Cross-border transaction processing method and device, equipment, storage medium and program product

By obtaining the link feature vector and time consumption prediction model of the cross-border transaction link, survey sequence information is generated to improve the efficiency of cross-border transaction anomaly detection, solving the problem of low efficiency in existing technologies.

CN120707284APending Publication Date: 2025-09-26INDUSTRIAL AND COMMERCIAL BANK OF CHINA
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510819101.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-18
Publication Date
2025-09-26

AI Technical Summary

Technical Problem

The efficiency of cross-border transaction anomaly detection in existing technologies is low.

Method used

By obtaining cross-border transaction links within a historical time period, the preset semantic distillation network is used to determine the link feature vector, and the time consumption prediction model is combined to determine the regulatory benefit parameters and cost parameters, and survey sequence information is generated for anomaly detection.

Benefits of technology

Improves the efficiency of cross-border transaction anomaly detection, ensuring the detection process meets the shortest execution path that meets regulatory benefits and human resource budgets.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120707284A_ABST
    Figure CN120707284A_ABST
Patent Text Reader

Abstract

The invention provides a cross-border transaction processing method and device, equipment, a storage medium and a program product, and relates to the technical field of finance or other technologies. The method comprises the following steps: acquiring a plurality of cross-border transaction links in a historical time period, wherein the cross-border transaction links comprise a plurality of pieces of cross-border transaction information of which account risk values are greater than a preset threshold value; for each cross-border transaction link, determining a link feature vector corresponding to the cross-border transaction link according to a preset semantic distillation network; calling a time consumption prediction model to determine time consumption information corresponding to the cross-border transaction link through the link feature vector, and determining a supervision income parameter and a supervision cost parameter corresponding to the cross-border transaction link based on investigation labor duration and document review duration in the time consumption information; and determining investigation sequence information corresponding to the cross-border transaction link according to the supervision income parameter and the supervision cost parameter, and performing anomaly detection on the cross-border transaction link according to the investigation sequence information. According to the method, the detection efficiency of the abnormal cross-border transaction can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to finance or other technical fields, and in particular to a method, apparatus, device, storage medium, and program product for processing cross-border transactions. Background Art

[0002] With the development of Internet technology, more and more users choose to complete cross-border transactions (for example, cross-border remittance transactions) through cross-border payment systems. In order to improve the security of cross-border transactions, it is necessary to detect and investigate abnormal cross-border transactions.

[0003] In related technologies, abnormal cross-border transactions are detected through link analysis: first, a single remittance is regarded as a node, and two transactions that meet the time window, consistent direction and amount threshold are connected into directed edges to form a cross-border transaction chain segment; then, by analyzing the cross-border transaction chain segments, abnormal cross-border transaction chain segments are identified.

[0004] However, the inventors have discovered that the prior art has at least the following technical problems: the efficiency of detecting abnormal cross-border transactions through link analysis is low. Summary of the Invention

[0005] The present application provides a method, apparatus, device, storage medium and program product for processing cross-border transactions, which are used to solve the technical problem of low efficiency in detecting abnormal cross-border transactions.

[0006] In a first aspect, the present application provides a method for processing cross-border transactions, comprising:

[0007] Acquire multiple cross-border transaction links within a historical time period, wherein the cross-border transaction links include cross-border transaction information with multiple account risk values ​​greater than a preset threshold;

[0008] For each cross-border transaction link, determine a link feature vector corresponding to the cross-border transaction link based on a preset semantic distillation network. The link feature vector includes regulatory feature information of the cross-border transaction link.

[0009] Using the link feature vector, a time consumption prediction model is called to determine the time consumption information corresponding to the cross-border transaction link, and based on the investigation labor time and document review time in the time consumption information, the regulatory benefit parameter and regulatory cost parameter corresponding to the cross-border transaction link are determined;

[0010] Based on the regulatory benefit parameter and the regulatory cost parameter, the investigation sequence information corresponding to the cross-border transaction link is determined. The investigation sequence information includes multiple target cross-border transaction information to be detected and the detection order of the multiple target cross-border transaction information. The cross-border transaction link is detected for anomalies based on the investigation sequence information.

[0011] In a second aspect, the present application provides a cross-border transaction processing device, comprising:

[0012] An acquisition module, configured to acquire a plurality of cross-border transaction links within a historical period, wherein the cross-border transaction links include information on a plurality of cross-border transactions whose account risk values ​​are greater than a preset threshold;

[0013] A first determination module is configured to determine, for each cross-border transaction link, a link feature vector corresponding to the cross-border transaction link based on a preset semantic distillation network, wherein the link feature vector includes regulatory feature information of the cross-border transaction link;

[0014] A second determination module is configured to use the link feature vector to call a time consumption prediction model to determine time consumption information corresponding to the cross-border transaction link, and determine a regulatory benefit parameter and a regulatory cost parameter corresponding to the cross-border transaction link based on the investigation labor time and document review time in the time consumption information;

[0015] A processing module is used to determine, based on the regulatory benefit parameter and the regulatory cost parameter, investigation sequence information corresponding to the cross-border transaction link, the investigation sequence information including multiple target cross-border transaction information to be detected and the detection order of the multiple target cross-border transaction information, and perform anomaly detection on the cross-border transaction link based on the investigation sequence information.

[0016] In a third aspect, the present application provides an electronic device, comprising: a memory, a processor;

[0017] Memory stores computer-executable instructions;

[0018] The processor executes the computer-executable instructions stored in the memory, so that the processor performs the implementation of the first aspect as described above.

[0019] In a fourth aspect, the present application provides a computer-readable storage medium, in which computer-executable instructions are stored. When the computer-executable instructions are executed by a processor, they are used to implement the implementation of the first aspect as described above.

[0020] In a fifth aspect, the present application provides a computer program product, comprising a computer program, which, when executed by a processor, is used to implement the implementation of the first aspect as described above.

[0021] The present application provides a method, apparatus, device, storage medium and program product for processing cross-border transactions, the method comprising: obtaining multiple cross-border transaction links within a historical time period, the cross-border transaction links comprising cross-border transaction information with multiple account risk values ​​greater than a preset threshold; for each cross-border transaction link, determining a link feature vector corresponding to the cross-border transaction link based on a preset semantic distillation network, the link feature vector comprising regulatory feature information of the cross-border transaction link; using the link feature vector, calling a time consumption prediction model to determine the time consumption information corresponding to the cross-border transaction link, and determining the regulatory benefit parameters and regulatory cost parameters corresponding to the cross-border transaction link based on the investigation manual time and document review time in the time consumption information; determining the investigation sequence information corresponding to the cross-border transaction link based on the regulatory benefit parameters and regulatory cost parameters, the investigation sequence information comprising multiple target cross-border transaction information to be detected and the detection order of the multiple target cross-border transaction information, and performing anomaly detection on the cross-border transaction link based on the investigation sequence information. In the disclosed embodiment, invalid content is deleted for each cross-border transaction link according to a preset semantic distillation network to obtain a link feature vector corresponding to the cross-border transaction link. The link feature vector can improve the efficiency of determining the time-consuming information corresponding to the cross-border transaction link; and the investigation sequence information corresponding to each cross-border transaction link is determined through the benefit parameter and the cost parameter. The investigation sequence information is the shortest execution path that meets both regulatory benefits and human resource budgets, and thus can improve the detection efficiency of abnormal cross-border transactions. BRIEF DESCRIPTION OF THE DRAWINGS

[0022] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.

[0023] Figure 1 A schematic diagram of an application scenario of a method for processing cross-border transactions provided in an embodiment of the present application;

[0024] Figure 2 A schematic diagram of a cross-border transaction processing method provided in an embodiment of the present application Figure 1 ;

[0025] Figure 3 A schematic diagram of a cross-border transaction processing method provided in an embodiment of the present application Figure 2 ;

[0026] Figure 4 A schematic diagram of a cross-border transaction processing method provided in an embodiment of the present application Figure 3 ;

[0027] Figure 5 A schematic diagram of a cross-border transaction processing method provided in an embodiment of the present application Figure 4 ;

[0028] Figure 6 A schematic diagram of a cross-border transaction processing method provided in an embodiment of the present application Figure 5 ;

[0029] Figure 7 A schematic diagram of the structure of a cross-border transaction processing device provided in an embodiment of the present application;

[0030] Figure 8 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application.

[0031] The above drawings illustrate specific embodiments of the present application, which will be described in more detail below. These drawings and the textual description are not intended to limit the scope of the present application in any way, but rather to illustrate the concepts of the present application to those skilled in the art by reference to specific embodiments. DETAILED DESCRIPTION

[0032] Exemplary embodiments will be described in detail herein, with examples illustrated in the accompanying drawings. In the following description, when referring to the drawings, identical numerals in different figures represent identical or similar elements, unless otherwise indicated. The embodiments described in the following exemplary embodiments are not intended to represent all embodiments consistent with the present application. Rather, they are merely examples of apparatus and methods consistent with certain aspects of the present application, as detailed in the appended claims.

[0033] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in one or more embodiments of this specification are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with relevant laws, regulations and standards, and provide corresponding operation entrances for users to choose to authorize or refuse.

[0034] With the development of Internet technology, more and more users choose to complete cross-border transactions (for example, cross-border remittance transactions) through cross-border payment systems. In order to improve the security of cross-border transactions, it is necessary to detect and investigate abnormal cross-border transactions.

[0035] Related technologies use chain analysis to detect abnormal cross-border transactions. First, a single remittance is considered a node. Two transactions that meet a time window, consistent direction, and a threshold amount are connected as directed edges, forming a cross-border transaction chain. Then, these cross-border transaction chains are analyzed to identify abnormal cross-border transaction chains. However, chain analysis is inefficient in detecting abnormal cross-border transactions.

[0036] It can be seen that how to further improve the efficiency of detecting abnormal cross-border transactions is a technical problem that needs to be solved urgently.

[0037] In order to solve the above technical problems, the inventors have come up with the following technical concept: in a scenario where both regulatory time limits and investigation resources are constrained, how to automatically generate the shortest executable investigation path for suspicious cross-border payment links, so that the maximization of penalty risk reduction and the minimization of manpower and computing power consumption can be uniformly measured and collaboratively optimized.

[0038] Accordingly, the specific steps may include: first, obtaining multiple cross-border transaction links within a historical time period, wherein the cross-border transaction links include cross-border transaction information with multiple account risk values ​​greater than a preset threshold; for each cross-border transaction link, determining the link feature vector corresponding to the cross-border transaction link based on a preset semantic distillation network, wherein the link feature vector includes the regulatory feature information of the cross-border transaction link. Then, through the link feature vector, calling the time consumption prediction model to determine the time consumption information corresponding to the cross-border transaction link, and based on the investigation manual time and document review time in the time consumption information, determining the regulatory benefit parameters and regulatory cost parameters corresponding to the cross-border transaction link. Finally, based on the regulatory benefit parameters and regulatory cost parameters, determining the investigation sequence information corresponding to the cross-border transaction link, the investigation sequence information includes multiple target cross-border transaction information to be detected and the detection order of the multiple target cross-border transaction information, and performing anomaly detection on the cross-border transaction link based on the investigation sequence information.

[0039] In this technical solution, for each cross-border transaction link, invalid content is deleted according to the preset semantic distillation network to obtain the link feature vector corresponding to the cross-border transaction link. The link feature vector can improve the efficiency of determining the time-consuming information corresponding to the cross-border transaction link; and, through the benefit parameters and cost parameters, the investigation sequence information corresponding to each cross-border transaction link is determined. The investigation sequence information is the shortest execution path that meets both regulatory benefits and human resource budgets, and therefore can improve the detection efficiency of abnormal cross-border transactions.

[0040] The cross-border transaction processing method, device, equipment, storage medium and program product provided in this application can be used in the field of cross-border transactions, and can also be used in any field other than cross-border transactions. This application does not limit the application field of the cross-border transaction processing method, device, equipment, storage medium and program product.

[0041] Figure 1 This is a schematic diagram of an application scenario of a method for processing cross-border transactions provided in an embodiment of the present application. Figure 1As shown, terminal 101 and server 102 are connected via a network. A user can send a detection request for abnormal cross-border transaction information to server 102 via terminal 101. Server 102 can use the cross-border transaction processing method provided in this application to perform anomaly detection on cross-border transaction information in multiple cross-border transaction links within a historical time period in response to the detection request sent by terminal 101.

[0042] The following specific embodiments describe in detail the technical solution of the present application and how the technical solution of the present application solves the above-mentioned technical problems. The following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The embodiments of the present application will be described below in conjunction with the accompanying drawings.

[0043] Figure 2 A schematic diagram of a cross-border transaction processing method provided in an embodiment of the present application Figure 1 ,like Figure 1 As shown, the method includes:

[0044] S201. Acquire multiple cross-border transaction links within a historical time period, where the cross-border transaction links include cross-border transaction information with multiple account risk values ​​greater than a preset threshold.

[0045] In the embodiment of the present application, the length of the historical time period and the value of the preset threshold are not specifically limited. For example, the length of the historical time period can be 1 day, 1 week, or 1 month. The value of the preset threshold can be 0.5, 0.6, or 0.8.

[0046] In some embodiments, the correspondence between transaction amount information, transaction country information, transaction time information and account risk value can be pre-stored, and the account risk value of the cross-border transaction information can be determined through the correspondence and the transaction amount information, transaction country information, and transaction time information of the cross-border transaction information.

[0047] In other embodiments, each cross-border transaction information is associated with a monitoring and tracing tag, which includes a remaining response time limit, a penalty benchmark, and a strong verification field. The account risk value of the cross-border transaction information can be calculated based on the penalty benchmark in the monitoring and tracing tag.

[0048] For example, the regulatory backtracking label is Λ={λ r ,φ r ,κ r}, where λ r is the remaining response time, φ r is the penalty benchmark, κ r This is a strong check field.

[0049] S202. For each cross-border transaction link, determine a link feature vector corresponding to the cross-border transaction link based on a preset semantic distillation network. The link feature vector includes regulatory feature information of the cross-border transaction link.

[0050] In some embodiments, the preset semantic distillation network is a self-attention and gated feedforward distillation network, which is used to input a cross-border transaction link and output a link feature vector corresponding to the cross-border transaction link.

[0051] Optionally, the image frame, full text of each cross-border transaction information in the cross-border transaction link and OCR text can be transcoded into a token stream and then input into the distillation network. The distillation network consists of four layers of self-attention and gated feedforward modules. After forward reasoning, it outputs the link feature vector corresponding to the cross-border transaction link:

[0052] S203. Using the link feature vector, call the time consumption prediction model to determine the time consumption information corresponding to the cross-border transaction link, and based on the investigation labor time and document review time in the time consumption information, determine the regulatory benefit parameters and regulatory cost parameters corresponding to the cross-border transaction link.

[0053] In some embodiments, the time consumption prediction model is called as a lightweight time consumption predictor. In this case, the lightweight time consumption predictor Φ(·) can be called and the survey labor time can be output at the same time. Document review time This lightweight time consumption predictor takes link semantic embedding (i.e., link feature vector) as input and combines long-term and short-term risk features through a residual-gating structure.

[0054] S204. Determine investigation sequence information corresponding to the cross-border transaction link based on the regulatory benefit parameter and the regulatory cost parameter. The investigation sequence information includes multiple target cross-border transaction information to be detected and the detection order of the multiple target cross-border transaction information. Perform anomaly detection on the cross-border transaction link based on the investigation sequence information.

[0055] The present application provides a method for processing cross-border transactions. For each cross-border transaction link, invalid content is deleted according to a preset semantic distillation network to obtain a link feature vector corresponding to the cross-border transaction link. The link feature vector can improve the efficiency of determining the time-consuming information corresponding to the cross-border transaction link; and, through the benefit parameter and the cost parameter, the investigation sequence information corresponding to each cross-border transaction link is determined. The investigation sequence information is the shortest execution path that meets both regulatory benefits and human resource budgets, thereby improving the detection efficiency of abnormal cross-border transactions.

[0056] Figure 3 A schematic diagram of a cross-border transaction processing method provided in an embodiment of the present application Figure 2,like Figure 3 As shown, the embodiment of the present application is Figure 2 Based on the embodiment, a possible implementation method of S201 acquiring multiple cross-border transaction links within a historical time period is described in detail. The method includes:

[0057] S301. Acquire information on multiple cross-border transactions in which the account risk value within a historical time period is greater than a preset threshold.

[0058] In some embodiments, this step may include the following steps (1) to (6):

[0059] (1) Obtain candidate cross-border transaction information based on a single remittance, wherein the candidate cross-border transaction information includes a global unique key, amount, time, currency, and image pointer of the single remittance; wherein the image pointer includes the storage address of the transaction image and text information.

[0060] In some embodiments, this step is: a single remittance r i Construct transaction node N for atomic i ={u i ,a i ,t i ,c i ,p i}, where ui is a globally unique key, a i is the amount, t i To unify the time zone timestamp, c i For currency, p i For the image pointer.

[0061] Optionally, cross-border transactions, KYC (Know Your Customer) files, and sanctions lists can be uniformly processed in terms of character sets, fields, and time zones. Format-preserving reversible encryption can be used for ID card numbers, passport numbers, or mobile phone numbers. After cleaning, key fields can be concatenated, and a globally unique key can be generated through a perturbation matrix and a bitwise XOR operation.

[0062] The corresponding specific steps are as follows: for cross-border transactions, KYC files and sanctions lists, first perform character set unification, field name remapping and separator standardization, then normalize and map all timestamps to UTC+0, and use minute-second error compensation Δτ≤1s to ensure cross-day continuity. For sensitive fields such as ID card number, mobile phone number, passport number, etc., use format-preserving encryption to perform reversible desensitization processing, so that the desensitized comparison symbols maintain cross-database consistency in subsequent hash operations. At this point, the three source data are losslessly aligned under the same parsing framework. For the records that have completed the cleansing, the key fields are spliced ​​into vector v i =[χ IDi ,χ Namei ,χ Banki ] T, and synchronously superimpose the first appearance time τ i , and then call the unified hash operator H(·) to generate a globally unique key:

[0063]

[0064] Where W is the non-trainable perturbation matrix, represents matrix multiplication, is bitwise exclusive OR.

[0065] (2) Traverse multiple candidate cross-border transaction information in ascending time order. When two adjacent candidate cross-border transaction information have the same currency, the same payment and receipt direction, and the time difference is less than a preset time length, establish an edge between the two adjacent candidate cross-border transaction information to obtain multiple transaction chain segments.

[0066] Optionally, this step is: traverse {N i}, when c i =c i+1 The direction of revenue and expenditure is consistent and 0<(t i+1 -t i )≤θ c When establishing an edge e between nodes i And append to the current segment S k ; The timestamps at the beginning and end of the chain segment are recorded as and Chain segment entities are precipitated as relationship layer nodes

[0067] (3) Determine at least one account information corresponding to the multiple candidate cross-border transaction information.

[0068] Optionally, this step is: extract account field a i and actual controller field b i Perform a two-way cross comparison. When a many-to-one or one-to-many mapping occurs, manual verification is triggered and the result is solidified as a unique subject node P. z and through the sanctions list interface for P z Bind external blacklist entries to achieve entity-level risk inheritance.

[0069] (4) Construct a three-layer heterogeneous graph information with candidate cross-border transaction information as transaction layer nodes, transaction chain segments as relationship layer nodes, and account information as subject layer nodes.

[0070] (5) Configure index information for each account information in the three-layer heterogeneous graph information, and the configured index information includes a time index and an account risk value index.

[0071] Optionally, this step is: i},{R k},{P z} and edge set {ei Generate a three-layer heterogeneous graph And according to φ r (Penalty basis) Calculate the initial risk of the node r i , the time dimension is t i ; Then construct the time-risk dual index:

[0072]

[0073] Among them, δ t and δ r The preset bin width.

[0074] Here, due to the selection of time bin width (such as seconds) and risk bin width, each node is configured with a time-risk dual index to achieve time positioning and high-risk priority retrieval.

[0075] (6) Based on the time index and risk value index, multiple cross-border transaction information with account risk values ​​greater than a preset threshold within a historical time period is queried from the three-layer heterogeneous graph information.

[0076] Optionally, multiple cross-border transaction information is a seed set to be replayed. Accordingly, this step is: according to the time index and risk value index, from the hierarchical heterogeneous graph Retrieve all the data with regulatory labels and risk scores higher than the threshold r min Account node, recorded as the starting account set For collections Any account a j , extract the timestamp of its most recent transaction and node risk value And according to the account dimension in the zipper index Write triples in This generates the first batch of seed sets to be replayed

[0077] S302. Determine the remaining effective working hours based on the difference between the supervision window duration and the system usage duration.

[0078] Optionally, this step is to start a countdown timer bound to the regulatory window and set the regulatory upper limit T reg = 24h, real-time reading of the system layer takes time T used , calculate the remaining effective working hours H0=T reg -T used .

[0079] S303. Determine the upper limit of the playback depth based on the ratio of the remaining effective working hours to the historical average time consumption of each layer of cross-border transaction information; the upper limit of the playback depth is used to limit the amount of cross-border transaction information on the cross-border transaction link.

[0080] Optionally, this step is: based on the remaining effective working hours, combined with the historical average traversal time per layer The initialization replay depth limit is:

[0081] S304: Generate multiple cross-border transaction links based on the upper limit of the playback depth and preset link generation conditions.

[0082] Optionally, this step includes the following steps (1) to (3):

[0083] (1) Using the transaction layer as the entry point, the seed collection Adopt the time series proximal priority strategy to expand adjacent transactions; each captured edge e j Calculate risk scores instantly and record its potential level of spread

[0084] The risk score is based on a comprehensive assessment of multiple factors including transaction amount, counterparty country risk, whether the company is on the sanctions list, and time decay:

[0085]

[0086] Among them, x j,1 is the normalized transaction amount, x j,2 is the counterparty country risk index, x j,3 is the currency sensitivity coefficient; time decay Δt j =t now -t j ; b j Indicates the sanctions list hit mark; α k ,β,γ,δ are the weights of offline calibration on the training set; 1 {·} is the indicator function.

[0087] (2) All candidate edges are divided into Enqueue to the maximum heap priority queue Q t The head of the team always keeps the edge with the highest risk; after the link is formed, the corresponding processing time is immediately deducted. and update the remaining hours

[0088] At the same time, the depth threshold is re-converged based on the real-time queue cost:

[0089]

[0090] In the formula, |Q t | is the number of edges in the current queue. Dynamically coupling the remaining working hours with the queue's average processing cost ensures that the diffusion depth shrinks in real time with remaining resources, fully aligning with regulatory deadlines.

[0091] (3) When the link first enters the relationship layer and detects a transaction substring with the same currency and continuous payment direction <e j ,e j+1 ,…,e j+m >, the system automatically aggregates into capital chain segment S seg , and Recalculate the risk weight of the chain segment; at the same time, retain the image pointers and original document pointers of the first and last transactions for direct call by subsequent cross-modal distillation.

[0092] It should be noted that, in some embodiments, all nodes, edges and their associated document streams can be written into the GPU memory pool in chronological order for the adopted link. Continuous address allocation is used during writing to ensure zero-copy reading and high-speed parallel access in the downstream inference stage. After each batch of writing is completed, the latest link status is immediately backfilled to the zipper index. And send a heartbeat signal to the monitoring thread; if H is detected t Below the preset freezing threshold H min , the system immediately freezes the current playback window and generates a data snapshot Σ t In this case, we can use the data snapshot Σ t The memory handle of the data snapshot Σ t Obtain multiple cross-border transaction links within a historical period.

[0093] Figure 4 A schematic diagram of a cross-border transaction processing method provided in an embodiment of the present application Figure 3 ,like Figure 4 As shown, the embodiment of the present application is Figure 2 Based on the embodiment, a possible implementation method for determining, for each cross-border transaction link, a link feature vector corresponding to the cross-border transaction link according to a preset semantic distillation network in S202 is described in detail. The method includes:

[0094] S401. For each cross-border transaction link, read the transaction image and text information of each cross-border transaction information in chronological order according to the image pointer in the cross-border transaction information.

[0095] Optionally, this step is: from the data snapshot Σ t Pull link number λ in batches q , and sequentially read the node objects N belonging to the same link q , image frame I q (including a scanned copy of the counter remittance application and a screenshot of the SWIFT receipt), the full text of the message M q (typically MT103 or MT799 message style) and OCR text generated by business camera missing word compensation q .

[0096] S402: Convert the transaction graphic information into a text sequence and input it into the regulatory field gating layer. The regulatory field gating layer checks and filters invalid content in the text sequence according to the regulatory keyword dictionary to obtain a compressed text sequence.

[0097] Optionally, this step may include the following steps (1) to (3):

[0098] (1) For image frame I q , call the region retrieval operator with geometric template constraints to construct a candidate window set at a fixed resolution Then, the comprehensive significance score is calculated for each candidate window and the maximum value window is selected as the three key areas of payment amount, paying bank, and business code; the complete area extraction formula is defined as:

[0099]

[0100] Among them, B q For the final set of key areas retained, I q (u,v) represents the pixel intensity, is the gradient field, Sal q (u,v) is the self-attention saliency map, and α, β, γ are weight constants.

[0101] Each b extracted q,k Enter the lightweight OCR module to complete character recognition and output character sequence and the corresponding rectangular frame coordinates The coordinates are stored in the device cache to ensure that the precise coordinates can be directly referenced for subsequent cross-modal alignment.

[0102] (2) Full text of message M q Perform field-level parsing. The parser automatically locates the following field tags based on the message protocol: 32A:, :52A:, :59:, etc., and accurately cuts the currency, beneficiary nationality, paying bank, and beneficiary address fields. The content of the cut field is recorded as Its byte offset interval in the character stream is recorded as

[0103] (3) Node timestamp t q As the global reference, the image rectangle Message range Text indexing with OCR Synchronize and map to the unified event axis, and construct a cross-modal alignment matrix:

[0104]

[0105] in, and are the time displacement vectors of the image and message fragments on the event axis, is the d-th dimension semantic encoding, D is the encoding dimension, θ d is the semantic alignment weight, and κ is the time decay coefficient.

[0106] Here, since the matrix A q The non-zero elements of mean that the time and content deviations of the same semantics have been eliminated between different modalities, ensuring that the subsequent feature distillation stage can directly aggregate information along the row index.

[0107] (4) A q Mapping to fragment sequence T q Then enter the regulatory field gating layer; the gating layer loads the regulatory keyword dictionary (covering OFAC sanctions list entries, beneficiary real-name verification trigger words, and high-penalty keywords), checking and filtering invalid content fragment by fragment, compressing the sequence and retaining the original fragment number:

[0108]

[0109] in, is the characteristic function, and ψ(·) is the gating operation.

[0110] Here, due to the strong constraint of preferentially preserving regulatory fields at the symbolic level, the input length for the next step of semantic distillation is significantly shortened.

[0111] S403: Input the compressed text sequence into a preset semantic distillation network to obtain a link feature vector corresponding to the cross-border transaction link.

[0112] Optionally, this step includes: q Transcode into token stream in the original order of appearance and embed the link risk label r at the beginning of the sequence q ; Then input the distillation network The network consists of four layers of self-attention and gated feedforward modules, which produce link-level vector representations through forward reasoning.

[0113] Figure 5 A schematic diagram of a cross-border transaction processing method provided in an embodiment of the present application Figure 4 ,like Figure 5 As shown, the embodiment of the present application is Figure 2 Based on the embodiment, a possible implementation method for determining the regulatory benefit parameter and regulatory cost parameter corresponding to the cross-border transaction link based on the investigation labor time and document review time in the time-consuming information in S203 is described in detail. The method includes:

[0114] S501: Call the historical penalty database to determine the overlap of historical penalties in the cross-border transaction link.

[0115] S502: Determine the penalty trigger probability and the penalty upper limit information based on the link feature vector, the historical penalty overlap and the transaction amount.

[0116] Optional, this step is: call the historical penalty database and the current sanctions list, based on the link feature vector z q , the overlap of past fines H q With transaction amount a q Calculating the probability of fines being triggered and fine cap

[0117]

[0118] Among them, u q is the historical violation semantic vector, w p is the penalty probability weight, η is the historical coincidence gain, ξ and ρ are penalty linear coefficients, β is the penalty nonlinear amplification exponent, l q The cumulative layer length of the link.

[0119] S503. Determine the regulatory benefit parameter corresponding to the cross-border transaction link based on the product of the penalty trigger probability and the penalty upper limit information.

[0120] For example, the regulatory yield parameter is:

[0121] S504: Determine the total duration of the investigation labor time and the document review time, and determine the supervision cost parameter corresponding to the cross-border transaction link based on the product of the total duration and the preset unit price information.

[0122] For example, the preset unit price information is the bank labor unit price, and the supervision cost parameter is the bank investigation cost. hr , will investigate the cost Convert it into monetary value and write it into the benefit-cost matrix together with the expected penalty:

[0123]

[0124] Among them, the order of rows and columns of the matrix corresponds to the four entities: <E bank ,E cust ,E assoc ,E reg >, banks, customers, related parties, regulators; and Potential benefits for customers and related parties, Prove material costs for customers. Consumption of regulatory approval resources.

[0125] Figure 6 A schematic diagram of a cross-border transaction processing method provided in an embodiment of the present application Figure 5 ,like Figure 6 As shown, the embodiment of the present application is Figure 2 Based on the embodiment, a possible implementation method for determining the investigation sequence information corresponding to the cross-border transaction link according to the regulatory benefit parameter and the regulatory cost parameter in S204 is described in detail. The method includes:

[0126] S601: Calling a Monte Carlo game searcher to determine multiple random survey sequences of cross-border transaction links.

[0127] Optionally, for each encoded state φ i , calling the Monte Carlo game searcher in the action space Expand the random survey sequence π i .

[0128] S602: For each random survey sequence, determine the penalty recovery parameter and the cumulative resource consumption parameter of the random survey sequence through a preset path evaluation model.

[0129] S603. Determine the comprehensive benefit parameter of the random survey sequence according to the difference between the penalty recovery parameter and the cumulative resource consumption parameter.

[0130] Optionally, this step is: accumulating resource consumption during the search process When C(π i ) Exceeding the real-time resource limit H rem Prune immediately when . The path evaluation function (also known as the comprehensive benefit parameter) is:

[0131]

[0132] Among them, κ is the resource penalty coefficient, Q f From the penalty branch online estimate.

[0133] Here, the search can be made to prioritize paths with high penalty recovery and low resource consumption, and an indicator function can be used to ensure that any over-limit sequence is scored zero and discarded.

[0134] The following describes the steps for obtaining an online estimate of the penalty branch:

[0135] First, for any state s i , and record its link vector z i , penalty expectation and resource consumption benchmark χ i , forming a triple In order to focus on learning in high-penalty and high-cost states, this application proposes and adopts a risk-cost balancing strategy:

[0136]

[0137] Among them, ρ,v is the temperature coefficient, which is adjusted offline through the historical penalty surface to ensure that the experience pool covers high-risk samples in the early stage, so that the dual-Q network will form a preference for the links with the highest regulatory concern from the startup stage.

[0138] Secondly, after the state vectorization is completed by sharing the first half layer encoder Ψ(·) through the dual Q framework, the output feature φ i =Ψ(s i ) and sent to the penalty branch Q f With resource fork Q r In order to make the two branches lose dynamic response to the real-time resource margin H rem , the system introduces an adjustable multiplier λ t =σ(γ1H rem -γ2), which decreases monotonically with the remaining working time. The overall multi-objective loss function at the time section of training step t is:

[0139]

[0140] in, is the dual-objective TD return, θ f ,θ r is the branch parameter, θ s is the shared encoder parameter and ζ is the stabilization coefficient.

[0141] It should be noted that the feasible path returned by the Monte Carlo search can be written back to the experience pool and compared with the corresponding real penalty. and actual resource consumption Align and update Q with a dual-branch TD objective f ,Q r Parameters; Strengthen the network's value estimation of high-return and low-cost strategies, and improve the cost-effectiveness of the investigation action sequence round by round. Furthermore, the penalty expectation curve is monitored in real time during the training cycle. The single-step decrease amplitude, when the decrease rate is detected to be lower than the threshold ε d That is, the network is considered to be close to the penalty convergence boundary. At this time, the shared encoder Ψ(·) is frozen and only the branch layer is allowed to be fine-tuned to avoid overfitting and dual-target oscillation.

[0142] S604. Select a random survey sequence with the highest comprehensive benefit parameter from multiple random survey sequences as survey sequence information corresponding to the cross-border transaction link.

[0143] Optionally, when the comprehensive performance indicators of both branches meet the remaining working time threshold Hrem ≥H min and penalty expectation threshold When , the training stops and all parameters are solidified; then a forward inference is performed on each link to be investigated, and the The criterion outputs the shortest investigation action sequence to maximize resource utilization.

[0144] The following describes the anomaly detection of cross-border transaction links based on the investigation sequence information in step S204 through a specific embodiment. The anomaly detection method may include the following steps (1) to (4):

[0145] (1) According to the action sequence π q Define the access order, link λ q Expand from top to bottom according to the node risk value to generate the first version of the node sequence to be checked And maintain the consistency of priorities within the sequence in a monotonically decreasing manner with risk value.

[0146] (2) For the sequence Ω q Each node n in q,k , the system synchronously calls the penalty contribution allocator, the labor time predictor and the historical success rate query to obtain the node-level expected penalty reduction ΔF q,k , survey working hours T q,k and success rate σ q,k The penalty contribution is shared through the risk amplification index and the sanction matching weight:

[0147]

[0148] Among them, r q,k is the node risk value, w q,k is the sanction matching weight, α is the amplification index, ΔF q Provides estimates for link-level penalty reductions.

[0149] (3) The indicator triple < ΔF q,k ,T q,k ,σ q,k >Concatenate with the node base field to generate a structured row object Γ q,k , and record the parameter source and data snapshot version number in its remarks field to ensure that future regulatory audits can directly restore all calculation basis based on row objects.

[0150] (4) Aggregate row objects based on the link dimension to form a decision table T q , together with the remaining working hours of the team on that day H team And the node forecast working time T q,kThe result is sent to the scheduling microservice. After receiving the decision table, the scheduling service immediately executes the linear allocation algorithm, attempts to match all nodes to be checked within the current team resource window, and outputs an executable or excess status indicator.

[0151] (5) When the scheduling feedback exceeds the quota, the system calculates the occupancy-contribution ratio for the nodes still in the list:

[0152]

[0153] Among them, γ is the penalty coefficient for failed rework, and β is the success rate reduction coefficient. q,k Sort in ascending order, mark the tail node with the largest ratio as the candidate for pruning and temporarily remove it from the decision table.

[0154] (6) The trimmed decision table is immediately resubmitted to the scheduling microservice for resource verification; if there is still an overage, the system recalculates ρ q,k And continue cutting until H is satisfied team If resources are still insufficient, the system will automatically issue an alert to add a team or delay the investigation, and push the manpower gap and delay duration to the operations management end.

[0155] (7) When the schedule returns to the "executable" state, the system freezes the final set of nodes to be checked And generate an execution list q Then push it to the survey end q , and register the estimated total penalty reduction and final working hours And write the execution checklist and key indicators into the supervision audit chain Complete the closed-loop lock of resource benefits.

[0156] Figure 7 A schematic diagram of a cross-border transaction processing device provided in an embodiment of the present application Figure 1 ,like Figure 7 As shown, the device includes:

[0157] An acquisition module 701 is configured to acquire a plurality of cross-border transaction links within a historical period, wherein the cross-border transaction links include information on a plurality of cross-border transactions with an account risk value greater than a preset threshold;

[0158] A first determining module 702 is configured to determine, for each cross-border transaction link, a link feature vector corresponding to the cross-border transaction link based on a preset semantic distillation network, wherein the link feature vector includes regulatory feature information of the cross-border transaction link;

[0159] A second determination module 703 is configured to use the link feature vector to call a time consumption prediction model to determine time consumption information corresponding to the cross-border transaction link, and determine a regulatory benefit parameter and a regulatory cost parameter corresponding to the cross-border transaction link based on the investigation labor time and document review time in the time consumption information;

[0160] Processing module 704 is used to determine the investigation sequence information corresponding to the cross-border transaction link based on the regulatory benefit parameter and the regulatory cost parameter, the investigation sequence information including multiple target cross-border transaction information to be detected and the detection order of the multiple target cross-border transaction information, and perform anomaly detection on the cross-border transaction link based on the investigation sequence information.

[0161] In one possible implementation, the acquisition module 701 acquires multiple cross-border transaction links within a historical time period, including: acquiring multiple cross-border transaction information within the historical time period whose account risk value is greater than a preset threshold; determining the remaining effective working hours based on the difference between the regulatory window duration and the system usage duration; determining the upper limit of the playback depth based on the ratio of the remaining effective working hours to the historical average time consumption of each layer of cross-border transaction information; the upper limit of the playback depth is used to limit the number of cross-border transaction information on the cross-border transaction link; and generating multiple cross-border transaction links based on the upper limit of the playback depth and preset link generation conditions.

[0162] In a possible implementation, the acquisition module 701 acquires multiple cross-border transaction information in which the account risk value within the historical time period is greater than a preset threshold, including: acquiring candidate cross-border transaction information based on a single remittance as a dimension, the candidate cross-border transaction information including the global unique key, amount, time, currency and image pointer of the single remittance; wherein the image pointer includes the storage address of the transaction image information; traversing multiple candidate cross-border transaction information in ascending order of time, when the currency of two adjacent candidate cross-border transaction information is the same, the payment direction is consistent and the time difference is less than the preset time length, the two adjacent candidate cross-border transaction information are selected. Establish edges between transaction information to obtain multiple transaction segments; determine at least one account information corresponding to the multiple candidate cross-border transaction information; construct a three-layer heterogeneous graph information with the candidate cross-border transaction information as the transaction layer node, the transaction segment as the relationship layer node, and the account information as the main layer node; configure index information for each account information in the three-layer heterogeneous graph information, the configured index information including a time index and an account risk value index; based on the time index and the risk value index, query the three-layer heterogeneous graph information for multiple cross-border transaction information whose account risk value is greater than a preset threshold within a historical time period.

[0163] In one possible implementation, the first determination module 702 determines, for each cross-border transaction link, a link feature vector corresponding to the cross-border transaction link based on a preset semantic distillation network, including: for each cross-border transaction link, reading the transaction image and text information of each cross-border transaction information in chronological order according to the image pointer in the cross-border transaction information; converting the transaction image and text information into a text sequence and inputting it into a regulatory field gating layer, using the regulatory field gating layer to check and filter invalid content in the text sequence according to a regulatory keyword dictionary to obtain a compressed text sequence; and inputting the compressed text sequence into a preset semantic distillation network to obtain a link feature vector corresponding to the cross-border transaction link.

[0164] In one possible implementation, the second determination module 703 determines the regulatory benefit parameters and regulatory cost parameters corresponding to the cross-border transaction link based on the investigation labor time and document review time in the time-consuming information, including: calling the historical penalty database to determine the historical penalty overlap of the cross-border transaction link; determining the penalty trigger probability and the penalty upper limit information based on the link feature vector, the historical penalty overlap and the transaction amount; determining the regulatory benefit parameter corresponding to the cross-border transaction link based on the product of the penalty trigger probability and the penalty upper limit information; determining the total duration of the investigation labor time and the document review time, and determining the regulatory cost parameter corresponding to the cross-border transaction link according to the product of the total duration and the preset unit price information.

[0165] In one possible implementation, the processing module 704 determines the investigation sequence information corresponding to the cross-border transaction link based on the regulatory benefit parameter and the regulatory cost parameter, including: calling a Monte Carlo game searcher to determine multiple random investigation sequences of the cross-border transaction link; for each random investigation sequence, determining the penalty recovery parameter and the cumulative resource consumption parameter of the random investigation sequence through a preset path evaluation model; determining the comprehensive benefit parameter of the random investigation sequence based on the difference between the penalty recovery parameter and the cumulative resource consumption parameter; and selecting the random investigation sequence with the highest comprehensive benefit parameter from the multiple random investigation sequences as the investigation sequence information corresponding to the cross-border transaction link.

[0166] Figure 8 This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present application. Figure 8 As shown, the electronic device 800 provided in this embodiment includes: at least one processor 801 and a memory 802. Optionally, the device 800 also includes a communication component 803. The processor 801, the memory 802 and the communication component 803 are connected via a bus 804.

[0167] During the specific implementation process, at least one processor 801 executes the computer-executable instructions stored in the memory 802, so that the at least one processor 801 performs the above method.

[0168] The specific implementation process of the processor 801 can be found in the above method embodiment. Its implementation principle and technical effects are similar and will not be repeated here in this embodiment.

[0169] In the above embodiments, it should be understood that the processor may be a central processing unit (CPU), other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), etc. A general-purpose processor may be a microprocessor or any conventional processor. The steps of the method disclosed in the present invention may be directly implemented by a hardware processor or implemented by a combination of hardware and software modules in the processor.

[0170] The memory may include a high-speed memory (Random Access Memory, RAM), and may also include a non-volatile memory (NVM), such as at least one disk memory.

[0171] The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus. Buses can be classified into address buses, data buses, and control buses. For ease of illustration, the buses in the drawings of this application are not limited to just one bus or just one type of bus.

[0172] An embodiment of the present application also provides a computer program product, including a computer program, which implements the above method when executed by a processor.

[0173] An embodiment of the present application further provides a computer-readable storage medium, in which computer-executable instructions are stored. When a processor executes the computer-executable instructions, the above-mentioned method is implemented.

[0174] The above-mentioned readable storage medium can be implemented by any type of volatile or non-volatile memory device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, magnetic disk or optical disk. The readable storage medium can be any available medium that can be accessed by a general-purpose or special-purpose computer.

[0175] An exemplary readable storage medium is coupled to a processor so that the processor can read information from the readable storage medium and write information to the readable storage medium. Of course, the readable storage medium can also be an integral part of the processor. The processor and the readable storage medium can be located in an application specific integrated circuit (ASIC). Of course, the processor and the readable storage medium can also exist in the device as discrete components.

[0176] It should be noted that for the aforementioned method embodiments, for the sake of simplicity, they are all expressed as a series of action combinations, but those skilled in the art should be aware that this application is not limited by the order of the actions described, because according to this application, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in this specification are all optional embodiments, and the actions and modules involved are not necessarily required by this application.

[0177] It should be further noted that, although the various steps in the flowchart are shown in sequence as indicated by the arrows, these steps are not necessarily performed in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order restriction on the execution of these steps, and these steps may be performed in other orders. Moreover, at least a portion of the steps in the flowchart may include multiple sub-steps or multiple stages, and these sub-steps or stages are not necessarily performed at the same time, but may be performed at different times. The execution order of these sub-steps or stages is not necessarily to be performed in sequence, but may be performed in turn or alternately with other steps or at least a portion of the sub-steps or stages of other steps.

[0178] It should be noted that the terms "first," "second," and the like in the claims, the specification, and the accompanying drawings are used to distinguish similar objects and are not necessarily used to describe a particular order or precedence. It should be understood that the terms used in this manner are interchangeable where appropriate, so that the embodiments of the invention described herein, for example, can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having," and any variations thereof, are intended to cover non-exclusive inclusions. For example, a process, system, product, or apparatus comprising a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units that are not explicitly listed or that are inherent to these processes, products, or apparatuses.

[0179] It should be understood that the above-described device embodiments are merely illustrative, and the device of the present application may also be implemented in other ways. For example, the division of units / modules in the above-described embodiments is merely a logical functional division, and actual implementations may employ other division methods. For example, multiple units, modules, or components may be combined or integrated into another system, or some features may be omitted or not implemented.

[0180] In addition, unless otherwise specified, the functional units / modules in the various embodiments of the present application may be integrated into a single unit / module, each unit / module may exist physically separately, or two or more units / modules may be integrated together. The aforementioned integrated units / modules may be implemented in the form of hardware or software program modules.

[0181] If the integrated unit / module is implemented in hardware, the hardware may be digital circuits, analog circuits, etc. The physical implementation of the hardware structure includes, but is not limited to, transistors, memristors, etc. Unless otherwise specified, the processor may be any appropriate hardware processor, such as a CPU, GPU, FPGA, DSP, and ASIC. Unless otherwise specified, the storage unit may be any appropriate magnetic storage medium or magneto-optical storage medium, such as resistive random access memory (RRAM), dynamic random access memory (DRAM), static random access memory (SRAM), enhanced dynamic random access memory (EDRAM), high-bandwidth memory (HBM), hybrid memory cube (HMC), etc.

[0182] If the integrated unit / module is implemented in the form of a software program module and sold or used as an independent product, it can be stored in a computer-readable memory. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product, which is stored in a memory and includes a number of instructions for enabling a computer device (which can be a personal computer, server or network device, etc.) to execute all or part of the steps of the various embodiments of the present application. The aforementioned memory includes various media that can store program codes, such as a USB flash drive, a read-only memory (ROM), a random access memory (RAM), a mobile hard disk, a magnetic disk or an optical disk.

[0183] In the above embodiments, the description of each embodiment has its own emphasis. For parts not described in detail in a particular embodiment, please refer to the relevant description of other embodiments. The technical features of the above embodiments can be combined in any way. To keep the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0184] Those skilled in the art will readily appreciate other embodiments of the present application after considering the specification and practicing the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of the present application that follow the general principles of the present application and include common knowledge or customary techniques in the art not disclosed herein. The description and examples are to be considered as exemplary only, and the true scope and spirit of the present application are indicated by the following claims.

[0185] It should be understood that the present application is not limited to the exact structure described above and shown in the drawings, and that various modifications and changes may be made without departing from the scope thereof. The scope of the present application is limited only by the appended claims.

Claims

1. A method for processing cross-border transactions, characterized in that: The method comprises: Acquire multiple cross-border transaction links within a historical time period, wherein the cross-border transaction links include cross-border transaction information with multiple account risk values ​​greater than a preset threshold; For each cross-border transaction link, determine a link feature vector corresponding to the cross-border transaction link based on a preset semantic distillation network. The link feature vector includes regulatory feature information of the cross-border transaction link. Using the link feature vector, a time consumption prediction model is called to determine the time consumption information corresponding to the cross-border transaction link, and based on the investigation labor time and document review time in the time consumption information, the regulatory benefit parameter and regulatory cost parameter corresponding to the cross-border transaction link are determined; Based on the regulatory benefit parameter and the regulatory cost parameter, the investigation sequence information corresponding to the cross-border transaction link is determined. The investigation sequence information includes multiple target cross-border transaction information to be detected and the detection order of the multiple target cross-border transaction information. The cross-border transaction link is detected for anomalies based on the investigation sequence information.

2. The processing method according to claim 1, characterized in that The acquisition of multiple cross-border transaction links within a historical time period includes: Obtain information on multiple cross-border transactions within a historical period where the account risk value exceeds a preset threshold; Determine the remaining effective working hours based on the difference between the supervision window duration and the system usage duration; Determine the upper limit of the playback depth based on the ratio of the remaining effective working hours to the historical average time consumption of each layer of cross-border transaction information; the upper limit of the playback depth is used to limit the number of cross-border transaction information on the cross-border transaction link; Based on the playback depth upper limit and preset link generation conditions, multiple cross-border transaction links are generated.

3. The processing method according to claim 2, characterized in that The obtaining of multiple cross-border transaction information in which the account risk value within the historical time period is greater than a preset threshold includes: Obtain candidate cross-border transaction information based on a single remittance, the candidate cross-border transaction information including a globally unique key, amount, time, currency, and image pointer of the single remittance; wherein the image pointer includes a storage address of the transaction image and text information; Traversing multiple candidate cross-border transaction information in ascending time order, when two adjacent candidate cross-border transaction information have the same currency, the same payment and receipt direction, and a time difference less than a preset time duration, establishing an edge between the two adjacent candidate cross-border transaction information to obtain multiple transaction chain segments; Determining at least one account information corresponding to the plurality of candidate cross-border transaction information; Constructing a three-layer heterogeneous graph information with the candidate cross-border transaction information as a transaction layer node, the transaction chain segment as a relationship layer node, and the account information as a subject layer node; Configuring index information for each account information in the three-layer heterogeneous graph information, wherein the configured index information includes a time index and an account risk value index; According to the time index and the risk value index, multiple cross-border transaction information with account risk values ​​greater than a preset threshold within a historical time period is queried from the three-layer heterogeneous graph information.

4. The processing method according to claim 1, characterized in that For each cross-border transaction link, determining a link feature vector corresponding to the cross-border transaction link according to a preset semantic distillation network includes: For each cross-border transaction link, read the transaction image and text information of each cross-border transaction information in chronological order according to the image pointer in the cross-border transaction information; The transaction graphic information is converted into a text sequence and then input into a regulatory field gating layer, and the regulatory field gating layer checks and filters invalid content in the text sequence according to a regulatory keyword dictionary to obtain a compressed text sequence; The compressed text sequence is input into a preset semantic distillation network to obtain a link feature vector corresponding to the cross-border transaction link.

5. The processing method according to claim 1, characterized in that Determining the regulatory benefit parameter and regulatory cost parameter corresponding to the cross-border transaction link based on the investigation labor time and document review time in the time-consuming information includes: Calling the historical penalty database to determine the overlap of historical penalties for the cross-border transaction link; Determining a penalty trigger probability and a penalty upper limit based on the link feature vector, the historical penalty overlap, and the transaction amount; Determining a regulatory benefit parameter corresponding to the cross-border transaction link based on the product of the penalty trigger probability and the penalty upper limit information; Determine the total duration of the investigation labor time and the document review time, and determine the supervision cost parameter corresponding to the cross-border transaction link based on the product of the total duration and the preset unit price information.

6. The processing method according to claim 1, characterized in that The determining, based on the regulatory benefit parameter and the regulatory cost parameter, the investigation sequence information corresponding to the cross-border transaction link includes: Invoking a Monte Carlo game searcher to determine multiple random survey sequences of the cross-border transaction link; For each random survey sequence, determine the penalty recovery parameter and the cumulative resource consumption parameter of the random survey sequence through a preset path evaluation model; Determining a comprehensive benefit parameter of the random survey sequence according to a difference between the penalty recovery parameter and the cumulative resource consumption parameter; A random survey sequence with the highest comprehensive benefit parameter is selected from multiple random survey sequences as the survey sequence information corresponding to the cross-border transaction link.

7. A cross-border transaction processing device, characterized in that: The device comprises: An acquisition module, configured to acquire a plurality of cross-border transaction links within a historical period, wherein the cross-border transaction links include information on a plurality of cross-border transactions whose account risk values ​​are greater than a preset threshold; A first determination module is configured to determine, for each cross-border transaction link, a link feature vector corresponding to the cross-border transaction link based on a preset semantic distillation network, wherein the link feature vector includes regulatory feature information of the cross-border transaction link; A second determination module is configured to use the link feature vector to call a time consumption prediction model to determine time consumption information corresponding to the cross-border transaction link, and determine a regulatory benefit parameter and a regulatory cost parameter corresponding to the cross-border transaction link based on the investigation labor time and document review time in the time consumption information; A processing module is used to determine, based on the regulatory benefit parameter and the regulatory cost parameter, investigation sequence information corresponding to the cross-border transaction link, the investigation sequence information including multiple target cross-border transaction information to be detected and the detection order of the multiple target cross-border transaction information, and perform anomaly detection on the cross-border transaction link based on the investigation sequence information.

8. An electronic device, characterized in that: The electronic device includes: a memory and a processor; The memory stores computer-executable instructions; The processor executes the computer-executable instructions stored in the memory, so that the processor performs the method according to any one of claims 1 to 6.

9. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer-executable instructions, which are used to implement the method according to any one of claims 1 to 6 when executed by a processor.

10. A computer program product, comprising a computer program, wherein when the computer program is executed by a processor, the method according to any one of claims 1 to 6 is implemented.