Transaction abnormity early warning method, device, equipment, medium and product

By analyzing multiple feature dimensions of transaction-related data, and performing quantitative evaluation and weighting, the accuracy problem of abnormal transaction identification and early warning in existing technologies has been solved, achieving more comprehensive and accurate risk assessment and early warning, and protecting users' property security.

CN121788232APending Publication Date: 2026-04-03INDUSTRIAL AND COMMERCIAL BANK OF CHINA
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-02-13
Publication Date
2026-04-03

AI Technical Summary

Technical Problem

Existing technologies are insufficient for quickly and accurately identifying and issuing early warnings of abnormal transactions, posing challenges to financial order and property security.

Method used

By acquiring transaction-related data of the target transaction, analyzing feature information from multiple dimensions, including transaction amount deviation, time anomaly features, geographical jump features, and account behavior features, quantitative evaluation and weighting are performed to achieve multi-dimensional anomaly warning.

Benefits of technology

It improves the comprehensiveness and accuracy of transaction risk assessment, enhances the ability to identify and warn of abnormal transactions, and safeguards users' assets.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121788232A_ABST
    Figure CN121788232A_ABST
Patent Text Reader

Abstract

The invention discloses a transaction abnormity early warning method, device and equipment, a medium and a product, and relates to the field of financial science and technology. The method comprises the following steps: acquiring transaction related data corresponding to a target transaction; according to the transaction related data, analyzing to obtain feature information corresponding to at least one feature dimension; determining at least one quantitative evaluation result corresponding to each feature dimension according to each piece of feature information; and performing abnormal early warning on the target transaction according to each quantitative evaluation result. In the technical scheme of the embodiment of the invention, multi-dimensional comprehensive evaluation can improve evaluation comprehensiveness and accuracy of the target transaction, and a user is more accurately helped to carry out transaction abnormity early warning.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of financial technology, and in particular to a method, apparatus, device, medium and product for early warning of abnormal transactions. Background Technology

[0002] With the accelerated digitalization of society and the utilization of various emerging technologies, abnormal transactions on telecommunications networks are becoming increasingly professional and covert. These abnormal transaction methods are constantly evolving and integrating with technology, shifting from broad-based targeting to precise identification of individuals. The money transfer chains are also becoming more complex and diverse, posing a continuous challenge to social property security and financial order. In this context, the ability of financial institutions, as key nodes in the flow of funds, to identify abnormal transactions in a timely and accurate manner has become a crucial line of defense for protecting the rights and interests of the public.

[0003] Currently, banks' systems for identifying and intercepting abnormal transactions are rapidly evolving from relying on static rules and human experience towards a more dynamic and intelligent approach. How to further identify and issue early warnings for potentially abnormal transactions has become a key research focus for professionals in this field. Summary of the Invention

[0004] This application provides a method, apparatus, device, medium, and product for early warning of abnormal transactions, in order to improve the comprehensiveness and accuracy of transaction risk assessment.

[0005] According to one aspect of this application, a method for early warning of abnormal transactions is provided, comprising: Obtain transaction-related data corresponding to the target transaction; Based on transaction-related data, analyze and obtain feature information corresponding to at least one feature dimension; Based on the information of each feature, at least one quantitative evaluation result corresponding to each feature dimension is determined; Based on the results of various quantitative assessments, abnormal alerts are issued for target transactions.

[0006] According to another aspect of this application, a transaction anomaly early warning device is provided, comprising: The transaction data acquisition module is used to acquire transaction-related data corresponding to the target transaction; The feature dimension determination module is used to analyze and obtain feature information corresponding to at least one feature dimension based on transaction-related data; The evaluation result quantification module is used to determine at least one quantitative evaluation result corresponding to each feature dimension based on each feature information. The transaction anomaly warning module is used to issue anomaly warnings for target transactions based on the results of various quantitative assessments.

[0007] According to another aspect of this application, an electronic device is provided, the electronic device comprising: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that can be executed by the at least one processor, which enables the at least one processor to perform the transaction anomaly warning method according to any embodiment of this application.

[0008] According to another aspect of this application, a computer-readable storage medium is provided, the computer-readable storage medium storing computer instructions for causing a processor to execute and implement the transaction anomaly warning method described in any embodiment of this application.

[0009] According to another aspect of this application, a computer program product is provided, the computer program product including a computer program that, when executed by a processor, implements the transaction anomaly warning method according to any embodiment of this application.

[0010] In the technical solution of this application embodiment, feature information corresponding to at least one feature dimension is obtained by analyzing the transaction-related data corresponding to the target transaction. Feature information of multiple different feature dimensions is obtained from the transaction-related data to provide different dimensions of basis for subsequent quantitative evaluation. Based on each feature information, at least one quantitative evaluation result corresponding to each feature dimension is determined, which enables quantitative evaluation in each dimension and lays the foundation for the overall risk assessment of the target transaction. Based on each quantitative evaluation result, anomaly warnings are issued for the target transaction. The comprehensive evaluation of multiple dimensions can improve the comprehensiveness and accuracy of the target transaction evaluation and more accurately help users issue warnings for abnormal transactions.

[0011] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of this application, nor is it intended to limit the scope of this application. Other features of this application will become readily apparent from the following description. Attached Figure Description

[0012] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0013] Figure 1 This is a flowchart of a transaction anomaly early warning method provided according to Embodiment 1 of this application; Figure 2 This is a schematic diagram of a transaction anomaly early warning device according to Embodiment 2 of this application; Figure 3 This is a schematic diagram of the structure of an electronic device that implements the transaction anomaly warning method of the embodiments of this application. Detailed Implementation

[0014] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present application, and not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative effort should fall within the scope of protection of the present application.

[0015] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0016] Example 1 Figure 1 This application provides a flowchart of a transaction anomaly early warning method according to Embodiment 1. This embodiment is applicable to situations where abnormal transactions may be prevented and warned against. The method can be executed by a transaction anomaly early warning device, which can be implemented in hardware and / or software and can be configured in an electronic device. Figure 1 As shown, the method includes: S110. Obtain transaction-related data corresponding to the target transaction.

[0017] The target transaction can be any transaction application between different accounts. This transaction refers to the transfer of value, actual amount, or data from one account to other accounts (which can be multiple accounts), resulting in corresponding changes to the records of these accounts. It is important to note that all data related to the target transaction can be obtained when the transaction application is submitted, allowing for identification and control before the transaction takes effect. Correspondingly, transaction-related data can be all data related to the target transaction, including application-related data and historical data. For example, application-related data may include, but is not limited to, the transferring account, the receiving account, the remittance amount, the remittance time, and the remittance location. Historical data may include, but is not limited to, any data that occurred in the account during a historical period. These will be described in detail later in this application embodiment and will not be exhaustively listed here. It should be noted that this application embodiment and its implementation methods will use a bank as an example to illustrate how to identify potential abnormal transaction risks from transaction data and provide protection for users' property security. When an account submits an application for a target transaction, the bank can directly obtain all data related to that target transaction.

[0018] It should be emphasized that this application is intended to provide users with early warnings of abnormal transactions to protect their rights. Therefore, the transaction data and account information collected are all information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, storage, use, processing, transmission, provision, disclosure, and application of the relevant data all comply with the relevant laws, regulations, and standards of the relevant countries and regions, and necessary confidentiality measures have been taken. The data does not violate public order and good morals, and corresponding operation portals are provided for users to choose to authorize or refuse.

[0019] S120. Based on transaction-related data, analyze and obtain feature information corresponding to at least one feature dimension.

[0020] The feature dimensions can be different perspectives used to characterize transaction-related data, and the corresponding feature information can be information extracted or parsed from these feature dimensions. These feature dimensions may include, but are not limited to, transaction feature dimensions, account behavior dimensions, related network dimensions, external intelligence dimensions, and problem feedback dimensions, etc., which will not be exhaustively listed in this embodiment. For example, the transaction feature dimension information may include time anomaly features, and the time or period in which an account applies for a transaction in the transaction-related data can be used as the basis for analyzing time anomaly features.

[0021] S130. Based on the information of each feature, determine at least one quantitative evaluation result corresponding to each feature dimension.

[0022] The quantitative evaluation result can be a quantitative result that evaluates a feature dimension. For example, assigning an evaluation score can be one form of quantitative evaluation result. The evaluation result for a feature dimension is assigned through specific scoring. For instance, based on pre-defined threshold ranges for different dimensions of data, when the feature information of a certain feature dimension falls within a certain threshold range, the corresponding score range is found and assigned a value, which can then be used as the quantitative evaluation result for that feature dimension.

[0023] S140. Based on the results of each quantitative assessment, issue anomaly warnings for target transactions.

[0024] The quantitative evaluation results from different dimensions can be weighted and summed to provide a quantitative assessment of the target transaction when submitting a transaction application. This weighted sum can be used to measure the level of risk of the target transaction from abnormal transactions. For example, the risk range corresponding to the weighted sum score can be preset, and warnings can be issued for transactions with higher risks. There are various ways to issue warnings, such as intercepting high-risk transactions and triggering manual review, imposing additional verification measures on users and controlling delayed payments for medium-risk transactions, and providing users with pop-up risk warnings for low-risk transactions. This application embodiment only provides some examples and does not limit the scope. Of course, the weights of different dimensions and the risk ranges can be set by those skilled in the art based on a large amount of historical data, experiments, and human experience. This application embodiment does not limit the scope of these settings.

[0025] In the technical solution of this application embodiment, feature information corresponding to at least one feature dimension is obtained by analyzing the transaction-related data corresponding to the target transaction. Feature information of multiple different feature dimensions is obtained from the transaction-related data to provide different dimensions of basis for subsequent quantitative evaluation. Based on each feature information, at least one quantitative evaluation result corresponding to each feature dimension is determined, which enables quantitative evaluation in each dimension and lays the foundation for the overall risk assessment of the target transaction. Based on each quantitative evaluation result, anomaly warnings are issued for the target transaction. The comprehensive evaluation of multiple dimensions can improve the comprehensiveness and accuracy of the target transaction evaluation and more accurately help users issue warnings for abnormal transactions.

[0026] In one optional implementation, the feature information includes transaction feature dimension information; The feature information corresponding to at least one feature dimension obtained by analyzing transaction-related data as described in S120 includes: Based on the transaction amount, frequency, time period, and address in the transaction-related data, the deviation of the transaction amount, the time anomaly characteristics, and the geographical jump characteristics of the target transaction are determined. Specifically, the transaction amount can be the specific amount to be transferred in the target transaction; the transaction frequency can be the frequency or number of times multiple transfers within the target transaction occur per unit of time; the transaction time period can be the time or time range for the execution of the target transaction application, which can be divided according to specific needs—for example, only the morning, afternoon, evening, or early morning time periods can be obtained, or it can be limited to a specific time; the transaction address can be the application address of the target transaction, which can be a network address or a physical address, depending on the specific device submitting the transaction application. It is understood that the transaction amount, frequency, time period, and address are all obtained by the bank when the target transaction application is submitted.

[0027] Transaction amount deviation refers to the degree of deviation between the target transaction amount and the usual transfer amount (determined by retrieving historical account data from the bank). For example, the average and standard deviation of the account's transactions in historical data can be calculated first. The target transaction amount is compared with the average transaction amount, and the difference is then compared with the standard deviation. This indicates whether the target transaction amount deviates too much from previous transactions. Temporal anomalies can be characteristics indicating abnormalities in the target transaction over time. For example, comparing historical data reveals that the target transaction was requested during an inactive period (e.g., 2-5 AM). Geographical jump characteristics can be characteristics indicating a sudden change in the location at the time of the target transaction request. For example, the login address at the time of the target transaction request may not match the commonly used login address in historical data, or the login address of the target account may change multiple times within a short period. Understandably, transaction amount, transaction frequency, transaction time period, and transaction address data form the basis for determining transaction amount deviation, temporal anomalies, and geographic jump characteristics. Of course, the specific determination process can use a pre-set numerical or field comparison algorithm to compare information such as monetary value, time value, or address field. The implementation method of this application will not be described in detail here.

[0028] Transaction amount deviation, time anomaly characteristics, and geographical jump characteristics are used as transaction feature dimensions. These dimensions must include at least three items: transaction amount deviation, time anomaly characteristics, and geographical jump characteristics. Based on these three items, a quantitative assessment of the target transaction can be performed.

[0029] Accordingly, S130 describes determining at least one quantitative evaluation result corresponding to each feature dimension based on each feature information, including: If the deviation of the transaction amount is the excess value of the transaction amount exceeding the historical transaction average of the target account corresponding to the target transaction, and meets the preset standard deviation threshold, then the quantitative evaluation result corresponding to the deviation of the transaction amount is determined according to the quantitative standard corresponding to the preset standard deviation threshold.

[0030] The historical transaction average can be the average amount of each transaction in the past history of the account applying for the target transaction. The excess value of the target transaction can be the amount by which the transaction amount exceeds the historical transaction average. The standard deviation threshold can be a measure of the severity of the excess value. This standard deviation threshold can be set using the standard deviation of the amount, for example, by calculating the standard deviation of historical transaction amounts, comparing the excess value with the standard deviation, and assigning a score corresponding to the threshold if it meets the corresponding standard deviation threshold. For example, the excess value is obtained by subtracting the transaction amount of the target transaction from the historical transaction average. If the excess value is greater than 3 times the standard deviation, the target transaction is assigned 40 points from the perspective of transaction amount deviation. If the excess value is greater than 2 times the standard deviation, the target transaction is assigned 20 points from the perspective of transaction amount deviation. It can be understood that the greater the excess value, the greater the deviation of the transaction amount of the target transaction from the normal situation. Of course, the specific score assignment can be set by those skilled in the art based on a large number of experiments or human experience, and this application embodiment does not limit this.

[0031] In response to the time anomaly characteristics meeting the preset inactive period conditions, the quantitative evaluation results corresponding to the time anomaly characteristics are determined.

[0032] The inactive period condition can be a pre-defined period of low trading activity in an account, during which very little trading occurs. This inactive period condition is used to assign a corresponding quantitative score to the target trade from the perspective of time anomalies. Of course, different time periods in the inactive period condition can be pre-set with different scores, which can be pre-defined by technical personnel in the relevant field.

[0033] When information indicating abnormal time characteristics suggests that an account application was made to trade during inactive periods, a corresponding score is assigned. For example, if a target trade application is made between 2:00 AM and 5:00 AM, the target trade is assigned a quantitative assessment score of 15 points based on abnormal time characteristics.

[0034] In response to the geographical jump feature meeting the preset conditions for changes in trading location, the quantitative assessment result corresponding to the geographical jump feature is determined.

[0035] The transaction location change condition can be used to characterize a change in location between an account's transactions and its historical transactions, and a corresponding quantitative score can be assigned to the target transaction based on this transaction location change condition. For example, if the distance between the target transaction and the account's previous transaction exceeds 500 kilometers, and the time interval between the two transactions is less than 2 hours, then the target transaction will be assigned a quantitative assessment score of 25 points.

[0036] In the above implementation, the target transaction is quantitatively evaluated from different perspectives based on three parts of the transaction characteristic dimension: transaction amount deviation, time anomaly characteristics, and geographical jump characteristics, in order to identify potential risks. The quantitative score provides a basis for some dimensions of the subsequent overall evaluation, which helps to improve the accuracy of risk identification and early warning, and thus helps to improve account security.

[0037] In one optional implementation, the feature information includes account behavior dimension information; The feature information corresponding to at least one feature dimension obtained by analyzing transaction-related data as described in S120 includes: Based on account information, login information, transaction channels, and transaction types from the transaction-related data, the account login characteristics, operation frequency characteristics, and biometric matching degree of the target transaction are determined. Account information can be information about the two or more accounts corresponding to the target transaction, such as information about the account itself or information about the operations performed by the account. Login information can be the login device information and login method information of each account, especially the account applying for the target transaction. Transaction channels can be the transaction platform, such as offline counters (low-frequency channels) or online electronic channels (high-frequency channels). Transaction types can be the type of transaction the account applies for, such as consumer transactions and investment transactions. It is understood that all account information, login information, transaction channels, and transaction types are obtained by the bank when the target transaction is submitted.

[0038] Account login characteristics, operation frequency characteristics, and biometric matching degree are used as account behavior dimension information. The account behavior dimension information should include at least these three items: account login characteristics, operation frequency characteristics, and biometric matching degree. Based on these three items, a quantitative evaluation of the target transaction can be carried out from the transaction characteristic dimension.

[0039] Account login features can include login environment data (such as login device information, operating system, etc.) and login behavior data (such as login method) generated when a user logs into a bank account. Operation frequency features can be used to characterize the frequency with which an account is accessed by a user. Biometric matching degree can be used to characterize the matching or affiliation between a user and an account. It is understood that account information, login information, transaction channels, transaction types, and other data form the basis for determining account login features, operation frequency features, and biometric matching degree. Of course, the specific determination process can employ pre-set numerical or field comparison algorithms to compare the number of operations or fields of login data within a unit of time; the implementation method in this application will not be elaborated upon here.

[0040] Accordingly, S130 describes determining at least one quantitative evaluation result corresponding to each feature dimension based on each feature information, including: In response to an account login feature matching a preset abnormal device login condition, the quantitative evaluation result corresponding to the account login feature is determined.

[0041] The abnormal login conditions can be pre-defined criteria used to determine whether an account applying for a target transaction has exhibited abnormal login activity. These conditions may include, but are not limited to, switching devices or repeatedly logging in multiple times on the same device within a short period. The target transaction is then quantitatively evaluated based on these abnormal login conditions and account login characteristics. When the account login characteristics indicate that the account login activity meets the abnormal login conditions, the account is identified as abnormal, and a corresponding score is assigned to the target transaction based on the pre-defined score range corresponding to the abnormal login conditions. For example, if the account applying for the target transaction switches to a new device for login, each time the new device logs in to the account, the evaluation score for the target transaction increases by 10 points (of course, this pre-defined score range can also be pre-defined by technical personnel in the relevant field).

[0042] In response to the operation frequency characteristics meeting the preset operation frequency anomaly conditions, the quantitative evaluation result corresponding to the operation frequency characteristics is determined.

[0043] The abnormal operation frequency condition can be a pre-set criterion used to determine whether the operation frequency of an account applying for the target transaction is abnormal. This condition may include, but is not limited to, pre-set criteria such as high-frequency operations occurring within a short period of time (e.g., hundreds of operation records within one minute) or the number of operations per unit time. The target transaction is quantitatively evaluated from the perspective of operation frequency characteristics based on this abnormal operation frequency condition. When the information on the operation frequency characteristics indicates that the account's operation meets the abnormal operation frequency condition, the account operation is determined to be abnormal, and a corresponding score is assigned to the target transaction according to the pre-set score range corresponding to the abnormal operation frequency condition. For example, when the account's number of operations within a unit time exceeds 200% of the pre-set standard number, the evaluation score of the target transaction is increased by 30 points (of course, this pre-set score range can also be pre-set by technical personnel in the relevant field).

[0044] In response to the biometric matching degree meeting the preset confidence level conditions, the quantitative evaluation result corresponding to the biometric matching degree is determined.

[0045] The confidence level condition can be a pre-defined criterion used to determine the accuracy and reliability of the biometric matching of an account applying for a target transaction. This condition may include, but is not limited to, facial recognition confidence level. Based on this confidence level condition, the target is quantitatively evaluated from the perspective of biometric matching. When the biometric matching information indicates that the account does not match the account holder's biometrics, it is determined that the account has been stolen, and a corresponding score is assigned to the target transaction according to the pre-defined confidence level condition's score range. For example, when the account's facial recognition confidence level is less than or equal to 85%, the target transaction's evaluation score is increased by 25 points (of course, this pre-defined score range can also be pre-defined by technical personnel in the relevant field).

[0046] In the above implementation, based on the three parts of account login characteristics—account login characteristics, operation frequency characteristics, and biometric matching degree—the target transaction is quantitatively evaluated from different perspectives to identify potential risks. The quantitative score provides a basis for some dimensions of the subsequent overall evaluation, which helps to improve the accuracy of risk identification and early warning, and thus helps to improve account security.

[0047] In one optional implementation, the feature information includes associated network dimension information; The step of analyzing and obtaining feature information corresponding to at least one feature dimension based on transaction-related data includes: Based on the associated account information and behavioral pattern information in the transaction-related data, the risk characteristics and group behavior similarity of the associated accounts in the target transaction are determined. The associated account information can be information about other accounts linked to the account applying for the target transaction; the behavioral pattern information can be a behavioral profile of the account's operations, i.e., information about the historical behavioral habits of the account applying for the target transaction. It is understandable that a sudden change in behavioral habits may indicate account misuse.

[0048] Related account risk characteristics can be risk information that has been recorded about other accounts associated with the current account applying for the target transaction; group behavior similarity can be feature information used to characterize the degree of similarity in behavioral patterns between the current account and other accounts.

[0049] The risk characteristics of related accounts and the similarity of group behavior are used as dimensions of the association network. The association network dimension information should include at least these two items: risk characteristics of related accounts and similarity of group behavior. Based on these two items, a quantitative assessment of the target transaction can be performed from the perspective of the association network.

[0050] Accordingly, determining at least one quantitative evaluation result corresponding to each feature dimension based on each feature information includes: In response to the related account risk characteristics meeting the preset related account risk conditions, the quantitative assessment result corresponding to the related account risk characteristics is determined.

[0051] The associated account risk criteria can be pre-defined as the basis for determining whether accounts associated with the current account applying for the target transaction are risky accounts. For example, a risky account blacklist can be pre-defined, and compliance with the blacklist information can be used as a risk criterion for associated accounts. In other words, if other accounts associated with the current account match the information in the pre-defined blacklist, the current account can be considered to also have a certain level of risk. Therefore, the target transaction can be quantitatively assessed from the perspective of associated account risk characteristics. For example, if the accounts to which the current account's funds are transferred match the information in the pre-defined blacklist, the assessment score for the target transaction can be increased by 30 points (of course, this pre-defined score can also be pre-defined by technical personnel in the relevant field).

[0052] In response to the group behavior similarity meeting the preset similarity conditions, the quantitative evaluation result corresponding to the group behavior similarity is determined.

[0053] The similarity criteria can be pre-defined criteria for judging the similarity of group behavior. For example, a database of a group's account operation patterns can be pre-built based on real-world conditions. The transaction-related data and behavior-related data can be compared with the data in this database to calculate the group behavior similarity. Of course, any similarity algorithm from the relevant data can be used for the similarity calculation; this application embodiment does not limit this. It is understood that if the behavior of the current account is highly similar to the behavior of the group using the account, account theft may exist. Therefore, the target transaction can be quantitatively evaluated from the perspective of group behavior similarity. For example, if the similarity between the current account's behavior pattern and the known behavior pattern of the group is greater than or equal to 60%, the target transaction is given an additional 25 points (of course, this preset score can also be pre-set by those skilled in the art).

[0054] In the above implementation, based on the risk characteristics of two related accounts and the similarity of group behavior in the related network dimension, the target transaction is quantitatively evaluated from different perspectives to identify potential risks. The quantitative score provides a basis for the subsequent overall evaluation, which helps to improve the accuracy of risk identification and early warning, and thus helps to improve account security.

[0055] In one alternative implementation, the feature information includes real-time intelligence dimension information; The process described in S130, which determines at least one quantitative evaluation result corresponding to each feature dimension based on each feature information, includes: In response to any data in the preset risk information database that matches the real-time intelligence dimension information, the quantitative assessment result corresponding to the real-time intelligence dimension information is determined.

[0056] The real-time intelligence dimension information can be risk information that appears in real time for the current account applying for the target transaction, such as risk warnings that the financial system may issue at any time. The risk information database pre-stores risk data corresponding to accounts identified as abnormal. These real-time intelligence dimension information are compared with the data in the pre-prepared risk information database. If the intelligence dimension information matches any data in the risk information database, a corresponding quantitative score is assigned to the target transaction based on the match. For example, for each match in the risk information database, the quantitative score of the target transaction increases by 10 points.

[0057] In the above implementation, based on real-time intelligence dimension information, the target transaction is quantitatively evaluated from the perspective of risk information to identify potential risks. The quantitative score provides a basis for some dimensions of the subsequent overall evaluation, which helps to improve the accuracy of risk identification and early warning, and thus helps to improve account security.

[0058] In one optional implementation, the feature information includes problem feedback dimension information; The feature information corresponding to at least one feature dimension obtained by analyzing transaction-related data as described in S120 includes: Based on the false alarm records and processing timeout records in the transaction-related data, the historical false alarm characteristics and delayed processing characteristics of the target transaction are determined. False alarm records can be records of faults reported during past transactions by the current account requesting the target transaction, which were later determined to be false alarms after being ruled out. Processing timeout records can be records of the current account failing to respond within the specified time after receiving a risk warning in the past.

[0059] Historical false alarm characteristics and delay processing characteristics are used as dimensions of problem feedback information. Problem feedback dimensions should include at least these two items, which can be used to quantitatively evaluate the target transaction from the perspective of the correlation network.

[0060] Accordingly, S130 describes determining at least one quantitative evaluation result corresponding to each feature dimension based on each feature information, including: In response to the historical false alarm characteristics meeting the preset false alarm frequency conditions, the quantitative evaluation results corresponding to the historical false alarm characteristics are determined.

[0061] The false alarm frequency condition can be a pre-defined criterion used to assess the impact of historical false alarm characteristics on trading risk. In essence, the more false alarms a current account has experienced in the past, the higher the risk associated with that account. Therefore, the target transaction can be quantitatively evaluated from the perspective of historical false alarm characteristics. For example, each false alarm generated by the current account within a preset historical time period adds 5 points to the quantitative score of the target transaction (of course, this preset score can also be pre-set by professionals in the relevant field).

[0062] In response to the delayed processing feature meeting the preset risk warning timeout conditions, the quantitative assessment risk corresponding to the delayed processing feature is determined.

[0063] The risk warning timeout condition can be a pre-set criterion for judging whether the current account has a risk in terms of processing delays. Understandably, the more frequently the current account has experienced delays in the past, the higher the risk of the account. Therefore, the target transaction can be quantitatively evaluated from the perspective of delay processing characteristics. For example, if the current account fails to respond within the timeout period after issuing a risk warning, 10 points are added to the quantitative score of the target transaction (of course, this preset score can also be pre-set by technical personnel in the relevant field).

[0064] In the above implementation, based on the two parts of historical false alarm characteristics and delay processing characteristics of the problem feedback dimension, the target transaction is quantitatively evaluated from different perspectives to identify potential risks. The quantitative score provides a basis for some dimensions of the subsequent overall evaluation, which helps to improve the accuracy of risk identification and early warning, and thus helps to improve account security.

[0065] Based on the aforementioned implementation methods, the scores from all different dimensions are summed to obtain the total evaluation score of the target transaction. Different intervention measures are then implemented according to the total score, which can effectively improve the accuracy of identifying potential risks in the transaction and the flexibility of the identification process, thereby ensuring the security of the transaction account.

[0066] Example 2 Figure 2 This is a schematic diagram of a transaction anomaly early warning device provided in Embodiment 2 of this application. Figure 2 As shown, the device 200 includes: The transaction data acquisition module 210 is used to acquire transaction-related data corresponding to the target transaction. The feature dimension determination module 220 is used to analyze and obtain feature information corresponding to at least one feature dimension based on transaction-related data. The evaluation result quantification module 230 is used to determine at least one quantitative evaluation result corresponding to each feature dimension based on each feature information. The transaction anomaly warning module 240 is used to issue anomaly warnings for target transactions based on the results of various quantitative assessments.

[0067] In the technical solution of this application embodiment, feature information corresponding to at least one feature dimension is obtained by analyzing the transaction-related data corresponding to the target transaction. Feature information of multiple different feature dimensions is obtained from the transaction-related data to provide different dimensions of basis for subsequent quantitative evaluation. Based on each feature information, at least one quantitative evaluation result corresponding to each feature dimension is determined, which enables quantitative evaluation in each dimension and lays the foundation for the overall risk assessment of the target transaction. Based on each quantitative evaluation result, anomaly warnings are issued for the target transaction. The comprehensive evaluation of multiple dimensions can improve the comprehensiveness and accuracy of the target transaction evaluation and more accurately help users issue warnings for abnormal transactions.

[0068] In one optional implementation, the feature information may include transaction feature dimension information; The feature dimension determination module 220 may include: The transaction feature dimension determination unit is used to determine the transaction amount deviation, time anomaly characteristics, and geographical jump characteristics of the target transaction based on the transaction amount, transaction frequency, transaction time period, and transaction address in the transaction-related data; and to use the transaction amount deviation, time anomaly characteristics, and geographical jump characteristics as transaction feature dimension information. Accordingly, the evaluation result quantification module 230 may include a transaction feature quantification evaluation unit, which may be specifically used for: If the transaction amount deviation is the excess value of the transaction amount exceeding the historical transaction average of the target account corresponding to the target transaction, and meets the preset standard deviation threshold, then the quantitative evaluation result corresponding to the transaction amount deviation is determined according to the quantitative standard corresponding to the preset standard deviation threshold. In response to the time anomaly characteristics meeting the preset inactive period conditions, the quantitative evaluation results corresponding to the time anomaly characteristics are determined; In response to the geographical jump feature meeting the preset conditions for changes in trading location, the quantitative assessment result corresponding to the geographical jump feature is determined.

[0069] In one optional implementation, the feature information may include account behavior dimension information; The feature dimension determination module 220 includes: The account behavior feature determination unit is used to determine the account login features, operation frequency features, and biometric matching degree of the target transaction based on the account information, login information, transaction channel, and transaction type in the transaction-related data; and to use the account login features, operation frequency features, and biometric matching degree as account behavior dimension information. Accordingly, the evaluation result quantification module 230 may include an account behavior quantification evaluation unit, which may be specifically used for: In response to an account login feature matching a preset abnormal device login condition, determine the quantitative evaluation result corresponding to the account login feature; In response to the operation frequency characteristics meeting the preset operation frequency anomaly conditions, the quantitative evaluation result corresponding to the operation frequency characteristics is determined; In response to the biometric matching degree meeting the preset confidence level conditions, the quantitative evaluation result corresponding to the biometric matching degree is determined.

[0070] In one optional implementation, the feature information includes associated network dimension information; The feature dimension determination module 220 may include: The association network dimension determination unit is used to determine the risk characteristics of associated accounts and the similarity of group behavior of the target transaction based on the associated account information and behavioral pattern information in the transaction-related data; and to use the associated account risk characteristics and the similarity of group behavior as the association network dimension information. Accordingly, the evaluation result quantification module 230 may include a correlation network quantification evaluation unit, which may be specifically used for: In response to the related account risk characteristics meeting the preset related account risk conditions, the quantitative assessment result corresponding to the related account risk characteristics is determined; In response to the group behavior similarity meeting the preset similarity conditions, the quantitative evaluation result corresponding to the group behavior similarity is determined.

[0071] In one alternative implementation, the feature information includes real-time intelligence dimension information; The evaluation result quantification module 230 may include: The external intelligence dimension determination unit is used to determine the quantitative assessment result corresponding to the real-time intelligence dimension information in response to any data in the preset risk information database that matches the real-time intelligence dimension information.

[0072] In one optional implementation, the feature information includes problem feedback dimension information; The feature dimension determination module 220 may include: The problem feedback dimension determination unit is used to determine the historical false alarm characteristics and delayed processing characteristics of the target transaction based on the fault false alarm records and processing timeout records in the transaction-related data; and to use the historical false alarm characteristics and delayed processing characteristics as problem feedback dimension information; Accordingly, the evaluation result quantification module 230 may include a problem feedback quantification evaluation unit, which may be specifically used for: In response to the historical false alarm characteristics meeting the preset false alarm frequency conditions, the quantitative evaluation results corresponding to the historical false alarm characteristics are determined; In response to the delayed processing feature meeting the preset risk warning timeout conditions, the quantitative assessment risk corresponding to the delayed processing feature is determined.

[0073] The transaction anomaly early warning device provided in this application embodiment can execute the transaction anomaly early warning method provided in any embodiment of this application, and has the corresponding functional modules and beneficial effects for executing each transaction anomaly early warning method.

[0074] Example 3 Figure 3A schematic diagram of an electronic device 10, which can be used to implement embodiments of this application, is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices (such as helmets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the application described and / or claimed herein.

[0075] like Figure 3 As shown, the electronic device 10 includes at least one processor 11 and a memory, such as a read-only memory 12 or a random access memory 13, communicatively connected to the at least one processor 11. The memory stores computer programs executable by the at least one processor. The processor 11 can perform various appropriate actions and processes based on the computer program stored in the read-only memory 12 or loaded from storage unit 18 into the random access memory 13. The random access memory 13 may also store various programs and data required for the operation of the electronic device 10. The processor 11, read-only memory 12, and random access memory 13 are interconnected via a bus 14. An input / output interface 15 is also connected to the bus 14.

[0076] Multiple components in electronic device 10 are connected to input / output interface 15, including: input unit 16, such as keyboard, mouse, etc.; output unit 17, such as various types of monitors, speakers, etc.; storage unit 18, such as disk, optical disk, etc.; and communication unit 19, such as network card, modem, wireless transceiver, etc. Communication unit 19 allows electronic device 10 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.

[0077] Processor 11 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of processor 11 include, but are not limited to, central processing units, graphics processing units, various special-purpose artificial intelligence computing chips, various processors running machine learning model algorithms, digital signal processors, and any suitable processor, controller, microcontroller, etc. Processor 11 performs the various methods and processes described above, such as transaction anomaly warning methods.

[0078] In some embodiments, the transaction anomaly warning method may be implemented as a computer program tangibly contained in a computer-readable storage medium, such as storage unit 18. In some embodiments, part or all of the computer program may be loaded and / or installed on electronic device 10 via read-only memory 12 and / or communication unit 19. When the computer program is loaded into random access memory 13 and executed by processor 11, one or more steps of the transaction anomaly warning method described above may be performed. Alternatively, in other embodiments, processor 11 may be configured to perform the transaction anomaly warning method by any other suitable means (e.g., by means of firmware). Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays, application-specific integrated circuits (ASICs), application-specific standard products (ASICs), system-on-a-chip (SoCs), payload programmable logic devices, computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.

[0079] Computer programs used to implement the methods of this application may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when executed by the processor, the computer programs cause the functions / operations specified in the flowcharts and / or block diagrams to be performed. The computer programs may be executed entirely on a machine, partially on a machine, or as a standalone software package, partially on a machine and partially on a remote machine, or entirely on a remote machine or server.

[0080] In the context of this application, a computer-readable storage medium can be a tangible medium that may contain or store a computer program for use by or in conjunction with an instruction execution system, apparatus, or device. A computer-readable storage medium can be, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. Alternatively, a computer-readable storage medium can be a machine-readable signal medium. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory, read-only memory, erasable programmable read-only memory, optical fibers, portable compact disk read-only memory, optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.

[0081] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a monitor with a cathode ray tube or liquid crystal display) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).

[0082] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or computing systems that include middleware components (e.g., application servers), or computing systems that include frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., communication networks). Examples of communication networks include local area networks (LANs), wide area networks (WANs), blockchain networks, and the Internet.

[0083] A computing system can include clients and servers. Clients and servers are generally geographically separated and typically interact via communication networks. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or cloud host, which is a host product within the cloud computing service system to address the shortcomings of traditional physical hosts and virtual private servers, such as high management difficulty and weak business scalability.

[0084] This application also discloses a computer program product, which includes a computer program that, when executed by a processor, implements the transaction anomaly warning method provided in any embodiment of this application. This program product shares the same inventive concept as the transaction anomaly warning methods disclosed in the embodiments of this application, and therefore will not be described further here.

[0085] It should be understood that the various forms of processes shown above can be used to rearrange, add, or delete steps. For example, the steps described in this application can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution of this application can be achieved, and this is not limited herein.

[0086] The specific embodiments described above do not constitute a limitation on the scope of protection of this application. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this application should be included within the scope of protection of this application.

Claims

1. A method for early warning of abnormal transactions, characterized in that, include: Obtain transaction-related data corresponding to the target transaction; Based on the transaction-related data, feature information corresponding to at least one feature dimension is obtained through analysis; Based on each of the aforementioned feature information, at least one quantitative evaluation result corresponding to each of the aforementioned feature dimensions is determined; Based on the quantitative assessment results, anomaly warnings are issued for the target transactions.

2. The method according to claim 1, characterized in that, The feature information includes transaction feature dimension information; The step of analyzing and obtaining feature information corresponding to at least one feature dimension based on the transaction-related data includes: Based on the transaction amount, transaction frequency, transaction time period, and transaction address in the transaction-related data, the transaction amount deviation, time anomaly characteristics, and geographical jump characteristics of the target transaction are determined respectively. The transaction amount deviation, the time anomaly feature, and the geographical jump feature are used as the transaction feature dimension information; Accordingly, determining at least one quantitative evaluation result corresponding to each feature dimension based on each feature information includes: In response to the transaction amount deviation being an excess value of the transaction amount exceeding the historical transaction average of the target account corresponding to the target transaction meeting a preset amount standard deviation threshold, the quantitative evaluation result corresponding to the transaction amount deviation is determined according to the quantitative standard corresponding to the preset amount standard deviation threshold. In response to the time anomaly feature meeting the preset inactive period conditions, the quantitative evaluation result corresponding to the time anomaly feature is determined; In response to the geographical jump feature meeting the preset transaction location change conditions, the quantitative evaluation result corresponding to the geographical jump feature is determined.

3. The method according to claim 1, characterized in that, The feature information includes account behavior dimension information; The step of analyzing and obtaining feature information corresponding to at least one feature dimension based on the transaction-related data includes: Based on the account information, login information, transaction channel, and transaction type in the transaction-related data, the account login characteristics, operation frequency characteristics, and biometric matching degree of the target transaction are determined respectively. The account login features, the operation frequency features, and the biometric matching degree are used as the account behavior dimension information; Accordingly, determining at least one quantitative evaluation result corresponding to each feature dimension based on each feature information includes: In response to the account login feature meeting the preset abnormal device login conditions, a quantitative evaluation result corresponding to the account login feature is determined; In response to the operation frequency characteristic meeting a preset operation frequency anomaly condition, a quantitative evaluation result corresponding to the operation frequency characteristic is determined. In response to the biometric matching degree meeting a preset confidence level condition, a quantitative evaluation result corresponding to the biometric matching degree is determined.

4. The method according to claim 1, characterized in that, The feature information includes associated network dimension information; The step of analyzing and obtaining feature information corresponding to at least one feature dimension based on the transaction-related data includes: Based on the associated account information and behavioral pattern information in the transaction-related data, the risk characteristics of associated accounts and the similarity of group behavior of the target transaction are determined respectively. The risk characteristics of the associated accounts and the similarity of the group behavior are used as the dimension information of the associated network; Accordingly, determining at least one quantitative evaluation result corresponding to each feature dimension based on each feature information includes: In response to the related account risk characteristics meeting the preset related account risk conditions, the quantitative assessment result corresponding to the related account risk characteristics is determined; In response to the group behavior similarity meeting the preset similarity conditions, the quantitative evaluation result corresponding to the group behavior similarity is determined.

5. The method according to claim 1, characterized in that, The feature information includes real-time intelligence dimension information; The step of determining at least one quantitative evaluation result corresponding to each feature dimension based on each feature information includes: In response to the real-time intelligence dimension information matching any data in a preset risk information database, a quantitative assessment result corresponding to the real-time intelligence dimension information is determined.

6. The method according to claim 1, characterized in that, The feature information includes problem feedback dimension information; The step of analyzing and obtaining feature information corresponding to at least one feature dimension based on the transaction-related data includes: Based on the fault false alarm records and processing timeout records in the transaction-related data, determine the historical false alarm characteristics and delayed processing characteristics of the target transaction; The historical false alarm characteristics and the delay processing characteristics are used as the problem feedback dimension information; Accordingly, determining at least one quantitative evaluation result corresponding to each feature dimension based on each feature information includes: In response to the historical false alarm characteristics meeting a preset false alarm frequency condition, a quantitative evaluation result corresponding to the historical false alarm characteristics is determined; In response to the delayed processing feature meeting the preset risk warning timeout condition, the quantitative assessment risk corresponding to the delayed processing feature is determined.

7. A transaction anomaly early warning device, characterized in that, include: The transaction data acquisition module is used to acquire transaction-related data corresponding to the target transaction; The feature dimension determination module is used to analyze and obtain feature information corresponding to at least one feature dimension based on the transaction-related data. The evaluation result quantification module is used to determine at least one quantitative evaluation result corresponding to each of the feature dimensions based on the feature information. The transaction anomaly warning module is used to issue anomaly warnings for the target transaction based on the quantitative evaluation results.

8. An electronic device, characterized in that, The electronic device includes: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that can be executed by the at least one processor, the computer program being executed by the at least one processor to enable the at least one processor to perform the transaction anomaly warning method according to any one of claims 1-6.

9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions that are used to cause a processor to execute the transaction anomaly warning method according to any one of claims 1-6.

10. A computer program product, characterized in that, The computer program product includes a computer program that, when executed by a processor, implements the transaction anomaly early warning method according to any one of claims 1-6.