Real-time financial regulatory data processing method and system

CN120912330BActive Publication Date: 2026-09-25NANJING FITECH DATA SYST CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510922507.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-07-04
Publication Date
2026-09-25
Estimated Expiration
2045-07-04

AI Technical Summary

Technical Problem

传统的监管数据处理方法大多依赖静态规则、批量分析和账户维度的独立评估,难以全面捕捉账户之间复杂关系演化下的行为协同特征,尤其在面对具有扰动规避性质的交易行为(如随机变动金额、切换交易时点)时,容易出现误判率高、漏判严重的问题

Benefits of technology

[0024]本发明通过金融监管数据构建账户与资产之间的金融交易图谱,并基于账户实体在滑动窗口内的出入度、方向切换频率与交易金额波动率构建行为特征向量,借助可疑节点分析网络对账户活跃性与行为稳定性进行动态标注,提升候选区域的准确性与图分析资源分配效率;随后对候选节点的1跳与2跳邻域构成的子图执行结构特征提取操作,提取候选子图的连接关系特征向量,并引入结构模板库进行相似度匹配,实现对价格操控、洗钱、账户对倒等异常结构的先验识别;最后在结构匹配基础上,将连接关系特征向量嵌入子图交易行为中构造行为分析向量,通过交易异常分析网络完成对交易行为模式的精细分类,有效增强系统对高规避性异常行为的结构感知能力与动态适应能力,避免仅依赖金额、时间等属性规则而引发的误判或漏判问题;构建了一种引入以节点行为特征驱动的候选筛选机制与拓扑结构特征编码方法,实现了对潜在异常交易模式的分阶段识别与分类标注。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120912330B_ABST
    Figure CN120912330B_ABST
Patent Text Reader

Abstract

The present application relates to the technical field of data analysis, and particularly relates to a real-time financial supervision data processing method and system.A real-time financial supervision data processing system comprises a financial transaction graph management module, a subgraph matching module and a transaction anomaly analysis module.The present application constructs a financial transaction graph between accounts and assets through financial supervision data, and introduces a candidate screening mechanism driven by node behavior characteristics and a topological structure feature coding method, so that phased identification and classification labeling of potential abnormal transaction patterns are realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of data analysis technology, specifically to a real-time financial regulatory data processing method and system. Background Technology

[0002] Within the existing financial regulatory system, as financial activities such as securities trading, futures contracts, and bond trading become increasingly complex and automated, abnormal behaviors hidden in the financial market, such as manipulation, money laundering, and account reconciliation, exhibit stronger interconnectedness, concealment, and disruptiveness. Traditional regulatory data processing methods mostly rely on static rules, batch analysis, and independent assessments at the account level, making it difficult to comprehensively capture the behavioral synergy characteristics under the complex evolution of relationships between accounts. This is especially true when facing transaction behaviors with disruptive evasion characteristics (such as random changes in amount or switching of transaction timing), which easily leads to high false positive rates and serious missed detections. Furthermore, existing methods make weak use of the structural information of transaction graphs, making it difficult to discover typical abnormal graph patterns such as closed-loop transaction chains, star-shaped manipulation groups, and chain-like fund transfers through graph structure mining techniques. Summary of the Invention

[0003] This invention constructs a financial transaction graph between accounts and assets using financial regulatory data. It then builds behavioral feature vectors based on the in-degree and out-degree of account entities within a sliding window, the frequency of direction switching, and the volatility of transaction amounts. A suspicious node analysis network is used to dynamically label account activity and behavioral stability, improving the accuracy of candidate regions and the efficiency of graph analysis resource allocation. Subsequently, structural feature extraction is performed on the subgraphs formed by the 1-hop and 2-hop neighbors of candidate nodes. Connection relationship feature vectors are extracted from the candidate subgraphs and introduced into a structural template library for similarity matching, enabling prior identification of abnormal structures such as price manipulation, money laundering, and account swapping. Finally, based on structural matching, the connection relationship feature vectors are embedded into the subgraph transaction behavior to construct behavioral analysis vectors. A transaction anomaly analysis network is used to perform fine-grained classification of transaction behavior patterns, effectively enhancing the system's structural perception and dynamic adaptability to highly abstainable abnormal behaviors, avoiding misjudgments or omissions caused by relying solely on attribute rules such as amount and time. This invention constructs a candidate screening mechanism driven by node behavioral features and a topological structure feature encoding method, achieving phased identification and classification labeling of potential abnormal transaction patterns.

[0004] This invention provides a real-time financial regulatory data processing method, characterized by comprising:

[0005] Continuously acquire financial regulatory data pushed by exchanges or intermediary clearing systems. For each piece of financial regulatory data, perform the following steps: extract account entities and asset entities from the financial regulatory data; match the extracted account entities and asset entities with the account entities and asset entities in the financial transaction graph; and update the financial transaction graph based on the matching results. The financial transaction graph consists of several sets of account entity-edge relationship attribute-asset entity triples. The edge relationship attributes include transaction type, transaction amount, and transaction time.

[0006] Obtain a snapshot of the financial transaction graph within the current monitoring time window; determine candidate subgraphs based on the in-degree, direction switching frequency, and transaction amount volatility of the account entities in the financial transaction graph snapshot; then match the candidate subgraphs with the standard subgraph feature library to determine the standard connection relationship feature vectors corresponding to the candidate subgraphs.

[0007] For each candidate subgraph, perform the following operations: add the standard connection feature vector corresponding to the candidate subgraph to the end of each edge attribute to form a behavior analysis vector, and then send all behavior analysis vectors into the transaction anomaly analysis network for processing to output a transaction anomaly type label.

[0008] As a preferred aspect, candidate subgraphs are determined based on the in-degree, direction switching frequency and transaction amount volatility of account entities in the financial transaction graph snapshot. Then, the candidate subgraphs are matched with the standard subgraph feature library to determine the standard connection relationship feature vector corresponding to the candidate subgraph.

[0009] Traverse all account entities in the financial transaction graph snapshot, extract the corresponding entity feature vector for each account entity. The entity feature vector includes in-degree, direction switching frequency and transaction amount volatility. The extracted entity feature vectors of the account entities are then fed into the suspicious node analysis network for processing, and node analysis labels are output. The node analysis labels include suspicious and not suspicious.

[0010] Account entities with suspicious node analysis labels are recorded as candidate nodes. For each candidate node, the following operations are performed: extract the candidate node and the graph structure corresponding to the 1-hop neighborhood and 2-hop neighborhood of the candidate node from the financial transaction graph snapshot to form a candidate subgraph;

[0011] For each candidate subgraph, the following operation is performed: the candidate subgraph is processed by a graph structure feature extraction network, and the connection relationship feature vector corresponding to the candidate subgraph is output;

[0012] For each candidate subgraph, perform the following operation: match the connection feature vector corresponding to the candidate subgraph with the standard connection feature vector in the standard subgraph feature library one by one. If the similarity between the connection feature vector corresponding to the candidate subgraph and the standard connection feature vector in the standard subgraph feature library is higher than the similarity threshold, it is considered a successful match, and the standard connection feature vector is associated with the corresponding candidate subgraph. Otherwise, continue to match the connection feature vector corresponding to the candidate subgraph with the standard connection feature vector in the standard subgraph feature library.

[0013] As a preferred approach, a standard subgraph feature library is constructed as follows: several training candidate subgraphs labeled with transaction anomaly type tags are constructed, and the training candidate subgraphs are fed into a graph structure feature extraction network for processing, outputting the corresponding connection relationship feature vectors.

[0014] Cluster analysis is performed on all connection feature vectors to construct several clusters. The cluster center of each cluster is regarded as a standard connection feature vector.

[0015] As a preferred aspect, the standard connection feature vectors in the standard subgraph feature library are arranged according to the hit rate of the standard connection feature vectors, and the hit rate of the standard connection feature vectors is the number of times the standard connection feature vectors are successfully matched within the time window.

[0016] As a preferred aspect, training the graph structure feature extraction network includes the following steps: obtaining several candidate training subgraphs labeled with transaction anomaly type tags, and forming a candidate subgraph training set by combining all candidate training subgraphs corresponding to each transaction anomaly type tag. The graph structure feature extraction network is then trained unsupervised using all candidate subgraph training sets, with the training objective being that the output connection relationship feature vectors of all candidate training subgraphs under the same candidate subgraph training set are consistent.

[0017] As a preferred aspect, training the transaction anomaly analysis network specifically includes the following steps: obtaining several transaction anomaly analysis training samples, which include behavioral analysis vectors; labeling the transaction anomaly analysis training samples with transaction anomaly type labels; forming a transaction anomaly analysis training set from all labeled transaction anomaly analysis training samples; and training the transaction anomaly analysis network using the transaction anomaly analysis training set, with the training target being the labeled transaction anomaly type labels.

[0018] This invention also provides a real-time financial regulatory data processing system, comprising:

[0019] The financial transaction graph management module is used to continuously acquire financial regulatory data pushed by exchanges or intermediary clearing systems. For each piece of financial regulatory data, the following steps are performed: extract the account entities and asset entities from the financial regulatory data; match the extracted account entities and asset entities with the account entities and asset entities in the financial transaction graph; and update the financial transaction graph based on the matching results. The financial transaction graph consists of several sets of account entity-edge relationship attribute-asset entity triples. The edge relationship attributes include transaction type, transaction amount, and transaction time.

[0020] The subgraph matching module is used to obtain a snapshot of the financial transaction graph within the time window at the current monitoring time point; it determines candidate subgraphs based on the in-degree, direction switching frequency and transaction amount volatility of account entities in the financial transaction graph snapshot; and then performs subgraph matching with the standard subgraph feature library to determine the standard connection relationship feature vector corresponding to the candidate subgraph.

[0021] The transaction anomaly analysis module performs the following operations for each candidate subgraph: it adds the standard connection feature vector corresponding to the candidate subgraph to the end of each edge attribute to form a behavior analysis vector, and then sends all behavior analysis vectors into the transaction anomaly analysis network for processing to output a transaction anomaly type label.

[0022] A computer-readable storage medium storing a computer program / instructions thereon, characterized in that the computer program / instructions, when executed by a processor, implement the steps of the above-described method.

[0023] The present invention has the following advantages:

[0024] This invention constructs a financial transaction graph between accounts and assets using financial regulatory data. It then builds behavioral feature vectors based on the in-degree and out-degree of account entities within a sliding window, the frequency of direction switching, and the volatility of transaction amounts. A suspicious node analysis network is used to dynamically label account activity and behavioral stability, improving the accuracy of candidate regions and the efficiency of graph analysis resource allocation. Subsequently, structural feature extraction is performed on the subgraphs formed by the 1-hop and 2-hop neighbors of candidate nodes. Connection relationship feature vectors are extracted from the candidate subgraphs and introduced into a structural template library for similarity matching, enabling prior identification of abnormal structures such as price manipulation, money laundering, and account swapping. Finally, based on structural matching, the connection relationship feature vectors are embedded into the subgraph transaction behavior to construct behavioral analysis vectors. A transaction anomaly analysis network is used to perform fine-grained classification of transaction behavior patterns, effectively enhancing the system's structural perception and dynamic adaptability to highly abstainable abnormal behaviors, avoiding misjudgments or omissions caused by relying solely on attribute rules such as amount and time. This invention constructs a candidate screening mechanism driven by node behavioral features and a topological structure feature encoding method, achieving phased identification and classification labeling of potential abnormal transaction patterns. Attached Figure Description

[0025] Figure 1 This is a schematic diagram of the structure of the real-time financial regulatory data processing system used in an embodiment of the present invention. Detailed Implementation

[0026] To enable those skilled in the art to better understand the technical solutions of this invention, the technical solutions of this invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of this invention.

[0027] Example 1: A real-time financial regulatory data processing method, comprising:

[0028] We continuously acquire financial regulatory data pushed by exchanges or intermediary clearing systems. This financial regulatory data is a real-time data stream, such as "transaction ID, account ID_buyer, account ID_seller, asset code, transaction time," etc. It reflects the transaction information generated in the financial trading market. The account represents the trading entity, which can be an individual, institution, or company. The asset represents financial products, such as stocks, bonds, and futures. The account is the initiator or recipient of all transactions. Here, a transaction refers to the buying and selling behavior of two trading entities on a certain financial product.

[0029] For each piece of financial regulatory data, the following steps are performed: First, extract the account entities and asset entities from the financial regulatory data. Here, account entities refer to the IDs corresponding to the seller and buyer, and asset entities refer to the asset codes. Then, match the extracted account entities and asset entities with those in the financial transaction graph. Update the financial transaction graph based on the matching results. The financial transaction graph consists of several sets of account entity-edge relationship attribute-asset entity triples. Edge relationship attributes include transaction type (buy and sell), transaction amount, and transaction time. The update here refers to dynamically modifying the account entities and asset entities in the financial transaction graph based on the financial regulatory data, or adding account entity-edge relationship attribute-asset entity triples to reflect the financial interaction behavior corresponding to the financial regulatory data, thereby enabling rapid detection of abnormal transaction behaviors (such as market manipulation and money laundering).

[0030] It should be noted that the account entity-edge relationship attribute-asset entity triple here describes the actual operation (buying and selling) of an account on an asset. For example, if account acct_001 buys asset 600519, this can be represented as a triple (acct_001-edge attribute-600519), where account acct_001 is the initiator of the transaction, asset 600519 is the object of the transaction, and edge attributes (such as purchase, amount, timestamp) describe the specific behavior and characteristics of the transaction and construct a directed edge from account acct_001 to asset 600519. This triple form can clearly capture the transaction relationship between the account and the asset, which is convenient for subsequent transaction anomaly detection and subgraph matching.

[0031] To obtain a snapshot of the financial transaction graph within the time window at the current monitoring time point, specifically, iterate through the transaction time in the edge attributes of all account entity-edge relationship attribute-asset entity triples in the financial transaction graph, and form a snapshot of the financial transaction graph by combining all account entity-edge relationship attribute-asset entity triples corresponding to the transaction time within the time window; it should be noted that the time interval between the current monitoring time point and the previous monitoring time point is the time window, and the length of the time window is generally 30 seconds;

[0032] Traverse all account entities in the financial transaction graph snapshot, and extract the corresponding entity feature vector for each account entity. The entity feature vector includes in-degree, direction switching frequency, and transaction amount volatility. The in-degree is the total number of directed edges connected to the account entity. The direction switching frequency is obtained by sorting all directed edges connected to the account entity according to the transaction time in the edge attribute. The ratio of the total number of buy-sell or sell-buy switches to the total number of directed edges connected to the account entity is the direction switching frequency. The transaction amount volatility is the standard deviation of the transaction amount corresponding to all directed edges. The entity feature vectors extracted for each account entity are then fed into the suspicious node analysis network for processing. The node analysis labels are output, including suspicious and not suspicious. If the node analysis label of the account entity is suspicious, it indicates that the corresponding account entity is actively trading or behaving abnormally, and should be given special attention.

[0033] Account entities with suspicious node analysis labels are designated as candidate nodes. For each candidate node, the following operations are performed: Extract the candidate node and the graph structures corresponding to its 1-hop and 2-hop neighbors from the financial transaction graph snapshot to form a candidate subgraph. It should be noted that a node (account entity or asset entity) connected to a candidate node by only one directed edge is a 1-hop neighbor of the candidate node, and a node connected to a candidate node by only two directed edges is a 2-hop neighbor of the candidate node. The candidate subgraph includes the candidate node, the nodes corresponding to its 1-hop neighbors and 2-hop neighbors, and all directed edges.

[0034] For each candidate subgraph, the following operations are performed: The candidate subgraph is processed through a graph structure feature extraction network, and the connection feature vector corresponding to the candidate subgraph is output. The connection feature vector describes the topological shape of the candidate subgraph. The features corresponding to these topological shapes can reflect transaction anomalies to a certain extent. For example, multiple accounts buy / sell the same asset to each other in a short period of time, with similar transaction amounts and intersecting transaction directions. The purpose is to create false trading volume and manipulate prices. The corresponding subgraph connection features are that the graph structure is a closed loop, and the nodes are multiple accounts and one or more assets and accounts forming a directed closed path through asset nodes, etc. Therefore, by matching the connection relationships of the subgraph, transaction anomalies can be detected.

[0035] For each candidate subgraph, the following operations are performed: The connection feature vector corresponding to the candidate subgraph is matched one by one with the standard connection feature vector in the standard subgraph feature library. If the similarity between the connection feature vector corresponding to the candidate subgraph and the standard connection feature vector in the standard subgraph feature library is higher than the similarity threshold, it is considered a successful match, and the standard connection feature vector is associated with the corresponding candidate subgraph. Otherwise, the matching process continues between the connection feature vector corresponding to the candidate subgraph and the standard connection feature vector in the standard subgraph feature library. Subgraph matching allows for prior analysis of nodes where transaction anomalies occur based on connection relationships. Furthermore, since behavioral attributes (amount, direction) are often perturbative, some money laundering activities deliberately alter the amount, transaction time, etc., to circumvent rules. Subgraph connection matching enhances the anti-circumvention capability of transaction anomaly detection. The similarity calculation uses a cosine similarity algorithm, and the similarity threshold is set in advance by the operator.

[0036] For each candidate subgraph, the following operations are performed: the standard connection feature vector corresponding to the candidate subgraph is added to the end of each edge attribute to form a behavior analysis vector. Then, all behavior analysis vectors are sent to the transaction anomaly analysis network for processing and output transaction anomaly type labels to realize the processing of financial regulatory data and the analysis of transaction anomalies. Transaction anomaly type labels include price manipulation, money laundering and account swapping, etc.

[0037] This application constructs a financial transaction graph between accounts and assets using financial regulatory data. It then builds behavioral feature vectors based on the in-degree and out-degree of account entities within a sliding window, the frequency of direction switching, and the volatility of transaction amounts. A suspicious node analysis network is used to dynamically label account activity and behavioral stability, improving the accuracy of candidate regions and the efficiency of graph analysis resource allocation. Subsequently, structural feature extraction is performed on the subgraphs formed by the 1-hop and 2-hop neighbors of candidate nodes. Connection relationship feature vectors are extracted from the candidate subgraphs and introduced into a structural template library for similarity matching, enabling prior identification of abnormal structures such as price manipulation, money laundering, and account swapping. Finally, based on structural matching, the connection relationship feature vectors are embedded into the subgraph transaction behavior to construct behavioral analysis vectors. A transaction anomaly analysis network is used to perform fine-grained classification of transaction behavior patterns, effectively enhancing the system's structural perception and dynamic adaptability to highly abstainable abnormal behaviors, avoiding misjudgments or omissions caused by relying solely on attribute rules such as amount and time. A candidate screening mechanism driven by node behavioral features and a topological structure feature encoding method are constructed, enabling phased identification and classification labeling of potential abnormal transaction patterns.

[0038] The standard subgraph feature library is constructed using the following method:

[0039] Several training candidate subgraphs labeled with transaction anomaly types are constructed. It should be noted that the training candidate subgraphs here refer to those constructed based on the account entities that the operators have determined have experienced transaction anomalies. The training candidate subgraphs are then fed into a graph structure feature extraction network for processing, and the corresponding connection relationship feature vectors are output.

[0040] All connection feature vectors are clustered to construct several clusters. The K-means algorithm is selected for clustering, and the cluster center of each cluster is regarded as a standard connection feature vector.

[0041] To improve the matching speed with the standard connection feature vectors in the standard subgraph feature library, the standard connection feature vectors in the standard subgraph feature library are arranged according to the hit rate of the standard connection feature vectors. The hit rate of the standard connection feature vectors is the number of times the standard connection feature vectors are successfully matched within the time window.

[0042] Training a graph structure feature extraction network involves the following steps:

[0043] Obtain several candidate training subgraphs labeled with transaction anomaly types, and form a candidate subgraph training set by combining all candidate training subgraphs corresponding to each transaction anomaly type label. Perform unsupervised training on the graph structure feature extraction network using all candidate subgraph training sets. The training objective is to ensure that the output connection feature vectors of all candidate training subgraphs under the same candidate subgraph training set are consistent. Determine whether the training conditions are met. The training condition is generally to reach the preset maximum number of training iterations. If the training conditions are met, output the trained graph structure feature extraction network; otherwise, continue unsupervised training on the graph structure feature extraction network using all candidate subgraph training sets.

[0044] Training the transaction anomaly analysis network involves the following steps:

[0045] Several training samples for transaction anomaly analysis are obtained. These training samples include behavioral analysis vectors, which are constructed based on the transaction regulatory map of actual financial transactions. The training samples are labeled with transaction anomaly type tags, which are determined by operators based on expert experience. These transaction anomaly type tags are in the form of word embeddings. All labeled training samples are combined into a transaction anomaly analysis training set. The transaction anomaly analysis network is trained using this training set, with the training objective being the labeled transaction anomaly type tags. The training conditions are then checked to determine if they are met. Generally, the accuracy of the transaction anomaly analysis network meets expectations. If the training conditions are met, the trained transaction anomaly analysis network is output; otherwise, the network is trained again using the training set.

[0046] Example 2: A real-time financial regulatory data processing system, see [link / reference] Figure 1 ,include:

[0047] The financial transaction graph management module continuously acquires financial regulatory data pushed by exchanges or intermediary clearing systems. This financial regulatory data is a real-time data stream, such as "Transaction ID, Account ID_Buyer, Account ID_Seller, Asset Code, Transaction Time," reflecting transaction information generated in the financial trading market. The account represents the trading entity, which can be an individual, institution, or company; the asset represents financial products such as stocks, bonds, and futures. The account is the initiator or recipient of all transactions. A transaction here refers to the buying and selling of a specific financial product between two trading entities. For each piece of financial regulatory data, the following steps are performed to extract the account entity and asset entity from the financial regulatory data. Here, the account entity refers to the seller and buyer... The corresponding ID and asset entity refer to the asset code. The account entities and asset entities extracted from financial regulatory data are matched with the account entities and asset entities in the financial transaction graph, and the financial transaction graph is updated based on the matching results. The financial transaction graph consists of several sets of account entity-edge relationship attribute-asset entity triples. The edge relationship attributes include transaction type (buy and sell), transaction amount and transaction time, etc. The update here refers to dynamically modifying the account entities and asset entities in the financial transaction graph according to the financial regulatory data, or adding account entity-edge relationship attribute-asset entity triples to reflect the financial interaction behavior corresponding to the financial regulatory data, so as to realize the rapid detection of abnormal transaction behavior (such as market manipulation and money laundering).

[0048] The subgraph matching module is used to obtain a snapshot of the financial transaction graph within a time window at the current monitoring time point. Specifically, it iterates through the transaction time in the edge attributes of all account entity-edge relationship attribute-asset entity triples in the financial transaction graph, and forms a snapshot of the financial transaction graph by combining all account entity-edge relationship attribute-asset entity triples corresponding to the transaction time within the time window. It should be noted that the time interval between the current monitoring time point and the previous monitoring time point is the time window, and the length of the time window is generally 30 seconds. It iterates through all account entities in the snapshot of the financial transaction graph and extracts the corresponding entity feature vector for each account entity. The entity feature vector includes in-degree, out-degree, and direction switching. Frequency and volatility of transaction amount are calculated, where in-degree is the total number of directed edges connected to the account entity. Direction switching frequency is obtained by sorting all directed edges connected to the account entity according to the transaction time attribute. The ratio of the total number of buy-sell or sell-buy switching events to the total number of directed edges connected to the account entity is the direction switching frequency. Transaction amount volatility is the standard deviation of the transaction amount corresponding to all directed edges. The corresponding entity feature vectors of the account entities are extracted and fed into a suspicious node analysis network for processing, outputting node analysis labels. Node analysis labels include suspicious and not suspicious. If the node analysis label corresponding to the account entity is suspicious, it indicates that the corresponding… Accounts with active trading or abnormal behavior should be closely monitored. Accounts with suspicious node analysis tags are designated as candidate nodes. For each candidate node, the following steps are performed: Extract the candidate node and its 1-hop and 2-hop neighbors from the financial transaction graph snapshot to form a candidate subgraph. Note that a node connected to a candidate node by only one directed edge (account entity or asset entity) is its 1-hop neighbor, and a node connected to a candidate node by only two directed edges is its 2-hop neighbor. The candidate subgraph includes the candidate node, the nodes corresponding to its 1-hop and 2-hop neighbors, and all directed edges. For each candidate subgraph... The following operations are performed: Candidate subgraphs are processed through a graph structure feature extraction network, and the connection feature vectors corresponding to the candidate subgraphs are output. The connection feature vectors describe the topological shape of the candidate subgraphs. The features corresponding to these topological shapes can reflect transaction anomalies to a certain extent. For example, multiple accounts buy / sell the same asset to each other in a short period of time, with similar transaction amounts and intersecting transaction directions. The purpose is to create false trading volume and manipulate prices. The corresponding subgraph connection features are that the graph structure is closed loop, and the nodes are multiple accounts and one or more assets and accounts forming directed closed paths through asset nodes, etc. Therefore, by matching the connection relationships of the subgraphs, transaction anomalies can be detected.For each candidate subgraph, the following operations are performed: The connection feature vector corresponding to the candidate subgraph is matched one by one with the standard connection feature vector in the standard subgraph feature library. If the similarity between the connection feature vector corresponding to the candidate subgraph and the standard connection feature vector in the standard subgraph feature library is higher than the similarity threshold, it is considered a successful match, and the standard connection feature vector is associated with the corresponding candidate subgraph. Otherwise, the matching process continues between the connection feature vector corresponding to the candidate subgraph and the standard connection feature vector in the standard subgraph feature library. Subgraph matching allows for prior analysis of nodes where transaction anomalies occur based on connection relationships. Furthermore, since behavioral attributes (amount, direction) are often perturbative, some money laundering activities deliberately alter the amount, transaction time, etc., to circumvent rules. Subgraph connection matching enhances the anti-circumvention capability of transaction anomaly detection. The similarity calculation uses a cosine similarity algorithm, and the similarity threshold is set in advance by the operator.

[0049] The transaction anomaly analysis module performs the following operations for each candidate subgraph: it adds the standard connection feature vector corresponding to the candidate subgraph to the end of each edge attribute to form a behavior analysis vector, and then sends all behavior analysis vectors into the transaction anomaly analysis network for processing, outputting transaction anomaly type labels to realize the processing of financial regulatory data and the analysis of transaction anomalies. Transaction anomaly type labels include price manipulation, money laundering, and account swapping.

[0050] A computer-readable storage medium storing a computer program / instructions thereon, characterized in that the computer program / instructions, when executed by a processor, implement the steps of the above-described method.

[0051] It should be understood that those skilled in the art can make improvements or modifications based on the above description, and all such improvements and modifications should fall within the protection scope of the appended claims. Parts not described in detail in this specification are prior art known to those skilled in the art.

Claims

1. A real-time financial regulatory data processing method, characterized in that, include: Continuously acquire financial regulatory data pushed by exchanges or intermediary clearing systems. For each piece of financial regulatory data, perform the following steps: extract account entities and asset entities from the financial regulatory data; match the extracted account entities and asset entities with the account entities and asset entities in the financial transaction graph; and update the financial transaction graph based on the matching results. The financial transaction graph consists of several sets of account entity-edge relationship attribute-asset entity triples. The edge relationship attributes include transaction type, transaction amount, and transaction time. A snapshot of the financial transaction graph within the current monitoring time window is obtained. Candidate subgraphs are determined based on the in-degree, direction switching frequency, and transaction amount volatility of the account entities in the financial transaction graph snapshot. The direction switching frequency is obtained as follows: all directed edges connected to the account entity are sorted according to the transaction time in the edge attribute. The ratio of the total number of buy-sell switching and the total number of sell-buy switching to the total number of all directed edges connected to the account entity is the direction switching frequency. Then, the candidate subgraphs are matched with the standard subgraph feature library to determine the standard connection relationship feature vector corresponding to the candidate subgraph. For each candidate subgraph, perform the following operations: add the standard connection feature vector corresponding to the candidate subgraph to the end of each edge attribute to form a behavior analysis vector, and then send all behavior analysis vectors into the transaction anomaly analysis network for processing to output a transaction anomaly type label. Candidate subgraphs are determined based on the in-degree, direction switching frequency, and transaction amount volatility of account entities in the financial transaction graph snapshot. Then, the candidate subgraphs are matched with the standard subgraph feature library to determine the standard connection relationship feature vectors corresponding to the candidate subgraphs. Traverse all account entities in the financial transaction graph snapshot, extract the corresponding entity feature vector for each account entity. The entity feature vector includes in-degree, direction switching frequency and transaction amount volatility. The extracted entity feature vectors of the account entities are then fed into the suspicious node analysis network for processing, and node analysis labels are output. The node analysis labels include suspicious and not suspicious. Account entities with suspicious node analysis labels are recorded as candidate nodes. For each candidate node, the following operations are performed: extract the candidate node and the graph structure corresponding to the 1-hop neighborhood and 2-hop neighborhood of the candidate node from the financial transaction graph snapshot to form a candidate subgraph; For each candidate subgraph, the following operation is performed: the candidate subgraph is processed by a graph structure feature extraction network, and the connection relationship feature vector corresponding to the candidate subgraph is output; For each candidate subgraph, perform the following operations: match the connection feature vector corresponding to the candidate subgraph with the standard connection feature vector in the standard subgraph feature library one by one. If the similarity between the connection feature vector corresponding to the candidate subgraph and the standard connection feature vector in the standard subgraph feature library is higher than the similarity threshold, it is considered a successful match, and the standard connection feature vector is associated with the corresponding candidate subgraph. Otherwise, continue to match the connection feature vector corresponding to the candidate subgraph with the standard connection feature vector in the standard subgraph feature library. The standard subgraph feature library is constructed as follows: several training candidate subgraphs labeled with transaction anomaly type are constructed, and the training candidate subgraphs are fed into the graph structure feature extraction network for processing, and the corresponding connection relationship feature vectors are output. All connection feature vectors are clustered to construct several clusters, and the cluster center of each cluster is regarded as a standard connection feature vector. The standard connection feature vectors in the standard subgraph feature library are arranged according to the hit rate of the standard connection feature vectors. The hit rate of the standard connection feature vectors is the number of times the standard connection feature vectors are successfully matched within the time window.

2. The real-time financial regulatory data processing method according to claim 1, characterized in that, Training the graph structure feature extraction network involves the following steps: obtaining several candidate subgraphs labeled with transaction anomaly types, and forming a candidate subgraph training set by combining all candidate subgraphs corresponding to each transaction anomaly type label. The graph structure feature extraction network is then trained unsupervised using all candidate subgraph training sets, with the training objective being that the output connection feature vectors of all candidate subgraphs in the same candidate subgraph training set are consistent.

3. The real-time financial regulatory data processing method according to claim 2, characterized in that, Training the transaction anomaly analysis network involves the following steps: obtaining several transaction anomaly analysis training samples, which include behavioral analysis vectors; labeling the transaction anomaly analysis training samples with transaction anomaly type labels; forming a transaction anomaly analysis training set from all labeled transaction anomaly analysis training samples; and training the transaction anomaly analysis network using the transaction anomaly analysis training set, with the training target being the labeled transaction anomaly type labels.

4. A real-time financial regulatory data processing system, characterized in that, The system employs a real-time financial regulatory data processing method according to any one of claims 1-3, comprising: The financial transaction graph management module is used to continuously acquire financial regulatory data pushed by exchanges or intermediary clearing systems. For each piece of financial regulatory data, the following steps are performed: extract the account entities and asset entities from the financial regulatory data; match the extracted account entities and asset entities with the account entities and asset entities in the financial transaction graph; and update the financial transaction graph based on the matching results. The financial transaction graph consists of several sets of account entity-edge relationship attribute-asset entity triples. The edge relationship attributes include transaction type, transaction amount, and transaction time. The subgraph matching module is used to obtain a snapshot of the financial transaction graph within the time window at the current monitoring time point; it determines candidate subgraphs based on the in-degree, direction switching frequency and transaction amount volatility of account entities in the financial transaction graph snapshot; and then performs subgraph matching with the standard subgraph feature library to determine the standard connection relationship feature vector corresponding to the candidate subgraph. The transaction anomaly analysis module performs the following operations for each candidate subgraph: it adds the standard connection feature vector corresponding to the candidate subgraph to the end of each edge attribute to form a behavior analysis vector, and then sends all behavior analysis vectors into the transaction anomaly analysis network for processing to output a transaction anomaly type label.

Citation Information

Patent Citations

  • Anti-money laundering identification method and device

    CN111476662A

  • Method, device and apparatus for detecting transaction exception group

    CN111538869A

  • Neutral geometric model assembly feature semantic construction method based on knowledge graph

    CN116541906A

  • Transaction chain abnormal node identification method based on knowledge graph enhancement

    CN120234582A