A transaction behavior risk detection method, device, storage medium and product

By constructing a transaction graph and using a graph neural network model to identify and calculate risk transmission weights, the problem of lagging detection of decentralized transaction behavior in existing technologies is solved, achieving more reliable risk detection and ensuring the security of financial transactions.

CN122492341APending Publication Date: 2026-07-31INDUSTRIAL AND COMMERCIAL BANK OF CHINA
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
INDUSTRIAL AND COMMERCIAL BANK OF CHINA
Filing Date
2026-04-24
Publication Date
2026-07-31

AI Technical Summary

Technical Problem

Existing technologies lack comprehensive risk detection capabilities for decentralized transactions with potential relationships, resulting in delayed detection results for abnormal transaction behaviors and affecting the security of the transaction process.

Method used

By constructing a transaction graph, a graph neural network model is used to identify transaction behaviors with potential relationships, and the risk transmission weights of the edges connecting nodes are calculated. Risk detection is then performed in conjunction with node attribute information.

Benefits of technology

This improves the reliability of transaction risk detection results and ensures the security of the transaction process on the financial business platform.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122492341A_ABST
    Figure CN122492341A_ABST
Patent Text Reader

Abstract

This invention discloses a method, device, storage medium, and product for detecting transaction behavior risks. The method includes: constructing a transaction graph based on real-time transaction data of a target financial product; periodically identifying target transaction behaviors that occur frequently within a target time and space range from the transaction graph; inputting the transaction graph into a graph neural network model; outputting the risk transmission weights corresponding to the connecting edges of each node in the transaction graph through the graph neural network model; extracting a target subgraph corresponding to the target transaction behavior from the transaction graph; and determining the risk detection result corresponding to the target transaction behavior based on the attribute information of each node in the target subgraph and the risk transmission weights corresponding to the connecting edges of each node. The technical solution of this invention can improve the reliability of transaction behavior risk detection results and ensure the security of the transaction process in a financial business platform.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of artificial intelligence technology, and is applicable to financial business scenarios. In particular, it relates to a method, device, storage medium, and product for detecting transaction behavior risks. Background Technology

[0002] Currently, with the development of digital transformation in financial services, more and more users can trigger transactions through specific financial products on financial service platforms. In order to ensure the security of these transactions, it is crucial to automatically detect risks associated with them.

[0003] In existing technologies, risk detection of transaction behavior usually adopts static discrimination rules, which judge each transaction behavior generated under financial products one by one. This lacks the comprehensive risk detection capability for dispersed transaction behaviors with potential relationships, resulting in delayed detection results of abnormal transaction behavior and affecting the security of the transaction process. Summary of the Invention

[0004] This invention provides a method, device, storage medium, and product for detecting transaction behavior risks. It can perform comprehensive risk detection on dispersed transaction behaviors with potential relationships, improve the reliability of transaction behavior risk detection results, and ensure the security of the transaction process in financial business platforms.

[0005] According to one aspect of the present invention, a method for detecting transaction behavior risk is provided, the method comprising: A transaction graph is constructed based on the real-time transaction data generated by the target financial product, and target transaction behaviors that occur in a concentrated manner within the target time and space are periodically identified from the transaction graph. The transaction graph is input into a graph neural network model, and the graph neural network model outputs the risk transmission weights corresponding to the connecting edges of each node in the transaction graph. Extract the target subgraph corresponding to the target transaction behavior from the transaction graph. Based on the attribute information of each node in the target subgraph and the risk transmission weights corresponding to the connecting edges of each node, determine the risk detection result corresponding to the target transaction behavior.

[0006] According to another aspect of the present invention, a transaction behavior risk detection device is provided, the device comprising: The graph construction module is used to construct a transaction graph based on the real-time transaction data generated by the target financial product, and periodically identify target transaction behaviors that occur in a concentrated manner within the target time and space range from the transaction graph. The model application module is used to input the transaction graph into a graph neural network model and output the risk transmission weights corresponding to the connecting edges of each node in the transaction graph through the graph neural network model. The risk detection module is used to extract the target subgraph corresponding to the target transaction behavior from the transaction graph, and determine the risk detection result corresponding to the target transaction behavior based on the attribute information of each node in the target subgraph and the risk transmission weight corresponding to the connecting edges of each node.

[0007] According to another aspect of the present invention, an electronic device is provided, the electronic device comprising: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that can be executed by the at least one processor, which enables the at least one processor to perform the transaction risk detection method according to any embodiment of the present invention.

[0008] According to another aspect of the present invention, a computer-readable storage medium is provided, the computer-readable storage medium storing computer instructions for causing a processor to execute and implement the transaction behavior risk detection method according to any embodiment of the present invention.

[0009] According to another aspect of the present invention, a computer program product is provided, the computer program product comprising a computer program that, when executed by a processor, implements the transaction behavior risk detection method described in any embodiment of the present invention.

[0010] The technical solution provided by this invention constructs a transaction graph based on real-time transaction data of the target financial product, periodically identifies target transaction behaviors that occur in a concentrated manner within a target time and space from the transaction graph, inputs the transaction graph into a graph neural network model, outputs the risk transmission weights corresponding to the connecting edges of each node in the transaction graph through the graph neural network model, extracts the target subgraph corresponding to the target transaction behavior from the transaction graph, and determines the risk detection result corresponding to the target transaction behavior based on the attribute information of each node in the target subgraph and the risk transmission weights corresponding to the connecting edges of each node. This technical means can comprehensively detect the risk of dispersed transaction behaviors with potential relationships, improve the reliability of transaction behavior risk detection results, and ensure the security of the transaction process in the financial business platform.

[0011] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of the present invention, nor is it intended to limit the scope of the invention. Other features of the invention will become readily apparent from the following description. Attached Figure Description

[0012] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0013] Figure 1 This is a flowchart of a transaction behavior risk detection method provided by an embodiment of the present invention; Figure 2 This is a flowchart of another transaction behavior risk detection method provided by an embodiment of the present invention; Figure 3 This is a schematic diagram of the structure of a transaction behavior risk detection device provided in an embodiment of the present invention; Figure 4 This is a schematic diagram of the structure of an electronic device that implements the transaction behavior risk detection method of this invention. Detailed Implementation

[0014] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.

[0015] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0016] Figure 1 This is a flowchart illustrating a transaction behavior risk detection method provided in an embodiment of the present invention. This embodiment is applicable to situations where risk detection is performed on transaction behaviors triggered in financial products. The method can be executed by a transaction behavior risk detection device, which can be implemented in hardware and / or software and configured within a financial business platform, such as... Figure 1As shown, the method includes: Step 110: Construct a transaction graph based on the real-time transaction data generated by the target financial product, and periodically identify target transaction behaviors that occur in a concentrated manner within the target time and space range from the transaction graph.

[0017] In this embodiment, after obtaining the real-time transaction data of the target financial product, the financial business platform can dynamically construct a transaction graph with transaction entities as nodes and their relationships as edges based on the real-time transaction data. Furthermore, the financial business platform can periodically identify transaction behaviors that occur in close proximity at similar times and locations from the transaction graph and mark these behaviors as suspicious transactions (i.e., target transactions).

[0018] Step 120: Input the transaction graph into a graph neural network model, and output the risk transmission weights corresponding to the connecting edges of each node in the transaction graph through the graph neural network model.

[0019] In this embodiment, after the transaction graph is constructed, it can be input into a pre-trained graph neural network model. The graph neural network model can extract features from the attribute information of each node in the transaction graph and the relationship between each node. Based on the feature extraction results and the pre-trained model parameters, the risk transmission weights corresponding to the connecting edges of each node in the transaction graph are calculated.

[0020] The risk transmission weight can be a quantified value of the intensity of risk transmission along each connection edge, used to characterize the probability of risk transmission along each connection edge. For example, suppose there are nodes A (representing a trading account), B (representing a trading device), and C (representing a trading merchant) in the transaction graph. Node A is connected to node B, and node B is connected to node C. If it is known that the trading account corresponding to node A is abnormal, the trading device corresponding to node B and the trading merchant corresponding to node C are normal, and the attribute information of node C includes positive reviews of the trading merchant, then it can be determined that the probability of risk transmission between node A and node B is high, and the probability of risk transmission between node B and node C is low. Therefore, a higher risk transmission weight can be set for the connection edge between node A and node B, and a lower risk transmission weight can be set for the connection edge between node B and node C.

[0021] In one embodiment of this example, before inputting the transaction graph into the graph neural network model, the method further includes: acquiring a graph data training set; the graph data training set includes transaction graph data and risk transmission labels corresponding to the relationships between transaction entities in the transaction graph data; and using the graph data training set to iteratively train the graph neural network model until the graph neural network model converges.

[0022] Specifically, before step 110, multiple transaction samples generated under the target financial product can be collected, and the multiple transaction samples can be processed according to the graph data structure to obtain transaction graph data. Then, the risk transmission labels in the manually reviewed transaction graph data are obtained, and a graph data training set is generated based on the risk transmission labels and the transaction graph data.

[0023] The advantage of this setup is that by training the graph neural network model using a graph data training set containing risk transmission labels, the graph neural network model can accurately and quickly output the risk transmission weights corresponding to the connecting edges of each node in the transaction graph, thereby improving the efficiency of risk detection in transaction behavior and the reliability of the detection results.

[0024] Step 130: Extract the target subgraph corresponding to the target transaction behavior from the transaction graph. Based on the attribute information of each node in the target subgraph and the risk transmission weights corresponding to the connecting edges of each node, determine the risk detection result corresponding to the target transaction behavior.

[0025] In this embodiment, after identifying target transaction behaviors that occur in a concentrated manner at similar times and locations through step 110, a target subgraph corresponding to the target transaction behavior can be extracted from the complete transaction graph. Optionally, after extracting the target subgraph, it can be determined whether the attribute information of each node in the target subgraph is normal, and at the same time, the risk transmission weights corresponding to the connecting edges of each node in the target subgraph are linearly calculated. Finally, based on the node judgment results and the calculation results of the risk transmission weights, the risk detection result corresponding to the target transaction behavior is determined.

[0026] The advantage of this setup is that, compared to the existing technology that uses static discrimination rules to judge each transaction behavior one by one, this embodiment first identifies target transaction behaviors that may have potential relationships in time and space, and then combines the risk transmission weights in the transaction graph to perform risk detection on the target transaction behaviors. This allows for comprehensive risk detection of dispersed transaction behaviors with potential relationships, thereby solving the blind spot of "single-point detection" in existing risk detection methods and improving the reliability of transaction behavior risk detection results.

[0027] The technical solution provided by this invention constructs a transaction graph based on real-time transaction data of the target financial product, periodically identifies target transaction behaviors that occur in a concentrated manner within a target time and space from the transaction graph, inputs the transaction graph into a graph neural network model, outputs the risk transmission weights corresponding to the connecting edges of each node in the transaction graph through the graph neural network model, extracts the target subgraph corresponding to the target transaction behavior from the transaction graph, and determines the risk detection result corresponding to the target transaction behavior based on the attribute information of each node in the target subgraph and the risk transmission weights corresponding to the connecting edges of each node. This technical means can comprehensively detect the risk of dispersed transaction behaviors with potential relationships, improve the reliability of transaction behavior risk detection results, and ensure the security of the transaction process in the financial business platform.

[0028] Figure 2 A flowchart of another transaction behavior risk detection method provided in an embodiment of the present invention is shown below. Figure 2 As shown, the method includes: Step 210: Extract multiple transaction entities and the relationships between them from the real-time transaction data generated by the target financial product.

[0029] In this step, specifically, the transaction entities may include transaction accounts, transaction devices, transaction locations, and transaction merchants, and the relationships between the transaction entities may include transfers, logins, etc., which are not limited in this embodiment.

[0030] Step 220: Treat each transaction entity as a node, and the relationship between each transaction entity as an edge connecting the nodes, and construct a transaction graph based on each node and the edges connecting the nodes.

[0031] In this step, the nodes corresponding to each transaction entity can be connected based on the relationships between them. For example, assuming that a transaction account D triggers a transfer operation to a merchant G through transaction device E at transaction location F, the following relationship can be established: DEG, DF.

[0032] The advantage of this setup is that by constructing a transaction graph corresponding to the target financial product, a global analysis of the transaction behavior generated by the target financial product can be achieved, making it easier to identify target transaction behaviors that occur in close proximity at similar times and locations.

[0033] Step 230: Periodically identify target transaction behaviors that occur in a concentrated manner within the target time and space range from the transaction graph.

[0034] In one embodiment of this example, identifying target transaction behaviors that occur in a concentrated manner within a target time and space range from the transaction graph includes: obtaining the timestamp and location information corresponding to each transaction behavior in the transaction graph; clustering multiple transaction behaviors in the transaction graph based on the timestamp and location information corresponding to each transaction behavior, a preset spatial neighborhood threshold, a temporal neighborhood threshold, and a transaction behavior quantity threshold; and determining the target transaction behaviors that occur in a concentrated manner within the target time and space range based on the clustering results.

[0035] In this embodiment, optionally, a spatiotemporal density clustering algorithm can be used to identify target transaction behaviors that are highly clustered in spatiotemporal space and may have potential relationships from the transaction graph based on the timestamp and location information corresponding to each transaction behavior, and to use the target transaction behaviors as the key objects for subsequent risk detection.

[0036] The spatiotemporal density clustering algorithm pre-sets spatial neighborhood thresholds, temporal neighborhood thresholds, and transaction behavior quantity thresholds. Specifically, when clustering multiple transaction behaviors in the transaction graph, each transaction behavior can be treated as a cluster point. The number of other points within the corresponding spatiotemporal neighborhood of each cluster point is counted, and this number is used as the spatiotemporal density of the cluster point. When the spatiotemporal density of a cluster point is greater than the preset quantity threshold, the cluster point is marked as a core point. Then, all points within the spatiotemporal neighborhood of the core point are grouped into clusters. Finally, all transaction behaviors in the clusters are used as the target transaction behavior.

[0037] The advantage of this setup is that by using a spatiotemporal density clustering algorithm to cluster multiple transaction behaviors in the transaction graph, it is possible to accurately identify target transaction behaviors that are highly clustered in time and space and may have potential relationships, thereby improving the reliability of transaction behavior risk detection results in the financial business platform.

[0038] Step 240: Input the transaction graph into a graph neural network model, convert the attribute information of each node in the transaction graph into a feature vector through an embedding layer, and input the feature vector into a graph pooling layer.

[0039] In this embodiment, the graph neural network model includes an embedding layer, a graph pooling layer, and a graph attention layer. In this step, after the transaction graph is input into the graph neural network model, the embedding layer can convert discrete node attribute information into low-dimensional, dense feature vectors, so that subsequent processing layers in the model can accurately understand and process the discrete attribute information.

[0040] Step 250: Aggregate the feature vectors through the graph pooling layer, and input the aggregation result into the graph attention layer. The graph attention layer calculates the risk propagation weights corresponding to the connection edges of each node based on the aggregation result.

[0041] In this step, after the feature vector is input into the graph pooling layer, the feature vector can be aggregated by the graph pooling layer to retain key information while reducing the data processing scale, thereby improving the data processing efficiency of subsequent processing layers in the model. After obtaining the aggregation result corresponding to the feature vector, an attention mechanism can be used through the graph attention layer to adaptively assign risk propagation weights to the connection edges of each node according to the degree of correlation between each node and its neighboring nodes in the aggregation result.

[0042] The advantage of this setup is that by deploying embedding layers, graph pooling layers, and graph attention layers in the graph neural network model, the model can accurately understand and process discrete node attribute information and quantify the risk transmission strength corresponding to the connecting edges of each node in the transaction graph, thereby improving the accuracy of subsequent target transaction behavior risk detection results.

[0043] Step 260: Extract the target subgraph corresponding to the target transaction behavior from the transaction graph, obtain the feature vector corresponding to the target subgraph from the output of the embedding layer, and input the feature vector corresponding to the target subgraph into the graph pooling layer.

[0044] Step 270: Aggregate the feature vector corresponding to the target subgraph and the risk propagation weights corresponding to the connecting edges of each node in the target subgraph through the graph pooling layer to obtain the embedding vector corresponding to the target subgraph.

[0045] In this step, the feature vector corresponding to the target subgraph and the risk propagation weights corresponding to the connecting edges of each node in the target subgraph can be aggregated to obtain a low-dimensional embedding vector of fixed length, which is convenient for subsequent classifier processing.

[0046] Step 280: Input the embedding vector corresponding to the target subgraph into a pre-trained classifier, and output the risk probability corresponding to the target subgraph through the classifier.

[0047] In this step, the risk probability output by the classifier can be a specific value between [0,1]. This risk probability is used to characterize the confidence level that the target transaction behavior is judged as abnormal. Specifically, if the risk probability output by the classifier is greater than a preset value, the financial business platform can trigger corresponding risk control measures based on the risk probability, such as sending alarm information to the transaction account in the target transaction behavior or intercepting the target transaction behavior. This embodiment does not impose any restrictions on this.

[0048] The advantage of this setup is that by inputting the embedding vector corresponding to the target subgraph into the pre-trained classifier, the risk detection results of the target transaction behavior can be quantified. This allows the financial business platform to quickly take corresponding risk control measures based on the quantified risk detection results, thus ensuring the security of the transaction process within the financial business platform.

[0049] In one embodiment of this example, the method further includes: after detecting newly added transaction graph data in the graph data training set, obtaining historical transaction graph data associated with the newly added transaction graph data; establishing an incremental training set based on the newly added transaction graph data, the historical transaction graph data, and the risk transmission labels corresponding to the newly added transaction graph data and the historical transaction graph data respectively; and using the incremental training set to incrementally train the graph neural network model.

[0050] In this embodiment, a method for adaptively optimizing a graph neural network model is also provided. Specifically, new transaction samples generated under the target financial product can be collected periodically, and the new transaction samples can be processed according to the graph data structure to obtain new transaction graph data. Then, the new transaction graph data can be added to the graph data training set.

[0051] In one specific embodiment, after detecting new transaction graph data in the graph data training set, it is not necessary to train the entire graph neural network model. Instead, an incremental training set is used to continue training specific processing layers (such as graph attention layers) in the model. This allows the graph neural network model to learn new data features while retaining existing knowledge, avoiding the high cost of training from scratch.

[0052] The technical solution provided by this invention constructs a transaction graph, periodically identifies target transaction behaviors that occur in a concentrated manner within a target time and space range from the transaction graph, inputs the transaction graph into a graph neural network model, converts the attribute information of each node in the transaction graph into feature vectors through an embedding layer, aggregates the feature vectors through a graph pooling layer, and calculates the risk transmission weights corresponding to the connection edges of each node based on the aggregation results through a graph attention layer. It then extracts the target subgraph corresponding to the target transaction behavior from the transaction graph, obtains the feature vectors corresponding to the target subgraph, aggregates the feature vectors and risk transmission weights corresponding to the target subgraph through a graph pooling layer to obtain an embedding vector, and inputs the embedding vectors corresponding to the target subgraph into a pre-trained classifier. By using the classifier to output the risk probability corresponding to the target subgraph, this technical means can comprehensively detect the risks of dispersed transaction behaviors with potential relationships, improve the reliability of transaction risk detection results, and ensure the security of the transaction process in the financial business platform.

[0053] It should be noted that the information collected in this embodiment is information and data authorized by the user or fully authorized by all parties. The collection, storage, use, processing, transmission, provision, disclosure and application of the relevant data all comply with the relevant laws, regulations and standards of the relevant countries and regions, and necessary confidentiality and protection measures have been taken. The "minimum necessary" requirement is followed, and it does not violate public order and good morals. Corresponding operation entry points are provided for users to choose to authorize or refuse.

[0054] Figure 3 This is a schematic diagram of the structure of a transaction behavior risk detection device provided in an embodiment of the present invention, as shown below. Figure 3 As shown, the device includes: a map construction module 310, a model application module 320, and a risk detection module 330.

[0055] The graph construction module 310 is used to construct a transaction graph based on the real-time transaction data generated by the target financial product, and periodically identify target transaction behaviors that occur in a concentrated manner within the target time and space range from the transaction graph. Model application module 320 is used to input the transaction graph into a graph neural network model and output the risk transmission weights corresponding to the connecting edges of each node in the transaction graph through the graph neural network model. The risk detection module 330 is used to extract the target subgraph corresponding to the target transaction behavior from the transaction graph, and determine the risk detection result corresponding to the target transaction behavior based on the attribute information of each node in the target subgraph and the risk transmission weight corresponding to the connecting edge of each node.

[0056] The technical solution provided by this invention constructs a transaction graph based on real-time transaction data of the target financial product, periodically identifies target transaction behaviors that occur in a concentrated manner within a target time and space from the transaction graph, inputs the transaction graph into a graph neural network model, outputs the risk transmission weights corresponding to the connecting edges of each node in the transaction graph through the graph neural network model, extracts the target subgraph corresponding to the target transaction behavior from the transaction graph, and determines the risk detection result corresponding to the target transaction behavior based on the attribute information of each node in the target subgraph and the risk transmission weights corresponding to the connecting edges of each node. This technical means can comprehensively detect the risk of dispersed transaction behaviors with potential relationships, improve the reliability of transaction behavior risk detection results, and ensure the security of the transaction process in the financial business platform.

[0057] Based on the above embodiments, the graph neural network model includes an embedding layer, a graph pooling layer, and a graph attention layer.

[0058] The device further includes: The training set acquisition module is used to acquire the graph data training set; the graph data training set includes transaction graph data and risk transmission labels corresponding to the relationships between transaction entities in the transaction graph data; The model training module is used to iteratively train the graph neural network model using the graph data training set until the graph neural network model converges. The incremental training module is used to detect newly added transaction graph data in the graph data training set, obtain historical transaction graph data associated with the newly added transaction graph data, establish an incremental training set based on the newly added transaction graph data, historical transaction graph data, and risk transmission labels corresponding to the newly added transaction graph data and historical transaction graph data respectively, and use the incremental training set to incrementally train the graph neural network model.

[0059] The map construction module 310 includes: The transaction entity extraction unit is used to extract multiple transaction entities and the relationships between the transaction entities from the transaction data generated in real time by the target financial product. The transaction graph construction unit is used to construct a transaction graph based on each of the transaction entities as nodes and the relationships between the transaction entities as edges connecting the nodes. The clustering unit is used to obtain the timestamp and location information corresponding to each transaction behavior in the transaction graph, and to cluster multiple transaction behaviors in the transaction graph based on the timestamp and location information corresponding to each transaction behavior, a preset spatial neighborhood threshold, a temporal neighborhood threshold, and a transaction behavior quantity threshold. Based on the clustering results, the target transaction behaviors that occur in a concentrated manner within the target time and space range are determined.

[0060] Model application module 320 includes: An embedding layer processing unit is used to convert the attribute information of each node in the transaction graph into a feature vector through the embedding layer, and input the feature vector into the graph pooling layer; The pooling layer processing unit is used to aggregate the feature vector through the graph pooling layer, input the aggregation result into the graph attention layer, and calculate the risk transmission weight corresponding to the connection edge of each node through the graph attention layer based on the aggregation result.

[0061] Risk detection module 330 includes: The feature vector acquisition unit is used to obtain the feature vector corresponding to the target subgraph from the output of the embedding layer, and input the feature vector corresponding to the target subgraph into the graph pooling layer. The vector aggregation unit is used to aggregate the feature vector corresponding to the target subgraph and the risk propagation weights corresponding to the connecting edges of each node in the target subgraph through the graph pooling layer to obtain the embedding vector corresponding to the target subgraph. The risk probability output unit is used to input the embedding vector corresponding to the target subgraph into a pre-trained classifier, and output the risk probability corresponding to the target subgraph through the classifier.

[0062] The above-described apparatus can execute the methods provided in all the foregoing embodiments of the present invention, and has the corresponding functional modules and beneficial effects for executing the above methods. Technical details not described in detail in the embodiments of the present invention can be found in the methods provided in all the foregoing embodiments of the present invention.

[0063] Figure 4 A schematic diagram of an electronic device 10, which can be used to implement embodiments of the present invention, is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices (e.g., helmets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the invention described and / or claimed herein.

[0064] like Figure 4 As shown, the electronic device 10 includes at least one processor 11 and a memory, such as a read-only memory (ROM) 12 or a random access memory (RAM) 13, communicatively connected to the at least one processor 11. The memory stores computer programs executable by the at least one processor. The processor 11 can perform various appropriate actions and processes based on the computer program stored in the ROM 12 or loaded into the RAM 13 from the storage unit 18. The RAM 13 can also store various programs and data required for the operation of the electronic device 10. The processor 11, ROM 12, and RAM 13 are interconnected via a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.

[0065] Multiple components in electronic device 10 are connected to I / O interface 15, including: input unit 16, such as keyboard, mouse, etc.; output unit 17, such as various types of displays, speakers, etc.; storage unit 18, such as disk, optical disk, etc.; and communication unit 19, such as network card, modem, wireless transceiver, etc. Communication unit 19 allows electronic device 10 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.

[0066] Processor 11 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, digital signal processing (DSP) processors, and any suitable processor, controller, microcontroller, etc. Processor 11 performs the various methods and processes described above, such as trading behavior risk detection methods.

[0067] In some embodiments, the transaction risk detection method may be implemented as a computer program tangibly contained in a computer-readable storage medium, such as storage unit 18. In some embodiments, part or all of the computer program may be loaded and / or installed on electronic device 10 via ROM 12 and / or communication unit 19. When the computer program is loaded into RAM 13 and executed by processor 11, one or more steps of the transaction risk detection method described above may be performed. Alternatively, in other embodiments, processor 11 may be configured to perform the transaction risk detection method by any other suitable means (e.g., by means of firmware).

[0068] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-chips (SoCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.

[0069] Computer programs used to implement the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when executed by the processor, the computer programs cause the functions / operations specified in the flowcharts and / or block diagrams to be performed. The computer programs may be executed entirely on a machine, partially on a machine, or as a standalone software package, partially on a machine and partially on a remote machine, or entirely on a remote machine or server.

[0070] In the context of this invention, a computer-readable storage medium can be a tangible medium that may contain or store a computer program for use by or in conjunction with an instruction execution system, apparatus, or device. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, RAM, ROM, erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.

[0071] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a cathode ray tube (CRT) or a liquid crystal display (LCD)) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).

[0072] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or middleware components (e.g., application servers), or frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., communication networks). Examples of communication networks include local area networks (LANs), wide area networks (WANs), blockchain networks, and the Internet.

[0073] A computing system can include clients and servers. Clients and servers are generally geographically separated and typically interact via communication networks. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or cloud host, which is a hosting product within the cloud computing service system. It addresses the shortcomings of traditional physical hosts and Virtual Private Servers (VPS) in terms of management difficulty and weak business scalability.

[0074] It should be understood that the various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps described in this invention can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution of this invention can be achieved, and this is not limited herein.

[0075] The specific embodiments described above do not constitute a limitation on the scope of protection of this invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this invention should be included within the scope of protection of this invention.

Claims

1. A method for detecting transaction behavior risks, characterized in that, The method includes: A transaction graph is constructed based on the real-time transaction data generated by the target financial product, and target transaction behaviors that occur in a concentrated manner within the target time and space are periodically identified from the transaction graph. The transaction graph is input into a graph neural network model, and the graph neural network model outputs the risk transmission weights corresponding to the connecting edges of each node in the transaction graph. Extract the target subgraph corresponding to the target transaction behavior from the transaction graph. Based on the attribute information of each node in the target subgraph and the risk transmission weights corresponding to the connecting edges of each node, determine the risk detection result corresponding to the target transaction behavior.

2. The method according to claim 1, characterized in that, A transaction graph is constructed based on real-time transaction data generated by the target financial product, including: Extract multiple transaction entities and the relationships between them from the real-time transaction data generated by the target financial product. Each transaction entity is treated as a node, and the relationships between the transaction entities are treated as edges connecting the nodes. A transaction graph is constructed based on each node and the edges connecting the nodes.

3. The method according to claim 1, characterized in that, Before inputting the transaction graph into the graph neural network model, the following steps are also included: Obtain a graph data training set; the graph data training set includes transaction graph data and risk transmission labels corresponding to the relationships between various transaction entities in the transaction graph data; The graph neural network model is iteratively trained using the graph data training set until the graph neural network model converges.

4. The method according to claim 1, characterized in that, Identifying target transaction behaviors that occur in a concentrated manner within a target time and space range from the transaction graph includes: Obtain the timestamp and location information corresponding to each transaction in the transaction graph; Based on the timestamp and location information corresponding to each transaction, a preset spatial neighborhood threshold, a temporal neighborhood threshold, and a transaction quantity threshold, multiple transaction behaviors in the transaction graph are clustered. Based on the clustering results, target transaction behaviors that occur in a concentrated manner within the target time and space range are identified.

5. The method according to claim 1, characterized in that, The graph neural network model includes an embedding layer, a graph pooling layer, and a graph attention layer; The graph neural network model outputs the risk transmission weights corresponding to the connecting edges of each node in the transaction graph, including: The embedding layer converts the attribute information of each node in the transaction graph into a feature vector, and then inputs the feature vector into the graph pooling layer. The feature vectors are aggregated by the graph pooling layer, and the aggregation result is input into the graph attention layer. The graph attention layer calculates the risk propagation weights corresponding to the connecting edges of each node based on the aggregation result.

6. The method according to claim 5, characterized in that, Based on the attribute information of each node in the target subgraph and the risk transmission weights corresponding to the connecting edges of each node, the risk detection result corresponding to the target transaction behavior is determined, including: In the output of the embedding layer, the feature vector corresponding to the target subgraph is obtained, and the feature vector corresponding to the target subgraph is input into the graph pooling layer; The graph pooling layer aggregates the feature vector corresponding to the target subgraph and the risk propagation weights corresponding to the connecting edges of each node in the target subgraph to obtain the embedding vector corresponding to the target subgraph. The embedding vector corresponding to the target subgraph is input into a pre-trained classifier, and the classifier outputs the risk probability corresponding to the target subgraph.

7. The method according to claim 3, characterized in that, The method further includes: After detecting newly added transaction graph data in the graph data training set, obtain the historical transaction graph data associated with the newly added transaction graph data; An incremental training set is established based on the newly added transaction chart data, historical transaction chart data, and the risk transmission labels corresponding to the newly added transaction chart data and historical transaction chart data, respectively. The graph neural network model is incrementally trained using the incremental training set.

8. An electronic device, characterized in that, The electronic device includes: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that can be executed by the at least one processor, the computer program being executed by the at least one processor to enable the at least one processor to perform the transaction risk detection method according to any one of claims 1-7.

9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions that, when executed by a processor, implement the transaction risk detection method according to any one of claims 1-7.

10. A computer program product, characterized in that, The computer program product includes a computer program that, when executed by a processor, implements the transaction risk detection method according to any one of claims 1-7.