An Adaptive Blocking System and Method for Transaction Risk Based on Large Model Behavioral Chain Analysis
The adaptive risk blocking system for trading, which uses large-scale model behavior chain analysis, solves the problem of insufficient risk identification in complex trading environments by traditional methods. It achieves real-time and accurate risk control, adapts to complex and ever-changing trading patterns, and improves the accuracy and response speed of risk assessment.
Patent Information
- Application Number
- CN202511238841.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-01
- Publication Date
- 2025-11-14
- Estimated Expiration
- 2045-09-01
AI Technical Summary
Traditional financial transaction risk control methods are ill-equipped to handle complex and ever-changing transaction behaviors and hidden risk patterns, and lack real-time capability, resulting in insufficient accuracy and timeliness in risk identification and control.
An adaptive blocking system for transaction risk based on large model behavior chain analysis is adopted. Through real-time data acquisition, behavior chain construction, dynamic temporal modeling and reinforcement learning controller, combined with multi-dimensional data analysis, it can achieve real-time and accurate assessment and adaptive blocking of transaction risk.
It enables real-time and accurate identification and control of financial transaction risks, improves risk response speed, enhances the comprehensiveness and accuracy of risk assessment, adapts to complex and ever-changing trading environments, and reduces misjudgments and omissions.
Smart Images

Figure CN120746712B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of financial transaction risk prevention and control technology, and in particular to an adaptive risk blocking system and method for transaction risk based on large model behavioral chain analysis. Background Technology
[0002] With the rapid development of fintech, financial transactions are becoming increasingly frequent, with ever-expanding transaction volumes and increasingly complex and diverse transaction patterns. Traditional risk control methods mainly rely on rule thresholds and simple models, which have played a certain role in processing structured data and simple transaction patterns. For example, setting limits on transaction amounts and transaction frequency to identify potentially risky transactions provided some risk control support in the early financial markets. However, with the rapid evolution of financial markets, the characteristics and manifestations of transaction risks have undergone profound changes, and traditional methods have gradually revealed many limitations.
[0003] Traditional risk control methods struggle to address the complex and ever-changing nature of transactions and the hidden patterns of risk. On one hand, financial market transactions are highly complex and diverse; relying solely on a single transaction characteristic (such as transaction amount) for risk assessment can easily lead to misjudgments and omissions. For example, in complex money laundering or fraudulent activities, perpetrators may circumvent traditional threshold-based monitoring rules by diversifying transaction amounts and frequently changing trading accounts, making it difficult to detect risky transactions in a timely manner. On the other hand, transaction risks are often influenced by a combination of factors, including the background information of the transaction participants, the time and location of the transaction, and the market environment. Traditional methods struggle to comprehensively integrate and deeply analyze this multi-dimensional information, thus failing to accurately identify potential risks.
[0004] In the era of digital transactions, the demand for real-time performance has increased, making traditional risk control methods inadequate. Traditional methods typically employ periodic or batch-based risk assessment models, resulting in significant time delays in data processing and risk judgment. For example, some risk assessment systems require centralized processing and analysis of the day's data after the close of trading each day, generating risk reports only the following day. This delay prevents financial institutions from promptly grasping the dynamics of transaction risks and responding quickly to ongoing high-risk transactions, potentially leading to escalating risks and substantial losses for both financial institutions and investors. Therefore, how to identify and control transaction risks in a real-time and accurate manner within the complex financial market environment has become a critical issue that urgently needs to be addressed in the financial sector. Summary of the Invention
[0005] In view of this, the present invention addresses the deficiencies of the existing technology, and its main objective is to provide a transaction risk adaptive blocking system and method based on large model behavioral chain analysis. Through real-time early warning, behavioral chain analysis and adaptive blocking technology, it effectively improves the accuracy and real-time performance of transaction risk prevention and control.
[0006] To achieve the above objectives, the present invention adopts the following technical solution:
[0007] An adaptive blocking system for transaction risk based on large-scale model behavioral chain analysis includes:
[0008] The data acquisition module is used to collect transaction data from the trading system in real time. The transaction data includes information on the trading entity, transaction time, transaction amount, transaction type, transaction terminal device information, and the user's real-time interactive behavior stream.
[0009] A behavior chain construction engine, connected to the data acquisition module, is used to construct a transaction behavior chain based on transaction data. The transaction behavior chain includes a sequence of transaction behaviors of a transaction entity at different points in time. The behavior chain construction engine employs a multi-chain fusion mechanism based on a directed acyclic graph structure to merge sub-behavior chains of the same transaction entity across different terminals and business scenarios, generating a unified main behavior chain. This main behavior chain has a unique chain identifier, version number, and chain digest based on a hash algorithm. Furthermore, when merging sub-behavior chains, the behavior chain construction engine also performs the following: cross-chain association of sub-behavior chain nodes from different terminals based on the semantic similarity and temporal proximity of transaction events; generating a supernode for the associated nodes, which stores multimodal feature summaries of all its associated child nodes; and generating a chain digest by performing a hash operation on the supernode structure.
[0010] The large model analysis module, connected to the behavior chain building engine, is used to perform large model analysis on the transaction behavior chain and extract in-depth risk features.
[0011] The dynamic temporal modeling module, connected to the behavior chain construction engine, is used to perform dynamic temporal modeling of the transaction behavior chain and generate temporal risk features. These temporal risk features are used to characterize the temporal risk features of the transaction behavior chain.
[0012] The large model analysis module and the dynamic time series modeling module adopt a joint training mechanism. The BERT model is fine-tuned using historical transaction behavior chain data to adapt it to transaction semantic feature extraction. The semantic feature vector output by BERT is concatenated with the transaction behavior feature vector and input into the LSTM model. The LSTM model outputs time series risk features and calculates risk assessment loss. The loss value is used to update the parameters of both the LSTM and BERT models simultaneously through a backpropagation mechanism.
[0013] After training, the large model analysis module uses a multimodal large language model fine-tuned from the transaction corpus to encode the structured and unstructured contextual data in the transaction behavior chain into a unified embedding vector. The multimodal large language model is a fine-tuned BERT and GNN fusion structure. The deep risk features are extracted by calculating the cosine similarity between this embedding vector and a predefined risk prototype vector library.
[0014] The system also includes a dynamic heterogeneous model array and a meta-reinforcement learning controller. Deep risk features and temporal risk features are concatenated and input to the dynamic heterogeneous model array. The dynamic heterogeneous model array contains multiple risk assessment models with different structures. The meta-reinforcement learning controller dynamically selects and fuses the outputs of the risk assessment models in the dynamic heterogeneous model array based on the current transaction context to generate a comprehensive risk assessment score. The state space of the meta-reinforcement learning controller includes transaction type, device fingerprint, network latency, and real-time computing resource utilization. Its reward function is used to balance the accuracy of risk assessment with decision latency.
[0015] The risk assessment and blocking module, connected to the meta-reinforcement learning controller, is used to receive the comprehensive risk assessment score and adaptively block transactions when the score exceeds a preset threshold.
[0016] As a preferred embodiment, the risk assessment and blocking module also includes
[0017] The interpretability submodule is used to generate an interpretable report on trading risks. This submodule constructs a risk root cause path graph based on GNN attention weights and LSTM time step contributions, and outputs risk warning information through natural language generation technology.
[0018] The reinforcement learning unit has a state space that includes market volatility, the rate of change in the credit score of the trading entity, the historical false blocking rate, and the abnormal score of the current trading behavior chain. The action space is a set of discrete offsets of the risk threshold. The reward function is defined as: R = α × (interception reward) - β × (false blocking cost) - γ × (response delay), where α, β, and γ are weight coefficients obtained through training with historical data.
[0019] Before the risk assessment and blocking module executes the blocking decision, a tiny random perturbation factor generated by a quantum random number generator is introduced to fine-tune the comprehensive risk assessment score; if the fine-tuned score exceeds a preset threshold, the transaction is adaptively blocked.
[0020] As a preferred solution, the system adopts an edge-cloud collaborative architecture. The terminal device deploys a lightweight behavior chain screening model for rapid anomaly detection of local transaction behavior; the cloud deploys a large model and an LSTM joint model for accurate risk assessment; and the terminal and the cloud transmit high-dimensional feature vectors through a feature distillation protocol.
[0021] As a preferred embodiment, the data acquisition module is also used to collect the geographical location information and operation behavior information of the transaction terminal device. The operation behavior information includes keyboard input speed, mouse movement trajectory, and screen touch frequency. The user's real-time interactive behavior stream includes the original trajectory and time series data used to generate cross-modal behavior anchor points.
[0022] As a preferred embodiment, it also includes a cross-modal behavior anchor generation module, which extracts biological behavior features from the user's real-time interactive behavior stream while constructing the behavior chain, and binds them with the current transaction semantic intent to generate a dynamically updated cross-modal behavior anchor. When constructing the transaction behavior chain, the behavior chain construction engine also considers the historical transaction behavior patterns of the transaction subject, including transaction frequency, average transaction amount, and common transaction types.
[0023] As a preferred option, the system also supports a federated learning mode, where multiple financial institutions can jointly train a behavioral chain risk assessment model without sharing the original transaction data. Homomorphic encryption technology is used to encrypt and upload the local model parameters; the central server aggregates the model parameters of each institution and distributes updates; each institution decrypts the data locally and continues training, forming a closed loop.
[0024] A method for applying the transaction risk adaptive blocking system based on large model behavioral chain analysis includes the following steps:
[0025] S1. Real-time acquisition of transaction data from the trading system;
[0026] S2. Construct a transaction behavior chain based on transaction data, and construct the main behavior chain using a multi-chain fusion mechanism based on a directed acyclic graph structure;
[0027] S3. Utilize the large model analysis module to analyze the transaction behavior chain and extract in-depth risk characteristics;
[0028] S4. Dynamically time-series model the transaction behavior chain that integrates the analysis results of the large model to generate time-series risk features; in steps S3 and S4, a joint training mechanism is used to perform end-to-end optimization of the large model and the LSTM model.
[0029] S5. Real-time assessment of transaction risk based on comprehensive risk assessment score, and adaptive blocking of transactions when the risk exceeds a preset threshold; and generation of interpretable risk reports and dynamic adjustment of risk thresholds based on reinforcement learning.
[0030] Compared with existing technologies, this invention has significant advantages and beneficial effects. Specifically, as shown in the above technical solution, by stringing together the trading behaviors of trading entities at different points in time to form a sequence, and combining this with dynamic time-series modeling to generate time-series risk characteristics, real-time and accurate risk assessment is achieved. Based on this, the system can quickly identify potential risky transactions and provide early warnings. Simultaneously, the risk assessment and blocking module dynamically adjusts risk thresholds based on market fluctuations and the creditworthiness of trading entities, adaptively blocking high-risk transactions to ensure that prevention and control strategies match actual needs. This solution also integrates multi-dimensional data, including geographical location and operational behavior information, further improving the comprehensiveness and accuracy of risk identification. Its beneficial effects are reflected in: first, real-time monitoring and early warning shorten risk response time and help financial institutions stop losses in a timely manner; second, accurate identification of hidden risks, which has significant advantages compared with traditional single-feature focus methods; third, dynamic response characteristics, which can adapt to complex and ever-changing trading risk environments; and fourth, replacing simple thresholds and improving the accuracy of risk assessment. Overall, this solution provides innovative and effective technical means for financial transaction risk prevention and control, effectively ensuring the safe and stable operation of financial transactions.
[0031] To more clearly illustrate the structural features and effects of the present invention, a detailed description is provided below in conjunction with the accompanying drawings and specific embodiments. Attached Figure Description
[0032] Figure 1 This is a schematic diagram of the system architecture and process of the present invention;
[0033] Figure 2 This is a schematic diagram of the blocking method steps of the present invention. Detailed Implementation
[0034] The present invention is as follows Figure 1 and Figure 2 As shown, an adaptive blocking system and method for transaction risk based on large-scale model behavioral chain analysis is presented. The system includes a data acquisition module, a behavioral chain construction engine, a large-scale model analysis module, a dynamic time-series modeling module, and a risk assessment and blocking module, wherein:
[0035] The data acquisition module is used to collect transaction data from the trading system in real time. The transaction data includes information on the trading entity, transaction time, transaction amount, transaction type, information on the trading terminal device, and the real-time interactive behavior stream of the user.
[0036] The behavior chain construction engine is connected to the data acquisition module and is used to construct a transaction behavior chain based on transaction data. The transaction behavior chain includes a sequence of transaction behaviors of the transaction subject at different points in time. The behavior chain construction engine uses a directed acyclic graph (DAG) structure to store the sub-behavior chains of the same transaction subject under different terminals and different business scenarios, and generates a unified main behavior chain. The main behavior chain has a unique chain identifier, version number and chain digest based on a hash algorithm.
[0037] The behavior chain construction engine, when merging sub-behavior chains, also performs the following: cross-chain association of sub-behavior chain nodes from different terminals based on the semantic similarity and temporal proximity of transaction events; generates a supernode for the associated node, which stores the multimodal feature summary of all its associated child nodes; and generates a chain summary by performing a hash operation on the supernode structure.
[0038] During the DAG main chain merging phase, the system simultaneously calculates two rules for each child chain node: semantic similarity and temporal proximity.
[0039] Semantic dimension: Vectorize fields such as transaction type, amount range, recipient category, and product description, and use cosine distance as a metric. Transaction types below a threshold θs (e.g., 0.15) are considered to be of the same type.
[0040] Time sequence dimension: It is required that the timestamp difference Δt between two nodes falls within the sliding window T (default 30 min, which can be dynamically scaled according to the transaction type) to ensure the real-time nature of causal relationships.
[0041] Only when both of the above conditions are met can a cross-chain edge be generated in the DAG, formally connecting the child nodes that were originally scattered across different terminals.
[0042] Several child nodes connected by cross-chain edges are aggregated into a "supernode," which stores the following internally:
[0043] Multimodal feature summary: including average transaction amount, geographic cluster center, mean of cross-modal behavior anchor points, device fingerprint hash, historical default labels, etc.
[0044] Member index: Retains a reverse pointer to each child node for easy tracing and auditing later;
[0045] Metadata: Records aggregated timestamps, version numbers, and associated business scenarios for incremental updates.
[0046] Through a single alignment-aggregation operation, local behaviors across terminals and scenarios are compressed into a single high-dimensional vector, which can then be read by subsequent large models at once, significantly reducing computational redundancy.
[0047] First, the multimodal feature summaries within the supernode are normalized, sorted, and serialized, and then SHA-256 is performed to obtain a 256-bit supernode hash.
[0048] All supernode hashes are rolled up level by level in a Merkle Tree to form the main chain's chain-digest, which is written to the tamper-proof log. If any child node data is tampered with, its hash change will be propagated along the Merkle path to the chain-digest, achieving second-level integrity verification. At the same time, this chain-digest serves as a "global fingerprint" and is directly called by the large model analysis module, ensuring that risk calculations are based on the latest and most complete multi-terminal behavior view and providing a traceable chain of evidence for regulatory audits.
[0049] Each child chain node contains a transaction timestamp, a transaction feature vector, and a hash pointer to the previous node. The main chain node stores the hash digests of all child chains and periodically generates a Merkle root to ensure the integrity and immutability of the behavioral chain.
[0050] To globally and uniquely identify and track a main behavior chain, the system first generates and writes its chain identifier (Chain-ID) through the following steps when generating the main behavior chain:
[0051] 1. Use the globally unique user identifier of the transaction entity (such as user UUID or ID number hash) as the prefix;
[0052] 2. Concatenate the current timestamp (accurate to milliseconds) with a 128-bit random salt (generated by the system CSPRNG);
[0053] 3. Perform a SHA-256 operation on the concatenated result and take the first 128 bits as the final Chain-ID.
[0054] The Chain-ID is persisted in the "id" field of the main chain root node and remains unchanged throughout its lifecycle.
[0055] To support version rollback and auditing, the main chain automatically increments its version number (Version-No) each time a structural update occurs (adding a sub-chain or changing the sub-chain digest). The version number uses a 64-bit unsigned integer, monotonically increasing from 1; old versions of the main chain nodes are still retained in cold storage, using "Chain-ID + Version-No" as a composite primary key for subsequent audit rollback.
[0056] The chain digest is generated as follows: First, a Merkle Tree calculation is performed on the hash list of all child chains within the main chain node to obtain the Merkle root; then, the Merkle root is combined with the current version number and Chain-ID to perform a double SHA-256 hash, and the final 256-bit result is the chain digest of the main chain. This digest is written to the tamper-proof log system along with the transaction log to ensure the integrity and verifiability of the main chain.
[0057] The large-scale model analysis module, connected to the behavior chain construction engine, is used to perform large-scale model analysis on the transaction behavior chain and extract deep risk features. The large-scale model analysis module includes the following two sub-modules:
[0058] The BERT semantic feature extraction submodule employs a pre-trained BERT model and processes the transaction text data through fine-tuning to extract risk-related semantic features. The multi-layer Transformer architecture of the BERT model can capture semantic information and contextual dependencies in the transaction text.
[0059] The Graph Neural Network (GNN) correlation analysis submodule analyzes the relationships between trading entities using GNNs to capture potential risk propagation paths. GNNs identify abnormal correlation patterns between trading entities through node embeddings and edge weight calculations. Training data is derived from historical trading data and an industry risk case library, ensuring the model can learn diverse risk characteristics.
[0060] The large model analysis module and the dynamic time series modeling module adopt a joint training mechanism, which specifically includes the following steps: fine-tuning the BERT model using historical transaction behavior chain data to adapt it to transaction semantic feature extraction; fusing the semantic feature vector output by BERT with the correlation feature vector output by GNN to form a comprehensive feature vector; concatenating the comprehensive feature vector with the transaction behavior feature vector and inputting it into the LSTM model; the LSTM model outputs time series risk features and calculates risk assessment loss; and updating the parameters of the LSTM, BERT, and GNN models simultaneously through a backpropagation mechanism to achieve end-to-end optimization.
[0061] The large-scale model analysis module employs pre-trained large language model technology to perform in-depth analysis of transaction behavior chains and related data, extracting richer risk characteristics and potential risk information. Its calculation formula is: MLF t =σ(W m ·X t + b m );
[0062] Among them, MLF tX represents the eigenvector of the large model analysis at time t. t W represents the feature vector of trading behavior at time t. m b represents the weight matrix of the large model. m Let σ represent the bias vector of the large model, and σ represent the activation function.
[0063] After training, the large model analysis module uses a multimodal large language model fine-tuned from the transaction corpus (the multimodal large language model is a fine-tuned BERT and GNN fusion structure) to encode the structured data and unstructured context data in the transaction behavior chain into a unified embedding vector; the deep risk features are extracted by calculating the cosine similarity between this embedding vector and a predefined risk prototype vector library.
[0064] Specifically, after training, the large model analysis module enters inference mode. It receives two types of data from the entire transaction behavior chain at once: ① structured fields—numerical or categorical features such as amount, timestamp, geographic location, device fingerprint, and cross-modal behavior anchors; ② unstructured context—free text such as transaction notes, chat logs, and product descriptions. Both types of data are fed into the same multimodal large language model that has undergone secondary fine-tuning of the transaction corpus to ensure semantic alignment with business requirements.
[0065] The model first performs word-level embedding on the text, then maps the structured features to the same high-dimensional semantic space through a cross-modal attention mechanism, finally outputting a 768-dimensional (example) unified embedding vector E. This vector carries both statistical information about the transaction itself and contextual semantics, and its fixed dimension facilitates subsequent high-speed computation.
[0066] During the offline phase, the system uses the embedding vectors of historical fraud, money laundering, and credit card fraud samples to cluster and obtain K "risk prototypes" {P1,…,Pk}. During the online phase, cos(E,Pi) is calculated in real time. cos(E,Pi) measures the similarity between the current transaction embedding vector E and the i-th risk prototype vector Pi. The higher the value, the more likely it belongs to the corresponding risk category. The maximum similarity or a weighted combination is taken as the deep risk feature score_deep. This score is concatenated with the LSTM temporal features and then fed into the downstream heterogeneous model array and meta-reinforcement learning controller. Simultaneously, E and score_deep are written to the audit log for subsequent tracking and interpretation.
[0067] The dynamic temporal modeling module is connected to the behavior chain construction engine and is used to perform dynamic temporal modeling on the transaction behavior chain to generate temporal risk features. The temporal risk features are used to characterize the temporal risk features of the transaction behavior chain.
[0068] The dynamic time series modeling module uses a Long Short-Term Memory (LSTM) network to model the transaction behavior chain that integrates the analysis results of a large model. The hidden layer dimension of the LSTM is set to 128, and the time window length T is set to the number of transaction time points within 10 minutes. The hidden layer dimension of 128 is the optimal value determined through cross-validation and grid search, which can balance model complexity and computational efficiency.
[0069] The specific process is as follows:
[0070] Initialize LSTM model parameters: Set the initial values of the weight matrices and bias vectors for the input gate, forget gate, and output gate. The dimension of the weight matrix is determined based on the number of transaction behavior features and the number of hidden layer neurons. The bias of the forget gate is initialized to be negatively correlated with the historical credit cycle of the transaction subject. The larger the forget gate bias, the more historical information is retained; the smaller the bias, the faster the forgetting. The system sets it to "negative multiplication of credit cycle". A longer credit cycle results in a smaller bias and faster forgetting; a shorter credit cycle results in a larger bias and more retention. This setting is automatically completed according to the subject's credit cycle without the need for parameter tuning, making the model's memory more closely match the individual's risk profile.
[0071] Each transaction in the transaction behavior chain, which integrates the analysis results of the large model, is represented as a feature vector and then sequentially input into the LSTM model. The feature vector includes key features such as transaction amount, transaction frequency, transaction time interval, and transaction type. Each feature is standardized to have zero mean and unit variance.
[0072] By updating the hidden layer states and cell states of the LSTM model, long-term dependencies and dynamic patterns in trading behavior can be captured. The hidden layer states record short-term characteristics of trading behavior, while the cell states preserve long-term memory information. By controlling the inflow and outflow of information through a gating mechanism, the model can effectively handle long-term dependencies in time series data.
[0073] The risk assessment and blocking module, connected to the dynamic time series modeling module, is used to assess transaction risk in real time based on time series risk characteristics and adaptively block transactions when the risk exceeds a preset threshold.
[0074] The risk assessment and blocking module includes an interpretability submodule. This submodule constructs a risk root cause path graph based on GNN attention weights and LSTM time step contributions. Using natural language generation technology, the path graph is transformed into risk warning information, including risk type, triggering behavior, related transaction nodes, and their weight distribution, for risk control personnel or users to review. The interpretability submodule constructs the risk root cause path graph based on GNN attention weights and LSTM time step contributions and outputs risk warning information using natural language generation technology. By analyzing the contributions of GNN attention weights and LSTM time steps, the interpretability submodule identifies the transaction nodes and time steps that have the greatest impact on the risk score. Based on a predefined risk type template, it generates a risk explanation report in natural language. The risk warning information also discloses whether the threshold trigger was caused by quantum perturbation, ensuring interpretability and compliance auditing. For example, a user makes a large transfer on a remote device at 10:15, a behavior significantly different from their historical transaction patterns, contributing 67% to the risk score.
[0075] The risk assessment and blocking module also includes a reinforcement learning unit. Its state space includes market volatility (such as the VIX index), the rate of change in the credit scores of trading entities, historical false blocking rates, and the anomaly scores of the current trading behavior chain. The action space is a set of discrete offsets of the risk threshold, and the reward function is defined as:
[0076] R = α × (Interception Revenue) - β × (Cost of False Interception) - γ × (Response Delay), where α, β, and γ are weighting coefficients obtained through training with historical data. The interception revenue in the reward function is defined as the amount of successfully intercepted suspicious transactions multiplied by a risk coefficient; the cost of false interception is defined as the number of falsely intercepted transactions multiplied by the average cost of handling user complaints; and the response delay is defined as the time difference between the occurrence of a transaction and the decision to block it. The weighting coefficients α, β, and γ are determined through grid search and cross-validation to maximize the cumulative reward.
[0077] The system also includes a dynamic heterogeneous model array and a meta-reinforcement learning controller. The dynamic heterogeneous model array contains multiple risk assessment models with different structures. The meta-reinforcement learning controller dynamically selects and merges the outputs of at least two models in the array according to the current transaction context to generate a comprehensive risk assessment score. The state space of the meta-reinforcement learning controller includes transaction type, device fingerprint, network latency, and real-time computing resource utilization. Its reward function aims to balance the accuracy of risk assessment with decision latency.
[0078] Before blocking, the system adds a "dynamic heterogeneous model array," containing multiple high-precision models with different structures, which output risk scores in parallel. The meta-reinforcement learning controller reads context such as transaction type, device fingerprint, network latency, and resource consumption in real time, and selects and weights the results of at least two models within milliseconds to generate a comprehensive risk score. This mechanism uses "accuracy-latency-resource" as a reward, balancing accuracy and real-time performance. The output comprehensive score directly enters the subsequent quantum perturbation and threshold comparison stages, forming an end-to-end decision-making closed loop.
[0079] Before the risk assessment and blocking module executes the blocking decision, a tiny random perturbation factor generated by a quantum random number generator is introduced to fine-tune the comprehensive risk assessment score; if the fine-tuned score exceeds a preset threshold, the transaction is adaptively blocked.
[0080] Before the final block, the system first uses a quantum random number generator to produce a tiny perturbation ε, fine-tuning the comprehensive risk score R given by the meta-reinforcement learning controller, resulting in R′ = R + ε, to prevent the fixed threshold from being precisely bypassed. If the fine-tuned R′ is still higher than the dynamic threshold T, the transaction is immediately blocked; otherwise, it is allowed. ε and R′ are written to the audit log throughout the process to ensure traceability. This mechanism introduces an unpredictable random safety margin without altering long-term statistical decisions, increasing the difficulty of circumventing the restrictions while meeting financial compliance and auditability requirements.
[0081] The risk assessment model uses a logistic regression model with a learning rate of 0.01 and a regularization parameter of 0.1. The model is trained using the Adam optimizer with a learning rate of 0.001, which is dynamically adjusted during training to accelerate convergence.
[0082] System latency metrics: The average response time from data acquisition to blocking decision is 50 milliseconds, and the system supports processing 1000 transactions per second (TPS). The system adopts a distributed computing architecture, achieving low latency through GPU acceleration and multi-threaded processing. The software architecture employs a microservice design, with each module deployed independently to ensure high concurrency processing capabilities.
[0083] Dynamic Threshold Adjustment: A reinforcement learning algorithm, Q-learning, is introduced to optimize the threshold adjustment strategy through a reward mechanism. The reward function dynamically adjusts the risk threshold based on the false blocking rate and risk aversion benefits to balance risk control and user experience. By integrating industry blacklists, historical risk cases, and real-time market dynamics with a knowledge graph, the system enhances risk correlation analysis capabilities. The knowledge graph identifies abnormal correlation patterns between trading entities through node embedding and edge weight calculation.
[0084] The system is deployed in the bank's data center and interfaces with the online transaction system's servers. The data acquisition module collects real-time transaction data from the online transaction system via a network interface. This data includes transaction entity information (such as user ID and account information), transaction time (accurate to the second), transaction amount (accurate to the minute), transaction type (such as transfer, consumption, and wealth management purchase), and transaction terminal device information (such as device model, operating system version, and IP address). Simultaneously, the data acquisition module also collects the geographical location information of the transaction terminal device (such as latitude and longitude information obtained through GPS positioning or IP address resolution) and operational behavior information (such as keyboard input speed, mouse movement trajectory, and screen touch frequency) through device sensors and operation logs. The user's real-time interactive behavior stream includes raw trajectory and time-series data used to generate cross-modal behavior anchor points. The real-time interactive behavior flow consists of raw trajectories (coordinates, pressure, key travel, etc.) synchronously collected by the terminal and millisecond-level time-series data. After denoising and statistical analysis by the cross-modal behavior anchor generation module, a 128-dimensional biological behavior vector is formed and bound to the current transaction semantic intent in real time, and refreshed incrementally with user operations. This anchor is written into the behavior chain node and co-encoded with the large model and LSTM to accurately identify bots or impersonation attacks.
[0085] The system adopts an edge-cloud collaborative architecture. Terminal devices deploy a lightweight behavioral chain initial screening model for rapid anomaly detection of local transaction behavior. A large-scale model and an LSTM joint model are deployed in the cloud for accurate risk assessment. High-dimensional feature vectors are transmitted between the terminal and the cloud via a feature distillation protocol, reducing bandwidth consumption and improving response speed. The terminal device quantizes and compresses the intermediate layer feature vectors of the local model and uploads them to the cloud via an HTTPS encrypted channel. The cloud model dequantizes the received feature vectors and performs knowledge distillation with the output of the local model, enabling the cloud model to maintain high accuracy while reducing its dependence on the original data.
[0086] In addition, the data acquisition module is also responsible for collecting other operational behavior information from the transaction terminal devices, such as the user's click intensity and the smoothness of swiping operations during the transaction process. This information is encrypted before being transmitted to the system to ensure data security and integrity. The system supports a federated learning mode, allowing multiple financial institutions to jointly train a behavioral chain risk assessment model without sharing the original transaction data. The specific implementation includes: encrypting and uploading local model parameters using homomorphic encryption technology; the central server aggregating the model parameters from each institution and distributing updates; and each institution decrypting the data locally and continuing training, forming a closed loop. The Paillier homomorphic encryption algorithm is used to encrypt the model parameters, ensuring they cannot be cracked during transmission and aggregation. The central server uses a secure aggregation protocol to calculate the average value of the encrypted model parameters and returns the result to each participating institution. Each institution uses its private key to decrypt and update its local model, completing one round of federated learning training.
[0087] In a federated learning model, multiple financial institutions participate in jointly training a behavioral chain risk assessment model, but do not share the original transaction data. To achieve aggregated updates of model parameters, a weighted average algorithm (such as FedAvg) is typically used. The specific process is as follows:
[0088] Weighted average algorithm (FedAvg)
[0089] Assume there are K financial institutions participating in federated learning, and the model parameters obtained by each institution through local training are... ,in, t represents the current federated learning round. After each institution updates its local model parameters, they are uploaded to the central server using homomorphic encryption. The central server aggregates the model parameters from all institutions and calculates the global model parameters. .
[0090] The aggregation process uses a weighted average algorithm, with weights w. k Typically, the contribution of an organization to the global model is proportional to the amount of local data it possesses; that is, the more data an organization has, the greater its contribution. The specific formula is as follows:
[0091] ;
[0092] The formula for calculating the weight wk is as follows:
[0093] ;
[0094] Here, nk represents the amount of local data of the k-th institution.
[0095] Aggregation process:
[0096] Local Update: Each financial institution k trains its model locally using its dataset Dk and updates the local model parameters. .
[0097] Encrypted upload: Homomorphic encryption is used to protect local model parameters. It is encrypted and uploaded to the central server.
[0098] Aggregate calculation: The central server receives all encrypted model parameters, performs a weighted average based on the amount of data from each institution, and calculates the global model parameters. .
[0099] Decryption and Update: The central server will aggregate the global model parameters. The data is distributed to various financial institutions, which then use their private keys to decrypt the data and update their local models, completing one round of federated learning.
[0100] In this way, federated learning can achieve model parameter sharing and joint optimization among multiple financial institutions while protecting data privacy.
[0101] Each institution's local model parameters are updated based on local data and then uploaded to the central server. When calculating the global model parameters, the central server uses a weighted average based on the amount of data from each institution, as shown in the following formula:
[0102] ;
[0103] The weights are proportional to the amount of local data each institution has.
[0104] The collected transaction data first undergoes a data preprocessing step to ensure data quality and analytical accuracy. The specific steps are as follows:
[0105] 1. Data cleaning: Remove obviously erroneous data records, such as negative transaction amounts or incorrect transaction time formats; at the same time, fill in missing values using a method based on the average of similar transaction entities. For example, for a user's transaction record, if a transaction amount is missing, fill it in based on the average of that user's historical transaction amounts.
[0106] 2. Deduplication: Identify and delete duplicate transaction records by comparing key fields such as transaction subject information, transaction time, and transaction amount to determine the uniqueness of the record.
[0107] 3. Format Conversion: Convert data of different formats into the format required by the system, such as converting date and time strings into a unified timestamp format, and converting monetary data into a numeric format.
[0108] 4. Feature Extraction: Extract key features from the original transaction data, including transaction amount, transaction frequency (calculate the number of transactions within a certain time window), transaction time interval (time difference between adjacent transactions), and transaction type distribution (proportion of each type of transaction).
[0109] 5. Outlier Handling: An anomaly detection method based on clustering algorithms is used to mark data that deviates significantly from normal transaction patterns as outliers, which are then corrected or deleted. For example, if a user's historical transaction amounts are mostly within 1,000 yuan, but a transaction of 1 million yuan suddenly appears, this transaction amount will be considered an outlier and will be further verified or corrected based on the actual situation.
[0110] The preprocessed transaction data is stored in a cache area so that the transaction behavior chain can be quickly built later.
[0111] In addition, the system also includes a cross-modal behavior anchor generation module, which extracts biological behavior features from the user's real-time interactive behavior stream while constructing the behavior chain, and binds them with the current transaction semantic intent to generate a dynamically updated cross-modal behavior anchor.
[0112] While the behavior chain building engine generates DAG nodes for each transaction, the cross-modal behavior anchor point generation module immediately connects to the interactive behavior stream collected in real time by the terminal, including more than 50 dimensions of fine-grained biological behavior signals such as keystroke interval, key travel, mouse trajectory curvature, touch pressure, sliding acceleration, and gyroscope jitter. These data are uploaded at millisecond-level frequency and undergo noise reduction, normalization, and sliding window segmentation locally to form a computable "original behavior tensor".
[0113] The cross-modal behavior anchor generation module uses an attention network to map the aforementioned biological behavior tensor into a 128-dimensional behavior feature vector. Then, this vector is aligned with the current transaction semantic intent (such as "large interbank transfer" or "nighttime wealth management purchase") through a joint embedding space to obtain the cross-modal behavior anchor. This anchor is not static, but is incrementally refreshed in real time with each subsequent key press, swipe, or click by the user, ensuring that the "behavior-intent" coupling always reflects the latest liveness state.
[0114] The updated anchor vector is written into the "multi-modal-anchor" field of the corresponding transaction behavior chain node, becoming one of the inputs to the subsequent large model analysis module and LSTM temporal network. It is co-encoded with features such as transaction text, amount, and geographical location during the joint training phase, and directly participates in cosine similarity calculation during the inference phase, thereby significantly improving the detection accuracy of bot scripts, account takeover, or deepfake behavior, and realizing an end-to-end risk closed loop.
[0115] The behavior chain construction engine considers the historical transaction behavior patterns of the transaction entity when constructing the transaction behavior chain. These patterns include transaction frequency, average transaction amount, and commonly used transaction types. The engine retrieves preprocessed transaction data from the cache, sorts the data according to transaction time, and converts the sorted data into a behavior sequence. Each behavior includes the transaction entity identifier, transaction timestamp, and key feature values (such as transaction amount and transaction type code). Feature enhancement is performed by incorporating the transaction entity's historical transaction behavior patterns during the construction of the transaction behavior chain. For example, for a user who primarily engages in small-amount, high-frequency transactions, their historical transaction behavior pattern is characterized by transaction amounts mostly below 1000 yuan, high transaction frequency (e.g., 5-10 transactions per day), and commonly used transaction types such as transfers and purchases. When the user's current transaction behavior exhibits large-amount, low-frequency, or infrequently used transaction types, the system compares these features with historical patterns and highlights potential anomalies in the behavior chain, forming a complete transaction behavior chain.
[0116] In addition, the behavior chain building engine will also consider other factors in the historical transaction behavior patterns of the transaction subjects, such as the geographical distribution of historical transactions and information on commonly used devices, to further enrich the feature dimensions of the behavior chain and improve the accuracy of abnormal behavior identification.
[0117] The dynamic time-series modeling module uses a Long Short-Term Memory (LSTM) network to model the transaction behavior chain. The specific process is as follows:
[0118] 1. Initialize LSTM model parameters: Set the initial values of the weight matrices of the input gate, forget gate, and output gate, as well as the bias vector. The dimension of the weight matrix is determined based on the number of transaction behavior features and the number of hidden layer neurons.
[0119] 2. Represent each transaction in the transaction chain as a feature vector, and input them sequentially into the LSTM model. The feature vector includes key features such as transaction amount, transaction frequency, transaction time interval, and transaction type. Each feature is standardized to have zero mean and unit variance.
[0120] 3. By updating the hidden layer states and cell states of the LSTM model, long-term dependencies and dynamic patterns of trading behavior can be captured. The hidden layer states record the short-term characteristics of trading behavior, while the cell states preserve long-term memory information. By controlling the inflow and outflow of information through a gating mechanism, the model can effectively handle long-term dependencies in time series data.
[0121] 4. Output the hidden layer state at each time step as a temporal risk feature.
[0122] The risk assessment and blocking module assesses transaction risk in real time based on time-series risk characteristics. The specific process is as follows:
[0123] 1. Calculate the statistical characteristics of time-series risk features within a preset time window (e.g., the most recent 10 minutes), including the mean, variance, and maximum value. These statistical characteristics can reflect the overall risk level and volatility of trading behavior within the time window.
[0124] 2. Utilize a pre-defined risk assessment model (such as a machine learning model based on logistic regression or random forest) to calculate the transaction risk assessment value based on statistical characteristics. During the training phase, the risk assessment model uses a large amount of historical transaction data (including normal and risky transaction samples) to learn and extract behavioral chain features and temporal risk features from the sample data, thereby accurately quantifying the risk level of the current transaction.
[0125] 3. Dynamically adjust risk thresholds based on market fluctuations (such as stock market index fluctuations and exchange rate fluctuations) and the creditworthiness of trading entities (such as credit scores and historical default records). For example, when market volatility is high, appropriately lower the risk threshold to increase the sensitivity of risk control; for trading entities with poor creditworthiness, set stricter risk thresholds to strengthen risk management.
[0126] 4. The system compares the transaction risk assessment value with the dynamically adjusted risk threshold. If the threshold is exceeded, the transaction is automatically blocked. Simultaneously, the system sends a risk warning to the transaction participant, informing them of the reason for the block (e.g., abnormal transaction behavior, potential account theft), the risk level (e.g., high risk, medium risk), and suggested actions (e.g., changing password, contacting bank customer service), so that the participant can promptly understand the risk situation and take appropriate measures.
[0127] For example, when the system detects multiple instances of unusual logins and large transfers to a user's account within a short period, and the risk value calculated by the risk assessment model exceeds the risk threshold dynamically adjusted based on current market fluctuations and the user's credit status, the system will immediately block these transactions and send the user a risk warning SMS containing the reason for the blocking, the risk level, and suggested actions, such as, "Dear user, your account has experienced abnormal logins and large transfers from other locations, which may indicate a risk of account theft and has been temporarily blocked by the system. We suggest you immediately change your password and call our customer service at 955XX for verification."
[0128] To ensure the accuracy and adaptability of the risk assessment model, it is necessary to train and optimize the model regularly. The specific steps are as follows:
[0129] 1. Collect a large amount of historical transaction data, including samples of normal and risky transactions. The sample data covers different transaction types, transaction entities, and transaction time information to ensure the diversity and representativeness of the data.
[0130] 2. Perform preprocessing and feature extraction on the sample data to extract behavioral chain features (such as transaction frequency and trend of amount change) and time-series risk features (such as time-series risk features output by the LSTM model).
[0131] 3. Use machine learning algorithms (such as logistic regression, random forest, neural networks) to train on sample data, and by adjusting model parameters (such as learning rate, regularization parameters) and optimization algorithms (such as gradient descent, genetic algorithm), obtain a model that can accurately assess trading risks.
[0132] 4. Regularly update and optimize the risk assessment model to adapt to market changes and new risk patterns. For example, retrain the model quarterly based on the latest transaction data and risk cases to optimize model parameters and improve the model's ability to identify and predict new risk behaviors.
[0133] The threshold adaptive adjustment unit dynamically adjusts the risk threshold based on market fluctuations and the creditworthiness of the trading entities. The specific implementation method is as follows:
[0134] 1. Market Volatility Monitoring: The system monitors financial market volatility indicators in real time, such as stock market index volatility and exchange rate volatility. When market volatility exceeds a preset volatility threshold, a risk threshold adjustment mechanism is triggered.
[0135] 2. Credit Assessment of Transaction Entities: The system periodically assesses the creditworthiness of transaction entities, including credit scores, historical default records, and account balance stability. For transaction entities with poor credit, the system lowers their risk threshold and increases the stringency of risk control measures.
[0136] 3. Dynamic Adjustment Algorithm: Employing a machine learning-based dynamic adjustment algorithm, the risk threshold is automatically adjusted based on market fluctuations and changes in the creditworthiness of trading entities. For example, a linear regression model is used to predict the impact of market fluctuations on the risk threshold, and the threshold is updated in real time based on the prediction results.
[0137] The adaptive blocking system for transaction risk based on large-scale model behavioral chain analysis of this invention includes a data acquisition module, a behavioral chain construction engine, a dynamic time-series modeling module, and a risk assessment and blocking module. The system's workflow is as follows:
[0138] The data acquisition module collects transaction data from the trading system in real time, including information on the trading entity, transaction time, transaction amount, transaction type, and transaction terminal device information, and transmits the collected data to the behavior chain building engine.
[0139] After preprocessing the transaction data, the behavior chain building engine constructs a transaction behavior chain, which connects the transaction behaviors of the transaction entities at different points in time to form a sequence, and enhances the features by combining the historical transaction behavior patterns of the transaction entities.
[0140] The dynamic time series modeling module performs dynamic time series modeling on the transaction behavior chain, uses LSTM technology to generate time series risk features, and captures the long-term dependencies and dynamic change patterns of transaction behavior.
[0141] The risk assessment and blocking module assesses transaction risk in real time based on time-series risk characteristics. It calculates the risk assessment value and compares it with a dynamically adjusted risk threshold. If the risk exceeds the preset threshold, it adaptively blocks the transaction and sends a risk warning message to the transaction entity.
[0142] The key design focus of this invention is to create an adaptive risk blocking system for transactions, incorporating a data acquisition module, a behavior chain construction engine, a dynamic time-series modeling module, and a risk assessment and blocking module. This system and method effectively address the complex risk challenges in financial transactions and possess the following innovative features:
[0143] 1. Real-time early warning mechanism: The system collects transaction data in real time and connects closely at each stage to achieve real-time monitoring and early warning of transaction risks. It can issue an alarm the moment a risk occurs, which greatly shortens the risk response time and enables financial institutions to take timely measures to prevent the expansion of losses.
[0144] 2. Behavioral Chain Analysis Technology: By introducing behavioral chain analysis, the trading behaviors of trading entities at different points in time are linked together to form a sequence, which comprehensively and deeply analyzes the behavioral patterns and characteristics of trading entities. Compared with traditional methods that only focus on a single trading feature, it can more accurately identify hidden risks and improve the accuracy of risk identification.
[0145] 3. Adaptive blocking function: Enhances the dynamic response characteristics of the system, adjusts the blocking strategy in real time according to the market and trading participants' conditions, ensures that risk control measures always meet actual needs, and effectively cope with complex and ever-changing trading risk environments.
[0146] 4. Dynamic temporal modeling replaces simple thresholds: The advanced Long Short-Term Memory (LSTM) network dynamic temporal modeling technology is used to replace the traditional simple threshold judgment method. It can capture the long-term dependencies and dynamic change patterns of transaction behavior, avoid the limitations of simple threshold methods, and improve the accuracy and reliability of risk assessment.
[0147] 5. Multi-dimensional data fusion: It innovatively integrates multi-dimensional data such as geographic location information and operational behavior information, enriching the feature system of risk assessment and improving the comprehensiveness and accuracy of risk identification.
[0148] In summary, the adaptive blocking system and method for transaction risk based on large model behavioral chain analysis of the present invention has significant advantages and innovations in the field of financial transaction risk prevention and control, and can provide a solid guarantee for the safe and stable operation of financial transactions.
[0149] The above description is merely a preferred embodiment of the present invention and does not constitute any limitation on the technical scope of the present invention. Therefore, any minor modifications, variations, and alterations made to the above embodiments based on the technical essence of the present invention shall still fall within the scope of the technical solution of the present invention.
Claims
1. A transaction risk adaptive blocking system based on large-scale model behavioral chain analysis, characterized in that, include: The data acquisition module is used to collect transaction data from the trading system in real time. The transaction data includes information on the trading entity, transaction time, transaction amount, transaction type, transaction terminal device information, and the user's real-time interactive behavior stream. A behavior chain construction engine, connected to the data acquisition module, is used to construct a transaction behavior chain based on transaction data. The transaction behavior chain includes a sequence of transaction behaviors of a transaction entity at different points in time. The behavior chain construction engine employs a multi-chain fusion mechanism based on a directed acyclic graph structure to merge sub-behavior chains of the same transaction entity across different terminals and business scenarios, generating a unified main behavior chain. This main behavior chain has a unique chain identifier, version number, and chain digest based on a hash algorithm. Furthermore, when merging sub-behavior chains, the behavior chain construction engine also performs the following: cross-chain association of sub-behavior chain nodes from different terminals based on the semantic similarity and temporal proximity of transaction events; generating a supernode for the associated nodes, which stores multimodal feature summaries of all its associated child nodes; and generating a chain digest by performing a hash operation on the supernode structure. The large model analysis module, connected to the behavior chain building engine, is used to perform large model analysis on the transaction behavior chain and extract in-depth risk features. The dynamic temporal modeling module, connected to the behavior chain construction engine, is used to perform dynamic temporal modeling of the transaction behavior chain and generate temporal risk features. These temporal risk features are used to characterize the temporal risk features of the transaction behavior chain. The large model analysis module and the dynamic time series modeling module adopt a joint training mechanism. The BERT model is fine-tuned using historical transaction behavior chain data to adapt it to transaction semantic feature extraction. The semantic feature vector output by BERT is concatenated with the transaction behavior feature vector and input into the LSTM model. The LSTM model outputs time series risk features and calculates risk assessment loss. The loss value is used to update the parameters of both the LSTM and BERT models simultaneously through a backpropagation mechanism. After training, the large model analysis module adopts a multimodal large language model fine-tuned from the transaction corpus. The multimodal large language model is a fine-tuned BERT and GNN fusion structure. It encodes the structured data and unstructured context data in the transaction behavior chain into a unified embedding vector. The deep risk features are extracted by calculating the cosine similarity between the embedding vector and the predefined risk prototype vector library. The system also includes a dynamic heterogeneous model array and a meta-reinforcement learning controller. Deep risk features and temporal risk features are concatenated and input to the dynamic heterogeneous model array. The dynamic heterogeneous model array contains multiple risk assessment models with different structures. The meta-reinforcement learning controller dynamically selects and fuses the outputs of the risk assessment models in the dynamic heterogeneous model array based on the current transaction context to generate a comprehensive risk assessment score. The state space of the meta-reinforcement learning controller includes transaction type, device fingerprint, network latency, and real-time computing resource utilization. Its reward function is used to balance the accuracy of risk assessment with decision latency. The risk assessment and blocking module, connected to the meta-reinforcement learning controller, is used to receive the comprehensive risk assessment score and adaptively block transactions when the score exceeds a preset threshold.
2. The transaction risk adaptive blocking system based on large model behavioral chain analysis according to claim 1, characterized in that, The risk assessment and blocking module also includes The interpretability submodule is used to generate interpretable reports on trading risks. It constructs a risk root cause path graph based on GNN attention weights and LSTM time step contributions, and outputs risk warning information through natural language generation technology. The reinforcement learning unit has a state space that includes market volatility, the rate of change in the credit score of the trading entity, the historical false blocking rate, and the abnormal score of the current trading behavior chain. The action space is a set of discrete offsets of the risk threshold. The reward function is defined as: R = α × (interception reward) - β × (false blocking cost) - γ × (response delay), where α, β, and γ are weight coefficients obtained through training with historical data. Before the risk assessment and blocking module executes the blocking decision, a tiny random perturbation factor generated by a quantum random number generator is introduced to fine-tune the comprehensive risk assessment score; if the fine-tuned score exceeds a preset threshold, the transaction is adaptively blocked.
3. The transaction risk adaptive blocking system based on large model behavioral chain analysis according to claim 1, characterized in that, The system adopts an edge-cloud collaborative architecture. The terminal device deploys a lightweight behavior chain screening model for rapid anomaly detection of local transaction behavior; the cloud deploys a large model and an LSTM joint model for accurate risk assessment; and high-dimensional feature vectors are transmitted between the terminal and the cloud through a feature distillation protocol.
4. The transaction risk adaptive blocking system based on large model behavioral chain analysis according to claim 1, characterized in that, The data acquisition module is also used to collect the geographical location information and operation behavior information of the transaction terminal device. The operation behavior information includes keyboard input speed, mouse movement trajectory and screen touch frequency. The user's real-time interactive behavior stream includes the original trajectory and time series data used to generate cross-modal behavior anchor points.
5. The transaction risk adaptive blocking system based on large model behavioral chain analysis according to claim 1, characterized in that, It also includes a cross-modal behavior anchor generation module, which extracts biological behavior features from the user's real-time interactive behavior stream while constructing the behavior chain, and binds them with the current transaction semantic intent to generate a dynamically updated cross-modal behavior anchor. When constructing the transaction behavior chain, the behavior chain construction engine also considers the historical transaction behavior patterns of the transaction subject, including transaction frequency, average transaction amount, and commonly used transaction types.
6. The transaction risk adaptive blocking system based on large model behavioral chain analysis according to claim 1, characterized in that, The system also supports a federated learning mode, where multiple financial institutions can jointly train a behavioral chain risk assessment model without sharing the original transaction data. Homomorphic encryption technology is used to encrypt and upload the local model parameters; the central server aggregates the model parameters of each institution and distributes updates; each institution decrypts the data locally and continues training, forming a closed loop.
7. A method for applying to a transaction risk adaptive blocking system based on large model behavioral chain analysis as described in any one of claims 1-6, characterized in that, Includes the following steps: S1. Real-time acquisition of transaction data from the trading system; S2. Construct a transaction behavior chain based on transaction data, and construct the main behavior chain using a multi-chain fusion mechanism based on a directed acyclic graph structure; S3. Utilize the large model analysis module to analyze the transaction behavior chain and extract in-depth risk characteristics; S4. Perform dynamic time-series modeling on the transaction behavior chain that integrates the analysis results of the large model to generate time-series risk characteristics; In steps S3 and S4, a joint training mechanism is used to perform end-to-end optimization of the large model and the LSTM model; S5. Real-time assessment of transaction risk based on comprehensive risk assessment score, and adaptive blocking of transactions when the risk exceeds a preset threshold; and generation of interpretable risk reports and dynamic adjustment of risk thresholds based on reinforcement learning.
Citation Information
Patent Citations
Federal learning-based privacy protection type large-scale model training and deployment method
CN118734360A