Message processing method and device, electronic equipment, medium and program product
By using a message recognition model to identify transaction entities and relationships, and combining it with a transaction knowledge graph to detect anomalies, the problems of low transaction message processing efficiency and insufficient identification of illegal transactions are solved, achieving efficient and accurate transaction anomaly detection.
Patent Information
- Application Number
- CN202511122835.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-12
- Publication Date
- 2025-11-21
AI Technical Summary
Existing technologies are inefficient in processing transaction messages and are prone to errors in identifying abnormal situations, leading to transaction risks. The new system lacks the ability to identify illegal transactions.
A trained message recognition model is used to identify entity relationships and detect transaction anomalies. Risk detection is performed by comparing transaction entities and transaction relationships and combining them with a transaction knowledge graph.
It improves the efficiency and accuracy of transaction message detection, quickly identifies risks of illegal transactions, and ensures the security and compliance of transactions.
Smart Images

Figure CN120996933A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the fields of big data and artificial intelligence, and more specifically to a message processing method, apparatus, device, medium, and program product. Background Technology
[0002] Transaction messages are standardized data carriers for transmitting transaction instructions and information between financial institutions. With technological and business development, financial institutions' transaction systems are periodically upgraded, updated, or even restructured. To ensure the correctness of the transaction message encapsulation by the new system, comparative testing of the messages encapsulated by the old and new systems is necessary. Simultaneously, the new system's ability to identify risks related to unauthorized transactions urgently needs improvement to avoid gaps in risk monitoring.
[0003] The inventors discovered that when processing a large number of transaction messages, the processing efficiency is low, and it is easy to misidentify abnormal situations in the transaction messages, which may even lead to transaction risks. Summary of the Invention
[0004] In view of the above problems, this application provides a message processing method, apparatus, device, medium and program product.
[0005] According to a first aspect of this application, a message processing method is provided, comprising: receiving a transaction message related to a target transaction; using a trained message recognition model to identify entity relationships in the received transaction message to obtain transaction entities and transaction relationships; and performing transaction anomaly detection on the transaction message based on the transaction entities and transaction relationships to obtain detection results.
[0006] According to an embodiment of this application, transaction anomaly detection is performed on transaction messages based on transaction entities and transaction relationships to obtain detection results, including: comparing the transaction entities and transaction relationships with historical transaction entities and historical transaction relationships identified from historical transaction messages to obtain comparison results, wherein the transaction messages and historical transaction messages are related to the same target transaction; and determining anomaly detection results that characterize whether there is a transaction anomaly in the transaction messages based on the comparison results.
[0007] According to an embodiment of this application, the transaction message is determined based on a first message rule, and the historical transaction message is determined based on a second message rule. The determination of an anomaly detection result, indicating whether a transaction message exhibits an anomaly, based on the comparison result includes: if the comparison result indicates that the message content difference information meets a preset difference condition, determining a rule anomaly detection result indicating that the first message rule has an abnormal rule parameter. The message content difference information represents at least one of the following: a first degree of difference between the transaction entity and historical transaction entities; a second degree of difference between the transaction relationship and historical transaction relationships.
[0008] According to an embodiment of this application, a trained message recognition model is used to identify entity relationships in received transaction messages to obtain transaction entities and transaction relationships. This includes: identifying semantic features of the transaction messages to obtain transaction semantic features, which represent the transaction process of the target transaction; and identifying transaction relationships based on the transaction semantic features to obtain multiple transaction relationships, which represent the resource transfer method or resource retention method in the transaction process of the target transaction.
[0009] According to an embodiment of this application, transaction anomaly detection is performed on transaction messages based on transaction entities and transaction relationships to obtain detection results, including: querying a preset transaction knowledge graph based on transaction entities and transaction relationships to obtain abnormal risk transaction entities; and determining a risk detection result indicating that the target transaction has abnormal transaction risk based on the abnormal risk transaction entities.
[0010] According to an embodiment of this application, the message recognition model is trained based on the following operations: acquiring associated sample messages and tag data, wherein the tag data includes multiple tag relationships determined from a preset knowledge graph; processing the sample messages using the semantic feature recognition layer of the initial message recognition model to obtain sample transaction semantic features; processing the sample transaction semantic features using the relationship recognition layer of the initial message recognition model to obtain multiple sample transaction relationships; and training the initial message recognition model based on the multiple sample transaction relationships and multiple tag relationships to obtain the message recognition model.
[0011] According to an embodiment of this application, the above method further includes: updating the current transaction knowledge graph using transaction relationships to obtain an updated transaction knowledge graph.
[0012] A second aspect of this application provides a message processing apparatus, comprising: a transaction message receiving module for receiving transaction messages related to a target transaction; an entity relationship identification module for using a trained message identification model to identify entity relationships in the received transaction messages to obtain transaction entities and transaction relationships; and a transaction anomaly detection module for detecting transaction anomalies in the transaction messages based on the transaction entities and transaction relationships to obtain detection results.
[0013] A third aspect of this application provides an electronic device comprising: one or more processors; and a memory for storing one or more computer programs, wherein the one or more processors execute the one or more computer programs to implement the steps of the method described above.
[0014] A fourth aspect of this application also provides a computer-readable storage medium having a computer program or instructions stored thereon, which, when executed by a processor, implement the steps of the above-described method.
[0015] The fifth aspect of this application also provides a computer program product, including a computer program or instructions that, when executed by a processor, implement the steps of the above-described method.
[0016] According to embodiments of this application, entity relationships are identified in received transaction messages using a trained message recognition model to obtain transaction entities and transaction relationships. This allows for transaction anomaly detection based on transaction entities and relationships, yielding detection results. Since entity recognition and relationship extraction utilize natural language processing technology to identify semantic information in messages, independent of message format, detection can be performed on messages of different formats, improving detection efficiency and solving the problem of message comparison requiring preset rules or manual processing. Furthermore, transaction entities and relationships accurately and intuitively reflect the transaction information contained in the message; detection based on transaction entities and relationships improves the accuracy of transaction anomaly detection and quickly identifies risks of illegal transactions. Attached Figure Description
[0017] The above-mentioned contents, other objects, features and advantages of this application will become clearer from the following description of embodiments with reference to the accompanying drawings, in which:
[0018] Figure 1 The illustrations depict application scenarios of message processing methods, apparatus, devices, media, and program products according to embodiments of this application.
[0019] Figure 2 A flowchart illustrating a message processing method according to an embodiment of this application is shown schematically.
[0020] Figure 3 A schematic diagram illustrating an abnormal risk transaction entity according to an embodiment of this application is shown.
[0021] Figure 4 This illustration schematically depicts the process of a message processing method according to an embodiment of this application;
[0022] Figure 5 The flowchart illustrating the training of a message recognition model according to an embodiment of this application is shown in the schematic diagram.
[0023] Figure 6 A schematic diagram of a simulator structure according to an embodiment of this application is shown.
[0024] Figure 7 This schematically illustrates a structural block diagram of a message processing apparatus according to embodiments of this application; and
[0025] Figure 8 A block diagram schematically illustrates an electronic device suitable for implementing a message processing method according to an embodiment of this application. Detailed Implementation
[0026] The embodiments of this application will now be described with reference to the accompanying drawings. However, it should be understood that these descriptions are exemplary only and are not intended to limit the scope of this application. In the following detailed description, numerous specific details are set forth to provide a thorough understanding of the embodiments of this application for ease of explanation. However, it will be apparent that one or more embodiments may be implemented without these specific details. Furthermore, descriptions of well-known structures and technologies are omitted in the following description to avoid unnecessarily obscuring the concepts of this application.
[0027] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit the scope of this application. The terms “comprising,” “including,” etc., as used herein indicate the presence of the stated features, steps, operations, and / or components, but do not exclude the presence or addition of one or more other features, steps, operations, or components.
[0028] All terms used herein (including technical and scientific terms) have the meanings commonly understood by those skilled in the art, unless otherwise defined. It should be noted that the terms used herein are to be interpreted in a manner consistent with the context of this specification, and not in an idealized or overly rigid way.
[0029] When using expressions such as "at least one of A, B and C", they should generally be interpreted in accordance with the meaning that is commonly understood by those skilled in the art (e.g., "a system having at least one of A, B and C" should include, but is not limited to, a system having A alone, a system having B alone, a system having C alone, a system having A and B, a system having A and C, a system having B and C, and / or a system having A, B and C, etc.).
[0030] In the technical solution of this application, the user information (including but not limited to user personal information, user image information, user device information, such as location information) and data (including but not limited to data used for analysis, stored data, and displayed data) involved are all information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, storage, use, processing, transmission, provision, disclosure, and application of related data all comply with relevant laws, regulations, and standards, take necessary confidentiality measures, do not violate public order and good morals, and provide corresponding operation entry points for users to choose to authorize or refuse.
[0031] In scenarios involving automated decision-making using personal information, the methods, devices, and systems provided in this application all offer users corresponding entry points for choosing to agree to or reject the automated decision-making results. If the user chooses to reject, the process proceeds to the expert decision-making stage. Here, "automated decision-making" refers to the activity of automatically analyzing and evaluating an individual's behavioral habits, interests, or economic, health, and credit status through computer programs, and then making a decision. Here, "expert decision-making" refers to the activity of making decisions by personnel who specialize in a particular field, possess specialized experience, knowledge, and skills, and have reached a certain level of professional expertise.
[0032] In conceiving this application, the inventors discovered that during the testing of the reconstructed system, message comparison could only be performed on messages with a predetermined format and consistent data type. This required pre-defined identification rules and processing according to fixed rules or manual intervention, lacking effective data integration and utilization, as well as efficient means of identifying and monitoring anomalies. This resulted in low message comparison efficiency and susceptibility to human factors. Furthermore, the new system had weak risk identification capabilities for unauthorized operations, requiring the migration of historical data from the old system or training the new system with large amounts of data to improve its risk identification capabilities. This led to low efficiency and poor accuracy in risk identification for the new system.
[0033] In view of this, embodiments of this application provide a message processing method, apparatus, electronic device, medium, and program product, which can be applied to the field of big data technology. The message processing method includes: receiving a transaction message related to a target transaction; using a trained message recognition model to identify entity relationships in the received transaction message, obtaining transaction entities and transaction relationships; and performing transaction anomaly detection on the transaction message based on the transaction entities and transaction relationships, obtaining detection results. Embodiments of this application also provide a message processing apparatus, device, storage medium, and program product.
[0034] Figure 1 The illustration shows an application scenario diagram of message processing according to an embodiment of this application.
[0035] like Figure 1 As shown, application scenario 100 according to this embodiment may include a first terminal device 101, a second terminal device 102, a third terminal device 103, a network 104, and a server 105. The network 104 serves as a medium for providing a communication link between the first terminal device 101, the second terminal device 102, the third terminal device 103, and the server 105. The network 104 may include various connection types, such as wired or wireless communication links, or fiber optic cables, etc.
[0036] Users can use the first terminal device 101, the second terminal device 102, and the third terminal device 103 to interact with the server 105 via the network 104 to receive or send messages, etc. Various communication client applications can be installed on the first terminal device 101, the second terminal device 102, and the third terminal device 103, such as shopping applications, web browser applications, search applications, instant messaging tools, email clients, social media platform software, etc. (for example only).
[0037] The first terminal device 101, the second terminal device 102, and the third terminal device 103 can be various electronic devices with displays and support web browsing, including but not limited to smartphones, tablets, laptops, and desktop computers.
[0038] Server 105 can be a server that provides various services, such as a backend management server that supports websites browsed by users using the first terminal device 101, the second terminal device 102, and the third terminal device 103 (this is just an example). The backend management server can analyze and process data such as received user requests, and feed back the processing results (such as web pages, information, or data obtained or generated according to user requests) to the terminal devices.
[0039] It should be noted that the message processing method provided in this application embodiment can generally be executed by server 105. Correspondingly, the message processing device provided in this application embodiment can generally be located in server 105. The message processing method provided in this application embodiment can also be executed by a server or server cluster that is different from server 105 and capable of communicating with the first terminal device 101, the second terminal device 102, the third terminal device 103, and / or server 105. Correspondingly, the message processing device provided in this application embodiment can also be located in a server or server cluster that is different from server 105 and capable of communicating with the first terminal device 101, the second terminal device 102, the third terminal device 103, and / or server 105.
[0040] It should be understood that Figure 1 The number of terminal devices, networks, and servers shown is merely illustrative. Depending on implementation needs, any number of terminal devices, networks, and servers can be included.
[0041] The following will be based on Figure 1 The described scene, through Figures 2-6 The message processing method according to the embodiments of this application will be described in detail.
[0042] Figure 2 A flowchart illustrating a message processing method according to an embodiment of this application is shown schematically.
[0043] like Figure 2 As shown, the message processing method of this embodiment includes operations S210 to S230.
[0044] In operation S210, a transaction message related to the target transaction is received.
[0045] During operation S220, the trained message recognition model is used to identify entity relationships in the received transaction messages, thereby obtaining the transaction entities and transaction relationships.
[0046] In operation S230, transaction anomaly detection is performed on transaction messages based on transaction entities and transaction relationships, and the detection results are obtained.
[0047] In the embodiments of this application, the target transaction can be a current transaction processed by the reconstructed new system. The current transaction can include historical transactions processed by the old system used by the financial institution before the new system went live, and new transactions processed after the new system went live. The target transaction includes, but is not limited to, the following transaction types: deposits, transfers, settlements, loans, etc.
[0048] In embodiments of this application, the transaction message can be encapsulated by the reconstructed new system, and the format of the transaction message can include: XML format, fixed-length text, JSON format, and a mixed format of fixed-length text and XML, etc. The transaction message can include account information, transaction amount information, transaction time information, transaction location information, and transaction venue information, etc.
[0049] In embodiments of this application, the message recognition model includes an entity relationship recognition module, which can perform entity recognition and relationship extraction on transaction messages. Entity recognition can be implemented based on named entity recognition algorithms to process the structured data in the transaction message to obtain transaction entities. Relationship extraction can be based on natural language processing to perform semantic analysis on unstructured data (e.g., text) in the transaction message to obtain transaction relationships.
[0050] The message recognition model can be constructed based on any type of algorithm. For example, it can be constructed based on convolutional neural network algorithms, attention network algorithms, etc. The embodiments of this disclosure do not limit the specific algorithm type for constructing the message recognition model.
[0051] In embodiments of this application, a transaction entity may include a transaction subject, transaction type, transaction time, transaction location, transaction status, transaction account information, transaction account type, transaction channel, etc. A transaction relationship characterizes the association between any two transaction entities.
[0052] For example, if account A transfers 5,000 yuan to account B via online banking at 9:00 AM, the new system will encapsulate this transaction into a transaction message and extract the transaction entity and transaction relationship. The transaction entity includes: account A, online banking, 9:00 AM, account B, and 5,000 yuan. The transaction relationship includes: account A's transfer channel is online banking, account A's transfer time is 9:00 AM, account A transfers to account B, account A transfers out 5,000 yuan, and account B transfers in 5,000 yuan, etc.
[0053] In the embodiments of this application, transaction anomaly detection may include detecting whether there are transaction anomalies in the transaction message and detecting whether there are abnormal transaction risks in the target transaction. Detecting whether there are transaction anomalies in the transaction message can verify the correctness of the message encapsulation in the reconstructed new system, and detecting whether there are abnormal transaction risks in the target transaction can identify illegal transaction risks and ensure the security and compliance of transactions.
[0054] According to embodiments of this application, entity relationships are identified in received transaction messages using a trained message recognition model to obtain transaction entities and transaction relationships. This allows for transaction anomaly detection based on transaction entities and relationships, yielding detection results. Since entity recognition and relationship extraction utilize natural language processing technology to identify semantic information in messages, independent of message format, detection can be performed on messages of different formats, improving detection efficiency and solving the problem of message comparison requiring preset rules or manual processing. Furthermore, transaction entities and relationships accurately and intuitively reflect the transaction information contained in the message; detection based on transaction entities and relationships improves the accuracy of transaction anomaly detection and quickly identifies risks of illegal transactions.
[0055] According to an embodiment of this application, transaction anomaly detection is performed on transaction messages based on transaction entities and transaction relationships to obtain detection results, including: comparing the transaction entities and transaction relationships with historical transaction entities and historical transaction relationships identified from historical transaction messages to obtain comparison results, wherein the transaction messages and historical transaction messages are related to the same target transaction; and determining anomaly detection results that characterize whether there is a transaction anomaly in the transaction messages based on the comparison results.
[0056] In the embodiments of this application, historical transaction messages can be messages obtained by encapsulating target transaction data in an older system. A message recognition model is used to extract historical transaction entities and historical transaction relationships from these messages. Historical transaction entities include the transaction subject, transaction type, transaction time, transaction location, transaction status, transaction account information, transaction account type, and transaction channel in the target transaction. Historical transaction relationships represent the association between any two historical transaction entities.
[0057] In the embodiments of this application, the anomaly detection result may include the presence of transaction anomalies in the transaction message, which can be understood as the presence of error information in the message encapsulated by the new system.
[0058] In the embodiments of this application, for the same transaction, the message recognition model is used to perform entity recognition and relationship extraction on the messages encapsulated by the new system and the old system respectively, and the recognized entities and relationships are compared to determine whether there are errors in the messages encapsulated by the new system.
[0059] For example, for a transfer transaction of account A, the historical transaction message contains the following information: Account A transferred 5,000 yuan to account B via online banking at 9:00 AM; the information contained in the transaction message should be the same as that in the historical transaction message. If the transaction entity or transaction relationship does not correspond to the historical transaction entity and historical transaction relationship, it can be determined that there is an error in the transaction message.
[0060] According to the embodiments of this application, by comparing historical transaction messages of the same transaction, it is possible to determine whether there are errors in the transaction messages without being limited by the message format. By comparing entities and relationships separately, error information in the transaction messages can be accurately located, improving detection efficiency and accuracy, and helping relevant personnel to adjust and correct the new system in a short time.
[0061] According to an embodiment of this application, the transaction message is determined based on a first message rule, and the historical transaction message is determined based on a second message rule. The determination of an anomaly detection result, indicating whether a transaction message exhibits an anomaly, based on the comparison result includes: if the comparison result indicates that the message content difference information meets a preset difference condition, determining a rule anomaly detection result indicating that the first message rule has an abnormal rule parameter. The message content difference information represents at least one of the following: a first degree of difference between the transaction entity and historical transaction entities; a second degree of difference between the transaction relationship and historical transaction relationships.
[0062] In the embodiments of this application, the first message rule can be used to guide the new system in the encapsulation format, transmission protocol, or content structure of transaction messages. The second message rule can be used to guide the old system in the encapsulation format, transmission protocol, or content structure of historical transaction messages. The first and second message rules may include field definitions, data types, and transmission protocols. The first message rule may be the same as or different from the second message rule; this application does not limit this.
[0063] In some embodiments, the first message rule and the second message rule can be communication standard rules corresponding to different message protocols. For example, the first message rule is a rule corresponding to the Transmission Control Protocol (TCP), and the second message rule is a communication standard rule corresponding to the Hypertext Transfer Protocol (HTTP).
[0064] In embodiments of this application, message content difference information represents the differences in information related to the same transaction contained in transaction messages and historical transaction messages. Message content difference information can be quantified by calculating Euclidean distance or cosine similarity, including: calculating a first difference degree between the transaction entity and historical transaction entities, and calculating a second difference degree between the transaction relationship and historical transaction relationships. The first difference degree can be a similarity value between the transaction entity and historical transaction entities, and the second difference degree can be a similarity value between the transaction relationship and historical transaction relationships. Message content difference information can be calculated by weighted summation of the first and second difference degrees.
[0065] In the embodiments of this application, the preset difference condition can be set using a similarity threshold. For example, the similarity threshold can be set to 0.25, then the preset difference condition can be that the difference in message content is greater than 0.25.
[0066] As an example, by comparing the transaction entity and historical transaction entities, the first difference score is 0.2; by comparing the transaction relationship and historical transaction relationship, the second difference score is 0.3. Setting the weight of the first difference score to 0.3 and the weight of the second difference score to 0.7, the message content difference information can be 0.27. Since the message content difference information meets the preset difference condition (message content difference information greater than 0.25), it can be determined that the first message rule has abnormal rule parameters.
[0067] According to embodiments of this application, by calculating the first and second difference measures to quantify message content difference information, and based on preset difference conditions, the rule anomaly detection result can be intuitively determined, improving detection efficiency and speed. Simultaneously, in the event of anomalies in the transaction message, the rule parameters of the first message rule can be promptly corrected, improving the accuracy of message encapsulation in the new system.
[0068] According to an embodiment of this application, a trained message recognition model is used to identify entity relationships in received transaction messages to obtain transaction entities and transaction relationships. This includes: identifying semantic features of the transaction messages to obtain transaction semantic features, which represent the transaction process of the target transaction; and identifying transaction relationships based on the transaction semantic features to obtain multiple transaction relationships, which represent the resource transfer method or resource retention method in the transaction process of the target transaction.
[0069] In the embodiments of this application, transaction semantic features may include transaction account features, transaction amount features, transaction time features, transaction location features, transaction venue features, resource flow features, or resource retention features, etc.
[0070] In the embodiments of this application, resource transfer methods may include bank transfers, remittances, fee deductions, cross-border transactions, etc. Transaction relationships may also represent resource transfer channels, including cash transaction channels, cross-border transaction channels, bank counters, etc. Resource retention methods may include deposits, prepayment retention, collateral, etc.
[0071] In the embodiments of this application, semantic features of transaction messages are extracted, such as amount, time, and transaction purpose. Based on the extracted semantic features, the transaction relationship is identified, such as the transaction purpose being salary payment.
[0072] According to the embodiments of this application, transaction semantic features are obtained by performing complex semantic recognition on message content, and multiple transaction relationships are obtained by identifying transaction relationships based on the transaction semantic features. This realizes the transformation of semantic information expressed by complex transaction processes in messages into structured transaction relationships, thereby improving the accuracy and detection rate of abnormal transactions in subsequent message detection.
[0073] According to an embodiment of this application, transaction anomaly detection is performed on transaction messages based on transaction entities and transaction relationships to obtain detection results, including: querying a preset transaction knowledge graph based on transaction entities and transaction relationships to obtain abnormal risk transaction entities; and determining a risk detection result indicating that the target transaction has abnormal transaction risk based on the abnormal risk transaction entities.
[0074] In the embodiments of this application, a transaction knowledge graph can be constructed by identifying historical transaction entities and relationships from a large number of historical transaction messages. Simultaneously, during the construction of the transaction knowledge graph, an account information database can be linked to extract account information matching the accounts in historical transaction messages, thereby identifying more transaction entities from the account information. For example, the account information database can be used to extract the account's opening bank information, account balance information, account type information, and account risk information, where account risk information may include the account's past illegal transactions or inclusion in an alert list. Utilizing the account information database can enhance the richness of the transaction knowledge graph, thereby improving the accuracy of transaction risk detection.
[0075] In the embodiments of this application, the abnormal risk transaction entity can be entity information in the transaction knowledge graph that matches the transaction entity. Based on the transaction entity and transaction relationship, a query is performed in the transaction knowledge graph to obtain abnormal risk transaction entities and abnormal risk transaction relationships that match the transaction entity and transaction relationship. Abnormal risk transaction entities and abnormal risk transaction relationships can be extracted in the form of multiple entity relationship triples or in the form of multiple entity relationship complex links. Among the extracted abnormal risk transaction entities, if there is a violation transaction risk entity, it is determined that the target transaction may have a violation transaction risk. By using violation risk transaction entities, it is possible to intuitively determine whether the target transaction has an abnormal transaction risk, thereby improving the accuracy of risk detection.
[0076] For example, if the entity relationship triple retrieved from the transaction knowledge graph is (Account A, Risk, Violation Risk Type Entity), then it can be determined that the target transaction carries a violation risk. Conversely, if the entity relationship triple retrieved from the transaction knowledge graph does not contain an entity representing a violation, then it can be determined that the target transaction does not carry a violation risk.
[0077] In the embodiments of this application, the risk detection results can also be verified by experts to determine whether the target transaction has any illegal transaction operations, thus avoiding incorrect identification.
[0078] In the embodiments of this application, the entity of illegal transaction risk can be an entity of illegal transaction type or an entity of account alert. The entity of illegal transaction type indicates the type of illegal transaction that may exist in the target transaction, and the entity of account alert indicates that the account itself has the risk of illegal transaction.
[0079] Figure 3 A schematic diagram of an abnormal risk transaction entity according to an embodiment of this application is shown.
[0080] like Figure 3As shown, based on the query of the transaction entity in the transaction knowledge graph, the following information is obtained: (Account A304, transaction frequency, 10 times in 3 days 305), (Account A304, transfer out, 1000 yuan 303), (Account B302, transfer in, 1000 yuan 303), (Account B302, risk, illegal transaction type entity 301), (Account A304, risk, illegal transaction type entity 301). From the illegal transaction type entity 301 in the queryed transaction knowledge graph, it can be seen that the target transaction involves illegal transactions.
[0081] Figure 4 The illustration shows the process of a message processing method according to an embodiment of this application.
[0082] like Figure 4 As shown, the transaction message is received 401, and entity relationship identification is performed on the transaction message 402 to obtain the transaction entity and transaction relationship.
[0083] The transaction entity and transaction relationship are input into the comparison and detection module 403. The comparison result is determined based on the historical transaction entity and historical transaction messages 405. Based on the message content difference information of the comparison result, it is determined whether the preset difference condition is met 407. If the preset difference condition is met, it is determined that the target transaction has rule parameter anomalies 409; if the preset difference condition is not met, it is determined that the target transaction does not have rule parameter anomalies 408.
[0084] Input the transaction entity and transaction relationship into the risk detection module 404, query the transaction knowledge graph 406, obtain the abnormal risk transaction entity, and determine the risk detection result 410 based on the abnormal risk transaction entity.
[0085] According to the embodiments of this application, risk detection is performed by querying the transaction entities and transaction relationships that match the target transaction in a preset transaction knowledge graph. Compared with traditional risk detection, this greatly reduces the amount of data computation and improves the response speed of risk detection. Moreover, due to the multi-link matching of the transaction knowledge graph, accurate risk detection can be achieved even when some historical data is missing.
[0086] Figure 5 The flowchart illustrating the training of a message recognition model according to an embodiment of this application is shown schematically.
[0087] like Figure 5 As shown, the message processing method of this embodiment includes operations S510 to S540.
[0088] During operation of S510, the associated sample message and tag data are obtained.
[0089] According to embodiments of this application, the tag data includes multiple tag relationships determined from a preset knowledge graph.
[0090] When operating the S520, the semantic feature recognition layer of the initial message recognition model is used to process the sample message to obtain the semantic features of the sample transaction.
[0091] When operating the S530, the relationship recognition layer of the initial message recognition model is used to process the semantic features of sample transactions to obtain multiple sample transaction relationships.
[0092] When operating the S540, an initial message recognition model is trained based on multiple sample transaction relationships and multiple label relationships to obtain the message recognition model.
[0093] In the embodiments of this application, sample messages can be obtained from historical transaction messages, which include various types of transactions such as transfers, loans, and cross-border transactions, covering different transaction scenarios. Tag data can be determined from a preset knowledge graph.
[0094] As an example, sample message and label data are divided into training and validation sets according to a certain ratio, for example, 80% as the training set and 20% as the validation set. Multiple iterations are performed on the training set, with the training set data divided into small batches and sequentially input into the initial message recognition model in each iteration. For each batch of data, the loss value between the model's predicted output and the label is calculated, and then the model parameters are updated using an optimization algorithm until the loss value meets preset conditions or the loss converges. During training, the model's performance is periodically evaluated on the validation set, such as calculating metrics like accuracy, recall, and F1 score, to monitor for overfitting. If the performance metrics on the validation set no longer improve after several consecutive iterations, training is stopped early to prevent overfitting.
[0095] According to embodiments of this application, training an initial message recognition model can improve the message recognition model's ability to identify entities and extract relationships from messages, thereby accurately identifying the transaction entities and transaction relationships in transaction messages and improving the accuracy of subsequent detection.
[0096] According to an embodiment of this application, the above method further includes: updating the current transaction knowledge graph using transaction relationships to obtain an updated transaction knowledge graph.
[0097] In the embodiments of this application, the transaction relationships of the target transaction can be continuously updated in the transaction knowledge graph, enriching the associations between entities in the graph and obtaining an updated transaction knowledge graph. Subsequently, the updated transaction knowledge graph can be used for risk detection.
[0098] According to embodiments of this application, updating transaction relationships to the transaction knowledge graph can enrich the associations between entities, increase the complexity of links in the graph, thereby improving the accuracy of queries and, consequently, the accuracy of detection.
[0099] Figure 6 A schematic diagram of a simulator structure according to an embodiment of this application is shown.
[0100] like Figure 6 As shown, the message processing method provided in this application can be implemented based on a simulator. The simulator may include a data analysis module 610, a message conversion module 620, a transaction matching module 660, and a message detection module 640. The data analysis module 610 can check, measure, interpret, and diagnose the target transaction data to determine if any data is missing. The data analysis module 610 sends the received target transaction data to the message conversion module 620, which encapsulates the target transaction data into a transaction message and sends the transaction message to the transaction matching module 660. The transaction matching module 660 can identify transaction entities and extract transaction relationships based on the received transaction messages, and send the obtained transaction entities and transaction relationships to the message detection module 640. The message detection module 640 can perform comparative detection of transaction messages and risk detection of the target transaction based on the transaction entities and transaction relationships, and output the detection results.
[0101] Based on the above message processing method, this application also provides a message processing apparatus. The following will be combined with... Figure 7 The device is described in detail.
[0102] Figure 7 A schematic block diagram of a message processing apparatus according to an embodiment of this application is shown.
[0103] like Figure 7 As shown, the message processing device 700 of this embodiment includes a transaction message receiving module 710, an entity relationship identification module 720, and a transaction anomaly detection module 730.
[0104] The transaction message receiving module 710 is used to receive transaction messages related to the target transaction. In one embodiment, the transaction message receiving module 710 can be used to perform the operation S210 described above, which will not be repeated here.
[0105] The entity relationship identification module 720 is used to identify the entity relationships in the received transaction messages using a trained message recognition model, thereby obtaining the transaction entities and transaction relationships. In one embodiment, the entity relationship identification module 720 can be used to perform the operation S220 described above, which will not be repeated here.
[0106] The transaction anomaly detection module 730 is used to perform transaction anomaly detection on transaction messages based on transaction entities and transaction relationships, and obtain detection results. In one embodiment, the transaction anomaly detection module 730 can be used to perform the operation S230 described above, which will not be repeated here.
[0107] According to embodiments of this application, entity relationships are identified in received transaction messages using a trained message recognition model to obtain transaction entities and transaction relationships. This allows for transaction anomaly detection based on transaction entities and relationships, yielding detection results. Since entity recognition and relationship extraction utilize natural language processing technology to identify semantic information in messages, independent of message format, detection can be performed on messages of different formats, improving detection efficiency and solving the problem of message comparison requiring preset rules or manual processing. Furthermore, transaction entities and relationships accurately and intuitively reflect the transaction information contained in the message; detection based on transaction entities and relationships improves the accuracy of transaction anomaly detection and quickly identifies risks of illegal transactions.
[0108] According to an embodiment of this application, the transaction anomaly detection module 730 includes a comparison submodule and a transaction anomaly determination submodule. The comparison submodule compares the transaction entity and transaction relationship with historical transaction entities and historical transaction relationships identified from historical transaction messages to obtain a comparison result, wherein the transaction message and historical transaction messages are related to the same target transaction. The transaction anomaly determination submodule determines an anomaly detection result, characterizing whether a transaction message exhibits a transaction anomaly, based on the comparison result.
[0109] According to embodiments of this application, transaction messages are determined based on a first message rule, and historical transaction messages are determined based on a second message rule. The transaction anomaly determination submodule includes a parameter anomaly determination unit and a difference information representation unit. The parameter anomaly determination unit is used to determine a rule anomaly detection result indicating that the first message rule has rule parameter anomalies, provided that the comparison result characterizes the message content difference information as meeting preset difference conditions. The difference information representation unit is used to represent at least one of the following in the message content difference information: a first degree of difference between the transaction entity and historical transaction entities; and a second degree of difference between the transaction relationship and historical transaction relationships.
[0110] According to an embodiment of this application, the entity relationship identification module 720 includes a semantic feature identification submodule and a transaction relationship identification submodule. The semantic feature identification submodule performs semantic feature identification on transaction messages to obtain transaction semantic features, which represent the transaction process of the target transaction. The transaction relationship identification submodule performs transaction relationship identification on the transaction semantic features to obtain multiple transaction relationships, which represent the resource flow method or resource retention method in the transaction process of the target transaction.
[0111] According to an embodiment of this application, the transaction anomaly detection module 730 further includes a query submodule and a risk determination submodule. The query submodule is used to query a preset transaction knowledge graph based on the transaction entity and transaction relationship to obtain abnormal risk transaction entities. The risk determination submodule is used to determine a risk detection result indicating that the target transaction has abnormal transaction risk based on the abnormal risk transaction entities.
[0112] According to embodiments of this application, the system further includes an acquisition module, a processing module, an identification module, and a training module. The acquisition module acquires associated sample messages and tag data, whereby the tag data includes multiple tag relationships determined from a preset knowledge graph. The processing module processes the sample messages using the semantic feature recognition layer of the initial message recognition model to obtain sample transaction semantic features. The identification module processes the sample transaction semantic features using the relationship recognition layer of the initial message recognition model to obtain multiple sample transaction relationships. The training module trains the initial message recognition model based on the multiple sample transaction relationships and multiple tag relationships to obtain a message recognition model.
[0113] According to an embodiment of this application, the message processing apparatus 700 further includes an update module. The update module is used to update the current transaction knowledge graph using transaction relationships to obtain an updated transaction knowledge graph.
[0114] According to embodiments of this application, any plurality of modules among the transaction message receiving module 710, entity relationship identification module 720, and transaction anomaly detection module 730 can be combined into one module, or any one of these modules can be split into multiple modules. Alternatively, at least part of the functionality of one or more of these modules can be combined with at least part of the functionality of other modules and implemented in one module. According to embodiments of this application, at least one of the transaction message receiving module 710, entity relationship identification module 720, and transaction anomaly detection module 730 can be at least partially implemented as hardware circuitry, such as a field-programmable gate array (FPGA), a programmable logic array (PLA), a system-on-a-chip, a system-on-a-substrate, a system-on-package, an application-specific integrated circuit (ASIC), or any other reasonable means of integrating or packaging circuitry, or implemented in hardware or firmware, or in any one of software, hardware, and firmware implementations, or in a suitable combination of any of these. Alternatively, at least one of the transaction message receiving module 710, entity relationship identification module 720, and transaction anomaly detection module 730 may be implemented at least partially as a computer program module, which can perform corresponding functions when the computer program module is run.
[0115] Figure 8A block diagram schematically illustrates an electronic device suitable for implementing a message processing method according to an embodiment of this application.
[0116] like Figure 8 As shown, an electronic device 800 according to an embodiment of this application includes a processor 801, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 802 or a program loaded from a storage portion 808 into a random access memory (RAM) 803. The processor 801 may include, for example, a general-purpose microprocessor (e.g., a CPU), an instruction set processor and / or an associated chipset and / or a special-purpose microprocessor (e.g., an application-specific integrated circuit (ASIC)), etc. The processor 801 may also include onboard memory for caching purposes. The processor 801 may include a single processing unit or multiple processing units for performing different actions of the method flow according to an embodiment of this application.
[0117] RAM 803 stores various programs and data required for the operation of electronic device 800. Processor 801, ROM 802, and RAM 803 are interconnected via bus 804. Processor 801 executes various operations of the method flow according to embodiments of this application by executing programs in ROM 802 and / or RAM 803. It should be noted that the programs may also be stored in one or more memories other than ROM 802 and RAM 803. Processor 801 may also execute various operations of the method flow according to embodiments of this application by executing programs stored in said one or more memories.
[0118] According to embodiments of this application, the electronic device 800 may further include an input / output (I / O) interface 805, which is also connected to a bus 804. The electronic device 800 may also include one or more of the following components connected to the input / output (I / O) interface 805: an input section 806 including a keyboard, mouse, etc.; an output section 807 including a cathode ray tube (CRT), liquid crystal display (LCD), etc., and a speaker, etc.; a storage section 808 including a hard disk, etc.; and a communication section 809 including a network interface card such as a LAN card, modem, etc. The communication section 809 performs communication processing via a network such as the Internet. A drive 910 is also connected to the input / output (I / O) interface 805 as needed. A removable medium 811, such as a disk, optical disk, magneto-optical disk, semiconductor memory, etc., is installed on the drive 810 as needed so that computer programs read from it can be installed into the storage section 808 as needed.
[0119] This application also provides a computer-readable storage medium, which may be included in the device / apparatus / system described in the above embodiments; or it may exist independently and not assembled into the device / apparatus / system. The computer-readable storage medium carries one or more programs, which, when executed, implement the message processing method according to the embodiments of this application.
[0120] According to embodiments of this application, the computer-readable storage medium can be a non-volatile computer-readable storage medium, such as including but not limited to: portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof. In this application, the computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. For example, according to embodiments of this application, the computer-readable storage medium may include ROM 802 and / or RAM 803 and / or one or more memories other than ROM 802 and RAM 803 described above.
[0121] Embodiments of this application also include a computer program product comprising a computer program containing program code for performing the methods shown in the flowchart. When the computer program product is run on a computer system, the program code enables the computer system to implement the message processing method provided in the embodiments of this application.
[0122] When the computer program is executed by the processor 801, it performs the functions defined in the system / apparatus of this application embodiment. According to the embodiments of this application, the systems, apparatuses, modules, units, etc., described above can be implemented by computer program modules.
[0123] In one embodiment, the computer program may rely on a tangible storage medium such as an optical storage device or a magnetic storage device. In another embodiment, the computer program may also be transmitted and distributed in the form of signals over a network medium, and may be downloaded and installed via the communication section 809, and / or installed from a removable medium 811. The program code contained in the computer program can be transmitted using any suitable network medium, including but not limited to: wireless, wired, etc., or any suitable combination thereof.
[0124] In such an embodiment, the computer program can be downloaded and installed from a network via the communication section 809, and / or installed from the removable medium 811. When the computer program is executed by the processor 801, it performs the functions defined in the system of this application embodiment. According to the embodiments of this application, the systems, devices, apparatuses, modules, units, etc., described above can be implemented by computer program modules.
[0125] According to embodiments of this application, program code for executing the computer programs provided in the embodiments of this application can be written in any combination of one or more programming languages. Specifically, these computational programs can be implemented using high-level procedural and / or object-oriented programming languages, and / or assembly / machine languages. Programming languages include, but are not limited to, languages such as Java, C++, Python, "C", or similar programming languages. The program code can be executed entirely on the user's computing device, partially on the user's device, partially on a remote computing device, or entirely on a remote computing device or server. In cases involving remote computing devices, the remote computing device can be connected to the user's computing device via any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computing device (e.g., via the Internet using an Internet service provider).
[0126] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this application. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram or flowchart, and combinations of blocks in a block diagram or flowchart, may be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.
[0127] Those skilled in the art will understand that the features described in the various embodiments of this application can be combined and / or combined in various ways, even if such combinations or combinations are not explicitly described in this application. In particular, the features described in the various embodiments of this application can be combined and / or combined in various ways without departing from the spirit and teachings of this application. All such combinations and / or combinations fall within the scope of this application.
Claims
1. A message processing method, characterized in that, The method includes: Receive transaction messages related to the target transaction; The trained message recognition model is used to identify entity relationships in the received transaction messages to obtain the transaction entities and transaction relationships. Based on the transaction entity and transaction relationship, the transaction message is subjected to transaction anomaly detection to obtain the detection result.
2. The method according to claim 1, characterized in that, Based on the transaction entity and transaction relationship, the transaction message is subjected to transaction anomaly detection to obtain the detection results, including: The transaction entity and transaction relationship are compared with historical transaction entities and historical transaction relationships identified from historical transaction messages to obtain a comparison result, wherein the transaction message and the historical transaction message are related to the same target transaction; and Based on the comparison results, an anomaly detection result is determined to characterize whether the transaction message contains transaction anomalies.
3. The method according to claim 2, characterized in that, The transaction message is determined based on the first message rule, and the historical transaction message is determined based on the second message rule; The determination of anomaly detection results, which characterize whether the transaction message exhibits transaction anomalies, based on the comparison results includes: If the comparison result indicates that the message content difference information meets the preset difference conditions, a rule anomaly detection result is determined, indicating that the first message rule has abnormal rule parameters. The message content difference information represents at least one of the following: The first degree of difference between the transaction entity and the historical transaction entity; The second degree of difference between the transaction relationship and the historical transaction relationship.
4. The method according to claim 1, characterized in that, The trained message recognition model is used to identify entity relationships in received transaction messages, resulting in transaction entities and transaction relationships, including: The transaction message is subjected to semantic feature recognition to obtain transaction semantic features, which represent the transaction process of the target transaction; The transaction semantic features are used to identify transaction relationships, resulting in multiple transaction relationships, which represent the resource transfer or resource retention methods in the transaction process of the target transaction.
5. The method according to claim 4, characterized in that, Based on the transaction entity and transaction relationship, the transaction message is subjected to transaction anomaly detection to obtain the detection results, including: Based on the transaction entities and transaction relationships, a query is performed in a pre-defined transaction knowledge graph to obtain abnormal risk transaction entities; and Based on the abnormal risk transaction entity, a risk detection result indicating that the target transaction has abnormal transaction risk is determined.
6. The method according to claim 4, characterized in that, The message recognition model was trained based on the following operations: Obtain associated sample messages and tag data, wherein the tag data includes multiple tag relationships determined from a preset knowledge graph; The sample message is processed using the semantic feature recognition layer of the initial message recognition model to obtain the semantic features of the sample transaction; The semantic features of the sample transactions are processed by the relation recognition layer of the initial message recognition model to obtain multiple sample transaction relationships. The initial message recognition model is trained based on the multiple sample transaction relationships and the multiple label relationships to obtain the message recognition model.
7. The method according to claim 1 or 4, characterized in that, The method further includes: The current transaction knowledge graph is updated using the transaction relationships to obtain the updated transaction knowledge graph.
8. A message processing apparatus, characterized in that, The device includes: The transaction message receiving module is used to receive transaction messages related to the target transaction; The entity relationship identification module is used to identify the entity relationships in the received transaction messages using a trained message recognition model, thereby obtaining the transaction entities and transaction relationships. The transaction anomaly detection module is used to perform transaction anomaly detection on the transaction message based on the transaction entity and transaction relationship, and obtain the detection result.
9. An electronic device, comprising: One or more processors; Memory, used to store one or more computer programs. The characteristic feature is that the one or more processors execute the one or more computer programs to implement the steps of the method according to any one of claims 1 to 7.
10. A computer-readable storage medium having a computer program or instructions stored thereon, characterized in that, When the computer program or instructions are executed by a processor, they implement the steps of the method according to any one of claims 1 to 7.
11. A computer program product, comprising a computer program or instructions, characterized in that, When the computer program or instructions are executed by a processor, they implement the steps of the method according to any one of claims 1 to 7.