Group abnormal transaction identification method and device and electronic equipment
By constructing a transaction graph structure and using graph neural networks and federated clustering methods, combined with homomorphic encryption technology, the problem of low efficiency and inaccuracy in identifying abnormal group transactions in existing technologies is solved, and efficient and accurate abnormal group transaction identification and privacy protection are achieved.
Patent Information
- Application Number
- CN202510622176.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-14
- Publication Date
- 2025-09-19
AI Technical Summary
In the existing technology, the identification of abnormal group transactions is inefficient and inaccurate, and it is difficult to identify complex abnormal group transaction patterns through preset rules and manual analysis.
By processing user account transaction data, building a transaction graph structure, using graph neural network models and federated clustering methods, combined with homomorphic encryption technology, abnormal transactions in user accounts can be identified and group clusters can be formed to protect user privacy.
It achieves efficient and accurate identification of abnormal group transactions while protecting user privacy and improving the efficiency and accuracy of risk management.
Smart Images

Figure CN120672447A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of artificial intelligence, and in particular to a method, device, and electronic device for identifying abnormal group transactions. Background Art
[0002] With the deep integration of finance and the internet, the scale of online payments has expanded, transaction processes have become fragmented, and information has become more complex. During the transaction process, abnormal transactions may occur, resulting in financial losses for users. Therefore, it is necessary to identify abnormal transactions.
[0003] In the existing technology, transaction data in the transaction process under a single user account is first matched based on preset rules to obtain a preliminary matching result. The preliminary matching result indicates whether the user account has any abnormal transactions; then, business personnel manually analyze each user account with abnormal transactions to determine whether there are group abnormal transactions. Among them, group abnormal transactions refer to abnormal transactions that occur when multiple user accounts constitute a group.
[0004] However, the above method first relies on rule matching to determine whether a single user account has any abnormal transactions; and then manually determines whether there are group abnormal transactions. This method is inefficient and inaccurate. Summary of the Invention
[0005] The embodiments of the present application provide a method, device, and electronic device for identifying abnormal group transactions, so as to achieve the effect of accurately and efficiently identifying abnormal group transactions.
[0006] In a first aspect, an embodiment of the present application provides a method for identifying abnormal group transactions, the method being applied to a client; the method comprising:
[0007] Processing the acquired transaction data of the user account to obtain transaction feature data of the user account; the transaction feature data represents the correlation between transaction processes between users;
[0008] The graph convolution layer in the initial graph neural network is processed based on the encrypted gradient value obtained from the server to obtain a graph neural network model; the transaction feature data is processed based on the graph neural network model to obtain an abnormal transaction prediction result for the user account;
[0009] performing clustering processing on each of the user accounts using a federated clustering method based on the transaction feature data of the user accounts to obtain at least one group cluster; wherein the group cluster includes at least one user account;
[0010] The abnormal transaction result of the group cluster is determined according to the abnormal transaction prediction result of each user account in the group cluster.
[0011] In a second aspect, an embodiment of the present application provides a device for identifying abnormal group transactions, the device being applied to a client; the device comprising:
[0012] An acquisition module, configured to process the acquired transaction data of the user account to obtain transaction feature data of the user account; the transaction feature data represents the correlation between the transaction processes between users;
[0013] a processing module, configured to process the graph convolution layer in the initial graph neural network based on the encrypted gradient value obtained from the server to obtain a graph neural network model; and process the transaction feature data based on the graph neural network model to obtain an abnormal transaction prediction result for the user account;
[0014] a clustering module, configured to perform clustering processing on each of the user accounts using a federated clustering method based on the transaction feature data of the user accounts to obtain at least one group cluster; wherein the group cluster includes at least one user account;
[0015] The determination module is configured to determine the abnormal transaction result of the group cluster according to the abnormal transaction prediction result of each user account in the group cluster.
[0016] In a third aspect, an embodiment of the present application provides an electronic device, comprising: a memory, a processor;
[0017] The memory stores computer-executable instructions;
[0018] The processor executes the computer-executable instructions stored in the memory, so that the processor executes the above first aspect and / or various possible implementations of the first aspect.
[0019] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, in which computer-executable instructions are stored. When the computer-executable instructions are executed by a processor, they are used to implement the first aspect above and / or various possible implementation methods of the first aspect.
[0020] In a fifth aspect, an embodiment of the present application provides a computer program product, including a computer program, which, when executed by a processor, implements the above first aspect and / or various possible implementation methods of the first aspect.
[0021] The embodiments of the present application provide a method, apparatus, and electronic device for identifying abnormal group transactions. These methods process acquired transaction data from user accounts to obtain transaction feature data for the user accounts. These transaction feature data represent the correlation between transaction processes between users. Furthermore, the graph convolutional layer in the initial graph neural network is processed based on the encrypted gradient values obtained from the server to obtain an optimized graph neural network model. The transaction feature data is then processed based on this graph neural network model to obtain abnormal transaction prediction results for the user accounts. Furthermore, based on the transaction feature data of the user accounts, each user account is clustered using a federated clustering method to obtain at least one group cluster, each of which includes at least one user account. Finally, based on the abnormal transaction prediction results for each user account in the group cluster, the abnormal transaction results for the group cluster are determined. Through the above-described means, the present application can achieve efficient and accurate identification of abnormal group transactions while protecting user privacy. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.
[0023] Figure 1 A schematic diagram of a method for identifying abnormal group transactions provided in an embodiment of the present application Figure 1 ;
[0024] Figure 2 A schematic diagram of a method for identifying abnormal group transactions provided in an embodiment of the present application Figure 2 ;
[0025] Figure 3 A schematic diagram of the structure of a group abnormal transaction identification device provided in an embodiment of the present application Figure 1 ;
[0026] Figure 4 A schematic diagram of the structure of a group abnormal transaction identification device provided in an embodiment of the present application Figure 2 ;
[0027] Figure 5 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application.
[0028] The above drawings illustrate specific embodiments of the present application, which will be described in more detail below. These drawings and the textual description are not intended to limit the scope of the present application in any way, but rather to illustrate the concepts of the present application to those skilled in the art by reference to specific embodiments. DETAILED DESCRIPTION
[0029] Exemplary embodiments will be described in detail herein, with examples illustrated in the accompanying drawings. In the following description, when referring to the drawings, identical numerals in different figures represent identical or similar elements, unless otherwise indicated. The embodiments described in the following exemplary embodiments are not intended to represent all embodiments consistent with the present application. Rather, they are merely examples of apparatus and methods consistent with certain aspects of the present application, as detailed in the appended claims.
[0030] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, storage, use, processing, transmission, provision, disclosure and application of relevant data comply with the relevant laws, regulations and standards of relevant countries and regions, take necessary confidentiality measures, do not violate public order and good morals, and provide corresponding operation entrances for users to choose to authorize or refuse.
[0031] In addition, this application involves big data analysis of user information (including but not limited to personal biometrics, identity data, consumption data, asset data, electronic terminal operation data, etc.), and the use of artificial intelligence technology for automated decision-making, and a technical solution for making decisions that have a significant impact on personal rights and interests based on the results of automated decision-making. The application provides users with corresponding operation entrances for users to choose to agree or reject the results of automated decision-making; if the user chooses to reject, the expert decision-making process will be entered.
[0032] It should be noted that the method, device, and electronic device for identifying abnormal group transactions provided in this application can be used in the field of artificial intelligence, and can also be used in any field other than artificial intelligence. The application field of the method, device, and electronic device for identifying abnormal group transactions in this application is not limited.
[0033] With the deep integration of finance and the internet, the scale of online payments continues to expand, transaction processes are becoming increasingly fragmented, and information is becoming more complex. This trend has brought many conveniences, but it has also brought new challenges, particularly in terms of transaction security and risk management. Abnormal transactions often occur during the transaction process, which can cause users to suffer financial losses or even trigger financial risks. Therefore, identifying and preventing abnormal transactions has become a critical task for financial institutions and payment platforms.
[0034] In existing technologies, financial institutions or payment platforms develop a series of pre-set rules based on historical data and experience. These rules define the characteristics of normal transactions and the patterns of abnormal transactions. For example, these rules may include transaction amount thresholds, transaction frequency limits, and reasonable transaction times. Transaction data from each user account is then matched against these rules to check whether it complies with the pre-set rules. If the transaction data violates a rule, a preliminary determination is made that the user account has engaged in abnormal transactions. This preliminary matching result only provides information on abnormal transactions for a single user account and cannot directly determine whether there are clustered abnormal transactions. Clustered abnormal transactions refer to abnormal transactions occurring within a group of multiple user accounts, which may involve more complex patterns and associations. Business personnel must manually analyze the preliminary matching results to further confirm whether clustered abnormal transactions exist. This includes examining the transaction relationships and similarities in transaction patterns across multiple user accounts. Through manual analysis, business personnel can ultimately determine whether clustered abnormal transactions exist and take appropriate measures.
[0035] Pre-set rules are typically based on historical data and experience, making it difficult to cover all possible abnormal transaction patterns. New abnormal transaction patterns may not be detected by existing rules, resulting in missed reports. Existing technologies have significant shortcomings in identifying abnormal group transactions. Abnormal transactions in a single user account do not necessarily indicate abnormal group transactions. Abnormal group transactions may involve more complex patterns and associations that are difficult to identify through simple rule matching and manual analysis.
[0036] Therefore, the method, device and electronic device for identifying abnormal group transactions provided by this application can solve the above problems.
[0037] The following specific embodiments describe in detail the technical solution of the present application and how the technical solution of the present application solves the above-mentioned technical problems. The following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The embodiments of the present application will be described below in conjunction with the accompanying drawings.
[0038] Figure 1 A schematic diagram of a method for identifying abnormal group transactions provided in an embodiment of the present application Figure 1 ,like Figure 1 As shown, the method is applied to the client, and the method includes:
[0039] S101. Process the acquired transaction data of the user account to obtain transaction feature data of the user account; the transaction feature data represents the correlation between transaction processes between users.
[0040] For example, the client first collects transaction data from a local database within a predetermined time period. Subsequently, the collected transaction data undergoes data cleaning to ensure data quality and accuracy. Data cleaning primarily involves removing duplicate data, addressing missing values, and handling outliers. Specifically, unique identifiers such as transaction IDs are used to identify and delete duplicate transaction records to ensure data uniqueness. For missing fields, different handling methods are adopted based on the actual situation, such as estimating transaction amounts based on other information, filling default values for non-critical fields, or deleting related records. Furthermore, outliers in the data are identified and addressed, such as correcting or deleting abnormal data such as transactions with negative amounts or large amounts that are clearly illogical.
[0041] After data cleaning, the transaction data undergoes data derivation processing to extract more valuable features. This data derivation processing includes summing numerical data such as transaction amounts to calculate the total transaction amount for each user account within a predetermined time period; calculating the average transaction amount for each user account (i.e., the total transaction amount divided by the number of transactions); and performing other statistical processing, such as calculating the number of transactions, maximum transaction amount, and minimum transaction amount. Through these processes, derived transaction data is obtained.
[0042] Next, a transaction graph is constructed, with user accounts as central nodes and transaction data as connecting edges. If a transaction record exists between two user accounts, an edge is established between the two corresponding nodes. The edge weight can be determined based on factors such as the transaction amount and the number of transactions. For example, the larger the transaction amount or the more transactions, the greater the edge weight. This graph data allows for intuitive visualization of transaction relationships between different users, such as which users frequently transact with each other and which users transact with larger amounts.
[0043] Based on the graph data, an adjacency matrix is constructed, with rows and columns representing different user accounts. Each element in the matrix represents the transaction correlation between two user accounts (e.g., transaction amount, number of transactions, etc.). Finally, transaction data and graph data are derived to form transaction feature data, such as the number of transactions, total transaction amount, average transaction amount, maximum transaction amount, and minimum transaction amount for each user account. This feature data can characterize the correlation between transaction processes between users and provide support for further analysis and application.
[0044] S102. Process the graph convolution layer in the initial graph neural network based on the encrypted gradient value obtained from the server to obtain a graph neural network model; process the transaction feature data based on the graph neural network model to obtain an abnormal transaction prediction result for the user account.
[0045] For example, each client first builds an initial graph neural network (GNN) model consisting of multiple graph convolutional layers to process graph-structured data. A graph convolutional layer aggregates information from neighboring nodes to update the feature representation of the current node. Subsequently, weights are initialized for each graph convolutional layer in the GNN. These initial weights are typically randomly generated and serve as the starting point for model training.
[0046] Next, the client prepares local graph data, which can include transaction relationship graphs between user accounts. This data typically includes node features (such as user attributes) and graph topology (such as transaction relationships between users). The initialized graph neural network model performs forward propagation calculations on the local data. In the graph convolutional layer, each node aggregates and updates information based on the features of its neighboring nodes and the weights of the current layer, resulting in a new node feature representation.
[0047] Next, a loss function is calculated based on the model's output and the true labels of the local data (such as transaction categories). The loss function measures the difference between the model's predictions and the true results. Common loss functions include cross-entropy loss. The gradient of the loss function with respect to the weights of each graph convolutional layer is calculated using the backpropagation algorithm. These gradients reflect the weights' influence on the loss function and are used for subsequent weight updates. Based on the calculated gradients, an optimization algorithm (such as gradient descent) is used to update the weights of each graph convolutional layer. The update formula is: new weight = old weight - learning rate × gradient value. The updated weights become the latest weights of the local model.
[0048] The client then encrypts the calculated weights for each graph convolutional layer and sends them to the server. Encryption ensures data security during transmission and prevents weight leakage. Technologies such as homomorphic encryption can be used to enable the server to calculate the encrypted weights without decrypting them. Multiple clients send their encrypted weights to the same server.
[0049] After receiving the encrypted weights from all clients, the server aggregates them using the Federated Averaging (FedAvg) algorithm. Each client's weight is assigned a weight coefficient based on its data volume or importance, and then a weighted average weight is calculated. The weighted average weight formula is: global weight = Σ(client weight × weight coefficient) / Σ weight coefficient. The weight coefficient can be a ratio of the client's data volume or another indicator reflecting the client's importance. The server then sends the calculated global weight as a gradient value to each client.
[0050] Each client updates the weights of each graph convolutional layer in its local graph neural network model based on the received gradient values. The update formula is: new weight = old weight - learning rate × gradient value. In this way, the client's model weights are updated based on global data without directly sharing local data.
[0051] The above process (from client-side calculation of local weight updates to client-side weight updates) typically needs to be repeated multiple times until the initial graph neural network converges and a graph neural network model is obtained. In each iteration, the client model is updated based on the gradient value, gradually learning more accurate global model features.
[0052] Transaction feature data, encompassing node features for each user account and the graph's topological structure, is fed into the graph neural network model. In the graph convolutional layer of the graph neural network, each node aggregates and updates information based on the features of neighboring nodes and the weights of the current layer. By aggregating neighboring node features, it updates its own feature representation, thereby capturing transaction relationships and local structural information between user accounts. The transaction feature data is then propagated layer by layer through the multi-layer graph convolutional layer, with each layer continuously updating and abstracting node features, gradually extracting higher-level feature representations to more accurately reflect the transaction behavior patterns of user accounts.
[0053] After propagating through multiple layers of graph convolutional layers, transaction feature data reaches the output layer of the graph neural network. This layer is typically a classifier (such as a softmax classifier), which classifies the user account's transaction behavior based on the extracted feature representation and determines whether the transaction is abnormal. The output layer calculates an abnormal transaction prediction result for each user account. This result is a probability value that represents the likelihood that the user account has experienced an abnormal transaction. If the probability value output by the model is higher than a preset threshold (such as 0.5), the user account is judged to have experienced an abnormal transaction; conversely, if the probability value is lower than the threshold, the transaction is considered normal.
[0054] S103 . Cluster each user account using a federated clustering method based on the transaction feature data of the user account to obtain at least one group cluster; wherein the group cluster includes at least one user account.
[0055] For example, the federated clustering method is suitable for distributed data environments, particularly in scenarios where data privacy and security are protected. It allows clients to collaboratively complete clustering tasks without sharing the original data. First, an initial cluster center is determined, either randomly or using a heuristic method (e.g., selecting the farthest data point). This initial cluster center is sent to all clients as the starting point for the clustering algorithm. Each client calculates the Euclidean distance between its local user account transaction feature data and the cluster center, assigning the data to the closest cluster center to form initial clusters. The mean of each cluster is then calculated and encrypted and sent to the server. The server receives the encrypted cluster centers from each client and aggregates them using the Federated Averaging Algorithm (FedAvg). Weight coefficients are assigned based on the amount or importance of each client's data, resulting in a weighted average cluster center calculated using the formula: global cluster center = Σ(client cluster center × weight coefficient) / Σ weight coefficient. The aggregated global cluster center is then broadcast to all clients as the basis for the next round of clustering. Each client repeats the local clustering calculation based on the updated global cluster center, including data point assignment and local cluster center calculation. After each iteration, the algorithm checks whether the change in cluster center is less than a preset threshold or the number of iterations has been reached. If convergence conditions are met, iteration stops; otherwise, it continues. After the clustering algorithm converges, each client assigns local user accounts to corresponding clusters based on the final cluster center, forming the final clusters. Analyzing clusters can reveal transaction patterns of user accounts, such as determining whether some clusters have high transaction frequency, while others are dominated by large transactions.
[0056] S104: Determine the abnormal transaction result of the group cluster based on the abnormal transaction prediction result of each user account in the group cluster.
[0057] Exemplarily, within each cluster, the number of user accounts marked as abnormal transactions is counted, and the proportion of abnormal transaction accounts is calculated. For example, if there are 10 user accounts in a cluster, 6 of which are marked as abnormal transactions, the abnormal proportion of the cluster is 60%. Based on business needs and risk preferences, a cluster abnormality threshold is set. If the abnormality ratio of a cluster exceeds the threshold, the cluster as a whole is considered to have an abnormal transaction risk; otherwise, the cluster transactions are considered normal. For each cluster, its abnormality ratio is compared with the set cluster abnormality threshold. If the abnormality ratio exceeds the threshold, the abnormal transaction result of the cluster is determined to be "abnormal"; otherwise, it is "normal."
[0058] An embodiment of the present application provides a method for identifying abnormal group transactions. This method processes the acquired transaction data of user accounts to obtain transaction feature data for the user accounts. These transaction feature data represent the correlation between transaction processes between users. Furthermore, the graph convolution layer in the initial graph neural network is processed based on the encrypted gradient value obtained from the server to obtain an optimized graph neural network model. Based on this graph neural network model, the transaction feature data is processed to obtain abnormal transaction prediction results for the user accounts. Furthermore, based on the transaction feature data of the user accounts, each user account is clustered using a federated clustering method to obtain at least one group cluster, wherein each group cluster includes at least one user account. Finally, based on the abnormal transaction prediction results for each user account in the group cluster, the abnormal transaction results for the group cluster are determined. Through the above-mentioned means, the present application can achieve efficient and accurate identification of abnormal group transactions while protecting user privacy.
[0059] Figure 2 A schematic diagram of a method for identifying abnormal group transactions provided in an embodiment of the present application Figure 2 ,like Figure 2 As shown, this embodiment Figure 1 Based on the embodiment, a method for identifying abnormal group transactions is described in detail. The method includes:
[0060] S201. Preprocess the transaction data of the user account to obtain first transaction data; determine the transaction graph structure based on the first transaction data, with the user account as the node and the transaction data as the connecting edge; determine the adjacency matrix and degree matrix based on the transaction graph structure; wherein the adjacency matrix represents the connection relationship between the nodes; and the degree matrix represents the number of connections between each node; concatenate the first transaction data, the adjacency matrix, and the degree matrix to obtain transaction feature data.
[0061] For example, first, the transaction data is preprocessed to obtain the first transaction data. Data preprocessing includes, but is not limited to, missing data supplementation, abnormal data processing, noise elimination, and data derivative processing. For missing data, appropriate methods are selected based on the specific circumstances. For example, missing age information can be supplemented with the average age, and missing transaction amounts can be estimated by referring to the amounts of similar transactions. In terms of abnormal data processing, if the transaction amount is negative or illogically large, it can be corrected or deleted based on the actual situation. Noise elimination aims to eliminate duplicate transaction records or irrelevant data points in the data to improve data quality. Data derivative processing expands some of the transaction data to generate derivative features such as transfer-in / transfer-out amount / number, transaction channel, average daily transaction amount, and number / amount of overnight transactions, in order to more comprehensively present the user's transaction behavior patterns.
[0062] Subsequently, a graph structure is constructed based on the first transaction data. Each user account is used as a node, and transaction data (such as contact address, method, transaction IP, and transaction MAC) is used as a connecting edge to realize heterogeneous associations between different user accounts. The weights of the edges with the same contact address, method, transaction IP, and transaction MAC correspond to the number of contact addresses, methods, transaction IPs, and transaction MACs shared by the two user accounts. The weights of each edge between the two nodes are normalized (for example, using maximum-minimum normalization to scale the weights to the range of 0-1), and then summed up to obtain weighted edges. The graph structure data thus generated can reflect the transaction relationship and association strength between user accounts.
[0063] Based on the graph structure data, the adjacency matrix and degree matrix are determined. The adjacency matrix is a square matrix, whose rows and columns correspond to the nodes (user accounts) in the graph, and the matrix elements represent the connection relationship between the nodes. If there is a connecting edge between two nodes, the corresponding matrix element value is the weight of the edge; otherwise, the element value is 0. The adjacency matrix is used to characterize the connection relationship between nodes. The degree matrix is a diagonal matrix, and the diagonal elements represent the degree of each node, that is, the number of connections between the node and other nodes. The off-diagonal elements are 0, and the diagonal element values correspond to the degree of the node. The degree matrix represents the number of connections between each node.
[0064] Finally, the primary transaction data, adjacency matrix, and degree matrix are concatenated to form transaction feature data. The primary transaction data encompasses various transaction behavior characteristics and customer information of user accounts, while the adjacency matrix and degree matrix reflect the transaction relationships and correlation strengths between user accounts. By concatenating these data, we can comprehensively consider the characteristics of user accounts, their position in the transaction network, and their relationships, providing more comprehensive feature data for subsequent analysis and modeling.
[0065] S202. Process the graph convolution layer in the initial graph neural network according to the encrypted gradient value obtained from the server to obtain a graph neural network model.
[0066] For example, this step may refer to the above-mentioned step S102 and will not be described in detail.
[0067] In one example, the following steps are repeatedly performed until a first preset iteration condition is obtained:
[0068] Send transaction feature data to the server; the transaction feature data is used to process the transaction feature data and the i-1th weight matrix based on the federated averaging algorithm to obtain the encrypted i-th gradient value;
[0069] The server receives the encrypted i-th gradient value sent by the server; decrypts the encrypted i-th gradient value, and determines the i-th weight matrix in combination with the i-1-th weight matrix stored by the client;
[0070] According to the i-th weight matrix, determine the i-th graph convolution layer; wherein the first weight matrix in the first graph convolution layer is randomly generated by the client; i is a positive integer greater than or equal to 2; and determine the value of i plus 1;
[0071] Among them, each graph convolution layer obtained when the first preset iteration condition is reached is used to determine the graph neural network model.
[0072] Exemplarily, the first weight matrix W1 in the first graph convolution layer of the graph neural network model is randomly generated by the client;
[0073] The client sends the transaction feature data to the server using homomorphic encryption. Homomorphic encryption ensures the security of the data during transmission.
[0074] The server determines the i-th gradient value based on the data volume of each client and the i-1-th weight matrix; the calculation formula is:
[0075]
[0076] Where ΔW i Represents the i-th gradient value; M n The data volume representing the transaction feature data of the nth client; M represents the data volume of the transaction feature data of all clients; W i-1 Represents the i-1th weight matrix; i is a positive integer greater than or equal to 2; W1 is randomly generated by the client.
[0077] Each client receives the encrypted i-th gradient value sent by the server, decrypts it, and obtains the plaintext gradient value. The client combines the decrypted i-th gradient value with the locally stored i-1th weight matrix W i-1 , use the gradient descent method to update the weight matrix and obtain the i-th weight matrix; the calculation formula is:
[0078] W i =W i-1 -αΔW i
[0079] Among them, W i Represents the i-th weight matrix; W i-1 represents the i-1th weight matrix; α represents the learning rate; ΔW i Represents the i-th gradient value.
[0080] According to the i-th weight matrix, determine the i-th graph convolution layer.
[0081] Repeat the above steps until the preset iteration condition is reached. The iteration condition can be reaching the maximum number of iterations or the change in the weight matrix is less than a certain threshold.
[0082] If the iteration conditions are met, the iteration is stopped and the final graph neural network model is obtained.
[0083] S203: Process the transaction feature data based on the graph neural network model to obtain abnormal transaction prediction results of the user account.
[0084] For example, this step may refer to the above-mentioned step S103 and will not be described in detail.
[0085] In one example, transaction feature data is input into a graph neural network, and the first-layer graph convolutional layer in the graph neural network processes the transaction feature data to obtain the first-layer node feature matrix;
[0086] Repeat the following steps until the second preset iteration condition is obtained: process the node feature matrix of layer j-1 with the j-th graph convolution layer in the graph neural network to obtain the node feature matrix of layer j; input the node feature matrix of layer j into the j+1-th graph convolution layer for convolution processing to obtain the node feature matrix of layer j+1; where j is a positive integer greater than or equal to 2; and determine the value of j plus 1;
[0087] Among them, the last layer of node feature matrix and graph neural network obtained when the second preset iteration condition is reached are used to determine the abnormal transaction prediction results of the user account.
[0088] Exemplarily, the transaction feature data is input into the graph neural network, and the transaction feature data is processed by the first graph convolution layer in the graph neural network to obtain the first-layer node feature matrix;
[0089] Repeat the following steps until the second preset iteration condition is obtained: the j-1 layer node feature matrix is processed by the j-th layer graph convolution layer in the graph neural network to obtain the j-th layer node feature matrix; the calculation formula is:
[0090]
[0091] Among them, H j Represents the feature matrix of the j-th layer node; σ represents the nonlinear activation function, such as RELU, Sigmoid, etc.; The representation is a diagonal matrix consisting of the inverse of the square roots of the diagonal elements of the degree matrix D; A is the adjacency matrix, I is the identity matrix; H j-1 W represents the feature matrix of the nodes in the j-1th layer; i Represents the jth weight matrix;
[0092] The node feature matrix of the jth layer is input into the j+1th layer graph convolution layer for convolution processing to obtain the node feature matrix of the j+1th layer; the calculation formula is:
[0093]
[0094] Among them, H j+1 Represents the feature matrix of the j+1th layer node; σ represents the nonlinear activation function, such as RELU, Sigmoid, etc. The representation is a diagonal matrix consisting of the inverse of the square roots of the diagonal elements of the degree matrix D; A is the adjacency matrix, I is the identity matrix; H j W represents the feature matrix of the j-th layer node; j+1 Represents the j+1th weight matrix;
[0095] Wherein, j is a positive integer greater than or equal to 2; and the value of j is determined to be plus 1 for loop;
[0096] After each iteration, it is checked whether the second preset iteration condition is met. For example, when the maximum number of iterations T is reached or the change of the node feature matrix is less than a certain threshold, the iteration is stopped.
[0097] When the second preset iteration condition is met, the last layer node feature matrix H is obtained L , where L is the number of layers of the graph neural network. The last layer node feature matrix H L , which is input into the output layer of the graph neural network (typically a classifier such as a softmax classifier). The output layer calculates a prediction of abnormal transactions for each user account. The prediction result is a probability value, indicating the likelihood of an abnormal transaction occurring in the user account. If the probability value output by the model is greater than a preset threshold (such as 0.5), the user account is considered to have experienced abnormal transactions; otherwise, the transaction is considered normal.
[0098] In one example, the obtained last-layer node feature matrix is processed according to the preset function in the graph neural network to obtain the abnormal transaction prediction results of the user account.
[0099] For example, the last layer node feature matrix H L Input into the preset function. The preset function is usually a classifier, such as the softmax classifier; the calculation formula is:
[0100] Z=softmax(H L )
[0101] Based on the output probability of the preset function, the abnormal transaction prediction result of each user account is determined. Usually, a threshold θ (such as 0.5) is set. If the predicted probability is greater than the threshold, the user account is considered to have abnormal transactions; otherwise, the transaction is considered normal.
[0102] S204 : Clustering each user account using a federated clustering method based on the transaction feature data of the user account to obtain at least one group cluster.
[0103] For example, this step may refer to the above-mentioned step S104 and will not be described in detail.
[0104] In one example, the following steps are repeated until the third preset condition is met; wherein the initial cluster center is randomly generated by the server:
[0105] For each cluster center, the transaction feature data is clustered based on the Euclidean distance between the transaction feature data and each cluster center to obtain each initial group cluster; the total number of cluster centers is T, where T is a positive integer greater than or equal to 2, and each initial group cluster includes at least one user account;
[0106] Perform feature summation processing on the transaction feature data of each user account in the initial group cluster to obtain the feature sum of the initial group cluster;
[0107] Using homomorphic encryption, the number of user accounts and the sum of features in the initial group cluster are sent to the server. The server is used to calculate the mean of the sum of features of the kth initial group cluster sent by each client based on the sum of the number of user accounts in the kth initial group cluster sent by each client, to obtain the kth group cluster mean, where the total number of group cluster means is T. The server then sends the T group cluster means to the client.
[0108] Decrypt the T group cluster means to obtain the decrypted T group cluster means;
[0109] Determine the decrypted T group cluster means as the new T cluster centers;
[0110] When the third preset condition is met, each of the obtained initial group clusters is at least one group cluster.
[0111] For example, in federated clustering, data is distributed across multiple clients, with each client processing only its local data. Clients do not directly share data, but rather collaborate on clustering tasks by sharing model parameters or clustering results. Federated clustering is an iterative process. In each iteration, the client updates its local model based on the global model and then sends the updated model parameters back to the server. The server aggregates these updates again to generate a new global model. This process repeats until the preset iteration conditions are met.
[0112] The server randomly generates T initial cluster centers, where T is the total number of cluster centers and T ≥ 2. These initial cluster centers serve as the starting points for the clustering algorithm. The server transmits these encrypted initial cluster centers to all clients. Each client calculates the Euclidean distance between its local transaction feature data and each cluster center based on the received cluster centers.
[0113] The transaction feature data of each user account is assigned to the nearest cluster center to form initial clusters, ensuring that each initial cluster contains at least one user account. Subsequently, the transaction feature data of the user accounts in each initial cluster is summed to obtain the sum of the features of each initial cluster.
[0114] The client uses homomorphic encryption to encrypt the number of user accounts and the sum of features in each initial cluster and sends the encrypted number of user accounts and sum of features to the server. After receiving the encrypted number of user accounts and sum of features from all clients, the server calculates the mean of the sum of features of the kth initial cluster sent by each client, based on the sum of the number of user accounts in the kth initial cluster sent by each client. This calculates the mean of the kth cluster, with a total number of cluster means T. The server then sends these T cluster means to all clients.
[0115] After receiving the T group cluster means, the client decrypts them to obtain the decrypted T group cluster means, and determines the decrypted T group cluster means as the new T cluster centers.
[0116] Repeat the above steps until a third pre-determined condition is met. This pre-determined condition can be a maximum number of iterations or a change in the cluster mean value that is less than a certain threshold. Once the pre-determined condition is met, iteration stops, and the resulting initial clusters become the final clusters.
[0117] S205 . Determine an abnormal transaction density value of the cluster based on the abnormal transaction prediction results of the user accounts in the cluster; if the abnormal transaction density value of the cluster is greater than or equal to a preset threshold, determine the cluster as an abnormal transaction cluster.
[0118] For example, based on the output of the graph neural network model, we obtain predictions for abnormal transactions for each user account. These predictions are probabilities, indicating the likelihood of abnormal transactions occurring in that user account. A threshold θ (e.g., 0.5) is set. If the predicted probability of abnormal transactions for a user account is greater than θ, the account is marked as an abnormal transaction account.
[0119] For each cluster, calculate the proportion of abnormal transaction accounts, i.e. the abnormal transaction density value. The specific formula is:
[0120]
[0121] A preset threshold, τ, is set to determine whether a cluster is an abnormal trading group. The abnormal trading density value of each cluster is compared with the preset threshold, τ. If the abnormal trading density value of a cluster is greater than or equal to τ, the cluster is determined to be an abnormal trading group; otherwise, the cluster is considered to be a normal trading group.
[0122] For example, there are 100 user accounts in cluster C1, 30 of which are marked as abnormal transaction accounts; there are 200 user accounts in cluster C2, 40 of which are marked as abnormal transaction accounts. The preset threshold τ=0.25.
[0123] Calculate the abnormal transaction density values of the two clusters; for cluster C1: abnormal transaction density 1 = 30 / 100 = 0.3; for cluster C2: abnormal transaction density 2 = 40 / 200 = 0.2;
[0124] Because 0.3>0.25, cluster C1 is determined to be an abnormal transaction group; because 0.2<0.25, cluster C2 is determined to be an abnormal transaction group.
[0125] Through the above steps, we can effectively determine the abnormal transaction density of a cluster based on the abnormal transaction prediction results of user accounts in the cluster, and determine whether the cluster is an abnormal trading group. This method can help institutions promptly detect and address potential abnormal trading behavior, improving the efficiency and accuracy of risk management.
[0126] An embodiment of the present application provides a method for identifying abnormal group transactions. The method constructs a transaction graph structure by preprocessing user account transaction data, extracts the adjacency matrix and the degree matrix, and splices them into transaction feature data; utilizes the server encryption gradient value and the federated averaging algorithm to iteratively optimize the graph neural network model weights to determine the final model; processes the transaction feature data based on the model, and obtains the node feature matrix by layer-by-layer convolution to generate abnormal transaction prediction results; at the same time, adopts the federated clustering method in combination with the homomorphic encryption technology to iteratively update the cluster center while protecting privacy and determine the group cluster; finally, based on the abnormal transaction prediction results within the group cluster, calculates the abnormal transaction density value and identifies the abnormal transaction group. On the basis of ensuring the privacy and security of user data, the abnormal transaction behavior of the group is accurately and efficiently identified. Through the combination of federated learning and homomorphic encryption technology, the accuracy and efficiency of abnormal transaction identification are effectively improved, while reducing the risk of data leakage, which helps to maintain the stability and security of the financial market.
[0127] Figure 3 A schematic diagram of the structure of a group abnormal transaction identification device provided in an embodiment of the present application Figure 1 ,like Figure 3As shown, the present embodiment provides a group abnormal transaction identification device 30 applied to a client, comprising:
[0128] The acquisition module 301 is used to process the acquired transaction data of the user account to obtain transaction feature data of the user account; the transaction feature data represents the correlation between the transaction processes between users;
[0129] Processing module 302 is configured to process the graph convolution layer in the initial graph neural network based on the encrypted gradient value obtained from the server to obtain a graph neural network model; and process the transaction feature data based on the graph neural network model to obtain abnormal transaction prediction results for the user account;
[0130] Clustering module 303, configured to perform clustering processing on each user account using a federated clustering method based on the transaction feature data of the user account to obtain at least one group cluster; wherein the group cluster includes at least one user account;
[0131] The determination module 304 is configured to determine the abnormal transaction result of the group cluster based on the abnormal transaction prediction result of each user account in the group cluster.
[0132] This embodiment provides a device for identifying abnormal group transactions, which can execute the method provided in the above method embodiment. Its implementation principle and technical effects are similar, and are not described in detail in this embodiment.
[0133] Figure 4 A schematic diagram of the structure of a group abnormal transaction identification device provided in an embodiment of the present application Figure 2 ,like Figure 4 As shown, the present embodiment provides a group abnormal transaction identification device 40 applied to a client, comprising:
[0134] The acquisition module 401 is used to process the acquired transaction data of the user account to obtain transaction feature data of the user account; the transaction feature data represents the correlation between the transaction processes between users;
[0135] Processing module 402 is configured to process the graph convolution layer in the initial graph neural network based on the encrypted gradient value obtained from the server to obtain a graph neural network model; and process the transaction feature data based on the graph neural network model to obtain an abnormal transaction prediction result for the user account;
[0136] Clustering module 403, configured to perform clustering processing on each user account using a federated clustering method based on the transaction feature data of the user account to obtain at least one group cluster; wherein the group cluster includes at least one user account;
[0137] The determination module 404 is configured to determine the abnormal transaction result of the group cluster based on the abnormal transaction prediction result of each user account in the group cluster.
[0138] In a possible implementation, the acquisition module 401 includes:
[0139] Performing data preprocessing on the transaction data of the user account to obtain first transaction data;
[0140] Determine a transaction graph structure based on the first transaction data, with user accounts as nodes and transaction data as connecting edges;
[0141] Based on the transaction graph structure, the adjacency matrix and degree matrix are determined. The adjacency matrix represents the connection relationship between nodes, and the degree matrix represents the number of connections between each node.
[0142] The first transaction data, the adjacency matrix, and the degree matrix are concatenated to obtain transaction feature data.
[0143] In a possible implementation, the processing module 402 includes:
[0144] Repeat the following steps until the first preset iteration condition is obtained:
[0145] Send transaction feature data to the server; the transaction feature data is used to process the transaction feature data and the i-1th weight matrix based on the federated averaging algorithm to obtain the encrypted i-th gradient value;
[0146] The server receives the encrypted i-th gradient value sent by the server; decrypts the encrypted i-th gradient value, and determines the i-th weight matrix in combination with the i-1-th weight matrix stored by the client;
[0147] According to the i-th weight matrix, determine the i-th graph convolution layer; wherein the first weight matrix in the first graph convolution layer is randomly generated by the client; i is a positive integer greater than or equal to 2; and determine the value of i plus 1;
[0148] Among them, each graph convolution layer obtained when the first preset iteration condition is reached is used to determine the graph neural network model.
[0149] In a possible implementation, the processing module 402 further includes:
[0150] The transaction feature data is input into the graph neural network and processed by the first graph convolution layer in the graph neural network to obtain the first-layer node feature matrix;
[0151] Repeat the following steps until the second preset iteration condition is obtained: process the node feature matrix of layer j-1 with the j-th graph convolution layer in the graph neural network to obtain the node feature matrix of layer j; input the node feature matrix of layer j into the j+1-th graph convolution layer for convolution processing to obtain the node feature matrix of layer j+1; where j is a positive integer greater than or equal to 2; and determine the value of j plus 1;
[0152] Among them, the last layer of node feature matrix and graph neural network obtained when the second preset iteration condition is reached are used to determine the abnormal transaction prediction results of the user account.
[0153] In a possible implementation, the processing module 402 further includes:
[0154] According to the preset function in the graph neural network, the obtained last layer node feature matrix is processed to obtain the abnormal transaction prediction results of the user account.
[0155] In a possible implementation, the clustering module 403 includes:
[0156] Repeat the following steps until the third preset condition is met; wherein the initial cluster center is randomly generated by the server:
[0157] For each cluster center, the transaction feature data is clustered based on the Euclidean distance between the transaction feature data and each cluster center to obtain each initial group cluster; the total number of cluster centers is T, where T is a positive integer greater than or equal to 2, and each initial group cluster includes at least one user account;
[0158] Perform feature summation processing on the transaction feature data of each user account in the initial group cluster to obtain the feature sum of the initial group cluster;
[0159] Using homomorphic encryption, the number of user accounts and the sum of features in the initial group cluster are sent to the server. The server is used to calculate the mean of the sum of features of the kth initial group cluster sent by each client based on the sum of the number of user accounts in the kth initial group cluster sent by each client, to obtain the kth group cluster mean, where the total number of group cluster means is T. The server then sends the T group cluster means to the client.
[0160] Decrypt the T group cluster means to obtain the decrypted T group cluster means;
[0161] Determine the decrypted T group cluster means as the new T cluster centers;
[0162] When the third preset condition is met, each of the obtained initial group clusters is at least one group cluster.
[0163] In a possible implementation, the determining module 404 includes:
[0164] Determine the abnormal transaction density value of the group cluster based on the abnormal transaction prediction results of the user accounts in the group cluster;
[0165] If the abnormal transaction density value of the group cluster is greater than or equal to a preset threshold, the group cluster is determined to be an abnormal transaction group.
[0166] This embodiment provides a device for identifying abnormal group transactions, which can execute the method provided in the above method embodiment. Its implementation principle and technical effects are similar, and are not described in detail in this embodiment.
[0167] Figure 5 This is a schematic diagram of the structure of the electronic device provided in the embodiment of the present application. Figure 5 As shown, the electronic device 50 provided in this embodiment includes: at least one processor 501 and a memory 502. Optionally, the device 50 further includes a communication component 503. The processor 501, the memory 502 and the communication component 503 are connected via a bus 504.
[0168] In a specific implementation process, at least one processor 501 executes the computer-executable instructions stored in the memory 502, so that the at least one processor 501 performs the above method.
[0169] The specific implementation process of the processor 501 can be found in the above method embodiment. Its implementation principle and technical effects are similar and will not be repeated here in this embodiment.
[0170] In the above embodiments, it should be understood that the processor may be a central processing unit (CPU), other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), etc. A general-purpose processor may be a microprocessor or any conventional processor. The steps of the method disclosed in the present invention may be directly implemented by a hardware processor or implemented by a combination of hardware and software modules in the processor.
[0171] The memory may include a high-speed memory (Random Access Memory, RAM), and may also include a non-volatile memory (NVM), such as at least one disk memory.
[0172] The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus. Buses can be classified into address buses, data buses, and control buses. For ease of illustration, the buses in the drawings of this application are not limited to just one bus or just one type of bus.
[0173] The present application also provides a computer program product, including a computer program, which implements the above method when executed by a processor.
[0174] The present application also provides a computer-readable storage medium, in which computer-executable instructions are stored. When a processor executes the computer-executable instructions, the above method is implemented.
[0175] The above-mentioned readable storage medium can be implemented by any type of volatile or non-volatile memory device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, magnetic disk or optical disk. The readable storage medium can be any available medium that can be accessed by a general-purpose or special-purpose computer.
[0176] An exemplary readable storage medium is coupled to a processor so that the processor can read information from the readable storage medium and write information to the readable storage medium. Of course, the readable storage medium can also be an integral part of the processor. The processor and the readable storage medium can be located in an application specific integrated circuit (ASIC). Of course, the processor and the readable storage medium can also exist in the device as discrete components.
[0177] The division of units is merely a logical functional division; actual implementations may employ alternative divisions, such as combining or integrating multiple units or components into another system, or omitting or disabling certain features. Furthermore, any direct coupling or communication connection shown or discussed may be an indirect coupling or communication connection between devices or units, either through an interface, electrical, mechanical, or other means.
[0178] Units described as separate components may or may not be physically separate, and components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.
[0179] In addition, each functional unit in each embodiment of the present invention may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.
[0180] If the function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the various embodiments of the present invention. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), disk or optical disk, and other media that can store program code.
[0181] Those skilled in the art will appreciate that all or part of the steps in the above-described method embodiments can be implemented using hardware associated with program instructions. The aforementioned program can be stored in a computer-readable storage medium. When executed, the program performs the steps of the above-described method embodiments. The aforementioned storage medium includes various media capable of storing program code, such as ROM, RAM, magnetic disks, or optical disks.
[0182] Finally, it should be noted that those skilled in the art will readily identify other embodiments of the present invention after considering the specification and practicing the invention disclosed herein. The present invention is intended to cover any variations, uses, or adaptations of the present invention that follow the general principles of the present invention and include common knowledge or customary techniques in the art not disclosed herein. The present invention is not limited to the precise structure described above and illustrated in the accompanying drawings, and various modifications and variations may be made without departing from the scope thereof. The scope of the present invention is limited solely by the appended claims.
Claims
1. A method for identifying abnormal group transactions, characterized in that: The method is applied to a client; the method comprises: Processing the acquired transaction data of the user account to obtain transaction feature data of the user account; the transaction feature data represents the correlation between transaction processes between users; The graph convolution layer in the initial graph neural network is processed based on the encrypted gradient value obtained from the server to obtain a graph neural network model; the transaction feature data is processed based on the graph neural network model to obtain an abnormal transaction prediction result for the user account; performing clustering processing on each of the user accounts using a federated clustering method based on the transaction feature data of the user accounts to obtain at least one group cluster; wherein the group cluster includes at least one user account; The abnormal transaction result of the group cluster is determined according to the abnormal transaction prediction result of each user account in the group cluster.
2. The method according to claim 1, characterized in that The acquired transaction data of the user account is processed to obtain transaction feature data of the user account, including: Performing data preprocessing on the transaction data of the user account to obtain first transaction data; Determine a transaction graph structure based on the first transaction data, with the user accounts as nodes and the transaction data as connecting edges; Determine an adjacency matrix and a degree matrix based on the transaction graph structure; wherein the adjacency matrix represents the connection relationship between nodes; and the degree matrix represents the number of connections between each node; The first transaction data, the adjacency matrix, and the degree matrix are concatenated to obtain the transaction feature data.
3. The method according to claim 1, characterized in that Processing the graph convolution layer in the initial graph neural network according to the encrypted gradient value obtained from the server to obtain a graph neural network model, the method comprising: Repeat the following steps until the first preset iteration condition is obtained: Sending the transaction feature data to the server; the transaction feature data is used to process the transaction feature data and the (i-1)th weight matrix based on the federated averaging algorithm to obtain an encrypted (i)th gradient value; Receiving the encrypted i-th gradient value sent by the server; decrypting the encrypted i-th gradient value, and determining the i-th weight matrix in combination with the i-1-th weight matrix stored in the client; According to the i-th weight matrix, determine the i-th graph convolution layer; wherein the first weight matrix in the first graph convolution layer is randomly generated by the client; i is a positive integer greater than or equal to 2; and determine the value of i plus 1; Among them, each graph convolution layer obtained when the first preset iteration condition is reached is used to determine the graph neural network model.
4. The method according to claim 1, wherein The transaction feature data is processed based on the graph neural network model to obtain abnormal transaction prediction results of the user account, including: Inputting the transaction feature data into the graph neural network, processing the transaction feature data with the first graph convolution layer in the graph neural network to obtain a first-layer node feature matrix; Repeat the following steps until a second preset iteration condition is obtained: process the j-1 layer node feature matrix with the j-th layer graph convolution layer in the graph neural network to obtain the j-th layer node feature matrix; input the j-th layer node feature matrix into the j+1 layer graph convolution layer for convolution processing to obtain the j+1 layer node feature matrix; wherein j is a positive integer greater than or equal to 2; and determine the value of j plus 1; Among them, the last layer node feature matrix and the graph neural network obtained when the second preset iteration condition is reached are used to determine the abnormal transaction prediction result of the user account.
5. The method according to claim 4, characterized in that The method further comprises: According to the preset function in the graph neural network, the obtained last layer node feature matrix is processed to obtain the abnormal transaction prediction result of the user account.
6. The method according to claim 1, characterized in that Based on the transaction feature data of the user accounts, clustering is performed on each of the user accounts using a federated clustering method to obtain at least one group cluster, including: Repeat the following steps until the third preset condition is met; wherein the initial cluster center is randomly generated by the server: For each cluster center, clustering the transaction feature data based on the Euclidean distance between the transaction feature data and each cluster center to obtain each initial group cluster; the total number of cluster centers is T, where T is a positive integer greater than or equal to 2, and the initial group cluster includes at least one user account; Performing feature summation processing on the transaction feature data of each user account in the initial group cluster to obtain the feature sum of the initial group cluster; Using homomorphic encryption, the number of user accounts and the sum of features in the initial group cluster are sent to the server; the server is configured to perform mean calculation processing on the sum of features of the kth initial group cluster sent by each client based on the sum of the number of user accounts in the kth initial group cluster sent by each client, to obtain the kth group cluster mean, where the total number of group cluster means is T; and the server is configured to send the T group cluster means to the client; Decrypt the T group cluster means to obtain the decrypted T group cluster means; Determine the decrypted T group cluster means as the new T cluster centers; When the third preset condition is met, the obtained initial group clusters are the at least one group cluster.
7. The method according to any one of claims 1 to 6, characterized in that Determining abnormal transaction results of the group cluster according to abnormal transaction prediction results of user accounts in the group cluster includes: Determining an abnormal transaction density value of the group cluster based on abnormal transaction prediction results of user accounts in the group cluster; If the abnormal transaction density value of the group cluster is greater than or equal to a preset threshold, the group cluster is determined to be an abnormal transaction group.
8. A device for identifying abnormal group transactions, characterized in that: The device is applied to a client; the device includes: An acquisition module, configured to process the acquired transaction data of the user account to obtain transaction feature data of the user account; the transaction feature data represents the correlation between the transaction processes between users; a processing module, configured to process the graph convolution layer in the initial graph neural network based on the encrypted gradient value obtained from the server to obtain a graph neural network model; and process the transaction feature data based on the graph neural network model to obtain an abnormal transaction prediction result for the user account; a clustering module, configured to perform clustering processing on each of the user accounts using a federated clustering method based on the transaction feature data of the user accounts to obtain at least one group cluster; wherein the group cluster includes at least one user account; The determination module is configured to determine the abnormal transaction result of the group cluster according to the abnormal transaction prediction result of each user account in the group cluster.
9. An electronic device, characterized in that: include: Memory, processor; The memory stores computer-executable instructions; The processor executes the computer-executable instructions stored in the memory, so that the processor performs the method according to any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer-executable instructions, which are used to implement the method according to any one of claims 1 to 7 when executed by a processor.