Abnormal co-debt correlation pattern graph learning and identification system for multi-source time series data

By constructing a graph learning and recognition system for abnormal debt association patterns in multi-source time series data, the problems of poor accuracy and real-time performance in identifying abnormal debt events in multi-source time series data are solved, and stable identification and pattern analysis of abnormal debt events are achieved.

CN121767089BActive Publication Date: 2026-05-15BAIWEIJINKE (SHANGHAI) INFORMATION TECH CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
BAIWEIJINKE (SHANGHAI) INFORMATION TECH CO LTD
Filing Date
2026-03-04
Publication Date
2026-05-15

AI Technical Summary

Technical Problem

In multi-source time-series data processing, existing technologies do not adequately consider the synchronization and transmission quality between events, resulting in poor accuracy and real-time performance in identifying abnormal debt events.

Method used

The system for learning and recognizing abnormal debt association patterns in multi-source time-series data includes modules for data acquisition and preprocessing, evidence synchronization and association construction, abnormal debt discrimination and prediction, and pattern subgraph learning and recognition. It adopts a two-level constraint mechanism of event synchronization value and event synchronization evidence to construct an event time-series association graph, and uses a spatiotemporal graph convolutional network model to discriminate and recognize abnormal debt events.

Benefits of technology

It reduces the risk of misalignment and omission in cross-data source update frequency differences, ensures the stability and reproducibility of edge connections in the event time sequence graph, and supports accurate identification and pattern analysis of abnormal debt events.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121767089B_ABST
    Figure CN121767089B_ABST
Patent Text Reader

Abstract

The application discloses a multi-source time sequence data-oriented abnormal co-debt correlation pattern graph learning and identification system, relates to the technical field of financial data processing, and comprises a data acquisition and preprocessing module, an evidence synchronization construction correlation module, an abnormal co-debt discrimination prediction module and a pattern subgraph learning and identification module.The data acquisition and preprocessing module is used for acquiring transaction debt data and performing preprocessing on the transaction debt data.The evidence synchronization construction correlation module is used for calculating synchronization values between events, screening relevant events and generating an event time sequence correlation graph.The abnormal co-debt discrimination prediction module is used for discriminating abnormal co-debt events, outputting abnormal co-debt prediction values and generating abnormal labels, and writing the abnormal co-debt prediction values and the abnormal labels into the event time sequence correlation graph.The pattern subgraph learning and identification module is used for generating real-time pattern embedding vectors, performing similarity retrieval and edge evidence consistency verification, and outputting abnormal co-debt correlation pattern graph data.The application solves the problem that, in the prior art, the synchronization between events and the transmission quality are not fully considered, resulting in poor accuracy and real-time performance of abnormal co-debt event identification.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of financial data processing technology, specifically to an abnormal debt association pattern learning and recognition system for multi-source time series data. Background Technology

[0002] With the development of multi-source data acquisition, edge computing, and graph learning modeling, quality status monitoring, anomaly pattern recognition, and process correlation analysis have gradually evolved from statistical discrimination based on single sensor data to deep feature extraction for time series data and structured recognition for multiple patterns. In existing technologies, various implementation paths based on time series models, attribute classifiers, and feature analysis have emerged, focusing on control chart pattern recognition, anomaly context attribute encoding, and zero-shot anomaly recognition.

[0003] For example, the embodiment with announcement number CN114997070B provides a training method for a control chart pattern recognition model and a control chart pattern recognition method, relating to the field of quality status monitoring technology. The training method includes: determining sample data based on simulation results of a product manufacturing process under preset control chart normal and abnormal modes; extracting features from the sample data using a preset time series model (Transformer) to obtain feature data for each preset control chart mode; training a preset classification model using the feature data for each control chart mode, and stopping training when a preset loss function is minimized, thus obtaining a control chart pattern recognition model.

[0004] For example, the invention with publication number CN118296438A provides a zero-shot composite control chart pattern recognition method based on ordered pattern feature analysis, including: Step 1: Data acquisition and generation: Acquire controlled data during the manufacturing process and generate a control chart pattern (CCP) sample set; Step 2: Establish attribute coding for abnormal situations: Each single anomaly of the CCP sample represents an abnormal attribute, obtaining the actual 0-1 attribute coding of all CCP samples; Step 3: Extract the ordered pattern (OP) feature set of single CCP samples from the training set; Step 4: Select the optimal time delay parameter for a single abnormal attribute; Step 5: Train the attribute classifier for a single abnormal attribute: Train a corresponding single abnormal attribute classifier for each single abnormal attribute; Step 6: Zero-shot composite abnormal attribute CCP anomaly recognition: Compare the predicted 0-1 attribute coding of the CCP sample to be identified with its actual 0-1 attribute coding to determine whether the CCP sample to be identified has a certain abnormal attribute, thereby realizing the anomaly recognition of zero-shot composite abnormal attribute CCPs.

[0005] The above-mentioned technical solutions are mainly aimed at pattern discrimination tasks of single-process controlled data or simulation samples, and usually take time series feature extraction or attribute classification as the core path. However, in scenarios with concurrent access of multi-source heterogeneous data, significant differences in sampling frequency, and coexistence of transmission delay and packet loss disturbance, there are still problems such as false association of events caused by cross-source time sequence misalignment and difficulty in constraining association evidence. As a result, it is difficult to stably extract and consistently identify abnormal co-debt patterns based on association structures.

[0006] Therefore, in order to address the above issues, there is an urgent need for an anomaly co-debt association pattern graph learning and recognition system for multi-source time series data. Summary of the Invention

[0007] Technical problems to be solved

[0008] To address the shortcomings of existing technologies, this invention provides an abnormal co-debt association pattern graph learning and recognition system for multi-source time-series data. This system solves the problem that the synchronization and transmission quality between events are not fully considered in the existing transaction debt data processing, resulting in poor accuracy and real-time performance in identifying abnormal co-debt events.

[0009] Technical solution

[0010] To achieve the above objectives, this invention provides the following technical solution: an abnormal joint debt association pattern graph learning and recognition system for multi-source time-series data, comprising: a data acquisition and preprocessing module, an evidence synchronization and association construction module, an abnormal joint debt discrimination and prediction module, and a pattern subgraph learning and recognition module. Specifically: the data acquisition and preprocessing module collects transaction debt data and performs abnormal data removal and standardization on the transaction debt data to generate preprocessed transaction debt data; the evidence synchronization and association construction module constructs transaction events based on the preprocessed transaction debt data and calculates the synchronization values ​​between events, filters out relevant events and generates event synchronization evidence for relevant events to perform consistency verification, and associates the event synchronization values ​​and event synchronization evidence with the event connection relationship to generate... The system comprises the following modules: an event time-series correlation graph; an abnormal debt discrimination and prediction module, used to build and train an abnormal debt discrimination model based on transaction debt data, identify abnormal debt events, construct time-series segment graph data based on the corresponding nodes of abnormal debt events in the event time-series correlation graph and input it into the spatiotemporal graph convolutional network model, output abnormal debt prediction values ​​and generate abnormal labels, and write the abnormal debt prediction values ​​and abnormal labels into the event time-series correlation graph; and a pattern subgraph learning and recognition module, used to extract abnormal debt correlation pattern subgraphs based on the event time-series correlation graph with abnormal labels, perform misalignment enhancement according to the time alignment threshold to construct training samples and train the correlation pattern graph representation model to generate a pattern embedding vector library, perform similarity retrieval and edge evidence consistency verification on the real-time pattern embedding vectors, and output abnormal debt correlation pattern graph data.

[0011] Further, the specific steps for collecting transaction debt data and performing outlier removal and standardization on the transaction debt data to generate preprocessed transaction debt data are as follows: Transaction debt data is collected in real time, including data source identifier, transaction account number, debt number, debt type, sampling timestamp, transaction amount, transaction category, transaction status, account balance, transaction frequency, data transmission latency, and data packet loss rate. For the collected transaction debt data, the Hample filter denoising algorithm is used to denoise the data, removing noise and outliers. Then, the min-max normalization algorithm is used to standardize the continuous numerical fields in the transaction debt data, outputting the preprocessed transaction debt data.

[0012] Furthermore, the specific steps for constructing transaction events and calculating inter-event synchronization values ​​based on preprocessed transaction debt data are as follows: Read the preprocessed transaction debt data; treat all transaction debt data at the corresponding sampling point as a single transaction event based on the debt number; generate a unique identifier for each transaction event based on the transaction account number and sampling timestamp; store the data source identifier and remaining transaction debt data as metadata for the current transaction event; for any two transaction events, extract the corresponding sampling timestamp, data transmission delay, and data packet loss rate; and synchronize the sampling timestamp of the i-th transaction event with that of the k-th transaction event. The time normalization term is obtained by subtracting the sampling timestamps and taking the absolute value, then dividing by the time alignment threshold. The larger of the data transmission delays for the two transaction events is taken as the representative value of the transmission delay, which is then divided by the delay normalization threshold to obtain the delay normalization term. The larger of the packet loss rates for the two transaction events is taken as the transmission quality threshold, which is then incremented by one and multiplied by the delay normalization term to obtain the delay quality term. The time normalization term and the delay quality term are added together and used as an exponent. The result is then used as an exponential function of the natural constant e to obtain the synchronization influence factor. The reciprocal of the synchronization influence factor is then incremented by one to obtain the inter-event synchronization value.

[0013] Further, relevant events are selected, and event synchronization evidence is generated for these events to perform consistency checks. The specific steps for generating an event time-series correlation graph by associating the synchronization values ​​between events with the event synchronization evidence are as follows: For each pair of transaction events, the synchronization value between events is compared with a synchronization threshold. When the synchronization value is greater than the synchronization threshold, the two events are marked as relevant events; when the synchronization value is less than or equal to the synchronization threshold, the two events are marked as unrelated events. For relevant events, consistency constraints are applied. The sampling timestamps of the two events are summed with their respective data transmission delays to obtain two corrected timestamps, and the two corrected timestamps are then differentially analyzed. The absolute value is taken to obtain the alignment time residual; the alignment time residual and the corresponding transmission quality gating quantity are used together as event synchronization evidence; the alignment time residual is compared with the time alignment threshold, and the transmission quality gating quantity is compared with the transmission quality threshold. When both satisfy the upper limit constraint, the relevant event mark is retained; otherwise, the relevant event mark is removed and the two events are marked as unrelated events; all transaction events are extracted as nodes, and a directed edge is established in each pair of related events. The direction of the directed edge is determined by the order of the sampling timestamps of the transaction events. The synchronization value between events is written into the directed edge weight field, and the event synchronization evidence is written into the directed edge evidence field to generate an event time sequence association graph.

[0014] Furthermore, based on transaction debt data, an abnormal joint debt discrimination model is constructed and trained. The specific steps for determining abnormal joint debt events are as follows: Extract the transaction account number, debt number, transaction amount, transaction category, transaction status, and account balance for each transaction event, and construct an abnormal joint debt discrimination model based on the isolated forest algorithm; extract transaction debt data for N historical abnormal joint debt events, divide the training set and validation set according to the training set ratio of m%, and input the training set and validation set into the abnormal joint debt discrimination model in batches for training; input each transaction event under the current sampling timestamp into the trained abnormal joint debt discrimination model in sequence to determine whether the transaction event is an abnormal joint debt event.

[0015] Furthermore, based on the corresponding nodes of abnormal joint debt events in the event time-series correlation graph, time-series segment graph data is constructed and input into the spatiotemporal graph convolutional network model. The abnormal joint debt prediction value is output and anomaly labels are generated. The specific steps for writing the abnormal joint debt prediction value and anomaly labels into the event time-series correlation graph are as follows: An abnormal joint debt time-series feature sequence is generated based on transaction debt data. The event time-series correlation graph is read, and the set of nodes identified as abnormal joint debt events is extracted. Time-series segment graph data is constructed using the sampling timestamp as the segment key. The abnormal joint debt time-series feature sequence is written into the corresponding node features according to the unique identifier of the transaction event. The data is processed by inputting the time-series segment graph data as a sample set into the spatiotemporal graph convolutional network model for training. The trained spatiotemporal graph convolutional network model is then fed back with the time-series segment graph data corresponding to the current sampling timestamp, outputting the abnormal common debt prediction value for each transaction event. This abnormal common debt prediction value is then associated with the unique identifier of the transaction event to generate abnormal common debt prediction result data. This abnormal common debt prediction result data is written back to the node attributes of the event time-series association graph, and anomaly marking is performed on transaction event nodes whose abnormal common debt prediction values ​​exceed the abnormal threshold. The output is an event time-series association graph with anomaly markings.

[0016] Furthermore, the specific steps for generating an abnormal co-debt time-series feature sequence based on transaction debt data are as follows: Read the set of transaction events determined to be abnormal co-debt events, group the abnormal co-debt events by debt number, and sort them in ascending order by sampling timestamp within each debt number group; extract the corresponding transaction debt data sequence for each abnormal co-debt event, perform differential operations on two adjacent abnormal co-debt event records according to the sampling timestamp order to obtain the transaction amount differential sequence, account balance differential sequence, transaction frequency differential sequence, and data transmission delay differential sequence, respectively, and bind the differential sequences with the corresponding sampling timestamps to generate the abnormal co-debt time-series feature sequence.

[0017] Further, the specific steps for extracting the abnormal co-debt association pattern subgraph based on the event time-series association graph with anomaly markers are as follows: Read the event time-series association graph with anomaly markers, extract the set of abnormally marked transaction event nodes and group them according to debt number; within each debt number group, perform K-order neighborhood expansion along the directed edges with the abnormally marked transaction event node as the center node to generate a candidate subgraph set, and associate and store the candidate subgraphs with the unique identifier of the transaction event and the debt number corresponding to the center node; extract the transaction account number, debt number, data source identifier and abnormal co-debt prediction value of the node for each candidate subgraph, and extract the edge weight field and edge evidence field of the directed edges; perform consistency screening on the candidate subgraphs, filter out candidate subgraphs with inconsistent debt numbers, and filter out candidate subgraphs whose transmission quality threshold in the edge evidence field does not meet the transmission quality threshold constraint, to obtain the set of abnormal co-debt association pattern subgraphs.

[0018] Further, the specific steps for constructing training samples and training the associated pattern graph representation model to generate a pattern embedding vector library by performing misalignment enhancement according to the time alignment threshold are as follows: Extract the set of abnormal debt associated pattern subgraphs corresponding to the historical abnormal debt event sample library, and construct an associated pattern graph representation model based on a graph isomorphic neural network; set the number of layers in the network to L layers, and use the node neighborhood information aggregation method for information propagation, and obtain the pattern graph representation through global pooling operation in the last layer; perform misalignment enhancement on each pattern subgraph according to the time alignment threshold to generate an enhanced subgraph, the misalignment enhancement includes performing time window translation on the node sequence and performing pruning on nodes outside the window, and performing synchronous removal on the associated edges of the pruned nodes; construct positive sample pairs with the original pattern subgraph and the enhanced subgraph, and construct a negative sample set with pattern subgraphs of different debt numbers, and input the positive and negative sample pairs into the associated pattern graph representation model in batches for training to generate a pattern embedding vector library.

[0019] Further, the specific steps for performing similarity retrieval and edge evidence consistency verification on the real-time pattern embedding vectors to output abnormal co-debt association pattern graph data are as follows: Input the set of abnormal co-debt association pattern subgraphs under the current sampling timestamp into the trained association pattern graph representation model to obtain real-time pattern embedding vectors, and retrieve candidate matching patterns with similarity greater than the similarity threshold in the pattern embedding vector library; perform edge evidence consistency verification on the candidate matching patterns, which includes ensuring that the alignment time residual meets the time alignment threshold constraint, the transmission delay representative value meets the delay normalization threshold constraint, and the transmission quality gating quantity meets the transmission quality threshold constraint. When the edge evidence consistency verification passes, abnormal co-debt association pattern recognition result data is generated; write the abnormal co-debt association pattern recognition result data back to the event time-series association graph, write the pattern number and pattern similarity to the transaction event nodes identified as the same abnormal co-debt association pattern, and write the pattern edge label to the directed edges within the pattern, and output the abnormal co-debt association pattern graph data according to the pattern number.

[0020] Beneficial effects

[0021] The present invention has the following beneficial effects:

[0022] (1) An abnormal debt association pattern graph learning and recognition system for multi-source time series data. Through a two-level constraint mechanism based on the synchronization value between events and the evidence of event synchronization, the sampling time difference, data transmission delay and transmission quality gating quantity are included in the consistency verification of event pairs. This reduces the risk of misalignment and missing connection under the condition of different update frequency across data sources, and ensures that the edge connection relationship of the event time series association graph is stable and reproducible.

[0023] (2) An abnormal debt association pattern graph learning and recognition system for multi-source time series data, by synchronously associating the connection relationship between events and the synchronization value and event synchronization evidence in the event time series association graph, so that each association edge has verifiable evidence, and supports edge-level tracing and consistency verification in the subsequent process of subgraph extraction, pattern recognition and result writing.

[0024] (3) A graph learning and recognition system for abnormal co-debt association patterns in multi-source time series data. It completes the screening of event-level abnormal co-debt events by adopting an abnormal co-debt discrimination model, and constructs a spatiotemporal graph convolutional network model for time series segment graph data input based on the corresponding nodes of abnormal co-debt events in the event time series association graph. It outputs abnormal co-debt prediction values ​​and abnormal labels, thereby realizing the joint characterization of abnormal co-debt risk on graph structure and time segments.

[0025] (4) An abnormal co-debt association pattern graph learning and recognition system for multi-source time series data performs misalignment enhancement on the abnormal co-debt association pattern subgraph according to the time alignment threshold, constructs positive and negative sample pairs and trains the association pattern graph representation model by time window translation, window clipping and clipping edge synchronous removal, reduces the instability of pattern embedding caused by time window drift and node entry and exit, and makes the same pattern recognizable under different alignment error conditions. Attached Figure Description

[0026] Figure 1 Flowchart of an anomaly co-debt correlation pattern learning and recognition system for multi-source time series data;

[0027] Figure 2 This is a correlation graph based on the synchronization values ​​between events;

[0028] Figure 3 A flowchart for constructing a subgraph of an abnormal joint debt association pattern. Detailed Implementation

[0029] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0030] Please see Figures 1-3This invention provides a technical solution: an abnormal joint debt association pattern graph learning and recognition system for multi-source time series data, comprising: a data acquisition and preprocessing module, an evidence synchronization and association construction module, an abnormal joint debt discrimination and prediction module, and a pattern subgraph learning and recognition module. The data acquisition and preprocessing module is used to acquire transaction debt data, perform abnormal data removal and standardization processing on the transaction debt data, and generate preprocessed transaction debt data. The evidence synchronization and association construction module is used to construct transaction events based on the preprocessed transaction debt data and calculate the synchronization value between events, filter out relevant events and generate event synchronization evidence for relevant events to perform consistency verification, associate the event synchronization value and event synchronization evidence with the event connection relationship, and generate an event time series. The system comprises several modules: a correlation graph and an abnormal debt discrimination and prediction module. The former is used to construct and train an abnormal debt discrimination model based on transaction debt data, identify abnormal debt events, construct time-series segment graph data based on the corresponding nodes of abnormal debt events in the event time-series correlation graph, input it into a spatiotemporal graph convolutional network model, output abnormal debt prediction values, generate abnormal labels, and write the abnormal debt prediction values ​​and abnormal labels into the event time-series correlation graph. The latter is used to extract abnormal debt correlation pattern subgraphs from the event time-series correlation graph with abnormal labels, perform misalignment enhancement according to time alignment thresholds to construct training samples, train the correlation pattern graph representation model to generate a pattern embedding vector library, perform similarity retrieval and edge evidence consistency verification on real-time pattern embedding vectors, and output abnormal debt correlation pattern graph data.

[0031] Specifically, the steps for collecting transaction debt data and performing abnormal data removal and standardization to generate preprocessed transaction debt data are as follows: Real-time collection of transaction debt data, including data source identifier, transaction account number, debt number, debt type, sampling timestamp, transaction amount, transaction category, transaction status, account balance, transaction frequency, data transmission latency, and data packet loss rate; where the data source identifier uses an enumerated coded field, written as a string into the collection stream, and its value is mapped from the access channel number, with the encoding rule being "channel category code - channel sequence number". The channel category code is used to identify the access channel category, and the channel... The serial number is used to identify the access channel number under the same channel category and to distinguish the event aggregation boundary of the same transaction account number under different data sources; the transaction account number is read from the account master data table by the transaction business interface and written along with the transaction record, and is used to construct a unique identifier for the transaction event according to the transaction account number; the debt number is written by the debt management interface when the transaction record is written to the database, and is used to aggregate sampling points and construct transaction events according to the debt number; the debt type is read from the debt type dictionary table by the debt management interface and written to the transaction record, and is used to perform type consistency verification on transaction events within the same debt number group; the sampling timestamp is generated by the collection server when receiving the transaction record. The local clock is generated and written after synchronization by the clock service, and is used for subsequent event sorting and time unification calculation between events; the transaction amount is written by the transaction execution interface during the transaction confirmation writing stage, and is used for the construction of the input field of the subsequent abnormal debt discrimination model; the transaction category is written by the transaction business interface according to the transaction instruction category, and is used for subsequent transaction event metadata storage and category enumeration verification; the transaction status is written by the transaction execution interface according to the transaction processing status code, and is used for subsequent transaction status enumeration verification and abnormal debt event filtering; the account balance is written by the clearing and settlement interface when the balance change is recorded, and is used for the construction of the input field of the subsequent abnormal debt discrimination model; the transaction frequency is determined by the acquisition server according to the transaction account. The transaction number is obtained and written by counting transaction records within a fixed statistical window. The transaction frequency is in seconds, and the window length of the fixed statistical window is configured in seconds. This is used to construct the input field of the subsequent abnormal debt discrimination model. The data transmission delay is obtained and written by the difference between the sending timestamp recorded by the network measurement device at the data access gateway and the receiving timestamp recorded by the acquisition server. The data transmission delay is in milliseconds. This is used for the calculation of the correction timestamp in the subsequent event synchronization evidence. The packet loss rate is calculated and written by the network measurement device based on the packet loss count on the acquisition server side and the sequence number count on the sending side. The packet loss rate is a ratio value ranging from 0 to 1. This is used for the calculation of the subsequent transmission quality gating quantity.The collected transaction debt data is sorted in ascending order by sampling timestamp. A key integrity check is performed on the transaction account number and debt number; records with missing transaction account numbers, missing debt numbers, and missing sampling timestamps are removed. Value range checks are performed on transaction amounts, account balances, transaction frequencies, data transmission delays (removing values ​​less than zero), and data packet loss rates (removing values ​​less than zero and removing values ​​greater than one). Enumeration checks are performed on transaction categories, transaction states, and debt types, removing records of non-preset categories. For the collected transaction debt data, a Hample filter denoising algorithm is used to denoise the data. Within a fixed-length sliding window, the transaction amount, account balance, and debt type are checked. The median of account balance, transaction frequency, data transmission delay, and data packet loss rate within a window is calculated and recorded as the median benchmark value. The absolute deviation sequence between the sample value and the median benchmark value is calculated for each field, and the median of the absolute deviation is calculated and recorded as the deviation median benchmark value. The deviation multiple is obtained by dividing the absolute deviation value of the current sample by the deviation median benchmark value. When the deviation multiple is greater than the preset multiple limit, the current sample is marked as an anomaly and removed. The anomaly marking result is bound to the sampling timestamp and written into the removal record. Then, the min-max normalization algorithm is used to standardize the continuous numerical fields in the transaction debt data. Within the current processing batch, the minimum and maximum values ​​of transaction amount, account balance, transaction frequency, data transmission delay, and data packet loss rate are calculated respectively. Each field is mapped to the value range of zero to one according to the minimum and maximum values ​​to eliminate the numerical bias caused by the difference in dimensions and scales on subsequent event synchronization calculation, event correlation judgment, and abnormal debt prediction modeling. The preprocessed transaction debt data is output.

[0032] In this implementation plan, constraints are applied to the integrity of the transaction account number, debt number, and sampling timestamp records. Constraints are also applied to the validity of the values ​​of transaction amount, account balance, transaction frequency, data transmission delay, and data packet loss rate. A robust anomaly identification calibrator for continuous numerical fields is formed using the Hampshire filtering denoising algorithm. Then, a min-max normalization algorithm is used to map the continuous numerical fields to a unified numerical range. This ensures that the preprocessed transaction debt data maintains consistent field caliber, controllable impact of anomalies, and stable comparability of numerical scales under cross-data source concurrent access conditions. This provides a consistent data input foundation for subsequent transaction event construction, inter-event synchronization value calculation, event synchronization evidence generation, and event time-series correlation graph generation.

[0033] Specifically, the steps for constructing transaction events and calculating synchronization values ​​between events based on preprocessed transaction debt data are as follows: Read the preprocessed transaction debt data; treat all transaction debt data at the corresponding sampling point as a single transaction event based on the debt number; generate a unique identifier for each transaction event based on the transaction account number and sampling timestamp; and store the data source identifier and remaining transaction debt data as metadata for the current transaction event. This ensures the uniqueness of each transaction event and provides stable and unified basic data for subsequent calculations. During data storage, associating the transaction account number with the sampling timestamp ensures that multiple transaction events from the same transaction account can be effectively sorted and traced back in chronological order. For any two transaction events, extract the corresponding sampling timestamp, data transmission delay, and packet loss rate. By extracting the sampling timestamp, the time difference between events can be calculated, reflecting the time misalignment between events. Data transmission delay represents the network transmission latency of data from one event to another, while the packet loss rate reflects the quality of data transmission between events, thus affecting the accuracy of event synchronization. By calculating the absolute value of the sampling timestamp difference for each pair of transaction events currently participating in the synchronization value calculation and averaging the set of absolute values, the time alignment threshold is obtained. The time normalization term is obtained by subtracting the sampling timestamp of the i-th transaction event from the sampling timestamp of the k-th transaction event and taking the absolute value, then dividing it by the time alignment threshold. The time normalization term measures the degree of time misalignment and scales it to a uniform range through standardization, facilitating subsequent weighting and comparison with other factors. The delay normalization threshold is obtained by extracting representative transmission delay values ​​from all transaction events currently involved in the synchronization value calculation and taking the maximum value of this set of representative transmission delay values. The larger of the data transmission delay values ​​for two transaction events is taken as the representative transmission delay value, and this value is divided by the delay normalization threshold to obtain the delay normalization term. This step ensures that the most severe delay during data transmission is reflected in the synchronization value by selecting the maximum transmission delay, while the delay normalization threshold ensures that the impact of transmission delay is within a reasonable range, avoiding unreasonable influence of extreme values ​​on the calculation results. The larger of the packet loss rates for the two transaction events is used to obtain the transmission quality (TQ) threshold. The TQ threshold ranges from 0 to 1, where 0 represents no data loss and 1 represents complete data loss. A larger TQ threshold indicates poorer transmission quality. The TQ threshold is then incremented by one and multiplied by a delay normalization term to obtain the delay quality term. This step comprehensively considers the impact of data transmission quality and delay. The TQ threshold, calculated using the packet loss rate, reflects the difference in data reliability between events, while the increment prevents numerical errors caused by a zero packet loss rate. By multiplying the packet loss rate by the delay normalization term, the combined effect of data reliability and transmission delay on event synchronization values ​​is demonstrated, thus influencing the synchronization relationship between events.The synchronization influence factor is obtained by adding the time term and the delay quality term to form an exponent, and then taking the exponential function value with respect to the natural constant e. This step introduces an exponential function, which enhances the impact of synchronization deviations caused by time misalignment and transmission delay by exponentializing the sum of the two terms. This makes events with greater influence have a more significant effect on their synchronization values. The role of the exponential function here is to amplify the impact of extreme values, thereby ensuring that in practical applications, significant time misalignment and poor transmission quality lead to more obvious synchronization deviations, helping to accurately label related events. The synchronization influence factor is then incremented by one and its reciprocal is taken to obtain the synchronization value between events. By taking the reciprocal of the synchronization influence factor, a larger synchronization influence factor results in a smaller synchronization value, and a smaller synchronization influence factor results in a larger synchronization value, thus quantifying the degree of synchronization and providing a basis for subsequent determination of related events. The reciprocal function here amplifies lower synchronization influence factors, ensuring that events that are close to synchronization are given sufficient weight for correlation labeling.

[0034] The specific formula for calculating the synchronization value between events is as follows:

[0035] ;

[0036] In the formula, This represents the inter-event synchronization value between the i-th transaction event and the k-th transaction event. This represents the sampling timestamp of the i-th transaction event. This represents the sampling timestamp of the k-th transaction event. Indicates the time alignment threshold. Indicates the transmission quality threshold. This represents the transmission delay value. This represents the delay normalization threshold.

[0037] In this embodiment, Table 1 shows the input data and corresponding calculation results used for calculating the inter-event synchronization value. This data is used to quantify and compare the temporal alignment degree and transmission disturbance level of event pairs, and provides input data for subsequent screening of related events based on the inter-event synchronization value and synchronization threshold, generating event synchronization evidence, and constructing an event temporal correlation graph. Specifically: In event pair 1, the sampling timestamp of the first transaction event is 2026-02-05.09:00:00.000, and the sampling timestamp of the second transaction event is 2026-02-05.09:00:00.180. The time alignment threshold is 0.180, the transmission quality threshold is 0.500, the representative value of transmission delay is 0.120, and the delay normalization threshold is 0.300, resulting in an inter-event synchronization value of 0.318. In event pair 2, the sampling timestamp of the first transaction event is 2026-02-05. At 09:05:10.000, the sampling timestamp for the second transaction event is 2026-02-05.09:00:00.180, the time alignment threshold is 0.420, the transmission quality gating value is 0.500, the representative value for transmission delay is 0.250, the delay normalization threshold is 0.300, and the corresponding inter-event synchronization value is 0.155. In event pair 3, the sampling timestamp for the first transaction event is 2026-02-05.09:05:10.000, and the sampling timestamp for the second transaction event is 2026-02-05.09. :10:30.050, time alignment threshold is 0.050, transmission quality threshold is 0.500, transmission delay representative value is 0.080, delay normalization threshold is 0.300, and corresponding event synchronization value is 0.409; In event pair 4, the sampling timestamp of the first transaction event is 2026-02-05.09:20:00.000, and the sampling timestamp of the second transaction event is 2026-02-05.09:19:59.700. The time alignment threshold is 0.300, transmission quality threshold is 0.500, and transmission delay representative value is 0.080, delay normalization threshold is 0.300, and corresponding event synchronization value is 0.409. The latency representative value is 0.180, the latency normalization threshold is 0.300, and the corresponding inter-event synchronization value is 0.223. In event pair 5, the sampling timestamp of the first transaction event is 2026-02-05.09:20:00.000, and the sampling timestamp of the second transaction event is 2026-02-05.09:19:59.700. The time alignment threshold is 0.650, the transmission quality threshold is 0.500, the transmission latency representative value is 0.300, the latency normalization threshold is 0.300, and the corresponding inter-event synchronization value is 0.087.In Table 1, the sampling timestamp of the i-th transaction event, the sampling timestamp of the k-th transaction event, the time alignment threshold, the transmission quality gating value, the representative value of transmission delay, and the delay normalization threshold of each event pair are used as input variables for calculating the inter-event synchronization value. The calculated inter-event synchronization value is used to determine the relevance of the event pair in the subsequent execution, and together with the event synchronization evidence, it supports the generation of the edge connection relationship of the event time sequence association graph.

[0038] Table 1. Data on Synchronization Values ​​Between Events

[0039]

[0040] like Figure 2 The chart shows the changes in synchronization values ​​between five event pairs. The horizontal axis of the bar chart represents the event pair number, and the vertical axis represents the synchronization value G between the events. Blue bars indicate that the synchronization value between event pairs is greater than the synchronization threshold, and are marked as related events; orange bars indicate that the synchronization value is less than or equal to the synchronization threshold, and are marked as unrelated events. The corresponding synchronization value is labeled at the top of each bar to facilitate a visual comparison of the synchronization status of each event pair. Specifically, the synchronization values ​​between event pairs 1, 3, and 4 are all greater than the synchronization threshold, and are marked as related events, while the synchronization values ​​between event pairs 2 and 5 are both lower than the synchronization threshold, and are marked as unrelated events. These data clearly demonstrate the synchronization relationship between event pairs, which helps in subsequent determination of the existence of abnormal joint debt events based on the synchronization values ​​between events, and further analysis of correlation patterns that match corresponding control strategies or risk predictions.

[0041] In this implementation scheme, by refining the processing of transaction debt data and calculating the synchronization values ​​between events, the inconsistencies caused by timing misalignment and transmission delay during data acquisition can be effectively eliminated, ensuring the accuracy and reliability of the synchronization values ​​between events. This method effectively amplifies the impact of abnormal events on synchronization values ​​by introducing indicators such as time normalization, delay normalization, and transmission quality gating, and combining the calculation of nonlinear exponential and reciprocal functions, thereby enhancing the fault tolerance capability for cross-source time-series data. Finally, after reasonable standardization and verification processing, the generated synchronization values ​​can more accurately reflect the actual synchronization relationship between transaction events, thus providing stable basic data support for subsequent abnormal event identification, correlation determination, and time-series graph construction, improving the accuracy and robustness of event synchronization judgment.

[0042] Specifically, the steps for selecting relevant events and generating event synchronization evidence for consistency verification, as well as associating event synchronization values ​​with event synchronization evidence to generate an event time-series correlation graph, are as follows: For each pair of transaction events, the event synchronization value is compared with a synchronization threshold. When the event synchronization value is greater than the synchronization threshold, the two events are marked as relevant events, and the unique identifiers of the two events are bound as event pair identifiers to record the comparison result. When the synchronization value is less than or equal to the synchronization threshold, the two events are marked as unrelated events, and the event pair identifiers are written to the unrelated record to skip subsequent consistency constraint calculations. The synchronization threshold is obtained by calculating the event synchronization value for all transaction event pairs currently participating in the correlation screening and taking the median of the event synchronization values. For related events, consistency constraints are applied. The sampling timestamp and data transmission delay are read for each event. The sampling timestamp and data transmission delay are summed to obtain the corrected timestamps for the i-th and k-th transaction events. The absolute value of the difference between the corrected timestamps of the i-th and k-th transaction events is then obtained to obtain the alignment time residual. This alignment time residual characterizes the degree of remaining timing misalignment between the two events after transmission delay compensation. The alignment time residual and the corresponding transmission quality threshold are used together as evidence of event synchronization. The transmission quality threshold is obtained by taking the larger value of the packet loss rates of the two events and is used to characterize the synchronization reliability of the event pair at the transmission link quality level. The alignment time residual is compared with a time alignment threshold to form a timing residual constraint determination result, and the transmission quality threshold is compared with a transmission quality threshold to form a transmission quality constraint determination result. Specifically, the transmission quality threshold is obtained by extracting the transmission quality threshold from all transaction event pairs currently marked as related events and taking the median of the transmission quality threshold. When both the time-series residual constraint and the transmission quality constraint satisfy the upper limit constraint, the relevant event markers are retained, and the event pair identifiers are bound to the alignment time residual and the transmission quality gating quantity to form an event synchronization evidence record; otherwise, the relevant event markers are revoked, and the two events are marked as unrelated events, and the event pair identifiers are bound to the revocation reason marker to form a consistency constraint revocation record. All transaction events are extracted as nodes, and directed edges are established in each pair of related events. The direction of the directed edge is determined by the order of the sampling timestamps of the two events, with the earlier sampling timestamp pointing to the later sampling timestamp. In the case of the same sampling timestamp, the direction of the directed edge is determined by the lexicographical order of the unique identifier of the transaction event. The synchronization value between events is written into the directed edge weight field, the event synchronization evidence is written into the directed edge evidence field, and the event pair identifier is written into the directed edge identifier field, generating an event time-series correlation graph.

[0043] In this implementation scheme, by accurately calculating and constraining the synchronization values ​​of transaction events, the temporal relationship between event pairs can be rigorously verified, eliminating erroneous associations caused by data quality issues or time misalignments. This method strengthens the mechanism for determining the synchronization degree between events by introducing alignment time residuals and transmission quality gating, making the synchronization relationship of related events more reliable. Furthermore, threshold constraints and consistency checks effectively eliminate irrelevant events. This not only improves the accuracy of event synchronization determination but also provides a reliable basis for subsequently constructing accurate event temporal relationship graphs, thereby providing high-quality data support for the identification, risk assessment, and pattern analysis of abnormal co-debt events.

[0044] Specifically, based on transaction debt data, an abnormal joint debt discrimination model is constructed and trained. The specific steps for determining abnormal joint debt events are as follows: Extract the transaction account number, debt number, transaction amount, transaction category, transaction status, and account balance for each transaction event; construct the abnormal joint debt discrimination model based on the isolated forest algorithm; during model construction, aggregate the transaction amount, transaction category, transaction status, and account balance of each transaction event into an event feature record using the unique identifier of the transaction event; perform field missing validation on the event feature record; remove missing transaction amount records, missing account balance records, missing transaction category records, and missing transaction status records; and perform field missing validation on the transaction category records. The transaction category code value is obtained by performing encoding mapping on the value taken, and the transaction status code value is obtained by performing encoding mapping on the value taken. The transaction amount, account balance, transaction category code value, and transaction status code value are then concatenated column by column to obtain the event feature vector. In the parameter setting process of the isolated forest algorithm, the number of trees is set to 200, the subsample capacity of each tree is set to 256 event feature records, the maximum split depth is set to 8 layers, the split features of a single tree are set to be uniformly randomly selected according to the column index of the event feature vector, the splitting point is set to be uniformly randomly sampled according to the minimum and maximum values ​​of the selected feature column in the current node sample, and the anomaly ratio parameter is set to 0.05 and used to determine the anomaly judgment quantile. The system extracts transaction debt data from N historical abnormal debt events, where N ranges from 1000 to 10000. These transaction debt data are aggregated into a set of historical event feature vectors based on the unique identifier of each transaction event. The system then divides the data into training and validation sets, with the training set accounting for m% of the total data and the validation set accounting for (100-m)%, where K ranges from 50 to 90. The training set is divided into several training batches of 128 event feature records, and the validation set is also divided into several validation batches of 128 event feature records. The training batches are sequentially input into the Isolation Forest algorithm for tree construction training. After each training of 10 trees, anomaly scores are calculated for the validation batches, and the anomaly score distribution drift is recorded. When the anomaly score distribution drift is less than a preset drift limit, the current round of training is completed, and the tree set is solidified. After training, anomaly determination quantiles are determined based on the anomaly score distribution of the validation set, and anomaly determination limits are generated. Each transaction event under the current sampling timestamp is sequentially input into the trained abnormal co-debt discrimination model. The abnormal score of each transaction event is calculated and compared with the abnormal judgment threshold. When the abnormal score is greater than the abnormal judgment threshold, the transaction event is marked as an abnormal co-debt event. When the abnormal score is less than or equal to the abnormal judgment threshold, the transaction event is marked as a non-abnormal co-debt event. The unique identifier of the transaction event is bound to the abnormal marking result and output. Here, co-debt refers to the fact that under the same debt number constraint, two or more transaction events corresponding to different transaction account numbers form a related event connection relationship in the event time sequence association graph, and the debt numbers of each transaction event are consistent.

[0045] In this implementation plan, the Isolation Forest algorithm model is precisely constructed and trained to effectively identify abnormal debt-related events and improve the accuracy of the identification. By reasonably aggregating and encoding the feature data of each transaction event, and by refining parameters such as the number of trees, subsample size, and maximum split depth, the robustness and generalization ability of the model under multi-sample data are ensured. Simultaneously, by reasonably dividing the training and validation sets and dynamically adjusting the anomaly determination quantiles based on the anomaly score distribution of the validation set, the model is ensured to continuously optimize and adapt to new data features during training. Finally, by accurately calculating the anomaly scores of transaction events through the model, efficient identification of abnormal debt-related events can be achieved while maintaining high accuracy, providing a solid data foundation for subsequent risk warning and decision support.

[0046] Specifically, the steps for constructing time-series segment graph data based on the corresponding nodes of abnormal joint debt events in the event time-series correlation graph and inputting it into the spatiotemporal graph convolutional network model, outputting abnormal joint debt prediction values ​​and generating anomaly markers, and writing the abnormal joint debt prediction values ​​and anomaly markers into the event time-series correlation graph are as follows: Generate an abnormal joint debt time-series feature sequence based on transaction debt data, and read the event time-series correlation graph, extracting the set of nodes identified as abnormal joint debt events, and constructing time-series segment graph data using the sampling timestamp as the segmentation key; during the generation of the abnormal joint debt time-series feature sequence, locate the differential values ​​of transaction amount, account balance, transaction frequency, and data transmission delay of the corresponding transaction event according to the unique identifier of the transaction event, and bind the differential values ​​with the corresponding sampling timestamp to form time-series feature records, and concatenate the time-series feature records under the same debt number arranged in ascending order of sampling timestamp to form the abnormal joint debt time-series feature sequence; during the construction of the time-series segment graph data, perform time-slicing on the event time-series correlation graph using the sampling timestamp as the segmentation key. The truncation range is determined by the start and end timestamps of the sampling timestamp segment key. Within the truncation range, the set of nodes and the set of directed edges are retained. At the same time, the directed edge weight field and the directed edge evidence field are written into the time-series segment graph data along with the edge to maintain the traceability of synchronous evidence of event connections within the time slice. The organization method of segmenting the segment graph data by sampling timestamp is adopted because transaction events have differences in data transmission delay and sampling timestamp jitter under multi-source acquisition conditions. Directly inputting the spatiotemporal graph convolutional network model on the global graph will cause misaligned connections across time slices to participate in adjacency propagation and introduce asynchronous noise. By segmenting the event connections by sampling timestamp key, the temporal sequence of directed edges is kept comparable within the time slice boundary, and the directed edge evidence field forms a consistent gating constraint within the time slice. This suppresses asynchronous noise during the forward propagation of the spatiotemporal graph convolutional network model, while retaining the directed dependency links across transaction events within the time slice for spatiotemporal feature aggregation.The abnormal joint debt time-series feature sequences are written into the corresponding node feature fields according to the unique identifier of the transaction event, and the time-series segment graph data is used as the sample set to input the spatiotemporal graph convolutional network model for training. During the writing process to the node feature fields, the abnormal joint debt time-series feature sequences are checked for length consistency. Abnormal joint debt time-series feature sequences that are not long enough are padded forward according to the sampling timestamp order, and abnormal joint debt time-series feature sequences that are too long are truncated according to the sampling timestamp order. The checked abnormal joint debt time-series feature sequences are written into the node feature fields to form a fixed-length node time-series feature tensor. During the construction of the training data, each time-series segment graph data is indexed by the sampling timestamp segment key and the debt number, and the time-series segment graph data is divided according to the sample index. To train and validate sample segments, training sample segments are written to the training queue in batches, and validation sample segments are written to the validation queue in batches. During the training of the spatiotemporal graph convolutional network model, the temporal segment graph data in the training queue is read in batches. The node temporal feature tensor is used as the temporal input, the directed edge weight field is used as the adjacency strength input, and the directed edge evidence field is used as the edge gating input. Forward propagation is performed on the spatiotemporal graph convolutional network model to obtain the initial value of the anomaly co-debt prediction. The initial value of the anomaly co-debt prediction and the anomaly labeling result are used to calculate the loss. Backpropagation is performed on the loss calculation result to update the model parameters. After each round of training, the anomaly co-debt prediction value is output to the validation queue and the validation loss is recorded to solidify the model parameters corresponding to the minimum validation loss. The trained spatiotemporal graph convolutional network model is input with the time-series graph data corresponding to the current sampling timestamp. It outputs the predicted value of abnormal common debt for each transaction event and associates these predicted values ​​with the unique identifiers of the transaction events to generate abnormal common debt prediction result data. During the output association process, the unique identifier of the transaction event is used as the key, and the predicted value of abnormal common debt is used as the value to write into the prediction result record. The prediction result record is then written into the prediction result sequence according to the sampling timestamp. The anomaly threshold is obtained by constructing a predicted value set from the predicted values ​​of abnormal common debt for all transaction event nodes in the current event's time-series association graph and taking the median of the predicted value set. The abnormal debt prediction results are written back to the node attributes of the event time series association graph. For transaction event nodes where the abnormal debt prediction value is greater than the abnormal threshold, anomaly marking is written, and the event time series association graph with anomaly marking is output. During the write-back process, the node attribute writing position is located by indexing the unique identifier of the transaction event. The abnormal debt prediction value is written to the abnormal debt prediction value field, the anomaly mark is written to the anomaly mark field, and the sampling timestamp is written to the prediction timestamp field to ensure that the subsequent association pattern subgraph extraction process can stably locate the abnormal debt event node set according to the anomaly mark field.

[0047] In this implementation scheme, by accurately extracting features and constructing temporal segment graphs from transaction debt data, the temporal relationships between transaction events and potential abnormal co-debt patterns can be effectively captured. The introduction of a spatiotemporal graph convolutional network model for training enables the effective identification of the synchronicity and anomalies of transaction events through multi-dimensional and multi-time-period information fusion. Accurate prediction and labeling of abnormal co-debt provides high-quality, structured data support for subsequent risk assessment and the learning of correlation pattern graphs, thus improving the detection capability of abnormal co-debt events. This method can not only be trained based on historical data but also predict new transaction events in real time, ensuring that the system can flexibly adapt to real-time data changes and accurately label potential abnormal events.

[0048] Specifically, the steps for generating an abnormal co-debt time-series feature sequence based on transaction debt data are as follows: First, read the set of transaction events identified as abnormal co-debt events. Group the abnormal co-debt events by debt number, and sort them in ascending order by sampling timestamp within each debt number group. During grouping, ensure that each transaction event for each debt number has a complete sampling timestamp; if a timestamp is missing or abnormal, the record is removed or corrected. Extract the corresponding transaction debt data sequence for each abnormal co-debt event. The transaction debt data includes fields such as transaction amount, account balance, transaction frequency, and data transmission delay. Ensure that the field values ​​for each transaction event are valid values ​​obtained after data cleaning and processing. Perform difference operations on adjacent abnormal co-debt event records according to the sampling timestamp order to obtain the transaction amount difference sequence, account balance difference sequence, transaction frequency difference sequence, and data transmission delay difference sequence, respectively. For the transaction frequency difference sequence, the time interval between adjacent events must be consistent so that the difference result truly reflects the frequency change trend. The purpose of difference operations is to extract the changing trends of transaction amount, account balance, transaction frequency, and data transmission delay by calculating the difference between two adjacent events, reflecting the dynamic changes of abnormal debt events in the time series. The difference sequence is then bound to the corresponding sampling timestamp to ensure that each difference data point corresponds one-to-one with its corresponding timestamp, generating an abnormal debt time series feature sequence. This sequence provides the basic data for time and feature synchronization for subsequent model training. Furthermore, the difference operation effectively eliminates the absolute value fluctuations in the original data, making the time series features more focused on the relative changes between events.

[0049] This implementation scheme, through refined processing and temporal differencing of transaction data related to abnormal debt events, effectively extracts the dynamic characteristics of each event, eliminates absolute value fluctuations in the data, and thus focuses on the relative changes of abnormal debt events in the time series. This method can fully reflect the changing trends of factors such as transaction amount, account balance, transaction frequency, and data transmission delay, making the temporal characteristics of abnormal debt events more accurate and stable. By binding each differencing sequence with a sampling timestamp, a close correlation between features and time information is ensured, providing high-quality input data and solid data support for subsequent abnormal debt discrimination and pattern recognition, thereby improving the accuracy and reliability of abnormal debt event identification.

[0050] Specifically, the steps for extracting the subgraph of abnormal co-debt association patterns based on the event sequence association graph with anomaly markers are as follows: Figure 3As shown, the process involves reading the event time-series correlation graph marked with anomalies, extracting the set of transaction event nodes marked with anomalies, and grouping them by debt number. Within each debt number group, a K-order neighborhood expansion is performed along directed edges with the transaction event node marked with anomalies as the center node, generating a set of candidate subgraphs. The candidate subgraphs are then associated and stored with the unique identifier of the transaction event and the debt number corresponding to the center node. The K-order neighborhood expansion involves further searching for neighboring nodes among the neighbors of each transaction event node and gradually expanding outwards along directed edges until a depth of K is reached, thereby discovering a wider range of correlations in the event time-series correlation graph. The value of K is generally recommended to be between 3 and 10. During the expansion process, it is ensured that the nodes contained in each subgraph are closely related in time, and that the directed edges in each candidate subgraph accurately reflect the temporal relationships between events and their mutual influence. For each candidate subgraph, the transaction account number, debt number, data source identifier, and abnormal co-debt prediction value of each node are extracted. The edge weight field and edge evidence field of the directed edges are also extracted. The transaction account number ensures the association between each transaction event and its account; the debt number guarantees the unique identification of the debt; the data source identifier distinguishes different data collection channels; and the abnormal co-debt prediction value provides a prediction of whether each transaction event constitutes abnormal co-debt. These data, when used as node feature inputs to the subgraph, effectively improve the subgraph's discriminative ability. The edge weight field of the directed edges reflects the synchronization strength between events, while the edge evidence field records the quality basis supporting the synchronization of that event. A consistency screening process is performed on the candidate subgraphs to remove those with inconsistent debt numbers and those whose transmission quality gating values ​​in the edge evidence field do not meet the transmission quality threshold constraints, resulting in a set of subgraphs exhibiting abnormal co-debt association patterns. During the screening process, the consistency of debt numbers is ensured; only events with the same debt number are considered possible abnormal co-debt association patterns. Simultaneously, the transmission quality gating values ​​in the edge evidence field provide verification of data transmission quality, ensuring that only subgraphs meeting the transmission quality requirements can be used for subsequent analysis, thereby improving the accuracy and effectiveness of the model.

[0051] In this implementation, by extracting subgraphs of abnormal co-debt association patterns from an event time-series association graph marked with anomalies, the associations between events related to abnormal co-debt can be systematically identified. This process uses a K-order neighborhood expansion approach, starting from each anomaly-marked transaction event node and progressively exploring other related events, ensuring that nodes closely related in time accurately reflect the temporal relationship between events. By screening candidate subgraphs that meet consistency criteria, it is further ensured that, under the condition of the same debt number, the generated subgraph accurately represents the co-debt association pattern, and the reliability of the data is guaranteed through verification by transmission quality gating. This method, through precise node feature extraction and consistency verification, provides high-quality input data for subsequent abnormal co-debt event identification, pattern recognition, and risk assessment, significantly improving the accuracy and robustness of the model.

[0052] Specifically, the steps for constructing training samples and training the association pattern graph representation model to generate a pattern embedding vector library by performing misalignment enhancement according to the time alignment threshold are as follows: Extract the set of abnormal debt association pattern subgraphs corresponding to the historical abnormal debt event sample library. The historical abnormal debt event sample library consists of historically collected abnormal debt event data, including features such as transaction account number, debt number, transaction amount, transaction category, transaction status, and account balance for each transaction event, as well as their corresponding abnormal labels. The construction of the historical abnormal debt event sample library relies on transaction event data previously identified as abnormal debts. This data is categorized and sorted according to different debt numbers and indexed by sampling timestamps. This sample library can provide rich training data for subsequent model training, ensuring the model's stable performance under different event features. The association pattern graph representation model is constructed based on a graph isomorphic neural network. The implementation of the association pattern graph representation model includes: setting the number of network layers to L, where L typically ranges from 3 to 10 layers. Each layer uses a method of aggregating neighboring node information for information propagation. Nodes at each layer receive and summarize feature information from their neighboring nodes, propagating and updating information layer by layer. In the final layer, node features are aggregated through global pooling to obtain the final pattern graph representation, which effectively expresses the association patterns and global information between nodes. For each pattern subgraph, misalignment enhancement is performed according to a time alignment threshold to generate an enhanced subgraph. Misalignment enhancement includes time window shifting of the node sequence and pruning nodes outside the window, as well as synchronous removal of edges associated with pruned nodes. Time window shifting, by offsetting the node sequence, allows the subgraph to cover event relationships across different time periods, thereby enhancing the model's adaptability to changes in event timelines. Pruning ensures that the node sequence does not exceed the time alignment threshold, thus avoiding interference from irrelevant nodes during model training. Synchronous removal deletes edges no longer connected to pruned nodes, ensuring the connectivity and synchronization of the subgraph. Positive sample pairs are constructed using the original pattern subgraph and the enhanced subgraph, and negative sample sets are constructed using pattern subgraphs with different debt numbers. The positive and negative sample pairs are then input into the associated pattern graph representation model in batches for training, generating a pattern embedding vector library. During training, the positive and negative sample pairs are used to enhance the model's ability to identify abnormal co-debt patterns, and the negative sample sets with different debt numbers are used to further enhance the model's generalization ability, ensuring that the trained pattern embedding vectors can accurately distinguish between relevant and irrelevant event patterns.

[0053] In this implementation plan, by effectively constructing and refining a sample database of historical abnormal debt events, and training a graph representation model of association patterns using a graph isomorphic neural network, the system can fully utilize the debt pattern characteristics reflected in historical data, ensuring the model's accurate identification of abnormal debt patterns. The misalignment enhancement operation, through time window shifting and synchronous removal, enhances the model's adaptability to changes in event timelines and ensures the high quality and representativeness of the training samples. By constructing and training positive and negative sample sets, the model's generalization ability to abnormal debt events is improved, enabling it to accurately distinguish between relevant and irrelevant events in complex multi-source data environments, thus providing more accurate and robust data support for subsequent abnormal debt pattern identification.

[0054] Specifically, the steps for performing similarity retrieval and side evidence consistency verification on real-time pattern embedding vectors to output abnormal co-debt association pattern graph data are as follows: Input the set of abnormal co-debt association pattern subgraphs under the current sampling timestamp into the trained association pattern graph representation model to obtain real-time pattern embedding vectors. Then, retrieve candidate matching patterns with similarity greater than a similarity threshold from the pattern embedding vector library. During similarity retrieval, calculate the cosine similarity between the real-time pattern embedding vector and each existing pattern in the pattern embedding vector library to ensure that patterns with higher similarity are selected as candidate matching patterns, thus guaranteeing the accuracy and relevance of the matching patterns. The cosine similarity measurement method measures similarity by calculating the angle between two vectors in the feature space. This effectively identifies events with similar feature value changes, especially when the performance of an event depends on relative change rather than absolute magnitude; cosine similarity provides an effective similarity measure. The similarity threshold is obtained by calculating the cosine similarity between the real-time pattern embedding vector and all existing patterns in the pattern embedding vector library and taking the median of the cosine similarity. A side evidence consistency check is performed on candidate matching patterns. This check includes ensuring that the alignment time residual meets the time alignment threshold constraint, the transmission delay representative value meets the delay normalization threshold constraint, and the transmission quality gating quantity meets the transmission quality threshold constraint. When the side evidence consistency check passes, abnormal co-debt association pattern recognition result data is generated. By comparing the alignment time residual with the time alignment threshold, the consistency of candidate patterns in temporal alignment is ensured, avoiding mismatches caused by time misalignment. At the same time, the checks on transmission delay and transmission quality gating quantity ensure the controllability of synchronization quality and reliability during data transmission, further improving the credibility of the pattern recognition results. The abnormal co-debt association pattern recognition result data is written back to the event temporal association graph. For transaction event nodes identified as having the same abnormal co-debt association pattern, a pattern number and pattern similarity are written, and a pattern edge label is written for the directed edges within the pattern. The abnormal co-debt association pattern graph data is output according to the pattern number. During the write-back process, it is ensured that the pattern number and pattern similarity information of each event node are accurately recorded for subsequent tracing and verification of abnormal co-debt patterns, and that the pattern edge labels of the directed edges can reflect the true relationship between events. This operation ensures that the pattern characteristics of each event node are accurately stored, and through the mapping between pattern number and similarity, it is possible to further track and verify the evolution and correlation of abnormal debt patterns in the event time sequence association graph.

[0055] In this implementation scheme, by accurately calculating the similarity of real-time pattern embedding vectors and combining it with edge evidence consistency verification, patterns related to abnormal debt can be effectively identified, ensuring the accuracy and reliability of abnormal debt patterns. Cosine similarity, when measuring relationships between events, accurately reflects the similarity of feature changes, ensuring the model's efficient capture of relevant events. Combining time alignment, transmission delay, and data quality gating verification further enhances the accuracy of pattern recognition, ensuring the impact of synchronization and transmission quality on pattern determination. By writing pattern numbers and similarities into the event time-series correlation graph and labeling directed edges within patterns, the accurate mapping of abnormal debt patterns in the graph structure is ensured, enabling subsequent analysis and verification to be based on accurate event correlations. Ultimately, this method not only optimizes the identification process of abnormal debt patterns but also provides reliable data support for real-time monitoring and risk assessment of abnormal debt events, enhancing the system's dynamic adaptability.

[0056] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus.

[0057] The preferred embodiments of the present invention disclosed above are merely illustrative of the invention. These preferred embodiments do not exhaustively describe all details, nor do they limit the invention to the specific implementations described. Clearly, many modifications and variations can be made based on the content of this specification. This specification selects and specifically describes these embodiments to better explain the principles and practical applications of the invention, thereby enabling those skilled in the art to better understand and utilize the invention. The invention is limited only by the claims and their full scope and equivalents.

Claims

1. A learning and recognition system for anomaly co-debt correlation patterns in multi-source time-series data, characterized in that: include: The module comprises a data acquisition and preprocessing module, an evidence synchronization and association construction module, an abnormal joint debt discrimination and prediction module, and a pattern subgraph learning and recognition module, among which: The data acquisition and preprocessing module is used to collect transaction debt data, which includes data source identifier, transaction account number, debt number, debt type, sampling timestamp, transaction amount, transaction category, transaction status, account balance, transaction frequency, data transmission delay and data packet loss rate. It also performs abnormal data removal and standardization processing on the transaction debt data to generate preprocessed transaction debt data. The evidence synchronization and association module is used to construct transaction events based on preprocessed transaction debt data and calculate the synchronization value between events, filter out relevant events and generate event synchronization evidence for relevant events to perform consistency verification, associate the synchronization value between events and the event synchronization evidence with the connection relationship between events, and generate an event time sequence association graph. The abnormal debt identification and prediction module is used to build and train an abnormal debt identification model based on transaction debt data, identify abnormal debt events, construct time-series segment graph data based on the corresponding nodes of abnormal debt events in the event time-series correlation graph and input it into the spatiotemporal graph convolutional network model, output abnormal debt prediction values ​​and generate abnormal labels, and write the abnormal debt prediction values ​​and abnormal labels into the event time-series correlation graph. The pattern subgraph learning and recognition module is used to extract abnormal co-debt association pattern subgraphs based on event time-series association graphs with anomaly labels. It performs misalignment enhancement according to time alignment thresholds to construct training samples and trains the association pattern graph representation model to generate a pattern embedding vector library. It performs similarity retrieval and edge evidence consistency verification on real-time pattern embedding vectors and outputs abnormal co-debt association pattern graph data. The specific steps for constructing training samples by performing misalignment enhancement based on the time alignment threshold and training the associated pattern graph representation model to generate a pattern embedding vector library are as follows: A set of abnormal debt association pattern subgraphs corresponding to the historical abnormal debt event sample library is extracted, and an association pattern graph representation model is constructed based on a graph isomorphic neural network. The network is set to L layers, and information propagation is carried out by the node neighborhood information aggregation method. The pattern graph representation is obtained by global pooling operation in the last layer. For each pattern subgraph, misalignment enhancement is performed according to the time alignment threshold to generate an enhanced subgraph. Misalignment enhancement includes performing time window translation on the node sequence and pruning nodes outside the window, as well as synchronously removing the associated edges of the pruned nodes. Positive sample pairs are constructed with the original pattern subgraph and the enhanced subgraph, and negative sample sets are constructed with pattern subgraphs of different debt numbers. The positive and negative sample pairs are input into the association pattern graph representation model in batches for training to generate a pattern embedding vector library.

2. The abnormal co-debt association pattern graph learning and recognition system for multi-source time series data according to claim 1, characterized in that: The specific steps for performing outlier removal and standardization on the transaction debt data to generate preprocessed transaction debt data are as follows: For the collected transaction debt data, the Hample filter denoising algorithm is used to denoise the transaction debt data to remove noise and outliers; then the min-max normalization algorithm is used to standardize the continuous numerical fields in the transaction debt data, and the preprocessed transaction debt data is output.

3. The abnormal co-debt association pattern graph learning and recognition system for multi-source time series data according to claim 1, characterized in that: The specific steps for constructing transaction events and calculating inter-event synchronization values ​​based on preprocessed transaction debt data are as follows: Read the preprocessed transaction debt data, treat all transaction debt data of the corresponding sampling point as a transaction event according to the debt number, and generate a unique identifier for each transaction event based on the transaction account number and sampling timestamp. Store the data source identifier and the remaining transaction debt data as the metadata of the current transaction event. For any two transaction events, extract the corresponding sampling timestamp, data transmission delay, and packet loss rate; take the difference between the sampling timestamp of the i-th transaction event and the sampling timestamp of the k-th transaction event, and divide the absolute value by the time alignment threshold to obtain the time normalization term; take the larger value of the data transmission delay of the two transaction events to obtain the representative value of the transmission delay, and divide the representative value of the transmission delay by the delay normalization threshold to obtain the delay normalization term; take the larger value of the packet loss rate of the two transaction events to obtain the transmission quality threshold, add one to the transmission quality threshold, and multiply it by the delay normalization term to obtain the delay quality term; add the time normalization term and the delay quality term to obtain the exponent, and take the exponential function value with respect to the natural constant e to obtain the synchronization influence factor; add one to the synchronization influence factor and take the reciprocal to obtain the inter-event synchronization value.

4. The abnormal co-debt association pattern graph learning and recognition system for multi-source time series data according to claim 1, characterized in that: The specific steps for filtering out relevant events, generating event synchronization evidence for these events to perform consistency checks, associating event synchronization values ​​with event synchronization evidence to the event connection relationships, and generating an event time-series correlation graph are as follows: For each pair of transaction events, the synchronization value between the events is compared with the synchronization threshold. When the synchronization value between the events is greater than the synchronization threshold, the two events are marked as related events; when the synchronization value is less than or equal to the synchronization threshold, the two events are marked as unrelated events. For related events, consistency constraints are applied. The sampling timestamps of the two events are summed with their respective data transmission delays to obtain two corrected timestamps. The absolute value of the difference between the two corrected timestamps is then taken to obtain the alignment time residual. The alignment time residual and the corresponding transmission quality threshold are used together as evidence of event synchronization. The alignment time residual is compared with the time alignment threshold, and the transmission quality threshold is compared with the transmission quality threshold. When both satisfy the upper limit constraint, the relevant event mark is retained; otherwise, the relevant event mark is removed and the two events are marked as unrelated events. Extract all transaction events as nodes, establish directed edges in each pair of related events, the direction of the directed edges is determined by the order of the sampling timestamps of the transaction events, write the synchronization value between events into the directed edge weight field, write the event synchronization evidence into the directed edge evidence field, and generate an event time sequence association graph.

5. The anomaly co-debt association pattern graph learning and recognition system for multi-source time series data according to claim 1, characterized in that: The specific steps for constructing and training an abnormal joint debt discrimination model based on transaction debt data to determine abnormal joint debt events are as follows: Extract the transaction account number, debt number, transaction amount, transaction type, transaction status, and account balance for each transaction event, and construct an abnormal debt discrimination model based on the isolated forest algorithm. Extract transaction debt data for N historical abnormal debt events, divide the training set and validation set into m% of the training set, and input the training set and validation set into the abnormal debt discrimination model in batches for training. Input each transaction event under the current sampling timestamp into the trained abnormal debt discrimination model in sequence to determine whether the transaction event is an abnormal debt event.

6. The abnormal co-debt association pattern graph learning and recognition system for multi-source time series data according to claim 1, characterized in that: The specific steps for constructing time-series segment graph data based on the corresponding nodes of abnormal co-debt events in the event time-series correlation graph, inputting it into the spatiotemporal graph convolutional network model, outputting abnormal co-debt prediction values ​​and generating anomaly labels, and writing the abnormal co-debt prediction values ​​and anomaly labels into the event time-series correlation graph are as follows: An abnormal co-debt time series feature sequence is generated based on transaction debt data, and the event time series correlation graph is read. The set of nodes that are identified as abnormal co-debt events is extracted, and time series segment graph data is constructed with the sampling timestamp as the segment key. The abnormal co-debt time series feature sequence is written into the corresponding node feature field according to the unique identifier of the transaction event, and the time series fragment graph data is used as a sample set to be input into the spatiotemporal graph convolutional network model for training. Input the time-series segment graph data corresponding to the current sampling timestamp into the trained spatiotemporal graph convolutional network model, output the abnormal common debt prediction value for each transaction event, and associate the abnormal common debt prediction value with the unique identifier of the transaction event to generate abnormal common debt prediction result data; Write back the abnormal debt prediction results to the node attributes of the event time series graph, and perform anomaly marking and writing on transaction event nodes whose abnormal debt prediction values ​​are greater than the abnormal threshold, and output the event time series graph with anomaly marking.

7. The anomaly co-debt association pattern graph learning and recognition system for multi-source time series data according to claim 6, characterized in that: The specific steps for generating an abnormal co-debt time-series feature sequence based on transaction debt data are as follows: Read the set of transaction events that are determined to be abnormal joint debt events, group the abnormal joint debt events by debt number, and sort them in ascending order by sampling timestamp within each debt number group; For each abnormal co-debt event, extract the corresponding transaction debt data sequence. Perform differential operation on two adjacent abnormal co-debt event records according to the sampling timestamp order to obtain the transaction amount differential sequence, account balance differential sequence, transaction frequency differential sequence, and data transmission delay differential sequence, respectively. Bind the differential sequence with the corresponding sampling timestamp to generate an abnormal co-debt time series feature sequence.

8. The abnormal co-debt association pattern graph learning and recognition system for multi-source time series data according to claim 1, characterized in that: The specific steps for extracting the subgraph of abnormal co-debt association pattern based on the event sequence association graph with anomaly markers are as follows: Read the event sequence association graph with anomaly markers, extract the set of transaction event nodes with anomaly markers and group them by debt number; within each debt number group, perform K-order neighborhood expansion along directed edges with the transaction event node with anomaly marker as the center node to generate a set of candidate subgraphs, and associate and store the candidate subgraphs with the unique identifier of the transaction event and the debt number corresponding to the center node; For each candidate subgraph, extract the transaction account number, debt number, data source identifier, and abnormal co-debt prediction value of the node, and extract the edge weight field and edge evidence field of the directed edge; Consistency screening is performed on the candidate subgraphs to remove candidate subgraphs with inconsistent debt numbers and candidate subgraphs whose transmission quality gating values ​​in the edge evidence field do not meet the transmission quality threshold constraints, thus obtaining a set of subgraphs with abnormal co-debt association patterns.

9. The abnormal co-debt association pattern graph learning and recognition system for multi-source time series data according to claim 1, characterized in that: The specific steps for performing similarity retrieval and edge evidence consistency verification on the real-time pattern embedding vector, and outputting abnormal co-debt association pattern graph data are as follows: The set of abnormal co-debt association pattern subgraphs under the current sampling timestamp is input into the trained association pattern graph representation model to obtain real-time pattern embedding vectors. Candidate matching patterns with similarity greater than the similarity threshold are retrieved from the pattern embedding vector library. Side evidence consistency verification is performed on the candidate matching patterns. Side evidence consistency verification includes the alignment time residual meeting the time alignment threshold constraint, the transmission delay representative value meeting the delay normalization threshold constraint, and the transmission quality gating quantity meeting the transmission quality threshold constraint. When the side evidence consistency verification passes, abnormal co-debt association pattern recognition result data is generated. Write the abnormal co-debt association pattern identification results back to the event time sequence association graph. Write the pattern number and pattern similarity to the transaction event nodes that are identified as the same abnormal co-debt association pattern, and write the pattern edge label to the directed edges in the pattern. Output the abnormal co-debt association pattern graph data according to the pattern number.