Abnormal transaction data identification method, device and system based on image data, equipment and medium

By obtaining bill images and automatically identifying transaction parameters using image recognition models, combining capital flow network diagrams and database data, the problem of time-consuming manually marking transaction bills is solved, and efficient and accurate identification and early warning of abnormal transaction data is achieved.

CN120451992APending Publication Date: 2025-08-08SHENZHEN XIGUO TECHNOLOGY CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202510464935.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-14
Publication Date
2025-08-08

AI Technical Summary

Technical Problem

In the prior art, manual marking of transaction bills consumes a lot of time and effort, resulting in inefficient transaction data processing and it is difficult to accurately identify abnormal transaction characteristics or risks.

Method used

By obtaining bill images, using the image recognition model to extract transaction parameters, combining the capital flow network diagram and database data, comparing the transaction flow data and amount data according to the transaction time and type, automatically identifying abnormal transaction data, and generating early warning information.

Benefits of technology

It greatly shortens processing time, improves the accuracy and accuracy of abnormal transaction data identification, reduces resource waste, and improves processing efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120451992A_ABST
    Figure CN120451992A_ABST
Patent Text Reader

Abstract

The invention provides an abnormal transaction data identification method, device and system based on image data, equipment and a medium. The method comprises the following steps: acquiring a bill image according to a preset time interval; calling a preset image recognition model to extract transaction parameters from the bill image; searching a corresponding fund flow network diagram based on the transaction type, and searching corresponding transaction flow data in a database according to a fund flow mechanism contained in the fund flow network diagram; and comparing the transaction flow data with the transaction amount data according to the transaction time and the transaction type to obtain abnormal transaction data. According to the method, the bill image is identified and the data is extracted to perform anomaly identification without manual marking and auditing, so that the processing time can be greatly shortened and the processing efficiency is improved; moreover, the data of the image is audited according to the preset time interval, the situation that bills are overlapped can be avoided, the situation that repeated bill data are adopted for auditing is avoided, and then the precision and accuracy of abnormal data recognition can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of abnormal transaction data identification, and in particular to an abnormal transaction data identification method, system, device and medium based on image data. Background Art

[0002] As the market for goods expands and trading becomes increasingly complex, transparency and security in the transaction process become increasingly important. To protect the interests of both buyers and sellers, more and more companies are building efficient trading platforms to facilitate the circulation of goods and the conversion of online data into valuable assets.

[0003] Because transactions involve multiple links and participants (both domestically and internationally), the amounts involved are substantial. The methods of conducting financial transactions that present abnormal characteristics or risks, such as frequent transfers, fraudulent offline transactions, and online parameter tampering, are becoming increasingly diverse. Therefore, to ensure the normal operation of the platform, it is imperative to accurately identify these transactions. A common approach currently involves obtaining manually labeled transaction invoices, extracting relevant transaction data from these invoices, and using trained models to compare these transaction data with database records to determine whether any abnormal data exists. This in turn identifies abnormal characteristics or risks based on the abnormal data.

[0004] However, the currently commonly used methods have the following technical problems: manually marking transaction bills requires a lot of time and effort, which increases processing time and reduces subsequent reconciliation efficiency. Summary of the Invention

[0005] In view of the above problems, the present application is proposed to provide a method, system, device and medium for identifying abnormal transaction data based on image data, which overcomes the above problems or at least partially solves the above problems, including:

[0006] A method for identifying abnormal transaction data based on image data, the method comprising:

[0007] Acquiring a bill image at a preset time interval, wherein the bill image is an image recording a business transaction;

[0008] Calling a preset image recognition model to extract transaction parameters from the bill image, the transaction parameters including: transaction type, transaction time, and transaction amount data;

[0009] Searching for a corresponding capital flow network diagram based on the transaction type, and searching for corresponding transaction flow data in a database according to the capital flow institutions included in the capital flow network diagram;

[0010] The transaction flow data and the transaction amount data are compared according to the transaction time and the transaction type to obtain abnormal transaction data.

[0011] In a possible implementation, comparing the transaction flow data and the transaction amount data according to the transaction time and the transaction type to obtain abnormal transaction data includes:

[0012] If the transaction type is a multi-party transaction, searching a preset database for a plurality of time stamps and a first threshold corresponding to each of the time stamps based on the transaction type;

[0013] Determining a time interval using the nodes corresponding to the multiple time markers, and dividing the transaction time according to the time interval to obtain a plurality of first time nodes;

[0014] sequentially calculating the difference between the transaction flow data and the transaction amount data based on the order of the plurality of first time nodes, to obtain a plurality of first difference data;

[0015] Data greater than a corresponding first threshold value is filtered out from the plurality of first difference data to obtain abnormal transaction data.

[0016] In a possible implementation, comparing the transaction flow data and the transaction amount data according to the transaction time and the transaction type to obtain abnormal transaction data includes:

[0017] If the transaction type is a unilateral transaction, determining a plurality of transaction link nodes and a second threshold corresponding to each of the transaction link nodes based on the transaction type;

[0018] Dividing the transaction time based on the plurality of transaction link nodes to obtain a plurality of second time nodes;

[0019] Calculating the difference between the transaction flow data and the transaction amount data one by one based on the order of the plurality of second time nodes to obtain a plurality of second difference data;

[0020] Data greater than the corresponding second threshold value is screened from the plurality of second difference data to obtain abnormal transaction data.

[0021] In one possible implementation, the operation of constructing the capital flow network diagram includes:

[0022] Obtain institutional information of the institution to which funds flow, flow information of fund transaction flows, and business information respectively;

[0023] Using the structural information to perform three-dimensional modeling to obtain multiple BIM models of fund flow institutions, and constructing a business structure tree based on the business information;

[0024] After converting the capital data corresponding to the flow information into real-time data, the real-time data is bound to the business structure tree to obtain a capital data tree;

[0025] Based on the node order of the capital data tree, multiple BIM models are connected in sequence, and the capital data is mapped to the multiple connected BIM models to form a capital flow network diagram.

[0026] In a possible implementation, after obtaining the abnormal transaction data, the method further includes:

[0027] Comparing the abnormal transaction data with a preset warning threshold to determine a warning level;

[0028] An alarm message is sent to the management personnel according to the warning level to prompt the management personnel to conduct an audit.

[0029] In a possible implementation, after obtaining the abnormal transaction data, the method further includes:

[0030] Determining a business link of the abnormal transaction data, where the business link includes multiple business nodes;

[0031] Screening corresponding abnormal service nodes from multiple service nodes in the service link;

[0032] The processing information of the business processor is obtained according to the abnormal business node, and the processing information is used to construct an early warning report for management personnel to review and process.

[0033] A device for identifying abnormal transaction data based on image data, the device comprising:

[0034] An acquisition module, configured to acquire bill images at preset time intervals, wherein the bill images are images recording business transactions;

[0035] An extraction module, configured to call a preset image recognition model to extract transaction parameters from the bill image, wherein the transaction parameters include transaction type, transaction time, and transaction amount data;

[0036] A search module, configured to search a corresponding funds flow network diagram based on the transaction type, and search a database for corresponding transaction flow data according to the funds flow institutions included in the funds flow network diagram;

[0037] An identification module is used to compare the transaction flow data and the transaction amount data according to the transaction time and the transaction type to obtain abnormal transaction data.

[0038] In a possible implementation, comparing the transaction flow data and the transaction amount data according to the transaction time and the transaction type to obtain abnormal transaction data includes:

[0039] If the transaction type is a multi-party transaction, searching a preset database for a plurality of time stamps and a first threshold corresponding to each of the time stamps based on the transaction type;

[0040] Determining a time interval using the nodes corresponding to the multiple time markers, and dividing the transaction time according to the time interval to obtain a plurality of first time nodes;

[0041] sequentially calculating the difference between the transaction flow data and the transaction amount data based on the order of the plurality of first time nodes, to obtain a plurality of first difference data;

[0042] Data greater than a corresponding first threshold value is filtered out from the plurality of first difference data to obtain abnormal transaction data.

[0043] In a possible implementation, comparing the transaction flow data and the transaction amount data according to the transaction time and the transaction type to obtain abnormal transaction data includes:

[0044] If the transaction type is a unilateral transaction, determining a plurality of transaction link nodes and a second threshold corresponding to each of the transaction link nodes based on the transaction type;

[0045] Dividing the transaction time based on the plurality of transaction link nodes to obtain a plurality of second time nodes;

[0046] Calculating the difference between the transaction flow data and the transaction amount data one by one based on the order of the plurality of second time nodes to obtain a plurality of second difference data;

[0047] Data greater than the corresponding second threshold value is screened from the plurality of second difference data to obtain abnormal transaction data.

[0048] In one possible implementation, the operation of constructing the capital flow network diagram includes:

[0049] Obtain institutional information of the institution to which funds flow, flow information of fund transaction flows, and business information respectively;

[0050] Using the structural information to perform three-dimensional modeling to obtain multiple BIM models of fund flow institutions, and constructing a business structure tree based on the business information;

[0051] After converting the capital data corresponding to the flow information into real-time data, the real-time data is bound to the business structure tree to obtain a capital data tree;

[0052] Based on the node order of the capital data tree, multiple BIM models are connected in sequence, and the capital data is mapped to the multiple connected BIM models to form a capital flow network diagram.

[0053] In a possible implementation, after obtaining the abnormal transaction data, the method further includes:

[0054] Comparing the abnormal transaction data with a preset warning threshold to determine a warning level;

[0055] An alarm message is sent to the management personnel according to the warning level to prompt the management personnel to conduct an audit.

[0056] In a possible implementation, after obtaining the abnormal transaction data, the method further includes:

[0057] Determining a business link of the abnormal transaction data, where the business link includes multiple business nodes;

[0058] Screening corresponding abnormal service nodes from multiple service nodes in the service link;

[0059] The processing information of the business processor is obtained according to the abnormal business node, and the processing information is used to build an early warning report for management personnel to review and process. The online trading platform is suitable for the above-mentioned abnormal transaction data identification method based on image data

[0060] A system for identifying abnormal transaction data based on image data, the system comprising: an online transaction platform and multiple smart terminals, the online transaction platform communicating with each smart terminal respectively; the online transaction platform is applicable to the abnormal transaction data identification method based on image data as described above.

[0061] A device includes a processor, a memory, and a computer program stored in the memory and capable of running on the processor, wherein when the computer program is executed by the processor, the steps of identifying abnormal transaction data based on image data as described above are implemented.

[0062] A computer-readable storage medium stores a computer program, which, when executed by a processor, implements the steps of identifying abnormal transaction data based on image data as described above.

[0063] This application has the following advantages:

[0064] In an embodiment of the present application, the present application can obtain bill images at preset time intervals; call a preset image recognition model to extract transaction parameters from the bill images; search for the corresponding capital flow network diagram based on the transaction type, and search for the corresponding transaction flow data in the database based on the capital flow institutions contained in the capital flow network diagram; compare the transaction flow data and transaction amount data based on the transaction time and transaction type to obtain abnormal transaction data. The present application identifies anomalies by identifying bill images and extracting data, without the need for manual marking and review, which can greatly shorten processing time and improve processing efficiency; and the present application reviews the image data at preset time intervals, which can stagger the situation where bills overlap with each other and avoid the situation where duplicate bill data is used for review, thereby improving the precision and accuracy of identifying abnormal data. BRIEF DESCRIPTION OF THE DRAWINGS

[0065] In order to more clearly illustrate the technical solution of the present application, the following is a brief introduction to the drawings required for the description of the present application. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0066] Figure 1 This is a flowchart of a method for identifying abnormal transaction data based on image data provided by an embodiment of the present application;

[0067] Figure 2 This is a structural block diagram of an abnormal transaction data identification device based on image data provided by an embodiment of the present application;

[0068] Figure 3 This is a structural block diagram of an abnormal transaction data identification system based on image data provided by an embodiment of the present application;

[0069] Figure 4 It is a structural diagram of a computer device provided in one embodiment of the present application. DETAILED DESCRIPTION

[0070] To make the objectives, features, and advantages of this application more readily apparent, the present application is further described below in conjunction with the accompanying drawings and specific embodiments. It is apparent that the embodiments described are only a portion of the embodiments of this application, not all of them. All other embodiments derived by persons of ordinary skill in the art based on the embodiments in this application without inventive effort are also within the scope of protection of this application.

[0071] As the market for goods expands and trading becomes increasingly complex, transparency and security in the transaction process become increasingly important. To protect the interests of both buyers and sellers, more and more companies are building efficient trading platforms to facilitate the circulation of goods and the conversion of online data into valuable assets.

[0072] Because transactions involve multiple links and participants (both domestically and internationally), the amounts involved are substantial. The methods of conducting financial transactions that present abnormal characteristics or risks, such as frequent transfers, fraudulent offline transactions, and online parameter tampering, are becoming increasingly diverse. Therefore, to ensure the normal operation of the platform, it is imperative to accurately identify these transactions. A common approach currently involves obtaining manually labeled transaction invoices, extracting relevant transaction data from these invoices, and using trained models to compare these transaction data with database records to determine whether any abnormal data exists. This in turn identifies abnormal characteristics or risks based on the abnormal data.

[0073] However, the currently commonly used methods have the following technical problems: manually marking transaction bills requires a lot of time and effort, which increases processing time and reduces subsequent reconciliation efficiency.

[0074] In order to solve the above technical problems, refer to Figure 1 , shows a flowchart of the steps of a method for identifying abnormal transaction data based on image data provided by an embodiment of the present application;

[0075] In one embodiment, the abnormal transaction data identification method based on image data is applicable to an online transaction platform or cloud platform for commodities. Data management and identification are performed through the online transaction platform or cloud platform without manual operation, which can shorten the bill processing time and improve the overall processing efficiency.

[0076] In one mode of operation, the online trading platform can communicate with multiple different smart terminals, each of which can be a buyer's smart device. Different users can communicate with the online trading platform through their smart terminals to conduct online transactions. At the same time, they can operate on the online operation interface of the online trading platform to conduct online transactions.

[0077] As an example, the method for identifying abnormal transaction data based on image data may include:

[0078] S11. Acquire a bill image at a preset time interval, where the bill image is an image that records a business transaction.

[0079] In one embodiment, different buyers or users may place orders and conduct online transactions on an online trading platform at different times. If abnormal transaction data identification is performed for each online transaction, not only would the number of processing steps be high, but resources would be wasted. To improve processing efficiency and reduce resource waste, bill images can be acquired at preset time intervals. These bill images record business transactions, and abnormal transaction data identification is then performed based on the bill images.

[0080] The bill image can be an image of a buyer performing different operations during an online transaction. For example, a user communicates with an online trading platform through their smart terminal and conducts an online transaction. The smart terminal can capture the user's interface image while filling in information to obtain a bill image. It can also capture images of refunds and completed payments to obtain a bill image.

[0081] For example, when a user operates an online trading platform's online interface to conduct an online transaction, the platform can capture images of the user confirming the purchase of the product and the various associated payments, as well as images of the transaction payment, to obtain a bill image. Alternatively, the platform can capture an image summarizing various transaction information after the transaction is completed.

[0082] S12. Call a preset image recognition model to extract transaction parameters from the bill image, where the transaction parameters include transaction type, transaction time, and transaction amount data.

[0083] In one embodiment, after obtaining a bill image, a preset image recognition model can be used to recognize the bill image in order to extract the text or numerical content within the bill image, thereby extracting various transaction parameters from the bill image. In one embodiment, the transaction parameters may include transaction type, transaction time, and transaction amount.

[0084] Since the preset image recognition model mainly recognizes texts such as various characters and numerical values in the bill image, in one operation mode, the preset image recognition model can be a text recognition model.

[0085] The training of the preset image recognition model may include the following steps:

[0086] The first step is to obtain the data to be trained, which includes n images pre-labeled by the user and containing various business information, where n≥1 and is a positive integer.

[0087] In the second step, the features of the n images are extracted through the first neural network and a spatial migration feature matrix is constructed. The first neural network can be a convolutional neural network. Through convolution and downsampling of the convolutional neural network, the matrix of n images can be converted into a first spatial feature map of size [n,h3,w3,channels1], where h3 is the height of the downsampled image, w3 is the width of the downsampled image, and channels1 is the number of spatial feature maps.

[0088] The spatial feature map can be understood as the features extracted by the first neural network after convolution on the height and width of the image. Channels1 can be understood as the number of extracted features. The size of channels1 is related to the number of convolution kernels in the convolutional neural network. The spatial feature map can be used to indicate the image features of n images.

[0089] In the third step, the second neural network is used to extract the features of n images and construct a sequence transfer feature matrix.

[0090] The second neural network can be a recurrent neural network, and the height of the image after downsampling is 1, and the second dimension is omitted. The features extracted by the recurrent neural network can include a first sequence feature map and a second sequence feature map. The size of the first sequence feature map is [n, w3, char_num], and the size of the second sequence feature map is [m, w3, char_num], where w3 can be the maximum length of the text in the image to be recognized, and char_num can be the number of characters in the text in the image to be recognized. The two sequence feature maps are converted into matrices to obtain a sequence migration feature matrix.

[0091] The fourth step is to train the image text recognition model according to the spatial migration feature matrix and the sequence migration feature matrix to obtain a preset image recognition model.

[0092] Among them, the image text recognition model can be a CNN neural network or an RNN neural network.

[0093] It should be noted that the loss function of the image text recognition model can be expressed as follows:

[0094] L total =α1Lcnn+α2Lrnn;

[0095] Among them L total Represents the loss function of the image text recognition model;

[0096] Lcnn represents the loss function of spatial migration features;

[0097] Lrnn represents the loss function of sequence migration features;

[0098] α1 and α2 are hyperparameters that balance the loss functions of each part. Hyperparameters can be understood as defining the structure of the model or the optimization strategy or controlling the action state of the model. The loss function can be optimized through hyperparameters to ensure that the model is not underfitting or overfitting. Common hyperparameters include the number of layers and kernel functions of the neural network. The selection of hyperparameters can be a combination. The embodiments of this application do not limit the hyperparameters. It can be the above two hyperparameters or other hyperparameters.

[0099] S13. Searching for a corresponding capital flow network diagram based on the transaction type, and searching for corresponding transaction flow data in a database according to the capital flow institutions included in the capital flow network diagram.

[0100] Next, based on the transaction type, a corresponding funds flow network diagram can be found. This diagram can be a pre-built twin model of funds flow for online transactions. The diagram records the fund flow process for different business transactions and can be displayed in real time within the twin model. The diagram can be used to determine the funds flow for online transactions, thereby identifying the payment method selected by the user. Based on the payment method, the funds receiving and paying institution can be determined, thereby determining the funds flow institution. Based on the funds flow institution, the corresponding transaction flow data is then searched within the database to determine whether the funds flow institution interacts with the online trading platform. If so, the funds flow institution is determined to have completed the payment or collection.

[0101] For example, buyer A chooses institution P to make an online payment. After completing the payment, buyer A interacts with the online trading platform at institution P to process the payment. The online trading platform can then record the transaction data for this payment and store it in a database. This data can then be directly extracted from the database to obtain transaction flow data.

[0102] Since the capital flow network diagram is a digital twin model, in order to combine the physical structure of each institution and the actual flow of funds, in an optional embodiment, the construction operation of the capital flow network diagram may include the following sub-steps:

[0103] S21. Obtain the institutional information of the fund flow institution, the flow information of the fund transaction flow, and the business information respectively.

[0104] S22: Use the structural information to perform three-dimensional modeling to obtain multiple BIM models of capital flow institutions, and construct a business structure tree based on the business information.

[0105] S23: After converting the capital data corresponding to the flow information into real-time data, the real-time data is bound to the business structure tree to obtain a capital data tree.

[0106] S24. Connect multiple BIM models in sequence based on the node order of the capital data tree, and map the capital data to the multiple connected BIM models and the capital flow network diagram.

[0107] In one operation mode, the institutional information of the fund flow institution, the flow information of the fund transaction flow, and the business information can be obtained respectively.

[0108] Among them, the institutional information of the institution to which funds flow can be the trademark or logo image of the institution, and the flow information of the fund transaction flow can be the fund amount data of different businesses, different transaction types, and different commodity transactions, as well as the recipients and payment objects of the amount. The business information can include the business type, the business processes included in each business type, etc., among which the business type can be personal purchase type, corporate purchase type, overseas purchase type, cross-border purchase type, etc.

[0109] Through the organization's trademark, users can quickly identify the organization in the digital twin model. Through flow information, users can quickly determine the transaction amount data and the flow direction of the amount in the digital twin model. Through business information, users can quickly determine the type of this business in the digital twin model.

[0110] Next, a BIM model can be constructed based on the trademark or logo image. This BIM model is created using BIM software. The created BIM model consists of numerous sub-components. Upon completion, the created BIM model has an initial state, including the trademark model's location coordinates, geometric dimensions, scale, display color, and attribute information.

[0111] At the same time, the application can also construct a business structure tree based on the business information, and specifically can construct a business structure tree based on the business process of the business type, and the business structure tree includes the transaction objects involved in the entire process.

[0112] For example, for personal purchases, the entire process involves users, merchants, manufacturers, and logistics merchants. The process is that the user places an order with the merchant, the merchant places an order with the manufacturer, the manufacturer places an order with the logistics merchant, the logistics merchant ships the goods to the user, and finally the user provides feedback to the merchant.

[0113] A business structure tree can be constructed according to the order of the entire process. Each process object in the business structure tree is a node. Referring to the above example, there are four nodes: users, merchants, manufacturers, and logistics providers. Their order is also based on the order in which the orders are placed.

[0114] To ensure the data security of each object within the business process, the financial data corresponding to the flow information can be converted into real-time data and then bound to the business structure tree to create a financial data tree. For example, the amount of an order placed by a user with a merchant can be converted into real-time data, and the amount of an order placed by a merchant with a manufacturer can be converted into real-time data. Each piece of real-time data can then be bound to its corresponding object.

[0115] After binding, the ordering process also corresponds to the process of capital flow. In order to view the entire business process more intuitively, multiple BIM models can be connected in sequence according to the order of ordering (that is, the arrangement order of each node), and the capital data can be mapped to the multiple BIM models that have been connected. In this way, the BIM model of each organization is bound to its capital data, thereby forming a capital flow network diagram of the business process.

[0116] Every time a business is triggered, the transaction amount data can be updated in real time for user viewing.

[0117] S14. Compare the transaction flow data and the transaction amount data according to the transaction time and the transaction type to obtain abnormal transaction data.

[0118] In one embodiment, the transaction time and transaction type can be determined. Different times and types may involve different transaction methods and data. To this end, the transaction flow data and transaction amount data can be compared based on the transaction time and transaction type. By comparing whether the two data are the same, abnormal data can be determined to obtain abnormal transaction data.

[0119] The comparison method can be to determine whether two data are the same, or to calculate the difference between the two data.

[0120] In one embodiment, a transaction involves multiple parties. For example, an online trading platform, such as xxfish, sells used products. During the transaction, the online trading platform charges a handling fee. In this case, the transaction involves the buyer, the seller, and the platform. Another example is when multiple buyers purchase a product simultaneously, involving multiple parties.

[0121] For the above-mentioned multi-party transaction situation, as an example, comparing the transaction flow data and the transaction amount data according to the transaction time and the transaction type to obtain abnormal transaction data may include the following sub-steps:

[0122] S31. If the transaction type is a multi-party transaction, search a preset database for several time stamps and a first threshold corresponding to each time stamp based on the transaction type.

[0123] S32. Determine a time interval using the nodes corresponding to the multiple time markers, and divide the transaction time according to the time interval to obtain multiple first time nodes.

[0124] S33. Calculate the difference between the transaction flow data and the transaction amount data one by one based on the order of the multiple first time nodes to obtain multiple first difference data.

[0125] S34. Filter data greater than the corresponding first threshold value from the plurality of first difference data to obtain abnormal transaction data.

[0126] In a specific operation, if the transaction type is a multi-party transaction, a preset database may be searched for several time stamps and a first threshold corresponding to each time stamp based on the transaction type.

[0127] The time stamp is the time point at which the transaction parties need to settle the payment. At the same time, a first threshold corresponding to each time point is obtained, and the first threshold is the value of the payment.

[0128] Next, we can calculate the interval between two adjacent time stamps to obtain the time interval. We can then divide the transaction time by this time interval to obtain multiple first time nodes. The transaction time is the traceable length of the transaction, or the length of time the buyer can cancel the transaction. For example, 7 days, 10 days, etc.

[0129] Since a payment is settled at each time node, the difference between the transaction flow data and the transaction amount data can be calculated one by one in the order of multiple first time nodes to obtain multiple first difference data.

[0130] Then, each first difference is compared with the value of the first threshold corresponding to it, and the first difference values different from the first threshold are screened out as abnormal transaction data.

[0131] In another optional embodiment, the two parties to the transaction may have a corresponding agreement before the transaction. Specifically, the corresponding amount values can be extracted from the transaction flow data and the transaction amount data respectively according to the numerical values calibrated in the agreement corresponding to the business type, and then the amount values of the two data are compared to see whether they are the same. If different, abnormal transaction data is determined. Otherwise, if they are the same, there is no abnormal transaction data.

[0132] In another embodiment, a transaction involves only one buyer. Referring to the above example, a buyer places an order to purchase goods from an online trading platform. In order to track the entire transaction process of a single buyer to determine whether there is any abnormal data, for example, comparing the transaction flow data and the transaction amount data based on the transaction time and the transaction type to obtain abnormal transaction data may include the following sub-steps:

[0133] S41. If the transaction type is a unilateral transaction, determine a number of transaction link nodes and a second threshold corresponding to each of the transaction link nodes based on the transaction type.

[0134] S42. Divide the transaction time based on the multiple transaction link nodes to obtain multiple second time nodes.

[0135] S43. Calculate the difference between the transaction flow data and the transaction amount data one by one based on the order of the plurality of second time nodes to obtain a plurality of second difference data.

[0136] S44. Filter data greater than the corresponding second threshold value from the plurality of second difference data to obtain abnormal transaction data.

[0137] For ease of explanation, referring to the above example, let's assume a buyer places an order for goods on a merchant's online trading platform. The merchant then places an order with the manufacturer, who then notifies the logistics provider for delivery. An error in the amount at any stage could disrupt the transaction, impacting the interests of all parties. To understand the entire process, if the transaction type is a one-way transaction (i.e., a buyer places an order for goods on the merchant's online trading platform), several transaction nodes and the corresponding second threshold for each transaction node can be determined based on the transaction type.

[0138] Among them, the transaction link node refers to the node where each object involved in the transaction performs an operation in the process from the buyer placing an order to the goods arriving at the buyer.

[0139] For example, a buyer placing an order on a merchant's online trading platform is a link node, a merchant placing an order with a manufacturer is a link node, a manufacturer placing an order with a logistics merchant is a link node, and a buyer receiving the goods and confirming receipt is a link node.

[0140] Then, the time node of each transaction link node at the transaction time can be determined, thereby obtaining several second time nodes.

[0141] Then, according to the order of the plurality of second time nodes, the difference between the transaction flow data and the transaction amount data is calculated one by one to obtain a plurality of second difference data.

[0142] Then, each second difference is compared with the value of the second threshold corresponding to it, and the second difference values having values different from the second threshold are screened out as abnormal transaction data.

[0143] Referring to the above embodiment, it is also possible that the trading platform and the parties have a corresponding agreement before the transaction. Specifically, the corresponding amount values can be extracted from the transaction flow data and the transaction amount data respectively according to the numerical values calibrated in the agreement corresponding to the business type, and then the amount values of the two data are compared to see whether they are the same. If different, abnormal transaction data is determined. Otherwise, if they are the same, there is no abnormal transaction data.

[0144] In one embodiment, if the amount of the abnormal transaction data is too high, there may be financial risks or financial loopholes, which may harm the interests of buyers and merchants. In order to promptly discover financial risks or financial loopholes, as an example, after obtaining the abnormal transaction data, the method may further include the following steps:

[0145] S51. Compare the abnormal transaction data with a preset warning threshold to determine a warning level.

[0146] S52: Send an alarm message to the management personnel according to the warning level to prompt the management personnel to conduct an audit.

[0147] In one embodiment, after the abnormal transaction data is obtained, the value of the abnormal transaction data may be compared with a preset warning threshold to determine a warning level.

[0148] In one operation mode, the preset warning thresholds include W low and W high The value of abnormal transaction data is P r .

[0149] The alarm levels are divided according to the values of abnormal transaction data. The commonly used classification standards are as follows:

[0150] Level 1 anomaly: the value P of abnormal transaction data r Less than the preset low warning threshold W low .

[0151] Secondary anomaly: the value P of abnormal transaction data r In the middle range W low <P r <W high .

[0152] Level 3 anomaly: the value P of abnormal transaction data r Greater than the high preset warning threshold W high .

[0153] Then, alarm information can be sent to management personnel based on different levels of abnormalities to prompt management personnel to conduct review and processing.

[0154] In one embodiment, in order to facilitate management personnel to quickly review the business corresponding to the abnormal transaction data, as an example, after obtaining the abnormal transaction data, the method may further include the following steps:

[0155] S61: Determine a business link of the abnormal transaction data, where the business link includes multiple business nodes.

[0156] S62: Filter corresponding abnormal service nodes among the multiple service nodes in the service link.

[0157] S63: Acquire processing information of the business processor according to the abnormal business node, and use the processing information to construct an early warning report for management personnel to review and process.

[0158] Referring to the above example, it can be seen that each business may involve different links, each link corresponds to a node, and a business link for obtaining abnormal transaction data can correspond to a branch link of the business structure tree analyzed above, and the business link includes multiple business nodes.

[0159] In actual operation, the corresponding abnormal business nodes can be screened from multiple business nodes in the business chain. Specifically, the nodes of the two parties of the abnormal transaction data can be selected, so that two abnormal business nodes can be obtained.

[0160] Next, the processing information of the business processors of the two abnormal business nodes can be obtained, and an early warning report can be constructed using the processing information and sent to the management personnel for review and processing.

[0161] In this embodiment, the embodiment of the present application provides a method for identifying abnormal transaction data based on image data, and its beneficial effects are: the present application can obtain bill images at preset time intervals; call a preset image recognition model to extract transaction parameters from the bill image; find the corresponding capital flow network diagram based on the transaction type, and search the database for corresponding transaction flow data based on the capital flow institution contained in the capital flow network diagram; compare the transaction flow data and transaction amount data based on the transaction time and transaction type to obtain abnormal transaction data. The present application identifies anomalies by identifying bill images and extracting data, without the need for manual marking and review, which can greatly shorten processing time and improve processing efficiency; and the present application reviews the image data at preset time intervals, which can stagger the situation where bills overlap with each other and avoid the situation where duplicate bill data is used for review, thereby improving the precision and accuracy of identifying abnormal data.

[0162] As for the system embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.

[0163] Reference Figure 2 , shows a structural block diagram of an abnormal transaction data identification device based on image data provided by an embodiment of the present application;

[0164] Specifically include:

[0165] An acquisition module 201 is configured to acquire bill images at preset time intervals, wherein the bill images are images recording business transactions;

[0166] Extraction module 202, configured to call a preset image recognition model to extract transaction parameters from the bill image, wherein the transaction parameters include transaction type, transaction time, and transaction amount data;

[0167] A search module 203 is configured to search for a corresponding capital flow network diagram based on the transaction type, and search for corresponding transaction flow data in a database according to the capital flow institutions included in the capital flow network diagram;

[0168] The identification module 204 is configured to compare the transaction flow data and the transaction amount data according to the transaction time and the transaction type to obtain abnormal transaction data.

[0169] In an optional embodiment, the comparing the transaction flow data and the transaction amount data according to the transaction time and the transaction type to obtain abnormal transaction data includes:

[0170] If the transaction type is a multi-party transaction, searching a preset database for a plurality of time stamps and a first threshold corresponding to each of the time stamps based on the transaction type;

[0171] Determining a time interval using the nodes corresponding to the multiple time markers, and dividing the transaction time according to the time interval to obtain a plurality of first time nodes;

[0172] sequentially calculating the difference between the transaction flow data and the transaction amount data based on the order of the plurality of first time nodes, to obtain a plurality of first difference data;

[0173] Data greater than a corresponding first threshold value is filtered out from the plurality of first difference data to obtain abnormal transaction data.

[0174] In an optional embodiment, the comparing the transaction flow data and the transaction amount data according to the transaction time and the transaction type to obtain abnormal transaction data includes:

[0175] If the transaction type is a unilateral transaction, determining a plurality of transaction link nodes and a second threshold corresponding to each of the transaction link nodes based on the transaction type;

[0176] Dividing the transaction time based on the plurality of transaction link nodes to obtain a plurality of second time nodes;

[0177] Calculating the difference between the transaction flow data and the transaction amount data one by one based on the order of the plurality of second time nodes to obtain a plurality of second difference data;

[0178] Data greater than the corresponding second threshold value is screened from the plurality of second difference data to obtain abnormal transaction data.

[0179] In an optional embodiment, the operation of constructing the capital flow network diagram includes:

[0180] Obtain institutional information of the institution to which funds flow, flow information of fund transaction flows, and business information respectively;

[0181] Using the structural information to perform three-dimensional modeling to obtain multiple BIM models of fund flow institutions, and constructing a business structure tree based on the business information;

[0182] After converting the capital data corresponding to the flow information into real-time data, the real-time data is bound to the business structure tree to obtain a capital data tree;

[0183] Based on the node order of the capital data tree, multiple BIM models are connected in sequence, and the capital data is mapped to the multiple connected BIM models to form a capital flow network diagram.

[0184] In an optional embodiment, after obtaining the abnormal transaction data, the method further includes:

[0185] Comparing the abnormal transaction data with a preset warning threshold to determine a warning level;

[0186] An alarm message is sent to the management personnel according to the warning level to prompt the management personnel to conduct an audit.

[0187] In an optional embodiment, after obtaining the abnormal transaction data, the method further includes:

[0188] Determining a business link of the abnormal transaction data, where the business link includes multiple business nodes;

[0189] Screening corresponding abnormal service nodes from multiple service nodes in the service link;

[0190] The processing information of the business processor is obtained according to the abnormal business node, and the processing information is used to construct an early warning report for management personnel to review and process.

[0191] As for the system embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.

[0192] Reference Figure 3 , shows a structural block diagram of an abnormal transaction data identification system based on image data provided by an embodiment of the present application;

[0193] Specifically, the system includes: an online transaction platform and multiple smart terminals, and the online transaction platform communicates with each smart terminal respectively; the online transaction platform is applicable to the abnormal transaction data identification method based on image data as described in the above embodiment.

[0194] Reference Figure 4 , showing a computer device of the present application's abnormal transaction data identification method based on image data, which may specifically include the following:

[0195] The computer device 12 is a general-purpose computing device. The components of the computer device 12 may include but are not limited to: one or more processors or processing units 16, a system memory 28, and a bus 18 connecting different system components (including the system memory 28 and the processing unit 16).

[0196] The bus 18 represents one or more of several types of bus 18 structures, including a memory bus 18 or memory controller, a peripheral bus 18, an accelerated graphics port, a processor, or a local bus 18 that utilizes any of a variety of bus 18 architectures. Examples of such architectures include, but are not limited to, an Industry Standard Architecture (ISA) bus 18, a Micro Channel Architecture (MAC) bus 18, an Enhanced ISA bus 18, an Audio Video Electronics Standards Association (VESA) local bus 18, and a Peripheral Component Interconnect (PCI) bus 18.

[0197] The computer device 12 typically includes a variety of computer system readable media. These media can be any available media that can be accessed by the computer device 12, including volatile and non-volatile media, removable and non-removable media.

[0198] System memory 28 may include computer system readable media in the form of volatile memory, such as random access memory (RAM) 30 and / or cache memory 32. Computer device 12 may further include other removable / non-removable, volatile / non-volatile computer system storage media. By way of example only, storage system 34 may be configured to read and write to non-removable, non-volatile magnetic media (commonly referred to as a "hard drive"). Although Figure 3Not shown, a disk drive for reading and writing to a removable non-volatile disk (such as a "floppy disk"), and an optical drive for reading and writing to a removable non-volatile optical disk (such as a CD-ROM, DVD-ROM, or other optical media) can be provided. In these cases, each drive can be connected to the bus 18 via one or more data medium interfaces. The memory may include at least one program product having a set (e.g., at least one) of program modules 42, which are configured to perform the functions of the various embodiments of the present application.

[0199] A program / utility 40 having a set (at least one) of program modules 42 may be stored, for example, in a memory. Such program modules 42 include, but are not limited to, an operating system, one or more application programs, other program modules 42, and program data, each of which, or some combination thereof, may include an implementation of a network environment. The program modules 42 generally perform the functions and / or methods of the embodiments described herein.

[0200] The computer device 12 may also communicate with one or more external devices 14 (e.g., a keyboard, a pointing device, a display 24, a camera, etc.), one or more devices that enable a user to interact with the computer device 12, and / or any device that enables the computer device 12 to communicate with one or more other computing devices (e.g., a network card, a modem, etc.). Such communication may be performed via an input / output (I / O) interface 22. Furthermore, the computer device 12 may also communicate with one or more networks (e.g., a local area network (LAN)), a wide area network (WAN), and / or a public network (e.g., the Internet) via a network adapter 20. As shown, the network adapter 20 communicates with the other modules of the computer device 12 via the bus 18. It should be understood that although Figure 3 Not shown, other hardware and / or software modules may be used in conjunction with the computer device 12, including but not limited to microcode, device drivers, redundant processing units 16, external disk drive arrays, RAID systems, tape drives, and data backup storage systems 34.

[0201] The processing unit 16 executes various functional applications and data processing by running programs stored in the system memory 28, such as implementing the abnormal transaction data identification method based on image data provided in the embodiment of the present application.

[0202] That is, when the processing unit 16 executes the above program, the following is achieved:

[0203] Acquiring a bill image at a preset time interval, wherein the bill image is an image recording a business transaction;

[0204] Calling a preset image recognition model to extract transaction parameters from the bill image, the transaction parameters including: transaction type, transaction time, and transaction amount data;

[0205] Searching for a corresponding capital flow network diagram based on the transaction type, and searching for corresponding transaction flow data in a database according to the capital flow institutions included in the capital flow network diagram;

[0206] The transaction flow data and the transaction amount data are compared according to the transaction time and the transaction type to obtain abnormal transaction data.

[0207] In an embodiment of the present application, the present application also provides a computer-readable storage medium on which a computer program is stored. When the program is executed by a processor, the abnormal transaction data identification method based on image data as provided in all embodiments of the present application is implemented.

[0208] That is, when the program is executed by the processor:

[0209] Acquiring a bill image at a preset time interval, wherein the bill image is an image recording a business transaction;

[0210] Calling a preset image recognition model to extract transaction parameters from the bill image, the transaction parameters including: transaction type, transaction time, and transaction amount data;

[0211] Searching for a corresponding capital flow network diagram based on the transaction type, and searching for corresponding transaction flow data in a database according to the capital flow institutions included in the capital flow network diagram;

[0212] The transaction flow data and the transaction amount data are compared according to the transaction time and the transaction type to obtain abnormal transaction data.

[0213] Any combination of one or more computer-readable media may be used. A computer-readable medium may be a computer signal medium or a computer-readable storage medium. A computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples (a non-exhaustive list) of computer-readable storage media include: an electrical connection having one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof. In this document, a computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device.

[0214] A computer-readable signal medium may include a data signal propagated in baseband or as part of a carrier wave, which carries computer-readable program code. Such a propagated data signal may take a variety of forms, including, but not limited to, electromagnetic signals, optical signals, or any suitable combination thereof. A computer-readable signal medium may also be any computer-readable medium other than a computer-readable storage medium that can transmit, propagate, or transport a program for use by or in conjunction with an instruction execution system, apparatus, or device.

[0215] The computer program code for performing the operations of the present application can be written in one or more programming languages or a combination thereof, including object-oriented programming languages such as Java, Smalltalk, C++, and conventional procedural programming languages such as "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as an independent software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computer (for example, using an Internet service provider to connect through the Internet). The various embodiments in this specification are described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same and similar parts between the various embodiments can be referenced to each other.

[0216] Although preferred embodiments of the present invention have been described, those skilled in the art may make additional changes and modifications to these embodiments once they become aware of the basic inventive concepts. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of the embodiments of the present invention.

[0217] Finally, it should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or terminal device that includes a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or terminal device. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of additional identical elements in the process, method, article, or terminal device that includes the element.

[0218] The above is a detailed introduction to the abnormal transaction data identification method, system, device and medium based on image data provided by the present application. Specific examples are used in this article to illustrate the principles and implementation methods of the present application. The description of the above embodiments is only used to help understand the method of the present application and its core idea; at the same time, for general technical personnel in this field, based on the ideas of the present application, there will be changes in the specific implementation methods and application scope. In summary, the content of this specification should not be understood as a limitation on the present application.

Claims

1. A method for identifying abnormal transaction data based on image data, characterized in that: The method comprises: Acquiring a bill image at a preset time interval, wherein the bill image is an image recording a business transaction; Calling a preset image recognition model to extract transaction parameters from the bill image, the transaction parameters including: transaction type, transaction time, and transaction amount data; Searching for a corresponding capital flow network diagram based on the transaction type, and searching for corresponding transaction flow data in a database according to the capital flow institutions included in the capital flow network diagram; The transaction flow data and the transaction amount data are compared according to the transaction time and the transaction type to obtain abnormal transaction data.

2. The method for identifying abnormal transaction data based on image data according to claim 1, characterized in that: The comparing the transaction flow data and the transaction amount data according to the transaction time and the transaction type to obtain abnormal transaction data includes: If the transaction type is a multi-party transaction, searching a preset database for a plurality of time stamps and a first threshold corresponding to each of the time stamps based on the transaction type; Determining a time interval using the nodes corresponding to the multiple time markers, and dividing the transaction time according to the time interval to obtain a plurality of first time nodes; sequentially calculating the difference between the transaction flow data and the transaction amount data based on the order of the plurality of first time nodes, to obtain a plurality of first difference data; Data greater than a corresponding first threshold value is filtered out from the plurality of first difference data to obtain abnormal transaction data.

3. The method for identifying abnormal transaction data based on image data according to claim 1, characterized in that: The comparing the transaction flow data and the transaction amount data according to the transaction time and the transaction type to obtain abnormal transaction data includes: If the transaction type is a unilateral transaction, determining a plurality of transaction link nodes and a second threshold corresponding to each of the transaction link nodes based on the transaction type; Dividing the transaction time based on the plurality of transaction link nodes to obtain a plurality of second time nodes; Calculating the difference between the transaction flow data and the transaction amount data one by one based on the order of the plurality of second time nodes to obtain a plurality of second difference data; Data greater than the corresponding second threshold value is screened from the plurality of second difference data to obtain abnormal transaction data.

4. The method for identifying abnormal transaction data based on image data according to claim 1, characterized in that: The operation of constructing the capital flow network diagram includes: Obtain institutional information of the institution to which funds flow, flow information of fund transaction flows, and business information respectively; Using the structural information to perform three-dimensional modeling to obtain multiple BIM models of fund flow institutions, and constructing a business structure tree based on the business information; After converting the capital data corresponding to the flow information into real-time data, the real-time data is bound to the business structure tree to obtain a capital data tree; Based on the node order of the capital data tree, multiple BIM models are connected in sequence, and the capital data is mapped to the multiple connected BIM models to form a capital flow network diagram.

5. The method for identifying abnormal transaction data based on image data according to any one of claims 1 to 4, characterized in that: After obtaining the abnormal transaction data, the method further includes: Comparing the abnormal transaction data with a preset warning threshold to determine a warning level; An alarm message is sent to the management personnel according to the warning level to prompt the management personnel to conduct an audit.

6. The method for identifying abnormal transaction data based on image data according to any one of claims 1 to 4, characterized in that: After obtaining the abnormal transaction data, the method further includes: Determining a business link of the abnormal transaction data, where the business link includes multiple business nodes; Screening corresponding abnormal service nodes from multiple service nodes in the service link; The processing information of the business processor is obtained according to the abnormal business node, and the processing information is used to construct an early warning report for management personnel to review and process.

7. A device for identifying abnormal transaction data based on image data, characterized in that: The device comprises: An acquisition module, configured to acquire bill images at preset time intervals, wherein the bill images are images recording business transactions; An extraction module, configured to call a preset image recognition model to extract transaction parameters from the bill image, wherein the transaction parameters include transaction type, transaction time, and transaction amount data; A search module, configured to search a corresponding funds flow network diagram based on the transaction type, and search a database for corresponding transaction flow data according to the funds flow institutions included in the funds flow network diagram; An identification module is used to compare the transaction flow data and the transaction amount data according to the transaction time and the transaction type to obtain abnormal transaction data.

8. An abnormal transaction data identification system based on image data, characterized in that: The system includes: an online trading platform and a plurality of smart terminals, wherein the online trading platform communicates with each smart terminal respectively; The online trading platform is applicable to the abnormal transaction data identification method based on image data as described in any one of claims 1-6.

9. An electronic device comprising: A memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, the method for identifying abnormal transaction data based on image data as described in any one of claims 1 to 6 is implemented.

10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer-executable program, and the computer-executable program is used to enable a computer to execute the abnormal transaction data identification method based on image data according to any one of claims 1 to 6.

Citation Information

Patent Citations

  • National financing platform supervision system and method based on comparison rules

    CN112598505A

  • Image recognition method and system based on computer network and storage medium

    CN117523299A

  • Abnormal transaction network identification method and device, electronic equipment and storage medium

    CN119741124A

  • Specific fund flow direction tracking method and system based on artificial intelligence

    CN119782951A

  • Capital monitoring method, capital monitoring system, terminal and readable storage medium

    WO2020000633A1