A credit risk management method and device, computer equipment and storage medium
Patent Information
- Application Number
- CN202610795088.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-06-03
- Publication Date
- 2026-08-28
AI Technical Summary
随着金融业务场景多元化与信贷服务普及化,新型欺诈手段不断涌现,团伙欺诈、身份伪造等风险频发,客户信用风险迁徙速度显著加快,传统风控模型已难以适配当前复杂的风险防控需求
[0009] In the above-mentioned credit risk management method, device, computer equipment, and storage medium, the following solutions can be implemented: multi-source behavioral data related to the target customer can be obtained through the client; a cross-domain behavioral graph can be constructed based on the multi-source behavioral data; a dynamic social risk score can be calculated based on the cross-domain behavioral graph using a graph neural network algorithm; the dynamic social risk score can be compared with a preset risk threshold; when the dynamic social risk score exceeds the preset risk threshold, a risk intervention strategy is triggered, and credit risk management is carried out through the risk intervention strategy, and the results are returned to the client. In this embodiment of the invention, by integrating the scattered data from multiple business lines within a financial institution, data barriers between different business scenarios are broken down, avoiding the data blind spots in traditional risk control. Simultaneously, by constructing a cross-domain behavioral graph, the risk transmission effect between related nodes can be captured using graph neural networks. This not only captures behavioral mutation signals of target customers themselves but also identifies potential fraud risks from related groups, solving the shortcomings of traditional risk control that only assesses independent individuals and cannot identify group risks or neighborly transmission risks. Furthermore, through a dynamically updated graph structure and real-time calculated social risk scores, signals of credit risk deterioration can be captured earlier, significantly shortening risk identification latency and allowing for more timely risk control intervention. This effectively improves the accuracy and timeliness of credit risk management, better protecting the security of financial credit assets.
Smart Images

Figure CN122656747A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of artificial intelligence technology, and in particular to a credit risk management method, apparatus, computer equipment, and storage medium. Background Technology
[0002] In the financial lending sector, credit risk management is a core element in ensuring the safety of financial assets and maintaining the sound operation of the business. With the diversification of financial business scenarios and the popularization of credit services, new types of fraud methods are constantly emerging, and risks such as gang fraud and identity forgery occur frequently. The migration speed of customer credit risk has accelerated significantly, and traditional risk control models are no longer suitable for the current complex risk prevention and control needs.
[0003] Current mainstream risk control models in the financial industry suffer from several technical deficiencies: First, traditional credit scoring systems rely heavily on lagging data such as historical repayment records and credit liabilities, failing to capture recent behavioral changes and early signs of credit risk deterioration in real time, resulting in significant time delays in risk identification. Second, data from multiple business segments within financial institutions is isolated, and behavioral data generated by customers in non-credit financial transactions is not integrated into the credit risk control system, creating data silos and risk blind spots, and a large amount of key information reflecting customer financial stability cannot be effectively utilized. Third, existing risk control models mostly use independent individuals as assessment units, lacking penetrating analysis of "neighbor risk" in social and behavioral networks, making it difficult to identify risk transmission effects and systemic risks formed by group fraud, resulting in loopholes in fraud risk prevention and control, and failing to provide comprehensive, timely, and accurate risk protection for financial lending businesses. Summary of the Invention
[0004] This invention provides a credit risk management method, apparatus, computer equipment, and medium, aiming to enhance the effectiveness of credit risk management and improve the risk protection capabilities of credit business.
[0005] In a first aspect, embodiments of the present invention provide a credit risk management method, comprising: Acquire multi-source behavioral data related to target customers; Construct a cross-domain behavior graph based on the multi-source behavior data; Based on the cross-domain behavior graph, a dynamic social risk score is calculated using a graph neural network algorithm. The dynamic social risk score is compared with a preset risk threshold; When the dynamic social risk score exceeds the preset risk threshold, a risk intervention strategy is triggered, and credit risk is managed through the risk intervention strategy.
[0006] Secondly, embodiments of the present invention provide a credit risk management device, comprising: The data acquisition unit is used to acquire multi-source behavioral data related to the target customer. The graph construction unit is used to construct a cross-domain behavior graph based on the multi-source behavior data; The scoring calculation unit is used to calculate a dynamic social risk score based on the cross-domain behavior graph using a graph neural network algorithm. The scoring comparison unit is used to compare the dynamic social risk score with a preset risk threshold. The intervention and control unit is used to trigger a risk intervention strategy when the dynamic social risk score exceeds a preset risk threshold, and to manage credit risk through the risk intervention strategy.
[0007] Thirdly, embodiments of the present invention provide a computer device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the steps of the credit risk management method described above.
[0008] Fourthly, embodiments of the present invention provide a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the steps of the credit risk management method described above.
[0009] In the above-mentioned credit risk management method, device, computer equipment, and storage medium, the following solutions can be implemented: multi-source behavioral data related to the target customer can be obtained through the client; a cross-domain behavioral graph can be constructed based on the multi-source behavioral data; a dynamic social risk score can be calculated based on the cross-domain behavioral graph using a graph neural network algorithm; the dynamic social risk score can be compared with a preset risk threshold; when the dynamic social risk score exceeds the preset risk threshold, a risk intervention strategy is triggered, and credit risk management is carried out through the risk intervention strategy, and the results are returned to the client. In this embodiment of the invention, by integrating the scattered data from multiple business lines within a financial institution, data barriers between different business scenarios are broken down, avoiding the data blind spots in traditional risk control. Simultaneously, by constructing a cross-domain behavioral graph, the risk transmission effect between related nodes can be captured using graph neural networks. This not only captures behavioral mutation signals of target customers themselves but also identifies potential fraud risks from related groups, solving the shortcomings of traditional risk control that only assesses independent individuals and cannot identify group risks or neighborly transmission risks. Furthermore, through a dynamically updated graph structure and real-time calculated social risk scores, signals of credit risk deterioration can be captured earlier, significantly shortening risk identification latency and allowing for more timely risk control intervention. This effectively improves the accuracy and timeliness of credit risk management, better protecting the security of financial credit assets. Attached Figure Description
[0010] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings used in the description of the embodiments of the present invention will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0011] Figure 1 This is a schematic diagram of an application environment for a credit risk management method according to an embodiment of the present invention; Figure 2 This is a flowchart illustrating a credit risk management method according to an embodiment of the present invention; Figure 3 This is a schematic diagram of the principle architecture of a credit risk management method in one embodiment of the present invention; Figure 4 This is a schematic diagram of a sub-process of the credit risk management method in one embodiment of the present invention; Figure 5 This is a schematic diagram of a credit risk management device according to an embodiment of the present invention; Figure 6 This is a schematic diagram of a substructure of the credit risk management device in one embodiment of the present invention; Figure 7 This is a schematic diagram of the structure of a computer device according to an embodiment of the present invention; Figure 8 This is another structural schematic diagram of a computer device according to one embodiment of the present invention. Detailed Implementation
[0012] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0013] The credit risk management method provided in this invention can be applied to, for example... Figure 1In this application environment, the client communicates with the server via a network. The server can obtain multi-source behavioral data related to the target customer through the client; construct a cross-domain behavioral graph based on the multi-source behavioral data; calculate a dynamic social risk score based on the cross-domain behavioral graph using a graph neural network algorithm; compare the dynamic social risk score with a preset risk threshold; when the dynamic social risk score exceeds the preset risk threshold, trigger a risk intervention strategy, and manage credit risk through the risk intervention strategy, feeding back to the client. The client can be, but is not limited to, various personal computers, laptops, smartphones, tablets, and portable wearable devices. The server can be implemented using a standalone server or a server cluster consisting of multiple servers. The invention will be described in detail below through specific embodiments.
[0014] Please see Figure 2 As shown, Figure 2 A flowchart of a credit risk management method provided in an embodiment of the present invention includes steps S101 to S105.
[0015] S101: Obtain multi-source behavioral data related to the target customer; S102: Construct a cross-domain behavior graph based on the multi-source behavior data; S103: Based on the cross-domain behavior graph, calculate the dynamic social risk score using a graph neural network algorithm; S104: Compare the dynamic social risk score with a preset risk threshold; S105: When the dynamic social risk score exceeds the preset risk threshold, a risk intervention strategy is triggered, and credit risk is managed through the risk intervention strategy.
[0016] In this embodiment, firstly, multi-source behavioral data related to the target customer is acquired; then, a cross-domain behavioral graph is constructed based on this data; then, a dynamic social risk score is calculated based on this graph using a graph neural network algorithm; finally, the score is compared with a preset risk threshold, and when the score exceeds the threshold, a risk intervention strategy is triggered to implement credit risk management.
[0017] Combination Figure 3This embodiment integrates scattered data from multiple business lines within a financial institution, breaking down data barriers between different business scenarios and avoiding data blind spots in traditional risk control. Simultaneously, by constructing a cross-domain behavioral graph, it leverages graph neural networks to capture the risk transmission effects between related nodes. This allows it to capture both sudden behavioral changes in target customers and potential fraud risks from related groups, addressing the shortcomings of traditional risk control that only assesses individual risks and cannot identify group risks or risks transmitted from neighbors. Furthermore, through a dynamically updated graph structure and real-time calculated social risk scores, it can capture credit risk deterioration signals earlier, significantly shortening risk identification latency and enabling more timely risk control intervention. This effectively improves the accuracy and timeliness of credit risk management, better protecting the security of financial credit assets.
[0018] This embodiment, based on the aforementioned credit risk management method, can upgrade the credit risk management model of financial institutions from reactive, post-event accountability to proactive, pre-event perception and intervention. Specifically: First, it effectively reduces fraud losses and safeguards financial assets. Through dynamic social risk scoring and graph neural network algorithms, risks can be identified in advance before fraud gangs carry out large-scale fake transactions and cash-outs, enabling precise interception and proactive prevention of new risks such as gang fraud and identity forgery.
[0019] Secondly, it significantly enhances the ability to identify credit risks in their early stages. Cross-domain behavioral mapping breaks down data barriers between multiple business segments within an institution, fully leveraging the forward-looking early warning value of non-financial behavioral data. It can capture risk deterioration trends that are difficult for traditional models to detect in advance, enabling early risk discovery and early warning.
[0020] Finally, optimize the synergistic efficiency of integrated financial services. By leveraging differentiated risk intervention strategies, risk management can be combined with integrated financial services to provide tailored protection and asset preservation services for clients with different risk profiles. This achieves a synergistic transformation between risk control and customer service, enhancing the long-term service value for clients.
[0021] In one embodiment, step S101 includes: The multi-source behavioral data is obtained through cross-business line data interfaces and preprocessed; wherein, the multi-source behavioral data includes business behavioral data and risk behavioral data; the preprocessing includes data cleaning, normalization and correlation alignment preprocessing.
[0022] In this embodiment, when acquiring multi-source behavioral data, data from various aspects such as credit business, payment business, wealth management business, and credit card business can be integrated through cross-business line data interfaces to obtain the aforementioned business behavior data (such as customer basic information, transaction records, product holding information, repayment behavior data, etc.) and risk behavior data (such as historical application records, overdue default records, associated risk markers, etc.). This can break down data barriers between different business segments, solve the problem of data silos, and unify and collect behavioral data that were originally scattered across various business lines and could reflect the customer's risk status.
[0023] After acquiring multi-source behavioral data, it undergoes appropriate preprocessing. For example, data cleaning removes missing values, outliers, and duplicate data; normalization scales feature data of different dimensions to a uniform range, eliminating the impact of dimension differences on subsequent model calculations; and association and alignment processes match and integrate data from different business sources of the same customer according to the customer's unique identifier, ensuring data consistency and relevance, and providing a high-quality data foundation for the subsequent construction of cross-domain behavioral maps.
[0024] In one embodiment, step S102 includes: Graph nodes are set based on the multi-source behavioral data; wherein, the graph nodes include customer ID, device ID, geographical location, contact person, insurance contract, and bank account; The cross-domain behavior graph is constructed by using the relationships and interactions between the graph nodes as graph edges. Acquire real-time behavioral data of target customers, and dynamically update the connection weights and node attributes of the cross-domain behavioral graph based on the real-time behavioral data.
[0025] In constructing the cross-domain behavior graph, this embodiment first abstracts various entities into corresponding graph nodes based on different types of information in multi-source behavior data. These nodes include customer IDs, device IDs, geographical locations, contacts, insurance contracts, and bank accounts. Furthermore, it can supplement these with entity nodes representing different dimensions, such as partner institutions and trading counterparties, based on business scenarios, covering all entity information related to customer behavior across all scenarios. Then, graph edges are determined based on the actual interactive relationships between nodes. For example, calls and transfers between a customer and their contacts correspond to social relationship edges, customer login operations using a device correspond to device relationship edges, and customer-initiated transactions at a specific geographical location correspond to location relationship edges. The interaction frequency, interaction amount, and interaction time interval between different nodes can be used to determine the initial weights of the graph edges. This allows the initial cross-domain behavior graph to be constructed.
[0026] After the initial cross-domain behavior graph is constructed, a dynamic update approach is used. When new real-time behavior data from the target customer is acquired, the attribute parameters of the relevant nodes are adjusted accordingly, and the connection weights of the corresponding graph edges are updated based on the newly generated interaction behavior. For example, when a new associated entity is generated, a corresponding node and edge are added, while if the existing association has not interacted for a long time, the weight of the corresponding edge is reduced. This ensures that the cross-domain behavior graph can reflect the target customer's current actual association relationships and behavioral status in real time, providing an accurate structural foundation for subsequent dynamic calculation of risk scores.
[0027] In one embodiment, such as Figure 4 As shown, step S103 includes steps S201 to S205.
[0028] S201: Obtain the customer nodes, associated nodes, and connecting edges between nodes in the cross-domain behavior graph, and use them as input to the graph neural network to assign a corresponding initial risk feature vector to each node; S202: Based on the initial risk feature vector, the convolutional layer of the graph neural network is used to aggregate neighborhood information of the customer node and its corresponding first-order and second-order associated nodes, and the risk features, connection weights and interaction frequencies of the associated nodes are weighted and fused to obtain the aggregated risk features of the customer node. S203: Calculate the risk transmission coefficient based on the interaction strength and correlation of the associated edges, and based on the risk transmission coefficient, integrate the credit score changes, default status and fraud labels of the associated parties into the aggregated risk features, and then transmit them to the current customer node; S204: The updated aggregated risk features are nonlinearly transformed through the fully connected layer of the graph neural network, and the basic social risk value of the target customer is output. S205: Based on the preset characteristics of fraud gangs, the cross-domain behavior map is clustered and identified, and gang risk weighting is applied to customer nodes in high-density connected clusters with highly similar behavior patterns according to the clustering and identification results, so as to obtain the final dynamic social risk score.
[0029] In this embodiment, when calculating the dynamic social risk score using a graph neural network algorithm, the first step is to input all associated entity nodes and connections in the cross-domain behavior graph into the graph neural network. An initial risk feature vector for each node is initialized according to its corresponding dimension, distinguishing the basic feature types of customer nodes and non-customer nodes. Subsequently, neighborhood information aggregation is performed through graph convolutional layers. For the target customer node, the risk features of associated nodes within the first and second-order neighborhoods are aggregated layer by layer. Weighted weights are calculated based on the connection weights of different edges and the frequency of interactions, fusing the features of the neighborhood nodes into the features of the target customer node to obtain the initial aggregated risk features of the target customer node. Based on this, the corresponding risk transmission coefficient is calculated according to the interaction strength and duration of the associated edges between nodes. Existing credit anomalies, default markers, and fraud labels of associated nodes are weighted according to the transmission coefficient and integrated into the current aggregated risk features of the target customer, achieving effective transmission of risk-related information. Finally, the updated aggregated risk features are input into a fully connected layer for nonlinear transformation, outputting the basic social risk value of the target customer. Finally, based on the preset fraud gang characteristic rules, community clustering analysis is performed on the entire cross-domain behavior graph to identify suspicious gang clusters with high connection density and highly similar node behavior patterns. Additional gang risk weighting adjustments are applied to target customer nodes within these clusters, ultimately resulting in a dynamic social risk score that accurately reflects the overall risk level of the target customer.
[0030] This embodiment, through the above-described method of calculating dynamic social risk scores, can more accurately capture the transmission impact of associated risks, avoid the bias of relying solely on individual data assessments, and at the same time make the potential fraud risks of group gatherings explicit, so that the risk scores are more in line with the actual risk level and provide a more reliable basis for subsequent risk judgments.
[0031] In one embodiment, step S105 includes: When the dynamic social risk score exceeds a preset risk threshold, a credit limit adjustment intervention and a cross-verification intervention are performed on the target customer; wherein, the credit limit adjustment intervention includes reducing the credit card limit or available loan limit in real time; the cross-verification intervention includes cross-verifying the customer's identity, workplace, and contact information.
[0032] In this embodiment, when managing credit risk through risk intervention strategies, for customers with credit limits, the first step is to adjust the credit limit, reducing their credit card limit or available loan amount in real time to prevent further risk escalation and reduce potential bad debt losses. Simultaneously, cross-verification intervention is initiated, such as cross-checking the target customer's declared identity information, workplace, and contact information through multiple channels to investigate the possibility of identity forgery or false information, further confirming the actual risk situation. Based on the results of the cross-verification, subsequent control strategies are adjusted to effectively safeguard the financial institution's assets.
[0033] Furthermore, in another embodiment, step S105 further includes: Determine whether the target factor causing the dynamic social risk score to exceed a preset risk threshold is a fraud cause; When the target factor that causes the dynamic social risk score to exceed the preset risk threshold is determined to be non-fraudulent, a product referral intervention operation is performed; wherein, the product referral intervention operation includes recommending insurance protection or asset protection services to the target customer.
[0034] In addition to the aforementioned limit adjustment intervention and cross-validation intervention, this embodiment also adopts differentiated intervention strategies based on different reasons that cause the score to exceed the threshold. If it is confirmed after investigation that the risk is not caused by fraud, but by short-term fluctuations in the target customer's own financial situation or by the impact of risk transmission from related parties, then instead of directly taking rigid limit reduction measures, product referral intervention is implemented to recommend suitable insurance protection products or asset protection services to the target customer. While helping customers cope with short-term financial pressure and mitigate credit risk, it also helps financial institutions expand service scenarios and increase intermediary business income, thus achieving an organic unity of risk management and customer service.
[0035] In one embodiment, the credit risk management method further includes: Historical cross-cycle risk events containing dynamic social risk score samples are obtained, and feature extraction and labeling are performed on the cross-cycle risk events to construct a labeled dataset; wherein, the labeled dataset contains default samples, fraud samples and early risk deterioration samples; Based on the labeled dataset, the distribution of the dynamic social risk score samples is fitted using the kernel density estimation algorithm, and the quantiles and confidence intervals corresponding to different risk levels are calculated. Based on preset constraints, a combination of logistic regression and extreme value theory is used to solve for the quantiles and confidence intervals to obtain the risk critical score; wherein, the constraints include business risk control tolerance, expected asset loss and regulatory indicator requirements; The risk threshold score is corrected by using a time decay factor and a business scenario weighting coefficient to adaptively generate the risk threshold.
[0036] In this embodiment, the risk threshold can be obtained by fitting historical risk data. By collecting historical cross-cycle risk events containing dynamic social risk score samples, different types of risk events are labeled to distinguish different samples such as default, fraud, and early risk deterioration. Then, the score distribution of different samples is fitted by the kernel density estimation algorithm. Combined with preset constraints such as business risk control tolerance, expected asset loss, and regulatory indicator requirements, the initial risk critical score is calculated by combining logistic regression and extreme value theory. Finally, the sample weights of different periods are adjusted by the time decay factor, giving higher weight to recent risk data. At the same time, the final risk threshold is obtained by combining the weighting coefficient of the current business scenario. This achieves adaptive dynamic adjustment of the risk threshold, making the risk threshold setting more in line with the actual risk characteristics of the current business and avoiding the defect of fixed thresholds being unable to adapt to risk evolution.
[0037] Figure 5 This is a schematic block diagram of a credit risk management device 500 provided in an embodiment of the present invention. The credit risk management device 500 includes: Data acquisition unit 501 is used to acquire multi-source behavioral data related to target customers; The graph construction unit 502 is used to construct a cross-domain behavior graph based on the multi-source behavior data; The scoring calculation unit 503 is used to calculate a dynamic social risk score based on the cross-domain behavior graph using a graph neural network algorithm. The scoring comparison unit 504 is used to compare the dynamic social risk score with a preset risk threshold. The intervention and control unit 505 is used to trigger a risk intervention strategy when the dynamic social risk score exceeds a preset risk threshold, and to manage credit risk through the risk intervention strategy.
[0038] In this embodiment, firstly, multi-source behavioral data such as business behavior data and risk behavior data of target customers are acquired; then, a cross-domain behavioral graph is constructed based on this data; then, a graph neural network algorithm is used to calculate a dynamic social risk score based on this graph; then, the score is compared with a preset risk threshold, and when the score exceeds the threshold, a risk intervention strategy is triggered to implement credit risk management.
[0039] Combination Figure 3This embodiment integrates scattered data from multiple business lines within a financial institution, breaking down data barriers between different business scenarios and avoiding data blind spots in traditional risk control. Simultaneously, by constructing a cross-domain behavioral graph, it leverages graph neural networks to capture the risk transmission effects between related nodes. This allows it to capture both sudden behavioral changes in target customers and potential fraud risks from related groups, addressing the shortcomings of traditional risk control that only assesses individual risks and cannot identify group risks or risks transmitted from neighbors. Furthermore, through a dynamically updated graph structure and real-time calculated social risk scores, it can capture credit risk deterioration signals earlier, significantly shortening risk identification latency and enabling more timely risk control intervention. This effectively improves the accuracy and timeliness of credit risk management, better protecting the security of financial credit assets.
[0040] This embodiment, based on the aforementioned credit risk management device, can upgrade the credit risk management model of financial institutions from reactive, post-event accountability to proactive, pre-event perception and intervention. Specifically: First, it effectively reduces fraud losses and safeguards financial assets. Through dynamic social risk scoring and graph neural network algorithms, risks can be identified in advance before fraud gangs carry out large-scale fake transactions and cash-outs, enabling precise interception and proactive prevention of new risks such as gang fraud and identity forgery.
[0041] Secondly, it significantly enhances the ability to identify credit risks in their early stages. Cross-domain behavioral mapping breaks down data barriers between multiple business segments within an institution, fully leveraging the forward-looking early warning value of non-financial behavioral data. It can capture risk deterioration trends that are difficult for traditional models to detect in advance, enabling early risk discovery and early warning.
[0042] Finally, optimize the synergistic efficiency of integrated financial services. By leveraging differentiated risk intervention strategies, risk management can be combined with integrated financial services to provide tailored protection and asset preservation services for clients with different risk profiles. This achieves a synergistic transformation between risk control and customer service, enhancing the long-term service value for clients.
[0043] In one embodiment, the data acquisition unit 501 includes: The data preprocessing unit is used to acquire the multi-source behavioral data through cross-business line data interfaces and preprocess the multi-source behavioral data; wherein the multi-source behavioral data includes business behavioral data and risk behavioral data; the preprocessing includes data cleaning, normalization and correlation alignment preprocessing.
[0044] In this embodiment, when acquiring multi-source behavioral data, data from various aspects such as credit business, payment business, wealth management business, and credit card business can be integrated through cross-business line data interfaces to obtain the aforementioned business behavior data (such as customer basic information, transaction records, product holding information, repayment behavior data, etc.) and risk behavior data (such as historical application records, overdue default records, associated risk markers, etc.). This can break down data barriers between different business segments, solve the problem of data silos, and unify and collect behavioral data that were originally scattered across various business lines and could reflect the customer's risk status.
[0045] After acquiring multi-source behavioral data, it undergoes appropriate preprocessing. For example, data cleaning removes missing values, outliers, and duplicate data; normalization scales feature data of different dimensions to a uniform range, eliminating the impact of dimension differences on subsequent model calculations; and association and alignment processes match and integrate data from different business sources of the same customer according to the customer's unique identifier, ensuring data consistency and relevance, and providing a high-quality data foundation for the subsequent construction of cross-domain behavioral maps.
[0046] In one embodiment, the map construction unit 502 includes: A node setting unit is used to set graph nodes based on the multi-source behavioral data; wherein, the graph nodes include customer ID, device ID, geographical location, contact person, insurance contract, and bank account; An edge setting unit is used to construct the cross-domain behavior graph by using the relationships and interactions between the graph nodes as graph edges. The dynamic update unit is used to acquire real-time behavioral data of the target customer and dynamically update the connection weights and node attributes of the cross-domain behavioral graph based on the real-time behavioral data.
[0047] In constructing the cross-domain behavior graph, this embodiment first abstracts various entities into corresponding graph nodes based on different types of information in multi-source behavior data. These nodes include customer IDs, device IDs, geographical locations, contacts, insurance contracts, and bank accounts. Furthermore, it can supplement these with entity nodes representing different dimensions, such as partner institutions and trading counterparties, based on business scenarios, covering all entity information related to customer behavior across all scenarios. Then, graph edges are determined based on the actual interactive relationships between nodes. For example, calls and transfers between a customer and their contacts correspond to social relationship edges, customer login operations using a device correspond to device relationship edges, and customer-initiated transactions at a specific geographical location correspond to location relationship edges. The interaction frequency, interaction amount, and interaction time interval between different nodes can be used to determine the initial weights of the graph edges. This allows the initial cross-domain behavior graph to be constructed.
[0048] After the initial cross-domain behavior graph is constructed, a dynamic update approach is used. When new real-time behavior data from the target customer is acquired, the attribute parameters of the relevant nodes are adjusted accordingly, and the connection weights of the corresponding graph edges are updated based on the newly generated interaction behavior. For example, when a new associated entity is generated, a corresponding node and edge are added, while if the existing association has not interacted for a long time, the weight of the corresponding edge is reduced. This ensures that the cross-domain behavior graph can reflect the target customer's current actual association relationships and behavioral status in real time, providing an accurate structural foundation for subsequent dynamic calculation of risk scores.
[0049] In one embodiment, such as Figure 6 As shown, the scoring calculation unit 503 includes: The network input unit 601 is used to obtain the customer nodes, associated nodes and connecting edges between nodes in the cross-domain behavior graph, and use them as input to the graph neural network to assign a corresponding initial risk feature vector to each node. The node aggregation unit 602 is used to aggregate neighborhood information of the customer node and its corresponding first-order and second-order associated nodes through the convolutional layer of the graph neural network based on the initial risk feature vector, and to weight and fuse the risk features, connection weights and interaction frequencies corresponding to the associated nodes to obtain the aggregated risk features of the customer node. Risk transmission unit 603 is used to calculate risk transmission coefficient based on the interaction strength and correlation of the associated edge, and based on the risk transmission coefficient, integrate the credit score changes, default status and fraud label of the associated party into the aggregated risk feature, and then transmit it to the current customer node; The basic output unit 604 is used to perform a nonlinear transformation on the updated aggregated risk features through the fully connected layer of the graph neural network and output the basic social risk value of the target customer. The risk weighting unit 605 is used to cluster and identify the cross-domain behavior map based on the preset fraud gang characteristics, and apply gang risk weighting to customer nodes in high-density connected clusters and with highly similar behavior patterns according to the clustering and identification results, so as to obtain the final dynamic social risk score.
[0050] In this embodiment, when calculating the dynamic social risk score using a graph neural network algorithm, the first step is to input all associated entity nodes and connections in the cross-domain behavior graph into the graph neural network. An initial risk feature vector for each node is initialized according to its corresponding dimension, distinguishing the basic feature types of customer nodes and non-customer nodes. Subsequently, neighborhood information aggregation is performed through graph convolutional layers. For the target customer node, the risk features of associated nodes within the first and second-order neighborhoods are aggregated layer by layer. Weighted weights are calculated based on the connection weights of different edges and the frequency of interactions, fusing the features of the neighborhood nodes into the features of the target customer node to obtain the initial aggregated risk features of the target customer node. Based on this, the corresponding risk transmission coefficient is calculated according to the interaction strength and duration of the associated edges between nodes. Existing credit anomalies, default markers, and fraud labels of associated nodes are weighted according to the transmission coefficient and integrated into the current aggregated risk features of the target customer, achieving effective transmission of risk-related information. Finally, the updated aggregated risk features are input into a fully connected layer for nonlinear transformation, outputting the basic social risk value of the target customer. Finally, based on the preset fraud gang characteristic rules, community clustering analysis is performed on the entire cross-domain behavior graph to identify suspicious gang clusters with high connection density and highly similar node behavior patterns. Additional gang risk weighting adjustments are applied to target customer nodes within these clusters, ultimately resulting in a dynamic social risk score that accurately reflects the overall risk level of the target customer.
[0051] This embodiment, through the above-described method of calculating dynamic social risk scores, can more accurately capture the transmission impact of associated risks, avoid the bias of relying solely on individual data assessments, and at the same time make the potential fraud risks of group gatherings explicit, so that the risk scores are more in line with the actual risk level and provide a more reliable basis for subsequent risk judgments.
[0052] In one embodiment, the intervention control unit 505 includes: The first execution unit is used to perform credit limit adjustment intervention and cross-verification intervention on the target customer when the dynamic social risk score exceeds a preset risk threshold; wherein, the credit limit adjustment intervention includes reducing the credit card limit or available loan limit in real time; the cross-verification intervention includes cross-verifying the customer's identity, workplace, and contact information.
[0053] In this embodiment, when managing credit risk through risk intervention strategies, for customers with credit limits, the first step is to adjust the credit limit, reducing their credit card limit or available loan amount in real time to prevent further risk escalation and reduce potential bad debt losses. Simultaneously, cross-verification intervention is initiated, such as cross-checking the target customer's declared identity information, workplace, and contact information through multiple channels to investigate the possibility of identity forgery or false information, further confirming the actual risk situation. Based on the results of the cross-verification, subsequent control strategies are adjusted to effectively safeguard the financial institution's assets.
[0054] In one embodiment, the intervention control unit 505 further includes: The factor judgment unit is used to determine whether the target factor that causes the dynamic social risk score to exceed a preset risk threshold is a reason for fraud. The second execution unit is used to perform product referral intervention when it is determined that the target factor causing the dynamic social risk score to exceed the preset risk threshold is a non-fraudulent cause; wherein, the product referral intervention includes recommending insurance protection or asset protection services to the target customer.
[0055] In addition to the aforementioned limit adjustment intervention and cross-validation intervention, this embodiment also adopts differentiated intervention strategies based on different reasons that cause the score to exceed the threshold. If it is confirmed after investigation that the risk is not caused by fraud, but by short-term fluctuations in the target customer's own financial situation or by the impact of risk transmission from related parties, then instead of directly taking rigid limit reduction measures, product referral intervention is implemented to recommend suitable insurance protection products or asset protection services to the target customer. While helping customers cope with short-term financial pressure and mitigate credit risk, it also helps financial institutions expand service scenarios and increase intermediary business income, thus achieving an organic unity of risk management and customer service.
[0056] In one embodiment, the credit risk management device 500 further includes: The dataset construction unit is used to acquire historical cross-cycle risk events containing dynamic social risk score samples, and to perform feature extraction and labeling processing on the cross-cycle risk events to construct a labeled dataset; wherein, the labeled dataset includes default samples, fraud samples and early risk deterioration samples; The sample fitting unit is used to fit the distribution of the dynamic social risk score samples based on the labeled dataset using a kernel density estimation algorithm, and to calculate the quantiles and confidence intervals corresponding to different risk levels. The scoring unit is used to solve the quantiles and confidence intervals based on preset constraints, using a combination of logistic regression and extreme value theory to obtain the risk critical score; wherein, the constraints include business risk control tolerance, expected asset loss and regulatory indicator requirements; The threshold generation unit is used to modify the risk threshold score by using a time decay factor and a business scenario weighting coefficient, and adaptively generate the risk threshold.
[0057] In this embodiment, the risk threshold can be obtained by fitting historical risk data. By collecting historical cross-cycle risk events containing dynamic social risk score samples, different types of risk events are labeled to distinguish different samples such as default, fraud, and early risk deterioration. Then, the score distribution of different samples is fitted by the kernel density estimation algorithm. Combined with preset constraints such as business risk control tolerance, expected asset loss, and regulatory indicator requirements, the initial risk critical score is calculated by combining logistic regression and extreme value theory. Finally, the sample weights of different periods are adjusted by the time decay factor, giving higher weight to recent risk data. At the same time, the final risk threshold is obtained by combining the weighting coefficient of the current business scenario. This achieves adaptive dynamic adjustment of the risk threshold, making the risk threshold setting more in line with the actual risk characteristics of the current business and avoiding the defect of fixed thresholds being unable to adapt to risk evolution.
[0058] Specific limitations regarding credit risk management devices can be found in the limitations of credit risk management methods described above, and will not be repeated here. Each module in the aforementioned credit risk management device can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in or independent of the processor in a computer device, or stored in the memory of a computer device as software, so that the processor can call and execute the corresponding operations of each module.
[0059] In one embodiment, a computer device is provided, which may be a server, and its internal structure diagram may be as follows: Figure 7 As shown, the computer device includes a processor, memory, network interface, and database connected via a system bus. The processor provides computing and control capabilities. The memory includes non-volatile and / or volatile storage media and internal memory. The non-volatile storage media stores the operating system, computer programs, and database. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage media. The network interface is used to communicate with external clients via a network connection. When the computer program is executed by the processor, it implements the functions or steps of a credit risk management method on the server side.
[0060] In one embodiment, a computer device is provided, which may be a client, and its internal structure diagram may be as follows: Figure 8As shown, the computer device includes a processor, memory, network interface, display screen, and input devices connected via a system bus. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs stored in the non-volatile storage media. The network interface is used to communicate with an external server via a network connection. When the computer program is executed by the processor, it implements the functions or steps of a credit risk management method on the client side.
[0061] In one embodiment, a computer device is provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to perform the following steps: Acquire multi-source behavioral data related to target customers; Construct a cross-domain behavior graph based on the multi-source behavior data; Based on the cross-domain behavior graph, a dynamic social risk score is calculated using a graph neural network algorithm. The dynamic social risk score is compared with a preset risk threshold; When the dynamic social risk score exceeds the preset risk threshold, a risk intervention strategy is triggered, and credit risk is managed through the risk intervention strategy.
[0062] In one embodiment, a computer-readable storage medium is provided having a computer program stored thereon, the computer program performing the following steps when executed by a processor: Acquire multi-source behavioral data related to target customers; Construct a cross-domain behavior graph based on the multi-source behavior data; Based on the cross-domain behavior graph, a dynamic social risk score is calculated using a graph neural network algorithm. The dynamic social risk score is compared with a preset risk threshold; When the dynamic social risk score exceeds the preset risk threshold, a risk intervention strategy is triggered, and credit risk is managed through the risk intervention strategy.
[0063] It should be noted that the functions or steps that can be implemented by the computer-readable storage medium or computer device described above can be referred to the relevant descriptions on the server side and client side in the foregoing method embodiments. To avoid repetition, they will not be described one by one here.
[0064] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium. When executed, the computer program can include the processes of the embodiments of the above methods. Any references to memory, storage, databases, or other media used in the embodiments provided in this application can include non-volatile and / or volatile memory. Non-volatile memory may include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory may include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in a variety of forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), dual data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), RAMbus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM), etc.
[0065] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the above-described division of functional units and modules is used as an example. In practical applications, the above functions can be assigned to different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above.
[0066] It should be noted that any AI models, software tools, or components not belonging to this company appearing in the embodiments of this application are merely illustrative examples and do not represent actual use. All user personal information involved in the embodiments of this application has been authorized (with the knowledge and consent) by the relevant parties or has been fully authorized by all parties, and the executing entity may obtain it through various legal and compliant means. The collection, storage, use, processing, transmission, provision, and disclosure of the information, data, and signals involved all comply with relevant laws and regulations and do not violate public order and good morals.
[0067] The above-described embodiments are only used to illustrate the technical solutions of the present invention, and are not intended to limit it. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should all be included within the protection scope of the present invention.
Claims
1. A credit risk management method, characterized in that, include: Acquire multi-source behavioral data related to target customers; Construct a cross-domain behavior graph based on the multi-source behavior data; Based on the cross-domain behavior graph, a dynamic social risk score is calculated using a graph neural network algorithm. The dynamic social risk score is compared with a preset risk threshold; When the dynamic social risk score exceeds the preset risk threshold, a risk intervention strategy is triggered, and credit risk is managed through the risk intervention strategy.
2. The credit risk management method according to claim 1, characterized in that, The acquisition of multi-source behavioral data related to the target customer includes: The multi-source behavioral data is obtained through cross-business line data interfaces and preprocessed; wherein, the multi-source behavioral data includes business behavioral data and risk behavioral data, and the preprocessing includes data cleaning, normalization and correlation alignment preprocessing.
3. The credit risk management method according to claim 1, characterized in that, The step of constructing a cross-domain behavior graph based on the multi-source behavior data includes: Graph nodes are set based on the multi-source behavioral data; The cross-domain behavior graph is constructed by using the relationships and interactions between the graph nodes as graph edges. Acquire real-time behavioral data of target customers, and dynamically update the connection weights and node attributes of the cross-domain behavioral graph based on the real-time behavioral data.
4. The credit risk management method according to claim 1, characterized in that, The calculation of a dynamic social risk score based on the cross-domain behavior graph using a graph neural network algorithm includes: The customer nodes, associated nodes, and connecting edges between nodes in the cross-domain behavior graph are obtained and used as input to the graph neural network to assign a corresponding initial risk feature vector to each node. Based on the initial risk feature vector, the convolutional layer of the graph neural network is used to aggregate neighborhood information of the customer node and its corresponding first-order and second-order associated nodes, and the risk features, connection weights and interaction frequencies of the associated nodes are weighted and fused to obtain the aggregated risk features of the customer node. The risk transmission coefficient is calculated based on the interaction strength and the degree of association of the related edges. Based on the risk transmission coefficient, the credit score changes, default status and fraud labels of the related parties are incorporated into the aggregated risk features and then transmitted to the current customer node. The updated aggregated risk features are nonlinearly transformed using a fully connected layer of a graph neural network, and the basic social risk value of the target customer is output. Based on the preset characteristics of fraud gangs, the cross-domain behavior map is clustered and identified. Based on the clustering results, gang risk weighting is applied to customer nodes in high-density connected clusters with highly similar behavior patterns to obtain the final dynamic social risk score.
5. The credit risk management method according to claim 1, characterized in that, When the dynamic social risk score exceeds a preset risk threshold, a risk intervention strategy is triggered, and credit risk management is carried out through the risk intervention strategy, including: When the dynamic social risk score exceeds the preset risk threshold, the target customer will be subject to a credit limit adjustment intervention and a cross-validation intervention.
6. The credit risk management method according to claim 1, characterized in that, The step of triggering a risk intervention strategy when the dynamic social risk score exceeds a preset risk threshold, and using the risk intervention strategy to manage credit risk, further includes: Determine whether the target factor causing the dynamic social risk score to exceed a preset risk threshold is a fraud cause; When the target factor that causes the dynamic social risk score to exceed the preset risk threshold is determined to be a non-fraudulent cause, a product referral intervention operation is performed.
7. The credit risk management method according to claim 1, characterized in that, Also includes: A cross-cycle historical risk event containing dynamic social risk score samples is obtained, and the cross-cycle historical risk event is subjected to feature extraction and labeling to construct a labeled dataset; wherein, the labeled dataset contains default samples, fraud samples and early risk deterioration samples; The distribution of the dynamic social risk score samples was fitted using a kernel density estimation algorithm, and the quantiles and confidence intervals under different risk levels were calculated. Based on preset constraints, a combination of logistic regression and extreme value theory is used to calculate the critical risk score based on quantiles and confidence intervals; wherein the constraints include business risk control tolerance, expected asset loss, and regulatory indicator requirements. The risk threshold score is corrected by using a time decay factor and a business scenario weighting coefficient to adaptively generate the risk threshold.
8. A credit risk management device, characterized in that, include: The data acquisition unit is used to acquire multi-source behavioral data related to the target customer. The graph construction unit is used to construct a cross-domain behavior graph based on the multi-source behavior data; The scoring calculation unit is used to calculate a dynamic social risk score based on the cross-domain behavior graph using a graph neural network algorithm. The scoring comparison unit is used to compare the dynamic social risk score with a preset risk threshold. The intervention and control unit is used to trigger a risk intervention strategy when the dynamic social risk score exceeds a preset risk threshold, and to manage credit risk through the risk intervention strategy.
9. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the steps of the credit risk management method as described in any one of claims 1 to 7.
10. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the credit risk management method as described in any one of claims 1 to 7.