Financial fraud prediction method and device based on multi-modal graph learning and storage medium

By constructing a multimodal graph structure and a change graph structure, and combining them with multimodal feature vectors, the problem that existing fraud prediction models cannot comprehensively and accurately predict the fraudulent behavior of target companies is solved, thus achieving accurate prediction of the fraudulent behavior of target companies.

CN120338827BActive Publication Date: 2026-04-07CAPITAL UNIV OF ECONOMICS & BUSINESS
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-14
Publication Date
2026-04-07

AI Technical Summary

Technical Problem

Existing fraud prediction models are unable to comprehensively and accurately predict fraudulent behavior by target companies due to reasons including insufficient information from single-modal data, failure to consider interactions within the business ecosystem, and inability to utilize long-term data and changes in relationships.

Method used

A multimodal graph structure is constructed. By combining the graph structure and change graph structure of multiple target time periods with multimodal feature vectors and a pre-trained fraud prediction model, it is possible to determine whether a target company is engaging in fraudulent activities.

Benefits of technology

It achieves comprehensive and accurate prediction of fraudulent activities by target companies, improves the accuracy of fraud prediction models, and can detect abnormal patterns and hidden fraudulent activities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120338827B_ABST
    Figure CN120338827B_ABST
Patent Text Reader

Abstract

This application discloses a financial fraud prediction method, apparatus, and storage medium based on multimodal graph learning, comprising: constructing multiple graph structures corresponding to each target time period, using target enterprises and objects associated with target enterprises within each target time period as nodes and the relationships between target enterprises and each object as edges; determining the first feature vector corresponding to each node in the multiple graph structures; comparing the graph structures of adjacent target time periods and determining the difference information between the graph structures, generating multiple corresponding modified graph structures based on the difference information; and inputting the multiple graph structures and multiple modified graph structures into a pre-trained fraud prediction model, and determining whether the target enterprise has engaged in fraudulent behavior based on the fraud probability output by the fraud prediction model.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of artificial intelligence technology, and in particular to a method, apparatus and storage medium for predicting financial fraud based on multimodal graph learning. Background Technology

[0002] To ensure the authenticity, transparency, and compliance of corporate financial information, regulatory agencies typically examine the financial situations of various companies and, based on these findings, predict whether fraudulent activities are possible. Currently, regulatory agencies often use pre-trained fraud prediction models and analyze the collected financial data of target companies to determine if there is a potential risk of fraud. These fraud prediction models can be, for example, models built on logistic regression or random forests.

[0003] However, the existing methods for using fraud prediction models to predict whether a target company has potential fraud risks have certain drawbacks. First, the data input into fraud prediction models is usually single-modal data (e.g., financial statement data corresponding to the target company), and single-modal data contains insufficient information. Therefore, when using fraud prediction models to predict whether a target company has engaged in fraudulent activities, the prediction results lack accuracy.

[0004] Second, because the data input into fraud prediction models is usually limited to the target company's internal data and does not take into account the target company's position in the business ecosystem (related to the target company and including multiple other companies) or the interaction between the target company and other companies in the business ecosystem, fraud prediction models cannot detect potential abnormal patterns and fraudulent behaviors of the target company, thus making it impossible for fraud prediction models to accurately predict whether the target company has engaged in fraudulent activities.

[0005] Third, since the fraudulent behavior of the target company is often the result of years of careful planning and lasts for several years, and the existing fraud prediction models can only judge whether the target company has engaged in fraudulent behavior based on data from the current period or a period close to the target company, they cannot make fraud predictions based on data from the target company over a long period of time. Therefore, the results predicted by the fraud prediction models are ultimately inaccurate.

[0006] Fourth, since the fraud prediction model does not take into account the changes in the relationship between the target company and other companies at different times, it cannot discover and identify abnormal transaction patterns between the target company and other companies based on the changes in the relationship between the target company and other companies. As a result, the fraud prediction model cannot discover the fraudulent behavior that the target company may be hiding, which leads to the lack of accuracy in the final prediction results obtained by the fraud prediction model.

[0007] There is currently no effective solution to the technical problem that existing fraud prediction models cannot comprehensively and accurately predict the fraudulent behavior of target companies. Summary of the Invention

[0008] The embodiments of this disclosure provide a financial fraud prediction method, apparatus, and storage medium based on multimodal graph learning, to at least solve the technical problem that existing fraud prediction models in the prior art cannot comprehensively and accurately predict the fraudulent behavior of target enterprises.

[0009] According to one aspect of the present disclosure, a financial fraud prediction method based on multimodal graph learning is provided, comprising: constructing multiple graph structures corresponding to each target time period, wherein the objects include listed companies, unlisted companies, and / or individuals; determining a first feature vector corresponding to each node in the multiple graph structures, wherein the first feature vector includes multimodal feature vectors corresponding to listed company nodes and target company nodes, and structural feature vectors corresponding to unlisted company nodes and individual nodes; comparing the graph structures of adjacent target time periods and determining the difference information between the graph structures, generating multiple corresponding modified graph structures based on the difference information, wherein the difference information includes node change information and edge change information; and inputting the multiple graph structures and the multiple modified graph structures into a pre-trained fraud prediction model, and determining whether the target company has engaged in fraudulent behavior based on the fraud probability output by the fraud prediction model.

[0010] According to another aspect of the present disclosure, a storage medium is also provided, the storage medium including a stored program, wherein, when the program is executed, a processor performs any of the methods described above.

[0011] According to another aspect of the present disclosure, a financial fraud prediction device based on multimodal graph learning is also provided, comprising: a graph structure construction module, used to construct multiple graph structures corresponding to each target time period, wherein the objects include listed companies, non-listed companies, and / or individuals, with target companies and objects associated with the target companies as nodes and the relationships between the target companies and each object as edges; a first feature vector determination module, used to determine a first feature vector corresponding to each node in the multiple graph structures, wherein the first feature vector includes multimodal feature vectors corresponding to listed company nodes and target company nodes, and structural feature vectors corresponding to non-listed company nodes and individual nodes; a modified graph structure generation module, used to compare the graph structures of adjacent target time periods and determine the difference information between the graph structures, and generate multiple modified graph structures corresponding to the difference information, wherein the difference information includes node change information and edge change information; and a fraud prediction module, used to input the multiple graph structures and multiple modified graph structures into a pre-trained fraud prediction model, and determine whether the target company has engaged in fraudulent behavior based on the fraud probability output by the fraud prediction model.

[0012] According to another aspect of the present disclosure, a financial fraud prediction device based on multimodal graph learning is also provided, comprising: a processor; and a memory connected to the processor, configured to provide the processor with instructions to process the following steps: constructing multiple graph structures corresponding to each target time period, wherein the objects include listed companies, unlisted companies, and / or individuals, with target companies and objects associated with target companies within each target time period as nodes and the relationships between target companies and each object as edges; determining a first feature vector corresponding to each node in the multiple graph structures, wherein the first feature vector includes multimodal feature vectors corresponding to listed company nodes and target company nodes, and structural feature vectors corresponding to unlisted company nodes and individual nodes; comparing graph structures of adjacent target time periods and determining difference information between graph structures, generating multiple corresponding modified graph structures based on the difference information, wherein the difference information includes node change information and edge change information; and inputting the multiple graph structures and multiple modified graph structures into a pre-trained fraud prediction model, and determining whether the target company has engaged in fraudulent behavior based on the fraud probability output by the fraud prediction model.

[0013] This application provides a financial fraud prediction method based on multimodal graph learning. First, the processor constructs multiple graph structures corresponding to each target time period, using target companies and their associated objects as nodes and the relationships between them as edges. Then, the processor determines the first feature vector corresponding to each node in the multiple graph structures. Further, the processor compares the graph structures of adjacent target time periods and determines the differences between them, generating multiple corresponding modified graph structures based on these differences. Finally, the processor inputs the multiple graph structures and the modified graph structures into a pre-trained fraud prediction model and determines whether the target company has engaged in fraudulent activities based on the fraud probability output by the model.

[0014] As can be seen from the above, since this application takes into account the impact of the target company's position and interaction in its associated business ecosystem on fraud prediction, this application does not simply predict whether the target company has engaged in fraudulent activities based on the internal data corresponding to the target company. Instead, it constructs a graph structure based on the target company and the objects that have relationships with the target company, and uses the graph structure and a pre-trained fraud prediction model to predict the target company's fraudulent activities. This helps the fraud prediction model discover potential abnormal patterns and fraudulent activities of the target company, thereby enabling the fraud prediction model to accurately predict the target company's fraudulent activities.

[0015] Furthermore, this application also considers that the financial fraud of target companies is often the result of years of meticulous planning. Therefore, this application constructs graph structures corresponding to multiple different target time periods, and dynamically predicts the fraudulent behavior of target companies based on long-term data information. In addition, this application generates multiple changing graph structures based on the differences between graph structures of adjacent target time periods, so that the fraud prediction model can mine and identify abnormal relationships and hidden fraudulent behaviors based on the changes of target companies over a long period of time.

[0016] This achieves the technical effect of accurately predicting the fraudulent activities of target companies in a comprehensive and accurate manner. It thus solves the technical problem that existing fraud prediction models cannot comprehensively and accurately predict the fraudulent activities of target companies.

[0017] Furthermore, since the initial feature vector corresponding to the node of the target enterprise in the graph structure of this application is a multimodal feature vector generated based on multimodal data, this application makes full use of the data information corresponding to the target enterprise and further improves the accuracy of the final output of the fraud prediction model. Attached Figure Description

[0018] The accompanying drawings, which are included to provide a further understanding of this disclosure and form part of this application, illustrate exemplary embodiments of this disclosure and are used to explain this disclosure, but do not constitute an undue limitation of this disclosure. In the drawings:

[0019] Figure 1 This is a hardware structure block diagram of a computing device used to implement the method described in Embodiment 1 of this application;

[0020] Figure 2 This is a schematic diagram of the financial fraud prediction system based on multimodal graph learning according to Embodiment 1 of this application;

[0021] Figure 3 This is a flowchart illustrating the financial fraud prediction method based on multimodal graph learning according to Embodiment 1 of this application;

[0022] Figure 4 This is a schematic diagram of multiple graph structures, multiple modified graph structures, and a fraud prediction model according to Embodiment 1 of this application;

[0023] Figure 5 This is a schematic diagram of the multimodal data and multimodal vectors according to Embodiment 1 of this application;

[0024] Figure 6 This is a schematic diagram of the financial fraud prediction device based on multimodal graph learning according to Embodiment 2 of this application;

[0025] Figure 7 This is a schematic diagram of a financial fraud prediction device based on multimodal graph learning according to Embodiment 3 of this disclosure. Detailed Implementation

[0026] To enable those skilled in the art to better understand the technical solutions of this disclosure, the technical solutions of the embodiments of this disclosure will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are merely some embodiments of this disclosure, and not all embodiments. Based on the embodiments of this disclosure, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of this disclosure.

[0027] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this disclosure are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this disclosure described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0028] Example 1

[0029] According to this embodiment, a method embodiment for financial fraud prediction based on multimodal graph learning is provided. It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Also, although a logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in a different order than that shown here.

[0030] The method embodiments provided in this example can be executed on mobile terminals, computer terminals, servers, or similar computing devices. Figure 1 A hardware block diagram of a computing device for implementing financial fraud prediction based on multimodal graph learning is shown. Figure 1 As shown, a computing device may include one or more processors (processors may include, but are not limited to, microprocessors such as MCUs or programmable logic devices such as FPGAs), memory for storing data, transmission devices for communication functions, and input / output interfaces. The memory, transmission devices, and input / output interfaces are connected to the processor via a bus. In addition, it may also include a display, keyboard, and cursor control device connected to the input / output interfaces. Those skilled in the art will understand that... Figure 1 The structure shown is for illustrative purposes only and does not limit the structure of the aforementioned electronic device. For example, a computing device may also include... Figure 1 The more or fewer components shown, or having the same Figure 1 The different configurations shown.

[0031] It should be noted that the aforementioned one or more processors and / or other data processing circuits are generally referred to herein as "data processing circuits". These data processing circuits may be embodied, in whole or in part, in software, hardware, firmware, or any other combination thereof. Furthermore, the data processing circuits may be a single, independent processing module, or may be integrated, in whole or in part, into any other element in a computing device. As involved in the embodiments of this disclosure, the data processing circuits serve as processor control (e.g., selection of a variable resistor termination path connected to an interface).

[0032] The memory can be used to store software programs and modules of application software, such as the program instructions / data storage device corresponding to the financial fraud prediction based on multimodal graph learning in the embodiments of this disclosure. The processor executes various functional applications and data processing by running the software programs and modules stored in the memory, thereby realizing the financial fraud prediction based on multimodal graph learning of the above-mentioned application. The memory may include high-speed random access memory, and may also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory may further include memory remotely located relative to the processor, and these remote memories can be connected to the computing device via a network. Examples of the above-mentioned networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.

[0033] The transmission device is used to receive or send data via a network. Specific examples of the network described above may include a wireless network provided by the computing device's communications provider. In one example, the transmission device includes a Network Interface Controller (NIC), which can connect to other network devices via a base station to communicate with the Internet. In another example, the transmission device may be a Radio Frequency (RF) module, used for wireless communication with the Internet.

[0034] The display can be, for example, a touchscreen liquid crystal display (LCD), which allows users to interact with the user interface of the computing device.

[0035] It should be noted here that, in some optional embodiments, the above... Figure 1 The computing device shown may include hardware elements (including circuitry), software elements (including computer code stored on a computer-readable medium), or a combination of both hardware and software elements. It should be noted that... Figure 1 This is only one instance of a specific particular instance, and is intended to illustrate the types of components that may exist in the aforementioned computing devices.

[0036] Figure 2This is a schematic diagram of the financial fraud prediction system based on multimodal graph learning as described in this embodiment. (Refer to...) Figure 2 As shown, the system includes: terminal device 100, processor 200 and server 300.

[0037] The terminal device 100 is communicatively connected to the processor 200 and is used to send the data information of the target enterprise to be predicted (such as the name information or tag information corresponding to the target enterprise) to the processor 200 through the terminal device 100.

[0038] The processor 200 is equipped with a pre-trained fraud prediction model, and the processor 200 is also used to determine the objects (including listed companies, non-listed companies and / or individuals) that are related to the target company based on the data information corresponding to the target company sent by the terminal device 100, and to construct a graph structure corresponding to each target time period based on the target company and the objects that are related to the target company.

[0039] In addition, the processor 200 is connected to the server 300 to collect multimodal information corresponding to the target company and multimodal information of listed companies that are related to the target company. Thus, the processor 200 can determine the first feature vector corresponding to each node in multiple graph structures based on the collected multimodal information.

[0040] Furthermore, the processor 200 is also used to compare the graph structures of adjacent target time periods and determine the differences between the graph structures, and generate multiple corresponding modified graph structures based on the differences. And when the processor 200 generates multiple graph structures and multiple modified graph structures, the multiple graph structures and multiple modified graph structures are input into the fraud prediction model, and the output of the fraud prediction model is used to determine whether the target company has engaged in fraudulent activities.

[0041] It should be noted that the terminal device 100, processor 200, and server 300 in the system can all be adapted to the hardware structure described above.

[0042] Under the aforementioned operating environment, according to the first aspect of this embodiment, a financial fraud prediction method based on multimodal graph learning is provided. This method comprises... Figure 2 The processor 200 shown is implemented. Figure 3 A flowchart illustrating the method is shown below. (Refer to...) Figure 3 As shown, the method includes:

[0043] S302: Take the target companies and objects associated with the target companies in each target time period as nodes, and the relationship between the target companies and each object as edges, and construct multiple graph structures corresponding to each target time period. The objects include listed companies, non-listed companies and / or individuals.

[0044] S304: Determine the first feature vector corresponding to each node in the multiple graph structures, wherein the first feature vector includes the multimodal feature vector corresponding to the listed company node and the target enterprise node, and the structural feature vector corresponding to the non-listed company node and the individual node;

[0045] S306: Compare the graph structures of adjacent target time periods and determine the differences between the graph structures. Based on the differences, generate multiple corresponding modified graph structures, where the differences include node change information and edge change information; and

[0046] S308: Input multiple graph structures and multiple change graph structures into a pre-trained fraud prediction model, and determine whether the target company has engaged in fraudulent activities based on the fraud probability output by the fraud prediction model.

[0047] Specifically, firstly, the terminal device 100 sends the data information corresponding to the target enterprise as determined by the user to the processor 200. Then, the processor 200 identifies the objects related to the target enterprise within each target time period. These relationships indicate investment relationships, cooperative relationships, etc. Objects related to the target enterprise can be, for example, subsidiaries or affiliated companies of the target enterprise, and can be listed companies, unlisted companies, or individuals. Thus, the processor 200 constructs multiple graph structures corresponding to each target time period, using the target enterprise and its associated objects as nodes and the relationships between the target enterprise and each object as edges (S302).

[0048] For example, first, processor 200 determines the target time period. Then processor 200 determines the target time period. Internally, entities associated with the target company During the target period Internally, entities associated with the target company ...; during the target period Internally, entities associated with the target company Furthermore, processor 200 will target the time period The target company and related parties within the target company As nodes, they connect the target company with various objects. The relationships between them are used as edges to construct a connection with the target time period. Corresponding graph structure Similarly, processor 200 can determine the target time period. Corresponding graph structure

[0049] Therefore, as can be seen from the above description, the processor 200 can determine the target time period. Corresponding graph structure In this embodiment, t = 3. That is, the processor 200 determines the target time period. and the target time period Corresponding graph structure

[0050] During the construction of processor 200 and various target periods Corresponding graph structure In this case, determine the structure of each graph. The processor 200 identifies listed company nodes and target enterprise nodes, and collects multimodal data corresponding to each listed company node and target enterprise node through server 300. For example, the processor 200 determines the graph structure. Listed company nodes Then, the processor 200 collects data from the nodes of each listed company via the server 300. Multimodal data corresponding to the target enterprise nodes. Furthermore, the processor 200 is based on data related to listed company nodes. The multimodal data corresponding to the target enterprise node is used to determine the connections between each listed company node. Multimodal feature vectors corresponding to the target enterprise node Similarly, processor 200 can determine the graph structure. Nodes between China and various listed companies Multimodal feature vectors corresponding to the target enterprise node and graph structure Nodes between China and various listed companies Multimodal feature vectors corresponding to the target enterprise node Therefore, as can be seen from the above, the processor 200 can determine the relationship with each graph structure. Listed company nodes Multimodal feature vectors corresponding to the target enterprise node

[0051] Furthermore, in the construction of processor 200 and various target time periods Corresponding graph structure In this case, the structural feature vectors corresponding to the nodes of non-listed companies and / or individual nodes in each graph structure can be determined based on their structural characteristics. These structural features can include, for example, node degree, weighted degree, second-order degree, joint degree, relative degree, and shortest path. For example, processor 200 determines the graph structure... Non-listed company nodes Then processor 200 is based on a non-listed company node. In graph structure The location within the context is determined in relation to nodes in non-listed companies. Corresponding structural feature vectors Similarly, processor 200 can determine the graph structure. Various non-listed company nodes Corresponding structural feature vectors and graph structure Various non-listed company nodes Corresponding structural feature vectors

[0052] Based on the same operations described above, the processor 200 can also determine the graph structure. Internally, with each individual node Corresponding structural feature vectors Thus, processor 200 can determine the graph structure. In the diagram, the structural feature vectors corresponding to each non-listed company node are... and the structural feature vectors corresponding to each individual node. The above-mentioned content will be described in detail later, so it will not be repeated here.

[0053] Thus, processor 200 is able to determine multiple graph structures. Nodes related to listed companies Multimodal feature vectors corresponding to the target enterprise node nodes with non-listed companies Corresponding structural feature vectors and personal nodes Corresponding structural feature vectors (i.e., the first feature vector) (S304). It is worth noting that in this embodiment, the first feature vector is used to indicate the initial feature vector input to the plurality of first graph neural network models and the plurality of second graph neural network models.

[0054] Furthermore, after the processor 200 determines the first feature vector corresponding to each node in the multiple graph structures, it further passes all the first feature vectors of the nodes through a learnable embedding layer and transforms them into learnable embeddings. That is, it converts the first feature vectors of the listed company nodes into learnable embeddings. Multimodal feature vectors corresponding to the target enterprise node nodes with non-listed companies Corresponding structural feature vectors and personal nodes Corresponding structural feature vectors Map to a space of the same dimension and make its dimensions the same.

[0055] Then, after the processor 200 constructs the graph structure corresponding to each target time period and determines the first feature vector corresponding to the node in each graph structure, the processor 200 compares the graph structures of adjacent target time periods and determines the difference information between the graph structures, and generates multiple corresponding modified graph structures based on the difference information (S306). For example, the processor 200 determines the graph structure corresponding to the target time period. Corresponding graph structure and target time period Corresponding graph structure Then, the processor 200 compares the graph structure. Graph Structure And determine the differences between the two. These differences include graph structure. Graph Structure The graph contains node change information and edge change information. Node change information includes graph structure. Graph Structure The addition or removal of nodes and edge changes include graph structure information. Graph Structure The addition or reduction of edges between them. Finally, the processor 200 determines the graph structure. Graph Structure The differences between them are used to generate a change diagram structure. Similarly, processor 200 can be based on the graph structure. Graph Structure The differences between them are used to generate a change diagram structure. Therefore, processor 200 can determine the target time period. Corresponding change diagram structure and the target time period Corresponding change diagram structure

[0056] In addition, due to the target time period The initial target time period, during the target time period Previously, there was no corresponding graph structure, therefore the graph structure It is impossible to compare the graph structure with the previous target time period, therefore there is no connection with the target time period. The corresponding change diagram structure.

[0057] Finally, the processor 200 determines the target time period. Corresponding graph structure and target time period Corresponding change diagram structure In the case of multiple graph structures and multiple change diagram structures The input is fed into a pre-trained fraud prediction model, and based on the fraud probability output by the fraud prediction model, it is determined whether the target company has engaged in fraudulent activities (S308). For example, the processor 200 will process multiple graph structures. and multiple change diagram structures When input into a fraud prediction model, the model outputs the fraud probability Z corresponding to the target company. x Then, processor 200 determines the fraud probability Z corresponding to the target company. x The relationship between the magnitude of the value and the pre-set fraud probability threshold Z. And the fraud probability Z corresponding to the target company. x If the probability is greater than or equal to the fraud probability threshold Z, it indicates that the target company has engaged in fraudulent activities. Conversely, if the probability is less than or equal to the threshold Z, it indicates that the target company has not engaged in fraudulent activities.

[0058] As described in the background section, existing methods for using fraud prediction models to predict whether a target company has potential fraud risks have certain shortcomings. Firstly, the data input into fraud prediction models is typically single-modal data (e.g., financial statement data corresponding to the target company). Since single-modal data contains insufficient information, the predictions obtained when using fraud prediction models to predict whether a target company is engaging in fraudulent activities lack accuracy.

[0059] Second, because the data input into fraud prediction models is usually limited to the target company's internal data and does not take into account the target company's position in the business ecosystem (related to the target company and including multiple other companies) or the interaction between the target company and other companies in the business ecosystem, fraud prediction models cannot detect potential abnormal patterns and fraudulent behaviors of the target company, thus making it impossible for fraud prediction models to accurately predict whether the target company has engaged in fraudulent activities.

[0060] Third, since the fraudulent behavior of the target company is often the result of years of careful planning and lasts for several years, and the existing fraud prediction models can only judge whether the target company has engaged in fraudulent behavior based on data from the current period or a period close to the target company, they cannot make fraud predictions based on data from the target company over a long period of time. Therefore, the results predicted by the fraud prediction models are ultimately inaccurate.

[0061] Fourth, since the fraud prediction model does not take into account the changes in the relationship between the target company and other companies at different times, it cannot discover and identify abnormal transaction patterns between the target company and other companies based on the changes in the relationship between the target company and other companies. As a result, the fraud prediction model cannot discover the fraudulent behavior that the target company may be hiding, which leads to the lack of accuracy in the final prediction results obtained by the fraud prediction model.

[0062] In view of this, this application provides a financial fraud prediction method based on multimodal graph learning. Furthermore, since this application considers the impact of the target company's position and interactions within its associated business ecosystem on fraud prediction, it does not merely predict whether the target company is engaging in fraudulent activities based on its internal data. Instead, it constructs a graph structure based on the target company and objects with which it has relationships, and then uses this graph structure and a pre-trained fraud prediction model to predict the target company's fraudulent activities. This helps the fraud prediction model discover potential abnormal patterns and fraudulent behaviors within the target company, enabling the model to accurately predict fraudulent activities.

[0063] Furthermore, this application also considers that the financial fraud of target companies is often the result of years of meticulous planning. Therefore, this application constructs graph structures corresponding to multiple different target time periods, and dynamically predicts the fraudulent behavior of target companies based on long-term data information. In addition, this application generates multiple changing graph structures based on the differences between graph structures of adjacent target time periods, so that the fraud prediction model can mine and identify abnormal relationships and hidden fraudulent behaviors based on the changes of target companies over a long period of time.

[0064] This achieves the technical effect of accurately predicting the fraudulent activities of target companies in a comprehensive and accurate manner. It thus solves the technical problem that existing fraud prediction models cannot comprehensively and accurately predict the fraudulent activities of target companies.

[0065] Furthermore, since the initial feature vector corresponding to the node of the target enterprise in the graph structure of this application is a multimodal feature vector generated based on multimodal data, this application makes full use of the data information corresponding to the target enterprise and further improves the accuracy of the final output of the fraud prediction model.

[0066] Optionally, the fraud prediction model includes multiple first graph neural network models, multiple second graph neural network models, and a fraud prediction network structure. The operation of inputting multiple graph structures and multiple modified graph structures into a pre-trained fraud prediction model, and determining whether a target company has engaged in fraudulent activities based on the fraud probability output by the fraud prediction model, includes: inputting multiple graph structures into the first graph neural network models respectively, and determining second feature vectors corresponding to each node in each graph structure; inputting multiple modified graph structures into the second graph neural network models, and determining third feature vectors corresponding to each node in each modified graph structure; and determining whether the target company has engaged in fraudulent activities based on the multiple second feature vectors and multiple third feature vectors, and using the fraud prediction network structure.

[0067] Specifically, Figure 4 This is a schematic diagram illustrating multiple graph structures, multiple modified graph structures, and a fraud prediction model according to embodiments of this application. (Reference) Figure 4 As shown, the fraud prediction model includes multiple first graph neural network models and multiple second graph neural network models. Furthermore, in this embodiment, the multiple first graph neural network models and multiple second graph neural network models can be, for example, HGT graph neural network models.

[0068] And the processor 200 defines multiple graph structures. In the case of, it will be related to the target time period Corresponding graph structures The data are input into the first graph neural network model, and the second feature vector corresponding to each node is determined. Specifically, the second feature vectors corresponding to the listed company node and the target company node are... The second feature vector corresponding to the non-listed company node and the second feature vector corresponding to the individual node

[0069] Similarly, processor 200 determines multiple change graph structures. In the case of, it will be in conjunction with the target time period Corresponding change diagram structures The data are then fed into the second graph neural network model, and the third feature vector corresponding to each node is determined. Specifically, the third feature vectors corresponding to the listed company node and the target company node are determined. The third feature vector corresponding to the non-listed company node And the third feature vector corresponding to the individual node

[0070] Finally, the processor 200 determines whether the target company has engaged in fraudulent activities based on multiple second feature vectors and multiple third feature vectors, as well as the fraud prediction network structure.

[0071] Optionally, the fraud prediction network structure includes an LSTM network and a multilayer perceptron. Based on multiple second and third feature vectors, and utilizing the fraud prediction network structure, the operation of determining whether a target company has engaged in fraudulent behavior includes: concatenating multiple second and third feature vectors for each target time period to generate a fourth feature vector corresponding to each target time period; inputting the fourth feature vector corresponding to each target time period into the LSTM network and determining a fifth feature vector corresponding to the last LSTM unit in the LSTM network, wherein the LSTM network includes multiple LSTM units; inputting the fifth feature vector into the multilayer perceptron and outputting the fraud probability corresponding to the target company; and determining whether the target company has engaged in fraudulent behavior based on the fraud probability. Further optionally, the method also includes: when the current target time period is the initial target time period among multiple target time periods, concatenating multiple second feature vectors corresponding to the current target time period and a mask to generate a fourth feature vector.

[0072] Specifically, refer to Figure 4 As shown, the fraud prediction model also includes a fraud prediction network structure, which includes an LSTM network and a multilayer perceptron.

[0073] Thus, when the fraud prediction network structure receives multiple second feature vectors corresponding to each graph structure in each target time period, and multiple third feature vectors corresponding to each changed graph structure in each target time period, it concatenates the multiple second feature vectors and multiple third feature vectors in each target time period to generate a fourth feature vector corresponding to each target time period.

[0074] For example, the fraud prediction network structure receives data related to the target time period. Internal graph structure The corresponding multiple second feature vectors (including multimodal feature vectors corresponding to the listed company node and the target enterprise node) Structural feature vectors corresponding to nodes of non-listed companies and the structural feature vectors corresponding to individual nodes Furthermore, the fraud prediction network structure receives data related to the target time period. Internal change diagram structure The corresponding multiple third feature vectors (including the third feature vectors corresponding to the listed company node and the target enterprise node) The third feature vector corresponding to the non-listed company node And the third feature vector corresponding to the individual node Furthermore, the fraud prediction network structure will be aligned with the target time period. Internal graph structure The corresponding multiple second feature vectors, sum with the target time period Internal change diagram structure The corresponding multiple third feature vectors are concatenated to generate a sequence corresponding to the target time period. The corresponding fourth feature vector

[0075] Similarly, the fraud prediction network structure will be related to the target time period. Internal graph structure The corresponding multiple second feature vectors, sum with the target time period Internal change diagram structure The corresponding multiple third feature vectors are concatenated to generate a sequence corresponding to the target time period. The corresponding fourth feature vector

[0076] Furthermore, since there is no change graph structure corresponding to the initial target time period among multiple target time periods, this embodiment introduces an all-zero vector (i.e., a mask) as the third feature vector corresponding to the change graph structure of the initial target time period. The all-zero vector is then concatenated with multiple second feature vectors corresponding to the initial target time period to generate a fourth feature vector corresponding to the initial target time period. For example, the fraud prediction network structure will be related to the target time period... Internal graph structure The corresponding multiple second feature vectors are concatenated with the all-zero vector to generate a vector corresponding to the target time period. The corresponding fourth feature vector

[0077] Therefore, based on the above method, the fraud prediction network structure can generate a network structure that matches the target time period. The corresponding fourth feature vector

[0078] The fraud prediction network then inputs the fourth feature vector corresponding to each target time period into the LSTM network to determine the fifth feature vector corresponding to the last LSTM unit in the LSTM network. The LSTM network consists of multiple LSTM units. For example, the fraud prediction network structure inputs the fourth feature vector corresponding to each target time period into the LSTM network. The corresponding fourth feature vector The input is fed into an LSTM network, and the fifth feature vector U output by the last LSTM unit in the LSTM network is determined. x .

[0079] Furthermore, the fraud prediction network structure will incorporate the fifth feature vector U x The input is fed into a multilayer perceptron (MLP) to ultimately output the fraud probability Z corresponding to the target company. x Finally, the processor 200 determines the fraud probability Z corresponding to the target company. x To determine whether the target company has engaged in fraudulent activities.

[0080] Since the fifth feature vector output by the last LSTM unit in the LSTM network contains the fusion information of multimodal data (corresponding to the target company and listed companies related to the target company), as well as the dynamic relationship pattern in the graph structure (i.e., the changes in the graph structure in different target time periods), the fraud prediction model can help identify abnormal transaction patterns and discover potentially hidden fraudulent behaviors. Thus, the fraud prediction model can comprehensively and accurately predict whether the target company has engaged in fraudulent behavior.

[0081] Optionally, the operation of comparing the graph structures of adjacent target time periods and determining the difference information between the graph structures, and generating multiple corresponding modified graph structures based on the difference information, includes: determining node change information between the graph structures of adjacent target time periods, wherein the node change information is used to indicate the addition or reduction of nodes; determining edge change information between the graph structures of adjacent target time periods, wherein the edge change information is used to indicate the addition or reduction of edges; and generating multiple modified graph structures based on the node change information and edge change information between the graph structures of adjacent target time periods.

[0082] Specifically, refer to Figure 4 As shown, before the processor 200 inputs the change graph structure corresponding to each target time period into multiple second graph neural networks, the processor 200 also needs to pre-generate the change graph structure corresponding to each target time period.

[0083] For example, processor 200 determines the target time period. Corresponding graph structure and target time period Corresponding graph structure Then, the processor 200 compares the graph structure. Graph Structure And determine the differences between the two. These differences include graph structure. Graph Structure Node change information and edge change information.

[0084] The node change information includes the graph structure. Graph Structure The addition or removal of nodes between them. Adding a node could be, for example, during a target time period. Newly established companies or individuals newly included in the research scope. The reduction of nodes could be, for example, during the target time period. Bankrupt companies or companies whose affiliations have been dissolved. Edge change information includes graph structure. Graph Structure The addition or reduction of the edges between them. An increase in the edge could be, for example, during the target time period. Newly established investment relationships or new cooperative relationships, etc. The reduction of sides could, for example, be during the target period. Cancelled investment relationships, etc.

[0085] Finally, processor 200 according to the graph structure Graph Structure The differences between them are used to generate a change diagram structure.

[0086] Similarly, processor 200 can be based on the graph structure. Graph Structure The differences between them are used to generate a change diagram structure. Therefore, processor 200 can determine the target time period. Corresponding change diagram structure and the target time period Corresponding change diagram structure

[0087] It is worth noting that in changing the diagram structure In this context, the types of nodes are listed companies, unlisted companies, and individuals, while the types of edges are increasing and decreasing edges.

[0088] In addition, due to the target time period The initial target time period, during the target time period Previously, there was no corresponding graph structure, therefore the graph structure It is impossible to compare the graph structure with the previous target time period, therefore there is no connection with the target time period. The corresponding change diagram structure.

[0089] Thus, by generating a change graph structure corresponding to the changes in the relationship between each target time period based on the graph structure corresponding to each target time period, the technical effect of providing the necessary foundation for subsequent fraud prediction models to identify abnormal transaction patterns of target enterprises and discover potentially hidden fraudulent behaviors is achieved.

[0090] Optionally, the operation of determining the first feature vector corresponding to each node in each graph structure includes: collecting multimodal data corresponding to listed company nodes and target enterprise nodes within each target time period, and determining the multimodal feature vector corresponding to the multimodal data. Further optionally, the operation of collecting multimodal data corresponding to listed company nodes within each target time period and determining the multimodal feature vector corresponding to the multimodal data includes: collecting multimodal data corresponding to listed company nodes, and using an attention mechanism to determine the weight values ​​corresponding to different modalities; and fusing the multimodal data based on the weight values ​​corresponding to different modalities, and determining the multimodal feature vector corresponding to the multimodal data.

[0091] Specifically, Figure 5 This is a schematic diagram of multimodal data and multimodal vectors according to embodiments of this application. (Reference) Figure 5 As shown, firstly, the processor 200 collects multimodal data corresponding to the listed company node and the target enterprise through the server 300. In this embodiment, the multimodal data includes, for example, financial statements corresponding to the numerical mode, corporate announcements and news reports corresponding to the text mode, telephone audio and conference audio corresponding to the audio mode, speeches by corporate managers corresponding to the language mode, and cluster diagrams corresponding to the network mode.

[0092] First, for the financial statements corresponding to the numerical modality, processor 200 extracts financial ratios from the financial statements. These financial statements include, for example, balance sheets, income statements, and cash flow statements. Then, processor 200 removes outlier and missing data from the financial ratios and standardizes the data after removal to make the data from different indicators comparable. Finally, processor 200 obtains the financial ratio data after removal and standardization. Finally, processor 200 uses a multilayer perceptron to deeply mine the embedded information of the financial ratio data and maps the financial ratio data to a dimension unified with other modality data, obtaining the feature vector corresponding to the numerical modality. Where m represents the unified dimension.

[0093] II. For enterprise announcements and news reports corresponding to the text modality, the processor 200 first preprocesses the data corresponding to the text modality. The preprocessing steps include: first, cleaning the data corresponding to the text modality, removing irrelevant characters, and standardizing the text format. Then, the text is segmented into multiple sentences, and each sentence is segmented into tokens, converting them into a token sequence of length n. Each token is assigned a Token embedding, a Segment embedding, and a Position embedding. The Token embedding is used to represent different lexical tags. The Segment embedding is used to distinguish different sentences. The Position embedding is used to represent the position of the token in the sentence. This generates a Token Embedding matrix E = [E1, E2, ..., E...]. e ], where j = 1 to e. And E j Let E represent the embedding vector of the j-th token. Further, the TokenEmbedding matrix E is input into the BERT model, and the BERT model outputs the feature vector corresponding to the text modality.

[0094] Third, for telephone audio and conference audio corresponding to the sound modality, processor 200 uses Praat acoustic software to extract the original acoustic features corresponding to the speaker from the audio text, thereby generating a feature vector corresponding to the sound modality. Among them, the original acoustic features include, for example, the mean and standard deviation of the fundamental frequency, the jitter and amplitude perturbation of the fundamental frequency, the mean and standard deviation of the harmonic noise ratio, and the proportion of voiced sounds.

[0095] Fourth, for the speeches of business managers corresponding to the language modality, LIWC (Linguistic Inquiry and Word Count) software is used to conduct in-depth analysis of the speakers' speeches, thereby quantifying the linguistic features in the speeches. Specifically, LIWC software is used to extract and calculate the following indicators: the proportion of first-person singular and plural pronouns used by the speaker, the frequency of impersonal pronouns, the number of words expressing positive and negative emotions, and the relative proportion of words expressing certainty and tentativeness. From the perspective of vocabulary usage habits and semantic expression, potential deceptive intentions or information manipulation signs hidden by the speaker in communication are explored, and finally, feature vectors corresponding to the language modality are obtained.

[0096] Fifth, since fraudulent companies are often hidden in a fraudulent "group" or "cluster," and the internal relationships of a fraudulent "group" or "cluster" are quite different from those of a normal corporate cluster, the prediction of fraudulent behavior by abnormally related groups is often very important.

[0097] Based on the above, this embodiment first constructs a subgraph memory network. Specifically, the target company is taken as the central node, and the H-order neighbor nodes surrounding the target company are taken as a subgraph.

[0098] The subgraph embedding vector L corresponding to the subgraph consists of three parts: graph walk embedding, graph theory method embedding, and organizational information embedding. Specifically, graph walk embedding refers to randomly walking from the node corresponding to the target enterprise and encoding the walk path as a vector. Graph theory method embedding calculates the degree distribution of nodes in the subgraph, the clustering coefficient of nodes in the subgraph, the shortest path length between nodes in the subgraph, and the specific structural features of the subgraph. Organizational information embedding calculates the number of surrounding investors corresponding to the target enterprise node, the size and number of neighboring enterprises, and the connection information of related enterprises.

[0099] Based on this, the subgraph memory network is constructed as follows:

[0100]

[0101] Where Emb means to embed the original data mapping, L u G″ represents the embedding vector corresponding to the u-th subgraph. x,u Represents the u-th subgraph. This represents the structure of the v-th graph.

[0102] Furthermore, the information from the K1 subgraphs most relevant to the target enterprise node is selected and aggregated into the target enterprise node's information. Specifically, the correlation between the target enterprise node and each subgraph in the K1 subgraphs is first calculated. Then, the financial ratio characteristics of the nodes in the K2 most relevant subgraphs are weighted and summed to obtain the final output. The specific calculation formula is as follows:

[0103] p u =softmax(AMN) T ×Emb(L))

[0104] M 0 =TopK(p u )×TopK(H u )

[0105] Where, p u H represents the similarity probability to the target node u. u M represents the financial ratio data corresponding to the target node u. 0 This represents the feature vector corresponding to the network mode. Wherein,

[0106] Then, the processor 200 uses an attention mechanism to determine the weight values ​​corresponding to data from different modalities. Specifically, in order to coordinate the predictive capabilities of the fraud prediction model for data from different modalities and achieve fusion between different modalities, this application uses an attention mechanism to calculate the weight values ​​corresponding to data from different modalities separately. The calculation formula is as follows:

[0107] a f +a t +a l +a s +a o =1

[0108]

[0109] Among them, a f a represents the weight corresponding to the numerical mode. c a represents the weight corresponding to the text modality. l a represents the weight corresponding to the sound mode. s a represents the weight corresponding to the language modality. o This represents the weights corresponding to the network modes.

[0110] Finally, the processor 200 fuses the weight values ​​calculated above with the data corresponding to different modalities to obtain the multimodal feature vector M corresponding to the multimodal data. x ={M x,1 M x,2 ,...M x,m}

[0111] Thus, by using an attention mechanism to fuse the collected multimodal data and then using the fused data as input to the fraud prediction model, the technical effect of more comprehensively utilizing complementary multimodal information is achieved, thereby improving the accuracy of the fraud prediction model's prediction results.

[0112] Furthermore, it is worth noting that the processor 200 needs to train the fraud prediction model in advance before using it to make fraud predictions against the target company.

[0113] The steps for processor 200 to train the fraud prediction model include:

[0114] First, processor 200 determines each sample time period. Within this framework, objects associated with the sample companies are identified, and based on these sample companies and their associated objects, a framework is constructed for each sample time period. Corresponding multiple graph structure samples In this embodiment, t = 3. That is, the processor 200 determines the sample time period. and the sample period Corresponding graph structure For example, processor 300 construction and sample time period Corresponding graph structure samples With sample time period Corresponding graph structure samples and the target time period Corresponding graph structure samples Furthermore, in this embodiment, the target period is the entire year of 2020, so the sample period is... For example, it could be the entire year of 2017, the sample period. For example, it could be the entire year of 2018, the sample period. For example, it could be the entire year of 2019. That is, the target period is the period that the fraud prediction model wants to predict, while the sample period is the period used to train the fraud prediction model.

[0115] Then, the processor 200 collects samples for each time period through the server 300. Within this, there is multimodal data corresponding to the sample companies, and multimodal data corresponding to the listed companies associated with the sample companies. For example, processor 200 collects sample data during the specified time period through server 300. The data includes multimodal data corresponding to the sample companies, as well as multimodal data corresponding to the listed companies associated with the sample companies.

[0116] Similarly, the processor collects samples during the 200-period sampling period. Within this, there is multimodal data corresponding to the sample companies, as well as multimodal data corresponding to the listed companies associated with the sample companies. And so on, with processor 200 collecting sample data for each period. Within this, there is multimodal data corresponding to the sample companies and multimodal data corresponding to the listed companies associated with the sample companies.

[0117] In this embodiment, the multimodal data corresponding to the sample companies and associated listed companies includes, for example, financial statements corresponding to the numerical mode, company announcements and news reports corresponding to the text mode, telephone audio and conference audio corresponding to the sound mode, speeches by company managers corresponding to the language mode, and cluster graphs corresponding to the network mode.

[0118] Then, different sample collection times were performed using processor 200. Given the multimodal data corresponding to the sample companies and the multimodal data corresponding to the listed companies associated with the sample companies, further processing is performed on the data of each modality, such as unifying dimensions and splicing, to generate multimodal feature vectors corresponding to the sample companies and multimodal feature vectors corresponding to the listed companies associated with the sample companies.

[0119] Furthermore, the processor 200 determines the time period for each sample. Corresponding graph structure samples In this case, the corresponding structural feature vector can be determined based on the structural characteristics of the unlisted companies and / or individuals associated with each sample company in the graph structure sample.

[0120] Therefore, based on the above description, the processor 200 can determine each graph structure sample. In this context, we have multimodal feature vectors corresponding to sample companies, multimodal feature vectors corresponding to listed companies, structural feature vectors corresponding to unlisted companies, and structural feature vectors corresponding to individuals.

[0121] The processor 200 then compares graph structure samples from adjacent target time periods and determines the differences between the graph structure samples, generating multiple corresponding changed graph structures based on the differences. For example, the processor 200 determines the changes between the sample time periods... Corresponding graph structure samples and sample time period Corresponding graph structure samples Then, the processor 200 compares the graph structure samples. Graph Structure And determine the differences between the two. These differences include graph structure samples. And graph structure samples The processor 200 then processes the node and edge change information based on the graph structure sample. And graph structure samples The differences between them are used to generate a change diagram structure sample. Similarly, processor 200 can base its analysis on graph structure samples. And graph structure samples The differences between them are used to generate a change diagram structure sample. Therefore, processor 200 can determine the sample time period. Corresponding change diagram structure sample and the sample period Corresponding change diagram structure sample

[0122] In addition, due to the sample period For the initial target time period, in the sample time period Previously, there were no corresponding graph structure samples, therefore graph structure samples It is impossible to compare the graph structure sample with the previous sample time period, therefore there is no matching sample time period. The corresponding change diagram structure sample.

[0123] Finally, the processor 200 determines the sample time period. Corresponding graph structure samples and sample time period Corresponding change diagram structure sample In the case of multiple graph structure samples and multiple change diagram structure samples The input samples and the actual fraud status of the sample companies are used as input samples to train the pre-built fraud prediction model, thereby training the fraud prediction model. The fraud prediction model includes multiple first graph neural networks, multiple second graph neural networks, and a fraud prediction network structure. The fraud prediction network structure includes an LSTM network (containing multiple LSTM units) and a multilayer perceptron.

[0124] Furthermore, to achieve higher accuracy in the trained fraud prediction model, the processor 200 utilizes graph-structured samples. And the change diagram structure sample Generate training and test sets. Evaluate the performance of the fraud prediction model using common metrics such as accuracy, recall, and F1 score. Consider using multimodal-specific metrics, such as multimodal consistency metrics, to measure the fusion effect between different modalities. Based on the evaluation results, adjust the structure and parameters of the fraud prediction model, and select different feature fusion methods and model integration strategies. Optimize the model using techniques such as cross-validation and grid search.

[0125] Thus, according to the first aspect of this embodiment, the technical effect of being able to accurately and comprehensively predict the fraudulent activities of the target enterprise is achieved.

[0126] In addition, refer to Figure 1 As shown, according to a second aspect of this embodiment, a storage medium is provided. The storage medium includes a stored program, wherein, when the program is executed, a processor performs any of the methods described above.

[0127] Thus, according to this embodiment, the technical effect of being able to accurately and comprehensively predict the fraudulent behavior of target enterprises is achieved.

[0128] It should be noted that, for the sake of simplicity, the foregoing method embodiments are all described as a series of actions. However, those skilled in the art should understand that the present invention is not limited to the described order of actions, because according to the present invention, some steps can be performed in other orders or simultaneously. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are preferred embodiments, and the actions and modules involved are not necessarily essential to the present invention.

[0129] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods according to the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes several instructions to cause a terminal device (which may be a mobile phone, computer, server, or network device, etc.) to execute the methods described in the various embodiments of the present invention.

[0130] Example 2

[0131] Figure 6 A financial fraud prediction device 600 based on multimodal graph learning according to this embodiment is shown, which corresponds to the method described according to embodiment 1. Referring to Figure 6, the device 600 includes: a graph structure construction module 610, used to construct multiple graph structures corresponding to each target time period, using target enterprises and objects associated with the target enterprises as nodes and the relationships between the target enterprises and each object as edges, wherein the objects include listed companies, non-listed companies and / or individuals; a first feature vector determination module 620, used to determine the first feature vector corresponding to each node in the multiple graph structures, wherein the first feature vector includes multimodal feature vectors corresponding to listed company nodes and target enterprise nodes, and structural feature vectors corresponding to non-listed company nodes and individual nodes; a modified graph structure generation module 630, used to compare the graph structures of adjacent target time periods and determine the difference information between the graph structures, and generate multiple modified graph structures based on the difference information, wherein the difference information includes node change information and edge change information; and a fraud prediction module 640, used to input the multiple graph structures and multiple modified graph structures into a pre-trained fraud prediction model, and determine whether the target enterprise has engaged in fraudulent behavior based on the fraud probability output by the fraud prediction model.

[0132] Optionally, the fraud prediction model includes multiple first graph neural network models, multiple second graph neural network models, and a fraud prediction network structure. The fraud prediction module 640 includes: a second feature vector determination module, used to input multiple graph structures into the first graph neural network models respectively, and determine the second feature vector corresponding to each node in each graph structure; a third feature vector determination module, used to input multiple modified graph structures into the second graph neural network models, and determine the third feature vector corresponding to each node in each modified graph structure; and a fraud prediction submodule, used to determine whether the target enterprise has engaged in fraudulent activities based on multiple second feature vectors and multiple third feature vectors and using the fraud prediction network structure.

[0133] Optionally, the fraud prediction network structure includes an LSTM network and a multilayer perceptron. The fraud prediction submodule includes: a fourth feature vector generation module, used to concatenate multiple second feature vectors and multiple third feature vectors in each target time period to generate a fourth feature vector corresponding to each target time period; a fifth feature vector generation module, used to input the fourth feature vector corresponding to each target time period into the LSTM network and determine the fifth feature vector corresponding to the last LSTM unit in the LSTM network, wherein the LSTM network includes multiple LSTM units; a fraud probability output module, used to input the fifth feature vector into the multilayer perceptron and output the fraud probability corresponding to the target enterprise; and a fraud behavior judgment module, used to judge whether the target enterprise has engaged in fraudulent behavior based on the fraud probability.

[0134] Optionally, the device 600 further includes a mask splicing module, used to splice multiple second feature vectors and a mask corresponding to the current target time period when the current target time period is the initial target time period among multiple target time periods, and generate a fourth feature vector.

[0135] Optionally, the modified graph structure generation module 630 includes: a node change information determination module, used to determine node change information between graph structures in adjacent target time periods, wherein the node change information is used to indicate the addition or reduction of nodes; an edge change information determination module, used to determine edge change information between graph structures in adjacent target time periods, wherein the edge change information is used to indicate the addition or reduction of edges; and a modified graph structure generation submodule, used to generate multiple modified graph structures based on the node change information and edge change information between graph structures in adjacent target time periods.

[0136] Optionally, the first feature vector determination module 620 includes: a multimodal feature vector determination module, used to collect multimodal data corresponding to the listed company node and the target enterprise node in each target time period, and determine the multimodal feature vector corresponding to the multimodal data.

[0137] Optionally, the multimodal feature vector determination module includes: a weight value determination module, used to collect multimodal data corresponding to listed company nodes and target enterprises, and use an attention mechanism to determine the weight values ​​corresponding to different modal data; and a multimodal feature vector determination submodule, used to fuse multimodal data based on the weight values ​​corresponding to different modal data, and determine the multimodal feature vectors corresponding to the multimodal data.

[0138] Thus, according to this embodiment, the technical effect of being able to accurately and comprehensively predict the fraudulent behavior of target enterprises is achieved.

[0139] Example 3

[0140] Figure 7 A financial fraud prediction device 700 based on multimodal graph learning according to this embodiment is shown, which corresponds to the method described according to embodiment 1. Reference Figure 7 As shown, the device 700 includes: a processor 710; and a memory 720 connected to the processor 710, used to provide the processor 710 with instructions to process the following steps: constructing multiple graph structures corresponding to each target time period, where the target companies and objects associated with the target companies within each target time period are used as nodes, and the relationships between the target companies and each object are used as edges; determining a first feature vector corresponding to each node in the multiple graph structures, where the first feature vector includes multimodal feature vectors corresponding to listed company nodes and target company nodes, and structural feature vectors corresponding to unlisted company nodes and individual nodes; comparing the graph structures of adjacent target time periods and determining the difference information between the graph structures, generating multiple corresponding modified graph structures based on the difference information, where the difference information includes node change information and edge change information; and inputting the multiple graph structures and multiple modified graph structures into a pre-trained fraud prediction model, and determining whether the target company has engaged in fraudulent behavior based on the fraud probability output by the fraud prediction model.

[0141] Optionally, the fraud prediction model includes multiple first graph neural network models, multiple second graph neural network models, and a fraud prediction network structure. The operation of inputting multiple graph structures and multiple modified graph structures into the pre-trained fraud prediction model, and determining whether the target company has engaged in fraudulent activities based on the fraud probability output by the fraud prediction model, includes: inputting multiple graph structures into the first graph neural network model respectively, and determining the second feature vector corresponding to each node in each graph structure; inputting multiple modified graph structures into the second graph neural network model, and determining the third feature vector corresponding to each node in each modified graph structure; and determining whether the target company has engaged in fraudulent activities based on the multiple second feature vectors and multiple third feature vectors, and using the fraud prediction network structure.

[0142] Optionally, the fraud prediction network structure includes an LSTM network and a multilayer perceptron. Based on multiple second and third feature vectors, the operation of determining whether a target company has engaged in fraudulent activities using the fraud prediction network structure includes: concatenating multiple second and third feature vectors for each target time period to generate a fourth feature vector corresponding to each target time period; inputting the fourth feature vector corresponding to each target time period into the LSTM network and determining a fifth feature vector corresponding to the last LSTM unit in the LSTM network, where the LSTM network includes multiple LSTM units; inputting the fifth feature vector into the multilayer perceptron and outputting the fraud probability corresponding to the target company; and determining whether the target company has engaged in fraudulent activities based on the fraud probability.

[0143] Optionally, the device 700 further includes: when the current target time period is the initial target time period among multiple target time periods, concatenating multiple second feature vectors and masks corresponding to the current target time period to generate a fourth feature vector.

[0144] Optionally, the operation of comparing the graph structures of adjacent target time periods and determining the difference information between the graph structures, and generating multiple corresponding modified graph structures based on the difference information, includes: determining node change information between the graph structures of adjacent target time periods, wherein the node change information is used to indicate the addition or reduction of nodes; determining edge change information between the graph structures of adjacent target time periods, wherein the edge change information is used to indicate the addition or reduction of edges; and generating multiple modified graph structures based on the node change information and edge change information between the graph structures of adjacent target time periods.

[0145] Optionally, the operation of determining the first feature vector corresponding to each node in each graph structure includes: collecting multimodal data corresponding to the listed company node and the target enterprise node within each target time period, and determining the multimodal feature vector corresponding to the multimodal data.

[0146] Optionally, the operation of collecting multimodal data corresponding to listed company nodes within each target time period and determining the multimodal feature vectors corresponding to the multimodal data includes: collecting multimodal data corresponding to listed company nodes and target enterprises, and using an attention mechanism to determine the weight values ​​corresponding to different modal data; and fusing the multimodal data based on the weight values ​​corresponding to different modal data, and determining the multimodal feature vectors corresponding to the multimodal data.

[0147] Thus, according to this embodiment, the technical effect of being able to accurately and comprehensively predict the fraudulent behavior of target enterprises is achieved.

[0148] The sequence numbers of the above embodiments of the present invention are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.

[0149] In the above embodiments of the present invention, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments.

[0150] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. The device embodiments described above are merely illustrative; for example, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the displayed or discussed mutual coupling, direct coupling, or communication connection may be through some interfaces; the indirect coupling or communication connection between units or modules may be electrical or other forms.

[0151] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0152] Furthermore, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0153] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, read-only memory (ROM), random access memory (RAM), portable hard drives, magnetic disks, or optical disks.

[0154] The above description is only a preferred embodiment of the present invention. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principle of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.

Claims

1. A financial fraud prediction method based on multimodal graph learning, characterized in that, include: Target companies and objects associated with each target time period are used as nodes, and the relationships between each target company and each object are used as edges. Multiple graph structures corresponding to each target time period are constructed, wherein the objects include listed companies, unlisted companies and / or individuals. Determine a first feature vector corresponding to each node in the plurality of graph structures, wherein the first feature vector includes a multimodal feature vector corresponding to listed company nodes and target enterprise nodes, and a structural feature vector corresponding to non-listed company nodes and individual nodes, wherein the operation of determining the first feature vector corresponding to each node in each graph structure includes: Collect multimodal data corresponding to the listed company node and the target enterprise node within each target time period, and determine the multimodal feature vector corresponding to the multimodal data. Specifically, this includes: collecting multimodal data corresponding to the listed company node and the target enterprise, and using an attention mechanism to determine the weight values ​​corresponding to different modalities of data. The multimodal data includes text modal data and audio modal data, and the operation of determining the multimodal feature vector corresponding to the multimodal data includes: The acquired text modal data is segmented and multiple token sequences are generated. The multiple token sequences are subjected to word embedding processing to generate a word embedding matrix, wherein the word embedding matrix includes multiple word embedding vectors; The word embedding matrix is ​​input into the BERT model, and the BERT model outputs the feature vector corresponding to the text modality data. The operation of determining the multimodal feature vector corresponding to the multimodal data further includes: Extract raw acoustic features from the acquired sound modal data, and generate feature vectors corresponding to the sound modal data based on the raw acoustic features; Based on the weight values ​​corresponding to the different modal data, the multimodal data is fused, and the multimodal feature vector corresponding to the multimodal data is determined; Compare the graph structures of adjacent target time periods and determine the differences between the graph structures. Generate multiple corresponding modified graph structures based on the differences, wherein the differences include node modification information and edge modification information; and The multiple graph structures and the multiple modified graph structures are input into a pre-trained fraud prediction model, and based on the fraud probability output by the fraud prediction model, it is determined whether the target enterprise has engaged in fraudulent activities. The fraud prediction model includes multiple first graph neural network models, multiple second graph neural network models, and a fraud prediction network structure. The specific operations include: The plurality of graph structures are respectively input into the first graph neural network model, and a second feature vector corresponding to the first feature vector of each node in each graph structure is determined; The plurality of modified graph structures are input into the second graph neural network model, and a third feature vector corresponding to the first feature vector of each node in each modified graph structure is determined; and Based on multiple second feature vectors and multiple third feature vectors, and utilizing the fraud prediction network structure, it is determined whether the target enterprise has engaged in fraudulent activities.

2. The method according to claim 1, characterized in that, The fraud prediction network structure includes an LSTM network and a multilayer perceptron. Based on multiple second feature vectors and multiple third feature vectors, the operation of determining whether the target enterprise has engaged in fraudulent activities using the fraud prediction network structure includes: Multiple second feature vectors and multiple third feature vectors within each target time period are concatenated to generate a fourth feature vector corresponding to each target time period. The fourth feature vector corresponding to each target time period is input into the LSTM network, and the fifth feature vector corresponding to the last LSTM unit in the LSTM network is determined, wherein the LSTM network includes multiple LSTM units; The fifth feature vector is input into the multilayer perceptron, and the fraud probability corresponding to the target enterprise is output; and Based on the fraud probability, it is determined whether the target company has engaged in fraudulent activities.

3. The method according to claim 2, characterized in that, Also includes: If the current target time period is the initial target time period among multiple target time periods, the multiple second feature vectors and masks corresponding to the current target time period are concatenated to generate a fourth feature vector.

4. The method according to claim 1, characterized in that, The operation of comparing the graph structures of adjacent target time periods and determining the difference information between the graph structures, and generating multiple corresponding modified graph structures based on the difference information, includes: Determine node change information between the graph structures of adjacent target time periods, wherein the node change information is used to indicate the addition or reduction of nodes; Determine edge change information between the graph structures of adjacent target time periods, wherein the edge change information is used to indicate the addition or reduction of the edges; and Based on the node change information and edge change information between the graph structures of adjacent target time periods, the multiple changed graph structures are generated.

5. A storage medium, characterized in that, The storage medium includes a stored program, wherein, when the program is executed, the method described in any one of claims 1 to 4 is performed by a processor.

6. A financial fraud prediction device based on multimodal graph learning, characterized in that, include: The graph structure construction module is used to construct multiple graph structures corresponding to each target time period, using target enterprises and objects associated with the target enterprises as nodes and the relationships between the target enterprises and each object as edges. The objects include listed companies, non-listed companies and / or individuals. The first feature vector determination module is used to determine a first feature vector corresponding to each node in the plurality of graph structures, wherein the first feature vector includes a multimodal feature vector corresponding to the listed company node and the target enterprise node, and a structural feature vector corresponding to the non-listed company node and the individual node. The first feature vector determination module includes a multimodal feature vector determination module, used to collect multimodal data corresponding to the listed company node and the target enterprise node within each target time period, and determine the multimodal feature vector corresponding to the multimodal data. The multimodal feature vector determination module includes: a weight value determination module, used to collect multimodal data corresponding to the listed company node and the target enterprise, and to determine the weight values ​​corresponding to different modal data using an attention mechanism, wherein... The multimodal data includes text modal data and audio modal data, and the weight value determination module is further configured to perform the following operations: The acquired text modal data is segmented and multiple token sequences are generated. The multiple token sequences are subjected to word embedding processing to generate a word embedding matrix, wherein the word embedding matrix includes multiple word embedding vectors; The word embedding matrix is ​​input into the BERT model, and the BERT model outputs the feature vector corresponding to the text modality data. The weight value determination module is also used to perform the following operations: Extract raw acoustic features from the acquired sound modal data, and generate feature vectors corresponding to the sound modal data based on the raw acoustic features; The multimodal feature vector determination submodule is used to fuse the multimodal data based on the weight values ​​corresponding to the different modal data, and determine the multimodal feature vector corresponding to the multimodal data; A graph structure change generation module is used to compare graph structures in adjacent target time periods and determine the differences between the graph structures, and generate multiple corresponding graph structures based on the differences, wherein the differences include node change information and edge change information; and A fraud prediction module is used to input the multiple graph structures and the multiple change graph structures into a pre-trained fraud prediction model, and determine whether the target enterprise has engaged in fraudulent activities based on the fraud probability output by the fraud prediction model. The fraud prediction model includes multiple first graph neural network models, multiple second graph neural network models, and a fraud prediction network structure. The fraud prediction module further includes: The second feature vector determination module is used to input the plurality of graph structures into the first graph neural network model respectively, and determine the second feature vector corresponding to the first feature vector of each node in each graph structure; The third feature vector determination module is used to input the plurality of changed graph structures into the second graph neural network model, and determine the third feature vector corresponding to the first feature vector of each node in each changed graph structure; and The fraud prediction submodule is used to determine whether the target company has engaged in fraudulent activities based on multiple second feature vectors and multiple third feature vectors, and by utilizing the fraud prediction network structure.

7. A financial fraud prediction device based on multimodal graph learning, characterized in that, include: processor; as well as A memory, connected to the processor, for providing the processor with instructions to perform the following processing steps: Target companies and objects associated with each target time period are used as nodes, and the relationships between each target company and each object are used as edges. Multiple graph structures corresponding to each target time period are constructed, wherein the objects include listed companies, unlisted companies and / or individuals. Determine a first feature vector corresponding to each node in the plurality of graph structures, wherein the first feature vector includes a multimodal feature vector corresponding to listed company nodes and target enterprise nodes, and a structural feature vector corresponding to non-listed company nodes and individual nodes, wherein the operation of determining the first feature vector corresponding to each node in each graph structure includes: Collect multimodal data corresponding to the listed company node and the target enterprise node within each target time period, and determine the multimodal feature vector corresponding to the multimodal data. Specifically, this includes: collecting multimodal data corresponding to the listed company node and the target enterprise, and using an attention mechanism to determine the weight values ​​corresponding to different modalities of data. The multimodal data includes text modal data and audio modal data, and the operation of determining the multimodal feature vector corresponding to the multimodal data includes: The acquired text modal data is segmented and multiple token sequences are generated. The multiple token sequences are subjected to word embedding processing to generate a word embedding matrix, wherein the word embedding matrix includes multiple word embedding vectors; The word embedding matrix is ​​input into the BERT model, and the BERT model outputs the feature vector corresponding to the text modality data. The operation of determining the multimodal feature vector corresponding to the multimodal data further includes: Extract raw acoustic features from the acquired sound modal data, and generate feature vectors corresponding to the sound modal data based on the raw acoustic features; Based on the weight values ​​corresponding to the different modal data, the multimodal data is fused, and the multimodal feature vector corresponding to the multimodal data is determined; Compare the graph structures of adjacent target time periods and determine the differences between the graph structures. Generate multiple corresponding modified graph structures based on the differences, wherein the differences include node modification information and edge modification information; and The multiple graph structures and the multiple modified graph structures are input into a pre-trained fraud prediction model, and based on the fraud probability output by the fraud prediction model, it is determined whether the target enterprise has engaged in fraudulent activities. The fraud prediction model includes multiple first graph neural network models, multiple second graph neural network models, and a fraud prediction network structure. The specific operations include: The plurality of graph structures are respectively input into the first graph neural network model, and a second feature vector corresponding to the first feature vector of each node in each graph structure is determined; The multiple change graph structures are input into the second graph neural network model, and a third feature vector corresponding to the first feature vector of each node in each change graph structure is determined; and based on the multiple second feature vectors and multiple third feature vectors, and using the fraud prediction network structure, it is determined whether the target enterprise has engaged in fraudulent activities.

Citation Information

Patent Citations

  • Fraud detection method, device and system based on graph neural network

    CN119809663A

  • Video data-based fraud detection method and apparatus, computer device, and storage medium

    WO2021051607A1