A method, device and medium for discovering clues of illegal financial activities

By collecting and analyzing data from fund transactions, publicly available internet information, and complaints, and by utilizing multi-category identification models and correlation analysis, the problem of delayed early detection of clues to illegal financial activities has been solved, enabling efficient risk monitoring and precise location, and improving regulatory efficiency.

CN122115102APending Publication Date: 2026-05-29天元大数据信用管理有限公司

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
天元大数据信用管理有限公司
Filing Date
2026-01-16
Publication Date
2026-05-29

AI Technical Summary

Technical Problem

Existing methods for discovering clues to illegal financial activities suffer from limitations such as relying on a single source of clues, insufficient automated collection and identification, difficulty in comprehensively monitoring publicly available internet data, and a lack of multi-dimensional feature analysis. This results in delayed early risk detection and insufficient targeted risk prevention and control.

Method used

Collect fund transaction data, publicly available internet data, and complaint and report data; use multi-category identification models to screen suspected clues of illegal financial activities; conduct correlation analysis; and generate a list of clues of illegal financial activities and reports of abnormal related accounts.

Benefits of technology

It has achieved comprehensive access to leads and early risk discovery, improved the efficiency of lead identification and the targeting of risk prevention and control, reduced the workload of regulatory personnel, and optimized the allocation of regulatory resources.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122115102A_ABST
    Figure CN122115102A_ABST
Patent Text Reader

Abstract

The application discloses a method, device and medium for discovering clues of illegal financial activities. The method comprises the following steps: collecting fund transaction data, Internet public data and complaint reporting data; based on a preset multi-category identification model, the fund transaction data, the Internet public data and the complaint reporting data are respectively screened in a targeted manner to obtain a plurality of suspected illegal financial activity clue data; the suspected illegal financial activity clue data is analyzed and processed through a preset logical rule to obtain illegal financial activity clues and correlation data; and based on the illegal financial activity clues and the correlation data, an illegal financial activity clue list and an abnormal correlation account report are generated. The method improves the clue identification efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of financial risk monitoring and data mining technology, and in particular to a method, device and medium for discovering clues to illegal financial activities. Background Technology

[0002] In the current financial market environment, illegal financial activities, such as illegal fundraising, are characterized by high concealment, rapid spread, and dispersed sources of information, posing significant challenges to financial supervision and risk prevention. Existing methods for detecting clues to illegal financial activities are clearly inadequate.

[0003] On the one hand, existing sources of clues about illegal financial activities are relatively limited, relying mostly on manual reports or offline investigations. This makes it difficult to cover the massive amounts of publicly available internet data, such as online advertisements, negative public opinion, and forum posts, thus failing to meet the needs of comprehensive monitoring. Furthermore, the large number of potential clues contained within this publicly available internet data is difficult to fully explore and utilize due to the lack of automated collection and identification mechanisms, directly leading to delays in early risk detection.

[0004] On the other hand, the identification of illegal financial activities lacks multi-dimensional feature analysis and intelligent discrimination models. Even if some data is obtained, it is impossible to efficiently filter out high-quality clues. In particular, when faced with complex transaction data such as abnormal fund movements, traditional manual analysis methods are not only inefficient, but also prone to missing key anomalies.

[0005] On the other hand, existing technologies have not achieved correlation analysis of multi-source clues, and cannot link abnormal fund movements, public opinion information, advertising content, whistleblower data, etc., making it difficult to accurately locate the main body and related accounts of illegal financial activities, resulting in insufficient targeting and effectiveness of risk prevention and control. Summary of the Invention

[0006] This application provides a method, device, and medium for discovering clues to illegal financial activities, which addresses the problems existing in the above-mentioned methods for discovering clues to illegal financial activities.

[0007] The embodiments of this application adopt the following technical solutions: On the one hand, embodiments of this application provide a method for discovering clues to illegal financial activities, the method comprising: Collect data on fund transactions, publicly available internet data, and complaint / reporting data; Based on a pre-set multi-category identification model, the fund transaction data, the publicly available Internet data, and the complaint and report data are targeted and filtered to obtain multiple clues of suspected illegal financial activities. By performing correlation analysis on suspected illegal financial activity clues data through preset logical rules, we can obtain clues to illegal financial activities and related relationship data. Based on the clues to illegal financial activities and the related relationship data, a list of clues to illegal financial activities and a report on abnormal related accounts are generated.

[0008] In one example, the collection of fund transaction data, publicly available internet data, and complaint / report data specifically includes: By using a pre-defined financial institution account interface, the system obtains fund transaction data from corporate accounts and accounts of relevant corporate personnel. Based on a pre-defined high-frequency term database of illegal financial activities, keyword-targeted retrieval and extraction are performed on publicly available data from the internet platform to obtain publicly available internet data that includes the characteristics of illegal financial activities. According to the preset collection frequency, the content of specific channels or sections of the preset target platform is fully crawled to obtain publicly available Internet data, including advertisements and public opinion information. Collect complaint and reporting data from regulatory departments at all levels through their reporting and complaint channels.

[0009] In one example, the preset multi-category recognition model is used to specifically filter the fund transaction data, the publicly available internet data, and the complaint and report data to obtain multiple clues of suspected illegal financial activities, specifically including: Based on preset abnormal transaction rules, the fund transaction data is verified one by one according to the reporting cycle. If the fund transaction data meets any of the abnormal transaction rules, the account transaction data corresponding to the fund transaction data is marked as suspected illegal financial activity clue data of abnormal fund movement. Extract relevant speech data of enterprises and their executives from publicly available Internet data, and use sentiment analysis algorithms to determine the polarity of the relevant speech data to obtain public opinion sentiment data. The proportion of negative public opinion data in the public opinion data is statistically analyzed. When the proportion of negative public opinion data is higher than a preset standard threshold, the relevant remarks data of the enterprise and its executives corresponding to the negative public opinion data are marked as suspected illegal financial activity clues data of negative public opinion. Using a pre-set advertising identification model, it is determined whether the advertising content in the publicly available Internet data has illegal advertising characteristics. Advertising content with illegal advertising characteristics and the relevant data of the corresponding companies are marked as suspected illegal financial activity clues in the category of online advertising. The complaint and report data is processed by feature extraction. A preset machine learning model is used to determine the correlation between the extracted features and illegal financial activities. When the correlation reaches a preset threshold, the information of the risky enterprises and related personnel corresponding to the complaint and report data is marked as suspected illegal financial activity clues in the complaint and report category.

[0010] In one example, the abnormal transaction rules include: The total number of transfers and / or remittances in the current reporting period is greater than or equal to a preset multiple of the total number of transfers and / or remittances in the previous reporting period, wherein the first reporting period is based on the previous calendar month. The number of transfers within the reporting period meets the preset number requirement, and the number of expenditures and the number of transfers meet the preset ratio. The number of transfers and / or remittances exceeding the preset ratio satisfies the income and expenditure matching relationship where the inflow amount meets the preset low standard and the outflow amount meets the preset high standard; In non-interbank transfers, the user identity characteristics of remittance accounts exceeding a preset percentage meet preset conditions, including age and gender extracted from ID card numbers; The number of transactions completed through third-party payment platforms within the reporting period that meet the preset large-amount threshold.

[0011] In one example, the process of performing correlation analysis on suspected illegal financial activity clues data through preset logical rules to obtain illegal financial activity clues and related relationship data specifically includes: Based on preset logical rules, extract details of abnormal fund movements from abnormal accounts in the data of suspected illegal financial activities related to fund anomalies; The details of the abnormal fund movements are matched with a preset specific transfer pattern to filter out suspected illegal financial activity clues that match the specific transfer pattern. Correlation analysis is performed on the abnormal accounts corresponding to the suspected illegal financial activities related to the abnormal fund movements, the companies to which the abnormal accounts belong, the individuals associated with the abnormal accounts, and the related accounts that have direct financial transactions with the abnormal accounts, in order to obtain multi-dimensional correlation data; Cross-category comparative analysis is conducted on data of suspected illegal financial activities related to negative public opinion, suspected illegal financial activities related to online advertising, and suspected illegal financial activities related to complaints and reports. Clues that are suspected of being related to illegal financial activities in two or more categories and that point to the same entity and whose core information corroborates each other are considered. The aforementioned clues will be used as leads for illegal financial activities.

[0012] In one example, generating a list of illegal financial activity leads and a report of abnormal related accounts based on the illegal financial activity leads and the correlation data specifically includes: The clues to illegal financial activities are classified and organized according to clue type, and the core information of each clue is extracted. Based on the aforementioned relationship data, the hierarchical relationships between abnormal accounts, the companies to which the abnormal accounts belong, the individuals associated with the abnormal accounts, and the related accounts with direct financial transactions with the abnormal accounts are clarified, forming a relationship graph data; According to the preset standardized format, the core information of the classified clues is integrated into a list of clues to illegal financial activities; The relationship graph data is integrated with the list of clues to illegal financial activities to obtain an abnormal related account report.

[0013] In one example, the method further includes: Regularly collect and report data on regulatory verification results; The accuracy and recall of the multi-category identification model are calculated based on the feedback data of the regulatory verification results. When the accuracy is lower than a preset accuracy threshold and / or the recall is lower than a preset recall threshold, the corresponding recognition model is retrained and optimized. Based on the characteristics of new types of illegal financial activities and changes in regulatory policies, we update the high-frequency terminology database for illegal financial activities and the rules for abnormal transactions.

[0014] In one example, the method further includes: The collected fund transaction data, publicly available internet data, and complaint and report data are encrypted during storage and transmission; A hierarchical access control mechanism is adopted to manage access to fund transaction data, publicly available internet data, and complaint and reporting data.

[0015] On the other hand, embodiments of this application provide an apparatus for detecting clues to illegal financial activities, comprising: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, the instructions being executed by the at least one processor to enable the at least one processor to perform any of the above-described methods for detecting clues to illegal financial activities.

[0016] On the other hand, embodiments of this application provide a non-volatile computer storage medium for discovering clues to illegal financial activities, which stores computer-executable instructions capable of executing any of the above-described methods for discovering clues to illegal financial activities.

[0017] The above-described technical solutions adopted in the embodiments of this application can achieve the following beneficial effects: The method provided in this application incorporates a vast amount of potential leads into the monitoring scope by collecting fund transaction data, publicly available internet data, and complaint and report data. This solves the problems of limited lead sources and delayed early risk detection in existing technologies, and achieves comprehensive lead sources and early risk detection.

[0018] By building dedicated recognition models for different data types and combining multi-dimensional features, automated screening is achieved through rule verification and intelligent algorithms, which greatly improves the efficiency of clue recognition, reduces false positive clues, strengthens the ability to process complex data, and effectively solves the problems of low recognition efficiency and difficulty in screening high-quality clues in existing technologies.

[0019] By performing correlation analysis on suspected illegal financial activity clues, the limitations of existing technologies in silencing multi-source clues are overcome. This allows for the precise identification of core entities, related personnel, and accounts involved in illegal financial activities, thereby enhancing the credibility of clues and the targeted nature of risk prevention and control, and addressing the issues of insufficient targeting and effectiveness in risk prevention and control.

[0020] By organizing information in a structured manner to form a standardized list of clues and constructing a visual relationship graph, the problems of non-standard output of existing technical clues and disconnection from regulatory needs are avoided. This significantly reduces the workload of regulatory personnel, helps optimize the allocation of regulatory resources, provides full-cycle support for early warning and follow-up of illegal financial activities, and effectively improves the efficiency and effectiveness of regulatory work. Attached Figure Description

[0021] To more clearly illustrate the technical solution of this application, some embodiments of this application will be described in detail below with reference to the accompanying drawings, in which: Figure 1 A flowchart illustrating a method for discovering clues to illegal financial activities provided in this application embodiment; Figure 2 This is a schematic diagram of the structure of a device for detecting clues to illegal financial activities provided in an embodiment of this application. Detailed Implementation

[0022] To make the objectives, technical solutions, and advantages of this application clearer, the technical solutions of this application will be clearly and completely described below in conjunction with specific embodiments and corresponding drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of them. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0023] Some embodiments of this application will now be described in detail with reference to the accompanying drawings.

[0024] Figure 1This is a flowchart illustrating a method for discovering clues to illegal financial activities, provided in an embodiment of this application. This method can be applied to different business areas, such as internet finance. The process can be executed by computing devices in the corresponding field (e.g., risk control servers or smart mobile terminals for payment services). Certain input parameters or intermediate results in the process can be manually adjusted to help improve accuracy.

[0025] The analysis method involved in the embodiments of this application can be implemented by a terminal device or a server, and this application does not impose any special limitations on it. For ease of understanding and description, the following embodiments are all described in detail using a server as an example.

[0026] It should be noted that the server can be a single device or a system composed of multiple devices, i.e., a distributed server. This application does not make any specific limitations on this.

[0027] Figure 1 The process includes the following steps: S101. Collect fund transaction data, publicly available internet data, and complaint and report data.

[0028] In some embodiments of this application, fund transaction data of corporate accounts and accounts of corporate personnel are obtained through a preset financial institution account interface.

[0029] The financial transaction data may include, for example, the number of transfers / remittances, the amount, the transaction counterparty, the transaction time, and the remitter's identity characteristics.

[0030] Optionally, in addition to using financial institution account interfaces, it is also possible to connect to authorized third-party payment platform data interfaces to obtain data through encrypted transmission protocols such as SSL / TLS, ensuring data transmission security.

[0031] Based on a pre-defined high-frequency keyword database for illegal financial activities, targeted keyword searches are performed on publicly available data from internet platforms to obtain publicly available internet data containing characteristics of illegal financial activity promotion. Following a pre-defined collection frequency, a full traversal of content from specific channels or sections of pre-defined target platforms is performed to obtain publicly available internet data including advertising and public opinion information.

[0032] Among them, the Internet platform refers to the platform that gathers information on illegal financial activities. The high-frequency term database for illegal financial activities may include terms such as high rate of return and guaranteed principal and interest.

[0033] By employing both keyword-targeted retrieval and full-volume crawling of specific channels / sections in parallel, we can ensure coverage of various potential leads, including advertisements, negative public opinion, and user reports. It should be noted that the crawling process must comply with the robots.txt protocol to avoid unauthorized data collection.

[0034] Collect complaint and reporting data from regulatory departments at all levels through their reporting and complaint channels.

[0035] S102. Based on a preset multi-category identification model, targeted screening is performed on fund transaction data, publicly available Internet data, and complaint and report data to obtain multiple clues of suspected illegal financial activities.

[0036] Among them, multi-category recognition models refer to dedicated recognition models built for different data types. For example, they may include fund movement recognition models based on abnormal transaction rules, negative public opinion recognition models driven by sentiment analysis algorithms, pre-trained advertising recognition models, and complaint and report recognition models driven by machine learning.

[0037] In some embodiments of this application, based on preset abnormal transaction rules, fund transaction data is verified one by one according to the reporting cycle. If the fund transaction data meets any abnormal transaction rule, the account transaction data corresponding to the fund transaction data is marked as suspected illegal financial activity clue data of abnormal fund movement.

[0038] Among them, the abnormal transaction rules refer to the quantitative judgment standards preset based on the characteristics of fund flow in illegal financial activities, which are used to accurately identify abnormal account transaction behavior.

[0039] Abnormal transaction rules may include, for example, a preset multiple by which the total number of transfers and / or remittances in the current reporting period is greater than or equal to the total number of transfers and / or remittances in the previous reporting period, where the first reporting period is based on the previous calendar month. For example, the total number of transfers and / or remittances in the current reporting period is greater than or equal to 5 times that of the previous period.

[0040] The number of transfers within the reporting period meets the preset number requirement, and the number of expenditures and the number of transfers meet the preset ratio. For example, the number of transfers within the reporting period is greater than or equal to 100, and the number of expenditures is less than 1 / 20 of the number of transfers.

[0041] A predetermined percentage or higher proportion of transfers and / or remittances meet the minimum threshold for incoming transfers and the maximum threshold for outgoing transfers, ensuring a proper balance between income and expenditure. For example, 90% or more of the transfers and / or remittances meet the following criteria: incoming transfers are less than or equal to RMB 100,000, and outgoing transfers are greater than or equal to RMB 1 million for private transactions and greater than or equal to RMB 2 million for corporate transactions.

[0042] In non-interbank transfers, the user identity characteristics of remittance accounts exceeding a predetermined percentage meet predetermined conditions. These user identity characteristics include age and gender extracted from the ID card number. For example, in non-interbank transfers, 90% or more of the remittance account users are over 55 years old or male, and the 17th digit of their ID card number is odd.

[0043] The number of transactions completed through third-party payment platforms within the reporting period that meet the preset large-amount threshold. For example, the number of transactions with a single transfer amount greater than or equal to 50,000 yuan through third-party payment platforms within the reporting period that are greater than or equal to 100.

[0044] We extract relevant statements from companies and their executives from publicly available internet data. We then use sentiment analysis algorithms to determine the polarity of these statements, obtaining public opinion sentiment data. We calculate the proportion of negative public opinion data. When the proportion of negative public opinion data exceeds a preset threshold, we mark the statements from the corresponding companies and their executives as suspected clues of illegal financial activities.

[0045] The relevant comments and data include keywords such as "missing" and "donation fraud".

[0046] By using a pre-set advertising identification model, it is determined whether advertising content in publicly available internet data has illegal advertising characteristics. Advertising content with illegal advertising characteristics and the relevant data of the corresponding companies are marked as suspected illegal financial activity clues in the category of online advertising.

[0047] Among the characteristics of illegal advertisements are false advertising and promises of high returns.

[0048] The complaint and report data is processed by feature extraction. A preset machine learning model is used to determine the relevance of the extracted features to illegal financial activities. When the relevance reaches a preset threshold, the information of the risky enterprises and related personnel corresponding to the complaint and report data is marked as suspected illegal financial activity clues.

[0049] S103. Through preset logical rules, perform correlation analysis on the suspected illegal financial activity clue data to obtain illegal financial activity clues and related relationship data.

[0050] In some embodiments of this application, suspected illegal financial activity clue data is classified and identified to obtain fund flow clue data and, based on preset logical rules, fund flow details of abnormal accounts in the suspected illegal financial activity clue data are extracted.

[0051] The details of abnormal fund movements are matched with preset specific transfer patterns to filter out suspected illegal financial activity clues that match the specific transfer patterns. Correlation analysis is then performed on the abnormal accounts corresponding to the suspected illegal financial activity clues, the companies owning the abnormal accounts, the individuals associated with the abnormal accounts, and related accounts with direct financial transactions with the abnormal accounts, to obtain multi-dimensional correlation data.

[0052] Among them, specific transfer modes include transferring funds from multiple accounts to the same account, or transferring funds from the same account to multiple accounts.

[0053] Cross-category comparative analysis is conducted on data related to suspected illegal financial activities, including negative public opinion, online advertising, and complaints / reports. Clues from two or more categories that point to the same entity and whose core information corroborates each other are considered as leads on illegal financial activities.

[0054] For example, the company being complained against can be compared with companies associated with accounts showing unusual fund movements to further identify entities suspected of engaging in illegal financial activities.

[0055] S104. Based on clues to illegal financial activities and related data, generate a list of clues to illegal financial activities and a report on abnormal related accounts.

[0056] In some embodiments of this application, clues to illegal financial activities are categorized and organized according to clue type, and the core information corresponding to each clue is extracted. Based on the relationship data, the hierarchical relationships between abnormal accounts, the enterprises to which the abnormal accounts belong, the personnel related to the abnormal accounts, and the related accounts with direct financial transactions with the abnormal accounts are clarified, forming a relationship graph data.

[0057] Following a pre-defined standardized format, the core information of the categorized clues is integrated into a list of clues for illegal financial activities. The relationship graph data is then integrated with this list to generate a report of abnormally related accounts.

[0058] The method provided in this application collects financial transaction data, publicly available internet data, and complaint / report data to include a vast amount of potential leads within its monitoring scope, achieving comprehensive lead sources and early risk detection. By constructing dedicated identification models for different data types and combining multi-dimensional features, it automates the screening process through rule validation and intelligent algorithms, significantly improving lead identification efficiency, reducing false positives, and enhancing the ability to process complex data.

[0059] By performing correlation analysis on data related to suspected illegal financial activities, the core entities, related personnel, and accounts of illegal financial activities can be accurately identified, thereby improving the credibility of the clues and the targeted nature of risk prevention and control.

[0060] By organizing information in a structured manner to form a standardized list of clues and constructing a visual relationship graph, the workload of regulatory personnel is significantly reduced, the allocation of regulatory resources is optimized, and full-cycle support is provided for early warning and follow-up of illegal financial activities, thereby effectively improving the efficiency and effectiveness of regulatory work.

[0061] It should be noted that, although the embodiments in this application are based on... Figure 1 Steps S101 to S104 will be described sequentially, but this does not mean that steps S101 to S104 must be performed in a strict order. The reason this embodiment follows this order is... Figure 1 The order in which steps S101 to S104 are described is provided to facilitate understanding of the technical solutions of the embodiments of this application by those skilled in the art. In other words, in the embodiments of this application, the order of steps S101 to S104 can be appropriately adjusted according to actual needs.

[0062] based on Figure 1 In addition to the method described herein, this specification also provides some specific implementation schemes and extension schemes of this method, which will be further explained below.

[0063] Furthermore, to improve the accuracy and effectiveness of clue identification, the method also includes: Regularly collect feedback data on regulatory inspection results. Calculate the accuracy and recall of the multi-category identification model based on this feedback data. When the accuracy falls below a preset accuracy threshold and / or the recall falls below a preset recall threshold, retrain and optimize the corresponding identification model. Update the high-frequency terminology database for illegal financial activities and abnormal transaction rules according to the characteristics of new types of illegal financial activities and changes in regulatory policies.

[0064] Furthermore, to control data access risks and prevent data misuse and leakage, the methods also include: The collected fund transaction data, publicly available internet data, and complaint / report data are encrypted during storage and transmission. A tiered access control mechanism is employed to manage access permissions for these data.

[0065] Based on the same idea, some embodiments of this application also provide devices and non-volatile computer storage media corresponding to the above methods.

[0066] Figure 2 A schematic diagram of a device for detecting clues to illegal financial activities provided in this application embodiment includes: At least one processor; and, A memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor, which, when executed, enable the at least one processor to perform any of the preceding methods for discovering clues to illegal financial activities.

[0067] Some embodiments of this application provide a non-volatile computer storage medium for discovering clues to illegal financial activities, which stores computer-executable instructions capable of executing any of the above-described methods for discovering clues to illegal financial activities.

[0068] The various embodiments in this application are described in a progressive manner. Similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, the device and medium embodiments are basically similar to the method embodiments, so the description is relatively simple; relevant parts can be referred to the description of the method embodiments.

[0069] The devices and media provided in this application are one-to-one with the methods. Therefore, the devices and media also have similar beneficial technical effects as their corresponding methods. Since the beneficial technical effects of the methods have been described in detail above, the beneficial technical effects of the devices and media will not be repeated here.

[0070] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0071] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0072] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1The function specified in one or more boxes.

[0073] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0074] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.

[0075] Memory may include non-persistent storage in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of computer-readable media.

[0076] Computer-readable media includes both permanent and non-permanent, removable and non-removable media that can store information using any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.

[0077] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitation, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0078] The above description is merely an embodiment of this application and is not intended to limit this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the technical principles of this application should fall within the protection scope of this application.

Claims

1. A method for discovering clues to illegal financial activities, characterized in that, The method includes: Collect data on fund transactions, publicly available internet data, and complaint / reporting data; Based on a pre-set multi-category identification model, the fund transaction data, the publicly available Internet data, and the complaint and report data are targeted and filtered to obtain multiple clues of suspected illegal financial activities. By performing correlation analysis on suspected illegal financial activity clues data through preset logical rules, we can obtain clues to illegal financial activities and related relationship data. Based on the clues to illegal financial activities and the related relationship data, a list of clues to illegal financial activities and a report on abnormal related accounts are generated.

2. The method according to claim 1, characterized in that, The data collected, including fund transaction data, publicly available internet data, and complaint / report data, specifically includes: By using a pre-defined financial institution account interface, the system obtains fund transaction data from corporate accounts and accounts of relevant corporate personnel. Based on a pre-defined high-frequency term database of illegal financial activities, keyword-targeted retrieval and extraction are performed on publicly available data from the internet platform to obtain publicly available internet data that includes the characteristics of illegal financial activities. According to the preset collection frequency, the content of specific channels or sections of the preset target platform is fully crawled to obtain publicly available Internet data, including advertisements and public opinion information. Collect complaint and reporting data from regulatory departments at all levels through their reporting and complaint channels.

3. The method according to claim 1, characterized in that, The pre-defined multi-category identification model performs targeted screening on the fund transaction data, the publicly available internet data, and the complaint and report data to obtain multiple clues of suspected illegal financial activities, specifically including: Based on preset abnormal transaction rules, the fund transaction data is verified one by one according to the reporting cycle. If the fund transaction data meets any of the abnormal transaction rules, the account transaction data corresponding to the fund transaction data is marked as suspected illegal financial activity clue data of abnormal fund movement. Extract relevant speech data of enterprises and their executives from publicly available Internet data, and use sentiment analysis algorithms to determine the polarity of the relevant speech data to obtain public opinion sentiment data. The proportion of negative public opinion data in the public opinion data is statistically analyzed. When the proportion of negative public opinion data is higher than a preset standard threshold, the relevant remarks data of the enterprise and its executives corresponding to the negative public opinion data are marked as suspected illegal financial activity clues data of negative public opinion. Using a pre-set advertising identification model, it is determined whether the advertising content in the publicly available Internet data has illegal advertising characteristics. Advertising content with illegal advertising characteristics and the relevant data of the corresponding companies are marked as suspected illegal financial activity clues in the category of online advertising. The complaint and report data is processed by feature extraction. A preset machine learning model is used to determine the correlation between the extracted features and illegal financial activities. When the correlation reaches a preset threshold, the information of the risky enterprises and related personnel corresponding to the complaint and report data is marked as suspected illegal financial activity clues in the complaint and report category.

4. The method according to claim 3, characterized in that, The abnormal transaction rules include: The total number of transfers and / or remittances in the current reporting period is greater than or equal to a preset multiple of the total number of transfers and / or remittances in the previous reporting period, wherein the first reporting period is based on the previous calendar month. The number of transfers within the reporting period meets the preset number requirement, and the number of expenditures and the number of transfers meet the preset ratio. The number of transfers and / or remittances exceeding the preset ratio satisfies the income and expenditure matching relationship where the inflow amount meets the preset low standard and the outflow amount meets the preset high standard; In non-interbank transfers, the user identity characteristics of remittance accounts exceeding a preset percentage meet preset conditions, including age and gender extracted from ID card numbers; The number of transactions completed through third-party payment platforms within the reporting period that meet the preset large-amount threshold.

5. The method according to claim 1, characterized in that, The process involves performing correlation analysis on suspected illegal financial activity clues using preset logical rules to obtain clues and related data on illegal financial activities, specifically including: Based on preset logical rules, extract details of abnormal fund movements from abnormal accounts in the data of suspected illegal financial activities related to fund anomalies; The details of the abnormal fund movements are matched with a preset specific transfer pattern to filter out suspected illegal financial activity clues that match the specific transfer pattern. Correlation analysis is performed on the abnormal accounts corresponding to the suspected illegal financial activities related to the abnormal fund movements, the companies to which the abnormal accounts belong, the individuals associated with the abnormal accounts, and the related accounts that have direct financial transactions with the abnormal accounts, in order to obtain multi-dimensional correlation data; Cross-category comparative analysis is conducted on data of suspected illegal financial activities related to negative public opinion, suspected illegal financial activities related to online advertising, and suspected illegal financial activities related to complaints and reports. Clues that are suspected of being related to illegal financial activities in two or more categories and that point to the same entity and whose core information corroborates each other are considered. The aforementioned clues will be used as leads for illegal financial activities.

6. The method according to claim 1, characterized in that, The process of generating a list of illegal financial activity leads and a report of abnormal related accounts based on the illegal financial activity leads and the related relationship data specifically includes: The clues to illegal financial activities are classified and organized according to clue type, and the core information of each clue is extracted. Based on the aforementioned relationship data, the hierarchical relationships between abnormal accounts, the companies to which the abnormal accounts belong, the individuals associated with the abnormal accounts, and the related accounts with direct financial transactions with the abnormal accounts are clarified, forming a relationship graph data; According to the preset standardized format, the core information of the classified clues is integrated into a list of clues to illegal financial activities; The relationship graph data is integrated with the list of clues to illegal financial activities to obtain an abnormal related account report.

7. The method according to claim 1, characterized in that, The method further includes: Regularly collect and report data on regulatory verification results; The accuracy and recall of the multi-category identification model are calculated based on the feedback data of the regulatory verification results. When the accuracy is lower than a preset accuracy threshold and / or the recall is lower than a preset recall threshold, the corresponding recognition model is retrained and optimized. Based on the characteristics of new types of illegal financial activities and changes in regulatory policies, we update the high-frequency terminology database for illegal financial activities and the rules for abnormal transactions.

8. The method according to claim 1, characterized in that, The method further includes: The collected fund transaction data, publicly available internet data, and complaint and report data are encrypted during storage and transmission; A hierarchical access control mechanism is adopted to manage access to fund transaction data, publicly available internet data, and complaint and reporting data.

9. A device for detecting clues to illegal financial activities, characterized in that, include: At least one processor; as well as, A memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor, which, when executed, enables the at least one processor to perform the method for discovering clues to illegal financial activities as described in any one of claims 1-8.

10. A non-volatile computer storage medium for discovering clues to illegal financial activities, storing computer-executable instructions, characterized in that... The computer-executable instructions are capable of executing the method for discovering clues to illegal financial activities as described in any one of claims 1-8.