A method and system for real-time fraud monitoring of financial transactions
By collecting user device interaction data and financial transaction data in real time, extracting the spectral feature vectors and entropy change indicators of operation curvature changes, and combining multi-scale pattern matching and spatiotemporal convolution fusion, the problem of insufficient deep correlation in financial fraud identification in existing technologies is solved, and accurate identification and real-time adaptation of complex fraud scenarios are achieved, thereby improving the security of financial transactions.
Patent Information
- Application Number
- CN202511119974.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-12
- Publication Date
- 2025-10-14
- Estimated Expiration
- 2045-08-12
AI Technical Summary
Existing technologies lack in-depth correlation analysis of operational behavior, capital flow and environmental information in financial fraud identification, making it difficult to cope with complex fraud scenarios. They cannot dynamically correlate the evolution of operational anomalies and financial risks, and the verification of environmental factors is insufficient, resulting in limited identification accuracy.
By collecting user device interaction data in real time, extracting the spectral feature vector of operation curvature change, combining account fund transaction data to calculate the entropy change index, performing multi-scale pattern matching and spatiotemporal convolution fusion, identifying multi-dimensional abnormal signals, and generating cross-scale risk warning instructions.
It achieves accurate identification and real-time adaptation of fraud risks, improves the ability to identify diverse fraud methods, provides a full-chain, multi-dimensional risk identification process, ensures that risk signals are not missed, and improves the security of financial transactions.
Smart Images

Figure CN120612087B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of financial security technology, and in particular relates to a real-time anti-fraud monitoring method and system for financial transactions. Background Art
[0002] With the rapid development of financial technology, online financial transactions have become the mainstream mode of transaction. However, the risks of financial fraud that accompany them are also becoming increasingly prominent. Fraudulent methods are becoming more diverse and covert, including remote control of device operation, impersonation of user behavior, and splitting funds for cross-regional transfers. To address these risks, the industry has developed risk identification technologies based on data mining and machine learning. By analyzing user transaction data, device operation records, and other information to build risk assessment models, the technology aims to detect and intercept fraudulent activities in advance and ensure the security of financial transactions.
[0003] Currently, financial fraud risk is primarily identified through two approaches: one is based on user device operation data, such as touch traces and click frequency, extracting operational characteristics and comparing them with historical normal behavior to identify abnormal operations; the other is based on account fund transaction data, such as transaction amount, frequency, and recipients, to analyze abnormal fund flows by constructing a fund network model. Some technologies combine these two types of data, but most of them simply superimpose features and lack in-depth correlation analysis between operational behavior, fund flows, and environmental information.
[0004] Existing technologies have fundamental limitations in overall solution design, making it difficult to address the core challenges of complex fraud scenarios: there is a lack of systematic characterization of risk characteristics, and the biometric characteristics of operational behavior, the network characteristics of capital flow, and the environmental characteristics of the equipment are not analyzed as an organic whole, resulting in insufficient ability to identify multi-dimensional collaborative fraud behaviors; there are gaps in the tracking of risk transmission paths, and it is impossible to dynamically correlate the evolution of operational anomalies and financial risks, making it difficult to capture the risk diffusion patterns from the operational level to the financial level; there is insufficient attention paid to the correlation between environmental factors and behavioral characteristics, and the verification role of the physical environment around the equipment in verifying the authenticity of the operation is ignored, resulting in limited accuracy in identifying remote theft and fraud in abnormal environments. Summary of the Invention
[0005] The purpose of the present invention is to provide a real-time anti-fraud monitoring method and system for financial transactions, aiming to solve the technical problems existing in the prior art identified in the background technology.
[0006] The present invention is implemented as follows: a real-time anti-fraud monitoring method for financial transactions, the method comprising:
[0007] Real-time collection of user device interaction data, including touch track coordinate sequence, pressure value sequence, three-axis acceleration data and interface operation event stream;
[0008] Extracting a spectral feature vector of the operation curvature change based on the touch trajectory coordinate sequence, and identifying a period of missing routine verification steps and a device silent state interval based on the three-axis acceleration data and the interface operation event stream;
[0009] Based on the operational curvature change spectrum feature vector and in combination with the real-time account fund transaction data, the local entropy growth rate caused by a single transaction and the spatial distribution of the fund network temperature gradient are dynamically calculated to generate an entropy change index;
[0010] Setting a curvature detection threshold based on the entropy change index, and using the adjusted curvature detection threshold to detect the spectral feature vector of the operation curvature change, performing multi-scale pattern matching on the silent state interval of the device, and obtaining device peripheral signal data based on the interface operation event stream;
[0011] The acquired device peripheral signal data is fused with the pressure value sequence through spatiotemporal convolution to perform stress testing.
[0012] The operation curvature change spectrum feature vector, entropy change index, and stress test results are subjected to spatiotemporal correlation analysis to identify multi-dimensional abnormal signals and generate cross-scale risk warning instructions.
[0013] As a further solution of the present invention, the identification of the period of absence of the conventional verification step and the device silent state interval specifically includes:
[0014] The touch trajectory coordinate sequence is smoothed and converted into a frequency domain signal. The amplitude, phase, and main frequency components of the curvature change in the 0-5 Hz frequency band are extracted to construct the spectral feature vector of the operation curvature change.
[0015] Compare the operation event sequence of the preset normal verification process, calculate the deviation between the interface operation event flow and the operation event sequence, mark the period where the deviation exceeds 30% and lasts for more than 10 seconds, and obtain the period where the regular verification step is missing;
[0016] The monitoring device has no interface operation events for 3 consecutive seconds, and the absolute values of the three-axis acceleration are all less than 0.02g. The start time, duration and last operation type before the end of the time interval are recorded to obtain the device silent state interval.
[0017] As a further solution of the present invention, the dynamic calculation of the local entropy growth rate and the spatial distribution of the capital network temperature gradient caused by a single transaction to generate an entropy change index specifically includes:
[0018] Based on the discreteness of the eigenvector of the operational curvature change spectrum, combined with the amount of a single transaction, the relevance of the transaction object, and the historical transaction frequency, the entropy change rate is calculated every 100ms to obtain a continuous local entropy growth rate curve.
[0019] The fund transaction network where the account is located is abstracted as a graph structure composed of nodes and edges, the transaction activity of the nodes and the weight of the edges are taken as parameters, the node activity index of each node is calculated through the heat conduction equation, a temperature gradient matrix with geographical area as the dimension is generated, and a spatial distribution of the fund network temperature gradient is obtained;
[0020] The peak value of the local entropy increase rate curve and the maximum change of the fund network temperature gradient are weighted and fused to obtain a quantization index of 0-10, and an entropy change index is generated.
[0021] As a further scheme of the application, the multi-scale pattern matching on the device silent state interval is specifically:
[0022] Taking the 95% quantile value corresponding operation curvature change spectrum feature vector amplitude as the initial threshold value based on the entropy change index distribution of historical normal transactions, and then dynamically adjusting the real-time entropy change index to set the curvature detection threshold value;
[0023] The device silent state interval is segmented by using time windows of 10s, 30s and 60s respectively, the device state features in each window after segmentation are extracted, cosine similarity matching is performed between the extracted features and the silent patterns in the historical sample library, the silent patterns refer to the feature patterns in the historical sample library that meet the device silent state interval, and the windows with a matching degree greater than 0.8 are recorded, and the multi-scale pattern matching on the device silent state interval is performed.
[0024] The time stamp of the interface operation event stream is used to trigger synchronous collection, the surrounding APs are scanned every 5s, the address and signal strength are recorded to form a WiFi signal strength matrix, the three-dimensional components are collected by the magnetometer every second, the fluctuation amplitude is calculated to obtain a geomagnetic field strength fluctuation sequence, and the light intensity distribution of the 400-700nm wave band is obtained by the photosensitive sensor to obtain ambient light spectrum data.
[0025] As a further scheme of the application, the stress test is specifically:
[0026] The WiFi signal strength matrix, the geomagnetic field strength fluctuation sequence, the ambient light spectrum data and the stress value sequence are taken as inputs, the spatio-temporal correlation features are extracted through three convolution layers, the fusion feature tensor is output, and spatio-temporal convolution fusion is performed.
[0027] Based on the entropy change index, three risk levels of low, medium and high are set, and the stress test results are obtained by simulating the fund path disturbance under the corresponding level.
[0028] As a further scheme of the application, the spatio-temporal correlation analysis is performed to identify multi-dimensional abnormal signals, and a cross-scale risk warning instruction is generated, which specifically includes:
[0029] Analyze the correlation between the operational curvature change spectrum feature vector, entropy change index, and stress test results in the time dimension, and analyze the spatial correlation between the stress test results and environmental spectral data;
[0030] Set the operational curvature change spectrum feature vector, the abnormal threshold of the entropy change index, and the abnormal threshold of the stress test result respectively, mark the abnormality of single indicators and the coordinated abnormality of multiple indicators, and identify multi-dimensional abnormal signals;
[0031] Basis: Single indicator abnormality is low risk, two indicator abnormalities are medium risk, and three indicator abnormalities are high risk. The severity of the abnormal signal is judged, and a cross-scale risk warning instruction is generated based on the severity.
[0032] Another object of the present invention is to provide a real-time anti-fraud monitoring system for financial transactions, the system comprising:
[0033] The real-time data acquisition module is used to collect user device interaction data in real time, including touch track coordinate sequence, pressure value sequence, three-axis acceleration data and interface operation event stream;
[0034] a curvature feature extraction module for extracting a characteristic vector of a frequency spectrum of an operation curvature change based on the touch trajectory coordinate sequence, and identifying periods of missing routine verification steps and periods of device silence based on the three-axis acceleration data and the interface operation event stream;
[0035] An entropy change index calculation module is used to dynamically calculate the local entropy growth rate and the temperature gradient spatial distribution of the capital network caused by a single transaction based on the operational curvature change spectrum feature vector and the real-time account capital transaction data to generate an entropy change index;
[0036] a curvature detection module, configured to set a curvature detection threshold based on an entropy change indicator, detect a spectral feature vector of an operation curvature change using the adjusted curvature detection threshold, perform multi-scale pattern matching on the device's silent state interval, and acquire device peripheral signal data based on an interface operation event stream;
[0037] The pressure value convolution fusion module is used to perform spatiotemporal convolution fusion of the acquired device peripheral signal data and the pressure value sequence to perform pressure testing;
[0038] The risk warning generation module is used to perform spatiotemporal correlation analysis on the operational curvature change spectrum feature vector, entropy change index, and stress test results, identify multi-dimensional abnormal signals, and generate cross-scale risk warning instructions.
[0039] The beneficial effects of the present invention are:
[0040] The application regards device operation behavior, fund network dynamics and physical environment characteristics as interrelated risk carriers instead of isolated analysis objects. From the data collection stage, multi-dimensional interaction information such as touch track, pressure change, device movement and operation event is covered, providing stereoscopic raw materials for subsequent analysis. This comprehensiveness ensures that risk signals will not be missed due to data loss. On this basis, by extracting the spectral features of operation curvature, micro-operation habits are converted into quantifiable biometric codes, and by combining verification process compliance and device silent mode analysis, an initial risk portrait is constructed from three aspects of how the operation is performed, whether it meets the specifications and whether the pause is abnormal. This multi-perspective feature extraction avoids the one-sidedness of a single behavior feature.
[0041] The scheme deeply binds operation characteristics and fund network dynamics, captures the immediate conduction of operation abnormalities to fund risks through local entropy increase rate, reflects the spatial diffusion trend of risks by means of fund network temperature gradient, and realizes the quantitative fusion of the two by means of entropy change index. This design enables risk assessment to anchor the operation source and track the systematic influence at the fund level, solving the problem of disconnection between operation and fund analysis in traditional technologies. The combination of dynamic threshold adjustment, multi-scale silent mode matching and environment signal collection enables risk detection to adapt to risk level changes in real time, and verifies the authenticity of risks through physical environment characteristics, effectively distinguishing between accidental operation errors and substantive fraudulent behaviors.
[0042] Through spatio-temporal correlation analysis to integrate multi-dimensional risk signals of operation, fund and environment, combined with multi-index collaborative anomaly recognition and graded early warning, the entire risk identification process forms a closed loop, from capturing subtle operation abnormalities, to verifying fund network fluctuations, to confirming risk scenarios combined with environmental characteristics, and finally outputting targeted disposal instructions. This overall idea of full-chain, multi-dimensional and dynamic nature not only improves the accuracy of fraud risk identification, but also adapts to the concealment and complexity of diversified fraudulent means, realizes the upgrade from passive defense to active early warning, and provides systematic protection for financial transaction security. BRIEF DESCRIPTION OF DRAWINGS
[0043] Figure 1 A flowchart of a financial transaction real-time anti-fraud monitoring method provided by an embodiment of the application;
[0044] Figure 2 A flowchart of identifying periods of missing regular verification steps and device silent state intervals provided by an embodiment of the application;
[0045] Figure 3 A flowchart of generating an entropy change index provided by an embodiment of the application;
[0046] Figure 4A flowchart of performing multi-scale pattern matching on the silent state interval of the device provided in an embodiment of the present invention;
[0047] Figure 5 A flowchart of performing a stress test according to an embodiment of the present invention;
[0048] Figure 6 A flowchart of generating cross-scale risk warning instructions provided by an embodiment of the present invention;
[0049] Figure 7 This is a structural block diagram of a real-time anti-fraud monitoring system for financial transactions provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0050] In order to make the purpose, technical solutions and advantages of the present invention more clearly understood, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention.
[0051] Figure 1 A flowchart of a real-time anti-fraud monitoring method for financial transactions provided by an embodiment of the present invention is shown in FIG. Figure 1 As shown, the method includes:
[0052] S100 collects user device interaction data in real time, including touch track coordinate sequence, pressure value sequence, three-axis acceleration data and interface operation event stream;
[0053] For the touch track coordinate sequence, a high-frequency sampling frequency of 200Hz is used to continuously record the X / Y coordinates on the device screen, generating a coordinate point every 5ms. The start and end timestamps of the track are also synchronously marked, and the screen area where the track is located is precisely demarcated. This high-frequency sampling design is designed to capture the subtle dynamic characteristics of user finger operations, including arc changes and speed fluctuations in natural sliding. These characteristics are often closely related to the user's physiological habits and are essential data for distinguishing genuine users from fraudsters.
[0054] The pressure value sequence is collected using the device's built-in capacitive pressure sensor, which captures the pressure applied to the screen in real time at a frequency of 100Hz. Each pressure value is then correlated with the rate of change of pressure at the corresponding coordinate point. This approach aims to fill in the information gaps in the coordinate trajectory through dynamic changes in the pressure dimension. While real users naturally adjust their pressure based on their intended operation, fraudulent activity often exhibits abnormal characteristics, such as uniform or sudden changes in pressure distribution. Recording the rate of change of pressure can further amplify these differences.
[0055] Three-axis acceleration data is collected using a MEMS accelerometer. A 50Hz sampling frequency ensures real-time capture of the device's motion while avoiding redundant data. High-frequency noise with an amplitude less than 0.05g is filtered out to ensure that only meaningful device motion information (such as slight shaking of the user holding the device or its stable state when placed on a desktop) is retained. This provides a basis for subsequent identification of the device's silent state interval. Without noise filtering, interference from environmental vibrations could lead to misjudgment of the device's static state, affecting the accuracy of silent mode matching.
[0056] The collection of interface operation event streams focuses on recording all details of user interaction behaviors on the interface, including operation types such as clicks, slides, and inputs, the control ID that triggers the operation, the duration of the operation, and the interval between two adjacent operations.
[0057] S200, extracting a characteristic vector of a frequency spectrum of an operation curvature change based on the touch trajectory coordinate sequence, and identifying a period of missing routine verification steps and a device silent state interval based on the three-axis acceleration data and the interface operation event stream;
[0058] When extracting the spectral feature vector of the operation curvature change, the touch trajectory coordinate sequence collected in S100 is first smoothed. This step filters out the high-frequency noise in the trajectory, making the trajectory curve closer to the actual operation intention and avoiding the interference of accidental fluctuations on feature extraction; then, the continuous coordinate points in the time domain are converted into frequency domain signals through Fourier transform, and the curvature change of the spatial trajectory is decomposed into components of different frequencies. The amplitude, phase and main frequency components of the 0-5Hz frequency band are extracted. This is because the natural frequency of human hand operations is usually in this range. Fraudulent behavior often manifests as spectral disorder or main frequency offset in this frequency band. The construction of a 128-dimensional feature vector is to systematize these spectral features and form a quantifiable operation biometric code, thereby realizing the implicit identification of the identity of the operating subject.
[0059] The process of identifying the period of missing routine verification steps is based on the preset normal verification process operation event sequence. This sequence is generated by analyzing the verification process of a large number of historical risk-free transactions, including the time sequence relationship of necessary steps such as SMS verification code input and fingerprint verification. The deviation of the real-time interface operation event stream from the benchmark sequence is calculated using the dynamic time warping (DTW) algorithm. It is used to solve the problem of inconsistent lengths of two sequences (for example, the normal process may be slightly longer due to network delay), and divided by Normalization eliminates the impact of sequence length differences, objectively reflecting the degree of deviation between real-time operations and standard processes. Marking periods of significant and persistent deviation aims to capture process shortcuts, a common phenomenon in fraudulent activity. To expedite operations, fraudsters often skip key verification steps. These deviations are not accidental fluctuations but rather signals of deliberate risk evasion. This process can identify such anomalies in real time during ongoing operations, providing early clues for risk warnings.
[0060] When identifying the device's silent state interval, the system monitors periods of 3 consecutive seconds without any interface operation events and with the absolute value of the three-axis acceleration less than 0.02g. The 3-second duration setting is sufficient to distinguish brief pauses in normal operation and capture abnormal silence with fraudulent characteristics. The three-axis acceleration threshold setting is used to eliminate interference caused by slight shaking of the device by the user, ensuring that the judgment of silence is based on the stable state of the device.
[0061] The start time, duration, and last operation type before the end of the recording interval are used to correlate the silent state with the preceding and following operations. Silence during normal use is often related to user decisions, while silence in fraudulent scenarios often accompanies preparations for abnormal operations. These details can be used to further distinguish the nature of the silence.
[0062] like Figure 2 As shown, the identification of the missing period of the conventional verification step and the device silent state interval specifically includes:
[0063] S210 , smoothing the touch trajectory coordinate sequence and converting it into a frequency domain signal, extracting the amplitude, phase, and main frequency component of the curvature change in the 0-5 Hz frequency band, and constructing a frequency spectrum feature vector of the operation curvature change;
[0064] S220, comparing the operation event sequence of the preset normal verification process, and calculating the deviation between the interface operation event flow and the operation event sequence:
[0065] ;
[0066] in, Represents the real-time collected interface operation event stream (including the event sequence of operation type, control ID, etc.), Represents the operational event sequence of the preset normal verification process (a standard event sequence extracted from historical risk-free transactions), is the dynamic time warping distance between the two sequences, and are the lengths of the two sequences respectively;
[0067] S230, marking the period when the deviation exceeds 30% and lasts for more than 10 seconds, and obtaining the period when the routine verification step is missing;
[0068] S240, monitoring the device for no interface operation event within 3s, and the absolute value of three-axis acceleration is less than 0.02g, recording the starting time, duration and last operation type before the end of the time interval, obtaining the device quiet state interval.
[0069] S300, based on the operation curvature change spectrum feature vector, combined with the real-time account transaction data, dynamically calculate the local entropy increase rate and the spatial distribution of the temperature gradient of the fund network generated by a single transaction, and generate the entropy change index;
[0070] Based on the dispersion of the operation curvature change spectrum feature vector extracted in S200, combined with the amount of a single transaction, the transaction object correlation degree and the historical transaction frequency, the entropy change rate is calculated every 100ms. The entropy here essentially reflects the degree of disorder of the operation characteristics. The operation habit of normal users is relatively stable, the curvature feature dispersion is low, and the entropy value changes slowly. Fraudulent behavior often accompanies the mutation of operation characteristics, resulting in a sharp increase in dispersion and an accelerated entropy increase rate. The key attributes of the transaction (amount, object, frequency) are included in the calculation in order to make the entropy increase rate not only reflect the operation itself, but also be associated with the risk level of the transaction, so that the local entropy increase rate can not only capture the operation anomaly, but also reflect the risk exposure of the transaction itself.
[0071] When constructing the spatial distribution of the temperature gradient of the fund network, the fund transaction network in which the account is located is first abstracted into a graph structure composed of nodes (accounts) and edges (transaction relationships). The purpose of this abstraction is to convert complex fund flow relationships into a calculable network model. The transaction activity of the node (the number of transactions in the past 24 hours, reflecting the activity level of the account) and the weight of the edge (the transaction amount ratio, reflecting the importance of the transaction) are used as parameters to calculate the node activity index of each node through the heat conduction equation. In essence, it simulates the heat propagation of fund flow: active nodes (high-frequency transaction accounts) will transfer activity to associated nodes like a heat source, while large transactions (high-weight edges) will accelerate this transfer.
[0072] Generating a temperature gradient matrix with geographical regions as dimensions is to associate this network activity with physical space, and reflect the flow trend of funds in different regions through gradient changes: under normal circumstances, the temperature gradient of the fund network presents a smooth distribution that matches economic activity; while fraudulent fund transfers often break this smoothness, forming abnormal regions with local temperature rising or gradient mutation.
[0073] When generating the entropy change index, the peak value of the local entropy increase rate curve and the maximum change of the capital network temperature gradient are weighted and fused to obtain a quantization index of 0-10. The logic of this fusion is that the local entropy increase rate reflects the immediate risk at the operation level, and the change of the capital network temperature gradient reflects the system risk at the capital flow level. The weighted combination of the two realizes the risk superposition of micro-operation abnormalities and macro-capital abnormalities.
[0074] The setting of the weight (the local entropy increase proportion is higher) reflects that operation abnormalities are the source of risk, and operation abnormalities often appear before capital abnormalities, which can early warn the risk. The abnormality of the capital network can verify whether the operation abnormality has been transformed into substantial capital risk. When the local entropy increase rate reaches the peak value due to operation abnormality, if the change of the capital network temperature gradient is small, it may be only an operation failure or temporary interference; but if both of them are significantly increased, it is probably a risk transmission caused by fraud. At this time, the entropy change index will jump to a higher level, providing a clear quantitative basis for subsequent risk judgment.
[0075] As shown in Figure 3 , the dynamic calculation of the local entropy increase rate and the spatial distribution of the capital network temperature gradient caused by a single transaction generates an entropy change index, specifically including:
[0076] S310, based on the dispersion of the operation curvature change frequency spectrum feature vector, combined with the amount of a single transaction, the transaction object correlation degree and the historical transaction frequency, the entropy change rate is calculated every 100ms to obtain a continuous local entropy increase rate curve:
[0077] ;
[0078] wherein, is the information entropy at the moment, , , is the probability density of the th component of the operation curvature change frequency spectrum feature vector (obtained by normalization processing of the feature vector), is the sampling interval, reflecting the change rate of the operation feature dispersion every 100ms, which indirectly reflects the stability of the transaction behavior.
[0079] S320, the capital transaction network in which the account is located is abstracted as a graph structure composed of nodes and edges, taking the transaction activity of the node and the weight of the edge as the parameters, and the node activity index of each node is calculated by the heat conduction equation:
[0080] ;
[0081] wherein, is the activity index of the th account node, is the weight coefficient, take 0.6, It is The number of transactions per account node in the past 24 hours, is the maximum number of transactions per node in the network, It is with The set of edges connecting account nodes, It's the edge The transaction amount, It is the total amount of all transactions in the network.
[0082] Generate a temperature gradient matrix with geographic area as the dimension:
[0083] ;
[0084] in, For geographic coordinates The temperature gradient vector at The geographic coordinates obtained by spatial interpolation The activity index, and The activity change rates in the east-west and north-south directions are shown. The matrix dimensions are consistent with the geographic partitioning accuracy.
[0085] Obtain the spatial distribution of temperature gradient of capital network;
[0086] S330, weighted fusion is performed on the peak value of the local entropy growth rate curve and the maximum change in the capital network temperature gradient to obtain a quantitative index of 0-10, generating an entropy change index:
[0087] ;
[0088] in, is the entropy change index (range 0-10), is the peak value of the local entropy growth rate curve, is the peak value of the maximum entropy growth rate in historical data, is the maximum change in the temperature gradient of the capital network, It is the reference gradient change (taken as the historical 95% percentile value). The entropy change characteristics of the two dimensions are integrated into a unified indicator through weighted normalization.
[0089] S400: Setting a curvature detection threshold based on an entropy change indicator, detecting a frequency spectrum feature vector of an operation curvature change using the adjusted curvature detection threshold, performing multi-scale pattern matching on the device's silent state interval, and acquiring device peripheral signal data based on an interface operation event stream.
[0090] The operation curvature change frequency spectrum feature vector amplitude corresponding to the 95% quantile value of the historical normal transaction entropy change index distribution is selected as the initial threshold. The selection of this benchmark aims to anchor the feature boundary of most normal operations and ensure that the initial threshold can effectively filter normal fluctuations without missing potential risks due to being too loose. The threshold is dynamically adjusted based on real-time entropy change indicators, and the core purpose is to make the detection sensitivity dynamically change with the risk level. When the entropy change indicator shows high transaction risk, lowering the threshold can more sensitively capture subtle curvature anomalies, avoiding missed judgments in high-risk scenarios. When the risk is low, a higher threshold can reduce the probability of normal operations being misjudged as abnormal. This dynamic adjustment mechanism makes the detection process more consistent with real-time risk situations.
[0091] When performing multi-scale pattern matching on the device silent state interval, the interval is divided into three time windows of 10s, 30s, and 60s. This multi-scale design is derived from the duration difference of silent behavior in different fraud scenarios: in remote control fraud, the gap between control instruction transmissions may exhibit a short silence of 10-30s; in gang fraud, waiting for partner instructions may result in a longer silence of more than 60s. Through multi-scale windows, we can comprehensively cover silent features of different lengths and avoid feature omission due to a single window scale.
[0092] After extracting the device state features in each window, cosine similarity matching is performed with the silent patterns in the historical sample library, which contains typical features of device silent periods in known fraud cases. Cosine similarity quantifies the vector angle between real-time features and sample features to objectively judge their similarity. Windows with a matching degree exceeding 0.8 are recorded, aiming to select abnormal silent intervals similar to known fraud patterns and provide behavior pattern-based evidence for risk judgment.
[0093] The timestamp synchronization triggers the collection of interface operation event streams. This time synchronization mechanism ensures the time sequence correlation between signal data and operation behavior, allowing subsequent analysis to correspond environmental features and operation features in the time dimension. Specifically, a WiFi signal strength matrix is scanned every 5s to reflect the network environment in which the device is located. The geomagnetic field strength fluctuation sequence is collected every second to capture subtle changes in the device's physical location (whether it is at a fixed location). The 400-700nm band of environmental light spectrum data can assist in determining the light environment in which the device is located, whether it can recognize faces, etc. These signal data can provide physical environmental features of the device, cross-verify with operation features and silent patterns, and normal operations are usually accompanied by stable environmental signals, while fraudulent behavior often causes significant changes in the surrounding signals, thereby adding environmental dimension verification for risk identification.
[0094] As Figure 4As shown, performing multi-scale pattern matching on the silent state interval of the device specifically includes:
[0095] S410, using the entropy change index distribution of historical normal transactions as a benchmark, taking the amplitude of the operational curvature change spectrum feature vector corresponding to the 95th percentile value as the initial threshold, and then dynamically adjusting it according to the real-time entropy change index to set the curvature detection threshold;
[0096] S420: Segment the device silence interval using 10s, 30s, and 60s time windows, extract device status features within each segmented window, and perform cosine similarity matching with silence patterns in the historical sample library. A silence pattern is a characteristic pattern that appears in the historical sample library and corresponds to the device silence interval. Window windows with a matching degree exceeding 0.8 are recorded, and multi-scale pattern matching is performed on the device silence interval.
[0097] S430, based on the timestamp synchronization trigger collection of the interface operation event stream, scans the surrounding APs every 5 seconds, records the addresses and signal strengths to form a WiFi signal strength matrix; uses the magnetometer to collect three-dimensional components once a second, calculates the fluctuation amplitude, and obtains the geomagnetic field intensity fluctuation sequence; uses the photosensor to obtain the light intensity distribution in the 400-700nm band and obtains the ambient light spectrum data.
[0098] S500: Perform spatiotemporal convolution fusion of the acquired device peripheral signal data and the pressure value sequence to perform a pressure test;
[0099] The WiFi signal strength matrix acquired in S400, the geomagnetic field intensity fluctuation sequence, the ambient light spectrum data, and the pressure value sequence collected in S100 are combined as inputs for feature extraction through three convolutional layers. The WiFi signal strength matrix reflects the device's network environment, the geomagnetic field intensity fluctuation sequence implies changes in the device's physical location, the ambient light spectrum data reflects the characteristics of the lighting environment, and the pressure value sequence records the changes in force during operation.
[0100] These four types of data belong to different dimensions: network environment, physical space, lighting conditions, and operating force. It's difficult to capture their correlations when analyzed individually. The 3D convolutional layer, however, uses a sliding window to extract the co-variation characteristics of these different data across time and space. When a normal user operates in a typical environment, the WiFi signal is stable, the geomagnetic field fluctuates slightly, the ambient light matches the operating time period, and the pressure value varies regularly with the type of operation. These features, after convolutional fusion, form a stable feature tensor. In fraud scenarios, however, unfamiliar WiFi signals, sudden changes in the geomagnetic field (the device has been moved), ambient light inconsistent with the typical time period, and erratic pressure changes may occur. The fused feature tensor will exhibit significant anomalies. This fusion design aims to break down data silos and integrate dispersed environmental and operating features into comprehensive features that reflect the reality of the scenario, providing more comprehensive input for subsequent risk simulations.
[0101] During stress testing, the system first categorizes transactions into three risk levels: low, medium, and high, based on the entropy change index generated by the S300. This categorization relies on the entropy change index's quantitative assessment of current transaction risk, aligning the intensity of the stress test with the actual risk landscape. A low entropy change index indicates a low risk level, resulting in less simulated disturbances in the simulated funds flow. A high entropy change index indicates a high risk level, resulting in more complex disturbances. Specifically, the low risk level simulates abnormal single transaction amounts, the medium risk level simulates abnormal cross-regional transfer frequencies, and the high risk level simulates chained transfers across multiple accounts. These simulations are based on common fund operation patterns seen in real fraud cases. By perturbing the funds flow, the system observes changes in the correlation between the fused feature tensor and the fund flow pattern, ultimately generating stress test results. The core purpose of this system is to proactively simulate risk scenarios, verifying the abnormal behavior of current transactions under different risk stresses, and determining whether they exhibit typical characteristics of fraudulent activity. While legitimate transactions typically exhibit robust resistance to disturbances during stress testing, fraudulent transactions exhibit significant abnormal responses under specific risk scenarios.
[0102] like Figure 5 As shown, the execution of the stress test specifically includes:
[0103] S510 takes the WiFi signal strength matrix, the geomagnetic field intensity fluctuation sequence, the ambient light spectrum data, and the pressure value sequence as input, extracts spatiotemporal correlation features through three convolutional layers, and outputs a fused feature tensor for spatiotemporal convolution fusion.
[0104] S520 sets three risk levels (low, medium, and high) based on the entropy change indicator, simulates the capital path disturbance under the corresponding levels, and executes to obtain the stress test results:
[0105] ;
[0106] in, is the result of stress test (risk score, range 0-10), is the weight coefficient, taking 0.5, is the similarity of the simulated trading path with the historical normal path (through path edit distance normalization), is the Euclidean distance of the fusion feature tensor with the benchmark feature tensor (through maximum distance normalization). The path deviation degree and the feature abnormality degree are integrated to quantify the trading risk under different risk levels.
[0107] S600, spatiotemporal correlation analysis is performed on the operation curvature change frequency spectrum feature vector, the entropy change index, and the result of the stress test to identify multi-dimensional abnormal signals and generate a cross-scale risk warning instruction.
[0108] The operation curvature change frequency spectrum feature vector, the entropy change index, and the stress test result are mined through a time-series correlation rule algorithm to find the internal relationship in the time dimension. The time sequence relationship between the sudden rise of the entropy change index and the operation curvature abnormality, or the synchronization of the stress test result abnormality with the former two, can capture the transmission path of the risk signal.
[0109] In normal trading, the fluctuations of each indicator are often independent and smooth, while in fraudulent behavior, operation abnormalities often precede changes in financial risk indicators, forming a traceable time sequence chain. At the same time, the spatial correlation between the stress test result and the environmental spectrum data is analyzed through spatial clustering (such as DBSCAN), for example, to determine whether high-risk stress test results are concentrated in a specific WiFi environment or geomagnetic field area. This spatial correlation can verify whether the risk is bound to an abnormal environment and avoid misjudging isolated indicator fluctuations as systematic risks. This two-dimensional analysis design breaks through the limitations of single-dimensional analysis, both tracking the temporal evolution of risks and locating the spatial distribution of risks, providing a three-dimensional analysis framework for anomaly recognition.
[0110] When identifying multi-dimensional abnormal signals, abnormal threshold values need to be set for the operation curvature change frequency spectrum feature vector, the entropy change index, and the stress test result. These threshold values are not fixed numbers, but are dynamically adjusted based on the feature distribution of historical normal transactions and risk tolerance.
[0111] The threshold for the operational curvature feature must be able to distinguish between natural operational fluctuations and deliberately simulated abnormal trajectories. The threshold for the entropy change indicator must reflect the degree of coordinated disorder between the capital network and the operational characteristics. The threshold for the stress test results must correspond to the tolerance for path perturbations at different risk levels. While flagging single-indicator anomalies can capture localized risk points, flagging coordinated anomalies across multiple indicators can identify systemic risks. This design aims to avoid misjudgments caused by single-indicator anomalies while improving the reliability of risk identification through multi-indicator collaborative verification.
[0112] In normal transactions, abnormal operation curvature may occur due to temporary operational inexperience, but the entropy change indicator and stress test results are stable. In this case, only a single indicator is marked as abnormal. In fraud scenarios, there is often a coordinated phenomenon of abnormal operation curvature, a sudden increase in entropy change indicators, and disordered stress test results. Multi-indicator abnormality marking can accurately capture this systemic risk.
[0113] When generating cross-scale risk warning instructions, the severity of the abnormal signal must be graded: a single-indicator abnormality corresponds to low risk, two-indicator abnormalities correspond to medium risk, and three-indicator abnormalities correspond to high risk. This grading is not a simple summation of numbers, but rather is based on the weight of each indicator in risk transmission. Operational curvature abnormalities reflect source operational risk, entropy change indicators reflect financial network risk, and stress test results reflect scenario resistance risk. The superposition of multiple-indicator abnormalities means that the risk has spread from the local level to the system level. The instruction content must include the abnormality type, the time period of occurrence, the characteristics of the associated equipment, and the disposal recommendations (such as suspending trading and triggering secondary verification). Its purpose is to provide risk control personnel or systems with specific and executable response plans, achieving a closed loop from risk identification to risk disposal.
[0114] Specifically: For low-risk warnings, only enhanced monitoring is prompted; for medium-risk warnings, additional verification (face recognition) is required; for high-risk warnings, transactions are directly suspended and security checks are triggered. This graded response can effectively prevent and control risks while reducing interference with normal transactions.
[0115] like Figure 6 As shown, the spatiotemporal correlation analysis is performed to identify multi-dimensional abnormal signals and generate cross-scale risk warning instructions, specifically including:
[0116] S610, analyzing the correlation between the operational curvature change spectrum feature vector, the entropy change index, and the stress test result in the time dimension, and simultaneously analyzing the spatial correlation between the stress test result and the environmental spectrum data;
[0117] S620: Set the operational curvature change spectrum feature vector, the abnormal threshold of the entropy change index, and the abnormal threshold of the stress test result, mark single-indicator abnormalities and multi-indicator coordinated abnormalities, and identify multi-dimensional abnormal signals;
[0118] S630, based on: single indicator abnormality is low risk, two indicator abnormalities are medium risk, and three indicator abnormalities are high risk, judge the severity of the abnormal signal and generate a cross-scale risk warning instruction based on the severity.
[0119] Figure 7 A structural block diagram of a real-time anti-fraud monitoring system for financial transactions provided by an embodiment of the present invention is shown in FIG. Figure 7 As shown, the system includes:
[0120] The real-time data acquisition module 100 is used to collect user device interaction data in real time, including touch track coordinate sequence, pressure value sequence, three-axis acceleration data and interface operation event stream;
[0121] The curvature feature extraction module 200 is used to extract the spectral feature vector of the operation curvature change based on the touch trajectory coordinate sequence, and to identify the period of missing routine verification steps and the device silent state interval based on the three-axis acceleration data and the interface operation event stream;
[0122] An entropy change index calculation module 300 is configured to dynamically calculate the local entropy growth rate and the temperature gradient spatial distribution of the capital network caused by a single transaction based on the operational curvature change spectrum feature vector and in combination with the account fund transaction data acquired in real time, thereby generating an entropy change index;
[0123] a curvature detection module 400 configured to set a curvature detection threshold based on an entropy change indicator, detect a spectral feature vector of an operation curvature change using the adjusted curvature detection threshold, perform multi-scale pattern matching on the device's silent state interval, and acquire device peripheral signal data based on an interface operation event stream;
[0124] The pressure value convolution fusion module 500 is used to perform spatiotemporal convolution fusion on the acquired device peripheral signal data and the pressure value sequence to perform pressure testing;
[0125] The risk warning generation module 600 is used to perform spatiotemporal correlation analysis on the operational curvature change spectrum feature vector, entropy change index, and stress test results, identify multi-dimensional abnormal signals, and generate cross-scale risk warning instructions.
[0126] The technical features of the above-mentioned embodiments can be combined arbitrarily. In order to make the description concise, not all possible combinations of the technical features in the above-mentioned embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0127] The above embodiments only express several implementation manners of the present application, which are described in a more specific and detailed manner, but should not be understood as a limitation on the patent scope of the present application. It should be noted that, for ordinary skilled persons in the art, several modifications and improvements can be made without departing from the concept of the present application, which are all within the protection scope of the present application. Therefore, the protection scope of the patent of the present application should be subject to the appended claims.
[0128] The above merely describes the preferred embodiments of the present application and should not be used to limit the present application. Any modification, equivalent replacement and improvement made within the spirit and principle of the present application should be included in the protection scope of the present application.
Claims
1. A real-time anti-fraud monitoring method for financial transactions, characterized in that: The method comprises: Real-time collection of user device interaction data, including touch track coordinate sequence, pressure value sequence, three-axis acceleration data and interface operation event stream; Extracting a spectral feature vector of the operation curvature change based on the touch trajectory coordinate sequence, and identifying a period of missing routine verification steps and a device silent state interval based on the three-axis acceleration data and the interface operation event stream; Based on the operational curvature change spectrum feature vector and in combination with the real-time account fund transaction data, the local entropy growth rate caused by a single transaction and the spatial distribution of the fund network temperature gradient are dynamically calculated to generate an entropy change index; Setting a curvature detection threshold based on the entropy change index, and using the adjusted curvature detection threshold to detect the spectral feature vector of the operation curvature change, performing multi-scale pattern matching on the silent state interval of the device, and obtaining device peripheral signal data based on the interface operation event stream; The acquired device peripheral signal data is fused with the pressure value sequence through spatiotemporal convolution to perform stress testing. Performing spatiotemporal correlation analysis on the operational curvature change spectrum feature vector, entropy change index, and stress test results to identify multi-dimensional abnormal signals and generate cross-scale risk warning instructions; The identification of the period of missing routine verification steps and the device silent state period specifically includes: The touch trajectory coordinate sequence is smoothed and converted into a frequency domain signal. The amplitude, phase, and main frequency components of the curvature change in the 0-5 Hz frequency band are extracted to construct the spectral feature vector of the operation curvature change. Compare the operation event sequence of the preset normal verification process, calculate the deviation between the interface operation event flow and the operation event sequence, mark the period where the deviation exceeds 30% and lasts for more than 10 seconds, and obtain the period where the regular verification step is missing; The monitoring device has no interface operation events for 3 consecutive seconds, and the absolute values of the three-axis acceleration are all less than 0.02g. The start time, duration and last operation type before the end of the time interval are recorded to obtain the device silent state interval; The performing multi-scale pattern matching on the silent state interval of the device specifically includes: Based on the entropy change index distribution of historical normal transactions, the amplitude of the operational curvature change spectrum feature vector corresponding to the 95% percentile value is taken as the initial threshold. Then, it is dynamically adjusted according to the real-time entropy change index to set the curvature detection threshold. The device silence interval is segmented using 10s, 30s, and 60s time windows. The device status features within each segmented window are extracted and matched against the silence patterns in the historical sample library using cosine similarity. The silence patterns are characteristic patterns that appear in the historical sample library and match the device silence interval. Windows with a matching degree exceeding 0.8 are recorded, and multi-scale pattern matching is performed on the device silence interval. The system triggers acquisition based on the timestamp synchronization of the interface operation event stream, scans surrounding APs every 5 seconds, and records the addresses and signal strengths to form a WiFi signal strength matrix. A magnetometer collects three-dimensional components once a second, calculates the fluctuation amplitude, and obtains the geomagnetic field intensity fluctuation sequence. A photosensor acquires the light intensity distribution in the 400-700nm band and obtains ambient light spectrum data. The execution of the stress test specifically includes: The WiFi signal strength matrix, geomagnetic field intensity fluctuation sequence, ambient light spectrum data, and pressure value sequence are used as input. Three convolutional layers are used to extract spatiotemporal correlation features. The fused feature tensor is output and then spatiotemporal convolution fusion is performed. Based on the entropy change indicator, we set three risk levels: low, medium, and high. We simulated the disturbance of the capital path under the corresponding levels and executed them to obtain the stress test results. The above-mentioned spatiotemporal correlation analysis, identification of multi-dimensional abnormal signals, and generation of cross-scale risk warning instructions specifically include: Analyze the correlation between the operational curvature change spectrum feature vector, entropy change index, and stress test results in the time dimension, and analyze the spatial correlation between the stress test results and environmental spectral data; Set the operational curvature change spectrum feature vector, the abnormal threshold of the entropy change index, and the abnormal threshold of the stress test result respectively, mark single indicator abnormalities and multi-indicator coordinated abnormalities, and identify multi-dimensional abnormal signals; Basis: Single indicator abnormality is low risk, two indicator abnormalities are medium risk, and three indicator abnormalities are high risk. The severity of the abnormal signal is judged, and a cross-scale risk warning instruction is generated based on the severity.
2. The method according to claim 1, characterized in that The dynamic calculation of the local entropy growth rate and the temperature gradient spatial distribution of the capital network caused by a single transaction generates an entropy change index, specifically including: Based on the discreteness of the eigenvector of the operational curvature change spectrum, combined with the amount of a single transaction, the relevance of the transaction object, and the historical transaction frequency, the entropy change rate is calculated every 100ms to obtain a continuous local entropy growth rate curve. The capital transaction network where the account resides is abstracted into a graph structure consisting of nodes and edges. Using the node transaction activity and edge weight as parameters, the node activity index of each node is calculated using the heat conduction equation. This generates a temperature gradient matrix with geographical regions as the dimension, and the spatial distribution of the temperature gradient of the capital network is obtained. The peak value of the local entropy growth rate curve and the maximum change in the temperature gradient of the capital network are weighted and fused to obtain a quantitative index of 0-10 to generate an entropy change index.
3. The method according to claim 1, characterized in that The system for implementing the real-time anti-fraud monitoring method for financial transactions includes: The real-time data acquisition module is used to collect user device interaction data in real time, including touch track coordinate sequence, pressure value sequence, three-axis acceleration data and interface operation event stream; a curvature feature extraction module for extracting a characteristic vector of a frequency spectrum of an operation curvature change based on the touch trajectory coordinate sequence, and identifying periods of missing routine verification steps and periods of device silence based on the three-axis acceleration data and the interface operation event stream; An entropy change index calculation module is used to dynamically calculate the local entropy growth rate and the temperature gradient spatial distribution of the capital network caused by a single transaction based on the operational curvature change spectrum feature vector and the real-time account capital transaction data to generate an entropy change index; a curvature detection module, configured to set a curvature detection threshold based on an entropy change indicator, detect a spectral feature vector of an operation curvature change using the adjusted curvature detection threshold, perform multi-scale pattern matching on the device's silent state interval, and acquire device peripheral signal data based on an interface operation event stream; The pressure value convolution fusion module is used to perform spatiotemporal convolution fusion of the acquired device peripheral signal data and the pressure value sequence to perform pressure testing; The risk warning generation module is used to perform spatiotemporal correlation analysis on the operational curvature change spectrum feature vector, entropy change index, and stress test results, identify multi-dimensional abnormal signals, and generate cross-scale risk warning instructions.
Citation Information
Patent Citations
Bank abnormal transaction detection method based on multi-modal data fusion
CN119850218A
System and Method for Blockchain Automatic Tracing of Money Flow Using Artificial Intelligence
US20220067738A1