Financial fraud analysis method based on graph neural network

By combining the multi-head self-attention mechanism of spectral domain graph convolution and spatial domain graph convolution modules, the problems of long-distance dependencies and fraudster spoofing behavior in graph neural networks are solved, achieving more efficient financial fraud detection.

CN120975783APending Publication Date: 2025-11-18UNIV OF ELECTRONICS SCI & TECH OF CHINA
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510828981.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-20
Publication Date
2025-11-18

AI Technical Summary

Technical Problem

In graph neural networks, feature extraction between nodes struggles to capture long-distance dependencies, and the exploitation of fraudster spoofing and multiple node relationships presents challenges, affecting the accuracy of financial fraud detection.

Method used

By combining spectral domain graph convolutional modules and spatial domain graph convolutional modules with a multi-head self-attention mechanism, and through wavelet transform and neighbor-level attention mechanism, a financial fraud analysis model based on graph neural network is constructed to capture long-distance dependencies and identify fraudsters' spoofing behavior.

Benefits of technology

It improves the accuracy and efficiency of financial fraud detection, effectively identifies multiple node relationships and fraudster spoofing behaviors, and enhances the model's flexibility and detection capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120975783A_ABST
    Figure CN120975783A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of artificial intelligence, in particular to a financial fraud analysis method based on a graph neural network, and the method comprises the following steps: S1, obtaining relation graph data; s2, constructing a financial fraud analysis and prediction model based on the graph neural network; the financial fraud analysis and prediction model comprises a spectral domain graph convolution module, a spatial domain graph convolution module, a network-level feature extraction module and a relation-level feature extraction module; and S3, inputting the relational graph data into the financial fraud analysis and prediction model to obtain the prediction probability of the financial fraud label of each node in the relational graph data. The method solves the problems that traditional spectral domain graph convolution cannot pay attention to the relation between node neighborhoods, the time complexity is high in calculation, and the extraction capacity of local node neighborhood features is limited. The problem that a fraudulent may have a disguise behavior is solved, and the problem that a single relationship cannot completely represent a mutual relationship in a financial system is solved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of artificial intelligence, and particularly relates to a financial fraud analysis method based on a graph neural network. BACKGROUND

[0002] Financial fraud detection has important research significance for the safety of the financial system and the property safety of users, and many researchers have conducted various researches in the field of financial fraud detection over the years. In general, the task of financial fraud detection can be regarded as a binary classification problem. After the relevant transaction data, user data or text information used by the user are given, it is determined through analysis whether the transaction, user or text belongs to the fraud class or the normal class, so as to facilitate the financial system to process the transaction, user or text in the next step, for example, to manually revisit the transaction with fraudulent behavior to ensure that the user's property is not deceived by illegal fraudsters. Recently, with the rapid development of deep learning and neural networks, more and more researchers have applied neural networks to financial fraud detection. In the method based on neural networks, the graph neural network is an important research direction because many data in the financial system can be represented as a graph structure, such as the transaction relationship between accounts, the social relationship between users, etc. The use of graph neural networks can better capture the features in the financial system and help the neural network to better predict and classify. There are the following problems in the current financial fraud detection based on graph neural networks:

[0003] (1) Feature extraction method between nodes: In the graph neural network, the feature extraction between nodes is realized through the message passing mechanism. The commonly used message passing mechanism in the graph neural network is graph convolution. According to the different ways of graph convolution, there are two main graph convolutional neural networks. One is the spectral domain-based graph convolutional neural network, and the other is the spatial domain-based graph convolutional neural network. The spatial domain-based graph convolutional network is difficult to capture the long-distance dependence relationship in the graph, and the spectral domain-based graph convolutional network is difficult to extract the feature information between the domains of the nodes. How to extract the long-distance dependence relationship in the graph while focusing on the information between the domains of the nodes is a challenge faced by the graph neural network.

[0004] (2) Discrimination of fraudsters' disguising behavior: The task of financial fraud detection based on the graph neural network is different from the general classification task based on the graph neural network. In addition to the sample imbalance, the fraudsters will also have disguising behavior, that is, some fraudsters will imitate the behavior of non-fraudsters to escape the detection of the system, establish some seemingly normal relationships to interfere with the detection results of the fraud detection system, and thus interfere with the results of the fraud detection of the graph neural network. If the model regards these disguised relationships as normal relationships, the model will perform poorly in some special scenarios.

[0005] (3) Utilization of multiple node relationships: In financial fraud detection, there are usually more than one kind of relationship between nodes, so more than one kind of relationship graph is constructed. If the model cannot input data of multiple graph structures at the same time, it is difficult to capture the node features under different relationships at the same time, thereby limiting the effect of fraud detection on the nodes. SUMMARY

[0006] The purpose of the present application is to provide a financial fraud analysis method based on a graph neural network, which solves the above technical problems.

[0007] In order to achieve the above purpose, a financial fraud analysis method based on a graph neural network is provided, comprising the following steps:

[0008] S1, obtaining relationship graph data;

[0009] S2, constructing a financial fraud analysis prediction model based on a graph neural network; the financial fraud analysis prediction model comprises:

[0010] A spectral domain graph convolution module is used to map the node signals in the relationship graph to the spectral domain through wavelet transform and convolution kernel, aggregate the node signals in the spectral domain, and then map the aggregated node signals in the spectral domain to the spatial domain through inverse wavelet transform to obtain an output matrix of each node signal after spectral domain graph convolution;

[0011] A spatial domain graph convolution module is used to extract features by defining a graph convolution module in the spatial domain. The graph convolution module uses a multi-head self-attention mechanism to perform convolution operations on the nodes in the neighborhood of each node in the relationship graph. After obtaining the output of each attention head, the outputs of all attention heads are spliced, and then linear transformation and an activation function are used to obtain an output matrix of the spatial domain graph convolution module;

[0012] A network-level feature extraction module is used to respectively weight and fuse the output matrix of the spectral domain graph convolution module and the output matrix of the spatial domain graph convolution module through mutual attention mechanisms, splice the original features of each node in the relationship graph, and obtain the final fused node feature data through a multi-layer perception machine as an output matrix and output;

[0013] A relationship-level feature extraction module is used to obtain a plurality of output matrices of the relationship graph through the network-level feature extraction module, which are used as feature data for relationship extraction. Each kind of feature data extracted from the relationship is regarded as a channel, and a channel attention mechanism is used to extract features from the feature information of different channels. Then, the channel attention mechanism is used for pooling processing, dimension reduction and dimension increase processing, and feature fusion processing, respectively. Finally, a linear layer and an activation function are used to obtain the final node label prediction result;

[0014] S3, inputting the relational graph data into the financial fraud analysis prediction model to obtain a prediction probability of a financial fraud label of each node in the relational graph data.

[0015] Further, the formula for performing spectral domain graph convolution calculation on the nodes of the relational graph in the spectral domain graph convolution module is as follows:

[0016]

[0017] where C is a convolution kernel vector, G represents a spectral domain graph convolution operation, X is a node signal matrix with a dimension of nxf, where n is the number of nodes in the graph, and f is the signal feature dimension of each node, C is a convolution kernel signal matrix obtained by copying n times of the convolution kernel vector c, with a dimension of nxf, X and C are representations on the spatial domain, ψ s is a wavelet transform matrix, is an inverse wavelet transform matrix with a dimension of n*n, represents Hadamard product, Y is an output matrix of the node signal vector after spectral domain convolution, with a dimension of nxf.

[0018] Further, in the process of calculation and analysis by the multi-head attention mechanism in the spatial domain graph convolution module, for each attention head h, the attention query matrix Q (h) , the key-value pair matrix K (h) , and the V (h) matrix need to be calculated first, and each row of the three matrices represents the query, key, and value vectors of a node; in self-attention, the matrices are obtained by calculation from the feature matrix of the node and three different weight matrices, and the calculation formula is as follows:

[0019]

[0020] where X is the feature matrix of the node, is the query weight matrix of the model, which is used to convert the node feature vector into a query vector through linear transformation, and similarly, and are the key weight matrix and the value weight matrix, which are used to produce the key vector and the value vector of the node;

[0021] The spatial domain graph convolution module calculates each attention head, calculates the attention score of the query vector and the key-value pair vector, and then performs weighted summation on the value vector to obtain the output matrix of the spatial domain graph convolution module.

[0022] Further, in the spatial domain graph convolution module, the calculation steps of one attention head of the multi-head self-attention mechanism for aggregating neighbor features and outputting node features include:

[0023] S201, for each node of the relation graph, calculate the dot product of the query and all neighbor nodes to obtain a similarity score, the calculation formula is as follows:

[0024]

[0025] Wherein, S ij represents the attention weight of node i relative to neighbor j, d i represents the degree of node i, that is, the number of neighbors of node i;

[0026] S202, calculate the attention score of all neighbor nodes of a node by Softmax function, the calculation formula is as follows:

[0027]

[0028] Wherein, P ij represents the attention weight of node i relative to neighbor j, Softmax i represents the Softmax operation on all neighbors of node i, exp represents the exponential calculation with e as the base;

[0029] S203, weight and sum the value vectors of each neighbor node by the attention weight to obtain the output feature representation vector of a node, the calculation formula is as follows:

[0030]

[0031] Wherein, represents the output vector corresponding to node i in the output matrix of attention head h;

[0032] S204, after obtaining the output of each attention head, the outputs of all attention heads are spliced, and then linear transformation and activation function are performed to obtain the output matrix of the spatial domain graph convolution layer.

[0033] Further, the calculation formula of the output matrix of the spatial domain graph convolution layer is as follows:

[0034] Y=h(Concat(Y (1) ,Y (2) ,…,Y (h) )W)

[0035] Wherein, Y is the output of the spatial domain graph convolution module, j is a nonlinear activation function, Concat represents the splicing operation of matrix, W is a linear transformation matrix learned by the model, which is used to scale the multi-head attention output result after splicing to a suitable feature dimension.

[0036] 6. The financial fraud analysis method based on a graph neural network according to claim 5, wherein the network-level feature extraction module performs the network-level attention-based feature extraction step as follows:

[0037] S211, calculating the output matrix X of the spectral domain graph convolution module (e) and the output matrix X of the spatial domain graph convolution module (a) with attention weight matrix, the calculation formula is as follows:

[0038]

[0039] wherein, W S is a learnable parameter matrix, S is the attention weight matrix, the dimension of X (e) is the same as the dimension of X (a) , the Softmax operation is applied to each column to normalize the attention weight;

[0040] S212, using the attention weight matrix to respectively weight and fuse the output matrix X (e) and the output matrix X (a) feature, the calculation formula is as follows:

[0041] X (e)′ = X (e) S

[0042] X (a)′ = X (a) S T

[0043] wherein, X (e)′ is the output matrix of the spectral domain graph convolution network after attention fusion, which contains the output matrix X (a) of the spatial domain graph convolution network, and X (a)′ is the output matrix of the spatial domain graph convolution network after attention fusion, which contains the output matrix X (e) of the spectral domain graph convolution network;

[0044] S213, through the splicing operation and linear transformation scaling to the set dimension;

[0045] S214, using the residual connection method to weight and calculate the original feature of the node and the output matrix of the spectral domain graph convolution network and the output matrix of the spatial domain graph convolution network;

[0046] S215, finally output the final node feature data through the multilayer perception.

[0047] Further, the calculation formula of the node feature data is as follows:

[0048] Y = MLP(Concat(X (e)′ ,X (a)′ )W1+XW2)

[0049] wherein W1 is a parameter matrix for linear transformation of the concatenated mutual attention output result, W2 is a parameter matrix for linear transformation of the original feature matrix, MLP represents a multi-layer perceptron, and Y is a result of fusion of the outputs of the two networks by mutual attention.

[0050] Further, the step of extracting the relationship features in the relationship graphs and analyzing the node label prediction result in the relationship level feature extraction module comprises:

[0051] S221, first, the embedding features of each channel are compressed using the average pooling operation, which is expressed by the formula

[0052]

[0053] wherein X (c) is the output node feature embedding matrix of the channel c, i.e. the output matrix of the network level feature extraction module; p is the dimension of the node feature, and Z is the node feature representation after the average pooling, which compresses the features of each node into a scalar, and the feature representations of all nodes are expressed as a vector, and then the vectors of all channels are combined into a matrix, each row representing a channel and each column representing a node.

[0054] S222, dimension reduction and dimension increase operations between the channels are performed through two fully connected layers, which are expressed by the formula

[0055] H = W2h(W1Z)

[0056] wherein W1 is a learnable fully connected layer parameter matrix for dimension reduction of the feature representations of multiple channels, h is a nonlinear activation function, W2 is a learnable fully connected layer parameter matrix for dimension increase operation of the dimension-reduced feature representations, and H represents the feature representations of each channel of the nodes after the channel attention.

[0057] S223, the feature representations of each channel are converted into weight representations between 0 and 1 through the Sigmoid function, which is expressed by the formula

[0058] S c = Sigmoid(H c )

[0059] wherein S represents the attention weight of each channel.

[0060] S224, update the original feature representation of each channel through the channel attention weight, and finally sum the updated node feature embedding matrix of each channel to obtain the multi-channel fused node feature representation, which is expressed as:

[0061]

[0062] wherein is the node feature representation matrix updated by multi-channel weighted summation, and q is the number of channels, i.e. the number of relationship graphs;

[0063] S225, obtain the final node label prediction result through a linear layer and a Sigmoid function.

[0064] Further, the calculation formula of the node label prediction result is:

[0065]

[0066] wherein W and b are the weight matrix and bias vector of the final output linear layer, and y is the label prediction probability of each node output by the model.

[0067] Principle and advantages:

[0068] 1. The scheme introduces a multi-relationship graph neural network mode and a relationship-level feature extraction module, so that the model can receive more than one graph structure relationship, construct a comprehensive feature representation of the node from multiple relationship graphs, and make more accurate predictions. Solve the problem that a single relationship cannot fully represent the mutual relationship in the financial system.

[0069] 2. The scheme introduces network-level attention, which enables the model to capture feature information in the graph from both spatial and spectral domains, while discovering potential patterns. Solve the problem that spectral domain graph convolution cannot focus on the relationship between node neighbors.

[0070] 3. The scheme optimizes the traditional financial fraud detection model through the sparsity and flexibility of wavelet transform, increases the attention to local features, and improves the efficiency and accuracy of detection. Solve the problem that traditional spectral domain graph convolution has high time complexity in calculation and limited ability to extract local node neighborhood features.

[0071] 4. The scheme introduces a neighbor-level attention mechanism in the spatial domain graph convolution module, enabling the model to explore the credibility of neighbor relationships when performing graph convolution, selectively aggregating the features of neighbor nodes, and having higher flexibility. Effectively solve the problem that fraudsters may have disguised behavior. BRIEF DESCRIPTION OF DRAWINGS

[0072] Figure 1This is a flowchart illustrating a financial fraud analysis method based on graph neural networks according to an embodiment of the present invention.

[0073] Figure 2 A schematic diagram of the functional structure of a financial fraud analysis and prediction model;

[0074] Figure 3 This is a functional structure diagram of the overall structure of the spectral domain graph convolution module.

[0075] Figure 4 This is a schematic diagram of the functional structure of each attention head in the spatial domain graph convolution module;

[0076] Figure 5 A functional structure diagram of the overall structure of the network-level feature extraction module;

[0077] Figure 6 This is a functional structure diagram of the overall structure of the relation-level feature extraction module. Detailed Implementation

[0078] The following detailed description illustrates the specific implementation method:

[0079] Example

[0080] A financial fraud analysis method based on graph neural networks, basically as follows: Figure 1 As shown, it includes the following steps:

[0081] S1. Obtain relationship diagram data;

[0082] S2. Construct a financial fraud analysis and prediction model based on graph neural networks; such as... Figure 2 As shown, the financial fraud analysis and prediction model includes:

[0083] like Figure 3 As shown, the spectral domain graph convolution module is used to map the convolution kernel and node signals in the relationship graph to the spectral domain through wavelet transform, perform Hadamard product on the node signals to aggregate them, and then use inverse wavelet transform to map the aggregated node signals in the spectral domain to the spatial domain, obtaining the node signals aggregated by the spectral domain graph convolution operation, i.e., obtaining the output matrix of each node signal after spectral domain graph convolution; the formula for calculating the spectral domain graph convolution of the nodes in the relationship graph in the spectral domain graph convolution module is as follows:

[0084]

[0085] Where C is the convolution kernel vector, * GLet X represent the spectral domain graph convolution operation, where X is the node signal matrix of dimension n×f, where n is the number of nodes in the graph, d is the signal feature dimension of each node, and C is the convolution kernel signal matrix obtained by copying the kernel vector c n times, also of dimension n×f. Both X and C are representations in the spatial domain, and ψ... s It is the wavelet transform matrix. is the inverse wavelet transform matrix with dimensions n×n, ⊙ represents the Hadamard product, and Y is the output matrix after the nodal signal vector is convolved in the spectral domain with dimensions n×f.

[0086] The foundation of wavelet transform-based spectral domain graph convolution is mapping graph signals from the spatial domain to the spectral domain. Compared to traditional Fourier transform-based mapping methods, wavelet transform-based methods offer greater flexibility and sparsity, enabling them to better capture multi-range features within the graph. This scheme uses a learnable vector C as the convolution kernel for the spectral domain graph convolution, defining the operation. The dimension of the kernel vector C is the same as the dimension of the signal features at each node. The input to the spectral domain graph convolution layer consists of the signals from each node in the graph, as well as the wavelet transform and inverse wavelet transform matrices calculated using the graph structure.

[0087] Spatial Domain Graph Convolution Module: Used for feature extraction by defining graph convolution modules in the spatial domain. These modules use a multi-head self-attention mechanism to perform convolution operations on nodes in the neighborhood of each node in the relational graph; for example... Figure 4 As shown, after obtaining the output of each attention head, the outputs of all attention heads are concatenated, and then the output matrix of the spatial domain graph convolution module is obtained through linear transformation and activation function. In the spatial domain graph convolution module, during the calculation and analysis process using the multi-head attention mechanism, for each attention head h, the attention query matrix Q needs to be calculated first. (h) and the key-value pair matrix K (h) and V (h) Each row of the three matrices represents a node's query, key, and value vector. In self-attention, the matrices are calculated from the node's feature matrix and three different weight matrices, using the following formulas:

[0088]

[0089] Where X is the feature matrix of the node. This is the learnable query weight matrix for the model, used to transform node feature vectors into query vectors through a linear transformation. Similarly, and These are the key weight matrix and value weight matrix, used to generate the key vector and value vector of a node;

[0090] The spatial domain graph convolution module calculates the attention score by calculating each attention head, querying the vector and the key-value pair vector, and then weighting and summing the value vector to obtain the output matrix of the spatial domain graph convolution module.

[0091] As shown in Figure 4 The calculation steps of the multi-head self-attention mechanism in the spatial domain graph convolution module include:

[0092] S201, for each node of the relation graph, the dot product of the query and all neighbor nodes is calculated to obtain the similarity score, and the calculation formula is as follows:

[0093]

[0094] Where, S ij represents the attention weight of node i relative to neighbor j, d i represents the degree of node i, i.e. the number of neighbors of node i;

[0095] S202, the attention score of all neighbor nodes of a node is calculated by the Softmax function, and the calculation formula is as follows:

[0096]

[0097] Where, P ij represents the attention weight of node i relative to neighbor j, Softmax i represents the Softmax operation on all neighbors of node i, and exp represents the exponential calculation with e as the base;

[0098] S203, the value vector of each neighbor node is weighted and summed by the attention weight to obtain the output feature representation vector of a node, and the calculation formula is as follows:

[0099]

[0100] Where, Y i (h) represents the output vector corresponding to node i in the output matrix of the attention head h;

[0101] S204, after obtaining the output of each attention head, the outputs of all attention heads are spliced, and then linear transformation and activation function are performed to obtain the output matrix of the spatial domain graph convolution layer. The calculation formula of the output matrix of the spatial domain graph convolution layer is as follows:

[0102] Y=h(Concat(Y (1) ,Y (2) ,…,Y (h) )W)

[0103] where Y is the output of the spatial domain graph convolution module, h is a nonlinear activation function, Concat represents the concatenation operation of the matrix, W is a linear transformation matrix that can be learned by the model, and is used to scale the multi-head attention output result after concatenation to a suitable feature dimension.

[0104] The spatial domain graph convolution module based on multi-head self-attention is used for feature extraction by defining a graph convolution module in the spatial domain. Unlike the spectral domain-based graph convolution method, this method no longer needs to project the graph signal to the spectral domain to define the convolution operation, but directly defines the graph convolution in the spatial domain. This method can pay more attention to the mutual relationship between nodes. Specifically, the spatial domain graph convolution module uses the positional level self-attention mechanism to selectively perform convolution operations on the nodes in the neighborhood, thereby giving lower attention to the disguised behavior of fraudsters and abnormal relationships, and giving higher attention to normal relationships. Unlike the direct calculation of attention weight of GAT, the method proposed in the present scheme adopts a multi-head self-attention mechanism similar to Transformer, calculates the attention score through the query vector and the key-value pair vector, and then obtains the output of the module by weighted summing the value vector. It has higher flexibility, and multiple self-attention heads can respectively pay attention to the features of the relationship between different nodes, effectively distinguishing the credibility of different relationships.

[0105] The network-level feature extraction module is used for respectively weighting and fusing the output matrix of the spectral domain graph convolution module and the output matrix of the spatial domain graph convolution module through mutual attention mechanism, concatenating with the original features of each node in the relationship graph, and obtaining the final fused node feature data through a multi-layer perception machine as an output matrix and output. Figure 5 As shown in the figure, the network-level feature extraction module performs the following steps for network-level attention feature extraction:

[0106] S211, calculating the output matrix X (e) of the spectral domain graph convolution module and the output matrix X (a) of the spatial domain graph convolution module, and the attention weight matrix S is calculated as follows:

[0107]

[0108] where W S is a learnable parameter matrix, S is the attention weight matrix, and the dimensions of X (e) and X (a) are the same, and the Softmax operation is applied to each column to normalize the attention weight;

[0109] S212, using the attention weight matrix S to respectively weight the output matrix X (e)and output matrix X (a) The characteristic is weighted and fused, and the calculation formula is as follows:

[0110] X (e)′ = X (e) S

[0111] X (a)′ = X (a) S T

[0112] Wherein, X (e)′ is the output matrix of the spectral domain graph convolution network after attention fusion, which contains the information of the output matrix X (a) of the spatial domain graph convolution network, and X (a)′ is the output matrix of the spatial domain graph convolution network after attention fusion, which contains the information of the output matrix X (e) of the spectral domain graph convolution network.

[0113] S213, through splicing operation and linear transformation scaling to the set dimension;

[0114] S214, using residual connection method to calculate and process the original features of the node, the output matrix of the spectral domain graph convolution network and the output matrix of the spatial domain graph convolution network; using residual connection method can avoid the loss of the linear of the node's own features in the process of graph convolution operation. Using residual connection method to weight the original features of the node and the network output features can alleviate the over-smoothing problem in the information aggregation process.

[0115] S215, finally output the final node feature data through multilayer perception. The calculation formula of the node feature data is as follows:

[0116] Y = MLP (Concat (X (e)′ , X (a)′ ) W1 + XW2)

[0117] Wherein, W1 is a parameter matrix for linear transformation of the connected mutual attention output result, W2 is a parameter matrix for linear transformation of the original feature matrix, MLP represents multilayer perception, and Y is the result of fusing the outputs of the two networks through mutual attention.

[0118] The network-level feature extraction module uses mutual attention to flexibly aggregate node embeddings of two networks, so that the model can simultaneously focus on the features of long-distance relationships in the spectral domain and identify the credibility of edges between nodes, thereby dealing with the fraud disguising behavior in the financial fraud detection task. The final fused node feature representation matrix is obtained through a multi-layer perceptron. This representation can fuse the output features of the two networks and focus on the relationship between the node neighborhood graph structure and the global spectral domain graph structure through network learning to deal with the fraud disguising behavior in the financial fraud detection task.

[0119] As shown in Figure 6 The relationship-level feature extraction module is used to obtain the output matrix of a plurality of associated relationship graphs through the network-level feature extraction module, and the feature data used for relationship extraction. Each type of relationship extraction feature data is regarded as a channel, and a channel attention mechanism is used to extract feature information of different channels. Then, the channel attention mechanism is used for pooling processing, dimension reduction and dimension increase processing, and feature fusion processing, respectively. Finally, a linear layer and an activation function are used to obtain the final node label prediction result. The steps of extracting relationship features in the relationship-level feature extraction module and analyzing the node label prediction result include:

[0120] S221, first, the embedding features of each channel are compressed using average pooling operation, which is represented by the formula

[0121]

[0122] wherein, X (c) is the output node feature embedding matrix of channel c, i.e. the output matrix of the network-level feature extraction module; p is the dimension of the node feature, and Z is the node feature representation after average pooling. The features of each node are compressed into a scalar, and the feature representations of all nodes are represented as a vector. Then, the vectors of all channels are combined into a matrix, each row representing a channel and each column representing a node.

[0123] S222, dimension reduction and dimension increase operations between channels are performed through two fully connected layers, which are represented by the following formulas:

[0124] H = W2h(W1Z)

[0125] wherein, W1 is a learnable fully connected layer parameter matrix used for dimension reduction of the feature representation of multiple channels, h is a nonlinear activation function, W2 is a learnable fully connected layer parameter matrix used for dimension increase operation of the dimension-reduced feature representation, and H represents the feature representation of each channel of the node after channel attention.

[0126] S223, the feature representation of each channel is converted into a weight representation between 0 and 1 by a Sigmoid function, and the formula is:

[0127] S c = Sigmoid(H c )

[0128] where S represents the attention weight of each channel;

[0129] S224, the original feature representation of each channel is updated by the channel attention weight, and finally the node feature embedding matrix of each updated channel is summed to obtain the multi-channel fused node feature representation, and the formula is:

[0130]

[0131] where is the node feature representation matrix updated by multi-channel weighted summation, and q is the number of channels, i.e. the number of relationship graphs;

[0132] S225, the final node label prediction result is obtained by a linear layer and a Sigmoid function. The calculation formula of the node label prediction result is:

[0133]

[0134] where W and b are the weight matrix and bias vector of the final output linear layer, and y is the label prediction probability of each node output by the model.

[0135] S3, input the relationship graph data into the financial fraud analysis prediction model to obtain the prediction probability of the financial fraud label of each node in the relationship graph data.

[0136] The fraud detection effect of the method proposed in the scheme is better than that of other fraud detection benchmark models based on graph neural network FdGars, GraphConsis, CARE-GNN, PC-GNN, GTAN and CaT-GNN in Yelp Fraud fraud detection dataset and Amazon Fraud fraud detection dataset. The recall rate on the Yelp Fraud dataset reaches 0.8034, and the ROC-AUC reaches 0.8723. The recall rate on the Amazon Fraud dataset reaches 0.9171, and the ROC-AUC reaches 0.9632.

[0137] The above-mentioned are only embodiments of the present application, and the common knowledge of the specific structure and characteristics in the scheme is not described too much, the ordinary skilled in the art knows all the ordinary technical knowledge in the field of the present application before the application date or the priority date, can know all the prior art in the field, and has the ability to apply the conventional experimental means before the date, the ordinary skilled in the art can improve and implement the present scheme under the inspiration given by the present application, and some typical known structure or known method should not become the obstacle for the ordinary skilled in the art to implement the present application. It should be pointed out that for those skilled in the art, without departing from the structure of the present application, a number of modifications and improvements can be made, which should also be considered as the protection scope of the present application, which will not affect the effect and practicality of the patent. The protection scope of the present application should be subject to the content of its claims, and the specific implementation mode and the like in the specification can be used to explain the content of the claims.

Claims

1. A financial fraud analysis method based on graph neural networks, characterized in that, Includes the following steps: S1. Obtain relationship diagram data; S2. Construct a financial fraud analysis and prediction model based on graph neural networks; The financial fraud analysis and prediction model includes: Spectral domain graph convolution module: It is used to map the node signals in the relation graph to the spectral domain through wavelet transform and convolution kernel, perform aggregation processing, and then map the aggregated node signals in the spectral domain to the spatial domain through inverse wavelet transform to obtain the output matrix of each node signal after spectral domain graph convolution. Spatial domain graph convolution module: Used to extract features by defining graph convolution modules in the spatial domain. The graph convolution module uses a multi-head self-attention mechanism to perform convolution operations on the nodes in the neighborhood of each node in the relation graph. After obtaining the output of each attention head, the outputs of all attention heads are concatenated, and then the output matrix of the spatial domain graph convolution module is obtained through linear transformation and activation function. Network-level feature extraction module: It is used to weight and fuse the output matrix of the spectral domain graph convolution module and the output matrix of the spatial domain graph convolution module through mutual attention mechanism, then concatenate them with the original features of each node in the relationship graph, and obtain the final fused node feature data through a multilayer perceptron, which is then output as the output matrix. The relation-level feature extraction module is used to obtain the output matrix of a relation graph with a certain number of related numbers through the network-level feature extraction module. This matrix is ​​used for feature data extraction of relations. Each type of relation feature data is treated as a channel, and a channel attention mechanism is used to extract features from different channels. Then, pooling, dimensionality reduction and expansion, and feature fusion are performed through the channel attention mechanism. Finally, a linear layer and an activation function are used to obtain the final node label prediction result. S3. Input the relationship graph data into the financial fraud analysis and prediction model to obtain the predicted probability of the financial fraud label for each node in the relationship graph data.

2. The financial fraud analysis method based on graph neural networks according to claim 1, characterized in that: The formula for calculating spectral domain graph convolution of nodes in the relation graph in the spectral domain graph convolution module is as follows: Where C is the convolution kernel vector, * G Let X represent a graph convolution operation in the spectral domain. X is a node signal matrix with dimensions n×f, where n is the number of nodes in the graph and f is the signal feature dimension of each node. C is a kernel signal matrix with dimensions b×f, obtained by copying the kernel vector c n times. Both X and C are representations in the spatial domain, and ψ... s It is the wavelet transform matrix. is the inverse wavelet transform matrix with dimensions n×n, ⊙ represents the Hadamard product, and Y is the output matrix after the nodal signal vector is convolved in the spectral domain with dimensions n×f.

3. The financial fraud analysis method based on graph neural networks according to claim 2, characterized in that: In the spatial domain graph convolution module, during the computation and analysis phase using a multi-head attention mechanism, for each attention head h, the attention query matrix Q needs to be calculated first. (h) and the key-value pair matrix K (h) and V (h) Each row of the three matrices represents a node's query, key, and value vector. In self-attention, the matrices are calculated from the node's feature matrix and three different weight matrices, using the following formulas: Where X is the feature matrix of the node. This is the learnable query weight matrix for the model, used to transform node feature vectors into query vectors through a linear transformation. Similarly, and These are the key weight matrix and value weight matrix, used to generate the key vector and value vector of a node; The spatial domain graph convolution module analyzes and calculates each attention head, queries the vector and key-value pair vector to calculate the attention score, and then obtains the output matrix of the spatial domain graph convolution module by weighted summation of the value vectors.

4. The financial fraud analysis method based on graph neural networks according to claim 3, characterized in that: In the spatial domain graph convolution module, the calculation steps for one attention head of the multi-head self-attention mechanism to aggregate neighbor features and output node features include: S201. For each node in the relationship graph, calculate the dot product between the query and all neighboring nodes to obtain the similarity score. The calculation formula is as follows: Among them, S ij d represents the attention weight of node i relative to neighbor j. i This represents the degree of node i, which is the number of neighbors of node i. S202. Calculate the attention scores of all neighboring nodes of a node using the Softmax function. The calculation formula is as follows: Among them, P ij Softmax represents the attention weight of node i with respect to neighbor j. i This indicates that a Softmax operation is performed on all neighbors of node i, and exp represents the exponentiation with base e. S203. The value vectors of each neighboring node are weighted and summed using attention weights to obtain the output feature representation vector of a node. The calculation formula is as follows: Among them, Y i (h) This represents the output vector corresponding to node i in the output matrix of the attention head h; S204. After obtaining the output of each attention head, the outputs of all attention heads are concatenated, and then the output matrix of the spatial domain graph convolutional layer is obtained through linear transformation and activation function.

5. The financial fraud analysis method based on graph neural networks according to claim 4, characterized in that: The formula for calculating the output matrix of the spatial domain graph convolutional layer is as follows: Y=h(Concat(Y (1) ,AND (2) ,…,AND (h) )W) Where Y is the output of the spatial domain graph convolution module, j is the non-linear activation function, Concat represents the matrix concatenation operation, and W is a learnable linear transformation matrix used to scale the concatenated multi-head attention output to a suitable feature dimension.

6. The financial fraud analysis method based on graph neural networks according to claim 5, characterized in that: The network-level feature extraction module performs the following feature extraction steps for network-level attention: S211, Calculate the output matrix X of the spectral domain graph convolution module. (e) The output matrix X of the spatial domain graph convolution module (a) The attention weight matrix is ​​calculated using the following formula: Among them, W S It is a learnable parameter matrix, S is the attention weight matrix, and X is... (e) Dimensions and X (a) The dimensions are the same, and the Softmax operation is applied to each column to normalize the attention weights; S212. Apply the attention weight matrix to the output matrix X respectively. (e) and output matrix X (a) The features are weighted and fused, and the calculation formula is as follows: X (e)′ =X (e) S Where, X (e)′ This is the output matrix of the spectral domain graph convolutional network after attention fusion, which includes the output matrix X of the spatial domain graph convolutional network. (a) Similarly, X (a)′ This is the output matrix of the spatial domain graph convolutional network after attention fusion, which includes the output matrix X of the spectral domain graph convolutional network. (e) Information; S213. Scale to the set dimension through splicing operations and linear transformations; S214. Use the residual connection method to perform weighted calculation processing on the original features of the nodes and the output matrices of the spectral domain graph convolutional network and the spatial domain graph convolutional network. S215. Finally, the final node feature data is output through a multilayer perceptron.

7. The financial fraud analysis method based on graph neural networks according to claim 6, characterized in that: The formula for calculating the node feature data is as follows: Y=MLP(Concat(X (e)′ ,X (a)′ )W1+XW2) Where W1 is the parameter matrix used to linearly transform the output of the mutual attention after connection, W2 is the parameter matrix used to linearly transform the original feature matrix, MLP stands for Multilayer Perceptron, and Y is the result of fusing the outputs of the two networks through mutual attention.

8. The financial fraud analysis method based on graph neural networks according to claim 7, characterized in that: The steps in the relation-level feature extraction module that extract relation features from several relation graphs and analyze them to obtain node label prediction results include: S221. First, the embedded features of each channel are compressed using average pooling, expressed by the formula: Among them, X (c) The output node feature embedding matrix for channel c is the output matrix of the network-level feature extraction module; p is the dimension of the node feature, Z is the node feature representation after average pooling, the feature of each node is compressed into a scalar, the feature representation of all nodes is a vector, and then the vectors of all channels are merged into a matrix, where each row represents a channel and each column represents a node. S222. Dimensionality reduction and dimensionality enhancement operations between channels are performed through two fully connected layers, as expressed by the following formula: H = W2h(W1Z) Where W1 is a learnable fully connected layer parameter matrix used to reduce the dimensionality of the feature representations of multiple channels, h is a non-linear activation function, W2 is a learnable fully connected layer parameter matrix used to increase the dimensionality of the reduced feature representations, and H represents the feature representations of each channel of the node after channel attention. S223. Transform the feature representations of each channel into weighted representations between 0 and 1 using the Sigmoid function, with the following formula: S c =Sigmoid(H c ) Where S represents the attention weight of each channel; S224. Update the original feature representation of each channel through the channel attention weights. Finally, sum the updated node feature embedding matrices of each channel to obtain the multi-channel fused node feature representation, as shown in the formula: in q is the node feature representation matrix updated after multi-channel weighted summation, where q is the number of channels, i.e., the number of relational graphs. S225. The final node label prediction result is obtained through a linear layer and the Sigmoid function.

9. The financial fraud analysis method based on graph neural networks according to claim 8, characterized in that: The formula for calculating the node label prediction result is as follows: Where W and b are the weight matrix and bias vector of the final output linear layer, and y is the label prediction probability of each node in the final output of the model.