transaction monitoring mainly relies on preset business rules. For example, setting transaction warning rules: triggering a warning when the number of transfers in a single day exceeds 5 times, triggering a warning when the single-amount exceeds 10,000 yuan, triggering a warning when the transaction amount exceeds 30,000 yuan for 3 consecutive days, etc. In an actual case, the corporate account of a small trading company was marked as abnormal by the system because it transferred 8000 yuan to each of 5 suppliers every day. After verification, it was a normal payment for goods, resulting in an invalid warning. Another situation is that an account avoided the monitoring threshold of 10,000 yuan per single by transferring 9000 yuan in 3 installments every day. This monitoring method based on fixed rules cannot effectively analyze the correlation between accounts, nor can it dynamically adjust the monitoring criteria according to different business scenarios, resulting in a large number of false alarms and missed reports.
[0033] After using this solution, the system can identify abnormal behaviors by analyzing the transaction network. In a real case, the system detected that 7 accounts had transactions within 2 days: first, 3 accounts each made 5 deposits of 8,000 yuan, and then transferred the money to 4 intermediate accounts. Each intermediate account then dispersed the funds to 2 - 3 downstream accounts, and these funds eventually converged to a target account within 36 hours. By calculating the importance score passed by the computing nodes, the system found that the score of the target account reached 0.75. By analyzing its link position characteristics, the system found that the fund dispersion degree was 0.62 and the path coordination degree was 0.58, and determined it as a fund convergence node. The system further identified a transaction group composed of 12 relevant accounts and found that it showed a "deposit - dispersion - convergence" transaction pattern, and successfully issued a warning. This method avoids misjudgment of normal operations and accurately identifies structured abnormal transaction behaviors.
[0034] For ease of understanding, the method provided in this implementation will be described in terms of its process in combination with the above scenario. Please refer to Figure 1 , which is a schematic flowchart of a method for risk monitoring and warning of a bank system based on artificial intelligence in an embodiment of this application.
[0035] S101. Construct an account transaction network based on the transaction data within a target time window, and extract the transaction characteristics of each account node in the account transaction network. The account transaction network takes each account as a node and the transaction relationship between the accounts as a directed edge.
[0036] Among them, the target time window represents a specific time range for risk monitoring and analysis, which can be fixed, such as one week or one month, or a sliding time window; the account transaction network is a network structure based on graph theory used to describe the transaction relationship between accounts; the transaction characteristics refer to various indicators that can characterize the account transaction behavior pattern, including information such as transaction frequency, transaction amount, and transaction counterpart; the directed edge represents the transaction direction of funds flowing from one account to another account.
[0037] This step is usually executed when the system starts the risk monitoring process. Specifically, the system first obtains all account transaction data within the target time window from the transaction database, maps each account to a node in the network, and establishes the connection relationship between accounts according to the transaction records to form a complete transaction network structure. Then, for each account node, extract its transaction behavior characteristics within this time window, including information in dimensions such as total transaction amount, transaction frequency, and number of transaction counterparts.
[0038] In some embodiments, the construction and feature extraction of the account transaction network can be achieved in the following manner: Optionally, first preprocess the original transaction data, including data cleaning, outlier handling, and standardization, then store the account nodes and transaction relationships using a graph database, and finally calculate the basic transaction features of the nodes; Optionally, use a distributed computing framework to perform parallel processing on large-scale transaction data, construct the account relationship network, and at the same time use feature engineering methods to extract multi-dimensional transaction features. It can be understood that other methods can also be used to achieve network construction and feature extraction, which are not limited herein.
[0039] S102. Obtain the flow characteristics of the account fund income and expenditure ratio relationship, the time correlation degree characteristics between the account and the trading counterparty, and the business portfolio mode characteristics of the account, and calculate the initial importance score of the account according to the flow characteristics, the time correlation degree characteristics, and the business portfolio mode characteristics.
[0040] Among them, the flow characteristics reflect the ratio relationship and flow direction of the account fund income and expenditure; the time correlation degree characteristics represent the tightness of the trading time sequence between the account and the trading counterparty; the business portfolio mode characteristics describe various business types involved in the account and their combination characteristics; the initial importance score is the initial evaluation value for measuring the abnormality degree of the account.
[0041] This step is executed after the construction of the account transaction network is completed. Specifically, the system calculates the feature values from three dimensions: fund flow, time correlation, and business portfolio based on the constructed transaction network. Then, through a specific weight combination method for these three types of features, the initial importance score of each account is calculated, and this score reflects the potential risk degree of the account.
[0042] In some embodiments, the feature calculation and score calculation can be achieved in the following manner: Optionally, use statistical methods to calculate features such as the fund income and expenditure ratio, the distribution of trading time intervals, and the entropy value of business types of the account, and then use the weighted summation method to obtain the initial score; Optionally, use a machine learning model to perform non-linear combination on multi-dimensional features, and obtain the initial importance score of the account through the model output. It can be understood that other methods can also be used to achieve feature extraction and score calculation, which are not limited herein.
[0043] S103. Perform importance transfer through the transaction relationship between nodes according to the initial importance score, and calculate the transferred importance score.
[0044] Among them, importance transmission refers to the process of spreading and diffusing the initial importance scores in the network according to the transaction relationships between account nodes; the transmitted importance score represents the final importance rating obtained by the account after network propagation; the transaction relationship between nodes refers to the fund transfer connection relationship between accounts, including features such as transaction amount, transaction frequency, and time series; the transaction amount ratio is used to represent the relative size of the transaction scale between adjacent nodes; the time decay coefficient represents the influence weight of the transaction time on importance transmission; the transaction time series correlation degree is used to measure the time correlation of transactions between accounts.
[0045] This step is executed after obtaining the initial importance scores of the accounts. Specifically, the system first sets the screening thresholds for the transaction scale and time interval, and filters out valid account node pairs based on these thresholds. For each pair of connected nodes, it calculates the proportion of the transaction amount between them, the decay coefficient based on the transaction time, and the correlation degree reflecting the transaction time series pattern. Then it multiplies the initial importance score of the source node by these eigenvalue to obtain the importance value transmitted to the target node. The system repeatedly performs this transmission calculation process until the importance scores of all nodes in the network reach a stable state.
[0046] In some embodiments, the transmission calculation of importance between nodes can be implemented in various ways: Optionally, first construct a transaction relationship matrix to record the connection relationship between nodes, then calculate the feature weights between node pairs, then use an iterative algorithm for importance transmission calculation, and finally normalize the transmission result to obtain the final score; Optionally, first convert the transaction network into a probability transition matrix, then calculate the steady-state distribution of nodes based on the random walk model, and finally combine the initial importance score to obtain the transmitted rating result. It can be understood that This step specifically includes: Set the transaction scale threshold and time interval threshold, and filter out the node pairs that meet the conditions in the account transaction network.
[0047] In this step, the transaction scale threshold refers to the minimum transaction amount standard for screening valid transaction relationships, which is used to filter out minor transactions; the time interval threshold refers to the maximum time interval standard for determining transaction relevance, which is used to filter out transactions with too large a time span; the node pair refers to two account nodes with a direct transaction relationship in the account transaction network.
[0048] The system first sets the basic screening criteria: the transaction scale threshold is set to a single transaction amount of not less than 10,000 yuan, and the time interval threshold is set to the time interval between adjacent transactions not exceeding 30 days. Based on these two thresholds, the system screens all node pairs in the account transaction network: traverses each transaction edge in the network, extracts the transaction amount and transaction time information, and determines whether the scale and time conditions are both met. For the node pairs that meet the conditions, their transaction relationships are retained, and the transaction edges between the node pairs that do not meet the conditions are removed. Through this screening, the system constructs a simplified network structure containing significant transaction relationships.
[0049] Obtain the transaction amount ratio, time decay coefficient, and transaction time sequence correlation degree between node pairs, and combine the initial importance score of the node with this transaction amount ratio, decay coefficient, and time sequence correlation degree to calculate the importance transfer value between nodes.
[0050] In this step, the transaction amount ratio refers to the proportion of the transaction amount between nodes to the total transaction amount of the source node; the time decay coefficient refers to the weight coefficient calculated based on the transaction time interval, which is used to reflect the time decay effect; the transaction time sequence correlation degree refers to the similarity degree of the time patterns of transactions between nodes; the importance transfer value refers to the risk degree value transferred from one node to adjacent nodes.
[0051] The system calculates three characteristic values for each pair of connected nodes: transaction amount ratio = transaction amount between nodes / total transaction amount of the source node; time decay coefficient = exp(-Δt / T), where Δt is the transaction time interval and T is the characteristic time scale (such as 30 days); the transaction time sequence correlation degree is obtained by calculating the correlation coefficient of the transaction time series of the two nodes. Then, the initial importance score of the source node is weighted and combined with these three characteristic values: transfer value = initial score × (w1 × amount ratio + w2 × decay coefficient + w3 × correlation degree), where w1, w2, and w3 are weight coefficients and satisfy w1 + w2 + w3 = 1.
[0052] Perform iterative calculations on this account transaction network to obtain the transfer importance scores of each account node.
[0053] In this step, iterative calculation refers to the process of repeatedly performing importance transfer calculations until the network reaches a stable state; the transfer importance score refers to the final importance score obtained by the node after network transfer.
[0054] The system updates the importance scores of nodes in an iterative manner. In each iteration, for each node in the network, the importance values passed from all its predecessor nodes are aggregated, and a new node score is calculated. The specific calculation formula is: new score = α × (sum of all incoming importance values) + (1 - α) × initial score, where α is the network transfer coefficient (0 < α < 1). The system repeats this update process until the change in scores of all nodes is less than a preset convergence threshold (such as 0.001), or the maximum number of iterations (such as 100 times) is reached. The finally obtained stable score is the transfer importance score of the node.
[0055] S104. Calculate the fund dispersion index and the path synergy index based on the previous transaction paths of the target account in the account transaction network, and construct the link position feature of the account according to the fund dispersion index and the path synergy index.
[0056] Among them, the previous transaction path refers to the fund inflow path obtained by backward tracing; the fund dispersion index is used to measure the degree of dispersion or concentration of funds on the inflow path; the path synergy index represents the temporal synchronization of fund flows on different paths; the link position feature refers to the structural feature of the account in the entire fund flow chain, reflecting its role and importance in the fund transfer process; the fund transfer scale refers to the amount of funds transferred on each path.
[0057] This step is executed after determining the target account to be analyzed. Specifically, the system starts from the target account and performs backward tracing in the transaction network to obtain all previous transaction paths within a preset number of layers. For these paths, calculate the fund transfer scale on each path, analyze the distribution of funds on different paths, and obtain the fund dispersion index. At the same time, study the time characteristics of fund flows on each path, calculate the temporal correlation between paths, and obtain the path synergy index. Finally, combine these two indexes to construct a feature vector representing the position feature of the account in the fund chain.
[0058] In some embodiments, the construction of the link position feature can be achieved in multiple ways: Optionally, first use the depth - first search algorithm to obtain the previous transaction paths, then calculate the fund flow distribution of each path, then analyze the transaction time - series pattern on the path, and finally use the feature fusion method to construct the position feature vector; Optionally, first use the breadth - first search to obtain multi - layer transaction paths, then use the entropy method to calculate the fund dispersion, then obtain the path synergy through time - series analysis, and finally obtain the position feature through multi - dimensional feature combination. It can be understood that other ways can also be used to achieve the extraction and construction of the link feature, which is not limited here.
[0059] This step specifically includes: Starting from the target account, the transaction network of this account is traced backward to obtain the previous transaction paths within the preset number of layers.
[0060] In this step, the target account refers to a specific account that needs to conduct risk analysis; the previous transaction path refers to all the capital flow chains where the funds flow into the target account; the preset number of layers refers to the maximum number of levels for upward tracing, which is used to limit the tracing depth; the backward tracing refers to starting from the target account and searching for paths in the reverse direction of the capital flow.
[0061] The system uses the breadth - first search algorithm for backward tracing. Starting from the target account, first obtain the first - level upstream accounts that directly transfer funds to it, forming the first - layer path. For each first - level upstream account, continue to trace its source of funds and obtain the second - level upstream accounts, forming the second - layer path. The system repeats this tracing process until the preset tracing layer number (such as 3 layers) is reached. During the tracing process, the system records all account nodes, transaction amounts, and transaction times on each path to construct a complete set of capital transfer paths.
[0062] Calculate the capital dispersion index based on the capital transfer scale of the previous transaction paths.
[0063] In this step, the capital transfer scale refers to the amount of funds transferred on each path; the capital dispersion index represents the degree of even distribution of funds on different paths.
[0064] The system calculates the capital dispersion for the obtained set of previous transaction paths. First, calculate the total capital transfer amount of each path, and sort all paths in descending order of capital scale. Then, use the Gini coefficient to calculate the capital dispersion: G=(n + 1−2×(∑(n + 1−i)×yi / Y)) / n, where n is the number of paths, yi is the amount of funds on the i - th path, and Y is the total amount of funds of all paths. The larger the G value, the more concentrated the fund distribution; the smaller the G value, the more dispersed the fund distribution. For example, when the funds are evenly distributed on all paths, G is close to 0; when the funds are concentrated on a few paths, G is close to 1.
[0065] Analyze the time - series combination characteristics of the previous transaction paths to obtain the path coordination index.
[0066] In this step, the time - series combination characteristics refer to the time - pattern characteristics of the capital flow on different paths; the path coordination index represents the degree of time synchronization of the capital flow on multiple paths.
[0067] The system analyzes the time series characteristics of transactions on each path. First, the transaction time points of each path are constructed into a time series, and the statistical characteristics of the transaction time intervals within the path are calculated. Then, the time series correlation between different paths is calculated, and the Pearson correlation coefficient is used to evaluate the degree of cooperation between paths. The path cooperation degree index is obtained by calculating the average value of the correlation coefficients of all path pairs: C = 2×∑∑corr(Ti, Tj) / (n×(n - 1)), where Ti and Tj are the time series of path i and path j, and n is the number of paths.
[0068] Construct the link position characteristics of the account based on this fund dispersion index and this path cooperation degree index.
[0069] In this step, the link position characteristics refer to the feature vector that comprehensively reflects the position characteristics of the account in the fund flow chain.
[0070] The system combines the fund dispersion index and the path cooperation degree index to construct a link position feature vector. The specific method is as follows: standardize the two index values and convert them into the interval [0, 1]; then construct a two-dimensional feature vector F = (G', C'), where G' is the standardized fund dispersion degree and C' is the standardized path cooperation degree. This feature vector describes the structural position characteristics of the account in the fund flow network: G' reflects the degree of fund concentration, and C' reflects the cooperation of fund flow. The system uses this feature vector for subsequent role recognition and risk assessment.
[0071] It can be understood that step S104 can be executed after step S103 or after step S101, and there is no limit here.
[0072] S105. Calculate the final suspiciousness score of the account based on this transfer importance score and this link position characteristic, and determine the account with the final suspiciousness score greater than the preset score threshold as a suspicious account.
[0073] Among them, the final suspiciousness score represents the risk assessment score obtained by comprehensively considering the importance transfer of the account in the network and the link position characteristic; the preset score threshold refers to the risk determination boundary set by the system to distinguish normal accounts and suspicious accounts; a suspicious account refers to an account that is determined to have potential risks after risk assessment; the risk assessment index system is used to represent the multi-dimensional index set for evaluating the risk degree of the account; the scoring weight represents the importance degree of different risk characteristics in the final score.
[0074] This step is executed after obtaining the transfer importance score and link position characteristics of the account. Specifically, the system first constructs a risk assessment index system, standardizes the transfer importance score and link position characteristics. Then, based on historical data and expert experience, the scoring weights of each feature are determined, and the final suspiciousness score of the account is calculated through weighted combination. The system compares this score with a pre-set risk threshold. If it exceeds the threshold, the account is marked as a suspicious account and enters the subsequent early warning processing flow.
[0075] In some embodiments, the calculation of the suspiciousness score and the identification of suspicious accounts can be achieved in various ways: Optionally, first perform data normalization on the transfer importance score and link characteristics, then use the principal component analysis method to extract key risk characteristics, then determine the feature weights through the analytic hierarchy process, and finally calculate the comprehensive score and apply the threshold rule to identify suspicious accounts; Optionally, first construct a multi-layer neural network model, then input the standardized features into the model, then calculate the risk score through the model, and finally determine suspicious accounts based on the dynamic threshold strategy. It can be understood that other methods can also be used to achieve suspiciousness scoring and risk account identification, which are not limited here.
[0076] S106. Send out an early warning message according to the transfer importance score of the suspicious account, the link position characteristics, and the structural position in the account trading network.
[0077] Among them, the structural position refers to the position characteristics of the account in the overall trading network topology; the early warning message refers to the risk prompt message sent by the system, including content such as the risk level and risk description; the role attribute is used to represent the functional position of the account in the fund chain; the associated account group refers to the set of accounts with a close trading relationship with the suspicious account; the trading mode represents the fund transfer characteristics within the account group.
[0078] This step is executed immediately after identifying the suspicious account. Specifically, the system first divides the suspicious account into different risk levels according to its transfer importance score and sets the corresponding early warning levels. Then, it analyzes the role attribute of the account in the fund chain to determine whether it is a fund pooling, transfer, or dispersion node. For suspicious accounts with specific roles, the system further analyzes their structural positions in the trading network, identifies the account groups closely related to them, and studies the trading mode characteristics within the groups. Finally, the system integrates the above information to generate an early warning message containing content such as the risk level, role characteristics, and correlation analysis.
[0079] In some embodiments, the generation and transmission of warning information can be achieved in various ways: Optionally, first design risk level division rules based on the transfer importance score, then identify associated account groups through community discovery algorithms, then analyze the transaction behavior patterns within the groups, and finally generate structured warning information and push it through multiple channels; Optionally, first establish a risk warning template library, then select a suitable warning template according to the role analysis results, then fill in account characteristics and risk description information, and finally perform hierarchical push through the warning platform. It can be understood that other methods can also be used to process and send risk warning information, which is not limited here.
[0080] This step specifically includes: Classify the suspicious account according to its transfer importance score and set high, medium, and low three-level warning thresholds.
[0081] In this step, the transfer importance score refers to the account risk score obtained through network transfer calculation; the risk level refers to the risk level divided according to the score; the warning threshold refers to the score boundary value for triggering different levels of warnings.
[0082] The system performs hierarchical processing on the transfer importance score of the suspicious account. First, determine three warning thresholds: the high-risk warning threshold is set to 0.8, the medium-risk warning threshold is set to 0.6, and the low-risk warning threshold is set to 0.4. Based on these thresholds, the system classifies the accounts into different risk levels: accounts with a score greater than 0.8 are classified as high-risk; accounts with a score between 0.6 and 0.8 are classified as medium-risk; accounts with a score between 0.4 and 0.6 are classified as low-risk. The system configures corresponding monitoring strategies and handling measures for each risk level.
[0083] Analyze the role attributes of the suspicious account in the fund chain based on the link position characteristics of the suspicious account, and determine whether the suspicious account is a fund pooling node, a transfer node, or a dispersion node.
[0084] In this step, the role attribute refers to the functional position assumed by the account in the fund flow; the fund pooling node refers to the account that receives funds from multiple sources; the transfer node refers to the account that receives and transfers funds of similar scale; the dispersion node refers to the node that disperses and transfers funds to multiple accounts.
[0085] The system identifies roles based on the link location characteristics of accounts. Decision rules are used for determination: when the fund dispersion index is less than 0.3 and the in-degree is greater than the out-degree, it is determined as a fund aggregation node; when the fund dispersion index is greater than 0.7 and the out-degree is greater than the in-degree, it is determined as a fund dispersion node; when the ratio of in-degree to out-degree is between 0.8 and 1.2 and the ratio of fund inflow to outflow amount is between 0.9 and 1.1, it is determined as a fund transfer node. The system records the role determination results of each account for subsequent risk analysis.
[0086] If so, according to the structural location characteristics of the account's transaction network, identify the associated account group of the suspicious account and determine the transaction pattern within the associated account group.
[0087] In this step, the associated account group refers to the set of accounts that have a close transaction relationship with the target account; the transaction pattern refers to the fund transfer characteristics between the accounts within the group; the structural location characteristics refer to the location characteristics of the account in the topological structure of the transaction network.
[0088] The system uses the community detection algorithm to identify the associated account group. First, calculate the association strength between accounts, including three dimensions: transaction frequency, amount ratio, and time correlation. Then use the Louvain algorithm for community partitioning, taking the association strength as the edge weight to partition the closely connected account groups. For each group, the system analyzes the internal transaction pattern: calculate indicators such as internal transaction density, fund circulation rate, and transaction timing characteristics within the group to identify typical transaction patterns such as chain transfer, circular cycle, and star dispersion.
[0089] When an account does not belong to a fund aggregation node, transfer node, or dispersion node, the system executes the following processing flow: First, the system marks the account as a general transaction node, indicating that it has no special functional positioning in the fund chain. For general transaction nodes, the system still records their basic transaction characteristics, including information such as total transaction amount, transaction frequency, and number of trading counterparts, but does not perform the identification of associated account groups and transaction pattern analysis. Such nodes usually show that both the in-degree and out-degree are small (e.g., both less than 3), the scale of fund inflow and outflow does not match (the ratio is less than 0.8 or greater than 1.2), and the fund dispersion index is at a medium level (between 0.3 and 0.7).
[0090] The system adopts a simplified monitoring strategy for such nodes: continuously record their transaction behaviors, but do not trigger the group analysis process. Only when their transaction characteristics change significantly (such as a sudden increase in transaction frequency or amount in a short period), re-evaluate their role attributes. This processing method avoids unnecessary in-depth analysis of ordinary transaction nodes and improves the operation efficiency of the system.
[0091] In the early warning information generation stage, the system only outputs basic risk information for such nodes, including account information, risk levels, and basic transaction characteristics, without including group analysis and transaction pattern-related content. This differentiated information generation strategy ensures the accuracy and practicality of the early warning information.
[0092] Generate early warning information including the basic information of the suspicious account, risk level, location characteristics, role description, and associated account group information.
[0093] In this step, the early warning information refers to the risk warning information generated by the system, which includes risk characteristic descriptions in multiple dimensions.
[0094] The system generates early warning information in a standard format. The early warning information includes the following fields: basic account information (account number, account opening name, account opening time, etc.); risk level (high, medium, low risk and corresponding score values); location characteristics (specific values of fund dispersion degree, path coordination degree); role description (node type and main risk characteristics); associated account information (group size, list of important nodes, description of typical transaction patterns). The system organizes this information in a structured format to form a complete early warning report and pushes it to relevant processing personnel through the early warning platform.
[0095] The following provides a further and more specific process description of the method provided in this embodiment. Please refer to Figure 2 , which is another process schematic diagram of the risk monitoring and early warning method for the bank system based on artificial intelligence in the embodiment of the present application.
[0096] S201. Set differentiated monitoring rules according to the risk level of the suspicious account. The monitoring rules include the daily maximum transaction amount, single-transaction maximum limit, and upper limit of the cumulative number of transactions for high-risk accounts.
[0097] Among them, the differentiated monitoring rules refer to the targeted transaction restriction conditions set according to different risk levels; the daily maximum transaction amount refers to the maximum total transaction amount allowed for a single account within a natural day; the single-transaction maximum limit refers to the maximum amount allowed for a single transaction; the upper limit of the cumulative number of transactions refers to the maximum number of transactions allowed for a single account within a specific time period.
[0098] Based on the risk levels of suspicious accounts calculated in the early stage, the system sets corresponding monitoring rules for different levels. For high-risk accounts, the strictest restriction conditions are set, such as the total daily transaction amount not exceeding 100,000 yuan, the single transaction amount not exceeding 20,000 yuan, and the daily transaction times not exceeding 5 times; for medium-risk accounts, the restrictions are appropriately relaxed, such as the total daily transaction amount not exceeding 500,000 yuan, the single transaction amount not exceeding 100,000 yuan, and the daily transaction times not exceeding 20 times; for low-risk accounts, relatively loose restrictions are adopted, such as the total daily transaction amount not exceeding 1,000,000 yuan, the single transaction amount not exceeding 200,000 yuan, and the daily transaction times not exceeding 50 times. At the same time, the system sets different limits for different business types. For example, different restriction standards are set for corporate accounts and personal accounts to ensure the rationality and effectiveness of the monitoring rules.
[0099] S202. When the current transaction behavior of the suspicious account triggers the monitoring rule, freeze the current transaction behavior and push an exception reminder to the target customer terminal.
[0100] Among them, the current transaction behavior refers to the transaction operation being carried out by the account; freezing refers to suspending the execution of this transaction; the target customer terminal refers to the operation terminal used by bank staff; the exception reminder refers to the risk prompt information generated by the system.
[0101] When an account initiates a transaction, the system checks in real time whether the transaction complies with the monitoring rules. When the system detects that a transaction triggers the monitoring rule, it immediately takes freezing measures. For example, if an 80,000 yuan transaction has occurred on a high-risk account on the same day and a 30,000 yuan transfer is initiated again, since it exceeds the daily transaction limit of 100,000 yuan, the system automatically intercepts this transaction. At the same time, the system pushes an exception transaction reminder to the bank management terminal, and the reminder information includes the basic account information, the current transaction amount, the cumulative transaction amount, the type of triggered rule, etc. After receiving the reminder, bank staff can view the detailed transaction information and risk analysis report for manual review and handling.
[0102] S203. Statistically analyze the number of times the suspicious account triggers the monitoring rule within the preset time window.
[0103] Among them, the preset time window refers to the fixed time period for statistical analysis; the number of triggers refers to the cumulative number of times the account triggers the monitoring rule; statistical analysis refers to summarizing and analyzing the trigger data.
[0104] The system counts the number of times the monitoring rules are triggered for each suspicious account within a fixed time window (such as one week or one month). The statistical content includes the total number of triggers, the distribution of the number of triggers for different rules, the trigger time distribution, etc. For example, the statistics show that a certain account has triggered the monitoring rules 15 times in the past week, including 8 times exceeding the daily transaction limit, 5 times exceeding the single-transaction limit, and 2 times exceeding the transaction frequency limit, and mainly concentrated in the afternoon of weekdays. The system records these statistical data for subsequent risk level adjustment and monitoring rule optimization. At the same time, the system conducts a classification analysis of the trigger behaviors to identify abnormal trigger patterns, such as whether there are attempts to evade monitoring and whether there are obvious regularities.
[0105] S204. When the number of triggers exceeds the preset threshold, increase the risk level of the suspicious account and adjust the monitoring rule parameters.
[0106] Among them, the preset threshold refers to the warning value of the number of triggers, which is used to judge whether it is necessary to increase the risk level; increasing the risk level means adjusting the risk rating of the account to a higher level; the monitoring rule parameters refer to the specific values that control transaction restrictions, including limit restrictions and frequency restrictions, etc.
[0107] The system implements a dynamic risk level adjustment mechanism to update risk control measures by continuously monitoring the abnormal behaviors of accounts. When the number of triggers of an account within the specified time window reaches the preset threshold (such as exceeding 10 times in one week), the system automatically increases the risk level of the account by one level. At the same time, adjust the monitoring rule parameters of the account, such as reducing the original daily transaction limit by 50%, reducing the single-transaction limit by 30%, and reducing the upper limit of the number of transactions by 40%. For accounts upgraded from medium risk to high risk, the system also adds additional monitoring dimensions, such as requiring supplementary materials for large transactions and adding a transaction delay review mechanism, etc. This dynamic adjustment ensures the timeliness and effectiveness of the monitoring measures and improves the accuracy of risk prevention and control.
[0108] S205. Record the trigger history of the monitoring rule and the results of manual handling.
[0109] Among them, the trigger history refers to the detailed record of the monitoring rule being triggered, including information such as the trigger time and trigger type; the results of manual handling refer to the review and handling of the trigger event by bank staff; the historical record refers to the storage and management of the above information.
[0110] The system establishes a complete monitoring record storage mechanism to record each rule trigger event in detail. The recorded content includes basic information such as trigger time, trigger account information, trigger rule type, transaction amount, and cumulative trigger times, as well as processing information such as manual review personnel, review time, review conclusion, and disposal measures. For each disposal result, the system records detailed information such as disposal type (such as release, rejection, manual verification, etc.), disposal basis, and supplementary materials. At the same time, the system classifies and stores these records and manages them through indexing, establishing multi-dimensional query interfaces to support retrieval according to conditions such as time, account, and rule type, facilitating subsequent analysis and traceability.
[0111] S206. Receive the disposal result mark of the warning information from the target customer terminal, and calculate the accuracy rate and false alarm rate of the warning rule based on this disposal result mark. The disposal result mark includes three types: real risk, false alarm, and to be observed.
[0112] The disposal result mark refers to the judgment result identifier made by bank personnel after reviewing the warning information, which is divided into three types: real risk (confirming the existence of risky behavior), false alarm (confirming as a normal transaction), and to be observed (needing continuous monitoring); the accuracy rate represents the proportion of risk accounts warned by the system that are confirmed as real risks; the false alarm rate represents the proportion of risk accounts warned by the system that are confirmed as false alarms; the target customer terminal refers to the operation terminal device used by bank risk control personnel to process warning information.
[0113] The system receives the disposal result mark of each warning information from the risk control personnel through the warning processing platform. For each warning account, the risk control personnel need to select the corresponding disposal result type after verifying the transaction information and analyzing the risk characteristics. The system calculates the accuracy index of the warning rule based on the accumulated disposal result data: accuracy rate = number of real risk warnings / total number of warnings; false alarm rate = number of false alarm warnings / total number of warnings. For example, among the last 100 warnings, 60 are marked as real risks, 30 are marked as false alarms, and 10 are marked as to be observed, then the accuracy rate is 60% and the false alarm rate is 30%. The system updates these statistical indicators in real time for evaluating the effectiveness of the warning rule.
[0114] S207. When the accuracy rate is lower than the preset accuracy rate threshold or the false alarm rate is higher than the preset false alarm rate threshold, adjust the score threshold in the warning rule.
[0115] The preset accuracy rate threshold refers to the minimum accuracy rate standard required by the system for judging whether the warning rule needs to be optimized; the preset false alarm rate threshold refers to the maximum false alarm rate upper limit allowed by the system; the score threshold refers to the scoring standard value used to determine whether an account is a suspicious account.
[0116] The system continuously monitors the accuracy rate and false alarm rate indicators of the early warning rules. When the accuracy rate is lower than the preset threshold (e.g., lower than 50%) or the false alarm rate is higher than the preset threshold (e.g., higher than 40%), the system automatically triggers the early warning rule optimization mechanism. The specific adjustment method is as follows: when the accuracy rate is too low, increase the decision score threshold for suspicious accounts to make the system more strictly screen risk accounts, such as increasing the score threshold from 0.7 to 0.8; when the false alarm rate is too high, lower the score threshold to make the system more lenient in determining risk accounts, such as lowering the score threshold from 0.7 to 0.6. When adjusting, comprehensively consider the changing trends of the accuracy rate and false alarm rate, and adopt a progressive adjustment strategy with the adjustment range controlled within 10% each time to ensure the stability of the system early warning. Continuously track the new accuracy rate and false alarm rate indicators after adjustment to verify the adjustment effect.
[0117] The risk monitoring and early warning system of the bank system in the embodiment of the present invention application will be described from the perspective of hardware processing. Please refer to Figure 3 , which is a schematic structural diagram of an entity device of the risk monitoring and early warning system of the bank system in the embodiment of the present application.
[0118] It should be noted that Figure 3 the structure of the risk monitoring and early warning system of the bank system shown is only an example and should not bring any restrictions to the functions and usage scopes of the embodiments of the present invention.
[0119] As Figure 3 shown, the risk monitoring and early warning system of the bank system includes a central processing unit (CPU) 301, which can perform various appropriate actions and processes according to the program stored in the read-only memory (ROM) 302 or the program loaded from the storage section 308 into the random access memory (RAM) 303, such as executing the method described in the above embodiments. In the RAM 303, various programs and data required for system operation are also stored. The CPU 301, ROM 302, and RAM 303 are connected to each other through a bus 304. The input / output (I / O) interface 305 is also connected to the bus 304.
[0120] The following components are connected to the I / O interface 305: an input section 306 including an audio input device, a pushbutton switch, etc.; an output section 307 including a liquid crystal display (LCD), an audio output device, an indicator light, etc.; a storage section 308 including a hard disk, etc.; and a communication section 309 including a network interface card such as a LAN (Local Area Network) card, a modem, etc. The communication section 309 performs communication processing via a network such as the Internet. The drive 310 is also connected to the I / O interface 305 as needed. A removable medium 311 such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc. is installed on the drive 310 as needed so that a computer program read therefrom can be installed into the storage section 308 as needed.
[0121] Specifically, according to an embodiment of the present invention, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, an embodiment of the present invention includes a computer program product that includes a computer program carried on a computer-readable medium, and the computer program includes a computer program for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from a network through the communication section 309, and / or installed from the removable medium 311. When the computer program is executed by the central processing unit (CPU) 301, various functions defined in the present invention are executed.
[0122] It should be noted that specific examples of the computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM), a flash memory, an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present invention, the computer-readable storage medium can be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device.
[0123] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present invention. Among them, each block in the flowchart or block diagram may represent a module, a program segment, or a part of code, and the above-mentioned module, program segment, or part of code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order from that marked in the accompanying drawings.
[0124] Specifically, the risk monitoring and early warning system of the bank system in this embodiment includes a processor and a memory. A computer program is stored on the memory. When the computer program is executed by the processor, it implements the method for risk monitoring and early warning of the bank system based on artificial intelligence provided in the above embodiment.
[0125] On the other hand, the present invention also provides a computer-readable storage medium. This storage medium may be included in the risk monitoring and early warning system of the bank system described in the above embodiment; or it may exist alone without being assembled into the risk monitoring and early warning system of the bank system. The above storage medium carries one or more computer programs. When the above one or more computer programs are executed by a processor of the risk monitoring and early warning system of the bank system, the risk monitoring and early warning system of the bank system is enabled to implement the method for risk monitoring and early warning of the bank system based on artificial intelligence provided in the above embodiment.
[0126] As mentioned above, the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present application.
[0127] As used in the above embodiments, depending on the context, the term "when..." may be interpreted to mean "if...", or "after...", or "in response to determining...", or "in response to detecting...". Similarly, depending on the context, the phrase "when determining..." or "if detecting (the stated condition or event)" may be interpreted to mean "if determining...", or "in response to determining...", or "when detecting (the stated condition or event)", or "in response to detecting (the stated condition or event)".
[0128] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by relevant hardware instructed by a computer program. This program can be stored in a computer-readable storage medium. When this program is executed, it can include the processes of the above method embodiments. The foregoing storage medium includes various media that can store program codes, such as ROM, random access memory (RAM), magnetic disks, or optical discs.
Claims
1. A method for risk monitoring and early warning of a bank system based on artificial intelligence, characterized in that, Applied to the bank system risk monitoring and early warning system, the method includes: Construct an account transaction network based on the transaction data within the target time window, and extract the transaction characteristics of each account node in the account transaction network. The account transaction network takes each account as a node, and the transaction relationship between accounts as a directed edge; Obtain the flow characteristics of the ratio relationship between account fund income and expenditure, the time correlation degree characteristics between the account and the counterparty, and the business combination mode characteristics of the account, and calculate the initial importance score of the account according to the flow characteristics, the time correlation degree characteristics, and the business combination mode characteristics; Conduct importance transmission through the transaction relationship between nodes according to the initial importance score, and calculate the transmitted importance score; Calculate the fund dispersion index and the path coordination index based on the pre-order transaction path of the target account in the account transaction network, and construct the link position characteristics of the account according to the fund dispersion index and the path coordination index; Calculate the final suspiciousness score of the account according to the transmitted importance score and the link position characteristics, and determine the account with the final suspiciousness score greater than the preset score threshold as a suspicious account; Send out a warning message according to the transmitted importance score, the link position characteristics of the suspicious account, and the structural position in the account transaction network.
2. The method according to claim 1, characterized in that, The step of conducting importance transmission through the transaction relationship between nodes according to the initial importance score and calculating the transmitted importance score specifically includes: Set a transaction scale threshold and a time interval threshold, and screen the eligible node pairs in the account transaction network; Obtain the transaction amount ratio, time decay coefficient, and transaction timing correlation degree between node pairs, and combine the initial importance score of the node with the transaction amount ratio, decay coefficient, and timing correlation degree to calculate the importance transmission value between nodes; Conduct iterative calculation on the account transaction network to obtain the transmitted importance score of each account node.
3. The method according to claim 1, wherein The step of calculating the fund dispersion index and the path coordination index based on the pre-order transaction path of the target account in the account transaction network and constructing the link position characteristics of the account according to the fund dispersion index and the path coordination index specifically includes: Perform backward tracing on the account transaction network starting from the target account to obtain the pre-order transaction path within the preset number of layers; Calculate the fund dispersion index based on the fund transfer scale of the pre-order transaction path; Analyze the timing combination characteristics of the pre-order transaction path to obtain the path coordination index; Construct the link position characteristics of the account according to the fund dispersion index and the path coordination index.
4. The method according to claim 1, characterized in that, The step of sending out a warning message according to the transmitted importance score, the link position characteristics of the suspicious account, and the structural position in the account transaction network specifically includes: Classify the risk level of the suspicious account according to the transmitted importance score of the suspicious account, and set high, medium, and low three-level warning thresholds; Analyze the role attributes of the suspicious account in the fund chain based on the link position characteristics of the suspicious account, and judge whether the suspicious account is a fund aggregation node, a transfer node, or a dispersion node; If so, identify the associated account group of the suspicious account and determine the transaction pattern within the associated account group according to the structural location characteristics of the account transaction network; Generate a warning message containing the basic information, risk level, location characteristics, role description, and associated account group information of the suspicious account.
5. The method according to claim 4, wherein After the step of generating the warning message containing the basic information, risk level, location characteristics, role description, and associated account group information of the suspicious account, the method further includes: Set differentiated monitoring rules according to the risk level of the suspicious account, where the monitoring rules include the maximum daily transaction amount, maximum single transaction limit, and upper limit of the cumulative number of transactions for high-risk accounts; When the current transaction behavior of the suspicious account triggers the monitoring rules, freeze the current transaction behavior and push an exception reminder to the target customer terminal.
6. The method according to claim 1, characterized in that, After the step of sending a warning message according to the transfer importance score of the suspicious account, the link location characteristics, and the structural location in the account transaction network, the method further includes: Statistically analyze the number of trigger times of the monitoring rules by the suspicious account within a preset time window; When the number of trigger times exceeds a preset threshold, increase the risk level of the suspicious account and adjust the monitoring rule parameters; Record the trigger history of the monitoring rules and the results of manual handling.
7. The method according to claim 6, characterized in that, After the step of recording the trigger history of the monitoring rules and the results of manual handling, the method further includes: Receive the disposal result mark of the warning message from the target customer terminal, and calculate the accuracy rate and false alarm rate of the warning rule according to the disposal result mark. The disposal result mark includes three types: real risk, false alarm, and to be observed; When the accuracy rate is lower than the preset accuracy rate threshold or the false alarm rate is higher than the preset false alarm rate threshold, adjust the score threshold in the warning rule.
8. A bank system risk monitoring and early warning system, characterized in that, The bank system risk monitoring and warning system includes: one or more processors and a memory; the memory is coupled to the one or more processors, the memory is used to store computer program code, the computer program code includes computer instructions, and the one or more processors call the computer instructions to enable the bank system risk monitoring and warning system to execute the method according to any one of claims 1-7.
9. A computer-readable storage medium, comprising instructions, characterized in that, When the instruction runs on the bank system risk monitoring and warning system, enable the bank system risk monitoring and warning system to execute the method according to any one of claims 1-7.
10. A computer program product, characterized in that, When the computer program product runs on the bank system risk monitoring and warning system, enable the bank system risk monitoring and warning system to execute the method according to any one of claims 1-7.
Citation Information
Patent Citations
Money laundering risk analysis method based on graph calculation
CN117829994A
Method and device for monitoring abnormal fund operation object
CN118467787A
Cited By
Scientific and technological finance comprehensive enabling service system and method based on Beidou satellite application industry
CN120975727A
Multi-dimensional anti-fraud and risk control auditing method and system for large transaction
CN120996940A
Intelligent early warning analysis method for fund flow abnormity
CN121258689A
Integration link resonance early warning method and early warning device
CN121724683A
Integral link resonance early warning method and early warning device
CN121724683B