Multi-dimensional anti-fraud and risk control auditing method and system for large transaction
By extracting multi-dimensional features and decomposing transaction data using wavelet transform, combined with kernel density estimation and device environment analysis, and employing a dynamic causal reasoning fusion method and progressive active learning verification, the problem of complex fraud identification and device counterfeiting in large transactions is solved, achieving efficient and accurate risk control auditing.
Patent Information
- Application Number
- CN202511525547.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-24
- Publication Date
- 2025-12-30
- Estimated Expiration
- 2045-10-24
AI Technical Summary
Existing risk control systems struggle to identify complex and ever-changing fraud tactics in large transactions, especially progressive fraud and device spoofing. Furthermore, they lack intelligent interactive verification mechanisms, leading to high false alarm rates and a decline in user experience.
By extracting multi-dimensional features and decomposing transaction data using wavelet transform, and constructing a probability distribution model of transaction behavior using kernel density estimation, an incremental learning algorithm is used to maintain the device fingerprint feature library, a Markov decision process is used to model device state transitions, and a dynamic causal reasoning fusion method and progressive active learning verification are combined to achieve accurate assessment of transaction risks.
It significantly improved the accuracy of large-value transaction fraud detection, reduced the false alarm rate, enhanced the system's adaptability to new fraud methods, and optimized user experience and refined risk control strategies.
Smart Images

Figure CN120996940B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of financial security technology, and in particular to a multi-dimensional anti-fraud and risk control audit method and system for large transactions. Background Technology
[0002] With the rapid development of e-commerce and internet finance, the frequency and scale of large-value transactions are constantly increasing, while transaction fraud methods are also becoming increasingly complex and varied. Traditional transaction risk control systems mainly rely on fixed rules and simple statistical models to identify suspicious transactions, which are insufficient to cope with the current complex and ever-changing fraud methods. Because large-value transactions involve substantial sums, fraud can cause significant economic losses to both users and financial institutions. Therefore, establishing an efficient and accurate anti-fraud and risk control system for large-value transactions has become an important research direction in the field of financial security.
[0003] Currently, large-transaction risk control systems have the following main defects and shortcomings in practical applications:
[0004] Existing risk control systems typically employ static feature analysis, lacking the ability to deeply mine and analyze transaction time-series data on multiple scales. They are unable to effectively capture abnormal fluctuation patterns in transaction behavior, and in particular, they struggle to identify elaborate, progressive fraud schemes. These frauds often build trust through long-term small-amount transactions before committing large-scale fraud.
[0005] The current device risk assessment methods are too simplistic, relying mainly on static information such as IP addresses and device identifiers. They lack dynamic analysis of device behavior and state transitions, making it difficult to deal with advanced fraud methods such as device impersonation and identity theft. In particular, the risk identification rate is low in complex scenarios involving cross-device collaborative crimes.
[0006] Traditional risk control systems mostly use fixed threshold judgment mechanisms, lacking intelligent interactive verification mechanisms and adaptive learning capabilities. This often leads to high false alarm rates and a decline in user experience. Especially when dealing with large legitimate transactions, they may reject normal transactions due to excessive control or allow fraudulent transactions due to insufficient control, making it difficult to achieve a good balance between security and user experience. Summary of the Invention
[0007] The embodiments of the present invention provide a multi-dimensional anti-fraud and risk control audit method and system for large transactions, which can solve the problems in the prior art.
[0008] A first aspect of this invention provides a multi-dimensional anti-fraud and risk control audit method for large-value transactions, comprising:
[0009] The historical transaction data of the transaction initiator and the transaction recipient are segmented according to time windows, and multi-dimensional features are extracted from the transaction behavior within each time window; wavelet transform is used to decompose the transaction amount sequence into multiple scales to extract fluctuation features at different frequencies; a probability distribution model of transaction behavior is constructed through kernel density estimation to calculate the degree of deviation between the current transaction behavior and the historical distribution and generate an anomaly score.
[0010] Acquire the device environment data of the transaction initiator, maintain the device fingerprint feature library and update the device credit score using an incremental learning algorithm; model the device state transition sequence through Markov decision process and calculate the probability score of the current state transition; construct the device behavior trajectory and generate the device credibility score by calculating the trajectory similarity.
[0011] Based on the multidimensional features and the fluctuation features, a feature similarity matrix is constructed, and combined with the behavior anomaly score, the device credit score, the probability score and the device credibility score, an initial risk score is calculated using a dynamic causal reasoning fusion method.
[0012] When the initial risk score exceeds the warning threshold, a targeted transaction verification question is generated, the verification answer from the transaction initiator is obtained, and based on the verification answer and the initial risk score, a progressive active learning verification method is used to calculate the transaction risk score.
[0013] The risk control strategy is determined based on the comparison between the transaction risk score and the preset transaction risk score threshold, and the option is to trigger a manual review process, perform secondary verification of the transaction initiator's identity, or directly allow the transaction.
[0014] The historical transaction data of both the transaction initiator and receiver are segmented according to time windows, and multi-dimensional features are extracted from the transaction behavior within each time window. Wavelet transform is used to perform multi-scale decomposition of the transaction amount sequence to extract fluctuation features at different frequencies. A probability distribution model of transaction behavior is constructed through kernel density estimation to calculate the degree of deviation between the current transaction behavior and the historical distribution, generating anomaly scores including:
[0015] The historical transaction data is segmented by an adaptive time window segmentation method. The weighted sum of the variance of the transaction behavior within each segment and the number of segments is used as the evaluation index for window segmentation, thus dividing the historical transaction data into multiple continuous time windows.
[0016] The statistical characteristics are obtained by calculating the mean, standard deviation, and frequency of transaction amounts within the time window, and the time series characteristics are obtained by calculating the distribution density and time interval of transaction occurrence. The transaction amount sequence is subjected to three-level wavelet decomposition to obtain the decomposition coefficients of each level. The sum of squares, probability distribution entropy, and standard deviation of the decomposition coefficients of each level are calculated to obtain the energy characteristics, entropy characteristics, and volatility characteristics. The statistical characteristics, the time series characteristics, and the energy characteristics, entropy characteristics, and volatility characteristics are combined in a dimension reduction manner using principal component analysis to form a multi-scale volatility characteristic vector.
[0017] Calculate the standard deviation and interquartile range of the transaction amount in the historical transaction data, select the smaller of the standard deviation and interquartile range as the product of the power function of the number of transaction samples as the bandwidth parameter for kernel density estimation, use the bandwidth parameter and Gaussian kernel function to calculate the probability density distribution of historical transaction behavior, and calculate the KL divergence value between the current transaction behavior data and the probability density distribution.
[0018] The volatility feature in the multi-scale volatility feature vector is weighted and combined with the KL divergence value to generate an anomaly score for trading behavior.
[0019] Acquire the device environment data of the transaction initiator, maintain the device fingerprint feature database and update the device credit score using an incremental learning algorithm; model the device state transition sequence through a Markov decision process and calculate the probability score of the current state transition; construct the device behavior trajectory, and generate the device credibility score by calculating trajectory similarity, including:
[0020] The hardware and software feature vectors of the device of the transaction initiator are collected and combined to form an initial device fingerprint feature. Based on the initial device fingerprint feature, the historical credit score of the device is matched from the device fingerprint feature library.
[0021] The device's real-time credibility is calculated based on the device's real-time transaction behavior data. The learning rate parameter is set to adjust the weight ratio between the historical credit score and the real-time credibility. The device's credit score at the current moment is then updated incrementally.
[0022] The system continuously collects equipment operation status data and classifies the equipment status into four types: normal, suspicious, risky, and unknown. Based on the operation status data, the system determines the equipment status type at each time moment, counts the transition frequency between each status type between adjacent time moments, calculates the status transition probability matrix based on the transition frequency, analyzes the change pattern of the equipment status sequence using the status transition probability matrix, and calculates the probability score of status transition.
[0023] The system records the device's geographic location coordinates, network environment parameters, and process list in real time, and assembles them into a current device behavior trajectory in chronological order. It then selects historical device behavior trajectories from the device behavior trajectory database, calculates the Euclidean distance between the current and historical device behavior trajectories in the spatiotemporal dimension, and calculates a behavior trajectory similarity score based on this Euclidean distance. Finally, it compares the behavior trajectory similarity score with pre-labeled credibility tags, calculates the optimal linear transformation parameters using the least squares method, and converts the behavior trajectory similarity score into a device credibility score.
[0024] Based on the multidimensional features and the fluctuation features, a feature similarity matrix is constructed. Then, combining the behavioral anomaly score, the device credit score, the probability score, and the device credibility score, an initial risk score is calculated using a dynamic causal reasoning fusion method, including:
[0025] The multidimensional features and fluctuation features are combined to form an initial feature matrix. The mean and standard deviation of each feature dimension in the initial feature matrix are calculated and standardized to obtain a standardized feature matrix. The cosine similarity and domain knowledge distance between the feature vectors in the standardized feature matrix are calculated to obtain a feature similarity matrix.
[0026] The feature similarity matrix is combined with the behavior anomaly score, device credit score, probability score, and device credibility score to form a feature set. Each feature in the feature set is used as a node. The initial edge weights between the feature nodes are calculated by combining the preset prior probability. The feature nodes and the initial edge weights are used to construct an initial causal graph.
[0027] Based on the initial causal graph, the conditional mutual information between feature nodes is calculated. When the conditional mutual information is less than the independence determination threshold, the corresponding edge is deleted. Vector perturbation is applied to the feature nodes connected by the remaining edges to obtain the intervention effect. The intervention effect is weighted and combined with the original edge weights to update the edge weights and obtain the dynamic causal graph.
[0028] In the dynamic causal graph, the direct causal strength value between adjacent nodes is calculated, and the indirect causal strength value is calculated by propagating along the node path. The weighted sum of the direct causal strength and the indirect causal strength is used as the total causal strength of the feature node by using an adaptive weighting coefficient. A normal distribution random perturbation is added to the feature set to generate a counterfactual feature set, and the total counterfactual causal strength value is calculated.
[0029] The initial risk score is obtained by weighting and adjusting the difference between the total causal strength value and the counterfactual total causal strength value and then mapping it through the Sigmoid function.
[0030] Calculating the direct causal strength value between adjacent nodes in the dynamic causal graph, and calculating the indirect causal strength value along the node path, includes:
[0031] Extract the temporal state sequence of adjacent nodes in the dynamic causal graph, count the occurrence frequency of each node state to obtain the marginal distribution probability of the node state, divide the state sequence of each pair of adjacent nodes into training sample pairs according to the sliding time window, use support vector regression with radial basis function kernel to train and obtain the conditional probability density function, perform discrete sampling on the conditional probability density function to obtain the local transition matrix, multiply the local transition matrix with the marginal distribution probability of the corresponding node to obtain the joint probability distribution of the node pair, and calculate the difference of conditional expectation under the intervention and non-intervention conditions based on the joint probability distribution to obtain the direct causal strength value between adjacent nodes.
[0032] In the dynamic causal graph, depth-first search is used to identify all reachable paths between any two nodes and store them as a path set. The direct causal strength values between adjacent nodes on each path are multiplied sequentially according to the node order to obtain the propagation coefficient of the path. An exponential decay factor is set based on the path length, and the decay factor is calculated by raising the number of path nodes to the power of the exponential decay factor to obtain the decay coefficient. The propagation coefficient and the decay coefficient are multiplied to obtain the indirect causal strength value of the path.
[0033] When the initial risk score exceeds the warning threshold, a targeted transaction verification question is generated, the verification answer from the transaction initiator is obtained, and based on the verification answer and the initial risk score, a progressive active learning verification method is used to calculate the transaction risk score, including:
[0034] The verification questions are stored in a hierarchical verification question pool by weighting the information gain, complexity and timeliness. The state entropy is calculated by taking the negative logarithm of the probability distribution of the initial risk score. The expected information gain of each question in the hierarchical verification question pool is calculated using the state entropy. The question with the largest expected information gain is selected as the first round verification question and sent to the transaction initiator. The confidence level of the first round verification answer returned by the transaction initiator is evaluated to obtain the first round confidence value.
[0035] The weighted sum of the first round confidence value and the initial risk score is multiplied by a preset coefficient to determine the subsequent verification rounds. The initial risk state probability distribution is weighted and corrected using the first round confidence value to obtain the updated risk state probability distribution. The correlation between the next layer verification problem and the updated risk state probability distribution is calculated to obtain the sampling probability. The problem with the highest sampling probability is selected as the next round verification problem.
[0036] Repeatedly perform the confidence assessment of the verification answer, the weighted correction of the probability distribution of the risk state, and the selection of the verification question until the verification round is completed. The confidence values of the verification answers in each round are used to form a verification feature vector. The verification feature vector is then subjected to a nonlinear transformation and weighted together with the initial risk score to obtain the transaction risk score.
[0037] A second aspect of this invention provides a multi-dimensional anti-fraud and risk control audit system for large-value transactions, comprising:
[0038] The first unit is used to segment the historical transaction data of the transaction initiator and the transaction recipient according to time windows, extract multi-dimensional features of the transaction behavior in each time window; use wavelet transform to perform multi-scale decomposition of the transaction amount sequence to extract fluctuation features at different frequencies; construct a probability distribution model of transaction behavior through kernel density estimation, calculate the degree of deviation between the current transaction behavior and the historical distribution, and generate a behavior anomaly score.
[0039] The second unit is used to acquire the device environment data of the transaction initiator, maintain the device fingerprint feature library and update the device credit score using an incremental learning algorithm; model the device state transition sequence through Markov decision process and calculate the probability score of the current state transition; construct the device behavior trajectory and generate the device credibility score by calculating the trajectory similarity.
[0040] The third unit is used to construct a feature similarity matrix based on the multidimensional features and the fluctuation features, and to calculate the initial risk score by combining the behavior anomaly score, the device credit score, the probability score and the device credibility score using a dynamic causal reasoning fusion method.
[0041] The fourth unit is used to generate targeted transaction verification questions when the initial risk score exceeds the warning threshold, obtain the verification answer from the transaction initiator, and calculate the transaction risk score based on the verification answer and the initial risk score using a progressive active learning verification method.
[0042] The fifth unit is used to determine the risk control strategy based on the comparison result between the transaction risk score and the preset transaction risk score threshold, and to choose to trigger the manual review process, verify the identity of the transaction initiator for a second time, or directly allow the transaction.
[0043] A third aspect of the present invention,
[0044] An electronic device is provided, comprising:
[0045] processor;
[0046] Memory used to store processor-executable instructions;
[0047] The processor is configured to invoke instructions stored in the memory to execute the aforementioned method.
[0048] Fourth aspect of the embodiments of the present invention,
[0049] A computer-readable storage medium is provided, having stored thereon computer program instructions that, when executed by a processor, implement the aforementioned method.
[0050] The beneficial effects of this application are as follows:
[0051] This invention extracts multi-dimensional features and decomposes transaction data using wavelet transform, and constructs a probability distribution model of transaction behavior by combining kernel density estimation. This model can accurately identify abnormal transaction patterns, significantly improve the accuracy of large-value transaction fraud detection, and effectively reduce the false alarm rate.
[0052] This invention introduces equipment environment data analysis and incremental learning algorithms to maintain an equipment fingerprint feature database. Combined with Markov decision processes and equipment behavior trajectory analysis, it realizes dynamic trust assessment of the transaction environment, enhances the system's adaptability to new fraud methods, and improves the overall defense capability of the risk control system.
[0053] This invention employs a dynamic causal reasoning fusion method and a progressive active learning verification mechanism, which intelligently triggers different levels of verification measures based on the degree of risk. This enables refined adjustments to risk control strategies, optimizes user experience while ensuring transaction security, and improves system operating efficiency and resource utilization. Attached Figure Description
[0054] Figure 1 This is a flowchart illustrating the multi-dimensional anti-fraud and risk control audit method for large transactions according to an embodiment of the present invention.
[0055] Figure 2 A diagram showing the accuracy comparison of different algorithms at various false positive rates;
[0056] Figure 3 This diagram illustrates the performance comparison between the dynamic causal reasoning fusion method and traditional methods in risk detection. Detailed Implementation
[0057] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0058] The technical solution of the present invention will be described in detail below with reference to specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments.
[0059] Figure 1 This is a flowchart illustrating the multi-dimensional anti-fraud and risk control audit method for large transactions according to an embodiment of the present invention. Figure 1 As shown, the method includes:
[0060] The historical transaction data of the transaction initiator and the transaction recipient are segmented according to time windows, and multi-dimensional features are extracted from the transaction behavior within each time window; wavelet transform is used to decompose the transaction amount sequence into multiple scales to extract fluctuation features at different frequencies; a probability distribution model of transaction behavior is constructed through kernel density estimation to calculate the degree of deviation between the current transaction behavior and the historical distribution and generate an anomaly score.
[0061] Acquire the device environment data of the transaction initiator, maintain the device fingerprint feature library and update the device credit score using an incremental learning algorithm; model the device state transition sequence through Markov decision process and calculate the probability score of the current state transition; construct the device behavior trajectory and generate the device credibility score by calculating the trajectory similarity.
[0062] Based on the multidimensional features and the fluctuation features, a feature similarity matrix is constructed, and combined with the behavior anomaly score, the device credit score, the probability score and the device credibility score, an initial risk score is calculated using a dynamic causal reasoning fusion method.
[0063] When the initial risk score exceeds the warning threshold, a targeted transaction verification question is generated, the verification answer from the transaction initiator is obtained, and based on the verification answer and the initial risk score, a progressive active learning verification method is used to calculate the transaction risk score.
[0064] The risk control strategy is determined based on the comparison between the transaction risk score and the preset transaction risk score threshold, and the option is to trigger a manual review process, perform secondary verification of the transaction initiator's identity, or directly allow the transaction.
[0065] In one optional implementation, the historical transaction data of the transaction initiator and receiver are segmented according to time windows, and multi-dimensional features are extracted from the transaction behavior within each time window; wavelet transform is used to perform multi-scale decomposition of the transaction amount sequence to extract fluctuation features at different frequencies; a probability distribution model of the transaction behavior is constructed through kernel density estimation, the degree of deviation between the current transaction behavior and the historical distribution is calculated, and an abnormal behavior score is generated, including:
[0066] Segment the historical transaction data through the adaptive time window segmentation method, and use the weighted sum of the variance of the transaction behavior within the segment and the number of segments as the window division evaluation index to divide the historical transaction data into multiple consecutive time windows;
[0067] Calculate the mean, standard deviation, and transaction frequency of the transaction amount within the time window to obtain statistical features, and calculate the distribution density and time interval of the transaction occurrence time to obtain time series features; perform three-layer wavelet decomposition on the transaction amount sequence to obtain the decomposition coefficients of each layer, and calculate the sum of squares, probability distribution entropy, and standard deviation of the decomposition coefficients of each layer to obtain energy features, entropy features, and volatility features. Use the principal component analysis method to reduce the dimension and combine the statistical features, the time series features, the energy features, the entropy features, and the volatility features to form a multi-scale volatility feature vector;
[0068] Calculate the standard deviation and interquartile range of the transaction amount in the historical transaction data, select the product of the smaller value between the standard deviation and the interquartile range and the power function of the number of transaction samples as the bandwidth parameter of kernel density estimation, use the bandwidth parameter and the Gaussian kernel function to calculate the probability density distribution of historical transaction behaviors, and calculate the KL divergence value between the current transaction behavior data and the probability density distribution;
[0069] Perform a weighted combination of the volatility feature in the multi-scale volatility feature vector and the KL divergence value to generate an anomaly score for the transaction behavior.
[0070] This embodiment provides a method for detecting abnormal transaction behaviors. This method realizes the accurate identification of abnormal transaction behaviors through multi-dimensional feature extraction and probability distribution modeling of transaction data.
[0071] In an actual application scenario, first obtain the historical transaction data between user A and user B, which includes information such as transaction time, transaction amount, transaction type, etc. For these historical transaction data, use the adaptive time window segmentation method for processing. Specifically, set an initial time window size of 7 days, and then calculate the variance of the transaction behavior within this window, denoted as V1. Then adjust the window size to 14 days and calculate the variance of the transaction behavior within the new window, denoted as V2. By comparing the sizes of V1 and V2, and considering the influence of the number of segments N1 and N2, calculate the evaluation indexes E1 = α×V1 + β×(1 / N1) and E2 = α×V2 + β×(1 / N2), where α = 0.7 and β = 0.3 are weight parameters. If E1 < E2, then select 7 days as the final window size; otherwise, continue to test larger windows, such as 21 days, 30 days, etc., until the optimal window size is found. For example, through iterative comparison, it is finally determined that 14 days is the best time window size, and the 180-day historical data is divided into 13 consecutive time windows.
[0072] For each time window, multidimensional features are extracted. Taking the third time window as an example, this window contains 27 transaction records. Statistical characteristics of these transactions are calculated, including a mean transaction amount of 3250 yuan, a standard deviation of 750 yuan, and a transaction frequency of 1.93 times / day. Simultaneously, the distribution of transaction times is analyzed, calculating a transaction density ratio of 3.5:1 between weekdays and non-weekdays, an average time interval between adjacent transactions of 8.7 hours, and a longest interval of 52 hours, forming time-series features.
[0073] For the transaction amount sequence, a three-level wavelet decomposition is performed. Specifically, the db4 wavelet basis is used to perform a discrete wavelet transform on the transaction amount sequence to obtain three levels of decomposition coefficients. The first level decomposition yields approximate coefficients a1 and detail coefficients d1. The second level further decomposes a1 to obtain a2 and d2, and the third level decomposes a2 to obtain a3 and d3. The energy characteristics of each level's detail coefficients are calculated, i.e., the sum of squares of coefficients d1, d2, and d3, which are 235000, 127500, and 42800, respectively. The probability distribution entropy of each level's coefficients is calculated, with entropy values of 4.82, 3.75, and 2.21 for d1, d2, and d3, respectively. The standard deviations of each level's coefficients are calculated, with standard deviations of 485, 352, and 187 for d1, d2, and d3, respectively; these constitute the volatility characteristics.
[0074] The statistical, temporal, energy, entropy, and volatility characteristics described above are combined to form a 37-dimensional feature vector. Principal component analysis is then used to reduce the dimensionality of this 37-dimensional feature vector to 12 dimensions, retaining 95% of the original features' information content, thus forming a multi-scale volatility feature vector F.
[0075] A probability density model is constructed based on historical transaction data. First, the standard deviation of the transaction amount σ = 750 yuan and the interquartile range IQR = 1050 yuan are calculated, and the smaller value, min(σ,IQR) = 750 yuan, is taken. Considering the sample size n = 27, the bandwidth parameter h = 750 × n is set. -0.2 =750 × 0.516 = 387 yuan. Using this bandwidth parameter and Gaussian kernel function, a probability density distribution model P(x) for historical transaction amounts is constructed.
[0076] When a new transaction of 8500 yuan is detected, the KL divergence between this transaction and the historical probability distribution is calculated. Specifically, the new transaction amount is substituted into the probability density function P(x), yielding the probability value P(8500) = 0.00012. Referring to the probability value Q = 0.0023 for the same degree of deviation under the standard normal distribution, the KL divergence value is calculated as KL = log(Q / P(8500)) = log(0.0023 / 0.00012) = 2.94.
[0077] Finally, the volatility feature (standard deviation feature) in the multi-scale volatility feature vector F is weighted and combined with the KL divergence value to generate an anomaly score S = γ × (d1 standard deviation / historical standard deviation) + δ × KL divergence = (0.4 × (485 / 750) + 0.6 × 2.94) = 0.258 + 1.764 = 2.022. An anomaly threshold of 1.8 is set. Since the anomaly score of this transaction is 2.022 > 1.8, it is determined to be an anomaly transaction.
[0078] In practical applications, the weight parameters α, β, γ, δ, and the anomaly threshold are dynamically adjusted based on the transaction characteristics of different user groups to improve the accuracy of anomaly detection. Furthermore, the model parameters can be continuously optimized based on feedback mechanisms to enhance detection performance, ensuring that anomaly scores accurately reflect the risk level of transaction behavior.
[0079] Figure 2 A diagram showing the accuracy comparison of different algorithms at various false positive rates:
[0080] This graph compares the accuracy of three different algorithms under various false positive rates. The horizontal axis represents the false positive rate, ranging from 0.00 to 0.10; the vertical axis represents the accuracy percentage, ranging from 70% to 100%. Three different shapes of data points and line types are used to distinguish the algorithms: circular solid lines represent the present invention, square dashed lines represent the random forest method, and triangular dashed lines represent the decision tree method. The graph clearly shows that, under all false positive rate conditions, the accuracy of the present invention is consistently higher than the other two methods, remaining above 90%, and generally increasing with the false positive rate, although with slight fluctuations. The random forest method performs second best, with an accuracy between 85% and 90%, also improving with the false positive rate, but showing a slight decrease in the 0.06 to 0.08 range. The decision tree method has the lowest accuracy, remaining in the 80%-85% range, and its performance curve fluctuates more significantly. The figure clearly shows that the performance differences among the three algorithms are particularly pronounced under conditions of low false positive tolerance (low false positive rate). While the accuracy of each algorithm improves with increasing acceptable false positive rate, performance gaps still exist. This result is of significant reference value for selecting appropriate algorithm models in practical applications, especially in security fields or financial risk control systems that are sensitive to false positives.
[0081] In one optional implementation, the device environment data of the transaction initiator is obtained; an incremental learning algorithm is used to maintain the device fingerprint feature database and update the device credit score; a Markov decision process is used to model the device state transition sequence, and the probability score of the current state transition is calculated; a device behavior trajectory is constructed, and a device credibility score is generated by calculating the trajectory similarity, including:
[0082] The hardware and software feature vectors of the device of the transaction initiator are collected and combined to form an initial device fingerprint feature. Based on the initial device fingerprint feature, the historical credit score of the device is matched from the device fingerprint feature library.
[0083] The device's real-time credibility is calculated based on the device's real-time transaction behavior data. The learning rate parameter is set to adjust the weight ratio between the historical credit score and the real-time credibility. The device's credit score at the current moment is then updated incrementally.
[0084] The system continuously collects equipment operation status data and classifies the equipment status into four types: normal, suspicious, risky, and unknown. Based on the operation status data, the system determines the equipment status type at each time moment, counts the transition frequency between each status type between adjacent time moments, calculates the status transition probability matrix based on the transition frequency, analyzes the change pattern of the equipment status sequence using the status transition probability matrix, and calculates the probability score of status transition.
[0085] The system records the device's geographic location coordinates, network environment parameters, and process list in real time, and assembles them into a current device behavior trajectory in chronological order. It then selects historical device behavior trajectories from the device behavior trajectory database, calculates the Euclidean distance between the current and historical device behavior trajectories in the spatiotemporal dimension, and calculates a behavior trajectory similarity score based on this Euclidean distance. Finally, it compares the behavior trajectory similarity score with pre-labeled credibility tags, calculates the optimal linear transformation parameters using the least squares method, and converts the behavior trajectory similarity score into a device credibility score.
[0086] This invention provides a security risk control method based on device fingerprints and behavioral trajectories, including technical means such as constructing a device fingerprint feature library, updating device credit scores, modeling state transition sequences, and calculating the credibility of behavioral trajectories.
[0087] This method first collects hardware and software feature vectors of the device initiating the transaction to form an initial device fingerprint. The hardware feature vector includes information such as CPU model, memory capacity, hard drive serial number, screen resolution, and MAC address; the software feature vector includes information such as operating system version, browser type and version, list of installed applications, and system font library. For example, for a device, its hardware characteristics might be "Intel i7-9750H, 16GB, WD-5000LPCX-123456, 1920x1080, 00:1A:2B:3C:4D:5E", and its software characteristics might be "Windows 10 Pro 21H2, Chrome 96.0.4664.110, App1&App2&App3, SimSun&Arial&Times New Roman". These feature vectors are hashed and combined into a fingerprint signature "f7d9e5b2c31a8d60". The historical credit score of the device is retrieved from the device fingerprint feature database using this signature. Let's assume the historical credit score is 85.
[0088] Next, the device's real-time credibility is calculated based on its real-time transaction behavior data. This data includes transaction amount, frequency, type, and time distribution. For example, if the device was detected to have completed 5 transactions in the past 24 hours, with transaction amounts of 100 yuan, 200 yuan, 150 yuan, 180 yuan, and 500 yuan respectively, and the transaction intervals were normal with no abnormally high-frequency operations, the calculated real-time credibility score is 90. Setting the learning rate parameter α=0.3, the current device credit score is calculated as 86.5 (85×0.7+90×0.3=86.5) using the formula "Current Credit Score = Historical Credit Score × (1-α) + Real-time Credibility × α". This updated credit score will be stored in the device's fingerprint feature database for subsequent risk control decisions.
[0089] Continuously collect device operational status data, including metrics such as CPU utilization, memory usage, network connections, and the number of abnormal processes. Based on these metrics, the device status is categorized into four types: normal, suspicious, risky, and unknown. For example, when CPU utilization is below 60%, memory usage is below 70%, network connections are below 50, and there are no abnormal processes, it is classified as a "normal" state; when CPU utilization reaches 60%-80%, memory usage reaches 70%-85%, network connections reach 50-100, or there are 1-2 suspicious processes, it is classified as a "suspicious" state; when CPU utilization exceeds 80%, memory usage exceeds 85%, network connections exceed 100, or there are 3 or more suspicious processes, it is classified as a "risky" state; when complete operational status data cannot be obtained, it is classified as an "unknown" state.
[0090] Record the device's state type at each sampling time and count the transition frequency between state types between adjacent time points. Assuming the observed state sequence over 10 consecutive time points is "Normal-Normal-Suspicious-Suspicious-Normal-Normal-Suspicious-Risk-Suspicious", the state transition frequency statistics are as follows: Normal to Normal 3 times, Normal to Suspicious 1 time, Suspicious to Suspicious 1 time, Suspicious to Normal 1 time, Suspicious to Risk 1 time, Risk to Suspicious 1 time. Based on these transition frequencies, calculate the state transition probability matrix. For example, the probability of transitioning from "Normal" to "Normal" is 0.75 (3 / 4), and the probability of transitioning from "Normal" to "Suspicious" is 0.25 (1 / 4). When the device's current state is observed to be "Suspicious" and the previous state was "Normal", querying the state transition probability matrix reveals a transition probability of 0.25, with a corresponding probability score of 75 points (100 - 0.25 × 100).
[0091] The system records the device's geographic location coordinates, network environment parameters, process list, and other information in real time, arranging them into a current device behavior trajectory in chronological order. For example, the device's behavior trajectory within 10 minutes might be "(116.307,39.984,WiFi-A,P1&P2&P3)-(116.308,39.985,WiFi-A,P1&P2&P4)-(116.310,39.987,WiFi-B,P1&P5&P6)". The system then selects a historical behavior trajectory for the device from the device behavior trajectory database, such as "(116.306,39.983,WiFi-A,P1&P2&P3)-(116.307,39.984,WiFi-A,P1&P2&P3)-(116.309,39.986,WiFi-B,P1&P5&P6)".
[0092] Calculate the Euclidean distance between the current trajectory and historical trajectories in the spatiotemporal dimension. For location coordinates, calculate the distance to the coordinates corresponding to each time point; for example, the distance to the first point is √[(116.307-116.306)²+(39.984-39.983)²]=0.0014. For network environments, compare whether the network identifiers are the same; if they are the same, record 0, and if they are different, record 1. For process lists, calculate the Jaccard similarity; if the process lists of the first point are completely identical, the similarity is 1, and the distance is 0. The overall Euclidean distance obtained by combining the distances of all dimensions is 0.0152.
[0093] Based on the spatiotemporal Euclidean distance, a behavioral trajectory similarity score is calculated, such as 93 points (the smaller the distance, the higher the score). This similarity score is compared with a pre-labeled credibility tag (such as 95 points). The linear transformation parameters a=0.95 and b=2 are calculated using the least squares method. The behavioral trajectory similarity score is converted into a device credibility score using the formula "Device Credibility Score = a × Similarity Score + b", which is 93 × 0.95 + 2 = 90.35 points.
[0094] Ultimately, by combining equipment credit scores, state transition probability scores, and equipment trustworthiness scores, the transaction risk level is determined, providing a basis for risk control decisions. This method effectively identifies fraud risks and improves transaction security through multi-dimensional analysis of equipment characteristics and behavioral patterns.
[0095] In one optional implementation, a feature similarity matrix is constructed based on the multidimensional features and the fluctuation features. Then, combining the behavioral anomaly score, the device credit score, the probability score, and the device credibility score, an initial risk score is calculated using a dynamic causal reasoning fusion method, including:
[0096] The multidimensional features and fluctuation features are combined to form an initial feature matrix. The mean and standard deviation of each feature dimension in the initial feature matrix are calculated and standardized to obtain a standardized feature matrix. The cosine similarity and domain knowledge distance between the feature vectors in the standardized feature matrix are calculated to obtain a feature similarity matrix.
[0097] The feature similarity matrix is combined with the behavior anomaly score, device credit score, probability score, and device credibility score to form a feature set. Each feature in the feature set is used as a node. The initial edge weights between the feature nodes are calculated by combining the preset prior probability. The feature nodes and the initial edge weights are used to construct an initial causal graph.
[0098] Based on the initial causal graph, the conditional mutual information between feature nodes is calculated. When the conditional mutual information is less than the independence determination threshold, the corresponding edge is deleted. Vector perturbation is applied to the feature nodes connected by the remaining edges to obtain the intervention effect. The intervention effect is weighted and combined with the original edge weights to update the edge weights and obtain the dynamic causal graph.
[0099] In the dynamic causal graph, the direct causal strength value between adjacent nodes is calculated, and the indirect causal strength value is calculated by propagating along the node path. The weighted sum of the direct causal strength and the indirect causal strength is used as the total causal strength of the feature node by using an adaptive weighting coefficient. A normal distribution random perturbation is added to the feature set to generate a counterfactual feature set, and the total counterfactual causal strength value is calculated.
[0100] The initial risk score is obtained by weighting and adjusting the difference between the total causal strength value and the counterfactual total causal strength value and then mapping it through the Sigmoid function.
[0101] The implementation process of constructing a feature similarity matrix based on multidimensional features and fluctuation features, and combining behavioral anomaly score, device credit score, probability score and device credibility score, and using dynamic causal reasoning fusion method to calculate the initial risk score is as follows.
[0102] The initial feature matrix is composed of multidimensional features and volatility features. In practical applications, multidimensional features may include user operation frequency, transaction amount distribution, and changes in login geographical location, while volatility features may include transaction amount volatility and operation time interval volatility. For example, for user A, their initial feature matrix might contain multidimensional data such as an operation frequency of 5 times per hour, an average transaction amount of 200 yuan, and a transaction amount volatility of 30%. The mean and standard deviation are calculated for each feature dimension in the initial feature matrix. For example, if the operation frequency has a mean of 3 times / hour and a standard deviation of 1.2 times / hour, standardization is performed to obtain a standardized feature matrix. Standardization converts each feature value into a value with a mean of 0 and a standard deviation of 1, facilitating subsequent similarity calculations.
[0103] Calculate the cosine similarity and domain knowledge distance between eigenvectors in the standardized feature matrix. Cosine similarity measures vector similarity by calculating the cosine of the angle between the vectors, with a value ranging from -1 to 1; a larger value indicates greater similarity. Domain knowledge distance is based on the feature association degree set according to business experience. For example, the domain knowledge distance between transaction amount and account balance can be set to 0.2, indicating a strong association. The cosine similarity and domain knowledge distance are weighted in a 7:3 ratio to obtain a comprehensive similarity, forming a feature similarity matrix. This matrix reflects the degree of association between each feature.
[0104] The feature similarity matrix is combined with behavioral anomaly scores, device credit scores, probability scores, and device trust scores to form a feature set. Behavioral anomaly scores can be calculated based on the deviation of a user's historical behavior patterns; for example, user A's recent operation sequence deviation is 0.72. Device credit scores can be evaluated based on historical device interactions; for example, device B's credit score is 85. Probability scores can be calculated using a behavioral probability model; for example, user A's current behavior probability score is 0.35. Device trust scores can be evaluated based on device environmental characteristics; for example, device B's trust score is 78.
[0105] Each feature in the feature set is treated as a node, and the initial edge weights between feature nodes are calculated based on a predefined prior probability. The prior probability is determined based on historical data statistics and expert knowledge; for example, the prior probability of behavioral anomaly rating and risk can be set to 0.8, indicating a strong correlation. The initial edge weights between nodes are calculated by multiplying the similarity value of corresponding feature pairs in the feature similarity matrix by the prior probability. For example, if the similarity between feature X and feature Y is 0.65 and the prior probability is 0.7, then the initial edge weight is 0.455. The feature nodes and initial edge weights are then used to construct an initial causal graph, which represents the initial causal relationship hypothesis between features.
[0106] Based on the initial causal graph, conditional mutual information between feature nodes is calculated. Conditional mutual information measures the amount of mutual information between two variables given a third variable; the smaller the value, the closer the two variables are to conditional independence. When the conditional mutual information is less than the independence threshold (e.g., 0.05), the corresponding edge is deleted, thus removing possible spurious associations. Vector perturbation is applied to the feature nodes connected by the remaining edges to obtain the intervention effect. The perturbation method involves adding a small amount of random noise (e.g., ±5% of the original value) to the original feature values and observing its influence on the connected nodes; this influence is the intervention effect. The intervention effect is then weighted and combined with the original edge weights in a 6:4 ratio to update the edge weights, resulting in a dynamic causal graph that reflects the true causal relationships better than the initial causal graph.
[0107] In a dynamic causal graph, the direct causal strength between adjacent nodes is calculated by multiplying the edge weight by the magnitude of the source node's intervention effect on the target node. The indirect causal strength is then calculated along the node path. For example, the indirect causal strength from node A through node B to node C is calculated by multiplying the direct causal strength from A to B by the direct causal strength from B to C by a decay coefficient (e.g., 0.8). An adaptive weighting coefficient is used to calculate the weighted sum of the direct and indirect causal strengths as the total causal strength of the feature node. The adaptive weights are dynamically adjusted based on the path length; the longer the path, the smaller the weight. For example, a path of length 1 has a weight of 0.6, a path of length 2 has a weight of 0.3, and a path of length 3 has a weight of 0.1.
[0108] A counterfactual feature set is generated by adding a normally distributed random perturbation to the feature set. The perturbation amplitude is ±10% of the original value and conforms to a normal distribution. The above causal strength calculation process is repeated for the counterfactual feature set to obtain the total counterfactual causal strength value. A weighted adjustment is performed based on the difference between the total causal strength value and the total counterfactual causal strength value. The larger the difference, the higher the feature sensitivity, and the greater the adjustment weight. The weighted risk value is mapped to the [0,1] interval using the Sigmoid function to obtain the initial risk score. For example, user A's final initial risk score is 0.83, indicating a high risk.
[0109] In one optional implementation, calculating the direct causal strength value between adjacent nodes in the dynamic causal graph, and calculating the indirect causal strength value along the node path, includes:
[0110] Extract the temporal state sequence of adjacent nodes in the dynamic causal graph, count the occurrence frequency of each node state to obtain the marginal distribution probability of the node state, divide the state sequence of each pair of adjacent nodes into training sample pairs according to the sliding time window, use support vector regression with radial basis function kernel to train and obtain the conditional probability density function, perform discrete sampling on the conditional probability density function to obtain the local transition matrix, multiply the local transition matrix with the marginal distribution probability of the corresponding node to obtain the joint probability distribution of the node pair, and calculate the difference of conditional expectation under the intervention and non-intervention conditions based on the joint probability distribution to obtain the direct causal strength value between adjacent nodes.
[0111] In the dynamic causal graph, depth-first search is used to identify all reachable paths between any two nodes and store them as a path set. The direct causal strength values between adjacent nodes on each path are multiplied sequentially according to the node order to obtain the propagation coefficient of the path. An exponential decay factor is set based on the path length, and the decay factor is calculated by raising the number of path nodes to the power of the exponential decay factor to obtain the decay coefficient. The propagation coefficient and the decay coefficient are multiplied to obtain the indirect causal strength value of the path.
[0112] Figure 3 A diagram illustrating the performance comparison between the dynamic causal reasoning fusion method and traditional methods for risk detection:
[0113] This figure illustrates a comprehensive comparative analysis of the risk detection performance between the dynamic causal reasoning fusion method and traditional methods. In terms of risk detection accuracy, this invention achieves 68.3%, significantly surpassing the XGBoost algorithm's 58.5% and the LSTM-CNN model's 53.0%, demonstrating superior detection precision. Regarding the false alarm rate reduction rate, this invention achieves a 55.0% reduction, compared to the XGBoost algorithm's 38.0% and the LSTM-CNN model's 32.0%, indicating a significant advantage in reducing false alarms. In the complex scene adaptability test, this invention achieves an adaptability score of 64.1%, far exceeding the XGBoost algorithm's 47.2% and the LSTM-CNN model's 43.1%, proving its stability and reliability in handling complex and variable environments. In terms of computational efficiency improvement, this invention achieves a 51.0% efficiency improvement, exceeding the XGBoost algorithm's 43.0% and the LSTM-CNN model's 30.0%.
[0114] In one embodiment, the present invention provides a method for calculating causal strength values in a dynamic causal graph. The method first calculates the direct causal strength values between adjacent nodes, and then calculates the indirect causal strength values by propagating along the node paths.
[0115] A dynamic causal graph is a directed graph model that describes causal relationships between variables, where nodes represent variables in the system and edges represent causal relationships between variables. In this implementation, for each pair of adjacent nodes in the dynamic causal graph, it is necessary to calculate the direct causal strength value between them. Specifically, the temporal state sequence of adjacent nodes is extracted from the dynamic causal graph. For example, for nodes A and B, their state change data in the time series is extracted. Assume that the state sequence of node A is [0.2, 0.5, 0.8, 0.3, 0.6] and the state sequence of node B is [0.1, 0.3, 0.7, 0.2, 0.5].
[0116] Next, we calculate the frequency of each node's state to obtain its marginal probability distribution. In this example, we can discretize the node states into multiple intervals, such as dividing the interval [0,1] into five sub-intervals: [0,0.2), [0.2,0.4), [0.4,0.6), [0.6,0.8), and [0.8,1.0]. We then calculate the frequency of node A's state in each interval to obtain its marginal probability distribution P(A). Similarly, we obtain the marginal probability distribution P(B) of node B.
[0117] The state sequences of each pair of adjacent nodes are divided into training sample pairs according to a sliding time window. Setting the time window size to 2, we can obtain training sample pairs {(0.2, 0.1), (0.5, 0.3), (0.8, 0.7), (0.3, 0.2), (0.6, 0.5)}, where the first element of each sample pair is the state of node A at time t, and the second element is the state of node B at time t.
[0118] A support vector regression model using a radial basis function kernel is trained to obtain the conditional probability density function. In practical applications, support vector regression can be implemented using open-source machine learning libraries. During training, the state of node A is used as the input feature, and the state of node B is used as the prediction target. After training, the support vector regression model can predict the conditional probability density of node B given the state of node A.
[0119] Discrete sampling of the conditional probability density function yields the local transition matrix. Specifically, for each possible state value of node A, the conditional probability distribution of node B is predicted and discretized into a probability vector. All these probability vectors are combined to form the local transition matrix M. For example, M might be a 5×5 matrix, where M[i][j] represents the conditional probability that node B is in state interval j when node A is in state interval i.
[0120] Multiplying the local transition matrix by the marginal probability distribution of the corresponding node yields the joint probability distribution of the node pair. Specifically, calculate P(A,B) = P(A) × M, where P(A) is the marginal probability distribution vector of node A, M is the local transition matrix, and P(A,B) is the joint probability distribution matrix of nodes A and B.
[0121] Based on the joint probability distribution, the difference in conditional expectation between the intervention and non-intervention scenarios is calculated to obtain the direct causal strength value between adjacent nodes. In the non-intervention scenario, the expectation value of node B can be calculated using the joint probability distribution P(A,B). In the intervention scenario, assuming node A's state is fixed at a specific value 'a', the conditional expectation of node B is calculated. This expectation difference is calculated for all possible state values of node A and then weighted to obtain the direct causal strength value of node A on node B. For example, if the calculated result is 0.35, it means that node A has a direct causal influence of 0.35 on node B.
[0122] After calculating the direct causal strength values for all adjacent node pairs, the indirect causal strength values between any two nodes are then calculated. A depth-first search algorithm is used in the dynamic causal graph to identify all reachable paths between any two nodes and store them as a set of paths. For example, for nodes A and C, there may be paths A→B→C and A→D→E→C.
[0123] For each path, the propagation coefficient is obtained by multiplying the direct causal strength values between adjacent nodes in the path according to the node order. For example, if in the path A→B→C, the direct causal strength of A to B is 0.35 and the direct causal strength of B to C is 0.28, then the propagation coefficient of this path is 0.35 × 0.28 = 0.098.
[0124] An exponential decay factor is set based on path length. In practical systems, causal effects typically weaken as path length increases. A base decay factor α (e.g., α = 0.9) is set, and α is calculated as the power of the number of path nodes as the decay coefficient. For example, for the path A→B→C, with 3 nodes, the decay coefficient is 0.9. 3 =0.729.
[0125] Multiplying the propagation coefficient by the attenuation coefficient yields the indirect causality strength of the path. Continuing the example, the indirect causality strength of path A→B→C is 0.098 × 0.729 = 0.071. If multiple paths exist from node A to node C, the indirect causality strength values of all paths can be summed to obtain the overall causality strength of node A to node C.
[0126] Using the method described above, the causal strength between any two nodes in a dynamic causal graph can be calculated, providing a quantitative basis for understanding the causal relationships between variables in a system. This method can be applied to multiple fields such as financial market analysis, ecosystem research, and social network analysis, helping analysts discover key causal relationships in complex systems.
[0127] In one optional implementation, when the initial risk score exceeds a warning threshold, a targeted transaction verification question is generated, the verification answer from the transaction initiator is obtained, and based on the verification answer and the initial risk score, a progressive active learning verification method is used to calculate the transaction risk score, including:
[0128] The verification questions are stored in a hierarchical verification question pool by weighting the information gain, complexity and timeliness. The state entropy is calculated by taking the negative logarithm of the probability distribution of the initial risk score. The expected information gain of each question in the hierarchical verification question pool is calculated using the state entropy. The question with the largest expected information gain is selected as the first round verification question and sent to the transaction initiator. The confidence level of the first round verification answer returned by the transaction initiator is evaluated to obtain the first round confidence value.
[0129] The weighted sum of the first round confidence value and the initial risk score is multiplied by a preset coefficient to determine the subsequent verification rounds. The initial risk state probability distribution is weighted and corrected using the first round confidence value to obtain the updated risk state probability distribution. The correlation between the next layer verification problem and the updated risk state probability distribution is calculated to obtain the sampling probability. The problem with the highest sampling probability is selected as the next round verification problem.
[0130] Repeatedly perform the confidence assessment of the verification answer, the weighted correction of the probability distribution of the risk state, and the selection of the verification question until the verification round is completed. The confidence values of the verification answers in each round are used to form a verification feature vector. The verification feature vector is then subjected to a nonlinear transformation and weighted together with the initial risk score to obtain the transaction risk score.
[0131] When the initial risk score exceeds the warning threshold, a targeted transaction verification question will be generated, and the verification answer from the transaction initiator will be obtained. Based on the verification answer and the initial risk score, a progressive active learning verification method will be used to calculate the final transaction risk score.
[0132] First, the verification questions are stored in a hierarchical manner according to a weighted combination of information gain, complexity, and timeliness, forming a hierarchical verification question pool. For example, the first layer might contain simple personal identification questions, the second layer might contain recent transaction habit questions, and the third layer might contain more complex account history behavior questions. The information gain weight can be set to 0.5, the complexity weight to 0.3, and the timeliness weight to 0.2.
[0133] Subsequently, the state entropy is calculated by taking the negative logarithm of the probability distribution of the initial risk score. Assuming the initial risk score is 85 (out of 100), the corresponding risk state probability distribution is [0.15, 0.85] (representing the probabilities of normal and risky transactions, respectively). The state entropy is then calculated as -(0.15 × negative logarithm 0.15 + 0.85 × negative logarithm 0.85). This state entropy is used to calculate the expected information gain of each question in the tiered verification question pool. The question with the highest expected information gain is selected as the first-round verification question and sent to the transaction initiator. For example, the question "What device did you last log in on?" is selected from the first-tier question pool, with an expected information gain of 0.58.
[0134] After the transaction initiator returns the first round of verification answers, a confidence assessment is performed to obtain the first round of confidence score. The confidence assessment is based on factors such as the accuracy of the answer, the response time, and the answer pattern. If the answer is correct and the response time is within 10 seconds, and the answer pattern matches the user's historical behavior, a confidence score of 0.8 may be obtained.
[0135] The subsequent validation rounds are determined by multiplying the weighted sum of the first round confidence score and the initial risk score by a preset coefficient. Assuming the initial risk score has a weight of 0.7, the confidence score has a weight of 0.3, and the preset coefficient is 1.5, the subsequent validation rounds are calculated as: [(85×0.7) + (0.8×100×0.3)]×1.5 / 100. Rounding down gives 1 round. Adding this to the completed round, the total number of validation rounds is 2.
[0136] The initial risk state probability distribution is weighted and corrected using the first-round confidence value to obtain the updated risk state probability distribution. If the first-round confidence value is 0.8, the updated risk state probability might become [0.28, 0.72], indicating a reduction in risk. The correlation between the next-level validation question and the updated risk state probability distribution is calculated to obtain the sampling probability. The question with the highest sampling probability is selected as the next-round validation question. For example, the question "Please confirm your most recent transaction exceeding 1000 yuan" might be selected from the second-level question pool, with a sampling probability of 0.67.
[0137] Continue to repeat the confidence assessment of the verification answer, the weighted correction of the probability distribution of the risk state, and the selection of verification questions until the required number of verification rounds are completed. Assuming that the confidence value obtained after the second round of verification is 0.9, the confidence values of the two rounds of verification answers constitute the verification feature vector [0.8, 0.9].
[0138] The final trading risk score is obtained by nonlinearly transforming the validation feature vector and weighting it with the initial risk score. The nonlinear transformation can be performed using the sigmoid function to map the validation feature vector to the interval [0,1], and then weighted with the initial risk score. Assuming the validation feature vector after nonlinear transformation is [0.75, 0.85], the initial risk score is 85, the weight of the validation feature vector is 0.4, and the weight of the initial risk score is 0.6, then the final trading risk score is calculated as: 85 × 0.6 + [(0.75 + 0.85) / 2] × 100 × 0.4 = 51 + 32 = 83.
[0139] In practical applications, the weight parameters can be dynamically adjusted. For example, for transactions with large sums of money, the weight of the verification feature vector can be increased; for transactions with abnormal login locations, the weight of the initial risk score can be increased. Furthermore, the problem pool and parameter settings will be continuously optimized based on historical verification results, such as removing problems with low information gain and adding new, efficient verification problems.
[0140] The advantage of the progressive active learning verification method lies in its ability to dynamically adjust verification strategies based on user feedback, reducing the verification burden on users during secure transactions while improving the accuracy of identifying risky transactions. Through a tiered question pool and information gain-driven question selection, the most valuable information can be obtained with the fewest verification attempts, achieving accurate assessment of transaction risks.
[0141] This invention provides a multi-dimensional anti-fraud and risk control audit system for large transactions, the system comprising:
[0142] The first unit is used to segment the historical transaction data of the transaction initiator and the transaction recipient according to time windows, extract multi-dimensional features of the transaction behavior in each time window; use wavelet transform to perform multi-scale decomposition of the transaction amount sequence to extract fluctuation features at different frequencies; construct a probability distribution model of transaction behavior through kernel density estimation, calculate the degree of deviation between the current transaction behavior and the historical distribution, and generate a behavior anomaly score.
[0143] The second unit is used to acquire the device environment data of the transaction initiator, maintain the device fingerprint feature library and update the device credit score using an incremental learning algorithm; model the device state transition sequence through Markov decision process and calculate the probability score of the current state transition; construct the device behavior trajectory and generate the device credibility score by calculating the trajectory similarity.
[0144] The third unit is used to construct a feature similarity matrix based on the multidimensional features and the fluctuation features, and to calculate the initial risk score by combining the behavior anomaly score, the device credit score, the probability score and the device credibility score using a dynamic causal reasoning fusion method.
[0145] The fourth unit is used to generate targeted transaction verification questions when the initial risk score exceeds the warning threshold, obtain the verification answer from the transaction initiator, and calculate the transaction risk score based on the verification answer and the initial risk score using a progressive active learning verification method.
[0146] The fifth unit is used to determine the risk control strategy based on the comparison result between the transaction risk score and the preset transaction risk score threshold, and to choose to trigger the manual review process, verify the identity of the transaction initiator for a second time, or directly allow the transaction.
[0147] A third aspect of the present invention provides an electronic device, comprising:
[0148] processor;
[0149] Memory used to store processor-executable instructions;
[0150] The processor is configured to invoke instructions stored in the memory to execute the aforementioned method.
[0151] A fourth aspect of the present invention provides a computer-readable storage medium having stored thereon computer program instructions that, when executed by a processor, implement the aforementioned method.
[0152] This invention can be a method, apparatus, system, and / or computer program product. The computer program product may include a computer-readable storage medium having computer-readable program instructions loaded thereon for performing various aspects of the invention.
[0153] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some or all of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present invention.
Claims
1. A multi-dimensional anti-fraud and risk control auditing method for large transaction, characterized in that, The application comprises the following steps: Segmenting the historical transaction data of the transaction initiator and the transaction receiver according to a time window, extracting multi-dimensional features of the transaction behavior in each time window; Performing multi-scale decomposition on the transaction amount sequence by wavelet transform to extract fluctuation features at different frequencies; Constructing a probability distribution model of the transaction behavior by kernel density estimation, calculating the deviation degree of the current transaction behavior from the historical distribution, and generating a behavior anomaly score; Obtaining the device environment data of the transaction initiator, and maintaining the device fingerprint feature library by using an incremental learning algorithm to update the device credit score; Modeling the device state transition sequence by Markov decision process, calculating the probability score of the current state transition, and constructing the device behavior trajectory to generate a device credibility score by trajectory similarity calculation; Based on the multi-dimensional features and the fluctuation features, a feature similarity matrix is constructed, and the initial risk score is calculated by using a dynamic causal reasoning fusion method in combination with the behavior anomaly score, the device credit score, the probability score and the device credibility score; When the initial risk score exceeds the early warning threshold, a targeted transaction verification question is generated, the verification answer of the transaction initiator is obtained, and the transaction risk score is calculated by using a progressive active learning verification method based on the verification answer and the initial risk score, including: The verification questions are stored in a hierarchical verification question pool according to the weighted combination of information gain, complexity and timeliness, the state entropy is calculated by taking the negative logarithm of the probability distribution of the initial risk score, the expected information gain of each question in the hierarchical verification question pool is calculated by using the state entropy, the question with the maximum expected information gain is selected as the first round of verification question and sent to the transaction initiator, and the first round of confidence value is obtained by performing confidence evaluation on the first round of verification answer returned by the transaction initiator; The weighted sum of the first round of confidence value and the initial risk score is multiplied by a preset coefficient to determine the subsequent verification round, the updated risk state probability distribution is obtained by weighting and correcting the initial risk state probability distribution by using the first round of confidence value, and the correlation degree between the next layer of verification question and the updated risk state probability distribution is calculated to obtain a sampling probability, and the question with the maximum sampling probability is selected as the next round of verification question; The confidence evaluation of the verification answer, the weighting correction of the risk state probability distribution and the selection of the verification question are repeatedly performed until the verification round is completed, the confidence values of the verification answers of each round are combined into a verification feature vector, the transaction risk score is obtained by nonlinear transformation of the verification feature vector and weighted combination with the initial risk score; According to the comparison result of the transaction risk score and the preset transaction risk score threshold, a risk control strategy is determined, and the artificial audit process is triggered, the identity of the transaction initiator is verified again, or the transaction is directly released.
2. The method of claim 1, wherein, Segmenting the historical transaction data of the transaction initiator and the transaction receiver according to a time window, extracting multi-dimensional features of the transaction behavior in each time window; The probability distribution model of transaction behavior is constructed by kernel density estimation, the deviation degree of current transaction behavior from historical distribution is calculated, and the behavior anomaly score is generated, including: The historical transaction data is segmented by an adaptive time window segmentation method, the weighted sum of the variance of transaction behavior within the segment and the number of segments is used as the window division evaluation index, and the historical transaction data is divided into multiple continuous time windows; The mean, standard deviation and transaction frequency of the transaction amount in the time window are calculated to obtain statistical characteristics, and the distribution density and time interval of transaction occurrence time are calculated to obtain time sequence characteristics; the three-layer wavelet decomposition is performed on the transaction amount sequence to obtain the decomposition coefficients of each layer, and the square sum, probability distribution entropy and standard deviation of each layer of decomposition coefficients are calculated to obtain energy features, entropy features and volatility features; principal component analysis method is used to reduce and combine the statistical characteristics, the time sequence characteristics, and the energy features, the entropy features and the volatility features to form a multi-scale fluctuation feature vector; The standard deviation and quartile range of the transaction amount in the historical transaction data are calculated, the smaller value of the standard deviation and the quartile range is selected, and the power function product of the transaction sample number is used as the bandwidth parameter of kernel density estimation; the probability density distribution of historical transaction behavior is calculated using the bandwidth parameter and Gaussian kernel function, and the KL divergence value of current transaction behavior data and the probability density distribution is calculated; The volatility feature in the multi-scale fluctuation feature vector is combined with the KL divergence value to generate an abnormal score of transaction behavior.
3. The method of claim 1, wherein, Obtain the device environment data of the transaction initiator, maintain the device fingerprint feature library using the incremental learning algorithm, and update the device credit score; model the device state transition sequence by Markov decision process, and calculate the probability score of current state transition; Construct a device behavior trajectory, and generate a device credibility score by trajectory similarity calculation, including: Collect the hardware feature vector and software feature vector of the device of the transaction initiator and combine them to form an initial device fingerprint feature, and match the historical credit score of the device from the device fingerprint feature library according to the initial device fingerprint feature; According to the real-time transaction behavior data of the device, the real-time credibility of the device is calculated, the learning rate parameter is set to adjust the weight proportion of the historical credit score and the real-time credibility, and the current time device credit score is updated by incremental method; Collect the running state data of the device continuously, divide the device state into four types: normal, suspicious, risk and unknown, determine the state type of the device at each time according to the running state data, count the transition frequency between each state type in adjacent time, calculate the state transition probability matrix based on the transition frequency, analyze the change rule of the device state sequence using the state transition probability matrix, and calculate the probability score of state transition. The real-time recording device records the geographical position coordinates, network environment parameters, and process list of the device, and forms a current device behavior trajectory in chronological order. A historical device behavior trajectory is selected from a device behavior trajectory database. The Euclidean distance of the current device behavior trajectory and the historical device behavior trajectory in a time-space dimension is calculated. A behavior trajectory similarity score is calculated based on the Euclidean distance in the time-space dimension. The behavior trajectory similarity score is compared with a pre-labeled credibility label. Optimal linear transformation parameters are calculated by a least square method. The behavior trajectory similarity score is converted into a device credibility score.
4. The method of claim 1, wherein, The feature similarity matrix is constructed based on the multi-dimensional features and the fluctuation features. The behavior anomaly score, the device credit score, the probability score, and the device credibility score are combined. An initial risk score is calculated by using a dynamic causal inference fusion method, including: The multi-dimensional features and the fluctuation features are combined to form an initial feature matrix. The mean and standard deviation of each feature dimension in the initial feature matrix are calculated and standardized to obtain a standardized feature matrix. The cosine similarity and domain knowledge distance between feature vectors in the standardized feature matrix are calculated to obtain a feature similarity matrix. The feature similarity matrix, the behavior anomaly score, the device credit score, the probability score, and the device credibility score are combined to form a feature set. Each feature in the feature set is taken as a node. The initial edge weight between the feature nodes is calculated based on a pre-set prior probability. The feature nodes and the initial edge weight are constructed into an initial causal graph. Based on the initial causal graph, the conditional mutual information between the feature nodes is calculated. When the conditional mutual information is less than an independence judgment threshold, the corresponding edge is deleted. The feature nodes connected by the remaining edges are disturbed to obtain an intervention effect. The intervention effect and the original edge weight are combined to update the edge weight to obtain a dynamic causal graph. In the dynamic causal graph, the direct causal strength value between adjacent nodes is calculated. The indirect causal strength value is calculated by propagation along the node path. The weighted sum of the direct causal strength and the indirect causal strength is taken as the total causal strength of the feature node by using an adaptive weight coefficient. A counterfactual feature set is generated by adding a normally distributed random disturbance to the feature set. The counterfactual total causal strength value is calculated. The difference value between the total causal strength value and the counterfactual total causal strength value is weighted and adjusted. The initial risk score is obtained by mapping through a Sigmoid function.
5. The method of claim 4, wherein, In the dynamic causal graph, the direct causal strength value between adjacent nodes is calculated. The indirect causal strength value is calculated by propagation along the node path, including: The time sequence state sequence of adjacent nodes in the dynamic causal graph is extracted, the frequency of occurrence of each node state is counted to obtain the marginal distribution probability of the node state, the state sequence of each pair of adjacent nodes is divided into training sample pairs according to a sliding time window, a support vector regression with a radial basis function kernel is used for training to obtain a conditional probability density function, the conditional probability density function is discretely sampled to obtain a local transition matrix, the local transition matrix is multiplied by the marginal distribution probability of the corresponding node to obtain the joint probability distribution of the node pair, and the difference between the conditional expectations under the intervention and non-intervention conditions is calculated based on the joint probability distribution to obtain the direct causal strength value between the adjacent nodes; In the dynamic causal graph, a depth-first search is used to identify all reachable paths between any two nodes and store them as a path set, the direct causal strength value between adjacent nodes on each path is multiplied in sequence according to the node order to obtain the propagation coefficient of the path, an exponential decay factor is set based on the path length, the path node number power of the exponential decay factor is calculated to obtain a decay coefficient, and the propagation coefficient is multiplied by the decay coefficient to obtain the indirect causal strength value of the path.
6. A multi-dimensional anti-fraud and risk control auditing system for large-value transactions, for implementing the method according to any one of claims 1-5, characterized in that, Comprise: A first unit for segmenting historical transaction data of a transaction initiator and a transaction receiver according to a time window, and extracting multi-dimensional features of transaction behaviors in each time window; A wavelet transform is used to perform multi-scale decomposition on the transaction amount sequence to extract fluctuation features at different frequencies; A probability distribution model of transaction behaviors is constructed through kernel density estimation, the deviation of the current transaction behavior from the historical distribution is calculated, and a behavior anomaly score is generated; A second unit for obtaining device environment data of the transaction initiator, and maintaining a device fingerprint feature library using an incremental learning algorithm to update a device credit score; A Markov decision process is used to model the device state transition sequence, and a probability score of the current state transition is calculated; a device behavior trajectory is constructed, and a device credibility score is generated through trajectory similarity calculation; A third unit for constructing a feature similarity matrix based on the multi-dimensional features and the fluctuation features, and combining the behavior anomaly score, the device credit score, the probability score, and the device credibility score to calculate an initial risk score using a dynamic causal reasoning fusion method; A fourth unit for generating a targeted transaction verification question when the initial risk score exceeds a warning threshold, obtaining a verification answer of the transaction initiator, and calculating a transaction risk score based on the verification answer and the initial risk score using a progressive active learning verification method; A fifth unit for determining a risk control strategy according to a comparison result of the transaction risk score and a preset transaction risk score threshold, selecting to trigger a manual review process, verifying the identity of the transaction initiator again, or directly releasing the transaction.
7. An electronic device, comprising: Comprise: A processor; A memory for storing processor-executable instructions; The processor is configured to invoke the instructions stored in the memory to execute the method of any one of claims 1 to 5.
8. A computer-readable storage medium having stored thereon computer program instructions, wherein, The computer program instructions are executed by the processor to implement the method of any one of claims 1 to 5.
Citation Information
Patent Citations
Photovoltaic active distribution network voltage out-of-limit problem tracing method
CN120150117A
Semiconductor device test equipment control system and method based on industrial data processing
CN120724333A