Financial transaction risk rapid identification system and method based on real-time data flow
Through a financial transaction risk identification system based on real-time data streams, using technologies such as multi-source data collection and streaming computing engines, real-time risk identification and dynamic adjustment are achieved, solving the problems of real-time risk identification and insufficient data integration in traditional methods, and improving the accuracy of risk identification and system adaptability.
Patent Information
- Application Number
- CN202510707771.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-29
- Publication Date
- 2025-09-19
AI Technical Summary
Traditional financial transaction risk identification methods are unable to detect potential risks in real time during the transaction process. They lack the ability to integrate multi-source heterogeneous data and efficiently process real-time data streams, resulting in an inability to respond quickly after a risk event occurs.
A rapid identification system for financial transaction risks based on real-time data streams is designed, including data acquisition, preprocessing, real-time stream processing, risk identification and decision-making, as well as visualization and storage modules. Through multi-source heterogeneous data acquisition, streaming computing engine, machine learning model and graph computing module, real-time risk identification and dynamic threshold adjustment are achieved.
It has achieved a transition from post-event review to pre-event warning and in-event intervention, which can timely detect potential risks, improve the comprehensiveness and accuracy of risk identification, reduce losses from risk events, enhance the adaptability and compliance of the system, and reduce manual monitoring costs.
Smart Images

Figure CN120672346A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of financial services, and in particular to a system and method for quickly identifying financial transaction risks based on real-time data streams. Background Art
[0002] With the rapid development of financial markets and the continuous expansion of transaction scale, the complexity and risks of financial transactions are also increasing. Traditional financial transaction risk identification methods are mainly based on post-event data statistics and analysis, which makes it difficult to timely detect potential risks in the real-time process of transactions. As a result, they cannot respond quickly after risk events occur, which may cause huge losses to financial institutions and investors. For example, in the existing technology, some risk identification systems can only analyze a single type of transaction data, cannot integrate multi-source heterogeneous data, and lack the ability to efficiently process real-time data streams and dynamically assess risks. They are difficult to adapt to the real-time and complexity requirements of the financial market. Therefore, the present invention proposes a financial transaction risk rapid identification system and method based on real-time data streams to solve the problems of poor real-time performance, insufficient data integration capabilities, and insufficient dynamic and efficient risk assessment of traditional risk identification methods proposed in the above background technology. Summary of the Invention
[0003] The present invention provides a system and method for quickly identifying financial transaction risks based on real-time data streams to solve the problems raised in the above background technology.
[0004] In order to solve the above technical problems, the technical solution adopted by the present invention is:
[0005] First, a rapid identification system for financial transaction risks based on real-time data streams includes a data acquisition module, a data preprocessing module, a real-time stream processing module, a risk identification and decision-making module, and a visualization and storage module.
[0006] A further improvement of the technical solution of the present invention is that: the data acquisition module is used to obtain real-time transaction data, market data and external data from multiple data sources, wherein the real-time transaction data acquisition module collects market transaction data, order data price, quantity and counterparty; the market data acquisition module collects real-time market quotes and market depth, and the external data acquisition module collects macroeconomic indicators, news and public opinion, regulatory announcements, and social media sentiment. The module obtains data through an API interface, a message queue RabbitMQ or a streaming data protocol WebSocket, and supports multi-source heterogeneous data access, including structured data, semi-structured data and unstructured data.
[0007] A further improvement of the technical solution of the present invention is that the data preprocessing module is used to clean and standardize the collected data and perform feature engineering processing. In terms of cleaning and standardization, outliers are filtered, missing values are filled, data formats are unified, timestamps are standardized, and currency units are converted. In terms of feature engineering processing, time series features are extracted, such as sliding window statistics, including mean, standard deviation, volatility, order bid-ask spread and depth slope, and derivative indicators are constructed, such as transaction frequency and proportion of large orders.
[0008] A further improvement of the technical solution of the present invention is that: the real-time stream processing module adopts a streaming computing engine module, and the real-time stream processing module includes a real-time rule engine module, a machine learning model inference module and a graph computing module, supports millisecond-level delay processing, processes disordered data based on event time, and ensures time series consistency. The real-time rule engine module predefines risk rules, such as a single transaction amount exceeding a threshold, high-frequency trading detection, and cross-market arbitrage patterns. The machine learning model inference module deploys a trained real-time risk identification model to detect time series anomalies or related risks. The graph computing module constructs a relationship diagram of transaction entities, such as a network of customers, accounts and counterparties, calculates node correlation in real time, and identifies money laundering and related transaction risks.
[0009] A further improvement of the technical solution of the present invention is that the risk identification and decision-making module includes a risk classification module and a decision engine module, and the risk classification module includes market risk, credit risk, operational risk and compliance risk.
[0010] A further improvement to the technical solution of the present invention is that: market risk refers to the risk of position loss caused by sharp price fluctuations; credit risk refers to the possibility of counterparty default, which is assessed through a real-time credit scoring model; operational risk refers to abnormal trading patterns; the decision engine module triggers multi-level warnings based on the risk scores output by the rules and models, such as freezing transactions, restricting positions, and notifying the compliance department.
[0011] A further improvement to the technical solution of the present invention is that the visualization and storage module includes a real-time monitoring module and a data storage module. The real-time monitoring module uses a real-time monitoring large screen to display key indicators. The data storage is used to store real-time data in a time series database or an in-memory database, and to archive historical data to a distributed file system or a data lake for model training and retrospective analysis.
[0012] Secondly, the identification method of the financial transaction risk rapid identification system based on real-time data stream is as follows;
[0013] S1: Data Collection: The data collection module obtains real-time transaction data, market data and external data from various data sources;
[0014] S2: Data preprocessing: Use the data preprocessing module to clean and standardize the collected data by filtering outliers, filling missing values, and unifying the data format. Then, perform feature engineering to extract time series features and construct derived indicators.
[0015] S3: Real-time stream processing: The pre-processed data is fed into the real-time stream processing module and processed using the stream computing engine module. The real-time rule engine module matches pre-defined risk rules, and the model in the machine learning model inference module is used to detect time series anomalies or associated risks. The graph computing module constructs a transaction entity relationship graph and calculates node correlation to identify potential risks.
[0016] S4: Risk Identification and Decision-making: The risk identification and decision-making module classifies transaction risks based on the output of the real-time stream processing module, triggers multi-level warnings based on the risk scores output by rules and models, and automatically executes corresponding risk control actions;
[0017] S5: Visualization and Storage: The real-time monitoring module of the visualization and storage module uses a real-time monitoring screen to display key indicators and transaction network maps, realizing visual monitoring of risks. The real-time data and historical data are stored in the corresponding database and file system respectively for subsequent model training and retrospective analysis.
[0018] Due to the adoption of the above technical solution, the present invention has the following technical advancements compared to the prior art:
[0019] 1. This invention provides a system and method for rapidly identifying financial transaction risks based on real-time data streams. This system shifts from post-event review to pre-event warning and in-process intervention. It can promptly identify potential risks during transactions, mitigating losses from risk events. By collecting and processing multi-source heterogeneous data in real time, it integrates various types of transaction information and external influencing factors, improving the comprehensiveness and accuracy of risk identification.
[0020] 2. The present invention provides a system and method for rapid identification of financial transaction risks based on real-time data streams. By utilizing a streaming computing engine module and advanced machine learning models and graph neural networks, it can efficiently process real-time data streams, capture long-term dependencies in time series and correlations between transaction entities, and effectively identify new and complex risk patterns, such as money laundering, related-party transactions, and market manipulation, thereby enhancing the system's generalized risk identification capabilities.
[0021] 3. The present invention provides a system and method for rapid identification of financial transaction risks based on real-time data streams. The system has dynamic threshold adjustment and online learning functions, and can automatically optimize risk identification strategies and model parameters according to market changes and historical data, thereby improving the adaptability and accuracy of the system. At the same time, the visualization and storage modules provide strong support for risk monitoring and subsequent analysis, facilitating risk control and compliance management for financial institutions, enhancing compliance, reducing the risk of compliance penalties, and automated processing reducing manual monitoring costs and optimizing business efficiency. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] Figure 1 This is a schematic diagram of the architecture of a system for rapidly identifying financial transaction risks based on real-time data streams according to the present invention;
[0023] Figure 2 Schematic diagram of the workflow of the data acquisition module of the present invention;
[0024] Figure 3 Schematic diagram of the workflow of the data preprocessing module of the present invention;
[0025] Figure 4 Schematic diagram of the working principle of the real-time stream processing module of the present invention;
[0026] Figure 5 This is a schematic diagram of the risk identification and decision-making module workflow of the present invention;
[0027] Figure 6 This is a schematic diagram of the classification of the visualization and storage modules of the present invention.
[0028] In the figure: 1. Data acquisition module; 2. Data preprocessing module; 3. Real-time stream processing module; 4. Risk identification and decision-making module; 5. Visualization and storage module; 6. Real-time transaction data acquisition module; 7. Market data acquisition module; 8. External data acquisition module; 9. Cleaning and standardization processing; 10. Feature engineering processing; 11. Streaming computing engine module; 12. Real-time rule engine module; 13. Machine learning model inference module; 14. Graph computing module; 15. Risk classification module; 16. Decision engine module; 17. Real-time monitoring module; 18. Data storage module. DETAILED DESCRIPTION
[0029] The present invention is described in further detail below in conjunction with the embodiments:
[0030] Example 1
[0031] like Figure 1-6As shown, the present invention provides a system and method for quickly identifying financial transaction risks based on real-time data streams, including a data acquisition module 1, a data preprocessing module 2, a real-time stream processing module 3, a risk identification and decision module 4, and a visualization and storage module 5.
[0032] Furthermore, the data collection module 1 is used to obtain real-time transaction data collection module 6, market data collection module 7 and external data collection module 8 from multiple data sources, wherein the real-time transaction data collection module 6 collects the market's transaction data, order data price, quantity and counterparty; the market data collection module 7 collects real-time market quotes and market depth, and the external data collection module 8 collects macroeconomic indicators, news and public opinion, regulatory announcements, and social media sentiment. This module obtains data through API interface, message queue RabbitMQ or streaming data protocol WebSocket, and supports multi-source heterogeneous data access, including structured data, semi-structured data and unstructured data.
[0033] The data preprocessing module 2 is used to clean and standardize the collected data 9 and perform feature engineering 10. In terms of cleaning and standardization, it filters outliers, fills missing values, unifies data formats, standardizes timestamps, and converts currency units. In terms of feature engineering, it extracts time series features such as sliding window statistics, which include mean, standard deviation, volatility, order bid-ask spread, and depth slope, and constructs derivative indicators such as transaction frequency and proportion of large orders.
[0034] The real-time stream processing module 3 adopts a streaming computing engine module 11. The real-time stream processing module 3 includes a real-time rule engine module 12, a machine learning model inference module 13 and a graph computing module 14. It supports millisecond-level delay processing, processes disordered data based on event time, and ensures time series consistency. The real-time rule engine module 12 predefines risk rules, such as a single transaction amount exceeding a threshold, high-frequency trading detection, and cross-market arbitrage patterns. The machine learning model inference module deploys a trained real-time risk identification model to detect time series anomalies or related risks. The graph computing module constructs a relationship graph of transaction entities, such as a network of customers, accounts, and counterparties, calculates node correlation in real time, and identifies money laundering and related transaction risks. In the real-time stream processing module 3, the streaming computing engine module 11 adopts an "event-driven" architecture. Data continuously enters the system in the form of streams, without the need for batch processing. The statistical values of the sliding window are stored through the RocksDB state backend to ensure the accuracy and efficiency of the calculation.
[0035] The risk identification and decision-making module 4 includes a risk classification module 15 and a decision engine module 16. The risk classification module 15 classifies market risk, credit risk, operational risk and compliance risk. Market risk refers to the risk of position loss caused by sharp price fluctuations. Credit risk refers to the possibility of counterparty default, which is evaluated through a real-time credit scoring model. Operational risk refers to abnormal trading patterns. The decision engine module 16 triggers multi-level warnings based on the risk scores output by rules and models, such as freezing transactions, restricting positions, and notifying compliance departments. In the risk identification and decision-making module 4, the decision engine module 16 dynamically adjusts the risk rule threshold of "single transaction amount exceeds threshold" based on the percentile of historical data. For example, during holidays when the market fluctuates greatly, the threshold is automatically increased by 10% to adapt to changes in market conditions. At the same time, the risk labels after manual review are used to conduct online learning of the machine learning model, update model parameters, and improve the recognition accuracy of the model.
[0036] The visualization and storage module 5 includes a real-time monitoring module 17 and a data storage module 18. The real-time monitoring module 17 uses a real-time monitoring screen to display key indicators. The data storage module 18 is used to store real-time data in a time series database or an in-memory database, and archive historical data to a distributed file system or a data lake for model training and retrospective analysis. The real-time monitoring screen of the visualization and storage module 5 is used to display the real-time number of risk events and high-risk account information. Real-time data is stored in InfluxDB, and historical data is archived in HDFS.
[0037] The following describes in detail the working principles of the system and method for rapid identification of financial transaction risks based on real-time data streams.
[0038] like Figure 1-6 As shown, the data acquisition module 1 continuously acquires real-time data from multiple sources. After cleaning and feature extraction by the data preprocessing module 2, the data is input into the real-time stream processing module 3. The real-time stream processing module 3 uses the streaming computing engine module 11 to process the data in real time. Combined with the real-time rule engine module 12, the machine learning model inference module 13, and the graph computing module 14, it identifies risks through multiple dimensions such as rule matching, time series anomaly detection, and transaction network analysis. The risk identification and decision module 4 classifies and makes decisions based on the identification results, triggering corresponding warnings and control actions. The visualization and storage module 5 implements real-time visual monitoring of risks and data storage, providing support for risk management and control. The entire system forms a closed loop, and through real-time data processing and dynamic model optimization, it can achieve rapid identification and effective control of financial transaction risks.
[0039] The above generally describes the present invention in detail. However, it is obvious to those skilled in the art that modifications or improvements may be made based on the present invention. Therefore, modifications or improvements that do not depart from the spirit of the present invention are within the scope of protection of the present invention.
Claims
1. A financial transaction risk rapid identification system based on real-time data streams, comprising a data acquisition module (1), a data preprocessing module (2), a real-time stream processing module (3), a risk identification and decision-making module (4), and a visualization and storage module (5).
2. The system for rapid identification of financial transaction risks based on real-time data streams according to claim 1 is characterized by: The data acquisition module (1) is used to obtain a real-time transaction data acquisition module (6), a market data acquisition module (7) and an external data acquisition module (8) from multiple data sources, wherein the real-time transaction data acquisition module (6) collects market transaction data, order data price, quantity and transaction counterparty; the market data acquisition module (7) collects real-time market quotes and market depth; the external data acquisition module (8) collects macroeconomic indicators, news and public opinion, regulatory announcements, and social media sentiment. The module obtains data through an API interface, a message queue RabbitMQ or a streaming data protocol WebSocket, and supports multi-source heterogeneous data access, including structured data, semi-structured data and unstructured data.
3. The financial transaction risk rapid identification system based on real-time data stream according to claim 1 is characterized by: The data preprocessing module (2) is used to clean and standardize the collected data (9) and perform feature engineering processing (10). In terms of cleaning and standardization, it filters outliers, fills missing values, unifies data formats, standardizes timestamps and converts currency units. In terms of feature engineering processing, it extracts time series features.
4. The system for rapid identification of financial transaction risks based on real-time data streams according to claim 1 is characterized in that: The real-time stream processing module (3) adopts a stream computing engine module (11). The real-time stream processing module (3) includes a real-time rule engine module (12), a machine learning model inference module (13) and a graph computing module (14). The module supports millisecond-level delay processing and processes disordered data based on event time to ensure time sequence consistency. The real-time rule engine module predefines risk rules, wherein the machine learning model inference module deploys a trained real-time risk identification model for detecting time sequence anomalies or associated risks, and the graph computing module constructs a transaction subject relationship diagram.
5. The system for rapid identification of financial transaction risks based on real-time data streams according to claim 1 is characterized in that: The risk identification and decision module (4) includes a risk classification module (15) and a decision engine module (16), wherein the risk classification module (15) classifies market risk, credit risk, operational risk and compliance risk.
6. The system for rapid identification of financial transaction risks based on real-time data streams according to claim 1 is characterized in that: Market risk refers to the risk of position loss due to sharp price fluctuations, credit risk refers to the possibility of counterparty default, which is assessed through a real-time credit scoring model, and operational risk refers to abnormal trading patterns. The decision engine module (16) triggers multi-level warnings based on the risk scores output by the rules and models.
7. The financial transaction risk rapid identification system based on real-time data stream according to claim 1 is characterized by: The visualization and storage module (5) includes a real-time monitoring module (17) and a data storage module (18). The real-time monitoring module (17) uses a real-time monitoring large screen to display key indicators. The data storage module (18) is used to store real-time data in a time series database or a memory database, and to archive historical data to a distributed file system or a data lake for model training and retrospective analysis.
8. Based on the financial transaction risk rapid identification system based on real-time data stream according to any one of claims 1 to 7, an identification method for the financial transaction risk rapid identification system based on real-time data stream is proposed, characterized in that: The identification method is as follows; S1: Data Collection: Obtain real-time transaction data, market data and external data from various data sources through the data collection module (1); S2: Data preprocessing: Use the data preprocessing module (2) to clean and standardize the collected data; S3: Real-time stream processing: The pre-processed data is input into the real-time stream processing module (3) and processed using the stream computing engine module; S4: Risk Identification and Decision-making: The risk identification and decision-making module (4) classifies transaction risks based on the output results of the real-time stream processing module; S5: Visualization and storage: The real-time monitoring module of the visualization and storage module (5) uses a real-time monitoring large screen to display key indicators and transaction network maps, thereby realizing visual monitoring of risks.