An abnormal transaction detection method
Patent Information
- Application Number
- CN202611095126.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-07-22
- Publication Date
- 2026-09-11
AI Technical Summary
[0005]然而,现有的金融交易团伙欺诈检测方法主要存在以下技术问题:超图模板依赖人工预定义,无法根据演化的欺诈模式自适应更新
[0041]本申请的这些实现方式或其他实现方式在以下实施例的描述中会更加简明易懂。
Smart Images

Figure CN122736760A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of information security, and in particular to a method for detecting abnormal transactions. Background Technology
[0002] With the rapid development of electronic payment services such as credit cards, third-party payments, and mobile wallets, financial transaction fraud cases are showing a clear trend towards organized crime, cross-regional operations, and sophisticated disguises. Organized fraudsters typically evade traditional detection methods based on individual transaction characteristics by sharing devices, using the same merchants, and coordinating small, dispersed transactions.
[0003] Existing methods for detecting fraud in financial transactions mainly fall into the following categories: rule-based and statistical methods, which rely on manually designed risk control rules and statistical features, such as daily transaction thresholds and device-bound card thresholds; comparing each new transaction to see if it triggers predefined hard rules. Methods based on ordinary graph neural networks (GNNs) construct users and transactions as an ordinary graph G=(V,E), aggregating neighbor information through a message passing mechanism for fraud detection; each edge e∈E connects only two nodes, and can only model binary relationships between pairs of nodes. Methods based on hypergraph neural networks use hyperedges h... V connects multiple nodes (|h|≥2), explicitly modeling higher-order relationships.
[0004] There are also graph fraud detection methods that incorporate Large Language Models (LLMs). Recent research has introduced LLMs into graph fraud detection tasks to mine semantic information from transaction data. Existing approaches mainly include using LLMs as node text feature encoders, as aligners for graph structure and text alignment, as predictors that directly output classification results, or as guides for hard negative sample similarity in contrastive learning.
[0005] However, existing methods for detecting fraud in financial transaction groups suffer from the following technical problems: Hypergraph templates rely on manual pre-definition and cannot adaptively update based on evolving fraud patterns. For example, when new fraud patterns emerge (such as "remotely assisted bulk cash-out"), the manually pre-defined fixed templates cannot cover the new patterns, leading to a sharp increase in the model's false negative rate. In existing hypergraph fraud detection methods, the generation mechanism of hyperedges relies entirely on human experience. The formulation of hyperedge templates depends on manual analysis of cases, pattern summarization, and rule writing, which is time-consuming (usually measured in weeks or months). The existing hypergraph template generation mechanism is essentially a manually driven static mapping, rather than a data-driven adaptive generation, resulting in a lack of self-evolution capabilities. Furthermore, the lack of an efficient dynamic hypergraph incremental construction and update mechanism in streaming trading scenarios fails to meet real-time requirements.
[0006] Therefore, improving the efficiency and accuracy of detecting abnormal transactions is a pressing technical problem that needs to be solved. Summary of the Invention
[0007] This application provides an abnormal transaction detection method to improve the efficiency and accuracy of detecting abnormal transactions.
[0008] Firstly, this application provides a method for detecting abnormal transactions, the method comprising: For each incoming transaction, determine whether to update the dynamic hypergraph. Any hyperedge in the dynamic hypergraph is generated based on multiple transaction information that conform to any hyperedge template. Each hyperedge template corresponds to a hyperedge type that represents a type of gang fraud. For any hyperedge in the dynamic hypergraph, perform hyperedge attention calculation on each node contained within the hyperedge to obtain the intermediate hyperedge information of the hyperedge; the intermediate hyperedge information represents the influence of each node on the hyperedge; For each node in the dynamic hypergraph, attention between hyperedges and nodes is calculated based on the intermediate hyperedge information of the different hyperedges to which the node belongs, and intermediate node information of the node is obtained based on the different hyperedges to which the node belongs; any intermediate node information represents the influence of different hyperedges on the node under its own hyperedge. Based on the intermediate node information of each node and the hyperedge type to which the node belongs, the type node information of the node under each hyperedge type is obtained; based on the type node information of the node under different hyperedge types, fusion attention calculation is performed to obtain the final information of the node; Based on the final information of each node of the hyperedge, determine the final information of the hyperedge; For each superedge, the final information identifies abnormal superedges where group fraud exists.
[0009] This application proposes a dynamic heterogeneous hypergraph construction mechanism based on hyperedge template constraints for streaming financial transactions. This mechanism uses multi-source entities such as users, merchants, devices, and IPs as heterogeneous nodes. Based on the relationship patterns and time constraints specified by the hyperedge templates, it performs local retrieval, candidate aggregation, and incremental edge construction on real-time transactions to form and update the dynamic hypergraph. Compared with static graph modeling based on binary relations, this method can explicitly represent high-order collaborative behaviors involving multiple entities and adapt to the dynamic process of group relationships continuously emerging, expanding, and fading with the transaction flow. It performs closed-loop encoding on the dynamic hypergraph, including node-to-hyperedge, hyperedge-to-node, same-type merging, cross-type fusion, and node-to-final-hyperedge. Specifically, the first layer determines which nodes and their temporal behaviors are more important within a single hyperedge; the second layer determines which relationships among all candidate group relationships a node participates in are more important; and the third layer eliminates the quantity bias of duplicate relationships of the same type and determines the relative contribution of different template patterns to the risk representation of the current node. This allows for the integration of node and superedge information to obtain accurate final information about the superedge, and based on this final information, accurate identification of abnormal superedges exhibiting group fraud is achieved, further improving the accuracy and efficiency of detecting abnormal transactions.
[0010] Optionally, determining the final information of the hyperedge based on the final information of each node of the hyperedge includes: Using the final information of each node in the hyperedge as the initial information, we recalculate the attention within the hyperedge, the attention between the hyperedge and the nodes, and the fusion attention until we obtain the final information of the hyperedge that meets the requirements.
[0011] By repeatedly executing the three-layer attention calculation process described above through polling, that is, using the final information of each node of the hyperedge as the initial information, the attention calculation within the hyperedge, the attention calculation between the hyperedge and the nodes, and the fusion attention calculation are performed again until the final information of the hyperedge that meets the requirements is obtained, which can further ensure the accuracy of the final information of the hyperedge.
[0012] Optionally, the step of performing hyperedge-internal attention calculation on each node contained within the hyperedge to obtain the intermediate hyperedge information includes: For each node contained within the hyperedge, relative time codes with different time scales are obtained based on the time information of the hyperedge and the time information of the node; wherein, the time information of the hyperedge is the latest update time of the hyperedge, and the time information of the node is the transaction time of the latest transaction corresponding to the node; Based on the initial information and relative time encoding of each node, the hyperedge attention is calculated with the initial information of the hyperedge to obtain the intermediate hyperedge information.
[0013] This application employs a three-layer attention computing mechanism: the first layer identifies key members and temporal behaviors within a single hyperedge; the second layer filters important specific relationships among all belonging hyperedges; and the third layer merges hyperedges of the same type and compares the contributions of different pattern types. This mechanism can suppress aggregation bias caused by repetitive evidence of the same type and imbalance in the number of types, while retaining key instance evidence and cross-pattern complementary information, thereby improving the discriminative and interpretable nature of gang risk representation.
[0014] The first layer of attention calculation involves aggregating information from the execution nodes within the hyperedge to the hyperedge itself. For any candidate hyperedge, different participating nodes typically contribute differently to the group risk assessment. For example, a device with multiple accounts linked in the short term may be more important than a regular device, a new account with high usage may be more important than a long-term stable account, and a node with recent concentrated activity may be more important than a node that was active a long time ago. Therefore, this layer uses the overall representation of the hyperedge as the query, and the attributes and relative time information of each node within the hyperedge as keys and values, to calculate the attention weight of each node to the current hyperedge, forming an intermediate hyperedge representation that includes information on member importance and time rhythm.
[0015] Optionally, the activity level of any hyperedge in the dynamic hypergraph is not lower than a preset condition; the activity level is determined based on the latest update time of the hyperedge, wherein the more recent the update time, the higher the activity level.
[0016] When there are no new transactions supporting the superedge for a long period of time, its activity level decreases smoothly over time; when new valid transactions are added, the activity level of the superedge can be enhanced, thus ensuring that the superedge can accurately represent the state of the latest transactions and accurately obtain superedge information.
[0017] Optionally, determining whether to update the dynamic hypergraph for each arriving transaction includes: For each arriving transaction, perform meta-path instance matching with each superedge template in the superedge template set; If the transaction information matches any hyperedge template, determine whether there is a corresponding hyperedge in the dynamic hypergraph. If there is, update the corresponding hyperedge; if there is no hyperedge and the hyperedge generation conditions of the hyperedge template are not met, record it as a candidate hyperedge.
[0018] By defining node combinations, relationship anchors, attribute constraints, time windows, and co-occurrence thresholds in the template, incremental matching is performed on local nodes and local hyperedges involved in new transactions without repeatedly rebuilding the entire graph. Through member expansion, repetition suppression, activity decay, and lifecycle elimination, the dynamic hypergraph can continuously express the generation, enhancement, expansion, and decay of group relationships, and explicitly represent high-order collaborative behaviors of multiple entities that are difficult to fully describe in ordinary binary graphs.
[0019] Optionally, each hyperedge template in the hyperedge template set adopts a quintuple structure, including: node type, attribute constraint, time window, co-occurrence frequency, and hyperedge type; The transaction information successfully matches any hyperedge template, including: If the transaction information satisfies the node type and attribute constraints of any superedge template, then the transaction information is determined to be a successful match with the superedge template; any superedge is determined based on the node type and the attribute constraints. The conditions for generating the superedge that satisfy the superedge template include: Based on the transaction information and the recorded candidate superedges, determine whether the time window and co-occurrence frequency of the superedge template are satisfied.
[0020] By jointly summarizing historical fraud cases, risk control rules, and labeled gang samples using a large language model, unstructured fraud knowledge is transformed into structured, verifiable, and executable heterogeneous hyperedge templates. Review feedback can continue to correct existing templates or trigger the generation of new templates, thereby improving the template library's adaptability to new fraud patterns and concept drift.
[0021] Optionally, for any hyperedge in the dynamic hypergraph, decay is performed based on a preset maximum retention time.
[0022] To prevent scattered transactions from repeatedly replenishing small amounts of activity and causing early hyperedges to persist for a long time, to ensure that the dynamic hypergraph does not expand indefinitely, to improve computational efficiency, and to avoid the impact of long-term invalid transactions, any hyperedge in the dynamic hypergraph can be decayed based on a preset maximum retention time.
[0023] Optionally, any superedge template is obtained by a large language model based on the input historical abnormal transaction information, risk control rule information, and labeled abnormal sample information.
[0024] The super-edge template can be obtained by accurately and efficiently combining the input historical abnormal transaction information, risk control rule information, and labeled abnormal sample information through a large language model.
[0025] Optionally, after determining the abnormal superedge containing group fraud based on the final information for each superedge, the method further includes: Based on the abnormal hyperedge, structured prompt information is constructed; the structured prompt information includes at least one of the following fields: hyperedge information, node information, transaction information, statistical features, and historical similar cases; The structured prompt information is input into the large language model to obtain the abnormal transaction information output by the large language model; the abnormal transaction information includes at least one of the following: judgment of the composition of abnormal personnel, description of abnormal transaction methods, key points of risk evidence, confidence level rating and handling suggestions.
[0026] Optionally, the method further includes: Receive feedback information regarding the abnormal transaction information; Based on the feedback information, the abnormal superedges corresponding to the abnormal transaction information are labeled; the labeled abnormal superedges are used as abnormal sample information and input into the large language model to participate in the process of obtaining the superedge template.
[0027] This application provides a feedback closed-loop update mechanism that, based on feedback information regarding abnormal transactions, uses the abnormal superedges corresponding to the abnormal transaction information as abnormal sample information, inputting them into a large language model to participate in the process of obtaining superedge templates. This further enriches the types of superedge templates and effectively identifies new types of group fraud transactions.
[0028] Secondly, this application provides an abnormal transaction detection device, the device comprising: The judgment module is used to determine whether to update the dynamic hypergraph for each incoming transaction information. Any hyperedge in the dynamic hypergraph is generated based on multiple transaction information that conform to any hyperedge template. Each hyperedge template corresponds to a hyperedge type that represents a type of gang fraud. The calculation module is used to perform intra-edge attention calculation for each node contained within any hyperedge in the dynamic hypergraph, to obtain intermediate hyperedge information of the hyperedge; the intermediate hyperedge information represents the influence of each node on the hyperedge; for each node in the dynamic hypergraph, based on the intermediate hyperedge information of different hyperedges to which the node belongs, perform attention calculation between hyperedges and nodes, and obtain intermediate node information of the node based on the different hyperedges to which the node belongs; any intermediate node information represents the influence of different hyperedges under which the node belongs on the node; based on the intermediate node information of each node and the type of hyperedge to which the node belongs, obtain the type node information of the node under each hyperedge type; based on the type node information of the node under different hyperedge types, perform fusion attention calculation to obtain the final information of the node; The identification module is used to identify abnormal superedges with gang fraud based on the final information of each superedge.
[0029] Optionally, the calculation module is specifically used to take the final information of each node of the hyperedge as the initial information, and re-perform the attention calculation within the hyperedge, the attention calculation between the hyperedge and the nodes, and the fusion attention calculation until the final information of the hyperedge that meets the requirements is obtained.
[0030] Optionally, the calculation module is specifically used to obtain relative time codes with different time scales for each node contained within the hyperedge, based on the time information of the hyperedge and the time information of the node; wherein, the time information of the hyperedge is the latest update time of the hyperedge, and the time information of the node is the transaction time of the latest transaction corresponding to the node; based on the initial information and relative time codes of each node, and the initial information of the hyperedge, perform hyperedge attention calculation to obtain the intermediate hyperedge information of the hyperedge.
[0031] Optionally, the activity level of any hyperedge in the dynamic hypergraph is not lower than a preset condition; the activity level is determined based on the latest update time of the hyperedge, wherein the more recent the update time, the higher the activity level.
[0032] Optionally, the judgment module is specifically used to perform meta-path instance matching between each arriving transaction information and each superedge template in the superedge template set; if the transaction information is successfully matched with any superedge template, determine whether there is a corresponding superedge in the dynamic supergraph; if there is, update the corresponding superedge; if there is no superedge and the superedge generation condition of the superedge template is not met, record it as a candidate superedge.
[0033] Optionally, each hyperedge template in the hyperedge template set adopts a quintuple structure, including: node type, attribute constraint, time window, co-occurrence frequency, and hyperedge type; The successful matching of the transaction information with any superedge template includes: if the transaction information satisfies the node type and attribute constraints of any superedge template, then it is determined that the transaction information is successfully matched with the superedge template; any superedge is determined based on the node type and the attribute constraints. The conditions for generating a superedge that satisfy the superedge template include: determining whether the time window and co-occurrence frequency of the superedge template are satisfied based on the transaction information and the recorded candidate superedges.
[0034] Optionally, the calculation module is further configured to attenuate any hyperedge in the dynamic hypergraph based on a preset maximum retention time.
[0035] Optionally, any super-edge template is obtained by using a large language model based on the historical abnormal transaction information and risk control rule information of the input, and the labeled abnormal sample information.
[0036] Optionally, the device further includes: An analysis module is used to construct structured prompt information based on the abnormal hyperedge; the structured prompt information includes at least one of the following fields: hyperedge information, node information, transaction information, statistical features, and historical similar cases; the structured prompt information is input into a large language model to obtain abnormal transaction information output by the large language model; the abnormal transaction information includes at least one of the following: judgment of abnormal personnel composition, description of abnormal transaction methods, key points of risk evidence, confidence rating, and handling suggestions.
[0037] Optionally, the device further includes: The feedback module is also used to receive feedback information regarding the abnormal transaction information; based on the feedback information, to label the abnormal superedges corresponding to the abnormal transaction information; and to input the labeled abnormal superedges as abnormal sample information into the large language model to participate in the process of obtaining the superedge template.
[0038] Thirdly, embodiments of this application provide a computer-readable storage medium storing a computer program that, when executed by a processor, implements the steps of any of the methods described in the first aspect.
[0039] Fourthly, this application provides an electronic device comprising at least a processor and a memory, wherein the processor is configured to execute a computer program stored in the memory to implement the steps of the method as described in any of the first aspects.
[0040] Fifthly, this application provides a computer program product comprising: computer program code, which, when executed on a computer, causes the computer to perform the steps of any of the methods described in the first aspect.
[0041] These or other implementations of this application will become clearer and easier to understand in the following description of the embodiments. Attached Figure Description
[0042] To more clearly illustrate the implementation methods in the embodiments of this application or related technologies, the accompanying drawings used in the description of the embodiments or related technologies will be briefly introduced below. Obviously, the accompanying drawings described below are some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings.
[0043] Figure 1 A schematic diagram of an abnormal transaction detection process is provided for some embodiments of this application; Figure 2 A schematic diagram of a super-edge template provided for some embodiments of this application; Figure 3 A schematic diagram of an abnormal super-edge provided for some embodiments of this application; Figure 4 A schematic diagram of the structure of an abnormal transaction detection device provided for some embodiments of this application; Figure 5 This is a schematic diagram of the structure of an electronic device provided for some embodiments of this application. Detailed Implementation
[0044] To make the objectives, technical solutions, and advantages of this application clearer, a further detailed description of this application will be provided below with reference to the accompanying drawings. Obviously, the embodiments described in this application are merely some embodiments, not all embodiments. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0045] It should be noted that the brief descriptions of terms in this application are only for the convenience of understanding the embodiments described below, and are not intended to limit the embodiments of this application. Unless otherwise stated, these terms should be understood in their ordinary and common meaning.
[0046] The terms "first," "second," "third," etc., used in the specification, claims, and accompanying drawings of this application are used to distinguish similar or related objects or entities, and do not necessarily imply a specific order or sequence, unless otherwise specified. It should be understood that such terms are interchangeable where appropriate.
[0047] The terms “comprising” and “having”, and any variations thereof, are intended to cover but not exclude inclusion, for example, a product or device that includes a range of components is not necessarily limited to all of the components that are clearly listed, but may include other components that are not clearly listed or that are inherent to such product or device.
[0048] The term "module" refers to any known or subsequently developed hardware, software, firmware, artificial intelligence, fuzzy logic, or combination of hardware and / or software code that is capable of performing the functions associated with that element.
[0049] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some or all of the technical features therein. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of this application.
[0050] In view of the problems existing in the background technology, this application provides an abnormal transaction detection method to improve the efficiency and accuracy of detecting abnormal transactions for new types of gang fraud.
[0051] The following is a detailed description of the proposed solution in conjunction with the accompanying drawings.
[0052] Figure 1 This is a schematic diagram illustrating an abnormal transaction detection process provided for some embodiments of this application. For example... Figure 1 As shown, the specific steps include: S101: For each arriving transaction information, determine whether to update the dynamic hypergraph. Any hyperedge in the dynamic hypergraph is generated based on multiple transaction information that conform to any hyperedge template. Each hyperedge template corresponds to a hyperedge type that represents a type of gang fraud.
[0053] The method in this application embodiment is applied to an electronic device, which may optionally be a server, PC, or other such device.
[0054] The existing methods for detecting fraud by financial transaction groups have the following three pressing technical problems that need to be addressed: The over-the-edge template relies on manual pre-definition, making it difficult to automatically construct from continuously accumulated fraud knowledge and evolve in a closed loop with new fraud patterns. When new fraud patterns such as "remote-assisted bulk cash-out" emerge, manually pre-defined fixed templates cannot cover them in time, easily leading to missed detections.
[0055] Existing solutions typically rely on manual case reading, pattern summarization, and rule writing, failing to automatically convert unstructured knowledge from historical cases, risk control rules, and labeled gang samples into machine-executable hyper-edge templates. The root cause is that template generation and updating remain manually driven static mappings, lacking a closed-loop mechanism encompassing knowledge extraction, structured template generation, template validation, and review feedback correction.
[0056] Existing static graphs or offline supergraphs are difficult to construct, expand, and eliminate high-level group relationships in real time according to template constraints in streaming financial transactions.
[0057] The surface phenomenon is that in streaming scenarios with tens of millions of transactions per day, the latency and resource consumption of full graph reconstruction or full scanning are unacceptable; and the binary edges in ordinary graphs are insufficient to fully represent the group relationships involving multiple users, devices, and merchants. The intermediate mechanism is that existing methods often rely on offline graph construction in fixed batches. When new transactions arrive, they cannot perform local retrieval and incremental updates solely based on the affected users, merchants, devices, IPs, and associated hyperedges. They also lack unified management of existing hyperedge member expansion, duplication suppression, activity enhancement, and expiration elimination. The root cause is that existing graph construction mechanisms lack online local matching mechanisms under template semantic constraints and hyperedge lifecycle models, thus failing to simultaneously guarantee high-order relationship expressiveness, real-time performance, and controllable dynamic graph scale.
[0058] Existing hypergraph aggregation methods fail to separate the importance of specific hyperedge instances from the importance of hyperedge pattern types, making them susceptible to redundancy of the same type and imbalances in the number of types. A superficial phenomenon is that a single node may connect to multiple hyperedges of the same type as well as a small number of hyperedges of other types. When directly summing, averaging, or performing one-time attention aggregation, the type with a larger number of instances tends to occupy a higher total weight, potentially drowning out crucial but fewer cross-type evidence. The intermediate mechanism is that existing methods typically complete the information propagation between nodes and hyperedges at a single granularity, without first comparing the true relevance of each specific hyperedge instance to the node, then merging relationships of the same type, and comparing the contributions of different pattern types. The root cause is the lack of a two-granularity hierarchical encoding mechanism of "instance-level relationship selection—same-type summarization—type-level fusion," making it difficult for the model to simultaneously consider fine-grained discriminative ability, redundancy suppression, type balance, and risk source explanation.
[0059] Based on this, optionally, this application proposes a dynamic heterogeneous hypergraph construction mechanism based on hyperedge template constraints for streaming financial transactions. This mechanism uses multi-source entities such as users, merchants, devices, and IPs as heterogeneous nodes. According to the relationship pattern and time constraints specified by the hyperedge template, it performs local retrieval, candidate aggregation, and incremental edge construction on real-time transactions to form a dynamic hypergraph. Furthermore, it can achieve dynamic updating and elimination of any hyperedge in the dynamic hypergraph through activity decay and lifecycle management.
[0060] Compared with static graph modeling based on binary relations, this method can explicitly represent high-order collaborative behaviors involving multiple entities and adapt to the dynamic process of group relationships continuously emerging, expanding and fading with transaction flows.
[0061] Specifically, for each arriving transaction, the information can be matched against pre-saved hyperedge templates to determine whether to update the dynamic hypergraph. In other words, for each arriving transaction, information such as the transaction partner, transaction device, transaction location, transaction amount, and transaction bank card can be matched against pre-saved hyperedge templates. If the constraints of any hyperedge template are met, a new hyperedge is generated, or an existing hyperedge is added, thereby updating the dynamic hypergraph.
[0062] In this dynamic hypergraph, any hyperedge is generated based on multiple transaction information that conform to any hyperedge template. Each hyperedge template can correspond to a hyperedge type that represents a type of gang fraud.
[0063] Figure 2 This is a schematic diagram of a super-edge template provided for some embodiments of this application. For example... Figure 2 As shown, optionally, a dynamic heterogeneous hypergraph can be constructed based on real-time transaction data and the constraints of the hyperedge template, such as time windows, attribute constraints, and co-occurrence frequency conditions. Each hyperedge in the dynamic heterogeneous hypergraph represents a group of higher-order related entities that satisfy specific hyperedge template constraints, such as multiple users, shared devices, shared merchants, and shared IP addresses.
[0064] It is important to note that the generation or updating of hyperedges represents the discovery and organization of candidate gang relationships, and it is not possible to determine whether a gang is fraudulent simply based on whether a hyperedge has formed. Judgment needs to be based on the final information of the subsequently determined hyperedge.
[0065] Optionally, in subsequent processes of this application, a hierarchical hypergraph attention network can be further utilized to encode the node attributes of the hyperedge, the contributions of the internal members of the hyperedge, the context of multiple hyperedges in which the node participates, the hyperedge pattern type, and the relative temporal relationship of the transactions into a discriminative vector representation, and to determine whether the hyperedge is abnormal through the final information of the hyperedge.
[0066] S102: For any hyperedge in the dynamic hypergraph, perform hyperedge attention calculation on each node contained within the hyperedge to obtain the intermediate hyperedge information of the hyperedge; the intermediate hyperedge information represents the influence of each node on the hyperedge.
[0067] To accurately obtain the information contained in a hyperedge, including the influence of its internal members on the hyperedge, we can, for any hyperedge in the hypergraph, determine the attention weight of each node relative to the hyperedge based on the initial information of each node within the hyperedge. Then, we calculate the intermediate hyperedge information based on the initial information of each node using these attention weights. This intermediate hyperedge information represents the influence of each node within the hyperedge on that hyperedge.
[0068] By calculating the attention within a hyperedge, it is possible to accurately determine which nodes within a single hyperedge are more important.
[0069] S103: For each node in the dynamic hypergraph, perform attention calculation between hyperedges and nodes based on the intermediate hyperedge information of different hyperedges to which the node belongs, and obtain the intermediate node information of the node based on the different hyperedges to which the node belongs; any intermediate node information represents the influence of different hyperedges on the node under its belonging hyperedge.
[0070] To accurately obtain the information contained in each node, for any node in the hypergraph, all hyperedges containing that node can be obtained. Based on the initial information of the node and the information of the intermediate hyperedges of all hyperedges, attention between hyperedges and nodes can be calculated to determine the attention weight of each hyperedge relative to the node, and the information of the intermediate nodes of the node can be obtained according to the attention weight.
[0071] By calculating the hyperedge and inter-node attention as described above, it is possible to determine which relationships among all the candidate gang relationships a node participates in are more important.
[0072] S104: Based on the intermediate node information of each node and the hyperedge type to which the node belongs, obtain the type node information of the node under each hyperedge type; based on the type node information of the node under different hyperedge types, perform fusion attention calculation to obtain the final information of the node.
[0073] To eliminate the quantity bias of repetitive relationships of the same type and to determine the relative contribution of different hyperedge types to the risk representation of the current node, cross-type attention calculation can be performed based on the type-level node representation of the node under different hyperedge types. The type-level attention weights of hyperedges of different hyperedge types relative to the node can be determined, and the different type-level node representations can be fused according to the type-level attention weights to obtain the final node representation of the node, i.e., the final information of the node.
[0074] By employing the aforementioned fusion attention calculation, the computational granularity can be elevated from "hyperedge instance level" to "pattern type level," suppressing the bias in the number of similar hyperedges. Since the same node may form multiple highly similar hyperedges of the same type due to continuous transactions or different time windows, directly performing the final fusion on all hyperedges might result in a type with more instances simply having a higher overall weight. Merging hyperedges of the same type first avoids the repeated amplification of duplicate evidence. Through fusion attention calculation based on different hyperedge types, instance importance and type importance can be separated. While other attention calculations at higher layers determine which specific hyperedge is more important, this layer determines which template pattern is more important; these two correspond to different semantic levels. Furthermore, it can preserve cross-pattern complementary evidence. Patterns such as device sharing, merchant concentration, IP aggregation, and high-frequency activity at night may collectively point to gang risk. Type-level attention can adaptively combine multiple pieces of evidence based on the current node state, reducing computational and storage pressure. When a node connects to a large number of hyperedges of the same type, this layer only needs to calculate attention between a small number of merged type representations.
[0075] S105: Determine the final information of the hyperedge based on the final information of each node of the hyperedge.
[0076] Through the above S103-S105, closed-loop encoding of "node to hyperedge, hyperedge to node, same type merging, cross type fusion, node to final hyperedge" is performed on the dynamic heterogeneous hypergraph to obtain the final information of the hyperedge.
[0077] The final representation of a node can characterize its contribution to the final gang-level representation of the hyperedge. It can further highlight the impact of abnormal users, abnormal devices, abnormal merchants, or abnormal IPs on gang identification.
[0078] S106: Identify abnormal superedges with gang fraud based on the final information of each superedge.
[0079] Optionally, the final information of the hyperedge can be input into a multilayer perceptron, and the gang fraud probability can be obtained through a classification function such as the Sigmoid function. When the gang fraud probability is not lower than the preset classification threshold δ, the hyperedge h can be output as an abnormal hyperedge.
[0080] This application proposes a dynamic heterogeneous hypergraph construction mechanism based on hyperedge template constraints for streaming financial transactions. This mechanism uses multi-source entities such as users, merchants, devices, and IPs as heterogeneous nodes. Based on the relationship patterns and time constraints specified by the hyperedge templates, it performs local retrieval, candidate aggregation, and incremental edge construction on real-time transactions to form and update the dynamic hypergraph. Compared with static graph modeling based on binary relations, this method can explicitly represent high-order collaborative behaviors involving multiple entities and adapt to the dynamic process of group relationships continuously emerging, expanding, and fading with the transaction flow. It performs closed-loop encoding on the dynamic hypergraph, including node-to-hyperedge, hyperedge-to-node, same-type merging, cross-type fusion, and node-to-final-hyperedge. Specifically, the first layer determines which nodes and their temporal behaviors are more important within a single hyperedge; the second layer determines which relationships among all candidate group relationships a node participates in are more important; and the third layer eliminates the quantity bias of duplicate relationships of the same type and determines the relative contribution of different template patterns to the risk representation of the current node. This allows for the integration of node and superedge information to obtain accurate final information about the superedge, and based on this final information, accurate identification of abnormal superedges exhibiting group fraud is achieved, further improving the accuracy and efficiency of detecting abnormal transactions.
[0081] This application also proposes a hierarchical hypergraph attention encoding mechanism with instance-type dual granularity. This mechanism first learns the contribution of different nodes to the candidate gang representation within a single hyperedge. Second, it models instance-level associations between a node and all its associated hyperedges without distinguishing between types. Furthermore, it adaptively merges hyperedges of the same type and performs cross-type attention and gating fusion between summaries of different types. This design, while preserving key specific hyperedge evidence, can suppress aggregation bias caused by redundancy of hyperedges of the same type and imbalance in the number of types, thereby obtaining a gang risk representation that combines fine-grained discriminative power with type-level interpretability.
[0082] Optionally, a concrete example will be used below to further illustrate the entire process of attention calculation described above. For example, at the current processing moment... The dynamic heterogeneous hypergraph is represented as: ; In the formula: Indicates the end time The set of nodes; Indicates the end time The set of candidate superedges; A matrix representing the original or initialized features of a node; This represents the set of time information for each hyperedge-related transaction; This represents a node type mapping function used to indicate the node type. For users, merchants, devices, or IP nodes; This represents a hyperedge pattern type mapping function used to indicate hyperedges. Which type of superedge template was used to generate it?
[0083] Optionally, the set of node types can be represented as:
[0084] in , , and These represent user, merchant, device, and IP node types, respectively.
[0085] Optionally, the set of hyperedge types, which is also the set of pattern types for hyperedge templates, can be represented as: ; And define any hyperedge The type of superedge is: ; Here This is a template type or pattern semantic tag inherited from the corresponding superedge template when the superedge is generated, such as "small merchant shared equipment cash-out", "same IP new card concentrated swiping", "nighttime high frequency small amount transaction type", etc. This tag does not indicate that the superedge has been judged as fraud, nor is it the same as the subsequent output "normal / fraud" classification result.
[0086] Optionally, output the final node information and the final hyperedge information: ; in, Represents a node The final risk feature formed after three layers of attention encoding Indicates the superedge The final gang-level characteristics.
[0087] Optionally, the probability of group fraud can be calculated based on the final hyperedge representation, i.e., the final information of the hyperedge: ; in .
[0088] Optionally, the dynamic heterogeneous hypergraph contains nodes with different semantics and dimensions. The original characteristics of user nodes may include credit score, account or card duration, credit limit, credit limit utilization rate, recent transaction frequency, nighttime transaction ratio, and transaction rejection ratio; the original characteristics of merchant nodes may include merchant category, recent transaction volume, transaction volume growth rate, refund rate, and chargeback rate; the original characteristics of device nodes may include device fingerprint, number of historically bound accounts, first appearance time, and device environment risk markers; the original characteristics of IP nodes may include IP address range, geographical location, number of recently active accounts, proxy IP markers, and cross-regional access characteristics.
[0089] Optionally, the node The original features, or initial information, are denoted as:
[0090] Original feature dimensions of different node types They can be different.
[0091] For node type The original features are mapped to a unified representation space using the corresponding learnable projection matrix and bias: ; in: The learnable projection matrix corresponding to the node type; For the corresponding learnable bias; To unify the representation of dimensional nodes; To unify feature dimensions, one implementation method can take... .
[0092] This process does not simply pad low-dimensional features with zeros, but allows users, merchants, devices, and IPs to learn feature combinations that conform to their own business semantics and participate in subsequent attention calculations in a unified space.
[0093] Optionally, the step of performing hyperedge-internal attention calculation on each node contained within the hyperedge to obtain the intermediate hyperedge information includes: For each node contained within the hyperedge, relative time codes with different time scales are obtained based on the time information of the hyperedge and the time information of the node; wherein, the time information of the hyperedge is the latest update time of the hyperedge, and the time information of the node is the transaction time of the latest transaction corresponding to the node; Based on the initial information and relative time encoding of each node, the hyperedge attention is calculated with the initial information of the hyperedge to obtain the intermediate hyperedge information.
[0094] Optional, the first layer of the three-layer attention calculation mechanism: attention calculation within the superedge. This can perform information aggregation from node to superedge. For any candidate superedge h, the contribution of different participating nodes to the group risk assessment typically varies. For example, a device with multiple accounts linked in the short term may be more important than a regular device, a new account with high usage may be more important than a long-term stable account, and a node with recent concentrated activity may be more important than a node that was active a long time ago.
[0095] Therefore, this layer uses the overall representation of the hyperedge as the query, and uses the attributes and relative time information of each node within the hyperedge as the key and value, calculates the attention weight of each node to the current hyperedge, and forms an intermediate hyperedge representation that includes member importance and time rhythm information.
[0096] Optionally, the initial representation of the hyperedge can be obtained using the following procedure: For the hyperedge h, we first perform basic pooling on the representation of the nodes it contains to obtain the initial representation of the hyperedge: ; Used to provide the overall query semantics of the current hyperedge. The basic pooling can be average pooling, summation pooling, or other permutation-invariant read operations, but average pooling is preferred to reduce the scale offset caused by differences in the number of hyperedge nodes.
[0097] Optionally, since the behavior of nodes has temporal characteristics, a relative time interval setting can be used: Will with hyper-edge The associated set of supporting transactions is denoted as The super-edge reference time can be retrieved to support the latest transaction time in the current trade:
[0098] For nodes in the hyperedge Record its most recent activity moment in the super-edge supported transactions as Then the time difference between the node and the reference time of the hyperedge is: The smaller the value, the closer the node's behavior is to the latest activity of the current superedge; The larger the value, the earlier the behavior occurred.
[0099] Optionally, multiple sets of learnable frequency parameters can be used to map continuous time differences into relative time vectors: ; in, For time frequency quantity, For the first One learnable frequency parameter .
[0100] This encoding can simultaneously express behavioral rhythms at the minute, hour, and day levels, and has the following technical effects: Different representations are formed for superedges containing the same nodes but with different levels of transaction concentration; the focus is on the relative intervals between actions, rather than relying on specific years, months or dates; irregular continuous time is directly processed without the need to manually divide fixed time buckets; the time scale of different fraud patterns is adapted through learnable frequencies; the encoding process is continuously differentiable and can be jointly trained with other parameters of the attention network.
[0101] Optionally, queries, key and value construction can be performed on nodes.
[0102] Concatenate the node's unified features with the relative time code: ; in This indicates vector concatenation.
[0103] Generate the query vector from the initial representation of the hyperedge: ; Generate key and value vectors from the joint representation of nodes and time:
[0104] in, , and All of these are learnable parameter matrices.
[0105] Optionally, node importance can be scored and normalized: node Compared to hyperedge The unnormalized correlation score is: ; Perform Softmax normalization across all nodes of the same hyperedge: ; And satisfy: ; Represents a node For superedge The relative contribution is determined by node attributes, relative time encoding, and training parameters, rather than by manual pre-setting.
[0106] Optional, the attention within the hyperedge between the node and the hyperedge: The first layer performs information aggregation from nodes to superedges. For any candidate superedge h, the contribution of different participating nodes to the group risk assessment is usually different. For example, a device that is bound to multiple accounts in the short term may be more important than an ordinary device, a new account with a high credit usage rate may be more important than a long-term stable account, and a node with concentrated activity recently may be more important than a node that was active a long time ago.
[0107] Therefore, this layer uses the overall representation of the hyperedge as the query, and the attributes and relative time information of each node within the hyperedge as the key and value. It calculates the attention weight of each node to the current hyperedge and forms an intermediate hyperedge representation containing member importance and time rhythm information, namely the intermediate hyperedge information.
[0108] Optional, the middle superedge represents: Under single-head attention, the middle super-edge is represented as: ; In the preferred multi-head implementation, the first The output of each attention head is: ; Will Attention heads are concatenated and mapped: ; Different attention points can focus on different risk factors such as account characteristics, device sharing level, abnormal merchant growth, IP concentration level, amount distribution, and time concentration level.
[0109] Optionally, the second layer of the three-layer attention calculation: attention calculation between hyperedges and nodes, calculates the attention between a node and all its hyperedges.
[0110] Technical objective and computational scope: A single node may participate in multiple candidate superedges simultaneously. The first layer is formed... It only describes the information inside a single hyperedge and does not yet reflect the context of the same node in other candidate group relationships. Therefore, the second layer performs information backhaul from the hyperedge to the node.
[0111] The key rule for this layer is: for nodes... Attention is calculated directly among all hyperedges containing the node, without pre-splitting them according to hyperedge pattern type. That is, regardless of whether the relevant hyperedges come from shared device templates, merchant centralized templates, same IP templates, or high-frequency nighttime templates, they all first enter the same instance-level competition space.
[0112] This setting allows the model to first answer which specific hyperedge instances are most important to the nodes, avoiding artificial grouping based on template type before instance-level relevance is determined.
[0113] Optional, the set of all superedges to which the node belongs: Define the included node The complete set of hyperedges is: ; The normalization range of the second-level calculation is the entire , without introducing As a grouping condition.
[0114] Optional, node query and superedge key-value pairs: Generate the second-level query vector from the initial node representation:
[0115] The intermediate hyperedges obtained from the first layer represent the generation of the key vector and value vector for the second layer: ; ; in, , and This is the learnable parameter matrix.
[0116] Optional, calculate the correlation between a node and all its superedges: node With its superedge The instance-level relevance score is:
[0117] At the node The set of all superedges to which it belongs Perform Softmax normalization within the function:
[0118] And satisfy: ; In the formula, the denominator covers This covers all superedges in the array, instead of just one type of superedge. This is the core formula correction compared to the original description.
[0119] Optional, node cross-hyperedge context representation: The context information that a node receives from all relevant hyperedges is as follows: ; The second-layer node representation is obtained by using residual connections and normalization: ; in, This is a learnable residual projection matrix. Residual connectivity is used to preserve the node's own properties and prevent the node representation from being completely replaced by the information of adjacent hyperedges; normalization is used to stabilize the numerical scale caused by the difference in the number of hyperedges connected to different nodes.
[0120] The second layer of attention calculation, namely the attention calculation between hyperedges and nodes, does not distinguish between hyperedge types and has the following functions: The system compares the true relevance of specific hyperedge instances to the current node within a unified scope; it prevents each type from being forcibly assigned a higher weight after normalization; it avoids hyperedge type labels from prematurely participating in instance-level competition and obscuring strongly related hyperedges across types; and it provides a unified instance-level attention weight for merging similar types in the third layer. The system separates "importance of specific relational instances" and "importance of risk pattern types" into two levels, resulting in clearer hierarchical semantics.
[0121] Optionally, the third layer of the three-layer attention computation is: fusion attention computation, which computes the merging of superedges of the same type and the attention of superedges of different types.
[0122] Optionally, the origin and meaning of the superedge type can also be referred to as the superedge pattern type: Super-edge mode type It originates from the hyperedge template generated or determined by this hyperedge, and is inherited by the hyperedge when generating it based on this template. The template identifier `template_id(h)`, template name, or pattern type field can be stored in the hyperedge data structure, and mapped using a mapping function. get .
[0123] For example, superedges generated based on the "Small Merchant Shared Equipment Cash-Out" template all belong to the mode type corresponding to that template; superedges generated based on the "Same IP New Card Centralized Swiping" template belong to another mode type. The same batch of nodes can simultaneously form multiple types of superedges by satisfying different templates.
[0124] It needs to be clarified that the hyperedge pattern type is a known structural semantic label, not a fraud label that the classifier is trying to predict. Further calculations are still needed. Output the probability that the candidate superedge belongs to the fraud group.
[0125] Optional, the set of types involved in the node and subsets of the same type: node The set of valid hyperedge pattern types involved is defined as follows: ; Among them, the subset of superedges of the same type are: ; Type classification is first used in the fusion attention computation layer.
[0126] Optionally, use the second-layer weights to merge superedges of the same type.
[0127] Due to the second layer Each specific hyperedge instance has been represented to its relation to the node. To determine the importance of the weight, the third layer can renormalize the weight within each type: ; in, To prevent division by zero of extremely small positive numbers. When When the denominator is not empty, it is usually positive.
[0128] Merge multiple hyperedges of the same type into a node. In type The following type-level hyperedge representation: ; in, For type The corresponding learnable projection matrix. This matrix is used to extract the discriminative semantics specific to the template pattern. For example, the device-type pattern focuses more on device binding relationships, the merchant-type pattern focuses more on transaction growth, refunds, and amount distribution, and the IP-type pattern focuses more on geographical distance, login concentration, and time difference.
[0129] In one alternative implementation, a learnable type embedding can be set for each pattern type. And obtained: ; If explicit type embedding is not used, then it can be made .
[0130] Optionally, during the fusion attention computation process, the attention between the node and the hyperedge representation of different types can be computed.
[0131] For example, using the information of the second-level nodes, i.e., the intermediate nodes, as the query: ; Use hyperedges of various types as keys and values: ; ; node With pattern type The type-level relevance score is: ; At the node The different pattern types involved Perform Softmax normalization between them: ; And satisfy: ; Indicates the pattern type For nodes The relative contribution of the final risk representation.
[0132] Optionally, the process for determining the final node representation, i.e., the final information of the node, can refer to the following process: Aggregate the hyperedge representations of different types according to type-level attention weights and perform residual fusion with the second-layer node representations: ; This representation preserves the node's own attributes, the specific hyperedge instance context, and the semantics of different template patterns.
[0133] The necessity and innovative role of integrating attention computation: The third layer does not repeat the computation of the second layer, but rather improves the computation granularity from "hyperedge instance level" to "pattern type level", which is necessary for the following reasons: Suppressing the bias in the number of similar instances. A single node may form multiple highly similar hyperedges of the same type due to consecutive transactions or different time windows. If the final merging is performed directly on all hyperedges, the type with more instances may simply have a higher total weight due to its larger quantity. Merging hyperedges of the same type first can prevent duplicate evidence from being amplified multiple times.
[0134] Separate instance importance from type importance. The second layer determines which specific hyperedge is more important, and the third layer determines which template pattern is more important; these two correspond to different semantic levels.
[0135] Preserve complementary evidence across patterns. Patterns such as device sharing, merchant concentration, IP aggregation, and high-frequency activity at night may collectively point to gang risk. Type-level attention can adaptively combine multiple pieces of evidence based on the current node state.
[0136] Improve interpretability. The model can output not only the attention weights of specific hyperedges. It can also output the weights of each template pattern. This helps to explain which type of relationship the risk mainly originates from.
[0137] Reduce computational and storage burden. When nodes connect a large number of hyperedges of the same type, the third layer only needs to compute attention between a small number of merged type representations.
[0138] Avoid premature typification. Type information should be introduced after instance-level relevance calculations are completed, which utilizes template semantics while reducing premature intervention by template priors in judging the importance of specific relationships.
[0139] Optionally, the final hyperedge representation, i.e., the final information of the hyperedge, and the process of determining abnormal hyperedges based on the final information of the hyperedge can be referred to as follows: Reconstruct the hyperedge representation from the final node representation: After completing the third layer, the super edge Each node has a final representation One basic implementation method is to use average readout: ; Preferably, attention-based readout can be used. First, the node's score in the final readout phase is calculated: ; Normalize within the hyperedge: ; The final hyperedge representation is: ; Represents a node Contribution to the final gang-level representation. Attention readout can further highlight the impact of anomalous users, devices, merchants, or IPs on gang identification.
[0140] Determining the final information of the hyperedge based on the final information of each node of the hyperedge includes: Using the final information of each node in the hyperedge as the initial information, we recalculate the attention within the hyperedge, the attention between the hyperedge and the nodes, and the fusion attention until we obtain the final information of the hyperedge that meets the requirements.
[0141] Optionally, the above three-layer attention calculation can be performed in multiple rounds. That is, the final information of each node of the first output hyperedge can be used as the initial information to re-perform the attention calculation within the hyperedge, the attention calculation between the hyperedge and the nodes, and the fusion attention calculation until the final information of the hyperedge that meets the requirements is obtained.
[0142] Optionally, to identify anomalous superedges with group fraud based on the final information of each superedge, the fraud probability can be calculated and output based on the final information of the superedge: Input the final hyperedge representation into the multilayer perceptron: ; The probability of group fraud is obtained using the Sigmoid function: ; when Not lower than the preset classification threshold At that time, the super edge can be The output is the suspected superedge: ; The aforementioned process is responsible for forming a discriminative representation of the superedge, i.e., the final information of the superedge; for each superedge's final information, abnormal superedges with gang fraud are identified. This process is responsible for outputting the classification probability and the suspicion result, and the functional boundaries of the two are clearly defined.
[0143] Optionally, this application provides a complete example calculation as follows: First layer: Aggregation within a single superedge.
[0144] Assuming candidate superedge Generated from the "Small Merchant Shared Equipment Cash-Out" template: ; After incorporating node attributes and relative time information, the first layer exemplarily yields node attention weights: ; ; but: ; The above values are only used to illustrate the calculation process; the actual weights are obtained by training the model based on the data.
[0145] Second layer: All super-edges compete in a unified manner.
[0146] Suppose Zhang San participates in the following four superedges simultaneously: Small businesses sharing equipment for cash-out schemes; Another method involves small businesses sharing equipment to cash out. : Nighttime high-frequency, low-value trading; Centralized login via IP address from a different location.
[0147] but: ; The second layer does not distinguish between types and directly performs Softmax between the four hyperedges. Assume we get: ; The sum of the four weights is Zhang San's cross-hyperedge context is: ; Third layer: Merge similar types.
[0148] and If they belong to the same template type, they are denoted as ; Belongs to type ; Belongs to type .
[0149] In type Internal renormalization: ; ; Therefore, merging of the same type is represented as: ; For types containing only one superedge: ; ; The third layer: different types of attention.
[0150] Assuming the nodes are represented by three types, the calculation yields: ; Then Zhang San's final expression is: ; This example illustrates the difference between two levels: the second level assigns weights among the four specific hyperedge instances; the third level first merges two hyperedges of the same type, and then assigns weights among the three different template patterns.
[0151] Functional division of labor and technical effects of the three-layer structure: The first layer is attention within the superedge. The information propagation direction is from node to superedge. No superedge pattern type is used. This addresses the question of which members, attributes, and temporal behaviors are more important within a single candidate superedge.
[0152] The second layer is hyperedge-to-node attention. Information propagation is from all participating hyperedges to the node. It does not use hyperedge pattern types and addresses the question of which relationships are more important among all the specific hyperedge instances in which the node participates.
[0153] The third layer involves merging similar types of evidence. The information propagation direction is from the same type superedge to the type-level representation. Using the superedge pattern type, duplicate or similar evidence of the same type is merged and quantity bias is eliminated.
[0154] The third layer is cross-type attention. Information propagation is directed to nodes based on different types of representations, using hyperedge pattern types to address the problem of how to adaptively combine different template patterns such as device, merchant, IP, and behavior.
[0155] The final reading shows that the information propagation direction is from the node to the final superedge. The merged node representations are aggregated at the group level to form the final superedge representation used for classification.
[0156] This attention calculation structure features a more explicit two-level competition mechanism: first, competition is conducted at the superedge instance level, followed by competition at the template type level. This structure can avoid the repeated amplification of multiple similar superedges within the same type, while preserving complementary risk information across types.
[0157] Optionally, this application also provides an alternative method for hypergraph encoding: in addition to hierarchical hypergraph attention networks, hypergraph convolutional networks (HGCNs) can be used to replace the attention mechanism for encoding. Specifically, hypergraph convolution operations based on the spectral domain or spatial domain are used to replace the attention layer inside the hyperedge, and the aggregation of messages of nodes inside the hyperedge is achieved through Laplacian smoothing operations, which can reduce computational complexity but has slightly inferior expressive power compared to the attention mechanism.
[0158] Optionally, the following process can be used to determine abnormal hyperedges based on the final information of the hyperedges, i.e., to identify suspected gangs: Optional, gang suspect identification and model training are as follows: Two-layer classification decoder: For each candidate superedge, output the final gang-level representation. In a preferred embodiment, a two-layer multilayer perceptron is used for decoding. The first layer maps the 128-dimensional hyperedge representation to a 64-dimensional hidden layer and activates it using GELU. The second layer outputs an unnormalized risk score.
[0159] ; ; ; in, , , and For learnable parameters, The probability of gang fraud for candidate superedge h.
[0160] Optional, suspected edge exceedance determination: ; The classification threshold δ can be determined based on the recall rate, precision rate, false positive cost, and business risk tolerance on the validation set. In one embodiment, δ can be set to 0.5; in high-risk payment scenarios, the threshold can also be lowered to improve the recall rate.
[0161] Optional, supervised classification loss: During model training, binary cross-entropy loss is applied to hyperedge samples with gang labels. Let the training batch contain N hyperedges, and the true labels be... The predicted probability is ,but: ; This loss makes the predicted probability of fraudulent superedges approach 1 and the predicted probability of normal superedges approach 0.
[0162] Figure 3 This is a schematic diagram of an abnormal hyperedge provided for some embodiments of this application. For example... Figure 3 As shown, the fraud probability of each hyperedge can be calculated based on the above process, and the judgment result can be determined based on the fraud probability, among which the suspected ones are abnormal hyperedges.
[0163] Optionally, each hyperedge template in the hyperedge template set adopts a quintuple structure, including: node type, attribute constraint, time window, co-occurrence frequency, and hyperedge type; The transaction information successfully matches any hyperedge template, including: If the transaction information satisfies the node type and attribute constraints of any superedge template, then the transaction information is determined to be a successful match with the superedge template; any superedge is determined based on the node type and the attribute constraints. The conditions for generating the superedge that satisfy the superedge template include: Based on the transaction information and the recorded candidate superedges, determine whether the time window and co-occurrence frequency of the superedge template are satisfied.
[0164] Optionally, in the abnormal transaction detection method of this application, the generation process of the hyperedge template can involve uniformly encoding historical fraud cases, risk control rules, and labeled gang samples into structured prompts to guide the generation of a large language model. The hyperedge template can include node types, attribute and relationship constraints, time windows, co-occurrence thresholds, and pattern labels, and can also be continuously updated based on review feedback. This achieves a closed-loop learning process from unstructured fraud knowledge extraction and structured gang pattern generation to manual feedback correction, reducing the reliance of traditional methods on manual rule design.
[0165] Optionally, this application provides an automatic hyperedge template mining scheme based on a large language model.
[0166] The input includes a collection of text describing historical fraud cases. Risk control rule document collection and the set of labeled gang samples The three types of input are not duplicate data: It primarily provides unstructured semantics of the crime process, entity relationships, and temporal behavior; It primarily provides executable business boundaries, thresholds, and compliance constraints; It mainly provides confirmed positive and negative group structures, template verification basis, and deduplication and conflict resolution constraints.
[0167]
[0168] The Encode() function organizes the case text, rule clauses, and structured samples into a structured hint that includes role descriptions, task definitions, examples, output fields, and JSON Schema constraints.
[0169] Optionally, the generation and validation of a large language model can be performed using the following process: ; ; The large language model first outputs a set of candidate templates. Subsequently, through format validation, field completeness validation, rule conflict validation, labeled sample coverage validation, and template similarity deduplication, an executable template set T is obtained. This validation step is used to suppress the generation of non-executable fields, contradictory thresholds, or highly repetitive templates by large language models.
[0170] Optionally, the application process of the 5-tuple template is as follows: Semantically, the r-th hyperedge template is represented by a quintuple: ; in, This indicates the node type, the number of nodes, and the constraints on the relationships between nodes. This indicates attribute constraints such as amount, card age, merchant category, and device attributes; Indicates the statistical time window; These represent thresholds such as the number of users, the number of transactions, and the frequency of co-occurrence. Indicates the semantic type of the template pattern.
[0171] To facilitate online execution, the node relationship constraints in the quintuple can be defined. Parsing as a constraint on the number of node types and associated anchor point extraction function and attribute constraints Recorded as This results in an equivalent runtime structure: ; The above runtime structure is merely an executable split of the quintuple fields and does not change the semantic definition of the template's quintuples.
[0172] For example, as mentioned above Figure 2 The diagram shows a hyperedge template. The hyperedge mode type can be denoted as... This is an inherent structural semantic label of the template. When generating a superedge based on the superedge template, the superedge can inherit this label; however, this label does not indicate that the superedge has been judged as fraudulent. The final normal / fraudulent result needs to be obtained by subsequent steps through multi-layer attention calculations on the superedge to obtain the final information of the superedge, and based on the final information, it is determined whether the superedge is an abnormal superedge involving group fraud.
[0173] Optionally, this application also provides an alternative method for hyperedge template mining: in addition to using a large language model to generate templates through prompt engineering, an end-to-end hyperedge template learning framework can be adopted to model the template generation task as a sequence-to-sequence generation task. A Transformer-based encoder-decoder architecture is used to encode historical case text and then directly decode it to generate quintuple templates. This method eliminates the need for manual prompt template design, but requires a large amount of labeled training data.
[0174] Optionally, the following specific example will be used to further illustrate the hyperedge template provided in this application.
[0175] For example, the first Each superedge template is denoted as: ; in: Indicates node type and quantity constraints; This indicates attribute constraints such as amount, card age, merchant category, and device attributes; This indicates the statistical time window corresponding to the template; This represents threshold parameters such as the number of users, the number of transactions, and the frequency of co-occurrence. This represents a function that extracts related anchors or candidate grouping keys from transaction records. Indicates the pattern semantic type of the template.
[0176] An example configuration of the "Small Merchant Shared Equipment Cash-out" template is as follows: at least three users, at least one shared device, at least one shared merchant, the merchant is a convenience store or small supermarket, the amount of a single transaction is between 300 yuan and 1,000 yuan, the users have a short card age, and the number of relevant transactions in the last 24 hours is no less than three.
[0177] Specifically, for each incoming transaction, it is determined whether to update the dynamic hypergraph. Any hyperedge in the dynamic hypergraph is generated based on multiple transaction information that conform to any hyperedge template; each hyperedge template corresponds to a hyperedge type that represents a type of gang fraud.
[0178] Optionally, determining whether to update the dynamic hypergraph for each arriving transaction includes: For each arriving transaction, perform meta-path instance matching with each superedge template in the superedge template set; If the transaction information matches any hyperedge template, determine whether there is a corresponding hyperedge in the dynamic hypergraph. If there is, update the corresponding hyperedge; if there is no hyperedge and the hyperedge generation conditions of the hyperedge template are not met, record it as a candidate hyperedge.
[0179] Alternatively, each transaction can be recorded in the following ways: Time A transaction that has arrived is recorded as:
[0180] in, , , and These represent users, merchants, devices, and IP entities, respectively. Indicates the transaction amount. Indicates the time when the transaction occurred. It indicates other transaction or entity attributes such as card age, credit limit, geographical location, and merchant category.
[0181] Optionally, template matching and candidate retrieval can be performed for newly arriving transactions: Basic attribute matching: Define a transaction Does it meet the template requirements? Indicator functions for basic attribute conditions:
[0182] when At that time, the transaction will not be entered into the template. The corresponding candidate accumulation process; when At that time, candidate grouping keys can be extracted based on the associated anchor points defined in the template.
[0183] Optional, associated anchor points and candidate grouping keys: For the "Small Merchant Shared Equipment Cash-Out" template, the combination of shared equipment and shared merchants can be used as the linking anchor:
[0184] For the same IP mode, the candidate grouping key can be an IP address or an IP range; for the same merchant mode, it can be a merchant identifier; for templates that allow multiple devices to participate, a device set, a merchant set, or a composite business identifier can also be used as the grouping key.
[0185] The associated anchor point is not a field that is uniformly fixed in the system, but rather part of the template, determined by the combination of nodes and associated semantics described by the template.
[0186] Optional, a set of candidate transactions within the time window: At the current transaction arrival time , and template and candidate grouping key The corresponding in-window transaction set is defined as follows:
[0187] "Transactions that satisfy the attribute constraints within the search time interval" refers to: Within the defined time window, the transaction records whose basic attribute conditions are true and whose associated anchor points are consistent with the current candidate group.
[0188] The system can perform partial searches using device identifiers, merchant identifiers, IP identifiers, and time indexes, without needing to rescan all historical transactions.
[0189] Optional: candidate entity set and co-occurrence frequency: Extract the set of users, devices, merchants, and IP nodes from the window transaction set:
[0190] The frequency of co-occurrence of transactions corresponding to a template can be defined as:
[0191] In other implementations, co-occurrence frequency can also be calculated based on different numbers of users, the number of transaction pairs satisfying a specified relationship, or a weighted number of transactions, for example:
[0192] in It can be determined based on the amount, risk score, or transaction confidence level.
[0193] The co-occurrence frequency threshold belongs to template parameters or template execution parameters, and can be included in... The value can be determined based on the statistical distribution of historical labeled samples, the effect of the validation set, business rules, or risk tolerance, and can be used as a hyperparameter for optimization.
[0194] Optionally, the update of the dynamic hypergraph includes temporary candidate accumulation and formal hyperedge generation: Optional, temporary candidate state: When the first or a small number of transactions meet the basic attribute conditions but have not yet reached the template's node and transaction quantity requirements, a temporary candidate state can be established:
[0195] Temporary candidates are only used to store local associations that are yet to be verified by subsequent transactions. They are not added to the dynamic hypergraph as formal hyperedges, thereby reducing erroneous edge construction caused by single or accidental transactions.
[0196] Optional, formal generation conditions for hyperedges: template The minimum requirements for the number of users and the number of transactions are denoted as follows: and Taking the shared equipment and shared merchant templates as an example, the formal generation conditions can be expressed as follows:
[0197] and:
[0198] More generally, whether a template satisfies a condition can be represented by a decision function:
[0199] when At that time, the system will convert the temporary candidate into a formal superedge.
[0200] Optionally, this application also provides a possible hyperedge data structure.
[0201] Officially generated hyperedge It can be represented as:
[0202] in: This indicates that the hyperedge contains nodes such as users, devices, merchants, and IPs. This represents the set of transactions that support the superedge; Indicates the type of superedge pattern inherited from the generated template; Indicates the creation time of the superedge; Indicates the time of recent activity; Indicates the activity of the superedge; It represents statistical characteristics such as the number of transactions, number of users, mean amount, and standard deviation of amount.
[0203] The generation of a hyperedge only indicates that a set of entities satisfies the higher-order association conditions described by a specific template, and is not equivalent to being identified as fraudulent. This candidate hyperedge still needs to undergo representation learning and probabilistic classification.
[0204] The following example will further illustrate the specific process of updating heterogeneous hypergraphs in this application.
[0205] First transaction: Establishing a temporary candidate: At 10:00 AM on May 1st, the system received a record of Li Si using device D01 to make a transaction of 500 yuan at Xingfu Convenience Store M01. The merchant category, amount, and card age of this transaction met the basic attribute conditions of the template, and the system... Create temporary candidates for the candidate grouping key.
[0206] at this time:
[0207] The superedge will not be officially generated because the conditions of at least three users and three transactions have not been met.
[0208] Second transaction: Expanding the provisional candidate: At 1:00 PM on May 1st, Wang Wu used the same device D01 to transact 800 yuan at the same merchant M01. The system retrieved the key value from the past 24 hours. The deal will add Wang Wu to the original temporary candidate list.
[0209] at this time:
[0210] The conditions for formal generation have not yet been met.
[0211] The third transaction: The superedge is officially generated.
[0212] At 2:30 PM on May 1st, Zhang San used device D01 to make a transaction of 600 yuan at merchant M01. The system retrieved three transactions from Li Si, Wang Wu, and Zhang San within the last 24 hours and confirmed that the amount, card age, shared device, and shared merchant all met the template requirements.
[0213] at this time:
[0214] The system generates hyperedges:
[0215] And record:
[0216] Optionally, there are already existing superedge retrieval, deduplication, and incremental updates: First, perform an existing hyperedge search: New transactions Upon arrival, the system constructs a superedge signature based on the template type and associated anchor points:
[0217] The signature of an existing superedge can be represented as:
[0218] in The associated anchor point used for this hyperedge. When Furthermore, when a transaction meets the member joining conditions of the template, existing hyperedges are updated first, rather than generating new hyperedges with highly repetitive content.
[0219] Optionally, another transaction can be made with the same member: If member Li Si uses device D01 to make a transaction of 700 yuan at merchant M01, the transaction set can be updated as follows:
[0220] The latest activity time has been updated to:
[0221] The number of transactions has been updated to:
[0222] The creation time of the superedge remains unchanged:
[0223] Optional, incremental update of statistical features: Let the sample size of transaction amounts before the update be . The mean is The new transaction amount is The updated mean is:
[0224] When using online variance calculation, the following can be defined:
[0225] This incremental update method does not require rescanning all historical transactions of the superedge every time.
[0226] Optional: New member addition and template constraint validation: For example, a new member expands an existing superedge: If Zhao Liu uses the same device D01 to conduct a transaction that meets the attribute conditions in the same merchant M01, then: Simultaneously, the transaction set, number of nodes, recent activity time, activity level, and statistical characteristics are updated. Dynamic superedges are not fixed after generation but can continuously expand with new members and transactions.
[0227] Same merchant but different equipment: If Qianqi transacts at merchant M01 but uses device D02, then for this template that requires shared devices:
[0228] Therefore, this transaction is not added to the original superedge, but instead enters another candidate group with the key value (D02, M01). Whether the devices must be identical is determined by the association constraints of the current template, not by a uniform rule across the entire system.
[0229] The same node participates in hyperedges of different pattern types: Assuming that Zhang San, Li Si, and Wang Wu, in addition to triggering the "Small Merchant Shared Equipment Cash-Out" template, also trigger the "Same IP New Card Concentrated Swiping" template due to using the same IP segment, having short card ages, and transaction amounts close to their credit limit, the system can generate another super-edge. .
[0230] Even if the user nodes of two super edges have the same height, they will still be retained as long as their template types are different: ; The two hyperedges respectively represent the semantics of shared devices and shared merchants, and shared IP and high-value transactions, and should not overlap. The same node is allowed to participate in multiple types of hyperedges, providing a structural foundation for cross-hyperedge context modeling, merging of similar types, and attention of different types.
[0231] Optionally, the activity level of any hyperedge in the dynamic hypergraph is not lower than a preset condition; the activity level is determined based on the latest update time of the hyperedge, wherein the more recent the update time, the higher the activity level.
[0232] Optionally, exponential decay can be used. When there are no new transactions supporting the superedge for a long period, its activity decreases smoothly over time. Let the activity after the most recent update be... At the current moment The decay activity is: ; in, This is the attenuation coefficient. It can be set separately for different template types, or it can be determined through historical data verification, business experience or model training, and used as a system hyperparameter for optimization.
[0233] The reason for choosing exponential decay is that it can continuously and smoothly reduce the influence of historical relationships, and it has memorylessness and low computational overhead. The system only needs to save the last activity level and the time of the most recent activity to calculate the current value.
[0234] Optionally, new transactions can enhance the activity of the superedge.
[0235] When new valid transactions Upon arrival, first calculate the attenuation value before arrival, then perform enhancement: , ; In the implementation of setting an activity limit, the following conditions are also met: ; in, To enhance the coefficient, The strength of support for the superedge of the trading pair can be a constant of one, or it can be determined based on the amount, risk score, or matching confidence level. This is an optional activity level cap.
[0236] Optionally, linear attenuation can also be used in other implementations: ; Alternatively, power-law decay can be used: ; Linear decay is simple to calculate, but may produce abrupt changes when reaching zero; power-law decay is suitable for describing long-term tail effects, but parameter interpretation and online maintenance are relatively complex. Exponential decay strikes a good balance between smoothness, computational efficiency, and parameter interpretability, and is therefore a preferred implementation method.
[0237] Optionally, for any hyperedge in the dynamic hypergraph, decay is performed based on a preset maximum retention time.
[0238] Optionally, when the current activity of the superedge is below the minimum retention threshold... At that time, it will be removed from the online dynamic hypergraph: ; What is eliminated is the active relationship in the current online hypergraph; there is no need to delete transaction and hyperedge records from the historical database. Historical records can still be used for model training, case review, and similar case retrieval.
[0239] To prevent sporadic transactions from repeatedly replenishing small amounts of activity and causing early super-edges to persist for an extended period, a maximum retention time can also be set. : ; The comprehensive elimination criteria can be expressed as: ; The minimum activity threshold, maximum allowable retention time, and decay coefficient are all system operating parameters or hyperparameters, which can be determined based on the historical distribution of hyperedge duration, validation set detection performance, dynamic graph size, and online computing resources.
[0240] Optionally, updates to the dynamic hypergraph can employ a local incremental graph construction mechanism: For each new transaction, the system only processes local candidate groups and local hyperedges related to the users, devices, merchants, IPs, and template-associated anchors involved in the transaction. Let the set of local hyperedges affected by the current transaction be: ; The system only supports It performs matching, updating, or decay corrections without rescanning all transactions and rebuilding the entire hypergraph at fixed intervals. This mechanism reduces the time and storage overhead of real-time graph construction and can reflect the formation, expansion, and decay of gang relationships in a timely manner.
[0241] Optionally, this application also provides an alternative method for maintaining dynamic hypergraphs: in addition to the exponential decay activity mechanism, a sliding time window mechanism can be used instead of exponential decay. Specifically, only hyperedges within the most recent T time window are retained, and hyperedges outside the window are directly removed, and activity scores are no longer maintained. This method is simpler to implement but cannot distinguish the "newness" of hyperedges within the window, and may retain inactive hyperedges that occupy resources.
[0242] Optionally, after determining the abnormal superedge containing group fraud based on the final information for each superedge, the method further includes: Based on the abnormal hyperedge, structured prompt information is constructed; the structured prompt information includes at least one of the following fields: hyperedge information, node information, transaction information, statistical features, and historical similar cases; The structured prompt information is input into the large language model to obtain the abnormal transaction information output by the large language model; the abnormal transaction information includes at least one of the following: judgment of the composition of abnormal personnel, description of abnormal transaction methods, key points of risk evidence, confidence level rating and handling suggestions.
[0243] Optionally, the anomalous transaction information output by the large language model can be an interpretable reasoning report: First, structured hints are constructed: For each suspected hyperedge h∈H_sus, five types of information can be extracted: basic hyperedge information, participating node attributes, key transaction sequences, statistical features, and historical similar cases, to construct a structured explanation hint P_explain(h). To avoid the large language model changing the classification results, the hint explicitly requires that it generate an explanation based on the given model probabilities and evidence, without re-performing numerical classification.
[0244] ; Output report It should include at least the determination of the gang's composition, a description of the modus operandi, key points of risk evidence, confidence level rating, and handling recommendations.
[0245] Optional, for Figure 2 The superedge h1 in the example is illustrated below: Gang composition assessment: Highly suspected credit card cash-out gang, with core members Zhang San, Li Si, and Wang Wu, and associated tools including iPhone-A1B2 and the merchant "Xingfu Convenience Store".
[0246] Description of the modus operandi: All three users had applied for credit cards within the last three months, and their credit limit utilization rates all exceeded 85%. Within 18 hours, they made three transactions at the same merchant using the same device, with the amounts concentrated in the range of 500-800 yuan. The merchant's transaction volume had increased abnormally in the past 30 days, and the refund rate was extremely low.
[0247] Device sharing anomaly: Three users are sharing one device, and the device has a high number of historically bound SIM cards; Abnormal merchant behavior: short-term increase in transaction volume, with orders concentrated in the early morning; Abnormal user attributes: short card age and high credit limit utilization rate; Abnormal timing: Related transactions occurred in a concentrated period of time; Structural evidence: The same batch of nodes appears simultaneously in multiple hyperedges of the device type, merchant type, or IP type.
[0248] Confidence rating: High. Recommendations: Verify account and merchant qualifications, confirm device control relationships, retrieve transaction records, and add the relevant devices and merchants to a priority monitoring list.
[0249] Optionally, the method further includes: Receive feedback information regarding the abnormal transaction information; Based on the feedback information, the abnormal superedges corresponding to the abnormal transaction information are labeled; the labeled abnormal superedges are used as abnormal sample information and input into the large language model to participate in the process of obtaining the superedge template.
[0250] Optionally, this application provides a feedback closed-loop update mechanism: For example, the review feedback stated: Risk control auditors confirm, misjudge, or label new patterns in the explanation reports and suspected boundary violations. Feedback can be expressed as:
[0251] in, For the verified, genuine label. Supplementary evidence or reasons for misjudgment by the auditor. This is an optional description of the new mode.
[0252] For example, incremental updates to the detection model: The verified positive and negative samples are added to the training queue, and the parameters of the hypergraph coding network and classifier can be incrementally updated in batches.
[0253] Where η is the learning rate. To avoid drastic model drift caused by a single new sample, mini-batch updates, experience replay, and upper limits on parameter variation can be used.
[0254] Optional: New template generation, deduplication, and database entry: When the auditor confirms that the existing template cannot fully describe the new modus operandi, and Re-encoding relevant transaction samples into template update prompts guides the large language model to generate candidate templates. Candidate templates are added to the template library after undergoing JSONSchema validation, rule conflict checks, historical sample playback testing, and manual review.
[0255] ; If a candidate template is highly similar to an existing template in terms of node type, attribute constraints, time window, and pattern semantics, the existing template should be merged or revised first, rather than being duplicated into the database.
[0256] Specifically, there are three feedback scenarios: Confirmation: The auditor confirmed that h1 was a fraudulent group and used it as a positive sample for incremental training.
[0257] Misjudgment: The auditor confirmed that the relevant users were relatives or had a normal joint payment relationship, and treated the excess edge as a negative sample to help the model distinguish between normal sharing and group fraud.
[0258] New model: When auditors discover behaviors not covered by existing templates, such as "controlling multiple devices through remote assistance software to cash out in bulk", new template candidates are generated.
[0259] Optionally, any super-edge template is obtained by using a large language model based on the historical abnormal transaction information and risk control rule information of the input, and the labeled abnormal sample information.
[0260] Optionally, the beneficial effects of this application include: automatic construction and closed-loop evolution capabilities of hyperedge templates: by jointly summarizing historical fraud cases, risk control rules and labeled gang samples through a large language model, unstructured fraud knowledge is converted into structured, verifiable and executable heterogeneous hyperedge templates; the review feedback can continue to correct existing templates or trigger the generation of new templates, thereby improving the template library's adaptability to new fraud patterns and concept drift.
[0261] Real-time modeling capability of high-order relationships for streaming transactions: Incremental matching is performed on local nodes and local hyperedges involved in new transactions through template-defined node combinations, relationship anchors, attribute constraints, time windows and co-occurrence thresholds, without the need to repeatedly rebuild the entire graph; Through member expansion, repetition suppression, activity decay and life cycle elimination, dynamic hypergraphs can continuously express the generation, enhancement, expansion and decay of group relationships, and explicitly represent the high-order collaborative behavior of multiple entities that is difficult to fully describe by ordinary binary graphs.
[0262] The instance-type dual-granularity risk representation capability consists of three layers: the first layer identifies key members and temporal behaviors within a single hyperedge; the second layer filters important specific relationships across all belonging hyperedges; and the third layer merges hyperedges of the same type and compares the contributions of different pattern types. This mechanism can suppress aggregation bias caused by repetitive evidence of the same type and imbalances in the number of types, while retaining key instance evidence and cross-pattern complementary information, thus improving the discriminative and interpretable nature of group risk representation.
[0263] Structured interpretability and human-machine collaboration capabilities: The node-level, instance-level, and type-level attention weights output in step S3 can serve as risk evidence. Step S5 further converts the topological structure, node attributes, key transaction sequences, and statistical features of the suspected superedge into structured prompts that can be understood by the large language model, generating gang composition, modus operandi, risk evidence, and disposal suggestions, reducing the cost for reviewers to understand numerical detection results.
[0264] Balancing real-time performance, data privacy, and computational efficiency: The online main pipeline only performs local incremental graph construction, sparse hypergraph attention, and lightweight classification computation; the large language model is deployed locally and is mainly used for low-frequency processes such as template mining and interpretation generation. This reduces the risk of leakage of sensitive financial data while avoiding the impact of large model inference on the response speed of the transaction detection main pipeline.
[0265] Based on the same technical concept, this application provides an abnormal transaction detection device. Figure 4 This is a schematic diagram of the structure of an abnormal transaction detection device provided for some embodiments of this application. For example... Figure 4 As shown, the device includes: The judgment module 401 is used to determine whether to update the dynamic hypergraph for each incoming transaction information. Any hyperedge in the dynamic hypergraph is generated based on multiple transaction information that conform to any hyperedge template. Each hyperedge template corresponds to a hyperedge type that represents a type of gang fraud. The calculation module 402 is configured to perform intra-edge attention calculation for each node contained within any hyperedge in the dynamic hypergraph, to obtain intermediate hyperedge information of the hyperedge; the intermediate hyperedge information represents the influence of each node on the hyperedge; for each node in the dynamic hypergraph, perform inter-edge and node attention calculation based on the intermediate hyperedge information of different hyperedges to which the node belongs, and obtain intermediate node information of the node based on the different hyperedges to which the node belongs; any intermediate node information represents the influence of different hyperedges under which the node belongs on the node; based on the intermediate node information of each node and the type of hyperedge to which the node belongs, obtain the type node information of the node under each hyperedge type; based on the type node information of the node under different hyperedge types, perform fusion attention calculation to obtain the final information of the node; The identification module 403 is used to identify abnormal superedges with gang fraud based on the final information of each superedge.
[0266] Optionally, the calculation module 402 is specifically used to take the final information of each node of the hyperedge as the initial information, and re-perform the hyperedge intra-attention calculation, hyperedge and node inter-attention calculation, and fusion attention calculation until the final information of the hyperedge that meets the requirements is obtained.
[0267] Optionally, the calculation module 402 is specifically used to obtain relative time codes with different time scales for each node contained within the hyperedge, based on the time information of the hyperedge and the time information of the node; wherein, the time information of the hyperedge is the latest update time of the hyperedge, and the time information of the node is the transaction time of the latest transaction corresponding to the node; based on the initial information of each node and the relative time code, perform hyperedge attention calculation with the initial information of the hyperedge to obtain the intermediate hyperedge information of the hyperedge.
[0268] Optionally, the activity level of any hyperedge in the dynamic hypergraph is not lower than a preset condition; the activity level is determined based on the latest update time of the hyperedge, wherein the more recent the update time, the higher the activity level.
[0269] Optionally, the judgment module 401 is specifically used to perform meta-path instance matching with each superedge template in the superedge template set for each arriving transaction information; if the transaction information is successfully matched with any superedge template, determine whether there is a corresponding superedge in the dynamic supergraph; if there is, update the corresponding superedge; if there is no superedge and the superedge generation condition of the superedge template is not met, record it as a candidate superedge.
[0270] Optionally, each hyperedge template in the hyperedge template set adopts a quintuple structure, including: node type, attribute constraint, time window, co-occurrence frequency, and hyperedge type; The successful matching of the transaction information with any superedge template includes: if the transaction information satisfies the node type and attribute constraints of any superedge template, then it is determined that the transaction information is successfully matched with the superedge template; any superedge is determined based on the node type and the attribute constraints. The conditions for generating a superedge that satisfy the superedge template include: determining whether the time window and co-occurrence frequency of the superedge template are satisfied based on the transaction information and the recorded candidate superedges.
[0271] Optionally, the calculation module 402 is further configured to attenuate any hyperedge in the dynamic hypergraph based on a preset maximum retention time.
[0272] Optionally, any super-edge template is obtained by using a large language model based on the historical abnormal transaction information and risk control rule information of the input, and the labeled abnormal sample information.
[0273] Optionally, the device further includes: An analysis module is used to construct structured prompt information based on the abnormal hyperedge; the structured prompt information includes at least one of the following fields: hyperedge information, node information, transaction information, statistical features, and historical similar cases; the structured prompt information is input into a large language model to obtain abnormal transaction information output by the large language model; the abnormal transaction information includes at least one of the following: judgment of abnormal personnel composition, description of abnormal transaction methods, key points of risk evidence, confidence rating, and handling suggestions.
[0274] Optionally, the device further includes: The feedback module is also used to receive feedback information regarding the abnormal transaction information; based on the feedback information, to label the abnormal superedges corresponding to the abnormal transaction information; and to input the labeled abnormal superedges as abnormal sample information into the large language model to participate in the process of obtaining the superedge template.
[0275] Based on the same concept, this application also provides a computer-readable storage medium storing a computer program executable by a processor, which, when run on a processor, causes the processor to execute the steps included in any of the abnormal transaction detection methods described in the above embodiments.
[0276] The aforementioned computer-readable storage medium can be any available medium or data storage device that can be accessed by the processor in an electronic device, including but not limited to magnetic storage such as floppy disks, hard disks, magnetic tapes, magneto-optical disks (MO), optical storage such as CDs, DVDs, BDs, HVDs, etc., and semiconductor storage such as ROMs, EPROMs, EEPROMs, non-volatile memory (NAND flash), solid-state drives (SSDs), etc.
[0277] Based on the same technical concept, optionally, embodiments of this application also provide an electronic device that can realize the function of the abnormal transaction detection device described above. Figure 5 This is a schematic diagram of the structure of an electronic device provided for some embodiments of this application. For example... Figure 5 As shown, the electronic device includes: a processor 501, a communication interface 502, a memory 503, and a communication bus 504, wherein the processor 501, the communication interface 502, and the memory 503 communicate with each other through the communication bus 504. The memory 503 stores a computer program, which, when executed by the processor 501, causes the processor 501 to perform the steps included in any of the abnormal transaction detection methods described in the above embodiments.
[0278] The communication bus mentioned in the above electronic devices can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. This communication bus can be divided into address bus, data bus, control bus, etc. For ease of illustration, only one thick line is used to represent it in the diagram, but this does not mean that there is only one bus or one type of bus.
[0279] Communication interface 502 is used for communication between the above-mentioned electronic device and other devices.
[0280] The memory may include random access memory (RAM) or non-volatile memory (NVM), such as at least one disk storage device. Optionally, the memory may also be at least one storage device located remotely from the aforementioned processor.
[0281] The processors mentioned above can be general-purpose processors, including central processing units, network processors (NPs), etc.; they can also be digital signal processors (DSPs), application-specific integrated circuits, field-programmable gate arrays or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc.
[0282] Based on the same inventive concept, this application also provides a computer program product, which includes computer program code. When the computer program code is run on a computer, it causes the computer to perform the steps of any of the abnormal transaction detection methods described above. Since the principle by which the above computer program product solves the problem is similar to that of the above abnormal transaction detection method, the implementation of the above computer program product can refer to the implementation of the method, and repeated details will not be described again.
[0283] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0284] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to this application. It should be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0285] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0286] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0287] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the spirit and scope of this application. Therefore, if such modifications and variations fall within the scope of the claims of this application and their equivalents, this application also intends to include such modifications and variations.
Claims
1. An abnormal transaction detection method, characterized in that, The method includes: For each incoming transaction, determine whether to update the dynamic hypergraph. Any hyperedge in the dynamic hypergraph is generated based on multiple transaction information that conform to any hyperedge template. Each hyperedge template corresponds to a hyperedge type that represents a type of gang fraud. For any hyperedge in the dynamic hypergraph, perform hyperedge attention calculation on each node contained within the hyperedge to obtain the intermediate hyperedge information of the hyperedge; the intermediate hyperedge information represents the influence of each node on the hyperedge; For each node in the dynamic hypergraph, attention between hyperedges and nodes is calculated based on the intermediate hyperedge information of the different hyperedges to which the node belongs, and intermediate node information of the node is obtained based on the different hyperedges to which the node belongs; any intermediate node information represents the influence of different hyperedges on the node under its own hyperedge. Based on the intermediate node information of each node and the hyperedge type to which the node belongs, the type node information of the node under each hyperedge type is obtained; based on the type node information of the node under different hyperedge types, fusion attention calculation is performed to obtain the final information of the node; The final information of the hyperedge is determined based on the final information of each node of the hyperedge; For each superedge, the final information identifies abnormal superedges where group fraud exists.
2. The method according to claim 1, characterized in that, Determining the final information of the hyperedge based on the final information of each node of the hyperedge includes: Using the final information of each node in the hyperedge as the initial information, we recalculate the attention within the hyperedge, the attention between the hyperedge and the nodes, and the fusion attention until we obtain the final information of the hyperedge that meets the requirements.
3. The method according to claim 1, characterized in that, The step of performing attention calculations within each node contained in the hyperedge to obtain the intermediate hyperedge information includes: For each node contained within the hyperedge, relative time codes with different time scales are obtained based on the time information of the hyperedge and the time information of the node; wherein, the time information of the hyperedge is the latest update time of the hyperedge, and the time information of the node is the transaction time of the latest transaction corresponding to the node; Based on the initial information and relative time encoding of each node, the hyperedge attention is calculated with the initial information of the hyperedge to obtain the intermediate hyperedge information.
4. The method according to claim 1, characterized in that, The activity level of any hyperedge in the dynamic hypergraph is not lower than a preset condition; the activity level is determined based on the latest update time of the hyperedge, wherein the more recent the update time, the higher the activity level.
5. The method according to claim 1, characterized in that, For each arriving transaction, determining whether to update the dynamic hypergraph includes: For each arriving transaction, perform meta-path instance matching with each superedge template in the superedge template set; If the transaction information matches any hyperedge template, determine whether there is a corresponding hyperedge in the dynamic hypergraph. If there is, update the corresponding hyperedge; if there is no hyperedge and the hyperedge generation conditions of the hyperedge template are not met, record it as a candidate hyperedge.
6. The method according to claim 5, characterized in that, Each hyperedge template in the hyperedge template set adopts a quintuple structure, including: node type, attribute constraint, time window, co-occurrence frequency, and hyperedge type; The transaction information successfully matches any hyperedge template, including: If the transaction information satisfies the node type and attribute constraints of any superedge template, then the transaction information is determined to be a successful match with the superedge template; any superedge is determined based on the node type and the attribute constraints. The conditions for generating the superedge that satisfy the superedge template include: Based on the transaction information and the recorded candidate superedges, determine whether the time window and co-occurrence frequency of the superedge template are satisfied.
7. The method according to claim 1, characterized in that, For any hyperedge in the dynamic hypergraph, decay is performed based on a preset maximum retention time.
8. The method according to any one of claims 1-7, characterized in that, Any super-edge template is obtained by using a large language model based on the historical abnormal transaction information and risk control rule information of the input, and the labeled abnormal sample information.
9. The method according to claim 1, characterized in that, After determining the abnormal superedges containing group fraud based on the final information for each superedge, the process also includes: Based on the abnormal hyperedge, structured prompt information is constructed; the structured prompt information includes at least one of the following fields: hyperedge information, node information, transaction information, statistical features, and historical similar cases; The structured prompt information is input into the large language model to obtain the abnormal transaction information output by the large language model; the abnormal transaction information includes at least one of the following: judgment of the composition of abnormal personnel, description of abnormal transaction methods, key points of risk evidence, confidence level rating and handling suggestions.
10. The method according to any one of claims 1-9, characterized in that, The method further includes: Receive feedback information regarding the abnormal transaction information; Based on the feedback information, the abnormal superedges corresponding to the abnormal transaction information are labeled; the labeled abnormal superedges are used as abnormal sample information and input into the large language model to participate in the process of obtaining the superedge template.