Financial fraud prediction method and device based on multi-modal graph learning, and storage medium

By constructing a multi-modal graph learning model, using the graph structure and difference information of the enterprise and the associated object, the problem of insufficient accuracy of the fraud prediction model in the existing technology is solved, and a comprehensive and accurate prediction of corporate fraud behavior is achieved.

CN120338827AActive Publication Date: 2025-07-18CAPITAL UNIV OF ECONOMICS & BUSINESS
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510457633.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-14
Publication Date
2025-07-18
Estimated Expiration
2045-04-14

AI Technical Summary

Technical Problem

Existing fraud prediction models cannot predict firm fraud comprehensively and accurately, for reasons including the limitations of single-modal data, the failure to consider business ecosystem interactions, time period limitations, and neglect of association changes.

Method used

By constructing a multimodal graph learning model, using the graph structure of the target enterprise and the associated object, determine the multimodal feature vector and structural feature vector, compare the differences in graph structures in adjacent time periods, generate a change graph structure, and input a pre-trained fraud prediction model for prediction.

Benefits of technology

A comprehensive and accurate prediction of the fraudulent behavior of the target company is achieved, improving the accuracy of the prediction results, and being able to discover potential abnormal patterns and hide fraud.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120338827A_ABST
    Figure CN120338827A_ABST
Patent Text Reader

Abstract

The invention discloses a financial fraud prediction method and device based on multi-modal graph learning and a storage medium, and the method comprises the steps: taking a target enterprise in each target time period and an object associated with the target enterprise as nodes, and taking an association relationship between the target enterprise and each object as an edge; constructing a plurality of graph structures corresponding to each target time period; determining a first feature vector corresponding to each node in the plurality of graph structures; comparing the graph structures of the adjacent target time periods, determining difference information between the graph structures, and generating a plurality of corresponding change graph structures based on the difference information; and inputting the plurality of graph structures and the plurality of changed graph structures into a pre-trained fraud prediction model, and judging whether the target enterprise has a fraud behavior based on a fraud probability output by the fraud prediction model.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of artificial intelligence technology, and in particular, to a financial fraud prediction method, device, and storage medium based on multimodal graph learning. Background Art

[0002] In order to ensure the authenticity, transparency, and compliance of enterprise financial information, regulatory agencies usually inspect the financial conditions of various enterprises and predict whether an enterprise has fraudulent behavior based on its financial condition. Currently, regulatory agencies usually use a pre-trained fraud prediction model and analyze the financial data of the target enterprise collected, so as to determine whether the target enterprise has potential fraud risks. Among them, the fraud prediction model can be, for example, a model constructed based on logistic regression or random forest.

[0003] However, the above existing method of using a fraud prediction model to predict whether a target enterprise has potential fraud risks has certain defects. First, since the data input into the fraud prediction model is usually single-modal data (for example, financial statement data corresponding to the target enterprise, etc.), and the information contained in single-modal data is not comprehensive enough, when using the fraud prediction model to predict whether the target enterprise has fraudulent behavior, the predicted result lacks accuracy.

[0004] Second, since the data input into the fraud prediction model is usually only limited to the internal data of the target enterprise, and does not consider the position of the target enterprise in the business ecosystem (related to the target enterprise and including multiple other enterprises), as well as the interaction between the target enterprise and other enterprises in the business ecosystem, the fraud prediction model cannot discover potential abnormal patterns and fraudulent behaviors of the target enterprise, and thus the fraud prediction model cannot accurately predict whether the target enterprise has fraudulent behavior.

[0005] Third, since the fraudulent behavior of the target enterprise is often the result of careful planning over the years and lasts for several years, and the existing fraud prediction models can often only judge whether the target enterprise has fraudulent behavior based on the data of the current period or adjacent periods of the target enterprise, and cannot perform fraud prediction on the target enterprise based on the data of the target enterprise over a long period of time, the result finally predicted by the fraud prediction model lacks accuracy.

[0006] Fourth, in addition, since the fraud prediction model does not consider the change situation of the association relationship between the target enterprise and other enterprises in each period, the fraud prediction model cannot, based on the change situation of the association relationship between the target enterprise and other enterprises, mine and identify abnormal transaction patterns between the target enterprise and other enterprises, so that the fraud prediction model cannot discover possible hidden fraudulent behaviors of the target enterprise, and thus the result finally predicted by the fraud prediction model lacks accuracy.

[0007] In view of the technical problem in the existing technology described above that the existing fraud prediction model cannot comprehensively and accurately predict the fraud behavior of the target enterprise, no effective solution has been proposed yet. Summary of the Invention

[0008] Embodiments of the present disclosure provide a financial fraud prediction method, apparatus, and storage medium based on multi-modal graph learning to at least solve the technical problem in the existing technology that the existing fraud prediction model cannot comprehensively and accurately predict the fraud behavior of the target enterprise.

[0009] According to one aspect of the embodiments of the present disclosure, there is provided a financial fraud prediction method based on multi-modal graph learning, including: taking the target enterprise and the objects associated with the target enterprise in each target period as nodes, and taking the association relationship between the target enterprise and each object as an edge to construct a plurality of graph structures corresponding to each target period, where the objects include listed companies, unlisted companies, and / or individuals; determining a first feature vector corresponding to each node in the plurality of graph structures, where the first feature vector includes a multi-modal feature vector corresponding to the listed company node and the target enterprise node, and a structural feature vector corresponding to the unlisted company node and the individual node; comparing the graph structures of adjacent target periods and determining the difference information between the graph structures, and generating corresponding multiple changed graph structures based on the difference information, where the difference information includes node change information and edge change information; and inputting the plurality of graph structures and the plurality of changed graph structures into a pre-trained fraud prediction model, and judging whether the target enterprise has fraud behavior based on the fraud probability output by the fraud prediction model.

[0010] According to another aspect of the embodiments of the present disclosure, there is also provided a storage medium, where the storage medium includes a stored program, and when the program runs, the method described in any one of the above is executed by a processor.

[0011] According to another aspect of the embodiments of the present disclosure, there is also provided a financial fraud prediction device based on multi-modal graph learning, including: a graph structure construction module, configured to use the target enterprises within each target period and the objects associated with the target enterprises as nodes, and use the association relationships between the target enterprises and each object as edges to construct a plurality of graph structures respectively corresponding to each target period, where the objects include listed companies, unlisted companies, and / or individuals; a first feature vector determination module, configured to determine a first feature vector corresponding to each node in the plurality of graph structures, where the first feature vector includes a multi-modal feature vector corresponding to the listed company node and the target enterprise node, and a structural feature vector corresponding to the unlisted company node and the individual node; a changed graph structure generation module, configured to compare the graph structures of adjacent target periods and determine the difference information between the graph structures, and generate corresponding multiple changed graph structures based on the difference information, where the difference information includes node change information and edge change information; and a fraud prediction module, configured to input the plurality of graph structures and the plurality of changed graph structures into a pre-trained fraud prediction model, and determine whether the target enterprise has fraud behavior based on the fraud probability output by the fraud prediction model.

[0012] According to another aspect of the embodiments of the present disclosure, there is also provided a financial fraud prediction device based on multi-modal graph learning, including: a processor; and a memory connected to the processor for providing instructions for the processor to perform the following processing steps: using the target enterprises within each target period and the objects associated with the target enterprises as nodes, and using the association relationships between the target enterprises and each object as edges to construct a plurality of graph structures respectively corresponding to each target period, where the objects include listed companies, unlisted companies, and / or individuals; determining a first feature vector corresponding to each node in the plurality of graph structures, where the first feature vector includes a multi-modal feature vector corresponding to the listed company node and the target enterprise node, and a structural feature vector corresponding to the unlisted company node and the individual node; comparing the graph structures of adjacent target periods and determining the difference information between the graph structures, and generating corresponding multiple changed graph structures based on the difference information, where the difference information includes node change information and edge change information; and inputting the plurality of graph structures and the plurality of changed graph structures into a pre-trained fraud prediction model, and determining whether the target enterprise has fraud behavior based on the fraud probability output by the fraud prediction model.

[0013] The present application provides a financial fraud prediction method based on multi-modal graph learning. First, the processor takes the target enterprises within each target period and the objects associated with the target enterprises as nodes, and takes the association relationships between the target enterprises and each object as edges to construct multiple graph structures corresponding to each target period respectively. Then, the processor determines the first feature vectors corresponding to each node in the multiple graph structures. Further, the processor compares the graph structures of adjacent target periods and determines the difference information between the graph structures, and generates corresponding multiple changed graph structures based on the difference information. Finally, the processor inputs the multiple graph structures and the multiple changed graph structures into a pre-trained fraud prediction model, and determines whether the target enterprise has fraud behavior based on the fraud probability output by the fraud prediction model.

[0014] As can be seen from the above, since the present application takes into account the influence of the position and interaction of the target enterprise in its associated business ecosystem on fraud behavior prediction, the present application does not simply predict whether the target enterprise has fraud behavior based on the internal data corresponding to the target enterprise, but constructs a graph structure based on the target enterprise and the objects having an association relationship with the target enterprise, and predicts the fraud behavior of the target enterprise based on the graph structure and the pre-trained fraud prediction model, thereby helping the fraud prediction model to discover potential abnormal patterns and fraud behaviors of the target enterprise, and further enabling the fraud prediction model to accurately predict the fraud behavior of the target enterprise.

[0015] Further, the present application also takes into account that the financial fraud behavior of the target enterprise is often the result of careful planning over the years. Therefore, the present application constructs graph structures corresponding to multiple different target periods respectively, and dynamically predicts the fraud behavior of the target enterprise based on the long-term data information of the target enterprise. In addition, the present application generates multiple changed graph structures based on the difference information between the graph structures of adjacent target periods, so that the fraud prediction model can mine and identify abnormal association relationships and hidden fraud behaviors according to the changes of the target enterprise over a long period of time.

[0016] Thus, the technical effect of being able to accurately predict the fraud behavior of the target enterprise comprehensively and accurately is achieved. Furthermore, the technical problem in the prior art that the fraud prediction model cannot predict the fraud behavior of the target enterprise comprehensively and accurately is solved.

[0017] In addition, since in the graph structure of the present application, the initial feature vector corresponding to the node of the target enterprise is a multi-modal feature vector generated based on multi-modal data, the present application comprehensively utilizes the data information corresponding to the target enterprise and further improves the accuracy of the result finally output by the fraud prediction model. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] The accompanying drawings described herein are used to provide a further understanding of the present disclosure and form a part of this application. The schematic embodiments of the present disclosure and their descriptions are used to explain the present disclosure and do not constitute an improper limitation to the present disclosure. In the drawings:

[0019] Figure 1 is a hardware structure block diagram of a computing device for implementing the method according to Embodiment 1 of the present application;

[0020] Figure 2 is a schematic diagram of a financial fraud prediction system based on multi-modal graph learning according to Embodiment 1 of the present application;

[0021] Figure 3 is a schematic flow diagram of a financial fraud prediction method based on multi-modal graph learning according to Embodiment 1 of the present application;

[0022] Figure 4 is a schematic diagram of multiple graph structures, multiple change graph structures, and a fraud prediction model according to Embodiment 1 of the present application;

[0023] Figure 5 is a schematic diagram of multi-modal data and multi-modal vectors according to Embodiment 1 of the present application;

[0024] Figure 6 is a schematic diagram of a financial fraud prediction device based on multi-modal graph learning according to Embodiment 2 of the present application;

[0025] Figure 7 is a schematic diagram of a financial fraud prediction device based on multi-modal graph learning according to Embodiment 3 of the present disclosure. Detailed implementation manners

[0026] In order to enable those skilled in the art to better understand the technical solutions of the present disclosure, the technical solutions in the embodiments of the present disclosure will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present disclosure. Obviously, the described embodiments are only a part of the embodiments of the present disclosure, rather than all the embodiments. Based on the embodiments in the present disclosure, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present disclosure.

[0027] It should be noted that the terms "first", "second", etc. in the specification, claims and the above-mentioned drawings of the present disclosure are used to distinguish similar objects, and do not necessarily have to be used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances, so that the embodiments of the present disclosure described here can be implemented in an order different from those illustrated or described here. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device comprising a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.

[0028] Embodiment 1

[0029] According to this embodiment, a method embodiment for financial fraud prediction based on multi-modal graph learning is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that here.

[0030] The method embodiment provided by this embodiment can be executed in a mobile terminal, a computer terminal, a server or a similar computing device. Figure 1 A hardware structure block diagram of a computing device for implementing financial fraud prediction based on multi-modal graph learning is shown. As Figure 1 shown, the computing device may include one or more processors (the processor may include, but is not limited to, a processing device such as a microprocessor MCU or a programmable logic device FPGA), a memory for storing data, a transmission device for communication functions, and an input / output interface. Among them, the memory, the transmission device and the input / output interface are connected to the processor through a bus. In addition, it may further include: a display, a keyboard and a cursor control device connected to the input / output interface. Those of ordinary skill in the art can understand that Figure 1 the structure shown is only schematic and does not limit the structure of the above-mentioned electronic device. For example, the computing device may further include more or fewer components than Figure 1 shown, or have a different configuration from Figure 1 shown.

[0031] It should be noted that one or more of the above-mentioned processors and / or other data processing circuits can generally be referred to as "data processing circuits" herein. The data processing circuit can be embodied in software, hardware, firmware, or any combination thereof, in whole or in part. In addition, the data processing circuit can be a single independent processing module, or be incorporated in whole or in part into any one of other elements in the computing device. As involved in the embodiments of the present disclosure, the data processing circuit is a kind of processor control (such as the selection of a variable resistance terminal path connected to an interface).

[0032] The memory can be used to store software programs and modules of application software, such as the program instructions / data storage device corresponding to the financial fraud prediction based on multi-modal graph learning in the embodiments of the present disclosure. The processor executes various functional applications and data processing by running the software programs and modules stored in the memory, that is, realizes the financial fraud prediction based on multi-modal graph learning of the above application program. The memory can include high-speed random access memory, and can also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memories. In some instances, the memory can further include a memory remotely disposed relative to the processor, and these remote memories can be connected to the computing device through a network. Examples of the above network include but are not limited to the Internet, intranet, local area network, mobile communication network, and combinations thereof.

[0033] The transmission device is used to receive or send data via a network. Specific examples of the above network can include a wireless network provided by a communication provider of the computing device. In one instance, the transmission device includes a network adapter (Network Interface Controller, NIC), which can be connected to other network devices through a base station and thus communicate with the Internet. In one instance, the transmission device can be a radio frequency (RF) module, which is used to communicate with the Internet wirelessly.

[0034] The display can be, for example, a touch-screen liquid crystal display (LCD), which enables a user to interact with the user interface of the computing device.

[0035] It should be noted here that in some alternative embodiments, the above Figure 1 shown computing device can include hardware elements (including circuits), software elements (including computer code stored on a computer-readable medium), or a combination of both hardware elements and software elements. It should be pointed out that Figure 1 is only an example of a specific specific instance and is intended to show the types of components that can exist in the above computing device.

[0036] Figure 2It is a schematic diagram of a financial fraud prediction system based on multi-modal graph learning according to the present embodiment. Refer to Figure 2 As shown, the system includes: a terminal device 100, a processor 200, and a server 300.

[0037] Among them, the terminal device 100 is communicatively connected to the processor 200, and is used to send data information of the target enterprise to be predicted (such as name information or label information corresponding to the target enterprise) to the processor 200 through the terminal device 100.

[0038] The processor 200 is provided with a pre-trained fraud prediction model, and the processor 200 is further used to determine objects (including listed enterprises, unlisted enterprises, and / or individuals) associated with the target enterprise based on the data information corresponding to the target enterprise sent by the terminal device 100, and construct a graph structure corresponding to each target time period based on the target enterprise and the objects associated with the target enterprise.

[0039] In addition, the processor 200 is communicatively connected to the server 300, and is used to collect multi-modal information corresponding to the target enterprise and multi-modal information of listed companies associated with the target enterprise from the server 300, so that the processor 200 can determine the first feature vector corresponding to each node in the multiple graph structures based on the collected multi-modal information.

[0040] Furthermore, the processor 200 is further used to compare the graph structures of adjacent target time periods and determine the difference information between the graph structures, and generate corresponding multiple changed graph structures based on the difference information. And when the processor 200 generates multiple graph structures and multiple changed graph structures, input the multiple graph structures and multiple changed graph structures into the fraud prediction model, and judge whether the target enterprise has fraud behavior based on the output result of the fraud prediction model.

[0041] It should be noted that the terminal device 100, the processor 200, and the server 300 in the system can all adopt the above-mentioned hardware structure.

[0042] Under the above operating environment, according to the first aspect of the present embodiment, a financial fraud prediction method based on multi-modal graph learning is provided, and this method is implemented by Figure 2 the processor 200 shown in Figure 3 shows the schematic flowchart of this method. Refer to Figure 3 As shown, this method includes:

[0043] S302: Use the target enterprises within each target time period and the objects associated with the target enterprises as nodes, and use the association relationships between the target enterprises and each object as edges to construct multiple graph structures corresponding to each target time period, where the objects include listed companies, unlisted companies, and / or individuals;

[0044] S304: Determine the first eigenvectors corresponding to each node in the multiple graph structures, where the first eigenvectors include multi-modal eigenvectors corresponding to the listed company nodes and the target enterprise nodes, and structural eigenvectors corresponding to the unlisted company nodes and the individual nodes;

[0045] S306: Compare the graph structures of adjacent target time periods and determine the difference information between the graph structures, and generate corresponding multiple changed graph structures based on the difference information, where the difference information includes node change information and edge change information; and

[0046] S308: Input the multiple graph structures and the multiple changed graph structures into a pre-trained fraud prediction model, and determine whether the target enterprise has fraud behavior based on the fraud probability output by the fraud prediction model.

[0047] Specifically, first, the terminal device 100 sends the data information corresponding to the target enterprise determined by the user to the processor 200. Then, the processor 200 respectively determines the objects associated with the target enterprise within each target time period. Among them, the association relationship is used to indicate investment relationships, cooperation relationships, etc. The objects associated with the target enterprise can be, for example, the subsidiaries or associated companies of the target enterprise, and the types of objects associated with the target enterprise can be listed companies, unlisted companies, and / or individuals. Thus, the processor 200 uses the target enterprises within each target time period and the objects associated with the target enterprises as nodes, and uses the association relationships between the target enterprises and each object as edges to construct multiple graph structures corresponding to each target time period (S302).

[0048] For example, first, the processor 200 determines the target time period Then the processor 200 determines that within the target time period the objects associated with the target enterprise Within the target time period the objects associated with the target enterprise ...; within the target time period the objects associated with the target enterprise Furthermore, the processor 200 uses the target enterprise within the target time period and the objects associated with the target enterprise as nodes, and uses the association relationships between the target enterprise and each object as edges to construct a graph structure corresponding to the target time period The corresponding graph structure Similarly, the processor 200 can determine the graph structure corresponding to the target time period The corresponding graph structure

[0049] Thus, from the above description, it can be known that the processor 200 can determine the graph structure corresponding to the target time period The corresponding graph structure In this embodiment, take t = 3. That is, the processor 200 determines the target time period and the graph structure corresponding to the target time period The corresponding graph structure

[0050] When the processor 200 constructs the graph structures corresponding to each target time period The corresponding graph structure Under this circumstance, determine the listed company nodes and target enterprise nodes in each graph structure and collect multi-modal data corresponding to each listed company node and target enterprise node through the server 300. For example, the processor 200 determines the listed company node in the graph structure The listed company node Then the processor 200 collects multi-modal data corresponding to each listed company node and the target enterprise node through the server 300. Further, the processor 200 determines the multi-modal feature vectors corresponding to each listed company node and the target enterprise node respectively based on the multi-modal data corresponding to the listed company node and the target enterprise node Similarly, the processor 200 can determine the multi-modal feature vectors corresponding to each listed company node and the target enterprise node in the graph structure The multi-modal feature vectors corresponding to each listed company node and the graph structure The multi-modal feature vectors corresponding to each listed company node and the target enterprise node in the graph structure Thus, from the above, it can be known that the processor 200 can determine the multi-modal feature vectors corresponding to the listed company nodes and the target enterprise nodes in each graph structure The multi-modal feature vectors corresponding to each listed company node

[0051] In addition, when the processor 200 constructs the graph structures corresponding to each target time period The corresponding graph structure In the case of, the structural feature vectors corresponding thereto can be determined based on the structural features of the non-listed company nodes and / or individual nodes in each graph structure. Among them, the structural features of the non-listed company nodes and / or individual nodes in each graph structure can be, for example, node degree, weighted degree, second-degree, joint degree, relative degree, and shortest path. For example, the processor 200 determines the graph structure in the non-listed company nodes Then the processor 200 is based on the non-listed company nodes in the graph structure to determine the structural feature vector corresponding to the non-listed company nodes Similarly, the processor 200 can determine the graph structure in each non-listed company node corresponding structural feature vector and the graph structure in each non-listed company node corresponding structural feature vector

[0052] Based on the same operations as above, the processor 200 can also determine within the graph structure the structural feature vectors corresponding to each individual node Thus, the processor 200 can determine the graph structure in, the structural feature vectors corresponding to each non-listed company node and the structural feature vectors corresponding to each individual node The above relevant content will be described in detail later, so it will not be elaborated here.

[0053] Thus, the processor 200 can determine the multi-modal feature vectors corresponding to the listed company nodes and the target enterprise nodes in multiple graph structures the structural feature vectors corresponding to the non-listed company nodes and the structural feature vectors corresponding to the individual nodes (i.e., the first feature vector) (S304). It should be noted that the first feature vector in this embodiment is used to indicate the initial feature vector input to the multiple first graph neural network models and the multiple second graph neural network models.

[0054] ​​​​​And when the processor 200 determines the first feature vectors corresponding to the respective nodes in the multiple graph structures, it further passes the first feature vectors of all the nodes through a learnable embedding layer and converts them into learnable embeddings. That is, for the listed company nodes and the multi-modal feature vectors corresponding to the target enterprise nodes and the unlisted company nodes the corresponding structural feature vectors and the personal nodes the corresponding structural feature vectors are mapped to a space of the same dimension to make their dimensions the same.

[0055] After that, when the processor 200 constructs the graph structures corresponding to the respective target time periods and determines the first feature vectors corresponding to the nodes in the respective graph structures, the processor 200 compares the graph structures of adjacent target time periods and determines the difference information between the graph structures, and generates corresponding multiple changed graph structures based on the difference information (S306). For example, the processor 200 determines the graph structure corresponding to the target time period and the graph structure corresponding to the target time period Then, the processor 200 compares the graph structure and the graph structure and determines the difference information between the two. The difference information includes the node change information and edge change information of the graph structure and the graph structure . The node change information includes the addition or reduction of nodes between the graph structure and the graph structure , and the edge change information includes the addition or reduction of edges between the graph structure and the graph structure . Finally, the processor 200 generates a changed graph structure and the graph structure according to the difference information between them. Similarly, the processor 200 can generate a changed graph structure and the graph structure according to the difference information between them. Thus, the processor 200 can determine the changed graph structure corresponding to the target time period and the changed graph structure corresponding to the target time period

[0056] In addition, since the target time period is the initial target time period, at the target time period Previously, there was no corresponding graph structure, so the graph structure could not be compared with the graph structure of the previous target period, and thus there was no change graph structure corresponding to the target period .

[0057] Finally, when the processor 200 determines the graph structure corresponding to the target period and the change graph structure corresponding to the target period , multiple graph structures and multiple change graph structures are input into a pre-trained fraud prediction model, and based on the fraud probability output by the fraud prediction model, it is determined whether the target enterprise has fraud behavior (S308). For example, when the processor 200 inputs multiple graph structures and multiple change graph structures into the fraud prediction model, the fraud prediction model outputs a fraud probability Z x corresponding to the target enterprise. Then, the processor 200 determines the magnitude relationship between the fraud probability Z x corresponding to the target enterprise and a pre-set fraud probability threshold Z. And when the fraud probability Z x corresponding to the target enterprise is greater than or equal to the fraud probability threshold Z, it indicates that the target enterprise has fraud behavior. Otherwise, it indicates that the target enterprise does not have fraud behavior.

[0058] As described in the background art, the existing method of using a fraud prediction model to predict whether a target enterprise has potential fraud risks has certain defects. First, since the data input into the fraud prediction model is usually single-modal data (for example, financial statement data corresponding to the target enterprise, etc.), and the information contained in single-modal data is not comprehensive enough, when using the fraud prediction model to predict whether the target enterprise has fraud behavior, the predicted result lacks accuracy.

[0059] Second, since the data input into the fraud prediction model is usually only limited to the internal data of the target enterprise, and does not consider the position of the target enterprise in the business ecosystem (related to the target enterprise and including multiple other enterprises), and the interaction between the target enterprise and other enterprises in the business ecosystem, the fraud prediction model cannot discover potential abnormal patterns and fraud behaviors of the target enterprise, and thus the fraud prediction model cannot accurately predict whether the target enterprise has fraud behavior.

[0060] III. Since the fraudulent acts of the target enterprise are often the result of years of careful planning and last for several years, while the existing fraud prediction models can often only judge whether the target enterprise has fraudulent acts based on the data of the current period or adjacent periods of the target enterprise, and cannot predict the fraud of the target enterprise based on the data of the target enterprise over a long period of time, the results finally predicted by the fraud prediction models lack accuracy.

[0061] IV. In addition, since the fraud prediction model does not consider the changes in the relationship between the target enterprise and other enterprises in each period, the fraud prediction model cannot discover and identify the abnormal transaction patterns between the target enterprise and other enterprises based on the changes in the relationship between the target enterprise and other enterprises, so that the fraud prediction model cannot discover the potential fraud of the target enterprise, and further leads to the lack of accuracy of the results finally predicted by the fraud prediction model.

[0062] In view of this, the present application provides a financial fraud prediction method based on multi-modal graph learning. And because the present application takes into account the influence of the position and interaction of the target enterprise in its associated business ecosystem on fraud behavior prediction, the present application does not simply predict whether the target enterprise has fraud behavior based on the internal data corresponding to the target enterprise, but constructs a graph structure based on the target enterprise and the objects having an associated relationship with the target enterprise, and predicts the fraud behavior of the target enterprise based on the graph structure and a pre-trained fraud prediction model, which helps the fraud prediction model discover the potential abnormal patterns and fraud behaviors of the target enterprise, and further enables the fraud prediction model to accurately predict the fraud behavior of the target enterprise.

[0063] Furthermore, the present application also takes into account that the financial fraud behavior of the target enterprise is often the result of years of careful planning. Therefore, the present application constructs graph structures corresponding to multiple different target periods respectively, and dynamically predicts the fraud behavior of the target enterprise based on the long-term data information of the target enterprise. In addition, the present application generates multiple changed graph structures based on the difference information between the graph structures of adjacent target periods, so that the fraud prediction model can discover and identify abnormal associated relationships and hidden fraud behaviors according to the changes of the target enterprise over a long period of time.

[0064] Thus, it achieves the technical effect of being able to comprehensively and accurately predict the fraud behavior of the target enterprise. Furthermore, it solves the technical problem in the prior art that the fraud prediction model cannot comprehensively and accurately predict the fraud behavior of the target enterprise.

[0065] In addition, in the graph structure of the present application, the initial feature vector corresponding to the node of the target enterprise is a multi-modal feature vector generated based on multi-modal data. Therefore, the present application comprehensively utilizes the data information corresponding to the target enterprise and further improves the accuracy of the result finally output by the fraud prediction model.

[0066] Optionally, the fraud prediction model includes multiple first graph neural network models, multiple second graph neural network models, and a fraud prediction network structure. The operation of inputting multiple graph structures and multiple changed graph structures into the pre-trained fraud prediction model and determining whether there is fraud behavior of the target enterprise based on the fraud probability output by the fraud prediction model includes: inputting multiple graph structures into the first graph neural network model respectively, and determining the second feature vectors corresponding to each node in each graph structure; inputting multiple changed graph structures into the second graph neural network model, and determining the third feature vectors corresponding to each node in each changed graph structure; and determining whether there is fraud behavior of the target enterprise based on multiple second feature vectors and multiple third feature vectors and using the fraud prediction network structure.

[0067] Specifically, Figure 4 is a schematic diagram of multiple graph structures, multiple changed graph structures, and the fraud prediction model according to the embodiments of the present application. Refer to Figure 4 As shown, the fraud prediction model includes multiple first graph neural network models and multiple second graph neural network models. And in this embodiment, multiple first graph neural network models and multiple second graph neural network models can be, for example, HGT graph neural network models.

[0068] And when the processor 200 determines multiple graph structures in the case of, each graph structure corresponding to the target time period is input into the first graph neural network model respectively, and the second feature vectors corresponding to each node are determined. That is, the second feature vectors corresponding to the listed company node and the target enterprise node the second feature vectors corresponding to the unlisted company node

[0069] Similarly, when the processor 200 determines multiple changed graph structures in the case of, each changed graph structure corresponding to the target time period is input into the second graph neural network model respectively, and the third feature vectors corresponding to each node are determined. That is, the third feature vectors corresponding to the listed company node and the target enterprise node and a third eigenvector corresponding to the individual node

[0070] Finally, the processor 200 determines whether the target enterprise has fraudulent behavior based on the multiple second eigenvectors, the multiple third eigenvectors, and the fraud prediction network structure.

[0071] Optionally, the fraud prediction network structure includes an LSTM network and a multi-layer perceptron. Based on the multiple second eigenvectors and the multiple third eigenvectors, and using the fraud prediction network structure, the operation of determining whether the target enterprise has fraudulent behavior includes: concatenating the multiple second eigenvectors and the multiple third eigenvectors in each target time period respectively, and generating a fourth eigenvector corresponding to each target time period; inputting the fourth eigenvector corresponding to each target time period into the LSTM network, and determining a fifth eigenvector corresponding to the last LSTM cell in the LSTM network, where the LSTM network includes multiple LSTM cells; inputting the fifth eigenvector into the multi-layer perceptron, and outputting a fraud probability corresponding to the target enterprise; and determining whether the target enterprise has fraudulent behavior based on the fraud probability. Further optionally, it further includes: in the case where the current target time period is the initial target time period among the multiple target time periods, concatenating the multiple second eigenvectors corresponding to the current target time period and a mask, and generating a fourth eigenvector.

[0072] Specifically, referring to Figure 4 as shown, the fraud prediction model further includes a fraud prediction network structure, where the fraud prediction network structure includes an LSTM network and a multi-layer perceptron.

[0073] Thus, when the fraud prediction network structure receives the multiple second eigenvectors corresponding to each graph structure in each target time period, and the multiple third eigenvectors corresponding to each changed graph structure in each target time period, it concatenates the multiple second eigenvectors and the multiple third eigenvectors in each target time period respectively, and generates a fourth eigenvector corresponding to each target time period.

[0074] For example, the fraud prediction network structure receives the multiple second eigenvectors corresponding to the graph structure in the target time period (wherein, including the multi-modal eigenvectors corresponding to the listed company node and the target enterprise node the structural eigenvector corresponding to the non-listed company node and the structural eigenvector corresponding to the individual node ). And the fraud prediction network structure receives the changed graph structure corresponding to the target time period in the target time period A corresponding plurality of third feature vectors (including third feature vectors corresponding to listed company nodes and target enterprise nodes) Third feature vectors corresponding to unlisted company nodes And third feature vectors corresponding to individual nodes ). Further, the fraud prediction network structure will be related to the target time period The graph structure within A corresponding plurality of second feature vectors, and the changed graph structure corresponding to the target time period Within A corresponding plurality of third feature vectors are concatenated, and a fourth feature vector corresponding to the target time period Is generated

[0075] Similarly, the fraud prediction network structure will be related to the target time period The graph structure within A corresponding plurality of second feature vectors, and the changed graph structure corresponding to the target time period Within A corresponding plurality of third feature vectors are concatenated, and a fourth feature vector corresponding to the target time period Is generated

[0076] In addition, since there is no changed graph structure corresponding to the initial target time period among the multiple target time periods, a all-zero vector (i.e., a mask) is introduced in this embodiment as the third feature vector corresponding to the changed graph structure of the initial target time period, and the all-zero vector is concatenated with the plurality of second feature vectors corresponding to the initial target time period, thereby generating a fourth feature vector corresponding to the initial target time period. For example, the fraud prediction network structure will be related to the target time period The graph structure within A corresponding plurality of second feature vectors, and the all-zero vector are concatenated, and a fourth feature vector corresponding to the target time period Is generated

[0077] Thus, based on the above method, the fraud prediction network structure can generate a fourth feature vector corresponding to the target time period Is generated

[0078] After that, the fraud prediction network structure inputs the fourth feature vectors corresponding to each target time period into the LSTM network, and determines a fifth feature vector corresponding to the last LSTM unit in the LSTM network. The LSTM network includes a plurality of LSTM units. For example, the fraud prediction network structure will be related to the target time period The corresponding fourth feature vector Input it into the LSTM network and determine the fifth feature vector U output by the last LSTM unit in the LSTM network x 。

[0079] Further, the fraud prediction network structure inputs the fifth feature vector U x into a multi-layer perceptron (MLP), and finally outputs the fraud probability Z corresponding to the target enterprise x 。Finally, the processor 200 determines whether the target enterprise has fraud behavior based on the determined fraud probability Z corresponding to the target enterprise x 。

[0080] Since the fifth feature vector output by the last LSTM unit in the LSTM network contains the fusion information of multi-modal data (corresponding to the target enterprise and the listed companies associated with the target enterprise), as well as the dynamic relationship pattern in the graph structure (i.e., the changes of the graph structure in each target time period), the fraud prediction model can help identify abnormal transaction patterns and discover possible hidden fraud behaviors, so that the fraud prediction model can comprehensively and accurately predict whether the target enterprise has fraud behavior

[0081] Optionally, compare the graph structures of adjacent target time periods and determine the difference information between the graph structures. The operations of generating corresponding multiple changed graph structures based on the difference information include: determining the node change information between the graph structures of adjacent target time periods, where the node change information is used to indicate the addition or reduction of nodes; determining the edge change information between the graph structures of adjacent target time periods, where the edge change information is used to indicate the addition or reduction of edges; and generating multiple changed graph structures based on the node change information and the edge change information between the graph structures of adjacent target time periods

[0082] Specifically, as shown in Figure 4 Before the processor 200 inputs the changed graph structures corresponding to each target time period into multiple second graph neural networks, the processor 200 also needs to pre-generate the changed graph structures corresponding to each target time period

[0083] For example, the processor 200 determines the graph structure corresponding to the target time period and the graph structure corresponding to the target time period Then, the processor 200 compares the graph structure and the graph structure and determines the difference information between the two. The difference information includes the graph structure and the graph structure node change information and edge change information

[0084] Among them, the node change information includes the graph structure and the graph structure the addition or reduction of nodes between. For example, the addition of nodes can be during the target period a newly established company or an individual newly included in the research scope. For example, the reduction of nodes can be during the target period a bankrupt company or a company whose affiliated relationship is cancelled. Edge change information includes the graph structure and the graph structure the addition or reduction of edges between. For example, the addition of edges can be during the target period a newly established investment relationship or a newly established cooperation relationship, etc. For example, the reduction of edges can be during the target period an investment relationship that is cancelled, etc.

[0085] Finally, the processor 200 generates a changed graph structure according to the difference information between the graph structure and the graph structure Similarly, the processor 200 can generate a changed graph structure according to the difference information between the graph structure

[0086] Similarly, the processor 200 can generate a changed graph structure according to the difference information between the graph structure and the graph structure Thus, the processor 200 can determine the changed graph structure corresponding to the target period and the changed graph structure corresponding to the target period and the changed graph structure corresponding to the target period and the changed graph structure corresponding to the target period

[0087] It should be noted that in the changed graph structure

[0088] the types of nodes are listed companies, non-listed companies, and individuals, while the types of edges are the addition and reduction of edges. In addition, since the target period is the initial target period, there is no corresponding graph structure before the target period Therefore, the graph structure cannot be compared with the graph structure of the previous target period, and thus there is no changed graph structure corresponding to the target period

[0089]

[0090] Thus, by generating a changed graph structure corresponding to the change situation of the association relationship for each target period based on the graph structure corresponding to each target period, the technical effect of being able to provide a necessary basis for the subsequent fraud prediction model to identify abnormal transaction patterns of target enterprises and discover possible hidden fraud behaviors is achieved.

[0090] Optionally, the operation of determining the first feature vector corresponding to each node in each graph structure includes: collecting multimodal data corresponding to the listed company node and the target enterprise node in each target time period, and determining the multimodal feature vector corresponding to the multimodal data. Further optionally, the operation of collecting multimodal data corresponding to the listed company node in each target time period and determining the multimodal feature vector corresponding to the multimodal data includes: collecting multimodal data corresponding to the listed company node, and using the attention mechanism to determine the weight values corresponding to different modal data; and based on the weight values corresponding to different modal data, fusing the multimodal data and determining the multimodal feature vector corresponding to the multimodal data.

[0091] Specifically, Figure 5 Schematic diagram of multimodal data and multimodal vectors according to an embodiment of the present application. Figure 5 As shown, first, the processor 200 collects multimodal data corresponding to the listed company node and the target enterprise through the server 300. In this embodiment, the multimodal data includes, for example, financial statements corresponding to the numerical modality, corporate announcements and news reports corresponding to the text modality, telephone audio and conference audio corresponding to the sound modality, speeches of corporate managers corresponding to the language modality, and cluster diagrams corresponding to the network modality.

[0092] 1. For financial statements corresponding to numerical modalities, the processor 200 extracts financial ratios from the financial statements. The financial statements include, for example, balance sheets, income statements, and cash flow statements. Then, the processor 200 removes abnormal data and missing data from the financial ratios, and standardizes the data after removal, so that the data of different indicators are comparable. Finally, the processor 200 obtains the financial ratio data after removal and annotation. Finally, the processor 200 uses a multi-layer perceptron to deeply mine the embedded information of the financial ratio data, and maps the financial ratio data to a dimension that is unified with other modal data, and obtains a feature vector corresponding to the numerical modality. Among them, m represents the unified dimension.

[0093] II. For enterprise announcements and news reports corresponding to the text modality, the processor 200 first preprocesses the data corresponding to the text modality. Among them, the preprocessing steps include: First, clean the data corresponding to the text modality, remove irrelevant characters, and standardize the text format. Then, split the text into multiple sentences, and perform word segmentation on each sentence to convert it into a token sequence of length n. Among them, each token is assigned a Token embedding, a Segment embedding, and a Postion embedding. The Token embedding is used to represent different lexical tokens. The Segment embedding is used to distinguish different sentences. The Postion embedding is used to represent the position of the token in the sentence. Thus, a Token Embedding matrix E = [E1, E2,..., E e can be generated, where j = 1 to e. And E j represents the embedding vector of the j-th token. Further, input the Token Embedding matrix E into the BERT model, and the BERT model outputs the feature vector corresponding to the text modality

[0094] III. For telephone audio and conference audio corresponding to the voice modality, the processor 200 uses Praat acoustic software to extract the original acoustic features corresponding to the speaker from the audio text. Thus, a feature vector corresponding to the voice modality is generated Among them, the original acoustic features include, for example, the mean and standard deviation of the fundamental frequency, the jitter and amplitude perturbation of the fundamental frequency, the mean and standard deviation of the harmonic-to-noise ratio, and the proportion of voiced sounds.

[0095] IV. For the speeches of enterprise managers corresponding to the language modality, use LIWC (i.e., Linguistic Inquiry and Word Count) software to deeply analyze the speeches of the speakers, so as to quantify the language features in the speeches. Specifically, use LIWC software to extract and calculate the following indicators: the proportion of the first-person singular and plural pronouns used by the speaker, the usage frequency of impersonal pronouns, the number of words expressing positive and negative emotions, and the relative proportion of words indicating certainty and tentativeness. Explore the possible hidden fraud intentions or signs of information manipulation of the speaker in communication from the perspective of vocabulary usage habits and semantic expressions, and finally obtain the feature vector corresponding to the language modality

[0096] V. Since fraudulent enterprises often hide in a fraud "group" or "cluster", and there are significant differences between the internal association situations of fraud "groups" or fraud "clusters" and those of normal enterprise clusters, the prediction of fraud behavior by abnormal association groups is often very important.

[0097] Based on the above, in this embodiment, a subgraph memory network is first constructed. Specifically, the target enterprise is used as the central node, and the H-order neighbor nodes around the target enterprise are used as a subgraph.

[0098] The subgraph embedding vector L corresponding to the subgraph consists of three parts: graph walk embedding, graph theory method embedding, and organizational information embedding. Specifically, graph walk embedding means starting a random walk from the node corresponding to the target enterprise and encoding the walk path as a vector. Graph theory method embedding calculates the degree distribution of nodes in the subgraph, the clustering coefficient of nodes in the subgraph, the shortest path length between nodes in the subgraph, and specific structural features of the subgraph. Organizational information embedding calculates the number of surrounding investors corresponding to the target enterprise node, the scale and quantity of adjacent enterprises, and the connection information of related enterprises, etc.

[0099] On this basis, the subgraph memory network is constructed as follows:

[0100]

[0101] Among them, Emb represents mapping and embedding the original data, and L u represents the embedding vector corresponding to the u-th subgraph, and G″ x,u represents the u-th subgraph, represents the v-th graph structure.

[0102] Furthermore, the information of the K1 subgraphs most relevant to the target enterprise node is screened out and aggregated into the information of the target enterprise node. Specifically, first calculate the relevance between the target enterprise node and each subgraph in the K1 subgraphs. Then, the financial ratio features of the nodes in the K2 most relevant subgraphs are weighted and summed as the final output result. The specific calculation formula is as follows:

[0103] p u = softmax(AMN T ×Emb(L))

[0104] M 0 = TopK(p u ) × TopK(H u )

[0105] Among them, p u represents the similarity probability corresponding to the target node u, H u represents the financial ratio data corresponding to the target node u, and M 0 represents the feature vector corresponding to the network modality. Among them,

[0106] After that, the processor 200 uses the attention mechanism to determine the weight values corresponding to data of different modalities. Specifically, in order to coordinate the prediction capabilities of the fraud prediction model for different modality data and achieve the fusion between different modalities, the present application uses the attention mechanism to calculate the weight values corresponding to different modality data respectively. The calculation formula is as follows:

[0107] a f +a t +a l +a s +a o =1

[0108]

[0109] Among them, a f represents the weight corresponding to the numerical modality, a c represents the weight corresponding to the text modality, a l represents the weight corresponding to the voice modality, a s represents the weight corresponding to the language modality, a o represents the weight corresponding to the network modality.

[0110] Finally, the processor 200 fuses the data corresponding to different modalities according to the weight values calculated above, and obtains the multi-modal feature vector M corresponding to the multi-modal data x ={M x,1 ,M x,2 ,...M x,m}.

[0111] Thus, by using the attention mechanism to fuse the collected multi-modal data and using the fused data as the data input to the fraud prediction model, the technical effect of being able to more comprehensively utilize the complementary multi-modal information to improve the accuracy of the prediction results of the fraud prediction model is achieved.

[0112] In addition, it is worth noting that the processor 200 also needs to pre-train the fraud prediction model before using the fraud prediction model to predict fraud for the target enterprise.

[0113] The steps for the processor 200 to train the fraud prediction model include:

[0114] First, the processor 200 determines the objects associated with the sample enterprise within each sample period and constructs multiple graph structure samples corresponding to each sample period based on the sample enterprise and the objects associated with the sample enterprise In this embodiment, t = 3. That is, the processor 200 determines the sample period and the sample period and the sample period The corresponding graph structure For example, the processor 300 constructs a graph structure corresponding to the sample period The graph structure sample corresponding to the sample period The sample period The graph structure sample corresponding to the sample period And the graph structure sample corresponding to the target period The graph structure sample corresponding to the target period In addition, in this embodiment, if the target period is the whole year of 2020, the sample period For example, it can be the whole year of 2017, the sample period For example, it can be the whole year of 2018, the sample period For example, it can be the whole year of 2019. That is, the target period is the period to be predicted by the fraud prediction model, and the sample period is the period used to train the fraud prediction model.

[0115] Then, the processor 200 collects the multimodal data corresponding to the sample enterprises and the multimodal data corresponding to the listed companies associated with the sample enterprises within each sample period through the server 300. For example, the processor 200 collects the multimodal data corresponding to the sample enterprises and the multimodal data corresponding to the listed companies associated with the sample enterprises within the sample period through the server 300.

[0116] Similarly, the processor 200 collects the multimodal data corresponding to the sample enterprises and the multimodal data corresponding to the listed companies associated with the sample enterprises within the sample period by analogy, the processor 200 collects the multimodal data corresponding to the sample enterprises and the multimodal data corresponding to the listed companies associated with the sample enterprises within the sample period by analogy, the processor 200 collects the multimodal data corresponding to the sample enterprises and the multimodal data corresponding to the listed companies associated with the sample enterprises within the sample period.

[0117] Among them, in this embodiment, the multimodal data corresponding to the sample enterprises and the associated listed companies includes, for example, financial statements corresponding to the numerical modality, corporate announcements and news reports corresponding to the text modality, telephone audio and conference audio corresponding to the sound modality, speeches of corporate managers corresponding to the language modality, and cluster diagrams corresponding to the network modality.

[0118] After the processor 200 collects the multimodal data corresponding to the sample enterprises and the multimodal data corresponding to the listed companies associated with the sample enterprises in different sample periods it further processes the data of each modality, such as unifying the dimensions and splicing, so as to generate a multimodal feature vector corresponding to the sample enterprises and a multimodal feature vector corresponding to the listed companies associated with the sample enterprises.

[0119] In addition, when the processor 200 determines the graph structure samples corresponding to each sample period , the corresponding structure feature vectors can be determined based on the structural features of the non-listed companies and / or individuals associated with each sample enterprise in the graph structure samples.

[0120] Thus, based on the above-mentioned content, the processor 200 can determine, for each graph structure sample , the multi-modal feature vectors corresponding to the sample enterprises, the multi-modal feature vectors corresponding to the listed companies, the structure feature vectors corresponding to the non-listed companies, and the structure feature vectors corresponding to the individuals.

[0121] After that, the processor 200 compares the graph structure samples of adjacent target periods and determines the difference information between the graph structure samples, and generates corresponding multiple modified graph structures based on the difference information. For example, the processor 200 determines the graph structure sample corresponding to the sample period and the graph structure sample corresponding to the sample period Then, the processor 200 compares the graph structure sample and the graph structure and determines the difference information between the two. The difference information includes the node change information and the edge change information of the graph structure sample and the graph structure sample Finally, the processor 200 generates a modified graph structure sample according to the difference information between the graph structure sample and the graph structure sample Similarly, the processor 200 can generate a modified graph structure sample according to the difference information between the graph structure sample and the graph structure sample Thus, the processor 200 can determine the modified graph structure sample corresponding to the sample period and the modified graph structure sample corresponding to the sample period

[0122] In addition, since the sample period is the initial target period, there is no corresponding graph structure sample before the sample period , so the graph structure sample cannot be compared with the graph structure sample of the previous sample period, and thus there is no modified graph structure sample corresponding to the sample period .

[0123] Finally, when the processor 200 determines the sample period Corresponding graph structure sample and the sample time period Corresponding changed graph structure sample In the case of multiple graph structure samples and multiple changed graph structure samples are used as input samples for training a pre - constructed fraud prediction model, and the true fraud status of the sample enterprise is used as the output sample for training the pre - constructed fraud prediction model, thereby training the fraud prediction model. Among them, the fraud prediction model includes multiple first graph neural networks, multiple second graph neural networks, and a fraud prediction network structure. And among them, the fraud prediction network structure includes an LSTM network (including multiple LSTM cells) and a multi - layer perceptron.

[0124] In addition, in order to make the trained fraud prediction model have a higher accuracy rate, the processor 200 uses the graph structure sample and the changed graph structure sample to generate a training set and a test set. Select common evaluation metrics such as accuracy rate, recall rate, F1 - value, etc. to evaluate the performance of the fraud prediction model. Consider using multi - modal specific evaluation metrics, such as multi - modal consistency metrics, etc., to measure the fusion effect between different modal data, and according to the evaluation results, adjust the structure and parameters of the fraud prediction model, and select different feature fusion methods and model integration strategies. Use techniques such as cross - validation and grid search for model optimization.

[0125] Thus, according to the first aspect of this embodiment, the technical effect of being able to accurately and comprehensively predict the fraud behavior of the target enterprise is achieved.

[0126] In addition, as shown in Figure 1 According to the second aspect of this embodiment, a storage medium is provided. The storage medium includes a stored program, wherein when the program runs, the method described in any one of the above is executed by a processor.

[0127] Thus, according to this embodiment, the technical effect of being able to accurately and comprehensively predict the fraud behavior of the target enterprise is achieved.

[0128] It should be noted that for the foregoing method embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should know that the present invention is not limited by the described action sequence, because according to the present invention, certain steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily essential to the present invention.

[0129] Through the description of the above embodiments, those skilled in the art can clearly understand that the method according to the above embodiments can be implemented by means of software plus a necessary general hardware platform. Of course, it can also be implemented by hardware, but in many cases, the former is a better implementation manner. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art can be embodied in the form of a software product. The computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), and includes several instructions for causing a terminal device (which may be a mobile phone, a computer, a server, or a network device, etc.) to execute the methods described in various embodiments of the present invention.

[0130] Embodiment 2

[0131] Figure 6 Fig. 6 shows a financial fraud prediction device 600 based on multi-modal graph learning according to the present embodiment. The device 600 corresponds to the method according to Embodiment 1. As shown in Fig. 6, the device 600 includes: a graph structure construction module 610, configured to use the target enterprises within each target time period and the objects associated with the target enterprises as nodes, and use the association relationships between the target enterprises and each object as edges to construct a plurality of graph structures corresponding to each target time period, where the objects include listed companies, unlisted companies, and / or individuals; a first feature vector determination module 620, configured to determine a first feature vector corresponding to each node in the plurality of graph structures, where the first feature vector includes a multi-modal feature vector corresponding to the listed company node and the target enterprise node, and a structural feature vector corresponding to the unlisted company node and the individual node; a changed graph structure generation module 630, configured to compare the graph structures of adjacent target time periods and determine the difference information between the graph structures, and generate corresponding changed graph structures based on the difference information, where the difference information includes node change information and edge change information; and a fraud prediction module 640, configured to input the plurality of graph structures and the plurality of changed graph structures into a pre-trained fraud prediction model, and determine whether the target enterprise has fraudulent behavior based on the fraud probability output by the fraud prediction model.

[0132] Optionally, the fraud prediction model includes a plurality of first graph neural network models, a plurality of second graph neural network models, and a fraud prediction network structure. The fraud prediction module 640 includes: a second feature vector determination module, configured to input the plurality of graph structures into the first graph neural network models respectively, and determine a second feature vector corresponding to each node in each graph structure; a third feature vector determination module, configured to input the plurality of changed graph structures into the second graph neural network models, and determine a third feature vector corresponding to each node in each changed graph structure; and a fraud prediction sub-module, configured to determine whether the target enterprise has fraudulent behavior based on the plurality of second feature vectors and the plurality of third feature vectors, and by using the fraud prediction network structure.

[0133] Optionally, the fraud prediction network structure includes an LSTM network and a multi-layer perceptron. The fraud prediction sub-module includes: a fourth feature vector generation module, configured to splice multiple second feature vectors and multiple third feature vectors within each target time period respectively, and generate a fourth feature vector corresponding to each target time period; a fifth feature vector generation module, configured to input the fourth feature vector corresponding to each target time period into the LSTM network, and determine a fifth feature vector corresponding to the last LSTM cell in the LSTM network, where the LSTM network includes multiple LSTM cells; a fraud probability output module, configured to input the fifth feature vector into the multi-layer perceptron, and output a fraud probability corresponding to the target enterprise; and a fraud behavior determination module, configured to determine whether the target enterprise has a fraud behavior based on the fraud probability.

[0134] Optionally, the apparatus 600 further includes: a mask splicing module, configured to splice multiple second feature vectors corresponding to the current target time period and a mask when the current target time period is the initial target time period among multiple target time periods, and generate a fourth feature vector.

[0135] Optionally, the changed graph structure generation module 630 includes: a node change information determination module, configured to determine node change information between the graph structures of adjacent target time periods, where the node change information is used to indicate the addition or reduction of nodes; an edge change information determination module, configured to determine edge change information between the graph structures of adjacent target time periods, where the edge change information is used to indicate the addition or reduction of edges; and a changed graph structure generation sub-module, configured to generate multiple changed graph structures based on the node change information and the edge change information between the graph structures of adjacent target time periods.

[0136] Optionally, the first feature vector determination module 620 includes: a multi-modal feature vector determination module, configured to collect multi-modal data corresponding to the listed company node and the target enterprise node within each target time period, and determine a multi-modal feature vector corresponding to the multi-modal data.

[0137] Optionally, the multi-modal feature vector determination module includes: a weight value determination module, configured to collect multi-modal data corresponding to the listed company node and the target enterprise, and determine weight values corresponding to different modal data by using an attention mechanism; and a multi-modal feature vector determination sub-module, configured to fuse the multi-modal data based on the weight values corresponding to different modal data, and determine a multi-modal feature vector corresponding to the multi-modal data.

[0138] Therefore, according to this embodiment, the technical effect of being able to accurately and comprehensively predict the fraud behavior of the target enterprise is achieved.

[0139] Embodiment 3

[0140] Figure 7 shows a financial fraud prediction device 700 based on multi-modal graph learning according to this embodiment, and the device 700 corresponds to the method according to Embodiment 1. Refer to Figure 7 As shown, the device 700 includes: a processor 710; and a memory 720, connected to the processor 710, for providing instructions for the processor 710 to process the following steps: taking the target enterprises within each target period and the objects associated with the target enterprises as nodes, and taking the association relationships between the target enterprises and each object as edges, to construct a plurality of graph structures respectively corresponding to each target period, where the objects include listed companies, unlisted companies, and / or individuals; determining first feature vectors corresponding to each node in the plurality of graph structures, where the first feature vectors include multi-modal feature vectors corresponding to listed company nodes and target enterprise nodes, and structural feature vectors corresponding to unlisted company nodes and individual nodes; comparing the graph structures of adjacent target periods and determining the difference information between the graph structures, and generating corresponding plurality of changed graph structures based on the difference information, where the difference information includes node change information and edge change information; and inputting the plurality of graph structures and the plurality of changed graph structures into a pre-trained fraud prediction model, and judging whether the target enterprise has fraud behavior based on the fraud probability output by the fraud prediction model.

[0141] Optionally, the fraud prediction model includes a plurality of first graph neural network models, a plurality of second graph neural network models, and a fraud prediction network structure. The operation of inputting the plurality of graph structures and the plurality of changed graph structures into a pre-trained fraud prediction model and judging whether the target enterprise has fraud behavior based on the fraud probability output by the fraud prediction model includes: inputting the plurality of graph structures into the first graph neural network models respectively, and determining second feature vectors corresponding to each node in each graph structure; inputting the plurality of changed graph structures into the second graph neural network models, and determining third feature vectors corresponding to each node in each changed graph structure; and judging whether the target enterprise has fraud behavior based on the plurality of second feature vectors and the plurality of third feature vectors, and using the fraud prediction network structure.

[0142] Optionally, the fraud prediction network structure includes an LSTM network and a multi-layer perceptron. Based on multiple second feature vectors and multiple third feature vectors, and using the fraud prediction network structure, the operation of determining whether a target enterprise has fraudulent behavior includes: concatenating multiple second feature vectors and multiple third feature vectors within each target time period respectively, and generating a fourth feature vector corresponding to each target time period; inputting the fourth feature vector corresponding to each target time period into the LSTM network, and determining a fifth feature vector corresponding to the last LSTM cell in the LSTM network, where the LSTM network includes multiple LSTM cells; inputting the fifth feature vector into the multi-layer perceptron, and outputting a fraud probability corresponding to the target enterprise; and based on the fraud probability, determining whether the target enterprise has fraudulent behavior.

[0143] Optionally, the apparatus 700 further includes: in the case where the current target time period is the initial target time period among multiple target time periods, concatenating multiple second feature vectors corresponding to the current target time period and a mask, and generating a fourth feature vector.

[0144] Optionally, the operation of comparing the graph structures of adjacent target time periods and determining the difference information between the graph structures, and generating corresponding multiple changed graph structures based on the difference information includes: determining the node change information between the graph structures of adjacent target time periods, where the node change information is used to indicate the addition or reduction of nodes; determining the edge change information between the graph structures of adjacent target time periods, where the edge change information is used to indicate the addition or reduction of edges; and generating multiple changed graph structures based on the node change information and the edge change information between the graph structures of adjacent target time periods.

[0145] Optionally, the operation of determining the first feature vector corresponding to each node in each graph structure includes: collecting multi-modal data corresponding to the listed company node and the target enterprise node within each target time period, and determining the multi-modal feature vector corresponding to the multi-modal data.

[0146] Optionally, the operation of collecting multi-modal data corresponding to the listed company node within each target time period, and determining the multi-modal feature vector corresponding to the multi-modal data includes: collecting multi-modal data corresponding to the listed company node and the target enterprise, and using an attention mechanism to determine the weight values corresponding to different modal data; and based on the weight values corresponding to different modal data, fusing the multi-modal data, and determining the multi-modal feature vector corresponding to the multi-modal data.

[0147] Thus, according to this embodiment, the technical effect of being able to accurately and comprehensively predict the fraudulent behavior of the target enterprise is achieved.

[0148] The serial numbers of the above embodiments of the present invention are only for description, and do not represent the advantages and disadvantages of the embodiments.

[0149] In the above embodiments of the present invention, the descriptions of the various embodiments each have their own focuses. For the parts not elaborated in a certain embodiment, reference may be made to the relevant descriptions of other embodiments.

[0150] In the several embodiments provided by the present application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces. The indirect couplings or communication connections of the units or modules can be in electrical or other forms.

[0151] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0152] In addition, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above-mentioned integrated units can be implemented in the form of hardware or in the form of software functional units.

[0153] If the above-mentioned integrated units are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server or a network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The foregoing storage medium includes: USB flash drives, read-only memories (ROMs), random access memories (RAMs), mobile hard disks, magnetic disks or optical discs and other media that can store program codes.

[0154] The above are only the preferred embodiments of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present invention, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of the present invention.

Claims

1. A financial fraud prediction method based on multi-modal graph learning, characterized in that, Including: Taking the target enterprises within each target time period and the objects associated with the target enterprises as nodes, and taking the association relationships between the target enterprises and each object as edges, constructing a plurality of graph structures respectively corresponding to the target time periods, where the objects include listed companies, unlisted companies, and / or individuals; Determining a first feature vector corresponding to each node in the plurality of graph structures, where the first feature vector includes a multi-modal feature vector corresponding to the listed company node and the target enterprise node, and a structural feature vector corresponding to the unlisted company node and the individual node; Comparing the graph structures of adjacent target time periods and determining the difference information between the graph structures, and generating corresponding multiple changed graph structures based on the difference information, where the difference information includes node change information and edge change information; And Inputting the plurality of graph structures and the plurality of changed graph structures into a pre-trained fraud prediction model, and judging whether the target enterprise has fraud behavior based on the fraud probability output by the fraud prediction model.

2. The method according to claim 1, characterized in that The fraud prediction model includes a plurality of first graph neural network models, a plurality of second graph neural network models, and a fraud prediction network structure. The operation of inputting the plurality of graph structures and the plurality of changed graph structures into a pre-trained fraud prediction model and judging whether the target enterprise has fraud behavior based on the fraud probability output by the fraud prediction model includes: Inputting the plurality of graph structures into the first graph neural network models respectively, and determining a second feature vector corresponding to each node in each graph structure; Inputting the plurality of changed graph structures into the second graph neural network models, and determining a third feature vector corresponding to each node in each changed graph structure; and Judging whether the target enterprise has fraud behavior based on the plurality of second feature vectors and the plurality of third feature vectors and using the fraud prediction network structure.

3. The method according to claim 2, wherein The fraud prediction network structure includes an LSTM network and a multi-layer perceptron. The operation of judging whether the target enterprise has fraud behavior based on the plurality of second feature vectors and the plurality of third feature vectors and using the fraud prediction network structure includes: Concatenating the plurality of second feature vectors and the plurality of third feature vectors within each target time period respectively, and generating a fourth feature vector corresponding to each target time period; Inputting the fourth feature vector corresponding to each target time period into the LSTM network, and determining a fifth feature vector corresponding to the last LSTM unit in the LSTM network, where the LSTM network includes a plurality of LSTM units; Inputting the fifth feature vector into the multi-layer perceptron, and outputting a fraud probability corresponding to the target enterprise; and Judging whether the target enterprise has fraud behavior based on the fraud probability.

4. The method according to claim 3, wherein Further including: In the case that the current target time period is the initial target time period among the plurality of target time periods, concatenating the plurality of second feature vectors corresponding to the current target time period and a mask, and generating a fourth feature vector.

5. The method according to claim 1, wherein Compare the graph structures of adjacent target time periods and determine the difference information between the graph structures, and generate corresponding operations for a plurality of changed graph structures based on the difference information, including: Determine the node change information between the graph structures of the adjacent target time periods, where the node change information is used to indicate the addition or deletion of the nodes; Determine the edge change information between the graph structures of the adjacent target time periods, where the edge change information is used to indicate the addition or deletion of the edges; and Generate the plurality of changed graph structures based on the node change information and the edge change information between the graph structures of the adjacent target time periods.

6. The method according to claim 1, wherein The operation of determining the first feature vector corresponding to each node in each graph structure includes: Collect the multi-modal data corresponding to the listed company node and the target enterprise node within each target time period, and determine the multi-modal feature vector corresponding to the multi-modal data.

7. The method according to claim 6, characterized in that, The operation of collecting the multi-modal data corresponding to the listed company node within each target time period and determining the multi-modal feature vector corresponding to the multi-modal data includes: Collect the multi-modal data corresponding to the listed company node and the target enterprise, and use the attention mechanism to determine the weight values corresponding to different modal data; and Based on the weight values corresponding to the different modal data, fuse the multi-modal data, and determine the multi-modal feature vector corresponding to the multi-modal data.

8. A storage medium, characterized in that, The storage medium includes a stored program, wherein, when the program runs, the method according to any one of claims 1 to 7 is executed by a processor.

9. A financial fraud prediction device based on multi-modal graph learning, characterized in that, Including: A graph structure construction module, configured to use the target enterprise within each target time period and the objects associated with the target enterprise as nodes, and use the association relationship between the target enterprise and each object as edges to construct a plurality of graph structures corresponding to each target time period respectively, where the objects include listed companies, unlisted companies, and / or individuals; A first feature vector determination module, configured to determine the first feature vector corresponding to each node in the plurality of graph structures, where the first feature vector includes the multi-modal feature vector corresponding to the listed company node and the target enterprise node, and the structural feature vector corresponding to the unlisted company node and the individual node; A changed graph structure generation module, configured to compare the graph structures of adjacent target time periods and determine the difference information between the graph structures, and generate corresponding plurality of changed graph structures based on the difference information, where the difference information includes node change information and edge change information; And A fraud prediction module, configured to input the plurality of graph structures and the plurality of changed graph structures into a pre-trained fraud prediction model, and determine whether the target enterprise has a fraud behavior based on the fraud probability output by the fraud prediction model.

10. A financial fraud prediction device based on multi-modal graph learning, characterized in that, Including: A processor; And A memory, connected to the processor, for providing instructions for the processor to perform the following processing steps: Taking the target enterprises within each target time period and the objects associated with the target enterprises as nodes, and taking the association relationships between the target enterprises and each object as edges, construct multiple graph structures respectively corresponding to the respective target time periods, where the objects include listed companies, unlisted companies, and / or individuals; Determine the first feature vectors corresponding to each node in the multiple graph structures, where the first feature vectors include multi-modal feature vectors corresponding to the listed company nodes and the target enterprise nodes, and structural feature vectors corresponding to the unlisted company nodes and the individual nodes; Compare the graph structures of adjacent target time periods and determine the difference information between the graph structures, and generate corresponding multiple changed graph structures based on the difference information, where the difference information includes node change information and edge change information; And Input the multiple graph structures and the multiple changed graph structures into a pre-trained fraud prediction model, and based on the fraud probability output by the fraud prediction model, determine whether the target enterprise has fraudulent behavior.

Citation Information

Patent Citations

  • Fraud detection method, device and system based on graph neural network

    CN119809663A

  • Systems and methods for medical fraud detection

    US20240370935A1

  • Method and system for multi-modal fusion model

    WO2018124309A1

  • Video data-based fraud detection method and apparatus, computer device, and storage medium

    WO2021051607A1