A bank system risk monitoring and early warning method and system based on artificial intelligence
By constructing an account transaction network, calculating initial importance scores, and analyzing fund dispersion and path coordination, suspicious accounts are identified. This solves the risk identification problem of multi-level account transfers and decentralized transactions in the banking system, and improves the timeliness and accuracy of risk monitoring.
Patent Information
- Application Number
- CN202510496713.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-21
- Publication Date
- 2025-12-30
- Estimated Expiration
- 2045-04-21
AI Technical Summary
Existing risk monitoring methods in the banking system are insufficient to effectively identify complex risk behaviors such as multi-level account transfers and decentralized transactions, and fixed rule models are difficult to adapt to new risk patterns, resulting in frequent underreporting and false alarms.
Construct an account transaction network, extract transaction features, calculate initial importance scores, transmit importance through transaction relationships between nodes, analyze the fund dispersion and path synergy of preceding transaction paths, identify suspicious accounts by combining link location features, and set differentiated monitoring rules and dynamic adjustment mechanisms.
It improves the timeliness and accuracy of risk monitoring in the banking system, enabling the identification of multi-level account transfers and decentralized transactions, reducing false alarm rates, and achieving precise risk positioning and rapid control.
Smart Images

Figure CN120298091B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of data processing for administrative, commercial, financial, management, supervision or prediction purposes, and in particular to a bank system risk monitoring and early warning method and system based on artificial intelligence. BACKGROUND
[0002] With the rapid development of financial technology, the scale and complexity of bank transactions are increasing, and bank system risk events are occurring frequently. In order to maintain financial order and ensure financial safety, the monitoring and early warning of bank system risks have become increasingly important.
[0003] In related technologies, risk identification can be performed using rule matching. By setting threshold rules for dimensions such as transaction amount, transaction frequency, and transaction time, transactions that exceed the threshold are marked and manually reviewed. At the same time, some banks are also trying to introduce statistical analysis methods to establish statistical models based on historical transaction data to statistically analyze and detect abnormalities in account transactions.
[0004] However, due to the inability to effectively analyze complex transaction relationships between accounts, this approach makes it difficult to discover risk behaviors that evade monitoring through multi-level account transfers and dispersed transactions. At the same time, as criminals constantly update their methods, fixed rule models are difficult to adapt to new risk patterns in a timely manner, making some risk behaviors unable to be discovered and warned in a timely manner. SUMMARY
[0005] The present application provides a bank system risk monitoring and early warning method and system based on artificial intelligence, which can improve the timeliness of discovering bank transaction risk behaviors.
[0006] In a first aspect, the application provides a bank system risk monitoring and early warning method based on artificial intelligence, applied to a bank system risk monitoring and early warning system. The method comprises: constructing an account transaction network based on transaction data in a target time window, and extracting transaction features of each account node in the account transaction network, wherein the account transaction network takes each account as a node, and the transaction relationship between the accounts as a directed edge; obtaining a flow direction feature of an account fund income and expenditure ratio relationship, a time correlation degree feature of an account and a transaction counterpart, and a business combination mode feature of the account, and calculating an initial importance score of the account according to the flow direction feature, the time correlation degree feature and the business combination mode feature; performing importance transmission between nodes according to the initial importance score, and calculating a transmission importance score; calculating a fund dispersion degree index and a path coordination degree index based on a previous transaction path of a target account in the account transaction network, and constructing a link position feature of the account according to the fund dispersion degree index and the path coordination degree index; calculating a final suspiciousness score of the account according to the transmission importance score and the link position feature, and determining an account with a final suspiciousness score greater than a preset score threshold as a suspicious account; and issuing an early warning information according to the transmission importance score of the suspicious account, the link position feature and the structural position in the account transaction network.
[0007] In the above embodiment, by constructing an account transaction network and extracting transaction features, an initial importance score is calculated in combination with account fund flow direction, time correlation and business mode features, and then importance transmission is performed between nodes. The system effectively identifies hidden risk behaviors such as multi-level account transfer and dispersed transactions by analyzing the fund dispersion degree and path coordination degree of the previous transaction path of the target account, can better adapt to and discover new risk forms, and improves the timeliness and accuracy of risk monitoring.
[0008] In combination with some embodiments of the first aspect, in some embodiments, the step of performing importance transmission between nodes according to the initial importance score and calculating a transmission importance score comprises: setting a transaction size threshold and a time interval threshold, and screening node pairs in the account transaction network that meet the conditions; obtaining a transaction amount ratio, a time decay coefficient and a transaction time sequence correlation degree between the node pairs, and combining the initial importance score of the node with the transaction amount ratio, the decay coefficient and the time sequence correlation degree to calculate an importance transmission value between the nodes; and performing iterative calculation on the account transaction network to obtain a transmission importance score of each account node.
[0009] In the above embodiments, node pairs are filtered by setting transaction size and time interval thresholds, and the importance transfer value is calculated by comprehensively considering factors such as transaction amount ratio, time decay coefficient, and transaction time sequence correlation. Through iterative calculation, the risk transfer process more accurately reflects the degree of correlation between accounts and the risk transfer path, thereby obtaining a more accurate transfer importance score for each account node, providing a more reliable basis for subsequent risk assessment.
[0010] In conjunction with some embodiments of the first aspect, in some embodiments, the step of calculating the fund dispersion index and path coordination index based on the preceding transaction path of the target account in the account transaction network, and constructing the link position characteristics of the account based on the fund dispersion index and the path coordination index, specifically includes: tracing back the account transaction network from the target account to obtain the preceding transaction path within a preset number of layers; calculating the fund dispersion index based on the fund flow scale of the preceding transaction path; analyzing the temporal combination characteristics of the preceding transaction path to obtain the path coordination index; and constructing the link position characteristics of the account based on the fund dispersion index and the path coordination index.
[0011] In the above embodiments, the preceding transaction path is obtained by tracing the target account backwards, the scale of fund flow is analyzed to calculate the fund dispersion index, and the path coordination index is obtained by combining the temporal combination characteristics of the path. This multi-level path analysis method enables the system to comprehensively grasp the characteristics of fund flow, effectively identify abnormal fund flow paths, and deeply characterize the risk characteristics of the account in the entire transaction network by constructing link position characteristics.
[0012] In conjunction with some embodiments of the first aspect, in some embodiments, the step of issuing a warning message based on the transmission importance score of the suspicious account, the link location characteristics, and the structural position of the account in the transaction network specifically includes: classifying the suspicious account into risk levels based on its transmission importance score and setting three warning thresholds: high, medium, and low; analyzing the role attributes of the suspicious account in the funding chain based on the link location characteristics of the suspicious account, and determining whether the suspicious account is a funding aggregation node, transit node, or decentralized node; if so, identifying the associated account groups of the suspicious account and determining the transaction patterns within the associated account groups based on the structural position characteristics of the account's transaction network; and generating a warning message containing basic information of the suspicious account, risk level, location characteristics, role description, and associated account group information.
[0013] In the above embodiments, suspicious accounts are classified into risk levels and tiered early warning thresholds are set. Based on the link location characteristics, the role attributes of accounts in the capital chain are analyzed to further identify the transaction patterns of related account groups. Through multi-dimensional profiling analysis of suspicious accounts, complete early warning information including basic information, risk level, and location characteristics is formed, realizing the accurate positioning and comprehensive characterization of risky accounts, and providing a more detailed and accurate early warning basis for risk control.
[0014] In conjunction with some embodiments of the first aspect, in some embodiments, after the step of generating warning information containing basic information of the suspicious account, risk level, location characteristics, role description and associated account group information, the method further includes: setting differentiated monitoring rules according to the risk level of the suspicious account, the monitoring rules including the maximum daily transaction amount, the maximum single transaction limit and the maximum number of cumulative transactions for high-risk accounts; when the current transaction behavior of the suspicious account triggers the monitoring rules, freezing the current transaction behavior and pushing an abnormal reminder to the target client terminal.
[0015] In the above embodiments, differentiated monitoring rules are set according to the risk level of suspicious accounts, including transaction amounts, limits, and frequency caps. When an account triggers the monitoring rules, transactions are frozen promptly and an anomaly alert is pushed. The differentiated monitoring rules and real-time response mechanism enable the system to quickly take control measures after detecting risks, effectively preventing the continuation of abnormal trading behavior and reducing the risk of financial loss.
[0016] In conjunction with some embodiments of the first aspect, in some embodiments, after the step of issuing a warning based on the transmission importance score of the suspicious account, the link location characteristics, and the structural position of the account in the transaction network, the method further includes: statistically analyzing the number of times the suspicious account triggers the monitoring rule within a preset time window; when the number of triggers exceeds a preset threshold, increasing the risk level of the suspicious account and adjusting the monitoring rule parameters; and recording the trigger history of the monitoring rule and the results of manual handling.
[0017] In the above embodiments, the number of times suspicious accounts trigger monitoring rules is statistically analyzed. When the number exceeds a preset threshold, the risk level and monitoring parameters are dynamically adjusted, and the trigger history and handling results are recorded. This dynamic risk level adjustment mechanism enhances the system's ability to identify persistent abnormal behavior, enabling monitoring rules to be adjusted promptly according to changes in risk, thus improving the flexibility and adaptability of risk prevention and control.
[0018] In conjunction with some embodiments of the first aspect, in some embodiments, after the step of recording the trigger history and manual handling results of the monitoring rule, the method further includes: receiving the handling result mark of the warning information from the target client terminal; calculating the accuracy and false alarm rate of the warning rule based on the handling result mark; the handling result mark includes three types: real risk, false alarm, and pending observation; and adjusting the score threshold in the warning rule when the accuracy is lower than a preset accuracy threshold or the false alarm rate is higher than a preset false alarm rate threshold.
[0019] In the above embodiments, the system receives the target client terminal's handling result label for the warning information. Based on three types of labels—real risk, false alarm, and pending observation—the accuracy and false alarm rate of the warning rules are calculated. When the accuracy or false alarm rate exceeds a preset threshold, the scoring threshold in the warning rules is automatically adjusted. This adaptive adjustment mechanism of the warning rules enables the system to continuously optimize the warning threshold during operation, thereby continuously improving the accuracy of warnings and reducing the false alarm rate.
[0020] Secondly, embodiments of this application provide a banking system risk monitoring and early warning system, which includes: one or more processors and a memory; the memory is coupled to the one or more processors, and the memory is used to store computer program code, which includes computer instructions, and the one or more processors call the computer instructions to cause the banking system risk monitoring and early warning system to perform the method described in the first aspect and any possible implementation thereof.
[0021] Thirdly, embodiments of this application provide a computer program product containing instructions that, when the computer program product is run on a banking system risk monitoring and early warning system, cause the banking system risk monitoring and early warning system to execute the method described in the first aspect and any possible implementation thereof.
[0022] Fourthly, embodiments of this application provide a computer-readable storage medium including instructions that, when executed on a banking system risk monitoring and early warning system, cause the banking system risk monitoring and early warning system to perform the method described in the first aspect and any possible implementation thereof.
[0023] Understandably, the banking system risk monitoring and early warning system provided in the second aspect, the computer program product provided in the third aspect, and the computer storage medium provided in the fourth aspect are all used to execute the methods provided in the embodiments of this application. Therefore, the beneficial effects they can achieve can be referred to the beneficial effects in the corresponding methods, and will not be repeated here.
[0024] One or more technical solutions provided in the embodiments of this application have at least the following technical effects or advantages:
[0025] 1. This application constructs an account transaction network and extracts transaction features. It calculates an initial importance score by combining account fund flows, time correlations, and business model characteristics, and then transmits importance through inter-node transaction relationships. By analyzing the fund dispersion and path coordination of the target account's preceding transaction paths, the system effectively identifies hidden risk behaviors such as multi-level account transfers and dispersed transactions. This allows for better adaptation to and discovery of new risk patterns, improving the timeliness and accuracy of risk monitoring.
[0026] 2. This application filters node pairs by setting thresholds for transaction size and time intervals, and calculates the importance transfer value by comprehensively considering factors such as the proportion of transaction amount, time decay coefficient, and transaction sequence correlation. Through iterative calculation, the risk transfer process more accurately reflects the degree of correlation between accounts and the risk transfer path, thereby obtaining a more accurate transfer importance score for each account node, providing a more reliable basis for subsequent risk assessment.
[0027] 3. This application obtains the preceding transaction path by tracing the target account in reverse, analyzes the scale of fund flow to calculate the fund dispersion index, and combines the temporal combination characteristics of the path to obtain the path synergy index. This multi-level path analysis method enables the system to comprehensively grasp the characteristics of fund flow, effectively identify abnormal fund flow paths, and deeply characterize the risk characteristics of the account in the entire transaction network by constructing link position characteristics. Attached Figure Description
[0028] Figure 1 This is a flowchart illustrating an artificial intelligence-based risk monitoring and early warning method for banking systems in this application embodiment;
[0029] Figure 2 This is another flowchart illustrating the AI-based risk monitoring and early warning method for banking systems in this application embodiment;
[0030] Figure 3 This is a schematic diagram of the physical device structure of a bank system risk monitoring and early warning system in the embodiments of this application. Detailed Implementation
[0031] The terminology used in the following embodiments of this application is for the purpose of describing particular embodiments only and is not intended to be limiting of this application. As used in the specification of this application, the singular expressions “a,” “an,” “the,” “the,” and “this” are intended to include the plural expressions as well, unless the context clearly indicates otherwise. It should also be understood that the term “and / or” as used in this application refers to any or all possible combinations including one or more of the listed items.
[0032] Hereinafter, the terms "first" and "second" are used for descriptive purposes only and should not be construed as implying or suggesting relative importance or implicitly indicating the number of indicated technical features. Thus, a feature defined as "first" or "second" may explicitly or implicitly include one or more of that feature, and in the description of the embodiments of this application, unless otherwise stated, "multiple" means two or more.
[0033] To facilitate understanding, the application scenarios of the embodiments of this application are described below.
[0034] In daily banking operations, the widespread adoption of electronic payments and online transfers has significantly increased the frequency and complexity of transactions. A typical example is a merchant who received 157 payments via online banking within a week, ranging from 500 to 3,000 yuan, with transactions occurring at different times of the day and in multiple cities. These funds were transferred through three to four intermediary accounts, and the individual transaction amounts and time intervals were carefully designed, making it difficult for traditional transaction monitoring systems to determine whether they were normal business transactions. Especially in interbank transactions, due to incomplete information, relying solely on simple characteristics such as transaction amount and frequency is insufficient to accurately identify potential risks. Banks need to establish a monitoring method capable of analyzing transaction chains, identifying fund flows, and assessing the importance of nodes to accurately detect abnormal transaction behaviors hidden within normal business operations.
[0035] Current transaction monitoring primarily relies on pre-set business rules. For example, transaction alert rules might be set up such as triggering an alert for more than 5 transfers in a single day, a single transaction exceeding 10,000 yuan, or transactions exceeding 30,000 yuan for three consecutive days. In one real-world example, a small trading company's corporate account was flagged as abnormal by the system for transferring 8,000 yuan to each of five suppliers daily. However, this was later verified as legitimate payments, resulting in an invalid alert. Another scenario involves an account circumventing the 10,000 yuan single-transaction monitoring threshold by transferring 9,000 yuan three times a day. This fixed-rule-based monitoring method cannot effectively analyze the correlation between accounts, nor can it dynamically adjust monitoring standards according to different business scenarios, leading to numerous false alarms and missed alerts.
[0036] After implementing this solution, the system can identify abnormal behavior by analyzing the transaction network. In a real-world case, the system detected transactions involving seven accounts over two days: first, three accounts made five deposits of 8,000 yuan each, which were then transferred to four intermediary accounts. Each intermediary account then distributed the funds to two or three downstream accounts, and these funds ultimately converged into a target account within 36 hours. The system calculated the importance score of node transmission and found that the target account scored 0.75. Analyzing its link location characteristics revealed a fund dispersion degree of 0.62 and a path coordination degree of 0.58, classifying it as a fund aggregation node. The system further identified a transaction group consisting of 12 related accounts, finding that it exhibited a "deposit-dispersion-aggregation" transaction pattern, and successfully issued an alert. This method avoids misjudging normal business transactions while accurately identifying structured abnormal transaction behavior.
[0037] To facilitate understanding, the method provided in this implementation will be described in detail below, using the above scenario as an example. Please refer to [link / reference]. Figure 1 This is a flowchart illustrating an artificial intelligence-based risk monitoring and early warning method for banking systems in this application.
[0038] S101. Construct an account transaction network based on transaction data within the target time window, and extract the transaction characteristics of each account node in the account transaction network. The account transaction network uses each account as a node and the transaction relationship between the accounts as a directed edge.
[0039] Among them, the target time window represents a specific time range for risk monitoring and analysis, which can be fixed, such as a week or a month, or a sliding time window; the account transaction network is a graph-based network structure used to describe the transaction relationship between accounts; transaction characteristics refer to various indicators that can characterize the account transaction behavior pattern, including transaction frequency, transaction amount, transaction counterparty and other information; directed edges represent the transaction direction of funds flowing from one account to another.
[0040] This step is typically performed when the system initiates its risk monitoring process. Specifically, the system first retrieves all account transaction data within the target time window from the transaction database, maps each account to a node in the network, and establishes connections between accounts based on transaction records, forming a complete transaction network structure. Then, for each account node, it extracts its transaction behavior characteristics within that time window, including information on dimensions such as total transaction amount, transaction frequency, and number of counterparties.
[0041] In some embodiments, the construction and feature extraction of the account transaction network can be achieved in the following ways: Optionally, the raw transaction data is first preprocessed, including data cleaning, outlier handling, and standardization; then, a graph database is used to store account nodes and transaction relationships; finally, the basic transaction features of the nodes are calculated. Optionally, a distributed computing framework is used to process large-scale transaction data in parallel to construct an account relationship network, while feature engineering methods are used to extract multi-dimensional transaction features. It is understood that other methods can also be used to achieve network construction and feature extraction, which are not limited here.
[0042] S102. Obtain the flow characteristics of the account's fund inflow and outflow ratio, the time correlation characteristics between the account and its counterparties, and the business combination pattern characteristics of the account. Calculate the initial importance score of the account based on these flow characteristics, time correlation characteristics, and business combination pattern characteristics.
[0043] Among them, the flow characteristics reflect the proportional relationship and flow direction of account funds inflow and outflow; the time correlation characteristics indicate the closeness of the transaction sequence between the account and the counterparty; the business combination pattern characteristics describe the various business types involved in the account and their combination characteristics; and the initial importance score is the initial assessment value for measuring the degree of account anomaly.
[0044] This step is performed after the account transaction network is constructed. Specifically, based on the constructed transaction network, the system calculates feature values from three dimensions: fund flow, time correlation, and business portfolio. Then, these three types of features are weighted in a specific way to calculate the initial importance score for each account, which reflects the potential risk level of the account.
[0045] In some embodiments, feature calculation and score calculation can be implemented in the following ways: Optionally, statistical methods can be used to calculate features such as the account's fund inflow / outflow ratio, transaction time interval distribution, and business type entropy, and then a weighted summation method can be used to obtain an initial score; Optionally, a machine learning model can be used to non-linearly combine multi-dimensional features, and the initial importance score of the account can be obtained through the model output. It is understood that other methods can also be used to implement feature extraction and score calculation, which are not limited here.
[0046] S103. Based on the initial importance score, importance is transferred through inter-node transaction relationships, and the transferred importance score is calculated.
[0047] Importance transfer refers to the process of propagating the initial importance score across the network based on the transaction relationships between account nodes; the transferred importance score represents the final importance score obtained by the account after propagation through the network; the transaction relationship between nodes refers to the connection relationship of funds between accounts, including characteristics such as transaction amount, transaction frequency, and time series; the transaction amount ratio is used to represent the relative size of the transaction scale between adjacent nodes; the time decay coefficient represents the weight of the influence of transaction time on importance transfer; and the transaction time series correlation is used to measure the time correlation of transactions between accounts.
[0048] This step is performed after obtaining the initial importance score of the account. Specifically, the system first sets filtering thresholds for transaction size and time interval, and filters out valid account node pairs based on these thresholds. For each pair of connected nodes, it calculates the proportion of transaction amount between them, the decay coefficient based on transaction time, and the correlation reflecting the transaction time sequence pattern. Then, it multiplies the initial importance score of the source node by these feature values to obtain the importance value passed to the target node. The system repeats this transfer calculation process until the importance scores of all nodes in the network reach a stable state.
[0049] In some embodiments, the calculation of importance transfer between nodes can be implemented in several ways: Optionally, firstly, a transaction relationship matrix is constructed to record the connection relationships between nodes, then the feature weights between node pairs are calculated, followed by an iterative algorithm to calculate importance transfer, and finally, the transfer result is normalized to obtain the final score; Optionally, the transaction network is first transformed into a probability transition matrix, then the steady-state distribution of nodes is calculated based on a random walk model, and finally, the score after transfer is obtained by combining the initial importance score. It is understandable that...
[0050] This step specifically includes:
[0051] Set transaction size thresholds and time interval thresholds to filter eligible node pairs in the account transaction network.
[0052] In this step, the transaction size threshold refers to the minimum transaction amount standard for screening valid transaction relationships, used to filter out small transactions; the time interval threshold refers to the maximum time interval standard for determining transaction correlation, used to filter transactions with excessively large time spans; and a node pair refers to two account nodes in the account transaction network that have a direct transaction relationship.
[0053] The system first sets basic screening criteria: a transaction size threshold of no less than 10,000 yuan per transaction and a time interval threshold of no more than 30 days between adjacent transactions. Based on these two thresholds, the system filters all node pairs in the account transaction network: it traverses each transaction edge in the network, extracts transaction amount and transaction time information, and determines whether both the size and time conditions are met. Node pairs that meet the conditions retain their transaction relationship, while transaction edges between node pairs that do not meet the conditions are removed. Through this screening, the system constructs a simplified network structure containing significant transaction relationships.
[0054] Obtain the transaction amount ratio, time decay coefficient, and transaction time sequence correlation between node pairs, and combine the initial importance score of the node with the transaction amount ratio, decay coefficient, and time sequence correlation to calculate the importance transfer value between nodes.
[0055] In this step, the transaction amount ratio refers to the proportion of the transaction amount between nodes to the total transaction amount of the source node; the time decay coefficient refers to the weighting coefficient calculated based on the transaction time interval, which is used to reflect the time decay effect; the transaction time sequence correlation degree refers to the similarity of the time patterns of transactions between nodes; and the importance transmission value refers to the risk level value that a node transmits to its neighboring nodes.
[0056] The system calculates three feature values for each pair of connected nodes: transaction amount ratio = inter-node transaction amount / total transaction amount of the source node; time decay coefficient = exp(-Δt / T), where Δt is the transaction time interval and T is the feature time scale (e.g., 30 days); and transaction time series correlation is obtained by calculating the correlation coefficient of the transaction time series of the two nodes. Then, the initial importance score of the source node is weighted and combined with these three feature values: transit value = initial score × (w1 × amount ratio + w2 × decay coefficient + w3 × correlation), where w1, w2, and w3 are weight coefficients and satisfy w1 + w2 + w3 = 1.
[0057] The transaction network of this account is iteratively calculated to obtain the transmission importance score of each account node.
[0058] In this step, iterative computation refers to the process of repeatedly performing importance propagation computation until the network reaches a stable state; propagation importance score refers to the final importance score obtained by the node after propagation through the network.
[0059] The system updates node importance scores iteratively. In each iteration, for each node in the network, the importance values passed down from all its predecessor nodes are summarized, and a new node score is calculated. The specific calculation formula is: New score = α × (sum of all incoming importance values) + (1-α) × initial score, where α is the network propagation coefficient (0 < α < 1). The system repeats this update process until the change in scores of all nodes is less than a preset convergence threshold (e.g., 0.001), or the maximum number of iterations (e.g., 100) is reached. The final stable score is the node's propagated importance score.
[0060] S104. Calculate the fund dispersion index and path coordination index based on the preceding transaction path of the target account in the account transaction network, and construct the link position characteristics of the account based on the fund dispersion index and the path coordination index.
[0061] Among them, the preceding transaction path represents the inflow path of funds obtained by reverse tracing; the fund dispersion index is used to measure the degree of dispersion or concentration of funds on the inflow path; the path coordination index represents the temporal synchronization of fund flows on different paths; the link position characteristics refer to the structural characteristics of the account in the entire fund flow chain, reflecting its role and importance in the fund transfer process; and the fund transfer scale refers to the amount of funds transferred on each path.
[0062] This step is executed after the target account to be analyzed is identified. Specifically, the system starts with the target account and traces backward through the transaction network to obtain all preceding transaction paths within a preset number of layers. For these paths, the system calculates the scale of fund flow on each path, analyzes the distribution of funds across different paths, and obtains a fund dispersion index. Simultaneously, the system studies the temporal characteristics of fund flows on each path, calculates the temporal correlation between paths, and obtains a path synergy index. Finally, these two indices are combined to construct a feature vector representing the account's positional characteristics within the fund chain.
[0063] In some embodiments, link location features can be constructed in several ways: Optionally, a depth-first search algorithm is first used to obtain preceding transaction paths, then the fund flow distribution of each path is calculated, followed by analysis of transaction time-series patterns on the paths, and finally, a feature fusion method is used to construct a location feature vector; alternatively, a breadth-first search is first used to obtain multi-layer transaction paths, then the entropy method is used to calculate fund dispersion, followed by time series analysis to obtain path synergy, and finally, location features are obtained through multi-dimensional feature combination. It is understood that other methods can also be used to extract and construct link features, which are not limited here.
[0064] This step specifically includes:
[0065] Starting from the target account, the transaction network of that account is traced backward to obtain the preceding transaction path within a preset number of layers.
[0066] In this step, the target account refers to the specific account that needs to be risk analyzed; the preceding transaction path refers to all the fund flow chains that lead to the target account; the preset number of layers refers to the maximum number of layers to trace upwards, which is used to limit the tracing depth; and reverse tracing refers to starting from the target account and searching the path in the opposite direction of the fund flow.
[0067] The system employs a breadth-first search algorithm for reverse tracing. Starting with the target account, it first identifies the primary upstream accounts that directly transferred funds to it, forming the first-level path. For each primary upstream account, it continues to trace the source of funds to obtain secondary upstream accounts, forming the second-level path. The system repeats this tracing process until a preset number of tracing levels (e.g., 3 levels) is reached. During the tracing process, the system records all account nodes, transaction amounts, and transaction times on each path, constructing a complete set of fund transfer paths.
[0068] The fund dispersion index is calculated based on the fund flow scale of the preceding transaction path.
[0069] In this step, the scale of fund transfer refers to the amount of funds transferred along each path; the fund dispersion index indicates the degree of evenness of fund distribution across different paths.
[0070] The system calculates the fund dispersion of the acquired set of preceding transaction paths. First, it calculates the total fund flow for each path and sorts all paths from largest to smallest fund size. Then, it uses the Gini coefficient to calculate the fund dispersion: G = (n+1 - 2 × (∑(n+1 - i) × yi / Y)) / n, where n is the number of paths, yi is the fund amount of the i-th path, and Y is the total fund amount across all paths. A larger G value indicates a more concentrated fund distribution, while a smaller G value indicates a more dispersed fund distribution. For example, when funds are evenly distributed across all paths, G approaches 0; when funds are concentrated on a few paths, G approaches 1.
[0071] The path synergy index is obtained by analyzing the temporal combination characteristics of the preceding transaction path.
[0072] In this step, the time sequence combination feature refers to the time pattern characteristics of capital flows on different paths; the path coordination index represents the degree of time synchronization of capital flows on multiple paths.
[0073] The system analyzes the time series characteristics of transactions on each path. First, the transaction timestamps of each path are constructed as time series, and the statistical characteristics of transaction time intervals within each path are calculated. Then, the time series correlation between different paths is calculated, and the Pearson correlation coefficient is used to assess the degree of synergy between paths. The path synergy index is obtained by calculating the average correlation coefficient of all path pairs: C = 2 × ∑∑corr(Ti, Tj) / (n × (n-1)), where Ti and Tj are the time series of paths i and j, and n is the number of paths.
[0074] The link location characteristics of the account are constructed based on the fund dispersion index and the path coordination index.
[0075] In this step, the link location feature refers to the feature vector that comprehensively reflects the position characteristics of the account in the fund flow chain.
[0076] The system combines the fund dispersion index and the path coordination index to construct a link location feature vector. Specifically, the two index values are standardized to the [0, 1] interval; then a two-dimensional feature vector F = (G', C') is constructed, where G' is the standardized fund dispersion and C' is the standardized path coordination. This feature vector characterizes the structural location of an account in the fund flow network: G' reflects the degree of fund aggregation, and C' reflects the coordination of fund flows. The system uses this feature vector for subsequent role identification and risk assessment.
[0077] It can be understood that step S104 can be executed after step S103 or after step S101, and there is no limitation here.
[0078] S105. Calculate the final suspiciousness score of the account based on the transmission importance score and the link location characteristics, and identify the account whose final suspiciousness score is greater than the preset score threshold as a suspicious account.
[0079] The final suspiciousness score represents the risk assessment score obtained by comprehensively considering the importance of the account in the network and the characteristics of the link location; the preset score threshold refers to the risk judgment boundary set by the system to distinguish between normal accounts and suspicious accounts; a suspicious account refers to an account that is identified as having potential risks after risk assessment; the risk assessment index system is a set of multi-dimensional indicators used to assess the risk level of an account; and the scoring weight represents the importance of different risk characteristics in the final score.
[0080] This step is executed after obtaining the account's transmission importance score and link location characteristics. Specifically, the system first constructs a risk assessment indicator system and standardizes the transmission importance score and link location characteristics. Then, based on historical data and expert experience, it determines the scoring weight of each characteristic and calculates the account's final suspiciousness score through a weighted combination. The system compares this score with a pre-set risk threshold; if it exceeds the threshold, the account is marked as a suspicious account and enters the subsequent early warning processing procedure.
[0081] In some embodiments, the calculation of suspiciousness scores and the identification of suspicious accounts can be achieved in several ways: Optionally, the importance score and link features are first normalized, then key risk features are extracted using principal component analysis, feature weights are determined using analytic hierarchy process (AHP), and finally, a comprehensive score is calculated and a threshold rule is applied to identify suspicious accounts; alternatively, a multi-layer neural network model is first constructed, then the standardized features are input into the model, a risk score is calculated using the model, and finally, a dynamic threshold strategy is used to determine suspicious accounts. It is understood that other methods can also be used to achieve suspiciousness scoring and risk account identification, which are not limited here.
[0082] S106. Based on the transmission importance score of the suspicious account, the location characteristics of the link, and the structural position of the account in the transaction network, issue an early warning message.
[0083] Among them, structural position refers to the positional characteristics of an account in the entire transaction network topology; early warning information represents the risk warning information issued by the system, including risk level, risk description, etc.; role attribute is used to represent the functional positioning of an account in the capital chain; associated account group refers to the set of accounts that have close transaction relationships with the suspicious account; transaction pattern represents the characteristics of capital flow within the account group.
[0084] This step is executed immediately upon identifying a suspicious account. Specifically, the system first categorizes suspicious accounts into different risk levels based on their importance score and sets corresponding warning levels. Then, it analyzes the account's role in the funding chain to determine if it is a consolidation, transfer, or distribution node. For suspicious accounts with specific roles, the system further analyzes their structural position in the transaction network, identifies closely related account groups, and studies the transaction pattern characteristics within these groups. Finally, the system integrates the above information to generate warning information that includes risk level, role characteristics, and correlation analysis.
[0085] In some embodiments, the generation and transmission of early warning information can be achieved in multiple ways: Optionally, firstly, risk level classification rules are designed based on the importance score of transmission; then, related account groups are identified through community discovery algorithms; next, transaction behavior patterns within the groups are analyzed; and finally, structured early warning information is generated and pushed through multiple channels. Optionally, a risk early warning template library is first established; then, appropriate early warning templates are selected based on role analysis results; next, account characteristics and risk description information are filled in; and finally, tiered push notifications are sent through an early warning platform. It is understood that other methods can also be used to process and transmit risk early warning information, and this is not limited here.
[0086] This step specifically includes:
[0087] Suspicious accounts are classified into risk levels based on their importance scores, and three warning thresholds (high, medium, and low) are set.
[0088] In this step, the importance score refers to the account risk score calculated and transmitted over the network; the risk level refers to the risk hierarchy divided according to the score; and the warning threshold refers to the score threshold value that triggers different levels of warnings.
[0089] The system categorizes suspicious accounts based on their perceived importance score. First, three warning thresholds are established: 0.8 for high risk, 0.6 for medium risk, and 0.4 for low risk. Based on these thresholds, the system classifies accounts into different risk levels: accounts with a score greater than 0.8 are classified as high-risk; accounts with scores between 0.6 and 0.8 are classified as medium-risk; and accounts with scores between 0.4 and 0.6 are classified as low-risk. The system then configures corresponding monitoring strategies and handling measures for each risk level.
[0090] Based on the link location characteristics of the suspicious account, analyze the role of the suspicious account in the fund chain to determine whether the suspicious account is a fund aggregation node, transit node or decentralized node.
[0091] In this step, role attributes refer to the functional positioning of an account in the flow of funds; fund aggregation nodes refer to accounts that receive funds from multiple sources; transit nodes refer to accounts that receive and transfer funds of similar size; and distribution nodes refer to nodes that distribute funds to multiple accounts.
[0092] The system identifies roles based on the link location characteristics of accounts. Decision rules are used for determination: when the fund dispersion index is less than 0.3 and the in-degree is greater than the out-degree, it is determined to be a fund aggregation node; when the fund dispersion index is greater than 0.7 and the out-degree is greater than the in-degree, it is determined to be a fund dispersion node; when the in-degree to out-degree ratio is between 0.8 and 1.2 and the fund inflow / outflow ratio is between 0.9 and 1.1, it is determined to be a fund transfer node. The system records the role determination result for each account for subsequent risk analysis.
[0093] If so, based on the structural and locational characteristics of the account's transaction network, identify the associated account groups of the suspicious account and determine the transaction patterns within those associated account groups.
[0094] In this step, the associated account group refers to the set of accounts that have close transaction relationships with the target account; the transaction pattern refers to the characteristics of fund transfers between accounts within the group; and the structural location characteristics refer to the location characteristics of the account in the transaction network topology.
[0095] The system employs a community detection algorithm to identify related account groups. First, it calculates the strength of the association between accounts, considering three dimensions: transaction frequency, amount proportion, and time correlation. Then, it uses the Louvain algorithm for community partitioning, using association strength as edge weights to divide closely connected account groups. For each group, the system analyzes its internal trading patterns: calculating indicators such as transaction density, capital circulation rate, and transaction timing characteristics, identifying typical trading patterns such as chain-like transmission, circular circulation, and star-shaped dispersion.
[0096] When an account is not a fund aggregation node, transit node, or decentralized node, the system executes the following processing procedure:
[0097] First, the system marks the account as a general transaction node, indicating that it has no special functional role in the funding chain. For general transaction nodes, the system still records their basic transaction characteristics, including total transaction amount, transaction frequency, number of counterparties, etc., but does not identify related account groups or analyze transaction patterns. These types of nodes typically exhibit the following characteristics: low in-degree and out-degree (e.g., both less than 3), mismatch between fund inflows and outflows (ratio less than 0.8 or greater than 1.2), and a moderate level of fund dispersion index (between 0.3 and 0.7).
[0098] The system employs a simplified monitoring strategy for these nodes: it continuously records their transaction behavior without triggering group analysis processes, and only reassesses their role attributes when their transaction characteristics change significantly (such as a sudden increase in transaction frequency or amount within a short period). This approach avoids unnecessary in-depth analysis of ordinary transaction nodes, improving the system's operational efficiency.
[0099] During the early warning information generation phase, the system only outputs basic risk information to these nodes, including account information, risk level, and basic transaction characteristics, excluding group analysis and transaction pattern-related content. This differentiated information generation strategy ensures the accuracy and usability of the early warning information.
[0100] Generate alert information that includes basic information about suspicious accounts, risk level, location characteristics, role descriptions, and information about associated account groups.
[0101] In this step, the warning information refers to the risk alert information generated by the system, which includes risk feature descriptions from multiple dimensions.
[0102] The system generates early warning information according to a standard format. The early warning information includes the following fields: basic account information (account number, account name, account opening time, etc.); risk level (high, medium, low risk and corresponding score); location characteristics (specific values for fund dispersion and path coordination); role description (node type and main risk characteristics); and related account information (group size, list of important nodes, and description of typical transaction patterns). The system organizes this information in a structured format to form a complete early warning report, which is then pushed to relevant personnel through the early warning platform.
[0103] The following provides a more detailed description of the process of the method provided in this implementation. Please refer to [link / reference]. Figure 2 This is another flowchart illustrating the AI-based risk monitoring and early warning method for banking systems in this application.
[0104] S201. Set differentiated monitoring rules based on the risk level of the suspicious account. These monitoring rules include the maximum daily transaction limit, the maximum single transaction limit, and the maximum number of cumulative transactions for high-risk accounts.
[0105] Among them, the differentiated monitoring rules refer to the targeted transaction restrictions set according to different risk levels; the daily maximum transaction limit refers to the maximum total transaction amount allowed for a single account within a natural day; the maximum single transaction limit refers to the maximum amount allowed for a single transaction; and the maximum cumulative number of transactions refers to the maximum number of transactions allowed for a single account within a specific time period.
[0106] Based on the risk level of suspicious accounts calculated in the early stages, the system sets corresponding monitoring rules for different levels. For high-risk accounts, the strictest restrictions are set, such as a daily transaction volume not exceeding 100,000 yuan, a single transaction not exceeding 20,000 yuan, and a daily transaction frequency not exceeding 5 times. For medium-risk accounts, the restrictions are appropriately relaxed, such as a daily transaction volume not exceeding 500,000 yuan, a single transaction not exceeding 100,000 yuan, and a daily transaction frequency not exceeding 20 times. For low-risk accounts, relatively lenient restrictions are adopted, such as a daily transaction volume not exceeding 1 million yuan, a single transaction not exceeding 200,000 yuan, and a daily transaction frequency not exceeding 50 times. At the same time, the system sets different limits for different business types, such as different restriction standards for corporate accounts and personal accounts, to ensure the rationality and effectiveness of the monitoring rules.
[0107] S202. When the current transaction behavior of the suspicious account triggers the monitoring rule, freeze the current transaction behavior and push an abnormality alert to the target client terminal.
[0108] Among them, "current transaction activity" refers to the transaction operation that the account is currently performing; "freeze" means to suspend the execution of the transaction; "target customer terminal" refers to the operating terminal used by bank staff; and "abnormal alert" refers to the risk warning information generated by the system.
[0109] When an account initiates a transaction, the system checks in real time whether the transaction complies with monitoring rules. If the system detects that a transaction triggers a monitoring rule, it immediately takes freezing measures. For example, if a high-risk account has already had 80,000 yuan in transactions that day, and then initiates another 30,000 yuan transfer, the system will automatically block the transaction because it exceeds the daily transaction limit of 100,000 yuan. Simultaneously, the system pushes an abnormal transaction alert to the bank's management terminal, including basic account information, the current transaction amount, the cumulative transaction amount, and the type of rule triggered. After receiving the alert, bank staff can view detailed transaction information and risk analysis reports for manual review and handling.
[0110] S203. Statistically analyze the number of times the suspicious account triggers the monitoring rules within the preset time window.
[0111] Among them, the preset time window refers to the fixed time period for statistical analysis; the number of triggers refers to the cumulative number of times the account triggers the monitoring rules; and the statistical analysis refers to the summarization and analysis of the trigger data.
[0112] The system tracks the number of times each suspicious account triggers monitoring rules within a fixed time window (e.g., one week or one month). The statistics include the total number of triggers, the distribution of triggers for different rules, and the distribution of trigger times. For example, the statistics might show that an account triggered monitoring rules 15 times in the past week, exceeding the daily transaction limit 8 times, the single transaction limit 5 times, and the transaction frequency limit 2 times, primarily concentrated in the afternoon hours of weekdays. The system records these statistics for subsequent risk level adjustments and monitoring rule optimization. Simultaneously, the system categorizes and analyzes the triggering behavior to identify abnormal triggering patterns, such as attempts to circumvent monitoring or the presence of obvious regularities.
[0113] S204. When the number of triggers exceeds the preset threshold, the risk level of the suspicious account is increased and the monitoring rule parameters are adjusted.
[0114] Among them, the preset threshold refers to the warning value for the number of triggers, which is used to determine whether the risk level needs to be increased; risk level increase refers to adjusting the account's risk rating to a higher level; monitoring rule parameters refer to the specific values that control transaction restrictions, including amount limits and number of times limits.
[0115] The system implements a dynamic risk level adjustment mechanism, updating risk control measures by continuously monitoring abnormal account behavior. When an account triggers a preset threshold number of times within a specified time window (e.g., more than 10 triggers within a week), the system automatically upgrades the account's risk level by one level. Simultaneously, the system adjusts the account's monitoring rule parameters, such as reducing the daily transaction limit by 50%, the single transaction limit by 30%, and the maximum number of transactions by 40%. For accounts upgraded from medium to high risk, the system adds additional monitoring dimensions, such as requiring supplementary materials for large transactions and implementing a transaction delay review mechanism. This dynamic adjustment ensures the timeliness and effectiveness of monitoring measures, improving the accuracy of risk prevention and control.
[0116] S205. Record the trigger history and manual handling results of this monitoring rule.
[0117] Among them, trigger history refers to the detailed record of the monitoring rules being triggered, including information such as trigger time and trigger type; manual handling results refer to the review and handling of the triggered events by bank staff; and historical records refer to the storage and management of the above information.
[0118] The system establishes a complete monitoring record storage mechanism, meticulously recording each rule-triggered event. Records include basic information such as trigger time, triggering account information, triggering rule type, transaction amount, and cumulative trigger count, as well as processing information such as the human reviewer, review time, review conclusion, and handling measures. For each handling result, the system records detailed information such as the handling type (e.g., release, rejection, manual verification), the basis for handling, and supplementary materials. Simultaneously, the system categorizes, stores, and indexes these records, establishing a multi-dimensional query interface that supports retrieval by time, account, rule type, and other criteria, facilitating subsequent analysis and traceability.
[0119] S206. Receive the target client terminal's handling result mark for the early warning information, and calculate the accuracy and false alarm rate of the early warning rule based on the handling result mark. The handling result mark includes three types: real risk, false alarm, and pending observation.
[0120] The handling result label refers to the judgment result label made by bank personnel after reviewing the warning information. It is divided into three types: real risk (confirmation of risky behavior), false alarm (confirmation of normal transaction), and pending observation (requires continued monitoring). The accuracy rate indicates the proportion of risky accounts warned by the system that are confirmed as real risks. The false alarm rate indicates the proportion of risky accounts warned by the system that are confirmed as false alarms. The target customer terminal refers to the operating terminal equipment used by bank risk control personnel to process warning information.
[0121] The system receives the handling results and markings for each early warning message from risk control personnel through the early warning processing platform. For each early warning account, risk control personnel need to select the appropriate handling result type after verifying transaction information and analyzing risk characteristics. The system calculates the accuracy indicators of the early warning rules based on the accumulated handling result data: Accuracy rate = Number of genuine risk warnings / Total number of warnings; False alarm rate = Number of false alarm warnings / Total number of warnings. For example, in the most recent 100 warnings, if 60 are marked as genuine risks, 30 are marked as false alarms, and 10 are marked as pending observation, then the accuracy rate is 60% and the false alarm rate is 30%. The system updates these statistical indicators in real time to evaluate the effectiveness of the early warning rules.
[0122] S207. When the accuracy rate is lower than the preset accuracy rate threshold or the false alarm rate is higher than the preset false alarm rate threshold, adjust the score threshold in the warning rule.
[0123] The preset accuracy threshold refers to the minimum accuracy standard required by the system, used to determine whether the warning rules need to be optimized; the preset false alarm rate threshold refers to the maximum false alarm rate allowed by the system; the score threshold refers to the scoring standard value used to determine whether an account is a suspicious account.
[0124] The system continuously monitors the accuracy and false alarm rate of the alert rules. When the accuracy falls below a preset threshold (e.g., below 50%) or the false alarm rate exceeds a preset threshold (e.g., above 40%), the system automatically triggers an alert rule optimization mechanism. Specifically, when the accuracy is too low, the scoring threshold for suspicious accounts is increased, making the system more stringent in screening risky accounts; for example, the scoring threshold is raised from 0.7 to 0.8. When the false alarm rate is too high, the scoring threshold is lowered, making the system more lenient in judging risky accounts; for example, the scoring threshold is lowered from 0.7 to 0.6. Adjustments are made by comprehensively considering the trends in accuracy and false alarm rates, using a progressive adjustment strategy, with each adjustment controlled within 10% to ensure the stability of the system's alerts. After adjustments, the new accuracy and false alarm rate indicators are continuously tracked to verify the adjustment effect.
[0125] The following describes the banking system risk monitoring and early warning system in the embodiments of this invention from the perspective of hardware processing. Please refer to [link / reference needed]. Figure 3 This is a schematic diagram of the physical device structure of a banking system risk monitoring and early warning system in this application embodiment.
[0126] It should be noted that, Figure 3 The structure of the banking system risk monitoring and early warning system shown is merely an example and should not impose any limitations on the functionality and scope of use of the embodiments of the present invention.
[0127] like Figure 3 As shown, the banking system risk monitoring and early warning system includes a central processing unit (CPU) 301, which can perform various appropriate actions and processes based on programs stored in read-only memory (ROM) 302 or programs loaded from storage section 308 into random access memory (RAM) 303, such as performing the methods described in the above embodiments. The RAM 303 also stores various programs and data required for system operation. The CPU 301, ROM 302, and RAM 303 are interconnected via a bus 304. An input / output (I / O) interface 305 is also connected to the bus 304.
[0128] The following components are connected to I / O interface 305: input section 306 including audio input devices, push-button switches, etc.; output section 307 including a liquid crystal display (LCD) and audio output devices, indicator lights, etc.; storage section 308 including a hard disk, etc.; and communication section 309 including a network interface card such as a LAN (Local Area Network) card, modem, etc. Communication section 309 performs communication processing via a network such as the Internet. Drive 310 is also connected to I / O interface 305 as needed. Removable media 311, such as a disk, optical disk, magneto-optical disk, semiconductor memory, etc., are installed on drive 310 as needed so that computer programs read from them can be installed into storage section 308 as needed.
[0129] In particular, according to embodiments of the present invention, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments of the present invention include a computer program product comprising a computer program carried on a computer-readable medium, the computer program containing computer programs for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via communication section 309, and / or installed from removable medium 311. When the computer program is executed by central processing unit (CPU) 301, it performs the various functions defined in the present invention.
[0130] It should be noted that specific examples of computer-readable storage media may include, but are not limited to: electrical connections having one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM), flash memory, optical fiber, portable compact disc read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof. In this invention, a computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device.
[0131] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present invention. Each block in a flowchart or block diagram may represent a module, program segment, or portion of code, which contains one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those shown in the drawings.
[0132] Specifically, the banking system risk monitoring and early warning system of this embodiment includes a processor and a memory. The memory stores a computer program. When the computer program is executed by the processor, it implements the artificial intelligence-based banking system risk monitoring and early warning method provided in the above embodiment.
[0133] In another aspect, the present invention also provides a computer-readable storage medium, which may be included in the banking system risk monitoring and early warning system described in the above embodiments; or it may exist independently and not assembled into the banking system risk monitoring and early warning system. The storage medium carries one or more computer programs, which, when executed by a processor of the banking system risk monitoring and early warning system, enable the banking system risk monitoring and early warning system to implement the artificial intelligence-based banking system risk monitoring and early warning method provided in the above embodiments.
[0134] The above-described embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit it. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of this application.
[0135] As used in the above embodiments, depending on the context, the term "when..." can be interpreted as meaning "if...", "after...", "in response to determining...", or "in response to detecting...". Similarly, depending on the context, the phrase "when determining..." or "if (the stated condition or event) is interpreted as meaning "if determining...", "in response to determining...", "when (the stated condition or event) is detected", or "in response to detecting (the stated condition or event)".
[0136] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. This program can be stored in a computer-readable storage medium, and when executed, it can include the processes described in the above method embodiments. The aforementioned storage medium includes various media capable of storing program code, such as ROM or random access memory (RAM), magnetic disks, or optical disks.
Claims
1. An artificial intelligence-based bank system risk monitoring and early warning method, characterized in that, The method is applied to a bank system risk monitoring and early warning system, and comprises the following steps: Based on transaction data within a target time window, an account transaction network is constructed, and transaction features of each account node in the account transaction network are extracted, wherein each account is taken as a node, and a transaction relationship between the accounts is taken as a directed edge; Flow direction features of an account fund income and expenditure proportion relationship, time correlation degree features of an account and a transaction counterpart, and business combination mode features of the account are obtained, and an initial importance score of the account is calculated according to the flow direction features, the time correlation degree features and the business combination mode features; A transaction size threshold and a time interval threshold are set, and a node pair meeting the conditions in the account transaction network is screened; A transaction amount proportion, a time attenuation coefficient and a transaction time sequence correlation degree between the node pair are obtained, and an importance transmission value between the nodes is calculated by combining the initial importance score of the node with the transaction amount proportion, the attenuation coefficient and the time sequence correlation degree; Iterative calculation is performed on the account transaction network to obtain a transmission importance score of each account node; A preceding transaction path within a preset layer is obtained by performing reverse tracing on the account transaction network with a target account as a starting point; A fund dispersion degree index is calculated based on a fund flow size of the preceding transaction path, and the fund dispersion degree index represents a uniformity degree of fund distribution on different paths; A path coordination degree index is obtained by analyzing time sequence combination features of the preceding transaction path, and the path coordination degree index represents a time synchronization degree of fund flow on multiple paths; A link position feature of the account is constructed according to the fund dispersion degree index and the path coordination degree index, and the link position feature is a feature vector comprehensively reflecting position characteristics of the account in a fund flow chain; A final suspiciousness score of the account is calculated according to the transmission importance score and the link position feature, and an account with a final suspiciousness score greater than a preset score threshold is determined as a suspicious account; According to the transmission importance score of the suspicious account, the link position feature and the structural position in the account transaction network, an early warning information is sent.
2. The method of claim 1, wherein, The step of sending the early warning information according to the transmission importance score of the suspicious account, the link position feature and the structural position in the account transaction network specifically comprises the following steps: The suspicious account is divided into risk levels according to the transmission importance score, and three-level early warning thresholds of high, medium and low are set; Whether the suspicious account is a fund collection node, a transfer node or a dispersion node is determined by analyzing a role attribute of the suspicious account in a fund chain based on the link position feature of the suspicious account; If yes, an associated account group of the suspicious account is identified and a transaction mode inside the associated account group is determined according to a structural position feature of the account transaction network; Early warning information containing basic information of the suspicious account, a risk level, a position feature, a role description and information of the associated account group is generated.
3. The method of claim 2, wherein, After the step of generating the early warning information containing the basic information of the suspicious account, the risk level, the position feature, the role description and the information of the associated account group, the method further comprises the following steps: According to the risk level of the suspicious account, a differentiated monitoring rule is set, including a daily maximum transaction limit, a single maximum transaction limit, and a transaction cumulative number limit for a high-risk account; When the current transaction behavior of the suspicious account triggers the monitoring rule, the current transaction behavior is frozen, and an abnormality reminder is pushed to the target client terminal.
4. The method of claim 1, wherein, After the step of issuing the early warning information according to the transfer importance score of the suspicious account, the link position feature, and the structural position in the account transaction network, the method further comprises: Statistically analyzing the number of times that the suspicious account triggers the monitoring rule within a preset time window; When the number of times exceeds a preset threshold, the risk level of the suspicious account is raised, and the monitoring rule parameters are adjusted; The triggering history and the manual disposal result of the monitoring rule are recorded.
5. The method of claim 4, wherein, After the step of recording the triggering history and the manual disposal result of the monitoring rule, the method further comprises: Receiving a disposal result mark of the target client terminal on the early warning information, calculating the accuracy rate and the false positive rate of the early warning rule according to the disposal result mark, the disposal result mark including three types of real risk, false positive, and observation; When the accuracy rate is lower than a preset accuracy rate threshold or the false positive rate is higher than a preset false positive rate threshold, the score threshold in the early warning rule is adjusted.
6. A bank system risk monitoring and early warning system, characterized in that, The bank system risk monitoring and early warning system comprises one or more processors and memories; the memories are coupled with the one or more processors, the memories are used to store computer program codes, the computer program codes comprise computer instructions, and the one or more processors invoke the computer instructions to enable the bank system risk monitoring and early warning system to perform the method according to any one of claims 1-5.
7. A computer-readable storage medium comprising instructions, wherein: When the instructions run on the bank system risk monitoring and early warning system, the bank system risk monitoring and early warning system performs the method according to any one of claims 1-5.
8. A computer program product, characterised in that, When the computer program product runs on the bank system risk monitoring and early warning system, the bank system risk monitoring and early warning system performs the method according to any one of claims 1-5.
Citation Information
Patent Citations
Money laundering risk analysis method based on graph calculation
CN117829994A
Method and device for monitoring abnormal fund operation object
CN118467787A