Abnormal transaction identification method and device, equipment, storage medium and product
By quantifying and calculating the similarity of transaction information and combining it with a machine learning model to identify abnormal transactions, the problems of low recognition efficiency and poor accuracy in existing technologies are solved, and efficient and accurate abnormal transaction monitoring is achieved.
Patent Information
- Application Number
- CN202510863385.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-25
- Publication Date
- 2025-09-30
AI Technical Summary
Existing technologies have difficulty adapting to changing trading environments when identifying abnormal transactions. Manual identification is inefficient and rule updates lag, resulting in frequent missed reports and difficulty in capturing subtle differences and correlations between transactions.
By obtaining the transaction information to be identified and performing quantitative processing, similarity calculation is performed with the historical abnormal transaction data set. Algorithms such as Jaccard similarity are used to determine whether the transaction is abnormal, and a second confirmation is performed in combination with a machine learning model.
It improves the accuracy and real-time performance of abnormal transaction identification, reduces reliance on manual intervention, enables timely detection of potential risks, and ensures transaction security.
Smart Images

Figure CN120725680A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of big data, and in particular to a method, device, equipment, storage medium and product for identifying abnormal transactions. Background Art
[0002] With the rapid development of internet technology, electronic transactions, thanks to their convenience, have rapidly become widespread, encompassing a wide range of areas, including shopping, digital asset trading, and virtual services. The scale of transactions continues to expand. However, at the same time, transaction security issues are becoming increasingly prominent, with abnormal transactions becoming a frequent occurrence. Abnormal transactions not only disrupt market order and undermine the fairness and stability of the trading ecosystem, but also expose users to financial losses and security risks, becoming a prominent issue that needs to be addressed urgently.
[0003] To ensure the security of electronic transactions, various technologies are currently used to identify and warn of unusual transactions. Rule-based detection technologies use pre-set thresholds based on factors such as the value of the transaction item, the credit ratings of both parties, and transaction frequency. When a transaction crosses the threshold, it is flagged as suspicious and issued a warning.
[0004] However, with the rapid growth in the number of transactions, manual review of each transaction takes a long time and transaction processing is slow. Rule-based detection relies on manual experience and historical data to set rules, which makes it difficult to fully cover complex and changeable abnormal transaction patterns. Rule updates are delayed and missed reports are prone to occur. Summary of the Invention
[0005] The present application provides a method, apparatus, device, storage medium and product for identifying abnormal transactions, which are used to solve the problem that identifying abnormal transactions based on preset rules is difficult to adapt to changing transaction environments and manual identification is inefficient.
[0006] In a first aspect, the present application provides a method for identifying abnormal transactions, comprising:
[0007] Obtaining first transaction information of a transaction to be identified;
[0008] quantifying the first transaction information to obtain a transaction data set;
[0009] Determining a plurality of similarities based on the transaction data set and each transaction data subset in the abnormal transaction data set; the similarities are used to indicate the degree of similarity between the transaction data set and the transaction data subset;
[0010] If at least one similarity among the plurality of similarities is greater than a preset threshold, the transaction to be identified is determined to be an abnormal transaction.
[0011] In a second aspect, the present application provides a device for identifying abnormal transactions, comprising:
[0012] an acquisition module, configured to acquire first transaction information of a transaction to be identified;
[0013] a processing module, configured to perform quantification processing on the first transaction information to obtain a transaction data set;
[0014] a determination module, configured to determine a plurality of similarities based on the transaction data set and each transaction data subset in the abnormal transaction data set; the similarities being used to indicate a degree of similarity between the transaction data set and the transaction data subset;
[0015] The determination module is further configured to determine that the transaction to be identified is an abnormal transaction if at least one similarity among the plurality of similarities is greater than a preset threshold.
[0016] In a third aspect, the present application provides an electronic device, comprising: a processor, and a memory communicatively connected to the processor;
[0017] The memory stores computer-executable instructions;
[0018] The processor executes the computer-executable instructions stored in the memory to implement the method for identifying abnormal transactions as described in the first aspect and various possible implementations of the first aspect.
[0019] In a fourth aspect, the present application provides a computer-readable storage medium having computer-executable instructions stored thereon, which, when executed by a processor, are used to implement the method for identifying abnormal transactions as described in the first aspect and various possible implementations of the first aspect.
[0020] In a fifth aspect, the present application provides a program product, including a computer program, which implements the above-mentioned method for identifying abnormal transactions when executed by a processor.
[0021] The abnormal transaction identification method, apparatus, device, storage medium, and product provided in this application quantify the transaction data of the transaction to be identified to obtain a transaction data set. This transaction data set is then compared with multiple subsets of transaction data corresponding to previously quantified abnormal transactions, and the similarity between the two is calculated. Based on this similarity, the identification of the transaction to be identified is determined to be abnormal. This method can capture subtle differences between transaction characteristics, improving identification accuracy, and enabling real-time monitoring and analysis of transaction data, facilitating the timely detection of abnormal transactions and reducing reliance on manual intervention. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.
[0023] Figure 1 A schematic diagram of a method for identifying abnormal transactions provided in an embodiment of the present application Figure 1 ;
[0024] Figure 2 A schematic diagram of a method for identifying abnormal transactions provided in an embodiment of the present application Figure 2 ;
[0025] Figure 3 A schematic diagram of a method for identifying abnormal transactions provided in an embodiment of the present application Figure 3 ;
[0026] Figure 4 A schematic diagram of the structure of an abnormal transaction identification device provided by this application;
[0027] Figure 5 This is a schematic diagram of the structure of an electronic device provided in this application.
[0028] The above drawings illustrate specific embodiments of the present application, which will be described in more detail below. These drawings and the textual description are not intended to limit the scope of the present application in any way, but rather to illustrate the concepts of the present application to those skilled in the art by reference to specific embodiments. DETAILED DESCRIPTION
[0029] Exemplary embodiments will be described in detail herein, with examples illustrated in the accompanying drawings. In the following description, when referring to the drawings, identical numerals in different figures represent identical or similar elements, unless otherwise indicated. The embodiments described in the following exemplary embodiments are not intended to represent all embodiments consistent with the present application. Rather, they are merely examples of apparatus and methods consistent with certain aspects of the present application, as detailed in the appended claims.
[0030] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, storage, use, processing, transmission, provision, disclosure and application of relevant data comply with relevant laws, regulations and standards, take necessary confidentiality measures, do not violate public order and good morals, and provide corresponding operation entrances for users to choose to authorize or refuse.
[0031] In addition, this application involves conducting big data analysis of user information (including but not limited to personal biometrics, identity data, consumption data, asset data, electronic terminal operation data, etc.), and using artificial intelligence technology to make automated decisions, and making technical solutions that have a significant impact on personal rights and interests based on the results of automated decisions. The application provides users with corresponding operation entrances for them to choose to agree or reject the results of automated decisions; if the user chooses to reject, the expert decision-making process will be entered.
[0032] It should be noted that the abnormal transaction identification method, device, equipment, storage medium and product provided in this application can be used in the big data field, and can also be used in any field other than big data. The application field of the abnormal transaction identification method, device, equipment, storage medium and product in this application is not limited.
[0033] Innovations in internet technology have fueled the rapid growth of electronic transactions. Their convenience and efficiency have reshaped the business landscape. From everyday online shopping to financial investments, electronic transactions have become deeply integrated into everyday life. However, as transaction volume and complexity increase, security issues are becoming increasingly prominent. Abnormal transactions are common, with some exploiting item scarcity, unique attributes, or historically high price differences to conduct transactions far exceeding normal values. Others obtain funds through illicit means such as creating fake accounts for fraudulent transactions, hacking accounts, and using third-party top-ups. These practices severely disrupt market order, threaten the financial security of participants, and undermine the stability of the electronic trading ecosystem.
[0034] To address abnormal transactions, the industry employs a variety of detection technologies. Early on, manual review was relied upon, with professionals using their experience to determine transaction compliance. However, with the exponential growth of electronic transaction data, manual review is inefficient, costly, and prone to errors, making it difficult to meet demand. Today, automated detection technology has become mainstream, with common methods including rule engines and machine learning models. These engines use pre-set transaction rules, such as maximum transaction amounts and frequency thresholds, to compare transaction data in real time, identifying violations as abnormalities.
[0035] However, rule development is limited by experience and specific scenarios. New anomalous trading methods continue to emerge, and rule updates lag behind, leading to frequent underreporting. Machine learning models require vast amounts of training data and are susceptible to noise. This leads to high hardware costs, slow response times, limited flexibility, and low operational efficiency. Furthermore, existing technologies often analyze individual transactions in isolation, ignoring transaction correlations and making it difficult to identify hidden anomalous transactions, such as those involving linked accounts. This limits the accuracy and comprehensiveness of detection.
[0036] In response to the above problems, this application proposes a method for identifying abnormal transactions. By determining the similarity between the transaction information of the transaction to be identified and historical abnormal transactions, it is possible to identify whether the transaction to be identified is an abnormal transaction. This can reduce reliance on manual review, thereby reducing operating costs. At the same time, it can accurately capture subtle differences and similarities between transactions, thereby improving recognition accuracy.
[0037] This application can be applied to multiple scenarios. In the financial field, it covers banks, insurance companies and other institutions. For example, by monitoring the flow of funds, transaction frequency and scale anomalies, illegal fund transfer chains can be uncovered. In e-commerce transactions, it can quickly lock in abnormal operations such as using fake accounts to swipe orders and hype reputation, stealing other people's accounts to buy high-priced goods, etc., to ensure the fairness of platform transactions and the rights of consumers. In the game industry, it can capture illegal transactions such as players obtaining virtual currency through plug-in programs and studios creating accounts in batches to swipe game props.
[0038] The following specific embodiments describe in detail the technical solution of the present application and how the technical solution of the present application solves the above-mentioned technical problems. The following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The embodiments of the present application will be described below in conjunction with the accompanying drawings.
[0039] Figure 1 A schematic diagram of a method for identifying abnormal transactions provided in an embodiment of the present application Figure 1 .like Figure 1 As shown, the method for identifying abnormal transactions provided in this embodiment includes:
[0040] S101: Acquire first transaction information of a transaction to be identified.
[0041] It can be understood that obtaining the first transaction information of the transaction to be identified is the first step in identifying abnormal transactions. When a transaction is initiated, the transaction identification system can extract various types of original transaction data related to the transaction through various channels and methods. For example, it can obtain transaction data by connecting to the interface of the transaction system, or it can extract transaction data from the log records of the transaction by parsing the log file.
[0042] Transaction data can include basic information about the initiator of the transaction, such as account number and customer identification, which helps clarify the subject of the transaction; specific details of the transaction execution, such as transaction time and transaction amount. Transaction time can reflect the time period in which the transaction occurred, and the transaction amount is often correlated with the degree of transaction risk; and the type of business involved in the transaction, such as transfer, payment, or investment. Different business types have their own unique risk characteristics. By comprehensively collecting this multi-dimensional and multi-level primary transaction information, transactions can be identified from multiple perspectives, avoiding omissions in transaction information and ensuring accurate transaction identification.
[0043] S102: Quantify the first transaction information to obtain a transaction data set.
[0044] Quantization processing refers to converting the acquired first transaction information into computer-processable numerical data to form a transaction data set. Quantization processing can include data cleaning to remove erroneous data, feature extraction to extract meaningful features from the raw data, and numerical encoding, such as using one-hot encoding or label encoding to convert textual data in the transaction information into numerical feature vectors.
[0045] Understandably, first transaction information is diverse in form, containing large amounts of text, numerical values, and other different types of data. Direct analysis and comparison presents significant challenges. Therefore, it is possible to convert the original first transaction information into numerical form that computers can understand and process, thereby constructing a transaction data set. This quantification process transforms the originally complex and diverse first transaction information into a clearly structured, easily computable transaction data set, providing a standardized data foundation for subsequent similarity calculations and abnormal transaction identification.
[0046] S103: Determine multiple similarities based on the transaction data set and each transaction data subset in the abnormal transaction data set.
[0047] The similarity is used to indicate the similarity between a transaction data set and a transaction data subset.
[0048] As can be understood, similarity calculation can quantitatively measure the degree of similarity between the transaction to be identified and known abnormal transactions. The abnormal transaction data set can be pre-collected and collated through extensive historical data analysis, risk model construction, and expert experience summary. It contains multiple transaction data subsets, each representing a known abnormal transaction pattern or category.
[0049] When calculating similarity, the transaction identification system can apply specific algorithms or models to compare and analyze the transaction data set of the transaction to be identified with each subset of the transaction data within the abnormal transaction data set. By comprehensively considering various dimensional characteristics of the transaction data set, such as amount distribution, transaction frequency, and temporal patterns, the system determines the degree of similarity between the two by calculating metrics such as the distance between feature vectors and the correlation coefficient. By calculating multiple similarities, the system can comprehensively and meticulously assess the correlation between the transaction to be identified and various known abnormal transaction patterns, providing a key basis for subsequent abnormal transaction judgment.
[0050] S104: If at least one similarity among the multiple similarities is greater than a preset threshold, the transaction to be identified is determined to be an abnormal transaction.
[0051] It is understandable that the preset threshold can be a standard value set in advance based on a comprehensive consideration of multiple factors such as business needs, risk tolerance, and historical data analysis results. When multiple similarities are checked one by one, if at least one similarity is found to be greater than the preset threshold, this means that the transaction to be identified has a high degree of similarity with known abnormal transaction patterns in at least one dimension or feature, and there is a greater potential risk. Based on this judgment logic, the transaction identification system can determine that the transaction to be identified is an abnormal transaction and take relevant measures to process the transaction. For example, it can send an alert to relevant business personnel, restrict the further execution of the transaction, etc., to prevent the potential risk from further expanding and ensure the safe and stable operation of the financial system.
[0052] This embodiment provides a method for identifying abnormal transactions. The method obtains first transaction information of a transaction to be identified, performs quantification processing on the first transaction information, and generates a transaction data set. Multiple similarities are determined between the transaction data set and each transaction data subset in the abnormal transaction data set. The multiple similarities are then individually evaluated. When a similarity exceeds a preset threshold, the transaction to be identified is identified as an abnormal transaction and an early warning is issued, thereby improving the accuracy and comprehensiveness of transaction identification.
[0053] Figure 2 A schematic diagram of a method for identifying abnormal transactions provided in an embodiment of the present application Figure 2 .like Figure 2 As shown, in Figure 1 Based on the embodiment, a method for determining an abnormal transaction data set is described in detail, including:
[0054] S201: Acquire second transaction information of historical abnormal transactions.
[0055] Understandably, in transaction data analysis scenarios, historical abnormal transaction records contain a wealth of valuable information. This information can reveal specific anomalies, such as money transactions occurring during non-business hours, high-frequency transactions involving multiple accounts linked to the same account or device, and so on. By analyzing this historical abnormal transaction information, we can identify the characteristics of these abnormal transactions, providing a basis for comparison when identifying current transactions. The method for obtaining the first transaction information for historical abnormal transactions is the same as that for obtaining the first transaction information, and will not be further elaborated here.
[0056] S202: Filter and process the second transaction information to obtain third transaction information.
[0057] Understandably, the acquired second transaction information may contain duplicate information or content that doesn't meet analysis requirements, necessitating filtering. This filtering can be done from a data quality perspective, removing data with missing values, erroneous values, or significant abnormal fluctuations. Alternatively, business needs and analysis objectives can be combined to filter out the information most critical for studying the characteristics and patterns of abnormal transactions. For example, when analyzing abnormal credit card fraud transactions, one might focus on factors such as whether the transaction location deviates significantly from the cardholder's usual activity area or whether the transaction frequency increases abnormally within a short period of time. Based on this, the second transaction information can be filtered to remove irrelevant fields and data entries, ultimately yielding refined and more analytically valuable third transaction information.
[0058] S203: Extract features from the third transaction information according to preset features to obtain multiple feature information subsets.
[0059] Among them, one feature information subset corresponds to one historical abnormal transaction.
[0060] It can be understood that preset features are key indicators or attributes pre-set based on the understanding and analysis objectives of abnormal transactions. After obtaining the third transaction information, feature extraction can be performed based on these preset features. For example, in the detection of abnormal orders on e-commerce platforms, preset features may include order amount volatility, the difference between the delivery address and the usual address, the abnormality of the product combination, etc. For each historical abnormal transaction, the specific numerical value or descriptive information of the corresponding preset feature can be extracted from the third transaction information to form a feature information subset. This subset fully describes the performance of the historical abnormal transaction in each key feature dimension. In this way, the originally complex transaction data is converted into a structured and quantifiable feature set, which characterizes the characteristics of the corresponding historical abnormal transaction from different angles and provides a clear dimension and basis for subsequent data processing and analysis.
[0061] S204: Quantitatively process the multiple feature information subsets respectively to obtain multiple transaction data subsets, and determine the multiple transaction data subsets as abnormal transaction data sets.
[0062] Understandably, while feature information subsets contain key characteristics of abnormal transactions, these characteristics may exist in different forms, such as text descriptions, classification labels, or numerical values of varying dimensions. To facilitate subsequent data analysis and calculations, it is necessary to quantify each of the multiple feature information subsets.
[0063] The quantification method varies depending on the feature type. For categorical features, one-hot encoding or word embedding can be used to convert them into numerical vectors. For numerical features, normalization or standardization may be required to make the values of different features comparable. After quantification, each feature information subset is converted into a transaction data subset consisting of numerical values, which has a unified format and computability. Finally, all quantified transaction data subsets are combined to form the abnormal transaction data set. This set helps to more accurately identify and analyze abnormal trading behavior.
[0064] It is important to note that the abnormal transaction data set integrates all relevant data on historical abnormal transactions. This data is used as a benchmark for similarity comparison with the real-time data of transactions to be identified to determine whether the current transaction to be identified is abnormal. As new abnormal transactions continue to emerge, the types and patterns of abnormal transactions continue to evolve. To ensure the timeliness and accuracy of subsequent transaction identification work, the abnormal transaction data set can be regularly updated and dynamically expanded according to preset time periods.
[0065] This embodiment provides a method for identifying abnormal transactions. By combing through historical abnormal transaction information, the method thoroughly cleans the original transaction records of redundant fields, incorrect formats, and invalid information. Key features (such as transaction amount, time, frequency, and counterparty attributes) are extracted and numerically encoded, thereby constructing a clearly structured dataset of historical abnormal transaction features. This dataset, serving as a benchmark, can be quickly compared with real-time transaction data. Using a multi-dimensional similarity algorithm, the method accurately calculates the degree of similarity between current transactions and historical abnormal cases. This method helps financial institutions identify potential risks within seconds, significantly improving the accuracy of abnormal transaction monitoring and the timeliness of early warnings.
[0066] Figure 3 A schematic diagram of a method for identifying abnormal transactions provided in an embodiment of the present application Figure 3 .like Figure 3 As shown, in Figure 1 Based on the embodiment, a method for determining similarity and identifying transactions based on similarity is described in detail, including:
[0067] S301: For any transaction data subset in the abnormal transaction data set, determine the intersection of the transaction data set and the transaction data subset.
[0068] It can be understood that the abnormal transaction data set includes multiple or multiple types of historical abnormal transactions, such as credit card fraud transactions, false transactions, cash-out transactions and other historical abnormal transactions, and each historical abnormal transaction has its corresponding transaction data subset. In order to comprehensively evaluate whether the transaction to be identified is an abnormal transaction, the similarity between the transaction to be identified and each historical abnormal transaction can be calculated, and the similarity between the transaction to be identified and various historical abnormal transactions can be quantified.
[0069] When calculating similarity, you can choose methods such as Jaccard similarity, the Deese coefficient, and cosine similarity. Jaccard similarity reflects the degree of similarity between two sets by measuring the ratio of the intersection to the union, and has significant advantages when analyzing similarity between set data. Therefore, this application uses Jaccard similarity as the primary similarity calculation method.
[0070] First, determine the intersection of the transaction data set and the transaction data subset. The intersection refers to the set of transaction data elements shared by the transaction data set and a transaction data subset. For example, if set A represents the transaction data set and set B represents any transaction data subset, then their intersection, A∩B, is the set consisting of all elements that belong to both A and B. In the actual transaction data scenario, these elements can be specific transaction records, each of which contains data from multiple dimensions, such as transaction time, transaction amount, information about the two parties, and details of the goods or services traded.
[0071] S302: Determine the union of the transaction data set and the transaction data subset.
[0072] As you can understand, a union is the set formed by combining the transaction data set of the transaction to be identified with all transaction data features or records in any transaction data subset, with duplicate features or records retained only once. For example, the union A∪B includes all elements belonging to either A or B.
[0073] S303: Determine the similarity between the transaction data set and the transaction data subset according to the intersection and the union.
[0074] It is understandable that after determining the intersection and union, the similarity between the transaction to be identified and any transaction data subset can be determined using the Jaccard similarity calculation formula. The Jaccard similarity calculation formula is:
[0075]
[0076] The Jaccard similarity coefficient ranges from 0 to 1. Values closer to 1 indicate a higher degree of similarity between the two sets, meaning the transaction data subset and the overall set are closer in data composition. Values closer to 0 indicate a lower degree of similarity, meaning the difference between the two sets is greater. For example, if the calculated Jaccard similarity coefficient between a transaction data subset and the overall set is 0.8, this indicates that the subset and the overall set share a high proportion of common transaction data and exhibit a high degree of similarity in data characteristics.
[0077] S304: traverse all similarities and determine whether there is at least one similarity greater than a preset threshold. If so, execute step S306; if not, execute step S305.
[0078] As you can understand, after multiple similarity calculations, we can obtain a similarity value between the transaction to be identified and each historical abnormal transaction. We can then check all similarities one by one to determine whether any similarity value exceeds a pre-set threshold. This traversal check can quickly locate any historical abnormal cases that are highly similar to the transaction to be identified.
[0079] S305: Determine whether the transaction to be identified is a normal transaction.
[0080] Understandably, if, after traversing all similarities, no single similarity value exceeds the preset threshold, this means that the degree of similarity between the identified transaction and all historical abnormal transactions is insufficient to trigger an abnormal transaction alert. Based on this result, the transaction can be preliminarily judged to be normal, and no further abnormality handling measures are required. This judgment helps reduce false alarms, improves the accuracy and efficiency of the transaction monitoring system, and ensures that normal transactions can be completed smoothly without affecting the user experience.
[0081] S306: Determine whether the transaction to be identified is an abnormal transaction.
[0082] As you can understand, if at least one similarity value exceeds a preset threshold during the traversal process, this indicates a high degree of similarity between the transaction being identified and one or more historically abnormal transactions, indicating potential risk or anomalous behavior. Based on this finding, the transaction identification system can mark the transaction as abnormal and initiate the appropriate exception handling process. This step can promptly detect and prevent potential fraud or violations, protecting financial security and maintaining business order.
[0083] S307: Determine a target similarity based on at least one similarity greater than a preset threshold, where the target similarity is the similarity with the highest value among the similarities greater than the preset threshold.
[0084] As will be appreciated, after confirming that at least one similarity exceeds a preset threshold, the highest value among these similarities exceeding the threshold can be identified, which is referred to as the target similarity. The target similarity can reflect the highest degree of similarity between the identified transaction and a historical abnormal transaction, and can also reflect the potential risk level associated with the transaction. Determining the target similarity provides a more specific and quantitative basis for subsequent warning level classification and risk response strategies.
[0085] S308: Determine the warning level of the abnormal transaction based on the target similarity and the preset level value, and send a warning message.
[0086] As you can understand, by combining target similarity with pre-set grading criteria, the transaction identification system can determine the warning level for abnormal transactions. Warning levels are typically categorized based on the degree of similarity, such as low risk for a similarity below 0.5, medium risk for a similarity between 0.5 and 0.8, and high risk for a similarity above 0.8. Different levels correspond to different response measures and urgency levels. Once the warning level is determined, the transaction identification system can send warning information to relevant personnel (such as risk management personnel and security teams), including specific information about the abnormal transaction, the warning level, potential risk points, and recommended countermeasures. This process ensures timely and effective handling of abnormal transactions, minimizing potential losses and risks.
[0087] In addition, other algorithms, such as machine learning models, manual recognition and other methods, can be combined to conduct secondary identification and confirmation of identified abnormal transactions.
[0088] Optionally, transactions determined to be abnormal transactions may be identified and analyzed to obtain specific causes of the abnormalities.
[0089] At least one target historical abnormal transaction corresponding to the similarity is determined according to at least one similarity greater than a preset threshold.
[0090] It is understood that after identifying that at least one similarity between the transaction to be identified and a set of historical abnormal transactions exceeds a preset threshold, the specific historical abnormal transaction cases corresponding to these high similarity values can be further located. For example, by establishing a mapping relationship between similarity values and historical abnormal transaction records, similarity results with values above the threshold can be traced back to their original calculation objects, thereby screening out at least one target historical abnormal transaction with the risk characteristics most similar to the current transaction to be identified.
[0091] The process of extracting transaction information from historical abnormal transactions can link historical databases with transaction identifiers (such as transaction ID, timestamp, and account characteristics), ensuring that each target historical abnormal transaction contains complete transaction context (such as fund flow, operation mode, and associated accounts). Through this mapping mechanism, the transaction identification system can transform abstract similarity values into interpretable risk case references, providing a clear comparison benchmark for subsequent analysis of the causes of abnormalities.
[0092] According to the transaction information of the target historical abnormal transactions, the abnormal transactions are matched and processed to determine the abnormal reasons for the abnormal transactions.
[0093] It is understandable that based on the screened target historical abnormal transaction set, the transaction identification system can initiate a multi-dimensional information matching process. For example, it can explore the common risks between the transactions to be identified and historical abnormal cases through means such as feature alignment, pattern comparison and association analysis.
[0094] For example, matching processing may include: behavioral feature matching, such as transaction behavior, amount distribution pattern, operation path and other behavioral features; it may also include association network mapping, such as identifying whether there are overlapping associated entities (such as common party accounts, shared IP address segments) through account association maps, IP address clustering, device fingerprint recognition and other technologies; it may also include risk label migration: the risk type (such as cash withdrawal, card fraud, etc.), modus operandi (such as counterfeit card transactions, fake merchant fraud) and associated scenarios (such as specific merchant category code MCC, cross-border transaction channels) of the target historical abnormal transactions are marked and migrated to the transaction to be identified through a rule engine or machine learning model; by integrating multi-source matching evidence, a structured abnormality cause report can be generated, covering key elements such as risk type, triggering conditions, and associated historical cases, providing an explainable basis for risk disposal decisions.
[0095] This embodiment provides a method for identifying abnormal transactions. The method compares transaction data subsets of multiple historical abnormal transactions with a transaction data set of a transaction to be identified, calculates multiple similarities, and determines whether the transaction to be identified is an abnormal transaction based on the similarities. At the same time, the historical abnormal transactions corresponding to the transaction data subsets whose similarities exceed a threshold can be extracted and analyzed to obtain the abnormal reasons for the transaction to be identified. The transaction identification system can then issue an early warning and suspend the processing of the abnormal transaction to remind relevant personnel to handle it in a timely manner to protect the user's funds.
[0096] Figure 4 This is a schematic diagram of the structure of an abnormal transaction identification device provided by this application. Figure 4 As shown, the present application provides a device for identifying abnormal transactions, and the device 400 for identifying abnormal transactions includes:
[0097] An acquisition module 401 is configured to acquire first transaction information of a transaction to be identified;
[0098] A processing module 402 is configured to perform quantization processing on the first transaction information to obtain a transaction data set;
[0099] a determination module 403 configured to determine a plurality of similarities based on the transaction data set and each transaction data subset in the abnormal transaction data set; the similarities indicating the degree of similarity between the transaction data set and the transaction data subset;
[0100] The determination module 403 is further configured to determine that the transaction to be identified is an abnormal transaction if at least one similarity among the plurality of similarities is greater than a preset threshold.
[0101] Optionally, the acquisition module 401 is further configured to acquire second transaction information of historical abnormal transactions;
[0102] The processing module 402 is further configured to filter the second transaction information to obtain third transaction information; extract features from the third transaction information according to preset features to obtain multiple feature information subsets, where each feature information subset corresponds to one historical abnormal transaction; quantify the multiple feature information subsets to obtain multiple transaction data subsets, and determine the multiple transaction data subsets as the abnormal transaction data set.
[0103] Optionally, the determination module 403 is specifically used to determine, for any transaction data subset in the abnormal transaction data set, the intersection of the transaction data set and the transaction data subset; determine the union of the transaction data set and the transaction data subset; determine the similarity between the transaction data set and the transaction data subset based on the intersection and the union; and repeat the similarity determination process to obtain multiple similarities corresponding to multiple transaction data subsets.
[0104] Optionally, the determination module 403 is specifically used to traverse all the similarities and determine whether there is at least one similarity greater than a preset threshold; if there is at least one similarity greater than the preset threshold, the transaction to be identified is determined to be an abnormal transaction, and the warning level of the abnormal transaction is determined; if there is not at least one similarity greater than the preset threshold, the transaction to be identified is determined to be a normal transaction.
[0105] Optionally, the determination module 403 is specifically used to determine a target similarity based on at least one similarity greater than the preset threshold, where the target similarity is the similarity with the highest value among the similarities greater than the preset threshold; determine the warning level of the abnormal transaction based on the target similarity and a preset level value, and send a warning message.
[0106] Optionally, the determination module 403 is further used to determine at least one target historical abnormal transaction corresponding to the similarity based on at least one similarity greater than the preset threshold; match the abnormal transaction based on the transaction information of the target historical abnormal transaction to determine the abnormal cause of the abnormal transaction.
[0107] The implementation principle and technical effects of the abnormal transaction identification device provided in the embodiment of the present application are similar to the implementation methods of each part of the aforementioned abnormal transaction identification method, and will not be repeated here.
[0108] Figure 5 This is a schematic diagram of the structure of an electronic device provided by this application. Figure 5 As shown, the present application provides an electronic device, which includes a receiver 501, a transmitter 502, a processor 503 and a memory 504.
[0109] Receiver 501, for receiving instructions and data;
[0110] Transmitter 502, used to send instructions and data;
[0111] Memory 504, for storing computer-executable instructions;
[0112] The processor 503 is configured to execute the computer-executable instructions stored in the memory 504 to implement the various steps of the abnormal transaction identification method in the above embodiment. For details, please refer to the relevant description in the above abnormal transaction identification method embodiment.
[0113] Optionally, the memory 504 may be independent or integrated with the processor 503 .
[0114] When the memory 504 is independently provided, the electronic device further includes a bus for connecting the memory 504 and the processor 503 .
[0115] The implementation principle and technical effects of the electronic device provided in this embodiment can be found in the aforementioned embodiments and will not be described in detail here.
[0116] An embodiment of the present application further provides a computer-readable storage medium, wherein the computer-readable storage medium stores computer-executable instructions. When a processor executes the computer-executable instructions, the method described in any of the above embodiments is implemented.
[0117] An embodiment of the present application further provides a computer program product, including a computer program, which implements the method described in any of the aforementioned embodiments when executed by a processor.
[0118] It should be noted that for the aforementioned method embodiments, for the sake of simplicity, they are all expressed as a series of action combinations, but those skilled in the art should be aware that this application is not limited by the order of the actions described, because according to this application, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in this specification are all optional embodiments, and the actions and modules involved are not necessarily required by this application.
[0119] It should be further noted that, although the various steps in the flowchart are shown in sequence as indicated by the arrows, these steps are not necessarily performed in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order restriction on the execution of these steps, and these steps may be performed in other orders. Moreover, at least a portion of the steps in the flowchart may include multiple sub-steps or multiple stages, and these sub-steps or stages are not necessarily performed at the same time, but may be performed at different times. The execution order of these sub-steps or stages is not necessarily to be performed in sequence, but may be performed in turn or alternately with other steps or at least a portion of the sub-steps or stages of other steps.
[0120] It should be understood that the above-described device embodiments are merely illustrative, and the device of the present application may also be implemented in other ways. For example, the division of units / modules in the above-described embodiments is merely a logical functional division, and actual implementations may employ other division methods. For example, multiple units, modules, or components may be combined or integrated into another system, or some features may be omitted or not implemented.
[0121] In addition, unless otherwise specified, the functional units / modules in the various embodiments of the present application may be integrated into a single unit / module, each unit / module may exist physically separately, or two or more units / modules may be integrated together. The aforementioned integrated units / modules may be implemented in the form of hardware or software program modules.
[0122] If an integrated unit / module is implemented in hardware, the hardware may be digital circuits, analog circuits, etc. The physical implementation of the hardware structure includes, but is not limited to, transistors, memristors, etc. Unless otherwise specified, the processor may be any appropriate hardware processor, such as a CPU, GPU, FPGA, DSP, and ASIC. Unless otherwise specified, the storage unit may be any appropriate magnetic storage medium or magneto-optical storage medium, such as resistive random access memory (RRAM), dynamic random access memory (DRAM), static random access memory (SRAM), enhanced dynamic random access memory (EDRAM), high-bandwidth memory (HBM), hybrid memory cube (HMC), etc.
[0123] If the integrated unit / module is implemented in the form of a software program module and sold or used as an independent product, it can be stored in a computer-readable memory. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product. The computer software product is stored in a memory and includes a number of instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the various embodiments of the present application. The aforementioned memory includes: U disk, read-only memory (ROM), random access memory (RAM), mobile hard disk, magnetic disk, or optical disk, etc., various media that can store program code.
[0124] In the above embodiments, the description of each embodiment has its own emphasis. For parts not described in detail in a particular embodiment, please refer to the relevant description of other embodiments. The technical features of the above embodiments can be combined in any way. To keep the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0125] Those skilled in the art will readily appreciate other embodiments of the present application after considering the specification and practicing the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of the present application that follow the general principles of the present application and include common knowledge or customary techniques in the art not disclosed herein. The description and examples are to be considered as exemplary only, and the true scope and spirit of the present application are indicated by the following claims.
[0126] It should be understood that the present application is not limited to the exact structure described above and shown in the drawings, and that various modifications and changes may be made without departing from the scope thereof. The scope of the present application is limited only by the appended claims.
Claims
1. A method for identifying abnormal transactions, characterized in that: include: Obtaining first transaction information of a transaction to be identified; quantifying the first transaction information to obtain a transaction data set; determining a plurality of similarities based on the transaction data set and each transaction data subset in the abnormal transaction data set; The similarity is used to indicate the degree of similarity between the transaction data set and the transaction data subset; If at least one similarity among the plurality of similarities is greater than a preset threshold, the transaction to be identified is determined to be an abnormal transaction.
2. The method according to claim 1, characterized in that Before obtaining the first transaction information of the transaction to be identified, the method further includes: Obtain the second transaction information of historical abnormal transactions; screening the second transaction information to obtain third transaction information; Extracting features from the third transaction information according to preset features to obtain multiple feature information subsets, each feature information subset corresponding to one historical abnormal transaction; Quantitative processing is performed on the plurality of characteristic information subsets respectively to obtain a plurality of transaction data subsets, and the plurality of transaction data subsets are determined as the abnormal transaction data set.
3. The method according to claim 1, characterized in that The determining of a plurality of similarities based on the transaction data set and each transaction data subset in the abnormal transaction data set includes: For any transaction data subset in the abnormal transaction data set, determining an intersection between the transaction data set and the transaction data subset; determining a union of the transaction data set and the transaction data subset; determining, based on the intersection and the union, a degree of similarity between the transaction data set and the transaction data subset; The similarity determination process is repeated to obtain multiple similarities corresponding to multiple transaction data subsets.
4. The method according to claim 1, wherein When at least one similarity is greater than a preset threshold, determining that the transaction to be identified is an abnormal transaction includes: Traversing all the similarities, and determining whether there is at least one similarity greater than a preset threshold; If there is at least one similarity greater than a preset threshold, the transaction to be identified is determined to be an abnormal transaction, and the warning level of the abnormal transaction is determined; If there is not at least one similarity greater than the preset threshold, it is determined that the transaction to be identified is a normal transaction.
5. The method according to claim 4, characterized in that Determining the warning level of the abnormal transaction includes: Determining a target similarity based on at least one similarity greater than the preset threshold, wherein the target similarity is the similarity with the highest value among the similarities greater than the preset threshold; According to the target similarity and the preset level value, the warning level of the abnormal transaction is determined, and a warning message is sent.
6. The method according to claim 4, characterized in that The method further comprises: Determining, based on at least one similarity greater than the preset threshold, at least one target historical abnormal transaction corresponding to the similarity; According to the transaction information of the target historical abnormal transaction, the abnormal transaction is matched and processed to determine the abnormal cause of the abnormal transaction.
7. A device for identifying abnormal transactions, characterized in that: include: an acquisition module, configured to acquire first transaction information of a transaction to be identified; a processing module, configured to perform quantification processing on the first transaction information to obtain a transaction data set; a determination module, configured to determine a plurality of similarities based on the transaction data set and each transaction data subset in the abnormal transaction data set; the similarities being used to indicate a degree of similarity between the transaction data set and the transaction data subset; The determination module is further configured to determine that the transaction to be identified is an abnormal transaction if at least one similarity among the plurality of similarities is greater than a preset threshold.
8. An electronic device, characterized in that: include: a processor, and a memory communicatively connected to the processor; The memory stores computer-executable instructions; The processor executes the computer-executable instructions stored in the memory to implement the method according to any one of claims 1 to 6.
9. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer-executable instructions, which are used to implement the method according to any one of claims 1 to 6 when executed by a processor.
10. A computer program product, characterized in that The invention comprises a computer program, which implements the method according to any one of claims 1 to 6 when being executed by a processor.