An account risk checking report generation method, device and equipment based on a relationship graph structure and multi-dimensional attribution, and a storage medium
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-06-30
- Publication Date
- 2026-08-11
AI Technical Summary
核查人员当前主要依赖人工逐笔翻查流水记录,效率低下,且难以在大量交易中快速定位关键证据
Smart Images

Figure CN122550178A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of financial risk control, and in particular to a method, apparatus, device, and storage medium for generating account risk verification reports based on a relational graph structure and multidimensional attribution. Background Technology
[0002] In the context of risk management for telecom fraud in inclusive finance, a typical business process is as follows: First, machine learning models (such as LightGBM and other gradient boosting tree models) issue risk warnings for accounts. For these warning accounts, manual investigators then analyze each point based on verification guidelines summarized by business experts (such as small test transactions, large transfers at night, and more than ten telecom fraud risk points like rapid inflows and outflows), ultimately forming a risk disposal decision. Currently, investigators mainly rely on manually reviewing transaction records one by one, which is inefficient and makes it difficult to quickly locate key evidence among a large number of transactions. Summary of the Invention
[0003] In view of this, the purpose of this invention is to provide a method, apparatus, device, and storage medium for generating account risk verification reports based on a relationship graph structure and multidimensional attribution, which can improve the efficiency of verification personnel in verifying risky accounts. The specific solution is as follows: Firstly, this application discloses a method for generating account risk verification reports based on relational graph structures and multidimensional attribution, including: The original transaction records of the target account are obtained, and the transaction flow sequence, real-time aggregation features and transaction relationship graph of the target account are determined based on each of the original transaction records. The transaction flow sequence is the natural language text representation of the original transaction record, the real-time aggregation features are the statistical feature vectors of the original transaction record in the target time window, and the transaction relationship graph is a graph structure data constructed with the transaction accounts of the original transaction records as nodes and the fund flow as directed edges. The first attribution method is used to determine the first dimension score of the original transaction record based on the transaction flow sequence; the second attribution method is used to determine the second dimension score of the original transaction record based on the real-time aggregation features; the third attribution method is used to determine the third dimension score of the original transaction record based on the transaction relationship graph; and the comprehensive risk score corresponding to the original transaction record is determined based on the first dimension score, the second dimension score, and the third dimension score. Based on the comprehensive risk score corresponding to each original transaction record of the target account, the first target key transaction corresponding to the target account is determined. The transaction flow sequence, real-time aggregation features and transaction relationship diagram of all the first target key transactions are spliced together to obtain the target context corresponding to the first target key transaction. Based on the target context and the target description corresponding to each target verification guide in the target verification guide library, the risk report segment corresponding to the target verification guide is determined. The fourth attribution method is used to determine the second target key transaction and target attribution score corresponding to each of the target verification guidelines, and the target attribution evidence corresponding to the risk report segment is determined based on the second target key transaction, the risk report segment, the target attribution score and the target attribution evidence, so as to generate a risk verification report corresponding to the target account.
[0004] Optionally, determining the first dimension score of the original transaction record based on the transaction flow sequence using the first attribution method includes: The transaction sequence is input into the first risk report generation model to obtain the original risk report corresponding to the target account, and the first risk report generation model is called to obtain the target risk report corresponding to each original transaction record based on the leave-one-out method; The target quantifier is used to obtain the first dimension score of the original transaction record corresponding to each target risk report based on the original risk report and the target risk report.
[0005] Optionally, determining the second dimension score of the original transaction record based on the real-time aggregated features using the second attribution method includes: The real-time aggregated features corresponding to all the original transaction records of the target account are input into the target risk scoring model to obtain the original risk score corresponding to the target account, and the target risk scoring model is called to obtain the target risk score corresponding to each original transaction record based on the leave-one-out method; The second dimension score of the original transaction record corresponding to each target risk score is determined based on the target difference between the original risk score and the target risk score.
[0006] Optionally, determining the third-dimensional score of the original transaction record based on the transaction relationship graph using a third attribution method includes: If the transaction relationship graph meets the preset unlabeled conditions, the target reconstruction error corresponding to the transaction relationship graph is obtained by using the target graph autoencoder, and the third dimension score of the original transaction record corresponding to the transaction relationship graph is determined based on the target reconstruction error. If the transaction relationship graph does not meet the preset unlabeled conditions, the target graph classification model is used to determine the target anomaly probability corresponding to each transaction account, and the third dimension score of the original transaction record corresponding to the transaction relationship graph is determined based on the target anomaly probability.
[0007] Optionally, determining the risk report segment corresponding to the target verification guide based on the target context and the target description corresponding to each target verification guide in the target verification guide library includes: Based on the target context and the target descriptions corresponding to each target verification guide in the target verification guide library, the second risk report generation model is invoked to generate risk report fragments corresponding to the target verification guides.
[0008] Optionally, determining the second target key transaction and target attribution score corresponding to each of the target verification guidelines using the fourth attribution method includes: The second risk report generation model is invoked, and the first target key transaction is processed based on the leave-one-out method to generate processed risk report fragments corresponding to each target verification guideline; Based on the risk report segment and the processed risk report segment corresponding to each of the target verification guidelines, the target explanatory contribution of each first target key transaction to the target verification guidelines is determined, and the second target key transaction and target attribution score corresponding to the target verification guidelines are determined based on the target explanatory contribution.
[0009] Optionally, determining the target attribution evidence corresponding to the risk report segment based on the second target key transaction includes: Using the leave-one-out method, based on the transaction flow sequence corresponding to the second target key transaction, phrase-level attribution is performed on the second target key transaction to determine the target text fragment corresponding to the target verification guide; The target feature indicators corresponding to the target verification guidelines are determined based on the real-time aggregated features corresponding to the second target key transaction using the target SHAP method. Based on the transaction relationship graph corresponding to the second target key transaction and the third dimension score, determine the target graph edge corresponding to the target verification guide; Based on the target text fragment, target feature indicators, and target graph edges corresponding to the target verification guidelines, the target attribution evidence corresponding to the risk report fragment is determined.
[0010] Secondly, this application discloses an account risk verification report generation device based on a relational graph structure and multidimensional attribution, comprising: The transaction record processing module is used to obtain the original transaction records of the target account, and determine the transaction flow sequence, real-time aggregation features and transaction relationship graph of the target account based on each of the original transaction records; the transaction flow sequence is the natural language text representation corresponding to the original transaction record, the real-time aggregation features are the statistical feature vectors of the original transaction record in the target time window, and the transaction relationship graph is a graph structure data constructed with the transaction accounts of the original transaction records as nodes and the fund flow as directed edges; The comprehensive score determination module is used to determine the first dimension score of the original transaction record based on the transaction flow sequence using a first attribution method, determine the second dimension score of the original transaction record based on the real-time aggregation features using a second attribution method, determine the third dimension score of the original transaction record based on the transaction relationship graph using a third attribution method, and determine the comprehensive risk score corresponding to the original transaction record based on the first dimension score, the second dimension score, and the third dimension score. The report fragment generation module is used to determine the first target key transaction corresponding to the target account based on the comprehensive risk score corresponding to each original transaction record of the target account, and to splice the transaction flow sequence, the real-time aggregation feature and the transaction relationship diagram of all the first target key transactions to obtain the target context corresponding to the first target key transaction. Based on the target context and the target description corresponding to each target verification guide in the target verification guide library, the module determines the risk report fragment corresponding to the target verification guide. The verification report generation module is used to determine the second target key transaction and target attribution score corresponding to each of the target verification guidelines using the fourth attribution method, and to determine the target attribution evidence corresponding to the risk report segment based on the second target key transaction, so as to generate a risk verification report corresponding to the target account based on the second target key transaction, the risk report segment, the target attribution score and the target attribution evidence.
[0011] Thirdly, this application discloses an electronic device, including: Memory, used to store computer programs; A processor is used to execute the computer program to implement the aforementioned method for generating account risk verification reports based on relational graph structures and multidimensional attribution.
[0012] Fourthly, this application discloses a computer-readable storage medium for storing a computer program, wherein the computer program, when executed by a processor, implements the aforementioned method for generating account risk verification reports based on relational graph structures and multidimensional attribution.
[0013] In this application, when generating a risk assessment report for a target account, the original transaction records of the target account are obtained, and the transaction flow sequence, real-time aggregation features, and transaction relationship graph of the target account are determined based on each of the original transaction records. The transaction flow sequence is the natural language text representation corresponding to the original transaction records, the real-time aggregation features are the statistical feature vectors of the original transaction records within a target time window, and the transaction relationship graph is a graph structure constructed with the transaction accounts of the original transaction records as nodes and fund flows as directed edges. A first attribution method is used to determine the first dimension score of the original transaction records based on the transaction flow sequence, a second attribution method is used to determine the second dimension score of the original transaction records based on the real-time aggregation features, and a third attribution method is used to determine the third dimension score of the original transaction records based on the transaction relationship graph. The results are then combined with the first dimension score, the second dimension score, and the third dimension score. The process involves: determining a comprehensive risk score corresponding to the original transaction records; determining a first target key transaction corresponding to the target account based on the comprehensive risk score of each original transaction record of the target account; concatenating the transaction flow sequence, real-time aggregation features, and transaction relationship diagram of all the first target key transactions to obtain the target context corresponding to the first target key transaction; determining a risk report segment corresponding to the target verification guide based on the target context and the target description corresponding to each target verification guide in the target verification guide library; determining a second target key transaction and target attribution score corresponding to each target verification guide using a fourth attribution method; determining target attribution evidence corresponding to the risk report segment based on the second target key transaction; and generating a risk verification report corresponding to the target account based on the second target key transaction, the risk report segment, the target attribution score, and the target attribution evidence. It is evident that the transaction flow sequence, real-time aggregation features, and transaction relationship diagram in this application... Figure 3 The unified input modeling across all dimensions is naturally aligned at the granularity of individual transactions. Dimensional scores for each transaction are independently determined across the three dimensions, thereby establishing a comprehensive risk score for the original transaction records. Based on this comprehensive risk score, the first key target transaction requiring attention is selected. Next, utilizing the target context corresponding to the first key target transaction and the target descriptions of various target verification guidelines in the target verification guide library, a risk report fragment corresponding to the target verification guide is obtained. From the first key target transaction, a second key target transaction is identified, along with its target attribution score and corresponding target attribution evidence. Finally, based on the second key target transaction, the risk report fragment, the target attribution score, and the target attribution evidence, a risk verification report for the target account is generated. This layered attribution refines the explanation to the granularity of individual transactions, helping auditors efficiently locate key evidence without manually reviewing transaction records, thus improving the efficiency and accuracy of auditors' risk account verification. Attached Figure Description
[0014] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on the provided drawings without creative effort.
[0015] Figure 1 This application discloses a flowchart of a method for generating account risk verification reports based on a relational graph structure and multidimensional attribution. Figure 2 This application discloses a specific system architecture diagram for generating account risk verification reports based on a relational graph structure and multidimensional attribution. Figure 3 This is a schematic diagram of a specific three-dimensional transaction attribution process disclosed in this application; Figure 4 This is a schematic diagram of a specific point-level risk report generation and hierarchical attribution process disclosed in this application; Figure 5 This is a schematic diagram of a specific visual output process disclosed in this application; Figure 6 This is a schematic diagram of the structure of an account risk verification report generation device based on a relational graph structure and multidimensional attribution disclosed in this application; Figure 7 This is a structural diagram of an electronic device disclosed in this application. Detailed Implementation
[0016] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0017] In the scenario of risk governance for telecom fraud in inclusive finance, a typical business process is as follows: First, machine learning models (such as gradient boosting tree models like LightGBM) issue risk warnings for accounts. For these warning accounts, manual investigators then analyze each point based on verification guidelines summarized by business experts (such as small test transactions, large transfers at night, and more than ten telecom fraud risk points like rapid inflows and outflows), ultimately forming a risk disposal decision. Currently, investigators mainly rely on manually reviewing transaction records one by one, which is inefficient and makes it difficult to quickly locate key evidence among a large number of transactions. To solve the above technical problems, this application discloses a method for generating account risk verification reports based on a relationship graph structure and multidimensional attribution, which can improve the efficiency of investigators in verifying risky accounts.
[0018] See Figure 1 As shown, this invention discloses a method for generating account risk verification reports based on relationship graph structure and multidimensional attribution, including: Step S11: Obtain the original transaction records of the target account, and determine the transaction flow sequence, real-time aggregation features, and transaction relationship graph of the target account based on each of the original transaction records; the transaction flow sequence is the natural language text representation corresponding to the original transaction record, the real-time aggregation features are the statistical feature vectors of the original transaction record in the target time window, and the transaction relationship graph is a graph structure data constructed with the transaction accounts of the original transaction records as nodes and the fund flow as directed edges.
[0019] In this embodiment, the target account is typically a high-risk account identified by a pre-emptive machine learning model, and the original transaction record is the transaction details of that account within a certain time range. The transaction flow sequence is the natural language text representation corresponding to the original transaction record, that is, the transaction of each account is serialized in chronological order into a natural language text that can be read by a large language model. Each transaction corresponds to a description in the text (e.g., including transaction time, amount, payment direction, counterparty name, etc.); the real-time aggregated features are the statistical feature vectors of the original transaction record on the target time window, that is, the statistical feature vectors calculated by the feature calculation engine with each transaction as the anchor point on multiple target time windows (e.g., the frequency of transfers in and out within 1 hour, 24 hours, and 7 days, the distribution of amounts, the number of counterparties for payment and receipt, etc.); the transaction relationship graph is a graph structure data constructed with the transaction accounts of the original transaction record as nodes and the flow of funds as directed edges, which serves as the input of the graph neural network. It should be noted that the above three dimensions are naturally aligned with a single transaction as the basic unit: each transaction of an account corresponds to a text description in the transaction flow sequence and a real-time aggregated feature vector, and is represented by an outgoing or incoming edge in the transaction relationship graph, thus laying the foundation for subsequent three-dimensional attribution and fusion at a unified granularity.
[0020] In this embodiment, as Figure 2 The diagram illustrates a specific system architecture for generating account risk verification reports based on a relational graph structure and multidimensional attribution. The overall processing can be divided into six layers. The first layer is the input layer, which includes the aforementioned transaction flow sequence, real-time aggregated features, and transaction relationships. Figure 3 The data sources are arranged in parallel and naturally aligned. The second layer is a single-dimensional attribution layer, which runs the corresponding attribution method on each data source to obtain the importance score of each transaction in that dimension. The third layer is a fusion layer, which merges the scores of the three dimensions into a comprehensive risk score and uses it to select the first target key transaction. The fourth layer is a key point reporting layer, which combines the three-dimensional data of the first target key transaction with the target verification guidance library, and uses a large language model to generate a unique risk report fragment for each target verification guidance. The fifth layer is a layer-by-layer attribution layer, which performs transaction-level and evidence-level layer-by-layer attribution on the risk report fragment of each target verification guidance. The sixth layer is an output layer, which presents the verification key points, key transaction highlights, and underlying evidence details in an interactive visual interface, forming a three-layer evidence chain.
[0021] Step S12: Determine the first dimension score of the original transaction record based on the transaction flow sequence using the first attribution method, determine the second dimension score of the original transaction record based on the real-time aggregation features using the second attribution method, determine the third dimension score of the original transaction record based on the transaction relationship graph using the third attribution method, and determine the comprehensive risk score corresponding to the original transaction record based on the first dimension score, the second dimension score, and the third dimension score.
[0022] In this embodiment, as Figure 3 As shown, attribution is performed on each of the three dimensions at the granularity of a single transaction. The specific process is as follows: For the first dimension (transaction flow text dimension), the first attribution method is used to determine the first dimension score of the original transaction records based on the transaction flow sequence. This includes: inputting the transaction flow sequence into the first risk report generation model to obtain the original risk report corresponding to the target account, and calling the first risk report generation model to obtain the target risk report corresponding to each original transaction record based on the leave-one-out method. That is, after deleting the t-th transaction from the transaction flow sequence each time, a new report is generated to obtain the target risk report corresponding to that transaction; the target quantifier is used to obtain the first dimension score of the original transaction record corresponding to each target risk report based on the original risk report and the target risk report. For example, the transaction flow of account T_1 to T_n is serialized into natural language text in chronological order, and the whole is input into the LLM (Large Language Model) to generate the original risk report y0. The Leave-One-Out (LOO) method (also known as the sequential deletion method) is used to delete the t-th transaction record sequentially. The LLM is then called to regenerate the report y(t) (i.e., the target risk report obtained after deleting the t-th transaction). The semantic deviation between y0 and y(t) is calculated using a Scalarizer (target quantizer, see next section). Specifically, Score_text(t) = 1 - Scalarizer(y0, y(t)). The greater the semantic difference between y(t) and y0 (the lower the Scalarizer value), the higher the Score_text(t), indicating that the t-th transaction has a more significant impact on the report content. This yields the text attribution score Score_text(t) for that transaction. This process requires n LLM calls, where n is the total number of transactions, linearly related to the number of transactions.
[0023] In one specific implementation, the target quantizer, or scalarizer, is a function that maps the LLM text output to real values. It is a key component for text attribution when logits are inaccessible. In one implementation, the metric function of the target quantizer can be expressed as Scalarizer(y, y0) = a × BERTScore(y, y0) + b × Sim_fin(y, y0), where BERTScore is the F1 similarity of the two reports calculated based on the DeBERTa model, Sim_fin is the cosine similarity of the embedding vectors of the two reports calculated based on a fine-tuned BGE-M3 model using financial corpora, which is more sensitive to semantic differences in financial terms such as "fraud," "abnormal transfers," and "high-risk accounts," and a and b are adjustable weighting coefficients, exemplarily a=b=0.5. Since the target quantizer only takes two text reports as input and does not rely on the model's internal logits, using only the text output, the first attribution method as a whole does not need to access the probability distribution within the large language model, thus adapting to privacy-preserving computation and API call scenarios.
[0024] For the second dimension (aggregated feature dimension), the second attribution method is used to determine the second dimension score of the original transaction records based on real-time aggregated features. This includes: inputting the real-time aggregated features corresponding to all original transaction records of the target account into the target risk scoring model to obtain the original risk score corresponding to the target account, and calling the target risk scoring model to obtain the target risk score corresponding to each original transaction record based on the leave-one-out method, that is, re-scoring after setting the feature vector corresponding to the t-th transaction to zero or masking it each time; and determining the second dimension score of the original transaction record corresponding to each target risk score based on the target difference between the original risk score and the target risk score. For example, the feature calculation engine generates an aggregated feature vector v_t for each transaction, which includes multi-time window statistical indicators (such as the frequency of transfers in and out within 1 hour / 24 hours / 7 days, amount distribution, number of payers and payees, etc.) anchored to the transaction. Using the same LOO method, the feature vector v_t corresponding to the t-th transaction is successively set to zero or masked, and input into a model that can output a numerical risk score (i.e., the target risk score model, including but not limited to gradient boosting tree model, neural network model or rule scoring engine). The change in risk score is observed. Specifically, Score_feat(t) = S0 - S(t), where S0 is the original risk score when using the full feature vector, and S(t) is the result of re-scoring after setting v_t to zero. The difference reflects the marginal contribution of the aggregated features of the t-th transaction to the overall risk score, and the attribution score Score_feat(t) under the feature dimension is obtained.
[0025] For the third dimension (transaction relationship graph dimension), the transaction relationship graph is constructed with accounts as nodes and fund flows as directed edges. The initial feature vectors of the nodes come from statistical information of the account dimension (including historical transaction amount, transaction frequency, number of counterparties, payment ratio, etc.), and the attributes of the edges include information such as single transaction amount, timestamp, and transaction type, thereby encoding the fund flow structure between accounts. The third attribution method is used to determine the third dimension score of the original transaction records based on the transaction relationship graph, including: if the transaction relationship graph meets the preset unlabeled conditions, the target graph autoencoder is used to obtain the target reconstruction error corresponding to the transaction relationship graph, and the third dimension score of the original transaction records corresponding to the transaction relationship graph is determined based on the target reconstruction error; if the transaction relationship graph does not meet the preset unlabeled conditions, the target graph classification model is used to determine the target anomaly probability corresponding to each transaction account, and the third dimension score of the original transaction records corresponding to the transaction relationship graph is determined based on the target anomaly probability.
[0026] In one specific implementation, depending on whether historical labeled data is available, GNN (Graph Neural Networks) is used to detect anomalies in the transaction graph in one of the following two ways: (a) Unlabeled scenario (i.e., the transaction graph meets the preset unlabeled conditions): A graph autoencoder is used, with GraphSAGE as the encoder, to compress each node and its neighborhood information into a low-dimensional embedding vector, and then the original node features are restored through a decoder. The training objective is to minimize the full graph reconstruction error. After training, the normalized reconstruction error of the node is used as its anomaly score—nodes with unusual behavior patterns and neighborhood structures have significantly higher reconstruction errors. (b) Labeled scenario (i.e., the transaction graph does not meet the preset unlabeled conditions): If there are historical fraudulent account labels, the anomaly detection is transformed into a node binary classification task. GraphSAGE directly outputs the anomaly probability of each node after aggregating neighborhood information, which is more accurate but depends on high-quality labeled data.
[0027] Specifically, since the GNN outputs anomaly scores / probabilities at the node (account) level, these need to be mapped to each specific transaction, i.e., mapping node scores to third-dimensional scores. In one specific implementation, for each original transaction record T_t of an account, starting from its direct counterparty account, the system expands outward along the edges of the graph, collecting anomaly scores of all associated accounts within one, two, and three hops. These scores are then multiplied by the corresponding distance decay coefficients (1.0 for one hop, 0.7 for two hops, and 0.4 for three hops to reflect the indirectness of the association). The maximum value among all weighted candidate scores is taken as the graph anomaly attribution score Score_graph(t) for that transaction. The maximum value is used instead of the mean because a warning should be triggered as long as there is a high-risk path in the risk transmission process; the mean would dilute local risks and mask the real threat. The business meaning of Score_graph(t) is: the maximum degree of anomaly risk that the account can be associated with on the graph structure through this transaction. Transactions with high Score_graph(t), even if the individual amount is small and the behavior pattern is normal, may be marked as requiring manual verification because there are high-risk nodes in the associated chain.
[0028] In one specific implementation, for each transaction T_t, a comprehensive risk score is calculated using a fusion function: F(t) = w1 × Score_text(t) + w2 × Score_feat(t) + w3 × Score_graph(t); Here, w1, w2, and w3 represent the weights for each dimension, satisfying w1 + w2 + w3 = 1. Initial values can be set based on business experience and can be adaptively adjusted through expert feedback. The comprehensive risk score takes into account three dimensions: semantic content, statistical behavior, and graph structure.
[0029] Step S13: Based on the comprehensive risk score corresponding to each original transaction record of the target account, determine the first target key transaction corresponding to the target account; stitch together the transaction flow sequence, the real-time aggregation feature and the transaction relationship diagram of all the first target key transactions to obtain the target context corresponding to the first target key transaction; and based on the target context and the target description corresponding to each target verification guide in the target verification guide library, determine the risk report segment corresponding to the target verification guide.
[0030] In this embodiment, as Figure 4As shown, based on the comprehensive risk score, all original transaction records of the target account are sorted in descending order by F(t). The top N records (N is a configurable parameter, typically 5 to 10) are taken as the TOP-N key transactions (i.e., the first target key transactions) and used as input for the generation of subsequent key-level reports (i.e., risk report fragments). The verification guidance library consists of several risk points (i.e., target verification guidelines) summarized by business experts for telecommunications fraud risks. Each target verification guide has a corresponding target description (such as small test transactions, large transfers at night, quick in and quick out, etc.). The system executes each verification guide in a loop: it concatenates the transaction history text, aggregated feature descriptions, and relationship diagram subgraph information of the TOP-N transactions into a structured context, and combines it with the description of the guide to generate a dedicated risk report fragment by LLM, so that the report content is accurately aligned with the business verification perspective.
[0031] In one specific implementation, based on the target context and the target descriptions corresponding to each target verification guide in the target verification guide library, the risk report fragment corresponding to the target verification guide is determined. This includes: based on the target context and the target descriptions corresponding to each target verification guide in the target verification guide library, calling the second risk report generation model to generate the risk report fragment corresponding to the target verification guide. Specifically, the three-dimensional data (i.e., transaction text fragments, aggregated feature descriptions, and relationship graph subgraph information) of N first target key transactions are concatenated into a structured target context. Combined with the target description of the kth target verification guide, this context is input into the second risk report generation model to generate a dedicated risk report fragment y_k0 for that guide. For example, for a small-amount test transaction guide, the second risk report generation model will focus on describing whether the account has any tentative transfers of extremely small amounts (such as 9.9 yuan or 0.1 yuan).
[0032] Step S14: Use the fourth attribution method to determine the second target key transaction and target attribution score corresponding to each target verification guideline, and determine the target attribution evidence corresponding to the risk report segment based on the second target key transaction, so as to generate a risk verification report corresponding to the target account based on the second target key transaction, the risk report segment, the target attribution score and the target attribution evidence.
[0033] In this embodiment, the fourth attribution method is used to determine the second target key transaction and target attribution score (i.e., the first-level transaction-level attribution) corresponding to each target verification guideline. This includes: calling the second risk report generation model, processing the first target key transactions based on the leave-one-out method to generate processed risk report fragments corresponding to each target verification guideline; determining the target explanatory contribution of each first target key transaction to the target verification guideline based on the risk report fragments and processed risk report fragments corresponding to each target verification guideline, and determining the second target key transaction and target attribution score corresponding to the target verification guideline based on the target explanatory contribution. In a specific implementation, LOO is performed on each of the TOP-N transactions: after deleting the t-th transaction, a new report y_k(t) is generated, and ξ_k(t) = 1 - Scalarizer(y_k(t), y_k0) is calculated. The larger ξ_k(t) is, the greater the explanatory contribution of the transaction to the k-th guideline. Sort by ξ_k(t) in descending order, and take the top M transactions (M < N, typically 3) as the most important key transactions for this guideline, that is, the second target key transactions. At the same time, take max(ξ_k(t)) as the key point attribution score (that is, the target attribution score) for this verification guideline, and use it to sort the importance of the key points and display the color intensity.
[0034] In this embodiment, determining the target attribution evidence (i.e., second-level evidence-level attribution) corresponding to the risk report fragment based on the second target key transaction includes: using the leave-one-out method to perform phrase-level attribution on the second target key transaction based on the transaction flow sequence corresponding to the second target key transaction, to determine the target text fragment corresponding to the target verification guide; using the target SHAP method to determine the target feature index corresponding to the target verification guide based on the real-time aggregated features corresponding to the second target key transaction; determining the target graph edge corresponding to the target verification guide based on the transaction relationship graph and the third-dimensional score corresponding to the second target key transaction; and determining the target attribution evidence corresponding to the risk report fragment based on the target text fragment, target feature index, and target graph edge corresponding to the target verification guide. In a specific implementation, phrase-level LOO attribution is performed on the transaction flow description text, phrases (such as time point, amount, counterparty account name, etc.) are deleted one by one, and the specific text fragment (i.e., target text fragment) that contributes the most to the verification guide is located; the SHAP method is used to perform local interpretation of the risk control scoring model, calculate the Shapley value of each feature, and quantify the marginal contribution of each feature index to the risk score of the transaction (while considering the interaction effect between features). The highest-scoring Shapley values are selected as target feature indicators, corresponding to "which statistical behavioral features in this transaction best explain its high-risk score." When refining the transaction relationship graph, the source node of the maximum value and its corresponding hop count are directly traced back to reconstruct the complete fund transfer path from the direct counterparty of T_t to the node (i.e., the specific edge sequence on the path), which serves as the counterparty path (i.e., the target graph edge) that contributes most to the anomaly judgment. The output includes: node anomaly score, corresponding hop count and decay coefficient, and the specific transaction record corresponding to each edge on the path. Finally, based on the target text fragment, the target feature indicators, and the target graph edges, the target attribution evidence corresponding to the risk report fragment is determined. After obtaining the above results, the second target key transaction, risk report fragment, target attribution score, and target attribution evidence are structurally summarized to generate the risk verification report corresponding to the target account. For example, for the k-th verification guideline, the output structured result is: {Guideline description, list of key transactions [T_i, ξ_k(T_i)], underlying evidence for each transaction [key text fragments / key feature indicators / key graph edges]}.
[0035] Furthermore, such as Figure 5As shown, this embodiment also provides a specific visualization method. The visualization interface involves two types of scores: the comprehensive risk score, which is the output of the three-dimensional fusion function F(t), reflects the comprehensive anomaly of the transaction in the global dimension, determining which transactions enter the TOP-N and their ranking order in the key transaction layer; and the target attribution score, which is the maximum value among the target explanation contributions ξ_k(t) of all first-target key transactions under the target verification guideline, reflecting the strongest evidence strength that the guideline can find, used for the color depth and sorting of the verification point layer. The higher the attribution score, the more obvious the triggering of the guideline by the current account, and the more priority the verifier should give it. The visualization interface can be presented in a three-layer evidence chain: the first layer is the verification point, sorted by the target attribution score, with the color depth reflecting the triggering strength; the second layer is the key transaction highlighted, with the comprehensive risk score and target attribution score attached; and the third layer is the bottom-level evidence details, displaying key fragments of the transaction text, key feature indicators, and key graph paths in three columns. After the inspector clicks on a target inspection guide, the key transaction layer is reordered and displayed according to the target interpretation contribution ξ_k(t) of each transaction under that guide, and the underlying evidence layer displays the three-dimensional detailed attribution results of each transaction in conjunction, so that it is not necessary to manually check the entire transaction record one by one.
[0036] It should be noted that several steps in the above implementation methods have alternative implementation methods. In one specific implementation method, regarding the fusion function, the above three-dimensional linear weighted fusion can be replaced by: firstly, learning-based fusion, that is, using the key transaction annotations of historical cases as supervision signals, and learning weights w1, w2, and w3 through supervised training; secondly, parameter-free fusion based on ranking aggregation, using the Reciprocal Rank Fusion (RRF) method to fuse the ranking results generated by the three dimensions respectively, calculate the comprehensive score based on the ranking position of each transaction in different dimensions, and generate the final ranking accordingly.
[0037] In one specific implementation, regarding the attribution methods for the first and second dimensions, the leave-one-out method described above can be replaced with other local attribution methods. For example, LIME (Local Interpretable Model-agnostic Explanations) or its variants can be used to replace the leave-one-out method in the first attribution method, or Local Shapley Explanation (L-SHAP) can be used to replace the difference calculation in the second attribution method, as long as it does not depend on the vocabulary-level probability distribution within the large language model. Regarding the mapping from node scores to transaction scores in the third dimension, the method of taking the maximum value after each hop decay can be replaced by a weighted summation of the scores after each hop decay, which is suitable for scenarios where risk nodes are relatively dispersed; or only the score of a single-hop associated node can be taken, abandoning multi-hop expansion to reduce computational complexity. Regarding graph anomaly detection models, GraphSAGE can be replaced with other graph neural networks such as Graph Attention Network (GAT). For example, GAT can adaptively assign different weights to different neighboring nodes through an attention mechanism, making it suitable for scenarios with significant differences in neighborhood structure. Alternatively, it can be replaced as needed with rule-based graph features based on relational database queries (such as the proportion of high-risk accounts within two hops). The features of nodes and edges can also be replaced with rule-based graph features.
[0038] In one specific implementation, regarding the target quantifier, the weighted combination of BERTS score and financial semantic similarity can be replaced by using only BERTS score to handle general scenarios, or by using only BGE-M3 cosine similarity fine-tuned based on financial corpus to handle lightweight scenarios. Regarding the target verification guidance library, the fixed target verification guidance library can be replaced by a dynamic guidance library, supporting business experts to add and delete guidance in real time, and the system automatically initiates an attribution process for newly added guidance.
[0039] It is understood that this embodiment is mainly applicable to account-level risk verification in telecommunications fraud prevention scenarios. After system deployment, investigators log in to the verification workbench, select the alerted account, and the system automatically presents a three-tiered evidence chain organized according to the verification guidelines. Investigators only need to confirm or conduct supplementary investigations on the highlighted key transactions, significantly reducing the verification time for a single case. Since the core attribution process relies entirely on text output and an independent Scalarizer model, it can work normally in cross-institutional privacy computing environments (federated learning / secure multi-party computation) and commercial API call scenarios, demonstrating broad engineering adaptability.
[0040] As can be seen, the transaction flow sequence, real-time aggregation features, and transaction relationships in this application... Figure 3The unified input modeling across all dimensions is naturally aligned at the granularity of individual transactions. Dimensional scores for each transaction are independently determined across the three dimensions, thereby establishing a comprehensive risk score for the original transaction records. Based on this comprehensive risk score, the first key target transaction requiring attention is selected. Next, utilizing the target context corresponding to the first key target transaction and the target descriptions of various target verification guidelines in the target verification guide library, a risk report fragment corresponding to the target verification guide is obtained. From the first key target transaction, a second key target transaction is identified, along with its target attribution score and corresponding target attribution evidence. Finally, based on the second key target transaction, the risk report fragment, the target attribution score, and the target attribution evidence, a risk verification report for the target account is generated. This layered attribution refines the explanation to the granularity of individual transactions, helping auditors efficiently locate key evidence without manually reviewing transaction records, thus improving the efficiency and accuracy of auditors' risk account verification.
[0041] See Figure 6 As shown, this application discloses an account risk verification report generation device based on a relationship graph structure and multidimensional attribution, comprising: The transaction record processing module 11 is used to obtain the original transaction records of the target account, and determine the transaction flow sequence, real-time aggregation features and transaction relationship graph of the target account based on each of the original transaction records; the transaction flow sequence is the natural language text representation corresponding to the original transaction record, the real-time aggregation features are the statistical feature vectors of the original transaction record in the target time window, and the transaction relationship graph is a graph structure data constructed with the transaction accounts of the original transaction records as nodes and the fund flow as directed edges; The comprehensive score determination module 12 is used to determine the first dimension score of the original transaction record based on the transaction flow sequence using a first attribution method, determine the second dimension score of the original transaction record based on the real-time aggregation feature using a second attribution method, determine the third dimension score of the original transaction record based on the transaction relationship graph using a third attribution method, and determine the comprehensive risk score corresponding to the original transaction record based on the first dimension score, the second dimension score and the third dimension score. The report fragment generation module 13 is used to determine the first target key transaction corresponding to the target account based on the comprehensive risk score corresponding to each original transaction record of the target account, splice the transaction flow sequence, the real-time aggregation feature and the transaction relationship diagram of all the first target key transactions to obtain the target context corresponding to the first target key transaction, and determine the risk report fragment corresponding to the target verification guide based on the target context and the target description corresponding to each target verification guide in the target verification guide library; The verification report generation module 14 is used to determine the second target key transaction and target attribution score corresponding to each of the target verification guidelines using the fourth attribution method, and to determine the target attribution evidence corresponding to the risk report segment based on the second target key transaction, so as to generate a risk verification report corresponding to the target account based on the second target key transaction, the risk report segment, the target attribution score and the target attribution evidence.
[0042] As can be seen, the transaction flow sequence, real-time aggregation features, and transaction relationships in this application... Figure 3 The unified input modeling across all dimensions is naturally aligned at the granularity of individual transactions. Dimensional scores for each transaction are independently determined across the three dimensions, thereby establishing a comprehensive risk score for the original transaction records. Based on this comprehensive risk score, the first key target transaction requiring attention is selected. Next, utilizing the target context corresponding to the first key target transaction and the target descriptions of various target verification guidelines in the target verification guide library, a risk report fragment corresponding to the target verification guide is obtained. From the first key target transaction, a second key target transaction is identified, along with its target attribution score and corresponding target attribution evidence. Finally, based on the second key target transaction, the risk report fragment, the target attribution score, and the target attribution evidence, a risk verification report for the target account is generated. This layered attribution refines the explanation to the granularity of individual transactions, helping auditors efficiently locate key evidence without manually reviewing transaction records, thus improving the efficiency and accuracy of auditors' risk account verification.
[0043] In one specific implementation, the comprehensive score determination module 12 may include: The risk report generation unit is used to input the transaction flow sequence into the first risk report generation model to obtain the original risk report corresponding to the target account, and to call the first risk report generation model to obtain the target risk report corresponding to each original transaction record based on the leave-one-out method; The first dimension score generation unit is used to obtain the first dimension score of the original transaction record corresponding to each target risk report based on the original risk report and the target risk report using the target quantifier.
[0044] In one specific implementation, the comprehensive score determination module 12 may include: The risk score generation unit is used to input the real-time aggregated features corresponding to all the original transaction records of the target account into the target risk score model to obtain the original risk score corresponding to the target account, and call the target risk score model to obtain the target risk score corresponding to each original transaction record based on the leave-one-out method; The second-dimensional score generation unit is used to determine the second-dimensional score of the original transaction record corresponding to each target risk score based on the target difference between the original risk score and the target risk score.
[0045] In one specific implementation, the comprehensive score determination module 12 may include: The third-dimensional score generation unit is used to obtain the target reconstruction error corresponding to the transaction relationship graph by using a target graph autoencoder if the transaction relationship graph meets the preset unlabeled conditions, and to determine the third-dimensional score of the original transaction record corresponding to the transaction relationship graph based on the target reconstruction error. The fourth dimension score generation unit is used to determine the target anomaly probability corresponding to each transaction account by using a target graph classification model if the transaction relationship graph does not meet the preset unlabeled conditions, so as to determine the third dimension score of the original transaction record corresponding to the transaction relationship graph based on the target anomaly probability.
[0046] In one specific implementation, the report fragment generation module 13 may include: The first report fragment generation unit is used to generate risk report fragments corresponding to the target verification guidelines by calling the second risk report generation big model based on the target context and the target descriptions corresponding to each target verification guide in the target verification guide library.
[0047] In one specific implementation, the verification report generation module 14 may include: The second report fragment generation unit is used to call the second risk report generation big model and process the first target key transaction based on the leave-one-out method to generate the processed risk report fragments corresponding to each of the target verification guidelines. The attribution score determination unit is used to determine the target explanatory contribution of each first target key transaction to the target verification guideline based on the risk report segment and the processed risk report segment corresponding to each target verification guideline, and to determine the second target key transaction and target attribution score corresponding to the target verification guideline based on the target explanatory contribution.
[0048] In one specific implementation, the verification report generation module 14 may include: The text fragment determination unit is used to perform phrase-level attribution on the second target key transaction based on the transaction flow sequence corresponding to the second target key transaction using the leave-one-out method, so as to determine the target text fragment corresponding to the target verification guide. The feature indicator determination unit is used to determine the target feature indicator corresponding to the target verification guide based on the real-time aggregated feature corresponding to the second target key transaction using the target SHAP method. The graph edge positioning unit is used to determine the target graph edge corresponding to the target verification guide based on the transaction relationship graph corresponding to the second target key transaction and the third dimension score. The attribution evidence determination unit is used to determine the target attribution evidence corresponding to the risk report segment based on the target text segment, the target feature index, and the target graph edge corresponding to the target verification guide.
[0049] Furthermore, embodiments of this application also disclose an electronic device, Figure 7 This is a structural diagram of an electronic device 20 according to an exemplary embodiment. The content of the diagram should not be construed as limiting the scope of this application.
[0050] Figure 7 This is a schematic diagram of the structure of an electronic device 20 provided in an embodiment of this application. Specifically, the electronic device 20 may include: at least one processor 21, at least one memory 22, a power supply 23, a communication interface 24, an input / output interface 25, and a communication bus 26. The memory 22 stores a computer program, which is loaded and executed by the processor 21 to implement the relevant steps in the account risk verification report generation method based on relational graph structure and multidimensional attribution disclosed in any of the foregoing embodiments. Alternatively, the electronic device 20 in this embodiment may specifically be a computer.
[0051] In this embodiment, the power supply 23 is used to provide operating voltage for each hardware device on the electronic device 20; the communication interface 24 can create a data transmission channel between the electronic device 20 and external devices, and the communication protocol it follows can be any communication protocol applicable to the technical solution of this application, and is not specifically limited here; the input / output interface 25 is used to acquire external input data or output data to the outside world, and its specific interface type can be selected according to specific application needs, and is not specifically limited here.
[0052] In addition, the memory 22, as a carrier for resource storage, can be a read-only memory, random access memory, disk, or optical disk, etc. The resources stored thereon can include an operating system 221, computer programs 222, etc., and the storage method can be temporary storage or permanent storage.
[0053] The operating system 221 is used to manage and control the various hardware devices on the electronic device 20 and the computer program 222, which may be Windows Server, Netware, Unix, Linux, etc. In addition to including a computer program capable of performing the account risk verification report generation method based on relational graph structure and multidimensional attribution disclosed in any of the foregoing embodiments, the computer program 222 may further include computer programs capable of performing other specific tasks.
[0054] Furthermore, this application also discloses a computer-readable storage medium for storing a computer program; wherein, when the computer program is executed by a processor, it implements the aforementioned disclosed method for generating account risk verification reports based on relational graph structures and multidimensional attribution. Specific steps of this method can be found in the corresponding content disclosed in the foregoing embodiments, and will not be repeated here.
[0055] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on its differences from other embodiments. Similar or identical parts between embodiments can be referred to interchangeably. For the apparatus disclosed in the embodiments, since it corresponds to the method disclosed in the embodiments, the description is relatively simple; relevant parts can be referred to in the method section.
[0056] Those skilled in the art will further recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components and steps of the various examples have been generally described in terms of functionality in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0057] The steps of the methods or algorithms described in conjunction with the embodiments disclosed herein can be implemented directly by hardware, a software module executed by a processor, or a combination of both. The software module can be located in random access memory (RAM), main memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disk, removable disk, CD-ROM, or any other form of storage medium known in the art.
[0058] Finally, it should be noted that in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.
[0059] The technical solutions provided in this application have been described in detail above. Specific examples have been used to illustrate the principles and implementation methods of this application. The descriptions of the above embodiments are only for the purpose of helping to understand the methods and core ideas of this application. At the same time, for those skilled in the art, there will be changes in the specific implementation methods and application scope based on the ideas of this application. Therefore, the content of this specification should not be construed as a limitation of this application.
Claims
1. An account risk check report generation method based on a relationship graph structure and multi-dimensional attribution, characterized in that, include: The original transaction records of the target account are obtained, and the transaction flow sequence, real-time aggregation features and transaction relationship graph of the target account are determined based on each of the original transaction records. The transaction flow sequence is the natural language text representation of the original transaction record, the real-time aggregation features are the statistical feature vectors of the original transaction record in the target time window, and the transaction relationship graph is a graph structure data constructed with the transaction accounts of the original transaction records as nodes and the fund flow as directed edges. The first attribution method is used to determine the first dimension score of the original transaction record based on the transaction flow sequence; the second attribution method is used to determine the second dimension score of the original transaction record based on the real-time aggregation features; the third attribution method is used to determine the third dimension score of the original transaction record based on the transaction relationship graph; and the comprehensive risk score corresponding to the original transaction record is determined based on the first dimension score, the second dimension score, and the third dimension score. Based on the comprehensive risk score corresponding to each original transaction record of the target account, the first target key transaction corresponding to the target account is determined. The transaction flow sequence, real-time aggregation features and transaction relationship diagram of all the first target key transactions are spliced together to obtain the target context corresponding to the first target key transaction. Based on the target context and the target description corresponding to each target verification guide in the target verification guide library, the risk report segment corresponding to the target verification guide is determined. The fourth attribution method is used to determine the second target key transaction and target attribution score corresponding to each of the target verification guidelines, and the target attribution evidence corresponding to the risk report segment is determined based on the second target key transaction, the risk report segment, the target attribution score and the target attribution evidence, so as to generate a risk verification report corresponding to the target account. 2.The account risk check report generation method based on a relationship graph structure and multi-dimensional attribution according to claim 1, characterized in that, The step of determining the first dimension score of the original transaction record based on the transaction flow sequence using the first attribution method includes: The transaction sequence is input into the first risk report generation model to obtain the original risk report corresponding to the target account, and the first risk report generation model is called to obtain the target risk report corresponding to each original transaction record based on the leave-one-out method; The target quantifier is used to obtain the first dimension score of the original transaction record corresponding to each target risk report based on the original risk report and the target risk report. 3.The account risk check report generation method based on a relationship graph structure and multi-dimensional attribution according to claim 1, characterized in that, The step of determining the second dimension score of the original transaction record based on the real-time aggregated features using the second attribution method includes: The real-time aggregated features corresponding to all the original transaction records of the target account are input into the target risk scoring model to obtain the original risk score corresponding to the target account, and the target risk scoring model is called to obtain the target risk score corresponding to each original transaction record based on the leave-one-out method; The second dimension score of the original transaction record corresponding to each target risk score is determined based on the target difference between the original risk score and the target risk score.
4. The method of claim 1, wherein, The step of determining the third-dimensional score of the original transaction record based on the transaction relationship graph using a third attribution method includes: If the transaction relationship graph meets the preset unlabeled conditions, the target reconstruction error corresponding to the transaction relationship graph is obtained by using the target graph autoencoder, and the third dimension score of the original transaction record corresponding to the transaction relationship graph is determined based on the target reconstruction error. If the transaction relationship graph does not meet the preset unlabeled conditions, the target graph classification model is used to determine the target anomaly probability corresponding to each transaction account, and the third dimension score of the original transaction record corresponding to the transaction relationship graph is determined based on the target anomaly probability.
5. The method of claim 1, wherein, The step of determining the risk report segment corresponding to the target verification guide based on the target context and the target description corresponding to each target verification guide in the target verification guide library includes: Based on the target context and the target descriptions corresponding to each target verification guide in the target verification guide library, the second risk report generation model is invoked to generate risk report fragments corresponding to the target verification guides.
6. The method of claim 5, wherein, The determination of the second target key transaction and target attribution score corresponding to each of the target verification guidelines using the fourth attribution method includes: The second risk report generation model is invoked, and the first target key transaction is processed based on the leave-one-out method to generate processed risk report fragments corresponding to each target verification guideline; Based on the risk report segment and the processed risk report segment corresponding to each of the target verification guidelines, the target explanatory contribution of each first target key transaction to the target verification guidelines is determined, and the second target key transaction and target attribution score corresponding to the target verification guidelines are determined based on the target explanatory contribution.
7. The method of claim 1 to 6, wherein, The determination of the target attribution evidence corresponding to the risk report segment based on the second target key transaction includes: Using the leave-one-out method, based on the transaction flow sequence corresponding to the second target key transaction, phrase-level attribution is performed on the second target key transaction to determine the target text fragment corresponding to the target verification guide; The target feature indicators corresponding to the target verification guidelines are determined based on the real-time aggregated features corresponding to the second target key transaction using the target SHAP method. Based on the transaction relationship graph corresponding to the second target key transaction and the third dimension score, determine the target graph edge corresponding to the target verification guide; Based on the target text fragment, target feature indicators, and target graph edges corresponding to the target verification guidelines, the target attribution evidence corresponding to the risk report fragment is determined.
8. An account risk check report generating apparatus based on a relationship graph structure and multi-dimensional attribution, characterized by, include: The transaction record processing module is used to obtain the original transaction records of the target account, and determine the transaction flow sequence, real-time aggregation features and transaction relationship graph of the target account based on each of the original transaction records; the transaction flow sequence is the natural language text representation corresponding to the original transaction record, the real-time aggregation features are the statistical feature vectors of the original transaction record in the target time window, and the transaction relationship graph is a graph structure data constructed with the transaction accounts of the original transaction records as nodes and the fund flow as directed edges; The comprehensive score determination module is used to determine the first dimension score of the original transaction record based on the transaction flow sequence using a first attribution method, determine the second dimension score of the original transaction record based on the real-time aggregation features using a second attribution method, determine the third dimension score of the original transaction record based on the transaction relationship graph using a third attribution method, and determine the comprehensive risk score corresponding to the original transaction record based on the first dimension score, the second dimension score, and the third dimension score. The report fragment generation module is used to determine the first target key transaction corresponding to the target account based on the comprehensive risk score corresponding to each original transaction record of the target account, and to splice the transaction flow sequence, the real-time aggregation feature and the transaction relationship diagram of all the first target key transactions to obtain the target context corresponding to the first target key transaction. Based on the target context and the target description corresponding to each target verification guide in the target verification guide library, the module determines the risk report fragment corresponding to the target verification guide. The verification report generation module is used to determine the second target key transaction and target attribution score corresponding to each of the target verification guidelines using the fourth attribution method, and to determine the target attribution evidence corresponding to the risk report segment based on the second target key transaction, so as to generate a risk verification report corresponding to the target account based on the second target key transaction, the risk report segment, the target attribution score and the target attribution evidence.
9. An electronic device, comprising: include: Memory, used to store computer programs; A processor is configured to execute the computer program to implement the account risk verification report generation method based on relational graph structure and multidimensional attribution as described in any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that, Used to store a computer program, wherein the computer program, when executed by a processor, implements the account risk verification report generation method based on a relational graph structure and multidimensional attribution as described in any one of claims 1 to 7.