A method for analyzing mobile payment transaction behavior based on spatial data
By constructing a spatial dependency network and an adaptive spatial weight matrix and dynamically adjusting detection parameters, the problem of ignoring the dynamic transmission mechanism of transaction amount fluctuations in existing technologies is solved, and accurate identification of transaction anomalies and risk prevention and control are achieved.
Patent Information
- Application Number
- CN202511093324.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-06
- Publication Date
- 2025-10-10
- Estimated Expiration
- 2045-08-06
AI Technical Summary
When dealing with the spatial dependence of transaction amounts, existing methods ignore the dynamic transmission mechanism of fluctuations in transaction amounts between regions, resulting in insufficient accuracy of analysis results when facing the heterogeneity of transaction data. It is difficult to capture the deep laws of mutual influence between regions, especially in scenarios with large fluctuations in transaction amounts, where the model has difficulty identifying abnormal transactions.
By acquiring time series data of transaction amounts in different geographical areas, constructing a spatial dependency network, analyzing the spatial distribution and temporal transmission patterns of transaction amounts, using an adaptive spatial weight matrix to identify abnormal areas, dynamically adjusting detection parameters, and optimizing the diffusion path prediction of abnormal fluctuations.
It has achieved accurate identification and early warning of financial transaction anomalies, improved financial risk prevention and control capabilities, increased the sensitivity of anomaly detection and reduced the false alarm rate.
Smart Images

Figure CN120597176B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information technology, and in particular to a method for analyzing mobile payment transaction behavior based on spatial data. Background Art
[0002] Studying the spatial dependence of transaction value distribution is crucial for financial risk management, regional economic analysis, and transaction anomaly detection. Analyzing the interactions between transaction values across different geographic regions can reveal patterns in regional economic activity, providing a basis for policymaking and risk prevention. However, existing methods for addressing the spatial dependence of transaction values often overlook the dynamic transmission mechanisms of interregional transaction value fluctuations and the complex impacts they trigger. This results in inaccurate analysis when dealing with heterogeneous transaction data. In particular, when transaction value fluctuations are significant, the model struggles to capture the underlying patterns of interregional influence. When transaction value in a commercial center increases significantly, this change can impact neighboring regions through various channels. On the one hand, due to cross-regional consumer spending, increased consumption in the central region can attract consumers from surrounding areas, leading to a decrease in transaction value in neighboring regions, exhibiting an inverse linkage pattern. On the other hand, if the central region's transaction activity is driven by regional promotional activities or economic policies, neighboring regions may also be similarly affected, experiencing a similar increase in transaction value. When transaction volume in one region fluctuates significantly, it not only impacts transaction levels in neighboring regions but also increases uncertainty in those regions, leading to increased variance. For example, if transaction volume in a tourist area surges during holidays, this seasonal fluctuation can be transmitted to surrounding accommodation, catering, and transportation service areas, causing greater volatility in transaction volume there as well. Conversely, when transaction volume in one region stabilizes, it can also have a stabilizing effect on neighboring regions, causing their transaction volume variance to converge. This complexity of fluctuation transmission makes traditional spatial weight matrix construction methods difficult to adapt to dynamically changing regional correlation patterns. Therefore, how to dynamically adjust the spatial weight matrix to capture the mutual influence mechanism of transaction volume fluctuations between adjacent regions, and thereby improve the sensitivity of transaction anomaly detection and reduce the false alarm rate, is an urgent technical problem to be solved. Summary of the Invention
[0003] The present invention provides a method for analyzing mobile payment transaction behavior based on spatial data, which mainly includes:
[0004] The time series data of transaction amounts in different geographical areas are obtained and feature extraction is performed to form a set of transaction amount fluctuation features. Spatial autocorrelation analysis is used on the fluctuation feature set to obtain the spatial correlation between regions. Based on the geographical radiation range and transaction type distribution, a spatial dependency network is constructed to obtain the spatial distribution characteristics of the transaction amount peak and determine the spatial dependency intensity distribution. Based on the spatial dependency intensity distribution, the transmission law of the transaction amount in the time dimension is analyzed, and the transmission direction and transmission speed characteristics are extracted. The transmission path and intensity are evaluated according to the transaction correlation strength and geographical distance between regions. The fluctuation cycle and the sensitivity of the adjacent regions are obtained in combination with the behavior pattern of the transaction subjects. According to the fluctuation cycle and the sensitivity of the adjacent regions, The weight values of spatiotemporal heterogeneity are corrected according to the spatiotemporal variation characteristics of inter-regional transaction intensity to determine the adaptive spatial weight matrix. A threshold analysis is performed on the adaptive spatial weight matrix to obtain the criteria for distinguishing abnormal fluctuations between regions. Anomalies are identified by comparing the deviation between actual transaction amounts and expected values, and a set of potential abnormal regions is obtained. The historical distribution pattern of transaction data in the set of potential abnormal regions is obtained, and the degree of deviation between the current fluctuation amplitude and the historical pattern is analyzed to determine the authenticity of the abnormal signal and determine the list of abnormal events. The degree of diffusion of the impact of abnormal events on surrounding areas is calculated to obtain the degree of variance expansion. The anomaly detection parameters are adjusted according to the abnormal event list, the detection rules are optimized, and the spatial dependency network is determined.
[0005] Furthermore, the acquisition of time series data of transaction amounts in different geographical areas and feature extraction to form a transaction amount fluctuation feature set includes:
[0006] The time series data of transaction amounts in different geographical areas are segmented, the total transaction amount and the number of transactions in each time period are calculated, the local maximum of the transaction amount is identified as the transaction amount peak, the time point and amount value of the transaction amount peak are recorded, the ratio of the difference in transaction amounts between adjacent time periods to the time interval is calculated as the rising rate, and time series feature data including the transaction amount peak, the rising rate and the transaction frequency are generated; based on the time series feature data, a transaction activity index is constructed, and the transaction activity index is based on the product of the transaction frequency and the rising rate, and the time period in which the transaction activity index exceeds the threshold is screened, and the distribution and duration of high-activity transaction periods in each geographical area are counted; the transaction location coordinates and transaction type information in the high-activity transaction period are extracted, and the transaction-intensive area is determined by using a density clustering algorithm, the geometric center of the intensive area and the maximum distance from the transaction location to the center are calculated as the geographical radiation range, and the proportion of the number of transaction types is counted; combined with the geographical radiation range, the proportion of the number of transaction types and the distribution of transaction active periods, a transaction amount fluctuation feature set is formed.
[0007] Further, the spatial correlation degree between regions is obtained by using spatial autocorrelation analysis on the fluctuation feature set, a spatial dependence relationship network is constructed based on geographical radiation range and transaction type distribution, including:
[0008] The correlation coefficient of the peak value of transaction amount in each region in the fluctuation feature set and the peak value of adjacent regions is calculated, a spatial weight matrix is constructed based on the reciprocal of the actual distance between regions, and global and local spatial autocorrelation values are calculated in combination with the spatial weight matrix to generate the spatial correlation degree between regions; based on the spatial correlation degree between regions and the proportion of the overlapping area of the geographical radiation range, the connection edge weight between regions is determined, and the spatial dependence relationship network is constructed.
[0009] Further, for the spatial dependence intensity distribution, the transmission rule of transaction amount in the time dimension is analyzed, and the transmission direction and transmission speed features are extracted, including:
[0010] The transaction amount change sequence of each region pair in the spatial dependence intensity distribution is extracted, the correlation coefficient sequence of the transaction amount change rate of the source region and the transaction amount change rate of the target region is calculated, the transmission direction and transmission time are determined based on the correlation coefficient sequence, and the ratio of geographical distance to transmission time is calculated as the transmission speed feature.
[0011] Further, according to the transaction correlation strength between regions and geographical distance, the propagation path and intensity are evaluated, and the fluctuation period and adjacent region sensitivity are obtained in combination with the transaction subject behavior mode, including:
[0012] Based on the transaction correlation strength between regions and geographical distance, the propagation path evaluation value is calculated, the path with an evaluation value exceeding a threshold value is selected as the main propagation path, the intensity attenuation ratio on the main propagation path is calculated, and the propagation intensity value is determined; the transaction amount time sequence of the region involved in the main propagation path is extracted, the frequency component of the time sequence is decomposed, the reciprocal of the main frequency is determined as the fluctuation period; the ratio of the transaction amount change amplitude of the target region to the change amplitude of the source region is calculated, and the response delay time is combined to generate the adjacent region sensitivity.
[0013] Further, according to the fluctuation period and the adjacent region sensitivity, the weight value of spatial and temporal heterogeneity is corrected according to the spatio-temporal variation characteristics of the transaction intensity between regions, an adaptive spatial weight matrix is determined, including:
[0014] The original weight value of each region pair is extracted, the difference value of the fluctuation period is calculated, the weight value is adjusted based on the fluctuation period difference value and the adjacent region sensitivity, and an intermediate weight matrix is generated; the time heterogeneity index and the spatial heterogeneity index of the transaction intensity sequence of the region pair in the intermediate weight matrix are calculated, a stability correction factor is generated based on the two indexes, the intermediate weight matrix is adjusted, and the adaptive spatial weight matrix is generated.
[0015] Furthermore, the adaptive spatial weight matrix is subjected to threshold analysis to obtain a criterion for determining abnormal fluctuations between regions. By comparing the deviation between actual transaction amounts and expected values, abnormal points are identified to obtain a set of potential abnormal regions, including:
[0016] Calculate the mean and standard deviation of the weight values in the adaptive spatial weight matrix, determine a high weight threshold, screen regional pairs whose weight values exceed the high weight threshold, and count the mean and standard deviation of the historical transaction amount fluctuations in the regional pairs whose weight values exceed the high weight threshold to generate an abnormal fluctuation discrimination standard; based on the abnormal fluctuation discrimination standard, calculate the relative deviation between the actual transaction amount of each region and the weighted expected value, mark the regions that exceed the threshold, and generate the potential abnormal region set.
[0017] Furthermore, the acquisition of the historical distribution pattern of the transaction data of the potential abnormal area, analysis of the degree of deviation between the current fluctuation range and the historical pattern, determination of the authenticity of the abnormal signal, and determination of the abnormal event list include:
[0018] The frequency distribution of historical transaction amounts in each area of the potential abnormal area set is counted, a probability density function is fitted, a normal transaction range is determined, the probability of the current transaction amount deviating from the normal transaction range is calculated, and a standardized deviation value is generated; based on the standardized deviation value, the abnormality duration and the impact range, an abnormality authenticity judgment index is constructed, and areas where the index exceeds the threshold are screened to generate the abnormal event list.
[0019] Furthermore, the calculation of the spread of the impact of the abnormal event on the surrounding area to obtain the variance expansion degree, adjusting the abnormality detection parameters according to the abnormal event list, optimizing the detection rules, and determining the spatial dependency network includes:
[0020] The geographic coordinates and intensity values of the abnormal events in the abnormal event list are obtained, and the impact intensity distribution is calculated based on the inverse distance and the Gaussian kernel function to generate an initial impact diffusion matrix; the variance of the impact intensity values in the initial impact diffusion matrix is calculated, and the spatial range parameters and sensitivity thresholds of the anomaly detection are adjusted based on the variance values to generate an updated anomaly detection rule set; based on the updated anomaly detection rule set, the sensitivity weights of the adjacent areas are adjusted, the adaptive spatial weight matrix is updated, and the final spatial dependency network is determined.
[0021] Furthermore, the method also includes: adjusting the geographical distance weight and correlation strength judgment criteria according to the actual coverage of the spread of abnormal events, correcting the deviation of capital flow and misjudgment of propagation direction, correcting the response intensity and impact radius boundary of adjacent areas to abnormal signals, updating the sensitivity distribution level and transmission time delay characteristics between regions, and ensuring that the transmission direction matches the actual capital flow direction.
[0022] The technical solution provided by the embodiment of the present invention may have the following beneficial effects:
[0023] The present invention discloses a method for analyzing mobile payment transaction behavior based on spatial data. By acquiring transaction amount time series data from different geographical regions, extracting transaction features and constructing a spatial dependency network, the spatial distribution and temporal transmission patterns of transaction amounts are analyzed. The present invention adopts an adaptive spatial weight matrix, combined with the behavioral patterns of transaction entities, to identify pairs of highly correlated regions and construct a lag effect model for inter-regional fluctuation transmission. By comparing the deviation between actual transaction amounts and expected values, potential abnormal areas are identified, and the authenticity of abnormal events is judged based on historical distribution patterns. The present invention also analyzes the impact and diffusion of abnormal events, dynamically adjusts detection parameters and spatial weights, and optimizes the diffusion path prediction of abnormal fluctuations, thereby achieving accurate identification and early warning of financial transaction anomalies and improving financial risk prevention and control capabilities. BRIEF DESCRIPTION OF THE DRAWINGS
[0024] Figure 1 This is a flow chart of a method for analyzing mobile payment transaction behavior based on spatial data according to the present invention.
[0025] Figure 2 Schematic diagram of a mobile payment transaction behavior analysis method based on spatial data according to the present invention. DETAILED DESCRIPTION
[0026] To help those skilled in the art better understand the technical solutions in this specification, the following will provide a clear and complete description of the technical solutions in the embodiments of this specification, in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of this specification, not all of them. All other embodiments derived by those skilled in the art based on the embodiments in this specification without creative effort shall fall within the scope of protection of this specification.
[0027] like Figure 1-2 In this embodiment, a method for analyzing mobile payment transaction behavior based on spatial data may specifically include:
[0028] S101. Obtain time series data of transaction amounts in different geographical areas, perform feature extraction, and form a transaction amount fluctuation feature set.
[0029] Obtain time series data on transaction amounts in different geographic regions, segment the transaction records for each geographic region according to a preset time window, calculate the total transaction amount and number of transactions within each time period, identify the local maximum transaction amount as the peak value using a sliding window method, record the time point when the peak occurs and the corresponding transaction amount value, calculate the difference between the transaction amount in the current time period and the transaction amount in the previous time period and divide it by the time interval to obtain the rate of increase, and form time series feature data containing peak time, peak amount, rate of increase, and transaction frequency. Based on this time series feature data, construct a transaction activity index, which is equal to the absolute value of the transaction frequency multiplied by the rate of increase. When the transaction activity index exceeds a preset threshold, the time period is determined to be a high-activity transaction period. The time distribution and duration of high-activity transaction periods in each geographic region are statistically analyzed to obtain the distribution characteristics of the transaction activity period. For the transaction data during the highly active transaction period, the specific location coordinates and transaction type information of the transaction are extracted, and the DBSCAN clustering algorithm is used to perform density clustering on the location coordinates. The neighborhood radius is set as the preset distance threshold, and the minimum number of samples is set as the preset quantity threshold to obtain the transaction-intensive area. The geometric center of all transaction locations in each dense area is calculated as the regional center, and the maximum distance from each transaction location to the regional center is determined as the radiation range of the geographical area. The proportion of the number of different transaction types in each dense area is counted. Through the radiation range, the proportion of the number of transaction types and the distribution characteristics of the active transaction period, combined with the peak value, rising rate and transaction frequency in the time series feature data, a transaction amount fluctuation feature vector is constructed. The vector contains the mean of the peak amount, the standard deviation of the rising rate, the coefficient of variation of the transaction frequency, the radiation range value, the proportion of the main transaction types and the mean duration of the high-activity period. After normalizing the data of each dimension, a transaction amount fluctuation feature set is formed.
[0030] In one possible implementation, when obtaining time-series data on transaction amounts in different geographic regions, all transaction records for each geographic region within a specific time period are extracted from the transaction database. Setting the time window is crucial, and the appropriate time granularity is typically selected based on the business characteristics. For example, retail businesses may use hourly windows, while wholesale businesses use daily windows. The sliding window method identifies local maxima by setting the window size and sliding step size. When the transaction amount in a certain time period is greater than that in the preceding and following time periods, it is determined to be a peak. The calculation of the rising rate reflects the changing trend of the transaction amount. It is calculated by dividing the difference between adjacent time periods by the time interval. A positive value indicates an upward trend, while a negative value indicates a downward trend. This quantitative method can accurately capture the dynamic changes in transaction activities.
[0031] Specifically, the construction of the transaction activity index comprehensively considers two dimensions: transaction frequency and the rate of change of transaction amount. When a geographical area experiences both high-frequency transactions and rapid growth in transaction amount within a short period of time, it indicates that the area is experiencing peak business. When setting the activity threshold, it is necessary to consider the distribution characteristics of historical data, and the 75th percentile of historical data is usually used as a reference. Identifying high-activity trading periods helps to identify hot trading periods, such as the peak trading hours in shopping malls on weekend afternoons and the intensive trading in financial streets on weekday mornings. By calculating the time distribution and duration of high-activity periods in various geographical areas, it is possible to understand the differences in trading rhythms in different regions, providing a basis for subsequent resource allocation and risk management.
[0032] It is important to note that the DBSCAN clustering algorithm demonstrates unique advantages when processing transaction location data. Based on the concept of density-based clustering, this algorithm can automatically discover dense transaction areas of any shape without requiring a pre-specified number of clusters. The neighborhood radius parameter determines the spatial range for determining density, while the minimum sample number parameter ensures that the resulting clusters are sufficiently representative. The algorithm effectively identifies areas where transactions are concentrated by classifying core points, boundary points, and noise points. The geometric center is calculated using the arithmetic mean of the coordinates of all transaction locations, while the radius reflects the spatial coverage of transaction activity. Analysis of the proportion of different transaction types reveals the business characteristics of each area. For example, commercial areas are dominated by retail transactions, while industrial areas have a higher proportion of wholesale transactions.
[0033] In one embodiment, the process of constructing a transaction amount fluctuation feature vector involves the integration and standardization of multi-dimensional data. The mean of the peak amount reflects the overall level of regional transaction volume, the standard deviation of the rate of increase reflects the stability of transaction changes, and the coefficient of variation measures the degree of dispersion of transaction frequency. Normalization uses a minimum-maximum standardization method to map each dimension of data to a range of 0 to 1, eliminating the impact of dimensional differences. This multi-dimensional feature representation comprehensively depicts transaction behavior patterns in various geographic regions, and the resulting feature set lays a solid foundation for subsequent regional comparisons, anomaly detection, and trend prediction.
[0034] S102. Use spatial autocorrelation analysis on the fluctuation feature set to obtain the spatial correlation between regions. Based on the geographical radiation range and transaction type distribution, construct a spatial dependency relationship network to obtain the spatial distribution characteristics of the peak transaction amount and determine the spatial dependency intensity distribution.
[0035] For each geographic region in the fluctuation feature set, the peak value data of the transaction amount of the region and the peak value data of the transaction amount of the adjacent region are calculated, the Pearson correlation coefficient of the peak value of each region and the peak value of the adjacent region is calculated, the adjacency relationship between the regions is determined through a spatial weight matrix, the spatial weight matrix is constructed based on the inverse of the actual distance between the regions, the global spatial autocorrelation value and the local spatial autocorrelation value of each region are obtained by using the Moran index, and the spatial correlation degree between the regions is obtained by multiplying the correlation coefficient and the local spatial autocorrelation value. According to the spatial correlation degree between the regions, in combination with the overlapping area proportion of the geographical radiation range and the cosine similarity of the transaction type distribution vector, when the overlapping area proportion of the radiation ranges of two regions exceeds a preset threshold and the cosine similarity of the transaction types is greater than a preset value, a connection edge between the regions is established, the weight of the connection edge is equal to the product of the spatial correlation degree and the cosine similarity, and a spatial dependence relationship network composed of nodes and weighted edges is formed. The weighted degree value of each node in the spatial dependence relationship network is calculated by using the number of connection edges and the sum of weights of each node, nodes with a weighted degree value in a preset percentage are identified as peak value aggregation centers, the peak value of the transaction amount of each aggregation center and the number of regions affected by the network connection are counted, the distribution of the peak value in different aggregation centers is recorded, and the spatial distribution feature of the peak value of the transaction amount is obtained. For the peak value aggregation centers and other regional nodes identified in the spatial distribution feature, a path reaching from any two nodes in the network through the least connection edge is calculated, the product of the weights of the edges on the path is taken as the dependence transmission intensity between the nodes, a dependence intensity matrix containing all regional pairs is constructed, each element in the matrix represents the spatial dependence intensity value between the corresponding regional pair, and the spatial dependence intensity distribution is determined.
[0036] Specifically, the calculation of the Pearson correlation coefficient involves the ratio of the covariance of the transaction amount peak value sequences of two regions to the product of the standard deviations. When the correlation coefficient is close to 1, it indicates that the transaction peak value change trends of the two regions are highly consistent, and there may be a business linkage relationship. The construction of the spatial weight matrix is based on the first law of geography, that is, the closer the distance between regions, the greater the mutual influence. The use of the inverse of the distance ensures that adjacent regions obtain higher weight values, and the influence of distant regions is appropriately weakened. The Moran index is used as a classic measure of spatial autocorrelation, and its global value reflects the overall spatial aggregation degree, and the local value reveals the similarity of each region and the surrounding area. Multiplying the correlation coefficient and the local spatial autocorrelation value comprehensively considers the business correlation and spatial proximity in two dimensions, and obtains a more accurate spatial correlation measure.
[0037] In one possible implementation, the percentage of geographic overlap is calculated by calculating the ratio of the intersection of two regional radiation circles to the area of the smaller circle. This metric reflects the actual degree of overlap in business coverage between regions. The transaction type distribution vector is constructed based on the percentage of each type of transaction, such as 0.6 for retail transactions, 0.3 for wholesale transactions, and 0.1 for service transactions, forming a normalized distribution vector. Cosine similarity calculates the cosine of the angle between two vectors, ranging from 0 to 1, with larger values indicating more similar transaction structures. By setting thresholds to filter and establish connecting edges, we avoid overly complex networks and retain connections between regions with genuine business relevance. Edge weights are calculated by integrating both spatial and business dimensions, reflecting the true strength of dependencies under the influence of multiple factors.
[0038] It's important to note that the calculation of weighted degree values takes into account not only the number of connections to a node but, more importantly, the strength of each connection. A region may be connected to only a few, but if the weights of these connections are high, its weighted degree value can still exceed that of a region with many connections but lower weights. Peak concentration centers are identified using a percentage ranking method, adapting to the needs of networks of varying sizes. These centers are often key nodes in regional trading networks, and changes in their trading activity can influence other regions through the network. Recording spatial distribution characteristics includes differences in peak size across centers, revealing the spatial imbalance of trading activity.
[0039] For example, the calculation of dependency transmission strength is based on the concept of network paths. Multiple paths may exist from a peak concentration center to a common area. The algorithm selects the path with the fewest connected edges as the shortest path. The continuous product of the edge weights along the path reflects the attenuation of influence during the transmission process. With each intermediate node, the influence decreases in proportion to the connection strength. The resulting dependency strength matrix is a complete map of the mutual influence between regions. Each value in the matrix represents the degree of spatial business dependence between a specific pair of regions.
[0040] S103. Analyze the transmission pattern of transaction amounts in the time dimension based on the spatial dependence intensity distribution, extract the transmission direction and transmission speed characteristics, evaluate the transmission path and intensity based on the transaction correlation strength and geographical distance between regions, and combine the behavior patterns of transaction entities to obtain the fluctuation cycle and sensitivity of adjacent regions.
[0041] For each region pair in the spatial dependency intensity distribution matrix, the transaction amount change sequence within the continuous time window is extracted. The correlation coefficient between the transaction amount change rate of the source region in the previous time window and the transaction amount change rate of the target region in each subsequent time window is calculated. The correlation coefficient sequence under different delays is obtained by moving the time window. When the correlation coefficient under a certain delay exceeds a preset threshold, the transmission direction is determined to be from the source region to the target region. The delay time when the maximum correlation coefficient is generated is recorded as the transmission time. The transmission speed value is obtained by dividing the geographical distance by the transmission time. Based on the transmission speed value and transmission direction, the dependency intensity in the spatial dependency intensity distribution matrix is used as the transaction correlation strength between regions. A propagation path evaluation value is constructed. This evaluation value is equal to the product of the transaction correlation strength and the inverse of the geographical distance, multiplied by the transmission speed value. If the evaluation value is greater than the preset threshold, it is determined to be the main propagation path. The intensity attenuation ratio of each intermediate region along the path is calculated, and the transmission intensity value from the source region to the target region is obtained by continuous multiplication. The high-influence area pairs identified by the propagation intensity value are extracted, and the transaction amount time series of each area in these area pairs are extracted. The frequency components of the time series are decomposed by fast Fourier transform, and the frequency component with the largest amplitude is selected as the main frequency, and its reciprocal is the fluctuation period of the area. At the same time, the time difference between the change of the transaction amount in the target area and the transaction amount in the source area is calculated as the response delay, and the ratio of the change amplitude of the transaction amount in the target area to the change amplitude of the source area is used as the response coefficient. The product of the reciprocal of the response delay and the response coefficient is the sensitivity of the adjacent area.
[0042] In one possible implementation, the rate of change in transaction value is calculated based on the difference between adjacent time windows. If the total transaction value in a region is 10 million in the first time window and 12 million in the second, with a one-hour interval, the rate of change is 2 million per hour. The delayed correlation coefficient is calculated using a moving time window, with an initial delay of 0 and gradually increasing delays. Each time, the correlation between the source and target regions at the corresponding time position is calculated. The correlation coefficient peaks at 0.85 at a two-hour delay, indicating that transaction changes in the source region take two hours to propagate to the target region. The physical meaning of the propagation speed value reflects the spatial diffusion efficiency of transaction influence. For example, if two regions are 50 kilometers apart and the propagation time is two hours, the propagation speed is 25 kilometers per hour.
[0043] Specifically, the transmission path assessment value is constructed by comprehensively considering multiple factors. Spatial dependency strength reflects the closeness of business connections between regions, the inverse of geographic distance reflects the role of spatial proximity, and the transmission speed value represents the timeliness of the impact on transmission. The comprehensive assessment value derived by multiplying these three factors can identify truly significant transmission paths. The calculation of the intensity decay ratio is based on the principle of energy loss in actual business transmission. With each intermediate region, the impact of a transaction decreases due to the absorption and conversion of the region itself. Assuming an initial transmission intensity of 1.0, it decays by 20% to 0.8 after passing through the first intermediate region, and then by 15% to 0.68 after passing through the second intermediate region. This continuous decay reflects the law of diminishing influence in reality.
[0044] It's important to note that when analyzing transaction amount time series, the Fast Fourier Transform (FFT) can decompose complex time-domain signals into a superposition of sinusoidal waves of varying frequencies. The dominant frequency component represents the most significant periodic pattern in trading activity, and its reciprocal is the fluctuation period. If the dominant frequency is 0.125, the fluctuation period is 8 time units, potentially corresponding to a trading peak occurring every 8 hours. Response latency is measured by comparing the time difference between transaction peaks in the source and target regions, reflecting the temporal nature of the influence. The response coefficient quantifies the sensitivity of the target region to changes in the source region; a larger coefficient indicates a more significant impact of the source region on the target region.
[0045] For example, if the transaction amount in the source region increases by 1 million, and the target region increases by 600,000 three hours later, the response delay is 3 hours, and the response coefficient is 0.6. The sensitivity of the adjacent region is calculated by multiplying the inverse of the response delay by the response coefficient: 0.33 times 0.6 equals 0.2. This value comprehensively reflects the speed and intensity of the target region's response to changes in the source region. The more sensitive the region pair, the stronger the interconnectedness of its transaction activities, and thus requires special attention in business planning and risk management. By calculating the sensitivity of all adjacent region pairs, a complete regional transaction sensitivity map can be constructed, providing a quantitative basis for precise regional collaborative management.
[0046] Extract high-correlation regional pairs from the spatial dependence intensity distribution, identify the radiation intensity and propagation attenuation law of the financial center to the surrounding areas based on the high-correlation regional pairs, analyze the cyclical trading habits and regional preference patterns of trading entities, determine the active periods and regional concentrations of different types of trading entities, construct a time-lag effect model for inter-regional fluctuation transmission, and quantify the sensitivity and fluctuation cycle of neighboring regions to the trading fluctuations in the core area.
[0047] The method extracts pairs of regions from the spatial dependency intensity distribution matrix whose dependency intensity exceeds a preset threshold as high-correlation region pairs. From these high-correlation region pairs, the regions with the highest predetermined percentage of average transaction amounts are selected as financial centers. The ratio of the dependency intensity value from the financial center to each surrounding region to the geographic distance is calculated as the radiation intensity per unit distance. The radiation intensity at different distance intervals is logarithmically regressed, and the negative value of the regression coefficient is the attenuation coefficient, resulting in a propagation law in which the radiation intensity decays exponentially with distance. Based on the financial centers and propagation law, the transaction records of each trading entity in consecutive time periods are extracted. The transaction frequency of each trading entity in each time period is counted. Significant periodic values are identified as cyclical trading habits by calculating the autocorrelation function of the transaction frequency series. The proportion of each trading entity's transaction amount in each region to its total transaction amount is calculated. The region with the highest proportion is identified as the primary preferred region. After grouping by transaction type, the time period with the highest transaction frequency for each type of entity is counted as the active period. The proportion of transaction amount of each type in the primary preferred region is calculated as the regional concentration. Through the active time periods, regional concentration and cyclical trading habits, the historical trading data of the financial center and the neighboring areas are obtained, and the trading changes in the neighboring areas at different delay times after the changes in the financial center's transactions are calculated. The ratio of the change in the neighboring area to the change in the financial center is used as the response coefficient under different delays. A time-lag effect relationship is constructed with the delay time as the independent variable and the response coefficient as the dependent variable. The delay time when the response coefficient reaches the maximum value is determined as the optimal time lag. The average value of the response coefficient under the optimal time lag of all neighboring areas is calculated as the response sensitivity, and the main periodic components of the trading sequence of the neighboring areas are extracted to determine the fluctuation period.
[0048] In one possible implementation, the identification of highly correlated regional pairs is based on threshold screening of the spatial dependency intensity distribution matrix. A dependency intensity value exceeding 0.7 indicates a close transaction linkage between the two regions. The identification of financial centers not only considers transaction volume but also their influence on surrounding areas. Calculation of radiation intensity per unit distance reveals the spatial propagation characteristics of financial influence. For example, the radiation intensity of a financial center is 0.8 for areas 1 kilometer away, decreasing to 0.3 for areas 5 kilometers away. This decreasing trend is linearized after logarithmic transformation. The absolute value of the slope obtained from the linear regression is the attenuation coefficient, which reflects the rate at which influence decays with distance.
[0049] Specifically, the autocorrelation function plays a key role in identifying transaction periodicity. By calculating the correlation of transaction frequency series at different time lags, hidden cyclical patterns can be discovered. When the autocorrelation coefficient reaches a peak of 0.75 after a 7-day lag, it indicates that there is a weekly pattern in transaction activity. The regional preference of trading entities is obtained by calculating the proportion of transaction amounts in each region. If a retailer's transactions in the commercial district account for 65% of its total transactions, then the commercial district is its main preferred area. Statistics on active time periods reveal behavioral differences between different types of entities. Wholesalers concentrate their transactions between 4 and 6 in the morning, while retailers are mainly active between 2 and 5 in the afternoon. Geographic concentration quantifies the degree of spatial aggregation of trading activities. The higher the value, the more concentrated the business is in a specific area.
[0050] It should be noted that constructing the time-lag effect relationship involves analyzing and processing a large amount of historical data. The input signal is the transaction changes in the financial center, and the output signal is the response of neighboring regions. Using a moving time window, the response strength is calculated under different delays. When the transaction volume of the financial center increases by 10 million, neighboring region A increases by 6 million two hours later, with a response coefficient of 0.6; region B increases by 4 million three hours later, with a response coefficient of 0.4. This delayed response reflects the transmission process of transaction impacts, with different regions exhibiting different response characteristics depending on their degree of business connection with the financial center.
[0051] For example, the optimal time lag is determined based on the peak of the response coefficient curve. As the delay increases, the response coefficient first rises and then falls, and the delay corresponding to the peak is the optimal time lag. This point in time represents the optimal timing for the transmission of the impact; too early, the impact has not yet fully propagated, while too late, the impact has already decayed. The response sensitivity is calculated by averaging the response coefficients of multiple adjacent regions, comprehensively reflecting the sensitivity of the entire regional network to changes in financial centers. The extraction of fluctuation cycles utilizes frequency domain analysis, converting the time domain transaction sequence into the frequency domain and identifying the frequency component with the highest energy concentration. The reciprocal of this frequency component is the primary fluctuation cycle.
[0052] S104. According to the fluctuation cycle and the sensitivity of the adjacent regions, the weight value of the spatiotemporal heterogeneity is corrected according to the spatiotemporal variation characteristics of the inter-regional transaction intensity, and an adaptive spatial weight matrix is determined.
[0053] Based on the obtained fluctuation cycles and neighboring region sensitivity values, the original weight values for each region pair are extracted from the initially constructed spatial weight matrix. The difference in the fluctuation cycles of each pair of regions is calculated and the absolute value is taken. When this absolute value is less than a preset threshold, it indicates that the fluctuations of the two regions are synchronized. The original weight values are multiplied by the corresponding neighboring region sensitivity to obtain an enhanced weight. If the absolute value exceeds the threshold, indicating that the fluctuations are asynchronous, the original weight values are divided by the neighboring region sensitivity to obtain a weakened weight, forming an intermediate weight matrix reflecting the synchronization of fluctuations. Based on the regional associations determined by this intermediate weight matrix, the trading intensity series of each region pair within a continuous time window is extracted. The sum of the squares of the difference between the value and the mean at each time point in each series is calculated and divided by the number of time points to obtain a temporal heterogeneity index. The sum of the squares of the difference in trading intensity between spatially adjacent pairs of regions is calculated and divided by the number of region pairs, and the square root is taken to obtain a spatial heterogeneity index. The inverse of the multiplication of these two indices is taken as the stability correction factor. The intermediate weight matrix is adjusted according to the stability correction factor, and each weight value in the matrix is multiplied by the stability correction factor of the corresponding region pair to obtain a weight value that comprehensively considers the fluctuation characteristics and spatiotemporal stability. The adjusted matrix is normalized row by row so that the sum of the elements in each row is 1, and the adaptive spatial weight matrix is determined.
[0054] In one possible implementation, the calculation of the difference in volatility cycles directly reflects the varying rhythms of trading activity across regions. If the volatility cycle in region A is 7 days and in region B is 8 days, with an absolute difference of 1 day, and a preset threshold of 2 days, the two regions are considered to be in volatility synchronization. This synchronization implies that the peak and trough periods of trading in the two regions are roughly aligned, indicating strong business linkage. In this case, multiplying the original weight of 0.3 by the sensitivity of 0.8 yields an enhanced weight of 0.24, strengthening the connection between the synchronized regions. Conversely, if the cycle in region C is 12 days, with a difference of 5 days from region A, exceeding the threshold and indicating volatility synchronization, the original weight of 0.4 divided by the sensitivity of 0.6 yields 0.67, which reasonably reflects the weakening effect of influence transmission between asynchronous regions.
[0055] Specifically, the calculation of the temporal heterogeneity index involves analyzing the degree of dispersion of the trading intensity time series. Suppose that the trading intensity of a region in 10 time windows is 1,000, 1,200, 950, 1,300, 1,100, 1,250, 900, 1,350, 1,050, and 1,150,000 yuan, with a mean of 1,125,000 yuan. The squared difference between the mean and the value at each time point is 156.25, 56.25, 306.25, 306.25, 6.25, 156.25, 506.25, 506.25, 56.25, and 6.25, respectively. The sum is 2056.5, which is divided by 10 to obtain 205.65, which is used as the temporal heterogeneity index. A larger value indicates greater temporal fluctuations in trading intensity and less stability.
[0056] It should be noted that the spatial heterogeneity index focuses on the degree of variation in transaction intensity between geographically adjacent regions. By calculating the difference in transaction intensity between adjacent regions, spatial imbalance can be quantified. For example, if the transaction intensities of adjacent regions D and E are 2 million and 1.5 million, respectively, the difference is 0.5 million; and if the transaction intensities of regions E and F are 1.5 million and 1.8 million, the difference is 0.3 million. Squared, summed, and squared, these differences yield a measure of spatial heterogeneity. The spatiotemporal heterogeneity index, obtained by multiplying these two measures, reflects the overall fluctuations in transaction activity across both time and space.
[0057] For example, the stability correction factor, as the inverse of the comprehensive index, physically means assigning smaller weights to regional pairs with high volatility. When the spatiotemporal heterogeneity index for a particular regional pair is 100, the stability correction factor is 0.01, indicating that the trading association for this regional pair is relatively unstable, and its influence in the spatial weight matrix needs to be moderately reduced. Normalization ensures that the overall spatial influence on each region remains constant, avoiding systematic biases caused by weight adjustments.
[0058] S105. Threshold analysis is performed on the adaptive spatial weight matrix to obtain a criterion for determining abnormal fluctuations between regions. Abnormal points are identified by comparing the deviation between actual transaction amounts and expected values, thereby obtaining a set of potential abnormal regions.
[0059] The weight values in the adaptive spatial weight matrix are statistically analyzed, and the mean and standard deviation of all weight values are calculated. The mean plus a preset multiple of the standard deviation is used as a high-weight threshold. Region pairs with weight values exceeding this threshold are selected as strongly correlated region pairs. The mean and standard deviation of the historical transaction amount fluctuations of each region in these strongly correlated region pairs are then calculated. The mean of the fluctuations plus a preset multiple of the standard deviation is used as the abnormal fluctuation threshold. Based on the abnormal fluctuation threshold and the adaptive spatial weight matrix, for each region, a weighted average is calculated using the weight value of the corresponding row in the matrix and the historical average transaction amount of other regions as the expected transaction amount for that region. The actual transaction amount for the region in the current period is obtained, and the absolute value of the difference between the actual and expected values is calculated and divided by the expected value to obtain the relative deviation. The relative deviation is then compared with the abnormal fluctuation threshold. If the relative deviation of a region exceeds the threshold, the region is marked as an abnormal region. The time of the abnormality, the relative deviation value, and the information about the strongly correlated region pair to which the region belongs are recorded. All marked abnormal regions and their associated information are summarized to form a set of potential abnormal regions.
[0060] In one possible implementation, the high-weight threshold is determined based on statistical outlier detection methods. The adaptive spatial weight matrix contains the association strength values between all region pairs, and these weight values typically exhibit a normal distribution. When the calculated weight mean is 0.3 and the standard deviation is 0.1, if the preset multiplier is 2, the high-weight threshold is 0.5. Region pairs exceeding this threshold are identified as strongly associated, indicating an unusually close business connection between these regions. Strong associations may arise from geographical proximity, upstream and downstream relationships in the industrial chain, or shared customer bases.
[0061] Specifically, the threshold for identifying abnormal fluctuations needs to consider the historical transaction characteristics of strongly correlated regions. Suppose regions A and B form a strongly correlated pair, with historical transaction fluctuations of 1 million and 1.5 million daily, respectively. By analyzing fluctuation data across multiple time windows, we find a mean of 1.25 million and a standard deviation of 300,000. Using the principle of three times the standard deviation, the threshold for identifying abnormal fluctuations is set at 2.15 million. This threshold reflects the upper limit of normal business fluctuations; fluctuations above this threshold are likely caused by special events.
[0062] It's important to note that the calculation of expected transaction amounts fully utilizes the association information in the spatial weight matrix. For target region C, its corresponding row in the matrix contains the weights relative to all other regions. Assume that region C's weight relative to region D is 0.6, with a historical average transaction amount of 10 million yuan; its weight relative to region E is 0.3, with a historical average transaction amount of 8 million yuan; and its weight relative to region F is 0.1, with a historical average transaction amount of 5 million yuan. The weighted calculation is 0.6 × 1000 + 0.3 × 800 + 0.1 × 500, resulting in an expected transaction amount of 8.9 million yuan for region C. This calculation method reflects the varying influence of different regions on the target region.
[0063] For example, the calculation of relative deviation provides a standardized measure of anomaly severity. When the actual transaction amount in region C is 12 million yuan and the expected value is 8.9 million yuan, the absolute value of the difference is 3.1 million yuan. Dividing this by the expected value of 8.9 million yuan yields a relative deviation of 0.348. Comparing this value with the threshold for identifying abnormal fluctuations, assuming the threshold corresponds to a relative deviation of 0.24, 0.348 significantly exceeds the threshold, and region C is flagged as an anomaly. Recorded correlation information includes key elements such as the anomaly occurring at 3:00 PM, a relative deviation of 34.8%, and a strong correlation with region D. Through this multi-layered screening and identification mechanism, the set of potential anomaly regions not only contains information about the anomaly regions themselves, but also preserves the strong correlation network to which they belong. This design enables subsequent anomaly analysis to proceed from point to surface, locating specific anomaly regions and tracing their propagation paths within the correlation network. The accuracy of anomaly detection benefits from the combination of global statistical features and local correlation structures, avoiding the potential misjudgment caused by relying solely on fixed thresholds and providing reliable technical support for early warning of transaction risks.
[0064] S106. Obtain the historical distribution pattern of the aggregate transaction data of the potential abnormal area, analyze the degree of deviation between the current fluctuation range and the historical pattern, determine the authenticity of the abnormal signal, and determine the abnormal event list.
[0065] The system obtains historical transaction data for each area in the set of potential abnormal areas, calculates the frequency distribution of transaction amounts by time period, identifies continuous intervals with probability density exceeding a preset density threshold as normal transaction intervals, and calculates the probability that the transaction amount during the current abnormal period falls outside the normal transaction interval. If this probability exceeds a preset deviation threshold, a historical distribution deviation is determined. Based on the determination of historical distribution deviation, the absolute value of the difference between the current transaction amount and the center value of the normal transaction interval is calculated for each area with deviation. This difference is then divided by the standard deviation of the historical transaction amount to obtain a standardized deviation value. The number of consecutive time windows from the first time the area was marked as abnormal to the current time is counted as the abnormal duration. The constructed regional association network is then queried to determine the number of areas directly connected to the abnormal area with similarly deviated transaction amounts as the impact range. An abnormality authenticity judgment index is constructed based on the standardized deviation value, abnormality duration and impact range. The index is equal to the product of the standardized deviation value and the abnormality duration, multiplied by the impact range plus one and then taking the natural logarithm. If the judgment index exceeds the preset authenticity judgment threshold, the abnormality in the area is confirmed to be a real event, and the area identification, abnormality start time, standardized deviation and number of affected areas are recorded. All confirmed real abnormalities are summarized to form an abnormal event list.
[0066] In one possible implementation, the kernel density estimation method fits the overall distribution characteristics by assigning a continuous probability distribution to historical transaction data points. This method does not presuppose that the data follows a specific distribution, but instead adaptively constructs a probability density function based on the density of actual data points. When 80% of the transaction amounts in a region historically are concentrated between 8 million and 12 million, kernel density estimation will produce a higher probability density value in this range. With a density threshold set to 0.7, continuous intervals exceeding this threshold are identified as normal transaction ranges. If the current transaction amount is 18 million, which clearly falls outside the normal range, the system calculates that the cumulative probability of this value in the historical distribution is only 0.02, far below the deviation threshold of 0.05, thus determining that there is a significant distribution deviation.
[0067] Specifically, the calculation of the standardized deviation reflects a quantitative assessment of the degree of anomaly. The center value of the normal trading range is determined by weighted average, assuming it is 10 million. The current trading volume of 18 million deviates from the center value by 8 million, while the historical standard deviation is 2 million. This gives a standardized deviation of 4. This value indicates that the current trading volume deviates from the normal level by 4 standard deviations, which is an extreme anomaly. The duration of the anomaly is calculated from the time the anomaly flag is first triggered, with each time window representing a monitoring period, such as one window per hour. If the anomaly persists for five consecutive windows, it indicates that this is not a random data fluctuation.
[0068] It's important to note that querying the regional correlation network leverages a previously constructed spatial dependency structure. This network captures the strength of business connections and geographic proximity between regions. Once a core abnormal region is identified, the system traverses all directly connected regional nodes to check whether similar transaction anomalies are occurring in these adjacent regions. If three of the five directly connected regions of abnormal region A experience simultaneous transaction deviations, the impact range is recorded as three. Such linked anomalies often indicate regional systemic risks or the impact of a major event.
[0069] For example, the construction of anomaly authenticity discrimination indicators adopts a multi-factor comprehensive evaluation approach. The standardized deviation is 4, the duration is 5, and the impact range is 3. According to the formula, 4×5×ln(3+1), or 20×1.39, equals 27.8. The design of taking the natural logarithm takes into account the marginal diminishing effect of the impact range, preventing individual large-scale events from overly dominating the score. When the discrimination threshold is set to 15, 27.8 clearly exceeds the threshold and is confirmed as a true anomaly. The records in the abnormal event list not only contain quantitative indicators but also retain temporal information and spatial correlation characteristics, providing a complete data foundation for subsequent anomaly cause analysis and risk transmission path tracing.
[0070] S107, obtain the variance expansion degree by calculating the influence diffusion degree of the abnormal event on the surrounding area, adjust the abnormal detection parameters according to the abnormal event list, optimize the detection rules, and determine the spatial dependence relationship network.
[0071] The geographical coordinates of the abnormal event occurrence position and the event intensity value are obtained, the Euclidean distance between the event and the center points of each surrounding area is calculated, the initial influence weight vector is constructed according to the distance reciprocal relationship, the influence intensity distribution of each adjacent area is calculated by the Gaussian kernel function exp(-d² / 2σ²), wherein d is the distance and σ is the bandwidth parameter, and the initial influence diffusion matrix of the abnormal event on the surrounding area is obtained. According to the influence intensity value of each area in the initial influence diffusion matrix, the mean and standard deviation of the intensity values of all affected areas are calculated, the variance value is obtained by squaring the standard deviation, and if the variance value exceeds 1.5 times the historical mean, it is judged as a high diffusion abnormal event, and the diffusion radius, influence peak value and decay rate of the event are recorded as diffusion characteristic parameters, and the variance expansion degree evaluation result is obtained. The diffusion radius in the variance expansion degree evaluation result is used to adjust the spatial range parameter of the abnormal detection, the detection sensitivity threshold is updated according to the influence peak value, which is the original threshold multiplied by the peak value proportion coefficient, the time window length is corrected according to the decay rate, and the parameters are adjusted iteratively until the detection accuracy converges, and the updated abnormal detection rule set containing the spatial range, sensitivity threshold and time window is obtained. The abnormal propagation path identified by the updated abnormal detection rule set is used to calculate the abnormal intensity change ratio between adjacent areas as the transfer coefficient, the time difference of abnormal peak value occurrence is counted as the response delay time, the sensitivity weight of adjacent areas is adjusted according to the product of the transfer coefficient and the response delay time, the adaptive spatial weight matrix containing directionality and time sequence is constructed, and the final spatial dependence relationship network is determined.
[0072] Specifically, when an abnormal event occurs in a certain area, first, the latitude and longitude coordinates of the event are located, and the intensity value is quantified.
[0073] For example, in the mobile payment scenario, a large number of abnormal transaction behaviors occur in a certain area, and the abnormal transaction hotspot position is recorded as east longitude 114.5 degrees and north latitude 38.0 degrees, and the abnormal transaction intensity score is 9.0. By calculating the Euclidean distance between the abnormal point and the center of each surrounding monitoring area, such as the distance between adjacent commercial circle A and commercial circle B, the weight vector is constructed according to the distance reciprocal 1 / 600 and 1 / 900. The application of the Gaussian kernel function exp(-d² / 2σ²) makes the influence intensity present natural decay characteristics, when the bandwidth parameter σ is set to 400, the influence intensity at a distance of 600 meters is about 0.37, and the influence intensity at a distance of 900 meters is reduced to 0.11, forming an influence diffusion matrix that conforms to the actual propagation law. This influence diffusion matrix provides a data basis for subsequent variance analysis.
[0074] In one possible implementation, the intensity average of all affected areas is calculated, such as the average impact intensity of 10 affected business circles being 3.8, the standard deviation being 2.3, and the variance value being 5.29. When the historical data shows that the average variance value under normal circumstances is 2.8, the current variance value of 5.29 exceeds the judgment threshold of 4.0, and it is judged that this is a high diffusion abnormal event. The record of the diffusion characteristic parameters includes the diffusion radius 1500 meters, the impact peak value 9.0 minutes, and the attenuation rate of 12% per hundred meters, which accurately describe the spatial propagation characteristics of the abnormal event.
[0075] It should be noted that these diffusion characteristic parameters directly guide the optimization of the detection rules. The diffusion radius of 1500 meters means that the detection range needs to be expanded from the original 1000 meters to 1500 meters to ensure that all potential affected areas are included in the monitoring. The ratio of the impact peak value 9.0 minutes to the historical average peak value 6 minutes is 1.5, which becomes the adjustment coefficient of the sensitivity threshold, and the original threshold is adjusted from 3.5 minutes to 5.25 minutes, improving the recognition ability of high-intensity anomalies. The attenuation rate determines the setting of the time window. Fast attenuation anomalies require a shorter time window for timely response, while slow attenuation anomalies require an extended observation time. By identifying the propagation path of the anomaly, the system found that when the abnormal transaction behavior was transmitted from business circle A to business circle B, the payment failure rate change ratio was 2.0, i.e., the abnormality of business circle B was 2.0 times that of business circle A. This ratio is the transmission coefficient. At the same time, 10 minutes after the abnormality occurred in business circle A, business circle B showed obvious abnormality, and this 10 minutes is the response delay time. The product of the transmission coefficient and the delay time, 20, is used to adjust the sensitivity weight of business circle B, making it more sensitive to anomalies from business circle A.
[0076] According to the actual coverage range of the abnormal event diffusion, the geographical distance weight and the correlation strength judgment standard are adjusted, the fund flow deviation and the propagation direction misjudgment are corrected, the response strength of adjacent areas to abnormal signals and the influence radius boundary are modified, the sensitivity distribution level and the transmission time delay characteristics between areas are updated, and it is ensured that the transmission direction matches the actual fund flow direction.
[0077] The set of geographic boundary coordinates actually affected by the abnormal event is obtained. The actual distance from the event center to each boundary point is calculated. The coverage radius value is determined based on the standard deviation of the distance distribution. The geographic distance weight coefficient is adjusted by the ratio of the actual coverage radius to the preset coverage radius to obtain a revised spatial weight distribution. The revised spatial weight distribution is used to identify inter-regional capital transaction records. The capital inflow and outflow between each pair of regions are counted. The net capital flow ratio is calculated by dividing the outflow by the inflow. If the net capital flow ratio for a region pair is less than 1 and the abnormal propagation direction is outflow, it is marked as a propagation direction misjudgment. The correlation strength judgment standard for this region pair is corrected based on the inverse of the net capital flow ratio, resulting in a capital flow consistency correction parameter set. The correction values in the capital flow consistency correction parameter set are used to adjust the anomaly detection threshold of adjacent regions. The change rate of capital transaction volume caused by historical abnormal events in each region is extracted. The mean of the change rate is calculated as the response intensity coefficient. The impact radius boundary value is updated based on the product of the response intensity coefficient and the distance. A regional sensitivity distribution matrix is constructed, which includes region identifiers, response intensity coefficients, and impact radius boundary values. The sensitivity level is determined by sorting the response intensity coefficients of each region in the regional sensitivity distribution matrix. The time interval for the abnormal signal to be transmitted from the high-sensitivity level to the low-sensitivity level is counted, and a delay feature vector containing the transmission time between levels is established. The diffusion position at the next moment is predicted based on the current abnormal position and the delay feature vector through the Markov chain. The transmission path is confirmed to be valid when the predicted diffusion direction is consistent with the net capital flow direction on the path.
[0078] Specifically, in the scenario of monitoring abnormal financial events, obtaining a set of geographical boundary coordinates of the actual impact is the key to accurately assessing the scope of the event impact.
[0079] Specifically, when a large, unusual transaction occurs at a bank branch, the system records the coordinates of all affected branches in its vicinity. By calculating the actual distances from the branch where the unusual transaction occurred to each affected branch, such as 2 kilometers for the nearest branch and 15 kilometers for the farthest, the standard deviation of these distance data reflects the dispersion of the affected area. When the standard deviation is 4.5 kilometers, the coverage radius is determined as the average distance plus the standard deviation: 8.5 kilometers plus 4.5 kilometers equals 13 kilometers. The original default coverage radius was 10 kilometers, and the ratio of 1.3 between the actual and default values becomes the adjustment factor for the geographic distance weight, making the weight distribution more consistent with actual transmission characteristics. This revised spatial weight distribution directly impacts the accuracy of capital flow analysis.
[0080] In one possible implementation, the system extracts historical transaction data between each pair of network points, and calculates that the amount of fund flowing from network point A to network point B is 5 million yuan, and the amount of fund flowing from network point B to network point A is 3 million yuan, and the net flow ratio is 0.6. When the abnormal event is transmitted from A to B, but the fund mainly flows from B to A, this reverse flow indicates that the transmission direction is misjudged. By correcting the correlation strength by the reciprocal of the net flow ratio 1.67, the abnormal transmission weight from B to A is higher than that from A to B, forming a more accurate fund flow consistency correction parameter set.
[0081] It should be noted that the application of these correction parameter sets significantly improves the accuracy of anomaly detection. The correction value 1.67 means that the detection threshold of network point B to network point A anomaly is adjusted from the original 1 million yuan to 1.67 million yuan, improving the detection specificity. Historical data shows that when similar anomalies occur, the daily transaction volume of surrounding network points increases by an average of 35%, and this growth rate is the response strength coefficient. The product of the response strength coefficient 0.35 and the distance 5 kilometers is 1.75 kilometers, which determines the boundary value of the influence radius at this distance, and constructs a complete sensitivity distribution matrix containing network point number, response strength and influence boundary.
[0082] Preferably, the hierarchical division based on the sensitivity distribution matrix provides the basis for time series prediction. Network points with a response strength coefficient greater than 0.3 are classified into a high sensitivity level, between 0.1 and 0.3 into a medium sensitivity level, and less than 0.1 into a low sensitivity level. Statistics show that it takes an average of 2 hours for an anomaly to transmit from a high sensitivity network point to a medium sensitivity network point, and 4 hours from a medium sensitivity network point to a low sensitivity network point, and these time intervals constitute the delay feature vector. The Markov chain predicts that the next time the anomaly will occur in the medium sensitivity network point B according to the current anomaly state in the high sensitivity network point A and the 2-hour delay feature. When the predicted path A to B is consistent with the direction of the net fund flow on this path, the effectiveness of this transmission path is confirmed, and the accurate matching of the transmission direction and the actual fund flow direction is achieved.
[0083] The above embodiments are only used to illustrate the technical solutions of the present application and not to limit, and the present application has been described in detail only with reference to the preferred embodiments. Those skilled in the art should understand that the technical solutions of the present application can be modified or replaced equivalently without departing from the spirit and scope of the technical solutions of the present application, and all should be covered in the scope of the claims of the present application.
Claims
1. A method for analyzing mobile payment transaction behavior based on spatial data, characterized in that: The method comprises: The time series data of transaction amounts in different geographical areas are obtained and feature extraction is performed to form a set of transaction amount fluctuation features. Spatial autocorrelation analysis is used on the fluctuation feature set to obtain the spatial correlation between regions. Based on the geographical radiation range and transaction type distribution, a spatial dependency network is constructed to obtain the spatial distribution characteristics of the transaction amount peak and determine the spatial dependency intensity distribution. Based on the spatial dependency intensity distribution, the transmission law of the transaction amount in the time dimension is analyzed, and the transmission direction and transmission speed characteristics are extracted. The transmission path and intensity are evaluated according to the transaction correlation strength and geographical distance between regions. The fluctuation cycle and the sensitivity of the adjacent regions are obtained in combination with the behavior pattern of the transaction subjects. According to the fluctuation cycle and the sensitivity of the adjacent regions, The weight values of spatiotemporal heterogeneity are corrected according to the spatiotemporal variation characteristics of inter-regional transaction intensity to determine the adaptive spatial weight matrix. A threshold analysis is performed on the adaptive spatial weight matrix to obtain the criteria for distinguishing abnormal fluctuations between regions. Anomalies are identified by comparing the deviation between actual transaction amounts and expected values, and a set of potential abnormal regions is obtained. The historical distribution pattern of transaction data in the set of potential abnormal regions is obtained, and the degree of deviation between the current fluctuation amplitude and the historical pattern is analyzed to determine the authenticity of the abnormal signal and determine the list of abnormal events. The degree of diffusion of the impact of abnormal events on surrounding areas is calculated to obtain the degree of variance expansion. The anomaly detection parameters are adjusted according to the abnormal event list, the detection rules are optimized, and the spatial dependency network is determined.
2. The method for analyzing mobile payment transaction behavior based on spatial data according to claim 1, characterized in that: The method of obtaining time series data of transaction amounts in different geographical areas and performing feature extraction to form a transaction amount fluctuation feature set includes: The time series data of transaction amounts in different geographical areas are segmented, the total transaction amount and the number of transactions in each time period are calculated, the local maximum of the transaction amount is identified as the transaction amount peak, the time point and amount value of the transaction amount peak are recorded, the ratio of the difference in transaction amounts between adjacent time periods to the time interval is calculated as the rising rate, and time series feature data including the transaction amount peak, the rising rate and the transaction frequency are generated; based on the time series feature data, a transaction activity index is constructed, and the transaction activity index is based on the product of the transaction frequency and the rising rate, and the time period in which the transaction activity index exceeds the threshold is screened, and the distribution and duration of high-activity transaction periods in each geographical area are counted; the transaction location coordinates and transaction type information in the high-activity transaction period are extracted, and the transaction-intensive area is determined by using a density clustering algorithm, the geometric center of the intensive area and the maximum distance from the transaction location to the center are calculated as the geographical radiation range, and the proportion of the number of transaction types is counted; combined with the geographical radiation range, the proportion of the number of transaction types and the distribution of transaction active periods, a transaction amount fluctuation feature set is formed.
3. The method for analyzing mobile payment transaction behavior based on spatial data according to claim 1, characterized in that: The spatial autocorrelation analysis of the fluctuation feature set is used to obtain the spatial correlation between regions, and a spatial dependency network is constructed based on the geographical radiation range and transaction type distribution, including: Calculate the correlation coefficient between the peak transaction amount of each region and the peak value of the adjacent region in the fluctuation feature set, construct a spatial weight matrix based on the inverse of the actual distance between regions, calculate the global and local spatial autocorrelation values in combination with the spatial weight matrix, and generate the spatial correlation between regions; based on the spatial correlation between regions and the proportion of overlapping area of the geographic radiation range, determine the weight of the connecting edges between regions and construct a spatial dependency network.
4. The method for analyzing mobile payment transaction behavior based on spatial data according to claim 1, characterized in that: The above mentioned method analyzes the transmission pattern of transaction amount in the time dimension based on the spatial dependence intensity distribution and extracts the transmission direction and transmission speed characteristics, including: Extract the transaction amount change sequence of each area pair in the spatial dependence intensity distribution, calculate the correlation coefficient sequence between the transaction amount change rate of the source area and the transaction amount change rate of the target area, determine the transmission direction and transmission time based on the correlation coefficient sequence, and calculate the ratio of the geographical distance to the transmission time as the transmission speed feature.
5. The method for analyzing mobile payment transaction behavior based on spatial data according to claim 1, characterized in that: The transmission path and intensity are evaluated based on the transaction correlation strength and geographical distance between regions, and the fluctuation cycle and sensitivity of neighboring regions are obtained by combining the behavior patterns of transaction entities, including: Based on the transaction correlation strength and geographical distance between the regions, the propagation path evaluation value is calculated, the path with the evaluation value exceeding the threshold is screened as the main propagation path, the intensity attenuation ratio on the main propagation path is calculated, and the propagation intensity value is determined; the transaction amount time series of the area involved in the main propagation path is extracted, the frequency component of the time series is decomposed, and the inverse of the main frequency is determined as the fluctuation period; the ratio of the change amplitude of the transaction amount in the target area to the change amplitude in the source area is calculated, and combined with the response delay time, the sensitivity of the adjacent area is generated.
6. The method for analyzing mobile payment transaction behavior based on spatial data according to claim 1, characterized in that: The method of correcting the weight value of spatiotemporal heterogeneity according to the fluctuation cycle and the sensitivity of adjacent regions and the spatiotemporal variation characteristics of inter-regional transaction intensity to determine the adaptive spatial weight matrix includes: The original weight values of each regional pair are extracted, the difference in the fluctuation period is calculated, and the weight values are adjusted based on the fluctuation period difference and the sensitivity of the adjacent regions to generate an intermediate weight matrix; the temporal heterogeneity index and spatial heterogeneity index of the regional pair transaction intensity series in the intermediate weight matrix are calculated, and a stability correction factor is generated based on the two indicators. The intermediate weight matrix is adjusted to generate the adaptive spatial weight matrix.
7. The method for analyzing mobile payment transaction behavior based on spatial data according to claim 1, characterized in that: The threshold analysis of the adaptive spatial weight matrix is performed to obtain the criteria for distinguishing abnormal fluctuations between regions. By comparing the deviation between actual transaction amounts and expected values, abnormal points are identified to obtain a set of potential abnormal regions, including: Calculate the mean and standard deviation of the weight values in the adaptive spatial weight matrix, determine a high weight threshold, screen regional pairs whose weight values exceed the high weight threshold, and count the mean and standard deviation of the historical transaction amount fluctuations in the regional pairs whose weight values exceed the high weight threshold to generate an abnormal fluctuation discrimination standard; based on the abnormal fluctuation discrimination standard, calculate the relative deviation between the actual transaction amount of each region and the weighted expected value, mark the regions that exceed the threshold, and generate the potential abnormal region set.
8. The method for analyzing mobile payment transaction behavior based on spatial data according to claim 1, characterized in that: The process of obtaining the historical distribution pattern of the transaction data of the potential abnormal area, analyzing the deviation between the current fluctuation range and the historical pattern, judging the authenticity of the abnormal signal, and determining the abnormal event list includes: The frequency distribution of historical transaction amounts in each area of the potential abnormal area set is counted, a probability density function is fitted, a normal transaction range is determined, the probability of the current transaction amount deviating from the normal transaction range is calculated, and a standardized deviation value is generated; based on the standardized deviation value, the abnormality duration and the impact range, an abnormality authenticity judgment index is constructed, and areas where the index exceeds the threshold are screened to generate the abnormal event list.
9. The method for analyzing mobile payment transaction behavior based on spatial data according to claim 1, characterized in that: The calculation of the diffusion degree of the impact of the abnormal event on the surrounding area to obtain the variance expansion degree, adjusting the abnormality detection parameters according to the abnormal event list, optimizing the detection rules, and determining the spatial dependency relationship network includes: The geographic coordinates and intensity values of the abnormal events in the abnormal event list are obtained, and the impact intensity distribution is calculated based on the inverse distance and the Gaussian kernel function to generate an initial impact diffusion matrix; the variance of the impact intensity values in the initial impact diffusion matrix is calculated, and the spatial range parameters and sensitivity thresholds of the anomaly detection are adjusted based on the variance values to generate an updated anomaly detection rule set; based on the updated anomaly detection rule set, the sensitivity weights of the adjacent areas are adjusted, the adaptive spatial weight matrix is updated, and the final spatial dependency network is determined.
10. The method for analyzing mobile payment transaction behavior based on spatial data according to claim 1, characterized in that: The method also includes: adjusting the geographical distance weight and correlation strength judgment criteria according to the actual coverage of the spread of abnormal events, correcting the deviation of capital flow and misjudgment of propagation direction, revising the response intensity and impact radius boundary of adjacent areas to abnormal signals, updating the sensitivity distribution level and transmission time delay characteristics between regions, and ensuring that the transmission direction matches the actual capital flow direction.
Citation Information
Patent Citations
Transaction data quality automatic analysis method based on artificial intelligence
CN118761843A
Abnormal transaction behavior detection method and system based on block chain
CN120197084A