Abnormal transaction data monitoring method and device
By constructing an abnormal transaction monitoring model, using adaptive sampling and feature hierarchical aggregation technology to optimize the transaction map, the problem of difficult to identify gang-type abnormal risk transactions in the existing technology is solved, and efficient and accurate abnormal transaction monitoring is achieved.
Patent Information
- Application Number
- CN202410573864.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-05-10
- Publication Date
- 2025-07-29
AI Technical Summary
The existing supervised machine learning model is difficult to effectively identify gang-type anomaly risk transactions, and it is impossible to quickly identify unknown new risk patterns, resulting in low monitoring efficiency and accuracy.
By constructing an abnormal transaction monitoring model, using historical transaction data to build the first transaction map, perform adaptive sampling and feature hierarchical aggregation, reconstruct the transaction map to train the graph neural network, optimize the distribution ratio and global traversal degree of abnormal nodes, and improve the ability to identify gang-type abnormal risk transactions.
It improves the monitoring efficiency and accuracy of gang-type abnormal risk transactions, ensures that the model can quickly identify potential abnormal nodes, and improves the prediction accuracy of the monitoring model.
Smart Images

Figure CN120387108A_ABST
Abstract
Description
Technical Field
[0001] This specification relates to the field of artificial intelligence technology, and in particular, to a method and device for monitoring abnormal transaction data. Background Art
[0002] Banks intercept abnormal risk transactions, which helps to ensure the stability of the economic order. There are mainly two existing ways to judge abnormal risk transactions, namely: formulating rule indicators through an expert model to monitor transactions for a period of time, and manually judging risky transactions through a visualization model of the fund flow chart. Both of these judgment methods rely on the subjective opinions of experts and have the defects of strong subjectivity and low processing efficiency. In order to improve the problems of strong subjectivity and low processing efficiency, a rule model and a supervised machine learning model can also be used to identify abnormal risk transactions. However, the existing supervised machine learning models mainly evaluate individual risks, and it is difficult to effectively capture the correlation between individuals, and it is impossible to effectively identify gang-type abnormal risk transactions. In addition, the supervised machine learning model learns based on the samples that have occurred in history, that is, it only learns the historical risk transaction patterns and it is difficult to quickly identify unknown new risk patterns. Therefore, there is an urgent need for a method for monitoring abnormal transaction data to improve the monitoring efficiency and accuracy of gang-type abnormal risk transactions. Summary of the Invention
[0003] In view of the fact that the existing supervised machine learning models mainly evaluate individual risks, and it is difficult to effectively capture the correlation between individuals, and it is impossible to effectively identify gang-type abnormal risk transactions. In addition, the supervised machine learning model learns based on the samples that have occurred in history, that is, it only learns the historical risk transaction patterns and it is difficult to quickly identify unknown new risk patterns. Therefore, there is an urgent need for a method for monitoring abnormal transaction data to improve the monitoring efficiency and accuracy of gang-type abnormal risk transactions, and this solution is proposed to overcome the above problems or at least partially solve the above problems.
[0004] On the one hand, the purpose of some embodiments of this specification is to provide a method for monitoring abnormal transaction data, and the method includes:
[0005] Receiving transaction data to be measured;
[0006] Inputting the transaction data to be measured into a preset abnormal transaction monitoring model to obtain an abnormal transaction monitoring result;
[0007] Among them, the abnormal transaction monitoring model adaptively samples based on the first transaction graph corresponding to historical transaction data to optimize the distribution ratio and global traversal degree of the first transaction graph, obtains a second transaction graph, and performs feature hierarchical aggregation on the second transaction graph to reconstruct the second transaction graph according to the hierarchical aggregation result, obtaining a third transaction graph, thereby training the first graph neural network using the third transaction graph to obtain the abnormal transaction monitoring model.
[0008] Further, the abnormal transaction monitoring model is established using the following steps:
[0009] Receive historical transaction data;
[0010] Perform one-hot encoding on the historical transaction data to obtain transaction features;
[0011] Select transaction features corresponding to a preset time panel to construct a first transaction graph according to the selection result;
[0012] Mark abnormal nodes in the first transaction graph to obtain a second transaction graph, where the second transaction graph includes normal nodes, abnormal nodes, and directed edges connecting each node;
[0013] Perform adaptive sampling on the second transaction graph to obtain sampled nodes;
[0014] Perform feature hierarchical aggregation on the node features of the sampled nodes and their neighbor nodes in the second transaction graph to obtain abnormal class node features;
[0015] Determine new abnormal nodes according to the abnormal class node features, and reconstruct the second transaction graph to obtain a third transaction graph;
[0016] Use the third transaction graph as a training sample to train the first graph neural network to obtain the abnormal transaction monitoring model.
[0017] Further, after receiving the historical transaction data, it further includes:
[0018] Clean the historical transaction data;
[0019] Perform normalization processing on the cleaned historical transaction data.
[0020] Further, the performing one-hot encoding on the historical transaction data to obtain transaction features includes:
[0021] Perform one-hot encoding and global normalization on the transaction information in the historical transaction data to obtain a first transaction sub-feature;
[0022] Perform one-hot encoding and feature summation on the user information in the historical transaction data to obtain the second transaction sub-feature;
[0023] Based on the transaction information and user information, search for legal litigation, business relationships, business risks, and business production information corresponding to the transaction information and user information from the target web page;
[0024] Use a preset text processing model to perform vector extraction and one-hot encoding on the legal litigation, business relationships, business risks, and business production information to obtain the third transaction sub-feature;
[0025] Concatenate the first transaction sub-feature, the second transaction sub-feature, and the third transaction sub-feature to obtain the transaction feature.
[0026] Further, the selecting the transaction features corresponding to the preset time panel to construct the first transaction graph according to the selection result includes:
[0027] According to the preset time panel, select the transaction features under multiple time series as the selection result;
[0028] Extract transaction objects from the selection result, use the transaction objects as transaction nodes, and determine directed edges according to the transaction relationship between the transaction objects;
[0029] Construct the first transaction graph according to the transaction nodes and directed edges.
[0030] Further, the adaptively sampling the second transaction graph to obtain sampling nodes further includes:
[0031] Determine the search domain corresponding to the second transaction graph;
[0032] Within the search domain, according to the preset population size, initialize the population using multiple chaotic mappings, and make the ratio of normal nodes to abnormal nodes in the initialization result fall within a preset ratio range;
[0033] Based on the data discreteness and randomness test, evaluate the global traversal degree of all individuals in the population;
[0034] Use a preset position update algorithm and an adaptive t-distribution perturbation mechanism to update the positions of the individuals in the population until the global traversal degree reaches a preset threshold to obtain the target population;
[0035] Use the transaction nodes corresponding to the target population as the sampling nodes.
[0036] Further, the feature hierarchical aggregation of the node features of the sampling nodes and their neighbor nodes in the second transaction graph to obtain the abnormal class node features includes:
[0037] Construct a corresponding node set according to the sampling node and the neighbor nodes of the sampling node;
[0038] Divide the node features of each node in the node set to obtain a division result including multiple division categories;
[0039] Use the aggregation functions corresponding to different division categories to perform aggregation at a preset level on the division result to obtain the abnormal class node features.
[0040] Further, taking the third transaction graph as a training sample to train the first graph neural network to obtain the abnormal transaction monitoring model further includes:
[0041] Use the local graph of the second transaction graph to train the second graph neural network to adjust the network parameters of the second graph neural network to obtain the trained second graph neural network;
[0042] Take the trained second graph neural network as the first graph neural network and use the third transaction graph to train the first graph neural network to obtain the abnormal transaction monitoring model.
[0043] On the other hand, some embodiments of this specification also provide an abnormal transaction data monitoring device, and the device includes:
[0044] A receiving module, configured to receive the to-be-detected transaction data;
[0045] A monitoring module, configured to input the to-be-detected transaction data into a preset abnormal transaction monitoring model to obtain an abnormal transaction monitoring result;
[0046] Wherein, the abnormal transaction monitoring model performs adaptive sampling based on the first transaction graph corresponding to the historical transaction data to optimize the distribution ratio and global traversal degree of the first transaction graph to obtain a second transaction graph, and performs feature hierarchical aggregation on the second transaction graph to reconstruct the second transaction graph according to the hierarchical aggregation result to obtain a third transaction graph, so as to train the first graph neural network using the third transaction graph to obtain the abnormal transaction monitoring model.
[0047] On the other hand, some embodiments of this specification also provide a computer device, including a memory, a processor, and a computer program stored on the memory, and when the computer program is run by the processor, it executes the instructions of the above method.
[0048] On the other hand, some embodiments of this specification also provide a computer storage medium, on which a computer program is stored, and when the computer program is run by the processor of the computer device, it executes the instructions of the above method.
[0049] On the other hand, some embodiments of this specification further provide a computer program product, which includes a computer program. When the computer program is executed by a processor of a computer device, the computer program executes instructions of the above method.
[0050] Some embodiments of this specification provide one or more technical solutions that have at least the following technical effects:
[0051] The embodiments of the present specification automatically receive transaction data to be tested and then utilize a pre-trained abnormal transaction monitoring model to quickly and accurately obtain abnormal transaction monitoring results. During the training of the abnormal transaction monitoring model, a corresponding first transaction graph is constructed using historical transaction data to represent transaction flows between groups. Subsequently, considering that abnormal transactions in the historical transaction data are relatively rare and highly dispersed, adaptive sampling is performed on the first transaction graph to optimize the distribution ratio and global traversal degree between abnormal nodes and normal nodes in the first transaction graph, thereby facilitating accurate identification of abnormal nodes during subsequent model training. Furthermore, since each transaction node involves multiple feature parameters, directly performing similarity detection and identification on node features during abnormal node detection and identification may result in difficulty in discovering potential abnormal nodes. Therefore, after obtaining a second transaction graph, feature hierarchical aggregation is performed on the second transaction graph to hierarchically aggregate the nodes in the second transaction graph to discover potential abnormal nodes, thereby reconstructing a third transaction graph to optimize the training sample and ensure the efficiency and accuracy of the abnormal transaction monitoring model, obtained by training the first graph neural network using the third transaction graph, in monitoring group-type abnormal risk transactions.
[0052] The above description is only an overview of the technical solutions of some embodiments of this specification. In order to more clearly understand the technical means of some embodiments of this specification, they can be implemented in accordance with the contents of the specification. In order to make the above and other purposes, features and advantages of some embodiments of this specification more obvious and easy to understand, the specific implementation methods of some embodiments of this specification are listed below. BRIEF DESCRIPTION OF THE DRAWINGS
[0053] In order to more clearly illustrate some embodiments of this specification or technical solutions in the prior art, the following briefly introduces the drawings required for the embodiments or descriptions of the prior art. Obviously, the drawings described below are only some embodiments described in this specification. For those skilled in the art, other drawings can be obtained based on these drawings without inventive work. In the drawings:
[0054] Figure 1Shows a schematic diagram of an implementation system of an abnormal transaction data monitoring method in some embodiments of this specification;
[0055] Figure 2 Shows a flowchart of an abnormal transaction data monitoring method in some embodiments of this specification;
[0056] Figure 3 Is a schematic diagram of the steps for establishing an abnormal transaction monitoring model in some embodiments of this specification;
[0057] Figure 4 Is a schematic diagram of the steps for preprocessing historical transaction data in some embodiments of this specification;
[0058] Figure 5 Is a schematic diagram of the steps for performing one-hot encoding on historical transaction data in some embodiments of this specification;
[0059] Figure 6 Is a schematic diagram of the steps for constructing a first transaction graph in some embodiments of this specification;
[0060] Figure 7 Is a schematic diagram of the steps for performing adaptive sampling on a second transaction graph in some embodiments of this specification;
[0061] Figure 8 Is a schematic diagram of the steps for performing feature hierarchical aggregation on a second transaction graph in some embodiments of this specification;
[0062] Figure 9 Is a schematic diagram of the steps for training a first graph neural network in some embodiments of this specification;
[0063] Figure 10 Is a schematic diagram of the structure of an abnormal transaction data monitoring device in some embodiments of this specification;
[0064] Figure 11 Is a schematic diagram of the structure of a computer device provided in some embodiments of this specification.
[0065]
Explanation of the reference numerals
[0066] 101, Terminal;
[0067] 102, Server;
[0068] 1001, Receiving module;
[0069] 1002, Monitoring module;
[0070] 1102, Computer device;
[0071] 1104, Processor;
[0072] 1106, Memory;
[0073] 1108. Driving mechanism;
[0074] 1110. Input / output interface;
[0075] 1112. Input device;
[0076] 1114. Output device;
[0077] 1116. Rendering device;
[0078] 1118. Graphical user interface;
[0079] 1120. Network interface;
[0080] 1122. Communication link;
[0081] 1124. Communication bus. Detailed implementation manners
[0082] In order to enable those skilled in the art of this technology to better understand the technical solutions in this specification, the technical solutions in the embodiments of this specification will be clearly and completely described below in conjunction with the accompanying drawings in some embodiments of this specification. Obviously, the described embodiments are only some embodiments of this specification, rather than all embodiments. Based on some embodiments in this specification, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the scope of protection of this specification.
[0083] It should be noted that the terms "first", "second", etc. in the specification and claims of this application and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily need to describe a specific order or sequence. It should be understood that such used data can be interchanged under appropriate circumstances so that the embodiments of this application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, device, product or equipment that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or equipment.
[0084] It should be noted that the acquisition, storage, use, processing, etc. of data in the technical solutions of this application all comply with the relevant regulations of relevant laws and regulations.
[0085] Such as Figure 1The following is a schematic diagram of an implementation system for an abnormal transaction data monitoring method according to an embodiment of the present invention, which may include: a terminal 101 and a server 102. The terminal 101 and the server 102 communicate with each other through a network. The network may include a local area network (LAN for short), a wide area network (WAN for short), the Internet, or a combination thereof, and is connected to a website, a user device (such as a computing device), and a backend system. A staff member can send an abnormal transaction data monitoring request to the server 102 through the terminal 101. After receiving the abnormal transaction data monitoring request, the server 102 calls the to-be-tested transaction data in the database for calculation and processing, obtains the monitoring result, and sends the monitoring result to the terminal 101 so that the staff member can process the business according to the monitoring result.
[0086] In an embodiment of this specification, the server 102 may be an independent physical server, or a server cluster or a distributed system composed of multiple physical servers. It may also be a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, content delivery network (CDN), and big data and artificial intelligence platforms.
[0087] In an optional embodiment, the terminal 101 may include, but is not limited to, types of electronic devices such as self-service terminal devices, desktop computers, tablet computers, laptop computers, and smart wearable devices. Optionally, the operating system running on the electronic device may include, but is not limited to, Android system, IOS system, Linux, Windows, etc. Of course, the terminal 101 is not limited to the above-mentioned electronic devices with a certain entity, and it may also be software running on the above-mentioned electronic devices.
[0088] In addition, it should be noted that Figure 1 What is shown is only an application environment provided by the present disclosure. In actual applications, there may also be multiple terminals 101, which are not limited in this specification.
[0089] Figure 2 The following is a flowchart of an abnormal transaction data monitoring method provided by an embodiment of the present invention. This specification provides the method operation steps as described in the embodiment or flowchart, but based on routine or non-creative labor, there may be more or fewer operation steps. The step order listed in the embodiment is only one way among the execution orders of numerous steps and does not represent the only execution order. When the actual system or device product executes, it may execute in the order of the method shown in the embodiment or the drawings, or execute in parallel. Specifically, such as Figure 2As shown, applying the above-mentioned server side, the method may include:
[0090] S201: receiving transaction data to be tested;
[0091] S202: Inputting the transaction data to be tested into a preset abnormal transaction monitoring model to obtain abnormal transaction monitoring results;
[0092] Among them, the abnormal transaction monitoring model performs adaptive sampling based on the first transaction graph corresponding to the historical transaction data to optimize the distribution ratio and global traversal degree of the first transaction graph to obtain a second transaction graph, and performs feature hierarchical aggregation on the second transaction graph to reconstruct the second transaction graph according to the hierarchical aggregation results to obtain a third transaction graph, and then uses the third transaction graph to train the first graph neural network to obtain the abnormal transaction monitoring model.
[0093] The embodiments of the present specification automatically receive transaction data to be tested and then utilize a pre-trained abnormal transaction monitoring model to quickly and accurately obtain abnormal transaction monitoring results. During the training of the abnormal transaction monitoring model, a corresponding first transaction graph is constructed using historical transaction data to represent transaction flows between groups. Subsequently, considering that abnormal transactions in the historical transaction data are relatively rare and highly dispersed, adaptive sampling is performed on the first transaction graph to optimize the distribution ratio and global traversal degree between abnormal nodes and normal nodes in the first transaction graph, thereby facilitating accurate identification of abnormal nodes during subsequent model training. Furthermore, since each transaction node involves multiple feature parameters, directly performing similarity detection and identification on node features during abnormal node detection and identification may result in difficulty in discovering potential abnormal nodes. Therefore, after obtaining a second transaction graph, feature hierarchical aggregation is performed on the second transaction graph to hierarchically aggregate the nodes in the second transaction graph to discover potential abnormal nodes, thereby reconstructing a third transaction graph to optimize the training sample and ensure the efficiency and accuracy of the abnormal transaction monitoring model, obtained by training the first graph neural network using the third transaction graph, in monitoring group-type abnormal risk transactions.
[0094] It can be understood that in some embodiments, the transaction data to be measured includes the transaction data between multiple transaction objects. The abnormal transaction monitoring model is a model pre-trained based on historical transaction data. The historical transaction data includes historical normal transaction data and historical abnormal transaction data. The first transaction graph is a transaction graph constructed based on historical transaction data. The transaction graph includes multiple nodes and directed edges. The directed edges represent the transfer direction of transactions, and the nodes represent transaction objects. The node features, i.e., transaction features, may include information such as transaction status, number of transaction pens, transaction area, frequency, and total amount. Specifically, the historical abnormal transaction data in the historical transaction data is much less than the historical normal transaction data. Correspondingly, the nodes with abnormal transactions in the first transaction graph are much smaller in both total number and distribution ratio compared to the nodes with normal transactions. Therefore, in order to further improve the training efficiency and prediction accuracy of the subsequent graph neural network model, it is necessary to optimize the distribution ratio of normal nodes and abnormal nodes in the first transaction graph. At the same time, it is also necessary to ensure the global traversal degree of abnormal nodes, that is, the distribution characteristics of abnormal nodes in the entire transaction graph should be as close as possible before and after optimization. After obtaining the optimized second transaction graph, considering that the dimensionality of the feature vectors of transaction nodes is relatively high, directly using the transaction node features as training samples may be difficult to ensure the retention degree of important feature information. Therefore, the segmentation performance is improved through the method of feature hierarchical aggregation, thereby further improving the monitoring accuracy of the finally trained abnormal transaction monitoring model.
[0095] Refer to the appendix Figure 3 , in some embodiments, the abnormal transaction monitoring model is established by using the following steps:
[0096] S301: Receive historical transaction data;
[0097] S302: Perform one-hot encoding on the historical transaction data to obtain transaction features;
[0098] S303: Select the transaction features corresponding to the preset time panel to construct the first transaction graph according to the selection result;
[0099] S304: Mark the abnormal nodes in the first transaction graph to obtain the second transaction graph, where the second transaction graph includes normal nodes, abnormal nodes, and directed edges connecting each node;
[0100] S305: Perform adaptive sampling on the second transaction graph to obtain sampled nodes;
[0101] S306: Perform feature hierarchical aggregation on the node features of the sampled nodes and their neighbor nodes in the second transaction graph to obtain abnormal class node features;
[0102] S307: Determine the newly added abnormal nodes according to the abnormal class node features, reconstruct the second transaction graph to obtain a third transaction graph;
[0103] S308: Use the third transaction graph as a training sample to train the first graph neural network to obtain the abnormal transaction monitoring model.
[0104] It can be understood that in some embodiments, after obtaining the historical transaction data, since the historical transaction data has discrete attributes, in order to improve the usability of the historical transaction data for the model, the historical transaction data can be one-hot encoded. One-hot encoding is also known as one-hot effective encoding. It mainly uses an N-bit status register to encode N states. Each state has its own independent register bit, and only one bit is valid at any time. Through one-hot encoding, the values of discrete features can be extended to the Euclidean space, making the subsequent calculation of the distance between features more reasonable. The preset time panel can be understood as a preset time period / preset time series. The first transaction graph constructed according to the preset time panel can fully reflect the transaction exchanges under the preset time panel. When marking the first transaction graph, the abnormal nodes and normal nodes in the first transaction graph can be marked based on a preset expert experience library, or marked with preset stock data. This article does not limit the specific marking method. It should be noted that since transactions are not one-sided, abnormal nodes are usually not independent nodes. They usually appear in the second transaction graph in groups / gangs. The directed edges connecting each node can be used to represent the flow direction of funds. After that, in order to improve the distribution ratio of abnormal nodes in the second transaction graph and at the same time take into account the global traversal degree of abnormal nodes, the abnormal class node features are obtained through adaptive sampling and feature hierarchical aggregation to determine the abnormal class nodes with potential risks. Thus, the abnormal class nodes with potential risks are used as newly added abnormal nodes to reconstruct the second transaction graph to obtain a third transaction graph for training the first graph neural network to obtain an abnormal transaction monitoring model that can accurately identify gang abnormal transaction behaviors.
[0105] Refer to the appendix Figure 4 In some embodiments, after receiving the historical transaction data, it may further include:
[0106] S401: Clean the historical transaction data;
[0107] S402: Perform normalization processing on the cleaned historical transaction data.
[0108] It can be understood that in some embodiments, there may be incomplete data / dirty data, etc. in the historical abnormal transaction data. Such data not only has no value for model training, but may also affect the training accuracy of the model and contaminate other data. Therefore, it is necessary to clean the historical transaction data to remove incomplete data and dirty data. In addition, since different types of data have different dimensions and dimension units, in order to eliminate the dimensional influence between indicators and improve the comparability between data, it is also necessary to normalize the cleaned historical transaction data.
[0109] Referring to the appendix Figure 5 , in some embodiments, the one-hot encoding of the historical transaction data to obtain transaction features may include:
[0110] S501: Perform one-hot encoding and global normalization on the transaction information in the historical transaction data to obtain a first transaction sub-feature;
[0111] S502: Perform one-hot encoding and feature summation on the user information in the historical transaction data to obtain a second transaction sub-feature;
[0112] S503: Based on the transaction information and user information, search for legal litigation, business relationships, business risks, and business production information corresponding to the transaction information and user information from the target web page;
[0113] S504: Use a preset text processing model to perform vector extraction and one-hot encoding on the legal litigation, business relationships, business risks, and business production information to obtain a third transaction sub-feature;
[0114] S505: Concatenate the first transaction sub-feature, the second transaction sub-feature, and the third transaction sub-feature to obtain the transaction feature.
[0115] It can be understood that in some embodiments, when performing one-hot encoding on historical transaction data to obtain transaction features, it is also possible to perform categorical encoding on the historical transaction data to construct transaction features. Specifically, transaction information may include transaction amount, number of transactions, transaction time, transaction object, etc., and user information may include account information and user portraits, etc. Further, in some embodiments, both transaction information and user information can be further divided or calculated to derive new feature items. For example, the transaction amount can be divided into cross-regional transaction amount, non-cross-regional transaction amount, etc., or the total debit amount, total number of debit transactions, total credit amount, total number of credit transactions, total amount of both debit and credit, total number of both debit and credit transactions, ratio of total amount of both debit and credit, ratio of total number of both debit and credit transactions, etc. The number of transactions can derive the number of transactions occurring at night, etc. This is not specifically limited herein. Since the data difference of transaction information may be large, it is also necessary to perform global normalization processing on it. In addition to one-hot encoding processing, since user information may involve data of multiple transaction accounts, it is necessary to perform feature summation processing on it to obtain the second transaction sub-feature after statistical induction. After establishing the first transaction sub-feature and the second transaction sub-feature for transaction information and user information respectively, it is also possible to search for relevant information related to transaction risks from the publicly available target web pages based on transaction information and user information, including legal litigation, business relationships, business risks, and business production information, so as to construct the third transaction feature sub-feature. Finally, the first transaction sub-feature, the second transaction sub-feature, and the third transaction sub-feature are spliced to obtain transaction features with rich feature information, so as to facilitate the prediction accuracy of the model obtained by subsequent training.
[0116] Refer to the appendix Figure 6 , in some embodiments, the selecting the transaction features corresponding to the preset time panel to construct the first transaction graph according to the selection result may include:
[0117] S601: According to the preset time panel, select the transaction features under multiple time series as the selection result;
[0118] S602: Extract the transaction objects from the selection result, use the transaction objects as transaction nodes, and determine the directed edges according to the transaction relationships between the transaction objects;
[0119] S603: Construct the first transaction graph according to the transaction nodes and the directed edges.
[0120] It can be understood that in some embodiments, due to the huge amount of historical transaction data, only the transaction features in a specified time series are selected to construct the first transaction graph. For example, the preset time panel can be a time period with a length of 10 days or 15 days, etc., the transaction object can be an individual user and / or a group user, and the transaction features can include the transaction situation between transaction objects, so as to quickly and accurately construct the first transaction graph according to the transaction features.
[0121] Refer to the appendix Figure 7 , in some embodiments, the adaptive sampling of the second transaction graph to obtain sampling nodes may further include:
[0122] S701: Determine the search domain corresponding to the second transaction graph;
[0123] S702: In the search domain, initialize the population using multiple chaotic maps according to the preset population quantity, and make the ratio of normal nodes to abnormal nodes in the initialization result fall within the preset ratio range;
[0124] S703: Based on the data discreteness and randomness tests, evaluate the global traversal degree of all individuals in the population;
[0125] S704: Use the preset position update algorithm and the adaptive t-distribution perturbation mechanism to update the positions of the individuals in the population until the global traversal degree reaches the preset threshold to obtain the target population;
[0126] S705: Use the transaction nodes corresponding to the target population as the sampling nodes.
[0127] It can be understood that in some embodiments, the purpose of adaptively sampling the second transaction graph is to increase the ratio of normal nodes to abnormal nodes in the sampled nodes compared to the corresponding ratio in the second transaction graph, and the distribution of the sampled abnormal nodes among all sampled nodes is close to the distribution of abnormal nodes in the second transaction graph. The distribution can include measures such as dispersion and shape metrics. Specifically, first, a search space corresponding to the second transaction graph, i.e., a search domain, is determined. Then, based on a preset population size, multiple chaotic mappings are used to fully ensure the randomness of initialization and reduce the possibility of falling into a local optimum. The multiple chaotic mappings can be Tent-Logistic-Cosine chaotic mappings, etc. The specific chaotic mapping method is not limited in this paper. Further, when mapping, it is necessary to make the ratio of normal nodes to abnormal nodes in the initialization result fall within a preset ratio interval. The method of separately sampling normal nodes and abnormal nodes can be used to make the ratio of normal nodes to abnormal nodes in the initialization result fall within the preset ratio interval. This is not limited in this paper. The preset ratio interval can make the ratio of normal nodes to abnormal nodes in the sampled nodes fall within a range higher than that in historical transaction data. Then, according to the dispersion and randomness of individuals in the population, the dispersion and randomness are used as evaluation indicators for the global traversal degree to evaluate the global traversal degree of individuals in the population. The preset position update algorithm can be the position update algorithm in the sparrow search algorithm or other position update algorithms. This is not limited in this paper. Further, in some embodiments, the adaptive t-distribution perturbation mechanism associates the perturbation change of the individual position with the number of iterations and is constructed using the following formula:
[0128]
[0129] Wherein, is the position of the individual after perturbation, x i is the position of the i-th individual before perturbation, and t(k) is the t-distribution with the number of iterations k as the degree of freedom.
[0130] Further, in some embodiments, in each iteration, the preset position update algorithm can be first used to update the individual position, and it is judged whether the updated individual position exceeds the preset search domain. If it exceeds, the adaptive t-distribution perturbation mechanism is used to update the individual position to ensure that the individual position is always within the search domain, thereby ensuring the effectiveness of the individual position update and preventing the individual position from falling into a local optimum. After each position update, it is necessary to judge whether the global traversal degree of all individuals in the current population reaches a preset threshold. The population when the global traversal degree reaches the preset threshold is used as the target population. The individuals in the target population are equivalent to transaction nodes, so as to quickly and accurately obtain the sampled nodes that meet the business requirements.
[0131] Refer to the appendixFigure 8 , in some embodiments, the feature hierarchical aggregation of the sampled nodes and their neighbor nodes in the second transaction graph to obtain abnormal class node features may include:
[0132] S801: Construct a corresponding node set according to the sampled node and the neighbor nodes of the sampled node;
[0133] S802: Divide the node features of each node in the node set to obtain a division result including multiple division categories;
[0134] S803: Use the aggregation functions corresponding to different division categories to perform a preset-level aggregation on the division result to obtain the abnormal class node features.
[0135] It can be understood that in some embodiments, after obtaining the sampled nodes, a corresponding node set is constructed according to the sampled nodes and their neighbor nodes. There may be abnormal class nodes with potential transaction risks in the node set, and based on preset business requirements and business attributes, the node features can be divided. For example, they can be divided into: loan ratio class features, amount and number of transactions class features, non-loan ratio class features, and non-amount and number of transactions class features. Further, in some embodiments, for loan ratio class features, the max pooling aggregation function can be used; for non-loan ratio class features and non-amount and number of transactions class features, the mean pooling aggregation function can be used; for amount and number of transactions class features, the sum aggregation function can be used, so as to fully ensure that effective feature information is retained to improve the accuracy of the finally obtained abnormal class node features. Specifically, in some embodiments, the max pooling aggregation function can be constructed using the following formula:
[0136]
[0137] where AGGREGATE pool1 is the max pooling aggregation function, max is to take the maximum value, σ is a non-linear function, W pool is the weight matrix, is the k-th order aggregated node, b is the adjustment parameter, N(v) is the sampled node set, u is any node in N(v), i is any loan ratio class feature, and F1 is the loan ratio class feature set.
[0138] Specifically, in some embodiments, the mean pooling aggregation function can be constructed using the following formula:
[0139]
[0140] where AGGREGATE pool2For the mean pooling aggregation function, mean is to take the average value, σ is a non-linear function, and W pool is the weight matrix, is the k-th order aggregation node, b is the adjustment parameter, N(v) is the set of sampled nodes, u is any node in N(v), i is any non-loan ratio type feature and non-amount transaction count type feature, and F2 is the set of non-loan ratio type features and non-amount transaction count type features.
[0141] Specifically, in some embodiments, the sum aggregation function can be constructed using the following formula:
[0142]
[0143] where AGGREGATE sum is the sum aggregation function, σ is a non-linear function, sum is to take the total, W is the weight matrix, is the (k - 1)-th order aggregation node, N(v) is the set of sampled nodes, u is any node in N(v), i is any amount transaction count type feature, and F3 is the set of amount transaction count type features.
[0144] Referring to the appendix Figure 9 , in some embodiments, using the third transaction graph as a training sample to train the first graph neural network to obtain the abnormal transaction monitoring model may further include:
[0145] S901: Using the local graph of the second transaction graph to train the second graph neural network to adjust the network parameters of the second graph neural network to obtain the trained second graph neural network;
[0146] S902: Using the trained second graph neural network as the first graph neural network and using the third transaction graph to train the first graph neural network to obtain the abnormal transaction monitoring model.
[0147] It can be understood that in some embodiments, since the third transaction graph still has a large amount of data, before obtaining the third transaction graph to train the first graph neural network, the local graph of the second transaction graph can be used to train the second graph neural network first. On the premise of minimizing the training amount as much as possible, the network parameters of the second graph neural network are adjusted to learn the internal rules and connections of the data in the second transaction graph. Using the trained second graph neural network as the first graph neural network, and then using the third transaction graph to train the first graph neural network, so that the first graph neural network can quickly analyze and predict the third transaction graph to improve the model training efficiency and prediction accuracy.
[0148] It should be noted that although the operations of the method of the present invention are described in a specific order in the above embodiments and accompanying drawings, this does not require or imply that these operations must be performed in that specific order, or that all the operations shown must be performed to achieve the desired result. Additionally or alternatively, certain steps may be omitted, multiple steps may be combined into one step for execution, and / or one step may be decomposed into multiple steps for execution.
[0149] Corresponding to the above abnormal transaction data monitoring method, some embodiments of this specification also provide an abnormal transaction data monitoring device. Referring to Figure 10 as shown, in some embodiments, the device may include:
[0150] A receiving module 1001, configured to receive transaction data to be measured;
[0151] A monitoring module 1002, configured to input the transaction data to be measured into a preset abnormal transaction monitoring model to obtain an abnormal transaction monitoring result;
[0152] Wherein, the abnormal transaction monitoring model performs adaptive sampling based on a first transaction graph corresponding to historical transaction data to optimize the distribution ratio and global traversal degree of the first transaction graph, obtains a second transaction graph, and performs feature hierarchical aggregation on the second transaction graph to reconstruct the second transaction graph according to the hierarchical aggregation result to obtain a third transaction graph, so as to train the first graph neural network using the third transaction graph to obtain the abnormal transaction monitoring model.
[0153] For the convenience of description, when describing the above device, various units are described separately according to their functions. Of course, when implementing this specification, the functions of each unit can be implemented in one or more software and / or hardware.
[0154] It should be noted that in the embodiments of this specification, the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved are all information and data that have been authorized and consented to by the user and fully authorized by all parties, and the collection, storage, use, processing, transmission, provision, disclosure, and application, etc. of the relevant data all comply with the relevant laws, regulations, and standards of the relevant countries and regions, have taken necessary confidentiality measures, do not violate public order and good customs, and provide corresponding operation entrances for users to choose to authorize or refuse.
[0155] It should be noted that in the embodiments of this specification, corresponding operation entrances are provided for users to choose to agree or refuse the automated decision-making results; if the user chooses to refuse, the expert decision-making process will be entered.
[0156] It should be noted that the computer program product described in this specification (this application) is a software product that mainly implements the method described in this specification (this application) through a computer program.
[0157] The embodiments of this specification also provide a computer device. As Figure 11 shown, in some embodiments of this specification, the computer device 1102 may include one or more processors 1104, such as one or more central processing units (CPUs) or graphics processing units (GPUs), and each processing unit may implement one or more hardware threads. The computer device 1102 may also include any memory 1106, which is used to store any kind of information such as code, settings, data, etc. In a specific embodiment, a computer program that can be run on the memory 1106 and on the processor 1104. When the computer program is run by the processor 1104, it can execute the instructions of the method described in any of the above embodiments. Non-limitingly, for example, the memory 1106 may include any one or more combinations of the following: any type of RAM, any type of ROM, flash memory devices, hard disks, optical discs, etc. More generally, any memory can use any technology to store information. Further, any memory can provide volatile or non-volatile retention of information. Further, any memory can represent a fixed or removable component of the computer device 1102. In one case, when the processor 1104 executes the associated instructions stored in any memory or combination of memories, the computer device 1102 can perform any operation of the associated instructions. The computer device 1102 also includes one or more drive mechanisms 1108 for interacting with any memory, such as a hard disk drive mechanism, an optical disc drive mechanism, etc.
[0158] The computer device 1102 may also include an input / output interface 1110 (I / O), which is used to receive various inputs (via the input device 1112) and to provide various outputs (via the output device 1114). A specific output mechanism may include a presentation device 1116 and an associated graphical user interface 1118 (GUI). In other embodiments, the input / output interface 1110 (I / O), the input device 1112, and the output device 1114 may not be included, and it only serves as a computer device in a network. The computer device 1102 may also include one or more network interfaces 1120, which are used to exchange data with other devices via one or more communication links 1122. One or more communication buses 1124 couple the components described above together.
[0159] The communication link 1122 can be implemented in any way, for example, through a local area network, a wide area network (e.g., the Internet), a point-to-point connection, etc., or any combination thereof. The communication link 1122 can include any combination of hardwired links, wireless links, routers, gateway functions, name servers, etc. governed by any protocol or combination of protocols.
[0160] This application is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), computer-readable storage media, and computer program products according to some embodiments of this specification. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, as well as the combination of flows and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processors to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processors generate means for implementing the functions specified in Figure 1 one or more flows and / or blocks Figure 1 one or more blocks.
[0161] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processors to work in a specific manner, such that the instructions stored in the computer-readable memory generate a manufactured article including instruction means that implement the functions specified in Figure 1 one or more flows and / or blocks Figure 1 one or more blocks.
[0162] These computer program instructions can also be loaded onto a computer or other programmable data processors, such that a series of operation steps are executed on the computer or other programmable devices to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable devices provide steps for implementing the functions specified in Figure 1 one or more flows and / or blocks Figure 1 one or more blocks.
[0163] In a typical configuration, a computer device includes one or more processors (CPUs), an input / output interface, a network interface, and a memory.
[0164] The memory may include non-permanent memory in the form of computer-readable media, random access memory (RAM), and / or non-volatile memory, such as read-only memory (ROM) or flash memory (flash RAM). The memory is an example of computer-readable media.
[0165] A computer-readable medium includes both permanent and non-permanent, removable and non-removable media that can store information by any method or technology. The information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, magnetic disk storage or other magnetic storage devices, or any other non-transitory medium that can be used to store information that can be accessed by a computing device. As defined in this specification, a computer-readable medium does not include transitory computer-readable media such as modulated data signals and carrier waves.
[0166] Those skilled in the art will appreciate that the embodiments of this specification can be provided as a method, a system, or a computer program product. Accordingly, the embodiments of this specification can take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware aspects. Moreover, the embodiments of this specification can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.
[0167] The embodiments of this specification can be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. The embodiments of this specification can also be practiced in a distributed computing environment where tasks are performed by remote processors connected through a communication network. In a distributed computing environment, program modules can be located in local and remote computer storage media including storage devices.
[0168] It should also be understood that in the embodiments of this specification, the term "and / or" is merely a description of the association relationship between associated objects, indicating that three relationships can exist. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. Additionally, the character " / " in this text generally represents an "or" relationship between the associated objects before and after.
[0169] Each embodiment in this specification is described in a progressive manner. For the same or similar parts among the embodiments, reference can be made to each other, and the differences between each embodiment and other embodiments are emphasized. In particular, for system embodiments, since they are basically similar to method embodiments, the description is relatively simple, and the relevant parts can refer to the description of the method embodiments.
[0170] In the description of this specification, the description with reference to terms such as "one embodiment", "some embodiments", "example", "specific example", or "some examples" means that the specific features, structures, materials, or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the embodiments of this specification. In this specification, the schematic description of the above terms does not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described can be combined in a suitable manner in any one or more embodiments or examples. In addition, without contradiction, those skilled in the art can combine and combine the different embodiments or examples described in this specification and the features of different embodiments or examples.
[0171] The above description is only for the embodiments of this application and is not intended to limit this application. For those skilled in the art, various changes and modifications can be made to this application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of this application shall be included within the scope of the claims of this application.
Claims
1. An abnormal transaction data monitoring method, characterized in that, The method includes: Receiving transaction data to be measured; Inputting the transaction data to be measured into a preset abnormal transaction monitoring model to obtain an abnormal transaction monitoring result; Among them, the abnormal transaction monitoring model performs adaptive sampling based on a first transaction graph corresponding to historical transaction data to optimize the distribution ratio and global traversal degree of the first transaction graph, obtains a second transaction graph, and performs feature hierarchical aggregation on the second transaction graph to reconstruct the second transaction graph according to the hierarchical aggregation result to obtain a third transaction graph, thereby training the first graph neural network using the third transaction graph to obtain the abnormal transaction monitoring model.
2. The method according to claim 1, characterized in that, The abnormal transaction monitoring model is established by using the following steps: Receiving historical transaction data; Performing one-hot encoding on the historical transaction data to obtain transaction features; Selecting transaction features corresponding to a preset time panel to construct a first transaction graph according to the selection result; Marking abnormal nodes in the first transaction graph to obtain a second transaction graph, where the second transaction graph includes normal nodes, abnormal nodes, and directed edges connecting each node; Performing adaptive sampling on the second transaction graph to obtain sampled nodes; Performing feature hierarchical aggregation on the node features of the sampled nodes and their neighbor nodes in the second transaction graph to obtain abnormal class node features; Determining new abnormal nodes according to the abnormal class node features and reconstructing the second transaction graph to obtain a third transaction graph; Using the third transaction graph as a training sample to train the first graph neural network to obtain the abnormal transaction monitoring model.
3. The method according to claim 2, wherein After receiving the historical transaction data, it further includes: Cleaning the historical transaction data; Performing normalization processing on the cleaned historical transaction data.
4. The method according to claim 2, wherein The performing one-hot encoding on the historical transaction data to obtain transaction features includes: Performing one-hot encoding and global normalization on the transaction information in the historical transaction data to obtain a first transaction sub-feature; Performing one-hot encoding and feature summation on the user information in the historical transaction data to obtain a second transaction sub-feature; Based on the transaction information and user information, searching for legal litigation, business relationships, business risks, and business production information corresponding to the transaction information and user information from the target web page; Using a preset text processing model to perform vector extraction and one-hot encoding on the legal litigation, business relationships, business risks, and business production information to obtain a third transaction sub-feature; Concatenating the first transaction sub-feature, the second transaction sub-feature, and the third transaction sub-feature to obtain the transaction features.
5. The method according to claim 2, wherein The selecting transaction features corresponding to a preset time panel to construct a first transaction graph according to the selection result includes: According to the preset time panel, selecting transaction features under multiple time series as the selection result; Extracting transaction objects from the selection result, using the transaction objects as transaction nodes, and determining directed edges according to the transaction relationship between the transaction objects; Constructing the first transaction graph according to the transaction nodes and directed edges.
6. The method according to claim 2, wherein The performing adaptive sampling on the second transaction graph to obtain sampled nodes further includes: Determine the search domain corresponding to the second transaction graph; Within the search domain, initialize the population using multiple chaotic mappings according to a preset population size, and ensure that the ratio of normal nodes to abnormal nodes in the initialization result is within a preset ratio range; Based on data discreteness and randomness tests, evaluate the global traversal degree of all individuals in the population; Use a preset position update algorithm and an adaptive t-distribution perturbation mechanism to update the positions of the individuals in the population until the global traversal degree reaches a preset threshold to obtain a target population; Use the transaction nodes corresponding to the target population as the sampling nodes.
7. The method according to claim 2, wherein The feature hierarchical aggregation of the node features of the sampling nodes and their neighbor nodes in the second transaction graph to obtain abnormal class node features includes: Construct a corresponding node set according to the sampling nodes and the neighbor nodes of the sampling nodes; Divide the node features of each node in the node set to obtain a division result including multiple division categories; Use the aggregation functions corresponding to different division categories to perform preset-level aggregation on the division result to obtain the abnormal class node features.
8. The method according to claim 2, wherein Use the third transaction graph as a training sample to train the first graph neural network to obtain the abnormal transaction monitoring model, which further includes: Use the local graph of the second transaction graph to train the second graph neural network to adjust the network parameters of the second graph neural network to obtain a trained second graph neural network; Use the trained second graph neural network as the first graph neural network and use the third transaction graph to train the first graph neural network to obtain the abnormal transaction monitoring model.
9. An abnormal transaction data monitoring device, characterized in that, The device includes: A receiving module for receiving the to-be-tested transaction data; A monitoring module for inputting the to-be-tested transaction data into a preset abnormal transaction monitoring model to obtain an abnormal transaction monitoring result; Among them, the abnormal transaction monitoring model performs adaptive sampling based on the first transaction graph corresponding to the historical transaction data to optimize the distribution ratio and global traversal degree of the first transaction graph to obtain a second transaction graph, and performs feature hierarchical aggregation on the second transaction graph to reconstruct the second transaction graph according to the hierarchical aggregation result to obtain a third transaction graph, so as to train the first graph neural network using the third transaction graph to obtain the abnormal transaction monitoring model.
10. A computer device, comprising a memory, a processor, and a computer program stored on the memory, characterized in that, When the computer program is run by the processor, it executes the instructions of the method according to any one of claims 1-8.
11. A computer storage medium having a computer program stored thereon, characterized in that, When the computer program is run by the processor of the computer device, it executes the instructions of the method according to any one of claims 1-8.
12. A computer program product, characterized in that, The computer program product includes a computer program, and when the computer program is run by the processor, it executes the instructions of the method according to any one of claims 1-8.