Cross-border fund flow data analysis method and system based on deep feature fusion
By employing a cross-border capital flow analysis method that combines deep feature fusion and dynamic granularity adjustment, the problems of data silos and spatiotemporal correlation in cross-border capital flow analysis are solved, enabling efficient identification and visual monitoring of complex money laundering activities.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- BEIJING WUZI UNIVERSITY
- Filing Date
- 2025-11-11
- Publication Date
- 2026-05-08
AI Technical Summary
Existing technologies for cross-border capital flow analysis systems suffer from problems such as data silos, lack of spatiotemporal joint analysis capabilities, fixed and rigid analysis granularity, and insufficient visualization, making it difficult to effectively monitor complex cross-border money laundering activities.
By integrating financial transaction data and blockchain transaction data through deep feature fusion technology, a risk time series data neighborhood model is constructed. The risk distance function is used for evaluation, and cross-system risk identification and monitoring are achieved by dynamically adjusting the analysis granularity and generating a visualized fund flow map.
It significantly improves the completeness and accuracy of cross-border capital flow analysis, enhances the timeliness of abnormal transaction identification and the efficiency of visualization, and reduces false alarm rate and computational resource consumption.
Smart Images

Figure CN121481736B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of digital transaction analysis technology, and more specifically, this application relates to a method and system for cross-border capital flow data analysis based on deep feature fusion. Background Technology
[0002] With the acceleration of global economic integration and the rapid development of digital payment technology, the scale of cross-border capital flows continues to expand, and the complexity of capital flows has increased significantly. Traditional anti-money laundering monitoring systems are mainly based on rule engines and static thresholds, which have obvious limitations in dealing with new money laundering methods.
[0003] In current technological practices, cross-border capital flow analysis mainly faces the following technical challenges:
[0004] Existing systems generally employ isolated data processing methods. Traditional financial transaction data and blockchain transaction data are processed by separate systems, creating information silos. Transaction monitoring systems in banks and other financial institutions primarily analyze structured transaction data, while blockchain data analysis systems focus on on-chain transaction graphs. There is a lack of effective data correlation and feature fusion mechanisms between the two systems. This fragmented processing approach makes it impossible to fully trace the flow of funds between the traditional financial system and the blockchain network, leaving regulatory blind spots for money laundering activities.
[0005] Existing risk assessment methods lack the ability to perform spatiotemporal joint analysis. Traditional risk scoring models are typically based on static analysis of transaction characteristics, failing to fully consider the impact of time factors on risk judgment. In practical applications, transaction behaviors with the same characteristics may have completely different risk implications at different points in time, and existing systems cannot dynamically adjust risk assessment strategies. Especially in cross-border money laundering scenarios, the time sensitivity of fund transfers is very high, and traditional systems struggle to capture money laundering patterns with time regularity in a timely manner.
[0006] Third, existing technologies lack adaptive mechanisms for adjusting the granularity of analysis. Most monitoring systems employ fixed analysis windows and correlation depths, which are either too coarse and miss risks, or too detailed and generate a large number of false alarms. For example, when analyzing cross-border capital flows, using a fixed 30-day time window may fail to detect rapid fund transfers that only take a few hours, while consistently using deep graph analysis would incur huge computational overhead and affect the system's real-time performance.
[0007] Fourth, the visualization capabilities are insufficient. Existing systems generate risk reports mostly in the form of two-dimensional charts, which make it difficult to clearly show the complex flow of funds in traditional financial channels and blockchain networks, and also fail to intuitively reflect the correlation between multiple dimensions such as time, amount, and risk, increasing the difficulty for analysts to understand and the time required for decision-making.
[0008] Especially in scenarios involving cross-border payments, money laundering often exhibits the following characteristics: dispersed transaction amounts, abnormally high transaction frequency, complex cross-chain transaction paths, and accelerated fund transfer speed. These characteristics make it more difficult for traditional monitoring technologies to detect and warn of risks in a timely manner. For example, blockchain transactions conducted through coin mixing services, or traditional bank transfers conducted through multiple shell companies, may evade detection by existing systems.
[0009] Therefore, there is a need for a cross-border capital flow analysis solution that can integrate multi-source data, dynamically adjust analysis strategies, and balance timeliness and accuracy in order to meet the increasingly complex anti-money laundering regulatory requirements. Summary of the Invention
[0010] To address the aforementioned technical issues, this technical solution provides a method and system for cross-border capital flow data analysis based on deep feature fusion, resolving the problems mentioned in the background section.
[0011] In a first aspect, embodiments of this application provide a method for cross-border capital flow data analysis based on deep feature fusion, characterized by the following steps: S1, acquiring financial transaction data and blockchain transaction data, extracting features according to an initial analysis granularity to obtain time-series feature vectors and graph feature vectors, and performing feature fusion to generate a fused feature vector; S2, constructing a risk time-series data neighborhood model, wherein: a preset ideal point is used as the neighborhood center, a risk distance function is constructed and obtained, the risk distance function is calculated based on risk offset and time decay; S3, mapping the fused feature vector to the risk time-series data neighborhood model and obtaining its corresponding position coordinates, and analyzing the risk based on the position coordinates. The distance function calculates the abnormal transaction risk score. It is determined whether the abnormal transaction risk score is greater than the preset first threshold. If it is, a first-level warning is issued; otherwise, proceed to step S4. In step S4, the initial analysis granularity is corrected based on the difference between the abnormal transaction risk score and the preset first threshold to obtain the first analysis granularity. Steps S1 to S3 are then re-executed, and the number of re-executions is recorded. This process continues until the number of re-executions reaches the preset upper limit or the Euclidean distance between the position coordinates corresponding to two adjacent abnormal transaction risk scores is less than the preset second threshold. The abnormal transaction risk score after the execution is completed is then obtained. In step S5, it is determined whether the abnormal transaction risk score after the execution is completed is greater than the preset first threshold. If it is, a second-level warning is issued, and a visualized fund flow chart is output.
[0012] Secondly, this application provides a cross-border capital flow data analysis system based on deep feature fusion, characterized by comprising: a data acquisition module: used to acquire financial transaction data and blockchain transaction data and extract features according to an initial analysis granularity to obtain time-series feature vectors and graph feature vectors, and perform feature fusion to generate a fused feature vector; a data construction module: used to construct a risk time-series data neighborhood model, wherein: a preset ideal point is used as the neighborhood center, a risk distance function is constructed and obtained, and the risk distance function is calculated based on the risk offset and time decay; a data judgment first module: used to map the fused feature vector to the risk time-series data neighborhood model and obtain its corresponding position coordinates, and calculate the risk distance function based on the position coordinates using the risk distance function. Upon receiving the abnormal transaction risk score, the system determines whether the score exceeds a preset first threshold. If so, a Level 1 warning is issued; otherwise, the system proceeds to the second data judgment module. The second data judgment module adjusts the initial analysis granularity based on the difference between the abnormal transaction risk score and the preset first threshold, obtaining a first analysis granularity. It then re-executes the data acquisition module and the first data judgment module, recording the number of re-executions until the number of re-executions reaches a preset upper limit or the Euclidean distance between the position coordinates corresponding to two adjacent abnormal transaction risk scores is less than a preset second threshold. This process yields the abnormal transaction risk score after execution. The data output module determines whether the abnormal transaction risk score after execution exceeds the preset first threshold. If so, a Level 2 warning is issued, and a visualized fund flow chart is output.
[0013] One or more technical solutions provided in the embodiments of this application have at least the following technical effects or advantages:
[0014] 1. By employing a multi-dimensional data feature fusion mechanism, the completeness of cross-border capital flow analysis is significantly improved. The system simultaneously processes the temporal characteristics of financial transaction data and the graph characteristics of blockchain transaction data, generating a comprehensive fused feature vector through feature fusion. This multi-source data fusion method overcomes the limitations of traditional single data sources, constructs a more comprehensive expression of capital flow characteristics, and provides a sufficient data foundation for accurately identifying abnormal transaction patterns.
[0015] 2. At the risk assessment level, an innovative spatiotemporal joint assessment model was constructed. By establishing a risk time-series data neighborhood model centered on a preset ideal point, risk offset and time decay are jointly incorporated into the risk distance function calculation. The time decay is quantified using an exponential decay function. This design allows risk assessment to not only focus on the spatial distribution characteristics of capital behavior but also fully consider the impact of dynamic changes in transaction time, achieving spatiotemporal dual-dimensional coverage of risk monitoring and significantly improving the accuracy and timeliness of abnormal transaction identification.
[0016] 3. It possesses intelligent adaptive adjustment capabilities for analytical precision. When the risk score of an abnormal transaction fails to reach a preset first threshold, the system can dynamically adjust the analytical granularity based on the difference between the risk score and the threshold, continuously refining the parameter settings for feature extraction and risk assessment through an iterative optimization process. This adaptive mechanism ensures that the system employs the most appropriate analytical precision when facing transactions of different risk levels, avoiding resource waste caused by over-analysis and preventing missed detections due to insufficient analysis, significantly improving the system's practicality and reliability in real-world applications. Attached Figure Description
[0017] Figure 1 A schematic diagram of the structure of the cross-border capital flow data analysis method based on deep feature fusion provided in the embodiments of this application;
[0018] Figure 2 A schematic diagram of the analysis granularity adjustment logic based on deep feature fusion provided for embodiments of this application;
[0019] Figure 3 A schematic diagram of the structure of a cross-border capital flow data analysis system based on deep feature fusion provided in this application embodiment. Detailed Implementation
[0020] Current technologies for analyzing cross-border capital flows face significant bottlenecks, including data silos, insufficient spatiotemporal correlation analysis capabilities, and rigid, fixed analytical granularity. Traditional systems process financial transaction data and blockchain data separately, resulting in incomplete tracking of capital flow paths. Risk assessment models lack dynamic adjustment mechanisms for the time dimension, making it difficult to capture time-sensitive money laundering patterns. Fixed analysis windows and correlation depths can easily lead to underreporting or false alarms, affecting the effectiveness of monitoring. A cross-border payment platform discovered that funds transferred through coin mixing services appeared as normal transactions in traditional banking systems, but related transactions in the blockchain network were not effectively linked, and existing monitoring systems failed to identify this money laundering chain.
[0021] To address the aforementioned issues, this study focuses on multi-source data fusion, dynamic risk modeling, and adaptive analysis. First, it recognizes the need to integrate the cross-system characteristics of fund flows and attempts to construct a unified feature space. Second, it identifies the time-decaying nature of risk, necessitating the development of an assessment model incorporating a time dimension. Third, it observes the need for differentiated analytical precision across different risk levels, leading to the exploration of an adaptive granularity mechanism. By introducing deep feature fusion technology, temporal and topological features are organically combined. When designing the risk distance function, risk offset and time decay are dynamically integrated. Finally, a dynamic adjustment strategy for analytical granularity is established to achieve a balance between detection accuracy and computational efficiency.
[0022] Therefore, this application proposes to acquire financial transaction data and blockchain transaction data, extract and fuse features to generate a fused feature vector; construct a risk time series data neighborhood model centered on a preset ideal point, calculate the risk score of abnormal transactions through a risk distance function; determine the triggering of early warning based on the risk score threshold, optimize the detection accuracy by dynamically adjusting the analysis granularity, and finally output a visualized fund flow map.
[0023] Compared to existing technologies, this solution achieves a breakthrough by deeply integrating traditional financial data with blockchain data, constructing a dynamic risk assessment space that includes a time decay factor. Through an adaptive adjustment mechanism for analysis granularity, it effectively balances detection sensitivity and computational resource consumption. Compared to traditional fixed-threshold monitoring systems, this method can capture short-term, high-frequency abnormal transaction patterns and accurately identify cross-system money laundering activities. Three-dimensional visualization technology solves the problem of two-dimensional charts being unable to display complex fund flows, providing a three-dimensional analytical view for risk assessment.
[0024] Through the above technical solutions, this application effectively solves the monitoring blind spot problem caused by isolated processing of multi-source data, and improves the accuracy of identifying abnormal cross-border capital flows. The dynamic adjustment mechanism enables the system to adapt to the detection needs of different risk levels, improving the detection rate of high-risk transactions while ensuring real-time performance. The spatiotemporal joint analysis model significantly enhances the timeliness of risk warnings, enabling timely blocking of time-sensitive money laundering operations. Improvements in visualization technology reduce the complexity of manual analysis and increase regulatory efficiency by approximately 40%.
[0025] To better understand the above technical solutions, the following will provide a detailed explanation of the technical solutions in conjunction with the accompanying drawings and specific implementation methods.
[0026] like Figure 1The diagram shown is a structural schematic of the cross-border capital flow data analysis method based on deep feature fusion provided in this application embodiment, including the following steps: S1, acquiring financial transaction data and blockchain transaction data, extracting features according to the initial analysis granularity to obtain time-series feature vectors and graph feature vectors, and performing feature fusion to generate a fused feature vector; S2, constructing a risk time-series data neighborhood model, wherein: a preset ideal point is used as the neighborhood center, a risk distance function is constructed and obtained, and the risk distance function is calculated based on the risk offset and time decay; S3, mapping the fused feature vector to the risk time-series data neighborhood model and obtaining its corresponding position coordinates, and then analyzing the risk based on the position coordinates. The distance function calculates the abnormal transaction risk score. It is determined whether the abnormal transaction risk score is greater than the preset first threshold. If it is, a first-level warning is issued; otherwise, proceed to step S4. In step S4, the initial analysis granularity is corrected based on the difference between the abnormal transaction risk score and the preset first threshold to obtain the first analysis granularity. Steps S1 to S3 are then re-executed, and the number of re-executions is recorded. This process continues until the number of re-executions reaches the preset upper limit or the Euclidean distance between the position coordinates corresponding to two adjacent abnormal transaction risk scores is less than the preset second threshold. The abnormal transaction risk score after the execution is completed is then obtained. In step S5, it is determined whether the abnormal transaction risk score after the execution is completed is greater than the preset first threshold. If it is, a second-level warning is issued, and a visualized fund flow chart is output.
[0027] The initial analysis granularity refers to the length of the time window for data feature extraction and the depth of the association network. Specifically, it can be achieved by using a sliding time window and an association degree threshold, such as setting a 48-hour time window and a one-degree association network.
[0028] Feature fusion processing refers to concatenating or weighting temporal feature vectors and spectral feature vectors in a unified feature space. Specifically, it can be implemented using a neural network feature concatenation layer or an attention mechanism fusion layer to retain feature information from different data sources.
[0029] The risk time series data neighborhood model refers to a risk assessment spatial model that includes time decay factors. Specifically, it can be constructed using a two-dimensional coordinate system, with the horizontal axis representing the risk offset and the vertical axis representing the time decay, to comprehensively assess the spatiotemporal characteristics of risk.
[0030] Location coordinate mapping refers to converting fused feature vectors into coordinate points in the model space. This can be achieved using linear transformation or nonlinear embedding methods to quantify the spatial location of risk states.
[0031] Granularity adjustment refers to adjusting feature extraction parameters based on the difference between the risk score and the threshold. This can be achieved by querying a preset granularity configuration table.
[0032] A visualized fund flow map is a three-dimensional display that integrates traditional financial paths with blockchain paths. Specifically, it can be generated using three-dimensional network graph rendering technology to intuitively present fund flow paths and risk distribution.
[0033] Specifically, this method first simultaneously acquires bank transfer records and blockchain transaction logs. It then extracts transaction frequency trend features and address association features using a preset initial time window and association depth. These two feature vectors are input into a fusion layer to generate a unified feature representation, which is mapped to a two-dimensional risk space containing a time decay axis. The risk distance between this coordinate point and the ideal point is calculated, and an alert is triggered when the score exceeds a threshold. For cases approaching the threshold, the analysis time window is automatically shortened, and the network association layers are deepened for recalculation. Iterative optimization improves detection accuracy. Finally, for confirmed high-risk transactions, a three-dimensional fund flow map containing both traditional accounts and blockchain addresses is generated.
[0034] Furthermore, generating a fused feature vector specifically includes: acquiring financial transaction data and blockchain transaction data; processing the financial transaction data using a time-series analysis model based on a preset initial analysis granularity to extract transaction frequency trend features, amount fluctuation features, and time distribution features, generating a time-series feature vector; processing the blockchain transaction data using a graph analysis model based on a preset initial analysis granularity to extract address association features, transaction path features, and network topology features, generating a graph feature vector; and fusing the time-series feature vector and the graph feature vector to generate a fused feature vector.
[0035] In this embodiment, the time series analysis model refers to the feature extraction model used to process time series data. Specifically, it can be implemented using a long short-term memory network or a temporal convolutional network to extract transaction frequency trend features, amount fluctuation features, and time distribution features from financial transaction data.
[0036] Graph analysis models refer to feature extraction models used to process graph-structured data. Specifically, they can be implemented using graph neural networks or graph embedding algorithms to extract address association features, transaction path features, and network topology features from blockchain transaction data.
[0037] Feature fusion processing refers to the operation of integrating feature vectors from different modalities. Specifically, it can be achieved by feature concatenation, weighted summation, or attention mechanisms to generate fused feature vectors containing multidimensional information.
[0038] Specifically, in the implementation process, transaction data is first obtained from cross-border payment systems of financial institutions and blockchain explorers. For financial transaction data, an initial analysis granularity is set, such as a time window on a daily basis, and time-series analysis models are used to extract time-series features reflecting the trend of fund flows. For blockchain transaction data, transaction paths between addresses are analyzed based on the same time window, and topological features reflecting the relationship of fund transfers are extracted using graph analysis models. Subsequently, the two types of feature vectors are input into a fusion module. For example, feature concatenation is used to merge the time-series feature vector and the graph feature vector into a high-dimensional vector, which is then subjected to dimensionality reduction processing through a fully connected layer, ultimately generating a fused feature vector that can simultaneously represent temporal dynamics and network relationships.
[0039] By fusing temporal and graphical features, the risk analysis model can simultaneously capture the temporal patterns of fund flows and cross-chain transfer paths, significantly improving its ability to identify complex cross-border money laundering activities. For example, when detecting money laundering activities that combine multi-bank transfers with blockchain coin mixing services, the fused features can simultaneously reflect the temporal clustering of traditional transactions and the abnormal correlation of blockchain addresses, thereby more accurately identifying hidden risks.
[0040] Furthermore, the specific process of constructing and obtaining the risk distance function is as follows: A preset attenuation coefficient is extracted from the cross-border capital flow database; the risk offset is obtained by calculating the Euclidean distance between the fused feature vector and the preset unit vector of the preset ideal point in the feature space; the time interval is calculated based on the transaction timestamps extracted from financial transaction data and blockchain transaction data and the current time, and the time decay is calculated using the exponential decay function. The specific calculation formula for the time decay is as follows: ,in, Indicates the amount of time decay. Represents the natural constant. This indicates the preset attenuation coefficient. The time interval is represented; the risk distance is calculated by weighted summation based on the risk offset and time decay. The specific risk distance function is as follows: ,in, Indicates risk distance, Indicates the risk offset. This indicates the preset first weight. This indicates that a second weight is preset. .
[0041] In this embodiment, the preset attenuation coefficient is a parameter that controls the degree of influence of time factors on risk. Specifically, it can be obtained by training on the time distribution pattern of risk events in historical transaction data, and is used to dynamically adjust the risk weight of transactions at different time intervals.
[0042] Risk offset refers to the degree of deviation between the current trading characteristics and the ideal safe state. Specifically, it can be obtained by calculating the difference in the projection of the feature vector in Euclidean space, and is used to quantify the degree of abnormality in trading behavior.
[0043] Time decay refers to the impact of the transaction time on the current risk assessment. Specifically, it can be calculated using an exponential function, where the value decreases exponentially as the time interval increases.
[0044] The risk distance function is a risk quantification model that integrates spatiotemporal factors. Specifically, it can combine risk offset and time decay through linear weighting, where the weighting coefficients can be dynamically configured according to regulatory requirements.
[0045] In the analysis of cross-border capital flows, a preset decay coefficient is first obtained from the database; for example, this coefficient could be 0.05, used to control the calculation rate of time decay. By calculating the Euclidean distance between the fused feature vector and a preset ideal point, a risk offset representing the degree of transaction anomaly is obtained. For example, this value will significantly increase when the transaction amount suddenly increases or the transaction path is abnormal. Based on the difference between the transaction timestamp and the current time, the time decay is calculated using an exponential decay function; for example, the time decay of a transaction three days ago might be 0.86, while a transaction thirty days ago might decay to 0.22. The risk offset and time decay are then linearly combined according to preset weights; for example, when α is set to 0.7 and β to 0.3, the risk distance calculation will place greater emphasis on the degree of anomaly of the current transaction characteristics.
[0046] By dynamically attenuating the influence weight of historical transactions, the system avoids interference from outdated data in current risk assessments. For example, it can automatically lower the risk score of historical transactions that have already undergone compliance review. The adjustable weight configuration mechanism allows the system to adapt to different business scenarios; for instance, in blockchain high-frequency transaction monitoring, the time decay weight can be increased to enhance real-time risk detection capabilities. The application of the exponential decay function ensures the non-linear impact of time factors, accurately reflecting the time sensitivity of rapid fund transfers in money laundering activities.
[0047] Furthermore, the specific process of mapping the fused feature vector to the risk time series data neighborhood model and obtaining its corresponding position coordinates is as follows: taking a preset ideal point as the origin of the coordinate system, the position coordinates of the fused feature vector in the two-dimensional coordinate system are calculated through a coordinate transformation algorithm. The specific formula of the coordinate transformation algorithm is as follows: ; ;in, The x-coordinate represents the position coordinates. The ordinate represents the position coordinates. Indicates the risk offset. Indicates the amount of time decay. This represents the coordinate rotation angle. The coordinate rotation angle is calculated through the following steps: Based on the variance distribution of the fused feature vector in the preset first dimension and the preset second dimension, the variance of the fused feature vector in the preset first dimension and the variance of the fused feature vector in the preset second dimension are obtained, and the coordinate rotation angle is calculated accordingly. The formula for calculating the coordinate rotation angle is: ,in, This represents the variance of the fused feature vector in the preset first dimension. This represents the variance of the fused feature vector in the preset second dimension.
[0048] In this embodiment, the preset ideal point refers to the benchmark point set in the risk time series data neighborhood model. Specifically, it can be implemented by using the mean or median of the feature vectors of historical normal transaction data, and is used as the origin of the coordinates to measure the degree of risk deviation of the current transaction data.
[0049] Coordinate transformation algorithms refer to the calculation rules that map multidimensional feature vectors to two-dimensional space. Specifically, they can be implemented by combining polar coordinate transformation with dimensional projection, and by using trigonometric function transformation to convert risk offset and time decay into planar coordinate parameters.
[0050] Risk offset refers to the degree of deviation between the fused feature vector and the preset ideal point in the feature space. Specifically, it can be achieved by calculating Euclidean distance or cosine similarity, and is used to characterize the difference between trading behavior and normal patterns.
[0051] Time decay refers to the dynamic adjustment coefficient of the impact of transaction time on risk. Specifically, it can be implemented by using an exponential function combined with a preset decay coefficient to reflect the weight of the impact of the transaction time on the current time on risk assessment.
[0052] The coordinate rotation angle refers to the rotation parameter of a two-dimensional coordinate system. Specifically, it can be achieved by calculating the variance ratio of the feature vector in different dimensions, and is used to adjust the direction of the coordinate axes to adapt to different data distribution characteristics.
[0053] Variance distribution refers to the degree of dispersion of feature vectors in a preset dimension. Specifically, it can be achieved by calculating the sample variance or standard deviation, and is used to determine the coordinate rotation angle to optimize the spatial representation of risk offset.
[0054] When determining the position coordinates of the fused feature vector, a two-dimensional coordinate system is first constructed using a preset ideal point as the origin. The risk offset and time decay are converted into planar coordinate parameters using formulas in the coordinate transformation algorithm. The θ value is determined by calculating the variance ratio of the feature vector in two preset dimensions. When calculating the variance distribution, the data distribution of the fused feature vector in the preset first and second dimensions is extracted. For example, the first dimension could be the transaction amount fluctuation feature, and the second dimension could be the transaction path complexity feature. The calculated rotation angle dynamically adjusts the coordinate axis direction, aligning the X-axis of the coordinate system with the dimension with the largest data variance, thus preserving the most important risk feature information during dimensionality reduction. This dynamic coordinate rotation mechanism allows transaction data from different batches or scenarios to automatically adapt to the optimal coordinate system, improving the accuracy of risk positioning.
[0055] Through a dynamic coordinate rotation mechanism, the coordinate axis orientation can be automatically optimized based on the actual data distribution, resulting in more accurate spatial representations of risk offset and time decay. Simultaneously, by mapping multi-dimensional feature vectors to an optimized two-dimensional coordinate system, computational complexity is significantly reduced while preserving key risk information, providing a technical foundation for real-time risk warning. This solution is particularly suitable for processing cross-border capital flow data with spatiotemporal correlation characteristics, effectively capturing the coupling characteristics of abnormal capital flow patterns in both time and space dimensions.
[0056] Furthermore, the specific process of calculating the abnormal transaction risk score based on the location coordinates using the risk distance function is as follows: Based on the location coordinates, calculate the normalized distance from the location coordinates to the preset ideal point; the formula for calculating the normalized distance is as follows: ,in, This represents the preset maximum normalized distance. This represents the normalized distance; the normalized distance is input into a preset risk score conversion function to calculate the abnormal transaction risk score. The risk score conversion function is as follows: ,in, Indicates the risk score of abnormal transactions. Represents the natural constant. This indicates the preset sensitivity coefficient.
[0057] In this embodiment, the normalized distance refers to the value after standardizing the geometric distance from the location coordinates to the ideal point. Specifically, it can be achieved by using the ratio of the square of the Euclidean distance to the preset maximum distance, which is used to eliminate the difference in dimensions under different transaction scenarios.
[0058] The preset maximum normalized distance refers to the upper limit of the risk distance determined based on the analysis of historical transaction data. For example, it can be 1.2 times the historical maximum risk distance, which is used to constrain the normalization calculation range.
[0059] The risk score transformation function is a mathematical function that maps normalized distance to a risk score interval. Specifically, it can be implemented using an exponential function, and the sensitivity of the risk score can be controlled by a preset sensitivity coefficient.
[0060] The preset sensitivity coefficient refers to the adjustment parameter that controls the rate of change of risk score with distance. For example, it can be a value between 0.5 and 1.5 to adapt to the sensitivity requirements of different regulatory scenarios.
[0061] In the risk time-series data neighborhood model, the horizontal and vertical coordinates of the location represent the risk offset and time decay, respectively. By calculating the normalized distance from the coordinate point to the ideal point, multidimensional risk characteristics are transformed into scalar values with uniform dimensions. This normalization process makes transaction data from different time spans comparable; for example, transactions from three days ago and transactions from three hours ago can be assessed for risk on the same scale. Subsequently, the risk score transformation function nonlinearly maps the normalized distance to the 0-1 interval. When k is 1, the distance is 63% of the maximum distance, corresponding to a risk score of 0.5. This transformation method allows a warning to be triggered at a moderate risk distance without reaching the maximum distance threshold. The preset sensitivity coefficient can be dynamically adjusted according to regulatory strategies; for example, it can be set to 1.2 during periods of strict regulation to improve the sensitivity of risk identification.
[0062] Normalization enables risk comparability across time spans, for example, placing large transactions from three days ago in the same assessment framework as current small transactions. The non-linear nature of the risk score transformation function enhances the sensitivity to potential risk identification, enabling the timely detection of suspicious transactions where the risk distance is rapidly increasing but has not yet reached a threshold. The introduction of a preset sensitivity coefficient provides a dynamic adjustment mechanism; for example, the sensitivity coefficient can be temporarily increased during anti-money laundering campaigns to enhance monitoring intensity, while it can be appropriately decreased during regular regulatory periods to reduce false alarms.
[0063] Furthermore, the specific process of obtaining the first analysis granularity and re-executing S1 to S3 accordingly, and recording the number of re-executings, is as follows: calculate the difference between the abnormal transaction risk score and the preset first threshold; based on the magnitude of the difference, query the corresponding analysis granularity parameter from the preset granularity configuration table; update the initial analysis granularity according to the queried analysis granularity parameter to obtain the first analysis granularity; re-executing steps S1 to S3 based on the first analysis granularity to generate the updated fusion feature vector and recalculate the abnormal transaction risk score.
[0064] In this embodiment, the difference refers to the numerical difference between the current risk score and the preset risk threshold, which can be achieved by arithmetic subtraction. This difference reflects the degree of matching between the risk detection sensitivity of the current analysis granularity and the actual needs.
[0065] A granularity configuration table is a data structure that stores the mapping relationship between different difference ranges and corresponding analysis granularity parameters. Specifically, it can be implemented using a hash table or a key-value database, and can quickly match the optimal analysis parameters through predefined difference ranges.
[0066] The analysis granularity parameters include the duration of the time series analysis window and the depth of the graph association. Specifically, the timestamp slicing algorithm and the adjacency matrix traversal algorithm can be used to control the fineness of feature extraction and the scope of association.
[0067] When an anomaly risk score is detected and falls below the warning threshold, the system automatically calculates the risk deviation. By querying a pre-defined granularity configuration table, it selects a more refined or coarser combination of analysis parameters based on the degree of deviation. The updated analysis granularity is applied to a new round of feature extraction, generating a fusion vector containing higher-frequency temporal features and broader correlation features. The recalculated risk score reflects the adjusted detection sensitivity, iteratively optimizing to gradually approach the true risk level.
[0068] By establishing a difference response mechanism and parameter mapping table, dynamic optimization and adjustment of the analysis granularity are achieved, enabling the feature extraction process to automatically adapt to the needs of different risk scenarios. This adaptive mechanism significantly reduces the computational overhead of repetitive analysis while ensuring the accuracy of risk detection, providing a more efficient solution for monitoring cross-border capital flows.
[0069] Furthermore, the configuration rules for the granularity configuration table include: when the difference is less than or equal to a preset first difference threshold, the corresponding time series analysis window is configured as the first duration, and the graph analysis depth is second-degree correlation; when the difference is greater than the preset first difference threshold and less than or equal to a preset second difference threshold, the corresponding time series analysis window is configured as the second duration, and the graph analysis depth is third-degree correlation; when the difference is greater than the preset second difference threshold, the corresponding time series analysis window is configured as the third duration, and the graph analysis depth is full-path correlation; the first duration is greater than the second duration, and the second duration is greater than the third duration.
[0070] In this embodiment, the granularity configuration table refers to a preset data structure that stores the mapping relationship between different risk difference ranges and analysis granularity parameters. Specifically, it can be implemented using a hash table or a two-dimensional array, and is used to quickly match the corresponding analysis parameters based on the real-time risk difference.
[0071] The difference refers to the numerical difference between the abnormal transaction risk score and the preset first threshold. It can be calculated by subtraction and is used to quantify the degree of deviation between the current risk level and the warning standard.
[0072] The time series analysis window refers to the length of the time range used to extract time series features. For example, it can be set to 30 days, 7 days, or 24 hours. Shortening it will enhance the sensitivity to recent trading patterns.
[0073] Graph analysis depth refers to the association level of blockchain transaction paths. For example, second-degree association only analyzes direct counterparties, while full-path association tracks all historical transaction links. Deepening this depth can improve the ability to identify complex money laundering paths.
[0074] When an abnormal transaction risk score is detected and fails to reach the warning threshold, the system determines the degree of risk deviation by calculating the risk difference.
[0075] When the risk difference is in a low range, a longer time series analysis window and a shallower graph correlation level are used. For example, a 30-day window is used to analyze cyclical trading patterns, while only tracking direct counterparty relationships, thereby reducing computational overhead while ensuring basic detection capabilities.
[0076] As the risk difference increases to a medium range, the time window is shortened to 7 days to focus on recent high-frequency trading, and the graph analysis is expanded to three-dimensional correlation to capture indirect fund flow paths. When the risk difference exceeds a high threshold, a 24-hour window is used to monitor fund anomalies in real time, and full-path correlation analysis is initiated to reconstruct the complete fund flow.
[0077] This tiered adjustment mechanism dynamically controls the granularity of analysis based on risk levels, prioritizing system efficiency when risks are low and automatically enhancing detection accuracy when risks increase.
[0078] By employing coarse-grained analysis to reduce unnecessary calculations, over-detection of normal transactions is avoided. In medium- to high-risk scenarios, a progressively refined analysis strategy significantly improves the identification rate of complex money laundering patterns. Especially when dealing with time-sensitive rapid fund transfers, the dynamically shortened time window can promptly capture changes in abnormal transaction rhythms, while deep graph analysis can accurately reconstruct cross-chain fund flow paths, forming a dual detection guarantee in both spatiotemporal dimensions.
[0079] Furthermore, the abnormal transaction risk score after execution is obtained, specifically including: initializing the execution counter and setting a preset maximum number of executions; incrementing the execution counter after each re-execution and recording the abnormal transaction risk score calculated for the current number of executions and its corresponding position coordinates; calculating the Euclidean distance between the position coordinates obtained from two adjacent executions, the formula for calculating the Euclidean distance is: ,in, Represents Euclidean distance. , Indicates the first The position coordinates of the next execution. , This represents the position coordinates of the (i-1)th execution. When the execution counter reaches the preset maximum number of executions or the Euclidean distance is less than the preset second threshold, the re-execution process is stopped, and the abnormal transaction risk score after the execution is completed is obtained.
[0080] In this embodiment, Figure 2 This is a schematic diagram of the analysis granularity adjustment logic based on deep feature fusion provided in the embodiments of this application; the execution counter refers to a counting device used to record the number of times the loop is executed, which can be implemented by accumulating memory variables, and is used to control the loop termination condition to prevent infinite iteration.
[0081] The preset maximum number of executions refers to the upper limit of the number of loops set in advance. The specific value can be set through the configuration file to ensure that the consumption of computing resources is within a controllable range.
[0082] Location coordinates refer to the projected coordinates of the feature vector in two-dimensional space. Specifically, they can be calculated through coordinate transformation algorithms and are used to quantify the spatial location of risk distribution.
[0083] Euclidean distance refers to the straight-line distance between two adjacent calculation positions. It can be calculated by taking the square root of the difference of squares and is used to measure the convergence of risk assessment results during the iteration process.
[0084] During the risk analysis process, the execution counter is first initialized and a maximum execution threshold is set. After each feature granularity adjustment, the execution counter automatically increments, and the currently calculated anomaly risk score and its corresponding coordinate position are stored in a cache queue.
[0085] By calculating the Euclidean distance between two adjacent coordinates, fluctuations in the risk assessment results can be dynamically monitored. When the number of executions reaches a preset upper limit or the coordinate fluctuation amplitude falls below a set threshold, the iteration process terminates and the final risk score is output.
[0086] For example, the maximum number of executions can be set to 5, and the second threshold can be set to 0.1 unit distance. When the coordinate distance calculated in two consecutive calculations is less than the threshold, it is determined that the result has converged.
[0087] By employing a dual judgment mechanism of execution counters and coordinate convergence, the analysis process ensures stable and reliable risk assessment results with reasonable resource consumption. In cross-border fund monitoring scenarios, this solution can adaptively adjust the computational depth, achieving a dynamic balance between detection accuracy and system load, and avoiding a decrease in real-time performance due to over-computation.
[0088] Furthermore, the specific process of outputting a visualized fund flow map includes: extracting relevant transaction path data from corresponding financial transaction data and blockchain transaction data based on the finally determined abnormal transaction risk score; constructing an overlay graph data structure containing traditional financial transaction paths and blockchain transaction paths; assigning corresponding risk level labels to different transaction paths according to the magnitude of the abnormal transaction risk score; and generating a three-dimensional visualized chart data of the transaction paths containing risk level labels.
[0089] In this embodiment, the overlay graph data structure refers to a composite data structure formed by topologically overlaying traditional financial transaction paths and blockchain transaction paths. Specifically, it can be implemented using multi-layer overlay technology in graph databases. By establishing node mapping relationships across data sources, the visualization and integration of different transaction networks can be achieved.
[0090] Risk level markings refer to visual markers that divide risk levels into ranges. These can be achieved using color coding or shape coding, for example, marking high-risk routes as red, medium-risk routes as yellow, and low-risk routes as green.
[0091] Three-dimensional visualization chart data refers to a three-dimensional display format that includes spatial coordinate axes, time axes, and risk dimensions. Specifically, it can be implemented using WebGL technology combined with a time axis sliding control, reflecting the intensity of capital flow through changes in the thickness of the connecting lines in three-dimensional space.
[0092] After completing the iterative calculation of risk scores, the system extracts transaction paths related to anomaly scores from the raw data processed by feature fusion. These paths include both traditional financial paths formed by bank transfer records and transfer links between blockchain addresses. By constructing an overlay graph, the system establishes a correlation mapping between transaction nodes in both types of paths, for example, arranging bank accounts and associated blockchain addresses adjacently in the spatial dimension. In the visualization rendering stage, based on the final risk score of each path, a color is automatically assigned according to a preset threshold range, and the transaction time is mapped to the Z-axis to form a time dimension. In the final generated 3D chart, the direction of fund flow is represented by 3D lines with arrows, and the transparency parameter of the lines reflects the proximity of the transaction time, forming a visual analysis interface of spatiotemporal correlation.
[0093] By constructing an overlay graph data structure, this project achieves, for the first time, joint visualization and analysis of traditional banking transactions and blockchain transactions. Existing technologies often use static labels for risk identification, while this solution updates labels in real time based on dynamically calculated risk scores, significantly improving the efficiency of risk path identification. Furthermore, the 3D visualization format overcomes the limitations of 2D charts in representing the time dimension; through a layered layout in three-dimensional space, it can simultaneously display the spatial topology and temporal evolution of fund flows.
[0094] like Figure 3 The diagram shown is a structural schematic of a cross-border capital flow data analysis system based on deep feature fusion provided in this application embodiment. It includes: a data acquisition module for acquiring financial transaction data and blockchain transaction data, extracting features according to the initial analysis granularity, obtaining time-series feature vectors and graph feature vectors, and performing feature fusion to generate a fused feature vector; a data construction module for constructing a risk time-series data neighborhood model, wherein: a preset ideal point is used as the neighborhood center, a risk distance function is constructed and obtained, and the risk distance function is calculated based on the risk offset and time decay; and a data judgment first module for mapping the fused feature vector to the risk time-series data neighborhood model and obtaining its corresponding position coordinates, and calculating the risk distance function based on the position coordinates using the risk distance function. Upon receiving the abnormal transaction risk score, the system determines whether the score exceeds a preset first threshold. If so, a Level 1 warning is issued; otherwise, the system proceeds to the second data judgment module. The second data judgment module adjusts the initial analysis granularity based on the difference between the abnormal transaction risk score and the preset first threshold, obtaining a first analysis granularity. It then re-executes the data acquisition module and the first data judgment module, recording the number of re-executions until the number of re-executions reaches a preset upper limit or the Euclidean distance between the position coordinates corresponding to two adjacent abnormal transaction risk scores is less than a preset second threshold. This process yields the abnormal transaction risk score after execution. The data output module determines whether the abnormal transaction risk score after execution exceeds the preset first threshold. If so, a Level 2 warning is issued, and a visualized fund flow chart is output.
[0095] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0096] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, as well as combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0097] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0098] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0099] Although preferred embodiments of the invention have been described, those skilled in the art, upon learning the basic inventive concept, can make other changes and modifications to these embodiments. Therefore, the appended claims are intended to be interpreted as including both the preferred embodiments and all changes and modifications falling within the scope of the invention.
[0100] Obviously, those skilled in the art can make various modifications and variations to this invention without departing from its spirit and scope. Therefore, if these modifications and variations fall within the scope of the claims of this invention and their equivalents, this invention also intends to include these modifications and variations.
Claims
1. A cross-border capital flow data analysis method based on deep feature fusion, characterized in that, Includes the following steps: S1. Acquire financial transaction data and blockchain transaction data, extract features according to the initial analysis granularity, obtain time-series feature vectors and graph feature vectors, and perform feature fusion to generate a fused feature vector; S2. Construct a risk time series data neighborhood model, wherein: a preset ideal point is used as the neighborhood center, and a risk distance function is constructed and obtained. The risk distance function is calculated based on the risk offset and the time decay. S3. Map the fused feature vector to the risk time series data neighborhood model and obtain its corresponding position coordinates. Calculate the abnormal transaction risk score based on the position coordinates using the risk distance function. Determine whether the abnormal transaction risk score is greater than the preset first threshold. If yes, issue a first-level warning; otherwise, proceed to S4. S4. Correct the initial analysis granularity based on the difference between the abnormal transaction risk score and the preset first threshold to obtain the first analysis granularity. Then, re-execute S1 to S3 and record the number of re-executions until the number of re-executions reaches the preset upper limit or the Euclidean distance between the position coordinates corresponding to the abnormal transaction risk scores of two adjacent times is less than the preset second threshold. Then, obtain the abnormal transaction risk score after the execution is completed. S5. Determine whether the abnormal transaction risk score after the execution is greater than the preset first threshold. If so, issue a second-level warning and output a visual fund flow chart. The specific process of mapping the fused feature vector to the risk time series data neighborhood model and obtaining its corresponding location coordinates is as follows: The risk time series data neighborhood model refers to a risk assessment spatial model that includes time decay factors. Specifically, it is constructed using a two-dimensional coordinate system, with the horizontal axis representing the risk offset and the vertical axis representing the time decay, and is used to comprehensively assess the spatiotemporal characteristics of risk. Using the preset ideal point as the origin, the position coordinates of the fused feature vector in the two-dimensional coordinate system are calculated through a coordinate transformation algorithm. The specific formula of the coordinate transformation algorithm is as follows: ; ; in, The x-coordinate represents the position coordinates. The ordinate represents the position coordinates. Indicates the risk offset. Indicates the amount of time decay. Indicates the rotation angle of the coordinate system; The coordinate rotation angle is calculated through the following steps: Based on the variance distribution of the fused feature vector in the preset first dimension and the preset second dimension, the variance of the fused feature vector in the preset first dimension and the variance of the fused feature vector in the preset second dimension are obtained, and the coordinate rotation angle is calculated accordingly. The formula for calculating the coordinate rotation angle is as follows: ,in, This represents the variance of the fused feature vector in the preset first dimension. This represents the variance of the fused feature vector in the preset second dimension.
2. The cross-border capital flow data analysis method based on deep feature fusion according to claim 1, characterized in that, The generation of the fused feature vector specifically includes: Acquiring financial transaction data and blockchain transaction data; Based on the preset initial analysis granularity, the financial transaction data is processed using a time series analysis model to extract transaction frequency trend features, amount fluctuation features and time distribution features, and generate time series feature vectors. Based on the preset initial analysis granularity, the graph analysis model is used to process the blockchain transaction data, extract address association features, transaction path features and network topology features, and generate graph feature vectors. The temporal feature vector and the spectral feature vector are fused to generate a fused feature vector.
3. The cross-border capital flow data analysis method based on deep feature fusion according to claim 1, characterized in that, The specific process of constructing and obtaining the risk distance function is as follows: The preset attenuation coefficient is obtained by extracting it from the cross-border capital flow database; The risk offset is obtained by calculating the Euclidean distance between the fused feature vector and the preset unit vector of the preset ideal point in the feature space; Based on the transaction timestamps extracted from the aforementioned financial transaction data and blockchain transaction data, and the current time, the time interval is calculated, and the time decay is calculated using an exponential decay function. The specific formula for calculating the time decay is as follows: ,in, Indicates the amount of time decay. Represents the natural constant. Indicates the preset attenuation coefficient. Indicates a time interval; Based on the risk offset and the time decay, the risk distance is calculated by weighted summation. The specific risk distance function is as follows: ,in, Indicates risk distance, Indicates the risk offset. This indicates the preset first weight. This indicates that a second weight is preset. .
4. The cross-border capital flow data analysis method based on deep feature fusion according to claim 1, characterized in that, The specific process for calculating the abnormal transaction risk score based on location coordinates using a risk distance function is as follows: Based on the location coordinates, calculate the normalized distance from the location coordinates to the preset ideal point; The formula for calculating the normalized distance is as follows: ,in, This represents the preset maximum normalized distance. Represents the normalized distance; The normalized distance is input into a preset risk score conversion function to calculate the abnormal transaction risk score. The risk score conversion function is as follows: ,in, Indicates the risk score of abnormal transactions. Represents the natural constant. This indicates the preset sensitivity coefficient.
5. The cross-border capital flow data analysis method based on deep feature fusion according to claim 1, characterized in that, The specific process of obtaining the first analysis granularity, re-executing S1 to S3 accordingly, and recording the number of re-executing times is as follows: Calculate the difference between the abnormal transaction risk score and a preset first threshold; Based on the magnitude of the difference, the corresponding analysis granularity parameter is queried from the preset granularity configuration table; The initial analysis granularity is updated based on the retrieved analysis granularity parameters to obtain the first analysis granularity; Based on the first analysis granularity, steps S1 to S3 are re-executed to generate an updated fused feature vector and recalculate the abnormal transaction risk score.
6. The cross-border capital flow data analysis method based on deep feature fusion according to claim 5, characterized in that, The configuration rules for the granularity configuration table include: When the difference is less than or equal to the preset first difference threshold, the corresponding time series analysis window is configured as the first duration, and the spectrum analysis depth is set to second-degree correlation. When the difference is greater than the preset first difference threshold and less than or equal to the preset second difference threshold, the corresponding time series analysis window is configured as the second duration and the spectrum analysis depth is three-dimensional correlation. When the difference is greater than the preset second difference threshold, the corresponding time series analysis window is configured to the third duration, and the spectrum analysis depth is full path association; The first duration is longer than the second duration, and the second duration is longer than the third duration.
7. The cross-border capital flow data analysis method based on deep feature fusion according to claim 1, characterized in that, The abnormal transaction risk score obtained after the execution is completed specifically includes: Initialize the execution counter and set the preset maximum number of executions; After each re-execution, the execution counter is incremented, and the abnormal transaction risk score calculated for the current number of times and its corresponding position coordinates are recorded; Calculate the Euclidean distance between the position coordinates obtained from two consecutive executions. The formula for calculating the Euclidean distance is as follows: ,in, Represents Euclidean distance. , Indicates the first The position coordinates of the next execution. , Indicates the position coordinates of the (i-1)th execution; When the execution counter reaches the preset maximum number of executions or the Euclidean distance is less than the preset second threshold, the re-execution process is stopped, and the abnormal transaction risk score after the execution is completed is obtained.
8. The cross-border capital flow data analysis method based on deep feature fusion according to claim 1, characterized in that, The specific process of outputting the visualized fund flow chart includes: Based on the final determined abnormal transaction risk score, relevant transaction path data is extracted from the corresponding financial transaction data and blockchain transaction data; Construct an overlay graph data structure that includes traditional financial transaction paths and blockchain transaction paths; Based on the magnitude of the abnormal transaction risk score, a corresponding risk level identifier is assigned to the different transaction paths. Generate 3D visualization chart data of the transaction path, including risk level indicators.
9. A cross-border capital flow data analysis system based on deep feature fusion, characterized in that, include: Data acquisition module: used to acquire financial transaction data and blockchain transaction data, extract features according to the initial analysis granularity, obtain time-series feature vectors and graph feature vectors, and perform feature fusion to generate fused feature vectors; Data construction module: used to construct a neighborhood model of risk time series data, wherein: a preset ideal point is used as the neighborhood center, and a risk distance function is constructed and obtained, the risk distance function is calculated based on the risk offset and the time decay. The first data judgment module is used to map the fused feature vector to the risk time series data neighborhood model and obtain its corresponding position coordinates. Based on the position coordinates, the abnormal transaction risk score is calculated through the risk distance function. It is then determined whether the abnormal transaction risk score is greater than the preset first threshold. If it is, a first-level warning is issued; otherwise, the process proceeds to the second data judgment module. The second data judgment module is used to correct the initial analysis granularity based on the difference between the abnormal transaction risk score and the preset first threshold, obtain the first analysis granularity, and re-execute the data acquisition module to the first data judgment module and record the number of re-executions until the number of re-executions reaches the preset upper limit or the Euclidean distance between the position coordinates corresponding to two adjacent abnormal transaction risk scores is less than the preset second threshold, and obtain the abnormal transaction risk score after the execution is completed. Data output module: Used to determine whether the abnormal transaction risk score after execution exceeds a preset first threshold. If so, a second-level warning is issued and a visual fund flow chart is output. The specific process of mapping the fused feature vector to the risk time series data neighborhood model and obtaining its corresponding location coordinates is as follows: The risk time series data neighborhood model refers to a risk assessment spatial model that includes time decay factors. Specifically, it is constructed using a two-dimensional coordinate system, with the horizontal axis representing the risk offset and the vertical axis representing the time decay, and is used to comprehensively assess the spatiotemporal characteristics of risk. Using the preset ideal point as the origin, the position coordinates of the fused feature vector in the two-dimensional coordinate system are calculated through a coordinate transformation algorithm. The specific formula of the coordinate transformation algorithm is as follows: ; ; in, The x-coordinate represents the position coordinates. The ordinate represents the position coordinates. Indicates the risk offset. Indicates the amount of time decay. Indicates the rotation angle of the coordinate system; The coordinate rotation angle is calculated through the following steps: Based on the variance distribution of the fused feature vector in the preset first dimension and the preset second dimension, the variance of the fused feature vector in the preset first dimension and the variance of the fused feature vector in the preset second dimension are obtained, and the coordinate rotation angle is calculated accordingly. The formula for calculating the coordinate rotation angle is as follows: ,in, This represents the variance of the fused feature vector in the preset first dimension. This represents the variance of the fused feature vector in the preset second dimension.
Citation Information
Patent Citations
POS machine transaction risk identification method based on data analysis and deep learning technology
CN120471624A
Abnormal transaction behavior identification method and system based on artificial intelligence
CN120912321A