Bank comprehensive business internet big data risk control method based on multi-agent collaborative decision-making

By dividing the business link nodes and anchoring breakpoints in the mobile banking integrated business session, the problem of difficulty in locating the breakpoint between the identity verification node and the fund processing node in the existing technology has been solved, and more accurate risk identification and fund transfer control have been achieved.

CN122335425BActive Publication Date: 2026-07-31NANJING DAYAN DIGITAL TECHNOLOGY CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
NANJING DAYAN DIGITAL TECHNOLOGY CO LTD
Filing Date
2026-06-03
Publication Date
2026-07-31

AI Technical Summary

Technical Problem

Existing bank payment risk identification technologies struggle to pinpoint the breakpoints between identity verification and fund processing nodes in mobile banking integrated business sessions, resulting in a missing risk identification link structure and insufficient risk level correction after account takeover.

Method used

The session entry node, identity verification node, business purpose node, and business status feedback node are divided into business link nodes. The link correction agent group anchors the connection breakpoints to form business link breakpoints. The dense chain segment of breakpoints between the identity verification node and the fund processing node is intercepted to correct the risk level output by the agent.

Benefits of technology

It improves the integrity of the risk identification chain and the accuracy of breakpoint location in mobile banking integrated business sessions, reduces the misjudgment of local low-risk nodes by a single model, and enhances the timeliness of fund transfer interception.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122335425B_ABST
    Figure CN122335425B_ABST
Patent Text Reader

Abstract

This invention relates to the technical field of internet banking risk control, and discloses a method for internet big data risk control of integrated banking business based on multi-agent collaborative decision-making. The method includes: dividing the same customer session into business link nodes, transforming mobile banking integrated business from discrete events into verifiable continuous links; anchoring connection breakpoints through link correction agent groups to locate abnormal session entry points, missing verification links, sudden changes in business objectives, and mismatched state pointers; extracting densely populated breakpoint segments between identity verification nodes and fund processing nodes to highlight the critical risk interval between account takeover and fund transfer; and then correcting the risk level output by each agent based on the breakpoint type and node location to reduce misjudgments of local low-risk nodes by a single model; thus improving the link integrity, breakpoint location accuracy, and timeliness of fund transfer interception in integrated business session risk identification.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the technical field of risk control in internet banking, and in particular to a method for risk control of comprehensive banking business based on multi-agent collaborative decision-making using internet big data. Background Technology

[0002] In mobile banking integrated business sessions, customers typically access account services through the mobile banking client, mini-program, SMS redirection, or third-party authorized entry. Within the same customer session, they sequentially go through business nodes such as login, identity verification, account inquiry, credit limit inquiry, payee maintenance, loan withdrawal, fund transfer, or wealth management redemption. Due to the existence of risk factors such as unofficial entry redirection, remote control, session hijacking, device replacement, and abnormal association of identity verification results, abnormal fund transfers may not necessarily manifest as abnormal single transaction amounts, but may be manifested as sudden changes in the session entry source, identity verification results, etc. If the customer session is not associated with subsequent business nodes, the business purpose jumps from the query node to the fund change node, or the subsequent business status cannot be traced back to the previous business processing status, there are chain anomalies. Traditional bank risk control technologies mostly rely on transaction amount, account history behavior, device fingerprints, blacklist rules or single risk models for identification. It is difficult to locate the concentrated distribution of multiple connection breakpoints between the identity verification node and the fund processing node. Therefore, the risk identification of rapid fund transfer after account takeover still has problems such as missing chain structure, unclear breakpoint location and insufficient correction of multi-model risk levels.

[0003] CN114708090A discloses a risk identification device for bank payment business based on big data, which includes a bank payment business acceptance module, a payment big data access module, a payment big data risk identification engine module, a payment big data user rating module, and a payment big data risk processing module. It improves the accuracy of risk approval for bank payment business through payment big data access and the risk identification engine, and solves problems such as slow querying of payment-related data, cumbersome risk identification confirmation, and delayed freezing of risky payment accounts. The technical focus of this solution is on payment business data access, the payment risk identification engine, and user rating processing, which can identify risky accounts or risky payment behaviors in bank payment business. However, this solution still focuses on the data processing and risk identification of the payment business itself, and does not divide the session entry node, identity verification node, business purpose node, and business status feedback node according to the order of business occurrence in the same customer session, nor does it form a business link breakpoint around the entry connection, verification connection, purpose transfer, and status feedback. Therefore, the identification device provided by CN114708090A still has difficulty identifying the densely connected chain segments between the identity verification node and the fund processing node in the continuous session from login entry, identity verification, change of business purpose to fund processing after account takeover.

[0004] CN117788164A discloses a multi-agent collaborative control algorithm and system for a large language model in the securities and futures industry. It employs a first agent module, a second agent module, and a third agent module to analyze different information. The first and second agent modules engage in a game based on the analysis results of the same task, and the third agent module adjusts its analysis based on the game results to arrive at a decision, thus making the final decision more reasonable and accurate. However, this solution is applied to task decision-making in the securities and futures industry, and its technical focus is on the analysis, game, and decision adjustment of multiple agents based on different information. It does not address the node connections between entry points, identity verification, changes in business purpose, and business status feedback in mobile banking integrated business internet sessions, nor does it disclose how to correct the risk level output of each agent based on the dense distribution of business link breakpoints between the identity verification node and the fund processing node. Therefore, although the method disclosed in CN117788164A involves multi-agent collaboration, it is difficult to solve the problem of link breakpoint location for account takeover and fund transfer risks in mobile banking integrated business sessions.

[0005] Given that existing bank payment risk identification technologies tend to focus on payment business data access, rule engines, or user ratings, and existing multi-agent collaborative decision-making technologies tend to focus on task analysis, game theory, and result adjustment, all of these technologies lack mechanisms for dividing business link nodes for the same customer session, anchoring adjacent connections, intercepting dense chain segments with breakpoints between identity verification nodes and fund processing nodes, and correcting risk levels for multiple agents, this invention proposes a risk control method for integrated banking business based on multi-agent collaborative decision-making using internet big data. This method solves the problem of how to locate breakpoints and correct risk levels for link anomalies before fund transfer after account takeover in mobile banking integrated business sessions. Summary of the Invention

[0006] The purpose of this section is to outline some aspects of the embodiments of the present invention and to briefly introduce some preferred embodiments. Some simplifications or omissions may be made in this section, as well as in the abstract and title of the present application, to avoid obscuring the purpose of this section, the abstract and title of the invention. Such simplifications or omissions shall not be used to limit the scope of the present invention.

[0007] In view of the aforementioned existing problems, the present invention is proposed.

[0008] To solve the above-mentioned technical problems, the present invention provides the following technical solution: according to the order of business occurrence in the same customer session, the session entry node, identity verification node, business destination node, and business status feedback node are divided into business link nodes; The link correction intelligent agent group anchors the connection breakpoints in the entry connection, verification connection, destination transfer and status return according to the adjacent connection relationship of the service link nodes, thus forming the service link breakpoint; The breakpoints in the business link are listed in the order of the business link nodes, and the dense chain segment of breakpoints between the identity verification node and the fund processing node is extracted. Based on the breakpoint type and node position corresponding to the dense breakpoint chain segment, the risk level output by each agent is corrected.

[0009] The beneficial effects of this invention are as follows: By dividing the session entry, identity verification, business purpose, and business status feedback within the same customer session into business link nodes, this invention transforms mobile banking integrated business from discrete events into a verifiable continuous link. Through link correction agents anchoring connection breaks in entry, verification, purpose transfer, and status feedback, it can locate session entry anomalies, missing verification associations, abrupt changes in business purpose, and mismatched status feedback. Furthermore, it extracts densely populated breakpoint segments between the identity verification node and the funds processing node, highlighting the critical risk interval between account takeover and fund transfer. Then, based on the breakpoint type and node location, it corrects the risk level output by each agent, reducing misjudgments of local low-risk nodes by a single model. Therefore, this invention improves the link integrity, breakpoint location accuracy, and timeliness of fund transfer interception in integrated business session risk identification. Attached Figure Description

[0010] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings used in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort. Wherein: Figure 1 This is a flowchart illustrating the internet big data risk control method for integrated banking business based on multi-agent collaborative decision-making, as shown in this invention. Detailed Implementation

[0011] To make the above-mentioned objects, features and advantages of the present invention more apparent and understandable, the specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments.

[0012] Based on the embodiments of this invention, all other embodiments obtained by those skilled in the art without inventive effort should fall within the scope of protection of this invention.

[0013] Many specific details are set forth in the following description in order to provide a full understanding of the invention. However, the invention may also be practiced in other ways different from those described herein, and those skilled in the art can make similar extensions without departing from the spirit of the invention. Therefore, the invention is not limited to the specific embodiments disclosed below.

[0014] In a preferred embodiment, the method of the present invention is applied to the risk control scenario of account takeover and fund transfer in a mobile banking integrated business session. After a customer enters the integrated business page through the mobile banking client, events such as login entry, device change, SMS verification code verification, face verification, adding payee, entering transfer amount, calling account balance status, and submitting fund transfer may occur sequentially. The bank's internet business risk control platform uses the same customer session as a processing unit to merge client events sent by the mobile banking client, server-side business acceptance events, identity verification events generated by the identity authentication system, and business status call events generated by the account business system into the same customer session. The same customer session is defined by at least two of the following: customer session identifier, customer account identifier, terminal device identifier, server acceptance time, and business transaction identifier. When the customer session identifier is missing, the same customer session is supplemented and merged based on the continuity of the customer account identifier, terminal device identifier, and server acceptance time. Events with adjacent server acceptance times not exceeding 300 seconds are merged into the same customer session, while events exceeding 300 seconds and without a continuous business transaction identifier are merged into a new customer session.

[0015] According to an embodiment of the present invention, in combination Figure 1 The flowchart shown illustrates a risk control method for integrated banking business based on multi-agent collaborative decision-making using internet big data, which specifically includes the following steps: S1. Based on the order of business transactions within the same customer session, divide the session entry node, identity verification node, business destination node, and business status feedback node into business link nodes. Note that the following should be noted in this step: S1.1 Extract session entry events, identity verification events, business processing events, and business status call events within the same customer session, and form a session event sequence according to the event occurrence time.

[0016] In a preferred embodiment, the bank's internet business risk control platform extracts events corresponding to the same customer session from a mobile banking client event set, an identity authentication event set, a comprehensive business acceptance event set, and an account status call event set. The mobile banking client event set includes client startup events, login entry events, activity page redirection events, message push entry events, QR code scan entry events, and deep link entry events. The identity authentication event set includes login password verification events, SMS verification code verification events, fingerprint verification events, facial recognition verification events, device binding verification events, and transaction password verification events. The comprehensive business acceptance event set includes payee addition events, transfer page entry events, and transfer amount events. The event set includes events such as amount entry, transfer submission, limit adjustment, login password modification, and device binding change; the account status call event set includes account balance status call events, payee status call events, transaction limit status call events, login device status call events, and historical transaction status call events; during extraction, events within the same customer session are first filtered from the above event set by the customer session identifier; then, the filtered results are cross-checked by the customer account identifier and the server acceptance time; when multiple events exist under the same server acceptance time, they are arranged according to the processing order of client events, identity verification events, business processing events, and business status call events, so that events within the same customer session have a unique sequential position.

[0017] In a preferred embodiment, the session entry event is an event that carries an entry source identifier and generates a path for the customer to enter the integrated business page. The entry source identifier includes one of the following: client homepage entry, message push entry, QR code entry, SMS link entry, and third-party redirection entry. For example, if a customer enters the mobile banking transfer page through an SMS link, then the SMS link entry event is determined to be a session entry event. The identity verification event is an event that generates an identity verification result, which includes one of the following: passed, failed, timed out, canceled, or abnormally interrupted. For example, if a customer completes SMS verification code verification before adding a payee, then the SMS verification code verification event is determined to be an identity verification event. The business processing event is an event that generates a business processing category or... Events that change the business processing category include one of the following: account inquiry, device change, payee management, transfer preparation, fund change, and limit adjustment. For example, if a customer is redirected from the account inquiry page to the payee addition page, the payee addition event is considered a business processing event. Business status invocation events are events that invoke the previous business processing status within the same customer session. The previous business processing status includes one of the following: payee addition status, identity verification passed status, transfer amount confirmed status, account balance available status, and transaction limit available status. For example, if the account balance available status is invoked before a transfer is submitted, the account balance status invocation event is considered a business status invocation event.

[0018] Preferably, the bank's internet business risk control platform first arranges the events extracted within the same customer session from earliest to latest according to the server acceptance time; when two or more events have the same server acceptance time, they are arranged from earliest to latest according to the client generation time; when both the server acceptance time and the client generation time are the same, they are arranged according to the order in which the events enter the bank's internet business risk control platform; after the arrangement is completed, an event sequence position is configured for each event, with the event sequence position increasing continuously from 1, so that each event within the same customer session has a unique event sequence position; the set of events arranged sequentially by the event sequence positions is the session event sequence.

[0019] For example, in the same customer session, the following events occur in sequence: SMS link entry, device binding verification, face verification, new payee, account balance status call, and transfer submission. The corresponding event sequence positions are 1, 2, 3, 4, 5, and 6, and these 6 events form the session event sequence.

[0020] S1.2 Mark the events that generate the source of the business entry in the session event sequence as session entry nodes, mark the events that generate the identity verification results as identity verification nodes, mark the events that cause changes in the business processing category as business destination nodes, and mark the events that call the previous business processing status as business status feedback nodes.

[0021] In a preferred embodiment, the bank's internet business risk control platform checks the event type, business processing category, entry source identifier, identity verification result, and business status call object in the session event sequence one by one, and marks the events as corresponding business link nodes according to the inspection results; for events that carry an entry source identifier and guide customers to the mobile banking integrated business page, the event is marked as a session entry node; for events that generate identity verification results and establish a corresponding relationship between the identity verification results and the same customer session, the event is marked as an identity verification node; for events that change the business processing category from account query category to payee management category, from payee management category to transfer preparation category, from transfer preparation category to fund change category, or from device change category to fund change category, the event is marked as a business destination node; for events that call the previous business processing status in the same customer session and submit the previous business processing status to the next business processing link, the event is marked as a business status feedback node.

[0022] Specifically, events that generate business entry points are determined by three factors: entry point identifier, entry page identifier, and client redirection source. An event is considered a business entry point event if it simultaneously possesses both an entry point identifier and an entry page identifier, and the client redirection source points to the mobile banking integrated business page. Events that generate identity verification results are determined by three factors: verification method, verification result, and verification completion time. An event is considered an identity verification result event if it uses any of the following verification methods: SMS verification code verification, fingerprint verification, facial recognition verification, device binding verification, or transaction password verification, and generates any of the following verification results: passed, failed, timed out, canceled, or abnormally interrupted. Events that cause changes in business processing categories are determined by the previous business processing... The difference between the category and the subsequent business processing category is determined as follows: when two adjacent business processing events have different business processing categories, and the subsequent business processing category belongs to the payee management category, transfer preparation category, fund change category, limit adjustment category, or equipment change category, the subsequent business processing event is determined as an event that causes a change in the business processing category; the event that calls the status of the preceding business processing event is determined by the status call object, the status source business flow identifier, and the customer session identifier. When the status source business flow identifier of the event call belongs to a business processing event that has already occurred within the same customer session, and the status call object is the payee new status, identity verification passed status, account balance available status, or transaction limit available status, the event is determined as an event that calls the status of the preceding business processing event.

[0023] S1.3 Configure node sequence identifiers for the session entry node, identity verification node, business destination node, and business status feedback node in sequence according to their positions in the session event sequence.

[0024] In a preferred embodiment, the bank's internet business risk control platform starts from the first event in the session event sequence and configures node sequence identifiers sequentially for events designated as session entry nodes, identity verification nodes, business purpose nodes, and business status feedback nodes, according to the order of event sequence position from smallest to largest. The node sequence identifier includes five items: customer session identifier, node number, node type, event sequence position, and server acceptance time. The node number increases continuously starting from 1, and the node type is one of the following: session entry type, identity verification type, business purpose type, and business status feedback type.

[0025] For example, in the same customer session C202605190001, the SMS link entry event is the first node, with its node sequence identifier being C202605190001-1-session entry type-event sequence position 1-15:02:11; the face verification event is the second node, with its node sequence identifier being C202605190001-2-identity verification type-event sequence position 2-15:02:35; and the recipient addition event is the third node, with its node sequence... The event sequence is identified as C202605190001-3-Business Purpose Type-Event Sequence Position 3-15:03:12; the account balance status call event is the 4th node, and its node sequence is identified as C202605190001-4-Business Status Feedback Type-Event Sequence Position 4-15:03:21; the transfer submission event is the 5th node, and its node sequence is identified as C202605190001-5-Business Purpose Type-Event Sequence Position 5-15:03:45.

[0026] S1.4. Following the node sequence identifier, connect the session entry node, identity verification node, business destination node, and business status feedback node in sequence to obtain the business link node.

[0027] In a preferred embodiment, the node type of the preceding node, the node type of the following node, and the order relationship between the two adjacent service link nodes are configured; wherein, the node type includes session entry type, identity verification type, service purpose type, and service status feedback type; the order relationship includes the preceding node type, the following node type, and the difference in node order identifier between the two adjacent service link nodes; the difference in node order identifier is the difference between the node order identifier of the following service link node and the node order identifier of the preceding service link node.

[0028] Furthermore, the bank's internet business risk control platform arranges the session entry node, identity verification node, business purpose node, and business status feedback node in ascending order according to the node sequence number in the node sequence identifier. It also configures the preceding node type, following node type, and node sequence identifier difference between adjacent nodes. When the preceding node type is session entry type and the following node type is identity verification type, the two adjacent nodes form an entry-to-verification connection. When the preceding node type is identity verification type and the following node type is business purpose type, the two adjacent nodes form a verification-to-business purpose connection. When both the preceding and following node types are business purpose types, the two adjacent nodes form a business purpose transfer connection. When the preceding node type is business status feedback type and the following node type is business purpose type, the two adjacent nodes form a status feedback-to-business purpose connection. These adjacent connection results constitute the business link nodes.

[0029] It should be noted that this embodiment solves the problem of multiple event sources, mixed event types, and difficulty in directly comparing preceding and following business relationships in account takeover and fund transfer risk control scenarios by converting the scattered entry, verification, business processing, and status call events generated in the mobile banking integrated business session into business link nodes with a unified sequence, unified node type, and unified succession relationship. Through the above processing, the entry source, identity verification, business purpose change, and preceding status call are incorporated into the chain structure of the same customer session, enabling the subsequent link correction intelligent agent group to identify abnormal connection positions based on clear node positions and node types, reducing the probability of misjudgment caused by judging the risk level based on only a single business event.

[0030] S2. The link correction intelligent agent group anchors the connection breakpoints in the entry connection, verification connection, destination transfer, and status return according to the adjacent connection relationship of the service link nodes, thus forming the service link breakpoints. It should be noted that in this step: S2.1. Based on the node sequence identifier of the business link nodes, extract the node type and sequence relationship of two adjacent business link nodes to form an adjacent connection relationship.

[0031] In a preferred embodiment, the bank's internet business risk control platform uses the node sequence identifier in the business link nodes as the sorting basis. First, it forms a candidate adjacent node pair by grouping two business link nodes with adjacent node numbers. Then, it extracts the node type of the preceding business link node, the node type of the following business link node, the node number of the preceding business link node, the node number of the following business link node, the entry source identifier of the preceding business link node, the entry source identifier of the following business link node, the identity verification result, the business processing category, and the preceding business processing status call object from the candidate adjacent node pair to form an adjacent connection relationship. Specifically, the adjacent connection relationship includes the preceding node type, the following node type, the difference in node sequence identifier, the consistency status of the entry source identifier, the association status of the identity verification result, the continuity status of the business processing category, and the return status of the preceding business processing status.

[0032] For example, if node number 1 is the SMS link entry node and node number 2 is the face verification node, then the adjacent connection relationship formed by the two includes the preceding node type being the session entry type, the following node type being the identity verification type, the node order identifier difference being 1, the entry source identifier being the SMS link entry, and the identity verification result association status being pending verification.

[0033] S2.2. In the adjacent connection relationship, the relationship from the session entry node to the identity verification node is classified into entry connection, the relationship from the identity verification node to the business destination node is classified into verification connection, the relationship from the business destination node to the next business destination node is classified into destination transfer, and the relationship from the business status reference node to the preceding business link node it calls is classified into status reference.

[0034] Specifically, the bank's internet business risk control platform combines the types of preceding and following nodes in each adjacent connection relationship for judgment: when the preceding node type is a session entry type and the following node type is an identity verification type, the adjacent connection relationship is classified as an entry connection; when the preceding node type is an identity verification type and the following node type is a business purpose type, the adjacent connection relationship is classified as a verification connection; when the preceding node type is a business purpose type and the following node type is also a business purpose type, the adjacent connection relationship is classified as a purpose transfer; when the preceding node type is a business status reference type, and the status call object corresponding to the business status reference type points to the preceding business link node within the same customer session, the adjacent connection relationship is classified as a status reference.

[0035] For adjacent connection relationships where the preceding node type and the following node type do not conform to the above four combinations, the bank's internet business risk control platform does not delete them directly, but submits them to the link correction intelligent agent group for node consistency verification, and the link correction intelligent agent group determines whether they constitute a connection breakpoint.

[0036] S2.3 The link correction intelligent agent group performs node consistency verification on the entry connection, verification connection, destination transfer and status return respectively, and extracts the following issues: missing corresponding node type, reversed node order, identity verification result not established with the same customer session association with the next business link node, abnormal jump of business destination, and business status cannot be returned to the position of the preceding business link node.

[0037] In a preferred embodiment, the link correction agent group is a software function module configured in the bank's internet business risk control platform. The link correction agent group includes an entry correction agent, a verification correction agent, a destination correction agent, and a return correction agent.

[0038] Specifically, the entry correction agent receives entry connections and adjacent connections that cannot be classified as entry connections but whose preceding node type involves the session entry type; the verification correction agent receives verification connections and adjacent connections involving identity verification types; the destination correction agent receives destination transfers and adjacent connections involving continuous changes in business destination types; the back pointer correction agent receives state back pointers and adjacent connections involving business state call objects; the above four correction agents respectively output the entry source change position, the missing identity verification result association position, the business processing category jump position, and the missing preceding business processing status, and submit the above positions to the business link breakpoint formation step.

[0039] Furthermore, the entry correction agent first checks whether the type of the preceding node in the entry connection is a session entry type, and then checks whether the type of the following node is an identity verification type. When the type of the preceding node in the entry connection is not a session entry type, or the type of the following node is not an identity verification type, the position of the following business link node is extracted as the position where the adjacent connection relationship lacks the corresponding node type. When both the preceding node type and the following node type meet the entry connection requirements, the entry correction agent further compares the entry source identifier of the preceding business link node with the entry source identifier of the following business link node. If the entry source identifier of the preceding business link node is the client homepage entry, and the entry source identifier of the following business link node becomes the SMS link entry, it indicates that the source of the same customer session has changed between entry and verification. The entry correction agent extracts the position of the following business link node as the position where the entry source has changed. If the node sequence number of the following business link node is less than or equal to the node sequence number of the preceding business link node, the position of the following business link node is extracted as the position where the node order is reversed.

[0040] The verification and correction agent first checks whether the preceding node type in the verification connection is an identity verification type, and then checks whether the following node type is a business purpose type. When the verification connection lacks an identity verification type node, or the identity verification type node has not generated an identity verification result in a passed state, and the subsequent business link node has already entered the payee management category, transfer preparation category, or fund change category, the position of the subsequent business link node is extracted as the position where the identity verification result association is missing. If the identity verification node has generated an identity verification result in a passed state, the verification and correction agent continues to check whether the customer session identifier corresponding to the identity verification result is consistent with the customer session identifier corresponding to the subsequent business link node. If the two are inconsistent, or the customer account identifier corresponding to the identity verification result is inconsistent with the customer account identifier corresponding to the subsequent business link node, the position of the subsequent business link node is extracted as the position where the identity verification result has not established the same customer session association with the subsequent business link node. If the node sequence number of the subsequent business link node is less than or equal to the node sequence number of the identity verification node, the position of the subsequent business link node is extracted as the node order inversion position.

[0041] The objective correction agent verifies the objective transfer according to the continuity of business processing categories. This continuity includes: account inquiry category to payee management category, payee management category to transfer preparation category, transfer preparation category to fund change category, limit adjustment category to fund change category, device change category to identity verification category, and then to fund change category. If the business processing category of the current objective node is account inquiry, and the business processing category of the next objective node directly enters the fund change category, and there is no identity verification node or business status feedback node between them, the position of the next objective node is extracted as the business processing category jump position. If the current objective node is device binding change category, and the next objective node is fund change category, and there is no identity verification node corresponding to the device binding verification event between them, the position of the next objective node is extracted as the business processing category jump position. If the node sequence numbers of the current and next objective nodes do not satisfy an increasing relationship, the position of the next objective node is extracted as the node sequence inverted position.

[0042] The backreference correction agent checks whether the business state backreference node in the state backreference can point to a preceding business link node that has already occurred within the same customer session. If the customer session identifier corresponding to the preceding business processing status called by the business state backreference node is inconsistent with the current customer session identifier, or the business transaction identifier corresponding to the preceding business processing status does not exist in the current customer session, then the position of the business state backreference node is extracted as the position where the preceding business processing status is missing. If the business state backreference node calls the account balance available status, but no account balance status call event occurs within the same customer session, or the node sequence number of the account balance status call event is later than the node sequence number of the transfer submission node, then the position of the business state backreference node is extracted as the position where the business state cannot be backreferenced to a preceding business link node. If the node sequence number of the business state backreference node is less than the node sequence number of the preceding business link node corresponding to its calling object, then the position of the business state backreference node is extracted as the position where the node order is reversed.

[0043] S2.4 Mark the locations where adjacent connections lack corresponding node types, node order is reversed, identity verification results are not associated with the same customer session with the next business link node, business purpose is abnormally redirected, and business status cannot be pointed back to the previous business link node as connection breakpoints.

[0044] In a preferred embodiment, the bank's internet business risk control platform receives the location results output by the link correction agent group, and configures the breakpoint type, the node sequence identifier where the breakpoint is located, the agent to which it belongs, and the reason for the breakpoint for each location result; wherein the breakpoint types include changes in the entry source, missing association of identity verification results, jump of business processing category, missing status of previous business processing, missing corresponding node type in adjacent connection relationship, and reversed node order.

[0045] The method for determining the absence of a corresponding node type in an adjacent connection relationship is as follows: the preceding node type and the following node type in the adjacent connection relationship cannot form any combination of entry connection, verification connection, destination transfer or status return, and the subsequent business link node has already entered the identity verification, payee management, transfer preparation or fund change stage.

[0046] The method for determining the reversed node order is as follows: the node number of the subsequent business link node is less than or equal to the node number of the preceding business link node, or the node number of the preceding business link node pointed to by the business status callback node is greater than the node number of the business status callback node.

[0047] The determination method for the identity verification result not being associated with the same customer session with the subsequent business link node is any of the following: the identity verification result is missing, the identity verification result is not in the pass state, or the customer session identifier corresponding to the identity verification result is inconsistent with the customer session identifier corresponding to the subsequent business link node.

[0048] The method for determining abnormal redirection of business purpose is as follows: the business processing category is directly transferred from the account query category, equipment change category, or payee management category to the fund change category, and there is no identity verification node or business status feedback node in between.

[0049] The determination method for business status not being able to point back to the preceding business link node is as follows: the preceding business processing status called by the business status pointing back node does not exist in the same customer session, or the preceding business processing status appears later than the current business status pointing back node.

[0050] S2.5 Sort the connection breakpoints according to the node sequence identifier to form business link breakpoints.

[0051] Specifically, the bank's internet business risk control platform arranges all connection breakpoints in ascending order of their node numbers according to the node sequence identifiers. When there are more than two connection breakpoints at the same business link node location, they are arranged in the following order: missing identity verification result association, missing preceding business processing status, business processing category jump, change of entry source, missing corresponding node type in adjacent connection relationships, and reversed node order. The set of connection breakpoints after this arrangement is the business link breakpoint.

[0052] For example, if node number 3 has a missing identity verification result, node number 4 has a business processing category jump, and node number 5 has a missing previous business processing status, then the business link breakpoints are arranged in order of node number as the three breakpoints corresponding to node number 3, node number 4, and node number 5.

[0053] It should be noted that this embodiment solves the problem of difficulty in uniformly locating changes in entry source, identity verification bypass, abnormal jumps in business processing categories, and missing preceding state calls in the same link by transforming the business link nodes in the same customer session from a simple sequential arrangement to an adjacent connection relationship that can be verified separately by multiple intelligent agents. By verifying different connection types separately by entry correction intelligent agents, verification correction intelligent agents, destination correction intelligent agents, and back-pointing correction intelligent agents, the judgment of risk anomalies can be advanced from single-point event judgment to link breakpoint judgment, improving the correspondence between risk identification results and actual business anomaly locations.

[0054] S3. Arrange the breakpoints in the business chain according to the order of the business chain nodes, and extract the densely populated breakpoint segments between the identity verification node and the fund processing node. Note that the following should be noted in this step: S3.1 Mark the business purpose node whose business processing category belongs to the fund change category as the fund processing node.

[0055] In a preferred embodiment, the bank's internet business risk control platform checks the business processing category of the business destination node in the business link node; when the business processing category is the fund change category, the corresponding business destination node is marked as the fund processing node; wherein, the fund change category includes one of the following: intra-bank transfer, inter-bank transfer, mobile phone number transfer, QR code payment, large amount transfer out, transfer out after redemption of wealth management products, and account balance transfer.

[0056] For account takeover and fund transfer risk control scenarios, if the business action corresponding to the business destination node is to submit an interbank transfer after adding a new payee, or to submit a large-amount transfer after equipment change, then the business destination node is marked as a fund processing node.

[0057] For example, in the same customer session, if node number 5 corresponds to an interbank transfer submission with a transfer amount of 50,000 yuan and the business processing category is fund change, then node number 5 is marked as the fund processing node.

[0058] S3.2. According to the node sequence identifier, classify the business link breakpoints to the corresponding business link node positions.

[0059] Specifically, the bank's internet business risk control platform uses the node sequence identifier of the breakpoint in the business link as the basis to classify each business link breakpoint into the business link node position corresponding to the same node sequence identifier. If the breakpoint type is a change in the entry source, it is classified into the business link node position after the change in the entry source occurs; if the breakpoint type is a missing identity verification result association, it is classified into the business link node position after the identity verification result is not received; if the breakpoint type is a jump in business processing category, it is classified into the business destination node position after entering the abnormal business processing category; if the breakpoint type is a missing previous business processing status, it is classified into the business status return node position where the previous business processing status cannot be returned; if the breakpoint type is a missing corresponding node type or an inverted node order in the adjacent connection relationship, it is classified into the business link node position after the abnormal link order.

[0060] Preferably, through the above-mentioned classification method, a one-to-one correspondence is formed between the breakpoint location and the business link node location, or a relationship of one node corresponding to multiple breakpoints is formed, so that the subsequent segmentation of densely brokenpoint links has clear node boundaries.

[0061] S3.3. Starting from the identity verification node and ending at the funds processing node, intercept the breakpoint in the business link between the identity verification node and the funds processing node.

[0062] Specifically, the bank's internet business risk control platform first identifies the identity verification node that is closest to and precedes the fund processing node in the same customer session, and uses this identity verification node as the starting node; then, it uses the already marked fund processing node as the ending node; then, it selects a business link breakpoint between the starting node and the ending node whose node number is greater than or equal to the starting node's node number and less than or equal to the ending node's node number; if there are more than two fund processing nodes in the same customer session, the above interception is performed on each fund processing node; if there is no identity verification node before the fund processing node in the same customer session, the session entry node closest to the fund processing node is used as a supplementary starting node, and the position lacking an identity verification node is synchronously classified into the business link breakpoint where the adjacent connection relationship lacks the corresponding node type.

[0063] S3.4. Group the business link breakpoints with adjacent node order identifiers and different breakpoint types into the same chain segment to obtain a breakpoint-dense chain segment.

[0064] Specifically, the bank's internet business risk control platform arranges the captured business link breakpoints in ascending order according to their node sequence identifiers. Starting from the first breakpoint, it compares the node number and breakpoint type of each adjacent breakpoint. If the node numbers of two adjacent breakpoints are consecutive and their breakpoint types are different, they are grouped into the same chain segment. Continuing the comparison, if the node number of the next breakpoint is consecutive with the previous breakpoint and its breakpoint type is different from the breakpoint type of the most recent breakpoint in that chain segment, it is grouped into that chain segment. If the node numbers are not consecutive or the breakpoint types are repeated consecutively, the current chain segment is terminated and a new chain segment begins.

[0065] The breakpoint types include changes in the entry source, missing associations in identity verification results, jumps in business processing categories, missing status of previous business processing, missing corresponding node types in adjacent connection relationships, and reversed node order.

[0066] For example, the breakpoint type of node number 2 is missing identity verification result association, the breakpoint type of node number 3 is business processing category jump, and the breakpoint type of node number 4 is missing previous business processing status. The node numbers of the three business link breakpoints are consecutive and the breakpoint types are different. Then, node number 2 to node number 4 form a breakpoint dense chain segment. If node number 5 is still missing previous business processing status, then node number 5 is not included in this breakpoint dense chain segment, but is treated as a breakpoint duplicate segment separately.

[0067] It should be noted that this embodiment addresses the problem of a large number of session breakpoints and significant interference from non-funds processing breakpoints in the final risk level in account takeover and funds transfer scenarios by focusing on the highly sensitive business interval between the identity verification node and the funds processing node from the established business chain breakpoints. By marking the funds processing node, listing breakpoint locations, and extracting densely populated breakpoint segments, entry anomalies, verification anomalies, business purpose jump anomalies, and status return anomalies are concentrated in the continuous chain segment before funds transfer, providing a direct basis for subsequent risk level correction, thereby improving the risk control platform's ability to identify rapid transfer behavior after account takeover.

[0068] S4. Based on the breakpoint type and node position corresponding to the densely populated breakpoint segments, adjust the risk level output by each agent. Note that the following should be noted in this step: S4.1. Based on the node sequence identification in the densely populated breakpoint chain segment, extract the breakpoint type, node location, and node interval between the breakpoint and the fund processing node in the business link to form the basis for risk level correction.

[0069] In a preferred embodiment, the bank's internet business risk control platform extracts the breakpoint type, node location, associated agent, breakpoint reason, and node interval between the breakpoint and the fund processing node for each business link breakpoint in ascending order of node sequence identifiers in the breakpoint-dense chain segment. The node location consists of the customer session identifier, node number, node type, and business processing category. The node interval is the difference between the node number of the fund processing node and the node number of the breakpoint in the business link.

[0070] For example, if the node number of the fund processing node is 6 and the node number of the breakpoint in a certain business link is 4, then the node interval between the breakpoint in the business link and the fund processing node is 2.

[0071] The risk control platform for internet banking business combines the breakpoint type, node location, associated intelligent agent, breakpoint cause, and node interval as the basis for risk level correction. The smaller the node interval, the closer the breakpoint in the business link is to the fund processing node. When correcting the risk level, breakpoints that require strong correction or collaborative correction will be given priority in the determination.

[0072] S4.2 Mark breakpoints in the business chain where the breakpoint type is missing identity verification result association or missing previous business processing status, and the node position is located before the fund processing node, as strong correction breakpoints.

[0073] S4.3. Business link breakpoints whose breakpoint type is change of entry source or business processing category jump, and which are adjacent to strong correction breakpoints, are marked as collaborative correction breakpoints.

[0074] S4.4. Convert the risk level output by each agent into a risk level ordinal value. The risk level ordinal value includes a first ordinal value, a second ordinal value, and a third ordinal value. The first ordinal value represents a low risk level, the second ordinal value represents a medium risk level, and the third ordinal value represents a high risk level. The third ordinal value is higher than the second ordinal value, and the second ordinal value is higher than the first ordinal value. When the risk level ordinal value of the agent to which the strong correction breakpoint belongs is the first or second ordinal value, replace the risk level ordinal value of the agent to which the strong correction breakpoint belongs with the third ordinal value. When the risk level ordinal value of the agent to which the cooperative correction breakpoint belongs is the first ordinal value, replace the risk level ordinal value of the agent to which the cooperative correction breakpoint belongs with the second ordinal value. When the risk level ordinal value of the agent to which the cooperative correction breakpoint belongs is the second ordinal value, replace the risk level ordinal value of the agent to which the cooperative correction breakpoint belongs with the third ordinal value.

[0075] S4.5. Merge the replaced risk level sequence values ​​in the order of third sequence value, second sequence value, and first sequence value, and take the highest risk level sequence value as the risk level correction result for the same customer session.

[0076] It should be noted that when the risk level ranking value after the replacement of at least one agent is the third ranking value, the risk level correction result for the same customer session is a high risk level; when there is no third ranking value but the risk level ranking value after the replacement of at least one agent is the second ranking value, the risk level correction result for the same customer session is a medium risk level; when the risk level ranking values ​​after the replacement of all agents are the first ranking value, the risk level correction result for the same customer session is a low risk level.

[0077] Preferably, the risk level correction result can be submitted to the transaction interception, secondary verification, manual review, or limit downgrade processing process of the bank's internet business risk control platform.

[0078] In a preferred application example, a customer session identifier is C202605190001. The customer initiates an interbank transfer of 50,000 yuan through a mobile banking client. This customer session forms the following business link nodes: Node 1 is the SMS link entry node, the node type is session entry type, and the entry source identifier is SMS link entry; Node 2 is the face verification node, the node type is identity verification type, and the identity verification result is passed, but the customer session identifier corresponding to this identity verification result is C202605190000; Node 3 is the payee addition node, the node type is business purpose type, and the business processing category is payee management category; Node 4 is the transfer submission node, the node type is business purpose type, and the business processing category is fund change category; Node 5 is the account balance status call node, the node type is business status feedback type, but the business transaction identifier corresponding to the account balance status it calls does not belong to C202605190001; In the above business link nodes, Node 4 is marked as the fund processing node.

[0079] In this example, when the verification and correction agent associates the identity verification result corresponding to node 2 with the customer session identifier corresponding to node 3, it finds that the identity verification result of node 2 does not belong to the same customer session. The position of node 3 is extracted as the position where the identity verification result association is missing, and a business link breakpoint of the type of identity verification result association is formed. When the destination correction agent checks the destination transfer from node 3 to node 4, it finds that node 3 is in the payee management category and node 4 is in the fund change category. Moreover, there is no transaction password verification node directly corresponding to the fund change category between the two. The position of node 4 is extracted as the business processing category jump position, and a business link breakpoint of the type of business processing category jump is formed. When the back pointer correction agent checks the status back pointer of node 5, it finds that the account balance status called by node 5 does not belong to the same customer session. The position of node 5 is extracted as the position where the previous business processing status is missing, and a business link breakpoint of the type of previous business processing status is formed.

[0080] After the bank's internet business risk control platform categorized the aforementioned business link breakpoints according to node sequence, it extracted the business link breakpoints between the identity verification node and the fund processing node. The breakpoint type of node 3 is missing identity verification result association, and the breakpoint type of node 4 is business processing category jump. Since their node numbers are consecutive and their breakpoint types are different, nodes 3 to 4 form a dense breakpoint chain. For node 3, its breakpoint type is missing identity verification result association, and its node position is before the fund processing node, so the business link breakpoint corresponding to node 3 is marked as a strong correction breakpoint. For node 4, its breakpoint type is business processing category jump, and it is adjacent to the strong correction breakpoint corresponding to node 3, so the business link breakpoint corresponding to node 4 is marked as a collaborative correction breakpoint. Although node 5 belongs to the category of missing preceding business processing status, its node position is later than the fund processing node, and it is not included in the dense breakpoint chain before the fund processing node.

[0081] Before risk level correction, the entry correction agent outputs a low-risk level, the verification correction agent outputs a medium-risk level, the destination correction agent outputs a medium-risk level, and the retrace correction agent outputs a low-risk level. The bank's internet business risk control platform converts these risk levels into first-order values, second-order values, second-order values, and first-order values, respectively. Since node 3 is a strong correction breakpoint and its agent is the verification correction agent, the second-order value of the verification correction agent is replaced with the third-order value. Since node 4 is a collaborative correction breakpoint and its agent is the destination correction agent, the second-order value of the destination correction agent is replaced with the third-order value. After the replacement, the entry correction agent has the first-order value, the verification correction agent has the third-order value, the destination correction agent has the third-order value, and the retrace correction agent has the first-order value. The bank's internet business risk control platform merges these values ​​in the order of third-order value, second-order value, and first-order value, and selects the third-order value as the risk level correction result for the same customer session, thus correcting the customer session to a high-risk level.

[0082] Preferably, this embodiment corrects the risk level of each agent's original output by linking the breakpoint type, node location, and fund processing node interval in the breakpoint-dense chain segment. This solves the problem that in account takeover and fund transfer scenarios, a single agent can only output low or medium risk based on local anomalies and cannot reflect continuous anomalies approaching the fund transfer node. Through the hierarchical replacement of strongly corrected breakpoints and collaboratively corrected breakpoints, the continuous risk relationship between missing identity verification, missing preceding states, changes in entry source, and business purpose jumps is incorporated into the final risk level. This can raise abnormal sessions after account takeover to a high-risk level before fund transfer, thereby improving the triggering accuracy of fund transfer interception, secondary verification, and manual review.

[0083] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention, and all such modifications or substitutions should be covered within the scope of the claims of the present invention.

Claims

1. A method for risk control of integrated banking business based on multi-agent collaborative decision-making using internet big data, characterized in that, include: Based on the order in which business occurs within the same customer session, the session entry node, identity verification node, business destination node, and business status feedback node are divided into business link nodes. The link correction intelligent agent group anchors the connection breakpoints in the entry connection, verification connection, destination transfer and status return according to the adjacent connection relationship of the service link nodes, thus forming the service link breakpoint; The link correction intelligent agent group is a software functional module deployed in the bank's internet business risk control platform. The link correction intelligent agent group includes an entry correction intelligent agent, a verification correction intelligent agent, a destination correction intelligent agent, and a return correction intelligent agent. The entry correction agent verifies the consistency between the entry source identifier of the previous service link node and the entry source identifier of the next service link node in the entry connection, and extracts the position of the next service link node with inconsistent entry source identifiers as the entry source change position. The verification and correction agent associates the identity verification result of the identity verification node in the verification connection with the customer session identifier of the next business link node for verification, and extracts the position of the next business link node that is not associated with the identity verification result or whose associated identity verification result does not belong to the same customer session as the missing position of the identity verification result association. The target correction agent performs continuous verification of the business processing category of the previous business target node and the business processing category of the next business target node in the target transfer, and extracts the position of the next business target node that enters the fund change category when there is a lack of identity verification node or business status feedback node as the business processing category jump position. The back-pointing correction agent performs back-pointing verification between the business state back-pointing node in the state back-pointing and the preceding business link node it calls, and extracts the position of the business state back-pointing node that cannot point to the preceding business processing status in the same customer session as the missing position of the preceding business processing status. The breakpoints in the business link are listed in the order of the business link nodes, and the dense chain segment of breakpoints between the identity verification node and the fund processing node is extracted. Based on the breakpoint type and node position corresponding to the densely populated breakpoint segments, the risk level output by each agent is corrected.

2. The method for risk control of integrated banking business based on multi-agent collaborative decision-making according to claim 1, characterized in that, The division into business link nodes includes: Extract session entry events, identity verification events, business processing events, and business status call events within the same customer session, and form a session event sequence according to the event occurrence time; The events that generate the source of the business entry in the sequence of the session events are marked as session entry nodes, the events that generate the identity verification result are marked as identity verification nodes, the events that cause a change in the business processing category are marked as business destination nodes, and the events that call the previous business processing status are marked as business status feedback nodes. According to their sequential positions in the session event sequence, the session entry node, the identity verification node, the service destination node, and the service status feedback node are configured with node sequence identifiers in that order. According to the node sequence identifier, the session entry node, the identity verification node, the business destination node, and the business status feedback node are sequentially connected to obtain the business link node.

3. The method for risk control of integrated banking business based on multi-agent collaborative decision-making according to claim 2, characterized in that, The node type of the preceding node, the node type of the following node, and the order of their configuration are configured between two adjacent service link nodes.

4. The method for risk control of integrated banking business based on multi-agent collaborative decision-making according to claim 3, characterized in that, The node types include session entry type, identity verification type, business purpose type, and business status feedback type; the sequence relationship includes the preceding node type, the following node type, and the node sequence identifier difference between two adjacent business link nodes; wherein, the node sequence identifier difference is the difference between the node sequence identifier of the following business link node and the node sequence identifier of the preceding business link node.

5. The method for risk control of integrated banking business based on multi-agent collaborative decision-making according to claim 1, characterized in that, The formation of the business link breakpoint includes: Based on the node sequence identifier of the business link node, extract the node type and sequence relationship of two adjacent business link nodes to form an adjacent connection relationship; The relationship between the session entry node and the identity verification node in the adjacent connection relationship is classified as entry connection; the relationship between the identity verification node and the business destination node is classified as verification connection; the relationship between the business destination node and the next business destination node is classified as destination transfer; and the relationship between the business status reference node and the preceding business link node it calls is classified as status reference. The link correction intelligent agent group performs node consistency verification on the entry connection, the verification connection, the destination transfer and the state back pointer respectively, and extracts the following issues: missing corresponding node type in adjacent connection relationship, node order reversed, identity verification result not established with the same customer session association with the next business link node, abnormal business destination jump, and business status cannot be back pointered to the position of the previous business link node. The following are identified as connection breakpoints: the adjacent connection relationship lacks a corresponding node type, the node order is reversed, the identity verification result is not associated with the same customer session with the next business link node, the business purpose is abnormally redirected, and the business status cannot be pointed back to the position of the preceding business link node. The connection breakpoints are sorted according to the node sequence identifier to form business link breakpoints.

6. The method for risk control of integrated banking business based on multi-agent collaborative decision-making according to claim 1, characterized in that, The interception of the densely populated chain segments between the identity verification node and the fund processing node includes: Mark the business purpose node whose business processing category belongs to the fund change category as the fund processing node; According to the node sequence identifier, the business link breakpoints are assigned to the corresponding business link node positions; Using the identity verification node as the starting node and the fund processing node as the ending node, the business link breakpoint located between the identity verification node and the fund processing node is intercepted. The business link breakpoints that are adjacent in the order of their node identifiers and have different breakpoint types are grouped into the same chain segment to obtain a breakpoint-dense chain segment.

7. The method for risk control of integrated banking business based on multi-agent collaborative decision-making according to claim 6, characterized in that, The correction of the risk level output by each agent includes: Based on the node sequence identifiers in the densely populated breakpoint chain segment, extract the breakpoint type, node location, and node interval between the business link breakpoint and the fund processing node to form the basis for risk level correction. Business link breakpoints with breakpoint types of missing identity verification results or missing previous business processing status, and whose node positions are located before the fund processing node, are marked as strong correction breakpoints. Business link breakpoints whose breakpoint type is change of entry source or business processing category jump, and which are adjacent to the strong correction breakpoint, are marked as collaborative correction breakpoints. The risk levels output by each agent are converted into risk level ordinal values, which include a first ordinal value, a second ordinal value, and a third ordinal value. When the risk level ordinal value of the agent to which the strong correction breakpoint belongs is the first or second ordinal value, the risk level ordinal value of the agent to which the strong correction breakpoint belongs is replaced with the third ordinal value. When the risk level ordinal value of the agent to which the collaborative correction breakpoint belongs is the first ordinal value, the risk level ordinal value of the agent to which the collaborative correction breakpoint belongs is replaced with the second ordinal value. When the risk level ordinal value of the agent to which the collaborative correction breakpoint belongs is the second ordinal value, the risk level ordinal value of the agent to which the collaborative correction breakpoint belongs is replaced with the third ordinal value. The replaced risk level sequence values ​​are merged in the order of third sequence value, second sequence value, and first sequence value, and the highest risk level sequence value is taken as the risk level correction result for the same customer session.

8. The method for risk control of integrated banking business based on multi-agent collaborative decision-making according to claim 7, characterized in that, The first position value represents a low-risk level, the second position value represents a medium-risk level, and the third position value represents a high-risk level. The third position value is higher than the second position value, and the second position value is higher than the first position value.