Graphical Node Clustering for Anomalous Connectivity Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current anti-money laundering (AML) methods fail to detect anomalous connectivity patterns between entities, leading to undetected suspicious activities and inadequate risk coverage for financial institutions.

Innovation Solution

The system employs network analysis, modeling, and visualization techniques to identify and generate visualizations of relationships between entities, define communities of interest, and analyze network growth patterns, thereby uncovering hidden connections indicative of anomalous behavior.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If current AML methods are used, then simplicity of detection is maintained, but detection precision of anomalous connectivity patterns deteriorates

Engineering Contradiction:
Improvedetection precisionVSAvoiddetection complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the detection process into distinct phases: generating graphical representations of entities and their interactions, identifying clusters of entities within these representations, and analyzing connectivity patterns within and between clusters. This segmentation allows complex anomalous pattern detection to be broken down into manageable analytical steps, improving detection precision without overwhelming system complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces graphical representations as a new dimension for visualizing and analyzing entity relationships. By transforming tabular data into graphical formats with nodes and links, the system enables detection of connectivity patterns that are not apparent in traditional tabular representations, significantly improving detection precision for anomalous behaviors.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If network analysis techniques are implemented, then risk coverage is improved, but processing time increases

Engineering Contradiction:
Improverisk coverageVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary actions by pre-generating graphical representations of entities and their interactions, and pre-identifying clusters of entities before actual anomaly detection occurs. This preliminary structuring of data allows for faster processing during actual detection operations, as the foundational analysis work has already been completed, thereby improving risk coverage without proportionally increasing processing time.

Inventive Principle:
Principle #10Preliminary action

3Difficulty of detecting and measuring

If graphical representations are generated for all entities, then detection capability is improved, but system complexity increases

Engineering Contradiction:
Improvedetection capabilityVSAvoidsystem complexity
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The patent applies local quality by focusing graphical representation and cluster analysis specifically on entities and relationships that exhibit anomalous connectivity patterns, rather than uniformly analyzing all entities. This targeted approach improves detection capability for suspicious activities while reducing system complexity by avoiding unnecessary analysis of normal, low-risk entities.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS20250190995A1Detecting undesirable activity based on matching parameters of groups of nodes in graphical representations
Publication Date: 2025.06.12 CITIGROUP TECHNOLOGY INC
  • US20250190995A1 patent drawing
  • US20250190995A1 patent drawing
  • US20250190995A1 patent drawing

AI summary

Methods and systems are described herein for identifying matching parameters of groups of nodes in graphical representations. The system may generate, in a graphical user interface, a graphical representation of nodes representing users associated with an entity. The system may activate the graphical representation as links connecting pairs of nodes, with the links representing interactions between users. The system may identify a grouping of nodes having a level of local clustering indicative of undesired activity. The system may determine graphical parameters relating to the level of local clustering and may identify the same graphical parameters in other groupings of nodes in other graphical representations. The system may thus identify indications of undesired activity based on matching parameters of groups of nodes.