Precious metal recovery anomaly detection method and system
By constructing an anomaly detection method that integrates user behavior trajectories and environmental variables, and using the isolated forest algorithm to identify dynamic anomalies in precious metal recycling transactions, this method solves the problems of risk identification delay and insufficient security in existing technologies, and achieves highly accurate risk interception and continuous security protection.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- SHENZHEN VECTOR GOLD TECH DEV CO LTD
- Filing Date
- 2026-01-09
- Publication Date
- 2026-04-21
AI Technical Summary
Existing technologies struggle to accurately identify dynamic and abnormal behaviors and potential spoofing signals in precious metal recycling transactions, leading to delayed risk response and insufficient security.
By collecting user operation data and order association information, user behavior trajectories are constructed, the complexity of abnormal behavior is quantified, environmental variables such as device, network, and geographical location are integrated to detect potential spoofing signals, and an anomaly detection model is built using the isolated forest algorithm to intercept risky transactions in real time.
It achieves accurate identification of dynamic abnormal behavior, improves the accuracy of abnormal identification to over 95%, avoids the spread of risks, forms a continuously iterative security protection mechanism, and meets the high-security and dynamic risk control needs of the precious metal recycling industry.
Smart Images

Figure CN121903589A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of industrial cloud computing technology, and in particular to a method and system for detecting anomalies in precious metal recycling. Background Technology
[0002] The precious metals recycling industry involves high-value asset transactions, and its security and efficiency directly affect market order and user trust. With the continuous expansion of transaction volume and the deepening of digital transformation, the concealment and complexity of abnormal behavior are constantly increasing, placing higher demands on the dynamic adaptation and real-time response capabilities of risk control technologies. The widespread adoption of industrial cloud computing provides strong support for the centralized processing and rapid analysis of massive transaction data, driving the precious metals recycling market towards intelligence and efficiency. However, it also makes it more difficult to identify disguised abnormal behavior across devices and networks, bringing new challenges to risk control work.
[0003] Currently, most existing technologies in the precious metals recycling field rely on fixed risk control rules or single behavioral indicators to identify anomalies. Even though some solutions utilize industrial cloud computing to achieve data storage and batch analysis, they lack the ability to deeply perceive dynamic changes in user behavior. These existing technologies often formulate static rules based on historical data, which cannot adapt to changes in user operating habits and the emergence of new anomaly patterns in a timely manner. Moreover, they fail to fully integrate transaction environment variables such as device identification, network address, and geographical location for multi-dimensional verification during the analysis process, resulting in a single dimension for judging abnormal behavior.
[0004] In practical applications, fixed rules are difficult to cover dynamic and abnormal scenarios such as frequent order modifications in a short period of time and cross-regional device switching. Single indicator analysis is also easily misled by spoofing behavior. The batch processing characteristics of industrial cloud computing may also lead to delays in risk response, making it impossible to intercept risks in a timely manner at critical transaction nodes.
[0005] This technological limitation results in a core drawback of existing technologies: they are unable to accurately identify dynamically changing abnormal behaviors and potential spoofing signals, thus failing to meet the high security requirements of precious metal recycling transactions. Summary of the Invention
[0006] This invention provides a method and system for detecting anomalies in precious metal recycling, which solves the problem that existing technologies are unable to accurately identify dynamically changing abnormal behaviors and potential spoofing signals. It enables accurate identification of dynamic abnormal behaviors in precious metal recycling transactions and real-time interception of key transaction nodes, thereby improving the security and reliability of transaction risk control.
[0007] Firstly, in order to solve the above-mentioned technical problems, the present invention provides a method for detecting anomalies in precious metal recycling, comprising: Collect user operation data and order association information in precious metal recycling transactions, extract behavioral features over time, and construct user behavior trajectories; Based on the user behavior trajectory, behavioral pattern analysis is performed to quantify the complexity of abnormal behavior and obtain preliminary abnormal indicators. If the preliminary abnormal indicators exceed the preset abnormal indicator judgment threshold, the environmental information sequence associated with the user behavior trajectory is extracted, and the corresponding transaction environment dynamic variables are integrated to form complete context information. Potential spoofing signals are detected by matching and filtering the context information with historical normal transaction data. If the potential spoofing signal is detected, a multi-dimensional fusion feature is extracted from the context information, the preliminary anomaly index and the potential spoofing signal using a preset anomaly detection model. Anomaly detection and correlation calculation are performed on the multi-dimensional fusion feature to identify dynamic anomaly patterns. If no potential spoofing signal is detected, the abnormal intensity, duration and frequency of occurrence are extracted from the preliminary abnormality indicators. Combined with the environmental stability parameters in the context information, a regular abnormality analysis vector is generated and matched with a preset template library to determine the regular abnormality pattern. Based on the dynamic anomaly mode or the conventional anomaly mode, the time window width and the consistency metric of the operation behavior in the order confirmation process are extracted as control parameters and fused to generate a judgment vector for the interception conditions. The judgment vector determines whether the abnormal interception trigger condition is met. If the abnormal interception trigger condition is met, the real-time response mechanism is activated to block risky transactions and the blocking effect is evaluated. If the abnormal interception trigger condition is not met, the transaction is marked as proceeding normally and transaction data feedback is recorded. Based on the blocking effect or the transaction data feedback, the analysis parameters of the behavior pattern analysis and the anomaly detection model are optimized to form a continuous security protection mechanism.
[0008] Secondly, the present invention provides an anomaly detection system for precious metal recycling, characterized in that it comprises: The data acquisition module is used to collect user operation data and order association information in precious metal recycling transactions, extract behavioral features over time, and construct user behavior trajectories. The behavior analysis module is used to perform behavior pattern analysis based on the user's behavior trajectory, quantify the complexity of abnormal behavior, and obtain preliminary abnormal indicators. The spoofing detection module is used to extract the environmental information sequence associated with the user behavior trajectory if the preliminary abnormal indicators exceed the preset abnormal indicator judgment threshold, integrate the corresponding transaction environment dynamic variables to form complete context information, and detect potential spoofing signals by matching and filtering the context information with historical normal transaction data. The dynamic anomaly identification module is used to extract multi-dimensional fusion features from the context information, the preliminary anomaly indicators and the potential spoofing signal through a preset anomaly detection model if the potential spoofing signal is detected, and to perform anomaly detection and correlation calculation on the multi-dimensional fusion features to identify dynamic anomaly patterns. The routine anomaly determination module is used to extract the anomaly intensity, duration and frequency of occurrence from the preliminary anomaly indicators if no potential spoofing signal is detected, combine it with the environmental stability parameters in the context information, generate a routine anomaly analysis vector and match it with a preset template library to determine the routine anomaly pattern. The interception condition determination module is used to extract the time window width and the consistency metric of operation behavior in the order confirmation process as control parameters based on the dynamic abnormal mode or the regular abnormal mode, and fuse them to generate an interception condition judgment vector. If the comprehensive deviation score of the judgment vector is higher than the preset interception trigger threshold, the triggering condition for abnormal interception is determined to be met. The transaction processing module is used to determine whether the abnormal interception trigger condition is met based on the judgment vector. If the abnormal interception trigger condition is met, the real-time response mechanism is activated to block risky transactions and evaluate the blocking effect. If the abnormal interception trigger condition is not met, the transaction is marked as proceeding normally and transaction data feedback is recorded. The model optimization module is used to optimize the analysis parameters of the behavior pattern analysis and the anomaly detection model based on the blocking effect or the transaction data feedback, so as to form a continuous security protection mechanism.
[0009] Compared with the prior art, the present invention has the following beneficial effects: (1) This invention constructs behavioral trajectories by collecting user operation and order data, quantifies abnormal indicators, and then integrates environmental variables such as device, network, and geographical location to detect potential spoofing signals. Furthermore, the complementary multi-dimensional data can avoid misjudgment by a single indicator, accurately capture spoofing abnormal behaviors across devices and regions, solve the core problem that existing technologies have difficulty in identifying complex spoofing signals, and improve the accuracy of anomaly identification to over 95%.
[0010] (2) This invention constructs an anomaly detection model using the isolated forest algorithm, integrates multi-dimensional features to identify dynamic anomaly patterns, and extracts the time window width and behavioral consistency measurement during the order confirmation process to trigger real-time interception. This immediately blocks risky transactions at critical transaction nodes, preventing risk spread, solving the problem of response delays in existing technologies, and effectively ensuring transaction security.
[0011] (3) By combining the blocking effect with feedback from normal transaction data, this invention optimizes the behavioral analysis parameters and model feature weights, dynamically adapts to changes in transaction scenarios, and forms a continuously iterative security protection mechanism that can continuously improve risk control adaptability and meet the high security and dynamic risk control needs of the precious metal recycling industry. Attached Figure Description
[0012] Figure 1 This is a schematic diagram of a method for detecting anomalies in precious metal recycling provided in the first embodiment of the present invention; Figure 2 This is a schematic diagram of the structure of a precious metal recycling anomaly detection system provided in the second embodiment of the present invention. Detailed Implementation
[0013] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0014] Reference Figure 1 The first embodiment of the present invention provides a method for detecting anomalies in precious metal recycling, comprising the following steps: S11: Collect user operation data and order association information in precious metal recycling transactions, extract behavioral features in the time dimension, and construct user behavior trajectories; S12, Based on the user behavior trajectory, perform behavior pattern analysis, quantify the complexity of abnormal behavior, and obtain preliminary abnormal indicators; S13, if the preliminary abnormal indicator exceeds the preset abnormal indicator judgment threshold, then extract the environmental information sequence associated with the user behavior trajectory, integrate the corresponding transaction environment dynamic variables to form complete context information, and detect potential spoofing signals by matching and filtering the context information with historical normal transaction data. S14, if the potential spoofing signal is detected, then through a preset anomaly detection model, multi-dimensional fusion features are extracted from the context information, the preliminary anomaly indicators and the potential spoofing signal, and anomaly detection and correlation calculation are performed on the multi-dimensional fusion features to identify dynamic anomaly patterns. S15, if no potential spoofing signal is detected, extract the abnormal intensity, duration and frequency of occurrence from the preliminary abnormal indicators, combine them with the environmental stability parameters in the context information, generate a regular abnormal analysis vector and match it with a preset template library to determine the regular abnormal pattern. S16, Based on the dynamic abnormal mode or the conventional abnormal mode, extract the time window width of the order confirmation process and the consistency measure of operation behavior as control parameters, and fuse them to generate a judgment vector of interception conditions. S17. Determine whether the abnormal interception trigger condition is met based on the judgment vector. If the abnormal interception trigger condition is met, start the real-time response mechanism to block risky transactions and evaluate the blocking effect. If the abnormal interception trigger condition is not met, mark the transaction as normal and record the transaction data feedback. S18. Based on the blocking effect or the transaction data feedback, optimize the analysis parameters of the behavior pattern analysis and the anomaly detection model to form a continuous security protection mechanism.
[0015] In step S11, the process of collecting user operation data and order association information in precious metal recycling transactions, extracting behavioral features over time, and constructing user behavior trajectories includes: The system obtains user operation data and order association information from the precious metal recycling trading platform, and associates operation type, order status and timestamp by user ID to obtain initial behavior sequence data. Extract the time interval features from the initial behavior sequence data, mark high-frequency change operations and count the change frequency to form a frequency feature vector; Based on the frequency feature vector, the distribution pattern of continuous operation intervals is analyzed, abnormal change nodes are screened and clustered to obtain a sequence of behavior change nodes. A trajectory curve is constructed based on the sequence of behavioral change nodes, and the timestamps of continuous nodes are merged to form a user behavior trajectory.
[0016] It should be noted that, firstly, the operation types cover core interactive behaviors such as creating orders, modifying orders, canceling orders, and confirming recycling. Order status includes pending confirmation, modified, canceled, and completed, with timestamps accurate to the second to ensure the accuracy of the time dimension of the behavior sequence. For example, if user ID U1001 creates an order at 9:05:23, modifies the metal weight in the order at 9:07:15, and confirms recycling at 9:08:30, these operation data, after being associated with the corresponding order information, form the initial behavior sequence data.
[0017] Next, the time interval between two adjacent operations is calculated. The preset time interval threshold is 5 minutes. This threshold is determined based on the platform's historical transaction data statistics and covers the operation interval habits of more than 90% of normal users. This can accurately mark abnormal behavior of frequent operations within a short period of time, while avoiding misjudging normal continuous operations. If the time interval is less than this threshold, it is marked as a high-frequency change operation. The number of high-frequency changes by users in the morning, noon, and evening is counted, with each period lasting 8 hours, forming a three-dimensional frequency feature vector. For example, if user U1002 makes 5 high-frequency changes in the morning, 3 in the noon, and 7 in the evening, the corresponding frequency feature vector is [5,3,7].
[0018] Subsequently, the mean, variance, and skewness of the interval distribution are calculated. If the distribution deviates from the normal transaction interval distribution range on the platform, the corresponding operation nodes are selected as abnormal change nodes. The K-means clustering algorithm is used to cluster the abnormal change nodes. The number of clusters is selected as three based on the concentration of abnormal nodes. This number was determined through testing with 500 sets of abnormal transaction data on the platform. This ensures accurate coverage of the three core abnormal patterns in the precious metal recycling scenario while avoiding confusion caused by too many clusters or omission of key abnormal nodes due to too few clusters. The final result is a sequence of behavioral change nodes arranged in chronological order. For example, the abnormal change nodes for user U1003 are concentrated at 10:12:00, 10:15:30, and 10:18:45, forming a sequence of behavioral change nodes.
[0019] Finally, using time as the horizontal axis and operation frequency as the vertical axis, the behavioral change nodes are connected in chronological order to form a trajectory curve. The threshold for merging consecutive nodes is set to 1 hour, based on the time distribution patterns of normal user operations. This ensures that continuous abnormal operations within a short period are merged and analyzed, clearly presenting the changing trends of user behavior. For example, user U1004's trajectory curve shows a high-frequency operation peak between 14:00 and 15:00. By merging the timestamps of all nodes within this period, a complete user behavior trajectory is formed.
[0020] In step S12, the behavioral pattern analysis based on the user's behavior trajectory, quantifying the complexity of abnormal behavior, and obtaining preliminary anomaly indicators include: Extract a sequence of consecutive operation timestamps from the user's behavior trajectory, calculate the time interval between adjacent operations, and form an initial interval list; Based on the initial interval list, the interval mean, variance, and proportion of short intervals are calculated to construct an interval statistical feature vector; wherein the short interval is an operation interval that is less than a preset time interval threshold set based on the statistical mean of operation intervals of historical normal transactions on the platform. The interval statistical feature vector is compared with the preset recycling transaction pattern template to calculate the pattern deviation value; If the pattern deviation value does not exceed the preset deviation threshold, it is determined to be a normal behavior pattern, the current behavior feature data is recorded and included in the user's historical behavior database, and the user's behavior trajectory is updated. If the pattern deviation value exceeds the preset deviation threshold, abnormal deviation nodes are marked and assigned statistical weights. The statistical weights are then fused to obtain a preliminary abnormality index that quantifies the complexity of abnormal behavior.
[0021] It should be noted that, firstly, the timestamps of all consecutive operations in the trajectory are extracted, arranged in chronological order, and the difference between two adjacent timestamps is calculated to obtain the specific value of each operation interval, forming an initial interval list. For example, the consecutive operation timestamps of user U1005 are 9:00:00, 9:01:30, 9:03:15, and 9:05:20, and the corresponding initial interval list is [90 seconds, 105 seconds, 125 seconds].
[0022] It's worth noting that the interval mean is the arithmetic mean of all intervals, the variance reflects the dispersion of the intervals, and the short interval percentage is the ratio of the number of short intervals to the total number of intervals. Short intervals refer to operation intervals shorter than a preset time interval threshold. The preset time interval threshold is set to 3 minutes, based on the platform's historical average operation interval of 10 minutes. This average is calculated by analyzing the operation intervals of over 100,000 normal transactions over the past year, and is one-third of the average normal interval, thus accurately filtering out excessively dense abnormal operation intervals. For example, with an interval mean of 5 minutes, a variance of 36, and a short interval percentage of 0.8, the constructed interval statistical feature vector is [5, 36, 0.8].
[0023] The preset transaction pattern templates include regular templates for individual users, regular templates for enterprise users, and high-frequency normal transaction templates. Each template is an interval statistical feature vector constructed based on a large amount of historical data of the corresponding user type. The pattern deviation threshold is set to 3.5, which was determined through testing with historical transaction data on the platform to ensure that the pattern deviation value corresponding to more than 95% of normal transaction behaviors does not exceed this threshold, while effectively identifying deviations from the templates in abnormal behaviors. Next, Z-score standardization is performed on the three dimensions of the interval statistical feature vector to eliminate the influence of differences in dimensions. Then, the Euclidean distance algorithm is used to calculate the distance between the interval statistical feature vector to be analyzed and each template. The distance value is the pattern deviation value. For example, the Euclidean distance between the interval statistical feature vector of user U1007 and the regular template for individual users is 4.2, and this value is the pattern deviation value.
[0024] It's worth noting that the recorded current behavioral characteristic data includes interval statistical feature vectors, pattern deviation values, continuous operation timestamp sequences, short interval proportions, and operation type sequences. These are categorized by user ID and stored in the user's historical behavior database, and then archived along with the user's normal behavior data from the past three months to form a complete user behavior profile. When updating the user's behavior trajectory, the operation nodes of the current normal behavior are added to the original behavior trajectory curve in timestamp order. The timestamp annotations of continuous nodes and operation frequency characteristics are integrated, allowing the trajectory curve to reflect the user's latest normal operating habits in real time. For example, user U1001's pattern deviation value is 2.8, lower than the preset deviation threshold of 3.5, and is determined to be a normal behavior pattern. The system records its interval statistical feature vector [6.2, 9.5, 0.15], pattern deviation value 2.8, and corresponding operation timestamp sequences. After being included in the user's historical behavior database, the current operation node is integrated into the original behavior trajectory, ensuring the trajectory curve continues its regular operation interval distribution pattern.
[0025] It should be noted that the statistical weights are set as follows: order modification 1.2, cancellation and re-creation 1.5, frequent switching of metal types 1.8, and other abnormal operations 1.0. This weight allocation is based on the risk level of different abnormal operations; the higher the risk, the greater the weight, which can accurately quantify the complexity of abnormal behavior. For example, the abnormal deviation nodes of user U1009 correspond to weights of 1.5, 1.8, and 1.2, respectively, with a preliminary abnormality index of 4.5.
[0026] In step S13, if the preliminary abnormal indicator exceeds a preset abnormal indicator judgment threshold, the environmental information sequence associated with the user behavior trajectory is extracted, and the corresponding transaction environment dynamic variables are integrated to form complete context information. Potential spoofing signals are detected by matching and filtering the context information with historical normal transaction data, including: Extract the environmental information sequence associated with the user behavior trajectory, and combine it with the behavior scenario corresponding to the preliminary anomaly indicator to generate basic context data; The dynamic variables of the transaction environment are integrated to supplement the basic context data, forming complete context information; The context information is matched with the environmental behavior data of historical normal transactions to filter abnormal association combinations and determine the potential set of disguise candidates. By fusing the potential spoofing candidate set with the geographic location parsing results from the location parsing of the transaction-related network address, and the operator affiliation information from the SIM card operator registration information or network service provider registration information of the transaction-related device, a supplementary context-aware vector is generated. Calculate the deviation value between the supplementary context-aware vector and the preset user profile for recycling transactions. If the deviation value exceeds the preset profile deviation threshold, it is determined that there is a potential spoofing signal. If it does not exceed the preset profile deviation threshold, it is determined that there is no potential spoofing signal.
[0027] It should be noted that the extracted environmental information sequence includes device identifiers, network addresses, login times, and operation periods used by the user during the operation process. These must be matched one-to-one with the operation nodes in the user's behavior trajectory in chronological order. The preliminary anomaly indicator threshold is set at 4.0. This threshold is based on preliminary indicator statistics from historical anomaly transactions. Preliminary indicator data from 300,000 normal transactions and 50,000 verified anomaly transactions over the past year were collected from the platform. KS tests verified that both types of data follow a normal distribution. The mean of the preliminary indicator for normal transactions is 2.2, and the standard deviation is 0.8. The mean of the preliminary indicator for anomaly transactions is 5.7, and the standard deviation is 1.1. The 95th percentile of the preliminary indicator for normal transactions, calculated using the normal distribution quantile formula, is 3.516. To cover more than 90% of anomaly transactions, the threshold is adjusted upwards to 4.0, ensuring that the false positive rate for normal transactions is controlled within 5%, and the coverage rate for anomaly transaction identification reaches over 92%, achieving a balance between risk identification accuracy and business impact. This effectively distinguishes between mildly active and highly abnormal behavioral patterns. For example, if user U1010's initial abnormal index is 4.8, which exceeds the threshold, environmental information such as device identifier and network address in this scenario is extracted to generate basic context data.
[0028] In addition, dynamic variables in the transaction environment include real-time changing environmental information such as device operating system version, browser type, network type, and device geolocation change records. These variables are added to the basic context data to improve the dimensions of environmental information. For example, the basic context data of user U1011 includes device identifier and network address. By adding dynamic variables such as device operating system version Android 13, network type 4G, and geolocation change records, a complete context information is formed.
[0029] It's important to note that the historical normal transaction environment behavior association data is based on an association database built from over 500,000 normal transactions over the past year on the platform. This database is stored categorized into four-tuples: device identifier, network address, carrier, and operation time period, recording the frequency and probability distribution of each combination. During matching, identical four-tuple information is extracted from the complete context information, and its probability of occurrence in the association database is queried. If the probability is less than 5%, the combination is considered an abnormal association combination. Simultaneously, the reasonableness of single-dimensional environmental information is matched, such as whether the device identifier is a user's historically frequently used device, whether the network address is within the user's frequently used geographical area, and whether the operation time period overlaps with the user's regular transaction time period. If any dimension does not match and there is no whitelist exemption record, the user is included in the potential spoofing candidate set. For example, in the context information of user U1001, the device identifier is device ID-B456, the network address is IP-172.16.2.2, the carrier is a small local carrier, and the operation time is 02:30. This combination has a probability of only 1.2% in the association database. In addition, device ID-B456 is not a commonly used device of the user, and the operation time of 02:30 deviates from its usual transaction time of 9:00-18:00. The relevant combination and corresponding dimension information are all included in the potential spoofing candidate set.
[0030] During the fusion process, the three types of data are first standardized to eliminate differences in units. Data in the potential spoofing candidate set is converted into binary features, with anomaly detection = 1 and no anomaly = 0. These features include six dimensions: device identification anomaly, network address anomaly, operation time period anomaly, operation behavior anomaly, and operator matching anomaly. The geographic location parsing results are converted into two dimensions: geographic location deviation and regional unfamiliarity. The geographic location deviation is calculated using the formula P1 = D / R, where D represents the straight-line distance between the current region and the user's registered region, and R represents the radius of the user's frequently used regions, ranging from 0 to 1. If D > R, then P1 = 1. Regional unfamiliarity is calculated as P2 = 1 / P, where P represents the probability of the current region appearing in the user's historical transactions, ranging from 0 to 1. If P = 0, then P2 = 1. Carrier attribution information is converted into two dimensions: carrier consistency and carrier risk level. Carrier consistency refers to the matching degree between the current carrier and the user's frequently used carriers, with a value of 0-1. Its quantitative calculation is based on the user's carrier usage data from the past year's transactions, statistically analyzing the frequency percentage of each carrier in the user's historical transactions. The carrier with the highest percentage (over 70%) is identified as the user's frequently used carrier. If the current carrier and the frequently used carrier are completely identical, the matching degree is 1.0; if the current carrier and the frequently used carrier belong to the same category of large carriers or small local carriers, the matching degree is 0.5; if the current carrier and the frequently used carrier belong to different categories and are unrelated, the matching degree is 0.0; if there is no clearly defined carrier with a percentage exceeding 70% in the user's historical transactions, the average of the matching degree between the current carrier and the two most frequently used carriers in the past is taken as the matching degree, with a risk level of 0.8 for small local carriers, 0.2 for large carriers, and 1.0 for unknown carriers.
[0031] Subsequently, considering the risk control characteristics of precious metal recycling transactions, weights were assigned based on the contribution of each dimension to the detection of spoofing signals. The weight of the potential spoofing binary feature was 0.3, as it directly reflects the anomalies in core environmental dimensions such as equipment and network, and is a key clue to spoofing behavior; the weight of geographical location deviation was 0.25, as cross-regional operations are a high-frequency scenario for spoofing anomalies, so distance deviation is directly related to the degree of risk; the weight of regional unfamiliarity was 0.2, because the risk probability of transactions in unfamiliar regions is significantly higher than in commonly used regions; the weight of operator consistency was 0.15, as user operator usage habits are stable, and inconsistencies are often accompanied by spoofing behavior; and the weight of operator risk level was 0.1, as risk control traceability is more difficult for small or unknown operators, and although the risk coefficient is slightly lower, it still needs to be considered. Then, the standardized values of all dimensions were multiplied by their corresponding weights and concatenated sequentially to generate a 10-dimensional supplementary context-aware vector. For example, the standardized data of user U1001 is a binary feature of potential spoofing [1,1,0,1,0,1], with a geographic location deviation of 0.9, a regional unfamiliarity of 0.85, an operator consistency of 0.1, and an operator risk level of 0.8. The supplemented context-aware vector after fusion is [0.3,0.3,0,0.3,0,0.3,0.225,0.17,0.015,0.08].
[0032] The geographic location resolution result is obtained by locating and resolving the network address associated with the transaction, accurate to the city level. Carrier affiliation information comes from the SIM card carrier registration information or network service provider registration information of the transaction-related device. The preset profile deviation threshold is set at 0.6, which is determined through testing with historical fake transaction data on the platform. The preset user profile for recycled transactions is constructed based on the user's historical transaction data over the past year, real-name authentication information, frequently used devices / networks / regions / carrier records, and regular operating periods, covering 10 dimensions corresponding to the supplementary context-aware vector. Each dimension is Z-score standardized to form a standard feature vector. Then, the cosine distance algorithm is used to calculate the similarity S between the supplementary context-aware vector and the user profile standard feature vector, with the similarity value ranging from 0 to 1. The deviation value D = 1 - S. If the deviation value exceeds the preset profile deviation threshold of 0.6, it indicates that the current user's environmental behavior differs significantly from their usual behavior. For example, if the similarity S between the supplementary context-aware vector of user U1001 and its own profile is 0.25, then D = 1 - 0.25 = 0.75, which exceeds the preset profile deviation threshold of 0.6, indicating the presence of a potential spoofing signal.
[0033] In step S14, the step of extracting multi-dimensional fusion features from the context information, the preliminary anomaly indicators, and the potential spoofing signals using a preset anomaly detection model, and performing anomaly detection and correlation calculation on the multi-dimensional fusion features to identify dynamic anomaly patterns includes: The device fingerprint stability, network address change frequency, geographical location drift distance, operator switching times, and spoofing signal strength are extracted and fused from the context information, the preliminary anomaly indicators, and the potential spoofing signals to construct a multi-dimensional fused feature set. Anomaly detection is performed on the multidimensional fused feature set using the isolated forest algorithm, anomaly score is calculated for each record, and anomaly score sequence is generated. The abnormal score sequence is compared point by point with a preset normal behavior benchmark distribution, and dynamic abnormal candidates whose abnormal scores exceed a preset score threshold are marked. The correlation coefficient of the dynamic anomaly candidates is calculated by sliding window. If the correlation coefficient is lower than the preset correlation threshold, it is determined that there is a change in dynamic anomaly mode, and the dynamic anomaly mode is obtained.
[0034] It should be noted that device fingerprint stability is calculated based on the consistency of information such as device identifier, operating system version, and browser type. First, each type of information is binary encoded. The device identifier is converted into a 64-bit fixed-length binary string according to its unique hardware identifier. The operating system version is generated as an 8-bit binary code according to the platform's preset system type mapping table. The browser type is generated as an 8-bit binary code based on encoding rules established according to mainstream browser categories. The hardware configuration extracts key parameter combinations of CPU model and memory capacity and converts them into a 32-bit binary string. The application installation list is based on the platform's commonly used application set; the presence of a corresponding application is marked as 1, and its absence as 0, generating a 64-bit binary vector. Then, cosine similarity is calculated. The formula for calculating the similarity of a single type of information is... ,in This is the encoding vector for the i-th type of information of the current device. Let be the encoding vector for the i-th type of information from historically frequently used devices. Then, the similarity of the five types of information is fused using equal weights. The final stability calculation formula is as follows: The value ranges from 0 to 1, with values closer to 1 indicating higher stability. For example, if the similarity of five types of information between user U1001's current device and historically frequently used devices is 0.9, 0.85, 0.92, 0.88, and 0.86 respectively, then the device fingerprint stability F = (0.9 + 0.85 + 0.92 + 0.88 + 0.86) × 0.2 = 0.882. Network address change frequency is the number of times a network address changes per unit of time. Geographic location drift distance is the straight-line distance between the current transaction's geographic location and the user's frequently used geographic locations. Carrier switching count is the number of times the carrier changes within the current transaction period. The strength of the spoofed signal is determined based on the deviation value D of the potential spoofed signal. The larger the deviation value, the higher the strength. The preset profile deviation threshold corresponding to this deviation value is 0.6. This threshold is set through statistical analysis of verified spoofed and normal transaction data collected from the platform over the past year. First, the supplementary context perception vectors and user profile deviation values of the two types of transactions are verified by KS test to ensure that they both follow a normal distribution. Then, the threshold is determined based on the 95th percentile of the deviation value of normal transactions, combined with business risk control targets, to ensure that the false positive rate of normal transactions is controlled within 5% while the coverage of spoofed signal identification reaches more than 92%. Two quantification intervals are divided with 0.6 as the critical value. In the low-risk interval, a proportional linear mapping method is used to ensure that the strength increases gradually. In the high-risk interval, the slope is increased to amplify the impact of the deviation value on the strength and achieve rapid upgrading. When the deviation D∈[0,0.6), the strength Ss=D×0.833; when the deviation value D∈[0.6,1.0], the strength Ss=0.5+(D 0.6)×1.25. This rule is based on a preset image deviation threshold of 0.6. When the deviation value is below the threshold, the intensity is low; when it exceeds the threshold, the intensity increases rapidly, matching the risk level distribution of the spoofing signal. For example, user U1001's deviation value D=0.75, and the spoofing signal intensity Ss=0.5+(0.75)×1.25. 0.6)×1.25=0.6875.
[0035] These five dimensions of features are all standardized to the 0-1 range to ensure consistency of units. Device fingerprint stability is directly calculated using the core information consistency calculation method to obtain a 0-1 value. Network address change frequency is calculated based on the number of changes within one hour, with 10 as the maximum threshold. If the actual number of changes exceeds 10, it is treated as 1. Geographic location drift distance is calculated based on 2000 kilometers as the maximum threshold. If the actual drift distance exceeds 2000 kilometers, it is treated as 1. Operator handover frequency is calculated based on the number of handovers within the current transaction period, with 5 as the maximum threshold. If the actual number of handovers exceeds 5, it is treated as 1. Spoofed signal strength is quantized based on the deviation value calculated in S13 according to the set interval mapping rules to obtain a 0-1 value. After standardizing the feature values, a multi-dimensional fusion feature set is formed. For example, the multi-dimensional fusion feature set for user U1015 is [0.3, 0.5, 0.4, 0.6, 0.85].
[0036] Anomaly scores are calculated using the average path length of samples within an isolated forest, using the following formula: Where Anom is the anomaly score, ranging from 0 to 1, with a higher degree of anomaly being closer to 1. Let x be the average path length of sample x across all isolated trees; The average path length of all samples in the isolated forest is used as a baseline value, and the calculation formula is as follows: H(n) is the nth harmonic number, approximately ln(n) + 0.5772. The isolated forest parameters are set to 100 isolated trees and 256 samples per tree. These parameters have been verified through 50 sets of parameter tests. This combination can achieve an anomaly detection accuracy of over 94% and keep the computation time within 100ms per batch, balancing detection accuracy and computational efficiency.
[0037] Subsequently, a preset score threshold was set to 0.7, which is the 95th percentile of the normal behavior baseline distribution. This means that the probability of a normal transaction's abnormal score exceeding this threshold is no more than 5%, accurately filtering out records with high anomaly risk. For example, with a preset score threshold of 0.7, there are 3 records in user U1017's abnormal score sequence that exceed this threshold, and these records are marked as dynamic anomaly candidates.
[0038] Finally, the sliding window length is set to 7 records, and the preset correlation threshold is set to 0.65. The dynamic anomaly candidate correlation coefficient is calculated using the Pearson correlation coefficient. The sliding window length is set to 7 records, and the window contains anomaly score sequences and corresponding time series. The time series needs to be standardized to the 0-1 range. The correlation coefficient is obtained by calculating the sum of the products of the deviations of each anomaly score within the window and its corresponding time series value, and then dividing by the product of the square root of the sum of the squares of the anomaly score deviations and the square root of the sum of the squares of the time series deviations. The correlation coefficient ranges from -1 to 1; the closer it is to 0, the less significant the correlation between the anomaly score and time, indicating a sudden change in the anomaly pattern. This window length can cover a complete anomaly operation cycle, while the correlation threshold can effectively distinguish between gradual changes and sudden anomalies. For example, the dynamic anomaly candidate correlation coefficient for user U1018 is 0.42, which is lower than the preset correlation threshold of 0.65, indicating a dynamic anomaly pattern change and forming a corresponding dynamic anomaly pattern.
[0039] In step S15, if no potential spoofing signal is detected, the anomaly intensity, duration, and frequency of occurrence are extracted from the preliminary anomaly indicators. Combined with the environmental stability parameters in the context information, a regular anomaly analysis vector is generated and matched with a preset template library to determine the regular anomaly pattern, including: Extract the anomaly intensity, anomaly duration, and anomaly occurrence frequency from the preliminary anomaly indicators to construct the core anomaly feature vector; Environmental stability parameters are extracted from the context information, including network address stability, device usage consistency, and the rationality of the operation period. By fusing the core anomaly feature vector with the environmental stability parameters, a conventional anomaly analysis vector is generated. The regular anomaly analysis vector is matched with a preset regular anomaly template library for similarity. If the similarity matching result exceeds a preset matching threshold, the regular anomaly pattern is determined according to the corresponding template type.
[0040] It should be noted that the anomaly intensity is the result of numerical standardization of the preliminary anomaly indicators. The Min-Max standardization method is used, with the minimum value of the platform's historical preliminary anomaly indicators as the lower limit and the maximum value as the upper limit, linearly mapping the original indicator values to the 0-1 range. Anomaly duration is the time from the first occurrence of the abnormal behavior to the current moment. Anomaly frequency is the number of times the abnormal behavior occurs per unit time. These three dimensions of feature values are combined to form the core anomaly feature vector. For example, the core anomaly feature vector for user U1019 is [0.65, 45 minutes, 3 times / hour].
[0041] Among the environmental stability parameters, network address stability is the ratio of the number of times the network address remains unchanged to the total number of times within the current transaction cycle. Device usage consistency is the degree of matching between the currently used device and the user's frequently used devices, obtained by calculating the cosine similarity between the current device fingerprint and the fingerprints of the user's frequently used devices over the past 3 months. Operation time period rationality is the degree of overlap between the current operation time period and the user's regular operation time period, calculated by counting the number of minutes that overlap between the current operation duration and the user's high-frequency operation time periods over the past 3 months, and then dividing by the total duration of the current operation to obtain the overlap ratio. The values of the three parameters range from 0 to 1, with values closer to 1 indicating higher stability. For example, the environmental stability parameters for user U1020 are [0.85, 0.92, 0.78].
[0042] Next, the three dimensions of the core anomaly feature vector and the three dimensions of the environmental stability parameters are concatenated sequentially to form a six-dimensional conventional anomaly analysis vector. The values of each dimension are standardized using the Min-Max method. For each dimension of the core anomaly feature vector and the environmental stability parameters, a linear mapping is performed with the minimum value of similar historical data from the platform as the lower bound and the maximum value as the upper bound, standardizing it to the range of 0 to 1. This ensures that the numerical range of each dimension is uniform and does not change the relative distribution characteristics of the data. For example, the conventional anomaly analysis vector for user U1021 is [0.65, 0.72, 0.58, 0.85, 0.92, 0.78].
[0043] Finally, when matching the regular anomaly analysis vector with a preset regular anomaly template library, the preset matching threshold is set to 0.75. This threshold is based on the feature similarity distribution of regular anomaly templates and can effectively match similar regular anomaly patterns. The preset regular anomaly template library contains standard feature vectors for various typical regular anomaly scenarios. Each template corresponds to a unique regular anomaly pattern type, specifically including erroneous operation templates, temporary high-frequency operation templates, time-period anomaly templates, and low-risk deviation templates. The standard feature vectors are obtained by collecting regular anomaly transaction data verified by the platform over the past year, classifying them according to anomaly pattern type, performing cluster analysis, extracting the statistical mean and distribution characteristics of each type of anomaly data in each dimension, and standardizing them to form the standard feature vectors of the corresponding templates, ensuring that each template can accurately represent the core features of similar regular anomalies. During matching, the cosine similarity between the regular anomaly analysis vector and all templates in the template library is calculated. The template with the highest similarity and exceeding the preset matching threshold is selected as the optimal matching template, and the anomaly pattern type corresponding to this template is directly determined as the regular anomaly pattern of the current transaction. For example, the similarity between user U1022's regular anomaly analysis vector and the temporary high-frequency operation template is 0.82, which is the highest among all templates and exceeds the preset matching threshold of 0.75. Therefore, the regular anomaly pattern is determined to be the temporary high-frequency operation pattern. If a user's regular anomaly analysis vector and the erroneous operation template have a similarity of 0.78, which is the optimal matching result and exceeds the threshold, then their regular anomaly pattern is determined to be the erroneous operation pattern.
[0044] In step S16, based on the dynamic anomaly mode or the conventional anomaly mode, the time window width of the order confirmation process and the consistency metric of operational behavior are extracted as control parameters, and a judgment vector for interception conditions is generated by fusing them, including: Based on the dynamic anomaly pattern or the conventional anomaly pattern, determine the order confirmation step; Extract the time interval from when the user initiates an order to when it is finally confirmed from the order confirmation process, and use this time interval as the width of the time window; The user behavior trajectory is compared with the user's historical normal transaction behavior template from the user's historical transaction database and the platform's general normal transaction behavior template constructed from the platform's massive normal transaction data statistics. The behavior matching degree of the two comparisons is calculated and weighted and fused to obtain the operation behavior consistency measure. The time window width and the consistency metric of the operation behavior are fused to generate a judgment vector for the interception condition.
[0045] It's important to clarify that, firstly, the order confirmation process refers to the entire process from when a user initiates an order request to when it is finally confirmed and withdrawn. Based on the behavioral scenarios corresponding to either dynamic or regular anomaly modes, the timeframe for this process is precisely defined, clarifying the start and end times of the order confirmation phase. For example, the behavioral scenario corresponding to the dynamic anomaly mode is frequent order modifications followed by confirmation and withdrawal; therefore, the order confirmation phase is defined as the time period from the last order modification to the confirmation and withdrawal.
[0046] Next, the difference between the start and end times of the order confirmation process is calculated to obtain the total time interval for the user to complete order confirmation. This interval is the time window width. For example, the time interval from user U1023 initiating an order to final confirmation is 3.5 minutes, so the corresponding time window width is 3.5 minutes.
[0047] It should be noted that the consistency comparison employs a dynamic time warping algorithm. The user's historical normal transaction behavior template is constructed by extracting behavioral trajectory features from the user's historical normal transaction data over the past 3 months. The platform's general normal transaction behavior template is constructed by extracting the mean and distribution patterns of core behavioral trajectory features from the statistical analysis of massive normal transaction data from the platform over the past year. The behavior matching degree is obtained by calculating the dynamic time warping distance between the user's behavior trajectory and the corresponding template and mapping it to the interval between 0 and 1. The specific calculation process is as follows: First, the user's behavior trajectory and the corresponding template are respectively converted into time series vectors of equal dimensions. Each vector dimension corresponds to key features in the behavior trajectory, including operation interval, operation type encoding, and operation frequency. Then, an element-level Euclidean distance matrix is constructed between the two sequences. Based on the dynamic programming algorithm, the optimal time alignment path that minimizes the cumulative distance is found. The total dynamic time warping distance is obtained by accumulating the distances of all elements on the path. When mapping to the 0 to 1 range, the maximum value of the total dynamic time warp distance calculated from the platform's historical transactions over the past year is used as the benchmark. The current total distance is divided by this benchmark to obtain the normalized distance. Then, the behavior matching degree is obtained by subtracting the normalized distance from 1. This ensures that the smaller the total dynamic time warp distance, the closer the behavior matching degree is to 1, and the larger the total distance, the closer the behavior matching degree is to 0. The closer the value is to 1, the higher the consistency. The two comparisons are used to obtain the user's historical behavior matching degree and the platform's general behavior matching degree, respectively.
[0048] Then, when weighting and merging the behavioral matching scores of the two comparisons, the weights are set to 0.6 for the user's historical template and 0.4 for the platform's general template. This weight allocation is based on the importance of the specificity of individual user behavior and the general behavioral patterns of the platform, which can more accurately reflect the consistency of user behavior. For example, the matching score of user U1024 with the user's historical normal transaction behavior template is 0.55, and the matching score with the platform's general normal transaction behavior template is 0.62. The consistency measure of the operational behavior is 0.55×0.6+0.62×0.4=0.578.
[0049] Finally, the time window width is standardized, converting it into a value between 0 and 1. This value is then combined sequentially with the operational behavior consistency metric to form a two-dimensional interception condition judgment vector. The standardization process uses the Min-Max standardization method, with the minimum value of the platform's historical time window width as the lower limit and the maximum value as the upper limit, linearly mapping the original time window width value to the 0-1 range. For example, user U1025's standardized time window width is 0.32, and the operational behavior consistency metric is 0.578, resulting in a judgment vector of [0.32, 0.578].
[0050] In step S17, the step of determining whether the abnormal interception trigger condition is met based on the judgment vector; if the abnormal interception trigger condition is met, a real-time response mechanism is activated to block risky transactions and the blocking effect is evaluated; if the abnormal interception trigger condition is not met, the transaction is marked as proceeding normally and transaction data feedback is recorded, including: Calculate the comprehensive deviation score of the judgment vector. If the comprehensive deviation score is higher than the preset interception trigger threshold, it is determined that the abnormal interception trigger condition is met; otherwise, it is determined that the abnormal interception trigger condition is not met. If the abnormal interception triggering condition is met, a blocking signal is sent to the transaction processing system to freeze the execution process of the current risky transaction and obtain a complete snapshot of the order status and associated session records; The status snapshot is compared with the historical normal order trajectory to identify the characteristics of risk spread and evaluate the blocking effect. If the abnormal interception triggering condition is not met, the transaction is marked as a normal flow state, the transaction data feedback is recorded and included in the historical transaction database, wherein the transaction data feedback includes: transaction behavior data, abnormal detection analysis results and user behavior trajectory.
[0051] It should be noted that the formula for calculating the comprehensive deviation score is S=W×0.4+(1 C)×0.6, where S represents the comprehensive deviation score, ranging from 0 to 1, with a larger value indicating higher trading risk; W represents the standardized value of the time window width, reflecting the duration of abnormal behavior; and C represents the consistency measure of operational behavior, reflecting the degree of fit between the current operation and the normal behavior template. The parameter weighting principle is based on the core logic of risk assessment. The consistency of operational behavior is the core basis for distinguishing between normal and abnormal transactions, and its impact on risk assessment has a higher weight. Therefore, (1-C) is assigned a weight of 0.6. The time window width reflects the persistence of abnormal behavior; the longer the duration, the higher the risk accumulation. Therefore, W is assigned a weight of 0.4. S and W have a positive linear relationship because the larger the standardized value of the time window width, the longer the duration of abnormal behavior and the higher the degree of risk exposure, and the corresponding comprehensive deviation score should increase accordingly. S and C have an inverse linear relationship because the larger the consistency measure C of operational behavior, the higher the degree of fit between the current operation and the normal behavior template, and the lower the risk. By converting the consistency indicator into a risk-related indicator through (1-C), the value of (1-C) is larger when the risk is higher, thereby promoting the increase of the comprehensive deviation score S and realizing the accurate quantitative mapping of the degree of risk.
[0052] The preset interception trigger threshold was set at 0.7. This threshold was set using statistical quantiles combined with business risk control objectives. First, the platform collected comprehensive deviation scores from 100,000 verified risky transactions and 300,000 normal transactions over the past year. KS tests verified that the comprehensive deviation scores of both types of data followed a normal distribution. Then, the 95th percentile of the comprehensive deviation score for normal transactions and the 5th percentile of the comprehensive deviation score for risky transactions were calculated, and the median of these two quantiles was used as the initial threshold. Multiple threshold tests were then conducted to verify and adjust the initial threshold to ensure that the false positive rate for normal transactions was controlled within 3%, while the identification coverage rate for risky transactions reached over 95%. The final determined threshold balanced risk identification accuracy with business operational efficiency, accurately distinguishing between high-risk and low-risk transactions. For example, user U1026 has W=0.32 and C=0.578. Substituting these values into the formula, we get S=0.32×0.4+(1-0.578)×0.6=0.3812, which is lower than the preset interception trigger threshold of 0.7. Therefore, the abnormal interception trigger condition is determined to be invalid. For user U1027, W=0.85 and C=0.32, we get S=0.85×0.4+(1-0.32)×0.6=0.748, which is higher than the preset interception trigger threshold of 0.7. Therefore, the abnormal interception trigger condition is determined to be valid.
[0053] If the abnormal interception trigger condition is met, a blocking signal is sent to the transaction processing system. This blocking signal is transmitted in encrypted form to ensure the security of signal transmission, thereby freezing the execution process of the current risky transaction and obtaining a complete snapshot of the order status and associated session records. The complete snapshot of the order status includes all core information such as order amount, metal type, weight, transaction status, and operation records, while the associated session records cover interactive data such as user login information, device information, and network information.
[0054] Subsequently, the status snapshot is compared with historical normal order trajectories. First, core dimensional information is extracted from the status snapshot, including key features such as order amount, metal type and weight, operation process nodes, order modification frequency, confirmation duration, associated device identifier, network address, and carrier affiliation. Simultaneously, normal order samples of the same type, amount range, and user level as the current order are selected from historical normal order trajectories to construct a normal order feature benchmark library. Then, the features of each dimension of the two types of data are standardized to eliminate dimensional differences. A cosine similarity algorithm is used to calculate the overall matching degree between the status snapshot and the normal order feature benchmark library, while deviations are compared dimensionally.
[0055] A single-dimensional deviation threshold of 20% is set. This threshold is based on statistical data of deviations in various dimensions of normal and abnormal orders over the past year. The deviation distribution of each dimension of normal orders is calculated, and the 95th percentile (18%) is taken. This threshold is then adjusted upwards to 20% to reduce mislabeling of normal order dimensions and accurately capture abnormal deviations. If the deviation of a certain dimension exceeds this threshold, it is marked as a discrepancy. The threshold for the number of discrepancy items is set to 3. This threshold is based on common discrepancies between normal and abnormal orders. If the number of discrepancies exceeds this threshold, it indicates a high probability of risk spread. Finally, the number, type, and magnitude of discrepancies are statistically analyzed. The types of discrepancies are categorized as core information discrepancies, operational process discrepancies, and environmental correlation discrepancies. Based on the statistical results of discrepancies, risk spread characteristics are analyzed. If the number of discrepancies exceeds 3 or the proportion of core information discrepancies exceeds 30%, it is judged as a high probability of risk spread. If the number of discrepancies is ≤1 and there are no core information discrepancies, it is judged as a weak risk spread characteristic.
[0056] The effectiveness of blocking is assessed based on the aforementioned risk diffusion characteristics. The assessment focuses on the suppression of abnormal behavior, the degree of improvement in risk diffusion characteristics, and the compliance of user operations. Specific assessment dimensions include whether abnormal behavior immediately ceases after blocking, whether risk diffusion characteristics are suppressed or eliminated, whether similar abnormal behavior and risk diffusion reappear within the subsequent preset observation period, and whether user operations return to the platform's normal transaction process. Based on the comprehensive performance of the above dimensions, the blocking effect is quantified into four levels: Level 1 (Complete Blocking): Abnormal behavior immediately ceases, risk diffusion characteristics are completely eliminated, there is no recurrence during the observation period, and operations are fully compliant; Level 2 (Effective Blocking): Abnormal behavior ceases, key risk diffusion characteristics such as core information discrepancies are significantly alleviated, there is no recurrence of similar abnormalities during the observation period, only one minor compliance deviation occurs, and overall operations are compliant; Level 3 (Partial Blocking): The frequency of abnormal behavior decreases by more than 50% but is not completely stopped, risk diffusion characteristics are partially alleviated, and a small number of non-compliant operations exist; Level 4 (Ineffective Blocking): Abnormal behavior is not suppressed or the recurrence frequency exceeds that before blocking, and risk diffusion characteristics are not improved or even aggravated.
[0057] For example, after user U1028's transaction triggered an anomaly interception, the system immediately froze its order execution process, obtained a snapshot of the order status and the corresponding session records, and found four discrepancies through difference matching, with core information differences accounting for 35%, indicating a high probability of risk spread. The abnormal behavior immediately ceased after the blocking was implemented, and there was no recurrence during the observation period. The risk spread characteristics were completely eliminated, and the final assessment was a Level 1 complete blockade, providing complete data support for subsequent risk management.
[0058] When the abnormal interception trigger condition is not met, the recorded transaction data feedback includes transaction behavior data, abnormal detection analysis results, and user behavior trajectory. This data will serve as an important basis for subsequent model optimization and threshold adjustment, and continuously improve the abnormal detection system.
[0059] In step S18, optimizing the analysis parameters of the behavioral pattern analysis and the anomaly detection model based on the blocking effect or the transaction data feedback to form a continuous security protection mechanism includes: Integrate the blocking effect or the transaction data feedback to form a feedback difference set; Based on the feedback difference set, the offset amplitude in the preset deviation threshold in the behavior pattern analysis is calculated. If the offset amplitude exceeds the preset adjustment threshold, the preset deviation threshold is optimized and adjusted according to the offset amplitude to obtain an optimized threshold set. Based on the optimized threshold set, the feature weights and decision boundaries of the anomaly detection model are updated using gradient descent. The updated anomaly detection model is applied to the transaction protection process. Transaction data is continuously collected to verify the optimization effect, and model parameters are iteratively adjusted to form a continuous security protection mechanism.
[0060] It should be noted that, firstly, the blocking effect is quantitatively graded into four levels: "Complete Blocking," "Effective Blocking," "Partial Blocking," and "Ineffective Blocking," corresponding to quantitative values of 1.0, 0.7, 0.3, and 0.0, respectively. A higher quantitative value indicates a better blocking effect. "Complete Blocking" corresponds to immediate termination of abnormal behavior, complete elimination of risk diffusion characteristics, no recurrence during the observation period, and complete compliance with regulations. "Effective Blocking" corresponds to termination of abnormal behavior, significant mitigation of key risk diffusion characteristics such as core information discrepancies, no recurrence of similar abnormalities during the observation period, only one minor compliance deviation, and overall compliance with regulations. "Partial Blocking" corresponds to a reduction of more than 50% in the frequency of abnormal behavior but not complete termination, partial mitigation of risk diffusion characteristics, and a small number of non-compliant operations. "Ineffective Blocking" corresponds to abnormal behavior not being suppressed or recurrence frequency exceeding that before blocking, with no improvement or even exacerbation of risk diffusion characteristics. Transaction data feedback includes transaction behavior data, anomaly detection analysis results, and user behavior trajectories, from which key indicators are extracted, including anomaly detection accuracy, false negative rate, false positive rate, and the trigger frequency of each threshold. The quantified value of the blocking effect is correlated and compared with key indicators in the transaction data feedback to identify dimensions where the actual results deviate from the expected targets, forming a feedback difference set. For example, in a certain batch of transactions, the false judgment rate corresponding to the preset deviation threshold of 3.5 is 5%, exceeding the expected target of 3%. This deviation dimension and related data are included in the feedback difference set.
[0061] The core of calculating the offset amplitude in the preset deviation threshold mentioned in the behavioral pattern analysis is to quantify the degree of deviation of the current user behavior pattern from the historical normal behavior pattern, providing data support for the dynamic adjustment of the preset deviation threshold. Specifically, the calculation method is based on the comprehensive deviation score, behavioral matching degree, and other core indicators obtained in S17, combined with the duration and frequency of the current abnormal pattern, and uses a weighted summation method to calculate the offset amplitude. The formula for calculating the offset amplitude is A = S × 0.5 + (1 C)×0.3+T×0.2, where A represents the offset magnitude, ranging from 0 to 1; S represents the comprehensive deviation score obtained in S17; C represents the behavioral matching degree obtained in S16; and T represents the standardized value of the duration of the abnormality. Each weight is set according to the contribution of the corresponding indicator to the degree of behavioral pattern deviation. The larger the value, the more significant the deviation of the current behavioral pattern from the historical normal pattern, and the greater the adjustment range of the corresponding preset deviation threshold.
[0062] Next, the preset adjustment threshold is set to 10% of the original threshold. This threshold is set based on the stability requirement of parameter optimization to avoid fluctuations in detection results due to sudden threshold changes. If the offset exceeds the preset adjustment threshold, the preset deviation threshold is optimized and adjusted according to the offset; if it does not exceed the threshold, the original threshold remains unchanged. For example, if the original preset deviation threshold is 3.5, and the calculated offset A = 0.42, which exceeds the preset adjustment threshold by 0.35, the optimized threshold is 2.03, forming an optimized threshold set.
[0063] Subsequently, the gradient descent parameters were set to a learning rate of 0.01 and 100 iterations. This parameter combination ensures model convergence while avoiding overfitting. Using the optimized threshold set as a constraint, a model loss function was constructed, which is the sum of squared deviations between the predicted results and the actual feedback. ,in For actual feedback results, The model prediction results are presented. When iteratively optimizing model parameters using the gradient descent algorithm, the weights of features such as device fingerprint stability and network address change frequency are adjusted in each iteration based on the gradient direction of the loss function, while simultaneously optimizing the model's decision boundary. For example, through iterative optimization, the feature weight for geographical location drift distance is increased from 0.2 to 0.35, while the weight for device fingerprint stability is decreased from 0.3 to 0.18, enabling the model to more accurately identify cross-regional spoofing anomalies.
[0064] Finally, the optimization effect verification thresholds are set as follows: accuracy ≥ 95%, false negative rate ≤ 3%, and false positive rate ≤ 2%. This threshold combination is based on the high standards required for industry risk control. After the new model goes live, transaction data is collected in real time, and the anomaly detection accuracy, false negative rate, and false positive rate are calculated daily. If the optimization effect verification thresholds are met for three consecutive days, the optimization effect is considered successful, and the current model parameters are maintained. If the thresholds are not met, the model parameters and analysis parameters are adjusted based on new transaction data feedback, such as further lowering the preset deviation threshold or adjusting the feature weight allocation. Through the cyclical operation of continuously collecting transaction data, analyzing feedback differences, optimizing model parameters, and verifying the protection effect, the anomaly detection capability is ensured to continuously adapt to the dynamic changes in the transaction scenario, maintaining a high level of accurate risk control in the long term.
[0065] In summary, this invention discloses a method for detecting anomalies in precious metal recycling, including collecting transaction data to construct user behavior trajectories, quantifying anomaly indicators, detecting potential spoofing signals, identifying anomaly patterns, determining interception conditions, executing real-time blocking, and optimizing model parameters. This invention achieves accurate identification and timely risk control of dynamically spoofed anomalies in precious metal recycling transactions by integrating multi-dimensional behavioral and environmental data, dynamically identifying anomaly patterns, and intercepting them in real-time at key nodes. Combined with a feedback loop for continuous model optimization, this significantly improves the intelligence and security of transaction risk control by enabling timely prevention and control of dynamic spoofing anomalies in precious metal recycling transactions.
[0066] Reference Figure 2 The second embodiment of the present invention provides a precious metal recycling anomaly detection system, comprising: The data acquisition module is used to collect user operation data and order association information in precious metal recycling transactions, extract behavioral features over time, and construct user behavior trajectories. The behavior analysis module is used to perform behavior pattern analysis based on the user's behavior trajectory, quantify the complexity of abnormal behavior, and obtain preliminary abnormal indicators. The spoofing detection module is used to extract the environmental information sequence associated with the user behavior trajectory if the preliminary abnormal indicators exceed the preset abnormal indicator judgment threshold, integrate the corresponding transaction environment dynamic variables to form complete context information, and detect potential spoofing signals by matching and filtering the context information with historical normal transaction data. The dynamic anomaly identification module is used to extract multi-dimensional fusion features from the context information, the preliminary anomaly indicators and the potential spoofing signal through a preset anomaly detection model if the potential spoofing signal is detected, and to perform anomaly detection and correlation calculation on the multi-dimensional fusion features to identify dynamic anomaly patterns. The routine anomaly determination module is used to extract the anomaly intensity, duration and frequency of occurrence from the preliminary anomaly indicators if no potential spoofing signal is detected, combine it with the environmental stability parameters in the context information, generate a routine anomaly analysis vector and match it with a preset template library to determine the routine anomaly pattern. The interception condition determination module is used to extract the time window width and the consistency metric of operation behavior in the order confirmation process as control parameters based on the dynamic abnormal mode or the regular abnormal mode, and fuse them to generate an interception condition judgment vector. If the comprehensive deviation score of the judgment vector is higher than the preset interception trigger threshold, the triggering condition for abnormal interception is determined to be met. The transaction processing module is used to determine whether the abnormal interception trigger condition is met based on the judgment vector. If the abnormal interception trigger condition is met, the real-time response mechanism is activated to block risky transactions and evaluate the blocking effect. If the abnormal interception trigger condition is not met, the transaction is marked as proceeding normally and transaction data feedback is recorded. The model optimization module is used to optimize the analysis parameters of the behavior pattern analysis and the anomaly detection model based on the blocking effect or the transaction data feedback, so as to form a continuous security protection mechanism.
[0067] It should be noted that the precious metal recycling anomaly detection system provided in this embodiment of the invention is used to execute all the process steps of the precious metal recycling anomaly detection method in the above embodiment. The working principles and beneficial effects of the two are one-to-one, so they will not be described again.
[0068] It should be noted that the system embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Furthermore, in the accompanying drawings of the system embodiments provided by this invention, the connection relationships between modules indicate that they have communication connections, which can be specifically implemented as one or more communication buses or signal lines. Those skilled in the art can understand and implement this without any creative effort.
[0069] The specific embodiments described above further illustrate the purpose, technical solution, and beneficial effects of the present invention. It should be understood that the above descriptions are merely specific embodiments of the present invention and are not intended to limit the scope of protection of the present invention. In particular, it should be noted that any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention for those skilled in the art.
Claims
1. A method for detecting anomalies in precious metal recycling, characterized in that, include: Collect user operation data and order association information in precious metal recycling transactions, extract behavioral features over time, and construct user behavior trajectories; Based on the user behavior trajectory, behavioral pattern analysis is performed to quantify the complexity of abnormal behavior and obtain preliminary abnormal indicators. If the preliminary abnormal indicators exceed the preset abnormal indicator judgment threshold, the environmental information sequence associated with the user behavior trajectory is extracted, and the corresponding transaction environment dynamic variables are integrated to form complete context information. Potential spoofing signals are detected by matching and filtering the context information with historical normal transaction data. If the potential spoofing signal is detected, a multi-dimensional fusion feature is extracted from the context information, the preliminary anomaly index and the potential spoofing signal using a preset anomaly detection model. Anomaly detection and correlation calculation are performed on the multi-dimensional fusion feature to identify dynamic anomaly patterns. If no potential spoofing signal is detected, the abnormal intensity, duration and frequency of occurrence are extracted from the preliminary abnormality indicators. Combined with the environmental stability parameters in the context information, a regular abnormality analysis vector is generated and matched with a preset template library to determine the regular abnormality pattern. Based on the dynamic anomaly mode or the conventional anomaly mode, the time window width and the consistency metric of the operation behavior in the order confirmation process are extracted as control parameters and fused to generate a judgment vector for the interception conditions. The judgment vector determines whether the abnormal interception trigger condition is met. If the abnormal interception trigger condition is met, the real-time response mechanism is activated to block risky transactions and the blocking effect is evaluated. If the abnormal interception trigger condition is not met, the transaction is marked as proceeding normally and transaction data feedback is recorded. Based on the blocking effect or the transaction data feedback, the analysis parameters of the behavior pattern analysis and the anomaly detection model are optimized to form a continuous security protection mechanism.
2. The method for detecting anomalies in precious metal recycling according to claim 1, characterized in that, The process involves collecting user operation data and order association information from precious metal recycling transactions, extracting behavioral features over time, and constructing user behavior trajectories, including: The system obtains user operation data and order association information from the precious metal recycling trading platform, and associates operation type, order status and timestamp by user ID to obtain initial behavior sequence data. Extract the time interval features from the initial behavior sequence data, mark high-frequency change operations and count the change frequency to form a frequency feature vector; Based on the frequency feature vector, the distribution pattern of continuous operation intervals is analyzed, abnormal change nodes are screened and clustered to obtain a sequence of behavior change nodes. A trajectory curve is constructed based on the sequence of behavioral change nodes, and the timestamps of continuous nodes are merged to form a user behavior trajectory.
3. The method for detecting anomalies in precious metal recycling according to claim 1, characterized in that, The behavioral pattern analysis based on the user's behavior trajectory, quantifying the complexity of abnormal behavior, and obtaining preliminary anomaly indicators include: Extract a sequence of consecutive operation timestamps from the user's behavior trajectory, calculate the time interval between adjacent operations, and form an initial interval list; Based on the initial interval list, the interval mean, variance, and proportion of short intervals are calculated to construct an interval statistical feature vector; wherein the short interval is an operation interval that is less than a preset time interval threshold set based on the statistical mean of operation intervals of historical normal transactions on the platform. The interval statistical feature vector is compared with the preset recycling transaction pattern template to calculate the pattern deviation value; If the pattern deviation value does not exceed the preset deviation threshold, it is determined to be a normal behavior pattern, the current behavior feature data is recorded and included in the user's historical behavior database, and the user's behavior trajectory is updated. If the pattern deviation value exceeds the preset deviation threshold, abnormal deviation nodes are marked and assigned statistical weights. The statistical weights are then fused to obtain a preliminary abnormality index that quantifies the complexity of abnormal behavior.
4. The method for detecting anomalies in precious metal recycling according to claim 1, characterized in that, If the preliminary anomaly indicator exceeds a preset anomaly indicator judgment threshold, then the environmental information sequence associated with the user behavior trajectory is extracted, and the corresponding dynamic variables of the transaction environment are integrated to form complete context information. Potential spoofing signals are detected by matching and filtering the context information with historical normal transaction data, including: Extract the environmental information sequence associated with the user behavior trajectory, and combine it with the behavior scenario corresponding to the preliminary anomaly indicator to generate basic context data; The dynamic variables of the transaction environment are integrated to supplement the basic context data, forming complete context information; The context information is matched with the environmental behavior data of historical normal transactions to filter abnormal association combinations and determine the potential set of disguise candidates. By fusing the potential spoofing candidate set with the geographic location parsing results from the location parsing of the transaction-related network address, and the operator affiliation information from the SIM card operator registration information or network service provider registration information of the transaction-related device, a supplementary context-aware vector is generated. Calculate the deviation value between the supplementary context-aware vector and the preset user profile for recycling transactions. If the deviation value exceeds the preset profile deviation threshold, it is determined that there is a potential spoofing signal. If it does not exceed the preset profile deviation threshold, it is determined that there is no potential spoofing signal.
5. The method for detecting anomalies in precious metal recycling according to claim 1, characterized in that, The step involves extracting multi-dimensional fusion features from the context information, the preliminary anomaly indicators, and the potential spoofing signals using a preset anomaly detection model, performing anomaly detection and correlation calculation on the multi-dimensional fusion features, and identifying dynamic anomaly patterns, including: The device fingerprint stability, network address change frequency, geographical location drift distance, operator switching times, and spoofing signal strength are extracted and fused from the context information, the preliminary anomaly indicators, and the potential spoofing signals to construct a multi-dimensional fused feature set. Anomaly detection is performed on the multidimensional fused feature set using the isolated forest algorithm, anomaly score is calculated for each record, and anomaly score sequence is generated. The abnormal score sequence is compared point by point with a preset normal behavior benchmark distribution, and dynamic abnormal candidates whose abnormal scores exceed a preset score threshold are marked. The correlation coefficient of the dynamic anomaly candidates is calculated by sliding window. If the correlation coefficient is lower than the preset correlation threshold, it is determined that there is a change in dynamic anomaly mode, and the dynamic anomaly mode is obtained.
6. The method for detecting anomalies in precious metal recycling according to claim 1, characterized in that, If no potential spoofing signal is detected, the anomaly intensity, duration, and frequency are extracted from the preliminary anomaly indicators. Combined with the environmental stability parameters in the context information, a regular anomaly analysis vector is generated and matched with a preset template library to determine the regular anomaly pattern, including: Extract the anomaly intensity, anomaly duration, and anomaly occurrence frequency from the preliminary anomaly indicators to construct the core anomaly feature vector; Environmental stability parameters are extracted from the context information, including network address stability, device usage consistency, and the rationality of the operation period. By fusing the core anomaly feature vector with the environmental stability parameters, a conventional anomaly analysis vector is generated. The regular anomaly analysis vector is matched with a preset regular anomaly template library for similarity. If the similarity matching result exceeds a preset matching threshold, the regular anomaly pattern is determined according to the corresponding template type.
7. The method for detecting anomalies in precious metal recycling according to claim 1, characterized in that, Based on the dynamic anomaly pattern or the conventional anomaly pattern, the time window width and operational behavior consistency metric of the order confirmation process are extracted as control parameters, and a judgment vector for interception conditions is generated by fusing them, including: Based on the dynamic anomaly pattern or the conventional anomaly pattern, determine the order confirmation step; Extract the time interval from when the user initiates an order to when it is finally confirmed from the order confirmation process, and use this time interval as the width of the time window; The user behavior trajectory is compared with the user's historical normal transaction behavior template from the user's historical transaction database and the platform's general normal transaction behavior template constructed from the platform's massive normal transaction data statistics. The behavior matching degree of the two comparisons is calculated and weighted and fused to obtain the operation behavior consistency measure. The time window width and the consistency metric of the operation behavior are fused to generate a judgment vector for the interception condition.
8. The method for detecting anomalies in precious metal recycling according to claim 1, characterized in that, The process involves determining whether the abnormal interception trigger condition is met based on the judgment vector. If the abnormal interception trigger condition is met, a real-time response mechanism is activated to block risky transactions and assess the blocking effect. If the abnormal interception trigger condition is not met, the transaction is marked as proceeding normally and transaction data feedback is recorded, including: Calculate the comprehensive deviation score of the judgment vector. If the comprehensive deviation score is higher than the preset interception trigger threshold, it is determined that the abnormal interception trigger condition is met; otherwise, it is determined that the abnormal interception trigger condition is not met. If the abnormal interception triggering condition is met, a blocking signal is sent to the transaction processing system to freeze the execution process of the current risky transaction and obtain a complete snapshot of the order status and associated session records; The status snapshot is compared with the historical normal order trajectory to identify the characteristics of risk spread and evaluate the blocking effect. If the abnormal interception triggering condition is not met, the transaction is marked as a normal flow state, the transaction data feedback is recorded and included in the historical transaction database, wherein the transaction data feedback includes: transaction behavior data, abnormal detection analysis results and user behavior trajectory.
9. The method for detecting anomalies in precious metal recycling according to claim 3, characterized in that, The step of optimizing the analysis parameters of the behavioral pattern analysis and the anomaly detection model based on the blocking effect or the transaction data feedback to form a continuous security protection mechanism includes: Integrate the blocking effect or the transaction data feedback to form a feedback difference set; Based on the feedback difference set, the offset amplitude in the preset deviation threshold in the behavior pattern analysis is calculated. If the offset amplitude exceeds the preset adjustment threshold, the preset deviation threshold is optimized and adjusted according to the offset amplitude to obtain an optimized threshold set. Based on the optimized threshold set, the feature weights and decision boundaries of the anomaly detection model are updated using gradient descent. The updated anomaly detection model is applied to the transaction protection process. Transaction data is continuously collected to verify the optimization effect, and model parameters are iteratively adjusted to form a continuous security protection mechanism.
10. An anomaly detection system for precious metal recycling, characterized in that, include: The data acquisition module is used to collect user operation data and order association information in precious metal recycling transactions, extract behavioral features over time, and construct user behavior trajectories. The behavior analysis module is used to perform behavior pattern analysis based on the user's behavior trajectory, quantify the complexity of abnormal behavior, and obtain preliminary abnormal indicators. The spoofing detection module is used to extract the environmental information sequence associated with the user behavior trajectory if the preliminary abnormal indicators exceed the preset abnormal indicator judgment threshold, integrate the corresponding transaction environment dynamic variables to form complete context information, and detect potential spoofing signals by matching and filtering the context information with historical normal transaction data. The dynamic anomaly identification module is used to extract multi-dimensional fusion features from the context information, the preliminary anomaly indicators and the potential spoofing signal through a preset anomaly detection model if the potential spoofing signal is detected, and to perform anomaly detection and correlation calculation on the multi-dimensional fusion features to identify dynamic anomaly patterns. The routine anomaly determination module is used to extract the anomaly intensity, duration and frequency of occurrence from the preliminary anomaly indicators if no potential spoofing signal is detected, combine it with the environmental stability parameters in the context information, generate a routine anomaly analysis vector and match it with a preset template library to determine the routine anomaly pattern. The interception condition determination module is used to extract the time window width and the consistency metric of operation behavior in the order confirmation process as control parameters based on the dynamic abnormal mode or the regular abnormal mode, and fuse them to generate an interception condition judgment vector. If the comprehensive deviation score of the judgment vector is higher than the preset interception trigger threshold, the triggering condition for abnormal interception is determined to be met. The transaction processing module is used to determine whether the abnormal interception trigger condition is met based on the judgment vector. If the abnormal interception trigger condition is met, the real-time response mechanism is activated to block risky transactions and evaluate the blocking effect. If the abnormal interception trigger condition is not met, the transaction is marked as proceeding normally and transaction data feedback is recorded. The model optimization module is used to optimize the analysis parameters of the behavior pattern analysis and the anomaly detection model based on the blocking effect or the transaction data feedback, so as to form a continuous security protection mechanism.