Enterprise risk control dynamic portrait generation method and device based on multi-modal data fusion

Through multimodal data fusion and dynamic behavior entropy calculation, a dynamic portrait of enterprise risk control is generated, which solves the problems of insufficient data utilization and cross-modal correlation in existing technologies, and realizes accurate identification of enterprise risks and real-time adaptive analysis.

CN120634261APending Publication Date: 2025-09-12CHINA ELECTRONICS CLOUD DIGITAL INTELLIGENCE TECH CO LTD

Patent Information

Application Number
CN202510781589.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-12
Publication Date
2025-09-12

AI Technical Summary

Technical Problem

Existing enterprise risk control models have deficiencies in data utilization, rule flexibility, and cross-modal data correlation, making it difficult to meet the needs of dynamic enterprise risk prevention and control, and unable to comprehensively and accurately identify complex risk scenarios.

Method used

A multimodal data fusion method is adopted to align heterogeneous data through the Transformer architecture to generate a unified feature vector. Dynamic behavior entropy calculation and risk label matching are combined to generate a dynamic risk profile, and the risk path is tracked through the graph diffusion algorithm.

Benefits of technology

It has achieved accurate analysis of multimodal data, improved the real-time and adaptability of risk identification, optimized the risk tracing process, and enhanced the ability to identify complex risks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120634261A_ABST
    Figure CN120634261A_ABST
Patent Text Reader

Abstract

The invention relates to an enterprise risk control dynamic portrait generation method and device based on multi-modal data fusion. The method comprises the steps that structured data, unstructured texts and time sequence behavior logs are collected and preprocessed, and the preprocessing comprises standardization processing, NLP keyword extraction and time sequence behavior feature extraction; then aligning the heterogeneous data by using a Transform architecture, generating a unified feature vector, and realizing cross-modal feature alignment; and on the basis, generating a dynamic risk portrait, calculating a dynamic behavior entropy value to quantify an operation anomaly degree, and generating a risk level map in combination with risk label matching. Through multi-modal data fusion, dynamic feature alignment and entropy quantification, the problems of single data, rule lagging and cross-modal association deficiency of traditional risk control are solved, the comprehensiveness, dynamicity and accuracy of risk identification are remarkably improved, accurate identification of composite risks such as business development places and actual travel itineraries can be realized, and the risk identification efficiency is improved. And the risk control level of enterprises is effectively improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of enterprise risk control technology, and in particular to a method, device, and electronic device for generating a dynamic enterprise risk control portrait using multimodal data fusion. Background Art

[0002] In the field of enterprise risk management (ERM), with the deepening of digital transformation, the scale and types of enterprise data are experiencing explosive growth, and the limitations of traditional risk control models in dealing with complex business scenarios are becoming increasingly prominent. Specifically, existing technologies have significant deficiencies in data utilization, rule adaptability, and cross-modal correlation analysis. This results in insufficient accuracy, timeliness, and comprehensiveness in risk identification, making it difficult to meet enterprises' core needs for dynamic risk prevention and control.

[0003] 1. Existing enterprise risk control models suffer from significant limitations in data utilization due to their single-source nature. Currently, risk control models primarily rely on structured data, such as the specific data fields in expense reimbursement forms. They struggle to effectively integrate and utilize unstructured text data (such as approval comments in various approval processes) and time-series behavior logs (time series records of employee operations). This leads to numerous blind spots in risk detection. Complex risk scenarios involving multiple data types, such as "serialized invoice numbers colluding with emails to submit illegal reimbursements," are prone to missed detection, making it difficult to comprehensively and accurately identify potential risks.

[0004] 2. Traditional risk control methods often rely on static rules to assess risk. For example, they use pre-set travel expense thresholds to determine whether there are unusual expense reimbursements. However, with the constant adjustments to corporate organizational structures and the gradual changes in employee behavior patterns, these static rules with fixed thresholds are difficult to adapt to in a timely manner and cannot meet the dynamic changes in risk assessment needs, thus affecting the accuracy and timeliness of risk assessments.

[0005] 3. There are also significant gaps in cross-modal data correlation. Enterprises generate data from multiple sources during their daily operations, such as OA systems (office automation systems), ERP systems (enterprise resource planning systems), and CRM systems (customer relationship management systems). The lack of effective semantic alignment makes it difficult to deeply integrate and analyze data from these disparate systems, resulting in some hidden risks remaining unidentified. For example, a risk scenario like "an employee's car usage record at a sensitive location is inconsistent with their expense report summary" can easily go unnoticed due to the inability to cross-modally correlate data to uncover potential risk information, posing a hidden risk to the company's risk management.

[0006] In addition, although some new enterprise risk control models have been developed one after another, for example, the Chinese patent application "A method and device for building a risk control model for marketing scenarios" (CN119026060A) discloses a method for building a risk control model for marketing scenarios, which consists of three parts: unsupervised algorithm model construction, unsupervised algorithm model recognition result validity judgment, and supervised algorithm model construction; by using unsupervised algorithms to build a risk control identification model that does not rely on sample labels, using relative entropy algorithms to identify large-scale and traffic-concentrated abnormal behaviors that are significantly different from normal behavior distributions, and using isolation forests to identify abnormal behaviors that are small in number and significantly different from normal data, the ability to actively discover new risks is built. For another example, the Chinese patent application “A method, system, terminal and medium for constructing a risk control model based on distribution” (CN116029810A) discloses a method for constructing a risk control model based on distribution, comprising: using a pre-established big data analysis tool to process data resources in the target institution's data platform to obtain evaluation data; deploying a sub-algorithm module on the data platform according to the business logic of the target institution; inputting the evaluation data into the sub-algorithm module to obtain first indicator data, and transmitting the first indicator data to the bank's risk control model assembly library; and constructing a risk control model based on the first indicator data using the risk control model assembly library. However, the above methods still have many shortcomings in the application process. For example, they mainly involve the processing of structured data, the fusion data type is single, and risk scenarios cannot be fully covered; cross-modal correlation is insufficient, and hidden risks cannot be effectively identified; risk identification is not proactive enough, and it is mainly based on supervised learning methods to train known risk behaviors. There is a delay in the identification of new risk behaviors, and it is necessary to wait for abnormal fluctuations in business data and expert analysis before identification; based on fixed thresholds to judge risks, it is impossible to dynamically adapt to organizational structure adjustments or changes in employee behavior patterns, and risk assessment is not accurate and dynamic enough; supervised classification algorithms such as logistic regression and random forest are mainly used to build models, which have high dependence on feature engineering, limited model expression ability, weak generalization ability, and high cost of model effect optimization; there is a lack of closed-loop feedback mechanism, and it is difficult to adapt to changes in corporate strategies and achieve continuous optimization and dynamic adjustment of models.

[0007] To sum up, existing enterprise risk control models have many defects in data utilization, rule flexibility, and cross-modal data association, which make it difficult to meet the increasingly complex and dynamically changing risk prevention and control needs of enterprises. There is an urgent need for a method that can effectively integrate multimodal data and construct a dynamic risk control portrait to make up for these shortcomings and improve the level of enterprise risk control. Summary of the Invention

[0008] In order to solve the above problems, this application proposes a new method for generating enterprise risk control dynamic portraits based on multimodal data fusion.

[0009] This application is mainly based on the following technical strategies: 1. Data collection and preprocessing through multimodal data fusion method: (1) Structured data (table): Standardized work order fields (such as reimbursement labor number, document number, etc.).

[0010] (2) Unstructured text (emails / approval comments): NLP extracts keywords (such as "rebate", "fictitious itinerary", etc.).

[0011] (3) Time series behavior log: records operation time, IP address, and access object (such as the same account requests sensitive files 10 times within 1 hour).

[0012] 2. Cross-modal feature alignment: Use the Transformer architecture to align heterogeneous data and generate a unified feature vector: ; Variable Description: Q (query): current data modality (e.g., the sequence of financial data request actions in an OA system); K (key): heterogeneous modeling dimension to be integrated (e.g., approval relationship in ERP system); V: A cross-modal interaction hub (e.g., linking the "Invoice Number Sudden Increase Operation Group (V→Approval Abnormal Feature Column)" with the "Reimbursement Account Flow (*V→Transfer Direction)"); T: Time difference detection of anomalies, (e.g., operation frequency → marking high behavioral entropy peaks + automatic truncation of analysis operation time window Δt in enterprise system logs, Δt > 12h = anomaly); d k (Scaling factor): The scaling factor ensures gradient stability and is related to business complexity. Set the scaling factor. , such as 64-dimensional vector d k = 8.

[0013] 3. Dynamic risk profile generation: Dynamic behavioral entropy (BE) calculation: quantifying the degree of operational abnormality.

[0014] , P(x i ) = Operating frequency (x i ) / total number of operations; Risk label matching: preset rule labels (such as "itinerary does not match business", "contradictory itinerary", etc.).

[0015] Risk level map: Combine BE values ​​and rule labels to generate profiles of high-risk personnel / departments.

[0016] P(x i ): Indicates the classification condition x of a specific risk event i Under the following circumstances (such as "bid-rigging operation mode X1" and "fictitious expense reimbursement mode X2"), according to the covariance matching rule of the behavior sequence and the historical black sample library, the probability benchmark of triggering the risk mode is calculated (normalized to system classification).

[0017] Typical use case explanation: Problem path tracing is achieved through the graph diffusion algorithm of risk event tracing: The graph diffusion model traces the risk path in reverse (e.g., “Supplier A → Purchasing Manager B → Finance C”).

[0018] Specifically, in order to achieve the above objectives, this application provides the following technical solutions: A first aspect of the present application provides a method for generating a dynamic risk control profile of an enterprise using multimodal data fusion, the method comprising: Multimodal data collection and preprocessing: Collect structured data, unstructured text data, and time-series behavior log data, perform standardized field extraction on the structured data, perform semantic feature extraction on the unstructured text data, and record operation sequences on the time-series behavior log data; Cross-modal feature alignment: The Transformer architecture is used to fuse features of multimodal data and generate a unified feature vector. The feature alignment process is achieved by associating the query vector Q, the key vector K, and the reduction factor dk, where dk is a scaling factor related to business complexity. Dynamic risk profile generation: Based on the unified feature vector, the dynamic behavior entropy value BE is calculated to quantify the degree of operational abnormality, and combined with the preset risk label matching results, a risk level map containing high-risk personnel / departments is generated.

[0019] Furthermore, in the method of the present application, in the multimodal data acquisition and preprocessing steps: The structured data includes basic enterprise information (such as registered capital, enterprise code), business transaction data (such as bid document code, deposit account flow), and approval process data (such as document number, work order fields); The unstructured text data includes text data from approval notes, email exchanges, and expert countersigned electronic opinions, and keywords (such as "rebate," "fictitious itinerary," and "invisible manipulation of voting processes") are extracted using natural language processing (NLP) technology. The time series behavior log data includes operation time, IP address, access object and operation frequency, and also covers the record data of the operation sequence of multiple requests for sensitive resources by the same account in a short period of time.

[0020] Furthermore, in the method of the present application, in the cross-modal feature alignment step, the Transformer architecture is used to encode the features of the heterogeneous data using an attention mechanism, and then align the heterogeneous data to generate a unified feature vector. The calculation formula is as follows: ; Where: Q is the query vector, which represents the operation sequence of the current data modality (such as the sequence of financial data request actions in the OA system); K is the key vector, which represents the heterogeneous modeling dimensions to be integrated (such as approval relationships and supplier holding paths in the ERP system); V represents a cross-modal interaction hub; T indicates time difference detection anomaly; The reduction factor , used to adjust the gradient stability of the attention matrix, where the dimension is the vector dimension of Q or K (such as dk=8 for a 64-dimensional vector).

[0021] Furthermore, in the method of this application, in the step of generating a dynamic risk profile, the calculation formula of the dynamic behavior entropy value BE is: BE = (α × financial entropy + β × operational entropy) / (γ × risk-based threshold); Among them, α, β, and γ are the weight coefficients of financial entropy, operational entropy, and risk-based threshold respectively; The financial entropy represents the degree of abnormality in the flow of funds, and the operational entropy represents the degree of abnormality in the frequency / time of operations.

[0022] Furthermore, in the method of the present application, in the step of generating a dynamic risk profile, the preset risk label is matched by matching the covariance of the unified feature vector with the historical black sample library; The risk level map is generated by weighted fusion of BE value and preset risk labels. High-risk personnel / departments are defined as entities whose BE value exceeds the warning threshold (such as BE>1.5 times the risk basic threshold) and matches at least two high-risk labels.

[0023] Furthermore, the method of the present application also includes the step of implementing risk path tracing through a graph diffusion algorithm, specifically including: Build a risk association graph using risk event-related entities (such as suppliers, purchasing managers, and financial personnel) as nodes and operational associations between entities (such as capital flows, IP access records, and document editing records) as edges. Based on the reverse diffusion mechanism, starting from the initial risk node (such as an abnormal supplier), the node risk probability is iteratively updated through the graph convolutional network (GCN) to locate the high-risk path (such as "supplier A→purchasing manager B→finance C").

[0024] Furthermore, in the method of the present application, the multimodal data collection and preprocessing steps also include regular matching to eliminate redundancy in structured data (such as the frequent change detection rule for corporate shareholder name change records within two years: an alarm is triggered when the equity level change rate is ≥30%), and deep semantic embedding of unstructured text (such as using the BERT model to calculate similar sentence clusters in the PDF text of the bidding materials).

[0025] A second aspect of the present application provides a device for generating a dynamic risk control portrait of an enterprise using multimodal data fusion, the device comprising: Multimodal data acquisition module: used to collect structured data, unstructured text data, and time-series behavior log data; Data preprocessing module: used to extract standardized fields from structured data, extract semantic features from unstructured text data, and record operation sequences from time-series behavior log data; Cross-modal feature alignment module: This module is used to perform feature fusion on multimodal data through the Transformer architecture to generate a unified feature vector. The feature alignment process is achieved by associating the query vector Q, the key vector K, and the reduction factor dk, where dk is a scaling factor related to business complexity. Dynamic risk profile generation module: used to calculate the dynamic behavior entropy value BE based on the unified feature vector to quantify the degree of operational abnormality, and combine the preset risk label matching results to generate a risk level map including high-risk personnel / departments.

[0026] When running, the device implements the steps of the aforementioned method for generating a dynamic enterprise risk control portrait by multimodal data fusion.

[0027] Furthermore, the device of the present application also includes: Risk path tracing module: used to construct risk association graphs and locate high-risk paths through graph diffusion algorithms.

[0028] A third aspect of the present application provides an electronic device, comprising: a memory and a processor; Memory: used to store computer programs; Processor: used to execute the computer program to implement the steps of the aforementioned method for generating a dynamic enterprise risk control portrait based on multimodal data fusion.

[0029] The fourth aspect of the present application provides a computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a processor, the steps of the method for generating a dynamic enterprise risk control portrait by multimodal data fusion are implemented.

[0030] In summary, compared with existing enterprise risk control methods, this application method has the following advantages: (1) Accurate risk analysis: Through multimodal data fusion, the analysis accuracy of risk and dynamic behavior entropy values ​​is effectively improved.

[0031] (2) Real-time and adaptability: The introduction of a closed-loop feedback mechanism ensures that the model can adapt to changes in corporate strategies in real time.

[0032] (3) Improved efficiency of risk tracing: The risk tracing process has been optimized, significantly improving the efficiency of locating and analyzing risk sources.

[0033] (4) Cross-modal collaboration: semantic alignment is achieved, enhancing the ability to identify complex risks such as "business location + actual travel itinerary".

[0034] Other features and advantages of this application will be described in detail in the following description, or will be understood through the implementation of the relevant technical solutions of this application. The objectives and other advantages of this application can be achieved through the technical features and technical means clearly indicated in the description, claims, and drawings, and obtained through the implementation of these technical contents. BRIEF DESCRIPTION OF THE DRAWINGS

[0035] To more clearly illustrate the technical solutions of the embodiments of the present application, the following briefly introduces the drawings involved in the description of the embodiments. It should be noted that the drawings only illustrate some embodiments of the present application. Those skilled in the art can deduce other relevant drawings based on these drawings without engaging in creative work.

[0036] Figure 1 This is the overall implementation flow chart of the method for generating dynamic risk control portraits for the enterprise applying for this application.

[0037] Figure 2 This is a structural diagram of the composition of the enterprise risk control dynamic portrait generation device for this application.

[0038] Figure 3 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0039] In order to make the purpose, technical solutions and advantages of the embodiments of the present application clearer, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. It should be understood that the described embodiments are only some embodiments of the present application, not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.

[0040] In this document, the term "including" and any variations thereof (such as "including," "comprising," etc.) are open-ended expressions and should be understood as meaning "including but not limited to," meaning that the listed contents are not exhaustive and may include other contents not explicitly mentioned. The term "based on" should be understood as meaning "based at least in part on," meaning that the basis or condition referred to may not be the only factor and may also involve other relevant factors. The term "one embodiment" should be understood as meaning "at least one embodiment," meaning that the described embodiment is not the only possible implementation method and that other similar embodiments may exist.

[0041] In this application, the terms "a" and "a plurality" are used to modify related elements or features in an illustrative, non-restrictive manner. Unless the context clearly indicates otherwise, "a" should be understood as meaning "at least one," and "a plurality" should be understood as meaning "at least two." Those skilled in the art should interpret these terms appropriately based on the semantics and logical relationships of the context to ensure that they encompass the possibility of "one or more."

[0042] Figure 1 The following is the overall implementation process of the method for generating dynamic risk control profiles of enterprises based on multimodal data fusion provided by this application, including the following steps: S1. Multimodal Data Acquisition and Preprocessing: Collect structured data, unstructured text data, and time-series behavior log data. Perform standardized field extraction on the structured data, perform semantic feature extraction on the unstructured text data, and record operation sequences on the time-series behavior log data. S2. Cross-modal feature alignment: We use the Transformer architecture to fuse features from multimodal data and generate a unified feature vector. Feature alignment is achieved by calculating the association between the query vector Q, the key vector K, and the scaling factor dk, where dk is a scaling factor related to the complexity of the business. S3. Dynamic risk profile generation: Based on the unified feature vector, the dynamic behavior entropy value BE is calculated to quantify the degree of operational abnormality. Combined with the preset risk label matching results, a risk level map containing high-risk personnel / departments is generated.

[0043] In order to more clearly illustrate the technical solution of the present application, the following will further illustrate it through embodiments of specific scenarios.

[0044] The method for generating a dynamic enterprise risk control profile using multimodal data fusion in this embodiment includes the following steps: Step 1: Multimodal data collection and feature screening Structured data (such as company registered capital, bid document code, and deposit account records) is entered into the bidding system. This data is then supplemented with real-time non-text data: approval notes from the procurement management system (e.g., a purchaser's handwritten note, "Recommends XX brand accessories...") and electronic expert review logs (IP ownership, editing time series). This data is then fed into the risk control analysis queue through a standardized data mapping layer, automatically matching against a library of risk violation tags (e.g., "hidden manipulation of the voting process" and "collusive bidding in the related supply chain").

[0045] Data processing details: To eliminate redundant interference, this system uses regular expressions to match records of changes in corporate shareholder names (applicable terms: an alarm will be triggered if corporate shareholders change frequently within two years and the equity level change rate is ≥30%), and performs deep embedding calculations of the BERT model on the PDF text of the bidding materials to compare similar sentence clusters.

[0046] Step 2: Dynamic encoding and alignment of supply chain risk images During the stage of aligning the characteristics of the equity path with the enterprise's dynamic behavior trajectory, the core operations are as follows: (1) Based on industrial and commercial big data and State-owned Assets Supervision and Administration Commission archives, the controlling path of supplier group A is analyzed: natural person shareholder M → subsidiary L → third-party shell company P (indirectly holding 31% of enterprise A, not recorded in the qualification review); (2) Capture the flow of funds in the bidding projects in which they participated in the past five months (35% of the funds paid by suppliers’ deposits flowed to the account of a third-party financial institution, S); (3) The timing anomaly analysis module calculates the IP login frequency (12 hours before the bid deadline, the bid evaluation expert group account established an access channel with the equipment of a supplier that did not bid, and the standard deviation of the login interval was 6.72 times that of the same batch of bids).

[0047] Algorithm execution description: In response to abnormal behavior of bidders, a multi-dimensional spatiotemporal attention mechanism model is activated to align the bid deposit payment sequence and the enterprise operation frequency trajectory (input parameters: the average amount Δ change is >±8%, and the number of logins suddenly increases to 13% of the historical average) to the feature space, and the dynamic entropy is output: BE = (1 × financial entropy + 0.7 × operational entropy) / (2 × risk-based threshold). If the result exceeds the warning value, manual review will be triggered.

[0048] Step 3: Cross-locating the semantics of the illegal behavior chain and equity linkage The system identifies potential bidding violations: Case Anchor Point 1: The text overlap index of the "Galvanizing Parameter Error Threshold" standard paragraph in the technical section of the bid documents of suppliers A and B reached 86%, higher than the industry average (25%-40%). The core description used the same erroneous data (which was confirmed to have been copied from expired technical files); Case Anchor Point 2: In the bidding deposit payment process, the payment account of Company C (the surface association chain shows that it is a non-related unit) is hosted by a third-party company S. After tracing through the graph database, direct chat records between the key agent of the hosting agreement and the financial executives of Group A were discovered.

[0049] Technical countermeasures: Use a cross-modal feature layer fusion engine to analyze the mapping between the bidders' semantic associations and the capital flow network. Combined with the equity association weight threshold (e.g., a joint venture with a secondary control interest of ≥25% is marked in red), the invisible supply chain links of Company C are included in the risk score.

[0050] Step 4: Event tracing process for violation risks (instance link backtracing) Through diffusion-type correlation penetration technology, high-risk node path chains are gradually located: Operation Entity Tracing: The anonymous remitter account G, to which the supplier's payment was initially directed, was matched with Wang (UID0345), the purchasing manager within the group. Technical data chain lock: During the editing period of the abnormal bid evaluation opinion (22:45 in the morning), the operation log captured two terminal IP addresses (the bidding agent server and the home routing gateway of Mr. Zhang from the Group Audit Department); Network location associated with the violation: Zhang used the intersection of three overseas travel records to cover the travel path of the supplier's legal representative and updated the supply chain review rules document during the trip.

[0051] Figure 2 The present application shows a device for generating a dynamic risk control portrait of an enterprise using multimodal data fusion, which includes: Multimodal data acquisition module: used to collect structured data, unstructured text data, and time-series behavior log data; Data preprocessing module: used to extract standardized fields from structured data, extract semantic features from unstructured text data, and record operation sequences from time-series behavior log data; Cross-modal feature alignment module: This module is used to perform feature fusion on multimodal data through the Transformer architecture to generate a unified feature vector. The feature alignment process is achieved by associating the query vector Q, the key vector K, and the reduction factor dk, where dk is a scaling factor related to business complexity. Dynamic risk profile generation module: used to calculate the dynamic behavior entropy value BE based on the unified feature vector to quantify the degree of operational abnormality, and combine the preset risk label matching results to generate a risk level map including high-risk personnel / departments.

[0052] When the above device is running, the steps of the enterprise risk control dynamic portrait generation method using multimodal data fusion disclosed in this application are implemented.

[0053] The flowcharts and block diagrams in the accompanying drawings illustrate possible implementations of the apparatus, methods, and computer program products according to various embodiments of the present application, including architecture, functions, and operations. In these figures, each box may represent a module, a program segment, or a portion of a code, which contains one or more executable instructions for implementing a specified logical function. It should be noted that each box in the block diagram and / or flowchart, and the combination of these boxes, can be implemented using a dedicated hardware-based system to implement the specified function or operation, or can be implemented by a combination of dedicated hardware and computer instructions.

[0054] like Figure 3 As shown, an embodiment of the present application further discloses an electronic device, comprising: a processor 310, a communication interface 320, a memory 330 for storing a computer program executable by the processor, and a communication bus 340. The processor 310, the communication interface 320, and the memory 330 communicate with each other via the communication bus 340. The processor 310 executes the executable computer program to implement the steps of the above-mentioned method for generating a dynamic enterprise risk control profile using multimodal data fusion.

[0055] It is understood that, in addition to the memory and processor, the electronic device may also include an input device (e.g., a keyboard), an output device (e.g., a display), and other communication modules. These input devices, output devices, and other communication modules all communicate with the processor via an I / O interface (i.e., an input / output interface).

[0056] The operation of the present application can be implemented by writing computer program code using one or more programming languages ​​or a combination thereof. The programming languages ​​include but are not limited to the following types: Object-oriented programming languages, such as Java, Smalltalk, C++, etc.; A conventional procedural programming language, such as "C" or a similar programming language.

[0057] The execution methods of the program code include but are not limited to: Executes entirely on the user's computer; Partially executed on the user's computer and partially on a remote computer; Executed as a standalone software package; Executes entirely on the remote computer or server.

[0058] In scenarios involving a remote computer, the remote computer can be connected to the user's computer via any type of network, including but not limited to a local area network (LAN) or a wide area network (WAN). Additionally, the remote computer can be connected to an external computer via an Internet service provider, such as the Internet.

[0059] Furthermore, the present application also discloses a computer-readable storage medium. When the instructions in the computer-readable storage medium are executed by the processor of an electronic device, the electronic device can execute the various steps of the enterprise risk control dynamic portrait generation method based on multimodal data fusion disclosed in the present application.

[0060] In the context of this application, computer-readable storage media refers to tangible media that can store computer program code and related data. Specific examples include, but are not limited to, the following: (1) Portable computer disk: A removable magnetic storage medium such as a floppy disk.

[0061] (2) Hard disk: includes fixed storage devices such as mechanical hard disks and solid-state hard disks.

[0062] (3) Random Access Memory (RAM): Volatile storage medium used for temporary storage of data and program code.

[0063] (4) Read-only memory (ROM): A non-volatile storage medium used to store fixed programs and data.

[0064] (5) Erasable Programmable Read-Only Memory (EPROM) or Flash Memory: A non-volatile storage medium that supports multiple erasing and programming.

[0065] (6) Fiber optic storage device: storage medium based on fiber optic technology.

[0066] (7) Compact Disc Read-Only Memory (CD-ROM): A read-only medium that stores data in the form of an optical disc.

[0067] (8) Optical storage devices: storage media based on optical principles, such as DVDs and Blu-ray discs.

[0068] (9) Magnetic storage devices: storage media based on magnetic principles, such as magnetic tapes and disks.

[0069] (10) Any suitable combination of the above: for example, combining multiple storage media to meet different storage requirements.

[0070] These computer-readable storage media can be used to store the program code and related data described in this application to support the operation of the program and the persistent storage of data.

[0071] In particular, according to an embodiment of the present application, the process described in the flowchart can be implemented as a computer software program. For example, an embodiment of the present application relates to a computer program product, which includes a computer program carried on a non-transitory computer-readable medium. The computer program includes program code for executing the enterprise risk control dynamic portrait generation method using multimodal data fusion disclosed in the present application. When the computer program is executed by a processing device, it can implement the above-mentioned functions defined in the embodiments of the present application.

[0072] Although the above discussion contains several specific implementation details, these details should not be interpreted as limiting the scope of this application. The above description is only a preferred embodiment of the present application and an illustration of the technical principles used. Those skilled in the art should understand that the scope of disclosure involved in this application is not limited to the technical solutions formed by the specific combination of the above technical features. At the same time, this application should also cover other technical solutions formed by any combination of the above technical features or their equivalent features without departing from the above disclosed concepts.

[0073] Those skilled in the art should also understand that they may modify the technical solutions described in the aforementioned embodiments, or replace some of the technical features therein with equivalents, without departing from the spirit and scope of the technical solutions of the embodiments of the present application. Such modifications or replacements will not cause the essence of the corresponding technical solutions to deviate from the core spirit and scope of the technical solutions of the embodiments of the present application.

Claims

1. A method for generating dynamic risk control portraits of enterprises based on multimodal data fusion, characterized in that: The method comprises: Multimodal data collection and preprocessing: Collect structured data, unstructured text data, and time-series behavior log data, perform standardized field extraction on the structured data, perform semantic feature extraction on the unstructured text data, and record operation sequences on the time-series behavior log data; Cross-modal feature alignment: The Transformer architecture is used to fuse features of multimodal data and generate a unified feature vector. The feature alignment process is achieved by associating the query vector Q, the key vector K, and the reduction factor dk, where dk is a scaling factor related to business complexity. Dynamic risk profile generation: Based on the unified feature vector, the dynamic behavior entropy value BE is calculated to quantify the degree of operational abnormality, and combined with the preset risk label matching results, a risk level map containing high-risk personnel / departments is generated.

2. The method according to claim 1, characterized in that In the multimodal data acquisition and preprocessing steps: The structured data includes basic enterprise information, business transaction data and approval process data; The unstructured text data includes text data of approval notes, email exchanges, and expert countersigned electronic opinions; The time series behavior log data includes operation time, IP address, access object and operation frequency, and also covers the record data of the operation sequence of multiple requests for sensitive resources by the same account in a short period of time.

3. The method according to claim 1, characterized in that In the cross-modal feature alignment step, the Transformer architecture is used to encode the features of heterogeneous data using an attention mechanism, and then align the heterogeneous data to generate a unified feature vector. The calculation formula is as follows: ; Where: Q is the query vector, which represents the operation sequence of the current data modality; K is the key vector, which represents the dimension of heterogeneous modeling to be fused; V represents a cross-modal interaction hub; T indicates time difference detection anomaly; The reduction factor dk = , used to adjust the gradient stability of the attention matrix, where the dimension is the vector dimension of Q or K.

4. The method according to claim 1, wherein In the step of generating a dynamic risk profile, the calculation formula of the dynamic behavior entropy value BE is: BE = (α × financial entropy + β × operational entropy) / (γ × risk-based threshold); Among them, α, β, and γ are the weight coefficients of financial entropy, operational entropy, and risk-based threshold respectively; The financial entropy represents the degree of abnormality in the flow of funds, and the operational entropy represents the degree of abnormality in the frequency / time of operations.

5. The method according to claim 1, characterized in that In the step of generating a dynamic risk profile, the preset risk label is matched by matching the covariance of the unified feature vector with the historical black sample library; The risk level map is generated by weighted fusion of BE value and preset risk labels. High-risk personnel / departments are defined as entities whose BE value exceeds the warning threshold and matches at least two high-risk labels.

6. The method according to claim 1, characterized in that The method further includes the step of implementing risk path tracing by using a graph diffusion algorithm, specifically including: Construct a risk association graph using risk event-related entities as nodes and operation associations between entities as edges; Based on the reverse diffusion mechanism, starting from the initial risk node, the node risk probability is iteratively updated through the graph convolutional network (GCN) to locate high-risk paths.

7. The method according to claim 1, characterized in that The multimodal data collection and preprocessing steps also include regular matching to eliminate redundancy in structured data and deep semantic embedding of unstructured text.

8. A device for generating dynamic risk control portraits of enterprises by fusion of multimodal data, characterized in that: The device comprises: Multimodal data acquisition module: used to collect structured data, unstructured text data, and time-series behavior log data; Data preprocessing module: used to extract standardized fields from structured data, extract semantic features from unstructured text data, and record operation sequences from time-series behavior log data; Cross-modal feature alignment module: This module is used to perform feature fusion on multimodal data through the Transformer architecture to generate a unified feature vector. The feature alignment process is achieved by associating the query vector Q, the key vector K, and the reduction factor dk, where dk is a scaling factor related to business complexity. Dynamic risk profile generation module: used to calculate the dynamic behavior entropy value BE based on the unified feature vector to quantify the degree of operational abnormality, and combine the preset risk label matching results to generate a risk level map including high-risk personnel / departments.

9. The device according to claim 8, characterized in that The device also includes: Risk path tracing module: used to construct risk association graphs and locate high-risk paths through graph diffusion algorithms.

10. An electronic device, characterized in that: include: memory and processor; Memory: used to store computer programs; Processor: used to execute the computer program to implement the steps of the enterprise risk control dynamic portrait generation method based on multimodal data fusion as described in any one of claims 1 to 7.

Citation Information

Patent Citations

  • Distributed risk control model construction method and system, terminal and medium

    CN116029810A

  • Risk control model building method and device for marketing scene

    CN119026060A

Cited By

  • User multi-modal data processing method and device, electronic equipment and readable medium

    CN122316688A