Abnormal trade identification method and system, storage medium and computer program product
By constructing a target trade chain and comparing it with a preset database, anomaly identification indicators and their weights are obtained, and the comprehensive anomaly degree is calculated. This automatically identifies abnormal trade, solving the problem of lack of standards in manual screening and achieving efficient and accurate identification of abnormal trade.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- CHINA PETROCHEMICAL CORP
- Filing Date
- 2024-10-25
- Publication Date
- 2026-04-28
AI Technical Summary
Current technologies for identifying abnormal trade mainly rely on manual screening, which lacks unified standards, resulting in insufficient accuracy and reliability in identification.
By constructing a target trade chain and comparing it with a pre-set trade chain database, anomaly identification indicators and their weights are obtained, the overall anomaly degree is calculated, identification standards are set, and abnormal trade is automatically identified.
It improves the efficiency and accuracy of abnormal trade identification, ensures the consistency and repeatability of the identification process, and enables the timely detection of potential anomalies, prevention, and mitigation of risks.
Smart Images

Figure CN121937210A_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to the field of information detection technology, and in particular to a method, system, storage medium, and computer program product for identifying abnormal trade. Background Technology
[0002] The risks of fictitious trade and financing trade are extremely harmful to enterprises. Due to the limited understanding of fictitious trade and financing trade, enterprises have suffered varying degrees of damage in the process of carrying out related illegal business activities. At best, they suffer financial losses, and at worst, they face insolvency and cessation of production and operation.
[0003] Currently, the identification of abnormal trade relies mainly on manual screening, which involves a high degree of human subjectivity and makes it difficult to establish unified standards for screening rules and methods, thus affecting the accuracy and reliability of identification. Summary of the Invention
[0004] This disclosure provides a method, system, storage medium, and computer program product for identifying abnormal trade, in order to solve the problem that in the prior art, manual screening of trade anomalies is difficult to standardize in terms of screening rules and methods, which affects the accuracy and reliability of abnormal trade identification.
[0005] Firstly, this disclosure provides a method for identifying abnormal trade, including:
[0006] Obtain basic data on the trade to be detected, and establish the target trade chain based on the basic data;
[0007] The target trade chain is compared with a preset trade chain database to determine the trade chain attributes of the trade.
[0008] Obtain the anomaly identification indicators corresponding to the trade chain attributes, and the weights corresponding to each anomaly identification indicator;
[0009] Based on the preset anomaly calculation rules, the anomaly degree of each anomaly identification indicator is determined, and the comprehensive anomaly degree of the trade is calculated according to the anomaly degree of each anomaly identification indicator and the weight corresponding to each anomaly identification indicator.
[0010] When the overall anomaly degree does not meet the preset identification criteria, the trade is determined to be an abnormal trade.
[0011] In one embodiment, prior to the step of acquiring basic trade data and establishing a target trade chain based on the basic data, the method further includes:
[0012] Retrieve multiple transaction documents within a target time period;
[0013] Based on preset identification rules, each of the transaction documents is identified to obtain the trade chain path corresponding to each of the transaction documents;
[0014] Each trade chain path is classified according to its attributes, and trade chain templates with different attributes are generated. The trade chain templates are then integrated to obtain the trade chain library.
[0015] In one embodiment, the step of comparing the target trade chain with a preset trade chain database to determine the trade chain attributes includes:
[0016] The target trade chain is traversed using a depth-first search algorithm;
[0017] Each node is compared with each node in the trade chain template in terms of similarity. The trade chain template with the highest similarity is determined as the trade chain template that matches the target trade chain. The attribute of the matched trade chain template is determined as the trade chain attribute.
[0018] In one embodiment, the trade chain attributes in the trade chain library include at least one of the following: idle transaction attribute, order processing attribute, and financing attribute.
[0019] In one embodiment, the step of obtaining the anomaly identification indicators corresponding to the trade chain attributes, and the weights corresponding to each anomaly identification indicator, includes:
[0020] Obtain the primary anomaly indicator corresponding to the trade chain attribute, and the secondary anomaly indicator subordinate to the primary anomaly indicator, wherein the secondary anomaly indicator is the anomaly identification indicator.
[0021] Based on the impact of each primary and secondary anomaly indicator on the anomaly risk, a first weight corresponding to each primary anomaly indicator and a second weight corresponding to each secondary anomaly indicator are determined, wherein the sum of the second weights of each secondary anomaly indicator belonging to the same primary anomaly indicator is 1.
[0022] In one embodiment, the basic trade data includes at least one of counterparty data, contract data, order data, transfer of ownership data, and settlement data.
[0023] In one embodiment, the step of determining the anomaly degree of each anomaly identification index based on a preset anomaly degree calculation rule includes:
[0024] Obtain the threshold values for each of the aforementioned anomaly identification indicators;
[0025] The actual value of each anomaly identification indicator is compared with the corresponding indicator threshold, and the anomaly degree of each anomaly identification indicator is determined based on the comparison result.
[0026] Secondly, this disclosure provides a system for identifying abnormal trade, including a memory, a processor, and a computer program stored in the memory, wherein the processor executes the computer program to implement the method described above.
[0027] Thirdly, this disclosure provides a computer-readable storage medium having a computer program stored thereon that, when executed by a processor, implements the methods described in the above aspects.
[0028] Fourthly, this disclosure provides a computer program product, including a computer program that, when executed by a processor, implements the methods described in the above aspects.
[0029] This disclosure provides a method, system, storage medium, and computer program product for identifying abnormal trade. By constructing a target trade chain and comparing it with a pre-set trade chain database, the trade chain attributes of the trade are located. This trade chain-based comparison method is more comprehensive and accurate than traditional manual judgment, reducing the possibility of misjudgment. The pre-set trade chain database, abnormal identification indicators and their weights, and abnormality rules provide a systematic framework and standardized operating procedures for identifying abnormal trade. This not only improves identification efficiency but also ensures the consistency and repeatability of the identification process. By calculating the comprehensive abnormality degree of trade and setting pre-set identification standards, potential abnormal trade behaviors can be detected and warned in a timely manner, helping to take timely measures to prevent and mitigate risks, maintain market order, and protect one's own interests. This solves the problem in existing technologies where human screening is heavily influenced by subjective factors, making it difficult to establish unified standards for screening rules and methods, thus affecting the accuracy and reliability of identification. Attached Figure Description
[0030] The present disclosure will be described in more detail below based on embodiments and with reference to the accompanying drawings:
[0031] Figure 1 A flowchart illustrating a method for identifying abnormal trades provided in this embodiment of the disclosure;
[0032] Figure 2 This is a schematic diagram of the structure of a portion of the trade chain templates in a trade chain library provided in an embodiment of the present disclosure;
[0033] Figure 3 This is a schematic diagram illustrating the specific classification results of an anomaly identification index provided in an embodiment of this disclosure;
[0034] Figure 4 This is an internal structural block diagram of an abnormal trade identification device provided in an embodiment of the present disclosure.
[0035] In the accompanying drawings, the same parts are referred to by the same reference numerals, and the drawings are not drawn to scale. Detailed Implementation
[0036] To enable those skilled in the art to better understand the technical solutions of this disclosure, and to fully understand and implement the process of how this disclosure applies technical means to solve technical problems and achieve corresponding technical effects, the technical solutions in the embodiments of this disclosure will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this disclosure, not all embodiments. The embodiments of this disclosure and the various features within them can be combined with each other without conflict, and the resulting technical solutions are all within the protection scope of this disclosure. All other embodiments obtained by those skilled in the art based on the embodiments of this disclosure without creative effort should fall within the protection scope of this disclosure.
[0037] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this disclosure are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this disclosure described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0038] It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although a logical order is shown in the flowchart, in some cases the steps shown or described may be executed in a different order than that shown here.
[0039] Example One
[0040] Figure 1 This is a flowchart illustrating a method for identifying abnormal trades provided in an embodiment of this disclosure. Figure 1 As shown, a method for identifying abnormal trade includes:
[0041] Step 110: Obtain the basic data of the trade to be detected, and establish the target trade chain based on the basic data;
[0042] In this embodiment, the basic trade data includes, but is not limited to: the main information of the trading parties (such as company name, registered address, business scope, etc.), detailed information of the traded goods (such as type, quantity, price, place of origin, etc.), transaction time, payment method, logistics information, etc. After obtaining the basic data, the basic data is organized according to the logical sequence of the purchase and sale process to form a clear target trade chain. This target trade chain reflects each link of the trade activity, thereby helping to clearly track the ins and outs of the trade activity during subsequent anomaly analysis.
[0043] In one embodiment, the basic trade data includes at least one of the following: counterparty data, contract data, order data, transfer of ownership data, and settlement data. In practice, the trade process typically involves a long period, with different data acquired at different times. For example, before formally establishing a trade, basic data available includes counterparty data (the counterparty's own entity information, relationship graph with the counterparty, basic information of purchasing suppliers, and basic information of sales customers, etc.) and transaction type. Therefore, a target trade chain can be established using this basic data, and anomaly analysis can be performed on this target trade chain. During the trade process, contract data and order data are further acquired, which can be used to further refine the target trade chain, and anomaly analysis can be performed on it. Some time after the trade ends, transfer of ownership data and settlement data are available, resulting in more complete basic data and a more complete target trade chain. Anomaly analysis on this target trade chain allows for a comprehensive review of the compliance and anomalies of trade transactions.
[0044] Step 120: Compare the target trade chain with a preset trade chain database to determine the trade chain attributes of the trade.
[0045] In this embodiment, the preset trade chain database contains a dataset of various normal and abnormal trade patterns. By comparing the target trade chain to be detected with the patterns in this database, the trade chain attribute of the trade can be preliminarily determined, i.e., what type of trade pattern it belongs to. This helps to quickly narrow down the scope of analysis and focus on identifying the links most likely to be abnormal.
[0046] Step 130: Obtain the anomaly identification indicators corresponding to the trade chain attributes, and the weights corresponding to each anomaly identification indicator;
[0047] In this embodiment, each trade chain attribute corresponds to a series of anomaly identification indicators, which are used to measure the degree of anomaly in specific aspects of trade activities. Furthermore, each indicator has its corresponding weight, reflecting its importance in the overall anomaly calculation.
[0048] In one embodiment, the system establishes an anomaly indicator library, which contains various anomaly identification indicators. These anomaly identification indicators are characteristic indicators extracted and summarized by integrating and analyzing information from multiple sources (such as case knowledge bases, management methods, internal control systems, and expert experience bases) to identify, assess, or monitor potential anomalies or problems in specific areas (such as risk management, business operations, and internal control). Examples include gross profit margin differences, the degree to which purchase and sales prices deviate from market levels, and payment methods. After determining the trade chain attributes of the trade, corresponding anomaly identification indicators are selected from the anomaly indicator library based on the characteristics of these attributes, and weights are assigned to each anomaly identification indicator.
[0049] In one embodiment, the system has a pre-set anomaly identification template. This template configures different anomaly identification indicators and corresponding weights for each trade chain with different attributes. Once the trade chain attributes are determined, the system can automatically match the anomaly identification criteria and corresponding weights. In one embodiment, the anomaly identification indicators can be freely combined, and the weights of each indicator can be customized, making the anomaly assessment method more flexible and applicable to different scenarios and usage requirements.
[0050] Step 140: Based on the preset anomaly calculation rules, determine the anomaly degree of each anomaly identification indicator, and calculate the comprehensive anomaly degree of the trade according to the anomaly degree of each anomaly identification indicator and the weight corresponding to each anomaly identification indicator.
[0051] In this embodiment, each anomaly identification indicator is quantitatively evaluated according to a preset anomaly calculation rule to obtain its anomaly degree. The anomaly degree can be calculated using various statistical methods and algorithms, such as standard deviation analysis and cluster analysis. By calculating the anomaly degree, one can intuitively understand in which aspects of trade activities are abnormal.
[0052] For example, regarding transaction amount as an anomaly identification indicator, the standard deviation method is used to calculate the anomaly score: Suppose the average transaction amount for a certain trade activity is 1 million yuan, and the standard deviation is 200,000 yuan. If a transaction amount is 1.6 million yuan, its anomaly score is (1.6 million - 1 million) / 200,000 = 3, indicating that the transaction amount is more than 3 standard deviations above the average. The standard set for this indicator is that the transaction amount should not exceed 2 standard deviations from the average. The greater the deviation from the average, the greater the anomaly score. Therefore, the anomaly score of this transaction is determined to be A. In addition, the percentage deviation between the indicator value and a benchmark value (such as historical averages, industry standards, etc.) can also be calculated. In practical applications, the anomaly score calculation rules can be selected and adjusted according to the specific application scenario and data characteristics; no specific restrictions are imposed here.
[0053] In one embodiment, the step of determining the anomaly degree of each anomaly identification indicator based on a preset anomaly degree calculation rule includes: obtaining the indicator threshold of each anomaly identification indicator; comparing the actual value of each anomaly identification indicator with the corresponding indicator threshold, and determining the anomaly degree of each anomaly identification indicator based on the comparison result.
[0054] In this embodiment, a corresponding threshold needs to be set for each anomaly identification indicator. These thresholds are used to determine whether the actual value is within the normal range, thereby identifying whether an anomaly exists. The threshold setting can be based on industry standards, historical data, expert opinions, or the company's own risk tolerance. The actual value of each anomaly identification indicator is compared with its corresponding threshold, and the comparison result determines the degree of anomaly of that indicator. Then, the anomaly degrees of each anomaly identification indicator are weighted and summed to obtain the comprehensive anomaly degree. The comprehensive anomaly degree provides a more comprehensive assessment of the anomaly degree of the transaction, avoiding the limitations of a single indicator.
[0055] Step 150: When the overall anomaly degree does not meet the preset identification criteria, the trade is determined to be an abnormal trade.
[0056] In this embodiment, the preset identification criterion can be that trade is considered normal when the overall anomaly score is less than the anomaly score threshold. In some embodiments, it can also be that the normality score of each anomaly identification indicator is calculated, and the normality scores of each anomaly identification indicator are weighted and summed to obtain the overall normality score. When the overall normality score does not reach the preset normality score threshold, the trade is determined to be abnormal trade.
[0057] In summary, the abnormal trade identification method provided in this embodiment constructs a target trade chain and compares it with a pre-set trade chain database to locate the trade chain attributes. This trade chain-based comparison method is more comprehensive and accurate than traditional manual judgment, reducing the possibility of misjudgment. The pre-set trade chain database, abnormal identification indicators and their weights, and abnormality rules provide a systematic framework and standardized operating procedures for abnormal trade identification. This not only improves identification efficiency but also ensures the consistency and repeatability of the identification process. By calculating the comprehensive abnormality of trade and setting pre-set identification standards, potential abnormal trade behaviors can be detected and warned in a timely manner, helping to take timely measures to prevent and mitigate risks, maintain market order and protect interests. This solves the problem in existing technologies where manual screening is subject to strong subjective factors, making it difficult to form unified standards in screening rules and methods, which affects the accuracy and reliability of identification.
[0058] Example Two
[0059] Based on the above embodiments, before the steps of acquiring basic trade data and establishing a target trade chain based on the basic data, the method further includes: acquiring multiple transaction documents within a target time period; identifying each transaction document based on preset identification rules to obtain the trade chain path corresponding to each transaction document; classifying each trade chain path according to attributes to generate trade chain templates with different attributes; and integrating the trade chain templates to obtain the trade chain library.
[0060] In this embodiment, the trade chain library uses predefined and standardized trade chain templates to enable rapid matching and location of the corresponding templates when identifying and analyzing trade chain attributes, thereby greatly reducing repetitive work and manual analysis time and improving the efficiency of abnormal trade identification.
[0061] Specifically, the system retrieves all relevant transaction documents for a specific time period (e.g., one year, one quarter, or one month). These documents record all of the company's transactions during this period, including but not limited to sales contracts, purchase orders, invoices, logistics documents, and payment vouchers. To extract useful information from a large volume of transaction documents, a series of identification rules need to be pre-defined. These rules can be based on document type, content, format, or keywords to automatically or manually identify key information in the documents, such as the transacting parties, product information, transaction amount, and transaction time. For example, identification rules include: identifying the buyer, seller, product name, quantity, unit price, and total price in a sales contract; extracting supplier information, purchased goods, quantity, and delivery date from a purchase order; and identifying the invoice number, invoice date, amount, and tax amount on an invoice. Using these rules, the system can automatically extract key information from each document, preparing for subsequent steps.
[0062] After identifying the key information in each document, this information can be further analyzed to construct the complete path of each transaction from start to finish, i.e., the trade chain path. Subsequently, these trade chain paths are classified based on certain common attributes in the paths (such as commodity type, transaction region, transaction method, etc.).
[0063] In one embodiment, the trade chain attributes in the trade chain database include at least one of the following: idle transaction attribute, order processing attribute, and financing attribute. The idle transaction attribute identifies transaction links that lack physical flow and are completed solely through fund circulation and falsified documents. The order processing attribute identifies links where documents do not match actual transactions, indicating potential fraud risks. The financing attribute identifies transaction links whose primary purpose is financing and carries potential financial risks. These different attributes collectively contribute to the complexity and diversity of trade chains. By identifying and analyzing these attributes, it is possible to better understand the operational mechanisms of trade chains, assess potential risks, and formulate corresponding optimization strategies to reduce financial risks.
[0064] Example Three
[0065] Based on the above embodiments, the step of comparing the target trade chain with a preset trade chain library to determine the trade chain attribute of the trade chain includes: traversing each node of the target trade chain using a depth-first search algorithm; comparing the similarity of each node with each node in the trade chain template, determining the trade chain template corresponding to the highest similarity as the trade chain template matching the target trade chain, and determining the attribute of the matching trade chain template as the trade chain attribute.
[0066] In this embodiment, the target trade chain is compared with a pre-defined trade chain database to more accurately and quickly determine the trade chain attributes. The comparison process combines a depth-first search (DFS) algorithm and similarity comparison technology, aiming to extract key attributes from complex trade data to facilitate analysis, monitoring, and optimization.
[0067] Depth-First Search (DFS) is an algorithm used to traverse or search a tree or graph. In this embodiment, it is used to traverse each node of the target trade chain. Starting from the initial node, the algorithm searches as deep as possible along a path until it reaches a leaf node or cannot continue. Then, it backtracks to the previous node and continues exploring other unexplored paths, thus systematically visiting every node in the target trade chain and ensuring that no important information is missed.
[0068] During the traversal, each node of the target trade chain is compared with each template node in the trade chain library for similarity. Similarity comparison can be based on various factors, such as node type, transaction amount, trading partners, and timestamps. By calculating a similarity score, the trade chain template that best matches the current target trade chain can be determined. The similarity score can be calculated using a weighted average, distance metrics (such as Euclidean distance or Manhattan distance), or more complex machine learning models. Once the trade chain template with the highest match to the target trade chain is found, the trade chain attributes of that trade can be determined, such as whether it is an idle trading attribute, a one-way trading attribute, or a financing attribute.
[0069] The trade chain attribute determination method in this embodiment, by combining DFS and similarity comparison technology, can automatically identify trade chain attributes in a target trade chain, improving processing efficiency and accuracy. Simultaneously, the pre-set trade chain database can be expanded and updated according to actual needs to adapt to the ever-changing trade environment and market trends. By identifying trade chains with high-risk attributes (such as empty transactions or unauthorized transactions), timely risk warnings and control measures can be provided to enterprises.
[0070] Example Three
[0071] Based on the above embodiments, the step of obtaining the anomaly identification indicators corresponding to the trade chain attribute and the weights corresponding to each anomaly identification indicator includes: obtaining the primary anomaly indicator corresponding to the trade chain attribute and the secondary anomaly indicators subordinate to the primary anomaly indicator, wherein the secondary anomaly indicator is the anomaly identification indicator; determining the first weight corresponding to each primary anomaly indicator and the second weight corresponding to each secondary anomaly indicator based on the impact of each primary anomaly indicator and the secondary anomaly indicator on the anomaly risk, wherein the sum of the second weights of each secondary anomaly indicator belonging to the same primary anomaly indicator is 1.
[0072] In this embodiment, primary anomaly indicators refer to high-level, general anomaly types or risk categories directly related to the trade chain attributes, providing a macro perspective for identifying potential risks. For example, primary anomaly indicators could include trading partners, order information, and settlement methods. Secondary anomaly indicators are specific anomaly points or risk manifestations further subdivided under primary anomaly indicators. They are a concretization and quantification of primary anomaly indicators, used to more accurately identify and assess risks. For example, if the trade chain attribute is determined to be order-based, the primary anomaly indicator for order-based trade is determined to be the trading partner (first weight 20%), and the secondary anomaly indicators are subdivided into upstream and downstream relationship anomalies (second weight 80%) and customer credit anomalies (second weight 20%).
[0073] In one embodiment, the secondary anomaly indicators can be further refined into tertiary anomaly indicators, which then serve as anomaly identification indicators. When calculating the overall anomaly score, a weighted summation is performed layer by layer to obtain the overall anomaly score. For example, the secondary anomaly indicator of customer credit anomaly is further subdivided into three tertiary anomaly indicators: trading counterparties, counterparties rated below A, and historically overdue counterparties; the upstream and downstream relationship anomaly is further subdivided into three tertiary anomaly indicators: same group, same senior management, and equity-related relationships. According to the preset anomaly score calculation rules, the anomaly score for trading counterparties is calculated as C1, for counterparties rated below A as C2, for historically overdue counterparties as C3, for same group as K1, for same senior management as K2, and for equity-related relationships as K3. The overall anomaly score P is then calculated as follows:
[0074] P=[(C1+C2+C3)*20%+(K1+K2+K3)*80%]*20%
[0075] This embodiment uses a multi-level classification of anomaly indicators, with each level further refining and deepening the previous level, allowing for a more detailed differentiation of different types of anomalies. Different levels of anomaly indicators represent different levels of risk or problem. Level 1 indicators provide an overall overview, while level 2 and 3 indicators delve into specific details. This hierarchical structure makes the assessment process more organized, helping decision-makers grasp the essence and severity of problems at different levels, making the identification process more systematic and comprehensive, thereby improving the accuracy of anomaly identification.
[0076] Example Four
[0077] Based on the above embodiments, this embodiment provides an application example that uses big data and other technologies to establish an abnormal trade identification model based on enterprise trade business documents, such as idle transactions, order processing, and financing trade. This model enables full-process management of abnormal trade, including pre-event simulation and prevention, in-event early warning and alerts, and post-event review and analysis, thereby improving the monitoring level of abnormal trade, reducing the frequency of abnormal trade, and reducing large-scale financial losses for enterprises.
[0078] The abnormal trade identification model system is the core of the application, comprising four main components: basic data cleaning, trade chain identification, abnormal indicator rule calculation, and abnormal trade identification. It acquires key data for trade chain identification, such as contract data, purchase and sales orders, inbound and outbound material vouchers, and purchase and sales invoices, and performs data correlation across the entire purchase and sales process. Using the DFS algorithm, it identifies trade chains based on key elements such as materials, materials + batches, and dates, generating trade chain data for one-to-one, one-to-many, many-to-one, many-to-many, closed loops, and open loops. Based on the abnormal trade characteristic indicator system (i.e., the abnormal indicator library in the above embodiments), it calculates trade chain-related characteristic indicators and establishes characteristic rule models based on the abnormal trade characteristic rule system, setting thresholds for abnormal characteristic indicators. Through abnormal trade case analysis and combined with business expert experience, it establishes a characteristic rule model system, forming identification models for idle orders and financing trade, generating an abnormal list to support further review and analysis of abnormal trade chains by enterprises and relevant business departments. For atypical abnormal situations, custom characteristic rules can be used, combined with custom identification models, to generate a custom suspected list.
[0079] Specifically, it includes the following steps:
[0080] 1. Data preparation: Retrieve key fields from basic business data to obtain five major categories of information, including counterparties, contracts, orders, transfer of ownership, and settlement information, and connect them according to business processes to form a data flow for the entire procurement and sales process.
[0081] 2. Trade Chain Identification: Utilizing big data algorithms to deeply mine transaction documents over a specific period, identification is performed based on rules such as purchase and sales quantity, price, upstream and downstream relationships, and capital occupation. These are then categorized into broad trade chains suspected of being idle, merely for transaction purposes, or involving financing, forming a trade chain database. For example... Figure 2 The image shown is a schematic diagram of a portion of the trade chain templates in the trade chain library.
[0082] 3. Anomaly Indicator Rule Calculation: By summarizing and generalizing from case knowledge bases, management methods, internal control systems, and expert experience databases, 5 major categories, 8 subcategories, and 30 anomaly characteristic indicators are formed to further identify anomalies in the trade chain and screen abnormal information such as contracts, logistics, and gross profit. For example... Figure 3 As shown, the specific classification details of the anomaly identification indicators in the embodiment are further refined layer by layer according to the first-level anomaly indicators, the second-level anomaly indicators, and the third-level anomaly indicators.
[0083] 4. Abnormal Trade Identification: Establish an abnormal trade identification model. By setting indicator thresholds, combining abnormal labels, and configuring weights, a more accurate list of abnormal trades (i.e., a combination of abnormal identification indicators) is generated. This list is then submitted to the company's business department, finance department, audit department, etc., for further verification of abnormal trade clues and to determine the compliance of abnormal trades.
[0084] 5. Model Configuration: Different weights are assigned to the three levels of indicators, and different scores are allocated based on the importance of each indicator. Finally, anomaly scores are assigned to trade transactions, and trade leads with high anomaly scores are marked as anomalous trade leads. For example, a general anomaly identification model is configured, and the configuration of its anomaly indicators at each level and their corresponding scores are shown in the table below:
[0085]
[0086] In this table, the percentage of the first-level anomaly indicator has the first weight, the percentage of the second-level anomaly indicator has the second weight, and the percentage before the third-level anomaly indicator represents the anomaly probability. Correspondingly, the anomaly degree of each third-level anomaly indicator (or anomaly identification indicator) is the corresponding indicator score multiplied by the corresponding anomaly probability. The final calculated comprehensive anomaly degree based on the above table is 95 points.
[0087] In this embodiment, a yellow alert can be set for a comprehensive anomaly score between 80 and 89.99, and a red alert for scores above 90. That is, when the comprehensive anomaly score is 95, the system issues a red alert, indicating that the anomaly score of the trade is extremely high.
[0088] Furthermore, an abnormal trade monitoring and application system will be established using an abnormal trade identification model. Specifically, this system will encompass "prevention, control during the process, and review afterward" to achieve comprehensive monitoring of the entire trade process, effectively improving management accuracy and efficiency, and reducing losses from fraudulent trade activities. Details are as follows:
[0089] (1) Pre-contract risk retrieval: Addressing the difficulties faced by business personnel in identifying risks in practice, the business simulation function and counterparty association query function resolve the issue of business personnel's judgment before contract signing. For key elements such as related or specific interest relationships between upstream and downstream enterprises, it eliminates business risks with obvious anomalies at the source. The counterparty association query function directly queries the upstream and downstream relationships of counterparties, effectively screening for risk information such as abnormal counterparty relationships. The business simulation function, based on a trade chain model, uses simulated data such as transaction type, supplier and customer basic information, and an abnormal trade identification model to identify and screen for abnormal indicators such as risky enterprises.
[0090] When querying the upstream and downstream relationships of trading partners, various query methods such as enterprises and individuals can be used to screen the relationships of the trading partners involved. Based on the screening results, a concise explanation of the relationship between enterprises is output, and a graph of the relationship between trading partners is displayed to assist in the query.
[0091] (2) In-process monitoring and early warning: For ongoing trade transactions, abnormal characteristics are judged at different stages according to the progress of the business. Documents with high abnormality are monitored and warned in a timely manner. After receiving the warning information, business personnel, financial personnel and risk control personnel can verify the warning information. Business personnel take measures such as suspending delivery and stopping payment in a timely manner for suspicious trades, and conduct offline investigations at the same time to effectively reduce the transaction risks of procurement and sales business and reduce the possibility of false trades.
[0092] (3) Post-event inspection and analysis: For trade chains composed of historical business data, abnormal trade chains are identified and a suspected list is generated through a public identification model. Users can view the details of the analysis results and chart analysis, and promptly investigate and deal with them. At the same time, users can flexibly configure identification tags and indicator thresholds according to various situations to realize self-service query and analysis of trade chain information, as well as custom investigation of abnormal trades.
[0093] In this embodiment, a clue details display function is also provided. Through this function, users can view the entire procurement and sales process and intuitively see the transaction links where problems occur, helping users to conduct in-depth investigation and analysis.
[0094] Example Five
[0095] Based on the above embodiments, such as Figure 4As shown, this embodiment provides a device for identifying abnormal trade, including:
[0096] The trade chain construction module 410 is used to acquire basic data of the trade to be detected and to establish a target trade chain based on the basic data.
[0097] The trade chain attribute determination module 420 is used to compare the target trade chain with a preset trade chain database to determine the trade chain attribute of the trade.
[0098] Anomaly identification index determination module 430 is used to obtain anomaly identification indexes corresponding to the trade chain attributes, and the weights corresponding to each anomaly identification index.
[0099] Anomaly calculation module 440 is used to determine the anomaly degree of each anomaly identification indicator based on a preset anomaly calculation rule, and to calculate the comprehensive anomaly degree of the trade based on the anomaly degree of each anomaly identification indicator and the weight corresponding to each anomaly identification indicator.
[0100] The judgment module 450 is used to determine that the trade is abnormal trade when the comprehensive anomaly degree does not meet the preset identification criteria.
[0101] In one embodiment, it also includes:
[0102] The acquisition module is used to acquire multiple transaction documents within a target time period;
[0103] The link identification module is used to identify each of the transaction documents based on preset identification rules to obtain the trade chain path corresponding to each of the transaction documents.
[0104] The trade chain library construction module is used to classify each trade chain path according to its attributes, generate trade chain templates with different attributes, and integrate the trade chain templates to obtain the trade chain library.
[0105] In one embodiment, the trade chain attribute determination module includes:
[0106] The node retrieval unit is used to traverse each node of the target trade chain using a depth-first search algorithm;
[0107] The comparison unit is used to compare the similarity of each node with each node in the trade chain template, determine the trade chain template with the highest similarity as the trade chain template that matches the target trade chain, and determine the attribute of the matched trade chain template as the trade chain attribute.
[0108] In one embodiment, the anomaly identification indicator determination module includes:
[0109] The indicator determination unit is used to obtain the primary abnormal indicator corresponding to the trade chain attribute, and the secondary abnormal indicator under the primary abnormal indicator, wherein the secondary abnormal indicator is the abnormal identification indicator.
[0110] The weight determination unit is used to determine the first weight corresponding to each of the first-level abnormal indicators and the second weight corresponding to each of the second-level abnormal indicators based on the degree of influence of each of the first-level abnormal indicators and the second-level abnormal indicators on the abnormal risk, wherein the sum of the second weights of the second-level abnormal indicators belonging to the same first-level abnormal indicator is 1.
[0111] In one embodiment, the anomaly calculation module includes:
[0112] The indicator threshold acquisition unit is used to acquire the indicator threshold of each of the anomaly identification indicators;
[0113] An anomaly calculation unit is used to compare the actual value of each anomaly identification indicator with the corresponding indicator threshold, and determine the anomaly degree of each anomaly identification indicator based on the comparison result.
[0114] Specific limitations regarding the identification device for irregular trade can be found in the limitations of the identification method for irregular trade described above, and will not be repeated here. Each unit in the aforementioned identification device for irregular trade can be implemented entirely or partially through software, hardware, or a combination thereof. These units can be embedded in the processor of the irregular trade identification system in hardware form or independent of it, or stored in the memory of the irregular trade identification system in software form, so that the processor can call and execute the corresponding operations of each unit.
[0115] Example Six
[0116] Based on the above embodiments, this embodiment provides an abnormal trade identification system, including a memory, a processor, and a computer program stored in the memory, wherein the processor executes the computer program to implement the method described in the above embodiments.
[0117] In some embodiments of this example, a computer-readable storage medium is provided, on which a computer program is stored, which, when executed by a processor, implements the methods described in the above embodiments.
[0118] In some embodiments of this example, a computer program product is provided, including a computer program that, when executed by a processor, implements the methods described in the above embodiments.
[0119] The processor may include, but is not limited to, one or more processors or microprocessors. Each processor may be implemented as an Application Specific Integrated Circuit (ASIC), Digital Signal Processor (DSP), Digital Signal Processing Device (DSPD), Programmable Logic Device (PLD), Field Programmable Gate Array (FPGA), controller, microcontroller, microprocessor, or other electronic component, for executing the methods in the above embodiments.
[0120] Computer-readable storage media can be implemented by any type of volatile or non-volatile storage device or a combination thereof. Computer-readable storage media may include, but are not limited to, random access memory (RAM), read-only memory (ROM), flash memory, EPROM memory, EEPROM memory, registers, and computer storage media (e.g., hard disks, floppy disks, solid-state drives, removable disks, Blu-ray discs, etc.).
[0121] Computer-readable storage media may also store at least one computer-executable program, such as computer-readable instructions. Computer-readable storage media include, but are not limited to, volatile memory and / or non-volatile memory. Volatile memory may include, for example, random access memory (RAM) and / or cache memory. Computer-readable storage media may include, for example, read-only memory (ROM), hard disk, flash memory, etc. For example, a non-transitory computer-readable storage medium may be connected to a computing device such as a computer, and then, when the computing device executes the computer-readable instructions stored on the computer-readable storage medium, the various methods described above can be performed.
[0122] In addition, the system for identifying abnormal trades may also include (but is not limited to) a data bus, an input / output (I / O) bus, a display, and input / output devices (e.g., keyboard, mouse, speaker, etc.).
[0123] The processor can communicate with external devices via the I / O bus through wired or wireless networks.
[0124] In one embodiment, the at least one computer-executable instruction may also be compiled into or comprise a software product / computer program product, wherein one or more computer-executable instructions are executed by a processor to perform the steps of the various functions and / or methods in the embodiments described herein.
[0125] In the embodiments provided in this disclosure, it should be understood that the disclosed apparatus and methods can also be implemented in other ways. The apparatus embodiments described above are merely illustrative; for example, the flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of apparatus, methods, and computer program products according to various embodiments of this disclosure. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than those marked in the drawings. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram and / or flowchart, and combinations of blocks in block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or action, or using a combination of dedicated hardware and computer instructions.
[0126] It should be noted that, in this disclosure, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitation, an element limited by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.
[0127] While the embodiments disclosed herein are as described above, the foregoing content is merely for the purpose of facilitating understanding of this disclosure and is not intended to limit this disclosure. Any person skilled in the art to which this disclosure pertains may make any modifications and changes in form and detail of the implementation without departing from the spirit and scope of this disclosure; however, the scope of patent protection of this disclosure shall still be determined by the scope defined in the appended claims.
Claims
1. A method for identifying abnormal trade, characterized in that, include: Obtain basic data on the trade to be detected, and establish the target trade chain based on the basic data; The target trade chain is compared with a preset trade chain database to determine the trade chain attributes of the trade. Obtain the anomaly identification indicators corresponding to the trade chain attributes, and the weights corresponding to each anomaly identification indicator; Based on the preset anomaly calculation rules, the anomaly degree of each anomaly identification indicator is determined, and the comprehensive anomaly degree of the trade is calculated according to the anomaly degree of each anomaly identification indicator and the weight corresponding to each anomaly identification indicator. When the overall anomaly degree does not meet the preset identification criteria, the trade is determined to be an abnormal trade.
2. The method according to claim 1, characterized in that, Before the step of acquiring basic trade data and establishing a target trade chain based on the basic data, the following steps are also included: Retrieve multiple transaction documents within a target time period; Based on preset identification rules, each of the transaction documents is identified to obtain the trade chain path corresponding to each of the transaction documents; Each trade chain path is classified according to its attributes, and trade chain templates with different attributes are generated. The trade chain templates are then integrated to obtain the trade chain library.
3. The method according to claim 2, characterized in that, The step of comparing the target trade chain with a preset trade chain database to determine the trade chain attributes includes: The target trade chain is traversed using a depth-first search algorithm; Each node is compared with each node in the trade chain template in terms of similarity. The trade chain template with the highest similarity is determined as the trade chain template that matches the target trade chain. The attribute of the matched trade chain template is determined as the trade chain attribute.
4. The method according to claim 1, characterized in that, The trade chain attributes in the trade chain library include at least one of the following: idle circulation attribute, order processing attribute, and financing attribute.
5. The method according to claim 1, characterized in that, The step of obtaining the anomaly identification indicators corresponding to the trade chain attributes, and the weights corresponding to each anomaly identification indicator, includes: Obtain the primary anomaly indicator corresponding to the trade chain attribute, and the secondary anomaly indicator subordinate to the primary anomaly indicator, wherein the secondary anomaly indicator is the anomaly identification indicator. Based on the impact of each primary and secondary anomaly indicator on the anomaly risk, a first weight corresponding to each primary anomaly indicator and a second weight corresponding to each secondary anomaly indicator are determined, wherein the sum of the second weights of each secondary anomaly indicator belonging to the same primary anomaly indicator is 1.
6. The method according to claim 1, characterized in that, The basic data for trade includes at least one of the following: counterparty data, contract data, order data, transfer of ownership data, and settlement data.
7. The method according to any one of claims 1-6, characterized in that, The step of determining the anomaly degree of each anomaly identification index based on a preset anomaly degree calculation rule includes: Obtain the threshold values for each of the aforementioned anomaly identification indicators; The actual value of each anomaly identification indicator is compared with the corresponding indicator threshold, and the anomaly degree of each anomaly identification indicator is determined based on the comparison result.
8. A system for identifying irregular trade, comprising a memory, a processor, and a computer program stored in the memory, characterized in that, The processor executes the computer program to implement the method of any one of claims 1 to 7.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the method of any one of claims 1 to 7.
10. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the method of any one of claims 1 to 7.