Real-time transaction anti-fraud monitoring system and method based on big data
By acquiring transaction characteristics and user behavior data in real time and dynamically assessing the credibility of user identities, the system solves the problems of insufficient fraud detection and high false alarm rate in existing systems under dynamic environments, and achieves efficient monitoring and adaptive optimization of the entire transaction process.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- 候相蕊
- Filing Date
- 2026-01-15
- Publication Date
- 2026-04-24
AI Technical Summary
Existing transaction security monitoring systems struggle to dynamically monitor the entire transaction process in complex network environments, are unable to identify session hijacking and remote control attacks, and lack continuous tracking of user behavior characteristics, resulting in insufficient fraud detection capabilities and a high false alarm rate.
By synchronously acquiring real-time transaction feature vectors and user behavior time-series data, biometric vectors are extracted, and combined with identity confidence coefficients and preliminary risk scores to achieve fusion risk scores. The parameters and risk thresholds of the biometric baseline model are dynamically updated to form an adaptive optimization mechanism.
It improves the real-time performance and accuracy of transaction security monitoring, reduces the false alarm rate, enhances the sensitivity of fraud detection, and improves the long-term effectiveness of the system.
Smart Images

Figure CN121921101A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of transaction security monitoring technology, specifically a real-time transaction anti-fraud monitoring system and method based on big data. Background Technology
[0002] In the field of transaction security monitoring technology, traditional anti-fraud systems generally adopt static rule bases and discrete identity verification mechanisms. These mechanisms can only perform single-point verification when a transaction is initiated and cannot implement dynamic monitoring of the entire transaction process. Since static rules are difficult to adapt to complex and ever-changing network environments, the system has obvious defects when facing man-in-the-middle attacks such as session hijacking and remote control. Attackers can bypass the initial verification and manipulate the account to perform abnormal operations.
[0003] Meanwhile, existing technologies also lack the ability to continuously track user behavior characteristics and cannot assess the credibility of identity based on subtle changes in the operation process. This results in a serious lack of ability of the system to identify fraud scenarios where normal behavior is simulated after account theft. These problems indicate that existing technologies have obvious deficiencies in terms of real-time performance, continuity, and adaptability, making it difficult to meet the security and smoothness requirements of electronic payments. To address these issues, existing technologies urgently need to be improved. Summary of the Invention
[0004] The purpose of this application is to provide a real-time transaction anti-fraud monitoring system and method based on big data, which can improve the real-time performance and accuracy of transaction security monitoring during electronic payment, reduce the false alarm rate, and achieve adaptive optimization.
[0005] The objective of this application can be achieved through the following technical solution: Firstly, a real-time transaction anti-fraud monitoring method based on big data, comprising the following steps:
[0006] Synchronously acquire real-time transaction feature vectors and user behavior time-series data within a preset detection period;
[0007] Extract real-time biometric vectors within the corresponding preset detection period based on the user behavior time-series data;
[0008] The real-time biometric vector is input into a preset biometric baseline model to output an identity confidence coefficient that represents the degree of matching between the two.
[0009] A preliminary risk score is obtained based on the real-time transaction feature vector, and a fused risk score is obtained by combining the identity confidence coefficient.
[0010] The fused risk score is compared with a preset risk threshold to obtain a real-time risk level that characterizes the risk level of the real-time transaction feature vector, and a preset response action matching the real-time risk level is triggered.
[0011] The model parameters of the biometric baseline model are updated based on the real-time risk level and the real-time biometric vector. The update magnitude and update frequency of the model parameters within a preset evaluation period are obtained, and the preset risk threshold is optimized based on the update magnitude and update frequency.
[0012] Secondly, a real-time transaction anti-fraud monitoring system based on big data includes the following modules:
[0013] The data acquisition module is used to synchronously acquire real-time transaction feature vectors and their user behavior time-series data within a preset detection period;
[0014] The data processing module is used to extract real-time biometric vectors within a corresponding preset detection period based on the user behavior time series data; and input the real-time biometric vectors into a preset biometric baseline model to output an identity confidence coefficient representing the degree of matching between the two.
[0015] The risk assessment module is used to obtain a preliminary risk score based on the real-time transaction feature vector and to obtain a fusion risk score by combining the identity confidence coefficient.
[0016] The risk management module is used to compare the fused risk score with a preset risk threshold to obtain a real-time risk level that characterizes the risk level of the real-time transaction feature vector, and to trigger a preset response action that matches the real-time risk level.
[0017] The data feedback module is used to update the model parameters of the biometric baseline model according to the real-time risk level and the real-time biometric vector, obtain the update magnitude and update frequency of the model parameters within a preset evaluation period, and optimize the preset risk threshold according to the update magnitude and update frequency.
[0018] Thirdly, a computer storage medium storing computer-executable instructions, which, when executed, implement the real-time transaction anti-fraud monitoring method based on big data described in the first aspect.
[0019] Compared with the prior art, the beneficial effects of this application are:
[0020] This application obtains real-time transaction feature vectors and user behavior time-series data, extracts real-time biometric vectors and inputs them into a biometric baseline model to output an identity confidence coefficient, combines a preliminary risk score to obtain a fused risk score, and triggers a response action after comparing it with a preset risk threshold. At the same time, it updates model parameters and optimizes the risk threshold based on the real-time risk level and real-time biometric vectors. This effectively solves the shortcomings of existing technologies in terms of real-time performance, continuity and adaptability, improves the real-time performance and accuracy of transaction security monitoring in electronic payment processes, reduces false alarm rates and achieves adaptive optimization. Attached Figure Description
[0021] Figure 1 This is a schematic diagram illustrating the steps of a real-time transaction anti-fraud monitoring method based on big data according to this application;
[0022] Figure 2 This is a schematic diagram of a module of a real-time transaction anti-fraud monitoring system based on big data according to this application. Detailed Implementation
[0023] The technical solutions of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. The components described and shown in the accompanying drawings can be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of this application provided in the accompanying drawings is not intended to limit the scope of the claimed application, but only to illustrate selected embodiments of this application.
[0024] Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without inventive effort are within the scope of protection of this application. It should be noted that similar reference numerals and letters in the following figures indicate similar items. Therefore, once an item has been defined in one figure, it does not need to be further defined and explained in subsequent figures. The terms "first", "second", etc. are used only for distinguishing descriptions and should not be construed as indicating or implying relative importance.
[0025] Traditional anti-fraud monitoring technologies employ static rules and discrete authentication mechanisms, lacking the ability to continuously assess user identity credibility. This results in an inability to defend against man-in-the-middle attacks such as session hijacking and remote control during transaction processes. Furthermore, they are insufficient in identifying fraudulent activities that occur after account theft, even if they are legitimate, and suffer from a high false alarm rate. This issue impacts the system's real-time detection sensitivity, risk assessment accuracy, and user operation smoothness. Specifically, the system cannot dynamically track changes in identity credibility during transactions, thus reducing overall security effectiveness.
[0026] For example, in the payment process of an e-commerce platform, after initial identity verification, a user enters the transaction process. However, the session can be hijacked by an attacker using remote control software, and the attacker can simulate the user's normal operating mode to conduct the transaction. Traditional systems rely solely on static rules for discrete verification points and do not monitor the continuity of behavior during the transaction process, thus failing to detect identity theft. Furthermore, minor changes in behavioral parameters of legitimate users due to fluctuations in device environment are misjudged as risk events, triggering additional identity verification steps and disrupting the continuity of the normal transaction process.
[0027] If the above problems are not addressed, the system will be unable to adapt to the evolving trends of dynamic fraudulent behavior, leading to a continuous expansion of security vulnerabilities and an increase in the risk of fraudulent transactions; the high false alarm rate will damage user trust and reduce system availability; and the long-term lack of a self-optimization mechanism will cause the defense system to gradually fail and be unable to maintain effective security monitoring capabilities.
[0028] Therefore, this application provides a real-time transaction anti-fraud monitoring method based on big data, such as... Figure 1 As shown, it includes the following steps:
[0029] Synchronously acquire real-time transaction feature vectors and user behavior time-series data within a preset detection period;
[0030] Extract real-time biometric vectors within the corresponding preset detection period based on the user behavior time-series data;
[0031] The real-time biometric vector is input into a preset biometric baseline model to output an identity confidence coefficient that represents the degree of matching between the two.
[0032] A preliminary risk score is obtained based on the real-time transaction feature vector, and a fused risk score is obtained by combining the identity confidence coefficient.
[0033] The fused risk score is compared with a preset risk threshold to obtain a real-time risk level that characterizes the risk level of the real-time transaction feature vector, and a preset response action matching the real-time risk level is triggered.
[0034] The model parameters of the biometric baseline model are updated based on the real-time risk level and the real-time biometric vector. The update magnitude and update frequency of the model parameters within a preset evaluation period are obtained, and the preset risk threshold is optimized based on the update magnitude and update frequency.
[0035] Traditional anti-fraud systems primarily rely on static rules and discrete authentication methods, such as one-time password verification or SMS verification code verification at the start of a transaction. This approach is insufficient to effectively defend against man-in-the-middle attacks such as session hijacking or remote control during the transaction process. For example, in the case of a user making a large transfer, if an attacker hijacks the session after the user has completed authentication, a traditional system might fail to detect anomalies in subsequent operations.
[0036] This application achieves continuous assessment of user identity credibility by synchronously acquiring real-time transaction feature vectors and user behavior time-series data, and extracting real-time biometric vectors from them. In the example above, even if an attacker hijacks a session, their operational behavior will differ significantly from the user's biometric baseline model, resulting in a decrease in the identity confidence coefficient. This continuous assessment mechanism enables the system to detect anomalies in user identity in real time, effectively compensating for the shortcomings of traditional systems in identifying fraud such as "normal operation after account theft."
[0037] Furthermore, this application innovatively integrates the identity confidence coefficient with the preliminary risk score to generate a fused risk score. In the example, even if a transaction itself has high-risk characteristics, if the user's biometrics match highly and the identity confidence coefficient is high, the fused risk score may be appropriately lowered to avoid false alarms. Conversely, if the transaction risk is not high, but the biometrics match is extremely low, the fused risk score will be raised to promptly detect potential fraudulent behavior. This dynamic fusion mechanism makes risk assessment more comprehensive and accurate, significantly reduces the false alarm rate, and improves the sensitivity of fraud detection.
[0038] Furthermore, this application introduces a mechanism to update the parameters of the biometric baseline model based on real-time risk levels and real-time biometric vectors, and to optimize the preset risk threshold according to the update magnitude and frequency of the model parameters. A user's typing rhythm may change slightly over time; by continuously updating the baseline model, the system can adapt to these normal changes and maintain the model's effectiveness. Simultaneously, by dynamically adjusting the risk threshold by evaluating the update status of the model parameters, the system can learn and evolve, forming a continuously optimized proactive defense system. This contrasts sharply with traditional systems that rely on fixed rules and static thresholds, which often struggle to adapt to constantly changing fraud methods and user behavior patterns.
[0039] This application, by introducing real-time biometric assessment, dynamic risk fusion, and model adaptive optimization mechanisms, achieves a transformation from "single-point verification" to "end-to-end monitoring," significantly improving the real-time detection sensitivity and accuracy of transaction hijacking and identity theft fraud, while optimizing the legitimate user experience and ensuring the long-term effectiveness of the system.
[0040] It should be further explained that, in the specific implementation process, the process of simultaneously acquiring real-time transaction feature vectors and their user behavior time-series data within the preset detection period includes:
[0041] The real-time transaction feature vector refers to the structured data set extracted by the system at the moment of transaction initiation or within a preset time window (usually 5 seconds before the start of the transaction to 2 seconds after the end of the transaction) to quantify the potential risks of this transaction. This vector consists of multiple predefined risk dimension feature values, which fully characterize the static attributes and dynamic contextual risks of a transaction. Its acquisition is a process of real-time querying and calculation of multi-source data, specifically including:
[0042] 1) Transaction amount: The value obtained directly from the order payment system of this transaction, usually expressed in the base currency unit; 2) Risk identifier of the payee: Obtained by querying internal or third-party risk intelligence databases. This identifier is usually a discrete level value used to indicate the historical suspiciousness of the collection account; 3) Distance deviation between transaction location and commonly used location: Calculate the spherical geographical distance between the geographical location corresponding to the IP address or GPS location that initiated this transaction and the user's historical commonly used geographical location.
[0043] 4) Deviation between transaction time and active period: Determine whether the transaction initiation time falls outside the typical active period derived from the analysis of the user's historical transaction behavior. If so, mark the deviation as 1 (abnormal); otherwise, mark it as 0 (normal). 5) Device fingerprint unfamiliarity flag: Compare the device fingerprint used in this transaction (generated by a combination hash of device model, operating system version, browser kernel version, screen resolution, IP address, etc.) with the user's historical commonly used device fingerprint database. If it does not appear in the database, mark it as 1 (unfamiliar device); otherwise, mark it as 0 (common device).
[0044] The user behavior time-series data refers to an ordered data sequence that reflects the user's operating habits and physiological state, synchronously collected from the user's client device within the same preset detection period. It aims to capture continuous behavioral biometrics beyond identity verification. This data is primarily acquired through a front-end monitoring SDK embedded in an application (APP) or webpage. This SDK automatically activates data collection when the transaction process begins and is strictly synchronized with the transaction event in time. The user behavior time-series data includes continuous image frames of the user's eyes and a sequence of sensor data from the user's terminal.
[0045] 1) Continuous image frames: The sequence of image frames obtained by continuously capturing the application transaction interface at fixed time intervals within the detection period. It records the changes in the interface state and possible micro-expressions of the user during the process of inputting information, browsing and confirming, and finally clicking. It uses a front-end JavaScript library or native APP SDK with appropriate permissions and starts to take screenshots at a high frame rate (such as 2-5 frames per second) after the user enters the payment page.
[0046] 2) Sensor Data Sequence: This is a raw data stream continuously read from the built-in sensors of a smartphone or tablet during the detection period, reflecting the device's physical motion state and touch interaction details. It continuously collects data from the three-axis accelerometer and three-axis gyroscope by calling the device's orientation and motion sensor APIs, with a sampling frequency typically between 50-100Hz. This data sequence can be used to infer the device's grip posture and stability, monitor and record all touch events on the touchscreen, and accurately extract the touch pressure, touch point coordinates, and event timestamp (accurate to milliseconds) for each touch event. From this, a swipe interval duration sequence (i.e., the time difference between two consecutive major touch actions) can be derived.
[0047] In some other embodiments, this application further proposes that the user behavior time-series data includes continuous image frames of the user's eyes and sensor data sequences of the user terminal; based on the continuous image frames, the movement vector of the pupil center between adjacent image frames is extracted, and based on the sensor data sequences, the pressure intensity sequence generated when the user operates the terminal and the sliding interval duration sequence between adjacent operations are extracted; the average amplitude and directional entropy of the movement vector are used as feature parameters of the continuous image frames, and the mean, standard deviation, and autocorrelation coefficient of the pressure intensity sequence and the sliding interval duration sequence are used as feature parameters of the sensor data sequences, and the above feature parameters are sequentially combined into a real-time biometric vector within a corresponding preset detection period.
[0048] Specifically, the pupil center movement vector refers to the trajectory of the user's pupil center position over time in consecutive image frames. By comparing the pupil center positions in adjacent image frames, the direction and distance of pupil movement can be calculated, thus forming the movement vector. The pressure intensity sequence refers to the continuous record of the pressure applied by a user's finger to the screen over time when operating a terminal (such as a touchscreen). The swipe interval duration sequence refers to the time interval between two adjacent swipe operations during continuous touch swipe operations.
[0049] The average amplitude of the pupil movement vector refers to the average length of all pupil movement vectors within a preset detection period, reflecting the user's eye movement activity level. Orientation entropy refers to the randomness or disorder of the distribution of pupil movement vector directions. The mean of the pressure intensity sequence reflects the average pressure applied by the user when operating the terminal, while the standard deviation reflects the stability or volatility of the pressure intensity variation, i.e., the uniformity of the user's screen pressure. The autocorrelation coefficient of the swipe interval duration sequence measures the correlation of the swipe interval duration sequence at different time lags, revealing the periodic or repetitive patterns of the user's swipe operation rhythm.
[0050] Through the above technical solution, this application can extract richer and more discriminative biometric features from multimodal user behavior data. By combining continuous image frames of the user's eyes and sensor data sequences from the user's terminal, and specifically extracting the average amplitude and directional entropy of the pupil movement vector, as well as the mean, standard deviation, and autocorrelation coefficient of the pressure intensity sequence and sliding interval duration sequence, the constructed real-time biometric vector can more comprehensively and meticulously reflect the user's unique behavioral patterns. This multi-dimensional and refined feature extraction method significantly enhances the accuracy and robustness of the biometric vector, making the calculation of the identity confidence coefficient more accurate. Therefore, in the process of real-time transaction anti-fraud monitoring, it can more effectively identify abnormal behavior and potential fraud risks, reduce the false positive rate and false negative rate, thereby improving the monitoring efficiency and security of the entire anti-fraud system.
[0051] In some other embodiments, this application further proposes using real-time biometric vectors from previous detection cycles as historical biometric vectors; and obtaining the normal distribution parameters of the same feature parameter from different historical biometric vectors. The biometric baseline model is a dynamic probability distribution model, which contains real-time normal distribution parameters for each feature parameter; a single feature parameter is obtained from the real-time biometric vector. The matching probability between its normal distribution parameters The mean of the matching probabilities of each feature parameter is used as the identity confidence coefficient of the corresponding real-time biometric vector.
[0052] By using real-time biometric vectors from previous detection periods as historical biometric vectors, a rich data foundation is provided for constructing user behavior baselines. Based on this, for each biometric parameter, its normal distribution parameter is calculated and maintained from this historical data. These parameters collectively constitute a dynamic probability distribution model that can be updated in real time and reflects the evolution of user behavior patterns. When the system receives a new real-time biometric vector, it compares each individual feature parameter with its corresponding normal distribution parameter in the baseline model, quantifying the degree of fit between the real-time feature and historical behavior patterns by calculating the matching probability. This probability calculation method can precisely assess the degree of anomaly in real-time behavior.
[0053] To obtain a comprehensive evaluation result, the system averages the matching probabilities of all individual feature parameters to obtain an overall identity confidence coefficient. This identity confidence coefficient intuitively represents the overall degree of matching between the real-time biometric vector and the user's historical behavioral patterns, providing crucial biometric dimension support for subsequent risk assessment. This dynamic, probability distribution-based baseline model construction and matching mechanism enables the system to more accurately identify subtle changes in user behavior and distinguish between normal and abnormal behavior. This effectively addresses the limitations of traditional methods where the baseline model is fixed and cannot adapt to dynamic changes in user behavior, significantly improving the accuracy of the identity confidence coefficient and the robustness of anti-fraud monitoring.
[0054] Through the above technical solution, this application can establish a dynamic and refined user biometric baseline model and match real-time biometrics based on probability distribution to obtain an accurate identity confidence coefficient. Specifically, historical biometric vectors are used to construct a dynamic probability distribution model, and the normal distribution parameters of each feature parameter are updated in real time, enabling the biometric baseline model to adaptively learn and reflect the evolution of user behavior patterns. This dynamism effectively solves the limitation of traditional fixed baseline models that cannot adapt to natural changes in user behavior, avoiding misjudgments caused by changes in user habits. By calculating the matching probability of a single feature parameter in the real-time biometric vector with the corresponding normal distribution parameter in the baseline model, and using the mean of these probabilities as the identity confidence coefficient, this solution can comprehensively evaluate the authenticity of user behavior, improving the accuracy and robustness of the identity confidence coefficient. This enables subsequent risk assessment to more accurately identify fraudulent behavior, reduces false positive and false negative rates, and significantly improves the overall effectiveness of real-time transaction anti-fraud monitoring.
[0055] In some other embodiments, this application further proposes a preliminary risk score acquisition step, which includes: querying the basic risk score corresponding to each element in the real-time transaction feature vector in a preset score mapping table, and performing a weighted calculation on the basic risk scores of different elements to obtain the preliminary risk score of their corresponding real-time transaction feature vector.
[0056] The preset rating mapping table is a predefined data structure used to store the correspondence between transaction features and risk scores. Its function is to map discrete or continuous transaction feature values to standardized risk scores. This mapping table is a relational database table containing fields such as feature name, feature value range, and corresponding risk score. By querying this mapping table, the system can quickly obtain the basic risk score for a specific transaction feature, thus providing a quantitative basis for subsequent risk assessment.
[0057] The basic risk score is a quantified risk value assigned to each independent element in the real-time transaction feature vector. Its purpose is to unify different types of transaction features into a single risk measurement system. The preliminary risk score, in real-time transaction anti-fraud monitoring methods, is a preliminary quantitative assessment of the risk level of a real-time transaction before incorporating user behavioral biometric information. Its role is to provide a risk benchmark based on the transaction's inherent attributes. For example, this score can be a value between 0 and 100, with higher values indicating higher transaction risk. This score forms the basis for subsequent fusion risk scoring using identity confidence coefficients, providing crucial input for the system to determine the transaction's risk level.
[0058] Through the aforementioned technical solution, when obtaining the preliminary risk score, the system can decompose the complex information in the real-time transaction feature vector into quantifiable independent elements and assign an objective basic risk score to each element. This meticulous evaluation method, combined with weighted calculation, makes the generation process of the preliminary risk score more transparent and interpretable, avoiding the biases that may arise from simplistic and crude risk assessments. Specifically, through a pre-set scoring mapping table, the system can quickly and accurately obtain the basic risk score for each transaction feature, improving the efficiency of risk assessment. Simultaneously, the introduction of weighted calculation allows the system to differentiate based on the contribution of different features to risk, thereby generating a more accurate and comprehensive preliminary risk score. This not only improves the accuracy of the preliminary risk score but also lays a solid foundation for subsequent fusion risk scoring using identity confidence coefficients, thereby enhancing the overall identification capability and decision-making accuracy of the entire real-time transaction anti-fraud monitoring method.
[0059] In some other embodiments, this application further proposes the aforementioned fusion risk score. , The discount factor is generated based on the identity confidence coefficient S, and its value ranges from (0, 1). ,in, For preliminary risk assessment, To preset the threshold, These are the preset baseline factor, sensitivity factor, and scaling factor, respectively.
[0060] The integrated risk score is the final risk assessment result adjusted for identity confidence coefficients. Its purpose is to provide a more comprehensive and accurate measure of transaction risk. This score comprehensively considers the risk characteristics of the transaction itself and the degree of matching of the user's identity, thus avoiding the bias that may arise from a single-dimensional assessment. The discount coefficient is an adjustment factor generated based on the identity confidence coefficient, with a value range of (0, 1). This coefficient dynamically adjusts the initial risk score according to the credibility of the user's identity.
[0061] When the confidence level of identity is high As the value approaches 1, its effect on adjusting the initial risk score weakens; when the confidence level of identity is low, A value close to 0 enhances the adjustment effect on the initial risk score. The benchmark factor, sensitivity factor, and scaling factor are all preset parameter values used to fine-tune the calculation logic of the fused risk score. The benchmark factor can be understood as the benchmark weight of the initial risk score when the identity confidence level is extremely high; the sensitivity factor controls the sensitivity of changes in identity confidence level to risk score adjustments; and the scaling factor adjusts the steepness of the impact of the difference between the identity confidence coefficient and the preset confidence threshold on the discount coefficient, enabling the model to flexibly adapt to different risk assessment strategies and business needs.
[0062] Through the aforementioned technical solution, this application organically combines preliminary risk assessment based on transaction characteristics with identity confidence assessment based on biometrics, achieving refined management of transaction risks. This solution introduces a discount coefficient and utilizes benchmark factors, sensitivity factors, and scaling factors for flexible configuration, enabling the system to dynamically adjust transaction risk scores based on the authenticity of the user's identity. When the user's identity is highly credible, the preliminary risk score can be appropriately reduced to minimize interference with normal transactions; conversely, when there are doubts about the user's identity, the risk score can be significantly increased to promptly identify potential fraudulent activities. This effectively solves the potential misjudgment problem that may occur when relying solely on transaction characteristics for risk assessment, significantly improving the accuracy and robustness of real-time transaction anti-fraud monitoring, reducing false positive and false negative rates, and thus providing users with a safer trading environment.
[0063] In some other embodiments, this application further proposes that the preset risk threshold includes a first risk threshold and a second risk threshold, wherein the first risk threshold is less than the second risk threshold; if the fused risk score is less than or equal to the first risk threshold, then the corresponding real-time transaction feature vector is marked as low risk and a release action is performed; if the fused risk score is greater than the first risk threshold and less than the second risk threshold, then the corresponding real-time transaction feature vector is marked as medium risk and a verification action is performed; if the fused risk score is greater than or equal to the second risk threshold, then the corresponding real-time transaction feature vector is marked as high risk and a blocking action is performed.
[0064] This application introduces two distinct thresholds: a first risk threshold and a second risk threshold, with the first risk threshold being lower than the second risk threshold. This design aims to provide a more granular risk classification capability, enabling the system to identify at least three distinct risk ranges, thus laying the foundation for subsequent differentiated processing. When the calculated fusion risk score is lower than or equal to the first risk threshold, it indicates that the fraud risk of the transaction is extremely low. At this point, the system marks the transaction as low-risk. To ensure user experience and transaction efficiency, the system will execute a release action, allowing the transaction to complete smoothly without additional manual intervention or verification. Release actions may include directly completing the payment or not performing additional verification.
[0065] When the fusion risk score falls between the first and second risk thresholds, it indicates that the transaction carries a certain risk of fraud, but has not yet reached a high-risk level. The system marks the transaction as medium-risk. To further confirm the legitimacy of the transaction and reduce potential losses, the system will perform verification actions. Verification actions may include, but are not limited to, sending SMS verification codes, performing facial recognition, requiring users to enter their payment passwords, and conducting telephone follow-ups, to increase the difficulty for fraudsters and obtain more verification information. When the fusion risk score reaches or exceeds the second risk threshold, it indicates that the transaction has an extremely high risk of fraud. The system marks the transaction as high-risk. To minimize fraud losses, the system will perform blocking actions, i.e., immediately suspend the transaction to prevent financial losses. Blocking actions may include directly rejecting the transaction, freezing relevant accounts, and notifying risk control personnel to intervene in the investigation.
[0066] Through the above technical solution, this application enables refined classification and differentiated processing of real-time transaction risks. By introducing a first risk threshold and a second risk threshold, the system can classify real-time transaction risks into three levels: low, medium, and high, and match corresponding preset response actions (allowing, verifying, or blocking) for different real-time risk levels. This multi-level risk response mechanism effectively solves the limitations of single threshold judgment, which is coarse and cannot balance transaction efficiency and risk control. It allows the system to maximize the smoothness of legitimate transactions while ensuring transaction security, avoiding excessive intervention in low-risk transactions, and adopting more precise and effective prevention and control measures for medium- and high-risk transactions, significantly improving the overall effectiveness of the anti-fraud system and user experience.
[0067] In other embodiments, this application proposes obtaining the normal distribution parameters of individual feature parameters in each real-time biometric vector corresponding to each real-time transaction feature vector marked as low risk within the current detection period. ; the normal distribution parameter of this single feature parameter in the biometric baseline model Update the parameters to obtain the updated normal distribution parameters. , ,in, This is the preset update factor.
[0068] From transactions deemed low-risk by the system, user biometric vectors associated with these transactions are extracted. Furthermore, the statistical distribution parameters of each individual feature parameter in these biometric vectors are calculated, specifically the mean and standard deviation. Here, low-risk transactions are considered normal and legitimate user behavior; therefore, their corresponding biometric data can serve as a reliable basis for updating the biometric baseline model.
[0069] This application employs a weighted average method, combining the old mean with the mean obtained from current low-risk transactions. Specifically, This is a preset update factor used to control the weighting of the old and new means during the update process. Similar to the mean update, the standard deviation also uses a weighted average method, combining the old standard deviation with the standard deviation obtained from current low-risk transactions. The update factor is also used to balance the influence of the old and new standard deviations. Its value typically ranges from 0 to 1. The larger the value, the stronger the model's dependence on historical data and the smoother the update, but the slower it responds to new behavioral patterns. The smaller the value, the faster the model responds to new data, but it may be more susceptible to short-term fluctuations.
[0070] Through the above technical solution, this application enables dynamic adaptive updating of the biometric baseline model, effectively solving the potential lag problem that may occur when the model faces the natural evolution of user behavior patterns. By updating model parameters using only transaction data marked as low-risk, this solution ensures the reliability and security of the update process, avoiding the negative impact of potential fraudulent behavior on model stability. This mechanism of weighted updates based on low-risk data allows the biometric baseline model to continuously and accurately reflect the user's true behavioral characteristics, thereby significantly improving the accuracy of identity confidence coefficient calculation. Ultimately, this helps improve the accuracy of the entire real-time transaction anti-fraud monitoring system in identifying legitimate transactions and the efficiency in intercepting fraudulent transactions, reducing the false positive rate and optimizing the user experience.
[0071] In other embodiments, this application further proposes that the preset evaluation period is composed of multiple preset detection periods, and the update frequency refers to the total number of times the model parameters are updated within the current evaluation period; the local update amplitude is obtained when a single update of the model parameters is performed within the current evaluation period. The average local update magnitude during each update of model parameters within the current evaluation period is used as the update magnitude. The obtained update frequency and update magnitude are compared with their corresponding preset frequency threshold and preset magnitude threshold, respectively. When both the update frequency and update magnitude are higher than their preset frequency threshold and preset magnitude threshold, the first risk threshold and the second risk threshold are increased simultaneously. When both the update frequency and update magnitude are lower than their preset frequency threshold and preset magnitude threshold, the first risk threshold and the second risk threshold are decreased simultaneously. No optimization operation is performed in other cases.
[0072] The preset evaluation period refers to the time span used for macroscopic evaluation of the updates to the biometric baseline model parameters, which consists of multiple preset detection periods. A preset evaluation period can be set to one day or one week, while each preset detection period may only be a few seconds or minutes. Update frequency refers to the total number of times the biometric baseline model parameters are updated within the current preset evaluation period, reflecting the activity or learning speed of the model parameters. Local update magnitude quantifies the degree of change in model parameters during a single update, reflecting the model's response strength to new data. Each time model parameters are updated, the system calculates and records the relative change between the old and new means. Update magnitude refers to the average of the local update magnitudes during all model parameter updates within the current evaluation period, used to measure the overall learning strength of the model over a period of time.
[0073] When both the update frequency and magnitude are higher than their preset frequency and magnitude thresholds, it indicates that the model is learning actively and changing drastically. In this case, the system will simultaneously increase both the first and second risk thresholds, for example, by adding a fixed value or a scaling factor to both. When both the update frequency and magnitude are lower than their preset frequency and magnitude thresholds, it indicates that the model is learning inactive and changing slowly. In this case, the system will simultaneously decrease both the first and second risk thresholds, for example, by decreasing both by a fixed value or a scaling factor. In other cases, no optimization operations are performed; that is, when the model parameter update activity or degree of change is within the normal range, the preset risk thresholds are kept unchanged to maintain system stability.
[0074] Through the aforementioned technical solution, this application enables the risk assessment strategy to remain synchronized with the learning status of the biometric baseline model. When the model is actively learning and changing rapidly, raising the risk threshold can effectively address potential new fraud patterns or significant changes in user behavior, avoiding false negatives due to rapid model adaptation, thereby improving the accuracy and security of anti-fraud measures. When the model is learning gradually and changing little, lowering the risk threshold can avoid excessive blocking, increase the success rate of normal transactions, optimize user experience, and reduce system operating costs. This adaptive risk threshold optimization mechanism makes the entire anti-fraud monitoring system more intelligent and flexible, better balancing risk control and user experience, and significantly improving the robustness and effectiveness of real-time transaction anti-fraud monitoring.
[0075] In another embodiment, this application also provides a real-time transaction anti-fraud monitoring system based on big data, such as... Figure 2 As shown, it includes the following modules:
[0076] The data acquisition module is used to synchronously acquire real-time transaction feature vectors and their user behavior time-series data within a preset detection period;
[0077] The data processing module is used to extract real-time biometric vectors within a corresponding preset detection period based on the user behavior time series data; and input the real-time biometric vectors into a preset biometric baseline model to output an identity confidence coefficient representing the degree of matching between the two.
[0078] The risk assessment module is used to obtain a preliminary risk score based on the real-time transaction feature vector and to obtain a fusion risk score by combining the identity confidence coefficient.
[0079] The risk management module is used to compare the fused risk score with a preset risk threshold to obtain a real-time risk level that characterizes the risk level of the real-time transaction feature vector, and to trigger a preset response action that matches the real-time risk level.
[0080] The data feedback module is used to update the model parameters of the biometric baseline model according to the real-time risk level and the real-time biometric vector, obtain the update magnitude and update frequency of the model parameters within a preset evaluation period, and optimize the preset risk threshold according to the update magnitude and update frequency.
[0081] The core innovation of this embodiment lies in quantifying the matching metric between real-time biometric vectors and biometric baseline models into an identity confidence coefficient, and using this coefficient as a dynamic discount factor to modulate transaction risk scoring in real time, thereby achieving a shift from single-point verification to end-to-end monitoring. Traditional anti-fraud systems rely on static rules and discrete identity verification, making it difficult to effectively defend against man-in-the-middle attacks such as session hijacking and remote control. Furthermore, they cannot continuously assess the credibility of user identities, resulting in insufficient identification of fraudulent activities such as "normal operations after account theft" and a high false alarm rate.
[0082] This application continuously outputs an identity confidence coefficient through a data processing module, and dynamically integrates this coefficient with a preliminary risk score through a risk assessment module. This enables the system to detect user identity anomalies in real time, significantly improving the sensitivity and accuracy of detecting transaction hijacking and identity theft fraud. Simultaneously, the closed-loop optimization mechanism of the data feedback module ensures the system's self-learning, maintaining long-term effectiveness through model parameter updates and dynamic adjustments to risk thresholds, forming a continuously evolving proactive defense system. Through the above technical solutions, this application improves security while optimizing the legitimate user experience, achieving an intelligent upgrade of dynamic risk integration and tiered handling.
[0083] In another embodiment, this application also provides a computer storage medium storing computer-executable instructions, which, when executed, implement the aforementioned real-time transaction anti-fraud monitoring system and method based on big data.
[0084] The above embodiments are only used to illustrate the technical methods of this application and are not intended to limit it. Although this application has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical methods of this application without departing from the spirit and scope of the technical methods of this application.
Claims
1. A real-time transaction anti-fraud monitoring method based on big data, characterized in that, Includes the following steps: Synchronously acquire real-time transaction feature vectors and user behavior time-series data within a preset detection period; Extract real-time biometric vectors within the corresponding preset detection period based on the user behavior time-series data; The real-time biometric vector is input into a preset biometric baseline model to output an identity confidence coefficient that represents the degree of matching between the two. A preliminary risk score is obtained based on the real-time transaction feature vector, and a fused risk score is obtained by combining the identity confidence coefficient. The fused risk score is compared with a preset risk threshold to obtain a real-time risk level that characterizes the risk level of the real-time transaction feature vector, and a preset response action matching the real-time risk level is triggered. The model parameters of the biometric baseline model are updated based on the real-time risk level and the real-time biometric vector. The update magnitude and update frequency of the model parameters within a preset evaluation period are obtained, and the preset risk threshold is optimized based on the update magnitude and update frequency.
2. The real-time transaction anti-fraud monitoring method based on big data according to claim 1, characterized in that, The user behavior time-series data includes continuous image frames of the user's eyes and sensor data sequences from the user's terminal. Based on the continuous image frames, extract the movement vector of the pupil center between adjacent image frames; based on the sensor data sequence, extract the touch pressure intensity sequence and the sliding interval duration sequence between adjacent operations generated when the user operates the terminal. The average amplitude and directional entropy of the movement vector are used as feature parameters of the continuous image frames, and the mean, standard deviation and autocorrelation coefficient of the pressure intensity sequence and the sliding interval duration sequence are used as feature parameters of the sensor data sequence. The above feature parameters are combined in sequence to form a real-time biofeature vector within the corresponding preset detection period.
3. The real-time transaction anti-fraud monitoring method based on big data according to claim 2, characterized in that, Use the real-time biometric vectors from each detection period prior to the current detection period as historical biometric vectors. The normal distribution parameters of the same feature parameter are obtained from the feature vectors of different historical organisms. The biometric baseline model is a dynamic probability distribution model, which contains real-time normal distribution parameters of each feature parameter. Obtain a single feature parameter from the real-time biometric vector. The matching probability between its normal distribution parameters The mean of the matching probabilities of each feature parameter is used as the identity confidence coefficient of the corresponding real-time biometric vector.
4. The real-time transaction anti-fraud monitoring method based on big data according to claim 1, characterized in that, The basic risk score corresponding to each element in the real-time transaction feature vector is queried in the preset scoring mapping table. The basic risk scores of different elements are weighted and calculated to obtain the preliminary risk score of the corresponding real-time transaction feature vector.
5. The real-time transaction anti-fraud monitoring method based on big data according to claim 4, characterized in that, The fusion risk score , The discount factor is generated based on the identity confidence coefficient S, and its value ranges from (0, 1). ,in, For preliminary risk assessment, To preset the threshold, These are the preset baseline factor, sensitivity factor, and scaling factor, respectively.
6. The real-time transaction anti-fraud monitoring method based on big data according to claim 3, characterized in that, The preset risk threshold includes a first risk threshold and a second risk threshold, wherein the first risk threshold is less than the second risk threshold; If the fusion risk score is less than or equal to the first risk threshold, the corresponding real-time transaction feature vector is marked as low risk and a release action is performed. If the fusion risk score is greater than the first risk threshold and less than the second risk threshold, the corresponding real-time transaction feature vector is marked as medium risk and a verification action is performed. If the fusion risk score is greater than or equal to the second risk threshold, the corresponding real-time transaction feature vector is marked as high risk and a blocking action is performed.
7. The real-time transaction anti-fraud monitoring method based on big data according to claim 6, characterized in that, Obtain the normal distribution parameters of individual feature parameters in each real-time biometric feature vector corresponding to each real-time transaction feature vector marked as low risk within the current detection period. ; The normal distribution parameter of this single feature parameter in the biometric baseline model Update the parameters to obtain the updated normal distribution parameters. , ,in, This is the preset update factor.
8. The real-time transaction anti-fraud monitoring method based on big data according to claim 7, characterized in that, The preset evaluation period consists of multiple preset detection periods, and the update frequency refers to the total number of times the model parameters are updated within the current evaluation period. Obtain the local update magnitude when updating model parameters once within the current evaluation period. The average of the local update amplitudes during each update of model parameters within the current evaluation period is taken as the update amplitude. The obtained update frequency and update amplitude are compared with their corresponding preset frequency thresholds and preset amplitude thresholds, respectively. When both the update frequency and update magnitude are higher than their preset frequency threshold and preset magnitude threshold, the first risk threshold and the second risk threshold are increased simultaneously. When both the update frequency and update magnitude are lower than their preset frequency threshold and preset magnitude threshold, the first risk threshold and the second risk threshold are decreased simultaneously. No optimization operation is performed in other cases.
9. A real-time transaction anti-fraud monitoring system based on big data, characterized in that, Includes the following modules: The data acquisition module is used to synchronously acquire real-time transaction feature vectors and their user behavior time-series data within a preset detection period; The data processing module is used to extract real-time biometric vectors within a corresponding preset detection period based on the user behavior time series data; and input the real-time biometric vectors into a preset biometric baseline model to output an identity confidence coefficient representing the degree of matching between the two. The risk assessment module is used to obtain a preliminary risk score based on the real-time transaction feature vector and to obtain a fusion risk score by combining the identity confidence coefficient. The risk management module is used to compare the fused risk score with a preset risk threshold to obtain a real-time risk level that characterizes the risk level of the real-time transaction feature vector, and to trigger a preset response action that matches the real-time risk level. The data feedback module is used to update the model parameters of the biometric baseline model according to the real-time risk level and the real-time biometric vector, obtain the update magnitude and update frequency of the model parameters within a preset evaluation period, and optimize the preset risk threshold according to the update magnitude and update frequency.
10. A computer storage medium storing computer-executable instructions, characterized in that, When the computer-executable instructions are executed, they implement the real-time transaction anti-fraud monitoring method based on big data as described in any one of claims 1-8.