A method and system for credit fraud prevention that integrates multimodal data and graph neural networks.

By collecting multimodal data and constructing a risk scoring model, combined with physiological responses and forgery feature detection, the problem of insufficient identification of fraud gangs in traditional credit anti-fraud methods has been solved, achieving efficient fraud identification and prevention.

CN122492330APending Publication Date: 2026-07-31JIASURONG (SUZHOU) TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
JIASURONG (SUZHOU) TECHNOLOGY CO LTD
Filing Date
2026-04-28
Publication Date
2026-07-31

AI Technical Summary

Technical Problem

Existing credit fraud prevention methods are ineffective in identifying fraud gangs' forgery and disguise, resulting in a high false alarm rate. They are unable to penetrate the homogeneous behavioral patterns and physiological response characteristics of fraud gangs, leading to a persistently high false negative rate. Furthermore, traditional methods have a weak ability to identify gang fraud.

Method used

Multimodal data of loan applicants is collected, fraud information is tested through a detection loop, physiological reaction data is generated, and a multimodal risk scoring model is constructed. Combining forgery feature detection and abnormal physiological reaction features, a comprehensive credit risk score and multimodal feature cross-validation are performed to identify fraudulent behavior.

Benefits of technology

It improves the accuracy of identifying fraud gangs, reduces false positives and false negatives, is adaptable to different scenarios, can quickly identify fraudulent behavior and formulate targeted prevention and control measures to reduce financial losses.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122492330A_ABST
    Figure CN122492330A_ABST
Patent Text Reader

Abstract

This invention discloses a credit anti-fraud method and system integrating multimodal data and graph neural networks, belonging to the field of financial credit anti-fraud technology. The method includes the following steps: S1: Collecting multimodal data of credit applicants and preprocessing the data; S2: Detecting forgery features in the multimodal data and simultaneously correlating the temporal correspondence between physiological reactions and test content; S3: Calculating the applicant's single-modal risk score and comprehensive credit risk score; S4: Judging the applicant's credit fraud behavior based on the comprehensive credit risk score and a preset judgment level; S5: Outputting the anti-fraud detection results. This invention, through verification with multimodal data, uses social correlation verification data and physiological reaction data to form a cross-verification of subjective and objective information, quickly identifying fraudulent behavior, identifying shared information and equipment characteristics of fraud gangs, improving the accuracy of gang fraud identification, and avoiding the limitations of relying on a single data dimension.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of financial credit anti-fraud technology, and in particular to a credit anti-fraud method and system that integrates multimodal data and graph neural networks. Background Technology

[0002] Credit business is one of the core businesses of the financial industry, but fraud, especially gang fraud, has become a key risk point restricting the development of the industry. Existing fraud gangs use methods such as carefully forging social relationships, tampering with application content, and mass reuse of equipment and images to commit loan fraud. Their behavior is characterized by strong concealment and outstanding coordination, which poses a huge challenge to the risk control of financial institutions and easily brings great difficulties to the review and risk control of financial credit.

[0003] Traditional credit fraud prevention methods primarily rely on rule engines and single-dimensional data models, which have limitations. Existing rule engines, dependent on human experience, struggle to cope with dynamically changing fraud tactics, resulting in high false positive rates. Furthermore, single models often focus on insufficient data dimensions within structured data, failing to penetrate the forgery and disguises of fraud rings. While some existing fraud prevention solutions incorporate multimodal data fusion or graph neural network (GNN) technologies, they still lack the ability to identify the subjective intent of fraudulent behavior. Face-to-face interviews become mere formalities, allowing well-trained fraudsters to easily evade detection, demonstrating weak identification capabilities for fraudulent applicants. Insufficient cross-applicant feature comparison fails to effectively identify the correlation between homogeneous behavioral patterns and physiological response characteristics of fraud rings. GNN applications rely heavily on node and community structure analysis, which is easily circumvented by fraud rings through the construction of fake social relationships. The difficulty in quantifying the risk of shared origins in fraud rings further contributes to the persistently high underreporting rate of traditional methods for fraud rings, exposing financial institutions to significant financial losses and compliance risks. Summary of the Invention

[0004] The purpose of this invention is to provide a credit anti-fraud method and system that integrates multimodal data and graph neural networks to solve the problems mentioned in the background art.

[0005] To achieve the above objectives, the present invention provides the following technical solution: a credit anti-fraud method integrating multimodal data and graph neural networks, comprising the following steps:

[0006] S1: Collect multimodal data of loan applicants. Applicants take a fraud information test by wearing a detection ring, generate physiological reaction data, and preprocess the data.

[0007] S2: Perform forgery feature detection on multimodal data, remove interference items, convert unstructured data into standardized features, synchronously correlate the temporal correspondence between physiological reactions and test content, and extract fraud risk correlation features under each modality;

[0008] S3: Construct a multimodal risk scoring model, input risk-related features into the model, and calculate the applicant's single-modal risk score and comprehensive credit risk score;

[0009] S4: Based on the comprehensive credit risk score and the preset judgment level, determine the applicant's credit fraud behavior;

[0010] If the comprehensive credit risk score is higher than the preset risk threshold, forgery or alteration features are detected and the penalty trigger conditions are met, or abnormal physiological reaction features reach the preset warning standard, the applicant is suspected of fraud if at least one of the conditions is met. The suspected applicant is cross-verified with existing fraud gangs and applicants at the same node to confirm whether the fraud is committed by a fraud gang.

[0011] S5: Output anti-fraud detection results.

[0012] Preferably, in step S1, the multimodal data includes application behavior data, device feature data, identity verification image data, and social association verification data;

[0013] The detection ring uses built-in sensors to collect real-time physiological response data on heart rate variability, skin conductance, skin temperature, and blood oxygen saturation from the wearer undergoing the fraud information test. The fraud information test includes test scenarios such as informing the applicant of the legal consequences of fraudulent behavior, verifying the authenticity of key application information, and inquiring about the reasons for abnormal application behavior.

[0014] Preferably, the data preprocessing steps in step S1 are as follows:

[0015] S11: Perform content consistency verification on application behavior data, identify traces of changes in application content, and eliminate contradictory and redundant information;

[0016] S12: Perform uniqueness verification and anomaly detection on equipment feature data to remove forged equipment information;

[0017] S13: Perform forgery detection, size normalization, and feature point extraction on the identity verification image data to generate an image authenticity feature matrix;

[0018] S14: Verify the authenticity of the applicant's social connection verification data and remove obviously forged contact information and false financial transaction records;

[0019] S15: Filter and denoise the physiological response data, align the time sequence, remove invalid data caused by motion interference and environmental interference, and retain physiological feature values ​​that are strongly correlated with the test scenario.

[0020] Preferably, in step S2, the forgery feature detection is used to remove forgery traces, transform redundancy and physiological data interference items, and the fraud risk association features under each modality include content consistency features, information authenticity features, behavioral continuity features and abnormal physiological reaction features.

[0021] Preferably, the risk association feature extraction in step S2 includes:

[0022] Regarding the content filled in, the degree of overlap between the application information and the historical records, the frequency of modifications to the content and the rationality of the modifications, and the consistency of information across application scenarios;

[0023] Regarding applicant information, the degree of matching between device information and identity information, the authenticity score of image data, and the verification pass rate of social association data are all considered.

[0024] Regarding the applicant's behavior, the degree of consistency between the application behavior and the applicant's historical behavior patterns, the rationality of the application time distribution, and the continuity of equipment usage behavior;

[0025] Regarding the applicant's physiological response, the fluctuation range of physiological indicators during the test, the correlation between abnormal physiological indicators and the test scenario, and the degree of deviation of physiological indicators from the baseline values ​​of the normal population.

[0026] Preferably, the multimodal risk scoring model in step S3 includes:

[0027] A weighted fusion algorithm was used to calculate the single-modal risk score, in which the weights of physiological reaction data, application behavior data, image authenticity data, and social association verification data were higher than the weights of device feature data.

[0028] The single-modal risk score includes behavioral change risk score, device forgery risk score, image authenticity risk score, social forgery risk score, and physiological abnormality risk score;

[0029] The comprehensive credit risk score incorporates penalties for forgery and alteration of characteristics, as well as weighting for abnormal physiological responses. The comprehensive credit risk score is calculated as follows:

[0030]

[0031] Wherein, A is the single-modal risk score, γ is the corresponding weight, B is the penalty term for the forgery and transformation features, and the penalty term is positively correlated with the number of detected forgery traces and the severity of the transformation content, and C is the weighted term for abnormal physiological reactions, which is positively correlated with the abnormal amplitude of physiological indicators and the sensitivity to abnormal scenarios.

[0032] Preferably, the fraud behavior determination process in step S4 further includes:

[0033] S41: If the comprehensive credit risk score is greater than or equal to the first preset threshold, or the weighted item for abnormal physiological reaction is greater than or equal to the preset warning threshold, it is marked as high fraud risk; if the comprehensive credit risk score is between the second preset threshold and the first preset threshold, it will enter the joint verification of forgery, alteration features and physiological features.

[0034] S42: Detect whether there are features such as social relationship forgery, application content transformation, and batch image reuse, and whether the abnormal physiological reaction features are temporally related to the above forgery and transformation features. If the conditions are met, the penalty item and the weighting item are superimposed, and the comprehensive credit risk score is raised to above the first preset threshold.

[0035] S43: For applicants who trigger the superimposed item, compare their multimodal data with the known fraud gang's behavioral feature database and physiological reaction pattern database to verify whether there is a correlation of homogenized behavioral patterns, shared equipment, image reuse, and similar physiological reaction patterns.

[0036] S44: If cross-validation confirms the presence of characteristics associated with organized fraud, it is determined to be organized fraud; if only a single forgery, alteration feature, or isolated physiological abnormality is detected but there is no organized connection, it is determined to be individual fraud.

[0037] Preferably, step S4, which involves cross-validating the multimodal features of the suspected applicant, further includes cross-applicant multimodal feature comparison at specified time points. The comparison steps are as follows:

[0038] S431: Calculate the similarity of identity verification image data of different applicants at the same node, and use the cosine similarity algorithm to generate image matching scores;

[0039] S432: Compare the device characteristic data and application content expression style of different applicants to generate device sharing risk score and content plagiarism risk score;

[0040] S433: Compare the similarity of physiological response patterns of different applicants in fraud-related information tests to generate physiological response homology risk scores;

[0041] S434: Compare the above scores with the authenticity of the information of the corresponding applicant for cross-validation of the multimodal features of the applicant's multiple groups at the same node.

[0042] Preferably, the anti-fraud detection results output in step S5 clearly indicate the fraud risk level and fraud type, and the results include:

[0043] The applicant's comprehensive credit risk score and risk level, fraud determination results, fraud association explanation, and risk score composition details, including the specific detection results of forgery-type features, alteration-type features, and physiological abnormality features, and the risk score composition details include the risk score of each single modality, penalty adjustment value, and physiological abnormality weighted value.

[0044] A credit fraud prevention system integrating multimodal data and graph neural networks, the system comprising:

[0045] The identity authentication and storage module is used to collect and store multimodal data of credit applicants. The multimodal data includes at least application behavior data, device feature data, identity verification image data, and social association verification data. It is also used to bind a unique identity to the applicant and record historical application records and fraud tags.

[0046] The data acquisition and transmission module includes a detection ring for the applicant to wear. The detection ring has a built-in physiological sensor for collecting the applicant's physiological response data such as heart rate variability, skin conductance, skin temperature and blood oxygen saturation in real time during the fraud information test, and for transmitting the collected multimodal data to the preprocessing module.

[0047] The preprocessing module is used to preprocess the received multimodal data. The preprocessing module performs content consistency verification and redundancy removal on the application behavior data, uniqueness verification and forgery detection on the device feature data, and forgery trace recognition, size normalization and feature point extraction on the identity verification image data.

[0048] The detection module is used to detect forgery features in the preprocessed multimodal data;

[0049] The network module is used to build and train a graph neural network model. The network module is used to perform multimodal cross-validation and group association analysis between the applicant and known fraud gangs and applicants at the same node.

[0050] The risk assessment and response module is used to determine whether an applicant has engaged in fraudulent behavior based on extracted risk-related features and a preset judgment level. The risk assessment and response module is also used to determine and output anti-fraud detection results.

[0051] The technical effects and advantages of this invention are as follows:

[0052] (1) This invention uses multimodal data verification and social association verification data and physiological reaction data to form a cross-verification of subjective and objective information. Even if the fraud gang carefully forges social contacts and financial transaction records, the physiological reactions such as guilt and tension generated in the fraud-related information test are difficult to control. It can quickly identify fraudulent behavior. The superposition design of forgery and change feature penalty items and physiological reaction abnormal weighting items can increase the risk score of applicants with forgery traces, content changes or physiological abnormalities. At the same time, it combines cross-applicant multimodal feature comparison to identify the shared information, equipment and other features of the fraud gang, improve the accuracy of gang fraud identification, and avoid the limitations of relying on a single data dimension in traditional methods.

[0053] (2) This invention introduces abnormal physiological reaction characteristics as the core risk dimension, avoiding the phenomenon that the information filled in by individuals cannot be judged as true or false in the traditional way. Moreover, the temporal correlation between physiological indicators and fraud-related test content can accurately locate abnormal physiological fluctuations when answering key questions. Through the layered screening of initial judgment, joint verification, cross-verification and final judgment, combined with the multi-dimensional judgment rules of comprehensive risk score and gang association matching, it avoids the fraud problem of misjudgment and omission caused by relying solely on application information, and improves the anti-fraud capability of credit.

[0054] (3) Through the weighted fusion design of the multimodal risk scoring model, the present invention can dynamically adjust the data weight of each modality according to the high-incidence scenarios of different fraud types, which has strong scenario adaptability. It can meet the anti-fraud needs of different regions and different credit products without reconstructing the model. The anti-fraud detection results clearly identify the risk level and fraud type, helping credit institutions to quickly locate risk points, formulate targeted prevention and control measures, and reduce the financial losses caused by fraud. Attached Figure Description

[0055] The accompanying drawings are provided to further illustrate the invention and form part of the specification. They are used together with the embodiments of the invention to explain the invention, but do not constitute a limitation thereof. In the drawings:

[0056] Figure 1 This is a schematic diagram of the method flow of the present invention;

[0057] Figure 2 This is a flowchart of the fraud behavior judgment process of the present invention;

[0058] Figure 3 This is a schematic diagram of the built-in sensor in the detection ring of the present invention. Detailed Implementation

[0059] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0060] This invention provides, for example Figures 1-3 This paper presents a credit fraud prevention method and system that integrates multimodal data and graph neural networks.

[0061] Example 1: Refer to Figure 1 The diagram shown is a schematic flowchart of a credit anti-fraud method integrating multimodal data and graph neural networks according to an embodiment of the present invention. In this embodiment, the credit anti-fraud method integrating multimodal data and graph neural networks includes the following steps:

[0062] S1: Collect multimodal data of loan applicants. Applicants take a fraud information test by wearing a detection ring, generate physiological reaction data, and preprocess the data.

[0063] S2: Perform forgery feature detection on multimodal data, remove interference items, convert unstructured data into standardized features, synchronously correlate the temporal correspondence between physiological reactions and test content, and extract fraud risk correlation features under each modality;

[0064] S3: Construct a multimodal risk scoring model, input risk-related features into the model, and calculate the applicant's single-modal risk score and comprehensive credit risk score;

[0065] S4: Based on the comprehensive credit risk score and the preset judgment level, determine the applicant's credit fraud behavior;

[0066] If the comprehensive credit risk score is higher than the preset risk threshold, forgery or alteration features are detected and the penalty trigger conditions are met, or abnormal physiological reaction features reach the preset warning standard, the applicant is suspected of fraud if at least one of the conditions is met. The suspected applicant is cross-verified with existing fraud gangs and applicants at the same node to confirm whether the fraud is committed by a fraud gang.

[0067] S5: Output anti-fraud detection results.

[0068] In a preferred embodiment, multimodal data of the loan applicant is collected, including application behavior data, device characteristic data, identity verification image data, and social association verification data. Basic data of the loan applicant is collected synchronously through the loan application system interface, a third-party data verification platform, and a device fingerprint collection tool. Applicant behavior data is obtained in real-time from system logs by capturing application operation sequence data, such as the duration of time spent filling in fields and modification trigger logs, combined with the applicant's performance records retrieved from the historical database of the core credit system. Device characteristic data of the applicant is collected through a front-end SDK to collect device hardware information, such as MAC address, operating system version, and IP address, for auxiliary verification. Identity verification image data is captured and uploaded in real-time by the camera on the financial application terminal, simultaneously recording the capture timestamp and device information. Social association verification data of the applicant is verified through interfaces with mobile information operators, banks, and other third-party entities to verify the validity of the contact's mobile phone number and the authenticity of fund transfer records, while also collecting supporting documents of the guarantee relationship provided by the applicant for auxiliary verification.

[0069] Specific application behavior data includes loan application frequency, application time interval, application content filling trajectory, historical application information change records, and historical loan performance records. Specific device characteristic data includes device model, operating system, IP address, MAC address, hardware fingerprint, and device usage behavior data. Specific identity verification image data includes the applicant's ID card photo, facial image, bank card photo, and other identity verification images. Specific social association verification data includes the contact information filled in by the applicant, fund transaction records, and guarantee relationship proof materials.

[0070] Applicants undergo a fraud detection ring test, generating physiological response data. This data is then preprocessed. The ring, using built-in sensors, collects real-time physiological response data on heart rate variability, electrodermal activity (EDA), skin temperature, and blood oxygen saturation. The ring can utilize existing wearable bracelet structures and incorporates an EDA EDA sensor, a PPG heart rate sensor, a SpO2 blood oxygen sensor, and a temperature sensor. The EDA EDA sensor measures EDA response through metal electrodes in contact with the skin. When feeling nervous or attempting to conceal information, sweat gland activity increases, leading to enhanced skin conductivity. This indicator is difficult to fully control and reflects the applicant's sympathetic nervous system activity during stress or emotional arousal. Depending on the system's activation level, the PPG heart rate sensor uses green LED light to illuminate the skin, measuring pulsating changes in blood volume to calculate heart rate. Increased heart rate and decreased HRV are typically associated with emotions such as stress and anxiety, and are used to assess the applicant's stress state. The SpO2 blood oxygen sensor uses red and infrared light to measure blood oxygen saturation; emotional fluctuations may affect breathing, leading to slight changes in blood oxygen levels. The temperature sensor measures skin temperature to help verify the applicant's emotional changes. Data from the detection ring is transmitted in real-time via Bluetooth and wireless to the financial application system. After the physiological data transmission is complete, the data within the detection ring is deleted, and the applicant's multimodal data is saved to the credit application system's storage file by time, name, and regional address.

[0071] Among them, the fraud information test includes test scenarios such as informing applicants of the legal consequences of fraudulent behavior, verifying the authenticity of key application information, and inquiring about the reasons for abnormal application behavior. The detection ring collects physiological reaction data in the corresponding scenarios in real time. The specific fraud-related information test includes test scenarios such as informing applicants of the legal consequences of fraudulent behavior, verifying the authenticity of key application information, inquiring about the reasons for abnormal application behavior, and core inquiries about whether there is a connection with credit fraud.

[0072] The data collected from the detection loop and the multimodal data collected from the loan applicants were preprocessed. The data preprocessing steps are as follows:

[0073] S11: Perform content consistency verification on application behavior data, identify traces of changes in application content, eliminate contradictory and redundant information, use the edit distance algorithm to verify the consistency of the filled content, and identify traces of changes such as high-frequency modifications and cross-time period applications in a short period of time through time series anomaly detection, and eliminate contradictory data;

[0074] S12: Perform uniqueness verification and anomaly detection on device feature data, remove forged device information, perform uniqueness verification based on device fingerprint hash value, detect anomalies through the association rule base of IP address and device model, and remove forged device information. For example, if an uncommon device model is combined with a high-risk IP segment, there is high-risk forged information, which needs to be removed.

[0075] S13: Forgery traces are identified in the identity verification image data, size is normalized and feature points are extracted to generate an image authenticity feature matrix. A CNN model is used to detect image tampering traces, such as blurred edges or abnormal EXIF ​​information. Existing synthetic image recognition and filtering of AI-generated images are used. After size normalization and uniform adjustment of the specified pixels, feature points are extracted using the existing SIFT algorithm to generate a 128-dimensional image feature matrix.

[0076] S14: Verify the authenticity of the applicant's social association verification data, remove obviously forged contact information and false fund transaction records, verify the authenticity of contacts through the mobile phone operator interface, analyze the rationality of the transaction flow using the entropy value of the fund transaction amount distribution, and remove batch forged characteristic data such as the same contact being associated with more than 10 applicants or the transaction amount being concentrated in abnormal time periods.

[0077] S15: The physiological response data is filtered and denoised, and time-series aligned to remove invalid data caused by motion interference and environmental interference, retain physiological feature values ​​that are strongly correlated with the test scenario. The Kalman filter algorithm is used to remove motion interference noise, and missing data is filled in by linear interpolation. Time-series alignment is performed based on the test scenario timestamp, and physiological feature values ​​that are strongly correlated with the scenario are retained, such as the heart rate peak within 3 seconds after the scenario switch. Through data preprocessing, high-quality data support is provided for subsequent feature extraction and other processes.

[0078] In a preferred embodiment, forgery feature detection is performed on multimodal data to remove interference items and convert unstructured data into standardized features. For unstructured data, such as text data like application reasons and contact notes, the TF-IDF algorithm is used to convert it into vector features, and for time-series data such as application time distribution, Fourier transform is used to convert it into frequency domain features, uniformly standardizing the feature values ​​in the [0,1] interval. Forgery feature detection is used to remove forgery traces, transformation redundancy, and interference items in physiological data. Forgery feature detection constructs a correlation graph about application information, devices, social networks, and images, and uses graph matching algorithms to detect forgery scenarios such as different applicants sharing devices but filling in unrelated social relationships, and highly similar image features but different identity information. The system also accesses the latest fraud case database and automatically updates the forgery feature rules weekly, including but not limited to new rules such as eye reflection features in AI face-swapped images and transaction note keywords in batch forged transaction records, for real-time identification of new forgery methods. Forgery feature detection can cover static forgery and dynamic changes in application content with frequent modifications, which can improve the accuracy of forgery identification.

[0079] Synchronous correlation between physiological responses and test content is established. For example, heart rate data from income verification scenarios can be linked to the time period. During temporal correlation, Unix timestamp alignment technology is used to precisely match physiological response data with the trigger time and application operation time of the test scenario, generating three-dimensional temporal features of the test scenario, behavior, and physiological components. For example, the correlation sequence between inquiring about loan purpose and modifying information and experiencing an increase in heart rate can be used. The temporal binding of physiological data with test scenarios provides a data foundation for linking physiological abnormalities with fraudulent behavior, facilitating better identification of fraudulent behavior by suspected applicants. By directly asking fraud test questions, applicants inevitably experience psychological reactions due to guilt and tension, which can psychologically prevent fraudulent behavior. Furthermore, it allows staff to assess applicants' credit behavior based on the results of the correlation test, avoiding misjudgments through temporal correlation.

[0080] Fraud risk association features were extracted for each modality. These features included content consistency, information authenticity, behavioral continuity, and abnormal physiological responses. The extracted risk association features included:

[0081] Regarding the content to be filled in, the content consistency features are the overlap between the application information and the historical records, the frequency of content modification and the rationality of the modification, and the information consistency across application scenarios. Cross-scenario consistency includes the logical matching degree between loan purpose and income source. The semantic similarity is calculated using the existing pre-trained BERT model.

[0082] Regarding the applicant's information, the authenticity characteristics are the binding and matching degree of device information and identity information, the authenticity score of image data, and the verification pass rate of social association data. The binding and matching degree of identity is based on the historical association frequency of device fingerprint and ID card number. The image authenticity score is the true probability value output by the CNN model, and a threshold of 0.7 is set. If the image authenticity is higher than 0.7, it is judged as real. The social verification pass rate is compared by the proportion of real contacts / the proportion of real financial transactions.

[0083] Regarding the applicant's behavior, the continuity characteristics include the degree of consistency between the application behavior and the applicant's historical behavior patterns, the rationality of the application time distribution, and the continuity of device usage behavior, such as the range of changes in device login address and usage duration. If the device is rarely turned on and used, there is a risk.

[0084] Regarding the applicant's physiological response, abnormal physiological response characteristics include the fluctuation range of physiological indicators during the test, the correlation of abnormal physiological indicators with the test scenarios, and the degree of deviation of physiological indicators from the baseline values ​​of the normal population. Among them, the fluctuation range of physiological indicators = standard deviation of indicators within the scenario / standard deviation of the normal population baseline; correlation of abnormal scenarios = number of physiological abnormalities in key problem scenarios / total number of scenarios; degree of deviation = (measured value - mean of the normal population) / standard deviation of the normal population, where the baseline of the normal population is generated through training with data from over 100,000 compliant applicants.

[0085] In a preferred embodiment, a multimodal risk scoring model is constructed. The model employs a multilayer perceptron and attention mechanism to build the scoring model. Risk-related features are input into the model to calculate the applicant's single-modal risk score and comprehensive credit risk score. The input layer of the model consists of the risk-related features extracted in step S2, and the hidden layer has three layers, for example, with 64, 32, and 16 neurons respectively. The output layer contains the single-modal risk score and the comprehensive risk score. The existing AHP (Analytic Hierarchy Process) combined with gradient descent optimization is used to determine the weights of each single-modal data. For example, the weight of physiological reaction data is 0.3, the weight of application behavior data is 0.25, the weight of image authenticity data is 0.2, the weight of social association verification data is 0.2, and the weight of device feature data is 0.05. The weights can be dynamically adjusted according to different credit product scenarios.

[0086] Multimodal risk scoring models include:

[0087] A weighted fusion algorithm is used to calculate the single-modal risk score, where the weights of physiological reaction data, application behavior data, image authenticity data, and social association verification data are higher than those of device feature data. The single-modal risk score includes behavior change risk score, device forgery risk score, image authenticity risk score, social forgery risk score, and physiological abnormality risk score. The behavior change risk score is based on abnormal features of application behavior data, such as modification frequency and cross-scenario consistency, and outputs a score of 0-100 through a logistic regression model, with higher scores indicating higher risk. The device forgery risk score is based on the uniqueness of device features and abnormal detection results, using a threshold comparison method; for example, high-risk IP segments correspond to scores above 80, and the score is weighted by combining historical device fraud rates. The image authenticity risk score directly uses the true probability value output by the CNN model; for example, a true probability of 0.6 corresponds to a score of 60. The social forgery risk score is calculated using the following formula:

[0088] Social Media Forgery Risk Score = (1 - Contact Verification Pass Rate) × 40 + Number of Batch Forgery Features Detected × 20 + (1 - Reasonableness Score of Fund Transactions) × 40, with the score ranged from 0 to 100. The calculation of the Social Media Forgery Risk Score includes verifying the authenticity of contact information, including the validity of contact methods and the degree of identity information matching; analyzing the reasonableness of fund transaction records, including the frequency of transactions, the transaction amount, and the degree of matching with the applicant's qualifications; and detecting batch forgery features in social media-related data, including the duplicate rate of contact information and the homogeneity of fund transaction paths. The Social Media Forgery Risk Score is positively correlated with the verification failure rate and the number of batch forgery features detected.

[0089] The physiological abnormality risk score is based on the abnormal physiological response characteristics and uses the existing vector machine model to classify and output the risk score. The baseline deviation of ≥2 times the standard deviation is directly scored as 80 points. Through the superposition design of penalty terms and weighting terms, the score of high-risk applicants with forgery characteristics and physiological abnormality characteristics is accurately improved, which solves the problem of the single scoring of traditional models, which leads to the inability to identify risks.

[0090] Specifically, the comprehensive credit risk score incorporates penalties for forgery and alteration of characteristics, as well as a weighted item for abnormal physiological responses. Within the abnormal physiological response weighted item, the higher the degree of physiological abnormality, the greater the corresponding increase in the risk score. The comprehensive credit risk score is calculated as follows:

[0091]

[0092] In this system, A represents the single-modal risk score, γ represents the corresponding weight, B represents the penalty for forgery and alteration features, and the penalty is positively correlated with the number of forgery traces detected and the severity of alteration content. Detecting one forgery / alteration feature adds 10 points, with a cumulative maximum of 30 points. For core forgery features such as forged ID cards or mass-produced reusable devices, an additional 20 points are added. C represents the weighting for abnormal physiological reactions, which is positively correlated with the magnitude of abnormal physiological indicators and sensitivity to abnormal scenarios. A physiological abnormality risk score ≥80 adds 20 points, 60-79 adds 10 points, and 40-59 adds 5 points. Because some individuals experience slight anxiety during testing, scores below 40 are not weighted. The system correlates the comprehensive credit risk score with the actual fraud rate to improve the accuracy of the scoring.

[0093] In a preferred embodiment, the applicant's credit fraud behavior is determined based on a comprehensive credit risk score and a preset judgment level. The fraud behavior determination process further includes:

[0094] S41: If the comprehensive credit risk score is greater than or equal to the first preset threshold, or the weighted item for abnormal physiological reaction is greater than or equal to the preset warning threshold, it is marked as high fraud risk. The first preset threshold can be set to 85 points. If the comprehensive credit risk score is between the second preset threshold and the first preset threshold, it will enter the joint verification of forgery, alteration features and physiological features. The second preset threshold can be set to 60 points. The warning threshold for abnormal physiological reaction is set to the number of abnormal events in key scenarios ≥ 2 times. The comprehensive score is calculated in real time by the model and compared with the threshold. High risk is directly marked, and medium risk enters the joint verification in the next step.

[0095] S42: Detect the presence of features such as social relationship forgery, application content alteration, and batch image reuse, and ensure that the abnormal physiological reaction features are temporally correlated with the aforementioned forgery and alteration features. If these conditions are met, the penalty and weighting items will be superimposed, and the comprehensive credit risk score will be raised to above the first preset threshold. By using the temporal correlation of forgery, alteration features and abnormal physiological features, it is easier to reassess medium risk. The multi-stage judgment process reduces false alarms and false negatives from single threshold judgments. Joint verification of medium risk reduces the false negative rate, while high risk is directly marked to improve review efficiency.

[0096] S43: For applicants who trigger the superimposed item, their multimodal data is compared with the known fraud gang's behavioral feature database and physiological reaction pattern database to verify whether there is a correlation of homogenized behavioral patterns, shared equipment, image reuse, and similar physiological reaction patterns. The credit system they apply for is then connected with the known fraud gang's feature database to compare behavioral patterns, equipment features, and physiological reaction patterns. The cosine similarity algorithm is used for comparison. If the similarity is ≥0.7, it is determined to be a correlation, indicating that there is gang fraud, which makes it easier for staff to focus on judgment.

[0097] Multimodal feature cross-validation of suspected applicants also includes cross-applicant multimodal feature comparison at specified time points. The comparison steps are as follows:

[0098] S431: Calculate the similarity of identity verification image data of different applicants at the same node, use the cosine similarity algorithm to generate image matching scores, set the similarity threshold to 0.8, and if it is higher than the threshold, it is judged as image reuse;

[0099] S432: Compare the device characteristic data and application content expression style of different applicants to generate a device sharing risk score and a content plagiarism risk score. The device sharing risk score = number of shared devices × 30 + overlap of device usage time × 70. A score ≥ 60 is considered high risk.

[0100] S433: Compare the similarity of physiological response patterns of different applicants in fraud-related information tests to generate a physiological response homology risk score. The physiological response pattern similarity is compared with the time series curve using the DTW algorithm. A similarity of ≥0.75 is judged as "homology physiological response".

[0101] S434: Compare the above scores with the authenticity of the information of the corresponding applicant for cross-validation of the multimodal features of the applicant's multiple groups at the same node.

[0102] S44: If cross-validation confirms the presence of characteristics associated with organized fraud, it is determined to be organized fraud; if only a single forgery, alteration feature, or isolated physiological abnormality is detected but there is no organized fraud, it is determined to be individual fraud.

[0103] Multimodal comparison across applicants accurately identifies common features of fraud gangs, solving the problem that traditional methods cannot penetrate individual disguises to identify gangs, improving the accuracy of gang fraud identification, and enhancing the efficiency of anti-fraud in the credit system. At the same time, time-series correlation verification avoids misjudgments due to isolated physiological anomalies, such as single indicator anomalies caused by applicants' nervousness, thus reducing the false alarm rate.

[0104] In a preferred embodiment, the anti-fraud detection results are output, which clearly indicate the fraud risk level and fraud type. The results include the applicant's comprehensive credit risk score and risk level, fraud determination results, fraud association descriptions, and risk score composition details. The fraud association descriptions include specific detection results for forgery features, alteration features, and abnormal physiological features. The risk score composition details include risk scores for each single modality, penalty adjustment values, and abnormal physiological reaction weighting values. The results are visualized through an association graph to facilitate review by credit review personnel.

[0105] Example 2: Based on Example 1, a credit anti-fraud system integrating multimodal data and graph neural networks is also provided. The system includes:

[0106] The identity authentication and storage module is used to collect and store multimodal data of credit applicants. The multimodal data includes at least application behavior data, device feature data, identity verification image data, and social association verification data. It is also used to bind a unique identity to the applicant, record historical application records and fraud labels.

[0107] The data acquisition and transmission module includes a detection ring for the applicant to wear. The detection ring has built-in physiological sensors to collect real-time physiological response data of the applicant's heart rate variability, skin conductance, skin temperature and blood oxygen saturation during the fraud information test, and to transmit the collected multimodal data to the preprocessing module.

[0108] The preprocessing module is used to preprocess the received multimodal data, including: performing content consistency verification and redundancy removal on application behavior data; performing uniqueness verification and forgery detection on device feature data; performing forgery trace recognition, size normalization, and feature point extraction on identity verification image data; performing authenticity verification on social association verification data; and performing filtering, noise reduction, time sequence alignment, and motion / environment interference removal on physiological reaction data.

[0109] The detection module is used to detect forgery features in the preprocessed multimodal data, remove interference items, convert unstructured data into standardized features, synchronously correlate the temporal correspondence between physiological response data and test content, and extract fraud risk correlation features under each modality; fraud risk correlation features include content consistency features, information authenticity features, behavioral continuity features, and abnormal physiological response features.

[0110] The network module is used to build and train a graph neural network model, constructing a heterogeneous graph structure between the applicant and known fraud gangs and applicants at the same node, and extracting the embedding representation of multimodal features, which is used to perform multimodal cross-validation and gang association analysis between the applicant and known fraud gangs and applicants at the same node.

[0111] The risk assessment and response module is used to calculate the single-modal risk score and comprehensive credit risk score based on the extracted risk correlation features and by calling the multimodal risk scoring model. It also determines whether the applicant has engaged in fraudulent behavior based on the preset judgment level. When fraud is suspected, the module is used to cross-validate the multimodal features of the suspected applicant with existing fraud gangs and applicants at the same node to confirm whether it is gang fraud. Finally, the anti-fraud detection results are output.

[0112] Although embodiments of the invention have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the appended claims and their equivalents.

Claims

1. A credit fraud prevention method integrating multimodal data and graph neural networks, characterized in that, Includes the following steps: S1: Collect multimodal data of loan applicants. Applicants take a fraud information test by wearing a detection ring, generate physiological reaction data, and preprocess the data. S2: Perform forgery feature detection on multimodal data, remove interference items, convert unstructured data into standardized features, synchronously correlate the temporal correspondence between physiological reactions and test content, and extract fraud risk correlation features under each modality; S3: Construct a multimodal risk scoring model, input risk-related features into the model, and calculate the applicant's single-modal risk score and comprehensive credit risk score; S4: Based on the comprehensive credit risk score and the preset judgment level, determine the applicant's credit fraud behavior; If the comprehensive credit risk score is higher than the preset risk threshold, forgery or alteration features are detected and the penalty trigger conditions are met, or abnormal physiological reaction features reach the preset warning standard, the applicant is suspected of fraud if at least one of the conditions is met. The suspected applicant is cross-verified with existing fraud gangs and applicants at the same node to confirm whether the fraud is committed by a fraud gang. S5: Output anti-fraud detection results.

2. The credit anti-fraud method integrating multimodal data and graph neural networks according to claim 1, characterized in that, In step S1, the multimodal data includes application behavior data, device feature data, identity verification image data, and social association verification data. The detection ring uses built-in sensors to collect real-time physiological response data on heart rate variability, skin conductance, skin temperature, and blood oxygen saturation from the wearer undergoing the fraud information test. The fraud information test includes test scenarios such as informing the applicant of the legal consequences of fraudulent behavior, verifying the authenticity of key application information, and inquiring about the reasons for abnormal application behavior.

3. The credit anti-fraud method integrating multimodal data and graph neural networks according to claim 1, characterized in that, The data preprocessing steps in step S1 are as follows: S11: Perform content consistency verification on application behavior data, identify traces of changes in application content, and eliminate contradictory and redundant information; S12: Perform uniqueness verification and anomaly detection on equipment feature data to remove forged equipment information; S13: Perform forgery detection, size normalization, and feature point extraction on the identity verification image data to generate an image authenticity feature matrix; S14: Verify the authenticity of the applicant's social connection verification data and remove obviously forged contact information and false financial transaction records; S15: Filter and denoise the physiological response data, align the time sequence, remove invalid data caused by motion interference and environmental interference, and retain physiological feature values ​​that are strongly correlated with the test scenario.

4. The credit anti-fraud method integrating multimodal data and graph neural networks according to claim 1, characterized in that, In step S2, the forgery feature detection is used to remove forgery traces, transform redundancy and physiological data interference items, and the fraud risk association features under each modality include content consistency features, information authenticity features, behavioral continuity features and abnormal physiological reaction features.

5. The credit anti-fraud method integrating multimodal data and graph neural networks according to claim 1, characterized in that, The risk association feature extraction in step S2 includes: Regarding the content filled in, the degree of overlap between the application information and the historical records, the frequency of modifications to the content and the rationality of the modifications, and the consistency of information across application scenarios; Regarding applicant information, the degree of matching between device information and identity information, the authenticity score of image data, and the verification pass rate of social association data are considered. Regarding the applicant's behavior, the degree of consistency between the application behavior and the applicant's historical behavior patterns, the rationality of the application time distribution, and the continuity of equipment usage behavior; Regarding the applicant's physiological response, the fluctuation range of physiological indicators during the test, the correlation between abnormal physiological indicators and the test scenario, and the degree of deviation of physiological indicators from the baseline values ​​of the normal population.

6. The credit anti-fraud method integrating multimodal data and graph neural networks according to claim 1, characterized in that, The multimodal risk scoring model in step S3 includes: A weighted fusion algorithm was used to calculate the single-modal risk score, in which the weights of physiological reaction data, application behavior data, image authenticity data, and social association verification data were higher than the weights of device feature data. The single-modal risk score includes behavioral change risk score, device forgery risk score, image authenticity risk score, social forgery risk score, and physiological abnormality risk score; The comprehensive credit risk score incorporates penalties for forgery and alteration of characteristics, as well as weighting for abnormal physiological responses. The comprehensive credit risk score is calculated as follows: Wherein, A is the single-modal risk score, γ is the corresponding weight, B is the penalty term for the forgery and transformation features, and the penalty term is positively correlated with the number of detected forgery traces and the severity of the transformation content, and C is the weighted term for abnormal physiological reactions, which is positively correlated with the abnormal amplitude of physiological indicators and the sensitivity to abnormal scenarios.

7. The credit anti-fraud method integrating multimodal data and graph neural networks according to claim 1, characterized in that, The fraud behavior determination process in step S4 also includes: S41: If the comprehensive credit risk score is greater than or equal to the first preset threshold, or the weighted item for abnormal physiological reaction is greater than or equal to the preset warning threshold, it is marked as high fraud risk; if the comprehensive credit risk score is between the second preset threshold and the first preset threshold, it will enter the joint verification of forgery, alteration features and physiological features. S42: Detect whether there are features such as social relationship forgery, application content transformation, and batch image reuse, and whether the abnormal physiological reaction features are temporally related to the above forgery and transformation features. If the conditions are met, the penalty item and the weighting item are superimposed, and the comprehensive credit risk score is raised to above the first preset threshold. S43: For applicants who trigger the superimposed item, compare their multimodal data with the known fraud gang's behavioral feature database and physiological reaction pattern database to verify whether there is a correlation of homogenized behavioral patterns, shared equipment, image reuse, and similar physiological reaction patterns. S44: If cross-validation confirms the presence of characteristics associated with organized fraud, it is determined to be organized fraud; if only a single forgery, alteration feature, or isolated physiological abnormality is detected but there is no organized connection, it is determined to be individual fraud.

8. The credit anti-fraud method integrating multimodal data and graph neural networks according to claim 7, characterized in that, The multimodal feature cross-validation of the suspected applicant in step S4 also includes cross-applicant multimodal feature comparison at specified time points. The comparison steps are as follows: S431: Calculate the similarity of identity verification image data of different applicants at the same node, and use the cosine similarity algorithm to generate image matching scores; S432: Compare the device characteristic data and application content expression style of different applicants to generate device sharing risk score and content plagiarism risk score; S433: Compare the similarity of physiological response patterns of different applicants in fraud-related information tests to generate physiological response homology risk scores; S434: Compare the above scores with the authenticity of the information of the corresponding applicant for cross-validation of the multimodal features of the applicant's multiple groups at the same node.

9. The credit anti-fraud method integrating multimodal data and graph neural networks according to claim 1, characterized in that, The anti-fraud detection results output in step S5 clearly define the fraud risk level and fraud type, including: The applicant's comprehensive credit risk score and risk level, fraud determination results, fraud association explanation, and risk score composition details, including the specific detection results of forgery-type features, alteration-type features, and physiological abnormality features, and the risk score composition details include the risk score of each single modality, penalty adjustment value, and physiological abnormality weighted value.

10. A credit fraud prevention system integrating multimodal data and graph neural networks, characterized in that, The system implementing the credit fraud prevention method integrating multimodal data and graph neural networks as described in any one of claims 1-9, the system comprising: The identity authentication and storage module is used to collect and store multimodal data of credit applicants. The multimodal data includes at least application behavior data, device feature data, identity verification image data, and social association verification data. It is also used to bind a unique identity to the applicant and record historical application records and fraud tags. The data acquisition and transmission module includes a detection ring for the applicant to wear. The detection ring has a built-in physiological sensor for collecting the applicant's physiological response data such as heart rate variability, skin conductance, skin temperature and blood oxygen saturation in real time during the fraud information test, and for transmitting the collected multimodal data to the preprocessing module. The preprocessing module is used to preprocess the received multimodal data. The preprocessing module performs content consistency verification and redundancy removal on the application behavior data, uniqueness verification and forgery detection on the device feature data, and forgery trace recognition, size normalization and feature point extraction on the identity verification image data. The detection module is used to detect forgery features in the preprocessed multimodal data; The network module is used to build and train a graph neural network model. The network module is used to perform multimodal cross-validation and group association analysis between the applicant and known fraud gangs and applicants at the same node. The risk assessment and response module is used to determine whether an applicant has engaged in fraudulent behavior based on extracted risk-related features and a preset judgment level. The risk assessment and response module is also used to determine and output the results of anti-fraud detection.