Financial transaction real-time risk identification method based on multi-source heterogeneous data

By constructing a dynamic risk map and spatiotemporal conflict binding technology, the problem of integrating multi-source heterogeneous data in financial transactions has been solved, the real-time tracking of the dynamic transmission path of funds and the improvement of the accuracy of risk identification have been achieved, and the security of financial transactions has been enhanced.

CN120807150AInactive Publication Date: 2025-10-17HEFEI JIUYI SOFTWARE DEV CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202511011544.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-22
Publication Date
2025-10-17
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Existing technologies have lags in identifying financial transaction risks, have difficulty integrating multi-source heterogeneous data, cannot track the dynamic transmission path of funds in real time, and lack spatiotemporal correlation verification, resulting in insufficient risk identification accuracy and low efficiency.

Method used

By analyzing user entity relationships to build a dynamic risk map, combined with the preset capital flow baseline threshold to locate abnormal jump nodes, and perform time and space conflict binding, marking the degree of overlap between environmental tampering risk points and capital jump paths as the basis for risk judgment.

Benefits of technology

It has achieved accurate capture of potential risks in complex transaction chains, improved the pertinence and timeliness of risk identification, and enhanced the security of financial transactions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120807150A_ABST
    Figure CN120807150A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of data processing, and discloses a financial transaction real-time risk identification method and system based on multi-source heterogeneous data, and the method comprises the steps: obtaining original heterogeneous data and a real-time transaction environment of a financial transaction; tracking an abnormal path of the financial transaction based on a user entity relationship in the original heterogeneous data so as to establish a dynamic risk map of the financial transaction; marking the real-time transaction environment with the tampering record as an environment tampering risk point of the financial transaction; taking an overlapping degree between the environment tampering risk point and a fund jump path in the dynamic risk map as a spatial conflict level of the financial transaction; and determining a risk judgment result of the financial transaction based on the spatial conflict level. The method solves the problems that the risk identification has hysteresis during the financial transaction and is difficult to adapt to the real-time risk identification requirement in a complex financial transaction scene.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of data processing, and in particular to a financial transaction real-time risk identification method and system based on multi-source heterogeneous data. BACKGROUND

[0002] In the field of financial transaction risk identification, the existing technology adopts single-dimensional analysis for the processing of multi-source heterogeneous data, which is difficult to integrate cross-domain information such as user entity relationship and device environment, resulting in a lag in risk identification. The traditional method only relies on static rule library to match abnormal transactions, and cannot track the dynamic transmission path of funds in multi-level transaction links in real time. When there is a complex account mapping level of fund transfer, potential risk nodes are easily missed, and the judgment of abnormal path lacks spatial correlation verification, making it difficult to quantify the dynamic conflict probability and resulting in insufficient precision in risk graph construction.

[0003] At the same time, the existing technology for security assessment of transaction environment is limited to single parameter detection, and does not perform spatial correlation analysis on environmental factors such as device fingerprint and location state with fund flow path. When the real-time transaction environment is tampered with, it is impossible to evaluate the risk level through the overlap degree of environmental tampering risk points and fund transfer path, and relying only on isolated environmental abnormal markers results in a lack of quantitative basis for spatial conflict dimension in risk judgment, making it difficult to adapt to real-time risk identification needs in complex financial transaction scenarios, and the overall identification efficiency and accuracy are low. SUMMARY

[0004] The present application provides a financial transaction real-time risk identification method and system based on multi-source heterogeneous data, which mainly aims to solve the problem of lag in risk identification during financial transactions and difficulty in adapting to real-time risk identification needs in complex financial transaction scenarios.

[0005] To achieve the above-mentioned purpose, the financial transaction real-time risk identification method based on multi-source heterogeneous data provided by the present application comprises: S1, obtaining original heterogeneous data of financial transactions and real-time transaction environment; S2, based on the user entity relationship in the original heterogeneous data, tracking the abnormal path of the financial transaction, thereby establishing a dynamic risk graph of the financial transaction; S3, marking the real-time transaction environment with tampering records as an environmental tampering risk point of the financial transaction; S4, taking the overlap degree between the environmental tampering risk point and the fund transfer path in the dynamic risk graph as the spatial conflict level of the financial transaction; S5, determining the risk judgment result of the financial transaction based on the spatial conflict level.

[0006] Preferably, the original heterogeneous data of the financial transaction and the real-time transaction environment are acquired, including: determining a secure access state of a multi-source heterogeneous data interface in the financial transaction; based on the secure access state, real-time pulling of the original heterogeneous data of the financial transaction; labeling device fingerprint parameters and location states of the financial transaction as real-time transaction environments of the financial transaction.

[0007] Preferably, the abnormal path of the financial transaction is tracked based on the user entity relationship in the original heterogeneous data, thereby establishing a dynamic risk map of the financial transaction, including: resolving the user entity relationship in the original heterogeneous data into a multi-level transaction link and an account mapping level; based on a preset fund flow baseline threshold, locating an abnormal jump node in the multi-level transaction link that exceeds a reference fluctuation range; tracing an abnormal fund transmission path of an adjacent abnormal jump node of the abnormal jump node along the account mapping level; spatiotemporal conflict binding of the abnormal fund transmission path and a real-time transaction sequence in the original heterogeneous data to obtain a dynamic conflict probability in the abnormal fund transmission path; based on the dynamic conflict probability and the abnormal fund transmission path, constructing a dynamic risk map of the financial transaction.

[0008] Preferably, the spatiotemporal conflict binding of the abnormal fund transmission path and the real-time transaction sequence in the original heterogeneous data to obtain the dynamic conflict probability in the abnormal fund transmission path includes: acquiring a fund flow frequency distribution and a transaction orientation vector of each transaction node in the real-time transaction sequence within a continuous time window; calculating a spatial offset of a node coordinate in the abnormal fund transmission path and the transaction orientation vector; accumulating and superimposing continuous spatial offsets in the direction of the abnormal fund transmission path to obtain a persistence conflict coefficient of the abnormal fund transmission path; behavior pattern conflict verification of the fund flow frequency distribution and the persistence conflict coefficient to obtain a dynamic conflict probability of the financial transaction.

[0009] Preferably, the real-time transaction environment in which the tampering record appears is marked as an environmental tampering risk point of the financial transaction, including: separating tampering features in the real-time transaction environment, and collecting the separated results as a potential tampering event sequence of the financial transaction; The potential tampering event is subjected to legality verification operation based on the preset environment benchmark library, and a tampering confirmation node is marked; The confirmation tampering node in the potential tampering event is marked based on the preset environment benchmark library; The confirmation tampering node is integrated as an environmental tampering risk point.

[0010] Preferably, the obtaining step of the preset environment benchmark library is: The real-time transaction environment in the historical security period is subjected to feature extraction, and original environment parameters of the financial transaction are obtained; Based on the legal behavior fluctuation value of the original environment parameters, an environment benchmark parameter matrix of the financial transaction is constructed; The compliance of the environment benchmark parameter matrix is verified by backtracking; The environment benchmark parameter matrix that passes the verification is input into a preset environment benchmark library.

[0011] Preferably, the degree of overlap between the environmental tampering risk point and the fund jump path in the dynamic risk map is taken as the spatial conflict level of the financial transaction, which includes: Based on the timestamp and physical coordinate information of the environmental tampering risk point, a space-time unit of the environmental tampering risk point is constructed; The abnormal fund jump path in the dynamic risk map is vectorized to obtain a fund space-time trajectory of the abnormal fund jump path; The degree of overlap between the space-time unit and the fund space-time trajectory is detected, and the degree of overlap is taken as the spatial etching depth of the fund space-time trajectory; The space-time conflict quantization value of the financial transaction is calculated through the time delay etching distance of the spatial etching depth; The space-time conflict quantization value is mapped to a preset conflict interval to obtain the spatial conflict level of the financial transaction.

[0012] Preferably, the calculation formula of the space-time conflict quantization value is:

[0013] Wherein: The space-time conflict quantization value, The gradient vector of the spatial etching depth, The tangent vector of the fund jump path, The environmental risk density in a unit space-time prism, The time series diffusion coefficient, The real-time fund behavior entropy corresponding to the fund flow frequency distribution, The historical benchmark entropy corresponding to the environment benchmark library, Risk entropy factor.

[0014] Preferably, the risk determination result of the financial transaction is determined based on the spatial conflict level, comprising: mapping the spatial conflict level to a preset risk classification interval to obtain a preliminary risk category of the financial transaction; verifying the validity of the preliminary risk category, and outputting the preliminary risk category that passes the verification as a risk determination result.

[0015] A financial transaction real-time risk identification system based on multi-source heterogeneous data, the system comprises: a data acquisition module for acquiring original heterogeneous data of a financial transaction and a real-time transaction environment; a graph construction module for tracking abnormal paths of the financial transaction based on user entity relationships in the original heterogeneous data, thereby establishing a dynamic risk graph of the financial transaction; a risk point acquisition module for marking the real-time transaction environment where tampering records occur as an environmental tampering risk point of the financial transaction; a level determination module for determining the degree of overlap between the environmental tampering risk point and the fund jump path in the dynamic risk graph as the spatial conflict level of the financial transaction; a result output module for determining the risk determination result of the financial transaction based on the spatial conflict level.

[0016] Advantages 1. By analyzing user entity relationships to construct a dynamic risk graph, combining a preset fund flow baseline threshold to locate abnormal jump nodes, tracing abnormal fund transmission paths along account mapping levels, and performing time-space conflict binding to quantify dynamic conflict probability, the potential risks in complex transaction links are accurately captured, overcoming the limitations of traditional static analysis in dealing with multi-level transaction links and account mapping levels, making risk identification more targeted and timely.

[0017] 2. Tampering records in the real-time transaction environment are marked as environmental tampering risk points, and the degree of overlap between them and the fund jump path in the dynamic risk graph is calculated to determine the spatial conflict level, which is used as the basis for risk determination. The correlation information between transaction environment and fund flow is effectively integrated. Spatial conflict quantitative analysis addresses the shortcomings of existing technologies that evaluate environmental abnormalities or fund abnormalities in isolation, providing a more comprehensive reflection of the risk status of financial transactions and improving the accuracy and reliability of real-time risk identification, providing stronger protection for financial transaction security. BRIEF DESCRIPTION OF DRAWINGS

[0018] Figure 1A flowchart of a financial transaction real-time risk identification method based on multi-source heterogeneous data provided by an embodiment of the present application is shown in FIG. Figure 2 A functional module diagram of a financial transaction real-time risk identification system based on multi-source heterogeneous data provided by an embodiment of the present application is shown in FIG. DETAILED DESCRIPTION

[0019] It should be understood that the specific embodiments described herein are merely intended to explain the present application and are not intended to limit the present application.

[0020] The embodiments of the present application provide a financial transaction real-time risk identification method based on multi-source heterogeneous data. The execution subject of the financial transaction real-time risk identification method based on multi-source heterogeneous data includes but is not limited to at least one of electronic devices such as a server, a terminal, etc. that can be configured to execute the method provided by the embodiments of the present application. In other words, the financial transaction real-time risk identification method based on multi-source heterogeneous data can be executed by software or hardware installed in a terminal device or a server device. The server includes but is not limited to a single server, a server cluster, a cloud server, or a cloud server cluster, etc. The server can be a stand-alone server, or a cloud server that provides cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, content distribution networks, and big data and artificial intelligence platforms, etc.

[0021] Referring to Figure 1 A flowchart of a financial transaction real-time risk identification method based on multi-source heterogeneous data provided by an embodiment of the present application is shown in FIG. In this embodiment, the financial transaction real-time risk identification method based on multi-source heterogeneous data includes: S1, obtaining original heterogeneous data of a financial transaction and a real-time transaction environment.

[0022] In this embodiment, the obtaining of the original heterogeneous data of the financial transaction and the real-time transaction environment includes: determining a secure access state of a multi-source heterogeneous data interface in the financial transaction; based on the secure access state, real-time pulling of the original heterogeneous data of the financial transaction; labeling device fingerprint parameters and location states of the financial transaction as the real-time transaction environment of the financial transaction.

[0023] Specifically, the security access state of the multi-source heterogeneous data interface refers to the security status of multiple different sources and different structure data interfaces involved in financial transactions, such as whether there are unauthorized access attempts, whether data transmission is encrypted, whether there are abnormal login records, etc. In the physical environment, it can be understood as the protection situation of the data interaction interface between the bank transaction system and the third-party payment platform, securities transaction system, etc. such as whether the firewall between the bank server and the Alipay interface is running normally, whether the data transmission channel is maliciously monitored, etc.

[0024] Specifically, the original heterogeneous data is data from multiple different channels in financial transactions with different data formats, such as user bank account transaction records, customer service communication voice records during transactions, user consumption behavior logs on e-commerce platforms, etc.

[0025] Specifically, the device fingerprint parameter is a series of parameters that can uniquely identify the transaction device, including the device's hardware model, operating system version, browser type and version, CPU information, network card MAC address, etc. From the physical environment, it is like each mobile phone and computer has its unique identity, such as the user's mobile phone model for transfer operation is iPhone14, the operating system is iOS16.5, etc. Parameter combination.

[0026] Specifically, the location state refers to the geographical location information of the device during the financial transaction, which can be obtained through GPS positioning, base station positioning, WiFi positioning, etc. such as the specific city and street location of the user during the transaction.

[0027] Specifically, the security access state of the multi-source heterogeneous data interface is determined: the system will actively conduct security detection on each data interface involved in financial transactions. By scanning the access log of the interface, it is checked whether there are access IP addresses that do not conform to the routine, abnormal access frequency; check whether the encryption protocol of the interface is effective, whether there are traces of tampering in the data transmission process, etc. For example, the bank system will regularly check the access records of the data interface with the stock exchange, and if it finds that a strange IP has tried to access the interface multiple times in a short period of time, it will be marked as a potential security risk, and the security access state of the interface will be determined to be abnormal.

[0028] Specifically, based on the security access state, real-time pulling of original heterogeneous data: when confirming that the data interface is in a secure access state, the system will start the data pulling mechanism. According to the preset frequency and data range, real-time transaction-related data is obtained from each data source. For example, when a user conducts an online payment transaction, the payment system will immediately obtain the user's account balance, transaction history from the bank, and different types of data such as product prices and order information from the merchant after confirming the security of the data interface with the bank and the merchant. If the security access state of the interface is abnormal, data pulling will be suspended, and a security warning mechanism will be triggered.

[0029] Specifically, the device fingerprint parameters and the location state are calibrated as the real-time transaction environment, and the system organizes and confirms the obtained device fingerprint related information and the location state information, and sets them as the real-time transaction environment parameters of the financial transaction. For example, when a user uses a mobile phone to make a credit card consumption in a certain mall in Shanghai, the system will integrate the device fingerprint parameters of the mobile phone and the location state of the mall in Shanghai as the real-time transaction environment of the consumption transaction, which is used for subsequent risk identification analysis.

[0030] S2, based on the user entity relationship in the original heterogeneous data, tracking the abnormal path of the financial transaction, thereby establishing a dynamic risk map of the financial transaction.

[0031] In this embodiment, based on the user entity relationship in the original heterogeneous data, the abnormal path of the financial transaction is tracked, thereby establishing a dynamic risk map of the financial transaction, comprising: The user entity relationship in the original heterogeneous data is parsed into a multi-level transaction link and an account mapping level; Based on a preset fund flow baseline threshold, locate the abnormal jump nodes in the multi-level transaction link that exceed the benchmark fluctuation range; Along the account mapping level, trace the abnormal fund transmission path of the adjacent abnormal jump nodes of the abnormal jump nodes; The abnormal fund transmission path and the real-time transaction sequence in the original heterogeneous data are spatiotemporally conflict-bonded to obtain a dynamic conflict probability in the abnormal fund transmission path; Based on the dynamic conflict probability and the abnormal fund transmission path, a dynamic risk map of the financial transaction is constructed.

[0032] Specifically, the user entity relationship is the association between different account subjects in the financial transaction scenario, such as employee accounts of enterprise association, parent-subsidiary account relationship, or account fund transfer association between individuals and friends, business partners, covering the relationships generated by interactions such as transfer, lending, and joint investment.

[0033] The multi-level transaction link is a multi-level transaction transmission path formed based on the fund flow direction. For example, enterprise A account→enterprise A subsidiary account→subcompany employee account→employee associated investment account, each layer of fund transfer constitutes a link level, reflecting the flow trajectory of funds from the source to the end.

[0034] The account mapping level is a hierarchical classification of accounts based on account ownership, function, and association. For example, bank public account layer, personal savings account layer, third-party payment account layer, and sub-levels in each layer according to business subdivision, reflecting the position and association of accounts in the system.

[0035] From multi-source heterogeneous data, sort out the inter-account fund transfer and ownership association. Through graph computing algorithms such as depth-first search, track the flow path of funds from the initial account after multiple transfers and transactions, and divide it into a multi-level structure of first-level link (direct transaction) - second-level link (indirect transaction); at the same time, according to the account type, the subject to which it belongs, and the business scenario, build a mapping level of core account - associated account - affiliated account, such as the hierarchical mapping of enterprise master account and branch account, and employee reimbursement account.

[0036] Specifically, the fund flow baseline threshold is the reasonable range of fund flow calculated from historical normal transaction data combined with financial business rules. It includes single transaction amount upper and lower limits, transaction frequency per unit time, and fund flow stability thresholds, which are the basis for determining whether a transaction is abnormal.

[0037] Abnormal jump node: an account or transaction link in the transaction chain that breaks the baseline threshold of fund flow. For example, if a company account transfers a large amount of money to a stranger's personal account on a single day, far exceeding the historical average, or if a personal savings account suddenly has high-frequency cross-border transactions, that account and the corresponding transaction steps are abnormal nodes.

[0038] In detail, first extract the transaction features of each node in the multi-level transaction chain and compare them with the preset baseline threshold. Use anomaly detection algorithms such as statistical threshold method and isolation forest to filter out nodes with sudden increases / decreases in amount, no historical association with transaction counterparties, and transaction time deviating from the business cycle, and mark them as abnormal jump nodes. For example, a retail enterprise in a non-purchasing season suddenly transfers a large amount of money to an overseas account, and the counterparties are not on the supplier list. This transfer node will be identified as abnormal.

[0039] Specifically, adjacent abnormal jump nodes are the upstream and downstream nodes directly associated with the already identified abnormal nodes in the account mapping level and transaction chain. For example, if the abnormal node is account A transferring money to account B, and account B subsequently transfers money to account C and is also abnormal, then accounts B and C are the adjacent abnormal nodes of account A, reflecting the chain abnormality of fund transmission.

[0040] Abnormal fund transmission path is the complete trajectory of abnormal funds flowing in the account system, formed by a series of abnormal jump nodes. For example, a suspicious overseas account → a company's sub-account → an employee's personal account → a cryptocurrency transaction account. Funds from the initial abnormal entry point, through multiple layers of transfer, form a specific transmission path, exposing the direction of risk diffusion.

[0041] In detail, starting from the located abnormal jump node, relying on the association relationship of the account mapping hierarchy, such as the main account-sub-account and the group account-member account, the account nodes of direct transactions are tracked upstream and downstream. The transactions of these adjacent nodes are checked for abnormalities, and the baseline threshold detection is reused. If abnormal, continue to extend the trace until the complete conduction path of the funds from the abnormal starting point to the end node is sorted out. For example, from the enterprise abnormal cross-border transfer node, trace back to the sub-account abnormal bonus, and then to the employee account abnormal consumption, a conduction path of transferring enterprise funds to personal consumption is connected.

[0042] Specifically, the real-time transaction sequence is a set of transaction events generated in real time in financial transactions, arranged in chronological order, containing information such as transaction time, location, amount, participating accounts, etc., reflecting the dynamic process of the transaction.

[0043] The space-time conflict binding is the matching conflict of abnormal fund conduction path and real-time transaction sequence in time and space dimensions. For example, a transaction in the conduction path claims to be a transfer during office hours, but the real-time sequence shows that the transaction occurred in the early morning; the spatial conflict is that the account claims to be a local transaction, but the real-time IP attribution shows that the transaction comes from a high-risk area. The abnormality is verified through cross-validation in time and space dimensions.

[0044] The dynamic conflict probability is based on the time-space conflict situation to quantify the risk degree of the abnormal fund conduction path. The more conflicts, the higher the probability, reflecting the possibility of the path deviating from the normal transaction logic, which is a key indicator for dynamic risk assessment.

[0045] In detail, the transaction time and location information of each node in the abnormal fund conduction path are extracted and compared with the time-space data of the real-time transaction sequence. Time-space matching algorithms such as timestamp difference calculation and spatial geographic fence verification are used to identify conflicts such as transaction time not within the business cycle and transaction location not matching the account's home location. The number and type of conflicts are counted, and the conflict-risk correspondence relationship of historical risk events is combined to calculate the dynamic conflict probability through a probability model such as Bayesian network.

[0046] For example, if three transactions in the conduction path all occur in the early morning (time conflict) and the IP comes from a high-risk area (space conflict), the dynamic conflict probability will significantly increase.

[0047] Specifically, the dynamic risk map is a graphical representation of the path, risk nodes, and risk degree of abnormal fund flow in financial transactions. Nodes represent account / transaction links, edges represent fund conduction relationships, and node color, size, or edge weight reflect dynamic conflict probability. It is a visual and structured result of real-time risk identification, helping to quickly locate high-risk links.

[0048] In detail, the nodes of the abnormal fund transmission path are taken as the vertices of the graph, and the fund flow direction is taken as the edge to construct the basic topology. The dynamic conflict probability is taken as the attribute of the node / edge, such as red high-probability node and large size display, and the account attributes in the original heterogeneous data, such as account type, belonging subject and transaction characteristics, are combined to supplement the graph dimension. Through the graph visualization technology such as the force-directed layout algorithm, a dynamically updated risk graph is generated to display the risk propagation path and key risk points in real time for monitoring and disposal by the risk control personnel.

[0049] In the embodiment, the abnormal fund transmission path and the real-time transaction sequence in the original heterogeneous data are spatio-temporally bound to obtain the dynamic conflict probability in the abnormal fund transmission path, which comprises: Obtaining the fund flow frequency distribution and the transaction position vector of each transaction node in the real-time transaction sequence within a continuous time window; Calculating the spatial offset of the node coordinates in the abnormal fund transmission path and the transaction position vector; Along the direction of the abnormal fund transmission path, the continuous spatial offset is accumulated and superimposed to obtain the persistence conflict coefficient of the abnormal fund transmission path; The fund flow frequency distribution and the persistence conflict coefficient are verified for behavior pattern conflict to obtain the dynamic conflict probability of the financial transaction.

[0050] Specifically, the real-time transaction sequence is a transaction event chain generated in real time according to the time sequence of financial transactions, which contains the transaction time, the involved account, the transaction amount and the like, and a dynamic sequence composed of behaviors such as bank transfer, securities transaction and third-party payment.

[0051] Continuous time window: for analyzing the transaction rules, the continuous time interval is set to cut the real-time transaction into observable time segments, which is convenient for statistical rules and adapts to the real-time monitoring and periodic characteristic analysis requirements of financial transactions.

[0052] The fund flow frequency distribution is the statistical distribution of the number of fund transactions and the amount of change of the transaction node within the time window. For example, the enterprise account usually has 5 small amount purchase transfers from 9:00 to 10:00, and the frequency distribution reflects the rules of the time period-transaction frequency / amount.

[0053] The transaction position vector is a spatial vector abstracted from the geographical attribute of the financial transaction, which contains the longitude and latitude of the transaction occurrence place and the spatial relative position of the account subject, and reflects the spatial direction characteristics of the fund flow.

[0054] In detail, the real-time transaction data is intercepted from the multi-source heterogeneous data source according to the continuous time window. For each transaction node, the number of fund inflow / outflow and the amount interval proportion within the window are counted to generate the fund flow frequency distribution.

[0055] Meanwhile, by geographic identification in transaction records, combined with account opening location information, the spatial vector of transaction occurrence location and account subject is calculated, and the transaction orientation vector is extracted.

[0056] Specifically, the node coordinates are the spatial positions of each transaction node in the abnormal fund transmission path, which can be converted into standardized coordinates based on the transaction orientation vector, and used to quantify the spatial position.

[0057] The spatial offset is the spatial difference between the abnormal node coordinates and the normal transaction orientation vector, reflecting the deviation of the actual transaction location from the normal business space position. For example, if the normal transaction orientation vector of an enterprise procurement account is the local supplier concentration area, and a transaction node coordinate suddenly appears in an unfamiliar overseas area, a large spatial offset will be generated.

[0058] In detail, the nodes of the abnormal fund transmission path are first converted into node coordinates based on transaction geographic information, and then the normal transaction orientation vector of the account / business to which the node belongs is retrieved, based on the spatial characteristics of historical normal transactions, such as the normal transaction orientation of an enterprise payroll account being the local employee residential area. The spatial distance algorithm, such as Euclidean distance, is used to calculate the difference between the node coordinates and the normal transaction orientation vector, and the spatial offset is obtained, quantifying the degree of abnormality in the spatial dimension.

[0059] Specifically, the transmission path direction is the direction of the abnormal fund flow in the account system, which is the logical sequence of fund transmission, determining the path of spatial offset accumulation.

[0060] The persistent conflict coefficient is the cumulative value of the spatial offset along the transmission path, reflecting the degree of continuous deviation of abnormal fund flow in the spatial dimension from the normal. The larger the offset is and the higher the cumulative value is, the larger the coefficient is, indicating that the fund is more likely to flow in an abnormal spatial trajectory (such as multiple transactions jumping to a high-risk overseas area).

[0061] In detail, the spatial offset of each node is extracted in the direction of the abnormal fund transmission path, and the cumulative algorithm, such as node-by-node addition, is used to accumulate the offsets of consecutive nodes. For example, the spatial offsets of 3 nodes in the path are 5, 8, and 10 respectively, and the cumulative superposition of the persistent conflict coefficient is 23. The larger the coefficient is, the more significant the conflict is, indicating that the abnormal fund continuously deviates from the normal transaction area in space.

[0062] Specifically, the behavior pattern conflict verification is to compare the fund flow frequency distribution and the persistent conflict coefficient to verify whether they conflict with the normal financial transaction behavior pattern.

[0063] For example, the normal pattern of an enterprise is high-frequency local transactions during weekdays, and if low-frequency overseas transactions occur in the early morning with a high spatial conflict coefficient, it is determined that the behavior pattern conflicts.

[0064] The dynamic conflict probability is a conflict that comprehensively considers time and space dimensions, a quantitative risk probability value, and reflects the possibility of a financial transaction deviating from a normal mode, and is a core quantitative index of real-time risk identification.

[0065] In detail, a normal financial transaction behavior mode library is constructed. The frequency distribution of fund flow and the persistence conflict coefficient are substituted into the mode library for matching verification. If the time frequency + space conflict of the actual transaction is greatly different from the normal mode, a dynamic conflict probability is calculated by a probability model such as logistic regression or neural network, the greater the difference, the higher the probability, and the transaction risk level is identified.

[0066] S3, the real-time transaction environment in which the tampering record appears is marked as an environment tampering risk point of the financial transaction.

[0067] In this embodiment, the real-time transaction environment in which the tampering record appears is marked as an environment tampering risk point of the financial transaction, comprising: Separating tampering features in the real-time transaction environment, and collecting the separated results as a potential tampering event sequence of the financial transaction; Based on a preset environment benchmark library, performing a legality verification operation on the potential tampering event, and marking a tampering confirmation node; Based on the preset environment benchmark library, marking the confirmation tampering node in the potential tampering event; Integrating the confirmation tampering node into an environment tampering risk point.

[0068] Specifically, the real-time transaction environment is full-scene data when the financial transaction occurs, including transaction device fingerprints, network environment, physical location, transaction time sequence and other multi-source heterogeneous data, which is an environment snapshot of transaction authenticity.

[0069] The tampering feature is an abnormal data feature in the real-time transaction environment that deviates from the normal mode and may be caused by tampering behavior. For example, sudden change of device fingerprint, IP address cross-region jump, and unordered transaction timestamp, which are core indexes for identifying tampering risk.

[0070] The potential tampering event sequence is an event chain that concatenates the separated tampering features in the order of transaction process / time sequence, reflecting how abnormal features appear and spread in the transaction environment, such as continuous abnormalities of device fingerprint anomaly→IP address forgery→transaction time sequence disorder, which constitute the behavior track of potential tampering.

[0071] In detail, full-amount data of real-time transaction environment is extracted from multi-source heterogeneous data sources. Feature engineering methods such as abnormality detection algorithm and pattern matching rule are used to filter out data points significantly different from historical normal transaction environment, and to separate tampering features such as identifying that the device MAC address is virtually modified and the transaction latitude and longitude conflict with the base station positioning. According to the time sequence and process link of transaction, such as login->transfer->confirmation, these tampering features are sorted, collected into potential tampering event sequences, and the occurrence logic of abnormal behavior is sorted out.

[0072] Specifically, the environment benchmark library is a knowledge base for storing normal transaction environment features, including historical normal transaction device fingerprint library, such as user's commonly used mobile phone model, system version distribution, network environment whitelist, such as enterprise office IP segment, commonly used transaction base station information, physical location association rule, such as the reasonable range of account residence and transaction site, transaction time sequence template, such as the normal time interval of login->transfer->confirmation, etc., which is a standard template for judging whether the transaction environment is legal.

[0073] The legality verification operation is to compare the features of the potential tampering event with the normal standard of the environment benchmark library to verify whether the event conforms to the legal environment rules of financial transaction.

[0074] For example, if the transaction device fingerprint is not in the user's commonly used device library and the IP address is not in the enterprise authorized network segment, it is determined that there is a conflict in legality.

[0075] The tampering confirmation node is an event node that deviates from the environment benchmark library and is confirmed to be caused by tampering. For example, if the device fingerprint is tampered and cannot match the normal device library, the node is marked as a tampering confirmation node, which is a key basis for risk judgment.

[0076] In detail, the standard data of the environment benchmark library is called to match and verify each event in the potential tampering event sequence. Rule engines such as if-then logic are used: if the transaction IP is not in the whitelist IP segment, it is determined to be abnormal, or machine learning models such as trained environment legality classifiers are used to identify events conflicting with the benchmark library.

[0077] After further verification of the conflicting events, such as checking whether the device is stolen or the IP is forged by proxy, it is confirmed that the conflict is caused by tampering, and the event is marked as a tampering confirmation node.

[0078] Specifically, the tampering confirmation node is consistent with the meaning of the tampering confirmation node, emphasizes the determination of the event node based on the environment benchmark library, and is a flow-based labeling of the second step tampering confirmation node to ensure that the node meets the verification logic of the benchmark library.

[0079] In detail, the standard of the reuse environment benchmark library is used to re-accurately match the abnormal nodes that have been preliminarily determined in the potential tampering event sequence. For example, for the transaction timestamp disorder event, the normal transaction time sequence template in the benchmark library is compared. If the actual time sequence is to transfer money immediately after login without manual operation interval, and combined with the benchmark library rules, the node is marked as a confirmed tampering node, and the determination basis of the risk node is strengthened.

[0080] Specifically, the environment tampering risk point: the risk identification formed by the confirmed tampering nodes in the financial transaction, reflecting the core risk area of the tampered transaction environment. It can be understood as a risk link jointly pointed to by multiple tampering nodes. For example, the login link jointly acted by device fingerprint forgery and network environment tampering is an environment tampering risk point, which is used for risk control personnel to focus on disposal.

[0081] In detail, the distribution of the confirmed tampering nodes in the transaction process is sorted out, and a graph analysis or clustering algorithm is used to integrate the tampering nodes related to functions and continuous in time sequence. For example, the device fingerprint tampering node, the IP address forgery node, and the transaction time sequence disorder node all belong to the transaction initiation stage. Therefore, these nodes are aggregated and marked as a transaction initiation environment tampering risk point, which clearly presents the link where the risk is concentrated and assists risk control decision-making.

[0082] In the embodiment, the acquisition step of the preset environment benchmark library is: Feature extraction is performed on the real-time transaction environment in the historical safe period to obtain original environment parameters of the financial transaction; Based on the legal behavior fluctuation value of the original environment parameters, an environment benchmark parameter matrix of the financial transaction is constructed; The compliance of the environment benchmark parameter matrix is verified by backtracking; The environment benchmark parameter matrix that passes the verification is input into a preset environment benchmark library.

[0083] Specifically, the historical safe period is a continuous time period selected from the financial transaction that is verified by risk control to be a risk-free event, which is a sample interval for constructing a normal environment benchmark. For example, a period of 6 months without transaction fraud and stable system operation of a certain bank in the past is selected as the historical safe period.

[0084] The original environment parameters are key feature data extracted from the real-time transaction environment in the historical safe period.

[0085] For example, the model distribution of the user's commonly used device, the operator network segment to which the transaction IP belongs, and the transaction time concentrated in weekdays 9:00-17:00 are basic data for constructing the benchmark library.

[0086] In detail, from the financial transaction system, the transaction data of the historical safe period is screened. The multi-source heterogeneous data in the real-time transaction environment is parsed by using feature engineering techniques such as data mining algorithms and regular expression matching.

[0087] Specifically, the legal behavior fluctuation value is the normal fluctuation range of the original environmental parameter in the historical safe period. For example, the user transaction device model is usually stable, but the network IP may have certain fluctuations due to roaming. The normal fluctuation interval is quantified by statistical methods to distinguish between legal fluctuations and abnormal tampering.

[0088] The environmental benchmark parameter matrix is a standardized matrix constructed by classifying the original environmental parameters by dimension and combining the legal behavior fluctuation value. Each row of the matrix represents an environmental dimension, and each column contains feature names, mean values, fluctuation upper and lower limits, weights, etc., forming a normal standard template for the financial transaction environment, which is used for subsequent verification of the legality of the transaction environment.

[0089] Specifically, compliance is whether the environmental benchmark parameter matrix meets the regulatory requirements and business rules of financial transactions. For example, network environment parameters need to cover the anti-money laundering high-risk area IP monitoring rules, and physical space parameters need to match the bank branch transaction compliance range to ensure that the benchmark library not only reflects the history normal, but also meets the industry compliance standards.

[0090] Backtracking verification is to apply the constructed environmental benchmark parameter matrix to the transaction data of the historical safe period in reverse to verify whether the matrix can accurately identify the legal transaction environment and exclude potential risks that do not trigger events.

[0091] In detail, collect financial industry regulatory rules such as anti-money laundering guidelines, payment clearing specifications, and internal business rules such as account out-of-area transaction limits and device change audit processes.

[0092] Compare the environmental benchmark parameter matrix with the rule library to check whether the matrix parameters cover the compliance requirements. Select edge transaction cases in the historical safe period and use the matrix to verify whether the matrix can correctly determine compliant transactions while identifying potential compliance risks that do not trigger events. If the matrix is found to miss compliance rules or misjudge cases, adjust the matrix parameters (such as correcting the fluctuation value and supplementing the dimension) in reverse to ensure compliance.

[0093] Specifically, the environmental benchmark library is a database that stores the environmental benchmark parameter matrix, which serves as the normal environmental standard source for real-time risk identification of financial transactions. The library contains multiple matrices that support real-time retrieval and verification of the legality of the transaction environment, and is the core knowledge base of the risk control system.

[0094] In detail, the environment benchmark parameter matrix that passes the backtracking verification is standardized. Through a data interface, the matrix is stored in an environment benchmark library, and corresponding business scenarios and historical safety period labels are associated. In subsequent real-time transaction risk identification, the risk control system can retrieve the corresponding matrix from the library to verify the legality of the transaction environment.

[0095] S4, the degree of overlap between the environment tampering risk point and the fund jump path in the dynamic risk map is taken as the spatial conflict level of the financial transaction.

[0096] The degree of overlap between the environment tampering risk point and the fund jump path in the dynamic risk map is taken as the spatial conflict level of the financial transaction, comprising: Based on the timestamp and physical coordinate information of the environment tampering risk point, a space-time unit of the environment tampering risk point is constructed; The abnormal fund jump path in the dynamic risk map is vectorized to obtain a fund space-time trajectory of the abnormal fund jump path; Detect the overlap between the space-time unit and the fund space-time trajectory, and take the overlap as the spatial etching depth of the fund space-time trajectory; Through the time delay etching distance of the spatial etching depth, the space-time conflict quantization value of the financial transaction is calculated; The space-time conflict quantization value is mapped to a preset conflict interval to obtain the spatial conflict level of the financial transaction.

[0097] Specifically, the environment tampering risk point is a risk node in the financial transaction environment that is verified and confirmed to have device / network / timing tampering, such as a device fingerprint forged login node and an IP address tampered transfer node, containing the time and physical location of tampering, and is a risk identifier of transaction environment security.

[0098] The timestamp is an accurate time record of the occurrence of the environment tampering risk point, reflecting the time attribute of the risk event, and is used to associate the transaction timing.

[0099] The space-time unit is a four-dimensional space (three-dimensional physical space + one-dimensional time) unit constructed by fusing the timestamp and physical coordinate information, used to accurately describe when and where the environment tampering risk point occurs, and form a space-time positioning of the risk point.

[0100] In detail, the timestamp and physical coordinate information are extracted from the multi-source heterogeneous data of the environment tampering risk point. Through a space-time modeling method, a four-dimensional space-time unit containing time dimension (T), longitude (X), latitude (Y), and altitude / region code is constructed.

[0101] Specifically, the dynamic risk map is a risk visualization map constructed based on abnormal fund transmission paths in financial transactions. The nodes represent account / trading links, and the edges represent fund flow directions, including time, space, and amount of fund jumps and other multi-source heterogeneous information, reflecting the flow trajectory of abnormal funds.

[0102] Vectorization is the conversion of spatial geometric characteristics and time characteristics of abnormal fund jump paths into mathematical vectors to facilitate the calculation of the spatiotemporal relationship of the trajectory.

[0103] The fund spatiotemporal trajectory is a continuous trajectory description of the abnormal fund jump path in four-dimensional space-time after vectorization, including the time sequence + spatial path vector of fund flow.

[0104] Specifically, the overlap degree is the degree of coincidence of the spatiotemporal unit of the environmental tampering risk point and the abnormal fund spatiotemporal trajectory in the spatiotemporal dimension. It includes: time overlap: whether the risk point timestamp falls within the time sequence interval of the trajectory; spatial overlap: whether the risk point physical coordinates fall within the spatial path range of the trajectory; the higher the overlap degree, the closer the association between the risk point and the abnormal fund flow. The spatial etching depth is the degree of influence of the environmental tampering risk on the abnormal fund trajectory quantified by the overlap degree, which can be understood as the erosion depth of the risk point in the spatiotemporal dimension on the fund trajectory. The higher the overlap degree, the greater the etching depth, reflecting the relevance of risk transmission.

[0105] In detail, time overlap detection is to extract the timestamp of the spatiotemporal unit and compare it with the time sequence of the fund spatiotemporal trajectory to determine whether the timestamp falls within the time sequence of the fund spatiotemporal trajectory and calculate the time overlap ratio.

[0106] Spatial overlap detection is to extract the physical coordinates of the spatiotemporal unit and compare them with the spatial path of the fund spatiotemporal trajectory to determine whether the coordinates fall within the path range. The spatial geometry library can be used to calculate the distance between the point and the line / surface. The smaller the distance, the higher the spatial overlap degree.

[0107] Overlap degree fusion is to weight and fuse the time overlap ratio and the spatial overlap ratio to obtain the total overlap degree.

[0108] Spatial etching depth assignment is to directly use the total overlap degree as the spatial etching depth. The higher the overlap degree, the greater the etching depth, indicating that the influence of the risk point on the fund trajectory is stronger.

[0109] In detail, the time delay etching distance is an extension measure of the spatial etching depth in the time dimension, reflecting the influence of the time difference between the risk point and the fund trajectory on the conflict. For example, the smaller the time difference between the risk point occurrence time and the key node time of the fund trajectory, the greater the time delay etching distance, and the more significant the conflict.

[0110] The quantified value of space-time conflict is a comprehensive measure of spatial etching depth and time delay etching distance. It quantifies the degree of space-time conflict in financial transactions and is the core indicator for determining risk levels. The larger the value, the more serious the space-time conflict.

[0111] Specifically, the preset conflict interval is a pre-divided time-space conflict quantification value interval based on the financial transaction risk tolerance, corresponding to different risk levels.

[0112] The spatial conflict level is the risk level obtained by mapping the quantitative value of the spatiotemporal conflict to the preset conflict interval. It is used to intuitively identify the degree of spatiotemporal conflict risk of the transaction.

[0113] In detail, loading the preset conflict interval is to retrieve the pre-defined conflict interval and level mapping rules from the risk control system configuration, such as configuration files and database tables.

[0114] Quantization value mapping is to compare the calculated spatiotemporal conflict quantization value with a preset interval.

[0115] In this embodiment, the calculation formula of the spatiotemporal conflict quantization value is:

[0116] in: is the quantized value of the spatiotemporal conflict, The gradient vector of the spatial etching depth, is the tangent vector of the capital jump path, is the environmental risk density within the unit space-time prism, is the temporal diffusion coefficient, is the real-time capital behavior entropy corresponding to the capital flow frequency distribution, is the historical benchmark entropy corresponding to the environmental benchmark library, is the risk entropy change factor.

[0117] Specifically, The gradient vector of the spatial etching depth is a vector describing the spatial etching depth The rate and direction of change in the time and space dimensions reflect the changing trend of the spatial erosion intensity of the environmental tampering risk point on the abnormal capital trajectory with location.

[0118] If the abnormal fund track passes through areas with risk points such as equipment tampering and IP forgery, There will be significant changes (such as an increase in the modulus of the gradient vector), indicating the dynamic changes of spatial conflicts.

[0119] For example, funds enter the device fingerprint tampering area from the normal device transaction area. The gradient will increase suddenly, reflecting the sudden change in the spatial etching depth.

[0120] The tangential vector of the fund jump path is the direction vector of the abnormal fund jump path, which describes the spatial direction of the fund flow, such as the direction of the transfer from account A to account B.

[0121] In financial transactions, Calculated by the difference of the physical coordinates of the fund transaction nodes, such as = (X2-X1, Y2-Y1, T2-T1), including spatial and temporal directions.

[0122] For example, the transfer of enterprise funds from the local corporate account coordinates (X1, Y1) to the foreign unknown account coordinates (X2, Y2), Will show obvious cross-border direction characteristics, and when it conflicts with the environment benchmark library, it will amplify the space-time conflict.

[0123] The environmental risk density in the unit space-time prism is the number density of environmental tampering risk points in the unit space-time area, reflecting the risk concentration of the financial transaction environment.

[0124] The space-time prism is a space-time slice of financial transactions, The larger the space-time prism, the higher the environmental risk in the space-time area.

[0125] For example, during a certain cross-border transaction period, multiple accounts have device fingerprint tampering + network environment forgery, Will significantly increase, indicating that the space-time area is risk-intensive and easy to cause space-time conflict.

[0126] The time diffusion coefficient is a measure of the time diffusion of abnormal fund flow, reflecting the range of time sequence deviation from the normal mode, wherein the calculation formula of the time diffusion coefficient is:

[0127] Wherein: The time diffusion coefficient, The time difference between the environmental tampering time and the time of the fund flow through the current node, The number of fund path nodes x average span, The actual time consumption of the fund flow from the starting point to the current node.

[0128] The real-time fund behavior entropy corresponding to the fund flow frequency distribution is a quantitative index of the chaos of real-time fund transaction behavior. The higher the entropy value, the more disordered the fund flow pattern and the more deviated from the normal.

[0129] The normal fund behavior entropy calculated based on the historical safe transaction data of the environment benchmark library is a historical benchmark entropy corresponding to the environment benchmark library, and is a benchmark reference for determining whether the real-time transaction is abnormal.

[0130] The risk entropy change factor is a factor for adjusting the influence degree of the difference between the real-time behavior entropy and the historical benchmark entropy on the space-time conflict, and reflects the risk sensitivity of the financial transaction to the behavior entropy change.

[0131] In detail, first, the gradient of the spatial etching depth and the cross product of the tangential vector of the fund path are calculated. The vector modulus of the spatial interaction is obtained , reflecting the spatial disturbance intensity of the environmental tampering risk to the fund path, and then divided by (environmental risk density x time sequence diffusion coefficient), normalizing the influence of spatial disturbance, and embodying the adjustment of risk density and time sequence anomaly to spatial conflict.

[0132] The difference between the real-time behavior entropy and the historical benchmark entropy is calculated, divided by the risk entropy change factor , and the entropy change logarithmic value is obtained. The influence of the entropy change is amplified by the exponential function

[0133] , and the greater the entropy change , the more significant the contribution of this item to .

[0134] Further, in the financial transaction scenario, the higher the space-time conflict between the environmental tampering risk point and the abnormal fund trajectory, the higher the risk level. For example, when there is a cross-border abnormal transfer + device tampering + significant behavior entropy change, the risk level will be much higher than normal transactions, triggering risk control warning.

[0135] S5, determining the risk determination result of the financial transaction based on the space conflict level.

[0136] In this embodiment, the determination of the risk determination result of the financial transaction based on the space conflict level comprises: mapping the space conflict level to a preset risk classification interval to obtain a preliminary risk category of the financial transaction; verifying the validity of the preliminary risk category, and outputting the preliminary risk category that passes the verification as a risk determination result.

[0137] ​Specifically, the spatial conflict level is quantified by the spatiotemporal conflict between environmental tampering risk points and abnormal capital trajectories. It reflects the risk level of financial transactions in the spatiotemporal dimension and is the core input for risk assessment.

[0138] The preset risk classification interval is a spatial conflict level-risk category mapping rule pre-defined by financial institutions based on historical risk events and regulatory requirements.

[0139] For example: low conflict level → low risk category (such as regular transaction fluctuations); medium conflict level → medium risk category (such as suspicious transactions that need attention); high conflict level → high risk category (such as fraudulent transactions that need to be blocked), to achieve standardized risk classification.

[0140] The preliminary risk category is a preliminary determination of the risk category obtained after the spatial conflict level is mapped to the preset interval, such as high risk - suspected fraud, which is an intermediate result of the risk determination.

[0141] Level matching mapping is the process of matching the real-time calculated spatial conflict level with pre-set rules. For example, if the rule defines a spatial conflict level ≥ 0.8 → high risk category (suspected fraud), the current transaction will be mapped to the high risk category, generating a preliminary risk category.

[0142] Specifically, we extract heterogeneous data from multiple sources of financial transactions and verify whether preliminary risk classifications conflict with multi-dimensional data. For example, if a transaction is initially identified as high-risk fraud, we need to verify whether the device fingerprint is forged, whether the IP address belongs to a high-risk area, and whether the capital flow conforms to a money laundering model.

[0143] If a conflict is found, the preliminary risk category will be adjusted; if consistent, the risk assessment will be strengthened.

[0144] Specifically, the financial risk control system searches the historical risk case database for cases with similar characteristics to the current transaction. For example, if the current transaction's characteristics of device tampering and abnormal cross-border transfers are highly matched with historical cross-border fraud cases, the preliminary risk classification is verified to be valid.

[0145] If a misjudgment case is matched, the preliminary risk category is revised; if a confirmed risk case is matched, the risk category is confirmed.

[0146] like Figure 2 , which is a functional module diagram of a real-time risk identification system for financial transactions based on multi-source heterogeneous data provided by an embodiment of the present invention.

[0147] The financial transaction real-time risk identification system 100 based on multi-source heterogeneous data can be installed in an electronic device. According to the functions implemented, the financial transaction real-time risk identification system 100 based on multi-source heterogeneous data can include a data acquisition module 101, a graph construction module 102, a risk point acquisition module 103, a level determination module 104, and a result output module 105. The modules of the present application can also be referred to as units, which refer to a series of computer program segments that can be executed by an electronic device processor and can complete a fixed function, which are stored in the memory of the electronic device.

[0148] In the present embodiment, the functions of each module / unit are as follows: The financial transaction real-time risk identification system 100 based on multi-source heterogeneous data includes: The data acquisition module 101 is used to acquire original heterogeneous data of financial transactions and real-time transaction environments; The graph construction module 102 is used to track abnormal paths of the financial transactions based on user entity relationships in the original heterogeneous data, thereby establishing a dynamic risk graph of the financial transactions; The risk point acquisition module 103 is used to mark the real-time transaction environment where tampering records occur as an environmental tampering risk point of the financial transactions; The level determination module 104 is used to determine the degree of overlap between the environmental tampering risk point and the fund jump path in the dynamic risk graph as the spatial conflict level of the financial transactions; The result output module 105 is used to determine the risk determination result of the financial transactions based on the spatial conflict level.

[0149] In several embodiments provided by the present application, it should be understood that the disclosed methods and systems can be implemented in other ways. For example, the system embodiments described above are only illustrative, for example, the division of the modules is only a logical functional division, and other division methods can be used in actual implementation.

[0150] The modules described as separate components can or can not be physically separated, and the components displayed as modules can or can not be physical units, i.e., they can be located in one place or distributed on multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the present embodiment.

[0151] In addition, each function module in each embodiment of the present application can be integrated in one processing unit, or each unit can exist physically separately, or two or more units can be integrated in one unit. The integrated unit can be realized in the form of hardware, or in the form of hardware plus software function module.

[0152] It is obvious for those skilled in the art that the present application is not limited to the details of the above exemplary embodiments, and the present application can be implemented in other specific forms without departing from the spirit or essential characteristics of the present application.

[0153] Embodiments of the present application can acquire and process related data based on artificial intelligence technology. Artificial intelligence is the theory, method, technology and application system for using digital computers or computer-controlled machines to simulate, extend and expand human intelligence, perceive environment, acquire knowledge and use knowledge to obtain optimal results.

[0154] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application and are not limiting. Although the present application has been described in detail with reference to the preferred embodiments, it should be understood by those skilled in the art that the technical solutions of the present application can be modified or replaced equivalently without departing from the spirit and scope of the technical solutions of the present application.

Claims

1. A real-time risk identification method for financial transactions based on multi-source heterogeneous data, characterized by: The method comprises: S1. Obtaining original heterogeneous data of financial transactions and real-time transaction environment; S2. Tracking abnormal paths of the financial transactions based on user entity relationships in the original heterogeneous data, thereby establishing a dynamic risk map of the financial transactions; S3. Marking the real-time transaction environment where the tampered record occurs as an environment tampering risk point for the financial transaction; S4. Using the degree of overlap between the environmental tampering risk point and the capital jump path in the dynamic risk map as the spatial conflict level of the financial transaction; S5. Determine a risk assessment result of the financial transaction based on the spatial conflict level.

2. The method for real-time risk identification of financial transactions based on multi-source heterogeneous data according to claim 1, characterized in that: The acquisition of original heterogeneous data of financial transactions and real-time transaction environment includes: Determining the security access status of multi-source heterogeneous data interfaces in the financial transaction; Pulling the original heterogeneous data of the financial transaction in real time based on the security access status; The device fingerprint parameters and location status of the financial transaction are calibrated as the real-time transaction environment of the financial transaction.

3. The method for real-time risk identification of financial transactions based on multi-source heterogeneous data according to claim 1, characterized in that: The step of tracing abnormal paths of the financial transactions based on user entity relationships in the original heterogeneous data, thereby establishing a dynamic risk map of the financial transactions, includes: Parsing the user entity relationships in the original heterogeneous data into multi-level transaction links and account mapping levels; Based on a preset fund flow baseline threshold, locate abnormal jump nodes in the multi-level transaction chain that exceed the baseline fluctuation range; Tracing back the abnormal funds transmission path of the abnormal jump node and its adjacent abnormal jump nodes along the account mapping hierarchy; Performing spatiotemporal conflict binding on the abnormal funds transmission path and the real-time transaction sequence in the original heterogeneous data to obtain a dynamic conflict probability in the abnormal funds transmission path; Based on the dynamic conflict probability and the abnormal capital transmission path, a dynamic risk map of the financial transaction is constructed.

4. The method for real-time risk identification of financial transactions based on multi-source heterogeneous data according to claim 3, characterized in that: The performing spatiotemporal conflict binding on the abnormal funds transmission path and the real-time transaction sequence in the original heterogeneous data to obtain the dynamic conflict probability in the abnormal funds transmission path includes: Obtaining a capital flow frequency distribution and a transaction orientation vector for each transaction node in the real-time transaction sequence within a continuous time window; Calculating the spatial offset between the node coordinates in the abnormal funds transmission path and the transaction orientation vector; Along the direction of the abnormal capital transmission path, the continuous spatial offsets are accumulated and superimposed to obtain a persistence conflict coefficient of the abnormal capital transmission path; A behavioral pattern conflict verification is performed on the fund flow frequency distribution and the persistence conflict coefficient to obtain a dynamic conflict probability of the financial transaction.

5. The method for real-time risk identification of financial transactions based on multi-source heterogeneous data according to claim 4, characterized in that: The step of marking the real-time transaction environment where the tampered record occurs as an environmental tampering risk point for the financial transaction includes: Separating tampering features in the real-time transaction environment and aggregating the separation results into a potential tampering event sequence of the financial transaction; Performing a legitimacy check operation on the potential tampering event based on a preset environmental benchmark library and marking a tampering confirmation node; Marking the confirmed tampering nodes in the potential tampering event based on a preset environmental reference library; The confirmed tampering node is integrated into an environmental tampering risk point.

6. The method for real-time risk identification of financial transactions based on multi-source heterogeneous data according to claim 5, characterized in that: The steps for obtaining the preset environmental benchmark library are: Extracting features of the real-time transaction environment within a historical security period to obtain original environmental parameters of the financial transaction; Constructing an environmental benchmark parameter matrix for the financial transaction based on the legal behavior fluctuation values ​​of the original environmental parameters; Retrospective verification of compliance with the environmental benchmark parameter matrix; The qualified environmental benchmark parameter matrix is ​​input into a preset environmental benchmark library.

7. The method for real-time risk identification of financial transactions based on multi-source heterogeneous data according to claim 6, characterized in that: The method of using the degree of overlap between the environmental tampering risk point and the capital jump path in the dynamic risk map as the spatial conflict level of the financial transaction includes: Constructing a spatiotemporal unit of the environment tampering risk point based on the timestamp and physical coordinate information of the environment tampering risk point; Vectorizing the abnormal fund jump path in the dynamic risk map to obtain the fund spatiotemporal trajectory of the abnormal fund jump path; Detecting the degree of overlap between the space-time unit and the space-time trajectory of funds, and using the degree of overlap as the spatial etching depth of the space-time trajectory of funds; Calculating a spatial-temporal conflict quantization value of the financial transaction by using a time-delayed etching distance of the spatial etching depth; The spatial conflict quantization value is mapped to a preset conflict interval to obtain the spatial conflict level of the financial transaction.

8. The method for real-time risk identification of financial transactions based on multi-source heterogeneous data according to claim 7, characterized in that: The calculation formula of the space-time conflict quantization value is: , in: is the quantized value of the spatiotemporal conflict, The gradient vector of the spatial etching depth, is the tangent vector of the capital jump path, is the environmental risk density within the unit space-time prism, is the temporal diffusion coefficient, is the real-time capital behavior entropy corresponding to the capital flow frequency distribution, is the historical benchmark entropy corresponding to the environmental benchmark library, is the risk entropy change factor.

9. The method for real-time risk identification of financial transactions based on multi-source heterogeneous data according to claim 8, characterized in that: The determining of the risk determination result of the financial transaction based on the spatial conflict level includes: Mapping the spatial conflict level to a preset risk classification interval to obtain a preliminary risk category of the financial transaction; The validity of the preliminary risk category is verified, and the preliminary risk category that passes the verification is output as a risk determination result.

10. A real-time risk identification system for financial transactions based on multi-source heterogeneous data, characterized by: The system comprises: Data acquisition module: used to obtain original heterogeneous data of financial transactions and real-time transaction environment; A graph construction module is used to track abnormal paths of the financial transactions based on the user entity relationships in the original heterogeneous data, thereby establishing a dynamic risk graph of the financial transactions; Risk point acquisition module: used for marking the real-time transaction environment where tampering records occur as the environment tampering risk point of the financial transaction; A level determination module is configured to use the degree of overlap between the environmental tampering risk point and the capital jump path in the dynamic risk map as the spatial conflict level of the financial transaction; A result output module is used to determine the risk determination result of the financial transaction based on the spatial conflict level.

Citation Information

Cited By

  • Cross-border fund flow data analysis method and system based on deep feature fusion

    CN121481736A