Network Graph Labeling via Multi-Feature Extraction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional feature extraction techniques for machine learning models in electronic communication processing systems fail to accurately identify anomalous entities due to their reliance on proximity-based methods, which do not account for the behavior of unknown entities and can lead to misidentification or missed identification of suspicious accounts.
Innovation Solution
The disclosed techniques measure the similarity in behavior between entities within an electronic communication network graph, determining proximity and behavior similarity to assign labels and generate new features such as node behavior features, neighbor convolution features, and community diffusion features for training machine learning models.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional proximity-based feature extraction techniques are used, then the system can process communications efficiently, but the accuracy of anomaly identification deteriorates because unknown entity behaviors are not accounted for
Solution Approach 1:
The feature extraction process is segmented into multiple independent procedures: node behavior feature extraction, neighbor convolution feature extraction, and community diffusion feature extraction. Each procedure analyzes different aspects of entity behavior and relationships, allowing the system to capture comprehensive anomaly patterns without overwhelming complexity in a single monolithic approach.
Solution Approach 2:
The patent transitions from traditional two-dimensional proximity-based features to multi-dimensional feature space by incorporating node behavior characteristics, neighbor relationship patterns through convolution, and community-level diffusion patterns. This dimensional expansion enables the system to capture nuanced behavioral patterns that traditional proximity metrics miss.
2Measurement precision
If multiple feature extraction procedures are implemented to capture behavior patterns, then anomaly detection accuracy improves, but computational resources and processing time increase
Solution Approach 1:
The system performs preliminary feature extraction and graph processing during normal operation to build up node behavior features, neighbor convolution features, and community diffusion features. By preparing these features in advance rather than computing them on-demand during anomaly detection, the system reduces real-time computational burden while maintaining high detection accuracy.
Solution Approach 2:
The feature extraction procedures operate continuously on the network graph as new data arrives, maintaining updated behavior patterns and relationships. This continuous processing allows the system to leverage previously computed features for new anomaly detection tasks, avoiding redundant computations and optimizing resource utilization over time.
Data Source
AI summary
Techniques are disclosed for maintaining a network graph by updating labels in the graph based on features generated using at least two different feature extraction procedures. A server system accesses a machine learning model trained using features generated using multiple feature extraction procedures. Using the model, the system determines labels for unlabeled nodes in a network graph whose nodes correspond to entities and whose edges correspond to electronic communications executed between the different entities, where the determining is performed based on output of the model for values of the features corresponding to the unlabeled nodes. Based on the determining, the system updates the graph by assigning the determined labels to the unlabeled nodes in the graph. The system performs, based on the assigned labels indicating that behavior of entities corresponding to the nodes are anomalous, preventative actions for entities corresponding to the nodes with assigned labels.


