Early warning method, device, equipment, medium and product

By receiving prompt information from the resource platform, determining the match between the resource quantity and available quantity of the candidate flow event, and generating early warning information, it solves the early warning problem of inconsistent usage descriptions in resource flow, and realizes real-time and accurate resource flow monitoring and cross-platform coverage.

CN120689995APending Publication Date: 2025-09-23INDUSTRIAL AND COMMERCIAL BANK OF CHINA
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510989743.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-17
Publication Date
2025-09-23

AI Technical Summary

Technical Problem

When resources flow in a resource account, it is difficult to determine whether the flow direction of resources provided by the resource platform is consistent with the usage description, which makes early warning difficult. Especially in the case of multiple transfers in and out with different purposes, it is even more difficult to issue early warning when the resource flow direction is inconsistent with the usage description.

Method used

By receiving prompt information from the resource platform, the candidate resource accounts and flow events into which the target resources flow are determined. From the aggregated set of resource flow events, it is judged whether the number of resources flowing to the preset field by the candidate flow events matches the available quantity. An early warning message is generated to indicate the handling of inconsistent flow events.

Benefits of technology

It achieves real-time and accurate resource flow monitoring, reduces the difficulty of warning resource flows with inconsistent usage descriptions, improves the detection speed and robustness of the warning process, has a wider coverage, and supports cross-platform warnings.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120689995A_ABST
    Figure CN120689995A_ABST
Patent Text Reader

Abstract

The invention provides an early warning method, device and equipment, a medium and a product, and relates to the field of financial science and technology or other related fields. The method comprises the following steps: receiving prompt information sent by a first resource platform, wherein the prompt information is used for indicating that a target resource flows out from the first resource platform; determining a candidate resource account into which the target resource flows and a candidate flow event out of which the resource flows from the candidate resource account from an event set for converging resource flow events of a plurality of resource platforms; determining the number of resources flowing to a preset field from the candidate flow event, and determining the available amount of resources flowing to the preset field in the candidate resource account before the candidate flow event occurs; and under the condition that the resource quantity is not matched with the available resource quantity, generating early warning information containing the candidate circulation event, and sending the early warning information to the first resource platform. The product provided by the invention can reduce the difficulty of early warning of the resource flow direction.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of financial technology or other related fields, and in particular to an early warning method, device, equipment, medium and product. Background Art

[0002] To promote the efficient use of resources such as data and funds and support the development of resource demanders, the resource platform provides various resource transfer services to resource demanders upon their request. Typically, when the resource platform transfers resources to a resource account, it includes a usage statement that limits the scope of use of the transferred resources. When resources are transferred between resource accounts, resource transfer information can be monitored to prevent discrepancies between the flow of resources and the usage statement.

[0003] The resources stored in a resource account can be complex. For example, they can be resources from the resource platform or resources deposited by the enterprise or individual corresponding to the resource account. Resource transfer events vary in type and volume. If resources are transferred in and out of a resource account multiple times for different purposes, the account's resources from the resource platform and its own resources can become mixed. It can be difficult to distinguish whether the flow of resources provided by the resource platform is consistent with the usage description, making it difficult to issue early warnings for resource flows that are inconsistent with the usage description. Summary of the Invention

[0004] The present application provides an early warning method, apparatus, equipment, medium and product to reduce the difficulty of issuing early warnings for resource flows that are inconsistent with usage descriptions.

[0005] In a first aspect, the present application provides an early warning method, comprising:

[0006] receiving prompt information sent by the first resource platform, the prompt information being used to indicate that target resources flow out of the first resource platform, the prompt information including a target domain to which the target resources may flow;

[0007] Determine, from an event set of resource flow events aggregated from multiple resource platforms, a candidate resource account into which the target resource flows and a candidate flow event from which resources flow out of the candidate resource account;

[0008] Determine the amount of resources that flow to a preset domain as a result of the candidate transfer event, and determine the available amount of resources that can flow to the preset domain in the candidate resource account before the candidate transfer event occurs, where the preset domain is a domain other than the target domain;

[0009] In the case where the resource quantity and the available resource quantity do not match, warning information including the candidate flow event is generated and sent to the first resource platform, wherein the warning information is used to instruct the handling of the candidate flow event.

[0010] In a second aspect, the present application provides an early warning device, comprising:

[0011] An information module, configured to receive prompt information sent by the first resource platform, wherein the prompt information is used to indicate that target resources flow out of the first resource platform, and the prompt information includes a target domain to which the target resources can flow;

[0012] An event module, configured to determine, from an event set of resource flow events aggregated from multiple resource platforms, candidate resource accounts into which the target resource flows and candidate flow events from which resources flow out of the candidate resource accounts;

[0013] a quantity module, configured to determine the quantity of resources flowing to a preset domain as a result of the candidate flow event, and to determine the available quantity of resources in the candidate resource account that can flow to the preset domain before the candidate flow event occurs, wherein the preset domain is a domain other than the target domain;

[0014] The early warning module is used to generate early warning information containing the candidate flow event when the resource quantity and the available resource quantity do not match, and send the early warning information to the first resource platform, wherein the early warning information is used to instruct the handling of the candidate flow event.

[0015] In a third aspect, the present application provides an electronic device comprising: a processor, and a memory communicatively connected to the processor; the memory stores computer-executable instructions; and the processor executes the computer-executable instructions stored in the memory to implement the above method.

[0016] In a fourth aspect, the present application provides a computer-readable storage medium, in which computer-executable instructions are stored. When the computer-executable instructions are executed by a processor, they are used to implement the above method.

[0017] In a fifth aspect, the present application provides a computer program product, comprising a computer program, which is used to implement the above method when executed by a processor.

[0018] In an early warning method, apparatus, equipment, medium and product provided by the present application, after receiving the prompt information, a candidate outflow event is determined from the event set, and whether to generate an early warning message is determined by determining whether the number of resources flowing to the preset field and the available amount of resources of the candidate outflow event match. This process converts the complex and time-consuming resource flow exploration process into a simple determination process of whether the number of resources and the available amount of resources match, and limits the number of resources used by the candidate resource account for the preset field in real time and accurately, and ensures the number of resources used by the candidate resource account for the target field, effectively reducing the difficulty of issuing early warnings for resource flows that are inconsistent with the usage description and improving the detection speed of candidate outflow events for early warning, thereby improving the robustness of the early warning process. In addition, the event set of resource flow events from multiple resource platforms is aggregated to achieve cross-platform early warning and improve the coverage of the early warning process. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.

[0020] Figure 1 A flowchart of an early warning method provided by an embodiment of the present invention;

[0021] Figure 2 An architectural diagram of a resource flow monitoring system provided by an embodiment of the present invention;

[0022] Figure 3 A schematic diagram of a process for building a data lake according to an embodiment of the present invention;

[0023] Figure 4 A schematic diagram of the structure of a knowledge graph provided by an embodiment of the present invention;

[0024] Figure 5 A schematic diagram of a process for determining candidate flow events to be warned provided by an embodiment of the present invention;

[0025] Figure 6 A schematic diagram of a process for issuing warning information provided by an embodiment of the present invention;

[0026] Figure 7 A schematic structural diagram of an early warning device provided by an embodiment of the present invention;

[0027] Figure 8 A schematic structural diagram of an electronic device provided by an embodiment of the present invention.

[0028] The above drawings illustrate specific embodiments of the present application, which will be described in more detail below. These drawings and the textual description are not intended to limit the scope of the present application in any way, but rather to illustrate the concepts of the present application to those skilled in the art by reference to specific embodiments. DETAILED DESCRIPTION

[0029] Exemplary embodiments will be described in detail herein, with examples illustrated in the accompanying drawings. In the following description, when referring to the drawings, identical numerals in different figures represent identical or similar elements, unless otherwise indicated. The embodiments described in the following exemplary embodiments are not intended to represent all embodiments consistent with the present application. Rather, they are merely examples of apparatus and methods consistent with certain aspects of the present application, as detailed in the appended claims.

[0030] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, storage, use, processing, transmission, provision, disclosure and application of relevant data comply with the relevant laws, regulations and standards of relevant countries and regions, take necessary confidentiality measures, do not violate public order and good morals, and provide corresponding operation entrances for users to choose to authorize or refuse.

[0031] It should be noted that the brief description of terms in this application is only for the convenience of understanding the embodiments described below, and is not intended to limit the embodiments of this application. Unless otherwise specified, these terms should be understood according to their ordinary and usual meanings. The terms "first", "second", etc. in the specification and claims and the above-mentioned drawings in this application are used to distinguish similar or similar objects or entities, and do not necessarily mean to limit a specific order or precedence, unless otherwise indicated. It should be understood that the terms used in this way can be interchangeable where appropriate, for example, they can be implemented in an order other than those given in the diagrams or descriptions of the embodiments of this application. The terms "including" and "having" in the specification and claims and the above-mentioned drawings in this application and any variations thereof are intended to cover but not exclude inclusion, for example, a product or device containing a series of components is not necessarily limited to those components clearly listed, but may include other components that are not clearly listed or inherent to these products or devices. The term "module" used in this application refers to any known or later developed hardware, software, firmware, artificial intelligence, fuzzy logic or combination of hardware and / or software code that can perform the functions associated with the element.

[0032] It should be noted that the early warning methods, devices, equipment, media and products provided in this application can be used in the field of financial technology, and can also be used in any field outside of financial technology. The application fields of the early warning methods, devices, equipment, media and products in this application are not limited.

[0033] In order to better illustrate the present disclosure and highlight the main purpose of this application, the specific embodiments in this specification describe resources such as loan funds. Those skilled in the art should understand that this specification can also be implemented for other types of resources such as data.

[0034] The technical content provided by this application is intended to solve the above technical problems of the prior art. In the early warning method, device, equipment, medium and product of this application, after receiving the prompt information, a candidate outflow event is determined from the event set, and whether to generate an early warning message is determined by determining whether the number of resources flowing to the preset field of the candidate outflow event and the available amount of resources match. This process converts the complex and time-consuming resource flow exploration process into a simple determination process of whether the resource quantity and the available amount of resources match, and limits the number of resources used by the candidate resource account for the preset field in real time and accurately, and ensures the number of resources used by the candidate resource account for the target field, effectively reducing the difficulty of issuing early warnings for resource flows that are inconsistent with the usage description and improving the detection speed of candidate outflow events for early warning, thereby improving the robustness of the early warning process. In addition, the event set of resource flow events from multiple resource platforms is aggregated to achieve cross-platform early warning and improve the coverage of the early warning process.

[0035] The following specific embodiments describe in detail the technical solution of the present application and how the technical solution of the present application solves the above-mentioned technical problems. The following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The embodiments of the present application will be described below in conjunction with the accompanying drawings.

[0036] Example 1

[0037] Figure 1 A flowchart of an early warning method provided by an embodiment of the present invention; Figure 1 As shown, the method includes:

[0038] Step 101: Receive prompt information sent by the first resource platform.

[0039] The first resource platform is used to provide resources to resource accounts and to facilitate resource transfers between resource accounts. During resource transfers, flow data such as resource inflow accounts, resource outflow accounts, resource transfer times, and resource transfer quantities may be generated. To distinguish resources provided by the first resource platform from those provided by other resource platforms, the resources provided by the first resource platform to resource accounts may be named target resources.

[0040] When the first resource platform provides resources to a resource account (i.e., the target resource flows out of the first resource platform), it will send a prompt message indicating that the target resource has flowed out of the first resource platform, so as to track the flow data of the target resource. After the target resource flows into the resource account of the first resource platform, it can flow into other resource accounts in the first resource platform or resource accounts in other resource platforms through the resource account.

[0041] The prompt information includes the target domain to which the target resource can flow, that is, the prompt information is used to limit the domain to which the target resource can flow. In addition, the prompt information may also include the domain to which the target resource cannot flow (that is, the preset domain).

[0042] If the first resource platform is a bank, the resource account can be an account of a business or individual within the bank, and the target resource can be a loan issued by the bank. The prompt information can include a loan contract signed between the resource account and the bank, which specifies the areas in which the loan can be used. The aforementioned usage description can be a loan contract. Furthermore, the loan contract can also include areas in which the loan cannot be used.

[0043] Step S102: Determine, from an event set of resource flow events aggregated from multiple resource platforms, candidate resource accounts into which the target resource flows and candidate flow events from which resources flow out of the candidate resource accounts.

[0044] After extracting resources from a resource account within a resource platform, the resource flow direction can be determined by analyzing the resource account's resource flow information. However, the diversity of resource platforms makes it very likely that resources will flow between different resource platforms. Due to the confidentiality requirements of business and customer information, cross-platform resource flow detection is difficult to achieve.

[0045] In one example, an event collection can be constructed to aggregate resource flow events from multiple resource platforms. This event collection can be used to explore the flow of target resources. This event collection can set permissions to protect information that needs to be protected. Specifically, the process of obtaining resource flow data in the resource collection can include:

[0046] (1) Each resource platform configures a data extraction script according to the preset data standards (including fund flow and account data standards), and executes the script regularly to generate data files and file list verification files;

[0047] (2) The resource platform encrypts the above files according to the agreed encryption algorithm;

[0048] (3) The resource platform transfers the encrypted file to the designated directory of the data lake via a dedicated network line;

[0049] (4) The resource flow monitoring system decrypts the encrypted files, transfers the files to the processing directory, and checks whether the files are complete according to the file list;

[0050] (5) The resource flow monitoring system executes the script to identify the files on each resource platform and checks the number and size of the files according to the file list. After confirmation, the files are imported into the data table of the resource collection (also known as the data lake);

[0051] (5) The resource flow monitoring system provides a tenant for each resource platform and sets data query permissions for the tenant. The resource platform can perform functions such as querying resource flow events through the tenant. The data query function can be a data view method.

[0052] Figure 2 This is an architecture diagram of a resource flow monitoring system provided by an embodiment of the present invention. Figure 2 As shown, the system includes a data integration module, which enables data access from various banks, data quality checks and feedback, and data permission control. Specifically, this module can perform the following functions: access account and transaction flow data from various banks; establish unified data standards and perform quality checks on the accessed data, providing feedback to each bank; and implement data access permission control and logically isolate data from each bank.

[0053] Figure 3 A schematic diagram of a process diagram for building a data lake provided by an embodiment of the present invention. Figure 3 As shown in the figure, Bank A, Bank B, and Bank C serve as three resource platforms, inputting loan fund flow data into the data lake. Afterwards, each bank can use the tenants provided by the resource flow monitoring system to perform data queries and other operations.

[0054] A candidate resource account is a resource account into which target resources flow. The candidate resource account can be a resource account from a different resource platform or a resource account from the same resource platform. A candidate flow event is a resource flow event in which resources flow out of a candidate resource account. After obtaining an event set, candidate resource accounts and candidate flow events for the candidate resource accounts can be determined therefrom. Specifically, the candidate resource accounts and candidate flow events can be determined based on the resource usage application of the candidate resource account and / or the resource inflow data corresponding to the resource usage application.

[0055] After determining the candidate resource accounts and candidate flow events, you can select candidate flow events that require alerts from the candidate flow events. Typically, the amount of resources flowing out of a candidate flow event should match the amount of resources available for outflow in the candidate resource account. Therefore, you can determine candidate flow events that require alerts based on the relationship between the amount of resources flowing out of a candidate flow event and the amount of resources available for outflow in the candidate resource account.

[0056] Step S103: Determine the amount of resources that flow to the preset domain in the candidate flow event, and determine the available amount of resources that can flow to the preset domain in the candidate resource account before the candidate flow event occurs.

[0057] The preset domain is a domain outside the target domain. Specifically, after the prompt information determines the target domain, the domain outside the target domain can be used as the preset domain. If there are domains in the prompt information to which the target resources cannot flow, these domains can also be determined as preset domains.

[0058] Each candidate flow event may flow to either the preset domain or the target domain. Typically, the resource source for the former can be resources other than the target resources, such as the candidate resource account's own resources; the resource source for the latter can be the target resources. Furthermore, the resource volume (i.e., the number of resources) corresponding to the former should be less than the number of resources that can flow to the preset domain (i.e., the available amount of resources). Otherwise, there's a possibility that the target resources will flow to the preset domain.

[0059] In one example, a first attribute and a second attribute can be set for a candidate resource account. The first attribute is used to store the available amount of the target resource in the candidate resource account, and the second attribute is used to store the available amount of resources in the preset domain in the candidate resource account. Furthermore, if there are many types of resources in the preset domain and each resource is available in different domains, the second attribute can include the available amount of multiple resources. When determining the available amount of a resource, the available amount of the resource can be directly read from the second attribute. By setting the first attribute and the second attribute, it is convenient to accurately distinguish the flow direction of the target resource and other resources.

[0060] Step S104: When the resource quantity does not match the available resource quantity, generate warning information including the candidate flow event, and send the warning information to the first resource platform.

[0061] As described above, the amount of resources flowing to the preset area should be less than the available amount of resources; otherwise, there is a possibility that the target resources will flow to the preset area. In one example, a value greater than or equal to zero can be preset. If the amount of resources is greater than the available amount of resources, and the difference between the two is greater than or equal to the preset value, the amount of resources is considered to be mismatched with the available amount of resources.

[0062] If the resource quantity does not match the available resource quantity, the candidate flow event corresponding to the resource quantity can be used as a flow event to be warned, and warning information containing the candidate flow event is generated and sent to the first resource platform. After receiving the warning information, the first resource platform can use the aforementioned tenant to query the relevant resource flow details to handle the candidate flow event.

[0063] Specifically, the tenant can query the transfer events related to the candidate transfer event to obtain the usage description attached to the target resource when the first resource platform issued it. The candidate transfer event and the related transfer events can be verified to see if they are consistent with the usage description. If the two are inconsistent, the user can take measures such as issuing a warning to the resource outflow account corresponding to the candidate transfer event and revoking the right to use the target resource. One of the resource accounts in the related flow event can be the same as or related to the resource outflow account of the candidate transfer event.

[0064] like Figure 2 As shown, the resource flow monitoring system can also include a loan fund coverage ratio analysis module, which can realize the calculation, analysis and early warning of the coverage ratio of the customer's own funds for non-loan contract purposes. Specifically, this module establishes virtual accounts for the transfer-out customers and transfer-in customers of each transaction flow, which are used to store the balances of own funds and loan funds respectively. According to the funds inflow and outflow of each transaction flow, it can be calculated whether the current balance of the virtual account is sufficient to cover the funds. If the transfer amount for non-loan contract purposes is greater than the own funds balance of the virtual account, it is determined that there is a possibility that the loan funds may flow into the illegal field and an early warning information is generated. Own funds are funds other than non-loan funds, and can be funds of enterprises or individuals.

[0065] In this example, after receiving the prompt information, a candidate outflow event is determined from the event set, and whether to generate an early warning message is determined by determining whether the number of resources flowing to the preset field and the available amount of resources in the candidate outflow event match. This process converts the complex and time-consuming resource flow exploration process into a simple determination process of whether the resource quantity and the available amount of resources match. It accurately limits the number of resources used by the candidate resource account for the preset field in real time, ensures the number of resources used by the candidate resource account for the target field, effectively reduces the difficulty of issuing early warnings for resource flows that are inconsistent with the usage description, and increases the speed of detecting candidate outflow events that are subject to early warning, thereby improving the robustness of the early warning process. In addition, the event set that aggregates resource flow events from multiple resource platforms enables cross-platform early warning and improves the coverage of the early warning process.

[0066] When there are relatively few candidate transfer events corresponding to the target resource, the resource quantity and availability can be determined directly from these candidate transfer events. However, during the resource transfer process, the resource often passes through a large number of resource accounts. For example, if the resource is a loan, the resource account can be an enterprise or an individual, and resource transfer events can occur between enterprises or between enterprises and individuals. When funds are transferred between multiple enterprise-linked accounts, sorting out the enterprise account affiliates to determine the resource quantity and availability is a tedious task that requires the use of relevant tools.

[0067] Specifically, when there are a large number of candidate flow events corresponding to the target resource, a knowledge graph or network flow graph can be constructed based on the candidate flow events, and the number of resources and the available amount of resources can be determined in the knowledge graph or network flow graph. In one implementation, determining the number of resources flowing to the preset domain due to the candidate flow event and determining the available amount of resources in the candidate resource account that can flow to the preset domain before the candidate flow event occurs includes:

[0068] Constructing a target knowledge graph based on the candidate flow events;

[0069] Determine a target edge and a target node from the target knowledge graph, where the target node is any node in the target knowledge graph, and the target edge is an edge emitted by the target node;

[0070] Determining the resource quantity from the event description text of the candidate flow event corresponding to the target edge;

[0071] The available amount of the resource is determined from attribute text of the resource account corresponding to the target node, where the attribute data includes data of resources that can flow to the preset domain.

[0072] The target knowledge graph is a knowledge graph constructed based on candidate flow events. A target knowledge graph can be constructed for each target resource flowing from the first resource platform. In the target knowledge graph, nodes represent resource accounts in the candidate flow events, and edges represent the candidate flow events. The target knowledge graph can be constructed based on the time sequence of each candidate flow event.

[0073] In the target knowledge graph, the attribute information of the candidate resource account can be stored in the attribute text corresponding to the node. The attribute information may include the aforementioned first attribute and second attribute. In addition, the attribute information may also include account data such as the name of the candidate resource account; the relevant information of the candidate flow event may include the number of flow resources, flow direction, flow summary, and the postscript set by the account before the resource flow. These relevant information can be stored in the event description text.

[0074] After building the target knowledge graph, the target knowledge graph can be used to determine the number and availability of resources. This can also be used to determine the use of resources other than the target resource in real time. Specifically, the availability of resources can be determined using attribute text, and the number of resources can be determined using event description text.

[0075] In this example, the knowledge graph is used to intuitively describe the complex flow process of the target resources. At the same time, the first attribute data of the knowledge graph is used to effectively distinguish the target resources from resources that can be used to limit the field outside the text. The prompt words are used to effectively determine the field to which the candidate outflow event belongs. These all help to improve the accuracy of the resource flow exploration process.

[0076] It should be understood that the number of resources and the available amount of resources in this application refer to the number of resources for the preset domain. Therefore, it is possible to first determine whether the candidate flow event is a related event of the preset domain (such as a flow event flowing from other domains to the preset domain, a flow event that flows resources out of the preset domain, and a flow event that flows within the preset domain, etc.), and then determine the number of resources and the available amount of resources. In one implementation, the determination of the number of resources from the event description text of the candidate flow event corresponding to the target edge includes:

[0077] Constructing prompt words for the preset field, and using the prompt words to search the attribute text and / or the event description text;

[0078] When the prompt word is retrieved, the resource quantity is determined from the event description text of the candidate flow event corresponding to the target edge.

[0079] The prompt words are keywords indicating a preset field. Specifically, corresponding prompt words can be extracted from the preset field by experts in the field or a large language model.

[0080] After setting the prompt word, you can use the prompt word to search for the prompt word in the relevant information of the candidate flow event. If the prompt word is not retrieved, the candidate flow event may be a flow event in the target field, and no further analysis of the event is required. If the prompt word is retrieved, the candidate flow event may be a flow event in the preset field, and further analysis of the event is required, such as determining the number of resources and the available resources.

[0081] like Figure 2 As shown, the resource flow monitoring system can also include a knowledge graph analysis module, which can connect and correlate customer account transactions across various banks. Specifically, this module uses graph database technology to generate a graph of the flow of funds between different accounts at different banks based on the transaction account numbers in the customer's transaction flow.

[0082] The relevant information for the candidate outflow event can be the aforementioned attribute text or event description text. Therefore, the attribute text and / or event description text can be searched for prompt words. In this way, before determining the resource quantity, the domain of the candidate outflow event is first explored using the prompt words. The resource quantity is only determined when the domain of the candidate outflow event is within the preset domain, which can reduce the waste of computing resources.

[0083] In one example, the number of resources and the available amount of resources of the candidate flow events in the target knowledge graph can be determined in sequence based on the order of occurrence, thereby traversing the candidate flow events in the target knowledge graph.

[0084] In the target knowledge graph, the same node can be both the resource inflow account of one candidate flow event and the resource outflow account of another candidate flow event. Therefore, the target knowledge graph can be constructed by comparing whether the resource inflow account of one candidate flow event is consistent with the resource outflow account of another candidate flow event. In one implementation, constructing the target knowledge graph based on the candidate flow events includes:

[0085] The first candidate resource account into which the target resource flows is used as the starting node of the target knowledge graph;

[0086] When the resource outflow account of the candidate flow event is the account represented by the node in the target knowledge graph, a new edge and a new node are added to the node, the new edge represents the edge corresponding to the candidate flow event, and the new node represents the node corresponding to the resource inflow account of the candidate flow event, and the node includes a starting node.

[0087] Among them, the starting node is the node corresponding to the candidate resource account that directly receives the target resource flowing out of the first resource platform in the target knowledge graph.

[0088] After determining the starting node, you can use it as the initial target knowledge graph. Based on this initial target knowledge graph, you can add edges corresponding to candidate flow events and add nodes to these edges to update the target knowledge graph. Newly added edges are named "new edges," and newly added nodes are named "new nodes."

[0089] When updating the target knowledge graph using candidate flow events, the candidate flow event's resource outflow account must be the resource inflow account corresponding to an existing node in the target knowledge graph. This allows the newly added edges corresponding to the candidate flow event to be added to the target knowledge graph. Therefore, if the candidate flow event's resource outflow account is determined to be the resource inflow account corresponding to an existing node in the target knowledge graph, new edges and nodes can be added to the existing nodes in the target knowledge graph until the flow chain for the target resource is completed.

[0090] Figure 4 A schematic diagram of the structure of a knowledge graph provided by an embodiment of the present invention. Figure 4 As shown in the figure, the first account to receive the loan is the starting node of the knowledge graph. The loan funds flow from the starting node to the transition account and the target account, with the target account being the last account in the path. Loan funds can flow between accounts on the same platform (such as from Bank A account to Bank A account), or between accounts on different platforms (such as from Bank A account to Bank B account, Bank C account, etc.).

[0091] Figure 5 The present invention provides a flow chart of determining candidate flow events to be warned. Figure 5 As shown, each account holds two types of funds: owned funds and loan funds. On July 5, 2024, Transition Account 3 transferred 200,000 yuan to Target Account 7 (a securities account). Since Transition Account 3 only had 100,000 yuan in owned funds, less than the transfer amount, this transfer transaction is considered likely to involve the influx of loan funds into illegal areas and is subject to a warning.

[0092] In this example, after retrieving candidate flow events, we can update them to the target knowledge graph based on the resource's outflow account. This process uses the resource outflow account in the candidate flow events to achieve timely and convenient updates to the target knowledge graph in a time-series manner, helping to improve the accuracy of the early warning process based on the knowledge graph.

[0093] During the flow of target resources, non-compliant candidate flow events usually have the characteristics of rapid inflow and outflow. Therefore, the flow time can be limited. In one implementation, when the resource outflow account of the candidate flow event is the account represented by the node in the target knowledge graph, adding a new edge and a new node to the node includes:

[0094] In a case where the resource outflow account of the candidate flow event is the account represented by the node, determining a time difference between the occurrence time and the initial time;

[0095] When the time difference is less than the detection duration, the newly added edge and the newly added node are added to the node.

[0096] The initial time is the time when the target resource flows out from the resource platform, and the occurrence time is the time when the candidate flow event occurs.

[0097] In one example, a time period for exploring the target resource (i.e., exploration time) can be preset to add candidate flow events within the exploration time to the target knowledge graph. The exploration time can be set to 2 months.

[0098] Specifically, we can first determine the time when the target resource flows out from the first resource platform (i.e., the initial time) and the time when the candidate flow event occurs (i.e., the occurrence time), and then determine the time difference between the occurrence time and the initial time. If the time difference is less than the exploration time, the candidate flow event can be added to the target knowledge graph.

[0099] The event of resource flow to the preset field usually occurs within a period of time after the target resources flow out of the first resource platform. In this example, the time difference of the target knowledge graph is limited by the exploration time, which can improve the speed of the early warning process without reducing the accuracy of the early warning process.

[0100] In addition to limiting the flow time, the length of the path in the knowledge graph can also be limited to improve the speed of the early warning process. In one implementation, when the resource outflow account of the candidate flow event is the account represented by the node in the target knowledge graph, adding a new edge and a new node to the node includes:

[0101] In a case where the resource outflow account of the candidate flow event is the account represented by the node, determining the path length between the node and the starting node;

[0102] When the path length is less than the exploration depth, the newly added edge and the newly added node are added to the node.

[0103] In one example, by presetting the path of the target resource to be explored (i.e., the exploration depth), candidate flow events that meet the exploration depth can be added to the target knowledge graph. Specifically, when it is determined that the resource outflow account of the candidate flow event is a node in the target knowledge graph, the path length between the node and the initial node can be determined first. If the path length is less than the exploration depth, the candidate flow event can be added to the target knowledge graph. The exploration depth can be set to 5 layers.

[0104] Since the event of resource flow to the preset field usually occurs within a certain path length after the target resource flows out of the first resource platform, in this example, the path length of the target knowledge graph is limited by the exploration depth, which can improve the speed of the early warning process without reducing the accuracy of the early warning process.

[0105] Since the event set aggregates resource flow events from multiple resource platforms, the resource inflow account and / or resource outflow account in the candidate flow event may belong to a resource platform other than the first resource platform. In one implementation, sending the warning information to the first resource platform includes:

[0106] Determine a second resource platform based on the text identifier of the resource inflow account of the candidate flow event, and determine a third resource platform based on the text identifier of the resource inflow account of the candidate flow event;

[0107] In the case where the second resource platform is different from the first resource platform, sending the warning information to the second resource platform at the same time as sending the warning information to the first resource platform;

[0108] In a case where the third resource platform is different from the first resource platform, the warning information is sent to the third resource platform at the same time as the warning information is sent to the first resource platform.

[0109] The second resource platform and the third resource platform are resource platforms in the event set except the first resource platform.

[0110] The first resource platform releases the target resource to a resource account in the first resource platform. Afterwards, the resource account in the first platform can transfer the target resource to the first resource platform or to a resource platform outside the first resource platform. Therefore, in addition to sending the warning information to the first resource platform, the warning information can also be sent to resource platforms outside the first resource platform involved in the candidate transfer event.

[0111] Specifically, the resource platforms to which the outflow and inflow accounts of a candidate transfer event belong can be determined based on the text identifiers of the resource outflow and inflow accounts. Furthermore, if the resource platform to which the outflow and inflow accounts belong is different from the first resource platform, in addition to sending the warning information to the first resource platform, the warning information can also be sent to the second resource platform corresponding to the outflow account and the third resource platform corresponding to the inflow account, thereby handling the candidate transfer event across multiple platforms.

[0112] In one example, when the flow of target resources involves multiple candidate flow events to be warned, an early warning list can be set up to record information such as the candidate flow events to be warned, the resource outflow accounts of the candidate flow events to be warned, and the resource platforms where the resource outflow accounts of the candidate flow events to be warned are located.

[0113] Figure 6 A schematic diagram of a process for issuing warning information provided by an embodiment of the present invention. Figure 6 As shown, transaction details are first constructed based on the transactions to be warned, and a warning list containing candidate resource accounts is constructed based on the transaction details. The transactions in the warning list are then sent to the lending bank (the bank from which the loan resources initially flowed out) and the non-lending bank (the bank other than the lending bank). The non-lending bank assists the lending bank in handling the transactions to be warned by verifying the transactions.

[0114] The resource transfer process may involve cross-platform transfers. In this example, after determining the resource platforms of the two accounts associated with the candidate transfer event, we determine whether the obtained resource platform is the same as the first resource platform. If not, we send an alert to the determined platform. This process enables cross-platform handling of candidate outflow events by sending alert information to multiple platforms, helping to improve the accuracy and speed of handling candidate outflow events.

[0115] Example 2

[0116] Figure 7 A schematic structural diagram of an early warning device provided by an embodiment of the present invention; Figure 7 As shown, the device includes:

[0117] An information module 71 is configured to receive a prompt message sent by a first resource platform, wherein the prompt message indicates that a target resource flows out of the first resource platform, and the prompt message includes a target domain to which the target resource may flow;

[0118] An event module 72 is configured to determine, from an event set of resource flow events aggregated from multiple resource platforms, candidate resource accounts into which the target resource flows and candidate flow events from which resources flow out of the candidate resource accounts;

[0119] A quantity module 73 is configured to determine the quantity of resources that flow to a preset domain as a result of the candidate transfer event, and to determine the available quantity of resources that can flow to the preset domain in the candidate resource account before the candidate transfer event occurs, where the preset domain is a domain other than the target domain.

[0120] The warning module 74 is used to generate warning information containing the candidate flow event when the resource quantity and the available resource quantity do not match, and send the warning information to the first resource platform. The warning information is used to instruct the handling of the candidate flow event.

[0121] The first resource platform is used to provide resources to resource accounts and to facilitate resource transfers between resource accounts. During resource transfers, flow data such as resource inflow accounts, resource outflow accounts, resource transfer times, and resource transfer quantities may be generated. To distinguish resources provided by the first resource platform from those provided by other resource platforms, the resources provided by the first resource platform to resource accounts may be named target resources.

[0122] When the first resource platform provides resources to a resource account (i.e., the target resource flows out of the first resource platform), it will send a prompt message indicating that the target resource has flowed out of the first resource platform, so as to track the flow data of the target resource. After the target resource flows into the resource account of the first resource platform, it can flow into other resource accounts in the first resource platform or resource accounts in other resource platforms through the resource account.

[0123] The prompt information includes the target domain to which the target resource can flow, that is, the prompt information is used to limit the domain to which the target resource can flow. In addition, the prompt information may also include the domain to which the target resource cannot flow (that is, the preset domain).

[0124] If the first resource platform is a bank, the resource account can be an account of a business or individual within the bank, and the target resource can be a loan issued by the bank. The prompt information can include a loan contract signed between the resource account and the bank, which specifies the areas in which the loan can be used. The aforementioned usage description can be a loan contract. Furthermore, the loan contract can also include areas in which the loan cannot be used.

[0125] After extracting resources from a resource account within a resource platform, the resource flow direction can be determined by analyzing the resource account's resource flow information. However, the diversity of resource platforms makes it very likely that resources will flow between different resource platforms. Due to the confidentiality requirements of business and customer information, cross-platform resource flow detection is difficult to achieve.

[0126] In one example, an event collection can be constructed to aggregate resource flow events from multiple resource platforms. This event collection can be used to explore the flow of target resources. This event collection can set permissions to protect information that needs to be protected. Specifically, the process of obtaining resource flow data in the resource collection can include:

[0127] (1) Each resource platform configures a data extraction script according to the preset data standards (including fund flow and account data standards), and executes the script regularly to generate data files and file list verification files;

[0128] (2) The resource platform encrypts the above files according to the agreed encryption algorithm;

[0129] (3) The resource platform transfers the encrypted file to the designated directory of the data lake via a dedicated network line;

[0130] (4) The resource flow monitoring system decrypts the encrypted files, transfers the files to the processing directory, and checks whether the files are complete according to the file list;

[0131] (5) The resource flow monitoring system executes the script to identify the files on each resource platform and checks the number and size of the files according to the file list. After confirmation, the files are imported into the data table of the resource collection (also known as the data lake);

[0132] (5) The resource flow monitoring system provides a tenant for each resource platform and sets data query permissions for the tenant. The resource platform can perform functions such as querying resource flow events through the tenant. The data query function can be a data view method.

[0133] like Figure 2 As shown, the system includes a data integration module, which enables data access from various banks, data quality checks and feedback, and data permission control. Specifically, this module can perform the following functions: access account and transaction flow data from various banks; establish unified data standards and perform quality checks on the accessed data, providing feedback to each bank; and implement data access permission control and logically isolate data from each bank.

[0134] like Figure 3 As shown in the figure, Bank A, Bank B, and Bank C serve as three resource platforms, inputting loan fund flow data into the data lake. Afterwards, each bank can use the tenants provided by the resource flow monitoring system to perform data queries and other operations.

[0135] A candidate resource account is a resource account into which target resources flow. The candidate resource account can be a resource account from a different resource platform or a resource account from the same resource platform. A candidate flow event is a resource flow event in which resources flow out of a candidate resource account. After obtaining an event set, candidate resource accounts and candidate flow events for the candidate resource accounts can be determined therefrom. Specifically, the candidate resource accounts and candidate flow events can be determined based on the resource usage application of the candidate resource account and / or the resource inflow data corresponding to the resource usage application.

[0136] After determining the candidate resource accounts and candidate flow events, you can select candidate flow events that require alerts from the candidate flow events. Typically, the amount of resources flowing out of a candidate flow event should match the amount of resources available for outflow in the candidate resource account. Therefore, you can determine candidate flow events that require alerts based on the relationship between the amount of resources flowing out of a candidate flow event and the amount of resources available for outflow in the candidate resource account.

[0137] The preset domain is a domain outside the target domain. Specifically, after the prompt information determines the target domain, the domain outside the target domain can be used as a preset domain. After the prompt information contains domains to which the target resources cannot flow, these domains can also be determined as preset domains.

[0138] Each candidate flow event may flow to either the preset domain or the target domain. Typically, the resource source for the former can be resources other than the target resources, such as the candidate resource account's own resources; the resource source for the latter can be the target resources. Furthermore, the resource volume (i.e., the number of resources) corresponding to the former should be less than the number of resources that can flow to the preset domain (i.e., the available amount of resources). Otherwise, there's a possibility that the target resources will flow to the preset domain.

[0139] In one example, a first attribute and a second attribute can be set for a candidate resource account. The first attribute is used to store the available amount of the target resource in the candidate resource account, and the second attribute is used to store the available amount of resources in the preset domain in the candidate resource account. Furthermore, if there are many types of resources in the preset domain and each resource is available in different domains, the second attribute can include the available amount of multiple resources. When determining the available amount of a resource, the available amount of the resource can be directly read from the second attribute. By setting the first attribute and the second attribute, it is convenient to accurately distinguish the flow direction of the target resource and other resources.

[0140] As described above, the amount of resources flowing to the preset area should be less than the available amount of resources; otherwise, there is a possibility that the target resources will flow to the preset area. In one example, a value greater than or equal to zero can be preset. If the amount of resources is greater than the available amount of resources, and the difference between the two is greater than or equal to the preset value, the amount of resources is considered to be mismatched with the available amount of resources.

[0141] If the resource quantity does not match the available resource quantity, the candidate flow event corresponding to the resource quantity can be used as a flow event to be warned, and warning information containing the candidate flow event is generated and sent to the first resource platform. After receiving the warning information, the first resource platform can use the aforementioned tenant to query the relevant resource flow details to handle the candidate flow event.

[0142] Specifically, the tenant can query the transfer events related to the candidate transfer event to obtain the usage description attached to the target resource when the first resource platform issued it. The candidate transfer event and the related transfer events can be verified to see if they are consistent with the usage description. If the two are inconsistent, the user can take measures such as issuing a warning to the resource outflow account corresponding to the candidate transfer event and revoking the right to use the target resource. One of the resource accounts in the related flow event can be the same as or related to the resource outflow account of the candidate transfer event.

[0143] like Figure 2 As shown, the resource flow monitoring system can also include a loan fund coverage ratio analysis module, which can realize the calculation, analysis and early warning of the coverage ratio of the customer's own funds for non-loan contract purposes. Specifically, this module establishes virtual accounts for the transfer-out customers and transfer-in customers of each transaction flow, which are used to store the balances of own funds and loan funds respectively. According to the funds inflow and outflow of each transaction flow, it can be calculated whether the current balance of the virtual account is sufficient to cover the funds. If the transfer amount for non-loan contract purposes is greater than the own funds balance of the virtual account, it is determined that there is a possibility that the loan funds may flow into the illegal field and an early warning information is generated. Own funds are funds other than non-loan funds, and can be funds of enterprises or individuals.

[0144] In this example, after receiving the prompt information, a candidate outflow event is determined from the event set, and whether to generate an early warning message is determined by determining whether the number of resources flowing to the preset field and the available amount of resources in the candidate outflow event match. This process converts the complex and time-consuming resource flow exploration process into a simple determination process of whether the resource quantity and the available amount of resources match. It accurately limits the number of resources used by the candidate resource account for the preset field in real time, ensures the number of resources used by the candidate resource account for the target field, effectively reduces the difficulty of issuing early warnings for resource flows that are inconsistent with the usage description, and increases the speed of detecting candidate outflow events that are subject to early warning, thereby improving the robustness of the early warning process. In addition, the event set that aggregates resource flow events from multiple resource platforms enables cross-platform early warning and improves the coverage of the early warning process.

[0145] When there are relatively few candidate transfer events corresponding to the target resource, the resource quantity and availability can be determined directly from these candidate transfer events. However, during the resource transfer process, the resource often passes through a large number of resource accounts. For example, if the resource is a loan, the resource account can be an enterprise or an individual, and resource transfer events can occur between enterprises or between enterprises and individuals. When funds are transferred between multiple enterprise-linked accounts, sorting out the enterprise account affiliates to determine the resource quantity and availability is a tedious task that requires the use of relevant tools.

[0146] Specifically, when there are many candidate flow events corresponding to the target resource, a knowledge graph or network flow graph can be constructed based on the candidate flow events, and the resource quantity and resource availability can be determined in the knowledge graph or network flow graph. Optionally, the quantity module 73 is used to:

[0147] Constructing a target knowledge graph based on the candidate flow events;

[0148] Determine a target edge and a target node from the target knowledge graph, where the target node is any node in the target knowledge graph, and the target edge is an edge emitted by the target node;

[0149] Determining the resource quantity from the event description text of the candidate flow event corresponding to the target edge;

[0150] The available amount of the resource is determined from attribute text of the resource account corresponding to the target node, where the attribute data includes data of resources that can flow to the preset domain.

[0151] The target knowledge graph is a knowledge graph constructed based on candidate flow events. A target knowledge graph can be constructed for each target resource flowing from the first resource platform. In the target knowledge graph, nodes represent resource accounts in the candidate flow events, and edges represent the candidate flow events. The target knowledge graph can be constructed based on the time sequence of each candidate flow event.

[0152] In the target knowledge graph, the attribute information of the candidate resource account can be stored in the attribute text corresponding to the node. The attribute information may include the aforementioned first attribute and second attribute. In addition, the attribute information may also include account data such as the name of the candidate resource account; the relevant information of the candidate flow event may include the number of flow resources, flow direction, flow summary, and the postscript set by the account before the resource flow. These relevant information can be stored in the event description text.

[0153] After building the target knowledge graph, the target knowledge graph can be used to determine the number and availability of resources. This can also be used to determine the use of resources other than the target resource in real time. Specifically, the availability of resources can be determined using attribute text, and the number of resources can be determined using event description text.

[0154] In this example, the knowledge graph is used to intuitively describe the complex flow process of the target resources. At the same time, the first attribute data of the knowledge graph is used to effectively distinguish the target resources from resources that can be used to limit the field outside the text. The prompt words are used to effectively determine the field to which the candidate outflow event belongs. These all help to improve the accuracy of the resource flow exploration process.

[0155] It should be understood that the number of resources and the amount of available resources in this application refer to the number of resources for the preset domain. Therefore, it is possible to first determine whether the candidate flow event is a related event of the preset domain (such as a flow event flowing from other domains to the preset domain, a flow event that flows resources out of the preset domain, and a flow event that flows within the preset domain, etc.), and then determine the number of resources and the amount of available resources. Optionally, the determination of the number of resources from the event description text of the candidate flow event corresponding to the target edge includes:

[0156] Constructing prompt words for the preset field, and using the prompt words to search the attribute text and / or the event description text;

[0157] When the prompt word is retrieved, the resource quantity is determined from the event description text of the candidate flow event corresponding to the target edge.

[0158] The prompt words are keywords indicating a preset field. Specifically, corresponding prompt words can be extracted from the preset field by experts in the field or a large language model.

[0159] After setting the prompt word, you can use the prompt word to search for the prompt word in the relevant information of the candidate flow event. If the prompt word is not retrieved, the candidate flow event may be a flow event in the target field, and no further analysis of the event is required. If the prompt word is retrieved, the candidate flow event may be a flow event in the preset field, and further analysis of the event is required, such as determining the number of resources and the available resources.

[0160] like Figure 2 As shown, the resource flow monitoring system can also include a knowledge graph analysis module, which can connect and correlate customer account transactions across various banks. Specifically, this module uses graph database technology to generate a graph of the flow of funds between different accounts at different banks based on the transaction account numbers in the customer's transaction flow.

[0161] The relevant information for the candidate outflow event can be the aforementioned attribute text or event description text. Therefore, the attribute text and / or event description text can be searched for prompt words. In this way, before determining the resource quantity, the domain of the candidate outflow event is first explored using the prompt words. The resource quantity is only determined when the domain of the candidate outflow event is within the preset domain, which can reduce the waste of computing resources.

[0162] In one example, the number of resources and the available amount of resources of the candidate flow events in the target knowledge graph can be determined in sequence based on the order of occurrence, thereby traversing the candidate flow events in the target knowledge graph.

[0163] In the target knowledge graph, the same node can be both the resource inflow account of one candidate flow event and the resource outflow account of another candidate flow event. Therefore, the target knowledge graph can be constructed by comparing whether the resource inflow account of one candidate flow event is consistent with the resource outflow account of another candidate flow event. Optionally, the target knowledge graph is constructed based on the candidate flow events, including:

[0164] The first candidate resource account into which the target resource flows is used as the starting node of the target knowledge graph;

[0165] When the resource outflow account of the candidate flow event is the account represented by the node in the target knowledge graph, a new edge and a new node are added to the node, the new edge represents the edge corresponding to the candidate flow event, and the new node represents the node corresponding to the resource inflow account of the candidate flow event, and the node includes a starting node.

[0166] Among them, the starting node is the node corresponding to the candidate resource account that directly receives the target resource flowing out of the first resource platform in the target knowledge graph.

[0167] After determining the starting node, you can use it as the initial target knowledge graph. Based on this initial target knowledge graph, you can add edges corresponding to candidate flow events and add nodes to these edges to update the target knowledge graph. Newly added edges are named "new edges," and newly added nodes are named "new nodes."

[0168] When updating the target knowledge graph using candidate flow events, the candidate flow event's resource outflow account must be the resource inflow account corresponding to an existing node in the target knowledge graph. This allows the newly added edges corresponding to the candidate flow event to be added to the target knowledge graph. Therefore, if the candidate flow event's resource outflow account is determined to be the resource inflow account corresponding to an existing node in the target knowledge graph, new edges and nodes can be added to the existing nodes in the target knowledge graph until the flow chain for the target resource is completed.

[0169] like Figure 4 As shown in the figure, the first account to receive the loan is the starting node of the knowledge graph. The loan funds flow from the starting node to the transition account and the target account, with the target account being the last account in the path. Loan funds can flow between accounts on the same platform (such as from Bank A account to Bank A account), or between accounts on different platforms (such as from Bank A account to Bank B account, Bank C account, etc.).

[0170] like Figure 5 As shown, each account holds two types of funds: owned funds and loan funds. On July 5, 2024, Transition Account 3 transferred 200,000 yuan to Target Account 7 (a securities account). Since Transition Account 3 only had 100,000 yuan in owned funds, less than the transfer amount, this transfer transaction is considered likely to involve the influx of loan funds into illegal areas and is subject to a warning.

[0171] In this example, after retrieving candidate flow events, we can update them to the target knowledge graph based on the resource's outflow account. This process uses the resource outflow account in the candidate flow events to achieve timely and convenient updates to the target knowledge graph in a time-series manner, helping to improve the accuracy of the early warning process based on the knowledge graph.

[0172] During the flow of target resources, non-compliant candidate flow events typically have the characteristics of rapid inflow and outflow. Therefore, the flow time can be limited. Optionally, when the resource outflow account of the candidate flow event is the account represented by the node in the target knowledge graph, adding a new edge and a new node to the node includes:

[0173] In a case where the resource outflow account of the candidate flow event is the account represented by the node, determining a time difference between the occurrence time and the initial time;

[0174] When the time difference is less than the detection duration, the newly added edge and the newly added node are added to the node.

[0175] The initial time is the time when the target resource flows out from the resource platform, and the occurrence time is the time when the candidate flow event occurs.

[0176] In one example, a time period for exploring the target resource (i.e., exploration time) can be preset to add candidate flow events within the exploration time to the target knowledge graph. The exploration time can be set to 2 months.

[0177] Specifically, we can first determine the time when the target resource flows out from the first resource platform (i.e., the initial time) and the time when the candidate flow event occurs (i.e., the occurrence time), and then determine the time difference between the occurrence time and the initial time. If the time difference is less than the exploration time, the candidate flow event can be added to the target knowledge graph.

[0178] The event of resource flow to the preset field usually occurs within a period of time after the target resources flow out of the first resource platform. In this example, the time difference of the target knowledge graph is limited by the exploration time, which can improve the speed of the early warning process without reducing the accuracy of the early warning process.

[0179] In addition to limiting the flow time, the length of the path in the knowledge graph can also be limited to improve the speed of the early warning process. Optionally, when the resource outflow account of the candidate flow event is the account represented by the node in the target knowledge graph, adding a new edge and a new node to the node includes:

[0180] In a case where the resource outflow account of the candidate flow event is the account represented by the node, determining the path length between the node and the starting node;

[0181] When the path length is less than the exploration depth, the newly added edge and the newly added node are added to the node.

[0182] In one example, by presetting the path of the target resource to be explored (i.e., the exploration depth), candidate flow events that meet the exploration depth can be added to the target knowledge graph. Specifically, when it is determined that the resource outflow account of the candidate flow event is a node in the target knowledge graph, the path length between the node and the initial node can be determined first. If the path length is less than the exploration depth, the candidate flow event can be added to the target knowledge graph. The exploration depth can be set to 5 layers.

[0183] Since the event of resource flow to the preset field usually occurs within a certain path length after the target resource flows out of the first resource platform, in this example, the path length of the target knowledge graph is limited by the exploration depth, which can improve the speed of the early warning process without reducing the accuracy of the early warning process.

[0184] Since the event set aggregates resource flow events from multiple resource platforms, the resource inflow account and / or resource outflow account in the candidate flow event may belong to a resource platform other than the first resource platform.

[0185] Determine a second resource platform based on the text identifier of the resource inflow account of the candidate flow event, and determine a third resource platform based on the text identifier of the resource inflow account of the candidate flow event;

[0186] In the case where the second resource platform is different from the first resource platform, sending the warning information to the second resource platform at the same time as sending the warning information to the first resource platform;

[0187] In a case where the third resource platform is different from the first resource platform, the warning information is sent to the third resource platform at the same time as the warning information is sent to the first resource platform.

[0188] The second resource platform and the third resource platform are resource platforms in the event set except the first resource platform.

[0189] The first resource platform releases the target resource to a resource account in the first resource platform. Afterwards, the resource account in the first platform can transfer the target resource to the first resource platform or to a resource platform outside the first resource platform. Therefore, in addition to sending the warning information to the first resource platform, the warning information can also be sent to resource platforms outside the first resource platform involved in the candidate transfer event.

[0190] Specifically, the resource platforms to which the outflow and inflow accounts of a candidate transfer event belong can be determined based on the text identifiers of the resource outflow and inflow accounts. Furthermore, if the resource platform to which the outflow and inflow accounts belong is different from the first resource platform, in addition to sending the warning information to the first resource platform, the warning information can also be sent to the second resource platform corresponding to the outflow account and the third resource platform corresponding to the inflow account, thereby handling the candidate transfer event across multiple platforms.

[0191] In one example, when the flow of target resources involves multiple candidate flow events to be warned, an early warning list can be set up to record information such as the candidate flow events to be warned, the resource outflow accounts of the candidate flow events to be warned, and the resource platforms where the resource outflow accounts of the candidate flow events to be warned are located.

[0192] like Figure 6 As shown, transaction details are first constructed based on the transactions to be warned, and a warning list containing candidate resource accounts is constructed based on the transaction details. The transactions in the warning list are then sent to the lending bank (the bank from which the loan resources initially flowed out) and the non-lending bank (the bank other than the lending bank). The non-lending bank assists the lending bank in handling the transactions to be warned by verifying the transactions.

[0193] The resource transfer process may involve cross-platform transfers. In this example, after determining the resource platforms of the two accounts associated with the candidate transfer event, we determine whether the obtained resource platform is the same as the first resource platform. If not, we send an alert to the determined platform. This process enables cross-platform handling of candidate outflow events by sending alert information to multiple platforms, helping to improve the accuracy and speed of handling candidate outflow events.

[0194] Example 3

[0195] Figure 8 A schematic diagram of the structure of an electronic device provided in an embodiment of the present invention, the device comprising:

[0196] The device includes a processor 891 and a memory 892; a communication interface 893, and a bus 894. The processor 891, memory 892, and communication interface 893 can communicate with each other via bus 894. Communication interface 893 can be used for information transmission. Processor 891 can invoke logic instructions in memory 892 to execute the method described above.

[0197] In addition, the logic instructions in the above-mentioned memory 892 can be implemented in the form of software functional units and can be stored in a computer-readable storage medium when sold or used as an independent product.

[0198] Memory 892, as a computer-readable storage medium, can be used to store software programs and computer-executable programs, such as program instructions / modules corresponding to the methods in the embodiments of the present application. Processor 891 executes the software programs, instructions, and modules stored in memory 892 to execute functional applications and data processing, that is, to implement the methods in the above method examples.

[0199] The memory 892 may include a program storage area and a data storage area. The program storage area may store an operating system and application programs required for at least one function; the data storage area may store data generated based on the use of the terminal device. Furthermore, the memory 892 may include high-speed random access memory and non-volatile memory.

[0200] An embodiment of the present application further provides a computer-readable storage medium, in which computer-executable instructions are stored. When the computer-executable instructions are executed by a processor, they are used to implement the method in any embodiment.

[0201] An embodiment of the present application further provides a computer program product, including a computer program, which is used to implement the method in any embodiment when executed by a processor.

[0202] It should be noted that for the aforementioned method embodiments, for the sake of simplicity, they are all expressed as a series of action combinations, but those skilled in the art should be aware that this application is not limited by the order of the actions described, because according to this application, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in this specification are all optional embodiments, and the actions and modules involved are not necessarily required by this application.

[0203] It should be further noted that, although the various steps in the flowchart are shown in sequence as indicated by the arrows, these steps are not necessarily performed in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order restriction on the execution of these steps, and these steps may be performed in other orders. Moreover, at least a portion of the steps in the flowchart may include multiple sub-steps or multiple stages, and these sub-steps or stages are not necessarily performed at the same time, but may be performed at different times. The execution order of these sub-steps or stages is not necessarily to be performed in sequence, but may be performed in turn or alternately with other steps or at least a portion of the sub-steps or stages of other steps.

[0204] It should be understood that the above-described device embodiments are merely illustrative, and the devices of the present application may also be implemented in other ways. For example, the division of units / modules in the above-described embodiments is merely a logical functional division, and actual implementations may employ other division methods. For example, multiple units, modules, or components may be combined or integrated into another system, or some features may be omitted or not implemented.

[0205] In addition, unless otherwise specified, the functional units / modules in the various embodiments of the present application may be integrated into a single unit / module, each unit / module may exist physically separately, or two or more units / modules may be integrated together. The aforementioned integrated units / modules may be implemented in the form of hardware or software program modules.

[0206] If the integrated unit / module is implemented in hardware, the hardware may be digital circuits, analog circuits, etc. The physical implementation of the hardware structure includes, but is not limited to, transistors, memristors, etc. Unless otherwise specified, the processor may be any appropriate hardware processor, such as a CPU, GPU, FPGA, DSP, and ASIC. Unless otherwise specified, the storage unit may be any appropriate magnetic storage medium or magneto-optical storage medium, such as resistive random access memory (RRAM), dynamic random access memory (DRAM), static random access memory (SRAM), enhanced dynamic random access memory (EDRAM), high-bandwidth memory (HBM), hybrid memory cube (HMC), etc.

[0207] If the integrated unit / module is implemented in the form of a software program module and sold or used as an independent product, it can be stored in a computer-readable memory. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product, which is stored in a memory and includes a number of instructions for enabling a computer device (which can be a personal computer, server or network device, etc.) to execute all or part of the steps of the various embodiments of the present application. The aforementioned memory includes various media that can store program codes, such as a USB flash drive, a read-only memory (ROM), a random access memory (RAM), a mobile hard disk, a magnetic disk or an optical disk.

[0208] In the above embodiments, the description of each embodiment has its own emphasis. For parts not described in detail in a particular embodiment, please refer to the relevant description of other embodiments. The technical features of the above embodiments can be combined in any way. To keep the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0209] Those skilled in the art will readily appreciate other embodiments of the present invention after considering the specification and practicing the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of the present invention that follow the general principles of this application and include common knowledge or customary techniques in the art not disclosed herein. The description and examples are to be considered as exemplary only, and the true scope and spirit of the present application are indicated by the following claims.

[0210] It should be understood that the present application is not limited to the exact structure described above and shown in the drawings, and that various modifications and changes may be made without departing from the scope thereof. The scope of the present application is limited only by the appended claims.

Claims

1. An early warning method, characterized in that: The method comprises: receiving prompt information sent by the first resource platform, the prompt information being used to indicate that target resources flow out of the first resource platform, the prompt information including a target domain to which the target resources may flow; Determine, from an event set of resource flow events aggregated from multiple resource platforms, a candidate resource account into which the target resource flows and a candidate flow event from which resources flow out of the candidate resource account; Determine the amount of resources that flow to a preset domain as a result of the candidate transfer event, and determine the available amount of resources that can flow to the preset domain in the candidate resource account before the candidate transfer event occurs, where the preset domain is a domain other than the target domain; In the case where the resource quantity and the available resource quantity do not match, warning information including the candidate flow event is generated and sent to the first resource platform, wherein the warning information is used to instruct the handling of the candidate flow event.

2. The method according to claim 1, characterized in that The determining of the amount of resources flowing to the preset domain by the candidate flow event and determining the available amount of resources in the candidate resource account that can flow to the preset domain before the candidate flow event occurs includes: Constructing a target knowledge graph based on the candidate flow events, wherein nodes in the target knowledge graph represent resource accounts in the candidate flow events and edges represent the candidate flow events; Determine a target edge and a target node from the target knowledge graph, where the target node is any node in the target knowledge graph, and the target edge is an edge emitted by the target node; Determining the resource quantity from the event description text of the candidate flow event corresponding to the target edge; The available amount of the resource is determined from attribute text of the resource account corresponding to the target node, where the attribute data includes data of resources that can flow to the preset domain.

3. The method according to claim 2, characterized in that The determining the resource quantity from the event description text of the candidate flow event corresponding to the target edge includes: Constructing prompt words for the preset field, and using the prompt words to search the attribute text and / or the event description text; When the prompt word is retrieved, the resource quantity is determined from the event description text of the candidate flow event corresponding to the target edge.

4. The method according to claim 2, characterized in that The step of constructing a target knowledge graph based on the candidate flow events includes: The first candidate resource account into which the target resource flows is used as the starting node of the target knowledge graph; When the resource outflow account of the candidate flow event is the account represented by the node in the target knowledge graph, a new edge and a new node are added to the node, the new edge represents the edge corresponding to the candidate flow event, and the new node represents the node corresponding to the resource inflow account of the candidate flow event, and the node includes a starting node.

5. The method according to claim 4, characterized in that When the resource outflow account of the candidate flow event is the account represented by the node in the target knowledge graph, adding a new edge and a new node to the node includes: In a case where the resource outflow account of the candidate flow event is the account represented by the node, determining the path length between the node and the starting node; When the path length is less than the exploration depth, the newly added edge and the newly added node are added to the node.

6. The method according to claim 4, characterized in that When the resource outflow account of the candidate flow event is the account represented by the node in the target knowledge graph, adding a new edge and a new node to the node includes: If the resource outflow account of the candidate flow event is the account represented by the node, determine the time difference between the occurrence time and the initial time, where the initial time is the time when the target resource flows out from the first resource platform, and the occurrence time is the time when the candidate flow event occurs; When the time difference is less than the detection duration, the newly added edge and the newly added node are added to the node.

7. The method according to claim 1, characterized in that The sending the warning information to the first resource platform includes: Determine a second resource platform based on the text identifier of the resource inflow account of the candidate flow event, and determine a third resource platform based on the text identifier of the resource inflow account of the candidate flow event; In the case where the second resource platform is different from the first resource platform, sending the warning information to the second resource platform at the same time as sending the warning information to the first resource platform; In a case where the third resource platform is different from the first resource platform, the warning information is sent to the third resource platform at the same time as the warning information is sent to the first resource platform.

8. An early warning device, characterized in that: The device comprises: An information module, configured to receive prompt information sent by the first resource platform, wherein the prompt information is used to indicate that target resources flow out of the first resource platform, and the prompt information includes a target domain to which the target resources can flow; An event module, configured to determine, from an event set of resource flow events aggregated from multiple resource platforms, candidate resource accounts into which the target resource flows and candidate flow events from which resources flow out of the candidate resource accounts; a quantity module, configured to determine the quantity of resources flowing to a preset domain as a result of the candidate flow event, and to determine the available quantity of resources in the candidate resource account that can flow to the preset domain before the candidate flow event occurs, wherein the preset domain is a domain other than the target domain; The early warning module is used to generate early warning information containing the candidate flow event when the resource quantity and the available resource quantity do not match, and send the early warning information to the first resource platform, wherein the early warning information is used to instruct the handling of the candidate flow event.

9. An electronic device, characterized in that: include: a processor, and a memory communicatively connected to the processor; The memory stores computer-executable instructions; The processor executes the computer-executable instructions stored in the memory to implement the method according to any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer-executable instructions, which are used to implement the method according to any one of claims 1 to 7 when executed by a processor.

11. A computer program product, characterized in that The invention comprises a computer program, which implements the method according to any one of claims 1 to 7 when being executed by a processor.