Repaid money security defense method and system based on informatization data processing

Through multi-source heterogeneous data fusion and graph computing technology, dynamic fund network portrait is constructed, combined with machine learning models to identify abnormal flow characteristics, the problems of lag in identification of reserve fund misappropriation risk and low defense response efficiency are solved, real-time risk score and hierarchical defense operations are realized, and real-time and refined control of the risk control system are improved.

CN120410539AActive Publication Date: 2025-08-01YIBIN DIGITAL CHAIN INTELLIGENT TECH CO LTD

Patent Information

Application Number
CN202510905792.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-02
Publication Date
2025-08-01
Estimated Expiration
2045-07-02

AI Technical Summary

Technical Problem

In the third-party payment business, the identification of misappropriation risks of reserve funds is lagging behind and the defense response is inefficient. Traditional risk control systems cannot effectively identify new misappropriation methods, and the response measures are out of touch with the risk level, resulting in misappropriation behavior hidden in data silos, and real-time risk scores and hierarchical responses cannot be achieved.

Method used

The real-time fusion of multi-source heterogeneous data generates a unified risk signal, and the graph computing technology is used to build a dynamic fund network portrait, combine machine learning models to identify abnormal flow characteristics, generate real-time risk scores, and automatically trigger hierarchical defense operations based on the dynamic threshold rule library.

Benefits of technology

Real-time risk score and dynamic defense response to reserve fund accounts are realized, the efficiency of identifying misappropriation risks is improved, the risk of capital loss is reduced, and the real-time and refined control of the risk control system is enhanced.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120410539A_ABST
    Figure CN120410539A_ABST
Patent Text Reader

Abstract

The invention discloses an informatization data processing-based excess payment security defense method and system, and the method comprises the steps: S1, receiving a multi-source heterogeneous data stream in real time, carrying out the cleaning, standardization, correlation analysis and semantic comprehension processing of the multi-source heterogeneous data stream, and carrying out the fusion to generate a unified risk data signal; s2, based on the unified risk data signal, constructing a dynamically updated reserve payment risk portrait signal by applying a graph computing technology; s3, inputting the unified risk data signal and the reserve payment risk portrait signal into a pre-trained machine learning model for real-time analysis, and generating a real-time risk scoring signal for a specific reserve payment account; and S4, matching the real-time risk scoring signal with a corresponding threshold according to a preset risk scoring threshold rule base. According to the invention, the method and system can solve the problems that the risk recognition of the embezzlement of the excess money is lagged, and the defending response efficiency is low.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of payment security risk control in fintech, and particularly to a safety defense method and system for reserve funds based on information data processing. Background Art

[0002] In third-party payment services, reserve funds, as the temporarily deposited funds of user payments, have long faced risks such as misappropriation and illegal transfer. Traditional risk control systems rely on bank custody data and manual audits, and have three major defects: First, data fragmentation leads to risk blind spots. Data such as the transaction flow of payment institutions, bank custody balances, and merchant historical behaviors are scattered in independent systems, and the ability to perform cross-source correlation analysis is weak. For example, when a merchant splits fund transfers through associated accounts, a single system can only capture fragmented transactions and cannot restore the complete fund closed-loop path, resulting in misappropriation behaviors being hidden in data islands.

[0003] Second, the identification mechanism lags behind risk evolution. Existing rule engines are mainly based on static thresholds (such as single-transaction limits) or simple statistical models (such as periodic balance fluctuations), and are poorly adaptable to new misappropriation means. When malicious merchants adopt evasion strategies such as high-frequency small-amount transfers and abnormal balance precipitation during holidays, the system often lacks the ability to analyze multi-dimensional behavioral characteristics and can only trigger an alarm after the funds are actually transferred, missing the best interception opportunity.

[0004] Finally, the response measures are out of touch with the risk level. Current solutions mostly adopt a binary disposal of "freeze / release" and lack refined control. For example, directly freezing a suspicious account can block risks, but misjudgment will affect the normal operation of merchants; if only a warning is given, it may lead to large-scale fund losses. Existing technologies are difficult to achieve hierarchical responses based on real-time risk scores, and even more difficult to build a risk conduction inhibition mechanism. Summary of the Invention

[0005] In view of the above-mentioned disadvantages of the prior art, the purpose of the present invention is to provide a safety defense method and system for reserve funds based on information data processing, which is used to solve the problems of lagging identification of reserve fund misappropriation risks and low efficiency of defense responses. The present invention generates a unified risk signal through real-time fusion of multi-source heterogeneous data, constructs a dynamic fund network portrait using graph computing technology, combines a machine learning model to identify abnormal flow characteristics and output a risk score, and finally automatically triggers hierarchical defense operations based on a dynamic threshold rule library.

[0006] The present invention provides a safety defense method for reserve funds based on information data processing, including: S1: Real-time receive multi-source heterogeneous data streams, and perform cleaning, standardization, correlation analysis, and semantic understanding processing on the multi-source heterogeneous data streams, and fuse them to generate a unified risk data signal representing the status of reserve funds, the flow of funds, the behaviors of related parties, and potential risk points; S2: Based on the unified risk data signal, apply graph computing technology to construct a dynamically updated risk portrait signal for reserve funds. The risk portrait signal includes the fund network topology relationship and real-time risk characteristics. S3: Input the unified risk data signal and the risk portrait signal of reserve funds into a pre-trained machine learning model for real-time analysis. The machine learning model identifies the abnormal flow characteristics and misappropriation risk characteristics of reserve funds based on historical risk patterns and unsupervised anomaly detection, and generates a real-time risk scoring signal for a specific reserve fund account. S4: According to the preset risk scoring threshold rule library, match the real-time risk scoring signal with the corresponding threshold, and automatically trigger and execute the defense response operation signal corresponding to the risk level. The defense response operation signal includes generating a risk warning signal, triggering a transaction review signal, executing a fund transfer delay signal, and implementing an account temporary freeze signal.

[0007] In an embodiment of the present invention, in step S1, the multi-source heterogeneous data stream includes the real-time transaction flow signal of the payment transaction system, the fund custody status change signal of the bank custody system, the historical violation behavior characteristic signal of the merchant portrait system, the operation trajectory time series signal of the user behavior analysis system, and the risk notification signal of the external supervision system. When performing cross-source correlation analysis on the above signals, through timestamp alignment and entity resolution technology, the fund operation events of the same merchant scattered in different systems are aggregated into a continuous behavior sequence signal, and based on this behavior sequence signal, the sudden change characteristics of the fund flow rate, the overlap degree characteristics of transaction counterparts, and the abnormal characteristics of the operation period are extracted, and a unified risk data signal containing dynamic behavior fingerprints is generated.

[0008] In an embodiment of the present invention, in step S2, take the reserve fund account as the central node, the fund transfer path as the directed edge, and the associated merchant as the secondary node to establish a multi-layer fund network topology structure. Detect the abnormal fund closed-loop flow pattern by real-time calculating the fund transfer density signal, edge weight mutation signal, and subgraph clustering coefficient signal between nodes. At the same time, fuse the external risk notification signal to apply risk marks to the associated nodes, and generate a risk portrait signal containing the heat map characteristics of the distribution of high-risk nodes and the vulnerability rating of the fund path.

[0009] In an embodiment of the present invention, in step S3, the machine learning model includes a time series pattern recognition module and a relationship network analysis module operating in parallel: the time series pattern recognition module extracts convolutional features from the fund balance fluctuation signal in the unified risk data signal to identify the periodic misappropriation feature waveform; the relationship network analysis module receives the subgraph clustering coefficient signal in the risk portrait signal and learns the abnormal fund aggregation pattern through a graph neural network. After the feature vectors output by the two modules are weighted by the fusion layer, a real-time risk scoring signal based on multi-dimensional risk contribution is generated.

[0010] In one embodiment of the present invention, the timing pattern recognition module adopts long short-term memory network units. Its input layer receives the end-of-day balance timing signal of the provision fund account after normalization processing. The hidden layer extracts features including but not limited to short-term volatility variance features, long-term trend deviation features, and holiday effect anomaly features. The output layer generates a probability signal representing abnormal fund precipitation, and this signal serves as the core weight factor of the real-time risk scoring signal.

[0011] In one embodiment of the present invention, in step S3, the preset risk scoring threshold rule library adopts a dynamic interval division mechanism: according to the current regulatory policy intensity signal, the industry risk level benchmark signal, and the system historical false alarm rate feedback signal, it automatically adjusts the width of the risk scoring threshold interval and the grading critical value. The high-risk threshold interval is positively correlated with the fund loss scale feature in the regulatory penalty case library, and the medium-risk threshold interval dynamically narrows with the merchant credit rating signal.

[0012] In one embodiment of the present invention, when the real-time risk scoring signal matches the high-risk threshold, the account temporary freeze signal includes a phased control strategy: in the first stage, a restricted transfer instruction signal is generated, only allowing funds to flow back to the white list accounts; in the second stage, a fund flow traceability signal is triggered, forcing the related party to provide compliance certification materials; in the final stage, based on the verification result signal of the certification materials, a full freeze or restriction removal operation is performed.

[0013] In one embodiment of the present invention, in step S4, during the execution of the fund transfer delay signal, the concurrent operation request signal of the delayed account is monitored in real time: if the characteristics of high-frequency small-amount exploratory transfers are detected, a secondary risk scoring signal is immediately generated. When the secondary risk score exceeds the first score value, the defense response is automatically upgraded to an account temporary freeze signal and a regulatory report signal is generated.

[0014] In one embodiment of the present invention, after generating the risk warning signal, a risk conduction suppression barrier is synchronously constructed: according to the fund network topology relationship in the risk portrait signal, a risk self-inspection instruction signal is sent to the high-risk related accounts. If the related account does not return the self-inspection result signal within the preset period, its risk scoring threshold is reduced and it is included in the real-time monitoring white list.

[0015] The present invention also provides a provision fund security defense system based on information data processing, including: An acquisition module that receives multi-source heterogeneous data streams in real time and fuses them to generate a unified risk data signal representing the provision fund status, fund flow, related party behavior, and potential risk points; A coordination module that, based on the unified risk data signal, constructs a dynamically updated provision fund risk portrait signal by applying graph computing technology; A verification module inputs the unified risk data signal and the provision risk portrait signal into a pre-trained machine learning model for real-time analysis. The machine learning model identifies the abnormal flow characteristics and misappropriation risk characteristics of provisions based on historical risk patterns and unsupervised anomaly detection, and generates a real-time risk scoring signal for a specific provision account. An early warning module matches the real-time risk scoring signal with the corresponding threshold according to a preset risk scoring threshold rule library, and automatically triggers and executes a defense response operation signal corresponding to the risk level. The defense response operation signal includes generating a risk warning signal, triggering a transaction review signal, executing a fund transfer delay signal, and implementing a temporary account freeze signal.

[0016] The provision security defense method and system based on information data processing provided by the present invention generate a unified risk signal through real-time fusion of multi-source heterogeneous data, construct a dynamic fund network portrait using graph computing technology, identify abnormal flow characteristics and output a risk score in combination with a machine learning model, and finally automatically trigger a hierarchical defense operation based on a dynamic threshold rule library. Description of the Drawings

[0017] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings required for the description of the embodiments will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present invention, and those of ordinary skill in the art can obtain other drawings without creative efforts based on these drawings.

[0018] Figure 1 It is a method flow chart of a provision security defense method based on information data processing; Figure 2 It is a system architecture diagram of a provision security defense system based on information data processing. Detailed Embodiments

[0019] The following illustrates the embodiments of the present invention through specific specific examples. Those skilled in the art can easily understand other advantages and effects of the present invention from the content disclosed in this specification. The present invention can also be implemented or applied through other different specific embodiments, and various details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of the present invention. It should be noted that, without conflict, the following embodiments and the features in the embodiments can be combined with each other.

[0020] It should be noted that the illustrations provided in the following embodiments only schematically illustrate the basic concept of the present invention. Therefore, only the components related to the present invention are shown in the drawings, rather than being drawn according to the number, shape, and size of the components in actual implementation. The type, quantity, and proportion of each component in actual implementation can be arbitrarily changed, and the component layout type may also be more complex.

[0021] In the following description, a large number of details are explored to provide a more thorough explanation of the embodiments of the present invention. However, it is obvious to those skilled in the art that the embodiments of the present invention can be implemented without these specific details. In other embodiments, well-known structures and devices are shown in the form of block diagrams rather than in detail to avoid making the embodiments of the present invention difficult to understand.

[0022] Please refer to Figure 1-2 , which shows the method and system for the safety defense of provision funds based on information-based data processing of the present invention. The method for the safety defense of provision funds based on information-based data processing of the present invention includes: S1: Real-time receiving multi-source heterogeneous data streams, and performing cleaning, standardization, correlation analysis, and semantic understanding processing on the multi-source heterogeneous data streams, and fusing and generating a unified risk data signal representing the status of provision funds, the flow of funds, the behavior of related parties, and potential risk points; S2: Based on the unified risk data signal, applying graph computing technology to construct a dynamically updated risk portrait signal of provision funds, and the risk portrait signal includes the fund network topology relationship and real-time risk characteristics; S3: Inputting the unified risk data signal and the risk portrait signal of provision funds into a pre-trained machine learning model for real-time analysis, and the machine learning model identifies the characteristics of abnormal fund flows and misappropriation risk characteristics of provision funds based on historical risk patterns and unsupervised anomaly detection, and generates a real-time risk score signal for a specific provision fund account; S4: According to the preset risk score threshold rule library, matching the real-time risk score signal with the corresponding threshold, and automatically triggering and executing a defense response operation signal corresponding to the risk level; The defense response operation signal includes generating a risk warning signal, triggering a transaction review signal, executing a fund transfer delay signal, and implementing an account temporary freeze signal.

[0023] As Figure 1As shown, the system continuously accesses the encrypted transaction flow signal generated by the payment transaction system, which contains fields such as transaction timestamp, amount, and counterparty hash identifier; synchronously receives the fund status change pulse signal of the bank custody system, reflecting the instantaneous fluctuation of the balance of the reserve fund account and the execution status of the custody instruction; at the same time, collects the risk label vector signal of the merchant portrait system (such as the historical number of violations, complaint rate quantization index) and the operation trajectory time series signal of the user behavior analysis system (including login device fingerprint, session duration, function jump path). The above signals enter the cleaning engine after asynchronous buffering through the distributed message queue: First, null value filling and outlier smoothing are performed. For example, the box plot statistical method is used to identify outliers in the transaction amount field and replace them with the mean of adjacent periods; secondly, through regular expression matching and semantic role annotation, the unstructured operation logs are converted into structured event sequences; finally, the timestamp alignment technology is adopted, taking the fund transfer instruction as the reference event, and aggregating the related events scattered in the payment system (transaction creation time T1), bank system (fund arrival time T2), and merchant system (commodity delivery time T3) into a behavior sequence signal on the unified time axis. This sequence signal extracts key features through a sliding window: calculating the change rate of the net fund outflow rate within a unit window as a mutation feature, counting the overlap degree between the set of trading counterparts and historical cooperation parties as an associated anomaly feature, and detecting the operation frequency during non-working hours at night or on holidays as a period anomaly feature. The vectorized splicing of the above features generates a dynamic behavior fingerprint, and then outputs a unified risk data signal, whose data structure contains three tensors: time dimension, entity dimension, and risk feature dimension.

[0024] Furthermore, taking the reserve fund account in the unified risk data signal as the root node, connecting merchant nodes (secondary nodes) and final recipient nodes (leaf nodes) according to the directed edges of the fund transfer path, a multi-layer fund network is constructed. The graph computing engine executes in real time: The update mechanism of the risk portrait signal adopts an event-driven mode: when the bank custody system sends a large amount transfer event signal, it immediately triggers the recalculation of the local subgraph; when the external supervision system pushes a risk notice signal, injects risk marks into the associated nodes and spreads to the three-degree neighbor nodes. The portrait signal output includes a topological structure snapshot and a dynamic risk matrix. In the heat map of the distribution of high-risk nodes, the depth of the node color is positively correlated with the scale of abnormal fund outflows in the recent 7 days; the vulnerability rating of the fund path is comprehensively calculated based on the path length, the risk level of the transit node, and the historical violation incidence rate.

[0025] As Figure 1As shown in the figure, the model input layer synchronously receives the time series feature vector (such as the 24-hour sequence of account balance) in the unified risk data signal and the graph structure feature vector (such as node clustering coefficient) in the risk profile signal. The time series pattern recognition channel adopts a three-layer LSTM network: the input layer receives the standardized balance sequence (eliminating the influence of weekday effect), the hidden layer extracts short-term fluctuation features (capturing high-frequency fluctuations through a one-dimensional convolution kernel) and long-term trend features (controlling the intensity of historical memory through the forget gate), and the output layer generates the abnormal probability P1 of capital precipitation. The relationship network analysis channel adopts a graph convolutional network: when aggregating the features of neighboring nodes, an attenuation coefficient is assigned to high-risk nodes to reduce interference; the weights of capital paths are learned through the graph attention mechanism, and the abnormal capital aggregation probability P2 is output. The feature fusion layer weights and synthesizes P1, P2 and the external risk notification intensity factor to obtain the final risk score S, and its calculation formula is: S = α·P1 + β·P2 + γ·external risk notification intensity factor. Among them, the weight coefficients α and β are dynamically optimized according to the F1 value of the model validation set, and γ represents the contribution weight of the external risk notification signal to the final score. The score signal is output on a scale of 0-100 and refreshed every 30 seconds.

[0026] Furthermore, the dual-channel parallel architecture of the machine learning model and the implementation mechanism of the time series pattern recognition module. The model is deployed using a heterogeneous computing framework: the time series pattern recognition module runs on a GPU cluster to process tensor data, and the relationship network analysis module is deployed on a graph computing engine. The dual-channel design solves the defect that a single model is insufficient in capturing spatio-temporal features: the input layer of the time series pattern recognition module receives the standardized time series signal of the reserve fund account balance, and its preprocessing includes eliminating the weekday effect - extracting daily / weekly / quarterly periodic components through Fourier transform and stripping the benchmark fluctuation curve from the original sequence. The processed signal is input into a three-level residual convolutional network: the first level uses a convolutional kernel with a width of 5 to scan hourly fluctuations and capture the features of sudden large transfers; the second level uses a convolutional kernel with a width of 24 to analyze the daily trend and identify the pattern of continuous decline in the balance; the third-level output layer is connected to a long short-term memory network, which controls the intensity of historical memory through the forget gate (enhancing the memory within 7 days when a holiday signal is detected), and generates three types of key features: short-term fluctuation variance feature (calculating the second derivative of the balance change within a 10-minute window), long-term trend deviation feature (the difference between the slope of the 72-hour linear regression fit and the industry benchmark), and abnormal precipitation feature (monitoring the increase in the balance during inactive periods). The above feature vectors are mapped to the abnormal probability P1 of capital precipitation through a fully connected layer, and the calculation introduces an attention mechanism: a weight of 1.8 times is assigned to the features during the high-occurrence period of misappropriation (such as the 2 hours before regulatory reporting).

[0027] As Figure 1As shown, the triggering logic and escalation mechanism of the transaction review signal are specified: when the real-time risk scoring signal falls into the medium-risk range, the system automatically generates a review task signal. This signal contains three structured data components, namely, the summary of suspicious transaction characteristics, the risk control terminal allocation identifier, and the preset response time limit. The feature summary is generated through an intelligent compression algorithm: First, key fields are extracted from the unified risk data signal, including the abnormal value of the counterparty dispersion, the peak value of the capital flow acceleration, and the abnormal coefficient of the operation period. Second, the vulnerability rating of the fund path and the risk heat of the associated nodes are obtained based on the risk profile signal. Finally, a natural language description is synthesized using a template engine, such as: "It is detected that the counterparty dispersion of account A has dropped by 85% during the inactive period, and the vulnerability of the fund path has risen to level B". The review task signal is distributed to the risk control terminals through a load balancing algorithm, and the distribution strategy depends on the current number of tasks to be processed by the terminal, the historical disposal efficiency, and the matching degree of the professional field. The system synchronously starts a time limit monitoring counter; if the time difference from task distribution to the operator clicking to accept exceeds the preset response time limit, an escalation trigger signal is immediately generated. This signal carries the original review task identifier and the timeout evidence chain, and automatically upgrades the disposal measure to an account temporary freeze signal. The escalation operation requires dual verification: the review task status is confirmed as unaccepted, and the timeout evidence complies with the audit rules. Before the escalation is executed, the system reserves a 30-second buffer period to allow the operator to intercept urgently. The review conclusion signal (regardless of whether it comes from manual determination or system automatic escalation) is fed back to the historical risk pattern library of the machine learning model as an incremental training sample. The feedback data includes the original risk score, the review conclusion label, and the disposal timestamp. The model calculates the feature weight correction amount by comparing the original prediction with the final conclusion. For example, when the feature of the long-term trend deviation of the balance is misjudged as high risk multiple times, the weight coefficient of this feature in the scoring formula is reduced to achieve continuous optimization based on business feedback.

[0028] Furthermore, the dynamic monitoring rules and defense escalation conditions during the fund transfer delay period: When the real-time risk score triggers the medium and low risk thresholds, a fund transfer delay signal is executed. This signal imposes three types of constraints, including: the single transfer amount does not exceed 50% of the available balance of the account; the minimum interval between adjacent transfer requests is 60 seconds; the daily cumulative transfer limit is 80% of the balance. During the delay period, the system monitors the concurrent operation request signals of the delayed account in real time, and analyzes the pattern characteristics of the request sequence through the stream processing engine. Detecting the characteristics of high-frequency small-amount exploratory transfers requires simultaneously meeting three conditions: the single amount is less than 10% of the average daily transfer amount before the delay; the request frequency exceeds 2 times per second; the similarity of the payee hash values of different requests is greater than 0.75. At this time, the secondary risk scoring process is immediately activated. The secondary scoring reuses the original machine learning model, but the input features focus on behavioral dynamics, and four exclusive indicators are added: the entropy value of the transfer request time distribution, the mutation rate of the payee ID, the retry ratio of failed requests, and the gradient of tentative balance consumption. The emergency acceleration mechanism is introduced in the secondary scoring calculation process, skipping the weighting of the feature fusion layer and directly using the original output probability value of the time series pattern recognition module. When the secondary risk scoring result exceeds the primary scoring, it is determined as a risk escalation event, and the system automatically executes the defense response upgrade, switching the original delay signal to an account temporary freeze signal. The upgrade operation needs to meet the time continuity constraint, that is, it has not exceeded the preset observation period (usually set to 30 minutes) after the primary scoring is generated. At the same time, a regulatory report signal is generated, which includes the comparison curve of the primary and secondary scores, the exploratory operation feature map, and the upgrade decision timestamp; the report is pushed to the regulatory node in real time through the encrypted channel. To avoid malicious triggering of upgrades, the system sets up a whitelist mechanism: merchants with a cooperation period of more than 3 years and a credit rating of A are exempt from high-frequency small-amount detection, but the secondary scoring permission is retained.

[0029] Such as Figure 2As shown in the figure, the present invention relates to a safety defense system for provision funds based on information data processing, including a collection module, which receives multi-source heterogeneous data streams in real time and fuses them to generate a unified risk data signal representing the status of provision funds, the flow of funds, the behavior of related parties, and potential risk points; a coordination module, which constructs a dynamically updated risk portrait signal of provision funds by applying graph computing technology based on the unified risk data signal; a verification module, which inputs the unified risk data signal and the risk portrait signal of provision funds into a pre-trained machine learning model for real-time analysis, and the machine learning model identifies the abnormal flow characteristics and misappropriation risk characteristics of provision funds based on historical risk patterns and unsupervised anomaly detection, and generates a real-time risk score signal for a specific provision fund account; an early warning module, which matches the real-time risk score signal with the corresponding threshold according to a preset risk score threshold rule library, and automatically triggers and executes a defense response operation signal corresponding to the risk level; the defense response operation signal includes generating a risk warning signal, triggering a transaction review signal, executing a fund transfer delay signal, and implementing an account temporary freeze signal.

[0030] As Figure 2As shown in the figure, a conduction inhibition system for risk early warning is constructed: when the risk early warning signal is generated, the system immediately activates the risk conduction inhibition barrier. Its core is to locate high-risk associated accounts based on the fund network topology relationship in the risk profile signal. The location algorithm adopts a three-order neighbor traversal strategy: with the early warning account as the center, the first layer is the direct counterparty, the second layer is the counterparty of the counterparty, and the third layer is the fund terminal recipient. For each associated account found through traversal, calculate the risk conduction coefficient, and the calculation formula is: the reciprocal of the topological distance from the early warning account multiplied by the historical fund transfer ratio (for example: the direct counterparty coefficient is 1, the indirect counterparty is 0.5, and the terminal node is 0.2). Send a risk self-inspection instruction signal to the account with a coefficient greater than 0.3. The instruction contains a standardized self-inspection list, requiring an explanation of abnormal transactions within 72 hours, proof documents of fund use, and account operation logs. The self-inspection signal ensures integrity through digital signature and is attached with a 48-hour countdown timer. If the associated account does not return the self-inspection result signal within the preset period, triple defense optimization will be automatically executed: lower the risk scoring threshold of this account (the specific adjustment rule is: the lower limit of the high-risk threshold is multiplied by a decay factor of 0.9, and the width of the medium-risk interval is narrowed to 80% of the original value); at the same time, include this account in the real-time monitoring white list. The white list monitoring adopts an enhanced mode, including: increasing the data sampling frequency to 1 time per second; expanding the feature dimension of the machine learning model to 32 dimensions; shortening the risk profile update cycle to 5 minutes. For the accounts that return the self-inspection results, the system starts an intelligent verification process: analyze the reasonableness of the description document through natural language processing technology; compare the authenticity of the proof document by computer vision; verify the integrity of the log through blockchain deposit. For the accounts with a verification confidence level lower than 0.6, the threshold reduction and white list monitoring are also triggered. When actual risks are found during verification, immediately append a risk notification signal to the original early warning account to form a cross-account collaborative defense network.

[0031] The method and system for the safety defense of reserve funds based on information-based data processing of the present invention generate a unified risk signal through real-time fusion of multi-source heterogeneous data, construct a dynamic fund network profile using graph computing technology, identify abnormal flow characteristics through a machine learning model and output a risk score, and finally automatically trigger hierarchical defense operations based on a dynamic threshold rule base: The data layer cleans multi-source signals such as payment, deposit, and merchant behavior, and extracts the mutation characteristics of fund flow; the profile layer establishes a fund topology network to locate high-risk nodes and closed-loop flow paths; the analysis layer generates a quantitative risk score through parallel analysis of time series pattern recognition and graph neural network; the execution layer automatically executes progressive defense from early warning to freezing according to the score threshold, forming a closed-loop risk control chain.

[0032] Therefore, through the method and system for the safety defense of reserve funds based on information-based data processing of the present invention, the problems of lagging risk identification of reserve fund misappropriation and low efficiency of defense response can be solved.

[0033] The above embodiments are only illustrative of the principles and effects of the present invention and are not intended to limit the present invention. Any person familiar with this technology can modify or change the above embodiments without departing from the spirit and scope of the present invention. Therefore, all equivalent modifications or changes made by those with ordinary knowledge in the technical field without departing from the spirit and technical ideas disclosed by the present invention should still be covered by the claims of the present invention.

Claims

1. A safety defense method for provision funds based on information-based data processing, characterized in that Including: S1: Real-time receive multi-source heterogeneous data streams, and perform cleaning, standardization, correlation analysis and semantic understanding processing on the multi-source heterogeneous data streams, and fuse and generate a unified risk data signal representing the status of provision funds, the flow of funds, the behavior of related parties and potential risk points; S2: Based on the unified risk data signal, apply graph computing technology to construct a dynamically updated risk portrait signal of provision funds, and the risk portrait signal includes a fund network topology relationship and real-time risk characteristics; S3: Input the unified risk data signal and the risk portrait signal of provision funds into a pre-trained machine learning model for real-time analysis. The machine learning model identifies the abnormal flow characteristics and misappropriation risk characteristics of provision funds based on historical risk patterns and unsupervised anomaly detection, and generates a real-time risk score signal for the provision fund account; S4: According to a preset risk score threshold rule library, match the real-time risk score signal with the corresponding threshold, and automatically trigger and execute a defense response operation signal corresponding to the risk level; the defense response operation signal includes generating a risk warning signal, triggering a transaction review signal, executing a fund transfer delay signal, and implementing an account temporary freeze signal.

2. The method for reserve fund security defense based on information-based data processing according to claim 1, wherein In step S1, the multi-source heterogeneous data streams include real-time transaction flow signals of the payment transaction system, fund custody status change signals of the bank custody system, historical violation behavior characteristic signals of the merchant portrait system, operation trajectory time series signals of the user behavior analysis system, and risk notification signals of the external supervision system; when performing cross-source correlation analysis on the above signals, through timestamp alignment and entity resolution technology, aggregate the same merchant's fund operation events scattered in different systems into a continuous behavior sequence signal, and based on this behavior sequence signal, extract the sudden change characteristics of the fund flow rate, the overlap degree characteristics of transaction counterparts, and the abnormal characteristics of the operation period, and generate a unified risk data signal containing dynamic behavior fingerprints.

3. The method for the safety defense of provision funds based on information-based data processing according to claim 1, characterized in that In step S2, take the provision fund account as the central node, the fund transfer path as the directed edge, and the associated merchant as the secondary node to establish a multi-layer fund network topology structure; detect abnormal fund closed-loop flow patterns by real-time calculating the fund transfer density signal, edge weight mutation signal and subgraph clustering coefficient signal between nodes; at the same time, fuse the external risk notification signal to apply risk marks to the associated nodes, and generate a risk portrait signal containing the heat characteristics of the distribution of high-risk nodes and the vulnerability rating of the fund path.

4. The method for the safety defense of provisions based on information-based data processing according to claim 1, wherein In step S3, the machine learning model includes a time series pattern recognition module and a relationship network analysis module operating in parallel: the time series pattern recognition module extracts convolutional features from the fund balance fluctuation signal in the unified risk data signal to identify the periodic misappropriation feature waveform; The relationship network analysis module receives the subgraph clustering coefficient signal in the risk portrait signal and learns the abnormal fund aggregation pattern through a graph neural network; the feature vectors output by the two modules are weighted by the fusion layer to generate a real-time risk score signal based on multi-dimensional risk contribution.

5. The method for reserve fund security defense based on information-based data processing according to claim 4, characterized in that The time series pattern recognition module adopts long short-term memory network units. Its input layer receives the time series signal of the end-of-day balance of the reserve fund account after standardization processing, and the hidden layer extracts features including but not limited to short-term volatility variance features, long-term trend deviation features, and holiday effect anomaly features; The output layer generates a probability signal representing abnormal fund precipitation, and this signal serves as the core weight factor of the real-time risk scoring signal.

6. The method for the safety defense of the provision funds based on information-based data processing according to claim 1, wherein In step S3, the preset risk scoring threshold rule library adopts a dynamic interval division mechanism: according to the current regulatory policy intensity signal, the industry risk level benchmark signal, and the system historical false alarm rate feedback signal, it automatically adjusts the width of the risk scoring threshold interval and the grading critical value; the high-risk threshold interval is positively correlated with the fund loss scale feature in the regulatory penalty case library, and the medium-risk threshold interval dynamically narrows with the merchant credit rating signal.

7. The method for the safety defense of the provision funds based on information-based data processing according to claim 6, wherein, When the real-time risk scoring signal matches the high-risk threshold, the implemented account temporary freeze signal includes a phased control strategy: in the first phase, a restricted transfer instruction signal is generated, only allowing funds to flow back to the white list accounts; in the second phase, a fund flow traceability signal is triggered, forcing the related party to provide compliance certification materials; in the last phase, based on the verification result signal of the certification materials, a full freeze or restriction removal operation is executed.

8. The method for safety defense of provisions based on information-based data processing according to claim 7, characterized in that, In step S4, during the execution of the fund transfer delay signal, the concurrent operation request signal of the delayed account is monitored in real time: if the feature of high-frequency small-amount exploratory transfer is detected, a secondary risk scoring signal is immediately generated; when the secondary risk score exceeds the first score value, the defense response is automatically upgraded to an account temporary freeze signal and a regulatory report signal is generated.

9. The method for the safety defense of the provision funds based on information-based data processing according to claim 8, characterized in that, After generating the risk warning signal, a risk conduction suppression barrier is constructed synchronously: according to the fund network topology relationship in the risk portrait signal, a risk self-check instruction signal is sent to the high-risk related accounts; if the related accounts do not return the self-check result signal within the preset period, their risk scoring threshold is reduced and they are included in the real-time monitoring white list.

10. A provision fund security defense system based on information-based data processing using any one of claims 1-9, characterized in that, Including: An acquisition module that receives multi-source heterogeneous data streams in real time and fuses them to generate a unified risk data signal representing the reserve fund status, fund flow, related party behavior, and potential risk points; A coordination module that constructs a dynamically updated reserve fund risk portrait signal based on the unified risk data signal by applying graph computing technology; A verification module that inputs the unified risk data signal and the reserve fund risk portrait signal into a pre-trained machine learning model for real-time analysis. The machine learning model identifies the abnormal fund flow features and misappropriation risk features of the reserve fund account based on historical risk patterns and unsupervised anomaly detection, and generates a real-time risk scoring signal for the reserve fund account; An early warning module that matches the real-time risk scoring signal with the corresponding threshold according to the preset risk scoring threshold rule library, and automatically triggers and executes a defense response operation signal corresponding to the risk level; the defense response operation signal includes generating a risk warning signal, triggering a transaction review signal, executing a fund transfer delay signal, and implementing an account temporary freeze signal.

Citation Information

Patent Citations

  • Cash machine reserve payment management method and device

    CN113095934A

  • Financial transaction anomaly detection and risk assessment method and device based on artificial intelligence

    CN119693111A

  • Bank flow risk assessment method and application system

    CN120047226A

Cited By

  • Financial business risk control management system based on big data model

    CN121724736A

  • A financial business risk control management system based on big data models

    CN121724736B