Financial abnormal behavior detection method and system based on federated learning privacy protection

Through federated learning, the production of pseudo-samples and real data merge training is combined with encryption algorithms, and the problem of insufficient privacy protection in financial abnormal behavior detection is solved, cross-institutional collaborative training is realized, and detection accuracy and system security are improved.

CN120354313AActive Publication Date: 2025-07-22DALIAN UNIV OF TECH

Patent Information

Application Number
CN202510815074.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-18
Publication Date
2025-07-22
Estimated Expiration
2045-06-18

AI Technical Summary

Technical Problem

The existing technology has problems such as insufficient privacy protection, security risks brought by data sharing and poor generalization capabilities in financial abnormal behavior detection, which makes cross-institutional collaborative training difficult to achieve.

Method used

Using the federated learning architecture, the data security is ensured by generating pseudo-samples and real data merged and combining symmetric encryption algorithms with asymmetric encryption algorithms. At the same time, the model parameters are optimized using convolutional neural networks to achieve cross-institutional collaborative training.

Benefits of technology

It improves the accuracy and system security of financial abnormal behavior detection, enhances data compliance, reduces the security risks of data sharing, and improves the generalization capabilities of the model.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120354313A_ABST
    Figure CN120354313A_ABST
Patent Text Reader

Abstract

The invention provides a financial abnormal behavior detection method and system based on federated learning privacy protection, and relates to the technical field of artificial intelligence and data security, and the method comprises the steps: merging a candidate sample with original data, then carrying out local training, and outputting an update parameter of a local model; the locally updated model weight parameters are encrypted, and security aggregation is carried out after updating; and decrypting the updated weight of the encryption model, re-encrypting the global model and returning the encrypted global model to the local node, decrypting the global model by the local node, comparing the global model with the local model in precision, updating parameters, and performing loop iteration until the performance index of the global model tends to be stable. The problems that cross-mechanism abnormal behavior detection samples are insufficient, the model generalization ability is weak, and the recognition accuracy and efficiency are affected due to scattered financial data and high privacy requirements are solved. Federal learning and pseudo sample generation are combined, multi-mechanism collaborative modeling is realized on the premise of protecting data privacy, and model training quality and detection performance are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the fields of fintech and artificial intelligence technologies, and in particular to a method and system for detecting financial abnormal behaviors based on federated learning privacy protection. Background Art

[0002] With the digital development of financial operations, abnormal behaviors such as financial fraud and account theft are becoming increasingly complex. It has become difficult for a single financial institution to cover cross-platform abnormal behaviors by relying on its own data to train models.

[0003] In recent years, Federated Learning, as a new type of distributed machine learning architecture, can achieve a collaborative training mechanism of "data does not leave the local area, and models are shared and upgraded", improving model performance while ensuring data privacy, and has been initially applied in fields such as healthcare and communication. However, there is still a lack of a systematic and practical method system for effectively applying federated learning to financial abnormal behavior detection.

[0004] Chinese Patent Application CN117874597A discloses a federated learning financial sensitive data identification and processing system. This system uses a financial federated learning large model in cooperation with a BERT-based NER model to classify and refine the acquired data, and intelligently recommends the best desensitization algorithm to ensure data compliance and accuracy. This patent solution has certain innovation in data privacy protection, automatic sensitive information identification and desensitization, but still faces problems such as unbalanced data distribution, large computational overhead, insufficient privacy protection, limitations of rule matching, and high demand for manual intervention. Therefore, the existing technology needs a method that can solve the problem of insufficient privacy protection, improve the identification accuracy of abnormal data, reduce the security risks brought by data sharing, and thus enhance the compliance and abnormal detection capabilities of financial data. Summary of the Invention

[0005] This application provides a method and system for detecting financial abnormal behaviors based on federated learning privacy protection, solving the technical problem of a method that can solve the problem of insufficient privacy protection, improve the identification accuracy of abnormal data, reduce the security risks brought by data sharing, and thus enhance the compliance and abnormal detection capabilities of financial data.

[0006] In view of the above problems, this application provides a method and system for detecting financial abnormal behaviors based on federated learning privacy protection.

[0007] In a first aspect, the present application provides a financial anomaly behavior detection method based on federated learning privacy protection. The financial anomaly behavior detection method based on federated learning privacy protection collects local financial data, constructs a public data generator based on a base model, generates pseudo-samples similar to local abnormal data by adjusting prompt texts, merges the candidate samples with the original data, and local nodes use a convolutional neural network to perform local training on the merged data, calculates the loss of the base model in real time, and optimizes the parameters according to the loss. After the training is completed, the updated parameters of the local base model are output; the weight parameters of the local base model updated locally are encrypted by combining a symmetric encryption algorithm and an asymmetric encryption algorithm, and the encrypted weight parameters of the local base model are sent to the central node for secure aggregation; the private key held by the central node is used to decrypt the encrypted updated weights of the base model from each local node, and the decrypted updated weights are used to calculate the updated parameters of the global model. The global model is re-encrypted by combining a symmetric encryption algorithm and an asymmetric encryption algorithm and returned to the local node. The local node decrypts the global model and compares it with the local model accuracy to perform parameter update; the processes of S2 - S4 are repeatedly executed in a loop until the performance metrics of the global model tend to be stable and meet the preset convergence conditions.

[0008] In a second aspect, the present application further provides a financial anomaly behavior detection system based on federated learning privacy protection for executing the financial anomaly behavior detection method based on federated learning privacy protection as described in the first aspect. Among them, the financial anomaly behavior detection system based on federated learning privacy protection includes: a candidate sample acquisition module, which is used to collect local financial data, construct a public data generator based on a base model, generate pseudo-samples similar to local abnormal data by adjusting prompt texts, and use the pseudo-samples as candidate samples; a local model updated parameter module, which is used to merge the candidate samples with the original data, local nodes use a convolutional neural network to perform local training on the merged data, calculate the loss of the base model in real time, and optimize the parameters according to the loss. After the training is completed, the updated parameters of the local base model are output; a local model updated parameter encryption module, which is used to encrypt the weight parameters of the local base model updated locally by combining a symmetric encryption algorithm and an asymmetric encryption algorithm, and send the encrypted weight parameters of the local base model to the central node for secure aggregation; Local Node Parameter Update Module. The local node parameter update module is used to decrypt the encrypted updated weights of the base model from each local node using the private key held by the central node. The decrypted updated weights will be used to calculate the updated parameters of the global model. The global model is re-encrypted using a combination of symmetric encryption algorithm and asymmetric encryption algorithm and returned to the local node. The local node decrypts the global model, compares it with the local model accuracy, and performs parameter update. Loop Iteration Module. The loop iteration module is used to repeatedly execute the loop iteration of the local model update parameter module - local model update parameter encryption module - local node parameter update module until the performance metrics of the global model tend to be stable and meet the preset convergence conditions.

[0009] One or more technical solutions provided in this application have at least the following beneficial effects: By collecting local financial data, constructing a public data generator based on the base model, generating pseudo-samples similar to local abnormal data by adjusting the prompt text, and using the pseudo-samples as candidate samples; merging the candidate samples with the original data, the local node uses a convolutional neural network to perform local training on the merged data, calculates the loss of the base model in real time, and optimizes the parameters according to the loss. After training is completed, the updated parameters of the local base model are output; the weight parameters of the locally updated local base model are encrypted using a combination of symmetric encryption algorithm and asymmetric encryption algorithm, and the encrypted weight parameters of the local base model are sent to the central node for secure aggregation; used to decrypt the encrypted model update weights from each local node using the private key held by the central node. The decrypted updated weights will be used to calculate the updated parameters of the global model. The global model is re-encrypted using a combination of symmetric encryption algorithm and asymmetric encryption algorithm and returned to the local node. The local node decrypts the global model, compares it with the local model accuracy, and performs parameter update; repeatedly execute the process loop iteration of S2 - S4 until the performance metrics of the global model tend to be stable and meet the preset convergence conditions. Through the federated learning architecture, each financial institution collaboratively trains the model without exchanging the original data, introduces AES symmetric encryption + RSA asymmetric encryption to ensure data security during the model update process, constructs a prompt template to guide the base large model to generate pseudo-abnormal samples similar to local abnormal data, and fuses the generated samples with the real data to improve the coverage and diversity of the training set, solves the problem of scarce abnormal data, and enhances the model's learning ability for abnormal patterns.

[0010] The above description is only an overview of the technical solution of the present application. In order to better understand the technical means of the present application, it can be implemented according to the content of the specification. In order to make the above and other purposes, features, and advantages of the present application more obvious and understandable, the following specific embodiments of the present application are specifically described. It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present application, nor is it used to limit the scope of the present application. Other features of the present application will become easily understood through the following description. Brief Description of the Drawings

[0011] In order to more clearly illustrate the technical solutions in the present application or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are only exemplary. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained according to the provided drawings.

[0012] Figure 1 It is a schematic flowchart of the method for detecting financial abnormal behaviors based on federated learning privacy protection in the present application.

[0013] Figure 2 It is a flowchart of generating augmented abnormal financial data for the pre-trained base model of the method for detecting financial abnormal behaviors based on federated learning privacy protection in the present application.

[0014] Figure 3 It is a flowchart of generating model performance indicators for the Resnet18 residual network of the method for detecting financial abnormal behaviors based on federated learning privacy protection in the present application.

[0015] Figure 4 It is a flowchart of encrypting and decrypting model update parameters by combining symmetric and asymmetric algorithms for the local nodes of the method for detecting financial abnormal behaviors based on federated learning privacy protection in the present application.

[0016] Figure 5 It is a flowchart of encrypting and decrypting model update parameters by combining symmetric and asymmetric algorithms for the central node of the method for detecting financial abnormal behaviors based on federated learning privacy protection in the present application.

[0017] Figure 6 It is a federated learning structure diagram of the method for detecting financial abnormal behaviors based on federated learning privacy protection in the present application.

[0018] Figure 7 It is a schematic structural diagram of the system for the method for detecting financial abnormal behaviors based on federated learning privacy protection in the present application.

[0019] Explanation of the reference numerals: candidate sample acquisition module 11, local model update parameter module 12, local model update parameter encryption module 13, local node parameter update module 14, loop iteration module 15. DETAILED DESCRIPTION

[0020] This application provides a method and system for detecting financial abnormal behavior based on federated learning privacy protection. The invention solves the technical problems in the prior art that the training of cross-institutional abnormal behavior detection models is limited, the model generalization ability is poor, and the accuracy of abnormal identification is low due to the high sensitivity and difficulty of sharing of financial data. Through the innovative design of the prompt-based large model pseudo sample generation method, the local enhancement training mechanism, and the encrypted federation aggregation strategy, the problems of scarce abnormal data, the inability to share private data, and the unstable model fusion are overcome, thereby improving the accuracy of cross-institutional financial abnormal behavior detection and the overall security and robustness of the system.

[0021] Below, the technical solutions in the present application will be clearly and completely described with reference to the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all of the embodiments of the present application. It should be understood that the present application is not limited to the example embodiments described herein. Based on the embodiments of the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present application. It should also be noted that, for the convenience of description, only the parts related to the present application are shown in the accompanying drawings, rather than all of them.

[0022] For example, please refer to the attached Figure 1 The present application provides a method for detecting financial abnormal behavior based on federated learning privacy protection, wherein the method for detecting financial abnormal behavior based on federated learning privacy protection is executed by a financial abnormal behavior detection system based on federated learning privacy protection, and the method for detecting financial abnormal behavior based on federated learning privacy protection specifically includes the following steps: S1. Collect local financial data, construct a public data generator based on the base model, and generate pseudo samples similar to local abnormal data by adjusting the prompt text, and use the pseudo samples as candidate samples.

[0023] Furthermore, the present application S1 includes: Participants connect to their financial core systems through standardized API interfaces to collect and structure local financial transaction behavior data in real time. The data is unified into a cross-domain time-series structured format; Design prompt templates and design unified prompt texts for different types of financial data to induce the base model to learn the characteristics of financial time series structured data and generate abnormal samples. The base model is DeepSeek LLM. Form a candidate sample set from the collected local abnormal behavior samples, use the prompt template as input, and call the base generation model to generate a large number of pseudo-samples similar to the candidate sample features, thereby constructing a public abnormal behavior data set without real user data.

[0024] Specifically, the local node docks with the core system of the financial institution through the API interface to collect cross-domain financial time-series structured data such as transaction flows in real time. The participants are the entities participating in the federated learning. For example, if multiple banks jointly build federated learning, the participants are multiple banks. The financial data is the local data set, including basic transaction information: transaction timestamp, transaction amount, transaction currency / location; cardholder and anonymized merchant information: encrypted cardholder ID, merchant category code MCC, merchant geographical location; transaction behavior characteristics: interval time from historical transactions, historical consumption frequency / amount pattern, whether it is an online transaction. The collected data includes but is not limited to transaction amount, transaction time, transaction location, transaction frequency, etc. After the data is collected, data cleaning is first performed to remove noise data and missing values to ensure the integrity and accuracy of the data.

[0025] Input the cleaned data into the pre-trained open-source base model DeepSeek to independently find abnormal transaction data and learn its internal laws. Generate augmented abnormal financial data through the found features. As Figure 2 shown, the specific steps are as follows: First, input the original financial data into the pre-trained base model. Assume that each piece of data contains information such as transaction amount, transaction time, and transaction location. To guide the large model to extract the features of abnormal data, we use the following fixed text segment template as input: "Please analyze the following financial transaction data and extract the features of abnormal transactions. The transaction data is as follows: - Transaction amount: [Amount] - Transaction time: [Time] - Transaction location: [Location] - Transaction frequency: [Frequency]" Where: [Amount] is replaced with the actual transaction amount; [Time] is replaced with the actual transaction time; [Location] is replaced with the actual transaction location; [Frequency] is replaced with the actual transaction frequency.

[0026] Second, feature extraction: After filling the above fixed text segment template with actual data, input it into the pre-trained base model, and the model will extract the features of abnormal data according to the text segment prompt. For example, the model may output the following features: a) High-value transactions (abnormal transaction amount); b) High-frequency transactions (abnormal transaction frequency); c) Off-site transactions (abnormal transaction location).

[0027] Next, data augmentation. Based on the extracted features, augmented abnormal financial data is generated. To guide the large model to generate augmented abnormal data, we use the following fixed text template as input: "Please generate augmented abnormal transaction data according to the extracted abnormal features." For example, generate an augmented abnormal transaction data: - Transaction amount: 15,000 yuan - Transaction time: 2023-10-01 15:00 - Transaction location: Shanghai - Transaction frequency: 10 times per hour.

[0028] Obtain the augmented financial data. The augmented financial data is the pseudo-samples generated by adjusting the prompt text in step S1, which are similar to the local abnormal data. The process of using the pre-trained base model to augment the abnormal financial data solves the problems of data scarcity and class imbalance in federated learning in the financial scenario.

[0029] S2. Merge the candidate samples with the original data. The local node uses a convolutional neural network to perform local training on the merged data, calculates the loss of the base model in real time, and optimizes the parameters according to the loss. After the training is completed, the updated parameters of the local base model are output.

[0030] Furthermore, S2 of this application includes: Merge the abnormal data of the candidate samples with the original financial data, and perform local training on the merged data using the convolutional neural network CNN; During the training process of the local base model, use the convolutional neural network CNN as the basic structure. The CNN network includes multiple convolutional layers, pooling layers, and fully connected layers, which are used to automatically extract local features and global features in the financial behavior data; Continuously optimize the parameters of the base model through the backpropagation algorithm. During the training process, monitor the performance metrics of the base model in real time, and dynamically adjust the learning rate and network structure based on the metric results to optimize the base model. The performance metrics include loss function, accuracy, and AUC; After the training is completed, output the weight parameters of the local base model as the updated result of the local base model to participate in the subsequent global model aggregation.

[0031] Specifically, the abnormal data of the candidate samples Merge with the original data to form a new data set . As Figure 3 shown, the ResNet residual network is used to locally train the merged data, presenting the process of the ResNet18 residual network extracting financial features. The model structure is as follows: The improved ResNet18 residual neural network model adopted by the present invention is used as the basic architecture for feature extraction and classification. The merged financial data goes through Convolutional Layer 1 - Convolutional Layer 2_x - Convolutional Layer 3_x - Convolutional Layer 4_x - Convolutional Layer 5_x - Global Average Pooling - Fully Connected Layer - Softmax Operation - Fully Connected Layer - Generate Model Performance Metrics. The convolutional layer consists of five consecutive stages, namely Convolutional Layer 1, Convolutional Layer 2_x, Convolutional Layer 3_x, Convolutional Layer 4_x, and Convolutional Layer 5_x. Among them, Convolutional Layer 1 is used for initial feature extraction, and its input is a two-dimensional structured financial feature map with a size of H×W, where H represents the step size of the time dimension and W represents the financial behavior feature dimension corresponding to each time step. Convolutional Layer 1 uses a 7×7 convolutional kernel for sliding operations, with a stride of 2, and the output size is H×W. For example, H = 24 represents a 24-hour trading sequence, and W = 12 represents 12 features, such as amount, IP address, device type, etc.

[0032] The Convolutional Layer 2_x module is the first residual module group in the network, and its input is H×W, which is the same as the output size of Convolutional Layer 1. In the financial anomaly behavior detection task, H represents the time window length, and W represents the multi-dimensional financial behavior features included in each time step, such as transaction amount, transaction method, account type, device fingerprint, operation geographical location, etc. It contains 2 residual blocks and a pooling layer. Each residual block has 2 convolutional layers, and the sizes of the three convolutional kernels are 1×1, 3×3, and 1×1 in sequence. After each convolutional layer, there is batch normalization and the non-linear activation function Relu. The pooling layer is a 2×2 maximum pooling operation, and the output size is H / 2×W / 2. That is, while maintaining the feature semantic expression ability, the size of the original feature map is compressed by introducing a spatial downsampling mechanism. The first residual block in the Convolutional Layer 2_x module uses a 3×3 convolutional operation with a stride of 2 to achieve synchronous downsampling of the input feature map in the time dimension and the feature dimension; The input of the convolutional layer 3_x part is a two-dimensional feature map of H / 2×W / 2, which contains 2 residual blocks connected in sequence and 1 pooling layer. Each residual block contains two 3×3 convolutional layers and an identity mapping structure, which can realize the in-depth extraction and expression of local features while ensuring the coherence of feature semantics. After each residual block, batch normalization and ReLU activation function are used to improve the stability of the training process and the non-linear expression ability. After the residual module, the pooling layer preferably uses max pooling operation with a stride of 2 to further compress the spatial dimension of the feature map and enhance the model's perception ability of local extreme value anomalies. Through this structure, the output feature map size of the convolutional layer 3_x module is H / 4×W / 4; The input of the convolutional layer 4_x part is H / 4×W / 4, which contains 2 residual blocks connected in sequence and 1 pooling layer. Each residual block still uses a double 3×3 convolutional structure and performs skip connection through an identity mapping or 1×1 convolution for channel alignment to ensure the integrity of feature transmission and information fidelity. After the two residual blocks, the pooling layer uses max pooling operation with a stride of 2 to realize the downsampling of the feature map again, and the output size is H / 8×W / 8; The input feature map size of the convolutional layer 5_x part is H / 8×W / 8, which contains 2 residual blocks connected in sequence and 1 pooling layer. The residual block still uses a standard double 3×3 convolutional structure, and non-linear activation ReLU and batch normalization operations are introduced between the convolutions to improve the non-linear expression ability and training stability of the deep network. The skip connection part can select an identity mapping or 1×1 convolution to match the channel dimension according to whether the number of input and output channels is the same. The pooling layer continues to use max pooling operation with a stride of 2, and the output size is H / 16×W / 16.

[0033] After global average pooling is performed on the feature map output by the convolutional layer 5_x part, a fully connected operation is performed in the fully connected layer to convert the output feature map into a one-dimensional vector. Finally, a Softmax operation is performed on the one-dimensional vector, and a fully connected operation is performed again in the fully connected layer to generate the model performance index.

[0034] During the training process, the cross-entropy loss function is used to measure the difference between the model prediction result and the true label. Assume the true label is , and the probability distribution predicted by the model is , then the loss function is: ; Among them, is the true label of the rd category, and is the prediction of the model for the The probability of each category. Calculate the loss function through the Backpropagation algorithm for the model parameters gradient, and use the Gradient Descent method to update the model parameters. The specific steps are as follows: Calculate the gradient: Calculate the loss function through the chain rule for the model parameters gradient: ; where represents the gradient of the loss function with respect to the parameter .

[0035] Parameter update: Use the Gradient Descent method to update the model parameters ; ; where is the Learning Rate, which controls the step size of parameter update.

[0036] S3. Encrypt the locally updated local base model weight parameters by combining symmetric encryption algorithm and asymmetric encryption algorithm, and send the encrypted local base model weight parameters to the central node for secure aggregation.

[0037] Furthermore, S3 of this application includes: Encrypt the locally updated base model weight parameters using the AES symmetric encryption algorithm, and encrypt the AES key used using the RSA asymmetric encryption algorithm; Send the encrypted base model update weights and the encrypted symmetric key to the central node. After receiving the encrypted data, the central node decrypts the symmetric key using the private key, and then decrypts the base model weight parameters using the decrypted symmetric key.

[0038] Specifically, as Figure 4 shown, adopt the mechanism of RSA+AES hybrid encryption algorithm to protect the transmission of model parameters, taking into account both privacy security and computational efficiency. The local node generates model update parameters , and encrypts the model update parameters by combining symmetric encryption algorithm and asymmetric encryption algorithm. The specific steps are as follows: First, symmetric encryption: Encrypt the model update parameters using the AES symmetric encryption algorithm to generate the encrypted parameters . The AES encryption method is as follows: ; where is the plaintext,[[]] is the ciphertext, is the encryption function, is the secret key.

[0039] Secondly, asymmetric encryption: Use the RSA asymmetric encryption algorithm to encrypt the symmetric key for encryption to generate the encrypted key . Regarding how to calculate the RSA key, first, select two large prime numbers p and q, where p and q are usually 1024 bits; Calculate n = p×q and z = (p - 1)×(q - 1); Select a number d that is prime to z; Find an e such that e×d = 1 (mod z); The public key is (e, n), and the private key is (d, n).

[0040] The RSA encryption method is as follows: ; where P represents the plaintext block obtained by dividing the plaintext into k-bit segments, where k is the largest integer satisfying 2×k < n, C represents the ciphertext block obtained by encryption, and n represents the value of the Euler totient function.

[0041] Finally, data transmission: Transmit the encrypted model update parameters and the encrypted symmetric key to the central node.

[0042] S4. It is used to decrypt the encrypted base model update weights from each local node using the private key held by the central node. The decrypted update weights will be used to calculate the update parameters of the global model. Combine the symmetric encryption algorithm and the asymmetric encryption algorithm to re-encrypt the global model and return it to the local node. The local node decrypts the global model and compares it with the local model accuracy to perform parameter update.

[0043] Furthermore, S4 of this application includes: The central node decrypts the encrypted base model update weights from multiple local nodes using the private key held by the central node to decrypt the encrypted base model update weights from each local node; Use the decrypted update weights to calculate the update parameters of the global model. Use federated averaging to perform weighted averaging on the decrypted base model update weights to generate the global model update weights; Encrypt the global model parameters using a new AES symmetric key and encrypt this symmetric key using the RSA public key of the target node; Return the encrypted global model parameters and the key ciphertext to the corresponding local node; Decrypt the encrypted symmetric key using the RSA private key held by the local node, decrypt the encrypted global model update parameters using the decrypted symmetric key, and load the decrypted global model parameters into the local system; The local node fuses the decrypted global model parameters with the current local base model parameters to generate a new local base model; The local node evaluates the accuracy of the fused base model on local data. If the accuracy of the global model is better than that of the local base model, the local node accepts the global model update and replaces the local base model; If the accuracy of the global model is not as good as that of the local base model, the local node rejects the update, retains the existing local base model, and records the reason for the update rejection.

[0044] Specifically, as Figure 5 shown, the central node receives the encrypted model update parameters and the encrypted symmetric key , decrypts the symmetric key using its private key , and then decrypts the model update parameters using the decrypted symmetric key . The decrypted model update parameters are securely aggregated at the central node. The specific steps are as follows: First, the decryption process: The central node uses the RSA private key to decrypt the symmetric key , obtaining : ; where is the plaintext, is the ciphertext, is the decryption function, is the key.

[0045] Regarding how to calculate the RSA key, two large prime numbers p and q (usually 1024 bits) need to be selected; calculate n = p×q and z = (p - 1)×(q - 1); select a number d that is prime to z; find an e such that e×d = 1 (mod z); the public key is (e, n), and the private key is (d, n). The RSA decryption method is as follows: ; where P represents the plaintext block obtained by dividing the plaintext into k-bit segments, where k is the largest integer satisfying 2×k < n. C represents the ciphertext block obtained by encryption, and n represents the Euler totient function value.

[0046] Then, use the symmetric key to decrypt the model update parameters to obtain ; ; where represents the plaintext, represents the ciphertext, is the decryption function, is the encryption key.

[0047] Then, secure aggregation is performed. The central node uses the Federated Averaging algorithm to perform weighted averaging on the model update parameters from multiple local nodes to generate global model update parameters : ; where N is the number of local nodes participating in the aggregation.

[0048] The central node uses the AES symmetric encryption algorithm to encrypt the global model update parameters and uses the RSA asymmetric encryption algorithm to encrypt the symmetric key. The encrypted global model update parameters and the encrypted symmetric key are returned to the local nodes together. After receiving the encrypted data, the local nodes first decrypt the symmetric key using their private key, and then use the decrypted symmetric key to decrypt the global model update parameters. The specific steps are as follows: First, the decryption process: The local node uses the RSA private key to decrypt the symmetric key: ; where is the plaintext, is the ciphertext, is the decryption function, is the encryption key.

[0049] Then, use the symmetric key to decrypt the global model update parameters: ; where represents the plaintext, represents the ciphertext, represents the decryption function, is the encryption key.

[0050] Third, model fusion: The local node fuses the global model update parameters with the local model and evaluates the accuracy of the fused model. If the accuracy of the global model is better than that of the local model, the update is accepted and the local model is replaced; otherwise, the local model is retained and the reason for the update rejection is recorded.

[0051] S5. Repeatedly execute the processes of S2 - S4 in a loop until the performance metrics of the global model tend to be stable and meet the preset convergence conditions.

[0052] Furthermore, step S5 of this application includes: S5-1: After each time the local node receives the global model update, it retrains the global model using local data to generate new local model update parameters, and sends them to the central node through encrypted transmission. The local data includes original data and augmented simulated data; S5-2: The central node performs secure aggregation again, calculates new global model update parameters, and returns them to the local node; S5-3: The central node executes the secure aggregation algorithm, calculates the global model update parameters, and transmits the updated global model weights back to each local node through an encryption mechanism for use in the next round of local training; S5-4: Repeatedly execute the process of S2-S4 in a loop until the performance metrics of the global model tend to be stable and meet the preset convergence conditions.

[0053] Specifically, as Figure 6 shown, it is a federated learning structure diagram, which clarifies the working process of the federated learning architecture, and realizes cross-institutional collaborative detection through global coordination and dual privacy protection. The final global model is used for financial anomaly detection. The local node is the data holder. After each time it receives the global model update, it retrains the model using local data (including original data and augmented simulated data) to achieve local computing, generates new model update parameters, and sends them to the central node of the central server through encrypted transmission for central aggregation. The central node performs secure aggregation again, calculates new global model update parameters, and returns them to the local node. This process is iterated until the performance metrics of the global model tend to be stable and reach the preset convergence conditions. When the global model converges, the finally generated global model can be used for financial anomaly detection. Specific application scenarios include but are not limited to fraud transaction detection, account theft warning, etc.

[0054] Furthermore, in step S5-2 of this application, when the central node performs secure aggregation again, calculates new global model update parameters, and returns them to the local node, it further includes: In each round of iteration, the central node performs secure aggregation on the encrypted model update parameters returned by multiple local nodes to calculate new global model update parameters ; =SecureAgg ; Among them, is the model update generated by the i-th local node in the t-th round of training, is the encryption operation, is the decryption operation, is the set of local nodes participating in the aggregation, and SecureAgg A security aggregation algorithm executed by the central node for weighting the decrypted model updates. The aggregated global model parameters will be used as the shared model to be synchronized back to each local node in the new round. After the local node receives the global model update parameters returned by the central node it will use the update parameters to fuse with the current parameters of the local model to generate a new round of local model parameters The fusion process algorithm is as follows: = × + ; Where is the model parameter of the local node in the round, is the global model parameter of the round returned by the central node, is the fusion coefficient; The fusion coefficient controls the acceptance degree of the local model for the global parameters and is dynamically adjusted according to the model accuracy; The local node will perform an evaluation after fusion. If the accuracy of the fused model is better than the original model, it will accept the update; otherwise, it will retain the original model and record the reason for rejection.

[0055] The above has made a detailed description of the implementation method of the present invention. By building a financial anomaly behavior detection method based on federated learning privacy protection, on the one hand, it can assist multiple parties to jointly learn an accurate and general financial anomaly behavior detection model without disclosing and sharing their local user data sets; on the other hand, through the prior knowledge of the pre-trained base model, it can automatically and unsupervised learn the laws between financial anomaly behavior data, effectively improving the training efficiency; in addition, through the dual encryption mechanism combining symmetric encryption algorithm and asymmetric encryption algorithm, the security of data transmission and storage is ensured.

[0056] Embodiment 2. Based on the same inventive concept as the financial anomaly behavior detection method based on federated learning privacy protection in the foregoing Embodiment 1, the present application also provides a financial anomaly behavior detection system based on federated learning privacy protection. Please refer to the appendix Figure 7 The financial anomaly behavior detection system based on federated learning privacy protection includes: A candidate sample acquisition module 11, which is used to collect local financial data, construct a public data generator based on the base model, generate pseudo-samples similar to local abnormal data by adjusting the prompt text, and use the pseudo-samples as candidate samples; Local model update parameter module 12, which is used to merge the candidate samples with the original data. The local node uses a convolutional neural network to perform local training on the merged data, calculates the performance metrics of the base model in real time, and optimizes the parameters according to the performance metrics. After the training is completed, the updated parameters of the local base model are output; Local model update parameter encryption module 13, which is used to encrypt the weights of the locally updated local base model by combining symmetric encryption algorithm and asymmetric encryption algorithm, and send the encrypted local base model update to the central node for secure aggregation; Local node parameter update module 14, which is used to decrypt the encrypted base model update weights from each local node using the private key held by the central node. The decrypted update weights will be used to calculate the update parameters of the global model. By combining symmetric encryption algorithm and asymmetric encryption algorithm, the global model is re-encrypted and returned to the local node. The local node decrypts the global model and compares it with the local model accuracy to perform parameter update; Loop iteration module 15, which is used to repeatedly execute the loop iteration of the local model update parameter module 12 - local model update parameter encryption module 13 - local node parameter update module 14 until the performance metrics of the global model tend to be stable and meet the preset convergence conditions.

[0057] In this specification, each embodiment is described in a progressive manner. The key point of each embodiment is to illustrate the differences from other embodiments. The foregoing Figure 1 The method and specific examples of financial anomaly behavior detection based on federated learning privacy protection in the foregoing embodiments are equally applicable to the financial anomaly behavior detection system based on federated learning privacy protection in this embodiment. Through the foregoing detailed description of the method of financial anomaly behavior detection based on federated learning privacy protection, those skilled in the art can clearly know the financial anomaly behavior detection system based on federated learning privacy protection in this embodiment. Therefore, for the sake of simplicity of the specification, it will not be elaborated here.

[0058] The above description of the disclosed embodiments enables those skilled in the art to implement or use the present application. Various modifications to these embodiments will be obvious to those skilled in the art, and the general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present application. Therefore, the present application will not be limited to the embodiments shown herein, but will be accorded the widest scope consistent with the principles and novel features disclosed herein.

[0059] Obviously, those skilled in the art can make several improvements and modifications to this application without departing from the principle of this application, and these improvements and modifications also fall within the protection scope of this application.

Claims

1. A method for detecting financial abnormal behaviors based on privacy protection of federated learning, characterized in that, The method includes: S1. Collect local financial data, construct a public data generator based on a base model, generate pseudo-samples similar to local abnormal data by adjusting prompt texts, and use the pseudo-samples as candidate samples; S2. Merge the candidate samples with the original data. The local node uses a convolutional neural network to locally train the merged data, calculate the loss of the base model in real time, and optimize the parameters according to the loss. After the training is completed, output the updated parameters of the local base model; S3. Encrypt the weight parameters of the locally updated local base model by combining a symmetric encryption algorithm and an asymmetric encryption algorithm, and send the encrypted weight parameters of the local base model to the central node for secure aggregation; S4. Use the private key held by the central node to decrypt the encrypted base model updated weight parameters from each local node. The decrypted updated weights will be used to calculate the updated parameters of the global model. Combine a symmetric encryption algorithm and an asymmetric encryption algorithm to re-encrypt the global model and return it to the local node. The local node decrypts the global model and compares it with the local model accuracy to perform parameter updates; S5. Repeatedly execute the processes of S2 - S4 in a loop iteration until the performance metrics of the global model tend to be stable and meet the preset convergence conditions.

2. The financial abnormal behavior detection method based on federated learning privacy protection according to claim 1, wherein, The collecting local financial data, constructing a public data generator based on a base model, generating pseudo-samples similar to local abnormal data by adjusting prompt texts, and using the pseudo-samples as candidate samples includes: The participant connects to its financial core system through a standardized API interface, and real-time collects and structures local financial transaction behavior data, and the data is unified into a cross-domain time-series structured format; Design a prompt template, design a unified prompt text for different types of financial data to induce the base model to learn the characteristics of financial time-series structured data and generate abnormal behavior samples. The base model is the publicly available large-scale pre-trained language model DeepSeek LLM; Form a candidate sample set from the collected local abnormal behavior samples, use the prompt template as the input, and call the base generation model to generate a large number of pseudo-samples similar to the candidate sample features, so as to construct a public abnormal behavior data set without real user data.

3. The financial abnormal behavior detection method based on federated learning privacy protection according to claim 1, wherein, The merging the candidate samples with the original data, the local node using a convolutional neural network to locally train the merged data, calculating the loss of the base model in real time, and optimizing the parameters according to the loss, and outputting the updated parameters of the local base model after the training is completed includes: Merge the abnormal data of the candidate samples with the original financial data, and locally train the merged data with a convolutional neural network CNN; During the training process of the local base model, use a convolutional neural network CNN as the basic structure. The CNN network includes multiple convolutional layers, pooling layers and fully connected layers, which are used to automatically extract local features and global features in financial behavior data; Continuously optimize the parameters of the base model through the backpropagation algorithm. During the training process, monitor the performance metrics of the base model in real time, and dynamically adjust the learning rate and network structure based on the metric results to optimize the base model. The performance metrics include the loss function, accuracy, and AUC. After training is completed, output the weight parameters of the local base model as the updated result of the local base model to participate in the subsequent global model aggregation.

4. The financial abnormal behavior detection method based on federated learning privacy protection according to claim 1, characterized in that, Encrypt the weight parameters of the local base model after local update using a combination of symmetric encryption algorithm and asymmetric encryption algorithm, and send the encrypted weight parameters of the local base model to the central node for secure aggregation, including: Use the AES symmetric encryption algorithm to encrypt the weight parameters of the updated local base model, and use the RSA asymmetric encryption algorithm to encrypt the AES key used. Send the encrypted updated weight of the base model and the encrypted symmetric key to the central node. After receiving the encrypted data, the central node uses the private key to decrypt the symmetric key, and then uses the decrypted symmetric key to decrypt the weight parameters of the base model.

5. The financial abnormal behavior detection method based on federated learning privacy protection according to claim 1, characterized in that, The private key held by the central node is used to decrypt the encrypted updated weights of the base model from each local node. The decrypted updated weights will be used to calculate the updated parameters of the global model. Use a combination of symmetric encryption algorithm and asymmetric encryption algorithm to re-encrypt the global model and return it to the local node. The local node decrypts the global model and compares it with the local model accuracy to perform parameter update, including: The central node decrypts the encrypted updated weights of the base model from multiple local nodes using the private key held by the central node to decrypt the encrypted updated weights of the base model from each local node. Use the decrypted updated weights to calculate the updated parameters of the global model. Use federated averaging to perform weighted averaging on the decrypted updated weights of the base model to generate the updated weights of the global model. Encrypt the global model parameters using a new AES symmetric key, and encrypt the symmetric key using the RSA public key of the target node. Return the encrypted global model parameters and the key ciphertext to the corresponding local node. Use the RSA private key held by the local node to decrypt the encrypted symmetric key, and use the decrypted symmetric key to decrypt the encrypted updated parameters of the global model. Load the decrypted global model parameters into the local system. The local node fuses the decrypted global model parameters with the current local base model parameters to generate a new local base model. The local node evaluates the accuracy of the fused base model on the local data. If the accuracy of the global model is better than that of the local base model, the local node accepts the global model update and replaces the local base model. If the accuracy of the global model is not as good as that of the local base model, the local node rejects the update, retains the existing local base model, and records the reason for the update rejection.

6. The financial abnormal behavior detection method based on federated learning privacy protection according to claim 1, wherein Repeatedly execute the process of S2 - S4 in a loop until the performance metrics of the global model tend to be stable and meet the preset convergence conditions, including: After each receipt of the global model update, the local node retrains the global model using local data to generate new local model update parameters, and sends them to the central node through encrypted transmission. The local data includes original data and augmented simulated data; The central node performs secure aggregation again, calculates new global model update parameters, and returns them to the local node; The central node executes the secure aggregation algorithm, calculates the global model update parameters, and transmits the updated global model weights back to each local node through an encryption mechanism for the next round of local training; The processes of S2 - S4 are repeatedly executed in a loop until the performance metrics of the global model tend to be stable and meet the preset convergence conditions.

7. The financial abnormal behavior detection method based on federated learning privacy protection according to claim 6, wherein, The central node performs secure aggregation again, calculates new global model update parameters, and returns them to the local node, including: In each round of iteration, the central node securely aggregates the encrypted model update parameters returned by multiple local nodes and calculates new global model update parameters ; =SecureAgg ; Among them, is the model update generated by the i-th local node in the t-th round of training, is the encryption operation, is the decryption operation, is the set of local nodes participating in the aggregation, SecureAgg is the secure aggregation algorithm executed by the central node for weighted processing of the decrypted model updates, is the aggregated global model parameter, which will be used as the model to be synchronized back to each local node in the new round; After the local node receives the global model update parameters returned by the central node it will use the update parameters to fuse with the current parameters of the local model to generate a new round of local model parameters The fusion process algorithm is as follows: = × + ; Among them, is the model parameter of the round of the local node, is the global model parameter of the round returned by the central node, is the fusion coefficient; The fusion coefficient controls the acceptance degree of the local model for the global parameters and is dynamically adjusted according to the local model accuracy; The local node will perform an evaluation after fusion. If the accuracy of the fused model is better than the original model, the update is accepted; otherwise, the original model is retained and the reason for rejection is recorded.

8. A financial abnormal behavior detection system based on federated learning privacy protection, characterized in that The system is applied to the financial anomaly behavior detection based on federated learning privacy protection described in claim 1. The system includes: A candidate sample acquisition module, which is used to collect local financial data, construct a public data generator based on the base model, generate pseudo - samples similar to local abnormal data by adjusting the prompt text, and use the pseudo - samples as candidate samples; A local model update parameter module, which is used to merge the candidate samples with the original data. The local node uses a convolutional neural network to perform local training on the merged data, calculates the loss of the base model in real - time, and optimizes the parameters according to the loss. After the training is completed, the update parameters of the local base model are output; A local model update parameter encryption module, which is used to encrypt the locally updated local base model weight parameters by combining a symmetric encryption algorithm and an asymmetric encryption algorithm, and send the encrypted local base model weight parameters to the central node for secure aggregation; A local node parameter update module, which is used to decrypt the encrypted base model update weights from each local node using the private key held by the central node. The decrypted update weights will be used to calculate the global model update parameters. By combining a symmetric encryption algorithm and an asymmetric encryption algorithm, the global model is re - encrypted and returned to the local node. The local node decrypts the global model and compares it with the local model accuracy to perform parameter update; A loop iteration module, which is used to repeatedly execute the loop iteration of the local model update parameter module - local model update parameter encryption module - local node parameter update module until the performance metrics of the global model tend to be stable and meet the preset convergence conditions.

Citation Information

Patent Citations

  • Federal learning financial sensitive data identification and processing system

    CN117874597A

  • Abnormal financial account detection method and device based on federated learning privacy protection

    CN117592096A

  • Supply chain financial credit risk assessment method and system based on federated learning and privacy protection, and storage medium

    CN118864087A

  • Method for parallel learning of cascade classifier by object recognition

    KR1020170109304A

  • Abnormality detection method and apparatus for accounts in federal learning system, and electronic device

    WO2022237194A1

Cited By

  • Digital economic risk identification system and method based on artificial intelligence

    CN121190204A