Money Transfer Fraud Alert System and Methods
Patent Information
- Application Number
- TW113131233
- Authority / Receiving Office
- TW · TW
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2024-08-20
- Publication Date
- 2026-09-01
- Estimated Expiration
- 2044-08-19
AI Technical Summary
Existing fraud prevention methods are ineffective in preventing fraudulent transfers due to victims' panic and forgetfulness, leading to high incidence of fraud cases.
A transfer fraud warning system that compares transfer data with internal and external fraud case data using feature vectors, generates warning messages based on similarity thresholds, and enhances warnings with confirmation tags and habitual operation analysis.
Prevents fraudulent activities by providing timely and intensified warnings, reducing the incidence of fraud cases by alerting customers to potential scams.
Smart Images

Figure TWG2TB001908515_001 
Figure TWG2TB001908515_002 
Figure TWG2TB001908515_003
Abstract
Description
[Technical Field]
[0001] This invention relates to an alarm system and method, and more particularly to an alarm system and method for fraudulent transfers. [Previous Technology]
[0002] In recent years, fraud cases have emerged one after another. At present, the means of preventing fraud are to regularly publicize fraud information or for the public to call the anti-fraud hotline to confirm whether they have been scammed, thereby achieving the effect of fraud prevention. In fact, when victims receive calls or messages from fraud groups, they are often in a state of panic and easily forget about fraud prevention information, and ultimately still unfortunately fall victim to fraud, which makes the incidence of fraud cases remain high. [Summary of the Invention]
[0003] Therefore, one of the objectives of the present invention is to provide a transfer fraud warning system that can prevent fraud.
[0004] Therefore, the transfer fraud alarm system of the present invention is suitable for electrical connection with a client electronic device for operation by a customer and an external resource server. The external resource server stores multiple external fraud case data, each external fraud case data corresponding to an external fraud feature vector. The transfer fraud alarm system includes a processing unit and a storage unit. The processing unit is electrically connected to the client electronic device and the external resource server. The storage unit is electrically connected to the processing unit and stores multiple internal fraud case data, each internal fraud case data corresponding to an internal fraud feature vector.
[0005] The processing unit receives transfer data from the client electronic device. The transfer data includes a receiving account, an account input history record corresponding to the receiving account field, a transfer amount, and an amount input history record corresponding to the transfer amount field. The account input history record contains one or more account field records, and the amount input history record contains one or more amount field records. The processing unit converts the receiving account, the account input history record, the transfer amount, and the amount input history record into a feature vector to be evaluated. The processing unit determines whether the similarity between the feature vector to be evaluated and an internal case of each internal fraud feature vector is greater than a similarity threshold, and generates an internal verification result. Furthermore, the processing unit also determines whether the similarity between the feature vector to be evaluated and an external case of each external fraud feature vector is greater than the similarity threshold, and generates an external verification result. If the internal verification result indicates that at least one internal case has a similarity greater than the similarity threshold, and / or the external verification result indicates that at least one external case has a similarity greater than the similarity threshold, the processing unit generates a fraud case summary based on the internal fraud case data corresponding to the internal case with a similarity greater than the similarity threshold, and / or the external fraud case data corresponding to the external case with a similarity greater than the similarity threshold. The processing unit then generates a preliminary warning message based on the fraud case summary and transmits the preliminary warning message to the client electronic device.
[0006] In some embodiments, after transmitting the initial warning message to the client electronic device, when the processing unit receives a transfer confirmation notification from the client electronic device corresponding to the transfer data, the processing unit generates one or more pending confirmation tag information and stores it in the storage unit. The pending confirmation tag information corresponds to the internal fraud case data and / or the external fraud case data, respectively. After receiving a fraud case confirmation notification corresponding to the internal fraud case data or the external fraud case data, the processing unit uses the pending confirmation tag information corresponding to the internal fraud case data or the external fraud case data as a fraud confirmation tag information. When the processing unit receives the transfer data and generates an internal verification result indicating that at least one internal case similarity is greater than the similarity threshold, and / or an external verification result indicating that at least one external case similarity is greater than the similarity threshold, the processing unit further determines whether the corresponding internal fraud case data and / or the external fraud case data exist in the storage unit, thereby generating a tag confirmation result. If the tag confirmation result indicates that the storage unit contains fraud confirmation tag information corresponding to the internal fraud case data and / or the external fraud case data, the processing unit generates an enhanced alert message based on the fraud case summary, wherein the enhanced alert message has a higher alert intensity than the initial alert message. The processing unit transmits the enhanced alert message to the client electronic device.
[0007] In some embodiments, the storage unit also stores a list of high-risk accounts, which includes multiple high-risk accounts. After receiving the transfer data, the processing unit compares the receiving account with the list of high-risk accounts and generates an account comparison result, wherein the account comparison result indicates whether there is a high-risk account in the list that matches the receiving account. If the account comparison result indicates that a high-risk account exists, the processing unit also generates the preliminary warning message based on the account comparison result.
[0008] In some embodiments, after transmitting the initial warning message to the client electronic device, when the processing unit receives a transfer confirmation notification from the client electronic device corresponding to the transfer data, the processing unit generates a pending confirmation tag and stores it in the storage unit. The pending confirmation tag corresponds to the high-risk account matching the receiving account. After receiving a fraud case confirmation notification corresponding to the high-risk account, the processing unit uses the pending confirmation tag corresponding to the high-risk account as fraud confirmation tag information. If the processing unit receives the transfer data and generates an account comparison result indicating that the account exists for the other transfer data, the processing unit further determines whether the corresponding high-risk account has the corresponding fraud confirmation tag information in the storage unit, and generates a tag confirmation result. If the tag confirmation result indicates that the storage unit has the fraud confirmation tag information corresponding to the high-risk account, the processing unit generates an enhanced warning message based on the high-risk account, wherein the warning intensity of the enhanced warning message is greater than that of the initial warning message. The processing unit transmits the enhanced alert message to the client electronic device.
[0009] In some embodiments, the storage unit also stores habitual operation trajectory information corresponding to the customer. The transfer data also includes transfer operation trajectory information, which indicates the customer's past habitual transfer operation trajectory and includes a habitual input sequence record and a habitual input time. The transfer operation trajectory information indicates the customer's operation trajectory for this transfer and includes a transfer input sequence record and a transfer input time. After receiving the transfer data, the processing unit also compares the transfer operation trajectory information with the habitual operation trajectory information and generates a habitual comparison result. The habitual comparison result indicates whether the transfer operation trajectory information does not match the habitual operation trajectory information. If the habitual comparison result indicates a mismatch, the processing unit also generates the preliminary warning message based on the habitual comparison result.
[0010] In some embodiments, after transmitting the initial warning message to the client electronic device, when the processing unit receives a transfer confirmation notification from the client electronic device corresponding to the transfer data, the processing unit generates a pending confirmation tag and stores it in the storage unit. The pending confirmation tag corresponds to the transfer operation trajectory information. After receiving a fraud case confirmation notification corresponding to the transfer operation trajectory information, the processing unit uses the pending confirmation tag corresponding to the transfer operation trajectory information as a fraud confirmation tag. If the processing unit receives the transfer data and generates a mismatch indication for the behavior comparison result corresponding to the other transfer data, the processing unit further determines whether the fraud confirmation tag corresponding to the transfer operation trajectory information exists in the storage unit, and generates a tag confirmation result. If the tag confirmation result indicates that the storage unit contains the fraud confirmation tag corresponding to the transfer operation trajectory information, the processing unit generates an enhanced warning message based on the transfer operation trajectory information, wherein the warning intensity of the enhanced warning message is greater than that of the initial warning message. The processing unit transmits the enhanced alert message to the client electronic device.
[0011] Therefore, another object of the present invention is to provide a method for preventing fraudulent transfers.
[0012] Therefore, the transfer fraud warning method of the present invention is implemented by a transfer fraud warning system. The transfer fraud warning system is suitable for electrical connection with a client electronic device for operation by a customer and an external resource server. The external resource server stores multiple external fraud case data, each external fraud case data corresponding to an external fraud feature vector. The transfer fraud warning system stores multiple internal fraud case data, each internal fraud case data corresponding to an internal fraud feature vector. The method includes the following steps.
[0013] The transfer fraud alert system receives transfer data from the client electronic device. The transfer data includes a receiving account, an account input history record corresponding to the receiving account field, a transfer amount, and an amount input history record corresponding to the transfer amount field. The account input history record contains one or more account field records, and the amount input history record contains one or more amount field records. The transfer fraud alert system converts the receiving account, the account input history record, the transfer amount, and the amount input history record into a feature vector to be evaluated. The transfer fraud alert system determines whether the similarity between the feature vector to be evaluated and an internal case of each internal fraud feature vector is greater than a similarity threshold, and generates an internal verification result. Furthermore, the transfer fraud alert system also determines whether the similarity between the feature vector to be evaluated and an external case of each external fraud feature vector is greater than the similarity threshold, and generates an external verification result. If the internal verification result indicates that at least one internal case has a similarity greater than the similarity threshold, and / or the external verification result indicates that at least one external case has a similarity greater than the similarity threshold, the transfer fraud alert system generates a fraud case summary based on the internal fraud case data corresponding to the internal case with a similarity greater than the similarity threshold, and / or the external fraud case data corresponding to the external case with a similarity greater than the similarity threshold. The transfer fraud alert system then generates a preliminary warning message based on the fraud case summary and transmits the preliminary warning message to the client electronic device.
[0014] In some embodiments, after transmitting the initial warning message to the client electronic device, when the transfer fraud alarm system receives a transfer confirmation notification from the client electronic device corresponding to the transfer data, the transfer fraud alarm system generates one or more pending confirmation tag information, which respectively correspond to the internal fraud case data and / or the external fraud case data. After receiving a fraud case confirmation notification corresponding to the internal fraud case data or the external fraud case data, the transfer fraud alarm system uses the pending confirmation tag information corresponding to the internal fraud case data or the external fraud case data as a fraud confirmation tag information. When the fraud alert system receives the transfer data and generates an internal verification result indicating that at least one internal case has a similarity greater than the similarity threshold, and / or an external verification result indicating that at least one external case has a similarity greater than the similarity threshold, the fraud alert system further determines whether the corresponding internal fraud case data and / or external fraud case data contain corresponding fraud confirmation tag information, thereby generating a tag confirmation result. If the tag confirmation result indicates the existence of fraud confirmation tag information corresponding to the internal fraud case data and / or the external fraud case data, the fraud alert system generates an enhanced warning message based on the fraud case summary, wherein the enhanced warning message has a higher warning intensity than the initial warning message. The fraud alert system then transmits the enhanced warning message to the client electronic device.
[0015] In some implementations, the transfer fraud alert system also stores a list of high-risk accounts, which includes multiple high-risk accounts. After receiving the transfer data, the transfer fraud alert system compares the receiving account with the list of high-risk accounts and generates an account comparison result. The account comparison result indicates whether there is a high-risk account matching the receiving account in the list of high-risk accounts. If the account comparison result indicates that a high-risk account exists, the transfer fraud alert system also generates a preliminary warning message based on the account comparison result.
[0016] In some embodiments, after transmitting the initial warning message to the client electronic device, when the transfer fraud alarm system receives a transfer confirmation notification from the client electronic device corresponding to the transfer data, the transfer fraud alarm system generates a pending confirmation tag, which corresponds to the high-risk account matching the receiving account. After receiving a fraud case confirmation notification corresponding to the high-risk account, the transfer fraud alarm system uses the pending confirmation tag corresponding to the high-risk account as a fraud confirmation tag. If the transfer fraud alarm system receives the transfer data and generates an account comparison result indicating existence for the other transfer data, the transfer fraud alarm system further determines whether the corresponding high-risk account has the corresponding fraud confirmation tag to generate a tag confirmation result. If the tag confirmation result indicates the existence of a fraud confirmation tag corresponding to the high-risk account, the transfer fraud alert system generates an enhanced alert message based on the high-risk account. This enhanced alert message has a higher alert intensity than the initial alert message. The transfer fraud alert system then transmits this enhanced alert message to the client's electronic device.
[0017] In some implementations, the transfer fraud alarm system also stores habitual operation trajectory information corresponding to the customer. The transfer data also includes transfer operation trajectory information, which indicates the customer's past habitual transfer operation trajectory and includes a habitual input sequence record and a habitual input time. The transfer operation trajectory information indicates the customer's operation trajectory for this transfer and includes a transfer input sequence record and a transfer input time. After receiving the transfer data, the transfer fraud alarm system also compares the transfer operation trajectory information with the habitual operation trajectory information and generates a habitual comparison result. The habitual comparison result indicates whether the transfer operation trajectory information does not match the habitual operation trajectory information. If the habitual comparison result indicates a mismatch, the transfer fraud alarm system also generates the preliminary warning message based on the habitual comparison result.
[0018] In some embodiments, after transmitting the initial warning message to the client electronic device, when the transfer fraud alarm system receives a transfer confirmation notification from the client electronic device corresponding to the transfer data, the transfer fraud alarm system generates a pending confirmation tag information, which corresponds to the transfer operation trajectory information. After receiving a fraud case confirmation notification corresponding to the transfer operation trajectory information, the transfer fraud alarm system uses the pending confirmation tag information corresponding to the transfer operation trajectory information as a fraud confirmation tag information. If the transfer fraud alarm system receives the transfer data and generates a mismatch indication for the behavior comparison result corresponding to the other transfer data, the transfer fraud alarm system further determines whether there is a fraud confirmation tag information corresponding to the transfer operation trajectory information, and generates a tag confirmation result. If the tag confirmation result indicates the existence of a fraud confirmation tag corresponding to the transfer operation trajectory information, the transfer fraud alarm system generates an enhanced warning message based on the transfer operation trajectory information. The enhanced warning message has a higher warning intensity than the initial warning message. The transfer fraud alarm system transmits the enhanced warning message to the client electronic device.
[0019] The advantage of this invention is that: after receiving the transfer data, the processing unit can compare the transfer data with internal fraud case data and external fraud case data for similarity. If the similarity of at least one internal case is greater than the similarity threshold and / or at least one external case is greater than the similarity threshold, a preliminary warning message is generated and transmitted to the client's electronic device. Therefore, the transfer fraud warning system can prevent fraudulent activities from occurring at the first instance and can provide specific information for the customer to make a judgment, thereby reducing the incidence of fraud cases.
Implementation Method
[0021] Before the present invention is described in detail, it should be noted that, unless otherwise defined, the term "electrically connected" in this patent specification is used to describe the "coupled" relationship between computer hardware (such as electronic systems, devices, apparatuses, units, components), and generally refers to "wired electrical connections" achieved by physically connecting multiple computer hardware components through conductor / semiconductor materials, and "radio connections" that achieve wireless data transmission using wireless communication technologies (such as, but not limited to, wireless networks, Bluetooth, and electromagnetic induction). On the other hand, unless otherwise defined, the term "electrical connection" in this patent specification also generally refers to "direct electrical connections" achieved by directly coupling multiple computer hardware components to each other, and "indirect electrical connections" achieved by indirectly coupling multiple computer hardware components through other computer hardware components.
[0022] Before the present invention is described in detail, it should be noted that the term "unit" in this patent specification refers to computer hardware rather than software. For example, "processing unit" is used to represent computer hardware or a combination of multiple computer hardware that have data processing functions.
[0023] Referring to FIG1, one embodiment of the transfer fraud alarm system 100 of the present invention is provided, for example, belonging to a banking institution, and the transfer fraud alarm system 100 is suitable for electrical connection with a client electronic device 10 for operation by a customer and an external resource server 20.
[0024] The client electronic device 10 is, for example, a smartphone owned by the client; however, in similar applications, the client electronic device 10 may also be a tablet computer, a laptop computer, or a desktop computer.
[0025] The external resource server 20 stores multiple external fraud case data. Such external fraud case data may be, for example, a fraud case news or a related article and comment on a social media platform, and each external fraud case data corresponds to an external fraud feature vector.
[0026] The transfer fraud alarm system 100 includes a processing unit 1 and a storage unit 2.
[0027] The processing unit 1 is adapted to connect the client electronic device 10 and the external resource server 20 via the Internet.
[0028] The storage unit 2 is electrically connected to the processing unit 1 and stores multiple internal fraud case data, a list of high-risk accounts, information on the customer's habitual operation trajectory, multiple fraud confirmation tag information, and a trained language generation model. In this embodiment, the language generation model can be, for example, an existing generative artificial intelligence model, but is not limited thereto. The internal case data can be, for example, records of fraud cases that have occurred in the past within the banking institution (e.g., descriptions of fraud methods, victim psychological weaknesses, and amount of loss), and each internal fraud case data corresponds to an internal fraud feature vector. The list of high-risk accounts includes multiple high-risk accounts, each of which can be, for example, an account whose proportion of reported and warned transactions exceeds 10% in the past 3 months. The habitual operation trajectory information indicates the customer's past habitual operation trajectory for transferring funds and includes a record of habitual input order and a record of habitual input time. The record of habitual input order can be, for example, a sequential record of the relevant information entered by the customer in the past when making transfer transactions. For example, when making a transfer, this customer always enters the amount to be transferred, then the account number, and always adds a transfer note in the remarks field. This habitual input time could be considered the average total processing time from input to submission of data in the customer's past transfer transactions.
[0029] More specifically, in this embodiment, the transfer fraud warning system 100 is a server device. The processing unit 1 is a processor implemented with integrated circuitry and has data processing and instruction transmission / reception functions. The storage unit 2 is a data storage device (such as a hard disk or other types of computer-readable recording media) for storing digital data. However, in similar embodiments, the processing unit 1 may also be a processing circuit including a processor, and the storage unit 2 may be a collection of multiple storage devices of the same or different types. Furthermore, in other embodiments, the transfer fraud warning system 100 may also be implemented as multiple server devices electrically connected to each other. In this case, the processing unit 1 may be implemented as a collection of multiple processors / processing circuits respectively possessed by the server devices, and the storage unit 2 may be implemented as a collection of multiple storage devices respectively possessed by the server devices. Therefore, the actual implementation of the transfer fraud warning system 100 in terms of computer hardware is not limited to this embodiment.
[0030] Referring to Figure 2, the operation of the transfer fraud warning system 100 in this embodiment will be described below.
[0031] First, as shown in step S101, the processing unit 1 receives transfer data from the client electronic device 10. The transfer data includes a receiving account, a corresponding account input history record for the receiving account field, a transfer amount, a corresponding amount input history record for the transfer amount field, and transfer operation trajectory information. The account input history record contains one or more account field records. The amount input history record contains one or more amount field records. More specifically, the account field records and the amount field records represent all data entered in the receiving account field and the transfer amount field before the customer enters the receiving account and the transfer amount to be transferred through the client electronic device 10. The transfer operation trajectory information indicates the customer's operation trajectory for this transfer and includes a transfer input sequence record and a transfer input time. The transfer input sequence record can be, for example, a sequential record of the relevant information entered by the customer during this transfer transaction. This input time could be, for example, the total operation time from inputting the data to sending it out during this transfer transaction.
[0032] Next, as shown in step S102, the processing unit 1 converts the receiving account, the account input history, the transfer amount, and the amount input history into a feature vector to be evaluated. It should be noted that, in a current fraud case, a fraudster induces a victim to first enter their ID number or random characters in the receiving account and transfer amount fields to gain their trust. Then, after multiple attempts, the fraudster induces the victim to enter the receiving account and transfer amount. Therefore, this invention further converts the account input history and the amount input history together into the feature vector to be evaluated, ensuring that fraudulent behavior can be detected during the customer's data entry process.
[0033] Next, as shown in step S103, the processing unit 1 compares the incoming account with the list of high-risk accounts and generates an account comparison result, wherein the account comparison result indicates whether there is a high-risk account in the list of high-risk accounts that matches the incoming account. If the account comparison result is yes, it means that one of the high-risk accounts matches the incoming account. If the account comparison result is no, it means that none of the high-risk accounts matches the incoming account.
[0034] Next, as shown in step S104, the processing unit 1 compares the transfer operation trajectory information with the habitual operation trajectory information and generates a habitual comparison result, wherein the habitual comparison result indicates whether the transfer operation trajectory information does not match the habitual operation trajectory information. If the account comparison result is yes, it means that the transfer operation trajectory information does not match the habitual operation trajectory information, that is, the customer's transfer input sequence record and transfer input time in this transaction do not match the habitual input sequence record and habitual input time, respectively. If the account comparison result is no, it means that the transfer operation trajectory information matches the habitual operation trajectory information, that is, the customer's transfer input sequence record and transfer input time in this transaction match the habitual input sequence record and habitual input time, respectively.
[0035] Next, as shown in step S105, the processing unit 1 determines whether the similarity between the feature vector to be evaluated and an internal case of each internal fraud feature vector is greater than a similarity threshold, and generates an internal verification result. Furthermore, the processing unit 1 also determines whether the similarity between the feature vector to be evaluated and an external case of each external fraud feature vector is greater than the similarity threshold, and generates an external verification result. The similarity threshold is preset and can be used, for example, to determine that two things are similar when their similarity exceeds the similarity threshold. If the internal verification result is yes and / or the external verification result is yes, it indicates that at least one internal case has a similarity greater than the similarity threshold, and / or the external verification result indicates that at least one external case has a similarity greater than the similarity threshold. That is, there is at least one case in the internal fraud case data and / or the external fraud case data that is similar to the transfer data. If both the internal verification result is yes and the external verification result is no, it indicates that at least one internal case has a similarity and at least one external case has a similarity not greater than the similarity threshold. In other words, there are no cases similar to the transfer information in either the internal or external fraud case files.
[0036] In this step, if the internal verification result is yes and / or the external verification result is yes, the processing unit 1 further generates a fraud case summary based on the internal fraud case data corresponding to the internal case similarity being greater than the similarity threshold, and / or the external fraud case data corresponding to the external case similarity being greater than the similarity threshold. For example, if the corresponding internal fraud case data and the external case data are related to a summary of "using identity verification as a pretext to induce people to repeatedly operate online banking", then the processing unit 1 generates the fraud case summary based on the summary content.
[0037] Next, as shown in step S106, if at least one of the account comparison result, the habit comparison result, the internal verification result, and the external verification result indicates yes, the processing unit 1 further determines whether the corresponding internal fraud case data, the external fraud case data, the high-risk account, and the transfer operation trajectory information exist in the storage unit 2, so as to generate a tag confirmation result. If the tag confirmation result indicates no, it means that the storage unit 2 does not have the fraud confirmation tag information corresponding to the internal fraud case data, the external fraud case data, the high-risk account, or the transfer operation trajectory information, and in this case, step S107 is performed. If the tag confirmation result indicates yes, it means that the storage unit 2 has the fraud confirmation tag information corresponding to the internal fraud case data, the external fraud case data, the high-risk account, or the transfer operation trajectory information, and in this case, step S108 is performed.
[0038] In step S107, if the storage unit 2 does not contain fraud confirmation tag information corresponding to the internal fraud case data, the external fraud case data, the high-risk account, or the transfer operation trajectory information, the processing unit 1 generates a preliminary warning message based on the corresponding fraud case summary, the account comparison result, or the habit comparison result, and transmits the preliminary warning message to the client electronic device 10 to warn the customer that this transaction may be a fraud case. The content of the preliminary warning message may include, for example, a warning statement, a summary of the fraud case, and a link to relevant news. For example, the content of the preliminary warning message is as follows: "The transfer information you entered is similar to a recent fraud case. In this case, the fraud group used the guise of identity verification to induce people to operate online banking multiple times. First, they guided people to enter non-account information in the account field. After the transaction failed, they gained the trust of the people and then defrauded them of money using a real account. For related news reports, please refer to the following link."
[0039] In step S108, if the storage unit 2 contains fraud confirmation tag information corresponding to the internal fraud case data, the external fraud case data, the high-risk account, or the transfer operation trajectory information, the processing unit 1 generates an enhanced warning message based on the corresponding fraud case summary, the account comparison result, or the habit comparison result, and transmits the enhanced warning message to the client electronic device 10 to warn the customer that this transaction is highly likely to be a fraud case. The warning intensity of the enhanced warning message is greater than that of the initial warning message, and the content of the enhanced warning message may include, for example, warning statements that are more warning-oriented than those in the initial warning message, a summary of the fraud case, and related news links. For example, the enhanced alert message reads as follows: "Please double-check! You are very likely being scammed! Our bank has had several similar cases. Scam groups exploit victims' panic, using identity verification as a pretext to induce people to repeatedly make online banking transactions. They first guide people to enter non-account information in the account field, and after the transaction fails to gain their trust, they use a real account to defraud them of funds, resulting in losses exceeding 500,000! Related news reports can be found at the following link."
[0040] When receiving fraudulent calls or messages, customers are often in a panicked state and easily misled by scammers, making them susceptible to being defrauded. Therefore, this initial warning message further alerts the customer, providing third-party warnings indicating that they may be being scammed, thus preventing the fraud from occurring at the first instance. Furthermore, the enhanced warning message further warns the customer with stronger language, reinforcing the warning that they may be being scammed, thereby achieving a more effective deterrent.
[0041] Referring to Figure 3, the following describes how the money transfer fraud alarm system 100 of this embodiment generates the fraud confirmation label information.
[0042] First, as shown in step S201, after transmitting the preliminary warning message to the client electronic device 10, the processing unit 1 receives a transfer confirmation notification from the client electronic device 10 corresponding to the transfer data. The processing unit 1 then generates one or more pending confirmation tag information based on the transfer confirmation notification and stores it in the storage unit 2. The pending confirmation tag information corresponds to at least one of the internal fraud case data, the external fraud case data, the high-risk account, or the transfer operation trajectory information. In other words, when the processing unit 1 warns the customer through the preliminary warning message that the transfer transaction may be fraudulent, but the customer still insists on making the transfer and sends the transfer confirmation notification to the processing unit 1, in this case, the processing unit 1 generates the pending confirmation tag information to annotate the corresponding internal fraud case data, the external fraud case data, the high-risk account, or the transfer operation trajectory information.
[0043] In other implementations, after the initial warning message is sent to the client electronic device 10, regardless of whether the processing unit 1 has received the transfer confirmation notification, the pending confirmation tag information will be generated to ensure that the corresponding internal fraud case information, external fraud case information, high-risk account or transfer operation trajectory information is noted.
[0044] Next, as shown in step S202, after receiving a fraud case confirmation notification corresponding to the internal fraud case information, the external fraud case information, the high-risk account, or the transfer operation trajectory information, the processing unit 1 uses the pending confirmation tag information corresponding to the internal fraud case information, the external fraud case information, the high-risk account, or the transfer operation trajectory information as fraud confirmation tag information. In other words, if the internal fraud case information, the external fraud case information, the high-risk account, or the transfer operation trajectory information with the corresponding pending confirmation tag information has been reported and confirmed as a fraud case by the customer or the police, then after receiving the fraud case confirmation notification, the processing unit 1 uses the pending confirmation tag information as the fraud confirmation tag information to confirm the case as a fraud case.
[0045] Accordingly, when the processing unit 1 receives the transfer data in the future, it will confirm whether the corresponding internal fraud case data, external fraud case data, high-risk account or transfer operation trajectory information has the corresponding fraud confirmation label information, so as to decide whether it is necessary to further generate the enhanced warning message to increase the warning effect.
[0046] In summary, the transfer fraud warning system 100, through its processing unit 1, can compare the transfer data with internal and external fraud case data after receiving the transfer data. If the similarity of at least one internal case exceeds the similarity threshold and / or at least one external case exceeds the similarity threshold, the system generates and transmits a preliminary warning message to the client electronic device 10. Therefore, the transfer fraud warning system 100 can prevent fraudulent activities at the first instance and provide relevant information for the customer to make a judgment, thereby reducing the incidence of fraud cases. Thus, the objective of this invention is indeed achieved.
[0047] However, the above description is only an embodiment of the present invention and should not be construed as limiting the scope of the present invention. Any simple equivalent changes and modifications made in accordance with the scope of the patent application and the contents of the patent specification shall still fall within the scope of the patent of the present invention. [Simplified Explanation of the Diagram]
[0020] Other features and effects of the present invention will be clearly presented in the embodiments with reference to the drawings, wherein: Figure 1 is a hardware block diagram for illustrating an embodiment of the transfer fraud warning system of the present invention, and a client electronic device and an external resource server suitable for cooperating with the embodiment; Figure 2 is a flowchart for exemplarily illustrating the operation of the embodiment in generating a preliminary warning message and an enhanced warning message; and Figure 3 is a flowchart for exemplarily illustrating the operation of the embodiment in generating the fraud confirmation label information.
Claims
1. A transfer fraud alarm system, suitable for electrical connection to a client electronic device for operation by a customer and an external resource server, the external resource server storing multiple external fraud case data, each external fraud case data corresponding to an external fraud feature vector, the transfer fraud alarm system comprising: a processing unit electrically connected to the client electronic device and the external resource server; and a storage unit electrically connected to the processing unit, storing multiple internal fraud case data and habitual operation trajectory information corresponding to the customer, each internal fraud case data corresponding to an internal fraud feature vector, the habitual operation trajectory information indicating the customer's past habitual transfer operation trajectory and including a habitual input sequence record and a habitual input time; The processing unit receives transfer data from the client's electronic device. This transfer data includes a receiving account, an account input history record corresponding to the receiving account field, a transfer amount, an amount input history record corresponding to the transfer amount field, and transfer operation trajectory information. The account input history record contains one or more account field records, the amount input history record contains one or more amount field records, and the transfer operation trajectory information indicates the customer's operation trajectory for this transfer and includes a transfer input sequence record and a transfer input time. The processing unit converts the receiving account, the account input history record, the transfer amount, and the amount input history record into a feature vector to be evaluated. The processing unit compares the transfer operation trajectory information with the habitual operation trajectory information and generates a habitual comparison result. The behavior comparison result indicates whether the transfer operation trajectory information does not match the behavior operation trajectory information; the processing unit determines whether the similarity between the feature vector to be evaluated and an internal case of each internal fraud feature vector is greater than a similarity threshold, and generates an internal verification result; the processing unit also determines whether the similarity between the feature vector to be evaluated and an external case of each external fraud feature vector is greater than the similarity threshold, and generates an external verification result; if the internal verification result indicates that at least one internal case similarity is greater than the similarity threshold, and / or the external verification result indicates that at least one external case similarity is greater than the similarity threshold, the processing unit generates a fraud case summary based on the internal fraud case data corresponding to the internal case similarity being greater than the similarity threshold, and / or the external fraud case data corresponding to the external case similarity being greater than the similarity threshold; the processing unit generates a preliminary warning message based on the fraud case summary and the behavior comparison result, and transmits the preliminary warning message to the client electronic device, wherein the behavior comparison result indicates a mismatch.
2. The transfer fraud alarm system as described in claim 1, wherein: After transmitting the initial warning message to the client electronic device, when the processing unit receives a transfer confirmation notification from the client electronic device corresponding to the transfer data, the processing unit generates one or more pending confirmation tag information and stores it in the storage unit. The pending confirmation tag information corresponds to the internal fraud case data and / or the external fraud case data, respectively. After receiving a fraud case confirmation notification corresponding to the internal fraud case data or the external fraud case data, the processing unit uses the pending confirmation tag information corresponding to the internal fraud case data or the external fraud case data as a fraud confirmation tag information. When the processing unit receives the transfer data and generates an internal verification result corresponding to another transfer data indicating that at least one internal case similarity is greater than the similarity threshold, and / or the external verification result indicating that at least one external case similarity is greater than the similarity threshold, the processing unit further determines whether the corresponding internal fraud case data and / or the external fraud case data exist in the storage unit with the corresponding fraud confirmation tag information, so as to generate a tag confirmation result. If the tag confirmation result indicates that the storage unit contains fraud confirmation tag information corresponding to the internal fraud case data and / or the external fraud case data, the processing unit generates an enhanced warning message based on the fraud case summary, wherein the enhanced warning message has a higher warning intensity than the initial warning message; the processing unit transmits the enhanced warning message to the client electronic device.
3. The money transfer fraud alarm system as described in claim 1, wherein, The storage unit also stores a list of high-risk accounts, which includes multiple high-risk accounts. After receiving the transfer information, the processing unit compares the receiving account with the list of high-risk accounts and generates an account comparison result. The account comparison result indicates whether there is a high-risk account in the list that matches the receiving account. If the account comparison result indicates that a high-risk account exists, the processing unit also generates the preliminary warning message based on the account comparison result.
4. The transfer fraud alarm system as described in claim 3, wherein: After transmitting the initial warning message to the client electronic device, when the processing unit receives a transfer confirmation notification from the client electronic device corresponding to the transfer data, the processing unit generates a pending confirmation tag and stores it in the storage unit. The pending confirmation tag corresponds to the high-risk account matching the receiving account. After receiving a fraud case confirmation notification corresponding to the high-risk account, the processing unit uses the pending confirmation tag corresponding to the high-risk account as fraud confirmation tag information. If the processing unit receives the transfer data and generates an account comparison result indicating that the account exists for the other transfer data, the processing unit further determines whether the corresponding high-risk account has a corresponding fraud confirmation tag in the storage unit to generate a tag confirmation result. If the tag confirmation result indicates that the storage unit has the fraud confirmation tag corresponding to the high-risk account, the processing unit generates an enhanced warning message based on the high-risk account, wherein the enhanced warning message has a higher warning intensity than the initial warning message. The processing unit transmits the enhanced warning message to the client electronic device.
5. The transfer fraud alarm system as described in claim 1, wherein: After transmitting the initial warning message to the client electronic device, when the processing unit receives a transfer confirmation notification from the client electronic device corresponding to the transfer data, the processing unit generates a pending confirmation tag and stores it in the storage unit. This pending confirmation tag corresponds to the transfer operation trajectory information. Upon receiving a fraud case confirmation notification corresponding to the transfer operation trajectory information, the processing unit uses the pending confirmation tag corresponding to the transfer operation trajectory information as a fraud confirmation tag. If the processing unit receives the transfer data and generates a mismatch indication for the habit comparison result corresponding to another transfer data, the processing unit further determines whether the fraud confirmation tag corresponding to the transfer operation trajectory information exists in the storage unit, generating a tag confirmation result. If the tag confirmation result indicates that the storage unit contains the fraud confirmation tag corresponding to the transfer operation trajectory information, the processing unit generates an enhanced warning message based on the transfer operation trajectory information, wherein the enhanced warning message has a higher warning intensity than the initial warning message. The processing unit transmits the enhanced warning message to the client electronic device.
6. A method for alerting against money transfer fraud, implemented by a money transfer fraud alerting system, the system being electrically connected to a client electronic device for operation by a customer and an external resource server, the external resource server storing multiple external fraud case data, each external fraud case data corresponding to an external fraud feature vector, the money transfer fraud alerting system storing multiple internal fraud case data and habitual operation trajectory information corresponding to the customer, each internal fraud case data corresponding to an internal fraud feature vector, the habitual operation trajectory information indicating the customer's past habitual money transfer operation trajectory and including a habitual input sequence record and a habitual input time, the method comprising the following steps: The fraudulent transfer alert system receives transfer data from the client's electronic device. This data includes a receiving account, a corresponding account input history for the receiving account field, a transfer amount, a corresponding amount input history for the amount field, and transfer operation trajectory information. The account input history includes one or more account field records, the amount input history includes one or more amount field records, and the transfer operation trajectory information indicates the customer's operation trajectory for this transfer and includes a transfer input sequence record and a transfer input time. The fraudulent transfer alert system converts the receiving account, the account input history, the transfer amount, and the amount input history into a feature vector to be evaluated. The fraudulent transfer alert system compares the transfer operation trajectory information with the habitual operation trajectory information and generates a habitual comparison result. The behavior comparison result indicates whether the transfer operation trajectory information does not match the behavior operation trajectory information; the transfer fraud alarm system determines whether the similarity between the feature vector to be evaluated and an internal case of each internal fraud feature vector is greater than a similarity threshold, and generates an internal verification result; furthermore, the transfer fraud alarm system also determines whether the similarity between the feature vector to be evaluated and an external case of each external fraud feature vector is greater than the similarity threshold, and generates an external verification result; if the internal verification result indicates that at least one internal case has a similarity greater than the similarity threshold, and / or the external verification result indicates that at least one external case has a similarity greater than the similarity threshold, the transfer fraud alarm system generates a fraud case summary based on the internal fraud case data corresponding to the internal case similarity greater than the similarity threshold, and / or the external fraud case data corresponding to the external case similarity greater than the similarity threshold; The money transfer fraud warning system generates a preliminary warning message based on the fraud case summary and the habit comparison results, and transmits the preliminary warning message to the client electronic device. The habit comparison results indicate a mismatch.
7. The method for alerting against money transfer fraud as described in claim 6, wherein: After transmitting the initial warning message to the client electronic device, when the transfer fraud alarm system receives a transfer confirmation notification from the client electronic device corresponding to the transfer data, the transfer fraud alarm system generates one or more pending confirmation tag information, which respectively correspond to the internal fraud case data and / or the external fraud case data; after receiving a fraud case confirmation notification corresponding to the internal fraud case data or the external fraud case data, the transfer fraud alarm system uses the pending confirmation tag information corresponding to the internal fraud case data or the external fraud case data as a fraud confirmation tag information; when the transfer fraud alarm system receives the transfer data and generates an internal verification result corresponding to another transfer data indicating that at least one internal case similarity is greater than the similarity threshold, and / or the external verification result indicates that at least one external case similarity is greater than the similarity threshold, the transfer fraud alarm system further determines whether the corresponding internal fraud case data and / or the external fraud case data have corresponding fraud confirmation tag information, so as to generate a tag confirmation result; If the tag confirmation result indicates the existence of fraud confirmation tag information corresponding to the internal fraud case data and / or the external fraud case data, the transfer fraud alarm system generates an enhanced warning message based on the fraud case summary, wherein the enhanced warning message has a higher warning intensity than the initial warning message; the transfer fraud alarm system transmits the enhanced warning message to the client electronic device.
8. The method for alerting against money transfer fraud as described in claim 6, wherein, The fraud alert system also stores a list of high-risk accounts, which includes multiple high-risk accounts. After receiving the transfer information, the system compares the receiving account with the list of high-risk accounts and generates an account comparison result. This result indicates whether a high-risk account matching the receiving account exists in the list. If the comparison result indicates that a high-risk account exists, the system generates a preliminary warning message based on the comparison result.
9. The method for alerting against money transfer fraud as described in claim 8, wherein: After transmitting the initial warning message to the client electronic device, when the transfer fraud alarm system receives a transfer confirmation notification from the client electronic device corresponding to the transfer data, the transfer fraud alarm system generates a pending confirmation tag, which corresponds to the high-risk account matching the receiving account. Upon receiving a fraud case confirmation notification corresponding to the high-risk account, the transfer fraud alarm system uses the pending confirmation tag corresponding to the high-risk account as a fraud confirmation tag. If the transfer fraud alarm system receives the transfer data and generates an account comparison result indicating the existence of the account corresponding to the other transfer data, the transfer fraud alarm system further determines whether the corresponding high-risk account has a corresponding fraud confirmation tag, generating a tag confirmation result. If the tag confirmation result indicates the existence of the fraud confirmation tag corresponding to the high-risk account, the transfer fraud alarm system generates an enhanced warning message based on the high-risk account, wherein the enhanced warning message has a higher warning intensity than the initial warning message. The fraud alert system will send an enhanced warning message to the client's electronic device.
10. The method for alerting against money transfer fraud as described in claim 6, wherein: After transmitting the initial warning message to the client electronic device, when the transfer fraud alarm system receives a transfer confirmation notification from the client electronic device corresponding to the transfer data, the transfer fraud alarm system generates a pending confirmation tag, which corresponds to the transfer operation trajectory information. Upon receiving a fraud case confirmation notification corresponding to the transfer operation trajectory information, the transfer fraud alarm system uses the pending confirmation tag corresponding to the transfer operation trajectory information as a fraud confirmation tag. If the transfer fraud alarm system receives the transfer data and generates a mismatch indication for the habit comparison result corresponding to another transfer data, the transfer fraud alarm system further determines whether there is a fraud confirmation tag corresponding to the transfer operation trajectory information, generating a tag confirmation result. If the tag confirmation result indicates the existence of a fraud confirmation tag corresponding to the transfer operation trajectory information, the transfer fraud alarm system generates an enhanced warning message based on the transfer operation trajectory information, wherein the enhanced warning message has a higher warning intensity than the initial warning message. The fraud alert system will send an enhanced warning message to the client's electronic device.
Citation Information
Patent Citations
Bank anti-call fraud data model construction method based on multi-feature fusion
CN117993919A
Transaction verification system
TWM603157U
Fund transfer fraud warning system
TWM662526U
Multi-stage filtering for fraud detection with customer history filters
US8447674B2