Network Graph Labeling via Multi-Feature Extraction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional feature extraction techniques for machine learning models in electronic communication processing systems fail to accurately identify anomalous entities due to their reliance on proximity-based methods, which do not account for the behavior of unknown entities and can lead to misidentification or missed identification of suspicious accounts.

Innovation Solution

The disclosed techniques measure the similarity in behavior between entities within an electronic communication network graph, determining proximity and behavior similarity to assign labels and generate new features such as node behavior features, neighbor convolution features, and community diffusion features for training machine learning models.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional proximity-based feature extraction techniques are used, then the system can process communications efficiently, but the accuracy of anomaly identification deteriorates because unknown entity behaviors are not accounted for

Engineering Contradiction:
Improveanomaly identification accuracyVSAvoidfeature extraction complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The feature extraction process is segmented into multiple independent procedures: node behavior feature extraction, neighbor convolution feature extraction, and community diffusion feature extraction. Each procedure analyzes different aspects of entity behavior and relationships, allowing the system to capture comprehensive anomaly patterns without overwhelming complexity in a single monolithic approach.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent transitions from traditional two-dimensional proximity-based features to multi-dimensional feature space by incorporating node behavior characteristics, neighbor relationship patterns through convolution, and community-level diffusion patterns. This dimensional expansion enables the system to capture nuanced behavioral patterns that traditional proximity metrics miss.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Measurement precision

If multiple feature extraction procedures are implemented to capture behavior patterns, then anomaly detection accuracy improves, but computational resources and processing time increase

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoidcomputational resource consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The system performs preliminary feature extraction and graph processing during normal operation to build up node behavior features, neighbor convolution features, and community diffusion features. By preparing these features in advance rather than computing them on-demand during anomaly detection, the system reduces real-time computational burden while maintaining high detection accuracy.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The feature extraction procedures operate continuously on the network graph as new data arrives, maintaining updated behavior patterns and relationships. This continuous processing allows the system to leverage previously computed features for new anomaly detection tasks, avoiding redundant computations and optimizing resource utilization over time.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS20250029000A1Label and Network Graph Expansion Using Multiple Feature Extraction Procedures
Publication Date: 2025.01.23 PAYPAL INC
  • US20250029000A1 patent drawing
  • US20250029000A1 patent drawing
  • US20250029000A1 patent drawing

AI summary

Techniques are disclosed for maintaining a network graph by updating labels in the graph based on features generated using at least two different feature extraction procedures. A server system accesses a machine learning model trained using features generated using multiple feature extraction procedures. Using the model, the system determines labels for unlabeled nodes in a network graph whose nodes correspond to entities and whose edges correspond to electronic communications executed between the different entities, where the determining is performed based on output of the model for values of the features corresponding to the unlabeled nodes. Based on the determining, the system updates the graph by assigning the determined labels to the unlabeled nodes in the graph. The system performs, based on the assigned labels indicating that behavior of entities corresponding to the nodes are anomalous, preventative actions for entities corresponding to the nodes with assigned labels.