Intelligent data processing system for intelligent evidence collection
By using distributed edge probe groups, a dynamic fraud strategy engine, and an intelligent evidence chain building module, the system addresses the shortcomings of intelligent evidence collection systems in terms of adaptability, data processing efficiency, architectural flexibility, and privacy compliance. This enables real-time response and reliable evidence collection, thereby enhancing evidence collection capabilities in the financial anti-fraud field.
Patent Information
- Application Number
- CN202511211362.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-28
- Publication Date
- 2025-11-14
- Estimated Expiration
- 2045-08-28
AI Technical Summary
Existing intelligent evidence collection systems suffer from insufficient adaptability, low data processing efficiency, architectural limitations, insufficient intelligent analysis capabilities, and privacy compliance risks when facing complex digital crime environments. They are unable to respond in real time to new criminal methods and are incompatible with heterogeneous data sources, resulting in the omission of key evidence, waste of resources, and privacy leaks.
Employing a distributed edge probe group, a dynamic fraud strategy engine, an intelligent evidence chain construction module, and a trusted evidence storage interface, this system achieves real-time response, cross-domain compliance, and end-to-end trusted evidence collection through edge intelligent collaboration and dynamic adversarial learning. The distributed probe group performs de-identification and hash solidification at the data source end; the dynamic strategy engine performs threat assessment based on graph neural networks and hidden Markov models; the intelligent evidence chain construction module performs multi-level fund flow tracking and interpretable AI analysis; and evidence storage is achieved by combining improved Merkle trees and zero-knowledge proof technology.
It achieves millisecond-level response, complete cross-platform evidence capture, dynamic strategy optimization, interpretable encrypted transaction intent parsing, and strict privacy protection, improving evidence collection efficiency, adaptability, and judicial credibility, and solving the bottleneck problems of traditional systems.
Smart Images

Figure CN120725697B_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of data processing, and specifically relates to an intelligent data processing system for intelligent evidence collection. Background Technology
[0002] Currently, intelligent data processing systems for intelligent forensics face multiple technical bottlenecks in dealing with the increasingly complex digital crime environment. Their core shortcomings are mainly reflected in the following aspects:
[0003] Insufficient adaptability is a significant weakness of current systems. Traditional forensic tools are mostly designed for specific intrusion behaviors or static network environments, lacking the ability to dynamically respond to new criminal methods (such as those utilizing encrypted communication or niche applications). When criminals employ variant attack techniques, the system cannot adjust its forensic strategies in real time or autonomously generate new detection modules, leading to the omission of crucial evidence. Simultaneously, low data processing efficiency causes severe performance bottlenecks. Faced with exponentially increasing data volumes (including structured and unstructured data), traditional centralized architectures rely on a single central analysis node, causing network congestion and processing delays. For example, massive amounts of audit data need to be transmitted back to the central server for analysis, which is difficult to achieve in real-time response in high-speed network environments. Furthermore, system resources cannot dynamically scale according to the attack scale, making it prone to crashing under high load and wasting resources under low load.
[0004] The limitations of the system architecture further restrict the reliability of forensic evidence collection. Existing tools often employ rigid designs, making them incompatible with heterogeneous data sources (such as IoT devices, cloud services, and encrypted communications). For example, the rapid iteration of niche apps or new HarmonyOS systems leads to excessively long adaptation cycles for forensic tools, while anti-forensic techniques (such as data erasure and hiding) make the integrity of evidence vulnerable to damage. Furthermore, the lack of technical standardization exacerbates compatibility issues. The lack of unified data interfaces and protocols among forensic tools from different vendors makes it difficult to transfer evidence across systems.
[0005] The shortcomings of intelligent analysis capabilities are equally prominent. Traditional OCR and other technologies can only recognize text in images and cannot analyze the contextual relationships of data such as chat logs (e.g., the relationship between nicknames and content), leading to fragmented clues. Although AI technology has been applied to automated evidence collection (e.g., automatic page turning, screenshotting), its underlying models lack sufficient depth in analyzing encrypted data and dynamic content (e.g., real-time chat streams), and the black-box nature of the algorithms raises questions about the interpretability of the results. Finally, privacy and compliance risks persist. Large-scale data collection may unauthorizedly obtain sensitive user information (e.g., medical records), while lagging laws and regulations result in a lack of a clear privacy protection framework in the evidence collection process, easily leading to ethical controversies.
[0006] In summary, the shortcomings of existing systems in terms of dynamic response, data processing efficiency, architectural flexibility, standardization, and compliance urgently need to be addressed through distributed intelligent architecture, adaptive algorithms, and cross-domain compliance frameworks. Summary of the Invention
[0007] This invention proposes an intelligent data processing system for intelligent evidence collection. This system solves five core problems in financial anti-fraud evidence collection: slow real-time response, difficulty in penetrating multi-layered money laundering, failure to detect new fraud patterns, lack of interpretation of encrypted transaction intent, and insufficient compliance of judicial evidence preservation. It achieves full-chain credible evidence collection in complex transaction environments through edge intelligent collaboration and dynamic adversarial learning.
[0008] The technical solution of the present invention is implemented as follows: an intelligent data processing system for intelligent evidence collection, including a distributed edge probe group, a dynamic fraud strategy engine, an intelligent evidence chain construction module, and a trusted evidence storage interface;
[0009] The distributed edge probe group is deployed in the core transaction system, with a built-in lightweight protocol parser. The parser is adapted to the SWIFT / UnionPay private protocol and a real-time de-identification module, and performs transaction account masking and behavior trajectory hashing solidification at the data source end.
[0010] The dynamic fraud strategy engine accesses the abnormal transaction flow of the edge probe group and stores cross-institutional transaction pattern vectors through the graph neural network fraud feature library; the real-time threat assessment unit detects the probability of abnormal transaction timing based on the hidden Markov model; the adaptive evidence collection controller dynamically activates targeted evidence collection instructions according to the threat value, and extends the evidence storage period of suspicious sessions by capturing cross-platform fund flows with high priority.
[0011] The intelligent evidence chain construction module includes a multi-level fund flow tracking unit and an interpretable AI parser. The multi-level fund flow tracking unit uses an entity association graph to map virtual accounts to actual controllers. The interpretable AI parser uses attention weight visualization technology to restore the semantics of encrypted transaction instructions and generate a decision heatmap.
[0012] The trusted evidence storage interface uses an improved Merkle tree to store the evidence chain in fragments. Each fragment integrates an edge device digital signature and a financial-grade timestamp, and outputs a compliant audit report.
[0013] The dynamic fraud strategy engine activates an adversarial sample generation mechanism when identifying unregistered transaction patterns: it uses a generative adversarial network to synthesize new fraudulent transaction features, updates the weights of the graph neural network, and isolates the original data into a financial regulatory sandbox.
[0014] Existing financial anti-fraud systems face multiple technical bottlenecks: First, the fragmented evidence collection from heterogeneous terminals, with ATMs, apps, and core systems processing data independently, leads to a break in the correlation of cross-platform money laundering activities (such as nested multi-account transfers), and traditional centralized architectures lose key transaction timing evidence due to data transmission delays; Second, the rigid static rule base means that detection mechanisms based on predefined fraud features (such as fixed threshold triggers) cannot identify unregistered transaction patterns (such as new types of cross-border cash-out), and manual updates to the feature base take weeks; Third, virtual account penetration fails, and tracking technologies relying on the surface of account transaction records are insufficient to map the actual controller, especially in encrypted communication scenarios where the intent to transfer funds cannot be analyzed; Fourth, the judicial validity of the evidence chain is insufficient, with blockchain evidence storage experiencing a surge in storage load due to redundant data, and lacking authoritative timestamps and standardized encapsulation, leading judicial institutions to question the integrity of electronic evidence; Fifth, privacy compliance risks are out of control, as the central node transmitting raw data may unauthorizedly obtain sensitive user information.
[0015] This solution specifically addresses the following technical challenges: Real-time edge collaboration challenges: By deploying lightweight probes (ATM dual-mode sniffer, APP TEE interceptor, and core system protocol reverse adapter) across domains, desensitization and hash solidification are completed at the data source head, eliminating backhaul delays;
[0016] Challenges in dynamic strategy generation: A dual-threshold triggering mechanism based on Hidden Markov Models and heterogeneous graph feature fusion is used to quantify threat levels in real time and dynamically allocate resources, resolving the contradiction between resource utilization and detection sensitivity in traditional systems. Challenges in fund penetration technology: A time-series penetration analysis enhanced by Depth-First Search (DFS) is employed, fusing unstructured data to construct a three-dimensional "account-beneficiary-device" graph, breaking through the barrier of virtual identity concealment. Challenges in intent interpretability: A hierarchical attention mechanism generates word-level heatmaps and behavioral decision trees, restoring encrypted instructions to legally understandable "subjective malice" evidence. Challenges in evidence preservation and judicial adaptation: A dual-chain anchoring structure (consortium chain + judicial chain) and quantum key sharding authorization balance data immutability and privacy protection requirements.
[0017] As a preferred implementation, the distributed edge probe group adopts a domain-based deployment architecture. The probes deployed on ATM terminals integrate magnetic stripe / chip dual-mode sniffers to capture the operation command stream of physical transaction terminals in real time. The probes on mobile APP terminals are embedded in a trusted execution environment and intercept encrypted communication data through system call hijacking technology. The probes of the core transaction system load private protocol reverse adapters and dynamically generate SWIFT / UnionPay private protocol parsing templates based on protocol field entropy values. The real-time desensitization module executes a hierarchical data processing pipeline: it uses a format-preserving encryption mask for transaction accounts, applies SM3 hashing to solidify behavioral trajectories, and injects key fragments protected by a hardware security module.
[0018] As a preferred implementation, in the dynamic fraud strategy engine: the graph neural network fraud feature library adopts heterogeneous graph fusion technology to map transaction entity nodes and relationship edges into high-dimensional feature vectors; the real-time threat assessment unit constructs a dual-threshold triggering mechanism: when the anomaly probability output by the hidden Markov model exceeds the first threshold, basic evidence collection is activated, and when it exceeds the second threshold, cross-platform fund flow capture is triggered; the adaptive evidence collection controller configures a strategy priority matrix and dynamically allocates computing resources to the suspicious session evidence storage link according to the threat value weight.
[0019] As a preferred implementation, the operation process of the intelligent evidence chain construction module is as follows: time-series penetration analysis is implemented through a multi-level fund flow tracking unit: the fund flow path is tracked based on an improved depth-first search algorithm, and unstructured data sources are integrated to construct evidence related to the actual controller; the interpretable AI parser deploys a hierarchical attention mechanism: a word-level attention weight heatmap is generated at the instruction semantic restoration layer, an operation logic decision tree is output at the behavior intent analysis layer, and model bias interference is eliminated through adversarial training.
[0020] As a preferred implementation, the trusted evidence storage interface operates through a dual-chain anchored evidence storage structure: the improved Merkle tree root hash is synchronously written into the financial consortium chain and the judicial evidence storage chain, and zero-knowledge proof technology is used to verify cross-chain consistency; a dynamic evidence encapsulation engine: generates standardized evidence packages as required, which integrate timestamps certified by the National Time Service Center, probe device digital certificates, and parser version traceability identifiers; and a sandbox data isolation mechanism: physical isolation storage is implemented for the original data of unregistered transaction modes, and access requires multiple biometric authentication and quantum key fragment decryption authorization.
[0021] After adopting the above technical solution, the beneficial effects of the present invention are as follows: In terms of evidence collection efficiency, the distributed edge probe group achieves millisecond-level response through near-source data processing, completely eliminating the data backhaul delay of the traditional architecture and ensuring the complete capture of key transaction behavior trajectories; the dynamic strategy engine intelligently allocates computing resources based on a dual threshold triggering mechanism, significantly improving the detection sensitivity of unknown fraud patterns and overcoming the rigidity of static rule bases.
[0022] At the system adaptation level, the adversarial sample generation mechanism enables real-time dynamic evolution of the fraud feature library, raising the compatibility of protocol iteration to an industry-leading level; the protocol reverse adapter effectively addresses the challenge of rapid upgrades of private communication protocols by using entropy-driven parsing template generation.
[0023] In terms of the validity of judicial evidence, the dual-chain anchored evidence storage structure, combined with zero-knowledge proof technology, constructs an immutable cross-chain consistency verification system; the dynamic evidence encapsulation engine integrates national-level timestamp certification and device digital certificates to output standardized evidence packages that meet the requirements of judicial institutions; and the visualized decision heatmap generated by the hierarchical attention mechanism provides explanatory evidence that meets the requirements of judicial evidence for the reconstruction of the intent of encrypted transactions.
[0024] In terms of privacy compliance, the hierarchical desensitization pipeline employs cryptographic enhancement techniques to minimize data collection and strictly adheres to the principles of personal information protection. The sandbox isolation mechanism integrates quantum key distribution and biometric authentication to establish a physical-level access control barrier, eliminating the risk of unauthorized evidence collection. Ultimately, this forms a closed-loop technology system encompassing real-time edge response, dynamic policy optimization, end-to-end evidence solidification, and privacy protection, comprehensively meeting the high-standard evidence collection needs of the financial anti-fraud field. Attached Figure Description
[0025] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0026] Figure 1 This is a system block diagram of the present invention. Detailed Implementation
[0027] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0028] Example:
[0029] like Figure 1 As shown, the intelligent data processing system for intelligent evidence collection includes a distributed edge probe group, a dynamic fraud strategy engine, an intelligent evidence chain construction module, and a trusted evidence storage interface.
[0030] The distributed edge probe group is deployed in the core transaction system, with a built-in lightweight protocol parser. The parser is adapted to the SWIFT / UnionPay private protocol and a real-time de-identification module, and performs transaction account masking and behavior trajectory hashing solidification at the data source end.
[0031] The dynamic fraud strategy engine accesses the abnormal transaction flow of the edge probe group and stores cross-institutional transaction pattern vectors through the graph neural network fraud feature library; the real-time threat assessment unit detects the probability of abnormal transaction timing based on the hidden Markov model; the adaptive evidence collection controller dynamically activates targeted evidence collection instructions according to the threat value, and extends the evidence storage period of suspicious sessions by capturing cross-platform fund flows with high priority.
[0032] The intelligent evidence chain construction module includes a multi-level fund flow tracking unit and an interpretable AI parser. The multi-level fund flow tracking unit uses an entity association graph to map virtual accounts to actual controllers. The interpretable AI parser uses attention weight visualization technology to restore the semantics of encrypted transaction instructions and generate a decision heatmap.
[0033] The trusted evidence storage interface uses an improved Merkle tree to store the evidence chain in fragments. Each fragment integrates an edge device digital signature and a financial-grade timestamp, and outputs a compliant audit report.
[0034] The dynamic fraud strategy engine activates an adversarial sample generation mechanism when identifying unregistered transaction patterns: it uses a generative adversarial network to synthesize new fraudulent transaction features, updates the weights of the graph neural network, and isolates the original data into a financial regulatory sandbox.
[0035] The implementation of this system in cross-border money laundering evidence collection scenarios begins with the collaborative operation of a distributed edge probe group: probes deployed at bank ATM terminals capture physical operation command streams (such as abnormal multiple cash withdrawals) through magnetic stripe / chip dual-mode sniffers; mobile APP probes hijack encrypted communication data (such as high-frequency small-amount transfer instructions) within a Trusted Execution Environment (TEE); and core transaction system probes activate private protocol reverse adapters to dynamically generate parsing templates based on SWIFT message field entropy values and strip redundant protocol headers in real time. All probes synchronously execute a hierarchical desensitization pipeline—using format-preserving encryption (FPE) to mask accounts, using the SM3 hash algorithm to solidify operation trajectories, and using a hardware security module (HSM) to fragment and manage keys to ensure that the original sensitive data does not leave the domain. When the probe detects an abnormal transaction flow (such as cross-bank fund transfers between multiple accounts), it immediately pushes it to the dynamic fraud strategy engine: The graph neural network fraud feature library first loads heterogeneous graph fusion technology to map transaction entities (accounts / IP / devices) and relationship edges (transfer dispersion, time density) into high-dimensional vectors to match known money laundering patterns; the real-time threat assessment unit constructs a transaction state transition probability matrix based on a hidden Markov model to identify time-series anomalies (such as large-amount transfers at night deviating from normal behavior patterns); if the anomaly probability exceeds the preset dual thresholds, the adaptive evidence collection controller immediately activates targeted instructions—performing basic session evidence storage for low-threat transactions, and initiating cross-platform fund flow capture and extending the evidence storage period for high-threat transactions.
[0036] Abnormal data then flows into the intelligent evidence chain construction module: the multi-level fund flow tracking unit implements depth-first search (DFS) enhanced time-series penetration analysis, and constructs a three-dimensional map of "account-actual controller-physical address" by parsing unstructured data such as virtual account registration information, device fingerprints and related customer service recordings, penetrating the hidden barriers of multi-layered nested accounts; the interpretable AI parser operates synchronously: a hierarchical attention mechanism is deployed at the instruction semantic restoration layer to generate a word-level weighted heatmap to analyze encrypted transaction instructions (such as the true intent of the " / " symbol in money laundering code words), outputs an operation decision tree at the behavioral logic layer, and eliminates model bias interference through adversarial training, ultimately forming a judicially understandable "subjective malice" evidence chain.
[0037] When the evidence chain is processed through the trusted evidence storage interface, it is first stored in fragments based on an improved Merkle tree—each fragment integrates an ATM probe digital signature and a financial-grade timestamp certified by the National Time Service Center; then, a dual-chain anchoring mechanism is activated: the Merkle tree root hash is synchronously written to the financial consortium chain and the judicial evidence storage chain, and zero-knowledge proof technology is used to verify cross-chain consistency; the dynamic evidence encapsulation engine automatically generates standardized evidence packages that conform to the requirements, embedding probe device certificates, parser version identifiers, and operation audit logs. When the system identifies an unregistered money laundering pattern (such as new virtual currency cash-out), the dynamic fraud strategy engine immediately triggers an adversarial example generation mechanism: using a generative adversarial network (GAN) to synthesize highly realistic fraudulent transaction features, injecting them into a graph neural network for incremental training to update the feature vector set; at the same time, the original data is physically isolated in a financial regulatory sandbox, and access requires authorization through iris / voiceprint multi-biometric authentication and quantum key fragment decryption, forming an absolute isolation zone for judicial auditing and privacy protection. The entire process realizes a closed loop from edge data capture, dynamic strategy response, intent judicial evidence presentation to trusted evidence storage, completely reconstructing the technical paradigm of financial anti-fraud evidence collection.
[0038] In the omnichannel transaction security system of commercial banks, distributed edge probe groups adopt a domain-based deployment architecture to achieve end-to-end monitoring of "physical terminal - mobile application - core system". The probes deployed on ATM terminals integrate magnetic stripe / chip dual-mode sniffers. When criminals steal bank card information by modifying ATM card readers, the dual-mode sniffers can capture abnormal signals in the physical operation command stream in real time - such as non-standard data reading requests that suddenly appear after a normal card insertion command. This triggers a local de-identification mechanism to mask the card number (retaining the first 6 and last 4 digits) and solidify the operation trajectory through SHA-256 hashing to prevent the leakage of original data.
[0039] The mobile app probe is embedded in a Trusted Execution Environment (TEE). When a user makes a transfer through mobile banking, if the app is infected with a malicious plugin attempting to hijack the transaction instructions, the probe intercepts abnormal API calls using system call hijacking technology. For example, a plugin-forged "modify recipient account" instruction will be identified as a non-user-triggered system call, freezing the session and uploading the instruction hash to the cloud. Meanwhile, the probe deployed in the core transaction system loads a private protocol reverse adapter. For mixed scenarios involving SWIFT messages and UnionPay POS transactions, the adapter dynamically generates parsing templates by analyzing protocol field entropy values (e.g., abnormal field length fluctuations). When an undefined combination of fields suddenly appears in a cross-border remittance message, it can quickly match the protocol feature library to complete data extraction and de-identification.
[0040] This domain-based deployment architecture has demonstrated significant advantages in actual operation: In one case, criminals simultaneously installed skimming devices on ATM terminals and implanted phishing apps on target mobile phones, attempting to commit fraud through "physical theft + remote hijacking." The domain-based probes captured abnormal card reading commands from the ATM terminal and forged transfer requests from the app terminal, respectively. Through cross-domain data correlation, the suspicious behavior was located within 10 seconds, providing raw data support for subsequent evidence collection.
[0041] In cross-border fund monitoring scenarios, the dynamic fraud strategy engine demonstrates powerful new risk identification capabilities. Its graph neural network fraud feature library stores millions of cross-institutional transaction pattern vectors—for example, cross-border remittances under normal trade items typically conform to the correlation of "order amount - logistics information - remittance amount," while abnormal patterns manifest as vector features of "multiple small, dispersed inflows + concentrated large outflows." When a remittance from an offshore account triggers an "unregistered transaction pattern" (such as the first appearance of the "virtual currency pledging + cross-border fiat currency exchange" combination), the system immediately initiates a multi-layered processing flow.
[0042] The real-time threat assessment unit calculates the probability of temporal anomalies based on a hidden Markov model: by analyzing the transaction timeline of the account over the past 3 months (e.g., remittances were usually made at 9 AM on weekdays, but this time the operation was carried out at 2 AM), it outputs an anomaly probability of 89%, exceeding the first threshold (70%), thus activating basic evidence collection; as it is subsequently discovered that the flow of funds is related to the IP address of a known fraud den, the threat value rises to 95%, exceeding the second threshold (90%), and the adaptive evidence collection controller immediately triggers a high-priority instruction—freezing the fund transfer, extending the session evidence storage period to 72 hours, and capturing the flow trajectory of the funds in payment institutions and digital currency exchanges through cross-platform interfaces.
[0043] More importantly, the adversarial sample generation mechanism plays a crucial role: when an unregistered transaction pattern is identified, the Generative Adversarial Network (GAN) immediately synthesizes 100,000 new samples based on existing fraud features (such as simulating fund splitting patterns of different offshore accounts), updates the weights of the graph neural network through backpropagation, and improves the model's accuracy in identifying this type of pattern; at the same time, the original transaction data is isolated in the financial regulatory sandbox, allowing regulatory agencies to analyze new fraud methods in a controlled environment, which not only ensures data security but also accelerates model iteration.
[0044] In the investigation of a cryptocurrency money laundering case, the intelligent evidence chain construction module demonstrated its ability to penetrate complex transaction networks. The multi-level fund flow tracking unit, through entity association graphs, penetrated the multi-layered nested structure of "cryptocurrency wallet - OTC trader - corporate account - personal card": First, it identified high-frequency fund transactions between a certain virtual account and five OTC traders. Then, through graph analysis, it was found that the corporate accounts of these traders ultimately pointed to the same actual controller—a legal person of a blacklisted foreign trade company. Even though this legal person hid the relationship through three layers of shell companies, the graph could still complete the mapping through weak association features such as equity pledge and actual office address.
[0045] Explainable AI parsers solve the problem of semantic reconstruction of encrypted transactions. For a Bitcoin transfer encrypted through a mixing service, the parser uses attention weight visualization technology to assign high attention weights to key fields in the transaction instructions (such as "mixing node ID" and "number of fund splits"), generating a decision heatmap with a high weighting percentage, thereby reconstructing the transaction intent of "circumventing regulation through high-frequency splits." This visual analysis plays an important role in courtroom testimony, allowing judges to intuitively understand the logic behind AI's fraud identification and avoid disputes over "black box decision-making."
[0046] When regulatory agencies audit a suspicious cross-border transaction, the dual-chain anchored evidence storage structure of the trusted evidence storage interface ensures the immutability of the evidence. The system first stores the evidence chain (including transaction instructions, fund flow graphs, analysis reports, etc.) in fragments using an improved Merkle tree—dividing the data into 128 fragments, each fragment integrating the hardware digital signature of the ATM terminal (tamper-proof) and the financial-grade timestamp (accurate to the millisecond level) from the National Time Service Center. Then, the Merkle tree root hash is synchronously written to the financial consortium blockchain (for internal bank auditing) and the judicial evidence storage chain (for regulatory agencies to retrieve).
[0047] The audit reports generated by the dynamic evidence encapsulation engine strictly comply with the requirements of the "Regulations on Anti-Money Laundering by Financial Institutions": the reports not only include transaction timelines and fund penetration paths, but also the on-chain storage address for each piece of evidence—regulators can directly verify the integrity and temporal validity of the fragments by entering the address through a blockchain explorer. For raw data of unregistered transaction patterns (such as the novel cross-border remittance records mentioned above), the sandbox data isolation mechanism plays a crucial role: auditors must undergo dual biometric authentication using fingerprints and Ukeys, and then decrypt the data through quantum key fragmentation (with key fragments held by three regulators) before they can access the isolated data, thus meeting regulatory requirements while preventing data misuse.
[0048] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.
Claims
1. An intelligent data processing system for intelligent evidence collection, characterized in that, This includes a distributed edge probe group, a dynamic fraud strategy engine, an intelligent evidence chain construction module, and a trusted evidence storage interface; The distributed edge probe group is deployed in the core transaction system. It has a built-in lightweight protocol parser and adapts to SWIFT and UnionPay private protocols and a real-time de-identification module within the parser. It performs transaction account masking and behavior trajectory hashing and solidification at the data source end. The dynamic fraud strategy engine accesses the abnormal transaction flow of the edge probe group and stores cross-institutional transaction pattern vectors through a graph neural network fraud feature library; the real-time threat assessment unit detects the probability of abnormal transaction timing based on a hidden Markov model. The adaptive forensics controller dynamically activates targeted forensics commands based on threat values, and extends the evidence storage period for suspicious sessions by capturing cross-platform fund flows with high priority. The intelligent evidence chain construction module includes a multi-level fund flow tracking unit and an interpretable AI parser. The multi-level fund flow tracking unit uses an entity association graph to map virtual accounts to actual controllers. The interpretable AI parser uses attention weight visualization technology to restore the semantics of encrypted transaction instructions and generate a decision heatmap. The trusted evidence storage interface uses an improved Merkle tree to store the evidence chain in fragments. Each fragment integrates an edge device digital signature and a financial-grade timestamp, and outputs a compliant audit report. The dynamic fraud strategy engine activates an adversarial sample generation mechanism when identifying unregistered transaction patterns: it uses a generative adversarial network to synthesize new fraudulent transaction features, updates the weights of the graph neural network, and isolates the original data into a financial regulatory sandbox.
2. The intelligent data processing system for intelligent evidence collection as described in claim 1, characterized in that: The distributed edge probe group adopts a domain-based deployment architecture, wherein the probes deployed on ATM terminals integrate magnetic strip and chip dual-mode sniffers to capture the operation command stream of physical transaction terminals in real time. The mobile app probe is embedded in a trusted execution environment and intercepts encrypted communication data through system call hijacking technology. The core transaction system probe loads a private protocol reverse adapter, which dynamically generates SWIFT and UnionPay private protocol parsing templates based on the protocol field entropy value. The real-time desensitization module executes a hierarchical data processing pipeline: it uses a format-preserving encryption mask for transaction accounts, applies SM3 hashing to solidify behavioral trajectories, and injects key fragments protected by a hardware security module.
3. The intelligent data processing system for intelligent evidence collection as described in claim 1, characterized in that: In the dynamic fraud strategy engine: the graph neural network fraud feature library adopts heterogeneous graph fusion technology to map transaction entity nodes and relationship edges into high-dimensional feature vectors; the real-time threat assessment unit constructs a dual-threshold triggering mechanism: when the anomaly probability output by the hidden Markov model exceeds the first threshold, basic evidence collection is activated, and when it exceeds the second threshold, cross-platform fund flow capture is triggered; the adaptive evidence collection controller configures a strategy priority matrix and dynamically allocates computing resources to the suspicious session evidence storage link according to the threat value weight.
4. The intelligent data processing system for intelligent evidence collection as described in claim 1, characterized in that: The operation process of the intelligent evidence chain construction module is as follows: time-series penetration analysis is implemented through multi-level fund flow tracking units: the fund flow path is tracked based on an improved depth-first search algorithm, and unstructured data sources are integrated to construct evidence related to the actual controller; the interpretable AI parser deploys a hierarchical attention mechanism: word-level attention weight heatmaps are generated at the instruction semantic restoration layer, operation logic decision trees are output at the behavior intent analysis layer, and model bias interference is eliminated through adversarial training.
5. The intelligent data processing system for intelligent evidence collection as described in claim 1, characterized in that: The trusted evidence storage interface operates through a dual-chain anchored evidence storage structure: the improved Merkle tree root hash is synchronously written into the financial consortium chain and the judicial evidence storage chain, and zero-knowledge proof technology is used to verify cross-chain consistency; a dynamic evidence encapsulation engine: generates standardized evidence packages as required, which integrate timestamps certified by the National Time Service Center, probe device digital certificates, and parser version traceability identifiers; and a sandbox data isolation mechanism: physical isolation storage is implemented for the original data of unregistered transaction modes, and access requires multiple biometric authentication and quantum key fragment decryption authorization.
Citation Information
Patent Citations
Quantum hidden Markov model solution fraud detection method and system, storage medium and terminal
CN113570452A
ETC fraud detection method
CN120493249A