Account exception monitoring method and device, equipment, storage medium and program product
By using a risk monitoring model based on a deep autoencoder and a multi-granularity feature pyramid, the problem of delayed response and insufficient coverage in risk customer identification in existing technologies has been solved. This enables accurate identification and real-time control of risk customers, improving the accuracy and coverage of risk monitoring.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-09
- Publication Date
- 2026-04-14
AI Technical Summary
Existing technologies suffer from problems such as delayed response, coarse identification granularity, and difficulty in covering complex abnormal patterns when identifying risky customers. They are unable to effectively prevent risky customers and arbitrage behavior while proactively recommending products.
A risk monitoring model employing a deep autoencoder and a multi-granularity feature pyramid is used to extract features from transaction order sequence data and perform multi-granularity processing to obtain coarse-grained, medium-grained, and fine-grained anomaly monitoring results, thereby enabling risk monitoring of target accounts.
It enables accurate identification of high-risk clients, has real-time response capabilities, effectively prevents risky behaviors such as arbitrage, and improves the accuracy and coverage of risk monitoring.
Smart Images

Figure CN121860741A_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to the field of computer technology, and in particular to a method, apparatus, device, storage medium, and program product for monitoring account anomalies. Background Technology
[0002] In the telecommunications and internet sector, service recommendation and risk control are two key tasks in the operational process. With the increasing complexity of service types and systems, effectively identifying and preventing risky customers and arbitrage activities while proactively recommending products has become a pressing technical challenge for the industry.
[0003] In related technologies, traditional risk control methods typically rely on pre-defined recommendation paths, combined with recall and ranking models for auxiliary recommendations, and then use post-event analysis to identify and manage at-risk customers. However, these methods often suffer from problems such as delayed response, coarse-grained identification, and difficulty in covering complex anomaly patterns. Summary of the Invention
[0004] This disclosure is made in view of the above-mentioned problems. This disclosure provides a method, apparatus, device, storage medium, and program product for monitoring account anomalies.
[0005] According to one aspect of this disclosure, a method for monitoring account anomalies is provided, comprising: The system acquires transaction order sequence data of the target account within a preset historical time period, as well as a pre-built risk monitoring model; wherein the risk monitoring model includes a deep autoencoder and a multi-granularity feature pyramid. The spatiotemporal compressed features are obtained by extracting features from the transaction order sequence data using the deep autoencoder. The spatiotemporal compression features are processed in multiple granularities using the multi-granularity feature pyramid to obtain multi-granularity anomaly monitoring results; wherein, the multi-granularity anomaly monitoring results include coarse-grained anomaly monitoring results, medium-grained anomaly monitoring results, and fine-grained anomaly monitoring results; Risk monitoring is performed on the target account based on the multi-granularity anomaly monitoring results.
[0006] According to another aspect of this disclosure, a monitoring device for account anomalies is provided, comprising: The acquisition module is used to acquire transaction order sequence data of the target account within a preset historical time period, as well as a pre-built risk monitoring model; wherein, the risk monitoring model includes a deep autoencoder and a multi-granularity feature pyramid; The processing module is used to extract features from the transaction order sequence data using the deep autoencoder to obtain spatiotemporal compressed features; The processing module is further configured to perform multi-granularity processing on the spatiotemporal compressed features through the multi-granularity feature pyramid to obtain multi-granularity anomaly monitoring results; wherein, the multi-granularity anomaly monitoring results include coarse-grained anomaly monitoring results, medium-granularity anomaly monitoring results, and fine-granularity anomaly monitoring results; The processing module is also used to perform risk monitoring on the target account based on the multi-granularity anomaly monitoring results.
[0007] In another aspect of exemplary embodiments of this disclosure, an electronic device is provided, including a memory, a processor, and a computer program stored in the memory, the processor executing the computer program to implement the methods described in exemplary embodiments of this disclosure.
[0008] In another aspect of exemplary embodiments of the present disclosure, a computer-readable storage medium is provided having a computer program stored thereon that, when executed by a processor, implements the methods described in exemplary embodiments of the present disclosure.
[0009] In another aspect of the exemplary embodiments of this disclosure, a computer program product is provided, including a computer program that, when executed by a processor, implements the methods described in the exemplary embodiments of this disclosure.
[0010] As will be described in detail below, the account anomaly monitoring method according to embodiments of this disclosure acquires transaction order sequence data of a target account within a preset historical time period and a pre-constructed risk monitoring model. The risk monitoring model includes a deep autoencoder and a multi-granularity feature pyramid. Features are extracted from the transaction order sequence data using the deep autoencoder to obtain spatiotemporal compressed features. The spatiotemporal compressed features are then processed in multiple granularities using the multi-granularity feature pyramid to obtain multi-granularity anomaly monitoring results. These multi-granularity anomaly monitoring results include coarse-grained anomaly monitoring results, medium-granularity anomaly monitoring results, and fine-grained anomaly monitoring results. Based on these multi-granularity anomaly monitoring results, risk monitoring of the target account is performed, which integrates spatiotemporal features, supports multi-granularity anomaly identification, and has real-time response capabilities. This allows for accurate product recommendations while effectively preventing and controlling risky behaviors such as arbitrage.
[0011] It should be understood that both the foregoing general description and the following detailed description are exemplary and intended to provide further illustration of the claimed technology. Attached Figure Description
[0012] The above and other objects, features, and advantages of this disclosure will become more apparent from the more detailed description of the embodiments thereof in conjunction with the accompanying drawings. The drawings are provided to further illustrate the embodiments of this disclosure and form part of the specification. They are used together with the embodiments of this disclosure to explain the disclosure and do not constitute a limitation thereof. In the drawings, the same reference numerals generally represent the same components or steps.
[0013] Figure 1 A flowchart illustrating an exemplary embodiment of the present disclosure of a method for monitoring account anomalies is shown. Figure 2 A schematic diagram of the architecture of the risk monitoring model provided in an exemplary embodiment of this disclosure is shown; Figure 3 This illustration shows a schematic diagram of the process for obtaining transaction order sequence data provided in an exemplary embodiment of this disclosure; Figure 4 A schematic diagram of the architecture of a deep autoencoder provided in an exemplary embodiment of this disclosure is shown; Figure 5 A schematic diagram of the architecture of the multi-granularity feature pyramid provided in an exemplary embodiment of this disclosure is shown; Figure 6 A complete architectural diagram of the risk monitoring model provided in this exemplary embodiment is shown; Figure 7 A schematic diagram of the structure of an account anomaly monitoring device provided in an exemplary embodiment of this disclosure is shown; Figure 8 A schematic diagram of the structure of an electronic device provided in an exemplary embodiment of this disclosure is shown; Figure 9 A schematic diagram of the structure of a computer system provided in an exemplary embodiment of this disclosure is shown. Detailed Implementation
[0014] To make the objectives, technical solutions, and advantages of this disclosure more apparent, exemplary embodiments according to this disclosure will now be described in detail with reference to the accompanying drawings. Obviously, the described embodiments are merely some embodiments of this disclosure, and not all embodiments of this disclosure. It should be understood that this disclosure is not limited to the exemplary embodiments described herein.
[0015] It should be understood that the steps described in the method embodiments of this disclosure may be performed in different orders and / or in parallel. Furthermore, the method embodiments may include additional steps and / or omit the steps shown. The scope of this disclosure is not limited in this respect.
[0016] The term "comprising" and its variations as used herein are open-ended, meaning "including but not limited to". The term "based on" means "at least partially based on". The term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one additional embodiment"; the term "some embodiments" means "at least some embodiments". Definitions of other terms will be given in the description below. It should be noted that the concepts of "first", "second", etc., used in this disclosure are only used to distinguish different devices, modules, or units, and are not intended to limit the order of functions performed by these devices, modules, or units or their interdependencies.
[0017] It should be noted that the terms "a" and "a plurality of" used in this disclosure are illustrative rather than restrictive, and those skilled in the art should understand that, unless otherwise expressly indicated in the context, they should be understood as "one or more".
[0018] The names of messages or information exchanged between multiple devices in the embodiments of this disclosure are for illustrative purposes only and are not intended to limit the scope of such messages or information.
[0019] In related technologies, various solutions for identifying risky accounts have been proposed. For example, some methods construct graph structures based on the transfer relationships between accounts and use quantum computing or graph embedding techniques to identify risky nodes; other methods are based on time series clustering, detecting anomalies by analyzing the clustering characteristics of user behavior over time; and still others improve the accuracy of fraudulent account identification by integrating the results of multiple models through ensemble learning.
[0020] Although these methods have achieved certain results in specific scenarios, they still have certain limitations: on the one hand, these solutions mostly focus on single-type anomaly detection, such as only identifying individual anomalies or only focusing on group behavior, making it difficult to comprehensively cover multiple risk forms such as "single anomaly point", "contextual anomaly" and "abnormal data group"; on the other hand, existing methods have not fully combined the dual characteristics of time and space in feature construction and model structure, which limits their recognition ability in high-dimensional and dynamic data environments.
[0021] Therefore, in order to solve the above problems, this disclosure provides a method for monitoring abnormal accounts, which can integrate spatiotemporal features, support multi-granularity anomaly identification, and have real-time response capabilities, so as to effectively prevent and control risky behaviors such as arbitrage while accurately recommending products.
[0022] The account anomaly monitoring method provided in this disclosure can be executed by a terminal or by a chip applied to the terminal.
[0023] For example, the terminal may include one or more of the following: mobile phone, tablet computer, wearable device, in-vehicle device, laptop computer, ultra-mobile personal computer (UMPC), netbook, PDA, and wearable device based on augmented reality (AR) and / or virtual reality (VR) technology. The exemplary embodiments disclosed herein do not impose specific limitations on these.
[0024] Figure 1 A flowchart illustrating an exemplary embodiment of the present disclosure of a method for monitoring account anomalies is shown. Figure 1 As shown, the methods for monitoring account anomalies include: S101, acquire transaction order sequence data of the target account within a preset historical time period, as well as a pre-built risk monitoring model; wherein, the risk monitoring model includes a deep autoencoder and a multi-granularity feature pyramid; S102, features are extracted from transaction order sequence data using a deep autoencoder to obtain spatiotemporal compressed features; S103, the spatiotemporal compression features are processed in multiple granularities through a multi-granularity feature pyramid to obtain multi-granularity anomaly monitoring results; among which, the multi-granularity anomaly monitoring results include coarse-grained anomaly monitoring results, medium-grained anomaly monitoring results, and fine-grained anomaly monitoring results; S104, risk monitoring of target accounts based on multi-granularity anomaly monitoring results.
[0025] Specifically, the aforementioned preset historical time period can be the period most recent to the current time. The specific length of the preset historical time period can be determined according to actual needs, and this embodiment does not impose specific limitations on it.
[0026] The process of obtaining the aforementioned transaction order sequence data can be as follows: First, obtain multiple transaction orders from the target account within a preset historical time period, arranged in chronological order; then, extract transaction order feature data from each transaction order; finally, arrange the transaction order feature data corresponding to multiple transaction orders in chronological order to obtain the transaction order sequence data. This transaction order sequence data can be two-dimensional feature data with dimension T×R, where T represents the time step and R represents the feature dimension.
[0027] Furthermore, since the transaction order sequence data within the aforementioned preset historical time period can be updated in real time as time progresses, it can provide real-time response capabilities for account risk monitoring.
[0028] Figure 2 This illustration shows an architectural diagram of the risk monitoring model provided in an exemplary embodiment of this disclosure, such as... Figure 2 As shown, the risk monitoring model 200 described above can be a pre-built neural network model in this embodiment of the disclosure, which may include a deep autoencoder 210 and a multi-granularity feature pyramid 220. The risk monitoring model 200 can be used to identify risks in the trading behavior of target accounts, thereby avoiding arbitrage risks while actively recommending products, and ultimately reducing operational risks.
[0029] Feature extraction is performed on the transaction order sequence data using a deep autoencoder 210 to obtain spatiotemporally compressed features. These spatiotemporally compressed features can be a comprehensive spatiotemporal feature representation of the temporal and spatial (structural) features extracted from the transaction order sequence data by the deep autoencoder.
[0030] Multi-granularity anomaly monitoring results are obtained by performing multi-granularity processing on spatiotemporal compressed features using a multi-granularity feature pyramid 220, and risk monitoring of target accounts is then conducted based on these results. The multi-granularity anomaly monitoring results include coarse-grained, medium-grained, and fine-grained anomaly monitoring results.
[0031] Based on this, the embodiments of this disclosure can perform comprehensive risk analysis on target accounts at different scales, so that the final multi-granularity anomaly monitoring results can cover anomaly monitoring results at three different scales: coarse-grained, medium-grained, and fine-grained. This can accurately identify complex arbitrage and fraudulent behaviors, with a wider range of identification and reduced possibility of false alarms (judging normal trading behavior as abnormal) and false negatives (failing to identify real trading anomalies).
[0032] As can be seen, this disclosure not only addresses the issue of accurate business recommendations in the telecommunications operator industry but also utilizes rich user transaction order information for risk arbitrage modeling, thereby effectively and in real-time identifying high-risk users. The method in this disclosure integrates reinforcement learning and deep learning, providing a novel approach and a faster response method for monitoring and applying user arbitrage risk status.
[0033] According to the technical solution of the example embodiment of this disclosure, transaction order sequence data of a target account within a preset historical time period and a pre-built risk monitoring model are obtained. The risk monitoring model includes a deep autoencoder and a multi-granularity feature pyramid. Features are extracted from the transaction order sequence data using the deep autoencoder to obtain spatiotemporal compressed features. The spatiotemporal compressed features are then processed in multiple granularities using the multi-granularity feature pyramid to obtain multi-granularity anomaly monitoring results. These multi-granularity anomaly monitoring results include coarse-grained anomaly monitoring results, medium-granularity anomaly monitoring results, and fine-grained anomaly monitoring results. Risk monitoring of the target account based on these multi-granularity anomaly monitoring results can integrate spatiotemporal features, support multi-granularity anomaly identification, and possess real-time response capabilities. This allows for accurate product recommendations while effectively preventing and controlling risky behaviors such as arbitrage.
[0034] In some embodiments, obtaining transaction order sequence data of a target account within a preset historical time period includes: Obtain multiple transaction order data for the target account, sorted by time. Extract multiple transaction order features from each transaction order data to construct one-dimensional feature data; Based on the preset time window size and preset sliding step size, determine multiple target one-dimensional feature data within the current time window from multiple one-dimensional feature data; Two-dimensional feature data is constructed based on multiple target one-dimensional feature data, serving as transaction order sequence data within a preset historical time period.
[0035] Specifically, the aforementioned multiple transaction order data can be related data of multiple transaction orders generated by the target account for business product transactions, and the multiple transaction order data are arranged in chronological order.
[0036] Figure 3 This illustration shows a schematic diagram of the process for obtaining transaction order sequence data provided in an exemplary embodiment of this disclosure, such as... Figure 3 As shown, this embodiment of the disclosure can extract multiple transaction order features from each transaction order data to construct one-dimensional feature data. These multiple transaction order features can be arranged based on attributes such as feature domain and feature correlation, and may include, but are not limited to, user features, product features, user product interaction behavior, timestamps (including year, month, day, hour, minute, second, etc.), and latitude and longitude. Multiple transaction order features belonging to the same row of the same transaction order data form a feature vector, constructing one-dimensional feature data. Multiple one-dimensional feature data are stacked in the time dimension to form a time-dimensional stacked data group.
[0037] The aforementioned preset time window size can be used to determine the size of the current time window, which can be determined based on the length of the preset historical time period mentioned above. Here, the specific values of the aforementioned preset time window size and the aforementioned preset sliding step size can be selected according to actual needs, and this embodiment does not impose specific limitations on them.
[0038] Suppose that the preset time window size is set to W, the sliding step size is set to S, and the minimum time interval is dynamically set to t0 based on the actual order frequency and sample distribution. Then, by using the preset time window size W to obtain the time dimension stacked data group within the current time window range, the time row (i.e., time dimension) T can be obtained from the minimum time interval t0, which is equal to W / t0.
[0039] Among them, the multiple one-dimensional feature data located within the current time window from multiple one-dimensional feature data are all target one-dimensional feature data; these multiple target one-dimensional feature data are constructed into two-dimensional feature data, which serve as transaction order sequence data within a preset historical time period.
[0040] Here, the logic for processing the one-dimensional feature data in each time row is as follows: 1) If a time row contains only one row of one-dimensional feature data, fill that row with data and move to the next row; 2) If a time row contains multiple rows of one-dimensional feature data, take the first row of one-dimensional feature data to fill it, and move the remaining rows of one-dimensional feature data to the next time row, then jump to the next row; 3) If a time row does not contain one-dimensional feature data, fill it with 0 and move to the next row; 4) After filling all the time rows in the current time window, return a two-dimensional feature matrix with dimension T×R, which serves as the two-dimensional feature data, i.e., the transaction order sequence data within the preset historical time period.
[0041] When updating at the current time point, a new time window W can be selected according to the sliding step size S, and steps 1) to 4) above can be continued until all candidate one-dimensional feature data are processed into a standard format. That is to say, according to the preset time window size and sliding step size, as the current time point slides, one-dimensional feature data outside the current time window is eliminated, and newly added one-dimensional feature data is stacked. After updating the two-dimensional feature data at each time point, it is input into the above-mentioned risk monitoring model for risk monitoring to determine whether the target account has arbitrage behavior.
[0042] In some embodiments, Figure 4 A schematic diagram of the architecture of a deep autoencoder provided in an exemplary embodiment of this disclosure is shown, such as... Figure 4As shown, the depth autoencoder 210 includes an encoder 211 and a decoder 212; the method also includes: During the training phase of the deep autoencoder, features are extracted from the transaction order sequence data by the encoder to obtain training spatiotemporal compressed features; The reconstructed transaction order sequence data is obtained by reconstructing the spatiotemporal compressed features of the training through a decoder. Calculate the pre-training loss based on transaction order sequence data and reconstructed transaction order sequence data; The deep autoencoder is pre-trained using the pre-training loss until it converges.
[0043] Specifically, such as Figure 4 As shown, during the training phase of the deep autoencoder 210, the encoder 211 extracts features from the transaction order sequence data to obtain training spatiotemporal compressed features (to distinguish them from the spatiotemporal compressed features output by the deep autoencoder 210 during the inference phase, the feature representation output by the encoder 211 during the training phase of the deep autoencoder 210 is referred to as the training spatiotemporal compressed features). In this process, the encoder 211 automatically learns how to perform feature engineering, intelligently compressing the high-dimensional, sparse transaction order sequence data (dimension T×R) into a low-dimensional, dense spatiotemporal compressed feature (dimension 1×TR).
[0044] This training spatiotemporal compression feature is no longer a simple list of the original transaction order sequence data, but rather removes redundancy and noise and extracts a high-level representation of the temporal and spatial patterns hidden in the underlying data.
[0045] After the encoder 211 outputs the spatiotemporal compressed features, the spatiotemporal compressed features are input to the decoder 212. The decoder 212 reconstructs the training spatiotemporal compressed features to obtain the reconstructed transaction order sequence data (dimension T×R). The reconstruction behavior of the decoder 212 is a strong constraint, which can force the training spatiotemporal compressed features generated by the encoder 211 to contain sufficient information during the training phase; otherwise, the decoder 212 will be unable to reconstruct the data.
[0046] Since the training data mostly consists of normal trading behavior, the deep autoencoder 210 tends to encode and decode normal trading behavior best. The aforementioned "compression and reconstruction" process allows the trained deep autoencoder 210 to focus on learning the common behavioral patterns shared by the vast majority of normal accounts.
[0047] After each iteration of training, a pre-training loss can be calculated based on the transaction order sequence data and the reconstructed transaction order sequence data. This pre-training loss is then used to pre-train the deep autoencoder until convergence. The pre-training loss can be calculated based on a loss function (such as Mean Squared Error, MSE), quantifying the difference between the reconstructed transaction order sequence data and the original transaction order sequence data, i.e., the reconstruction error. During the training phase, this reconstruction error serves as a learning signal to adjust the model parameters of the deep autoencoder 210, guiding how to improve the encoding capability of the encoder 211 and the decoding capability of the decoder 212.
[0048] When the pre-training loss converges, it means that the deep autoencoder 210 has learned to reconstruct most normal data with high fidelity. At this point, the encoder 211 has become a stable and reliable feature extractor. The spatiotemporal compressed features output by this pre-trained encoder 211 during the inference phase are a high-quality feature representation that is very friendly to downstream tasks (multi-granularity anomaly detection).
[0049] Based on this, this phased training strategy (unsupervised pre-training followed by supervised fine-tuning / application) is a successful model in deep learning. It allows the model to learn general patterns from massive amounts of unlabeled data first, and then optimizes it for specific tasks, which greatly improves the model's generalization ability and performance.
[0050] In some embodiments, such as Figure 4 As shown, encoder 211 includes a temporal feature extractor 2111 and a spatial feature extractor 2112; The encoder extracts features from the transaction order sequence data to obtain training spatiotemporal compressed features, including: The transaction order sequence data is extracted using a time feature extractor to obtain the positive time features. The reverse time features are obtained by extracting reverse time features from the transaction order sequence data using a time feature extractor. The transaction order sequence data, forward time features, and reverse time features are merged to obtain the merged features; Spatial features are extracted from the merged features using a spatial feature extractor to obtain training spatiotemporal compressed features.
[0051] Specifically, the time feature extractor 2111 extracts forward time features from the transaction order sequence data, obtaining forward time features (with a dimension of T×R). This forward order processing (from past to present) simulates natural causal relationships and the passage of time, allowing the time feature extractor 2111 to learn the evolutionary trends and long-term dependencies of transaction behavior. For example, the time feature extractor 2111 can learn a positive behavioral chain such as "users typically claim coupons first and then complete the purchase within minutes." This is crucial for identifying progressive, planned arbitrage behaviors.
[0052] The time feature extractor 2111 extracts reverse time features from the transaction order sequence data, resulting in reverse time features (dimension T×R). This reverse processing (from present to past) significantly shortens the information path, enabling the time feature extractor 2111 to more accurately link the final result with recent behavior without the interference of a long historical sequence, and to focus more directly on the most recent and decisive transaction behavior. For example, a fraudulent act may only reveal its intent in the final step (such as a large withdrawal).
[0053] Here, the network architecture of the aforementioned time feature extractor 2111 can be selected according to actual needs, and this disclosure embodiment does not impose specific limitations on it. In the method of this disclosure embodiment, the time feature extractor 2111 can be a Long Short-Term Memory (LSTM) network.
[0054] The transaction order sequence data, forward time features, and reverse time features are merged to obtain a merged feature (with dimensions T×R×3). This merging process can be used to splice the feature dimensions to form a three-dimensional tensor of T×R×3. This three-dimensional tensor is a super feature representation that is information-redundant and complementary. It ensures that the subsequent spatial feature extractor can obtain the richest and most three-dimensional temporal information, laying a solid foundation for extracting powerful spatial features.
[0055] Spatial features are extracted from the merged features by the spatial feature extractor 2112 to obtain the training spatiotemporal compressed features (1×TR). The spatial feature extractor 2112 compresses the information-rich three-dimensional feature tensor of the merged features into a one-dimensional spatiotemporal compressed feature vector, which contains two key types of information: the forward and backward dependencies of time and the spatial combination of features.
[0056] Here, the network architecture of the aforementioned spatial feature extractor 2112 can be selected according to actual needs, and this disclosure embodiment does not specifically limit it. In the method of this disclosure embodiment, the spatial feature extractor 2112 can be a Visual Geometry Group (VGG) network.
[0057] In some embodiments, such as Figure 4 As shown, the decoder 212 includes a linear transformation layer 2121 and a temporal feature reconstructor 2122; The reconstructed transaction order sequence data is obtained by reconstructing the training spatiotemporal compressed features using a decoder, including: The training spatiotemporal compressed features are linearly transformed by a linear transformation layer to obtain dimensionality-transformed features. The reconstructed transaction order sequence data is obtained by reconstructing the dimensional transformation features using a time feature reconstructor.
[0058] Specifically, since the dimension of the training spatiotemporal compression feature is 1×TR, while the dimension of the transaction order sequence data is T×R, this embodiment of the present disclosure can first perform a linear transformation on the training spatiotemporal compression feature through a linear transformation layer 2121 to obtain a dimension-transformed feature (dimension T×R), thereby achieving spatial alignment in the feature dimension.
[0059] Here, the network architecture of the aforementioned linear transformation layer 2121 can be selected according to actual needs, and this disclosure embodiment does not impose specific limitations on it. In the method of this disclosure embodiment, the linear transformation layer 2121 can be a linear layer or a fully connected layer (Linear Layer).
[0060] The time feature reconstructor 2122 reconstructs the dimensional transformation features to obtain reconstructed transaction order sequence data (dimension T×R). In this reconstruction process, the time feature reconstructor 2122 can learn how to generate reconstructed transaction order data for the current time step based on the reconstruction state of the previous time step, thereby reconstructing the dynamic evolution of the entire sequence over time.
[0061] Here, the network architecture of the aforementioned time feature reconstructor 2122 can be selected according to actual needs, and this disclosure embodiment does not impose specific limitations on it. In the method of this disclosure embodiment, the time feature reconstructor 2122 selects a network architecture symmetrical to the time feature extractor 2111, which can effectively reconstruct the time sequence to retain key temporal information. For example, the time feature reconstructor 2122 can be a Long Short-Term Memory (LSTM) network.
[0062] Based on this, in a specific implementation, the embodiments of this disclosure can utilize spatial feature extraction characteristics to construct two-dimensional feature data from the feature data based on the time dimension. Since the constructed two-dimensional feature data simultaneously possesses spatial and sequential properties, the encoder structure of the deep autoencoder is designed as LSTM+VGG, and the decoder structure is LSTM. During the encoding process, LSTM is first used to extract sequential properties, and then VGG is used to extract spatial features. This effectively integrates a deep autoencoder with a type of neural network and introduces it into the field of risk customer identification. It utilizes the temporal construction of two-dimensional feature data (transaction order sequence data) combined with the LSTM+VGG method to extract temporal and spatial relationships, thus solving the problem that the original model can only identify abnormal data points.
[0063] In some embodiments, during the inference phase of the risk monitoring model 200, the encoder 211 in the deep autoencoder 210 is used to extract features from the transaction order sequence data to obtain spatiotemporal compressed features.
[0064] Specifically, in the inference phase of the risk monitoring model 200, the decoder 212 in the deep autoencoder 210 is discarded, and only the encoder 211 is run, which greatly reduces the amount of computation. This allows the complex risk monitoring model 200 to be deployed in a high-concurrency, real-time production environment to perform instant risk assessment on each transaction order or each session to meet real-time requirements.
[0065] In some embodiments, the method further includes: During the training phase, the encoder and the multi-granularity feature pyramid are jointly trained to obtain the risk monitoring model.
[0066] Specifically, such as Figure 2 As shown, after the deep autoencoder 210 is trained, the encoder 211 in the deep autoencoder 210 is copied, and the copied encoder 211 and the multi-granularity feature pyramid 220 are jointly trained to obtain the risk monitoring model 200. This risk monitoring model 200 can be called a one-class neural network (OC-NN).
[0067] This joint training approach treats the replicated encoder 211 and the multi-granularity feature pyramid 220 as a single network, allowing their model parameters (weights and biases) to be updated and optimized simultaneously according to the final risk detection target. This significantly improves the risk identification accuracy of the final risk monitoring model 200 and enhances its robustness and generalization ability, thereby improving its overall stability and reliability.
[0068] During the joint training phase, the objective function of the risk monitoring model is:
[0069] Where r represents the hyperplane bias, V represents the weights from the input to the hidden unit, g(·) represents the sigmoid function of the hidden layer, Xn represents the spatiotemporal compression feature, w represents the weights of the output layer, N represents the total number of training samples, and n represents the nth training sample. v This represents a hyperparameter that controls the hyperplane and the origin.
[0070] When learning the weights of the multi-granularity feature pyramid 220, the weights of encoder 211 are not frozen, but participate in the training. The specific process can be represented as follows: (1) Input spatiotemporal compression feature Xn; (2) Initialize r; (3) Determine whether the risk monitoring model to be constructed has converged. If it has not converged, execute (4); if it has converged, execute (7). (4) Fix r, update w and V; (5) Update r with the new values of w and V; (6) Determine whether the risk monitoring model to be constructed has converged. If it has not converged, repeat (4) and (5). (7) End the iteration; (8) Calculate the score Sn=yn-r for each input Xn; (9) If Sn is greater than or equal to 0, it is considered normal; (10) If Sn is less than 0, it is considered abnormal; (11) Return {Sn}.
[0071] In some embodiments, Figure 5 This illustration shows a schematic diagram of the architecture of a multi-granularity feature pyramid provided in an exemplary embodiment of this disclosure. Figure 6 A complete architectural diagram of the risk monitoring model provided in this exemplary embodiment is shown, such as... Figure 5 and Figure 6 As shown, the multi-granularity feature pyramid 220 includes a coarse-grained feature extraction branch 221, a medium-grained feature extraction branch 222, and a fine-grained feature extraction branch 223; Multi-granularity anomaly monitoring results are obtained by performing multi-granularity processing on spatiotemporal compressed features using a multi-granularity feature pyramid, including: By using a coarse-grained feature extraction branch to extract spatiotemporal compressed features in a coarse-grained manner, coarse-grained anomaly monitoring results representing anomalous points are obtained. Medium-granularity feature extraction is used to extract spatiotemporal compressed features, resulting in medium-granularity anomaly monitoring results that characterize the anomaly group. By using a fine-grained feature extraction branch to extract spatiotemporal compressed features, fine-grained anomaly monitoring results that characterize contextual anomalies are obtained.
[0072] Specifically, such as Figure 5 As shown, the coarse-grained feature extraction branch 221 can be based on a macroscopic overall perspective, typically using a larger receptive field or less downsampling, to retain relatively global information and focus on obvious anomalies. Its detection target is the fine-grained anomaly monitoring results (size 1×T) characterizing the anomaly points, representing a single anomalous data point channel, specifically designed to capture independent, drastic, and highly skewed single anomalous events.
[0073] The medium-granularity feature extraction branch 222 can capture medium-range feature interactions and sequence patterns based on a local correlation perspective through further downsampling and feature fusion, focusing on morphologies composed of multiple behaviors. Its detection target is the medium-granularity anomaly monitoring results (size 1×T) characterizing the anomaly group, representing the anomaly data group channel, specifically used to capture sequence patterns where a single behavior is normal, but consecutive occurrences constitute anomalies.
[0074] The fine-grained feature extraction branch 223, based on microscopic details and contextual perspective, has a minimal receptive field and can capture very subtle local changes and feature combinations at specific locations, focusing on behaviors that only become anomalous under specific circumstances. Its detection target is the fine-grained anomaly monitoring results (size 1×T) characterizing contextual anomalies, representing the contextual anomaly data channel, specifically designed to capture behaviors whose anomalies heavily depend on specific background or contextual relationships.
[0075] As can be seen, the embodiments of this disclosure can perform comprehensive anomaly monitoring of spatiotemporal compression features based on coarse-grained feature extraction branch 221, medium-grained feature extraction branch 222 and fine-grained feature extraction branch 223. Through comprehensive judgment of multiple granularities, many false alarms can be avoided.
[0076] Compared with other risk control systems and risk account locking, the risk monitoring method used in this disclosure is different. It can not only discover single abnormal data (abnormal point), but also discover data that is abnormal only under certain data combinations (contextual abnormality), and can also discover data groups that are not abnormal but appear simultaneously (abnormal group), thereby effectively locating risky customers.
[0077] In some embodiments, such as Figure 5 As shown, the coarse-grained feature extraction branch 221 includes a first convolutional network 2211 and a first fully connected layer 2212; the first convolutional network 2211 is used to perform the first downsampling of the spatiotemporal compressed features to obtain the first bypass features; the first fully connected layer 2212 is used to perform fusion processing on the first bypass features and the first feedforward back-sampling features to obtain the coarse-grained anomaly monitoring results. The medium-granularity feature extraction branch 222 includes a second convolutional network 2221 and a second fully connected layer 2222; the second convolutional network 2221 is used to perform a second downsampling on the spatiotemporal compressed features to obtain the second bypass features; the second fully connected layer 2222 is used to perform fusion processing on the second bypass features and the second feedforward back upsampling features to obtain the medium-granularity anomaly monitoring results. The fine-grained feature extraction branch 223 includes a third convolutional network 2231 and a third fully connected layer 2232; the third convolutional network 2231 is used to perform a third downsampling on the spatiotemporal compressed features to obtain the third bypass features; the third fully connected layer 2232 is used to perform fusion processing on the third bypass features and the third feedforward back-sampling features to obtain the fine-grained anomaly monitoring results.
[0078] Specifically, in convolutional neural networks, low-level feature maps have high resolution and rich details, but weak semantics; while high-level feature maps have strong semantics, but low resolution and loss of details.
[0079] Bypass features (including first bypass features, second bypass features, and third bypass features): These represent features derived from the early stages of the backbone network. They have high resolution, more details, and location information, but they are relatively primitive and belong to low-level features.
[0080] Feedforward backsampling features (including the first feedforward backsampling feature, the second feedforward backsampling feature, and the third feedforward backsampling feature): These represent features passed from the deep layers of the backbone network. Due to multiple convolutions, they are rich in semantic information, but their location information is coarse due to their low resolution.
[0081] Based on this, the embodiments of this disclosure can integrate the two in order to obtain deep features that simultaneously possess accurate positioning capabilities and powerful semantic understanding capabilities.
[0082] like Figure 5 As shown, the first convolutional network 2211 performs the first downsampling to obtain the first bypass feature. At this time, the downsampling ratio is small, the feature map size is large, and the richest spatial details and accurate location information are preserved.
[0083] First, the first bypass feature is fused with the first feedforward backsampled feature from a deeper layer to obtain a fused feature of size 1 / 2T×1 / 2R. This allows the branch to not only have precise localization capabilities but also to understand what constitutes a significant anomaly. Then, the first fully connected layer 2212 extracts coarse-grained anomaly monitoring results from the fused feature, which can very accurately locate those significant, isolated anomalies.
[0084] The second convolutional network 2221 performs a second downsampling to obtain the second bypass feature (size 1 / 4T×1 / 4R). At this point, the feature map size is further reduced, and local patterns begin to be abstracted from the details.
[0085] The second bypass feature is fused with the corresponding second feedforward back-sampling feature to obtain a fused feature of size 1 / 4T×1 / 4R. This fused feature contains both the local pattern information constituting the behavior sequence and is endowed with a deep semantic context. Then, the second fully connected layer 2222 uses the fused feature to identify anomaly groups composed of multiple consecutive behaviors.
[0086] The third convolutional network 2231 performs a third downsampling to obtain the third bypass feature. At this point, the feature map size is the smallest, representing the most abstract and global semantic information.
[0087] First, the third bypass feature is fused with the corresponding third feedforward backsampling feature to obtain a fused feature of size 1 / 8T×1 / 8R. This fusion is more like a refinement and enhancement of the deepest and most abstract understanding of the backbone network. Then, based on this highly abstract but semantically strong fused feature, the third fully connected layer 2232 is able to perceive contextual anomalies that rely on global context and complex feature interactions to be discovered.
[0088] Based on this, the embodiments of this disclosure can achieve true multi-scale perception, that is, by downsampling at different depths in three branches, input features are forcibly observed and analyzed from different scales, thereby possessing the ability to perceive abnormal patterns of different scales. The three branches adopt the same "bypass + upsampling fusion + full connection" design pattern, with a unified and clear structure, which is easy to understand and implement. At the same time, this design allows the results of three granularities to be calculated in parallel in one forward propagation, resulting in high computational efficiency.
[0089] The foregoing mainly describes the solutions provided by the embodiments of this disclosure. It is understood that, in order to achieve the above functions, the electronic device includes hardware structures and / or software modules corresponding to the execution of each function. Those skilled in the art should readily recognize that, based on the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein, this disclosure can be implemented in hardware or a combination of hardware and computer software. Whether a function is executed in hardware or by computer software driving hardware depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this disclosure.
[0090] This disclosure embodiment can divide the electronic device into functional units according to the above method example. For example, each function can be divided into a separate functional module, or two or more functions can be integrated into one processing module. The integrated module can be implemented in hardware or as a software functional module. It should be noted that the module division in this disclosure embodiment is illustrative and only represents one logical functional division; other division methods may be used in actual implementation.
[0091] By dividing each functional module according to its corresponding function, an exemplary embodiment of this disclosure provides a device for monitoring account anomalies, which can be a terminal or a chip applied to the terminal. Figure 7 A schematic diagram of the structure of a monitoring device for account anomalies provided in an exemplary embodiment of this disclosure is shown. Figure 7 As shown, the device 700 includes: The acquisition module 701 is used to acquire transaction order sequence data of the target account within a preset historical time period, as well as a pre-built risk monitoring model; wherein, the risk monitoring model includes a deep autoencoder and a multi-granularity feature pyramid; Processing module 702 is used to extract features from the transaction order sequence data using the deep autoencoder to obtain spatiotemporal compressed features; The processing module 702 is further configured to perform multi-granularity processing on the spatiotemporal compression features through the multi-granularity feature pyramid to obtain multi-granularity anomaly monitoring results; wherein, the multi-granularity anomaly monitoring results include coarse-grained anomaly monitoring results, medium-granularity anomaly monitoring results, and fine-grained anomaly monitoring results; The processing module 702 is also used to perform risk monitoring on the target account based on the multi-granularity anomaly monitoring results.
[0092] In some embodiments, the acquisition module 701 is further configured to acquire multiple transaction order data of the target account sorted by time; Multiple transaction order features are extracted from each of the transaction order data to construct one-dimensional feature data; Based on the preset time window size and preset sliding step size, determine multiple target one-dimensional feature data within the current time window from multiple one-dimensional feature data; Two-dimensional feature data is constructed based on the multiple target one-dimensional feature data, which serves as the transaction order sequence data within the preset historical time period.
[0093] In some embodiments, the depth autoencoder includes an encoder and a decoder; The processing module 702 is further configured to extract features from the transaction order sequence data through the encoder during the training phase of the deep autoencoder to obtain training spatiotemporal compressed features; The reconstructed transaction order sequence data is obtained by reconstructing the training spatiotemporal compressed features using the decoder. Based on the transaction order sequence data and the reconstructed transaction order sequence data, calculate the pre-training loss; The deep autoencoder is pre-trained based on the pre-training loss until convergence.
[0094] In some embodiments, the encoder includes a temporal feature extractor and a spatial feature extractor; The processing module 702 is further configured to extract positive time features from the transaction order sequence data using the time feature extractor to obtain positive time features; The time feature extractor is used to extract the reverse time features from the transaction order sequence data to obtain the reverse time features. The transaction order sequence data, the forward time feature, and the reverse time feature are merged to obtain the merged feature; Spatial features are extracted from the merged features using the spatial feature extractor to obtain training spatiotemporal compressed features.
[0095] In some embodiments, the decoder includes a linear transformation layer and a temporal feature reconstructor; The processing module 702 is further configured to perform a linear transformation on the training spatiotemporal compressed features through the linear transformation layer to obtain dimensionality transformation features; The time feature reconstructor reconstructs the dimensional transformation features to obtain reconstructed transaction order sequence data.
[0096] In some embodiments, during the inference phase of the risk monitoring model, the encoder in the deep autoencoder is used to extract features from the transaction order sequence data to obtain the spatiotemporal compressed features.
[0097] In some embodiments, the processing module 702 is further configured to jointly train the encoder and the multi-granularity feature pyramid during the training phase to obtain the risk monitoring model.
[0098] In some embodiments, the multi-granularity feature pyramid includes a coarse-grained feature extraction branch, a medium-granularity feature extraction branch, and a fine-grained feature extraction branch; The processing module 702 is further configured to perform coarse-grained extraction of the spatiotemporal compression features through the coarse-grained feature extraction branch to obtain the coarse-grained anomaly monitoring results characterizing the anomaly points; The spatiotemporal compressed features are extracted using the medium-granularity feature extraction branch to obtain the medium-granularity anomaly monitoring results that characterize the anomaly group; The spatiotemporal compressed features are extracted in a fine-grained manner through the fine-grained feature extraction branch to obtain the fine-grained anomaly monitoring results that characterize contextual anomalies.
[0099] In some embodiments, the coarse-grained feature extraction branch includes a first convolutional network and a first fully connected layer; the first convolutional network is used to perform a first downsampling on the spatiotemporal compressed features to obtain a first bypass feature; the first fully connected layer is used to perform fusion processing on the first bypass feature and the first feedforward back-sampling feature to obtain the coarse-grained anomaly monitoring result. The medium-granularity feature extraction branch includes a second convolutional network and a second fully connected layer; the second convolutional network is used to perform a second downsampling on the spatiotemporal compressed features to obtain a second bypass feature; the second fully connected layer is used to perform fusion processing on the second bypass feature and the second feedforward back-sampling feature to obtain the medium-granularity anomaly monitoring result. The fine-grained feature extraction branch includes a third convolutional network and a third fully connected layer; the third convolutional network is used to perform a third downsampling on the spatiotemporal compressed features to obtain a third bypass feature; the third fully connected layer is used to perform fusion processing on the third bypass feature and the third feedforward back-sampling feature to obtain the fine-grained anomaly monitoring result.
[0100] This disclosure also provides an electronic device, including a memory, a processor, and a computer program stored in the memory, wherein the processor executes the computer program to implement the steps of the methods disclosed in this disclosure.
[0101] Figure 8 A schematic diagram of the structure of an electronic device provided in an exemplary embodiment of this disclosure is shown. For example... Figure 8 As shown, the electronic device 800 includes at least one processor 801 and a memory 802 coupled to the processor 801. The processor 801 can perform the corresponding steps in the methods disclosed in the embodiments of this disclosure.
[0102] The processor 801 described above can also be called a Central Processing Unit (CPU), which can be an integrated circuit chip with signal processing capabilities. Each step in the method disclosed in this embodiment can be implemented by the integrated logic circuitry in the processor 801 or by software instructions. The processor 801 can be a general-purpose processor, a digital signal processor (DSP), an ASIC, a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the method disclosed in this embodiment can be directly implemented by a hardware decoding processor, or implemented by a combination of hardware and software modules in the decoding processor. The software modules can be located in the memory 802, such as random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, or other mature storage media in the art. The processor 801 reads information from the memory 802 and, in conjunction with its hardware, completes the steps of the method described above.
[0103] Furthermore, various operations / processes according to this disclosure, implemented via software and / or firmware, can be transmitted from a storage medium or network to a computer system with a dedicated hardware architecture, for example, Figure 9 The computer system 900 shown is equipped with the programs that constitute the software. When various programs are installed, the computer system is able to perform various functions, including functions such as those described above. Figure 9 A schematic diagram of the structure of a computer system provided in an exemplary embodiment of this disclosure is shown.
[0104] Computer system 900 is intended to represent various forms of digital electronic computer devices, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. Electronic devices can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the present disclosure described and / or claimed herein.
[0105] like Figure 9As shown, the computer system 900 includes a computing unit 901, which can perform various appropriate actions and processes based on a computer program stored in a read-only memory (ROM) 902 or a computer program loaded into a random access memory (RAM) 903 from a storage unit 908. The RAM 903 may also store various programs and data required for the operation of the computer system 900. The computing unit 901, ROM 902, and RAM 903 are interconnected via a bus 904. An input / output (I / O) interface 905 is also connected to the bus 904.
[0106] Multiple components in the computer system 900 are connected to the I / O interface 905, including: an input unit 906, an output unit 907, a storage unit 908, and a communication unit 909. The input unit 906 can be any type of device capable of inputting information into the computer system 900. The input unit 906 can receive input numerical or character information and generate key signal inputs related to user settings and / or function control of the electronic device. The output unit 907 can be any type of device capable of presenting information and may include, but is not limited to, a monitor, speaker, video / audio output terminal, vibrator, and / or printer. The storage unit 908 may include, but is not limited to, a hard disk and an optical disk. The communication unit 909 allows the computer system 900 to exchange information / data with other devices via a network such as the Internet, and may include, but is not limited to, a modem, network card, infrared communication device, wireless communication transceiver, and / or chipset, such as Bluetooth™ device, WiFi device, WiMax device, cellular communication device, and / or the like.
[0107] The computing unit 901 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the computing unit 901 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The computing unit 901 performs the various methods and processes described above. For example, in some embodiments, the methods disclosed in this disclosure can be implemented as a computer software program tangibly contained in a machine-readable medium, such as storage unit 908. In some embodiments, part or all of the computer program can be loaded and / or installed on an electronic device via ROM 902 and / or communication unit 909. In some embodiments, the computing unit 901 can be configured to perform the methods disclosed in this disclosure by any other suitable means (e.g., by means of firmware).
[0108] This disclosure also provides a computer-readable storage medium, wherein when the instructions in the computer-readable storage medium are executed by a processor of an electronic device, the electronic device is able to perform the methods disclosed in this disclosure.
[0109] The computer-readable storage medium in this disclosure can be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, apparatus, or device. The aforementioned computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specifically, the aforementioned computer-readable storage medium may include electrical connections based on one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.
[0110] The aforementioned computer-readable medium may be included in the aforementioned electronic device; or it may exist independently and not assembled into the electronic device.
[0111] This disclosure also provides a computer program product, including a computer program, wherein when the computer program is executed by a processor, it implements the methods disclosed in the embodiments of this disclosure.
[0112] In embodiments of this disclosure, computer program code for performing the operations of this disclosure can be written in one or more programming languages or a combination thereof. These programming languages include, but are not limited to, object-oriented programming languages such as Java, Smalltalk, and C++, as well as conventional procedural programming languages such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network (including a local area network (LAN) or a wide area network (WAN)), or it can be connected to an external computer.
[0113] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this disclosure. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.
[0114] The modules, components, or units described in the embodiments of this disclosure can be implemented in software or hardware. The names of the modules, components, or units do not necessarily constitute a limitation on the module, component, or unit itself.
[0115] The functions described above in this document can be performed at least in part by one or more hardware logic components. For example, without limitation, exemplary hardware logic components that can be used include: field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), system-on-a-chip (SoCs), complex programmable logic devices (CPLDs), and so on.
[0116] The above description is merely an illustration of some embodiments of this disclosure and the technical principles employed. Those skilled in the art should understand that the scope of this disclosure is not limited to technical solutions formed by specific combinations of the above-described technical features, but should also cover other technical solutions formed by arbitrary combinations of the above-described technical features or their equivalents without departing from the above-described concept. For example, technical solutions formed by substituting the above features with (but not limited to) technical features disclosed in this disclosure that have similar functions.
[0117] While specific embodiments of this disclosure have been described in detail by way of example, those skilled in the art should understand that the examples are for illustrative purposes only and not intended to limit the scope of this disclosure. Those skilled in the art should understand that modifications can be made to the above embodiments without departing from the scope and spirit of this disclosure. The scope of this disclosure is defined by the appended claims.
Claims
1. A method for monitoring account anomalies, characterized in that, include: The system acquires transaction order sequence data of the target account within a preset historical time period, as well as a pre-built risk monitoring model; wherein the risk monitoring model includes a deep autoencoder and a multi-granularity feature pyramid. The spatiotemporal compressed features are obtained by extracting features from the transaction order sequence data using the deep autoencoder. The spatiotemporal compression features are processed in multiple granularities using the multi-granularity feature pyramid to obtain multi-granularity anomaly monitoring results; wherein, the multi-granularity anomaly monitoring results include coarse-grained anomaly monitoring results, medium-grained anomaly monitoring results, and fine-grained anomaly monitoring results; Risk monitoring is performed on the target account based on the multi-granularity anomaly monitoring results.
2. The method as described in claim 1, characterized in that, The step of obtaining the transaction order sequence data of the target account within a preset historical time period includes: Obtain multiple transaction order data for the target account, sorted by time. Multiple transaction order features are extracted from each of the transaction order data to construct one-dimensional feature data; Based on the preset time window size and preset sliding step size, determine multiple target one-dimensional feature data within the current time window from multiple one-dimensional feature data; Two-dimensional feature data is constructed based on the multiple target one-dimensional feature data, which serves as the transaction order sequence data within the preset historical time period.
3. The method as described in claim 1, characterized in that, The depth autoencoder includes an encoder and a decoder; the method further includes: During the training phase of the deep autoencoder, the encoder is used to extract features from the transaction order sequence data to obtain training spatiotemporal compressed features; The reconstructed transaction order sequence data is obtained by reconstructing the training spatiotemporal compressed features using the decoder. Based on the transaction order sequence data and the reconstructed transaction order sequence data, calculate the pre-training loss; The deep autoencoder is pre-trained based on the pre-training loss until convergence.
4. The method as described in claim 3, characterized in that, The encoder includes a temporal feature extractor and a spatial feature extractor; The step of extracting features from the transaction order sequence data using the encoder to obtain training spatiotemporal compressed features includes: The time feature extractor is used to extract positive time features from the transaction order sequence data to obtain positive time features. The time feature extractor is used to extract the reverse time features from the transaction order sequence data to obtain the reverse time features. The transaction order sequence data, the forward time feature, and the reverse time feature are merged to obtain the merged feature; Spatial features are extracted from the merged features using the spatial feature extractor to obtain training spatiotemporal compressed features.
5. The method as described in claim 3, characterized in that, The decoder includes a linear transformation layer and a temporal feature reconstructor; The process of reconstructing the training spatiotemporal compressed features using the decoder to obtain reconstructed transaction order sequence data includes: The training spatiotemporal compressed features are linearly transformed by the linear transformation layer to obtain dimensional transformation features. The time feature reconstructor reconstructs the dimensional transformation features to obtain reconstructed transaction order sequence data.
6. The method as described in claim 3, characterized in that, During the inference phase of the risk monitoring model, the encoder in the deep autoencoder is used to extract features from the transaction order sequence data to obtain the spatiotemporal compressed features.
7. The method as described in claim 3, characterized in that, The method further includes: During the training phase, the encoder and the multi-granularity feature pyramid are jointly trained to obtain the risk monitoring model.
8. The method as described in claim 1, characterized in that, The multi-granularity feature pyramid includes a coarse-grained feature extraction branch, a medium-grained feature extraction branch, and a fine-grained feature extraction branch; The process of performing multi-granularity processing on the spatiotemporal compressed features through the multi-granularity feature pyramid to obtain multi-granularity anomaly monitoring results includes: The spatiotemporal compressed features are extracted in a coarse-grained manner through the coarse-grained feature extraction branch to obtain the coarse-grained anomaly monitoring results that characterize the anomaly points; The spatiotemporal compressed features are extracted using the medium-granularity feature extraction branch to obtain the medium-granularity anomaly monitoring results that characterize the anomaly group; The spatiotemporal compressed features are extracted in a fine-grained manner through the fine-grained feature extraction branch to obtain the fine-grained anomaly monitoring results that characterize contextual anomalies.
9. The method as described in claim 8, characterized in that, The coarse-grained feature extraction branch includes a first convolutional network and a first fully connected layer; the first convolutional network is used to perform a first downsampling on the spatiotemporal compressed features to obtain a first bypass feature; the first fully connected layer is used to perform fusion processing on the first bypass feature and the first feedforward back-sampling feature to obtain the coarse-grained anomaly monitoring result. The medium-granularity feature extraction branch includes a second convolutional network and a second fully connected layer; the second convolutional network is used to perform a second downsampling on the spatiotemporal compressed features to obtain a second bypass feature; the second fully connected layer is used to perform fusion processing on the second bypass feature and the second feedforward back-sampling feature to obtain the medium-granularity anomaly monitoring result. The fine-grained feature extraction branch includes a third convolutional network and a third fully connected layer; the third convolutional network is used to perform a third downsampling on the spatiotemporal compressed features to obtain a third bypass feature; the third fully connected layer is used to perform fusion processing on the third bypass feature and the third feedforward back-sampling feature to obtain the fine-grained anomaly monitoring result.
10. A monitoring device for abnormal accounts, characterized in that, include: The acquisition module is used to acquire transaction order sequence data of the target account within a preset historical time period, as well as a pre-built risk monitoring model; wherein, the risk monitoring model includes a deep autoencoder and a multi-granularity feature pyramid; The processing module is used to extract features from the transaction order sequence data using the deep autoencoder to obtain spatiotemporal compressed features; The processing module is further configured to perform multi-granularity processing on the spatiotemporal compressed features through the multi-granularity feature pyramid to obtain multi-granularity anomaly monitoring results; wherein, the multi-granularity anomaly monitoring results include coarse-grained anomaly monitoring results, medium-granularity anomaly monitoring results, and fine-granularity anomaly monitoring results; The processing module is also used to perform risk monitoring on the target account based on the multi-granularity anomaly monitoring results.
11. The apparatus as claimed in claim 10, characterized in that, The acquisition module is also used to acquire multiple transaction order data of the target account sorted by time; Multiple transaction order features are extracted from each of the transaction order data to construct one-dimensional feature data; Based on the preset time window size and preset sliding step size, determine multiple target one-dimensional feature data within the current time window from multiple one-dimensional feature data; Two-dimensional feature data is constructed based on the multiple target one-dimensional feature data, which serves as the transaction order sequence data within the preset historical time period.
12. The apparatus as claimed in claim 10, characterized in that, The depth autoencoder includes an encoder and a decoder; The processing module is also used to extract features from the transaction order sequence data through the encoder during the training phase of the deep autoencoder to obtain training spatiotemporal compressed features. The reconstructed transaction order sequence data is obtained by reconstructing the training spatiotemporal compressed features using the decoder. Based on the transaction order sequence data and the reconstructed transaction order sequence data, calculate the pre-training loss; The deep autoencoder is pre-trained based on the pre-training loss until convergence.
13. The apparatus as claimed in claim 12, characterized in that, The encoder includes a temporal feature extractor and a spatial feature extractor; The processing module is also used to extract positive-order time features from the transaction order sequence data using the time feature extractor to obtain positive-order time features; The time feature extractor is used to extract the reverse time features from the transaction order sequence data to obtain the reverse time features. The transaction order sequence data, the forward time feature, and the reverse time feature are merged to obtain the merged feature; Spatial features are extracted from the merged features using the spatial feature extractor to obtain training spatiotemporal compressed features.
14. The apparatus as claimed in claim 12, characterized in that, The decoder includes a linear transformation layer and a temporal feature reconstructor; The processing module is also used to perform a linear transformation on the training spatiotemporal compressed features through the linear transformation layer to obtain dimensionality transformation features; The time feature reconstructor reconstructs the dimensional transformation features to obtain reconstructed transaction order sequence data.
15. The apparatus as claimed in claim 12, characterized in that, During the inference phase of the risk monitoring model, the encoder in the deep autoencoder is used to extract features from the transaction order sequence data to obtain the spatiotemporal compressed features.
16. The apparatus as claimed in claim 12, characterized in that, The processing module is also used to jointly train the encoder and the multi-granularity feature pyramid during the training phase to obtain the risk monitoring model.
17. The apparatus as claimed in claim 10, characterized in that, The multi-granularity feature pyramid includes a coarse-grained feature extraction branch, a medium-grained feature extraction branch, and a fine-grained feature extraction branch; The processing module is also used to perform coarse-grained extraction of the spatiotemporal compression features through the coarse-grained feature extraction branch to obtain the coarse-grained anomaly monitoring results characterizing the anomaly points; The spatiotemporal compressed features are extracted using the medium-granularity feature extraction branch to obtain the medium-granularity anomaly monitoring results that characterize the anomaly group; The spatiotemporal compressed features are extracted in a fine-grained manner through the fine-grained feature extraction branch to obtain the fine-grained anomaly monitoring results that characterize contextual anomalies.
18. The apparatus as claimed in claim 17, characterized in that, The coarse-grained feature extraction branch includes a first convolutional network and a first fully connected layer; the first convolutional network is used to perform a first downsampling on the spatiotemporal compressed features to obtain a first bypass feature; the first fully connected layer is used to perform fusion processing on the first bypass feature and the first feedforward back-sampling feature to obtain the coarse-grained anomaly monitoring result. The medium-granularity feature extraction branch includes a second convolutional network and a second fully connected layer; the second convolutional network is used to perform a second downsampling on the spatiotemporal compressed features to obtain a second bypass feature; the second fully connected layer is used to perform fusion processing on the second bypass feature and the second feedforward back-sampling feature to obtain the medium-granularity anomaly monitoring result. The fine-grained feature extraction branch includes a third convolutional network and a third fully connected layer; the third convolutional network is used to perform a third downsampling on the spatiotemporal compressed features to obtain a third bypass feature; the third fully connected layer is used to perform fusion processing on the third bypass feature and the third feedforward back-sampling feature to obtain the fine-grained anomaly monitoring result.
19. An electronic device comprising a memory, a processor, and a computer program stored in the memory, characterized in that, The processor executes the computer program to implement the steps of the method according to any one of claims 1 to 9.
20. A computer-readable storage medium having a computer program stored thereon, characterized in that, When executed by a processor, the computer program implements the steps of the method described in any one of claims 1 to 9.
21. A computer program product, comprising a computer program, characterized in that, When executed by a processor, the computer program implements the steps of the method described in any one of claims 1 to 9.