Risk identification system, method, device, equipment, medium and program product

By employing a federated learning framework in the field of financial anti-money laundering risk identification system, a global risk identification model is generated through collaborative training between a central server and bank client nodes. This solves the problems of insufficient privacy protection and identification accuracy in existing technologies, and achieves efficient risk identification and data security.

CN121581979APending Publication Date: 2026-02-27INDUSTRIAL AND COMMERCIAL BANK OF CHINA
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511780961.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-28
Publication Date
2026-02-27

AI Technical Summary

Technical Problem

Existing technologies in the field of financial anti-money laundering are insufficient to accurately identify complex money laundering patterns while ensuring privacy protection, and compliance costs are high.

Method used

The system employs a federated learning framework, which consists of a central server and multiple bank client nodes. The system trains a model by building a time-series transaction graph locally, performs privacy processing, and then uploads the graph to the central server for secure aggregation to generate a global risk identification model.

Benefits of technology

It improves the accuracy and reliability of identifying complex money laundering patterns, while enhancing data privacy protection and reducing compliance costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121581979A_ABST
    Figure CN121581979A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a risk identification system, method, device and equipment, a medium and a program product, and relates to the field of big data. The method comprises the following steps: by constructing a federal learning system consisting of a central server and a plurality of bank client nodes, each client node performs local training on a global risk identification model by using local time sequence transaction graph data under the coordination of the central server; and updating and uploading the model subjected to privacy processing to a server for security aggregation, and finally distributing the optimized global model to each client node to execute high-precision local risk identification. In the process, through cooperation of graph structure data and time sequence data of multiple bank institutions, a global risk identification model can identify a cross-institution complex fund circulation mode and spatio-temporal behavior characteristics, meanwhile, data security is improved through privacy processing, the method improves risk accuracy and accuracy, and at the same time, the data security is improved. And the privacy protection of the data is enhanced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of big data, and in particular to a risk identification system, method, apparatus, equipment, medium, and program product. Background Technology

[0002] In the field of financial anti-money laundering, money laundering activities are carried out through complex transaction networks that span banks and regions, for example, by concealing the source of funds through unusual transaction patterns.

[0003] Currently, to regulate money laundering activities, existing technologies typically rely on internal bank rule engines or centralized machine learning models. Rule engines trigger alerts by setting static thresholds (e.g., maximum transaction amount per transaction, transaction frequency within a specific time period), but this method struggles to adapt to complex and ever-changing money laundering patterns, resulting in low accuracy in risk identification in practical applications. Graph neural networks regulate money laundering by establishing a network of transaction relationships between accounts, but this method requires aggregating data from various banks, making it difficult to meet privacy protection requirements and reducing data security. Summary of the Invention

[0004] This application provides a risk identification system, method, apparatus, equipment, medium, and program product, which aims to enhance the technical effect of improving the accuracy and precision of risk identification while strengthening data privacy protection.

[0005] Firstly, this application provides a risk identification system, comprising:

[0006] A central server is used to distribute the initial risk identification model to multiple client nodes;

[0007] Multiple client nodes are deployed in multiple banking institutions to build a time-series transaction graph locally. The time-series transaction graph includes nodes representing accounts and edges representing transaction behaviors. The received initial risk identification model is trained locally based on the time-series transaction graph to obtain a local model. After privacy processing of the local model, it is uploaded to the central server.

[0008] The central server is also used to aggregate the local models received from each client node, generate a global risk identification model, and distribute it to multiple client nodes so that each client node can identify risks in its local account transaction behavior through the global risk identification model.

[0009] Secondly, this application provides a risk identification method, including:

[0010] An initial risk identification model is distributed to multiple client nodes; these client nodes are deployed in multiple banking institutions, enabling each client node to build a time-series transaction graph locally, train the received initial risk identification model locally based on the time-series transaction graph, and obtain a local model; after privacy processing of the local model, it is uploaded to the central server; the time-series transaction graph includes nodes representing accounts and edges representing transaction behaviors;

[0011] The local models received from each client node are aggregated to generate a global risk identification model, which is then distributed to multiple client nodes so that each client node can identify risks in its local account transaction behavior through the global risk identification model.

[0012] Thirdly, this application provides a risk identification device, comprising:

[0013] The sending module is used to distribute the initial risk identification model to multiple client nodes. The multiple client nodes are deployed in multiple banking institutions, so that each client node can build a time-series transaction graph locally, train the received initial risk identification model locally based on the time-series transaction graph to obtain a local model, and upload the local model to the central server after privacy processing. The time-series transaction graph includes nodes representing accounts and edges representing transaction behaviors.

[0014] The processing module is used to aggregate the local models received from each client node, generate a global risk identification model, and distribute it to multiple client nodes so that each client node can identify risks in its local account transaction behavior through the global risk identification model.

[0015] Fourthly, embodiments of this application provide an electronic device, including: a memory and a processor;

[0016] The memory stores the instructions that the computer executes;

[0017] The processor executes computer execution instructions stored in memory, causing the processor to perform the first aspect and / or various possible implementations of the first aspect as described above.

[0018] Fifthly, embodiments of this application provide a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, are used to implement the first aspect and / or various possible implementations of the first aspect.

[0019] In a sixth aspect, embodiments of this application provide a computer program product, including a computer program that, when executed by a processor, implements the first aspect and / or various possible implementations of the first aspect.

[0020] The risk identification system, method, apparatus, equipment, media, and program products provided in this application construct a federated learning system consisting of a central server and multiple bank client nodes. Under the coordination of the central server, each client node uses local time-series transaction graph data to train a global risk identification model locally. The updated model, after privacy processing, is then uploaded to the server for secure aggregation. Finally, the optimized global model is distributed to each client node to perform high-precision local risk identification. In this process, by coordinating graph structure data and time-series data from multiple banking institutions, the global risk identification model can identify complex cross-institutional fund flow patterns and spatiotemporal behavioral characteristics. Simultaneously, privacy processing enhances data security, thereby improving the accuracy and precision of risk identification while strengthening data privacy protection. Attached Figure Description

[0021] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.

[0022] Figure 1 A schematic diagram of the risk identification system provided in this application;

[0023] Figure 2 Flowchart of the risk identification method provided in this application Figure 1 ;

[0024] Figure 3 Flowchart of the risk identification method provided in this application Figure 2 ;

[0025] Figure 4 A schematic diagram of the risk identification device provided in this application;

[0026] Figure 5 A schematic diagram of the structure of the electronic device provided in this application.

[0027] The accompanying drawings illustrate specific embodiments of this application, which will be described in more detail below. These drawings and descriptions are not intended to limit the scope of the concept in any way, but rather to illustrate the concept of this application to those skilled in the art through reference to particular embodiments. Detailed Implementation

[0028] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.

[0029] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, storage, use, processing, transmission, provision, disclosure, and application of the relevant data all comply with the relevant laws, regulations, and standards of the relevant countries and regions, have taken necessary confidentiality measures, do not violate public order and good morals, and provide corresponding operation access points for users to choose to authorize or refuse.

[0030] Furthermore, the technical solution involved in this application, which involves big data analysis of user information (including but not limited to personal biometrics, identity data, consumption data, asset data, electronic terminal operation data, etc.) and the use of artificial intelligence technology for automated decision-making, and makes decisions that have a significant impact on personal rights based on the results of automated decision-making, provides users with corresponding operation entry points for users to choose to agree to or reject the results of automated decision-making; if the user chooses to reject, the process will proceed to the expert decision-making process.

[0031] It should be noted that the risk identification system, method, apparatus, equipment, media and program products provided in this application can be used in the field of big data, or in any field other than big data. The application fields of the risk identification system, method, apparatus, equipment, media and program products in this application are not limited.

[0032] In the field of financial anti-money laundering, money laundering activities are usually carried out through complex transaction networks across banks and regions, such as the rapid transfer of funds between different banks through multiple layers of accounts.

[0033] Existing technologies for identifying money laundering activities employ either a single-bank rule engine approach, which identifies suspicious behavior by pre-setting transaction characteristic thresholds (e.g., large transfers), or a centralized machine learning model approach, which models transaction relationship networks based on neural networks.

[0034] To protect customer privacy, banks cannot directly share customer transaction data. This results in each bank using rule engine methods being able to identify money laundering activities based on local transaction data, while banks using centralized machine learning models cannot obtain effective and reliable aggregated data for centralized training of neural networks. Therefore, existing technologies have limitations in reducing the accuracy and reliability of risk identification results. Furthermore, as the spatiotemporal correlation of transaction data increases, existing methods are unable to cope with the dynamic evolution of complex money laundering patterns.

[0035] Furthermore, when banks submit compliance reports regularly, logs and documents need to be manually compiled to demonstrate the compliance and effectiveness of the anti-money laundering model. This process is time-consuming and prone to errors. Moreover, because different roles (e.g., regulatory agencies, bank management, and technical teams) have significantly different requirements for the content dimensions, level of detail, and presentation format of anti-money laundering reports, existing technical methods have poor adaptability for multi-role compliance reporting.

[0036] In summary, while existing technologies meet privacy protection requirements, they have low accuracy in identifying complex money laundering patterns and high compliance costs.

[0037] The risk identification method provided in this application, under the constraints of privacy protection and compliance, deploys multiple client nodes, integrated into a federated learning framework, at various banking institutions. An initial risk identification model is then distributed to each client node's corresponding bank via a central server. Each client node constructs a local time-series transaction graph based on its local account transaction data and trains the initial risk identification model using this local time-series transaction graph, obtaining a local model. After privacy processing, the local model is uploaded to the central server. The central server aggregates the received local models from each client node to generate a global risk identification model, which is then redistributed to the client nodes. This allows each client node to analyze its local account transaction data using the received global risk identification model to identify risky account transaction behaviors. This application, while satisfying privacy protection, improves the accuracy and reliability of identifying complex money laundering patterns by enriching the user model training dataset, thereby further reducing compliance costs.

[0038] The risk identification system, method, apparatus, equipment, media, and program products provided in this application are intended to solve the above-mentioned technical problems of the prior art.

[0039] The technical solution of this application and how the technical solution of this application solves the above-mentioned technical problems are described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments. The embodiments of this application will now be described with reference to the accompanying drawings.

[0040] The risk identification method of this application is applied to a risk identification system, which includes a central server and multiple client nodes. The central server distributes an initial risk identification model to the multiple client nodes. The client nodes, deployed at multiple banking institutions, are used to locally construct a time-series transaction graph, which includes nodes representing accounts and edges representing transaction behaviors. Based on the time-series transaction graph, the received initial risk identification model is trained locally to obtain a local model. After privacy processing, the local model is uploaded to the central server. The central server also aggregates the local models received from each client node to generate a global risk identification model, which is then distributed to the multiple client nodes, enabling each client node to identify risks in its local account transaction behaviors using the global risk identification model.

[0041] Figure 1 A schematic diagram of the risk identification system provided in this application is shown below. Figure 1 As shown, the risk identification system in this embodiment adopts a layered architecture, consisting of a bottom-up infrastructure, a model layer, and an application layer. The lower layers provide technical support and services to the upper layers, and the layers communicate and interact with each other through standard interfaces and protocols. Through collaboration among the layers, risks are identified and compliance reports are generated. The bottom-up infrastructure provides core computing, data communication, and data storage functions for the risk identification system. This infrastructure includes client nodes, each deployed in different banking institutions. Each client node is equipped with a federated privacy communication module to transmit data with the central server via a federated communication protocol, thereby achieving encrypted data transmission and further ensuring the security and integrity of interactive information such as local models during transmission. The client nodes deployed locally in the banking institutions access the bank's local data, account transaction data, and customer profile data, among other raw data. Simultaneously, the risk identification system uses privacy computing technologies (such as differential privacy and homomorphic encryption) to protect privacy during data computation and utilizes blockchain and blockchain nodes to store key operation logs on the blockchain, thereby enhancing the immutability and traceability of process data.

[0042] Optionally, the model layer includes a local model, a federated parameter server, and a model aggregation module, with the federated parameter server located on a central server. This model layer is used to distribute the initial risk identification model to each client node, receive the encrypted local model uploaded by the client nodes, and generate a global risk identification model after performing secure aggregation processing on each encrypted local model, and then distribute it to each client node.

[0043] Optionally, the application layer includes a risk identification engine, a compliance report generation engine, and an abnormal transaction alert interface. This application layer is used to provide users with specific business functions. That is, each client node, based on the application layer's risk identification engine, uses a trained global risk identification model to perform real-time risk scanning on local transaction data.

[0044] Optionally, a compliance report generation engine based on the application layer automatically generates corresponding risk reports based on real-time user input. An abnormal transaction alert interface based on the application layer visually displays the identified risk results to the user.

[0045] In one possible embodiment, client nodes deployed across multiple banking institutions retrieve account transaction data from their respective local databases and process this data using spatiotemporal graph embedding technology. The resulting feature data is then used to train an initial risk identification model locally, generating a local model. This local model undergoes privacy processing and is uploaded to a central server via a federated privacy communication module. The central server's model aggregation module securely aggregates the local models from multiple client nodes to generate an updated global risk identification model, which is then distributed back to each client node. Each client node's risk identification engine uses the received global risk identification model to identify risky behaviors based on its local bank's account transaction data and presents the identified potential risks to the user through an abnormal transaction warning interface. Simultaneously, a compliance report generation engine responds to different user input requests and generates corresponding compliance reports based on training metadata stored on the blockchain and the central server.

[0046] In one possible embodiment, a general spatiotemporal graph neural network is initialized by a central server, serving as the initial risk identification model. This initial risk identification model is then distributed to each client node participating in federated learning. Subsequently, the central server receives privacy-preserving local models uploaded by each client node and, by invoking a model aggregation module, fuses the local models using a secure aggregation algorithm to generate a global risk identification model. The central server then distributes the aggregated global risk identification model to each client node, enabling each client node's deployed banking institution to use the model training results fused from multiple banking institutions to improve its own risk identification capabilities, while ensuring the security of the original data from each banking institution.

[0047] This application embodiment achieves cross-institutional collaborative modeling under the premise of data isolation through a distributed modeling framework. This enables a single bank institution to identify risk behaviors that are difficult to detect locally based on a global risk identification model. The account transaction data is processed through spatiotemporal graph embedding technology, and the obtained features are used to further train the initial risk identification model locally to generate a local model. This step improves the accuracy and reliability of risk identification behavior. The privacy protection processing mechanism enhances the data security of the bank institution where each client node is located and strengthens data privacy protection.

[0048] Figure 2 Flowchart of the risk identification method provided in this application Figure 1 ,like Figure 2 As shown, for any client node, the method includes:

[0049] S201. Obtain account transaction data within a preset time window from the local database, and construct a time-series transaction graph based on the local account transaction data.

[0050] More specifically, account transaction data within a preset time window is retrieved from the local database, and a time-series transaction graph is constructed locally. The time-series transaction graph includes nodes representing accounts and edges representing transaction behaviors.

[0051] Optionally, the client node retrieves account transaction data within a preset time window (e.g., the past 30 days) from the local database and constructs a time-series transaction graph in local memory. This time-series transaction graph is a data structure where nodes uniquely represent an account entity (e.g., a personal or corporate account), and edges represent transactions occurring between two nodes.

[0052] Optionally, for any client node, when constructing a time-series transaction graph based on local account transaction data, the client node specifically performs the following: retrieves account transaction data within a preset time window from the local database; generates spatial embedding features of nodes by performing spatial graph modeling on the account transaction data, and generates temporal embedding features of nodes by performing time-series modeling on the account transaction data; and obtains the time-series transaction graph by fusing the spatial embedding features and the temporal embedding features.

[0053] In one possible implementation, account transaction data within a preset time window is extracted from the local database where the client node resides. The account transaction data includes: a unique transaction identifier, the payer's account ID, the payee's account ID, a transaction timestamp, the transaction amount, and the transaction type (e.g., "small transfer," "large transfer").

[0054] For example, for each unique account ID (e.g., "Acc001", "Acc002"), create the node as a graph node. The node can have attributes, such as the account opening duration.

[0055] For example, an edge is a directed edge established between the corresponding payer and payee nodes for each successful transaction. Edges may have attributes attached, such as the transaction amount and timestamp.

[0056] In one possible implementation, for each account node (e.g., Acc001), the time-dimensional features of all associated transactions of that account node are extracted. These associated transactions include transactions initiated by the account node as a payer and transactions initiated by the account node as a payee. The time dimension refers to the sequential pattern of transaction behavior over time, and the features in the time dimension include: a transaction timestamp sequence (i.e., a sequence recording the times when transactions occurred), a transaction amount sequence (i.e., transaction amounts arranged in chronological order), and a transaction frequency sequence (e.g., a sequence of the number of transactions per day over the past 7 days).

[0057] Optionally, spatial graph modeling refers to learning feature representations of nodes (accounts) and edges (transaction relationships) in an account transaction network using graph neural networks to capture the topological dependencies between accounts. For example, if there are transactions between account X and account Y of bank A, a graph attention network can be used to learn the impact of the transaction relationship between account X and account Y on the risk identification result of account X.

[0058] Optionally, time series modeling refers to modeling the trading behavior of an account (e.g., transaction amount, transaction frequency) over time to capture the dynamic evolution patterns of trading behavior. For example, neural networks can be used to analyze the changing trends of the transaction amount of account X at different points in time to identify whether it is a risky pattern of rapid entry and exit.

[0059] In one possible implementation, within a bank's local database, the topology of the account transaction network (e.g., transaction paths between accounts) is first extracted using spatial graph modeling. Then, temporal features of transaction behavior (e.g., patterns in transaction amount changes) are extracted using time series modeling. Finally, by jointly modeling the aforementioned temporal features and topology, the current model can simultaneously understand both the static relationships and dynamic behaviors between accounts, thereby providing a more comprehensive feature representation for identifying cross-institutional money laundering activities.

[0060] Optionally, after performing spatial graph modeling, the method further includes fusing spatial embedding features with temporal embedding features to generate a unified representation of account behavior.

[0061] For example, spatial embedding features refer to the node representations of an account transaction network generated by a graph neural network, reflecting the account's position within the transaction network. For instance, the graph embedding vector of account X includes topological information about the relationship between account X and transaction accounts Y and Z.

[0062] For example, temporal embedding features refer to dynamic representations of account transaction behavior generated through time series models, reflecting the transaction characteristics of an account at different times. For instance, the temporal embedding vector of account X includes the periodic fluctuation characteristics of the transaction amount of account X.

[0063] For example, a unified account behavior representation refers to an account representation that incorporates spatial and temporal features for subsequent risk identification. For instance, the final embedding vector of account X combines account X's location within the transaction network with trends in transaction amount changes.

[0064] In one possible embodiment, after the spatial embedding features and temporal embedding features are generated separately, they are combined through a feature fusion mechanism (e.g., concatenation, weighted summation) to generate a unified account behavior representation. This unified account behavior representation includes both the account's structural information in the transaction network (e.g., risk level of trading partners) and the dynamic patterns of its transaction behavior (e.g., rapid inflow and outflow of funds), providing more comprehensive input features for risk scoring calculation.

[0065] Optionally, the initial risk identification model is a spatiotemporal graph neural network; the initial risk identification model includes: a spatial modeling module, used to learn the associated risks of accounts in the transaction network; and a temporal modeling module, used to analyze the dynamic evolution pattern of account transaction behavior over time.

[0066] Alternatively, a spatiotemporal graph neural network is a deep learning model that simultaneously processes graph structure spatial information and time series information attached to the graph structure spatial information.

[0067] Optionally, a spatial modeling module is constructed based on graph convolutional networks or graph attention networks. This module learns the associated risk of the target node in the transaction network by aggregating the features of nodes adjacent to the target node. For example, if an account with no abnormal transactions has frequent fund transfers with multiple known high-risk accounts, the spatial association can be used to take into account the factors of the high-risk accounts that transact with it, and comprehensively identify whether the account's transaction behavior is risky.

[0068] Optionally, a time modeling module is constructed based on recurrent neural networks or temporal convolutional networks. This module is used to analyze the dynamic evolution patterns of account trading behavior over time. The dynamic evolution pattern refers to the account's trading habits (e.g., amount, frequency, and time distribution), and these habits exhibit trend-like, periodic, or abrupt changes over time. The time modeling module captures dynamic evolution patterns of potentially risky behaviors, such as an abnormal surge in trading frequency in a short period or a sudden shift in trading hours from daytime to nighttime.

[0069] This embodiment uses a combined approach of spatial graph modeling and time series modeling to enable the model to simultaneously capture the topological structure and time series characteristics of the account transaction network, thereby enhancing the accuracy and reliability of identifying cross-institutional money laundering activities.

[0070] Optionally, when the client node performs time series modeling on the account transaction data and generates the node's time embedding features, it specifically performs the following: extracts the features of the account transaction data associated with the node in the time dimension, including transaction timestamp sequences, transaction amount sequences, and transaction frequency sequences; and encodes the features of the account transaction data in the time dimension through a time encoder to generate the node's time embedding vector as the time embedding feature.

[0071] Optionally, the features along the aforementioned time dimension are encoded using a temporal encoder, and a fixed-length vector is output. This vector is the temporal embedding vector of the account node. The temporal embedding vector includes the account's transaction time behavior pattern, which is used as the temporal embedding feature of the account node.

[0072] In one possible embodiment, a time-series encoder refers to a neural network module used for time-series feature extraction. For example, a Transformer model is used to encode the transaction timestamps, transaction amounts, and transaction frequencies of account X, generating a time-series embedding vector. The time-series embedding vector is a vector generated by the time-series encoder to represent the dynamic characteristics of transaction behavior. For example, the time-series embedding vector of account X includes information on the periodic fluctuations in the transaction amounts of account X.

[0073] This embodiment enhances the model's ability to identify the temporal evolution of transaction behavior by using a time encoder, which helps improve the model's ability to identify abnormal behavior.

[0074] Optionally, when the client node performs spatial graph modeling on the account transaction data and generates spatial embedding features of the nodes, it specifically performs the following: learns the association strength between nodes in the time-series transaction graph by means of edges through a graph attention network; aggregates the neighboring nodes of the current central node based on the association strength to generate spatial embedding features of the current central node; and / or inputs the time-series transaction graph into a heterogeneous graph neural network to model different types of nodes and edges in the time-series transaction graph and generate spatial embedding features of the nodes.

[0075] Optionally, a graph attention network refers to a graph neural network that calculates the weights of relationships between nodes through an attention mechanism. For example, a graph attention network calculates the attention weights between account X and account Y to reflect the impact of account Y on the risk identification results of account X.

[0076] Alternatively, a heterogeneous graph neural network refers to a graph neural network capable of handling multiple types of nodes (e.g., personal accounts, corporate accounts) and edges (e.g., local transactions, interbank transactions). For example, a heterogeneous graph neural network distinguishes between the node types of "personal accounts" and "corporate accounts" to generate corresponding edge types for transactions.

[0077] In one possible embodiment, a graph attention network is used to calculate the importance weights (i.e., association strengths) of neighboring nodes to the current center node, and the neighbor features are aggregated using these weights to generate the spatial embedding features of the current center node.

[0078] In one possible embodiment, a time-series transaction graph containing multiple types of nodes (e.g., personal accounts, corporate accounts) and edges (e.g., small transfers, large transfers) is input into a heterogeneous graph neural network to distinguish different types of nodes, and information aggregation processing is performed based on the type recognition results, thereby improving the accuracy of the generated spatial embedding features.

[0079] In one possible embodiment, based on the constructed transaction graph topology, a graph neural network is used to learn the structural features of each node in the corresponding neighbor network. For example, a graph attention network is used to calculate the association strength between nodes and aggregate neighbor node information to generate a spatial embedding feature for each node. This spatial embedding feature can be used to indicate the position and association relationships of account nodes in the transaction graph.

[0080] This embodiment provides two methods, graph attention networks and heterogeneous graph neural networks, to enable the model to adapt to the differences in account types of different banks, thereby enhancing the model's generalization ability.

[0081] S202. Based on the time series transaction graph, the received initial risk identification model is trained locally to obtain a local model.

[0082] Optionally, during local training, training process metadata is collected, including the hash value of the local model and a record of the differential privacy budget consumed for privacy processing; the training process metadata is then uploaded to a central server.

[0083] In one possible embodiment, after model training is completed, training process metadata is obtained by calculating the hash value of the local model file and recording the differential privacy budget consumed in this round of model training. The training process metadata is then uploaded to a central server for compliance verification.

[0084] S203. After performing privacy processing on the local model, upload it to the central server.

[0085] Optionally, when performing privacy processing on the local model, the client node specifically performs privacy processing on the local model by: injecting controllable noise into the local model based on differential privacy technology; and / or, performing privacy processing on the local model by encrypting the transmission of the local model based on a secure aggregation protocol.

[0086] In one possible implementation, noise is added to the local model according to a preset privacy budget to enhance the security of local account transaction data.

[0087] In one possible implementation, client nodes encrypt the changes in model weights and / or gradients of their local models based on a secure aggregation protocol before uploading them to a central server. After collecting the encrypted local models from each client node, the central server directly performs the aggregation calculation in the encrypted state. Upon completion of the calculation, the central server obtains the encrypted result (i.e., the global risk identification model) and sets a decryption mechanism for this encrypted result (e.g., decryption jointly by all client nodes, or decryption by another trusted party), ensuring that each client node receives the global risk identification model in plaintext. In this process, since the central server does not decrypt the local models uploaded by any client node, the privacy and security of the training data of each client node are enhanced.

[0088] This embodiment provides two technical paths or combinations for privacy processing of the local model, ensuring from the algorithmic or communication level that it is difficult to obtain the account transaction data of a single client node even during the transmission of the local model, thereby enhancing data security.

[0089] S204. Upon receiving the global risk identification model distributed by the central server, the local account transaction behavior is identified using the global risk identification model.

[0090] Optionally, the risk identification system also includes a compliance report generation engine. Upon receiving a report generation request initiated by the current requesting role, the compliance report generation engine retrieves a subset of training process metadata matching the current requesting role from the central server based on the report generation request; determines the target report template corresponding to the current requesting role based on a preset role-report mapping relationship; and fills the retrieved subset of training process metadata into the target report template to generate a compliance report sent to the current requesting role.

[0091] Optionally, evidence chain data can be determined based on a subset of training process metadata associated with the report generation request.

[0092] In one possible embodiment, when a regulatory agency initiates a report generation request, the compliance report generation engine obtains a subset of training process metadata related to the report generation request (e.g., participants, model version, overall privacy protection strength), and fills the evidence chain data determined based on the subset of training process metadata related to the report generation request into the regulatory report template corresponding to the report generation request, thereby generating a compliance report that conforms to the format required by the report generation request, and sending it to the regulatory agency through a secure channel.

[0093] In one possible embodiment, Figure 3 Flowchart of the risk identification method provided in this application Figure 2 ,like Figure 3 As shown, in this embodiment... Figure 2 Based on the implementation examples, the report generation process is described in detail. When the risk identification system identifies the regulatory role currently initiating the report generation request, it extracts a subset of training process metadata from the central server that is more relevant to the regulatory role's needs than a preset threshold. The compliance report generation engine then accesses the report template library to match the report template corresponding to the regulatory role. Next, the report output module selects suitable evidence chain data from the training process metadata subset and fills it into the report template, generating a structured draft report. The engine conversion component then converts the structured draft report into a publication document format. Finally, a formal report in PDF format that meets regulatory reporting requirements is output and sent to the system designated by the regulatory agency through secure channels.

[0094] This embodiment utilizes a compliance report generation engine to dynamically retrieve a matching subset of metadata from a central server based on the requester's role or identity and populate it into the corresponding report template, thereby generating a customized report. This achieves automated compliance report generation, accurately meeting the differentiated information needs of different roles such as regulators, management, and auditors, saving time and manpower costs associated with manual report writing, and improving the efficiency of compliance operations.

[0095] Figure 4 A schematic diagram of the risk identification device provided in this application is shown below. Figure 4 As shown, the risk identification device 40 provided in this embodiment includes:

[0096] Sending module 401 distributes the initial risk identification model to multiple client nodes;

[0097] Processing module 402 is used to construct a time-series transaction graph locally, which includes nodes representing accounts and edges representing transaction behaviors; to train the received initial risk identification model locally based on the time-series transaction graph to obtain a local model; and to upload the local model to the central server after privacy processing.

[0098] The processing module 402 is also used to aggregate the local models of each received client node, generate a global risk identification model, and distribute it to multiple client nodes so that each client node can identify risks in its local account transaction behavior through the global risk identification model.

[0099] Optionally, the processing module 402 is also used to obtain account transaction data within a preset time window from a local database;

[0100] Spatial embedding features of nodes are generated by performing spatial graph modeling on account transaction data, and temporal embedding features of nodes are generated by performing time series modeling on account transaction data.

[0101] By fusing spatial embedding features and temporal embedding features, a time-series transaction graph is obtained.

[0102] Optionally, the processing module 402 is also used to learn the associated risks of accounts in the transaction network and to analyze the dynamic evolution of account trading behavior over time.

[0103] Optionally, the processing module 402 is also used to collect training process metadata during local training, including the hash value of the local model and a record of the differential privacy budget consumed for privacy processing.

[0104] The training process metadata is uploaded to the central server.

[0105] Optionally, the processing module 402 is further configured to, upon receiving a report generation request initiated by the current requesting role, obtain a subset of training process metadata matching the current requesting role from the central server based on the report generation request;

[0106] Based on the preset role-report mapping relationship, the target report template corresponding to the current requesting role is determined, and the obtained training process metadata subset is filled into the target report template to generate a compliance report sent to the current requesting role.

[0107] Optionally, the processing module 402 is further configured to perform privacy processing on the local model by injecting controllable noise into the local model based on differential privacy technology; and / or,

[0108] Based on a secure aggregation protocol, local models are encrypted during transmission to protect their privacy.

[0109] Optionally, the processing module 402 is also used to extract the features of the account transaction data associated with the node in the time dimension, including the transaction timestamp sequence, the transaction amount sequence and the transaction frequency sequence;

[0110] The temporal encoder encodes the features of account transaction data in the time dimension, generating temporal embedding vectors for nodes as temporal embedding features.

[0111] Optionally, the processing module 402 is also used to learn the correlation strength between nodes in the time-series transaction graph connected by edges through a graph attention network;

[0112] Based on association strength, the neighboring nodes of the current central node are aggregated to generate the spatial embedding features of the current central node; and / or,

[0113] The time-series transaction graph is input into a heterogeneous graph neural network to model different types of nodes and edges in the time-series transaction graph and generate spatial embedding features of nodes.

[0114] The risk identification device provided in this embodiment can execute the method provided in the above method embodiment. Its implementation principle and technical effect are similar, and will not be described in detail here.

[0115] Figure 5 A schematic diagram of the structure of the electronic device provided in this application. Figure 5 As shown, the electronic device 50 provided in this embodiment includes at least one processor 501 and a memory 502. Optionally, the device 50 further includes a communication component 503. The processor 501, memory 502, and communication component 503 are connected via a bus 504.

[0116] In a specific implementation, at least one processor 501 executes computer execution instructions stored in memory 502, causing at least one processor 501 to perform the above-described method.

[0117] The specific implementation process of processor 501 can be found in the above method embodiments, and its implementation principle and technical effect are similar. It will not be repeated here.

[0118] In the above embodiments, it should be understood that the processor can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), etc. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the method disclosed in this invention can be directly implemented by a hardware processor, or implemented by a combination of hardware and software modules within the processor.

[0119] The memory may include random access memory (RAM) and may also include non-volatile memory (NVM), such as at least one disk storage device.

[0120] The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. Buses can be categorized as address buses, data buses, control buses, etc. For ease of illustration, the buses shown in the accompanying drawings are not limited to a single bus or a single type of bus.

[0121] This application also provides a computer program product, including a computer program that, when executed by a processor, implements the above-described method.

[0122] This application also provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, implement the above-described method.

[0123] The aforementioned readable storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk. The readable storage medium can be any available medium accessible to a general-purpose or special-purpose computer.

[0124] An exemplary readable storage medium is coupled to a processor, enabling the processor to read information from and write information to the readable storage medium. Of course, the readable storage medium can also be a component of the processor. The processor and the readable storage medium can reside in an Application Specific Integrated Circuit (ASIC). Alternatively, the processor and the readable storage medium can exist as discrete components in the device.

[0125] It should be noted that, for the sake of simplicity, the foregoing method embodiments are all described as a series of actions. However, those skilled in the art should understand that this application is not limited to the described order of actions, as some steps may be performed in other orders or simultaneously according to this application. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are all optional embodiments, and the actions and modules involved are not necessarily essential to this application.

[0126] It should be further noted that although the steps in the flowchart are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowchart may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these sub-steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the sub-steps or stages of other steps.

[0127] It should be understood that the above-described device embodiments are merely illustrative, and the device of this application can also be implemented in other ways. For example, the division of units / modules in the above embodiments is only a logical functional division, and there may be other division methods in actual implementation. For example, multiple units, modules, or components may be combined, or integrated into another system, or some features may be ignored or not executed.

[0128] Furthermore, unless otherwise specified, the functional units / modules in the various embodiments of this application can be integrated into one unit / module, or each unit / module can exist physically separately, or two or more units / modules can be integrated together. The integrated units / modules described above can be implemented in hardware or as software program modules.

[0129] When integrated units / modules are implemented in hardware, the hardware can be digital circuits, analog circuits, etc. The physical implementation of the hardware structure includes, but is not limited to, transistors, memristors, etc. Unless otherwise specified, the processor can be any suitable hardware processor, such as a CPU, GPU, FPGA, DSP, and ASIC, etc. Unless otherwise specified, the storage unit can be any suitable magnetic or magneto-optical storage medium, such as Resistive Random Access Memory (RRAM), Dynamic Random Access Memory (DRAM), Static Random Access Memory (SRAM), Enhanced Dynamic Random Access Memory (EDRAM), High-Bandwidth Memory (HBM), Hybrid Memory Cube (HMC), etc.

[0130] If the integrated unit / module is implemented as a software program module and sold or used as an independent product, it can be stored in a computer-readable storage device (CMD). Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a memory and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this application. The aforementioned memory includes various media capable of storing program code, such as a USB flash drive, read-only memory (ROM), random access memory (RAM), portable hard drive, magnetic disk, or optical disk.

[0131] In the above embodiments, the descriptions of each embodiment have their own emphasis. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments. The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as the combination of these technical features does not contradict each other, it should be considered within the scope of this specification.

[0132] Other embodiments of this application will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of this application that follow the general principles of this application and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of this application are indicated by the following claims.

[0133] It should be understood that this application is not limited to the precise structure described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of this application is limited only by the appended claims.

Claims

1. A risk identification system, characterized in that, include: A central server is used to distribute the initial risk identification model to multiple client nodes; Multiple client nodes, deployed in multiple banking institutions, are used to build a time-series transaction graph locally. The time-series transaction graph includes nodes representing accounts and edges representing transaction behaviors. The received initial risk identification model is trained locally based on the time-series transaction graph to obtain a local model; and the local model is then uploaded to the central server after privacy processing. The central server is also used to aggregate the local models received from each client node, generate a global risk identification model, and distribute it to the multiple client nodes, so that each client node can identify risks in its local account transaction behavior through the global risk identification model.

2. The system according to claim 1, characterized in that, For any given client node, when constructing a time-series transaction graph based on local account transaction data, the client node is specifically used for: Retrieve account transaction data within a preset time window from the local database; Spatial embedding features of nodes are generated by performing spatial graph modeling on account transaction data, and temporal embedding features of nodes are generated by performing time series modeling on account transaction data. The time-series transaction graph is obtained by fusing the spatial embedding features and the temporal embedding features.

3. The system according to claim 1, characterized in that, The initial risk identification model is a spatiotemporal graph neural network; The initial risk identification model includes: The spatial modeling module is used to learn the associated risk of accounts within a transaction network; The time modeling module is used to analyze the dynamic evolution of account transaction behavior over time.

4. The system according to claim 1, characterized in that, Also includes: During local training, training process metadata is collected, including the hash value of the local model and the differential privacy budget record consumed for privacy processing. The training process metadata is uploaded to the central server.

5. The system according to claim 4, characterized in that, Also includes: The compliance report generation engine is used to obtain a subset of training process metadata that matches the current requesting role from the central server based on the report generation request when it receives a report generation request initiated by the current requesting role. Based on the preset role-report mapping relationship, the target report template corresponding to the current requesting role is determined, and the obtained training process metadata subset is filled into the target report template to generate a compliance report sent to the current requesting role.

6. The system according to claim 1, characterized in that, When performing privacy processing on the local model, the client node is specifically used for: Based on differential privacy technology, controllable noise is injected into the local model to perform privacy processing on the local model; and / or, Based on a secure aggregation protocol, the local model is encrypted during transmission to achieve privacy protection.

7. The system according to claim 2, characterized in that, When the client node performs time-series modeling on account transaction data and generates the node's time embedding features, it is specifically used for: Extract the time-dimensional features of the account transaction data associated with the node, including transaction timestamp sequence, transaction amount sequence, and transaction frequency sequence; The temporal features of the account transaction data are encoded by a temporal encoder to generate the temporal embedding vector of the node, which serves as the temporal embedding feature.

8. The system according to claim 2, characterized in that, When the client node performs spatial graph modeling on account transaction data and generates spatial embedding features of nodes, it is specifically used for: The graph attention network is used to learn the strength of the association between nodes in a time-series transaction graph connected by edges. Based on the association strength, the neighboring nodes of the current central node are aggregated to generate the spatial embedding features of the current central node. And / or, The time-series transaction graph is input into a heterogeneous graph neural network to model different types of nodes and edges in the time-series transaction graph and generate spatial embedding features of the nodes.

9. A risk identification method, characterized in that, include: Distribute the initial risk identification model to multiple client nodes; The multiple client nodes are deployed in multiple banking institutions, enabling each client node to construct a time-series transaction graph locally. Based on the time-series transaction graph, the received initial risk identification model is trained locally to obtain a local model. After privacy processing, the local model is uploaded to the central server. The time-series transaction graph includes nodes representing accounts and edges representing transaction behaviors. The local models received from each client node are aggregated to generate a global risk identification model, which is then distributed to the multiple client nodes so that each client node can identify risks in its local account transaction behavior through the global risk identification model.

10. A risk identification device, characterized in that, include: The sending module is used to distribute the initial risk identification model to multiple client nodes; The multiple client nodes are deployed in multiple banking institutions, enabling each client node to construct a time-series transaction graph locally. Based on the time-series transaction graph, the received initial risk identification model is trained locally to obtain a local model. After privacy processing, the local model is uploaded to the central server. The time-series transaction graph includes nodes representing accounts and edges representing transaction behaviors. The processing module is used to aggregate the local models received from each client node, generate a global risk identification model, and distribute it to the multiple client nodes so that each client node can identify risks in its local account transaction behavior through the global risk identification model.

11. An electronic device, characterized in that, include: A processor, and a memory communicatively connected to the processor; The memory stores computer-executed instructions; The processor executes computer execution instructions stored in the memory to implement the method as described in claim 9.

12. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the method as described in claim 9.

13. A computer program product, characterized in that, Includes a computer program that, when executed by a processor, implements the method of claim 9.