Financial transaction risk identification method for digital economy
Patent Information
- Application Number
- CN202611264607.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-08-20
- Publication Date
- 2026-09-22
AI Technical Summary
[0007]本发明的目的在于克服现有技术的缺点,解决现有技术在处理复杂金融交易时计算开销大、高频噪声干扰导致误报率上升以及缺乏轻量级超低延迟环境动态防御的技术问题,提供一种面向数字经济的金融交易风险识别方法
1、通过相邻交易时间差调整动态拓扑权重参数,并在图神经网络模型中执行一阶邻域特征聚合计算,使聚合结果能够同时反映交易发生的紧密程度和多向资金流转关系,系统无需增加图网络的搜索层数和采样规模,即可生成能够表征交易主体节点行为特征的特征收敛状态向量,从而减少多层图卷积带来的迭代计算开销,缩短金融交易风险识别的处理时间,满足分布式清算场景下的实时响应要求。
Smart Images

Figure CN122798534A_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of core financial risk control and distributed clearing data processing technology, and relates to a method for identifying financial transaction risks in the digital economy. Background Technology
[0002] Currently, using big data and artificial intelligence models for real-time risk identification and control of financial transactions has become a common technical means in the fintech field. However, in complex financial transaction scenarios, existing technologies still have certain limitations in verifying the correlation between transaction time and transaction relationships, handling samples with extremely unbalanced categories, and providing security protection when the transaction environment is tampered with or interfered with.
[0003] First, in existing risk control systems that use transaction relationship graphs to process transaction data, there are significant shortcomings in system response speed and feature aggregation of different types of transaction relationships. For example, Chinese invention patent application CN112396160A discloses a transaction fraud detection method and system based on graph neural networks. This method extracts transaction time-series features through long short-term memory networks and uses multi-layer graph convolutional networks to propagate the features of adjacent nodes layer by layer. Since this method requires multi-layer and multi-level propagation in the graph, it will generate a large iterative computational overhead in the distributed clearing scenario with short latency and high concurrency, making it difficult to meet the millisecond-level real-time processing requirements of clearing transactions.
[0004] Second, Chinese invention patent application CN118211970A discloses a method for detecting fraudulent transaction accounts based on heterogeneous graph convolutional networks. This method calculates the degree of conflict in time and space of transactions based on device fingerprints and orientation vectors. However, it requires the client to provide complete multi-source environmental features. In highly decentralized or strictly secure financial core distributed clearing environments, it is often difficult to obtain data on the client's external environment. If complex entropy calculations are still performed on external environmental data in the core computing stage, it is easy to cause data congestion. Therefore, under the condition of using only streaming transaction flow data, this method is difficult to quickly complete the aggregation of transaction relationship features within the first-order neighborhood.
[0005] Third, Chinese invention patent application CN120807150A discloses a method for real-time risk identification of financial transactions based on multi-source heterogeneous data. This method calculates the spatial conflict level by utilizing the degree of overlap between external environmental tampering risk points and dynamic risk maps. However, it is also limited by the real-time interaction capability of multi-source heterogeneous data under strict security isolation conditions. In a closed operating environment that only uses high-frequency transaction flow data from a single source, this method is difficult to adaptively calibrate statistical deviations according to changes in transaction time and transaction relationships. The dependence on external data links also brings communication delays, which in turn cause a lag in risk interception.
[0006] Therefore, existing financial transaction risk identification technologies still need to analyze the time relationships, transaction relationships and their changing characteristics of transaction data from different sources and of different types, while adopting a dynamic risk protection method with lower computational load and lower response latency, and ensuring that risk judgment takes into account accuracy, low latency and the existing security isolation boundaries of the financial core system throughout the entire processing cycle. This is the technical problem that this invention aims to solve. Summary of the Invention
[0007] The purpose of this invention is to overcome the shortcomings of the prior art, solve the technical problems of high computational overhead, high-frequency noise interference leading to increased false alarm rate, and lack of lightweight ultra-low latency dynamic defense when processing complex financial transactions, and provide a financial transaction risk identification method for the digital economy.
[0008] To achieve the above-mentioned objectives, this invention provides a method for identifying financial transaction risks in the digital economy, comprising the following steps: Step S101, parse the transaction data to extract the subject identifier and adjacent timestamps: obtain the financial transaction data packet, and extract the transaction subject identifier and adjacent transaction timestamps contained in the financial transaction data packet; Step S102, construct graph nodes according to fund flow to generate static strength value: convert the transaction entity identifier into transaction entity node, construct directed connection edge according to fund flow, and count the cumulative transaction frequency of the transaction entity nodes at both ends of the directed connection edge in the historical window to generate static transaction strength value. Step S103, generating dynamic topology weights based on time difference triggering control flow: calculate the time difference between adjacent transaction timestamps, use the adjacent transaction time difference to trigger conditional control flow based on transaction settlement time limit, adjust the static transaction strength value to generate dynamic topology weight parameters, and limit sudden transaction disturbances to the local memory range of the active cache graph; Step S104, Aggregate first-order neighborhood features to generate feature convergence state vector: Use dynamic topological weight parameters as weighting factors, call the first-order neighborhood feature aggregation calculation in the graph neural network model to generate feature convergence state vector representing the behavior characteristics of the transaction subject node. Step S105, calibrate the feature convergence state vector based on the global residual ratio: perform linear fine-tuning of the dynamic topology weight parameters based on the global statistical residual ratio of the directed association graph at the current time, so as to calibrate the feature convergence state vector in situ. Step S106, Calculate the sum of squared differences of vector differences to generate an abnormal deviation value: Calculate the sum of squared discrete differences between the feature convergence state vector and the preset compliance benchmark feature vector in the memory dictionary to generate an abnormal deviation value. Step S107: Map deviation to generate risk score and send it to risk control module: Use a monotonically increasing mapping function to project abnormal deviation values to a fixed number axis range to generate a quantitative risk score, and send the quantitative risk score as a control command to the risk control response module.
[0009] Step S103 of the present invention includes the following sub-steps: Step S1031, if the time difference between adjacent transactions is not greater than 200ms, calculate the expansion coefficient based on the ratio of 200ms to the time difference between adjacent transactions, and multiply the static transaction intensity value by the expansion coefficient to generate dynamic topology weight parameters; Step S1032, if the time difference between adjacent transactions is greater than 200ms and not greater than 1000ms, calculate the attenuation ratio based on the difference between the time difference between adjacent transactions and 200ms, and lower the static transaction intensity value according to the attenuation ratio to generate dynamic topology weight parameters.
[0010] Step S103 of the present invention includes the following sub-steps: Step S1033, if the time difference between adjacent transactions is greater than 1000ms, a truncation control instruction is generated to cut off the logical transmission path that exceeds the time limit; Step S1034, in the state where the logical transmission path is cut off, the sudden transaction disturbance is isolated in the local memory range of the active cache graph, and the historical association base graph is updated asynchronously and non-blockingly using the background memory pool.
[0011] The step S103 of the present invention, which restricts sudden transaction disturbances to the local memory range of the active cache graph, includes the following sub-steps: Step S1035, calling the first-order feature accumulation function of the active cache graph to sum and accumulate the node status in the newly input financial transaction flow data packet with the first-order neighborhood features in the active cache graph, so as to update the local memory node features of the active cache graph in situ.
[0012] The asynchronous non-blocking update of the historical associated base map using the background memory pool in step S1034 of the present invention includes the following sub-steps: Step S10341, the cut transaction data is isolated to an independent data queue, and the asynchronous update function is called in the background memory pool to merge the data in the independent data queue into the historical associated base map.
[0013] The step S104 of the present invention includes the following sub-steps: Step S1041, retrieve the set of transaction subject nodes, identify the heterogeneous association edge types between different transaction subject nodes, and call the type weight matrix to perform weighted calculation on the first-order directed neighborhood features, and generate the feature convergence state vector through graph convolution aggregation operation.
[0014] Step S107 of the present invention includes the following sub-steps: Step S1071, compare the quantitative risk score with the graded risk threshold, and trigger the corresponding level of risk interception signal when the quantitative risk score exceeds the graded risk threshold to drive the risk control response module to close the transaction interface.
[0015] In the context of generating feature convergence state vectors, the present invention further includes the following steps: Step S108, continuously recording the historical evolution sequence of feature convergence state vectors within a continuous time period, calculating the rate of change of the historical evolution sequence over time to generate a trend quantification index, and triggering a risk warning signal when the trend quantification index continuously exceeds the calibration threshold.
[0016] The compliance behavior feature rule matrix described in this invention further includes the following steps: Step S109, obtaining the compliance audit results from external feedback, and correcting the compliance benchmark feature vector based on the compliance audit results.
[0017] Compared with the prior art, the present invention has at least the following beneficial effects: 1. By adjusting the dynamic topology weight parameters through the time difference between adjacent transactions and performing first-order neighborhood feature aggregation calculation in the graph neural network model, the aggregation result can simultaneously reflect the closeness of the transaction and the multi-directional capital flow relationship. The system can generate feature convergence state vectors that can characterize the behavior characteristics of the transaction subject nodes without increasing the number of search layers and sampling scale of the graph network. This reduces the iterative calculation overhead caused by multi-layer graph convolution, shortens the processing time for financial transaction risk identification, and meets the real-time response requirements in distributed clearing scenarios.
[0018] 2. The dynamic topology weight parameter can be adjusted according to the time difference between adjacent transactions to regulate high-frequency trading behavior. When abnormal transactions weaken the characteristics of a single transaction by splitting and transferring multiple nodes in a short period of time, this adjustment can make the deviation of abnormal behavior in the feature convergence state vector more obvious and widen the numerical difference between it and the compliance benchmark feature vector. Therefore, the abnormal transfer features hidden in high-frequency split transactions are easier to identify. At the same time, it can avoid the abnormal features being overly weakened during the aggregation process and improve the stability of transaction relationship features under complex interference conditions.
[0019] 3. By truncating control commands to cut off logical transmission paths exceeding the time limit, and by having the active cache graph and the historical associated base graph handle real-time processing and historical data updates respectively, sudden surges in high-concurrency transactions can limit the sudden transaction disturbances to a local memory range. The background memory pool performs asynchronous non-blocking updates to the historical associated base graph, which will not block the processing of subsequent financial transaction flow data packets, thereby avoiding the chain update of network features caused by local disturbances. While maintaining the risk control response speed, it also maintains the continuity of historical transaction data updates and the stability of the overall processing. Attached Figure Description
[0020] Figure 1 This is a schematic diagram of the transaction risk identification steps of the present invention; Figure 2 This is a schematic diagram of the characteristic index curve of the adjustment state of the present invention. Detailed Implementation
[0021] The technical solution of the present invention will be clearly and completely described below with reference to the embodiments and accompanying drawings.
[0022] Example 1: This embodiment discloses a method for identifying financial transaction risks in the digital economy, including the following steps: Step S101, parse the transaction data to extract the subject identifier and adjacent timestamps: obtain the financial transaction data packet, and extract the transaction subject identifier and adjacent transaction timestamps contained in the financial transaction data packet; Step S102, construct graph nodes according to fund flow to generate static strength value: convert the transaction entity identifier into transaction entity node, construct directed connection edge according to fund flow, and count the cumulative transaction frequency of the transaction entity nodes at both ends of the directed connection edge in the historical window to generate static transaction strength value. Step S103, generating dynamic topology weights based on time difference triggering control flow: calculate the time difference between adjacent transaction timestamps, use the adjacent transaction time difference to trigger conditional control flow based on transaction settlement time limit, adjust the static transaction strength value to generate dynamic topology weight parameters, and limit sudden transaction disturbances to the local memory range of the active cache graph; Step S104, Aggregate first-order neighborhood features to generate feature convergence state vector: Use dynamic topological weight parameters as weighting factors, call the first-order neighborhood feature aggregation calculation in the graph neural network model to generate feature convergence state vector representing the behavior characteristics of the transaction subject node. Step S105, calibrate the feature convergence state vector based on the global residual ratio: perform linear fine-tuning of the dynamic topology weight parameters based on the global statistical residual ratio of the directed association graph at the current time, so as to calibrate the feature convergence state vector in situ. Step S106, Calculate the sum of squared differences of vector differences to generate an abnormal deviation value: Calculate the sum of squared discrete differences between the feature convergence state vector and the preset compliance benchmark feature vector in the memory dictionary to generate an abnormal deviation value. Step S107: Map deviation to generate risk score and send it to risk control module: Use a monotonically increasing mapping function to project abnormal deviation values to a fixed number axis range to generate a quantitative risk score, and send the quantitative risk score as a control command to the risk control response module.
[0023] Step S103 in this embodiment includes the following sub-steps: Step S1031, if the time difference between adjacent transactions is not greater than 200ms, calculate the expansion coefficient based on the ratio of 200ms to the time difference between adjacent transactions, and multiply the static transaction intensity value by the expansion coefficient to generate dynamic topology weight parameters; Step S1032, if the time difference between adjacent transactions is greater than 200ms and not greater than 1000ms, calculate the attenuation ratio based on the difference between the time difference between adjacent transactions and 200ms, and lower the static transaction intensity value according to the attenuation ratio to generate dynamic topology weight parameters.
[0024] Step S103 in this embodiment includes the following sub-steps: Step S1033, if the time difference between adjacent transactions is greater than 1000ms, a truncation control instruction is generated to cut off the logical transmission path that exceeds the time limit; Step S1034, in the state where the logical transmission path is cut off, the sudden transaction disturbance is isolated in the local memory range of the active cache graph, and the historical association base graph is updated asynchronously and non-blockingly using the background memory pool.
[0025] In this embodiment, step S103, which restricts sudden transaction disturbances to the local memory range of the active cache graph, includes the following sub-steps: Step S1035, calling the first-order feature accumulation function of the active cache graph to sum and accumulate the node status in the newly input financial transaction data packet with the first-order neighborhood features in the active cache graph, so as to update the local memory node features of the active cache graph in situ.
[0026] In this embodiment, step S1034, which uses the background memory pool to asynchronously and non-blockingly update the historical associated base map, includes the following sub-steps: Step S10341, the severed transaction data is isolated to an independent data queue, and the asynchronous update function is called in the background memory pool to merge the data in the independent data queue into the historical associated base map.
[0027] Step S104 in this embodiment includes the following sub-steps: Step S1041, retrieve the set of transaction subject nodes, identify the heterogeneous association edge types between different transaction subject nodes, and call the type weight matrix to perform weighted calculation on the first-order directed neighborhood features, and generate the feature convergence state vector through graph convolution aggregation operation.
[0028] Step S107 in this embodiment includes the following sub-steps: Step S1071, compare the quantitative risk score with the graded risk threshold, and trigger the corresponding level of risk interception signal when the quantitative risk score exceeds the graded risk threshold to drive the risk control response module to close the transaction interface.
[0029] In the context of generating feature convergence state vectors as described in this embodiment, the following steps are also included: Step S108, continuously record the historical evolution sequence of feature convergence state vectors within a continuous time period, calculate the rate of change of the historical evolution sequence over time to generate a trend quantification index, and trigger a risk warning signal when the trend quantification index continuously exceeds the calibration threshold.
[0030] The compliance behavior feature rule matrix described in this embodiment also includes the following steps: Step S109, obtaining the compliance audit results from external feedback, and correcting the compliance benchmark feature vector based on the compliance audit results.
[0031] Example 2: In this embodiment, the distributed clearing network continuously receives financial transaction data packets input in a streaming manner. Some abnormal transaction entities utilize multiple related accounts to form nested directed flow structures, and employ short-term multi-directional flow and multi-node fund splitting methods to make the abnormal transaction characteristics resemble high-frequency normal business distribution. When the clearing system processes massive amounts of data, if a correspondence between clearing latency and topological correlation strength is not established, the computational overhead of graph operations will increase with search depth, causing the clearing transaction processing latency to exceed the preset millisecond-level response requirement. The data processing module receives financial transaction data packets at the account clearing boundary and calls the secure distributed clearing network to process them. The SHA-256 algorithm is used to anonymize the original transaction entity identifiers, generating globally unique encrypted tokens. These tokens are then used as the transaction entity identifiers. Subsequently, each transaction entity identifier is converted into a transaction entity node. Directed connections are constructed between these nodes according to the flow of funds. The cumulative transaction frequency and single settlement amount of the transaction entity nodes at both ends of the directed connection within the historical window are counted. The static transaction strength value is obtained by multiplying these two values, and this static transaction strength value is written into the local storage feature array of the corresponding directed connection as the initial spatial feature parameter.
[0032] The initial temporal feature vector of the transaction entity node is composed of multi-dimensional basic statistical features from the financial transaction flow data packet. These basic statistical features include the maximum single transaction amount, the average transaction frequency within the past hour, the device terminal type code, and the geographical location span index. The data processing module performs maximum and minimum value normalization on the above discrete values, converting them into a dense numerical matrix conforming to a standard Gaussian distribution, and generates a dense embedded feature vector with a fixed dimension of 64 dimensions. This vector serves as the initial state input for the transaction entity node. This initial temporal feature vector is written into the distributed cache area of the ledger clearing boundary during the system initialization phase, and is called by the graph neural network model when performing first-order neighborhood feature aggregation calculations. The data processing module extracts the latest transaction timestamp on the current directed connection edge in chronological order and reads the adjacent preceding transaction timestamps from the locally stored feature array. Let the latest transaction timestamp be... The previous transaction timestamp is ,in, and These represent the transaction entity nodes at both ends of the directed connection edge. The time difference between adjacent transactions represents the sequence number of the current transaction on the directed connection edge. for: When the time difference between adjacent transactions is no greater than 200ms, the conditional control flow enters the expansion branch, assuming the static transaction strength value corresponding to the connecting edge is... The coefficient of thermal expansion is The dynamic topology weight parameters are Then calculate according to the following formula: When the time difference between adjacent transactions is greater than 200ms but not greater than 1000ms, the conditional control flow enters the decay branch.
[0033] The attenuation ratio is defined as the proportion of the difference between adjacent transaction times and 200ms to the width of the 200ms to 1000ms interval. Let the attenuation ratio be... Then, the static transaction intensity value will be reduced according to the following formula: When the time difference between adjacent transactions exceeds 1000ms, the data processing module generates a truncation control command, sets the corresponding dynamic topology weight parameter to 0, cuts off the logical transmission path exceeding the time limit, and isolates the sudden transaction disturbance in the local memory range of the active cache graph. The cut-off transaction data is written to an independent data queue. After the foreground processing thread completes the writing, it continues to process subsequent financial transaction flow data packets without waiting for the historical correlation base map to be updated. The background memory pool calls the asynchronous update function to read the transaction data in the independent data queue in turn and merge it into the historical correlation base map. The historical correlation base map uses a 3600s historical observation window to store transaction data for long-term statistics. This historical observation window is only used to limit the merging range of background data and is not used as a truncation condition for logical transmission paths.
[0034] To update the local memory node features in the active cache graph in situ, a one-hot encoder and a linear projection layer are set at the data input end. The transaction entity identifier and adjacent transaction timestamps in the financial transaction log data packet are converted into high-dimensional sparse state vectors by the one-hot encoder, and then input into a preset linear projection matrix for dimensional compression and spatial alignment, resulting in 64-dimensional node states with the same dimension as the node features in the active cache graph. Subsequently, the first-order feature accumulation function of the active cache graph is called to sum the node state element-wise with the first-order neighborhood features of the corresponding transaction entity node, and the summation result is written back to the original local memory address. After receiving the update, the graph neural network model... The current directed graph is defined, and the graph convolutional search depth is limited to first order. The heterogeneous connection edge types in the transaction entity node set are divided into three categories according to the fund transfer business attributes: bank card to bank card clearing edge, third party to bank card recharge edge, and corporate account to personal account settlement edge. The type weight matrix is a 3×3 symmetric mapping matrix, and its matrix elements represent the interaction impedance coefficient between different heterogeneous connection edge types. It is initialized according to the clearing failure probability of each type of directed connection edge in the historical window. When performing the weighted calculation of the first-order directed neighborhood features, the graph neural network model first groups the first-order directed neighborhood features according to the heterogeneous connection edge type.
[0035] Let the current transaction entity node be , No. The set of first-order directed neighbors corresponding to heterogeneous association edges is Neighboring transaction entity nodes The initial time series feature vector is Then, the initial temporal feature vectors of each neighboring transaction entity node of the same type are multiplied by the dynamic topology weight parameters and summed to obtain the type feature matrix. The OK : , characteristic matrix The dimension is 3×64, and the graph neural network model uses a 3×3 type weight matrix. Left multiplication of type feature matrix Then, sum the three rows of the resulting matrix along the heterogeneous associative edge type direction to obtain the type-weighted first-order directed neighborhood features. : Let the initial temporal feature vector of the current transaction entity node be... The normalized component corresponding to its in-degree is The feature convergence state vector is Then the graph convolution aggregation operation is performed according to the following formula: The static transaction strength value of the directed connection edge retains the cumulative transaction frequency and settlement amount information within the historical window, while the dynamic topology weight parameter changes with the time difference between adjacent transactions. Therefore, when the graph neural network model performs first-order neighborhood feature aggregation calculation, the weight parameter read simultaneously includes the current transaction time sequence features and historical transaction statistical features, thereby forming the feature convergence state vector of the transaction subject node within the first-order search range.
[0036] At the settlement boundary of each calculation cycle, the data processing module calculates the residual of the characteristic convergence state vector of each transaction entity node relative to the previous calculation cycle, and statistically analyzes the residuals of all transaction entity nodes to obtain the statistical value of the network-wide residuals for the current cycle. Simultaneously, read the continuous data before the current processing time from the historical correlation base map. Calculate the expected value of the network residual statistics for each calculation period. The global statistical residual ratio of the directed correlation graph at the current moment. Calculate according to the following formula: Let the feedback compensation constant be... The dynamic topology weight parameters before calibration are: The calibrated dynamic topology weight parameters are Then, the dynamic topology weight parameters are finely adjusted linearly: After completing linear fine-tuning, only the transaction entity nodes affected by weight changes are re-performed with first-order neighborhood feature aggregation calculation, and the recalculated feature convergence state vector is written to the original storage location to complete the in-situ calibration of the feature convergence state vector; the risk audit unit extracts the template components corresponding to the average compliant transaction rate and the settlement difference ratio from the compliant behavior feature rule matrix pre-set in the memory dictionary to form the compliance benchmark feature vector, assuming the current transaction entity node The characteristic convergence state vector in the th The eigenvalues of dimension are The compliance benchmark feature vector is in the th The template component value of dimension is The total dimension of the features is The abnormal deviation value is The anomaly deviation value is then calculated by summing the squares of the discrete differences in each dimension: In this embodiment, the total number of feature dimensions is... The scoring and mapping module receives the abnormal deviation value, calls a monotonically increasing mapping function for centering and scaling, and then projects the abnormal deviation value onto a fixed number axis range of 0 to 100 through Sigmoid mapping and full-scale linear adjustment to generate a quantitative risk score. The memory dictionary also stores graded risk thresholds corresponding to different risk levels, where 85 is the safety red line threshold corresponding to the high-risk level. The scoring and mapping module compares the quantitative risk score with the graded risk thresholds in turn. When the quantitative risk score exceeds the graded risk threshold corresponding to a certain level, a risk interception signal for that level is generated. The quantitative risk score and the risk interception signal are used as control commands and sent to the risk control response module through the high-speed data bus. Under the condition that the data processing latency is 12ms to 15ms, when the quantitative risk score is greater than 85, the risk control response module receives the high-risk level risk interception signal and closes the trading interface corresponding to the target trading entity.
[0037] Example 3: In this embodiment, the streaming electronic transaction test platform imports a standardized open clearing flow dataset containing 1,000,000 account records. Gaussian white noise with a signal-to-noise ratio of 20dB and power frequency interference harmonics at a frequency of 50Hz are superimposed on the directed connection edge signal at the input end to simulate the clearing operation condition where high-frequency splitting and transfer behavior is mixed with environmental background noise. When the upper limit of the input flow rate is 100MB / s, the data acquisition module sets the sampling period to 10ms to balance data throughput and information timeliness requirements. The streaming clearing channel is configured with a sample group that retains the topological characteristics of the directed flow, a control group that removes the feature-deficient flow based on the time difference between adjacent transactions, and a control group that adjusts relevant parameters to outside the preset boundary. In the sample group of this scheme, the data processing module extracts the time difference between adjacent transactions. For flow sequences between 12.4ms and 38.6ms, since this time difference falls into the expansion branch, the conditional control flow adjusts the static transaction strength value according to the time difference between adjacent transactions, causing the static transaction strength value of the corresponding directed connection edge to change from 1.25 to a dynamic topology weight parameter. With a value of 5.84, the single-layer graph neural network uses this dynamic topological weight parameter as a weighting factor to perform first-order neighborhood feature aggregation calculation, generating the feature convergence state vector of the current transaction entity node. The corresponding computation latency of the transaction entity node is 13.2ms. The feature missing control group uses the same input data, but does not perform dynamic correction of edge weights based on the time difference between adjacent transactions. The graph neural network completes feature aggregation through a five-order convolutional layer, and its data processing latency reaches 154.6ms. The two sets of data correspond to the same input conditions. The difference in processing latency comes from the different computation paths used by dynamic weight aggregation in the first-order neighborhood and multi-order convolutional search.
[0038] In the out-of-range control group, the 200ms boundary used to distinguish between expansion and decay branches was first lowered to 5ms. At this point, directed connections with adjacent transaction time differences within the range of 10ms to 50ms entered the decay branch. The system calculated the decay ratio based on the difference between the adjacent transaction time differences and the adjusted boundary, and accordingly lowered the static transaction intensity value. The resulting dynamic topology weight parameter decreased, thereby reducing the abnormal deviation value. The data was initially too low. Subsequently, the historical observation window used when merging the background memory pool into the historical association base map was extended from 3600s to 10000s. In this background update link, the hard truncation blocking branch did not participate in the historical data merging. Data outside the original observation window continued to enter the graph topology space. The memory buffer of the transaction subject node became saturated as the data accumulated. The growth slope of the abnormal deviation value over time tended to flatten after exceeding the boundary of the original observation window. The parameter turning points generated by the two out-of-range configurations corresponded to the expansion and decay boundaries of the dynamic topology weights, as well as the effective accumulation range of historical features in the historical association base map.
[0039] The potential risk intensity test employs a three-level data inflow gradient, increasing the frequency of liquidation transactions within a specific closed-loop path in the directed flow graph from 3 times per minute to 45 times per minute. The risk audit unit sequentially retrieves the feature convergence state vectors corresponding to each level of input, calculates the sum of squared discrete differences between these vectors and the compliance benchmark feature vector across each dimension, and obtains anomaly deviation values of 0.18, 0.46, and 0.89, respectively. The scoring mapping module first performs a centering shift and scaling on the above anomaly deviation values, multiplies them by a preset scaling factor, subtracts the centering shift constant, and then inputs S. The igmoid mapping operator multiplies the output value by 100 and projects it onto a fixed number axis range of 0 to 100 after full-scale linear mapping adjustment, generating quantitative risk scores of 21.3, 54.7, and 91.6 respectively. The lowest score falls below 50, causing the score corresponding to normal slight disturbances to enter the lower segment of the fixed number axis range. The quantitative risk score corresponding to the highest frequency exceeds the safety red line threshold of 85. Based on this, the score mapping module generates a high-risk level risk interception signal and sends it to the risk control response module through the data bus, which then closes the target trading interface.
[0040] Example 4: This embodiment combines Figures 1 to 2 This section explains methods for identifying financial transaction risks in the digital economy, such as... Figure 1As shown, the initial stage executes step S101, which involves parsing the transaction data to extract the main identifier and adjacent timestamps. This process then proceeds to step S102, which involves constructing graph nodes based on the fund flow to generate static strength values. After completing step S102, the process moves to step S103, which involves generating dynamic topological weights based on time difference-triggered control flow. The process then continues downwards to step S104, which involves aggregating first-order neighborhood features to generate a feature convergence state vector. After feature aggregation, the process moves to step S105, which involves calibrating the feature convergence state vector based on the global residual ratio. The process then proceeds to step S106, which involves calculating the sum of squared vector differences to generate anomaly deviation values. After calculating the deviation values, the process finally reaches step S107, which involves mapping the deviation to generate a risk score and sending it to the risk control module.
[0041] like Figure 2 As shown, the solid line corresponds to the global statistical residual ratio index, and the dashed line corresponds to the feedback compensation adjustment parameter value. The horizontal axis in the figure represents the dynamic adjustment time, with values ranging from 0, 20, 40, 60, 80, and 100. The vertical axis represents the adjustment state characteristic index, with values ranging from 0, 0.05, 0.10, 0.15, and 0.20. At time zero (0 ms), the initial value of the global statistical residual ratio index is 0.05. As the dynamic adjustment time increases, this index gradually rises, reaching its highest point at approximately 30 ms, with a value of 0.18. Thereafter, as the dynamic adjustment time continues... As the value continues to increase, the global statistical residual ratio gradually decreases, falling back to around 0.06 at 100ms. Simultaneously, the feedback compensation adjustment parameter, which initially corresponds to a value of 0.01 at 0ms, gradually increases with dynamic adjustment, reaching its maximum value of 0.035 at approximately 50ms. As the adjustment time further extends, the feedback compensation adjustment parameter gradually decreases in the latter part, dropping to around 0.01 at 100ms. This achieves the process of dynamic calibration and adjustment through the feedback compensation adjustment parameter when the global statistical residual ratio of the system fluctuates.
[0042] Example 5: In this embodiment, when the data throughput rate of the distributed clearing system changes, the directed connection edges in the clearing network are continuously updated with the transaction flow relationship. The financial transaction flow data packets cached in the data processing channel are prone to congestion. If the compliance behavior feature rule matrix remains unchanged, the compliance benchmark feature vector cannot keep up with the changes in transaction frequency and clearing delay in a timely manner. During long-term auditing, the abnormal deviation value will decrease, causing the risk identification false alarm rate to exceed the system's stable operation index. When the main control processor operates at a frequency greater than or equal to 2.4GHz, it reads historical processing records from the active cache graph and establishes a sliding window containing 512 consecutive clearing cycles. At the end of each calculation cycle, the sliding window removes the data of the earliest cycle and writes the data of the latest cycle to keep the window length unchanged.
[0043] The data processing module continuously records the characteristic convergence state vectors of each transaction entity node to form a historical evolution sequence. Based on the coefficient of variation of the characteristic convergence state vectors of adjacent periods, it determines the zero-point drift of the dynamic topology weight parameters along the time axis. At the boundary of each calculation period, the data processing module calculates the statistical value of the network-wide residual for the current period and reads the expected value of the network-wide topology residual for the previous period from the sliding window. The ratio of the statistical value of the network-wide residual for the current period to the expected value of the network-wide topology residual is used as the global statistical residual ratio of the directed correlation graph at the current moment. This ratio is dimensionless, and its error control upper limit is set to 0.15.
[0044] The feedback compensation loop operates with a 10ms adjustment period, continuously monitoring the envelope of the first derivative of the global statistical residual ratio. When the slope of this envelope is greater than 0 and remains monotonically increasing, the feedback compensation constant increases in fixed steps of 0.005 per adjustment period until it reaches 0.05. When the absolute value of the envelope slope approaches 0 or enters a flattening state, the feedback compensation constant decreases in the same fixed steps until it drops to 0.01. The feedback compensation constant varies between 0.01 and 0.05 and is used in conjunction with the global statistical residual ratio to linearly fine-tune the dynamic topology weight parameters. After fine-tuning, the graph neural network model re-executes the first-order neighborhood feature aggregation calculation on the transaction subject nodes affected by the weight changes, and writes the regenerated feature convergence state vector back to the original storage location. In this way, the feature convergence state vector is calibrated in situ within the local memory range of the active cache graph, avoiding the need for multi-order convolution updates across the entire network to the directed association graph at the current time. When the global statistical residual ratio exceeds 0.15, the data processing module outputs an error control instruction and continues to adjust the feedback compensation constant according to the changing direction of the current first derivative envelope until the ratio falls back to within the upper limit of the error control.
[0045] While recording the historical evolution sequence of the feature convergence state vector, the data processing module calculates the rate of change of this historical evolution sequence over time, generating a trend quantification index. The calibration threshold is determined based on the range of change of the feature convergence state vector during stable system operation. When the trend quantification index continuously exceeds the calibration threshold within a continuous time period, the system generates a risk warning signal to mark the continuously increasing node behavior deviation. The risk audit unit retrieves the calibrated feature convergence state vector and extracts its first 64 features, calculates the sum of squared discrete differences between it and the compliance benchmark feature vector in each dimension, obtains the abnormal deviation value, and the scoring mapping module assigns the abnormal deviation value to the target vector. The deviation value is input into a monotonically increasing mapping function to generate the latest quantitative risk score. When a high-frequency directional flow appears in the directed association graph and the quantitative risk score exceeds the safety red line threshold of 85, the data bus sends a high-risk level risk interception signal to the risk control response module. After receiving the signal, the risk control response module closes the transaction interface of the corresponding transaction entity. The linear fine-tuning of the dynamic topology weight parameters and the first-order neighborhood feature aggregation calculation calibrate the statistical residuals generated by feature drift within the single-layer graph structure, keeping the identification latency of non-real business data formed by multi-account nested flow within 15ms, and returning the calibrated transaction entity node to the safety threshold state.
[0046] Example 6: In this embodiment, during the initial deployment of the distributed clearing node, the main control processor, operating at a frequency greater than or equal to 2.4 GHz, retrieves the previous multi-period historical transaction dataset from the de-identified transaction flow storage unit as the benchmark sampling source for the compliance behavior feature rule matrix. The data processing module statistically analyzes the average turnover rate and capital retention ratio of different trading entities within the normal settlement cycle, and writes the obtained statistical expected values into the corresponding storage node of the compliance behavior feature rule matrix, forming the initial compliance benchmark feature vector used before the financial transaction flow data packet is accessed. The system obtains the compliance audit results from external feedback and matches the compliance audit results with historical transaction records according to the transaction entity identifier. For transaction records whose audit results confirm compliance, the average turnover rate and capital retention ratio are recalculated, and the re-obtained statistical expected values are written back to the corresponding storage node of the compliance behavior feature rule matrix. For transaction records whose audit results confirm abnormalities, they are not included in the compliance benchmark statistics. After writing back, the system corrects the compliance benchmark feature vector according to the updated matrix components.
[0047] After a new clearing network node is connected to the streaming electronic trading channel, the data processing module extracts adjacent transaction timestamps from the financial transaction data packets and calculates the time difference between adjacent transactions. When changes in node load cause the global statistical residual ratio of the directed graph at the current moment to exceed the preset topology error control upper limit, the feedback compensation loop adjusts the feedback compensation constant stepwise within the range of 0.01 to 0.05, and performs linear fine-tuning of the dynamic topology weight parameters based on the global statistical residual ratio. The calibrated dynamic topology weight parameters are then re-inputted into the graph neural network model as weighting factors to address the impact of weight changes. The transaction entity nodes perform first-order neighborhood feature aggregation calculations to generate updated feature convergence state vectors and reduce computational latency deviations caused by changes in node load. The risk audit unit calculates the sum of squared discrete differences between the feature convergence state vector and the compliance benchmark feature vector corrected by the compliance audit results, generating an abnormal deviation value. The scoring mapping module uses a monotonically increasing mapping function to project the abnormal deviation value onto a fixed number axis interval to generate a quantitative risk score. After the dynamic topology weight parameters and the compliance benchmark feature vector are calibrated, the quantitative risk score falls back to below the safety red line threshold of 85.
Claims
1. A method for identifying financial transaction risks in the digital economy, characterized in that, Includes the following steps: Step S101: Obtain financial transaction data packets and extract the transaction entity identifier and adjacent transaction timestamps contained in the financial transaction data packets; Step S102: Convert the transaction entity identifier into a transaction entity node, construct a directed connection edge based on the fund flow, and count the cumulative transaction frequency of the transaction entity nodes at both ends of the directed connection edge within the historical window to generate a static transaction intensity value. Step S103: Calculate the time difference between adjacent transaction timestamps, use the time difference between adjacent transactions to trigger a conditional control flow based on transaction clearing time constraints, adjust the static transaction strength value to generate dynamic topology weight parameters, and limit sudden transaction disturbances to the local memory range of the active cache graph. Step S104: Using the dynamic topology weight parameters as weighting factors, the first-order neighborhood feature aggregation calculation is called in the graph neural network model to generate a feature convergence state vector representing the behavioral characteristics of the transaction subject nodes. Step S105: Based on the global statistical residual ratio of the directed association graph at the current time, the dynamic topology weight parameters are linearly fine-tuned to calibrate the feature convergence state vector in situ. Step S106: Calculate the sum of squared discrete differences between the feature convergence state vector and the preset compliance benchmark feature vector in the memory dictionary to generate an abnormal deviation value. Step S107: The abnormal deviation value is projected onto a fixed number axis range using a monotonically increasing mapping function to generate a quantitative risk score, and the quantitative risk score is sent to the risk control response module as a control command.
2. The method for identifying financial transaction risks in the digital economy according to claim 1, characterized in that, Step S103 includes the following sub-steps: Step S1031, if the time difference between adjacent transactions is not greater than 200ms, calculate the inflation coefficient based on the ratio of 200ms to the time difference between adjacent transactions, and multiply the static transaction intensity value by the inflation coefficient to generate dynamic topology weight parameters; Step S1032, if the time difference between adjacent transactions is greater than 200ms and not greater than 1000ms, calculate the attenuation ratio based on the difference between the time difference between adjacent transactions and 200ms, and lower the static transaction intensity value according to the attenuation ratio to generate dynamic topology weight parameters.
3. The method for identifying financial transaction risks in the digital economy according to claim 1, characterized in that, Step S103 includes the following sub-steps: Step S1033, if the time difference between adjacent transactions is greater than 1000ms, a truncation control instruction is generated to cut off the logical transmission path that exceeds the time limit; Step S1034, in the state where the logical transmission path is cut off, the sudden transaction disturbance is isolated in the local memory range of the active cache graph, and the historical association base graph is updated asynchronously and non-blockingly using the background memory pool.
4. The method for identifying financial transaction risks in the digital economy according to claim 1, characterized in that, Step S103 restricts sudden transaction disturbances to the local memory range of the active cache graph, including the following sub-steps: Step S1035, calls the first-order feature accumulation function of the active cache graph to sum and accumulate the node status in the newly input financial transaction data packet with the first-order neighborhood features in the active cache graph, so as to update the local memory node features of the active cache graph in situ.
5. The method for identifying financial transaction risks in the digital economy according to claim 3, characterized in that, Step S1034, which uses the background memory pool to perform asynchronous non-blocking updates on the historical associated base map, includes the following sub-steps: Step S10341, isolate the cut transaction data to an independent data queue, and call the asynchronous update function in the background memory pool to merge the data in the independent data queue into the historical associated base map.
6. The method for identifying financial transaction risks in the digital economy according to claim 1, characterized in that, Step S104 includes the following sub-steps: Step S1041, retrieve the set of transaction subject nodes, identify the heterogeneous association edge types between different transaction subject nodes, and call the type weight matrix to perform weighted calculation on the first-order directed neighborhood features, and generate the feature convergence state vector through graph convolution aggregation operation.
7. The method for identifying financial transaction risks in the digital economy according to claim 1, characterized in that, Step S107 includes the following sub-steps: Step S1071, compare the quantitative risk score with the graded risk threshold, and trigger the corresponding level of risk interception signal when the quantitative risk score exceeds the graded risk threshold to drive the risk control response module to close the trading interface.
8. The method for identifying financial transaction risks in the digital economy according to claim 1, characterized in that, In the context of generating the feature convergence state vector, the following steps are also included: Step S108, continuously record the historical evolution sequence of the feature convergence state vector within a continuous time period, calculate the rate of change of the historical evolution sequence over time to generate a trend quantification index, and trigger a risk warning signal when the trend quantification index continuously exceeds the calibration threshold.
9. The method for identifying financial transaction risks in the digital economy according to claim 1, characterized in that, Based on the compliance behavior feature rule matrix, the following steps are also included: Step S109, obtain the compliance audit results from external feedback, and correct the compliance benchmark feature vector according to the compliance audit results.
Citation Information
Patent Citations
Transaction fraud detection method and system based on graph neural network
CN112396160A
Heterogeneous graph convolutional network-based fraudulent transaction account detection method
CN118211970A
Financial transaction real-time risk identification method based on multi-source heterogeneous data
CN120807150A