Abnormal fund analysis method based on account bill transaction record
By constructing a multi-dimensional transaction feature matrix and a dynamic capital flow link, real-time tracking and comparison of capital flows, and iterative adjustment of the topology, the problem of lagging response to changes in capital behavior patterns in existing technologies has been solved, enabling efficient and accurate analysis of abnormal capital activities.
Patent Information
- Application Number
- CN202512011104.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-29
- Publication Date
- 2026-01-30
AI Technical Summary
Existing financial transaction risk monitoring methods cannot adjust the analysis structure in real time, resulting in a lag in response to changes in fund behavior patterns, leading to false alarms or omissions. Furthermore, they lack a dynamic iterative analysis process and cannot effectively address the challenges of analyzing complex fund flows.
Construct a multi-dimensional transaction feature matrix, build a dynamic capital flow link, extract key nodes and assign state mappings, use historical records to build a reference transaction cluster, calculate the abnormal deviation degree, dynamically generate monitoring strategies, track and compare capital flows in real time, iteratively adjust the topology structure until the state of key nodes converges to a steady state, and output analysis conclusions.
The analysis model enables real-time response and synchronous characterization of capital flow behavior, improving the sensitivity and accuracy of detecting abnormal capital activities, reducing misjudgments, and enhancing the robustness of analysis conclusions.
Smart Images

Figure CN121435084A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of financial transaction risk control technology, specifically to a method for analyzing abnormal funds based on transaction records. Background Technology
[0002] In the field of financial transaction risk monitoring, existing technologies primarily rely on constructing static transaction relationship networks or graphs from massive amounts of transaction records. These methods identify abnormal transaction patterns and central nodes within the network through pre-set rules, fixed feature models, or periodic graph calculations. However, fund flows are highly time-series and dynamically interactive, making it difficult for static graphs to depict the continuous process and subsequent evolution of fund transfers between entities. Analysis models based on historical snapshots cannot automatically adjust their internal analytical structure when transaction behavior dynamically changes, leading to a lag in responding to new or variant abnormal fund activities with altered behavioral patterns, resulting in decreased monitoring accuracy.
[0003] Conventional anomaly detection often employs one-off or batch calculation methods. This involves calculating an anomaly score based on transaction characteristics at the current moment or within a fixed time window, comparing it to a preset threshold to output a conclusion. This method separates the analysis process from the subsequent evolution of fund behavior. Faced with complex fund transfer behaviors that attempt to evade monitoring and evolve in stages, one-off detections can generate numerous false positives or false negatives. Monitoring systems lack an iterative analysis process that dynamically approaches a stable judgment based on monitoring actions and counterparty feedback, making it impossible to reach reliable conclusions in adversarial environments.
[0004] There is a need for a technical solution that enables the structure of the analysis model to adapt to the behavior of funds in real time and to make a final robust judgment on the dynamic evolution of fund behavior through an iterative convergence process, in order to cope with the increasingly complex challenges of abnormal fund flow analysis. Summary of the Invention
[0005] The purpose of this invention is to provide a method for analyzing abnormal funds based on billing transaction records, so as to solve the problems mentioned in the background art.
[0006] To achieve the above objectives, this invention provides a method for abnormal fund analysis based on billing transaction records, the method comprising:
[0007] Construct a multi-dimensional transaction feature matrix corresponding to transaction records derived from the billing and transaction system;
[0008] Based on the multi-dimensional transaction feature matrix, a dynamic capital flow link reflecting the temporal relationship of capital transfer across entities is constructed.
[0009] Extract key nodes with fund aggregation and distribution attributes from the dynamic fund flow link, and assign state mappings to the key nodes according to the fund flow direction;
[0010] A reference transaction cluster is constructed using historical normal transaction records, and the abnormal deviation of the transaction record to be analyzed relative to the reference transaction cluster is calculated;
[0011] Based on the difference between the abnormal deviation and the preset compliance indicators, a monitoring strategy for the key node is dynamically generated.
[0012] Based on the monitoring strategy, the inflow and outflow of funds at the key nodes are tracked and compared in real time.
[0013] Based on the results of real-time tracking and comparison, the state mapping of the key nodes is updated, and the topology adjustment of the dynamic capital flow link is triggered.
[0014] After the topology is adjusted, the abnormal deviation is reassessed, and the steps of dynamically generating monitoring strategies, real-time tracking and comparison, and updating state mapping are iteratively executed.
[0015] When the state mapping of the key node converges to a steady state, the fund behavior pattern of the transaction record to be analyzed is determined;
[0016] Based on the described fund behavior pattern, output the abnormal fund analysis conclusions of the transaction records to be analyzed.
[0017] Preferably, the construction of the multi-dimensional transaction feature matrix corresponding to the transaction records from the billing system includes:
[0018] The original data fields of the billing system are parsed to separate the transaction entity identifier, transaction counterparty identifier, transaction timestamp, transaction amount value, and transaction type code;
[0019] The transaction entity identifier and the transaction counterparty identifier are associated with each other by entity synonyms and merged into a unified set of entity identifiers;
[0020] The transaction timestamps are converted into a continuous time slice sequence, and the transaction amount is accumulated and distributed according to the time slice sequence.
[0021] By integrating the unified set of entity identifiers, the time slice sequence, and the cumulative and distribution statistical results, a multi-dimensional transaction feature matrix is formed, with entities as rows, time slices as columns, and statistical results as elements.
[0022] Preferably, constructing a dynamic fund flow link reflecting the temporal relationship of fund transfers across entities based on the multi-dimensional transaction feature matrix includes:
[0023] Iterate through the transaction amount values of each pair of entities in the same or adjacent time slices in the multi-dimensional transaction feature matrix;
[0024] When the transaction amount exceeds the directional threshold, a directed edge with timestamp and amount weight is established between the pair of entities.
[0025] Aggregate all the directed edges to form a dynamic fund flow link with entities as vertices and directed edges with timestamps and monetary weights as connections.
[0026] Preferably, the step of extracting key nodes with fund aggregation and distribution attributes from the dynamic fund flow link and assigning state mappings to the key nodes according to the fund flow direction includes:
[0027] Calculate the weighted in-degree and weighted out-degree of each entity in the dynamic capital flow link. The weighted in-degree and weighted out-degree are obtained by summing the monetary weights of the directed edges connected to the entity.
[0028] Entities whose weighted in-degree or weighted out-degree exceeds the network centrality threshold are selected and marked as key nodes with fund aggregation and distribution attributes.
[0029] Analyze the net flow of funds at each key node, and assign a corresponding state mapping label to each key node based on net inflow, net outflow, or equilibrium status.
[0030] Preferably, the step of constructing a reference transaction cluster using historical normal transaction records and calculating the abnormal deviation of the transaction record to be analyzed relative to the reference transaction cluster includes:
[0031] Select transaction records marked as normal within a historical time period, and generate a historical normal transaction feature matrix and a historical normal fund flow link according to the method of constructing a multi-dimensional transaction feature matrix corresponding to the transaction records from the billing system and constructing a dynamic fund flow link that reflects the time sequence relationship of fund transfers across entities.
[0032] Pattern mining is performed on the historical normal capital flow links, and patterns with similar topology and flow distribution are classified into a reference transaction cluster;
[0033] The dynamic capital flow link corresponding to the transaction record to be analyzed is compared with each of the reference transaction clusters in terms of structural similarity and flow distribution similarity.
[0034] The minimum value of the similarity metric is selected as the abnormal deviation of the transaction record to be analyzed relative to the reference transaction cluster.
[0035] Preferably, the step of dynamically generating a monitoring strategy for the key node based on the difference between the abnormal deviation and a preset compliance indicator includes:
[0036] Establish the aforementioned compliance indicators to distinguish between normal and suspicious financial activities;
[0037] Compare the abnormal deviation with the compliance indicator. When the abnormal deviation exceeds the compliance indicator, locate the substructure with the greatest difference from the reference transaction cluster in the dynamic capital flow link corresponding to the transaction record to be analyzed.
[0038] Extract the key nodes contained in the substructure, and for each extracted key node, generate the monitoring strategy that includes the monitoring frequency and comparison rules.
[0039] Preferably, the real-time tracking and comparison of fund inflows and outflows at the key nodes based on the monitoring strategy includes:
[0040] Based on the monitoring frequency in the monitoring strategy, the sequence of fund inflows and outflows of the key nodes in the latest time slice is periodically obtained;
[0041] The fund inflow and outflow sequences are matched with the comparison rules in the monitoring strategy. The comparison rules include the expected inflow / outflow ratio threshold and the historical fluctuation range for the same period.
[0042] Record any abnormal transaction events in the fund inflow and outflow sequences that violate the comparison rules.
[0043] Preferably, updating the state mapping of the key nodes and triggering the topology adjustment of the dynamic fund flow link based on the results of real-time tracking and comparison includes:
[0044] Based on the number and severity of the abnormal transaction events, adjust the confidence level of the state mapping label corresponding to the key node;
[0045] If the confidence level drops below the update threshold, the state mapping label of the key node will be updated to a higher-level abnormal state identifier.
[0046] Based on the updated state mapping, specific directed edges initiated or received by the key node and associated with the abnormal transaction event are temporarily weakened or removed in the dynamic fund flow link, thereby completing the topology adjustment.
[0047] Preferably, the step of re-evaluating the abnormal deviation after the topology adjustment and iteratively executing subsequent steps includes:
[0048] Based on the dynamic capital flow link after the topology adjustment, the structural similarity and flow distribution similarity with each of the reference transaction clusters are recalculated to obtain a new abnormal deviation.
[0049] Using the new abnormal deviation as input, the steps of dynamically generating a monitoring strategy for the key node, performing real-time tracking and comparison based on the monitoring strategy, updating the state mapping of the key node based on the results, and triggering topology adjustment are executed again.
[0050] Record the change trajectory of the state mapping label of the key node in each iteration.
[0051] Preferably, when the state mapping of the key node converges to a steady state, determining the fund behavior pattern of the transaction record to be analyzed includes:
[0052] The trajectory of the state mapping label of the key node is monitored. When the state mapping label and its confidence level no longer change in multiple consecutive iterations, it is determined that the node has converged to a steady state.
[0053] The final state mapping labels of all the key nodes in a steady state are summarized to form a vectorized expression of the capital behavior pattern of the transaction records to be analyzed;
[0054] The vectorized representation of the fund behavior pattern is matched with a predefined abnormal pattern library, and an abnormal fund analysis conclusion is generated based on the matching result for the transaction record to be analyzed.
[0055] Compared with the prior art, the beneficial effects of the present invention are:
[0056] The dynamic network topology adjustment mechanism based on state mapping feedback ensures that the analysis network representing fund flow relationships is no longer a static structure. The system updates the state of key nodes based on real-time tracking and comparison results and proactively triggers topology adjustments across the entire dynamic fund flow chain. This approach enables the core structure of the analysis model to respond in real-time to the latest changes in fund flow behavior, achieving closed-loop linkage between the monitoring strategy and the underlying analysis model. The connection weights and critical paths of the analysis network are optimized in real-time, keeping the model's characterization of fund flows synchronized with current actual behavior patterns. This improves the model's sensitivity and accuracy in detecting and characterizing abnormal fund activities whose behavior patterns have changed or are evolving, reducing misjudgments caused by the model structure lagging behind behavioral changes.
[0057] This dynamic system approach, employing iterative convergence to determine fund behavior patterns, constructs anomaly analysis as an iterative process seeking system steady-state. After each topology adjustment, the system recalculates the anomaly deviation and iteratively executes subsequent strategy generation, behavior tracking, and state update steps based on the new results. This process continues until the state mappings of key nodes no longer change significantly, reaching a convergent steady state, at which point the final judgment is output. This approach ensures that the analysis conclusion is not based on a snapshot at a particular moment, but rather on a dynamic equilibrium reached after multiple rounds of interaction, feedback, and adjustment. This enhances the analytical depth for complex, circuitous, or exploratory fund behavior patterns, enabling the final conclusion to comprehensively consider the dynamic evolution trajectory of behavior throughout the observation period, thus improving the robustness and reliability of the judgment. Attached Figure Description
[0058] Figure 1 This is a schematic diagram illustrating the working principle of the abnormal fund analysis method based on billing transaction records described in this invention.
[0059] Figure 2 A flowchart for constructing a multi-dimensional transaction feature matrix;
[0060] Figure 3 A flowchart for extracting key nodes and assigning state mappings;
[0061] Figure 4 Diagram showing the configuration of monitoring strategy parameters for key nodes;
[0062] Figure 5 This is a diagram of the dynamic capital flow network structure. Detailed Implementation
[0063] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0064] Please see Figure 1This invention provides a method for abnormal fund analysis based on billing and transaction records. The method includes: constructing a multi-dimensional transaction feature matrix corresponding to transaction records from the billing and transaction record system; constructing a dynamic fund flow link reflecting the temporal relationship of fund transfers across entities based on the multi-dimensional transaction feature matrix; extracting key nodes with fund aggregation and dispersion attributes from the dynamic fund flow link and assigning state mappings to the key nodes according to the fund flow direction; constructing a reference transaction cluster using historical normal transaction records and calculating the abnormal deviation degree of the transaction record to be analyzed relative to the reference transaction cluster; dynamically generating a monitoring strategy for the key nodes based on the difference between the abnormal deviation degree and preset compliance indicators; tracking and comparing the fund inflow and outflow behavior of the key nodes in real time according to the monitoring strategy; updating the state mapping of the key nodes and triggering the topology adjustment of the dynamic fund flow link based on the results of real-time tracking and comparison; re-evaluating the abnormal deviation degree after the topology adjustment and iteratively executing the steps of dynamically generating the monitoring strategy, real-time tracking and comparison, and updating the state mapping; determining the fund behavior pattern of the transaction record to be analyzed when the state mapping of the key node converges to a steady state; and outputting the abnormal fund analysis conclusion of the transaction record to be analyzed based on the fund behavior pattern.
[0065] Example 1: See Figure 2 The system analyzes the raw data fields of the billing system, separating the transaction entity identifier, transaction counterparty identifier, transaction timestamp, transaction amount, and transaction type code. It then associates the transaction entity identifier and transaction counterparty identifier with entities and merges them into a unified set of entity identifiers. The transaction timestamp is converted into a continuous time slice sequence, and the transaction amount is accumulated and distributed according to the time slice sequence. Finally, it integrates the unified set of entity identifiers, the time slice sequence, and the accumulated and distributed statistical results to form a multi-dimensional transaction feature matrix with entities as rows, time slices as columns, and statistical results as elements.
[0066] In practical implementation, the original data fields of the billing and transaction record system are parsed to separate the transaction entity identifier, counterparty identifier, transaction timestamp, transaction amount, and transaction type code. The billing and transaction record system originates from a transaction record repository in the financial or telecommunications fields. In some embodiments, the original data fields are stored in a structured table format, with each field corresponding to an attribute of a transaction record. The transaction entity identifier, counterparty identifier, transaction timestamp, transaction amount, and transaction type code are extracted through the data parsing module. In practical implementation, the transaction entity identifier and counterparty identifier are associated with entity synonyms and merged into a unified entity identifier set. The entity synonym association is based on identifier mapping rules. For example, when the transaction entity identifier and counterparty identifier point to the same entity, they are mapped to a unique identifier in the entity identifier set. It can be understood that the entity synonym association process involves identifier normalization processing to ensure that the same entity has a consistent representation in different transaction records. In specific implementation, transaction timestamps are converted into continuous time-slice sequences. These time-slice sequences are generated based on preset time intervals, such as dividing continuous time windows into hours, days, or weeks. Transaction amounts are then accumulated and statistically analyzed according to the time-slice sequences. This accumulation and distribution analysis includes summing, counting, or averaging the transaction amounts for each entity within each time slice. Optionally, the time-slice sequence conversion is implemented using a time window function to ensure that transaction timestamps are mapped to their corresponding time-slice indices. In specific implementation, a unified set of entity identifiers, time-slice sequences, and accumulation and distribution statistical results are integrated to form a multi-dimensional transaction feature matrix with entities as rows, time slices as columns, and statistical results as elements. The construction of this multi-dimensional transaction feature matrix is accomplished using a matrix filling algorithm, where each entity in the entity identifier set corresponds to one row in the matrix, each time slice in the time-slice sequence corresponds to one column, and the matrix elements are the statistical result values. In some embodiments, the accumulation and distribution statistical results are calculated using the following formula:
[0067]
[0068] in: Represents entities in a multi-dimensional transaction feature matrix In time slice The matrix element values, Representing entities In time slice The collection of all transaction records within, Indicates a single transaction record The data comparison is reflected in the rows and columns of the multi-dimensional transaction feature matrix. For example, comparing the matrix element values of different entities in the same time slice, or comparing the matrix element values of the same entity in different time slices, to reveal differences in transaction patterns. Optionally, missing values are handled by interpolation or zeroing during the matrix filling process to ensure the integrity of the matrix structure.
[0069] Example 2: See Figure 3 The system iterates through the transaction amount values of each pair of entities in the same or adjacent time slices within the multi-dimensional transaction feature matrix. When the transaction amount value exceeds the directionality threshold, a directed edge with timestamps and amount weights is established between the pair of entities. All directed edges are aggregated to form a dynamic fund flow link with entities as vertices and directed edges with timestamps and amount weights as connections. The weighted in-degree and weighted out-degree of each entity in the dynamic fund flow link are calculated. The weighted in-degree and weighted out-degree are obtained by summing the amount weights of the directed edges connected to the entity. Entities with weighted in-degree or weighted out-degree exceeding the network centrality threshold are selected and marked as key nodes with fund aggregation and dispersion attributes. The net fund flow of each key node is analyzed, and a corresponding state mapping label is assigned to each key node according to net inflow, net outflow, or equilibrium state.
[0070] In specific implementation, the transaction amount values of each pair of entities in the multi-dimensional transaction feature matrix within the same or adjacent time slices are traversed. In some embodiments, the traversal process is implemented using a double loop algorithm. The outer loop traverses all entities in the multi-dimensional transaction feature matrix as the starting entities, and the inner loop traverses all other entities in the multi-dimensional transaction feature matrix as the target entities. For each pair of entities, the matrix element value corresponding to its index in the same or adjacent time slices is extracted as the transaction amount value to be compared. In specific implementation, when the transaction amount value exceeds a directional threshold, a directed edge with a timestamp and amount weight is established between the pair of entities. The directional threshold is a pre-set value used to determine whether the fund flow is significant. The timestamp records the time slice information of the transaction, and the amount weight directly adopts the transaction amount value exceeding the directional threshold. It can be understood that the direction of the directed edge is determined by the fund flow, from the paying entity to the receiving entity. The established directed edge data structure includes a starting vertex identifier, a target vertex identifier, a timestamp attribute, and an amount weight attribute. In practical implementation, all directed edges are aggregated to form a dynamic fund flow link with entities as vertices and directed edges with timestamps and monetary weights as connections. Internally, the dynamic fund flow link is represented as a graph data structure, where the vertex set corresponds to all involved entities, and the edge set corresponds to all established directed edges. Optionally, the dynamic fund flow link supports slice queries by time dimension, allowing extraction of subgraph structures within a specific time window. In practical implementation, the weighted in-degree and weighted out-degree of each entity in the dynamic fund flow link are calculated. The weighted in-degree and weighted out-degree are obtained by summing the monetary weights of the directed edges connected to the entity. The weighted in-degree calculation accumulates the monetary weights of all directed edges with the entity as the target vertex, and the weighted out-degree calculation accumulates the monetary weights of all directed edges with the entity as the starting vertex. In some embodiments, the formula for calculating the weighted in-degree is:
[0071]
[0072] in: Represents vertices Weighted in-degree, Represents all points to vertices The set of directed edges, Represents a directed edge The weighting of monetary amounts is determined. In practice, entities with a weighted in-degree or weighted out-degree exceeding the network centrality threshold are selected and marked as key nodes with fund aggregation and dispersion attributes. The network centrality threshold is used to identify entities with abnormal fund flows in the network. The selection process compares the weighted in-degree and weighted out-degree values of each entity with the network centrality threshold. Entities with either value exceeding the network centrality threshold are marked. In practice, the net fund flow of each key node is analyzed. Based on net inflow, net outflow, or equilibrium status, a corresponding state mapping label is assigned to each key node. The net fund flow is determined by comparing the weighted in-degree and weighted out-degree values of the key node. When the weighted in-degree value is significantly greater than the weighted out-degree value, a net inflow state mapping label is assigned; when the weighted out-degree value is significantly greater than the weighted in-degree value, a net outflow state mapping label is assigned; and when the two values are similar, an equilibrium state mapping label is assigned.
[0073] Example 3: Select transaction records marked as normal within a historical time period. Following the method of constructing a multi-dimensional transaction feature matrix and a dynamic capital flow chain, generate a historical normal transaction feature matrix and a historical normal capital flow chain. Perform pattern mining on the historical normal capital flow chain, classifying patterns with similar topological structures and flow distributions into a reference transaction cluster. Measure the structural similarity and flow distribution similarity between the dynamic capital flow chain corresponding to the transaction record to be analyzed and each reference transaction cluster. Select the minimum value of the similarity measurement as the abnormal deviation degree of the transaction record to be analyzed relative to the reference transaction cluster. Set compliance indicators to distinguish between normal and suspicious capital behavior. Compare the abnormal deviation degree with the compliance indicators. When the abnormal deviation degree exceeds the compliance indicators, locate the substructure with the greatest difference from the reference transaction cluster in the dynamic capital flow chain corresponding to the transaction record to be analyzed. Extract the key nodes contained in the substructure. For each extracted key node, generate a monitoring strategy including monitoring frequency and comparison rules.
[0074] In specific implementation, transaction records marked as normal within a historical time period are selected. The historical time period is a pre-defined past time interval representing normal business activities, and the marking of normal transactions originates from compliance indicators or manual review conclusions within the business system. In some embodiments, following the method of constructing a multi-dimensional transaction feature matrix and a dynamic fund flow link, a historical normal transaction feature matrix and a historical normal fund flow link are generated. Each normal transaction record within the historical time period is processed. First, a historical normal transaction feature matrix corresponding to that historical time period is constructed, and then a historical normal fund flow link reflecting the fund transfer relationship within that historical time period is constructed. In specific implementation, pattern mining is performed on the historical normal fund flow links. Patterns with similar topological structures and flow distributions are grouped into a reference transaction cluster. Pattern mining is implemented using a graph pattern mining algorithm. The algorithm extracts frequently occurring subgraph structures and their edge weight distribution features from the historical normal fund flow links. Topological similarity is determined based on the vertex connection relationships and edge directions of the subgraph, while flow distribution similarity is determined based on the statistical characteristics of the amount weights on the edges. Patterns that meet the similarity criteria are grouped into the same reference transaction cluster. Optionally, each reference transaction cluster is represented by a representative central subgraph and its flow distribution feature vector. In practice, the dynamic fund flow link corresponding to the transaction record to be analyzed is compared with each reference transaction cluster in terms of structural similarity and flow distribution similarity. The measurement process includes calculating the graph edit distance or graph isomorphism matching degree between the dynamic fund flow link corresponding to the transaction record to be analyzed and the central subgraph of each reference transaction cluster as the structural similarity score, and calculating the correlation coefficient or cosine similarity of the amount weight sequences on the corresponding edges as the flow distribution similarity score. In practice, the minimum value of the similarity measurement is selected as the abnormal deviation degree of the transaction record to be analyzed relative to the reference transaction cluster, specifically calculated using the following formula:
[0075]
[0076] in: Indicates the degree of abnormal deviation. Represents the set of indices for all reference transaction clusters. Indicates the relationship with the first Structural similarity score of each reference transaction cluster Indicates the relationship with the first Similarity score of traffic distribution for each reference transaction cluster and This refers to the coefficients that adjust the weights of the two similarity criteria. In practice, data comparison involves simultaneously calculating the similarity scores between the dynamic fund flow link corresponding to the transaction record to be analyzed and multiple different reference transaction clusters. By comparing these scores, the minimum value corresponding to the least similar case is selected to calculate the abnormal deviation. In practice, a compliance indicator is set to distinguish between normal and suspicious fund behavior. The compliance indicator is a numerical threshold determined based on the statistical distribution of abnormal deviations in historical normal transaction records, for example, taking a specific percentile of the abnormal deviation distribution of historical normal transaction records. In some embodiments, the abnormal deviation is compared with the compliance indicator. When the abnormal deviation exceeds the compliance indicator, the substructure with the greatest difference from the reference transaction cluster in the dynamic fund flow link corresponding to the transaction record to be analyzed is located. The substructure with the greatest difference is determined by comparing the dynamic fund flow link to the reference transaction cluster. The central subgraph of the reference transaction cluster corresponding to the minimum value is used to locate and identify the set of local vertices and edges whose differences in topological connectivity or edge weight exceed a preset difference threshold.
[0077] In practical implementation, key nodes are extracted from the substructure. For each extracted key node, a monitoring strategy is generated, including monitoring frequency and comparison rules. Key nodes are vertices in the substructure that possess the attribute of fund aggregation and dispersion. A monitoring strategy is generated independently for each extracted key node. The monitoring frequency defines the time interval for checking its fund inflow and outflow behavior, and the comparison rules define the expected fund behavior pattern for that key node, such as a threshold for the fund inflow and outflow ratio. It can be understood that the location and extraction process is based on a graph structure difference analysis algorithm, and the generation of monitoring strategies is dynamic and targeted.
[0078] In its implementation, the graph structure difference analysis algorithm involves a detailed comparison between the dynamic capital flow link corresponding to the transaction record to be analyzed and the central subgraph of the reference transaction cluster. The algorithm locates the substructure with the greatest difference by calculating the topological differences in vertex connectivity and edge direction, as well as the differences in the distribution of edge weights. The algorithm presets a difference threshold; when the deviation between the local subgraph of the link to be analyzed and the central subgraph of the reference cluster in terms of graph edit distance or the statistical characteristics of the edge weight sequence exceeds this threshold, it is identified as a region with significant differences. After location, the algorithm traverses all vertices in the substructure, filtering out entities that meet the definition of a key node (i.e., whose weighted in-degree or weighted out-degree exceeds the network centrality threshold), thus completing the extraction of key nodes. Based on the extraction results, the generation of the monitoring strategy reflects dynamic targeting, i.e., each key node is independently configured with a monitoring frequency and comparison rules. The monitoring frequency is adaptively set according to the node's trading activity during historical normal periods, while the comparison rules incorporate the node's typical capital inflow / outflow ratio threshold and historical fluctuation range within the reference transaction cluster, ensuring a close coupling between the strategy and the specific behavioral characteristics of the node. Optionally, the comparison rules may also include the typical transaction amount fluctuation range of the key node within the same time slice during a normal historical period.
[0079] See Figure 4 This is a bar chart comparing the parameters of key node monitoring strategies, used to demonstrate the monitoring configuration and fluctuation range of different key nodes in abnormal fund analysis. This chart corresponds to the "dynamic generation of monitoring strategies" stage in abnormal fund analysis. The parameter characteristics of node 4 (high-frequency monitoring, narrow normal fluctuation, wide abnormal fluctuation) indicate that it is judged as a high-risk node, requiring more intensive monitoring and stricter fluctuation thresholds. The difference in monitoring frequency and fluctuation range reflects the "targeting" of the monitoring strategy; the higher the risk of the node, the more intensive the monitoring and the stricter the normal fluctuation threshold. The chart's purpose includes visually displaying the risk classification of key nodes, verifying the rationality of the monitoring strategy, ensuring more sufficient investment of monitoring resources for high-risk nodes, and assisting in subsequent strategy adjustments.
[0080] Example 4: Based on the monitoring frequency in the monitoring strategy, the fund inflow and outflow sequences of key nodes within the latest time slice are periodically acquired. These sequences are then matched against the comparison rules in the monitoring strategy, which include expected inflow / outflow ratio thresholds and historical fluctuation ranges for the same period. Abnormal transaction events that violate the comparison rules in the fund inflow and outflow sequences are recorded. Based on the number and severity of abnormal transaction events, the confidence level of the state mapping label corresponding to the key node is adjusted. If the confidence level drops below the update threshold, the state mapping label of the key node is updated to a higher-level abnormal state identifier. Based on the updated state mapping, specific directed edges initiated or received by the key node and associated with abnormal transaction events are temporarily weakened or removed from the dynamic fund flow chain, completing the topology adjustment. Based on the dynamic capital flow link after the topology adjustment, the structural similarity and flow distribution similarity with each reference transaction cluster are recalculated to obtain a new abnormal deviation. Using the new abnormal deviation as input, the steps of dynamically generating monitoring strategies for key nodes, real-time tracking and comparison based on the monitoring strategies, updating the state mapping of key nodes based on the results and triggering topology adjustment are executed again. The change trajectory of the state mapping label of key nodes in each iteration is recorded.
[0081] In specific implementation, based on the monitoring frequency in the monitoring strategy, the inflow and outflow sequences of funds at key nodes within the latest time slice are periodically acquired. The monitoring frequency defines the time period for acquiring data, such as per minute, per hour, or per day. In some embodiments, the inflow sequence is obtained by querying the billing system, filtering out all transaction records with key nodes as payees within the latest time slice, extracting their transaction amounts, and arranging them in chronological order. The outflow sequence is obtained by filtering out all transaction records with key nodes as payers within the latest time slice, extracting their transaction amounts, and arranging them in chronological order. In specific implementation, the inflow and outflow sequences are matched against the comparison rules in the monitoring strategy. The comparison rules in the monitoring strategy are preset independently for each key node. The comparison rules include the expected inflow / outflow ratio threshold and the historical fluctuation range for the same period. The matching process includes calculating the actual ratio of the sum of the inflow sequence to the sum of the outflow sequence, determining whether the actual ratio exceeds the expected inflow / outflow ratio threshold, and determining whether each value in the inflow and outflow sequences exceeds the upper and lower limits defined by the historical fluctuation range for the same period.
[0082] In practice, abnormal transaction events that violate the comparison rules in the fund inflow and outflow sequences are recorded. For cases where the actual proportion exceeds a threshold, it is recorded as a proportion anomaly event. For cases where a single value in the sequence exceeds the historical fluctuation range for the same period, it is recorded as a fluctuation anomaly event for that specific transaction. Each abnormal transaction event records its timestamp, transaction amount, associated counterparty, and the specific rule clause violated. It can be understood that the historical fluctuation range is derived from historical data on fund inflows or outflows over multiple identical time periods for that key node, for example, by calculating the mean and standard deviation. Data comparison is achieved by comparing the real-time acquired sequence data with preset rule thresholds and historical statistical ranges, as shown in Table 1 for specific comparison details.
[0083] Table 1: Monitoring and Comparison Record Table
[0084] Key node identifier Monitoring time slice Total amount of capital inflow Total amount of capital outflow Actual inflow-outflow ratio Expected proportion threshold Is the ratio abnormal? Number of transactions exceeding the permitted scope Node_A 2023-10-01 150,000 50,000 3.0 2.5 yes 2 Node_B 2023-10-01 80,000 75,000 1.07 1.5 no 0
[0085] In practice, the confidence level of the state mapping label corresponding to the key node is adjusted based on the number and severity of abnormal transaction events. The confidence level is a numerical value; the initial state mapping label carries an initial confidence level. The more abnormal transaction events there are, and the greater the deviation of a single transaction amount from its historical fluctuation range, the greater the downward adjustment of the confidence level. Optionally, the confidence level adjustment is calculated using a formula:
[0086]
[0087] in: This indicates the adjusted new confidence level. This indicates the original confidence level before adjustment. This indicates the total number of abnormal transaction events recorded within the current monitoring period. This indicates the degree of deviation in amount for a single abnormal transaction event. and This is a preset penalty coefficient. In specific implementations, if the confidence level drops below the update threshold, the state mapping label of the key node is updated to a higher-level abnormal state identifier. The update threshold is a pre-set confidence level threshold value. A higher-level abnormal state identifier represents a stronger degree of abnormality, such as updating from "observation" to "suspicious" or from "suspicious" to "highly suspicious". In some embodiments, based on the updated state mapping, specific directed edges initiated or received by the key node and associated with abnormal transaction events are temporarily weakened or removed from the dynamic fund flow link to complete the topology adjustment. The weakening operation can be multiplying the amount weight of the specific directed edge by a decay coefficient less than 1, and the removal operation is removing the specific directed edge from the edge set of the dynamic fund flow link. In specific implementations, based on the dynamic fund flow link after topology adjustment, its structural similarity and flow distribution similarity with each reference transaction cluster are recalculated to obtain a new abnormal deviation. The recalculation process uses a similarity measurement method and an abnormal deviation calculation formula, but the input is the dynamic fund flow link after structural adjustment. In practice, the new anomaly deviation is used as input to repeatedly execute the steps of dynamically generating monitoring strategies for key nodes, real-time tracking and comparison based on the monitoring strategies, and updating the state mapping of key nodes based on the results and triggering topology adjustments. This process constitutes an iterative loop, with each iteration starting from the new anomaly deviation output from the previous iteration and the updated dynamic capital flow chain. In practice, the change trajectory of the state mapping labels of key nodes in each iteration is recorded. The change trajectory is stored in list or sequence form. The state mapping label of each key node and its corresponding confidence level are recorded after each iteration to track its state evolution process.
[0088] Example 5: Monitor the change trajectory of the state mapping labels of key nodes. When the state mapping labels and their confidence levels no longer change in multiple consecutive iterations, it is determined that the convergence has reached a steady state. Summarize the final state mapping labels of all key nodes in the steady state to form a vectorized expression of the capital behavior pattern of the transaction record to be analyzed. Match the vectorized expression of the capital behavior pattern with a predefined abnormal pattern library. Generate abnormal capital analysis conclusions of the transaction record to be analyzed based on the matching results.
[0089] In practical implementation, the change trajectory of the state mapping labels of key nodes is monitored. After each iteration, the change trajectory is a sequence of the state mapping labels and their confidence levels for each key node. The monitoring process is achieved by the program iteratively checking the change trajectory data. In some embodiments, when the state mapping labels and their confidence levels no longer change in multiple consecutive iterations, it is determined that convergence has reached a steady state. The number of consecutive iterations is a preset positive integer threshold, such as three or five consecutive iterations. "No longer changing" means that the text identifiers of the state mapping labels are completely identical and the numerical difference in the confidence levels is less than a very small tolerance threshold. In practical implementation, the convergence condition can be formally checked using a formula:
[0090]
[0091] in: Indicates information about key nodes The Boolean result of whether it converges. This indicates the current total number of iterations. This represents the preset threshold for the number of consecutive iterations. Indicates key nodes In the The state mapping label after the next iteration Indicates key nodes In the Confidence level after the next iteration It is a very small positive number as the tolerance threshold, sign This represents the logical AND operation. It can be understood that the symbols in the formula... Represents a key node, symbol Represents the total number of iterations, symbol Represents the threshold for the number of consecutive judgments, symbol Represents state mapping labels, symbols Represents confidence level, symbol This represents the tolerance threshold for numerical comparisons.
[0092] In specific implementation, the final state mapping labels of all key nodes in a steady state are aggregated to form a vectorized expression of the capital behavior pattern of the transaction record to be analyzed. The aggregation process collects the final state mapping labels of all key nodes determined to have converged to a steady state. The vectorized expression of the capital behavior pattern can be a multi-dimensional vector, where each dimension corresponds to a possible state mapping label type. The element values of the vector can be the number of key nodes with that label or the weighted sum of confidence levels. In some embodiments, data comparison involves juxtaposing and comparing the vectorized expressions of the capital behavior patterns of different transaction records to be analyzed to observe the differences in their pattern distribution. In specific implementation, the vectorized expression of the capital behavior pattern is matched with a predefined abnormal pattern library. The abnormal pattern library is a set where each element is a predefined vector template representing a certain known abnormal capital behavior feature. The matching process calculates the similarity between the vectorized expression of the capital behavior pattern of the transaction record to be analyzed and each template vector in the abnormal pattern library, for example, by calculating cosine similarity or Euclidean distance. In practice, based on the matching results, an abnormal fund analysis conclusion is generated for the transaction record to be analyzed. The matching results include which template vector in the abnormal pattern library is most similar to the record and the specific similarity value. If the highest similarity exceeds a preset matching threshold, the generated conclusion indicates that the fund behavior of the transaction record to be analyzed matches a certain type of abnormal pattern; otherwise, the generated conclusion indicates that no known abnormal pattern with a clear match was found. Optionally, the abnormal fund analysis conclusion may include the identifier of the matched abnormal pattern type, the similarity score, and a list of key nodes involved.
[0093] See Figure 5 This is a dynamic fund flow topology diagram used to illustrate the relationships and risk status of transaction nodes in abnormal fund analysis. All associated transactions are shown in red (abnormal transactions), and these connect to numerous other nodes (including suspicious, high-net-worth, and normal nodes), reflecting their "fund aggregation and dispersal attributes" and serving as hubs for abnormal fund flows. Abnormal transactions primarily revolve around node 15, extending to risk nodes such as 3 and 7, reflecting the targeted transfer paths of abnormal funds. Light gray (normal transactions) cover most ordinary nodes, clearly distinguishing them from the abnormal transaction topology and facilitating the identification of abnormal substructures. This diagram corresponds to the "Dynamic Fund Flow Link Construction and Key Node Extraction" stage in abnormal fund analysis, and its value includes: intuitively identifying core aggregation and dispersal nodes of abnormal funds; tracing the propagation path of abnormal transactions and locating risk-related nodes; and assisting in the generation of subsequent monitoring strategies.
[0094] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus.
[0095] Although embodiments of the invention have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the appended claims and their equivalents.
Claims
1. An abnormal fund analysis method based on transaction records of account statements, characterized in that, The method comprises: constructing a multi-dimensional transaction feature matrix corresponding to the transaction records derived from the account statement system; based on the multi-dimensional transaction feature matrix, constructing a dynamic fund flow link reflecting the timing relationship of fund transfer across entities; extracting key nodes with fund collection and distribution attributes from the dynamic fund flow link, and assigning state mapping to the key nodes according to the fund flow direction; using historical normal transaction records to construct a reference transaction cluster, and calculating the abnormal deviation degree of the transaction records to be analyzed relative to the reference transaction cluster; According to the difference between the abnormal deviation degree and the preset compliance index, the monitoring strategy for the key node is dynamically generated; According to the monitoring strategy, the fund inflow and outflow behavior of the key node is tracked and compared in real time; Based on the results of real-time tracking and comparison, update the state mapping of the key node, and trigger the topology adjustment of the dynamic fund flow link; After the topology adjustment, re-evaluate the abnormal deviation degree, and iteratively execute the steps of dynamically generating the monitoring strategy, real-time tracking and comparison, and updating the state mapping; When the state mapping of the key node converges to a steady state, the fund behavior mode of the transaction record to be analyzed is determined; According to the fund behavior mode, output the abnormal fund analysis conclusion of the transaction record to be analyzed.
2. The method of claim 1, wherein the abnormal fund analysis based on the transaction record of the account statement is characterized by, The method comprises: analyzing the original data fields of the account statement system, separating the transaction subject identifier, the transaction counterparty identifier, the transaction timestamp, the transaction amount value and the transaction type code; Perform entity synonymous association on the transaction subject identifier and the transaction counterparty identifier, and merge them into a unified entity identifier set; Convert the transaction timestamp to a continuous time slice sequence, and accumulate and distribute the transaction amount value according to the time slice sequence; Fuse the unified entity identifier set, the time slice sequence and the accumulation and distribution statistical results to form the multi-dimensional transaction feature matrix with entity as row, time slice as column and statistical result as element.
3. The method of claim 2, wherein the abnormal fund analysis based on the transaction record of the account statement is characterized by, The method comprises: Traverse the transaction amount value of each pair of entities in the same time slice or adjacent time slice in the multi-dimensional transaction feature matrix; When the transaction amount value exceeds the direction threshold, a directed edge with timestamp and amount weight is established between the pair of entities; Aggregate all the directed edges to form the dynamic fund flow link with entity as vertex and directed edge with timestamp and amount weight as connection.
4. The method of claim 3, wherein the abnormal fund analysis based on the transaction record of the account statement is characterized by, The method comprises: Calculate the weighted in-degree and weighted out-degree of each entity in the dynamic fund flow link, which is obtained by summing the amount weight of the directed edges connected to the entity; Screening out entities with weighted in-degree or weighted out-degree exceeding a network centrality threshold, and marking as the key nodes with the fund concentration attribute; Analyzing the net fund flow direction of each key node, and assigning a corresponding state mapping label to each key node according to net inflow, net outflow or balanced state.
5. The method of claim 4, wherein the abnormal fund analysis based on the transaction record of the account statement is characterized by, The method for constructing a reference transaction cluster using historical normal transaction records and calculating the abnormal deviation degree of the transaction record to be analyzed relative to the reference transaction cluster comprises: Selecting transaction records marked as normal in a historical time period, generating a historical normal transaction feature matrix and a historical normal fund flow link according to the method for constructing a multi-dimensional transaction feature matrix corresponding to the transaction record derived from the account statement system and the method for constructing a dynamic fund flow link reflecting the timing relationship of fund transfer between entities; Performing pattern mining on the historical normal fund flow link, and classifying patterns with similar topological structure and flow distribution into one reference transaction cluster; Measuring the structural similarity and flow distribution similarity of the dynamic fund flow link corresponding to the transaction record to be analyzed and each reference transaction cluster; Selecting the minimum value of the similarity measure as the abnormal deviation degree of the transaction record to be analyzed relative to the reference transaction cluster.
6. The method of claim 5, wherein the abnormal fund analysis based on the transaction record of the account statement is characterized by, The method for dynamically generating a monitoring strategy for the key node according to the difference between the abnormal deviation degree and a preset compliance indicator comprises: Setting the compliance indicator for distinguishing between normal and suspicious fund behavior; Comparing the abnormal deviation degree and the compliance indicator, and locating the substructure with the largest difference from the reference transaction cluster in the dynamic fund flow link corresponding to the transaction record to be analyzed when the abnormal deviation degree exceeds the compliance indicator; Extracting the key nodes contained in the substructure, and generating the monitoring strategy including monitoring frequency and comparison rules for each extracted key node.
7. The method of claim 6, wherein the abnormal fund analysis based on the transaction record of the account statement is characterized by, The method for real-time tracking and comparison of the fund inflow and outflow behavior of the key node according to the monitoring strategy comprises: Periodically obtaining the fund inflow amount sequence and fund outflow amount sequence of the key node in the latest time slice according to the monitoring frequency in the monitoring strategy; Matching the fund inflow amount sequence and fund outflow amount sequence with the comparison rules in the monitoring strategy, which include the expected inflow-outflow ratio threshold and the historical same-period fluctuation range; Recording abnormal transaction events in the fund inflow amount sequence and fund outflow amount sequence that violate the comparison rules.
8. The method of claim 7, wherein the abnormal fund analysis based on the transaction record of the account statement is characterized by, The method for updating the state mapping of the key node and triggering the topological structure adjustment of the dynamic fund flow link based on the results of real-time tracking and comparison comprises: Adjusting the confidence level of the state mapping label corresponding to the key node according to the number and severity of the abnormal transaction events; If the confidence level falls below the update threshold, updating the state mapping label of the key node to a higher level of abnormal state identification. According to the updated state mapping, temporarily weakening or removing specific directed edges initiated or received by the key node and associated with the abnormal transaction event in the dynamic fund flow link, completing the topology adjustment.
9. The method of claim 8, wherein the abnormal fund analysis based on the transaction record of the account statement is characterized by, After the topology adjustment, re-evaluating the abnormal deviation degree and iteratively performing the subsequent steps include: Based on the topology-adjusted dynamic fund flow link, recalculating the structural similarity and flow distribution similarity with each reference transaction cluster to obtain a new abnormal deviation degree; Taking the new abnormal deviation degree as input, again performing the steps of dynamically generating a monitoring strategy for the key node, performing real-time tracking and comparison according to the monitoring strategy, and updating the state mapping of the key node based on the results and triggering topology adjustment; Recording the change trajectory of the state mapping label of the key node in each iteration.
10. The method of claim 9, wherein the abnormal fund analysis based on the transaction record of the account statement is characterized by, When the state mapping of the key node converges to a steady state, determining the fund behavior pattern of the transaction record to be analyzed includes: Monitoring the change trajectory of the state mapping label of the key node, and when the state mapping label and its confidence level no longer change in continuous multiple iterations, it is determined to converge to a steady state; Summarizing the final state mapping label of all key nodes in a steady state to form a vectorized expression of the fund behavior pattern of the transaction record to be analyzed; Matching the vectorized expression of the fund behavior pattern with a pre-defined abnormal pattern library, and generating an abnormal fund analysis conclusion of the transaction record to be analyzed according to the matching result.
Citation Information
Patent Citations
Financial data analysis, identification and acquisition method and system
CN120562951A
Risk monitoring method for electricity market transaction
CN120612169A
Transaction anomaly detection method and system based on financial analysis
CN120705773A
Fund backflow tracking method based on AI large model
CN121073619A
Network mapping behavior anomaly detection method and system based on machine learning
US20250358316A1