Risk warning methods and systems for medical aesthetic service transaction data

By aligning and analyzing user behavior and institutional qualifications over time during medical aesthetic service transactions, potential risks are identified, solving the problem of delayed risk warnings in existing technologies and achieving more accurate risk identification and prevention.

CN122134353APending Publication Date: 2026-06-02SUZHOU GENGMEI INTERACTIVE INFORMATION TECHNOLOGY CO LTD

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
SUZHOU GENGMEI INTERACTIVE INFORMATION TECHNOLOGY CO LTD
Filing Date
2026-03-05
Publication Date
2026-06-02

AI Technical Summary

Technical Problem

Existing methods for identifying risks in medical aesthetic service transactions lack dynamic analysis of user behavior time series during the transaction process, making it impossible to detect the correlation between abnormal changes and changes in institutional qualifications in a timely manner. This results in delayed risk warnings, a lack of foresight and adaptability, and a high risk of underreporting or false reporting.

Method used

By acquiring user operation time series and service institution qualification validity information, time dimension alignment analysis is performed to identify the overlap between time interval mutations and qualification nearing expiration, generating associated anomaly metrics. By combining the deviation of the ratio of transaction node execution time from the statistical distribution range, risk nodes are marked, and the node execution time threshold is adjusted based on historical risk transaction data to generate preventive verification instructions.

Benefits of technology

It improved the accuracy and timeliness of risk identification, reduced false alarms and missed alarms, enabled precise risk warnings, and safeguarded transaction security and user rights.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122134353A_ABST
    Figure CN122134353A_ABST
Patent Text Reader

Abstract

This invention provides a risk warning method and system for medical aesthetic service transaction data, relating to the field of medical aesthetic service risk management. The method includes acquiring user operation time sequences, institution qualification validity information, and transaction node execution duration; analyzing the correlation between sudden changes in time intervals and approaching qualification validity periods; identifying risk nodes and labeling risk types; and then, based on historical data characteristics, adjusting the expected duration of pending execution nodes to generate preventative verification instructions. This method achieves accurate identification and early warning of medical aesthetic transaction risks, effectively preventing fraud risks and improving transaction security.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to a medical beauty service risk management technology, in particular to a medical beauty service transaction data risk early warning method and system. BACKGROUND

[0002] With the rapid development of the medical beauty industry, medical beauty service transactions are increasing, accompanied by various risks. Medical beauty services have the characteristics of strong professionalism, high risk, strict qualification requirements, etc. The transaction process involves multiple links, including institution selection, plan development, signing and payment, preoperative preparation, surgery implementation, and postoperative care. In this process, due to factors such as service agency qualification problems, information asymmetry, and non-standard operation, consumers may face health risks, economic losses, and other problems.

[0003] The existing risk identification method is mainly based on static information auditing, lacking dynamic analysis of the time series of user behavior in the transaction process, and unable to timely discover the relevance between abnormal changes in user operation patterns and changes in agency qualifications, resulting in delayed risk early warning. It is difficult to accurately identify abnormal nodes in the transaction process, and it is easy to miss or misreport, affecting the accuracy and effectiveness of risk early warning.

[0004] The existing technology lacks learning ability based on historical risk transaction data, and cannot automatically adjust the expected node execution duration standard according to different risk types, nor can it perform preventive verification according to the dependency relationship between nodes, making the risk early warning system lack foresight and adaptability, and difficult to effectively prevent potential risks. SUMMARY

[0005] The medical beauty service transaction data risk early warning method and system provided by the embodiments of the present application can solve the problems in the prior art.

[0006] In a first aspect of the embodiments of the present application, a medical beauty service transaction data risk early warning method is provided, comprising:

[0007] Obtaining a user operation time series in a transaction process, service agency qualification validity period information, and transaction node execution duration;

[0008] Extracting the time interval of adjacent operations in the user operation time series, aligning and analyzing the time interval and the service agency qualification validity period information in the time dimension, identifying the coincidence relationship between the time interval mutation time and the qualification validity period approaching expiration time, and generating an associated abnormality metric value;

[0009] When the ratio of the associated abnormal metric value to the execution time of the transaction node deviates from the statistical distribution range of normal transactions, the transaction node is identified as a risk node, and the transaction risk type is marked.

[0010] Extract the node execution time deviation features corresponding to the transaction risk type from historical risk transaction data, use the node execution time deviation features as constraints to correct the expected execution time of each node to be executed in the current transaction process, and generate the corrected node execution time threshold.

[0011] Based on the type of transaction risk, the execution dependencies between nodes in the transaction process are analyzed to identify the nodes to be executed that depend on the risk nodes. Preventive verification instructions containing the corrected node execution time threshold are generated for the nodes to be executed and sent to the user terminal and the service institution terminal.

[0012] Extract the time intervals between adjacent user operations in the time series, align these time intervals with the service provider's qualification validity information along the time dimension, identify the overlap between moments of abrupt time interval changes and moments when the qualification validity is nearing expiration, and generate correlation anomaly metrics including:

[0013] Extract the timestamps of adjacent operations in the user operation time series, calculate the difference between adjacent timestamps, generate a time interval series, and perform smoothing processing. Calculate the rate of change and acceleration of change of the smoothed time interval series, construct a time interval abrupt change judgment threshold, and divide the time interval series into multiple time interval segments according to the time interval abrupt change judgment threshold.

[0014] Calculate the mean and standard deviation of the time interval within the time interval segments, and determine the candidate time interval abrupt change based on the difference in mean and standard deviation between adjacent time interval segments;

[0015] Calculate the change amplitude score, duration score, and fluctuation degree score of the candidate time interval abrupt change moment, combine them to generate a time interval abrupt change intensity value, and determine the time interval abrupt change moment based on the time interval abrupt change intensity value;

[0016] Calculate the remaining duration and duration decay rate of the service provider's qualification validity information, and determine the time when the qualification validity period is about to expire based on the duration decay rate;

[0017] Align the abrupt change in time interval with the time when the qualification validity period is about to expire in the time dimension, calculate the overlapping interval, and generate a related anomaly metric based on the overlapping interval.

[0018] When the ratio of the associated abnormal metric value to the execution time of a transaction node deviates from the statistical distribution range of normal transactions, the transaction node is identified as a risk node, and the transaction risk type is labeled as follows:

[0019] The execution time of the transaction node is normalized to generate a normalized execution time. The associated anomaly metric is mapped to the normalized execution time. The ratio of the associated anomaly metric to the normalized execution time is calculated to generate a ratio sequence.

[0020] The ratio sequence is divided into multiple time windows, and the mean, variance and standard deviation within each time window are calculated to construct a distribution feature matrix. Based on the distribution feature matrix, the statistical distribution interval of normal transactions is determined.

[0021] Calculate the deviation of the ratio sequence from the statistical distribution interval of normal transactions, and generate the deviation sequence;

[0022] The deviation value sequence is grouped, the distribution density of each group is calculated, and the transaction nodes whose distribution density exceeds the preset witness threshold are identified as candidate risk nodes.

[0023] Calculate the temporal and distribution characteristics of candidate risk nodes, and determine the candidate risk nodes whose combined value of the temporal and distribution characteristics exceeds a preset risk threshold as risk nodes;

[0024] Wavelet transform is performed on the deviation value sequence of risk nodes to obtain multi-scale decomposition coefficients. The magnitude and rate of change of each scale decomposition coefficient are calculated. The risk level is determined according to the magnitude of the magnitude and a preset grading threshold. The evolution type is determined according to the rate of change and a preset trend threshold. The combination result of risk level and evolution type is labeled as the trading risk type.

[0025] Extract the node execution time deviation features corresponding to the transaction risk type from historical risk transaction data. Use these node execution time deviation features as constraints to correct the expected execution time of each node to be executed in the current transaction process, generating corrected node execution time thresholds, including:

[0026] Select the node execution time sequence corresponding to the transaction risk type from historical risk transaction data, calculate the time difference sequence of execution time of adjacent nodes, perform segmented statistics on the time difference sequence to obtain a numerical distribution matrix, calculate the mean and standard deviation of the time difference based on the numerical distribution matrix, and use the combined feature of the mean and standard deviation as the node execution time deviation feature.

[0027] By utilizing the node execution time deviation features, a feature vector is constructed. The projection distribution of the feature vector in the time dimension is calculated. The fluctuation range and fluctuation frequency of the projection distribution are extracted. The fluctuation range is mapped to the constraint boundary value, and the fluctuation frequency is mapped to the constraint threshold. The node execution time constraint conditions are generated by combining these features.

[0028] The expected execution time sequence of the nodes to be executed in the current transaction process is divided into segments according to the segmentation method of time difference sequence. The distance difference between the segment and the constraint boundary value is calculated. Based on the distance difference and the constraint threshold, the correction coefficient matrix is ​​calculated. The segments of the expected execution time sequence are corrected according to the correction coefficient matrix.

[0029] The corrected expected execution time sequence is segmented for verification. The deviation of each segment from the original sequence is calculated. Segments with deviations exceeding the preset deviation range are marked as segments to be optimized. New correction coefficients are calculated based on the correction coefficient matrix. The segments to be optimized are corrected. The correction process is repeated until the deviation of all segments is within the preset deviation range. Finally, the corrected node execution time threshold is generated.

[0030] A feature vector is constructed using the node execution time deviation feature. The projection distribution of the feature vector in the time dimension is calculated, and the fluctuation range and fluctuation frequency of the projection distribution are extracted. The fluctuation range is mapped to the constraint boundary value, and the fluctuation frequency is mapped to the constraint threshold. The node execution time constraints are generated by combining these constraints.

[0031] The node execution time deviation feature is converted into a time-numerical two-dimensional feature matrix. Singular value decomposition is performed on the time-numerical two-dimensional feature matrix to obtain singular value vectors. Feature components are reconstructed based on the singular value vectors. The feature components are divided into multiple time windows according to the time dimension. Segmentation processing is performed in each time window to obtain feature vectors.

[0032] Eigenvalue decomposition is performed on the eigenvectors to obtain eigenvalue sequences and eigenvector sequences. Based on the eigenvalue sequences, the eigenvector sequences are selected to construct a projection matrix. The projection matrix is ​​then reconstructed in the time dimension to obtain the projection distribution.

[0033] The maximum and minimum points of the projected distribution are calculated to obtain the wave boundary point sequence. The wave interval is divided based on the wave boundary point sequence, and the wave frequency is obtained by calculating the time difference between adjacent wave boundary points.

[0034] Multi-scale transformation is performed on the fluctuation range and fluctuation frequency to obtain a multi-layer feature sequence. Principal components are extracted from the multi-layer feature sequence to obtain the constraint boundary value and constraint threshold.

[0035] The constraint boundary values ​​and constraint thresholds are decomposed to obtain the feature space. A constraint matrix is ​​constructed in the feature space. Hierarchical clustering is performed on the constraint matrix to extract stable features. Based on the stable features, node execution time constraints are generated.

[0036] Based on the type of transaction risk, the execution dependencies between nodes in the transaction process are analyzed to identify nodes to be executed that depend on risk nodes. Preventive verification instructions containing revised node execution duration thresholds are generated for these nodes and sent to user terminals and service provider terminals, including:

[0037] Extract the node execution sequence from the transaction process, construct the information state transition probability matrix based on the node execution sequence, calculate the execution dependency probability and information propagation coefficient between nodes in combination with the transaction risk type, and combine the execution dependency probability and information propagation coefficient to generate the execution dependency matrix.

[0038] The execution dependency matrix is ​​subjected to eigenvalue decomposition to obtain node execution feature vectors. An execution dependency network between nodes is constructed based on the node execution feature vectors. Execution dependency links are extracted from the execution dependency network. Nodes to be executed that have execution dependencies with risk nodes are identified through the execution dependency links.

[0039] Extract the time-series state sequence from the execution records of the node to be executed, convert the time-series state sequence into a state probability distribution, and calculate the node execution risk score based on the state probability distribution;

[0040] For nodes to be executed, a risk monitoring interval is set based on the node execution risk score. The verification time point and verification granularity parameters are determined according to the risk monitoring interval. The corrected node execution duration threshold is converted into a preventive verification instruction according to the verification time point and verification granularity parameters.

[0041] Preventive verification instructions are sent to user terminals and service provider terminals via encrypted channels.

[0042] The execution dependency matrix is ​​subjected to eigenvalue decomposition to obtain node execution feature vectors. An execution dependency network between nodes is constructed based on these feature vectors. Execution dependency links are extracted from this network, and nodes with execution dependencies on risky nodes are identified through these links.

[0043] The execution dependency matrix is ​​projected onto the time and space dimensions to obtain the projection matrix. The eigenvalue distribution of the projection matrix is ​​calculated. Information gain weights are constructed based on the skewness and kurtosis of the eigenvalue distribution. The node execution feature components are extracted from the execution dependency matrix using the information gain weights.

[0044] Based on the node execution feature components, calculate the time-series autocorrelation coefficient and cross-correlation coefficient, calculate the spatial covariance value and correlation coefficient, and combine them to generate the node execution feature vector;

[0045] The node association matrix is ​​obtained by calculating the cosine distance between the node execution feature vectors. An execution dependency network between nodes is constructed based on the node association matrix. The information entropy value of the nodes in the execution dependency network is calculated, and the execution dependency links are extracted according to the rate of change of the information entropy value.

[0046] The propagation path length from the risk node to each node in the execution dependency link is calculated as the propagation attenuation coefficient. The fluctuation threshold is determined based on the mean and standard deviation of the propagation attenuation coefficient. Nodes whose propagation attenuation coefficient exceeds the fluctuation threshold are identified as nodes to be executed that have an execution dependency relationship with the risk node.

[0047] A second aspect of the present invention provides a risk warning system for medical aesthetic service transaction data, comprising:

[0048] The acquisition unit is used to acquire the time sequence of user operations during the transaction process, the validity period of the service provider's qualifications, and the execution duration of transaction nodes.

[0049] The processing unit is used to extract the time interval between adjacent operations in the user operation time series, perform alignment analysis between the time interval and the service institution's qualification validity information in the time dimension, identify the overlap between the moment when the time interval changes abruptly and the moment when the qualification validity is about to expire, and generate the correlation anomaly measurement value.

[0050] The risk determination unit is used to identify a transaction node as a risk node and label the transaction risk type when the ratio of the associated abnormal metric value to the execution time of the transaction node deviates from the statistical distribution range of normal transactions.

[0051] The correction unit is used to extract the node execution time deviation features corresponding to the transaction risk type from historical risk transaction data, use the node execution time deviation features as constraints, correct the expected execution time of each node to be executed in the current transaction process, and generate the corrected node execution time threshold.

[0052] The execution unit is used to analyze the execution dependencies between nodes in the transaction process based on the transaction risk type, determine the nodes to be executed that depend on the risk nodes, generate preventive verification instructions for the nodes to be executed that include the corrected node execution time threshold, and send them to the user terminal and the service institution terminal.

[0053] A third aspect of the present invention provides an electronic device, comprising:

[0054] processor;

[0055] Memory used to store processor-executable instructions;

[0056] The processor is configured to invoke instructions stored in the memory to execute the aforementioned method.

[0057] A fourth aspect of the present invention provides a computer-readable storage medium having stored thereon computer program instructions that, when executed by a processor, implement the aforementioned method.

[0058] In this embodiment, by aligning the time intervals of adjacent operations in the user's operation time series with the validity period information of the service institution's qualifications, the potential correlation between abnormal time behavior and the approaching expiration of qualifications can be effectively identified, thereby discovering potential risky transactions in advance and improving the accuracy and timeliness of risk identification. Combining the analysis of the ratio of correlation anomaly measurement values ​​to the execution time of transaction nodes, a more comprehensive risk assessment mechanism is established, avoiding misjudgments that may arise from single-dimensional judgments and significantly improving the accuracy of risk identification. Based on the node execution time deviation characteristics extracted from historical risky transaction data, the expected execution time of each node to be executed in the current transaction process is corrected, making risk warnings more targeted and forward-looking, effectively reducing false alarms and missed alarms caused by traditional fixed thresholds. Precise risk warning pushes are achieved, avoiding the user experience damage that global warnings may cause, while improving the efficiency of risk prevention and control. By simultaneously sending preventative verification instructions containing the corrected node execution time thresholds to both the user terminal and the service institution terminal, a two-way risk prevention and control mechanism is constructed, effectively reducing potential risks in medical aesthetic service transactions and ensuring transaction security and user rights. Attached Figure Description

[0059] Figure 1 This is a flowchart illustrating the risk warning method for medical aesthetic service transaction data according to an embodiment of the present invention;

[0060] Figure 2 This is a flowchart illustrating the transaction risk node detection and identification process according to an embodiment of the present invention. Detailed Implementation

[0061] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0062] The technical solution of the present invention will be described in detail below with reference to specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments.

[0063] Figure 1This is a flowchart illustrating the risk warning method for medical aesthetic service transaction data according to an embodiment of the present invention. Figure 1 As shown, the method includes:

[0064] Obtain the time sequence of user operations during the transaction process, the validity period of service provider qualifications, and the execution duration of transaction nodes;

[0065] Extract the time interval between adjacent operations in the user operation time series, perform alignment analysis between the time interval and the service institution's qualification validity information in the time dimension, identify the overlap between the moment when the time interval changes abruptly and the moment when the qualification validity is about to expire, and generate correlation anomaly measurement values;

[0066] When the ratio of the associated abnormal metric value to the execution time of the transaction node deviates from the statistical distribution range of normal transactions, the transaction node is identified as a risk node, and the transaction risk type is marked.

[0067] Extract the node execution time deviation features corresponding to the transaction risk type from historical risk transaction data, use the node execution time deviation features as constraints to correct the expected execution time of each node to be executed in the current transaction process, and generate the corrected node execution time threshold.

[0068] Based on the type of transaction risk, the execution dependencies between nodes in the transaction process are analyzed to identify the nodes to be executed that depend on the risk nodes. Preventive verification instructions containing the corrected node execution time threshold are generated for the nodes to be executed and sent to the user terminal and the service institution terminal.

[0069] In one optional implementation, the time intervals between adjacent operations in the user operation time series are extracted, and the time intervals are aligned with the service provider's qualification validity information in the time dimension. The overlap between the moment when the time interval changes abruptly and the moment when the qualification validity is about to expire is identified, and the associated anomaly measurement value is generated, including:

[0070] Extract the timestamps of adjacent operations in the user operation time series, calculate the difference between adjacent timestamps, generate a time interval series, and perform smoothing processing. Calculate the rate of change and acceleration of change of the smoothed time interval series, construct a time interval abrupt change judgment threshold, and divide the time interval series into multiple time interval segments according to the time interval abrupt change judgment threshold.

[0071] Calculate the mean and standard deviation of the time interval within the time interval segments, and determine the candidate time interval abrupt change based on the difference in mean and standard deviation between adjacent time interval segments;

[0072] Calculate the change amplitude score, duration score, and fluctuation degree score of the candidate time interval abrupt change moment, combine them to generate a time interval abrupt change intensity value, and determine the time interval abrupt change moment based on the time interval abrupt change intensity value;

[0073] Calculate the remaining duration and duration decay rate of the service provider's qualification validity information, and determine the time when the qualification validity period is about to expire based on the duration decay rate;

[0074] Align the abrupt change in time interval with the time when the qualification validity period is about to expire in the time dimension, calculate the overlapping interval, and generate a related anomaly metric based on the overlapping interval.

[0075] First, extract the timestamps of adjacent operations from the user operation time series, calculate the difference between adjacent timestamps to obtain the time interval series, and smooth this series. A weighted average algorithm is applied to the time interval data within each window using a sliding window method, assigning higher weights to recent data and lower weights to older data. The smoothing factor can be set to 0.8. The rate of change (the difference between adjacent smoothed time intervals) and the acceleration of change (the difference between adjacent rates of change) are calculated for the smoothed time interval series. A threshold for determining abrupt changes in time intervals is constructed and set to three times the standard deviation of the mean of the smoothed time interval series. The time interval series is divided into multiple time interval segments according to the threshold. When the rate of change or acceleration of change value at a certain moment exceeds the threshold, that moment is designated as the segmentation point.

[0076] For each time interval segment, calculate the time interval mean and standard deviation. The time interval mean is obtained by summing the data and dividing by the number of time intervals in the segment, while the standard deviation is calculated by taking the square root of the mean square. Candidate moments for time interval abrupt changes are determined based on the difference in means and standard deviation between adjacent time interval segments. When the difference in means between adjacent segments exceeds 2.5 times the standard deviation of the previous segment, the segment point is marked as a candidate moment for a time interval abrupt change. For example, in a time series of user operations for a medical aesthetic service, the time interval mean of segment 1 is 3 hours and the standard deviation is 0.5 hours, while the mean of segment 2 is 5.5 hours and the standard deviation is 0.8 hours. The difference in means between the two segments, 2.5 hours, exceeds 2.5 times the standard deviation of segment 1 (0.5 hours), therefore the boundary point between the two segments is marked as a candidate moment for a time interval abrupt change.

[0077] For each candidate mutation moment, three key indicators are calculated: the magnitude of change score, the duration score, and the volatility score. The magnitude of change score represents the degree of change in the time interval before and after the mutation, calculated as the difference between the means of adjacent segments divided by the mean of the previous segment; the duration score represents the duration after the mutation, calculated as the duration of the next segment divided by the overall sequence length; the volatility score represents the stability of the time interval after the mutation, calculated as 1 minus the ratio of the standard deviation of the next segment to the mean. These three scores are combined using a weighted summation method to generate a time interval mutation intensity value, with weights set to 0.5, 0.3, and 0.2, respectively. When the mutation intensity value exceeds a preset threshold of 0.7, the candidate moment is determined as a time interval mutation moment.

[0078] This section displays the remaining validity period and decay rate of the parallel computing service provider's qualification certificate. The remaining validity period is the difference between the qualification's expiration date and the current date, expressed in days. The decay rate represents the rate at which the remaining validity period changes, calculated as the ratio of the daily decrease in remaining validity to the total validity period. The time when the qualification is nearing its expiration is determined based on the decay rate. A certificate is considered nearing its expiration when the remaining validity is less than 15% of the total validity period. For a 365-day qualification certificate, a certificate is considered nearing its expiration when the remaining days are less than 55 days.

[0079] The time interval abrupt change and the time when the qualification validity period is about to expire are aligned in the time dimension, and the overlap interval between the two is calculated using a time window method. The time window size is set to 7 days. If the time difference between the time interval abrupt change and the time when the qualification validity period is about to expire is less than the time window size, an overlap interval is considered to exist. A correlation anomaly metric is generated based on the overlap interval. The calculation method is to divide the number of overlap days by the time window size, and then multiply it by the product of the time interval abrupt change intensity value and the qualification nearing expiration degree value (the inverse ratio of the remaining time to the total validity period). The correlation anomaly metric ranges between 0 and 1, with a larger value indicating a higher degree of anomaly. When the time when the user's operation time interval changes significantly coincides with the time when the service provider's qualification is about to expire, the correlation anomaly metric is close to 1, indicating that there may be high-risk behavior.

[0080] When a user was browsing cosmetic surgery service providers, the initial average interval was 4 hours, with a standard deviation of 0.7 hours. Subsequently, the interval suddenly shortened to an average of 1.5 hours, with a standard deviation of 0.3 hours. The mutation strength value calculated at this point was 0.85. Simultaneously, it was detected that the service provider's qualification certificate had 18 days of remaining validity, with a total validity period of 365 days, indicating a significant approaching expiration date. The time difference between the two points was 3 days, within a 7-day window, resulting in a correlation anomaly metric of 0.83. Based on this, the system generated a risk warning.

[0081] In this embodiment, multi-dimensional feature extraction and fusion techniques are employed to overcome the problem of single features being susceptible to noise interference, thereby improving the accuracy of anomaly detection. Through time-dimensional alignment and overlapping interval calculation, a quantitative assessment of the correlation between changes in user behavior and qualification status is achieved, providing an objective basis for risk warning. Parameters can be adjusted according to different scenarios to meet diverse risk monitoring needs, while maintaining low computational complexity and supporting large-scale real-time monitoring, which is of significant value in improving the security of medical aesthetic service transactions.

[0082] like Figure 2 The diagram shows the flowchart for the detection and identification of transaction risk nodes in this embodiment.

[0083] In one optional implementation, when the ratio of the associated anomaly metric to the execution time of a transaction node deviates from the statistical distribution range of normal transactions, the transaction node is identified as a risk node, and the transaction risk type is labeled as follows:

[0084] The execution time of the transaction node is normalized to generate a normalized execution time. The associated anomaly metric is mapped to the normalized execution time. The ratio of the associated anomaly metric to the normalized execution time is calculated to generate a ratio sequence.

[0085] The ratio sequence is divided into multiple time windows, and the mean, variance and standard deviation within each time window are calculated to construct a distribution feature matrix. Based on the distribution feature matrix, the statistical distribution interval of normal transactions is determined.

[0086] Calculate the deviation of the ratio sequence from the statistical distribution interval of normal transactions, and generate the deviation sequence;

[0087] The deviation value sequence is grouped, the distribution density of each group is calculated, and the transaction nodes whose distribution density exceeds the preset witness threshold are identified as candidate risk nodes.

[0088] Calculate the temporal and distribution characteristics of candidate risk nodes, and determine the candidate risk nodes whose combined value of the temporal and distribution characteristics exceeds a preset risk threshold as risk nodes;

[0089] Wavelet transform is performed on the deviation value sequence of risk nodes to obtain multi-scale decomposition coefficients. The magnitude and rate of change of each scale decomposition coefficient are calculated. The risk level is determined according to the magnitude of the magnitude and a preset grading threshold. The evolution type is determined according to the rate of change and a preset trend threshold. The combination result of risk level and evolution type is labeled as the trading risk type.

[0090] The execution time of transaction nodes is normalized to generate a normalized execution time. The normalization process uses a maximum-minimum normalization method, i.e., (original execution time - minimum execution time) / maximum execution time - minimum execution time. This converts the execution time into a value between 0 and 1, eliminating the dimensional differences in execution times between different transaction nodes. The previously calculated correlation anomaly metrics are mapped to the scale space of the normalized execution time using a linear scaling transformation to maintain the relative magnitude of the correlation anomaly metrics. The ratio of the correlation anomaly metrics to the normalized execution time is calculated to generate a ratio sequence. In a medical aesthetics service transaction scenario, during a user's browsing and booking of beauty services, the normalized execution times of five transaction nodes are 0.3, 0.5, 0.4, 0.7, and 0.6, respectively, with corresponding correlation anomaly metrics of 0.2, 0.4, 0.5, 0.8, and 0.9. The calculated ratio sequence is 0.67, 0.8, 1.25, 1.14, and 1.5.

[0091] The ratio sequence is divided into multiple time windows, the size of which is set according to the time span of the transaction data. A suitable window size for medical aesthetic service transactions is 30 transaction nodes. Statistical characteristics are calculated within each time window, including mean, variance, and standard deviation. The mean is calculated as the arithmetic mean of all ratios within the window; the variance is calculated as the sum of the squares of the differences between each ratio and the mean divided by the number of ratios; and the standard deviation is the square root of the variance. The statistical characteristics of each time window are organized into a distribution feature matrix, where each row of the matrix represents a time window, and the columns are the mean, variance, and standard deviation, respectively. Based on the distribution feature matrix, the statistical distribution interval for normal transactions is determined using the normal distribution assumption. The upper limit of the interval is the mean plus twice the standard deviation, and the lower limit is the mean minus twice the standard deviation. Taking the user transactions mentioned above as an example, if the mean of the ratio sequence within a certain time window is 1.1 and the standard deviation is 0.25, then the statistical distribution interval for normal transactions is [0.6, 1.6].

[0092] The deviation of the ratio sequence from the statistical distribution interval of normal transactions is calculated to generate a deviation value sequence. The deviation value is calculated by subtracting the absolute value of the interval mean from the ratio and dividing by the interval standard deviation. When the ratio is within the interval, the deviation value is small; when the ratio exceeds the interval, the deviation value increases significantly. For the ratio 1.5 in the aforementioned ratio sequence, the calculated deviation value is 1.6, indicating that the ratio deviates significantly from the normal transaction distribution. The deviation value sequence is grouped using equal-width grouping, uniformly dividing the deviation value range into multiple intervals. The number of deviation values ​​in each group is calculated and divided by the total number of deviation values ​​to obtain the distribution density of each group. Transaction nodes with a distribution density exceeding a preset density threshold are identified as candidate risk nodes. The preset density threshold is set based on historical risk detection results and can be set to 0.15 in the medical aesthetics transaction scenario. When the distribution density of a group exceeds 0.15, the corresponding transaction node in that group is marked as a candidate risk node.

[0093] Calculate the temporal and distribution characteristics of candidate risk nodes. Temporal characteristics include the number of consecutive increases in deviation values, the fluctuation frequency of deviation values, and the peak-to-trough ratio of deviation values; distribution characteristics include the outlier degree of deviation values, the clustering density of deviation values, and the tail thickness of deviation values.

[0094] In the calculation of temporal features, the number of consecutive increases is the number of nodes where the deviation value continues to rise; the fluctuation frequency is the number of times the direction of the deviation value changes per unit time; and the peak-to-valley ratio is the ratio of the local maximum to the local minimum. In the calculation of distribution features, the outlier degree is the Mahalanobis distance between the deviation value and the overall deviation value distribution; the clustering density is the local density function value of the deviation value; and the tail thickness is the proportion of deviation values ​​outside the interval. The temporal features and distribution features are combined by weighted summation, with weights allocated according to feature importance. Candidate risk nodes whose combined value exceeds a preset risk threshold are identified as risk nodes.

[0095] In practical applications, the temporal characteristic value of a candidate risk node in a certain medical aesthetics transaction is 0.78, the distribution characteristic value is 0.86, and the weights are 0.6 and 0.4 respectively. The calculated combined value is 0.81, which exceeds the preset risk threshold of 0.75, and therefore it is identified as a risk node.

[0096] Wavelet transform is performed on the deviation sequence of risk nodes, and multi-scale decomposition is performed using the db4 wavelet basis function to obtain decomposition coefficients at different scales, including low-frequency approximation coefficients and high-frequency detail coefficients. The magnitude and rate of change of the decomposition coefficients at each scale are calculated; the magnitude represents the degree of deviation, and the rate of change represents the trend of deviation. The risk level is determined according to the magnitude of the values ​​and a preset grading threshold, which can be set to three levels: low risk (0.5), medium risk (0.8), and high risk (1.2). When the magnitude is below 0.5, it is considered low risk; between 0.5 and 0.8, it is considered medium risk; between 0.8 and 1.2, it is considered high risk; and above 1.2, it is considered severe risk.

[0097] The evolution type is determined based on the rate of change according to a preset trend threshold. The trend thresholds can be set as follows: -0.1 for a downward trend, 0.1 for a stable trend, and 0.3 for an upward trend. When the rate of change is below -0.1, it is considered a downward trend; between -0.1 and 0.1, it is considered a stable trend; between 0.1 and 0.3, it is considered a slow upward trend; and above 0.3, it is considered a rapid upward trend. The combination of risk level and evolution type is labeled as the trading risk type, such as "medium risk - stable trend" or "high risk - rapid upward trend."

[0098] In this embodiment, by combining temporal and distributional features for evaluation, the dynamic changes of risk nodes are comprehensively captured, reducing the false positive rate. The application of wavelet transform makes risk classification and trend judgment more objective and scientific, providing a basis for formulating targeted prevention and control strategies for different risk types. The overall solution has strong anti-interference capabilities and adaptability, and can cope with complex risk scenarios in medical aesthetic service transactions, providing strong support for ensuring transaction security.

[0099] In one optional implementation, node execution time deviation features corresponding to the transaction risk type are extracted from historical risk transaction data. These node execution time deviation features are then used as constraints to correct the expected execution time of each node to be executed in the current transaction process, generating a corrected node execution time threshold, including:

[0100] Select the node execution time sequence corresponding to the transaction risk type from historical risk transaction data, calculate the time difference sequence of execution time of adjacent nodes, perform segmented statistics on the time difference sequence to obtain a numerical distribution matrix, calculate the mean and standard deviation of the time difference based on the numerical distribution matrix, and use the combined feature of the mean and standard deviation as the node execution time deviation feature.

[0101] By utilizing the node execution time deviation features, a feature vector is constructed. The projection distribution of the feature vector in the time dimension is calculated. The fluctuation range and fluctuation frequency of the projection distribution are extracted. The fluctuation range is mapped to the constraint boundary value, and the fluctuation frequency is mapped to the constraint threshold. The node execution time constraint conditions are generated by combining these features.

[0102] The expected execution time sequence of the nodes to be executed in the current transaction process is divided into segments according to the segmentation method of time difference sequence. The distance difference between the segment and the constraint boundary value is calculated. Based on the distance difference and the constraint threshold, the correction coefficient matrix is ​​calculated. The segments of the expected execution time sequence are corrected according to the correction coefficient matrix.

[0103] The corrected expected execution time sequence is segmented for verification. The deviation of each segment from the original sequence is calculated. Segments with deviations exceeding the preset deviation range are marked as segments to be optimized. New correction coefficients are calculated based on the correction coefficient matrix. The segments to be optimized are corrected. The correction process is repeated until the deviation of all segments is within the preset deviation range. Finally, the corrected node execution time threshold is generated.

[0104] In one optional implementation, node execution time deviation features corresponding to the transaction risk type are extracted from historical risk transaction data. These deviation features are then used as constraints to correct the expected execution time of each node to be executed in the current transaction process, generating a corrected node execution time threshold. This method selects node execution time sequences corresponding to the transaction risk type from the historical risk transaction database. Data selection employs a risk type matching mechanism; specifically, for the "high-risk - rapid upward trend" type, transaction records marked with the same risk type in historical data are selected, and their node execution time sequences are extracted. For the medical aesthetics service transaction scenario, the node execution time sequence for a certain type of high-risk transaction is selected as [120 seconds, 85 seconds, 190 seconds, 45 seconds, 210 seconds, 75 seconds]. The time difference sequence of adjacent node execution times is calculated, i.e., the execution time of the next node minus the execution time of the previous node, resulting in the time difference sequence [-35 seconds, 105 seconds, -145 seconds, 165 seconds, -135 seconds].

[0105] The time difference sequence is segmented and statistically analyzed using a sign-change segmentation method, dividing the sequence based on the positive or negative change of the time difference. The time difference sequence can be divided into three segments: the first segment [-35 seconds], the second segment [105 seconds, -145 seconds], and the third segment [165 seconds, -135 seconds]. The numerical distribution of each segment is statistically analyzed to construct a numerical distribution matrix. The rows of the matrix represent each segment, and the columns represent statistical characteristics, including the minimum, maximum, average, and standard deviation. Based on the numerical distribution matrix, the mean and standard deviation of the time differences are calculated. For the three segments, the means are -35 seconds, -20 seconds, and 15 seconds, and the standard deviations are 0 seconds, 125 seconds, and 150 seconds, respectively. The means and standard deviations are combined into feature vectors: [-35, 0], [-20, 125], and [15, 150]. These combined features serve as the node execution time deviation features.

[0106] A feature vector matrix is ​​constructed using the node execution time deviation characteristics, with each row representing a segmented feature vector. The projection distribution of the feature vectors on the time dimension is calculated using principal component analysis, projecting the high-dimensional feature vectors onto the time axis to obtain a projection sequence. The fluctuation range and fluctuation frequency of the projection sequence are extracted. The fluctuation range represents the range of fluctuation of the projected value, and the fluctuation frequency represents the number of times the fluctuation direction changes per unit time. For the execution time of the medical aesthetics transaction node, the analysis shows that the fluctuation range of the projection sequence is [-150 seconds, 170 seconds], and the fluctuation frequency is 0.4 times / minute. The fluctuation range is mapped to constraint boundary values ​​by multiplying the two endpoints of the range by safety factors of 1.2 and 0.8, respectively, to obtain constraint boundary values ​​[-180 seconds, 136 seconds]. The fluctuation frequency is mapped to a constraint threshold using the formula: threshold = baseline value × (1 + fluctuation frequency × adjustment factor). The baseline value is set to 1.0, and the adjustment factor is set to 0.5, resulting in a constraint threshold of 1.2. The constraint boundary values ​​and constraint threshold are combined to generate node execution time constraints.

[0107] The expected execution time sequence of the nodes to be executed in the current transaction process is segmented according to the time difference sequence. Assuming the expected execution time sequence of the current medical aesthetic service transaction is [100 seconds, 80 seconds, 150 seconds, 60 seconds, 180 seconds, 90 seconds], the time difference sequence between adjacent nodes is calculated as [-20 seconds, 70 seconds, -90 seconds, 120 seconds, -90 seconds]. Based on the sign change segmentation method, this sequence is segmented into three segments: [-20 seconds], [70 seconds, -90 seconds], and [120 seconds, -90 seconds]. The distance difference between each segment and the constraint boundary value is calculated using the formula: the absolute value of the segment mean minus the constraint boundary mean. For the above three segments, the calculated distance differences from the constraint boundary mean are 15 seconds, 22 seconds, and 27 seconds, respectively. A correction coefficient matrix is ​​calculated based on the distance difference and the constraint threshold. The correction coefficient is calculated using the formula: 1 - (distance difference / constraint boundary range) × constraint threshold. For the three segments, the calculated correction coefficients are 0.95, 0.92, and 0.90, respectively. Based on the correction coefficient matrix, each segment of the expected execution time sequence is corrected by multiplying the original expected execution time by the corresponding segment's correction coefficient. The corrected expected execution time sequence is [95 seconds, 76 seconds, 138 seconds, 55.2 seconds, 162 seconds, 81 seconds].

[0108] The revised expected execution time sequence is segmented for verification, and the deviation of each segment from the original sequence is calculated using the formula |(revised value - original value) / original value|. For the revised sequence, the deviations for each node are 5%, 5%, 8%, 8%, 10%, and 10%, respectively. Segments with deviations exceeding a preset deviation range of 7% are marked as segments requiring optimization. Therefore, the segments containing the third to sixth nodes are marked as segments requiring optimization.

[0109] The new correction coefficients are calculated based on the correction coefficient matrix. The formula for the new correction coefficients is: original correction coefficient × (1 - deviation excess × adjustment factor). The deviation excess is the deviation level minus the preset deviation upper limit, and the adjustment factor is set to 0.5. For the segment to be optimized, the calculated new correction coefficients are 0.93 and 0.925. The segment to be optimized is then corrected, resulting in a new execution time sequence of [95 seconds, 76 seconds, 139.5 seconds, 55.8 seconds, 167.4 seconds, 83.25 seconds]. The verification and correction process is repeated until the deviation levels of all segments are within the preset deviation range. After two rounds of correction, the final corrected node execution time thresholds are [95 seconds, 76 seconds, 140 seconds, 56 seconds, 167 seconds, 83 seconds], with deviation levels of 5%, 5%, 6.7%, 6.7%, 6.7%, and 6.7% for each node, all within the preset deviation range.

[0110] In this embodiment, the segmented statistical characteristics of the time difference sequence are utilized to capture the temporal pattern features of transactions of different risk types, providing data support for threshold correction. Through projection analysis of feature vectors in the time dimension, an effective conversion from multi-dimensional features to one-dimensional constraints is achieved, simplifying computational complexity. Segmented verification and iterative optimization mechanisms ensure the rationality of the correction results, avoiding misjudgments caused by over-correction. The threshold parameters can be dynamically adjusted according to different risk types, providing a more reliable decision-making basis for risk warnings in medical aesthetic service transactions and significantly reducing the probability of transaction risks occurring.

[0111] In one optional implementation, a feature vector is constructed using the node execution time deviation feature. The projection distribution of the feature vector in the time dimension is calculated, and the fluctuation range and fluctuation frequency of the projection distribution are extracted. The fluctuation range is mapped to the constraint boundary value, and the fluctuation frequency is mapped to the constraint threshold. The node execution time constraint conditions are then generated by combining these conditions.

[0112] The node execution time deviation feature is converted into a time-numerical two-dimensional feature matrix. Singular value decomposition is performed on the time-numerical two-dimensional feature matrix to obtain singular value vectors. Feature components are reconstructed based on the singular value vectors. The feature components are divided into multiple time windows according to the time dimension. Segmentation processing is performed in each time window to obtain feature vectors.

[0113] Eigenvalue decomposition is performed on the eigenvectors to obtain eigenvalue sequences and eigenvector sequences. Based on the eigenvalue sequences, the eigenvector sequences are selected to construct a projection matrix. The projection matrix is ​​then reconstructed in the time dimension to obtain the projection distribution.

[0114] The maximum and minimum points of the projected distribution are calculated to obtain the wave boundary point sequence. The wave interval is divided based on the wave boundary point sequence, and the wave frequency is obtained by calculating the time difference between adjacent wave boundary points.

[0115] Multi-scale transformation is performed on the fluctuation range and fluctuation frequency to obtain a multi-layer feature sequence. Principal components are extracted from the multi-layer feature sequence to obtain the constraint boundary value and constraint threshold.

[0116] The constraint boundary values ​​and constraint thresholds are decomposed to obtain the feature space. A constraint matrix is ​​constructed in the feature space. Hierarchical clustering is performed on the constraint matrix to extract stable features. Based on the stable features, node execution time constraints are generated.

[0117] The node execution time deviation features are converted into a time-numerical two-dimensional feature matrix. The conversion method uses time as the row index and different dimensions of the deviation features as column indices to construct a two-dimensional matrix. Taking the execution time deviation features of five nodes in a medical aesthetics service transaction as an example, these five nodes are appointment consultation, service selection, payment confirmation, service appointment and service evaluation, and the corresponding deviation features are the mean and standard deviation. The converted time-numerical two-dimensional feature matrix is ​​a 5×2 matrix, where the rows represent the five different transaction nodes and the columns represent the mean and standard deviation, respectively. The data in this matrix is ​​preprocessed, including normalization and noise reduction. The processed matrix is ​​[[0.23, 0.15], [0.35, 0.28], [0.42, 0.36], [0.51, 0.45], [0.38, 0.32]].

[0118] Singular value decomposition (SVD) is performed on the time-numerical two-dimensional feature matrix. SVD decomposes the matrix into the product of three matrices: a left singular matrix, a singular value diagonal matrix, and the transpose of the right singular matrix. SVD is performed on the above 5×2 matrix to obtain the singular value vector [1.58, 0.12]. Feature components are reconstructed based on the singular value vector. The reconstruction method selects the singular vectors corresponding to the principal singular values ​​for reconstruction. Since the first singular value 1.58 is much larger than the second singular value 0.12, the left and right singular vectors corresponding to the first singular value are selected for reconstruction to obtain the principal feature components. The feature components are divided into multiple time windows according to the time dimension. The size of the time window is determined according to the time granularity of the transaction data. For medical aesthetic service transactions, the window size can be set to two transaction nodes. Segmentation processing is performed within each time window. The segmentation processing method uses linear interpolation to smooth the feature components within the window, obtaining the feature vector. The five nodes mentioned above are divided into three time windows: [0, 1], [1, 3], and [3, 4], with corresponding feature vectors of [0.23, 0.35], [0.35, 0.42, 0.51], and [0.51, 0.38], respectively.

[0119] Eigenvalue decomposition is performed on the eigenvectors, which decomposes the matrix into eigenvalues ​​and eigenvectors. A covariance matrix is ​​constructed for the eigenvectors of each time window, and eigenvalue decomposition is performed on the covariance matrix to obtain an eigenvalue sequence and an eigenvector sequence. For the first time window [0.23, 0.35], eigenvalue decomposition is performed on the covariance matrix, resulting in an eigenvalue sequence [0.0072, 0.0001] and an eigenvector sequence [[0.85, 0.52], [0.52, -0.85]]. The eigenvector sequence is then selected based on the eigenvalue sequence, choosing eigenvectors with eigenvalues ​​greater than a threshold. The threshold is set to 5% of the sum of the eigenvalues; for the eigenvalue sequence [0.0072, 0.0001], the threshold is 0.00037, therefore the first eigenvector [0.85, 0.52] is selected. A projection matrix is ​​constructed from the selected eigenvectors, by combining the eigenvectors as column vectors into a matrix. The projection distribution is obtained by reconstructing the projection matrix in the time dimension. The reconstruction method is to map the feature vector back to the original time dimension. For medical aesthetics transaction data, the obtained projection distribution is [0.20, 0.31, 0.38, 0.46, 0.33].

[0120] The maximum and minimum points of the projected distribution are calculated to obtain the fluctuation boundary point sequence. The calculation method compares the magnitudes of adjacent points; a point is a maximum when it is greater than its two adjacent points, and a point is a minimum when it is less than its two adjacent points. For the projected distribution [0.20, 0.31, 0.38, 0.46, 0.33], the maximum point is 0.46, and the minimum points are 0.20 and 0.33, resulting in the fluctuation boundary point sequence [0.20, 0.46, 0.33]. The fluctuation interval is divided based on the fluctuation boundary point sequence, which is the range from the minimum to the maximum value of the fluctuation boundary points, i.e., [0.20, 0.46]. The fluctuation frequency is obtained by calculating the time difference between adjacent fluctuation boundary points, with the time difference in units of the number of transaction nodes. The fluctuation frequency is calculated by dividing the number of fluctuation boundary points by the total time span, resulting in a fluctuation frequency of 3 / 4 = 0.75.

[0121] Multi-scale transformation was performed on the fluctuation range and fluctuation frequency to obtain multi-level feature sequences. The multi-scale transformation adopted the wavelet transform method to decompose the fluctuation range and fluctuation frequency at different scales. Wavelet transform was performed on the fluctuation range [0.20, 0.46] and the fluctuation frequency 0.75, using the db2 wavelet basis function and a decomposition scale of 2 to obtain multi-level feature sequences. Principal components were extracted from the multi-level feature sequences to obtain constraint boundary values ​​and constraint thresholds. The extraction method was to calculate the weighted average of the coefficients at each scale. The weighted average of the multi-level feature sequences of the fluctuation range yielded the constraint boundary value [0.18, 0.48], and the weighted average of the multi-level feature sequences of the fluctuation frequency yielded the constraint threshold 0.80.

[0122] The feature space is obtained by eigenvalue decomposition of the constraint boundary values ​​and constraint thresholds. The eigenvalue decomposition method combines the constraint boundary values ​​and constraint thresholds into vectors, and performs principal component analysis on the vectors to obtain the principal component space. A constraint matrix is ​​constructed in the feature space by mapping the constraint boundary values ​​and constraint thresholds to the feature space, forming a constraint relationship matrix. Hierarchical clustering is performed on the constraint matrix to extract stable features. Hierarchical clustering uses an agglomerative clustering algorithm to calculate the similarity of each element in the constraint matrix and cluster them according to the similarity to obtain a stable feature set. Node execution time constraints are generated based on the stable features. The generation method maps the stable features back to the original feature space to construct constraint condition expressions. For the node execution time of medical aesthetic service transactions, the generated constraint condition is: when the node execution time deviates from the constraint boundary value [0.18, 0.48] or the change frequency exceeds the constraint threshold of 0.80, a risk warning is triggered.

[0123] In this embodiment, mathematical tools such as singular value decomposition and eigenvalue decomposition are used to effectively extract the implicit time patterns and fluctuation characteristics in transaction data, reducing the interference of data noise on risk assessment. Through multi-scale transformation and hierarchical clustering techniques, a fine characterization of fluctuation ranges and frequencies is achieved, resulting in constraints with strong adaptability and robustness. The automated conversion process from raw transaction data to constraints avoids the subjectivity and uncertainty of manually setting thresholds based on experience, improving the accuracy and reliability of risk warnings for medical aesthetic service transactions and effectively reducing transaction risks.

[0124] In one optional implementation, based on the transaction risk type, the execution dependencies between nodes in the transaction process are analyzed to determine the nodes to be executed that depend on the risk nodes. A preventative verification instruction containing a modified node execution duration threshold is generated for each node to be executed and sent to the user terminal and service provider terminal, including:

[0125] Extract the node execution sequence from the transaction process, construct the information state transition probability matrix based on the node execution sequence, calculate the execution dependency probability and information propagation coefficient between nodes in combination with the transaction risk type, and combine the execution dependency probability and information propagation coefficient to generate the execution dependency matrix.

[0126] The execution dependency matrix is ​​subjected to eigenvalue decomposition to obtain node execution feature vectors. An execution dependency network between nodes is constructed based on the node execution feature vectors. Execution dependency links are extracted from the execution dependency network. Nodes to be executed that have execution dependencies with risk nodes are identified through the execution dependency links.

[0127] Extract the time-series state sequence from the execution records of the node to be executed, convert the time-series state sequence into a state probability distribution, and calculate the node execution risk score based on the state probability distribution;

[0128] For nodes to be executed, a risk monitoring interval is set based on the node execution risk score. The verification time point and verification granularity parameters are determined according to the risk monitoring interval. The corrected node execution duration threshold is converted into a preventive verification instruction according to the verification time point and verification granularity parameters.

[0129] Preventive verification instructions are sent to user terminals and service provider terminals via encrypted channels.

[0130] The execution sequence of nodes is extracted from the transaction process. This extraction method involves arranging the execution status of each node in chronological order based on transaction log records to obtain a complete node execution sequence. The medical aesthetics service transaction process typically includes nodes such as consultation and appointment, service selection, payment confirmation, identity verification, service appointment, preliminary examination, service implementation, and post-operative follow-up. An information state transition probability matrix is ​​constructed based on the node execution sequence. This is done by statistically analyzing the transition frequency between nodes in historical transaction data and calculating the transition probability. For medical aesthetics service transactions, we assume the statistically obtained transition probabilities between some nodes are as follows: consultation and appointment to service selection is 0.85, service selection to payment confirmation is 0.68, payment confirmation to identity verification is 0.92, and identity verification to service appointment is 0.78. The execution dependency probability between nodes is calculated by combining the transaction risk type with the product of the basic transition probability and the risk type adjustment coefficient. For the "high-risk - rapid upward trend" type, the adjustment coefficient is 1.2, and the calculated execution dependency probability is: the dependency probability from consultation appointment to service selection is 0.85×1.2=1.02 (the probability value is taken as 1 when it exceeds 1), and the dependency probability from service selection to payment confirmation is 0.68×1.2=0.816.

[0131] The information propagation coefficient between nodes is calculated by analyzing the overlap and influence of the information content transmitted between nodes. Information content overlap is calculated by comparing the similarity of the node's input and output parameters, while information influence is calculated by the degree to which the node affects subsequent decision-making processes. In a medical aesthetics service transaction, the information content overlap between the payment confirmation node and the identity verification node is 0.65, and the information influence is 0.75, resulting in a combined information propagation coefficient of 0.7. The execution dependency probability and information propagation coefficient are combined to generate an execution dependency matrix using a weighted average method with weights of 0.6 and 0.4, respectively. In the generated execution dependency matrix, the dependency strength from the payment confirmation node to the identity verification node is 0.92 × 0.6 + 0.7 × 0.4 = 0.832.

[0132] Eigenvalue decomposition is performed on the execution dependency matrix to obtain node execution feature vectors. The feature decomposition method calculates the eigenvalues ​​and eigenvectors of the matrix, selecting the eigenvectors corresponding to the principal eigenvalues. The execution dependency matrix is ​​then decomposed to obtain a sequence of eigenvectors, and the first three principal eigenvectors are selected to form an eigenvector matrix. An execution dependency network is constructed based on the node execution feature vectors. This is done by mapping the feature vectors to the network space, with the dependency strength between nodes serving as the weight of the network connections. In the constructed execution dependency network, nodes represent various operation points in the transaction process, edges represent dependencies between nodes, and the edge weights represent dependency strength. Execution dependency links are extracted from the execution dependency network. This extraction method sets a dependency strength threshold and filters out node pairs with dependency strengths exceeding the threshold, forming dependency links. With a threshold of 0.8, the extracted dependency links include "payment confirmation → identity verification → service reservation". Execution dependency links identify nodes that have execution dependencies on risk nodes. This identification method finds the direct successor nodes of the risk node in the dependency link. Assuming the payment confirmation node is identified as a risk node, the execution nodes dependent on the payment confirmation node are the identity verification node and the service reservation node.

[0133] The execution records of nodes awaiting execution are used to extract a temporal state sequence. This extraction method records the changes in the execution state of nodes in chronological order. In medical aesthetics service transactions, the temporal state sequence of an identity verification node may include states such as "Pending Verification → Verification in Progress → Verification Passed / Verification Failed." The temporal state sequence is then converted into a state probability distribution. This conversion method involves statistically analyzing the frequency of each state and calculating its probability distribution. The probability distribution of the identity verification node's state might be: 0.15 for "Pending Verification," 0.25 for "Verification in Progress," 0.55 for "Verification Passed," and 0.05 for "Verification Failed." Based on the state probability distribution, a node execution risk score is calculated. The calculation formula is the weighted sum of the risk weight of each state and its probability. The risk weights for each state of the identity verification node are 0.2, 0.4, 0.1, and 0.8, respectively. The calculated risk score is 0.15×0.2 + 0.25×0.4 + 0.55×0.1 + 0.05×0.8 = 0.225.

[0134] For nodes to be executed, a risk monitoring interval is set based on the node execution risk score. This is achieved by mapping the risk score to a predefined risk level range. Assuming risk levels are categorized as low risk (0-0.3), medium risk (0.3-0.6), and high risk (0.6-1.0), the risk monitoring interval for authentication nodes is the low-risk interval. Verification time points and granularity parameters are determined based on the risk monitoring interval. For high-risk intervals, more frequent verification time points and finer granularity are used. For authentication nodes in the low-risk interval, the verification time point is set to 30 seconds after node execution begins, and the granularity parameter is 60 seconds, meaning verification occurs every 60 seconds. The modified node execution duration threshold is converted into a preventative verification instruction based on the verification time point and granularity parameters. This conversion method generates an instruction format containing the verification time point, granularity, and execution duration threshold. The generated preventative verification instruction is: "Node: Authentication, Verification Time Point: 30 seconds, Verification Granularity: 60 seconds, Execution Duration Threshold: 180 seconds".

[0135] Preventative verification instructions are sent to user terminals and service provider terminals via an encrypted channel. The instructions are encrypted using asymmetric encryption technology and transmitted to the terminal devices via a secure communication protocol. Upon receiving the verification instruction, the user terminal prompts the user to confirm the operation progress at a specified verification time and determines if any anomalies exist based on an execution duration threshold. Upon receiving the verification instruction, the service provider terminal initiates a monitoring program in the system background to track the execution status of the corresponding nodes in real time. When the execution duration is detected to be approaching the threshold, an early warning mechanism is triggered, alerting operators to the transaction risks.

[0136] In this embodiment, the node dependency characteristics in the medical aesthetics service transaction process are accurately captured using information state transition probability matrix and eigenvalue decomposition technology, providing a scientific basis for risk propagation path analysis. By constructing a node execution dependency network and extracting dependency links, nodes to be executed affected by risk nodes are accurately identified, preventing the spread and escalation of risks. A monitoring mechanism based on node execution risk scoring enables the rational allocation of risk control resources and improves system efficiency. The generation and issuance of preventative verification instructions provide an effective means for early intervention in medical aesthetics service transaction risks, significantly improving the timeliness and accuracy of risk warnings and ensuring transaction security and user rights.

[0137] In one optional implementation, the execution dependency matrix is ​​subjected to eigenvalue decomposition to obtain node execution feature vectors. An inter-node execution dependency network is constructed based on these feature vectors. Execution dependency links are extracted from the network, and nodes to be executed that have execution dependencies on risky nodes are identified through these links.

[0138] The execution dependency matrix is ​​projected onto the time and space dimensions to obtain the projection matrix. The eigenvalue distribution of the projection matrix is ​​calculated. Information gain weights are constructed based on the skewness and kurtosis of the eigenvalue distribution. The node execution feature components are extracted from the execution dependency matrix using the information gain weights.

[0139] Based on the node execution feature components, calculate the time-series autocorrelation coefficient and cross-correlation coefficient, calculate the spatial covariance value and correlation coefficient, and combine them to generate the node execution feature vector;

[0140] The node association matrix is ​​obtained by calculating the cosine distance between the node execution feature vectors. An execution dependency network between nodes is constructed based on the node association matrix. The information entropy value of the nodes in the execution dependency network is calculated, and the execution dependency links are extracted according to the rate of change of the information entropy value.

[0141] The propagation path length from the risk node to each node in the execution dependency link is calculated as the propagation attenuation coefficient. The fluctuation threshold is determined based on the mean and standard deviation of the propagation attenuation coefficient. Nodes whose propagation attenuation coefficient exceeds the fluctuation threshold are identified as nodes to be executed that have an execution dependency relationship with the risk node.

[0142] The execution dependency matrix is ​​projected onto the time and space dimensions to obtain the projection matrix. A linear projection transformation is used, and the cumulative distribution of matrix elements is calculated along the time and space axes, respectively. For the execution dependency matrix in a medical aesthetics service transaction, assuming a matrix size of 6×6, it represents the dependencies between six nodes: consultation appointment, service selection, payment confirmation, identity verification, service appointment, and service implementation. After the projection transformation, the time-dimensional projection matrix and the space-dimensional projection matrix are obtained, representing the evolutionary characteristics of nodes in the time series and the correlation characteristics in the spatial structure, respectively. The eigenvalue distribution of the projection matrix is ​​calculated by performing eigenvalue decomposition on the projection matrix to obtain the eigenvalue sequence and calculating the statistical distribution characteristics of the eigenvalues. For the eigenvalue distribution of the time-dimensional projection matrix, the calculated eigenvalue sequence is [0.92, 0.75, 0.61, 0.43, 0.28, 0.11].

[0143] Information gain weights are constructed based on the skewness and kurtosis values ​​of the eigenvalue distribution. Skewness is calculated as the third central moment divided by the cube of the standard deviation, and kurtosis is calculated as the fourth central moment divided by the square of the variance minus 3. For the eigenvalue distribution [0.92, 0.75, 0.61, 0.43, 0.28, 0.11], the calculated skewness is -0.31, indicating a slightly left-skewed distribution; the kurtosis is -1.24, indicating a relatively flat distribution. The information gain weights are constructed as a weighted sum of the normalized absolute values ​​of skewness and kurtosis, with a weight allocation of 0.4 for skewness and 0.6 for kurtosis. The calculated information gain weight is (0.31 / 1.55)×0.4 + (1.24 / 1.55)×0.6 = 0.56. Information gain weights are used to extract node execution feature components from the execution dependency matrix. The extraction method involves multiplying each element of the execution dependency matrix by the information gain weight to obtain a weight matrix, and then extracting the main feature components from the weight matrix. For the execution dependency matrix of medical aesthetic service transactions, the extracted node execution feature components are feature vectors of six nodes.

[0144] The time-series autocorrelation coefficient and cross-correlation coefficient are calculated based on the node execution feature components. The autocorrelation coefficient is calculated using the delayed autocorrelation function of the feature component, and the cross-correlation coefficient is calculated using the cross-correlation function between different feature components. For the feature component sequence of the service selection node [0.78, 0.69, 0.54, 0.42, 0.35, 0.29], the calculated first-order autocorrelation coefficient is 0.94, indicating strong temporal continuity; the cross-correlation coefficient with the feature component of the payment confirmation node is 0.87, indicating high temporal dependence between the two nodes. The spatial covariance and correlation coefficient are calculated. The covariance is calculated using the second-order central moment of the feature component, and the correlation coefficient is calculated using the product of the covariance and the standard deviation. For the service selection node and the payment confirmation node, the calculated covariance is 0.12, and the correlation coefficient is 0.82, indicating high spatial correlation. The node execution feature vector is generated by combining the temporal and spatial features into a high-dimensional vector, followed by dimensionality reduction using principal component analysis. The generated node execution feature vector has a dimension of 4, representing temporal autocorrelation, temporal cross-correlation, spatial covariance, and spatial correlation, respectively.

[0145] The node association matrix is ​​obtained by calculating the cosine distance between the feature vectors of the execution nodes. The cosine distance is calculated as 1 minus the inner product of the feature vectors divided by the product of their moduli. For the feature vectors of the service selection node and the payment confirmation node, the calculated cosine distance is 0.12, indicating high feature similarity between the two nodes and an association strength of 1-0.12=0.88. An execution dependency network is constructed based on the node association matrix. The construction method is to connect node pairs with an association strength greater than a threshold, which is set to 0.7. In the constructed execution dependency network, nodes represent the six operation points in the transaction process, edges represent the dependencies between nodes, and the weights of the edges represent the association strength. The information entropy value of the nodes in the execution dependency network is calculated using the normalized entropy of the edge weights connecting the nodes. For the payment confirmation node, the edge weights are [0.88, 0.92, 0.75], and the calculated information entropy value is 1.52. Execution dependency links are extracted according to the rate of change of information entropy values. The extraction method is to find the path with the largest rate of change of information entropy as the primary dependency link. In medical aesthetic service transactions, the main execution dependency chain extracted is "consultation and appointment → service selection → payment confirmation → identity verification → service appointment", with an information entropy change rate of 0.38.

[0146] The propagation path length from the risk node to each node in the execution dependency chain is calculated as the propagation attenuation coefficient. The calculation method is the shortest path length between the risk node and the target node in the dependency network. Assuming the payment confirmation node is a risk node, the propagation path length to the identity verification node is 1, to the service reservation node is 2, and to the service implementation node is 3. These path lengths are the corresponding propagation attenuation coefficients. The fluctuation threshold is determined based on the mean and standard deviation of the propagation attenuation coefficients. The fluctuation threshold is calculated as the product of the mean and the standard deviation, with the product coefficient set according to risk sensitivity. For the propagation attenuation coefficients [1, 2, 3], the calculated mean is 2, the standard deviation is 0.82, and the coefficient is set to 1.2. Therefore, the upper limit of the fluctuation threshold is 2 + 0.82 × 1.2 = 2.98, and the lower limit of the fluctuation threshold is 2 - 0.82 × 1.2 = 1.02. Nodes whose propagation attenuation coefficients exceed the fluctuation threshold are identified as execution nodes with execution dependencies on the risk node. The determination method is to compare the relationship between the propagation attenuation coefficient and the fluctuation threshold. An authentication node with a propagation attenuation coefficient of 1 is less than the lower fluctuation threshold of 1.02. Therefore, the authentication node is identified as an execution node with a significant execution dependency on the risk node.

[0147] In this embodiment, by introducing information gain weights constructed from skewness and kurtosis values, the ability to capture non-normal distribution characteristics is enhanced, improving the accuracy of feature extraction. The execution dependency network constructed based on cosine distance and the dependency links extracted from information entropy change rate accurately reflect the propagation path and scope of risk in the transaction process. The introduction of a propagation attenuation coefficient makes quantitative assessment of risk impact possible, providing a reliable basis for the accurate identification of nodes to be executed. This achieves an automated analysis process from risk nodes to nodes to be executed, significantly improving the foresight and targeting of risk warnings in medical aesthetic service transactions, and providing strong protection for transaction security.

[0148] A second aspect of the present invention provides a risk warning system for medical aesthetic service transaction data, the system comprising:

[0149] The acquisition unit is used to acquire the time sequence of user operations during the transaction process, the validity period of the service provider's qualifications, and the execution duration of transaction nodes.

[0150] The processing unit is used to extract the time interval between adjacent operations in the user operation time series, perform alignment analysis between the time interval and the service institution's qualification validity information in the time dimension, identify the overlap between the moment when the time interval changes abruptly and the moment when the qualification validity is about to expire, and generate the correlation anomaly measurement value.

[0151] The risk determination unit is used to identify a transaction node as a risk node and label the transaction risk type when the ratio of the associated abnormal metric value to the execution time of the transaction node deviates from the statistical distribution range of normal transactions.

[0152] The correction unit is used to extract the node execution time deviation features corresponding to the transaction risk type from historical risk transaction data, use the node execution time deviation features as constraints, correct the expected execution time of each node to be executed in the current transaction process, and generate the corrected node execution time threshold.

[0153] The execution unit is used to analyze the execution dependencies between nodes in the transaction process based on the transaction risk type, determine the nodes to be executed that depend on the risk nodes, generate preventive verification instructions for the nodes to be executed that include the corrected node execution time threshold, and send them to the user terminal and the service institution terminal.

[0154] A third aspect of the present invention provides an electronic device, comprising:

[0155] processor;

[0156] Memory used to store processor-executable instructions;

[0157] The processor is configured to invoke instructions stored in the memory to execute the aforementioned method.

[0158] A fourth aspect of the present invention provides a computer-readable storage medium having stored thereon computer program instructions that, when executed by a processor, implement the aforementioned method.

[0159] This invention can be a method, apparatus, system, and / or computer program product. The computer program product may include a computer-readable storage medium having computer-readable program instructions loaded thereon for performing various aspects of the invention.

[0160] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some or all of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present invention.

Claims

1. A risk warning method for medical aesthetic service transaction data, characterized in that, include: Obtain the time sequence of user operations during the transaction process, the validity period of service provider qualifications, and the execution duration of transaction nodes; Extract the time interval between adjacent operations in the user operation time series, perform alignment analysis between the time interval and the service institution's qualification validity information in the time dimension, identify the overlap between the moment when the time interval changes abruptly and the moment when the qualification validity is about to expire, and generate correlation anomaly measurement values; When the ratio of the associated abnormal metric value to the execution time of the transaction node deviates from the statistical distribution range of normal transactions, the transaction node is identified as a risk node, and the transaction risk type is marked. Extract the node execution time deviation features corresponding to the transaction risk type from historical risk transaction data, use the node execution time deviation features as constraints to correct the expected execution time of each node to be executed in the current transaction process, and generate the corrected node execution time threshold. Based on the type of transaction risk, the execution dependencies between nodes in the transaction process are analyzed to identify the nodes to be executed that depend on the risk nodes. Preventive verification instructions containing the corrected node execution time threshold are generated for the nodes to be executed and sent to the user terminal and the service institution terminal.

2. The method according to claim 1, characterized in that, Extract the time intervals between adjacent user operations in the time series, align these time intervals with the service provider's qualification validity information along the time dimension, identify the overlap between moments of abrupt time interval changes and moments when the qualification validity is nearing expiration, and generate correlation anomaly metrics including: Extract the timestamps of adjacent operations in the user operation time series, calculate the difference between adjacent timestamps, generate a time interval series, and perform smoothing processing. Calculate the rate of change and acceleration of change of the smoothed time interval series, construct a time interval abrupt change judgment threshold, and divide the time interval series into multiple time interval segments according to the time interval abrupt change judgment threshold. Calculate the mean and standard deviation of the time interval within the time interval segments, and determine the candidate time interval abrupt change based on the difference in mean and standard deviation between adjacent time interval segments; Calculate the change amplitude score, duration score, and fluctuation degree score of the candidate time interval abrupt change moment, combine them to generate a time interval abrupt change intensity value, and determine the time interval abrupt change moment based on the time interval abrupt change intensity value; Calculate the remaining duration and duration decay rate of the service provider's qualification validity information, and determine the time when the qualification validity period is about to expire based on the duration decay rate; Align the abrupt change in time interval with the time when the qualification validity period is about to expire in the time dimension, calculate the overlapping interval, and generate a related anomaly metric based on the overlapping interval.

3. The method according to claim 1, characterized in that, When the ratio of the associated abnormal metric value to the execution time of a transaction node deviates from the statistical distribution range of normal transactions, the transaction node is identified as a risk node, and the transaction risk type is labeled as follows: The execution time of the transaction node is normalized to generate a normalized execution time. The associated anomaly metric is mapped to the normalized execution time. The ratio of the associated anomaly metric to the normalized execution time is calculated to generate a ratio sequence. The ratio sequence is divided into multiple time windows, and the mean, variance and standard deviation within each time window are calculated to construct a distribution feature matrix. Based on the distribution feature matrix, the statistical distribution interval of normal transactions is determined. Calculate the deviation of the ratio sequence from the statistical distribution interval of normal transactions, and generate the deviation sequence; The deviation value sequence is grouped, the distribution density of each group is calculated, and the transaction nodes whose distribution density exceeds the preset witness threshold are identified as candidate risk nodes. Calculate the temporal and distribution characteristics of candidate risk nodes, and determine the candidate risk nodes whose combined value of the temporal and distribution characteristics exceeds a preset risk threshold as risk nodes; Wavelet transform is performed on the deviation value sequence of risk nodes to obtain multi-scale decomposition coefficients. The magnitude and rate of change of each scale decomposition coefficient are calculated. The risk level is determined according to the magnitude of the magnitude and a preset grading threshold. The evolution type is determined according to the rate of change and a preset trend threshold. The combination result of risk level and evolution type is labeled as the trading risk type.

4. The method according to claim 1, characterized in that, Extract the node execution time deviation features corresponding to the transaction risk type from historical risk transaction data. Use these node execution time deviation features as constraints to correct the expected execution time of each node to be executed in the current transaction process, generating corrected node execution time thresholds, including: Select the node execution time sequence corresponding to the transaction risk type from historical risk transaction data, calculate the time difference sequence of execution time of adjacent nodes, perform segmented statistics on the time difference sequence to obtain a numerical distribution matrix, calculate the mean and standard deviation of the time difference based on the numerical distribution matrix, and use the combined feature of the mean and standard deviation as the node execution time deviation feature. By utilizing the node execution time deviation features, a feature vector is constructed. The projection distribution of the feature vector in the time dimension is calculated. The fluctuation range and fluctuation frequency of the projection distribution are extracted. The fluctuation range is mapped to the constraint boundary value, and the fluctuation frequency is mapped to the constraint threshold. The node execution time constraint conditions are generated by combining these features. The expected execution time sequence of the nodes to be executed in the current transaction process is divided into segments according to the segmentation method of time difference sequence. The distance difference between the segment and the constraint boundary value is calculated. Based on the distance difference and the constraint threshold, the correction coefficient matrix is ​​calculated. The segments of the expected execution time sequence are corrected according to the correction coefficient matrix. The corrected expected execution time sequence is segmented for verification. The deviation of each segment from the original sequence is calculated. Segments with deviations exceeding the preset deviation range are marked as segments to be optimized. New correction coefficients are calculated based on the correction coefficient matrix. The segments to be optimized are corrected. The correction process is repeated until the deviation of all segments is within the preset deviation range. Finally, the corrected node execution time threshold is generated.

5. The method according to claim 4, characterized in that, A feature vector is constructed using the node execution time deviation feature. The projection distribution of the feature vector in the time dimension is calculated, and the fluctuation range and fluctuation frequency of the projection distribution are extracted. The fluctuation range is mapped to the constraint boundary value, and the fluctuation frequency is mapped to the constraint threshold. The node execution time constraints are generated by combining these constraints. The node execution time deviation feature is converted into a time-numerical two-dimensional feature matrix. Singular value decomposition is performed on the time-numerical two-dimensional feature matrix to obtain singular value vectors. Feature components are reconstructed based on the singular value vectors. The feature components are divided into multiple time windows according to the time dimension. Segmentation processing is performed in each time window to obtain feature vectors. Eigenvalue decomposition is performed on the eigenvectors to obtain eigenvalue sequences and eigenvector sequences. Based on the eigenvalue sequences, the eigenvector sequences are selected to construct a projection matrix. The projection matrix is ​​then reconstructed in the time dimension to obtain the projection distribution. The maximum and minimum points of the projected distribution are calculated to obtain the wave boundary point sequence. The wave interval is divided based on the wave boundary point sequence, and the wave frequency is obtained by calculating the time difference between adjacent wave boundary points. Multi-scale transformation is performed on the fluctuation range and fluctuation frequency to obtain a multi-layer feature sequence. Principal components are extracted from the multi-layer feature sequence to obtain the constraint boundary value and constraint threshold. The constraint boundary values ​​and constraint thresholds are decomposed to obtain the feature space. A constraint matrix is ​​constructed in the feature space. Hierarchical clustering is performed on the constraint matrix to extract stable features. Based on the stable features, node execution time constraints are generated.

6. The method according to claim 1, characterized in that, Based on the type of transaction risk, the execution dependencies between nodes in the transaction process are analyzed to identify nodes to be executed that depend on risk nodes. Preventive verification instructions containing revised node execution duration thresholds are generated for these nodes and sent to user terminals and service provider terminals, including: Extract the node execution sequence from the transaction process, construct the information state transition probability matrix based on the node execution sequence, calculate the execution dependency probability and information propagation coefficient between nodes in combination with the transaction risk type, and combine the execution dependency probability and information propagation coefficient to generate the execution dependency matrix. The execution dependency matrix is ​​subjected to eigenvalue decomposition to obtain node execution feature vectors. An execution dependency network between nodes is constructed based on the node execution feature vectors. Execution dependency links are extracted from the execution dependency network. Nodes to be executed that have execution dependencies with risk nodes are identified through the execution dependency links. Extract the time-series state sequence from the execution records of the node to be executed, convert the time-series state sequence into a state probability distribution, and calculate the node execution risk score based on the state probability distribution; For nodes to be executed, a risk monitoring interval is set based on the node execution risk score. The verification time point and verification granularity parameters are determined according to the risk monitoring interval. The corrected node execution duration threshold is converted into a preventive verification instruction according to the verification time point and verification granularity parameters. Preventive verification instructions are sent to user terminals and service provider terminals via encrypted channels.

7. The method according to claim 6, characterized in that, The execution dependency matrix is ​​subjected to eigenvalue decomposition to obtain node execution feature vectors. An execution dependency network between nodes is constructed based on these feature vectors. Execution dependency links are extracted from this network, and nodes with execution dependencies on risky nodes are identified through these links. The execution dependency matrix is ​​projected onto the time and space dimensions to obtain the projection matrix. The eigenvalue distribution of the projection matrix is ​​calculated. Information gain weights are constructed based on the skewness and kurtosis of the eigenvalue distribution. The node execution feature components are extracted from the execution dependency matrix using the information gain weights. Based on the node execution feature components, calculate the time-series autocorrelation coefficient and cross-correlation coefficient, calculate the spatial covariance value and correlation coefficient, and combine them to generate the node execution feature vector; The node association matrix is ​​obtained by calculating the cosine distance between the node execution feature vectors. An execution dependency network between nodes is constructed based on the node association matrix. The information entropy value of the nodes in the execution dependency network is calculated, and the execution dependency links are extracted according to the rate of change of the information entropy value. The propagation path length from the risk node to each node in the execution dependency link is calculated as the propagation attenuation coefficient. The fluctuation threshold is determined based on the mean and standard deviation of the propagation attenuation coefficient. Nodes whose propagation attenuation coefficient exceeds the fluctuation threshold are identified as nodes to be executed that have an execution dependency relationship with the risk node.

8. A risk warning system for medical aesthetic service transaction data, used to implement the method of any one of claims 1-7, characterized in that, include: The acquisition unit is used to acquire the time sequence of user operations during the transaction process, the validity period of the service provider's qualifications, and the execution duration of transaction nodes. The processing unit is used to extract the time interval between adjacent operations in the user operation time series, perform alignment analysis between the time interval and the service institution's qualification validity information in the time dimension, identify the overlap between the moment when the time interval changes abruptly and the moment when the qualification validity is about to expire, and generate the correlation anomaly measurement value. The risk determination unit is used to identify a transaction node as a risk node and label the transaction risk type when the ratio of the associated abnormal metric value to the execution time of the transaction node deviates from the statistical distribution range of normal transactions. The correction unit is used to extract the node execution time deviation features corresponding to the transaction risk type from historical risk transaction data, use the node execution time deviation features as constraints, correct the expected execution time of each node to be executed in the current transaction process, and generate the corrected node execution time threshold. The execution unit is used to analyze the execution dependencies between nodes in the transaction process based on the transaction risk type, determine the nodes to be executed that depend on the risk nodes, generate preventive verification instructions for the nodes to be executed that include the corrected node execution time threshold, and send them to the user terminal and the service institution terminal.

9. An electronic device, characterized in that, include: processor; Memory used to store processor-executable instructions; The processor is configured to invoke instructions stored in the memory to execute the method according to any one of claims 1 to 7.

10. A computer-readable storage medium having computer program instructions stored thereon, characterized in that, When the computer program instructions are executed by the processor, they implement the method described in any one of claims 1 to 7.