Abnormal customer identification method and device based on multi-modal data, equipment and medium

By constructing a heterogeneous network graph and performing multimodal data fusion and time series analysis, combined with federated learning and differential privacy technology, the problem of low accuracy in abnormal customer identification in existing technologies is solved, and efficient and accurate abnormal customer identification is achieved.

CN120635908APending Publication Date: 2025-09-12CHINA PING AN LIFE INSURANCE CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510722338.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-30
Publication Date
2025-09-12

AI Technical Summary

Technical Problem

Existing abnormal customer identification technology is based on single modal analysis, which makes it difficult to identify complex abnormal behavior patterns, resulting in low recognition accuracy and the rule engine is easy to circumvent.

Method used

By constructing a heterogeneous network graph, extracting text semantics and image features from multi-source data, performing feature fusion, and using time series analysis and federated learning models for real-time updates, abnormal patterns are identified, and differential privacy technology is combined to protect customer privacy.

Benefits of technology

It improves the accuracy of identifying abnormal customers, identifies abnormal behaviors of short-term intensive transactions and long-term dormant accounts, protects customer sensitive information, and enhances model accuracy during cross-institutional collaborative training.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120635908A_ABST
    Figure CN120635908A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of data analysis, can be applied to business system platforms of financial science and technology, medical health and the like, and discloses an abnormal customer identification method, device, equipment and medium based on multi-modal data, and the method comprises the steps: constructing a heterogeneous network diagram corresponding to a target customer according to multi-source data; extracting a sub-graph mode in the heterogeneous network graph according to a transaction detection demand, and extracting text semantic features and image features corresponding to the sub-graph mode; performing feature fusion on the text semantic features and the image features, and analyzing an abnormal mode corresponding to a target fusion feature by using a time sequence; updating the multi-source data of the target customer in real time by using incremental learning, and updating model parameters of a preset federated learning model according to the updated multi-source data; and performing score analysis on the abnormal mode by using the updated federal learning model, and when the target score is greater than a preset score threshold, determining the target customer as an abnormal customer. And the accuracy of abnormal customer identification is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data analysis technology, and in particular to a method, device, equipment and medium for identifying abnormal customers based on multimodal data. Background Art

[0002] As the digitalization process accelerates, the customer data accumulated in various industries are massive, heterogeneous and dynamic. Risky behaviors have also evolved from a single model to a complex combination. Coupled with the rapid development of new business formats, new technologies and new payment methods, there are more and more risky customers. In order to accurately identify risky customers, it is necessary to conduct a multi-dimensional analysis of the customer group.

[0003] In the field of healthcare, patient data covers multimodal information such as electronic medical records (text), medical imaging (images), gene sequencing (sequence data), and real-time vital signs (time series data). Single modality analysis (such as relying solely on blood test values) may miss the diagnosis of early complex diseases (such as abnormalities in the imaging characteristics and biochemical indicators of tumors), resulting in incomplete user portraits and difficulty in accurately identifying target customers.

[0004] In the financial technology business field, customer behavior data includes transaction flows, APP operation logs, customer service voice records, social network connections, etc. Relying solely on transaction amount thresholds to judge abnormal behavior (such as single numerical rules) is prone to misjudging or missing new abnormal behavior patterns (such as small and scattered transfers, abnormal IP logins, and abnormal connections between social accounts), resulting in inaccurate identification of target customers.

[0005] Existing abnormal customer identification technology is based on a unified rule engine to identify customers. However, the rule engine is easy to circumvent and has difficulty identifying hidden abnormal patterns. In addition, single-dimensional analysis leads to a large number of misjudgments, resulting in incomplete identification of target customers, and thus low accuracy in abnormal customer identification. Summary of the Invention

[0006] The present invention provides a method, apparatus, device and medium for identifying abnormal customers based on multimodal data, so as to solve the technical problem of low accuracy in identifying abnormal customers.

[0007] In a first aspect, a method for identifying abnormal customers based on multimodal data is provided, comprising:

[0008] Collect multi-source data of target customers, and construct a heterogeneous network graph corresponding to the target customers based on the multi-source data;

[0009] Extracting subgraph patterns in the heterogeneous network graph according to preset transaction detection requirements, and extracting text semantic features and image features corresponding to the subgraph patterns;

[0010] Fusing the text semantic features and the image features to obtain target fusion features, and analyzing abnormal patterns corresponding to the target fusion features using a preset time series;

[0011] Use the preset incremental learning to update the target customer's multi-source data in real time, and update the model parameters of the preset federated learning model based on the updated multi-source data;

[0012] The updated federated learning model is used to perform score analysis on the abnormal pattern to obtain a target score for the target customer. When the target score is greater than a preset score threshold, the target customer is determined to be an abnormal customer.

[0013] In a second aspect, a device for identifying abnormal customers based on multimodal data is provided, comprising:

[0014] A heterogeneous network graph construction module is used to collect multi-source data of target customers and construct a heterogeneous network graph corresponding to the target customers based on the multi-source data;

[0015] A feature extraction module, configured to extract subgraph patterns in the heterogeneous network graph according to preset transaction detection requirements, and extract text semantic features and image features corresponding to the subgraph patterns;

[0016] An abnormal pattern analysis module is used to fuse the text semantic features and the image features to obtain a target fusion feature, and analyze the abnormal pattern corresponding to the target fusion feature using a preset time series;

[0017] The model parameter update module is used to update the multi-source data of target customers in real time using the preset incremental learning, and to update the model parameters of the preset federated learning model based on the updated multi-source data;

[0018] The abnormal customer identification module is used to use the updated federated learning model to perform score analysis on the abnormal pattern to obtain a target score for the target customer. When the target score is greater than a preset score threshold, the target customer is determined to be an abnormal customer.

[0019] In a third aspect, a computer device is provided, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the steps of the above-mentioned method for identifying abnormal customers based on multimodal data are implemented.

[0020] In a fourth aspect, a computer-readable storage medium is provided, which stores a computer program. When the computer program is executed by a processor, the steps of the above-mentioned abnormal customer identification method based on multimodal data are implemented.

[0021] In the above-mentioned scheme implemented by the abnormal customer identification method, device, equipment and medium based on multimodal data, multi-source data of the target customer can be collected through the client, and a heterogeneous network graph corresponding to the target customer can be constructed based on the multi-source data; sub-graph patterns in the heterogeneous network graph can be extracted according to the preset transaction detection requirements, and the text semantic features and image features corresponding to the sub-graph patterns can be extracted; the text semantic features and image features are fused to obtain target fusion features, and the abnormal patterns corresponding to the target fusion features are analyzed using the preset time series; the multi-source data of the target customer are updated in real time using the preset incremental learning, and the model parameters of the preset federated learning model are updated according to the updated multi-source data; the updated federated learning model is used to update the model parameters of the target customer according to the updated multi-source data; the updated federated learning model is used to update the model parameters of the target customer according to the updated multi-source data; the updated federated learning model is used to update the model parameters of the target customer according to the updated multi-source data. The learning model performs score analysis on abnormal patterns to obtain the target score of the target customer. When the target score is greater than the preset score threshold, the target customer is determined to be an abnormal customer and the abnormal customer is fed back to the client. In the present invention, multimodal data fusion and graph neural network technology are introduced through the customer's multi-source data to improve the accuracy of high-risk customer identification; time series-aware graph neural network is introduced to identify abnormal activation of short-term intensive transactions and long-term dormant accounts; differential privacy technology is used to add noise during cross-institutional collaborative training to protect customer sensitive information; based on capital flow and social relationships, the probability of risk diffusion in the transaction network is quantified, thereby solving the technical problem of low accuracy in abnormal customer identification. BRIEF DESCRIPTION OF THE DRAWINGS

[0022] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments of the present invention. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative labor.

[0023] Figure 1 1 is a schematic diagram of an application environment of an abnormal customer identification method based on multimodal data in one embodiment of the present invention;

[0024] Figure 2 1 is a flow chart of a method for identifying abnormal customers based on multimodal data in one embodiment of the present invention;

[0025] Figure 3 yes Figure 2 A schematic flow chart of a specific implementation of step S2;

[0026] Figure 4 yes Figure 2 A schematic flow chart of a specific implementation of step S3;

[0027] Figure 5 1 is a schematic structural diagram of an abnormal customer identification device based on multimodal data in one embodiment of the present invention;

[0028] Figure 6 is a structural diagram of a computer device in one embodiment of the present invention;

[0029] Figure 7 FIG. 2 is another structural diagram of a computer device according to an embodiment of the present invention. DETAILED DESCRIPTION

[0030] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of them. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.

[0031] The abnormal customer identification method based on multimodal data provided by the embodiment of the present invention can be applied in the following situations: Figure 1 In an application environment, the client communicates with the server through the network. The server can collect multi-source data of the target customer through the client, and construct a heterogeneous network graph corresponding to the target customer based on the multi-source data; extract the sub-graph pattern in the heterogeneous network graph according to the preset transaction detection requirements, and extract the text semantic features and image features corresponding to the sub-graph pattern; perform feature fusion on the text semantic features and image features to obtain the target fusion features, and use the preset time series to analyze the abnormal patterns corresponding to the target fusion features; use the preset incremental learning to update the multi-source data of the target customer in real time, and update the model parameters of the preset federated learning model according to the updated multi-source data; use the updated federated learning model to perform score analysis on the abnormal patterns, The target score of the target customer is obtained. When the target score is greater than the preset score threshold, the target customer is determined to be an abnormal customer, and the abnormal customer is fed back to the client. In the present invention, multimodal data fusion and graph neural network technology are introduced through the multi-source data of the customer to improve the accuracy of high-risk customer identification; time series-aware graph neural network is introduced to identify abnormal activation of short-term intensive transactions and long-term dormant accounts; differential privacy technology is used to add noise during cross-institutional collaborative training to protect customer sensitive information; based on capital flow and social relationships, the probability of risk diffusion in the transaction network is quantified, thereby solving the technical problem of low accuracy in abnormal customer identification. Among them, the client can be but is not limited to various personal computers, laptops, smart phones, tablets and portable wearable devices. The server can be implemented with an independent server or a server cluster composed of multiple servers. The present invention is described in detail below through specific embodiments.

[0032] See also Figure 2 As shown, Figure 2A flowchart of a method for identifying abnormal customers based on multimodal data provided by an embodiment of the present invention includes the following steps:

[0033] S1. Collect multi-source data of target customers and construct a heterogeneous network graph corresponding to the target customers based on the multi-source data.

[0034] In an embodiment of the present invention, the multi-source data includes customer portrait data, transaction flow data and unstructured data, wherein customer portrait data refers to structured data, including but not limited to the target customer's identity information, occupation, and account opening channel; transaction flow data includes but is not limited to transfer amount, frequency, and counterparty relationship; unstructured data includes but is not limited to customer communication records (emails, customer service recordings) and public intelligence (sanctions lists, negative news).

[0035] In detail, multi-source data of target customers can be obtained from a pre-stored storage area through computer statements with data crawling functions (such as Java statements, Python statements, etc.), where the storage area includes but is not limited to databases and blockchains.

[0036] Furthermore, in order to abstract the complex relationships in the financial field into a computable graph structure, the probability of customer risk diffusion in the transaction network is quantified based on capital flows and social relationships.

[0037] In an embodiment of the present invention, the heterogeneous network diagram refers to constructing customers and counterparties into a heterogeneous network, in which customers and counterparties belong to different node types. Edge types such as transfer and device usage require clear direction and semantics, which can intuitively present the customer-device-counterparty association path and assist risk control personnel in discovering hidden risks (such as multiple account groups operated through the same overseas device).

[0038] In an embodiment of the present invention, constructing a heterogeneous network graph corresponding to the target customer based on the multi-source data includes:

[0039] Performing data enhancement processing on the multi-source data to obtain multi-source enhanced data;

[0040] Extracting entity data and entity relationships from the multi-source enhanced data;

[0041] Performing data alignment on the entity data to obtain entity-aligned data;

[0042] Determining node features based on the entity alignment data, and determining edge features based on the entity relationships;

[0043] A heterogeneous network graph is constructed based on the node features and the edge features.

[0044] In detail, data cleaning operations are performed on multi-source data, such as removing fields with missing values ​​exceeding 30% (such as invalid transaction notes), correcting logical contradictions (such as negative transaction amounts), synthesizing samples for low-frequency abnormal data (such as cross-border transfers), adding Gaussian noise to device IP addresses, protecting privacy while retaining geographical distribution characteristics, and heterogeneous networks need to clearly distinguish between node types (such as customers, devices) and edge types (such as transfers, co-locations) to avoid semantic ambiguity in traditional table data. Natural language algorithms are used to extract entity data and entity relationships from multi-source enhanced data. Entity data includes customer entities, counterparty entities, and subsidiary entities. Customer entities include personal / corporate IDs, surnames, and other related entities. The transaction counterparty entity includes the payee ID parsed from the transfer record, distinguishing between personal accounts, corporate accounts, and public accounts (such as platform merchants); the affiliated entities include device ID, IP address, and geographic location (such as province / city / district); the entity relationship includes transfer relationship, device applicability relationship, and regional relationship, among which the transfer relationship includes attributes marked as directed edges (payer → payee), attached amount, timestamp, etc.; the device applicability relationship includes customer → use → device, recording login time and operation type (such as transfer / query); the regional relationship includes customer → location → address, which is used to analyze spatiotemporal behavior (such as the separation of office and transaction location).

[0045] Specifically, in order to eliminate duplicate and ambiguous data in data silos, it is necessary to align entity data. For example, for individual customers, cross-verification is performed through ID number + mobile phone number + device fingerprint to match the same person in different data sources (such as customers in the transaction system and credit report); for corporate customers, the unified social credit code + legal person name + equity structure is used to align the business entities in the industrial and commercial data and transaction data, and then give the graph structure business meaning. The entity alignment data is determined as node features, such as node features including customers (ID, risk score, industry classification, registration place), bank accounts (account number, opening bank, balance, transaction frequency), transaction devices (IP address, device model, login time distribution), Geographic location (GPS coordinates, address type (residential / office)), edge features include transfer (amount, timestamp, transaction channel, remarks), shareholding / position (shareholding ratio, position type, term of office), shared equipment / address (length of co-location, equipment active period), guarantee association (guarantee amount, effective date, guarantee type), then a heterogeneous network graph is constructed based on node features and edge features, that is, using an attribute graph model (such as Neo4j), nodes contain type labels and attribute dictionaries, edges contain type labels and directions, thereby integrating multi-source data such as transactions, equipment, and credit information to form a 360-degree view of the customer, solving the one-sidedness of a single data source (for example, only looking at the transaction flow cannot discover the risk of equipment sharing).

[0046] Furthermore, transaction detection improves detection efficiency and accuracy by focusing on specific scenarios and narrowing the analysis scope to local features related to the needs through sub-graph mode.

[0047] For example, multi-source data association analysis can be used to screen abnormal customers in the hospital. The structured data includes the patient's hospitalization time, such as 15 consecutive days of hospitalization but only 3 test reports, drug consumption records, and fluctuations in medical insurance reimbursement amounts; unstructured data includes medical record text, impact data, hospitalization behavior data, etc., and a patient-doctor-pharmacy-drug association map is constructed to identify abnormal associations.

[0048] In addition, cross-border e-commerce platforms can jointly identify abnormal payment customers with banks. Structured data includes the splitting of single transaction amounts, high-frequency transactions at night, and sensitive countries of counterparties. Unstructured data includes text data. Behaviors that deviate far from normal transaction patterns, the relationship network of related enterprises, shareholders, suppliers, and logistics providers can be identified. It is discovered that companies engage in abnormal transaction behaviors through multi-layer nested related-party circular transfers.

[0049] S2. Extracting subgraph patterns in the heterogeneous network graph according to preset transaction detection requirements, and extracting text semantic features and image features corresponding to the subgraph patterns.

[0050] In an embodiment of the present invention, the subgraph pattern is a local structure composed of specific nodes and edges extracted from a heterogeneous network graph, reflecting a specific relationship combination between entities. In transaction detection, the subgraph pattern usually corresponds to preset risk characteristics (such as closed-loop funds, multi-layer transfers, intensive transactions within the community, etc.).

[0051] In an embodiment of the present invention, extracting a subgraph pattern from the heterogeneous network graph according to a preset transaction detection requirement includes:

[0052] Extracting key demand words from the transaction detection demand;

[0053] Matching the key demand words with the entity data nodes in the heterogeneous network graph to obtain matching nodes;

[0054] Determining matching edges in the heterogeneous network graph according to the matching nodes;

[0055] A subgraph pattern in the heterogeneous network is determined according to the matching nodes and the matching edges.

[0056] In detail, first, natural language processing (NLP) is performed on the text of the transaction detection requirements. Through word segmentation, part-of-speech tagging, keyword extraction and other technologies, core entities, attributes or behavioral keywords are identified. If the detection requirement is to identify abnormal capital loops between a customer and related companies, key demand words may include customer name, related companies, fund transfers, time ranges, etc., and then the extracted key demand words are matched with the nodes (entities) in the heterogeneous network graph to filter out qualified nodes. Matching nodes can be retrieved by node attributes. Based on the identified matching nodes, the edges (entity relationships) connected to them are retrieved to filter out edges that meet the detection requirements, such as edge type, transfer, guarantee, equity association, etc.; edge attributes, transaction amount, timestamp, transfer frequency, etc. If the detection requirement focuses on high-frequency transfers in a short period of time, the matching edges must meet the transfer type and the transaction time must be within the specified time window and the frequency must exceed the threshold.

[0057] Specifically, matching nodes and their associated matching edges are combined into a subgraph. This subgraph is a subgraph pattern that meets the transaction detection requirements. The subgraph pattern includes a node set: target customers, counterparties, related entities, etc.; an edge set: transaction relationships between nodes, time series, amount flows, etc. For example, a bidirectional edge subgraph containing customer A→supplier B (transfer 1 million, 2025-05-01) and supplier B→customer A (transfer 800,000, 2025-05-05) may reflect an abnormal capital loop.

[0058] Furthermore, the data in the sub-graph pattern usually contains multimodal information such as text (such as transaction descriptions) and images (such as certificates). Single-modal analysis is difficult to fully capture risk characteristics, and it is necessary to analyze the multimodal features in the sub-graph pattern.

[0059] In an embodiment of the present invention, the text semantic features refer to the semantic information implicit in text data, which is converted into a structured vector representation through natural language processing technology to reflect the deep meaning of the text, such as the theme, emotion, entity relationship, etc.; the image features refer to the visual features extracted from image data, which are used to describe the content, style or structure of the image, including color, texture, shape, object category, etc.

[0060] In the embodiment of the present invention, referring to Figure 3 As shown, the extracting of text semantic features and image features corresponding to the sub-image pattern includes:

[0061] S31, extracting text data and image data in the sub-image pattern;

[0062] S32, determining a text theme according to the entity data in the text data, and determining a text semantic feature corresponding to the subgraph pattern according to the text theme;

[0063] S33: Identify the color features and background features of the image data, and determine the image features corresponding to the sub-image pattern according to the color features and the background features.

[0064] In detail, text data comes from the attribute fields of subgraph nodes or edges, such as customer name, counterparty description, transaction notes, contract text, log records and other structured or unstructured texts. For example, the attributes of node enterprise A include business scope: technology product research and development, and the attributes of edge transfer include transaction remarks: equipment purchase payment; image data comes from document images uploaded by customers (such as ID cards, business licenses), transaction-related bill images (such as invoices, checks) or corporate logos and related scene images crawled from the web, such as business execution scans associated with corporate nodes, customer portrait images, etc. The text data and image data in the subgraph model can be obtained through computer statements with data capture functions.

[0065] Specifically, the text data is preprocessed by word segmentation, stop word removal, word frequency statistics, etc., and the topic model (such as LDA, BERTopic) is used to identify the core topics. For example, the words such as raw materials, imports, and exchange rates appear frequently in the transaction notes text. The theme can be summarized as cross-border raw material procurement, and then the text is converted into a semantic vector that can be understood by the computer to reflect the deep meaning of the text, such as sensitive keywords in customer service recordings; the OpenCV library is used to extract the RGB histogram and HSV color space distribution of the image data, and the statistical characteristics of the image such as color distribution, main color, color contrast, etc. are analyzed. For example, the business license image is blue, The primary color is white, and invoice images may contain red seal areas. The system also identifies scenes, objects, or texture patterns in the image, such as the background texture, watermark, and border style of the document. For example, the background of an ID card image contains the Great Wall pattern and a grid texture, and the background of a business license may contain a company registration code background. Convolutional neural networks (CNNs) such as ResNet and YOLO are used to perform target detection and feature extraction on the image, identifying fixed elements or abnormal areas in the background. For example, equipment purchases in the text may correspond to normal transactions, but the supplier name on the invoice in the image is inconsistent with the company name in the text, which may reveal the risk of counterfeit bills.

[0066] Furthermore, structured (transaction flow) + unstructured (text, voice) + graph data (transaction network) are jointly modeled, thereby fusion of data to reduce the risk of misjudgment of a single modality.

[0067] S3. Fusing the text semantic features and the image features to obtain target fusion features, and analyzing abnormal patterns corresponding to the target fusion features using a preset time series.

[0068] In an embodiment of the present invention, the target fusion feature is a comprehensive feature representation obtained by fusing text semantic features with image features, integrating complementary information of cross-modal data to form a more comprehensive description of the sub-graph pattern.

[0069] In detail, text and image data are merged at the raw data level. For example, the text embedding vector and the image feature vector are spliced ​​into a single feature vector, such as the BERT vector (768 dimensions) of the customer contract text and the ResNet feature vector (2048 dimensions) of the contract attachment image are spliced ​​into a 2816-dimensional fusion vector, or independent models are trained for text and images respectively, and then the prediction results (such as anomaly scores) are fused through weighted averaging, voting mechanisms, etc. For example, the text model outputs an anomaly probability of 0.8, the image model output is 0.6, and the fusion probability is 0.7 (weighted average), thereby obtaining the fused features.

[0070] Furthermore, it is impossible to distinguish normal business clusters from abnormal clusters by only looking at the network structure at a certain point in time (such as community density and loop existence). By analyzing how characteristics change over time (such as a sudden expansion of community size and a sudden shortening of loop period), the dynamic evolution of risks can be identified.

[0071] In an embodiment of the present invention, the abnormal pattern refers to capturing patterns such as community aggregation and capital loops in a transaction network. Community aggregation occurs in a normal transaction network, where the connection between customers and counterparties should be based on real business needs (such as suppliers and customers), and the community structure is loose and has industry attributes. The abnormal manifestation is that non-industry-related entities (such as cross-sector enterprises and individuals) form a close community, and the transaction frequency / amount within the community far exceeds the normal market level. It may be an abnormal network (dispersing funds through related entities) or a false trade network (falsifying transactions through closed-loop transactions). The capital loop is unidirectional in normal capital flow (such as payment of goods and salary distribution), and the loop is mostly the result of accidental or long-term cooperation (such as two-way transactions between upstream and downstream of the supply chain). The abnormal manifestation is the formation of a closed loop in a short period of time (such as 1-3 days), and the transactions within the loop have no actual business support (such as the transaction note is current account, but there is no contract / invoice matching), which may be self-financing and self-use (funds flow out of the account and return through multiple layers of circulation) or shell arbitrage (avoiding supervision through third-party accounts).

[0072] In the embodiment of the present invention, referring to Figure 4 As shown, the abnormal pattern corresponding to the target fusion feature is analyzed using a preset time series, including:

[0073] S41, analyzing the time series fluctuation characteristics of the target fusion feature according to the time series;

[0074] S42, extracting community-level features and loop features of the target fusion features;

[0075] S43. Analyzing the community feature score of the community-level feature according to the time series fluctuation feature, and analyzing the loop feature score of the loop feature;

[0076] S44. Determine an abnormal pattern corresponding to the target fusion feature according to the community feature score and the loop feature score.

[0077] Specifically, time series fluctuation characteristics refer to the dynamic patterns of changes in target fusion features over time, including trends (such as continuous rise / fall of eigenvalues), periodicity (such as patterns that repeat on a weekly / monthly basis), mutation points (such as sudden abnormal jumps in eigenvalues), and volatility (such as changes in variance). Time series analysis tools (such as ARIMA and wavelet transform) are used to extract statistics of eigenvalues ​​in the time dimension (such as mean, standard deviation, and autocorrelation coefficient), or short-term / long-term trend differences are calculated through a sliding window. If a customer's fusion eigenvalue increases significantly every Friday in the past three months, it may indicate a regularly occurring abnormal trading pattern.

[0078] Specifically, community-level features refer to the structural features of communities composed of closely connected nodes (such as customers and counterparties) in heterogeneous networks, such as community size (number of nodes), community density (number of edges / maximum possible number of edges), and community centrality (degree of core nodes / betweenness centrality); loop features refer to the closed loop formed by the flow of funds or information in the network, such as the triangular loop of customer A→customer B→customer C→customer A, or multi-level complex loops, with features including loop length (number of edges), loop weight (total transaction amount), and loop cycle (time to complete a cycle). Based on the quantitative assessment of the abnormality of the community structure, the community density is significantly higher than the industry average (for example, the normal community density is 0.3, and the current community density is 0.3). The score is 0.8 in the regional area, which is relatively high. Based on the quantitative assessment of loop structure abnormalities, such as the score of short-cycle loops is higher than that of long-cycle loops, the community characteristic score and the loop characteristic score are integrated to identify two types of core abnormal patterns. When the community characteristic score is greater than the preset community score threshold, the community cluster corresponding to the community-level characteristics is determined to be an abnormal pattern; when the loop characteristic score is greater than the preset loop score threshold, the capital loop corresponding to the loop characteristic is determined to be an abnormal pattern. Community cluster anomaly refers to the existence of non-business-rational close connections in high-density communities (such as high-frequency transfers within a group of related enterprises with no substantive business), and capital loop anomaly refers to short-cycle, high-amount, regular closed-loop transactions (such as self-financing and self-use cycles in fictitious trade).

[0079] For example, a medical relationship network of patients, doctors, pharmacies and testing institutions is constructed. The number of nodes in a patient's community (for example, involving 3 hospitals and 5 pharmacies) and the edge density are as follows: for example, the proportion of internal association operations is 70%, which is much higher than that of similar patient groups. Three days before each follow-up visit, the patient frequently purchases the same type of non-prescribed drugs in different pharmacies, forming a short-cycle behavior loop of pharmacy A→pharmacy B→pharmacy C→follow-up visit. It is comprehensively judged that the patient has two abnormal patterns of excessive medical-related community aggregation and non-compliant medication behavior loop, indicating possible complications or medication compliance problems. For example, in the consumer credit scenario, the community-level feature refers to the user-contact person-consumer merchant network. The number of community nodes in the user's community is 20, the edge density is 0.75, and there is a direct connection with multiple high-risk users. The loop feature refers to the formation of a cycle of user borrowing → consumer merchant consumption → funds flowing back to the associated account → borrowing again.

[0080] Furthermore, in order to ensure the real-time update of multi-source data and provide the latest feature input for anomaly detection, it is necessary to continuously update multi-source data to improve the timeliness and accuracy of transaction network risk detection.

[0081] S4. Use the preset incremental learning to update the multi-source data of the target customer in real time, and update the model parameters of the preset federated learning model based on the updated multi-source data.

[0082] In an embodiment of the present invention, incremental learning is a machine learning method, which uses newly input data to gradually update the model without having to start training from scratch each time. That is, through API interfaces, log systems and other channels, multi-source data of target customers (such as transaction records, social behaviors, device information, etc.) is obtained in real time, and the data is cleaned (noise removal, filling missing values) and converted (normalized, feature encoding) and other preprocessing are performed to ensure that the data format is consistent with historical data. Using a preset incremental learning algorithm (such as online gradient descent, incremental decision tree, etc.), the new data is input into the existing model, the model parameters are gradually adjusted, the understanding of customer characteristics is updated, the updated model output is integrated with the historical data, and stored in the customer data warehouse to form a dynamically updated multi-source data set.

[0083] Furthermore, based on the updated multi-source data, cross-institutional joint training models are conducted to share risk characteristics and prevent data from leaving the domain, thereby protecting sensitive customer information.

[0084] In an embodiment of the present invention, different institutions collaborate to train models without sharing original data. By exchanging model parameters (such as gradients) rather than data, data can be made available but invisible, avoiding cross-regional transmission or leakage of customer data, breaking down data silos, and integrating multi-regional data to improve model accuracy.

[0085] In the embodiment of the present invention, updating the model parameters of the preset federated learning model according to the updated multi-source data includes:

[0086] Generate an update trigger event based on updated multi-source data;

[0087] Generating a training request for a preset federated learning model according to the update trigger event;

[0088] extracting local encrypted data corresponding to different target areas through the training request;

[0089] Using the local encrypted data to train a preset local model to obtain gradient parameters;

[0090] The gradient parameters are fused to obtain a global fusion model, and the global fusion model is determined as an updated federated learning model.

[0091] In detail, when the target customer's multi-source data (such as transaction records, behavior logs, etc.) changes (such as new data, data correction), the changes are automatically detected through preset rules (such as data increment threshold, data update time interval), and an update trigger event is generated. That is, the data warehouse is monitored through a message queue (such as Kafka) or a scheduled task, and the difference between real-time data and historical data is compared to trigger the event notification module. After receiving the update trigger event, the event notification module sends a training request to the federated learning management platform to clarify the training objectives (such as updating model parameters), participants (such as bank branches in different regions) and data scope.

[0092] Specifically, after receiving the training request, each regional node extracts the encrypted original data (such as transaction amount, customer IP address) or pre-processed features (such as transaction frequency, device fingerprint hash value) from the local database according to the data timestamp and range, and uses technologies such as homomorphic encryption and differential privacy to ensure that the data cannot be decrypted during extraction and transmission to meet privacy protection requirements. Each regional node uses local encrypted data to train the local model copy (consistent with the global model structure). The algorithm can be logistic regression, neural network, etc. After training is completed, the local model calculates the gradient value of the model parameter instead of the original data. The gradient parameter only reflects the model update direction and amplitude and does not contain customer sensitive information. Then, each regional node encrypts the gradient parameter and uploads it to the federated learning central server. The central server uses an aggregation algorithm (such as FedAvg) to perform weighted averaging on the gradient to generate a global gradient update value. Based on the global gradient update value, the original global model parameters are updated to generate a global fusion model, which is then sent to each regional node to replace the local model copy, completing a round of training iterations to obtain the updated federated learning model.

[0093] For example, when new patient data is entered into the system, or existing patient data is updated (such as a new examination report or a change in diagnosis results), an update trigger event is generated. Based on the update trigger event, a training request is sent to each hospital node participating in federated learning to clarify the training task and data range. After receiving the training request, each hospital node extracts the local patient encrypted data. For example, a hospital extracts the electronic medical records and examination data of its diabetic patients and encrypts them. The local encrypted data is used to train the preset local model (such as a complication prediction model based on a neural network), and the gradient parameters are calculated. The gradient parameters of each hospital node are uploaded to the central server, and fused through an aggregation algorithm (such as FedAvg) to obtain a global fusion model, which is then sent to each node as an updated federated learning model.

[0094] Furthermore, abnormal behavior often takes the form of patterns like community aggregation and capital circulation, and these patterns evolve over time (e.g., new transaction paths). The updated federated learning model continuously absorbs new data features through incremental learning. Combined with dynamic weight adjustments, it can capture new abnormal patterns in real time, preventing model obsolescence and enabling more accurate risk assessment of target customers.

[0095] S5. Use the updated federated learning model to perform score analysis on the abnormal pattern to obtain a target score for the target customer. When the target score is greater than a preset score threshold, the target customer is determined to be an abnormal customer.

[0096] In the embodiment of the present invention, the target score refers to a quantitative indicator obtained by analyzing the multi-source fusion features (text, image, time series, etc.) of the target customer through a federated learning model and adjusting the weights of the abnormal pattern features.

[0097] In the embodiment of the present invention, the updated federated learning model is used to perform score analysis on the abnormal pattern to obtain the target score of the target customer, including:

[0098] Perform homomorphic encryption on the target fusion features of the target user to obtain the ciphertext feature vector;

[0099] Analyzing the initial score corresponding to the ciphertext feature vector using the updated federated learning model;

[0100] Identifying pattern features corresponding to the abnormal pattern, and adjusting weights in the updated federated learning model according to the pattern features to obtain updated weights;

[0101] The initial score is updated according to the updated weight to obtain the target score of the target customer.

[0102] In detail, the target fusion features (fused data containing text semantics and image features) must first be homomorphically encrypted, and the original data can be input into the federated learning model for analysis without decryption, ensuring that user privacy data is not leaked during transmission and calculation; the updated federated learning model has optimized parameters through incremental training of multi-source data. After receiving the ciphertext feature vector, the model outputs an initial score through linear transformation and nonlinear activation of each layer of the neural network (such as convolution and fully connected layers), which is used to quantify the abnormal pattern risk of the target customer (such as the probability of abnormal capital flow).

[0103] Specifically, the key features of abnormal patterns (such as the density of community aggregation in the transaction network, the scale of the capital loop, etc.), namely pattern features, are identified through historical data or expert rules; according to the importance of the pattern features, the corresponding weight parameters in the federated learning model are adjusted (such as increasing the weight coefficient corresponding to the community aggregation feature) to obtain updated weights. By identifying pattern features and adjusting weights in real time, the model can dynamically adapt to changes in risk, avoid detection lags caused by static weights, and use the updated weights to perform weighted calculations on the initial scores to highlight the impact of the key features of the abnormal pattern. For example, if a customer is detected to be involved in a high-density community aggregation transaction, its initial score is 60 points, which may be increased to 80 points after adjustment, intuitively reflecting the change in risk level, and defining risk level labels (high risk / medium risk / low risk) to display key risk factors, such as associating 3 customers on the sanctions list.

[0104] For example, the input data is that customer A has made 20 remittances to high-risk countries in the past three months, with a total amount exceeding US$5 million. Its related customer B was recently included in the abnormal list. The customer service record shows that customer A refused to provide details of the purpose of the remittance (NLP identified it as "fuzzy statement"). Then, graph network features and text features are extracted, and customers A and B form a star-shaped transaction structure, with funds transferred out at multiple levels. Keywords such as "invest in crypto assets" and "no contract required" appear frequently in the conversation records, and GNN detects a circular flow of funds (A→B→C→A). The risk score rises to 92 points (threshold 80), and an early warning report is generated, recommending freezing the account and submitting a transaction report (STR).

[0105] It can be seen that in the above solution, multimodal data fusion and graph neural network technology are introduced through multi-source data of customers to improve the accuracy of identifying high-risk customers; time series-aware graph neural network is introduced to identify abnormal activation of short-term intensive transactions and long-term dormant accounts; differential privacy technology is used to add noise during cross-institutional collaborative training to protect customer sensitive information; based on capital flow and social relationships, the probability of risk diffusion in the transaction network is quantified, thereby solving the technical problem of low accuracy in identifying abnormal customers.

[0106] It should be understood that the size of the serial numbers of the steps in the above embodiments does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.

[0107] In one embodiment, a device for identifying abnormal customers based on multimodal data is provided. The device for identifying abnormal customers based on multimodal data corresponds one-to-one to the method for identifying abnormal customers based on multimodal data in the above embodiment. Figure 5 As shown, the abnormal customer identification device based on multimodal data includes a heterogeneous network graph construction module 101, a feature extraction module 102, an abnormal pattern analysis module 103, a model parameter updating module 104 and an abnormal customer identification module 105. The functional modules are described in detail as follows:

[0108] A heterogeneous network graph construction module 101 is used to collect multi-source data of target customers and construct a heterogeneous network graph corresponding to the target customers based on the multi-source data;

[0109] A feature extraction module 102 is configured to extract subgraph patterns in the heterogeneous network graph according to preset transaction detection requirements, and extract text semantic features and image features corresponding to the subgraph patterns;

[0110] The abnormal pattern analysis module 103 is used to fuse the text semantic features and the image features to obtain a target fusion feature, and analyze the abnormal pattern corresponding to the target fusion feature using a preset time series;

[0111] The model parameter updating module 104 is used to update the multi-source data of the target customer in real time using the preset incremental learning, and to update the model parameters of the preset federated learning model according to the updated multi-source data;

[0112] The abnormal customer identification module 105 is used to use the updated federated learning model to perform score analysis on the abnormal pattern to obtain a target score for the target customer. When the target score is greater than a preset score threshold, the target customer is determined to be an abnormal customer.

[0113] In one embodiment, the heterogeneous network graph construction module 101, when executing the construction of the heterogeneous network graph corresponding to the target customer based on the multi-source data, is configured to:

[0114] Performing data enhancement processing on the multi-source data to obtain multi-source enhanced data;

[0115] Extracting entity data and entity relationships from the multi-source enhanced data;

[0116] Performing data alignment on the entity data to obtain entity-aligned data;

[0117] Determining node features based on the entity alignment data, and determining edge features based on the entity relationships;

[0118] A heterogeneous network graph is constructed based on the node features and the edge features.

[0119] In one embodiment, the feature extraction module 102, when extracting subgraph patterns in the heterogeneous network graph according to a preset transaction detection requirement, is configured to:

[0120] Extracting key demand words from the transaction detection demand;

[0121] Matching the key demand words with the entity data nodes in the heterogeneous network graph to obtain matching nodes;

[0122] Determining matching edges in the heterogeneous network graph according to the matching nodes;

[0123] A subgraph pattern in the heterogeneous network is determined according to the matching nodes and the matching edges.

[0124] In one embodiment, the feature extraction module 102, when extracting the text semantic features and image features corresponding to the sub-image pattern, is further configured to:

[0125] extracting text data and image data in the sub-image pattern;

[0126] Determining a text theme based on entity data in the text data, and determining text semantic features corresponding to the subgraph pattern based on the text theme;

[0127] The color features and background features of the image data are identified, and the image features corresponding to the sub-image pattern are determined according to the color features and the background features.

[0128] In one embodiment, the abnormal pattern analysis module 103, when analyzing the abnormal pattern corresponding to the target fusion feature using a preset time series, is configured to:

[0129] Analyzing the temporal fluctuation characteristics of the target fusion feature according to the time series;

[0130] Extracting community-level features and loop features of the target fusion features;

[0131] Analyzing the community feature score of the community-level feature according to the time series fluctuation feature, and analyzing the loop feature score of the loop feature;

[0132] An abnormal pattern corresponding to a target fusion feature is determined according to the community feature score and the loop feature score.

[0133] In one embodiment, when updating the model parameters of the preset federated learning model based on the updated multi-source data, the model parameter updating module 104 is configured to:

[0134] Generate an update trigger event based on updated multi-source data;

[0135] Generating a training request for a preset federated learning model according to the update trigger event;

[0136] extracting local encrypted data corresponding to different target areas through the training request;

[0137] Using the local encrypted data to train a preset local model to obtain gradient parameters;

[0138] The gradient parameters are fused to obtain a global fusion model, and the global fusion model is determined as an updated federated learning model.

[0139] In one embodiment, the abnormal customer identification module 105, when performing score analysis on the abnormal pattern using the updated federated learning model to obtain the target score of the target customer, is configured to:

[0140] Perform homomorphic encryption on the target fusion features of the target user to obtain the ciphertext feature vector;

[0141] Analyzing the initial score corresponding to the ciphertext feature vector using the updated federated learning model;

[0142] Identifying pattern features corresponding to the abnormal pattern, and adjusting weights in the updated federated learning model according to the pattern features to obtain updated weights;

[0143] The initial score is updated according to the updated weight to obtain the target score of the target customer.

[0144] The present invention provides an abnormal customer identification device based on multimodal data. By introducing multimodal data fusion and graph neural network technology through multi-source data of customers, the accuracy of high-risk customer identification is improved; a time-series-aware graph neural network is introduced to identify abnormal activations of short-term intensive transactions and long-term dormant accounts; differential privacy technology is used to add noise during cross-institutional collaborative training to protect customer sensitive information; based on capital flows and social relationships, the probability of risk diffusion in the transaction network is quantified, thereby solving the technical problem of low accuracy in abnormal customer identification.

[0145] The specific limitations of the device for identifying abnormal customers based on multimodal data can be found in the limitations of the method for identifying abnormal customers based on multimodal data described above and will not be further elaborated here. Each module in the aforementioned device for identifying abnormal customers based on multimodal data can be implemented in whole or in part through software, hardware, or a combination thereof. Each of these modules can be embedded in or independent of a processor in a computer device in hardware form, or stored in a computer device memory in software form, so that the processor can call and execute the corresponding operations of each module.

[0146] In one embodiment, a computer device is provided. The computer device may be a server, and its internal structure diagram may be as follows: Figure 6 As shown. The computer device includes a processor, memory, network interface and database connected via a system bus. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes non-volatile and / or volatile storage media and internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and computer program in the non-volatile storage medium. The network interface of the computer device is used to communicate with an external client via a network connection. When the computer program is executed by the processor, it implements the functions or steps on the server side of an intelligent question-answering processing method based on artificial intelligence.

[0147] In one embodiment, a computer device is provided. The computer device may be a client, and its internal structure diagram may be as follows: Figure 7 As shown. The computer device includes a processor, memory, network interface, display screen, and input device connected via a system bus. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and computer program in the non-volatile storage medium. The network interface of the computer device is used to communicate with an external server via a network connection. When the computer program is executed by the processor, it implements the functions or steps on the client side of an intelligent question-answering processing method based on artificial intelligence.

[0148] In one embodiment, a computer device is provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the following steps are performed:

[0149] Collect multi-source data of target customers, and construct a heterogeneous network graph corresponding to the target customers based on the multi-source data;

[0150] Extracting subgraph patterns in the heterogeneous network graph according to preset transaction detection requirements, and extracting text semantic features and image features corresponding to the subgraph patterns;

[0151] Fusing the text semantic features and the image features to obtain target fusion features, and analyzing abnormal patterns corresponding to the target fusion features using a preset time series;

[0152] Use the preset incremental learning to update the target customer's multi-source data in real time, and update the model parameters of the preset federated learning model based on the updated multi-source data;

[0153] The updated federated learning model is used to perform score analysis on the abnormal pattern to obtain a target score for the target customer. When the target score is greater than a preset score threshold, the target customer is determined to be an abnormal customer.

[0154] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the following steps are implemented:

[0155] Collect multi-source data of target customers, and construct a heterogeneous network graph corresponding to the target customers based on the multi-source data;

[0156] Extracting subgraph patterns in the heterogeneous network graph according to preset transaction detection requirements, and extracting text semantic features and image features corresponding to the subgraph patterns;

[0157] Fusing the text semantic features and the image features to obtain target fusion features, and analyzing abnormal patterns corresponding to the target fusion features using a preset time series;

[0158] Use the preset incremental learning to update the target customer's multi-source data in real time, and update the model parameters of the preset federated learning model based on the updated multi-source data;

[0159] The updated federated learning model is used to perform score analysis on the abnormal pattern to obtain a target score for the target customer. When the target score is greater than a preset score threshold, the target customer is determined to be an abnormal customer.

[0160] It should be noted that the above functions or steps that can be implemented by the computer-readable storage medium or computer device can be found in the relevant descriptions of the server side and the client side in the aforementioned method embodiment. To avoid repetition, they will not be described one by one here.

[0161] Those skilled in the art will appreciate that all or part of the processes in the above-mentioned embodiments can be implemented by instructing the relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to memory, storage, database or other media used in the embodiments provided in this application can include non-volatile and / or volatile memory. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM) or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link (Synchlink) DRAM (SLDRAM), memory bus (Rambus) direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM).

[0162] Those skilled in the art will clearly understand that for the sake of convenience and brevity of description, only the division of the above-mentioned functional units and modules is used as an example. In actual applications, the above-mentioned functions can be distributed and completed by different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above.

[0163] It should be noted that if software tools or components other than those of our company appear in the embodiments of this application, they are only used for illustration and do not represent actual use.

[0164] The embodiments described above are only used to illustrate the technical solutions of the present invention, rather than to limit the same. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. These modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the various embodiments of the present invention, and should all be included in the scope of protection of the present invention.

Claims

1. A method for identifying abnormal customers based on multimodal data, characterized in that: include: Collect multi-source data of target customers, and construct a heterogeneous network graph corresponding to the target customers based on the multi-source data; Extracting subgraph patterns in the heterogeneous network graph according to preset transaction detection requirements, and extracting text semantic features and image features corresponding to the subgraph patterns; Fusing the text semantic features and the image features to obtain target fusion features, and analyzing abnormal patterns corresponding to the target fusion features using a preset time series; Use the preset incremental learning to update the target customer's multi-source data in real time, and update the model parameters of the preset federated learning model based on the updated multi-source data; The updated federated learning model is used to perform score analysis on the abnormal pattern to obtain a target score for the target customer. When the target score is greater than a preset score threshold, the target customer is determined to be an abnormal customer.

2. The abnormal customer identification method based on multimodal data according to claim 1, characterized in that: The step of constructing a heterogeneous network graph corresponding to the target customer based on the multi-source data includes: Performing data enhancement processing on the multi-source data to obtain multi-source enhanced data; Extracting entity data and entity relationships from the multi-source enhanced data; Performing data alignment on the entity data to obtain entity-aligned data; Determining node features based on the entity alignment data, and determining edge features based on the entity relationships; A heterogeneous network graph is constructed based on the node features and the edge features.

3. The abnormal customer identification method based on multimodal data according to claim 1, characterized in that: The extracting of the subgraph pattern in the heterogeneous network graph according to the preset transaction detection requirements includes: Extracting key demand words from the transaction detection demand; Matching the key demand words with the entity data nodes in the heterogeneous network graph to obtain matching nodes; Determining matching edges in the heterogeneous network graph according to the matching nodes; A subgraph pattern in the heterogeneous network is determined according to the matching nodes and the matching edges.

4. The abnormal customer identification method based on multimodal data according to claim 1, characterized in that: The extracting of text semantic features and image features corresponding to the sub-image pattern includes: extracting text data and image data in the sub-image pattern; Determining a text theme based on entity data in the text data, and determining text semantic features corresponding to the subgraph pattern based on the text theme; The color features and background features of the image data are identified, and the image features corresponding to the sub-image pattern are determined according to the color features and the background features.

5. The abnormal customer identification method based on multimodal data according to claim 1, characterized in that: The analyzing the abnormal pattern corresponding to the target fusion feature by using a preset time series includes: Analyzing the temporal fluctuation characteristics of the target fusion feature according to the time series; Extracting community-level features and loop features of the target fusion features; Analyzing the community feature score of the community-level feature according to the time series fluctuation feature, and analyzing the loop feature score of the loop feature; An abnormal pattern corresponding to a target fusion feature is determined according to the community feature score and the loop feature score.

6. The abnormal customer identification method based on multimodal data according to claim 1, characterized in that: The updating of the model parameters of the preset federated learning model according to the updated multi-source data includes: Generate an update trigger event based on updated multi-source data; Generating a training request for a preset federated learning model according to the update trigger event; Extracting local encrypted data corresponding to different target areas through the training request; Using the local encrypted data to train a preset local model to obtain gradient parameters; The gradient parameters are fused to obtain a global fusion model, and the global fusion model is determined as an updated federated learning model.

7. The abnormal customer identification method based on multimodal data according to claim 1, characterized in that: The updated federated learning model is used to perform score analysis on the abnormal pattern to obtain the target score of the target customer, including: Perform homomorphic encryption on the target fusion features of the target user to obtain the ciphertext feature vector; Analyzing the initial score corresponding to the ciphertext feature vector using the updated federated learning model; Identifying pattern features corresponding to the abnormal pattern, and adjusting weights in the updated federated learning model according to the pattern features to obtain updated weights; The initial score is updated according to the updated weight to obtain the target score of the target customer.

8. An abnormal customer identification device based on multimodal data, characterized in that: include: A heterogeneous network graph construction module is used to collect multi-source data of target customers and construct a heterogeneous network graph corresponding to the target customers based on the multi-source data; A feature extraction module, configured to extract subgraph patterns in the heterogeneous network graph according to preset transaction detection requirements, and extract text semantic features and image features corresponding to the subgraph patterns; An abnormal pattern analysis module is used to fuse the text semantic features and the image features to obtain a target fusion feature, and analyze the abnormal pattern corresponding to the target fusion feature using a preset time series; The model parameter update module is used to update the multi-source data of target customers in real time using the preset incremental learning, and to update the model parameters of the preset federated learning model based on the updated multi-source data; The abnormal customer identification module is used to use the updated federated learning model to perform score analysis on the abnormal pattern to obtain a target score for the target customer. When the target score is greater than a preset score threshold, the target customer is determined to be an abnormal customer.

9. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the computer program, the abnormal customer identification method based on multimodal data according to any one of claims 1 to 7 is implemented.

10. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the abnormal customer identification method based on multimodal data according to any one of claims 1 to 7 is implemented.

Citation Information

Cited By

  • Supply chain credible traceability management method, system and terminal

    CN121414380A