Model training and anomaly detection method and device, electronic equipment and storage medium

By building a weighted graph network and artificial intelligence model and combining transaction data for abnormal detection, the problem of inaccurate merchant abnormal detection in the existing technology is solved and the accuracy of detection is improved.

CN120337044APending Publication Date: 2025-07-18TENCENT TECHNOLOGY (SHENZHEN) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410079934.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-01-18
Publication Date
2025-07-18

AI Technical Summary

Technical Problem

When detecting whether merchants have abnormal transaction behaviors, the existing technology causes normal merchants to misjudgment based on a single human-set rule, and the detection is not accurate enough, making it difficult to effectively identify abnormal merchants.

Method used

By obtaining transaction data between the target object and the first object, a weighted graph network is built, and anomaly detection is performed using the artificial intelligence model based on the graph network and node feature vectors, and the model is trained to learn the deep transaction behavior characteristics of the target object.

Benefits of technology

It improves the accuracy of abnormal detection, can better identify abnormal merchants and meet actual detection needs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120337044A_ABST
    Figure CN120337044A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a model training and anomaly detection method and device, electronic equipment and a storage medium, and relates to the fields of artificial intelligence, cloud technology and the like. The method comprises the following steps: acquiring transaction data of a plurality of to-be-detected target objects; based on the transaction information between the associated object pairs, the association degree of the associated object pairs is determined, and the associated object pairs comprise a target object and a first object which have a transaction; taking each target object and each first object as nodes, and constructing a connection edge with a weight between two nodes corresponding to each associated object pair to obtain a target graph network; the weight of one connecting edge is in positive correlation with the correlation degree of the corresponding correlation object pair; and based on the target graph network and the determined target feature vector of each node in the target graph network, through a trained anomaly detection model, determining an anomaly detection result corresponding to each target node. Based on the method, the anomaly detection accuracy of the target object can be effectively improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application belongs to the field of computer technology and may involve fields such as artificial intelligence and cloud technology. Specifically, this application relates to a model training and anomaly detection method, device, electronic device, and storage medium. Background Art

[0002] With the popularization of Internet technology and the rise of e-commerce, more and more users purchase goods through online platforms.

[0003] In e-commerce platforms, a large number of abnormal transaction orders have emerged along with the growth of transaction order volumes. In order to create a good online shopping environment and avoid the adverse consequences caused by abnormal transactions, it is necessary to detect merchants with abnormal transaction behaviors in the platform to impose restrictions on relevant merchants.

[0004] Currently, when detecting whether a merchant has abnormal transaction behaviors, it is usually based on the transaction data between consumers and merchants and the detection rules set manually based on expert experience for judgment. However, a single rule set manually often leads to misjudgment of a large number of normal trading merchants, and the detection of abnormal merchants is not accurate enough. Summary of the Invention

[0005] The purpose of the embodiments of this application is to provide a model training and anomaly detection method, device, electronic device, and storage medium that can effectively improve the anomaly detection accuracy of target objects. To achieve this purpose, the technical solutions provided by the embodiments of this application are as follows:

[0006] On the one hand, the embodiments of this application provide an anomaly detection method, which includes:

[0007] Obtain the transaction data of multiple target objects to be detected; the transaction data of each target object includes the transaction information between the target object and at least one first object;

[0008] For each associated object pair, determine the degree of association of the associated object pair based on the transaction information between the associated object pair; the associated object pair includes a target object and a first object that has a transaction with the target object;

[0009] By taking each object in each of the target objects and the first objects as a node respectively, and constructing a weighted edge between each pair of associated nodes, a target graph network is obtained, where the associated node pair is the two nodes corresponding to the associated object pair, and the weight of an edge is positively correlated with the degree of association of the associated object pair corresponding to the edge;

[0010] Determine the target feature vector of each node in the target graph network;

[0011] Based on the target graph network and the target feature vectors of each node in the target graph network, determine the anomaly detection results corresponding to each target node through a trained anomaly detection model, where the target node is the node corresponding to the target object;

[0012] Among them, the anomaly detection model is obtained by training an artificial intelligence model based on multiple first samples. Each first sample includes a first sample graph network corresponding to multiple labeled sample objects, and the target feature vectors of each node in the first sample graph network. The label of a sample object indicates whether the sample object is abnormal.

[0013] On the other hand, an embodiment of the present application also provides an anomaly detection device, which includes:

[0014] An acquisition module, configured to acquire transaction data of multiple target objects to be detected; the transaction data of each target object includes transaction information between the target object and at least one first object;

[0015] An association degree determination module, configured to determine the association degree of each pair of associated objects based on the transaction information between the pair of associated objects; the pair of associated objects includes a target object and a first object having a transaction with the target object;

[0016] A graph network construction module, configured to obtain a target graph network by respectively taking each of the target objects and each of the first objects as a node and constructing a weighted edge between each pair of associated nodes, where the pair of associated nodes is the two nodes corresponding to the pair of associated objects, and the weight of an edge is positively correlated with the association degree of the pair of associated objects corresponding to the edge;

[0017] A feature determination module, configured to determine the target feature vector of each node in the target graph network;

[0018] An anomaly detection module, configured to determine the anomaly detection results corresponding to each target node based on the target graph network and the target feature vectors of each node in the target graph network through a trained anomaly detection model, where the target node is the node corresponding to the target object;

[0019] Among them, the anomaly detection model is obtained by training an artificial intelligence model based on multiple first samples. Each first sample includes a first sample graph network corresponding to multiple labeled sample objects, and the target feature vectors of each node in the first sample graph network. The label of a sample object indicates whether the sample object is abnormal.

[0020] Optionally, the feature determination module may be used to:

[0021] Determine the initial feature vector of the node according to at least one of the transaction characteristics of the node or the network structure characteristics of the node in the target graph network;

[0022] Update the initial feature vector of the node based on the correlation between the initial feature vectors of each associated node pair including the node, and obtain the target feature vector of the node.

[0023] Optionally, the feature determination module can be used to:

[0024] Input the initial feature vectors of each node in the target graph network into a trained embedding model to obtain the target feature vectors of each node;

[0025] Wherein, the embedding model is trained in the following manner:

[0026] Obtain a plurality of second samples, each of the second samples including the initial feature vectors of each node in a second sample graph network;

[0027] For each of the second sample graph networks, input the initial feature vectors of each node in the second sample graph network into a neural network model to be trained, and obtain the predicted feature vectors of each node in the second sample graph network;

[0028] For each of the second sample graph networks, determine the first training loss corresponding to the second sample graph network based on the correlation between the predicted feature vectors of each associated node pair in the second sample graph network;

[0029] Determine the first comprehensive loss based on the first training losses corresponding to each of the second sample graph networks;

[0030] If the first training end condition is satisfied, use the neural network model as the embedding model;

[0031] If the first training end condition is not satisfied, adjust the model parameters in the neural network model based on the first training loss, and continue to train the adjusted neural network model based on each of the second samples.

[0032] Optionally, the transaction characteristics of any node are determined in the following manner:

[0033] Determine the transaction data related to the node from the transaction data of multiple target objects;

[0034] Based on the transaction data related to the node, determine the transaction characteristics of the node; the transaction characteristics include at least one of the transaction resource amount or the number of transactions corresponding to the node.

[0035] Optionally, for any node in the target graph network, the network structure features of the node in the target graph network include at least one of the degree of the node, the clustering coefficient of the node, or the centrality of the node.

[0036] Optionally, the target feature vector of any node includes eigenvalue of multiple feature dimensions;

[0037] The artificial intelligence model is a decision tree model, and the decision tree model is constructed in the following manner:

[0038] According to the target feature vectors of the corresponding nodes of each sample object in each first sample graph network, and the labels of each sample object, determine the influence factor corresponding to each feature dimension, and the influence factor corresponding to each eigenvalue under each feature dimension respectively; the influence factor is information gain or Gini index;

[0039] Take the feature dimension with the largest determined influence factor among each feature dimension as the target feature dimension, and determine the eigenvalue with the largest influence factor under the target feature dimension as the target eigenvalue;

[0040] Using the target feature dimension as the splitting feature and the target eigenvalue as the splitting point, divide the nodes corresponding to each sample object in each first sample graph network;

[0041] If the division result meets the preset tree building stop condition, construct a decision tree model according to the determined splitting features and corresponding splitting points;

[0042] If the division result does not meet the preset tree building stop condition, for each branch obtained from the most recent division, according to the target feature vectors of the corresponding nodes of each sample object in each first sample graph network under this branch, and the labels of each sample object, re-determine the splitting feature and splitting point corresponding to this branch, and divide the nodes corresponding to each sample object in each first sample graph network under this branch through the splitting feature and splitting point corresponding to this branch.

[0043] Optionally, the anomaly detection model is trained in the following manner:

[0044] Obtain multiple first samples;

[0045] Based on each first sample, continuously perform training operations on the artificial intelligence model to be trained until the second training end condition is met, and obtain a trained anomaly detection model. The training operations include:

[0046] Input the first sample graph network corresponding to each first sample, and the target feature vectors of each node in each first sample graph network into the artificial intelligence model to obtain the predicted anomaly detection results corresponding to each sample object in each first sample;

[0047] Determine a second training loss according to the labels of the sample objects in each first sample and the predicted anomaly detection results corresponding to the sample objects in each first sample.

[0048] If the second training end condition is not satisfied, adjust the model parameters in the artificial intelligence model based on the second training loss.

[0049] Optionally, the device further includes an update module, and the update module can be used for:

[0050] Send the anomaly detection results of the target objects to the target terminal;

[0051] Receive the labels corresponding to the target objects sent by the target terminal; the label of one target object represents whether the target object is abnormal;

[0052] Construct a third sample based on the labels corresponding to the target objects and the target graph network, so as to update and train the anomaly detection model based on the third sample.

[0053] Optionally, the acquisition module can be used for:

[0054] Obtain the transaction data of each target object within the first time period;

[0055] Divide the transaction data within the first time period into transaction data of at least two sub-time periods according to a preset time length, and use the transaction data of each target object in each sub-time period as the transaction data of the multiple target objects respectively;

[0056] The anomaly detection module is further used for:

[0057] For each target object, determine the final detection result of the target detection object based on the anomaly detection results corresponding to the target object in each sub-time period.

[0058] On the other hand, an embodiment of the present application further provides a model training method, and the method includes:

[0059] Obtain a plurality of fourth samples; each fourth sample includes a fourth sample graph network corresponding to a plurality of sample objects with labels and the target feature vectors of the nodes in the fourth sample graph network, and the label of one sample object represents whether the sample object is abnormal;

[0060] Based on each fourth sample, continuously perform training operations on the artificial intelligence model to be trained until the third training end condition is satisfied, and obtain a trained anomaly detection model. The training operations include:

[0061] Input the fourth sample graph network corresponding to each fourth sample and the target feature vectors of each node in each fourth sample into the artificial intelligence model to obtain the predicted anomaly detection results corresponding to each sample object in each fourth sample;

[0062] Determine the third training loss according to the labels of each sample object in each fourth sample and the predicted anomaly detection results corresponding to each sample object in each fourth sample;

[0063] If the third training end condition is not satisfied, adjust the model parameters in the artificial intelligence model based on the third training loss;

[0064] Among them, the fourth sample graph network corresponding to each fourth sample is constructed in the following way:

[0065] Obtain the transaction data of each sample object in this fourth sample; the transaction data of each sample object includes the transaction information between this sample object and at least one first object;

[0066] For each pair of associated objects, determine the degree of association of this pair of associated objects based on the transaction information between this pair of associated objects; the pair of associated objects includes a sample object and a first object having a transaction with this sample object;

[0067] By taking each object in each of the sample objects and the first objects as a node respectively, and constructing a weighted edge between each pair of associated nodes, obtain the fourth sample graph network corresponding to this fourth sample; where, the pair of associated nodes is the two nodes corresponding to the pair of associated objects, and the weight of an edge is positively correlated with the degree of association of the pair of associated objects corresponding to this edge.

[0068] On the other hand, an embodiment of the present application also provides a model training device, and this device includes:

[0069] A sample acquisition module, configured to acquire a plurality of fourth samples; each fourth sample includes a fourth sample graph network corresponding to a plurality of labeled sample objects, and the target feature vectors of each node in the fourth sample graph network, and the label of a sample object represents whether this sample object is abnormal;

[0070] A training module, configured to continuously perform training operations on the artificial intelligence model to be trained based on each fourth sample until the third training end condition is satisfied, and obtain a trained anomaly detection model, and the training operations include:

[0071] Input the fourth sample graph network corresponding to each fourth sample and the target feature vectors of each node in each fourth sample into the artificial intelligence model to obtain the predicted anomaly detection results corresponding to each sample object in each fourth sample;

[0072] Determine a third training loss based on the labels of the sample objects in each fourth sample and the predicted anomaly detection results corresponding to the sample objects in each fourth sample;

[0073] If the third training end condition is not satisfied, adjust the model parameters in the artificial intelligence model based on the third training loss;

[0074] Wherein, the fourth sample graph network corresponding to each fourth sample is constructed in the following manner:

[0075] Obtain the transaction data of the sample objects in the fourth sample; the transaction data of each sample object includes the transaction information between the sample object and at least one first object;

[0076] For each pair of associated objects, determine the degree of association of the pair of associated objects based on the transaction information between the pair of associated objects; the pair of associated objects includes a sample object and a first object having a transaction with the sample object;

[0077] By taking each object in each of the sample objects and the first objects as a node respectively, and constructing weighted edges between the pairs of associated nodes, obtain the fourth sample graph network corresponding to the fourth sample; wherein, the pair of associated nodes is the two nodes corresponding to the pair of associated objects, and the weight of an edge is positively correlated with the degree of association of the pair of associated objects corresponding to the edge.

[0078] An embodiment of the present application also provides an electronic device, which includes a memory and a processor. A computer program is stored in the memory, and the processor executes the computer program to implement the method provided in any optional embodiment of the present application.

[0079] On the other hand, an embodiment of the present application also provides a computer-readable storage medium, in which a computer program is stored, and when the computer program is executed by a processor, it implements the method provided in any optional embodiment of the present application.

[0080] On the other hand, an embodiment of the present application also provides a computer program product, which includes a computer program, and when the computer program is executed by a processor, it implements the method provided in any optional embodiment of the present application.

[0081] The beneficial effects brought by the technical solution provided by the embodiment of the present application are as follows:

[0082] The anomaly detection method provided by the embodiments of the present application determines the association degree of associated object pairs with transactions based on the transaction information between the business objects (target object and the first object) of the transaction, constructs weighted edges between the associated node pairs with each business object as a node to obtain a graph network, and performs anomaly detection on the target object through an anomaly detection model trained by artificial intelligence technology based on the graph network and the target feature vectors of the nodes in the graph network. By combining the graph network and artificial intelligence technology, the potential relationship between the transaction behaviors of the target object and the first object can be captured based on the edges between the nodes in the constructed graph network and the target feature vectors of the nodes in the graph network, so that the trained anomaly detection model can learn the deeper anomaly transaction behavior characteristics of the target object, improve the accuracy of anomaly detection of the target object, and better meet the actual detection requirements. BRIEF DESCRIPTION OF THE DRAWINGS

[0083] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the accompanying drawings required for the description in the embodiments of the present application.

[0084] Figure 1 Schematic structural diagram of an anomaly detection system applicable to the embodiments of the present application;

[0085] Figure 2 Schematic flowchart of an anomaly detection method provided by the embodiments of the present application;

[0086] Figure 3 Schematic network structure diagram of a target graph network provided by the embodiments of the present application;

[0087] Figure 4 Schematic structural diagram of a decision tree provided by the embodiments of the present application;

[0088] Figure 5 Schematic flowchart of performing anomaly detection on a target object provided by the embodiments of the present application;

[0089] Figure 6 Schematic flowchart of a model training method provided by the embodiments of the present application;

[0090] Figure 7 Schematic structural diagram of an anomaly detection device provided by the embodiments of the present application;

[0091] Figure 8 Schematic structural diagram of a model training device provided by the embodiments of the present application;

[0092] Figure 9 Schematic structural diagram of an electronic device provided by the embodiments of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0093] The embodiments of the present application will be described below with reference to the accompanying drawings in the present application. It should be understood that the embodiments described below with reference to the accompanying drawings are exemplary descriptions for explaining the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions of the embodiments of the present application.

[0094] Those skilled in the art of the present technology can understand that, unless specifically stated otherwise, the singular forms "a", "an", "the" and "said" used herein may also include the plural forms. It should be further understood that the terms "including" and "comprising" used in the embodiments of the present application mean that the corresponding features can be implemented as the presented features, information, data, steps, operations, elements, and / or components, but do not exclude the implementation of other features, information, data, steps, operations, elements, components, and / or their combinations supported by the art of the present technology. It should be understood that when we say that an element is "connected" or "coupled" to another element, the one element can be directly connected or coupled to the other element, or it can mean that the one element and the other element establish a connection relationship through an intermediate element. In addition, the "connection" or "coupling" used here can include wireless connection or wireless coupling. The term "and / or" used here indicates at least one of the items defined by the term, for example, "A and / or B" can be implemented as "A", or implemented as "B", or implemented as "A and B". When describing multiple (two or more) items, if the relationship between the multiple items is not clearly defined, the multiple items can refer to one, more, or all of the multiple items. For example, for the description of "parameter A includes A1, A2, A3", it can be implemented that parameter A includes A1 or A2 or A3, and it can also be implemented that parameter A includes at least two of the three items of parameter A1, A2, and A3.

[0095] In the current related technologies, generally, experts analyze the transaction data of the trading platform or combine the manifestations of common abnormal transactions to summarize the detection rules for the corresponding abnormal transaction behaviors, so as to perform abnormal detection on the target object and the corresponding transaction behaviors. However, the abnormal detection effect of this related solution is highly dependent on expert experience, and the effect is unstable. Moreover, the analysis by experts based on historical transaction data often has lag, and the abnormal detection effect is poor.

[0096] Based on the above existing problems, the embodiments of the present application provide a model training and anomaly detection method, apparatus, electronic device, and storage medium. In this method, based on the transaction information between the business objects (target object and the first object) of the transaction, the association degree of the associated object pairs with transactions is determined, and taking each business object as a node, a weighted edge is constructed between each associated node pair to obtain a graph network. Based on the graph network and the target feature vectors of each node in the graph network, an anomaly detection model trained by artificial intelligence technology is used to perform anomaly detection on the target object. In the embodiments of the present application, by integrating the graph network and the artificial intelligence algorithm, based on the constructed graph network and the target feature vectors of each node in the graph network, the potential relationship between the transaction behaviors of the target object and the first object can be captured, so that the trained anomaly detection model can learn the deeper transaction behavior characteristics of the target object, improve the anomaly detection accuracy of the target object, and better meet the actual detection requirements.

[0097] Among them, the method provided by the embodiments of the present application may involve artificial intelligence (AI) technology. For example, the anomaly detection result of the target object can be predicted by the trained anomaly detection model, where the trained anomaly detection model can be trained in a machine learning (ML) manner based on multiple first samples.

[0098] Artificial intelligence is to use a digital computer or a machine controlled by a digital computer to simulate, extend, and expand human intelligence, a theory, method, technology, and application system that can perceive the environment, acquire knowledge, and use knowledge to obtain the best results. In other words, artificial intelligence is a comprehensive technology in computer science. It attempts to understand the essence of intelligence and produce a new intelligent machine that can react in a way similar to human intelligence. Artificial intelligence is also to study the design principles and implementation methods of various intelligent machines to enable the machine to have the functions of perception, reasoning, and decision-making.

[0099] Artificial intelligence technology is an interdisciplinary subject, involving a wide range of fields, including both hardware-level technologies and software-level technologies. The basic technologies of artificial intelligence generally include technologies such as sensors, dedicated artificial intelligence chips, cloud computing, distributed storage, big data processing technology, operation / interaction systems, and mechatronics. The software technologies of artificial intelligence mainly include several major directions such as computer vision technology, speech processing technology, natural language processing technology, and machine learning / deep learning, autonomous driving, and intelligent transportation.

[0100] Among them, Machine Learning (ML) is an interdisciplinary subject that involves multiple disciplines such as probability theory, statistics, approximation theory, convex analysis, and algorithm complexity theory. It specifically studies how computers simulate or implement human learning behaviors to acquire new knowledge or skills and reorganize the existing knowledge structure to continuously improve their own performance. Machine learning is the core of artificial intelligence and the fundamental way to make computers intelligent, and its applications cover all fields of artificial intelligence. Machine learning and deep learning usually include technologies such as artificial neural networks, belief networks, reinforcement learning, transfer learning, inductive learning, and rote learning.

[0101] With the research and progress of artificial intelligence technology, artificial intelligence technology has been studied and applied in multiple fields. For example, common ones include smart homes, smart wearable devices, virtual assistants, smart speakers, smart marketing, driverless, autonomous driving, drones, robots, smart healthcare, smart customer service, vehicle networking, autonomous driving, and intelligent transportation. It is believed that with the development of technology, artificial intelligence technology will be applied in more fields and play an increasingly important role.

[0102] Optionally, the solution provided in the embodiments of the present application may involve cloud technology. For example, the solution in the embodiments of the present application may be executed by a server. Among them, the server may be a cloud server. The data processing involved in the implementation process of this solution may be based on cloud technology, and the data storage involved in the implementation process may use cloud storage. For example, the construction of a decision tree may be implemented using cloud technology, and the training data set used during the training of the anomaly detection model may be a data set stored in a cloud server.

[0103] Among them, cloud technology is the general term for network technology, information technology, integration technology, management platform technology, application technology, etc. based on the cloud computing business model, which can form a resource pool, be used as needed, and be flexible and convenient. Cloud computing technology will become an important support. Cloud storage is a new concept extended and developed from the concept of cloud computing. A distributed cloud storage system (hereinafter referred to as a storage system) refers to a storage system that combines a large number of different types of storage devices (storage devices are also called storage nodes) in the network through cluster applications, grid technology, and distributed file systems, and collaborates through application software or application interfaces to jointly provide data storage and business access functions.

[0104] It should be noted that in the alternative embodiments of the present application, for data related to object information (such as transaction data), when the embodiments in the present application are applied to specific products or technologies, object permission or consent needs to be obtained, and the collection, use, and processing of relevant data need to comply with relevant laws, regulations, and standards of relevant countries and regions. That is to say, if the embodiments in the present application involve data related to an object, it needs to be obtained under the authorization and consent of the object, the authorization and consent of relevant departments, and compliance with relevant laws, regulations, and standards of the country and region. In the embodiments, if personal information is involved, the consent of the individual needs to be obtained for all personal information. If sensitive information is involved, the separate consent of the information subject needs to be obtained, and the embodiments also need to be implemented under the authorization and consent of the object.

[0105] The anomaly detection method provided by the embodiments of the present application can theoretically be applied to scenarios for anomaly detection of target objects in any trading platform. The trading platform includes, but is not limited to, any service platform capable of conducting transactions such as e-commerce service platforms, game service platforms, etc. Transactions in the platform can be value exchanges between buyers and sellers with resources or services as the medium. The target object in the trading platform is the business object conducting the transaction, and the first object is another business object conducting a transaction with the target object in the trading platform. In one embodiment, the anomaly detection method can be applied to the application environment as Figure 1 shown. Among them, the anomaly detection system can include a server 10 and multiple terminals 11 to 1n (exemplarily represented by mobile phones in the figure). The server 10 and the terminals 11 to 1n can communicate in a wired or wireless manner. Each terminal can correspond to a business object (the first object or the target object). When the business object conducts a transaction through the terminal, the terminals 11 to 1n upload the collected transaction data to the server 10. The server 10 determines the transaction data of multiple target objects to be detected from the received transaction data, and performs anomaly detection on the target objects by executing the anomaly detection method provided by the embodiments of the present application.

[0106] Among them, the above-mentioned server 10 can be an independent physical server, a server cluster or a distributed system composed of multiple physical servers, or a cloud server that provides cloud computing services (which can be referred to as the cloud). The embodiments of the present application can be applied to the anomaly detection scenario in the trading platform. The server 10 can be the background server corresponding to the trading platform, such as the server corresponding to the e-commerce service platform or the server corresponding to the game service platform, or a server dedicated to detecting anomalies of the target object. The terminals 11 to 1n (which can also be referred to as user terminals or user devices) can be smart phones, tablet computers, laptop computers, desktop computers, intelligent voice interaction devices (such as smart speakers), wearable electronic devices (such as smart watches), vehicle-mounted terminals, intelligent home appliances (such as smart TVs), AR / VR devices, etc., but are not limited thereto. The terminals 11 to 1n and the server 10 can be directly or indirectly connected through wired or wireless communication methods, and the present application does not limit this.

[0107] Next, through the description of several embodiments, the technical solutions of the embodiments of the present application and the technical effects produced by the technical solutions of the present application will be described. It should be noted that the following embodiments can refer to, draw on or combine with each other. For the same terms, similar features and similar implementation steps in different embodiments, they will not be described repeatedly.

[0108] Figure 2 The flowchart of an anomaly detection method provided by an embodiment of the present application is shown. This method can be executed by any computer device, such as a terminal or a server, or can be implemented by the cooperation of multiple computer devices. For example, it can be implemented by the cooperation of a terminal and a server. The terminal constructs a target graph network based on the obtained transaction data and sends the target graph network to the server, and the server performs anomaly detection on the nodes corresponding to the target object based on the target graph network.

[0109] As Figure 2 shown, the anomaly detection method provided by the embodiment of the present application can include the following steps S110 to step S150.

[0110] Step S110: Obtain the transaction data of multiple target objects to be detected.

[0111] The technical solution of this application can be applied to the anomaly detection of target objects in a trading platform. The target objects in the trading platform are business objects involved in transactions. The transaction data of each target object includes the transaction information between the target object and at least one first object. The first object is another business object with which the target object conducts transactions in the trading platform. The first object can conduct transactions with multiple target objects, and the target objects do not conduct transactions with each other. In an alternative embodiment, the target object can be a seller (merchant, store, etc.), and the first object can be a buyer (consumer, user). In other alternative embodiments, the target object can also be a buyer, and the first object is a seller.

[0112] Among them, the transaction information between the target object and the first object may include the number of transactions between the target object and the first object, the transaction time of each transaction order, the amount of transaction resources, the traded goods, the shipping address, the receiving address, and so on.

[0113] Optionally, since there may be invalid or incorrect data in the original transaction data of the target object in the trading platform, such as missing values, outliers, etc., in order to ensure the quality of the transaction data and avoid affecting the subsequent anomaly detection results, it is necessary to first clean the original transaction data, remove the invalid or incorrect data in the original transaction data, and then perform subsequent processing on the transaction data obtained after data cleaning.

[0114] Step S120: For each pair of associated objects, determine the degree of association of the pair of associated objects based on the transaction information between the pair of associated objects.

[0115] Among them, a pair of associated objects includes a target object and a first object that has a transaction with the target object. The transaction information between the pair of associated objects is the transaction information between the target object and the first object in the pair of associated objects.

[0116] Optionally, the degree of association of each pair of associated objects can be determined based on at least one of the number of transactions and the amount of transaction resources in the transaction information between the pairs of associated objects. Among them, the more transactions there are between the pair of associated objects and the greater the amount of transaction resources, the higher the degree of association of the pair of associated objects.

[0117] As an alternative embodiment, for each pair of associated objects, determine the total amount of transaction resources of the pair of associated objects according to the amount of transaction resources of each transaction order between the target object and the first object in the pair of associated objects. Determine the transaction frequency of the pair of associated objects according to the number of transactions between the target object and the first object in the pair of associated objects and the duration across which the transactions occur. Determine the degree of association of each pair of associated objects according to the total amount of transaction resources of the pair of associated objects and the transaction frequency between the target object and the first object in the pair of associated objects.

[0118] Exemplarily, the association degree of each associated object pair can be calculated by the following formula:

[0119]

[0120]

[0121]

[0122] Wherein, U represents the target object, V represents the first object, w(U, V) represents the association degree between the target object and the first object, n(U, V) represents the number of transactions between the target object and the first object, T represents the transaction duration across which the transaction data is involved, f(U, V) represents the transaction frequency between the target object and the first object, max(f) represents the highest transaction frequency between the target object and the first object in the trading platform, m(U, V) represents the total amount of transaction resources between the target object and the first object, j represents the jth transaction between the target object and the first object, and M(U, V) j represents the amount of transaction resources for the jth transaction between the target object and the first object, and max(m) represents the maximum total amount of transaction resources between the target object and the first object in the trading platform, and α is the weight corresponding to the number of transactions.

[0123] Step S130: By taking each of the target objects and each of the first objects as a node respectively, and constructing a weighted edge between each pair of associated nodes, a target graph network is obtained.

[0124] Wherein, the constructed graph network can be a complex network, the associated node pair is the two nodes corresponding to the associated object pair, the weight of an edge is positively correlated with the association degree of the associated object pair corresponding to the edge, and the higher the association degree between the target object and the first object in the associated object pair, the greater the weight of the edge corresponding to the associated object pair. As an optional implementation manner, the weight of an edge can be equal to the association degree of the associated object pair corresponding to the edge.

[0125] Exemplarily, Figure 3A schematic diagram of the structure of a target graph network provided by an embodiment of the present application. The target graph network is a directed weighted graph network. The gray-filled circles in the graph represent the target nodes corresponding to the target objects, and the unfilled circles represent the first nodes corresponding to the first objects. The target nodes in the graph include node B1, node B2, and node B3, and the first nodes include nodes A1 to A7. There are edges between the nodes corresponding to the target objects and the first objects with transactions, that is, there are edges between the nodes corresponding to the associated object pairs. In the graph, there are edges between B1 and A1, A2, A6, A7, between B2 and A2, A3, A4, A5, and between B3 and A5, A6, A7. The weights of the edges between the nodes in the graph (not marked in the graph) are positively correlated with the degree of association of the associated object pairs (the length of the edges in the graph has nothing to do with the weights), and the direction of the edges is from the first nodes to the target nodes.

[0126] Step S140: Determine the target feature vectors of each node in the target graph network.

[0127] In the embodiment of the present application, for each node in the target graph network, the initial feature vector of the node can be determined according to at least one of the transaction features of the node or the network structure features of the node in the target graph network. Then, based on the correlation between the initial feature vectors of the associated node pairs including the node, the initial feature vector of the node is updated to obtain the target feature vector of the node. Among them, the correlation between the initial feature vectors of the associated node pairs refers to the correlation between the initial feature vector of the target node and the initial feature vector of the first node in the associated node pair.

[0128] Optionally, for any node in the target graph network, determine the weights of the edges between the node and the neighbor nodes in each corresponding associated node pair; according to the weights of the edges between the node and each neighbor node, and the sum of the edge weights between the node and each neighbor node, determine the feature association index of each neighbor node to the node; based on the initial feature vector of the node, the initial feature vectors of each neighbor node of the node, and the determined feature association index of each neighbor node to the node, update the initial feature vector of the node to obtain the target feature vector of the node. Among them, the neighbor node is the other node in the associated node pair including the node.

[0129] Exemplarily, in Figure 3 For node B3, its neighbor nodes are node A5, node A6, and node A7. Assume that the initial feature vector of node B3 is S B3 , the initial feature vector of node A5 is S A5 , the initial feature vector of node A6 is S A6 , and the initial feature vector of node A7 is S A7, the edge weight between A5 and B3 is 2, the edge weight between A6 and B3 is 6, the edge weight between A7 and B3 is 9, and the sum of the edge weights of B3 connected to each neighbor node is 2 + 6 + 9 = 17.

[0130] The feature correlation index of each neighbor node to the B3 node is:

[0131] The feature correlation index of the A5 node to the B3 node is 2 / (2 + 6 + 9) = 2 / 17;

[0132] The feature correlation index of the A6 node to the B3 node is 6 / (2 + 6 + 9) = 6 / 17;

[0133] The feature correlation index of the A7 node to the B3 node is 9 / (2 + 6 + 9) = 9 / 17;

[0134] The target feature vector of the B3 node is: T B3 = S B3 + 2 / 17S A5 + 6 / 17S A6 + 9 / 17S A7 .

[0135] Optionally, for each node in the graph network, the initial feature vectors of the nodes in the graph network can also be used as the target feature vectors.

[0136] Optionally, for any node in the target graph network, the network structure features of the node in the target graph network include at least one of the degree of the node, the clustering coefficient of the node, and the centrality of the node. The centrality of the node includes the degree centrality, between centrality, closeness centrality, eigenvector centrality, etc.

[0137] Among them, the degree of the node is the number of edges connected to the node. For example, for the B3 node in Figure 3 , the degree of the B3 node is 3. The clustering coefficient of the node is used to measure the degree of connection between network nodes, which refers to the ratio of the actual number of edges between the neighbor nodes of the node to the possible number of edges (the maximum number of edges) between the neighbor nodes. Since in the target graph network in the embodiments of the present application, only there is an edge between the first node and the target node, there is no edge between the first node and the first node, and there is no edge between the target node and the target node, that is, the actual number of edges between the neighbor nodes of any node in the target graph network is 0. Therefore, the clustering coefficient of each node in this target graph network is 0.

[0138] Optionally, the transaction characteristics of a node reflect the node's transaction behavior and can be determined as follows: Determine the transaction data related to the node from the transaction data of multiple target objects. Based on the transaction data related to the node, determine the amount of transaction resources and the number of transactions of the node. Based on at least one of the amount of transaction resources or the number of transactions of the node, determine the transaction characteristics of the node.

[0139] Optionally, the network structure characteristics of the graph network further include the average path length of the graph network, that is, the average of the shortest path lengths between any two nodes in the graph network, which reflects the degree of separation between the nodes in the graph network. For any node in the graph network, the average path length corresponding to the node is the average path length of the graph network where the node is located.

[0140] Optionally, when determining the target feature vectors of the nodes in the graph network, the initial feature vectors of each node in the graph network can be input into a trained embedding model to obtain the target feature vectors of each node in the graph network. Among them, embedding refers to the technology of converting network structure information into a fixed-length vector, and the embedding model can adopt the node embedding model (node2vec).

[0141] The goal of node embedding is to map the nodes into the embedding space to obtain the low-dimensional feature representation of the nodes. If the nodes have high similarity in the graph network, the low-dimensional feature representations of the nodes in the embedding space should also have high similarity. In the embodiments of the present application, for any two nodes in the graph network, if there is an edge between the two nodes, the similarity of the two nodes is high, and the higher the weight of the edge, the higher the similarity. Therefore, the training goal of this embedding model is to maximize the feature similarity of the nodes with edges in the graph network as the optimization goal, learn the target feature vectors (embedding vectors) of each node in the graph network, so as to better capture the structure information of the graph network, and based on the target feature vectors of the nodes in the graph network, perform subsequent anomaly detection.

[0142] As an optional solution, the embedding model can be trained as follows:

[0143] Obtain multiple second samples. Each second sample includes the initial feature vectors of the nodes in a second sample graph network, and the construction method of the second sample graph network is the same as that of the above target graph network, which can be referred to the above content.

[0144] For each second sample graph network, input the initial feature vectors of the nodes in the second sample graph network into the neural network model to be trained to obtain the predicted feature vectors of the nodes in the second sample graph network.

[0145] Optionally, the initial feature vectors of each node can be randomly initialized, and the initial feature vectors include multiple feature dimensions. Assume that the second sample graph network includes N nodes, and the initial feature vector of each node includes d feature dimensions, then the size of the feature vector matrix corresponding to the second sample graph network is N×d. In this feature vector matrix, the k-th row represents the initial feature vector of the k-th node in the second sample graph network.

[0146] For each second sample graph network, based on the correlation between the predicted feature vectors of each associated node pair in the second sample graph network, determine the first training loss corresponding to the second sample graph network.

[0147] Exemplarily, the first training loss of any second sample graph network can be expressed by the following formula:

[0148]

[0149] where, u represents the target node corresponding to the target object, v represents the first node corresponding to the first object, L represents the first training loss, E represents the set of associated node pairs / edges in the second sample graph network, (u, v) ∈ E represents the target node and the first node with an edge in the second sample graph network, e u represents the target feature vector of node u, e v represents the target feature vector of node v, e u .e v represents the feature similarity between node u and node v, and P represents the set of all nodes (target nodes and first nodes) in the second sample graph network.

[0150] Based on the first training losses corresponding to each second sample graph network, determine the first comprehensive loss.

[0151] Optionally, by processing the first training losses corresponding to each second sample graph network, obtain and determine the first comprehensive loss. Among them, the processing methods include but are not limited to summation, averaging, etc.

[0152] If the first training end condition is satisfied, regard the neural network model as the trained embedding model.

[0153] If the first training end condition is not satisfied, adjust the model parameters in the neural network model based on the first training loss, and continue to train the adjusted neural network model based on each second sample pair.

[0154] Among them, both the above-mentioned first training end condition and the loss function of the model can be configured according to requirements. For example, the first training end condition can include, but is not limited to, the number of training times reaching a first threshold, the convergence of the loss function (such as the first training loss of the model being less than a second threshold, or the first training losses for multiple consecutive times being less than the second threshold, etc.), the test metrics of the model meeting preset metrics, and so on.

[0155] Step S150: Based on the target graph network and the target feature vectors of each node in the target graph network, determine the anomaly detection results corresponding to each target node through the trained anomaly detection model.

[0156] Among them, the target node is the node corresponding to the target object, and the target graph network includes the edges and corresponding weights between the nodes in the target graph network. Input the target feature vectors of each node in the target graph network and the connection relationships (edges and corresponding weights) between the nodes into the trained anomaly detection model to obtain the anomaly detection results corresponding to each target node.

[0157] Optionally, the anomaly detection model can be obtained by training a large number of first samples on the initial anomaly detection model, that is, the artificial intelligence model to be trained. Each first sample includes the first sample graph network corresponding to multiple labeled sample objects and the target feature vectors of each node in the first sample graph network. The label of a sample object indicates whether the sample object is abnormal. Continuously training the model based on a large amount of labeled sample data can enable the model to learn knowledge that can effectively detect whether the target node corresponding to the target object is abnormal, so that the trained model can identify whether the target node corresponding to the target object to be detected is abnormal.

[0158] Optionally, the embodiment of the present application does not limit the structure of the artificial intelligence model. For example, a neural network model, a decision tree, a support vector machine, etc. can be adopted.

[0159] As an optional solution, the trained anomaly detection model is obtained through the following method:

[0160] Obtain a plurality of first samples. Among them, each first sample includes the first sample graph network corresponding to multiple labeled sample objects and the target feature vectors of each node in the first sample graph network. The label of a sample object indicates whether the sample object is abnormal. For example, if the sample object is normal, the label is marked as 1, and if the sample object is abnormal, it is marked as 0.

[0161] Based on each first sample, continuously perform training operations on the artificial intelligence model to be trained until the second training end condition is met, and obtain a trained anomaly detection model. Among them, the specific network architecture of the anomaly detection model is not uniquely limited in the embodiments of the present application and can be selected according to actual application requirements. In theory, the anomaly detection model can adopt any neural network model capable of detecting whether a target node is abnormal.

[0162] Among them, the training operations include:

[0163] Input the first sample graph network corresponding to each first sample and the target feature vectors of each node in each first sample into the artificial intelligence model, and obtain the predicted anomaly detection results corresponding to each sample object in each first sample. Optionally, the predicted anomaly detection result can be the predicted anomaly probability of the sample object.

[0164] Determine the second training loss according to the labels of each sample object in each first sample and the predicted anomaly detection results corresponding to each sample object in each first sample.

[0165] If the second training end condition is not met, adjust the model parameters in the artificial intelligence model based on the second training loss.

[0166] Among them, the above-mentioned second training end condition and the loss function of the model can be configured according to requirements. For example, the second training end condition can include but is not limited to the number of training times reaching the third threshold, the loss function converging (such as the second training loss of the model being less than the fourth threshold, or the second training losses for multiple consecutive times being less than the fourth threshold, etc.), the test metrics of the model meeting the preset metrics, and so on. The second training loss of the model represents the deviation between the predicted anomaly detection results corresponding to the sample objects in each first sample and the labels (actual whether abnormal) of the sample objects in each first sample. Through the first sample with labels and the training loss function of the model, and using the gradient descent algorithm to perform supervised training on the model, the anomaly detection results of the sample objects predicted by the model can continuously approach the true detection results of the sample objects, so that a trained anomaly detection model that meets the actual application requirements can be obtained.

[0167] Optionally, the performance of the model can be evaluated by means of cross-validation. The obtained sample data is split and combined into multiple different training sample sets and test sample sets. The training sample set is used to train the model, and the test sample set is used to evaluate the quality of the model prediction. Among them, the embodiments of the present application do not limit the method of cross-validation, and any method such as simple cross-validation, S-fold cross-validation, leave-one-out cross-validation, etc. can be adopted.

[0168] Optionally, when the artificial intelligence model adopts a decision tree model, the decision tree model can be constructed in the following way:

[0169] According to the target feature vectors of the corresponding nodes of each sample object in each first sample graph network, and the labels of each sample object, respectively determine the influence factor corresponding to each feature dimension, and the influence factor corresponding to each feature value under each feature dimension. Among them, the influence factor corresponding to each feature dimension includes the sum of the influence factors corresponding to each feature value under this dimension.

[0170] Among them, the target feature vector of any node includes the feature values of multiple feature dimensions. The feature dimension (also called feature attribute) is used to describe the feature information of the same category. Taking the target feature vector of the node in the target graph network as an example, the degree of the node is a feature dimension, and the feature value under each feature dimension is the feature information of the node under this feature dimension. The degree of a node is 8.

[0171] The influence factor can be information gain or Gini index. The information gain corresponding to a feature dimension represents the difference in information entropy before and after dividing the data set by this feature dimension. The greater the information gain corresponding to a feature dimension, the greater the degree of reduction in information uncertainty based on this feature dimension for division, and the better the division effect. The smaller the Gini index corresponding to a feature dimension, the smaller the error rate based on this feature dimension for division, and the better the division effect.

[0172] The information gain corresponding to a feature dimension can be calculated by the following formula:

[0173]

[0174]

[0175] Among them, l represents the l-th category of the detection result of the target object, L represents the total number of types of the detection result of the target object. In the embodiments of the present application, L = 2, including two categories: abnormal and normal. P l represents the proportion of samples of the l-th category among all sample objects, D represents the sample data set, Ent(D) represents the information entropy of the root node in the decision tree model under the sample data set D. a represents any feature dimension, k represents the k-th feature value under the a feature dimension, K represents the total number of feature values, |D| represents the total number of sample objects in the sample data set, |D k | represents the number of samples corresponding to the k-th feature value under the a feature dimension, Ent(D k ) represents the information entropy corresponding to the k-th feature value under the a feature dimension. Gain(D, a) represents the information gain of the sample data set D under the a feature dimension.

[0176] The Gini index corresponding to a feature dimension can be calculated by the following formula:

[0177]

[0178]

[0179] Among them, Gini(D) represents the Gini index corresponding to the root node in the decision tree model under the sample data set D. Gini(D,a) represents the Gini index of the sample data set D in the feature dimension a.

[0180] Take the feature dimension with the largest influence factor among the feature dimensions of the target feature vector as the target feature dimension, and determine the feature value with the largest influence factor under the target feature dimension as the target feature value;

[0181] Use the target feature dimension as the splitting feature and the target feature value as the splitting point to divide the nodes corresponding to each sample object in each first sample graph network;

[0182] If the division result meets the preset tree building stop condition, construct a decision tree model according to the determined splitting features and corresponding splitting points;

[0183] If the division result does not meet the preset tree building stop condition, for each branch obtained from the most recent division, according to the target feature vectors of the nodes corresponding to each sample object in each first sample graph network under this branch, and the labels of each sample object, re-determine the splitting feature and splitting point corresponding to this branch, and use the splitting feature and splitting point corresponding to this branch to divide the nodes corresponding to each sample object in each first sample graph network under this branch.

[0184] Among them, the preset tree building stop condition can be set as needed. For example, the depth of the decision tree reaches the preset depth value, or the number of sample objects in the leaf node is less than the fifth threshold, etc.

[0185] Exemplarily, taking the feature dimensions including transaction frequency, feature vector centrality, and transaction resource volume as an example, based on each sample object in the root node, it is calculated that the feature dimension with the largest information gain under each feature dimension is the transaction frequency. Then the first splitting feature for dividing the root node is the transaction frequency, and the splitting value corresponding to the first splitting feature is the feature value F1 with the largest information gain in the feature dimension of the transaction frequency.

[0186] For the left branch node obtained by dividing the root node, based on each sample object under the left branch node, it is calculated that the feature dimension with the largest information gain under each feature dimension is the feature vector centrality. Then the second splitting feature for dividing the left branch node is the feature vector centrality, and the splitting value corresponding to the second splitting feature is the feature value Q1 with the largest information gain in the feature dimension of the feature vector centrality.

[0187] For the right branch node obtained by the third layer of partitioning, based on each sample object under the right branch node, it is calculated that the feature dimension with the largest information gain under each feature dimension is the transaction resource volume. Then, the third splitting feature for partitioning the right branch node is the transaction resource volume, and the splitting value corresponding to the third splitting feature is the feature value P1 with the largest information gain under the feature dimension of the transaction resource volume.

[0188] The first splitting feature is the transaction frequency, and the corresponding splitting value is F1; the second splitting feature is the feature vector centrality, and the corresponding splitting value is Q1; the third splitting feature is the transaction resource volume, and the corresponding splitting value is P1. Based on the determined splitting features and splitting values, a decision tree is constructed, as Figure 4 shown. For each merchant to be detected, it can be judged whether the transaction frequency of the merchant is less than F1. If the transaction frequency is not less than F1, the merchant is considered an abnormal merchant. Otherwise, continue to judge whether the feature vector centrality corresponding to the merchant is less than Q1. If it is less than Q1, the merchant is considered an abnormal merchant. Otherwise, continue to judge whether the transaction resource volume of the merchant is greater than P1. If so, the merchant is considered an abnormal merchant, otherwise it is a normal merchant.

[0189] Optionally, during the training process of the decision tree model, decision tree generation algorithms such as ID3 (Iterative Dichotomiser 3), C4.5 (an extension of the ID3 algorithm that uses the information gain ratio to select splitting features), and CART (Classification And Regression Tree algorithm) can be used to construct the decision tree. The embodiments of the present application do not limit this.

[0190] Optionally, for the constructed decision tree model, based on the predicted anomaly detection results of each sample object corresponding to the node in each leaf node of the decision tree, and the labels of each sample object, the evaluation index of the decision tree model is calculated. Among them, the evaluation index includes the recall rate of abnormal samples, the anomaly detection accuracy, etc., and the model parameters of the decision tree model are adjusted based on the evaluation index.

[0191] Optionally, for each leaf node in the decision tree model, based on the predicted anomaly detection results of each sample object corresponding to the node in the leaf node, the predicted result corresponding to the leaf node is determined. For example, the average or mode of the predicted anomaly probabilities of each sample object corresponding to the node in the leaf node can be used as the predicted result corresponding to the leaf node.

[0192] Optionally, when performing anomaly detection on the target object through the trained anomaly detection model, in order to reduce the false alarm rate, an anomaly threshold can be set. When the anomaly probability of the target node is greater than the anomaly threshold, it is determined that the target node corresponding to the target node is abnormal, and it can be further reviewed manually.

[0193] Based on Figure 2 the anomaly detection method shown, by combining graph network and artificial intelligence technology, based on the connections between nodes in the constructed graph network and the target feature vectors of each node in the graph network, the potential relationship of the transaction behavior between the target object and the first object can be captured, so that the trained anomaly detection model can learn deeper anomaly transaction behavior characteristics of the target object, improve the anomaly detection accuracy of the target object, and better meet the actual detection requirements.

[0194] Figure 5 The present application provides a flowchart for anomaly detection of a target object. Based on the transaction data of multiple target objects, a target graph network can be constructed. Among them, each target object and each first object in the target graph network are used as nodes, and connections are constructed based on the transaction information between the target object and the first object, and the weight of the connection is positively correlated with the degree of association between the target object and the first object. The initial feature vectors of each node in the target graph network are input into the trained embedding model to obtain the target feature vectors of each node in the target graph network. Based on the constructed associated node pairs, connection weights in the target graph network, and the target feature vectors of each node in the target graph network, through the trained anomaly detection results, the anomaly detection results corresponding to the target nodes are obtained, and the anomaly detection results corresponding to the target nodes represent whether the target object is abnormal.

[0195] Optionally, when performing anomaly detection on the target object in the embodiment of the present application, the transaction data of each target object in the first time period can be obtained, and the transaction data in the first time period can be preprocessed for subsequent analysis. Specifically, according to the preset duration, the transaction data in the first time period is divided into transaction data of at least two sub - time periods, and the transaction data of each target object in each sub - time period is respectively used as the transaction data of multiple target objects.

[0196] The division of the sub - time period can be expressed by the following formula:

[0197] W i ={t|t∈[T i , T i+1 )}; i≥0

[0198] T i =T0 + i×W

[0199] where, W i represents the i - th sub - time period, T i represents the start time of the i - th sub - time period, T0 represents the initial time, that is, the start time of the first time period, and W represents the preset duration, that is, the length of the sub - time period.

[0200] Suppose the preset duration is 1 day and the initial time is November 1, 2023. Then the first sub-period is [November 1, 2023, November 2, 2023), the second sub-period is [November 2, 2023, November 3, 2023), and so on. If a transaction order occurs on November 1, 2023, then the transaction order is assigned to the first sub-period. If a transaction order occurs on November 2, 2023, then the transaction order is assigned to the second sub-period.

[0201] Optionally, after assigning the transaction order to the corresponding sub-period, for each sub-period, a target graph network corresponding to the sub-period can be constructed based on the transaction data of multiple target objects within the sub-period, and based on the target graph network of the sub-period and the target feature vectors of each node in the target graph network of the sub-period, the anomaly detection result of the target node within the sub-period can be obtained through a trained anomaly detection model. Among them, the associated node pairs in the target graph networks of different sub-periods are not completely the same, and the weights of the edges connecting the associated node pairs are also different.

[0202] Optionally, after assigning the transaction order to the corresponding sub-period, the final detection result of the target object can also be determined based on the anomaly detection results of the respective sub-periods corresponding to the first time period. For each sub-period in the first time period, a target graph network corresponding to the sub-period is constructed based on the transaction data of multiple target objects within the sub-period, and based on the target graph network of the sub-period and the target feature vectors of each node in the target graph network of the sub-period, the anomaly detection result of the target node within the sub-period is obtained through a trained anomaly detection model. Finally, based on the anomaly detection results of the target nodes within each sub-period, the final detection results of each target node within the first time period are determined.

[0203] Optionally, for the target graph network of each sub-period, the weight of the edge connecting the associated node pairs in the target graph network of the sub-period is positively correlated with the degree of association between the corresponding associated object pairs. For each sub-period, the degree of association between the associated object pairs of the sub-period can be determined based on the total amount of transaction resources of each associated object pair within the sub-period and the transaction frequency between the target object and the first object in each associated object pair.

[0204] Optionally, since there are endless emerging abnormal trading means and the abnormal trading strategies are constantly updated, in order to quickly adapt to the newly emerging abnormal trading means, when performing abnormal detection based on the real-time generated trading data, the abnormal detection results of each target object can be sent to the target terminal, and the labels corresponding to each target object sent by the target terminal can be received. Among them, the label of the target object is labeled by the annotator based on expert experience, indicating whether the target object is abnormal, that is, the real detection result. Optionally, the label of the target object can be a label indicating whether the abnormal detection result of the target object is correct. For example, if the abnormal detection result is correct, it is labeled as 1, otherwise it is labeled as 0. Based on the labels corresponding to each target object and the target graph network, a third sample is constructed.

[0205] When the number of the collected third samples reaches the preset value, the abnormal detection model is updated and trained based on the collected third samples. So that the updated abnormal detection model can quickly adapt to the new type of abnormal trading means and meet the latest needs of abnormal detection.

[0206] Optionally, when updating and training the abnormal detection model, in order to improve the model training efficiency and make the model achieve a better training effect, the target nodes corresponding to the target objects misrecognized by the abnormal detection model can be determined based on the labels of each target object, so as to construct a third sample based on the misrecognized target nodes.

[0207] The embodiment of the present application also provides a model training method, as Figure 6 shown. This method can be executed by any computer device, such as a terminal or a server, or can be implemented by multiple computer devices in cooperation. This model training method may include the following steps S210 to step S220.

[0208] S210: Obtain a plurality of fourth samples.

[0209] Among them, each fourth sample includes a fourth sample graph network corresponding to a plurality of sample objects with labels and the target feature vectors of each node in the fourth sample graph network. The label of a sample object indicates whether the sample object is abnormal.

[0210] The fourth sample graph network corresponding to each fourth sample is constructed in the following way:

[0211] Obtain the trading data of each sample object in the fourth sample. Among them, the trading data of each sample object includes the trading information between the sample object and at least one first object.

[0212] For each pair of associated objects, based on the trading information between the pair of associated objects, determine the degree of association of the pair of associated objects. Among them, the pair of associated objects includes a sample object and a first object having a transaction with the sample object.

[0213] By taking each sample object and each first object as a node respectively, and constructing weighted edges between each pair of associated nodes, a fourth sample graph network corresponding to the fourth sample is obtained. Among them, an associated node pair is two nodes corresponding to an associated object pair, and the weight of an edge is positively correlated with the degree of association of the associated object pair corresponding to the edge.

[0214] S220: Based on each fourth sample, continuously perform training operations on the artificial intelligence model to be trained until the third training end condition is met, and obtain a trained anomaly detection model.

[0215] Among them, the training operations include:

[0216] Input the fourth sample graph network corresponding to each fourth sample and the target feature vectors of each node in each fourth sample into the artificial intelligence model to obtain the predicted anomaly detection results corresponding to each sample object in each fourth sample.

[0217] Determine the third training loss according to the labels of each sample object in each fourth sample and the predicted anomaly detection results corresponding to each sample object in each fourth sample.

[0218] If the third training end condition is not met, adjust the model parameters in the artificial intelligence model based on the third training loss.

[0219] Optionally, the embodiment of the present application does not limit the structure of the artificial intelligence model. For example, a neural network model, a decision tree, a support vector machine, etc. can be used. Among them, for the construction process of the decision tree model, reference can be made to the detailed content in the above step S150.

[0220] It should be noted that the detailed process of the above model training method has been elaborated in detail in the above step S150, and the present application will not repeat it here. Reference can be made to the above content. The fourth sample used in the model training method can use the same sample data as the above first sample, second sample, and third sample, and the third training end condition can be the same as the above first training end condition and second training end condition. The anomaly detection model trained by this model training method can be applied to Figure 2 the anomaly detection method shown.

[0221] Based on Figure 6 the model training method shown, by constructing a graph network, based on the edges and weights of each node in the graph network, and combining the target feature vectors of each node in the graph network, the potential relationship of the transaction behavior between the sample object and the first object can be captured, so that the anomaly detection model can learn the deeper anomaly transaction behavior characteristics of the sample object, improve the anomaly detection accuracy of the sample object, and better meet the actual detection requirements.

[0222] Based on the same principle as the anomaly detection method provided in the embodiments of the present application, the embodiments of the present application provide an anomaly detection device. As Figure 7 shown, the anomaly detection device 300 may include an acquisition module 310, a correlation degree determination module 320, a graph network construction module 330, a feature determination module 340, and an anomaly detection module 350.

[0223] The acquisition module 310 is configured to acquire transaction data of a plurality of target objects to be detected; the transaction data of each target object includes transaction information between the target object and at least one first object;

[0224] The correlation degree determination module 320 is configured to determine the correlation degree of each pair of associated objects based on the transaction information between the pair of associated objects; the pair of associated objects includes a target object and a first object having a transaction with the target object;

[0225] The graph network construction module 330 is configured to obtain a target graph network by respectively taking each object in the target objects and the first objects as a node and constructing a weighted edge between each pair of associated nodes, where the pair of associated nodes are the two nodes corresponding to the pair of associated objects, and the weight of an edge is positively correlated with the correlation degree of the pair of associated objects corresponding to the edge;

[0226] The feature determination module 340 is configured to determine a target feature vector of each node in the target graph network;

[0227] The anomaly detection module 350 is configured to determine an anomaly detection result corresponding to each target node based on the target graph network and the target feature vectors of the nodes in the target graph network through a trained anomaly detection model, where the target node is the node corresponding to the target object;

[0228] Wherein, the anomaly detection model is obtained by training an artificial intelligence model based on a plurality of first samples. Each first sample includes a first sample graph network corresponding to a plurality of sample objects with labels, and the target feature vectors of the nodes in the first sample graph network. The label of a sample object represents whether the sample object is abnormal.

[0229] Optionally, the feature determination module 340 may be configured to:

[0230] Determine an initial feature vector of the node according to at least one of the transaction feature of the node or the network structure feature of the node in the target graph network;

[0231] Updating the initial feature vector of the node based on the correlation between the initial feature vectors of each associated node pair including the node to obtain the target feature vector of the node.

[0232] Optionally, the feature determination module 340 may be used to:

[0233] Input the initial feature vectors of the nodes in the target graph network into the trained embedding model to obtain the target feature vectors of the nodes;

[0234] Among them, the embedding model is trained in the following way:

[0235] Obtain a plurality of second samples, each of the second samples including the initial feature vectors of the nodes in a second sample graph network;

[0236] For each of the second sample graph networks, input the initial feature vectors of the nodes in the second sample graph network into the neural network model to be trained to obtain the predicted feature vectors of the nodes in the second sample graph network;

[0237] For each of the second sample graph networks, determine the first training loss corresponding to the second sample graph network based on the correlation between the predicted feature vectors of each associated node pair in the second sample graph network;

[0238] Determine the first comprehensive loss based on the first training losses corresponding to each of the second sample graph networks;

[0239] If the first training end condition is satisfied, use the neural network model as the embedding model;

[0240] If the first training end condition is not satisfied, adjust the model parameters in the neural network model based on the first training loss, and continue to train the adjusted neural network model based on each of the second samples.

[0241] Optionally, the transaction feature of any node is determined in the following way:

[0242] Determine the transaction data related to the node from the transaction data of multiple target objects;

[0243] Based on the transaction data related to the node, determine the transaction feature of the node; the transaction feature includes at least one of the transaction resource amount or the number of transactions corresponding to the node.

[0244] Optionally, for any node in the target graph network, the network structure feature of the node in the target graph network includes at least one of the degree of the node, the clustering coefficient of the node, or the centrality of the node.

[0245] Optionally, the target feature vector of any node includes eigenvalues of multiple feature dimensions;

[0246] The artificial intelligence model is a decision tree model, and the decision tree model is constructed in the following way:

[0247] According to the target feature vectors of the nodes corresponding to the sample objects in each first sample graph network, and the labels of the sample objects, determine the influence factors corresponding to each feature dimension, and the influence factors corresponding to each eigenvalue under each feature dimension respectively; the influence factor is information gain or Gini index;

[0248] Take the feature dimension with the largest determined influence factor among the feature dimensions as the target feature dimension, and determine the eigenvalue with the largest influence factor under the target feature dimension as the target eigenvalue;

[0249] Use the target feature dimension as the splitting feature and the target eigenvalue as the splitting point to divide the nodes corresponding to the sample objects in each first sample graph network;

[0250] If the division result meets the preset tree-building stop condition, construct a decision tree model according to the determined splitting features and corresponding splitting points;

[0251] If the division result does not meet the preset tree-building stop condition, for each branch obtained from the most recent division, according to the target feature vectors of the nodes corresponding to the sample objects in each first sample graph network under this branch, and the labels of the sample objects, re-determine the splitting feature and splitting point corresponding to this branch, and use the splitting feature and splitting point corresponding to this branch to divide the nodes corresponding to the sample objects in each first sample graph network under this branch.

[0252] Optionally, the anomaly detection model is trained in the following way:

[0253] Obtain a plurality of first samples;

[0254] Based on each first sample, continuously perform training operations on the artificial intelligence model to be trained until the second training end condition is met, and obtain a trained anomaly detection model. The training operations include:

[0255] Input the first sample graph network corresponding to each first sample, and the target feature vectors of the nodes in each first sample graph network, into the artificial intelligence model to obtain the predicted anomaly detection results corresponding to the sample objects in each first sample;

[0256] According to the labels of the sample objects in each first sample, and the predicted anomaly detection results corresponding to the sample objects in each first sample, determine the second training loss;

[0257] If the second training end condition is not satisfied, the model parameters in the artificial intelligence model are adjusted based on the second training loss.

[0258] Optionally, the device further includes an update module, and the update module can be used to:

[0259] Send the anomaly detection results of each of the target objects to the target terminal;

[0260] Receive the labels corresponding to each of the target objects sent by the target terminal; the label of a target object represents whether the target object is abnormal;

[0261] Based on the labels corresponding to each of the target objects and the target graph network, a third sample is constructed to update and train the anomaly detection model based on the third sample.

[0262] Optionally, the obtaining module 310 can be used to:

[0263] Obtain the transaction data of each of the target objects within the first time period;

[0264] According to a preset time length, the transaction data within the first time period is divided into transaction data of at least two sub-time periods, and the transaction data of each of the target objects in each sub-time period is respectively used as the transaction data of the multiple target objects;

[0265] The anomaly detection module 350 is further used to:

[0266] For each of the target objects, based on the anomaly detection results corresponding to each of the sub-time periods of the target object, determine the final detection result of the target detection object.

[0267] Based on Figure 7 The anomaly detection device shown can, by fusing a graph network and an artificial intelligence algorithm, based on the constructed graph network, the target feature vectors of each node in the graph network can capture the potential relationship between the transaction behaviors of the target object and the first object, so that the trained anomaly detection model can learn deeper anomaly transaction behavior features of the target object, improve the anomaly detection accuracy of the target object, and better meet the actual detection requirements.

[0268] An embodiment of this application further provides a model training device, as Figure 8 shown, the model training device 400 may include a sample obtaining module 410 and a training module 420.

[0269] A sample acquisition module 410 is configured to acquire a plurality of fourth samples; each of the fourth samples includes a fourth sample graph network corresponding to a plurality of sample objects with labels, and target feature vectors of each node in the fourth sample graph network, and the label of a sample object indicates whether the sample object is abnormal;

[0270] A training module 420 is configured to continuously perform training operations on an artificial intelligence model to be trained based on each fourth sample until a third training end condition is satisfied, and obtain a trained anomaly detection model. The training operations include:

[0271] Input the fourth sample graph network corresponding to each fourth sample and the target feature vectors of each node in each fourth sample into the artificial intelligence model to obtain a predicted anomaly detection result corresponding to each sample object in each fourth sample;

[0272] Determine a third training loss according to the labels of each sample object in each fourth sample and the predicted anomaly detection results corresponding to each sample object in each fourth sample;

[0273] If the third training end condition is not satisfied, adjust the model parameters in the artificial intelligence model based on the third training loss;

[0274] Wherein, the fourth sample graph network corresponding to each fourth sample is constructed in the following manner:

[0275] Acquire the transaction data of each sample object in the fourth sample; the transaction data of each sample object includes transaction information between the sample object and at least one first object;

[0276] For each pair of associated objects, determine the degree of association of the pair of associated objects based on the transaction information between the pair of associated objects; the pair of associated objects includes a sample object and a first object having a transaction with the sample object;

[0277] By respectively taking each object in each of the sample objects and the first objects as a node, and constructing weighted edges between each pair of associated nodes, the fourth sample graph network corresponding to the fourth sample is obtained; wherein, the pair of associated nodes is the two nodes corresponding to the pair of associated objects, and the weight of an edge is positively correlated with the degree of association of the pair of associated objects corresponding to the edge.

[0278] Based on Figure 8 The model training device shown can capture the potential relationship between the transaction behaviors of sample objects and first objects based on the constructed graph network and the target feature vectors of each node in the graph network by integrating the graph network and the artificial intelligence algorithm, so that the anomaly detection model can learn deeper anomaly transaction behavior features of sample objects and improve the anomaly detection accuracy of sample objects.

[0279] The device according to an embodiment of the present application can execute the method provided by the embodiment of the present application, and their implementation principles are similar. The actions performed by each module in the device according to each embodiment of the present application correspond to the steps in the method according to each embodiment of the present application. For a detailed description of the functions of each module of the device, reference can be specifically made to the description in the corresponding method shown above, and details are not described herein again.

[0280] In an embodiment of the present application, the term "module" or "unit" refers to a computer program with a predetermined function or a part of a computer program, which works together with other related parts to achieve a predetermined goal, and can be fully or partially implemented by using software, hardware (such as a processing circuit or a memory), or a combination thereof. Similarly, a processor (or multiple processors or memories) can be used to implement one or more modules or units. In addition, each module or unit can be a part of an overall module or unit that includes the function of the module or unit.

[0281] An embodiment of the present application provides an electronic device, including a memory, a processor, and a computer program stored on the memory. When the processor executes the computer program stored in the memory, the method according to any optional embodiment of the present application can be implemented.

[0282] Figure 9 FIG. shows a schematic structural diagram of an electronic device applicable to an embodiment of the present invention. As Figure 9 shown, the electronic device can be a server or a user terminal, and the electronic device can be used to implement the method provided in any embodiment of the present invention.

[0283] As Figure 9 shown in, the electronic device 2000 mainly includes at least one processor 2001 ( Figure 9 one is shown in), a memory 2002, a communication module 2003, and an input / output interface 2004, etc. Optionally, the components can be connected and communicate with each other through a bus 2005. It should be noted that Figure 9 the structure of the electronic device 2000 shown in is only schematic and does not constitute a limitation on the electronic device applicable to the method provided in the embodiment of the present application.

[0284] Among them, the memory 2002 can be used to store the operating system, application programs, etc. The application programs can include computer programs that implement the methods shown in the embodiments of the present invention when called by the processor 2001, and can also include programs for implementing other functions or services. The memory 2002 can be a ROM (Read Only Memory), or other types of static storage devices that can store static information and instructions, a RAM (Random Access Memory), or other types of dynamic storage devices that can store information and computer programs, or an EEPROM (Electrically Erasable Programmable Read Only Memory), a CD-ROM (Compact Disc Read Only Memory), or other optical disc storage, optical disc storage (including compact discs, laser discs, optical discs, digital versatile discs, Blu-ray discs, etc.), magnetic disk storage media, or other magnetic storage devices, or any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto.

[0285] The processor 2001 is connected to the memory 2002 through the bus 2005 and realizes corresponding functions by calling the application programs stored in the memory 2002. Among them, the processor 2001 can be a CPU (Central Processing Unit), a general-purpose processor, a DSP (Digital Signal Processor), an ASIC (Application Specific Integrated Circuit), an FPGA (Field Programmable Gate Array), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof, which can implement or execute various exemplary logical blocks, modules, and circuits described in connection with the disclosure of the present invention. The processor 2001 can also be a combination that realizes computing functions, such as a combination including one or more microprocessors, a combination of a DSP and a microprocessor, etc.

[0286] The electronic device 2000 can be connected to a network through the communication module 2003 (which can include but is not limited to components such as a network interface) to communicate with other devices (such as user terminals or servers, etc.) through the network, so as to achieve data interaction, such as sending data to other devices or receiving data from other devices. Among them, the communication module 2003 can include a wired network interface and / or a wireless network interface, etc., that is, the communication module can include at least one of a wired communication module or a wireless communication module.

[0287] The electronic device 2000 can be connected to the required input / output devices through the input / output interface 2004, such as a keyboard, a display device, etc. The electronic device 2000 itself can have a display device, and can also externally connect other display devices through the interface 2004. Optionally, a storage device such as a hard disk can also be connected through the interface 2004, so as to store the data in the electronic device 2000 into the storage device, or read the data in the storage device, and can also store the data in the storage device into the memory 2002. It can be understood that the input / output interface 2004 can be a wired interface or a wireless interface. According to different actual application scenarios, the devices connected to the input / output interface 2004 can be components of the electronic device 2000 or external devices connected to the electronic device 2000 when needed.

[0288] The bus 2005 for connecting each component can include a path to transmit information between the above components. The bus 2005 can be a PCI (Peripheral Component Interconnect) bus or an EISA (Extended Industry Standard Architecture) bus, etc. According to different functions, the bus 2005 can be divided into an address bus, a data bus, a control bus, etc.

[0289] Optionally, for the solution provided by the embodiments of the present invention, the memory 2002 can be used to store a computer program for executing the solution of the present invention, and is run by the processor 2001. When the processor 2001 runs the computer program, it implements the actions of the method or device provided by the embodiments of the present invention.

[0290] Based on the same principle as the method provided by the embodiments of the present application, the embodiments of the present application provide a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the corresponding content of the foregoing method embodiments can be implemented.

[0291] The embodiment of the present application also provides a computer program product, which includes a computer program. When the computer program is executed by a processor, it can implement the corresponding content of the foregoing method embodiment.

[0292] It should be noted that the terms "first", "second", "third", "fourth", "1", "2", etc. (if any) in the specification, claims and the above-mentioned drawings of the present application are used to distinguish similar objects, and do not necessarily have to be used to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of the present application described herein can be implemented in an order other than the illustrated or described order.

[0293] It should be understood that although the flowchart in the embodiment of the present application indicates each operation step by an arrow, the execution order of these steps is not limited to the order indicated by the arrow. Unless otherwise clearly stated in this article, in some implementation scenarios of the embodiment of the present application, the implementation steps in each flowchart can be executed in other orders according to requirements. In addition, some or all of the steps in each flowchart may include multiple sub-steps or multiple stages based on the actual implementation scenario. Some or all of these sub-steps or stages can be executed at the same time, and each sub-step or stage of these sub-steps or stages can also be executed at different times. In the scenario where the execution times are different, the execution order of these sub-steps or stages can be flexibly configured according to requirements, and the embodiment of the present application does not limit this.

[0294] The above are only optional implementation manners of some implementation scenarios of the present application. It should be pointed out that for those of ordinary skill in the art, without departing from the technical concept of the solution of the present application, using other similar implementation means based on the technical idea of the present application also belongs to the protection scope of the embodiments of the present application.

Claims

1. An anomaly detection method, characterized in that, The method includes: Obtaining transaction data of a plurality of target objects to be detected; the transaction data of each target object includes transaction information between the target object and at least one first object; For each pair of associated objects, determining the degree of association of the pair of associated objects based on the transaction information between the pair of associated objects; the pair of associated objects includes a target object and a first object having a transaction with the target object; By taking each object in each of the target objects and the first objects as a node respectively, and constructing a weighted edge between each pair of associated nodes, a target graph network is obtained; wherein, the pair of associated nodes is the two nodes corresponding to the pair of associated objects, and the weight of an edge is positively correlated with the degree of association of the pair of associated objects corresponding to the edge; Determining a target feature vector of each node in the target graph network; Based on the target graph network and the target feature vectors of the nodes in the target graph network, through a trained anomaly detection model, determining an anomaly detection result corresponding to each target node, where the target node is the node corresponding to the target object; Wherein, the anomaly detection model is obtained by training an artificial intelligence model based on a plurality of first samples, each first sample includes a first sample graph network corresponding to a plurality of labeled sample objects, and the target feature vectors of the nodes in the first sample graph network, and the label of a sample object represents whether the sample object is abnormal.

2. The method according to claim 1, wherein For each node in the target graph network, determining the target feature vector of the node includes: Determining an initial feature vector of the node according to at least one of the transaction feature of the node or the network structure feature of the node in the target graph network; Updating the initial feature vector of the node based on the correlation between the initial feature vectors of the associated node pairs including the node, to obtain the target feature vector of the node.

3. The method according to claim 1 or 2, characterized in that, Determining the target feature vector of each node in the target graph network includes: Inputting the initial feature vectors of the nodes in the target graph network into a trained embedding model to obtain the target feature vectors of the nodes; Wherein, the embedding model is obtained by training in the following manner: Obtaining a plurality of second samples, each second sample includes the initial feature vectors of the nodes in a second sample graph network; For each second sample graph network, inputting the initial feature vectors of the nodes in the second sample graph network into a neural network model to be trained, to obtain the predicted feature vectors of the nodes in the second sample graph network; For each second sample graph network, determining a first training loss corresponding to the second sample graph network based on the correlation between the predicted feature vectors of the associated node pairs in the second sample graph network; Determining a first comprehensive loss based on the first training losses corresponding to the second sample graph networks; If a first training end condition is satisfied, taking the neural network model as the embedding model; If the first training end condition is not satisfied, adjust the model parameters in the neural network model based on the first training loss, and continue to train the adjusted neural network model based on each of the second samples.

4. The method according to claim 2, wherein The transaction feature of any node is determined in the following manner: Determine the transaction data related to the node from the transaction data of multiple target objects; Based on the transaction data related to the node, determine the transaction feature of the node; the transaction feature includes at least one of the transaction resource amount or the number of transactions corresponding to the node.

5. The method according to claim 2, characterized in that, For any node in the target graph network, the network structure feature of the node in the target graph network includes at least one of the degree of the node, the clustering coefficient of the node, or the centrality of the node.

6. The method according to claim 1, wherein The target feature vector of any node includes feature values of multiple feature dimensions; The artificial intelligence model is a decision tree model, and the decision tree model is constructed in the following manner: According to the target feature vectors of the corresponding nodes of each sample object in each first sample graph network, and the labels of each sample object, respectively determine the influence factor corresponding to each feature dimension, and the influence factor corresponding to each feature value under each feature dimension; the influence factor is the information gain or the Gini index; Take the feature dimension with the largest determined influence factor among the feature dimensions as the target feature dimension, and determine the feature value with the largest influence factor under the target feature dimension as the target feature value; Use the target feature dimension as the splitting feature and the target feature value as the splitting point to divide the nodes corresponding to each sample object in each first sample graph network; If the division result meets the preset tree-building stop condition, construct a decision tree model according to the determined splitting features and corresponding splitting points; If the division result does not meet the preset tree-building stop condition, for each branch obtained in the most recent division, according to the target feature vectors of the corresponding nodes of each sample object in each first sample graph network under the branch, and the labels of each sample object, re-determine the splitting feature and splitting point corresponding to the branch, and divide the nodes corresponding to each sample object in each first sample graph network under the branch through the splitting feature and splitting point corresponding to the branch.

7. The method according to claim 1, characterized in that, The anomaly detection model is trained in the following manner: Obtain multiple first samples; Based on each first sample, continuously perform training operations on the artificial intelligence model to be trained until the second training end condition is met, and obtain a trained anomaly detection model. The training operations include: Input the first sample graph network corresponding to each first sample, and the target feature vectors of each node in each first sample graph network, into the artificial intelligence model to obtain the predicted anomaly detection results corresponding to each sample object in each first sample; Determine the second training loss according to the labels of each sample object in each first sample and the predicted anomaly detection results corresponding to each sample object in each first sample; If the second training end condition is not satisfied, adjust the model parameters in the artificial intelligence model based on the second training loss.

8. The method according to claim 1, characterized in that The method further includes: Send the anomaly detection results of each of the target objects to the target terminal; Receive the tags corresponding to each of the target objects sent by the target terminal; the tag of one target object indicates whether the target object is abnormal; Based on the tags corresponding to each of the target objects and the target graph network, construct a third sample to update and train the anomaly detection model based on the third sample.

9. The method according to claim 1, characterized in that, The obtaining the transaction data of multiple target objects to be detected includes: Obtain the transaction data of each of the target objects within the first time period; According to a preset time duration, divide the transaction data within the first time period into transaction data of at least two sub-time periods, and use the transaction data of each of the target objects in each sub-time period as the transaction data of the multiple target objects respectively; The method further includes: For each of the target objects, determine the final detection result of the target detection object based on the anomaly detection results corresponding to each of the sub-time periods of the target object.

10. A model training method, characterized in that, The method includes: Obtain multiple fourth samples; each fourth sample includes a fourth sample graph network corresponding to multiple labeled sample objects, and target feature vectors of each node in the fourth sample graph network, and the label of one sample object indicates whether the sample object is abnormal; Based on each fourth sample, continuously perform training operations on the artificial intelligence model to be trained until a third training end condition is met, and obtain a trained anomaly detection model. The training operations include: Input the fourth sample graph network corresponding to each fourth sample and the target feature vectors of each node in each fourth sample into the artificial intelligence model to obtain the predicted anomaly detection results corresponding to each sample object in each fourth sample; Determine the third training loss according to the labels of each sample object in each fourth sample and the predicted anomaly detection results corresponding to each sample object in each fourth sample; If the third training end condition is not met, adjust the model parameters in the artificial intelligence model based on the third training loss; Among them, the fourth sample graph network corresponding to each fourth sample is constructed in the following manner: Obtain the transaction data of each sample object in the fourth sample; the transaction data of each sample object includes the transaction information between the sample object and at least one first object; For each pair of associated objects, determine the degree of association of the pair of associated objects based on the transaction information between the pair of associated objects; the pair of associated objects includes a sample object and a first object having a transaction with the sample object; By taking each of the sample objects and each of the first objects as a node respectively, and constructing a weighted edge between each pair of associated nodes, obtain the fourth sample graph network corresponding to the fourth sample; wherein, the pair of associated nodes is the two nodes corresponding to the pair of associated objects, and the weight of an edge is positively correlated with the degree of association of the pair of associated objects corresponding to the edge.

11. An anomaly detection device, characterized in that, The device includes: An obtaining module, configured to obtain the transaction data of multiple target objects to be detected; the transaction data of each target object includes the transaction information between the target object and at least one first object; An association degree determination module, configured to determine the association degree of each pair of associated objects based on the transaction information between the pair of associated objects; the pair of associated objects includes a target object and a first object having a transaction with the target object; A graph network construction module, configured to obtain a target graph network by respectively taking each object in each of the target objects and the first objects as a node and constructing a weighted edge between each pair of associated nodes, where the pair of associated nodes are two nodes corresponding to the pair of associated objects, and the weight of an edge is positively correlated with the association degree of the pair of associated objects corresponding to the edge; A feature determination module, configured to determine the target feature vector of each node in the target graph network; An anomaly detection module, configured to determine the anomaly detection result corresponding to each target node based on the target graph network and the target feature vectors of the nodes in the target graph network through a trained anomaly detection model, where the target node is the node corresponding to the target object; Wherein, the anomaly detection model is obtained by training an artificial intelligence model based on a plurality of first samples. Each of the first samples includes a first sample graph network corresponding to a plurality of labeled sample objects and the target feature vectors of the nodes in the first sample graph network. The label of a sample object represents whether the sample object is abnormal.

12. A model training device, characterized in that, The apparatus includes: A sample acquisition module, configured to acquire a plurality of fourth samples; each of the fourth samples includes a fourth sample graph network corresponding to a plurality of labeled sample objects and the target feature vectors of the nodes in the fourth sample graph network. The label of a sample object represents whether the sample object is abnormal; A training module, configured to continuously perform a training operation on the artificial intelligence model to be trained based on each of the fourth samples until a third training end condition is satisfied, and obtain a trained anomaly detection model. The training operation includes: Inputting the fourth sample graph network corresponding to each of the fourth samples and the target feature vectors of the nodes in each of the fourth samples into the artificial intelligence model to obtain the predicted anomaly detection result corresponding to each sample object in each of the fourth samples; Determining a third training loss according to the labels of the sample objects in each of the fourth samples and the predicted anomaly detection results corresponding to the sample objects in each of the fourth samples; If the third training end condition is not satisfied, adjusting the model parameters in the artificial intelligence model based on the third training loss; Wherein, the fourth sample graph network corresponding to each fourth sample is constructed in the following manner: Obtaining the transaction data of each sample object in the fourth sample; the transaction data of each sample object includes the transaction information between the sample object and at least one first object; For each pair of associated objects, determining the association degree of the pair of associated objects based on the transaction information between the pair of associated objects; the pair of associated objects includes a sample object and a first object having a transaction with the sample object; By taking each of the sample objects and each of the first objects as a node respectively, and constructing a weighted edge between each pair of associated nodes, a fourth sample graph network corresponding to the fourth sample is obtained; wherein, the pair of associated nodes is the two nodes corresponding to the pair of associated objects, and the weight of an edge is positively correlated with the degree of association of the pair of associated objects corresponding to the edge.

13. An electronic device, characterized in that, The electronic device includes a memory and a processor. A computer program is stored in the memory, and the processor executes the computer program to implement the method according to any one of claims 1 to 9 or claim 10.

14. A computer-readable storage medium, characterized in that, A computer program is stored in the storage medium, and when the computer program is executed by a processor, the method according to any one of claims 1 to 9 or claim 10 is implemented.

15. A computer program product, characterized in that, The computer product includes a computer program, and when the computer program is executed by a processor, the method according to any one of claims 1 to 9 or claim 10 is implemented.