Method and system for reducing likelihood of fraudulent transactions
The server estimates the profit after transaction to determine fraudulent transactions, which solves the problem of poor adaptability of existing fraud prevention systems when environmental changes, and achieves more accurate fraud detection and better user experience.
Patent Information
- Application Number
- CN202380074101.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2022-10-20
- Filing Date
- 2023-09-12
- Publication Date
- 2025-06-03
AI Technical Summary
The existing fraud prevention system has poor adaptability when environmental changes are changed, which is prone to high false alarms or missed reports, resulting in high friction or minor fraud not being detected by normal users.
The server estimates the profits that can be obtained within a time period after the user's transaction is allowed or blocked, and based on this estimate, determine whether the transaction is a fraudulent transaction and take corresponding measures.
It improves the adaptability of the fraud prevention system, reduces false alarms and underreports, improves the user experience, and effectively prevents fraudulent transactions.
Smart Images

Figure CN120092252A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates generally but not exclusively to methods and systems for reducing the likelihood of fraudulent transactions Background Art
[0002] Platforms that provide services such as ride-hailing services, delivery services, merchandise sales, food, and other similar services typically have anti-fraud systems, which usually consist of a series of manually defined rules or machine learning (ML) models that take actions against platform users when suspicious behavior is detected. Professional fraudsters may use advanced techniques to abuse promotions provided by the platform on a large scale, while some users may only occasionally attempt to take advantage of promotions. Based on the severity, different actions will be taken, such as promotion blocking, transaction blocking, and account banning
[0003] However, rules and models with manually defined thresholds are less adaptable to the environment. When the environment changes due to factors such as the pandemic, business competition, and national regulations, user behavior will also change. Therefore, static rules and models may generate high false positives (e.g., identifying normal users as fraudsters) or false negatives (e.g., failing to detect fraudsters), which bring unnecessary friction to normal users or result in overly severe punishment measures for minor fraud. Such a poor user experience may lead to a high complaint rate, a high user churn rate, and ultimately revenue loss
[0004] Therefore, there is a need to provide methods and systems that seek to overcome or at least minimize the challenges mentioned above Summary of the Invention
[0005] According to a first aspect of the present disclosure, there is provided a method for reducing the likelihood of fraudulent transactions, the method comprising: estimating, by a server, the profit that can be obtained from a user within a period of time after each of allowing a user's transaction and blocking a user's transaction, the estimated profit being based on information related to the user; determining, by the server, whether the transaction is a fraudulent transaction based on the estimated profit, and allowing or blocking the transaction based on the determination
[0006] According to a second aspect of the present disclosure, there is provided a system for reducing the likelihood of fraudulent transactions, comprising: at least one processor; and at least one memory including computer program code; the at least one memory and the computer program code are configured to, together with the at least one processor, cause the system to at least: estimate the profit that can be obtained from a user within a period of time after each of allowing a user's transaction and blocking a user's transaction, the estimated profit being based on information related to the user; determine whether the transaction is a fraudulent transaction based on the estimated profit, and allow or block the transaction based on the determination Brief Description of the Drawings
[0007] Embodiments and implementations are provided by way of example only, and those of ordinary skill in the art will better understand and readily appreciate the embodiments and implementations from the following written description read in conjunction with the accompanying drawings, in which:
[0008] Figure 1 There is shown a system for reducing the likelihood of fraudulent transactions in accordance with various embodiments of the present disclosure.
[0009] Figure 2 is a schematic diagram of an action server in accordance with various embodiments of the present disclosure.
[0010] Figure 3 Depicts an overview of reinforcement learning (RL) in accordance with various embodiments.
[0011] Figure 4 Depicts an exemplary illustration of how the likelihood of fraudulent transactions can be reduced in accordance with various embodiments.
[0012] Figure 5 There is shown an exemplary flowchart of a method for reducing the likelihood of fraudulent transactions in accordance with various embodiments.
[0013] Figure 6A is a general computer system on which the Figure 2 action server can be practiced.
[0014] Figure 6B is a general computer system on which the Figure 1 combined transaction processing and action server can be practiced.
[0015] Figure 7 There is shown an example of a computing device for implementing the Figure 1 transaction processing server shown in
[0016] Figure 8 There is shown an example of a computing device for implementing the Figure 1 action server shown in
[0017] Figure 9 There is shown an example of a computing device for implementing the Figure 1 combined transaction processing and action server shown in
[0018] Those skilled in the art will understand that the elements in the drawings are illustrated for simplicity and clarity and are not necessarily drawn to scale. For example, the dimensions of some elements in the illustration, block diagram, or flowchart may be exaggerated relative to other elements to assist in improving the understanding of the embodiments of the present invention. Detailed Description
[0019] Term Explanation
[0020] A platform refers to a set of technologies that serve as a basis for facilitating exchanges between two or more interdependent servers, entities, and / or devices (such as an exchange between a requesting device (for a product or service) and a providing device (for a product or service)). For example, a platform can provide services offered by a provider to a requester, such as ride-hailing, delivery, online shopping, insurance, and other similar services. A requester can typically access the platform via a website, an application, or other similar means.
[0021] A platform can implement an anti-fraud system to detect suspicious behavior, such as attempts to abuse the platform. For example, a platform may sometimes offer promotions for its services, such as discounts, membership benefits, giveaways, and other similar promotions. Some users of the platform may abuse the promotions, for example, by setting up multiple accounts to take advantage of promotions that can only be used once per user, making one or more transactions and canceling them shortly thereafter, or other similar behavior. Such abuse may result in a loss of profit for the platform, a degradation in the performance of the platform application due to a sudden temporary increase in the number of users, or other similar consequences. To counter such fraudulent behavior, actions may be taken to block and penalize these users. For example, an action can be taken based on a determination of whether a user's transaction is a fraudulent transaction, the action being one or more of allowing the transaction, blocking the transaction, blocking the promotion associated with the transaction, banning the user's account, and other similar actions. Determining whether a transaction is fraudulent and what action to take can be based on the estimated profit obtained from the user over a period of time after each action, and can also be based on historical data (including previously obtained information related to the user, previous determinations of whether to allow or block the user's transactions, and the profit obtained from the user over a period of time after the previous determination). The profit can be estimated based on information related to the user (such as user profile, transaction history, risk profile, and the user's financial profile).
[0022] A deep reinforcement learning (DRL) system refers to a self-learning system that reinforces its correct decisions and learns from wrong decisions by attempting to maximize the rewards after the actions it observes. The reward can be the profit obtained from the user within a period of time after taking an action in response to a user's transaction (e.g., allowing the transaction, blocking the transaction, blocking the promotion associated with the transaction, banning the user's account, and other similar actions). Such a system can be used to determine which action to take by exploring to adapt to changes in the environment, for example, using epsilon-greedy action selection. Epsilon-greedy is a method that balances exploration and exploitation by randomly choosing exploration and exploitation. Exploration allows the agent (e.g., a deep neural network) to improve its current knowledge of each action, hoping to bring long-term benefits. Improving the accuracy of the estimated profit enables the agent to make more informed decisions in the future. On the other hand, by exploiting the agent's current action-value estimates, exploitation selects the "greedy" action to obtain the maximum reward (e.g., taking the action with the highest estimated profit). However, being greedy in action-profit estimation may not actually obtain the maximum reward and may lead to suboptimal behavior. When the agent explores, it gets more accurate action-value estimates, and when it exploits, it may get more rewards. However, it cannot choose both at the same time, which is also known as the exploration-exploitation dilemma. In epsilon-greedy, epsilon refers to the probability of randomly deciding to take an action (e.g., allowing the user's transaction, blocking the transaction, blocking the promotion associated with the transaction, banning the user's account, and other similar actions). This probability can be called the epsilon probability, which can be set depending on the application. Therefore, determining whether a transaction is a fraudulent transaction can also be based on this probability, for example, the probability of randomly making a decision to allow or block the transaction. It should be understood that in addition to allowing or blocking the transaction, other actions can also be included, such as blocking the promotion associated with the transaction, banning the user's account, and other similar actions.
[0023] In at least some embodiments, the user can be any suitable type of entity, which can include a person, a consumer who wishes to purchase a product or service via a transaction processing server, a seller or merchant who wishes to sell a product or service via a transaction processing server, a motorcycle driver or a passenger on the backseat in the case where the user wishes to book or offer a motorcycle ride via the transaction processing server, a car driver or a passenger in the case where the user wishes to book or offer a car ride via the transaction processing server, and other similar entities. A user registered with the transaction processing server will be referred to as a registered user. A user not registered with the transaction processing server will be referred to as an unregistered user. The term user will be used to generally refer to both registered users and unregistered users. A user can be interchangeably referred to as a requester (e.g., a person requesting a product or service) or a provider (e.g., a person providing the requested product or service to the requester).
[0024] In at least some embodiments, the action server is a server that hosts a software application for reducing the likelihood of fraudulent transactions. The action server can be implemented as shown in the schematic diagram of Figure 2 to reduce the likelihood of fraudulent transactions.
[0025] In at least some embodiments, the transaction processing server is a server that hosts a software application for processing payment transactions such as ride coordination requests, user purchases of goods or services, and other similar services. The transaction processing server communicates with any other server (e.g., the action server) regarding the processing of payment transactions related to the purchase of goods or services. For example, data related to a user's payment transaction (e.g., date, time, details of the goods or services to be purchased, and other similar data), information related to the user (e.g., user profile, transaction history, risk profile, and the user's financial profile), and other similar data can be provided to and processed by the action server to reduce the likelihood of fraudulent transactions. The transaction processing server can use various different protocols and procedures in order to process payment and / or ride coordination requests.
[0026] Transactions that can be performed via the transaction processing server include product or service purchases, credit purchases, debit transactions, fund transfers, account withdrawals, etc. The transaction processing server can be configured to process transactions via cash substitutes, which can include payment cards, letters of credit, checks, payment accounts, etc.
[0027] In at least some embodiments, the transaction processing server is generally managed by a service provider, which can be an entity (e.g., a company or organization) that operates to process transaction requests and / or ride coordination requests. The transaction processing server can include one or more computing devices for processing transaction requests and / or ride coordination requests.
[0028] In at least some embodiments, a transaction account is an account of a user registered with the transaction processing server. The user can be a customer, a merchant offering products for joining the platform and / or selling on the platform, a taxi provider (e.g., a driver), or any third party (e.g., a courier) who wants to use the transaction processing server. In some cases, a transaction account does not need to use the transaction processing server. The transaction account includes details of the user (e.g., name, address, vehicle, facial image, etc.). The transaction processing server manages the transactions.
[0029] Embodiments will be described by way of example only with reference to the accompanying drawings. Like reference numerals and characters in the drawings denote identical elements or equivalents.
[0030] Some portions of the description below are presented, either explicitly or implicitly, in terms of algorithms and functional or symbolic representations of operations on data within a computer memory. These algorithmic descriptions and functional or symbolic representations are the means used by those skilled in the data processing arts to most effectively convey the substance of their work to others skilled in the art. An algorithm is here, and generally, conceived as a self-consistent sequence of steps leading to a desired result. The steps are those requiring physical manipulation of physical quantities such as electrical, magnetic, or optical signals that can be stored, transferred, combined, compared, and otherwise manipulated.
[0031] Unless otherwise specifically set forth, and as will be apparent from the following, it should be understood that throughout this specification, discussions using terms such as "estimating," "acquiring," "extracting," "evaluating," "determining," "associating," "selecting," "calculating," "processing," "storing," "indicating," "identifying," etc., refer to actions and processes of a computer system or similar electronic device that manipulates and transforms data represented as physical quantities within the computer system into other data similarly represented as physical quantities within the computer system or other information storage, transmission, or display device.
[0032] Additionally, this specification also implicitly discloses a computer program, since it will be apparent to those skilled in the art that the various steps of the methods described herein can be implemented by computer code. The computer program is not intended to be limited to any specific programming language and its implementation. It should be understood that various programming languages and their encodings can be used to implement the teachings of the disclosure contained herein. Furthermore, the computer program is not intended to be limited to any specific control flow. There are many other variants of the computer program that can use different control flows without departing from the scope of this specification.
[0033] Moreover, one or more of the steps of the computer program can be executed in parallel rather than sequentially. Such a computer program can be stored on any computer-readable medium. The computer-readable medium can include storage devices such as magnetic disks or optical disks, memory chips, or other storage devices suitable for interfacing with a computer. The computer-readable medium can also include hardwired media (such as exemplified in an Internet system), or include wireless media (such as exemplified in a GSM mobile telephone system). When the computer program is loaded and executed on such a computer, it effectively results in an apparatus that implements the steps of the preferred method.
[0034] In a typical fraud prevention system, the resources required to manage and update hundreds of rules and models are substantial, and many rules are defined based on human experience, which makes maintenance and updating difficult. There is a need to provide a system that can automatically adapt to changes in the environment while quantitatively optimizing to minimize user friction and fraud losses (e.g., profit losses due to fraudulent behavior).
[0035] In the present disclosure, a solution is proposed for making personalized decisions on actions taken by various types of users using deep reinforcement learning (DRL). It is a self-learning system that reinforces its correct decisions and learns from wrong decisions by attempting to maximize the reward after the actions it observes. The system adapts to changes in the environment by exploring and using epsilon-greedy action selection. The reward can be any business metric that can be optimized, such as the profit of all users checked by a fraud prevention system (Profit = Revenue - Cost - Fraud Loss).
[0036] Compared with traditional rule-based and ML model-based systems, the proposed DRL system has the advantage that the DRL system can automatically adapt to the environment. It can advantageously choose to explore unknown results (e.g., the results of actions with low estimated values) and discover changes in the environment by giving random actions with an epsilon probability. In addition, the system uses a quantitatively measurable metric (e.g., the profit obtained from a user within a period of time after an action) as the reward to be maximized by the agent and does not require any manually selected thresholds that may be subjective.
[0037] Figure 1 A block diagram of an exemplary system 100 for reducing the likelihood of fraudulent transactions is shown. In some embodiments, system 100 enables the transaction of goods or services and / or the request for a ride or delivery of physical items (e.g., one or more food items or packages) between a requester and a provider.
[0038] System 100 includes a requester device 102, a provider device 104, an acquirer server 106, a transaction processing server 108, an issuer server 110, an action server 140, and a reference database 150.
[0039] The requester device 102 communicates with the provider device 104 via a connection 112 and can be associated with a user. The connection 112 can be wireless (e.g., via NFC communication, Bluetooth, etc.) or via a network (e.g., the Internet). The requester device 102 also communicates with the action server 140 via a connection 121, where the action server 140 can be configured to receive user-related information (e.g., user profile, transaction history, risk profile, and financial profile of the user) from the requester device 102. The connection 121 can be via a network (e.g., the Internet). The requester device 102 can also be connected to the cloud, which facilitates system 100 in reducing the likelihood of fraudulent transactions. For example, the requester device 102 can directly send signals or data to the cloud via a wireless connection (e.g., via NFC communication, Bluetooth, etc.) or via a network (e.g., the Internet).
[0040] As described above, the provider device 104 typically communicates with the requester device 102 via the transaction processing server 108 and may also be associated with a user. The provider device 104 then communicates with the acquirer server 106 via connection 114. The provider device 104 also communicates with the action server 140 via connection 123, where the action server 140 may be configured to receive data related to the user's transaction (e.g., date, time, details of the goods or services to be purchased, and other similar data) and information related to the user (e.g., user profile, transaction history, risk profile, and the user's financial profile) from the provider device 104. Connections 114 and 123 may be via a network (e.g., the Internet). The provider device 104 may also be connected to a cloud, which facilitates the system 100 in reducing the likelihood of fraudulent transactions. For example, the provider device 104 may send signals or data directly to the cloud via a wireless connection (e.g., via NFC communication, Bluetooth, etc.) or over a network (e.g., the Internet).
[0041] The acquirer server 106 then communicates with the transaction processing server 108 via connection 116. The transaction processing server 108 then communicates with the issuer server 110 via connection 118. Connections 116 and 118 may be via a network (e.g., the Internet).
[0042] The transaction processing server 108 also communicates with the action server 140 via connection 120. Connection 120 may be over a network (e.g., local area network, wide area network, Internet, etc.). In one arrangement, the transaction processing server 108 and the action server 140 are combined, and connection 120 may be an interconnecting bus.
[0043] The action server 140 then communicates with the reference database 150 via respective connections 122. Connections 122 may be over a network (e.g., the Internet). The action server 140 may also be connected to a cloud, which facilitates the system 100 in reducing the likelihood of fraudulent transactions. For example, the action server 140 may send signals or data directly to the cloud via a wireless connection (e.g., via NFC communication, Bluetooth, etc.) or over a network (e.g., the Internet).
[0044] The reference database 150 may include data used by the action server 140 to reduce the likelihood of fraudulent transactions. For example, historical data including previously obtained user-related information (e.g., user profiles, transaction histories, risk profiles, and financial profiles of the user), previous determinations of whether to allow or block user transactions, and the profit history obtained from the user within a period after the previous determination may be stored in the reference database 150. The reference database 150 may also store user-related information (e.g., user profiles, transaction histories, risk profiles, and financial profiles of the user). In an implementation, the reference database 150 may be combined with the action server 140. In an example, the reference database 150 may be managed by an external entity.
[0045] The action server 140 may be configured to estimate the profit that can be obtained from the user after each of allowing the user's transaction and blocking the user's transaction. The estimated profit may be based on user-related information. The action server 140 may then be configured to determine whether the transaction is a fraudulent transaction based on the estimated profit, and allow or block the transaction based on the determination.
[0046] In an implementation, determining whether a transaction is a fraudulent transaction may also be based on historical data (e.g., stored in the reference database 150), which includes previously obtained user-related information, previous determinations of whether to allow or block user transactions, and the profit obtained from the user within a period after the previous determination. The determination may also be based on the probability of randomly making a determination to allow or block the transaction. The action server 140 may also be configured to update the historical data based on the profit obtained within a period after allowing or blocking the transaction. Then, the action server 140 may be trained based on the updated historical data.
[0047] In an implementation, determining whether a transaction is a fraudulent transaction may also be based on maximizing the estimated profit that can be obtained from the user within a period.
[0048] In an implementation, estimating the profit that can be obtained from the user within the period may also include: defining a vector representing the user based on information (the information includes one or more of user profiles, transaction histories, risk profiles, and financial profiles of the user), and estimating a value based on the defined vector.
[0049] In an implementation, the estimation may also include: estimating the profit that can be obtained from the user within a period after blocking the promotion associated with the transaction, where determining whether the transaction is a fraudulent transaction is also based on the estimated profit within the period after blocking the promotion; and blocking the promotion based on the determination.
[0050] In an implementation, the estimation may further include: estimating the profit that can be obtained from the user within a period of time after the user's account is blocked, where determining whether a transaction is a fraudulent transaction is also based on the estimated profit within the period of time after the user's account is blocked; and blocking the user's account based on the determination.
[0051] In an implementation, there may be more than one reference database, where the action server 140 may be configured to determine which database to use for each step during the process of reducing the likelihood of fraudulent transactions. Alternatively, one or more modules instead of the reference database 150 may store the above-mentioned data, where the module may be integrated as part of the action server 140 or external to the action server 140.
[0052] In an illustrative implementation, each of the devices 102, 104 and the servers 106, 108, 110, 140 and / or the reference database 150 provides an interface to enable communication with other connected devices 102, 104 and / or servers 106, 108, 110, 140 and / or the reference database 150. Such communication is facilitated through an application programming interface ("API"). Such an API may be part of a user interface, which may include a graphical user interface (GUI), a web-based interface, a programming interface (such as an application programming interface (API)) and / or a set of remote procedure calls (RPCs) corresponding to interface elements, where the interface elements correspond to a messaging interface for messages of a communication protocol, and / or a suitable combination thereof. For example, in response to an inquiry shown on a GUI running on the corresponding API, the requesting device 102 and / or the providing device 104 may send data related to the transaction. In response to an inquiry shown on a GUI running on the corresponding API, the requesting device 102 and / or the providing device 104 may also send data related to the user.
[0053] The term'server' as used herein may mean a single computing device or multiple interconnected computing devices operating together to perform a specific function. That is, a server may be contained within a single hardware unit or distributed among several or more different hardware units.
[0054] The action server 140 is associated with an entity (such as a regulator of a company or organization or service). In one arrangement, the action server 140 is owned and operated by the entity operating the transaction processing server 108. In such an arrangement, the action server 140 may be implemented as part of the transaction processing server 108 (such as a computer program module, a computing device, etc.).
[0055] The transaction processing server 108 can also be configured to manage user registration. A registered user has a transaction account (see the discussion above), which includes the user's detailed information. The registration process is referred to as on-boarding. A user can use the requester device 102 or the provider device 104 to perform the on-boarding to the transaction processing server 108.
[0056] It may not be necessary to have a transaction account at the transaction processing server 108 to access the functions of the transaction processing server 108. However, there are functions available for registered users. These additional functions will be discussed below.
[0057] The on-boarding process of the user is performed by the user through one of the requester device 102 or the provider device 104. In one arrangement, the user downloads an application (which includes an API to interact with the transaction processing server 108) to the requester device 102 or the provider device 104. In another arrangement, the user accesses a website (which includes an API to interact with the transaction processing server 108) on the requester device 102 or the provider device 104. Then, the user can interact with the action server 140. The user can be a requester or a provider associated with the requester device 102 or the provider device 104 respectively.
[0058] The registration details can include, for example, the user's name, the user's address, date of birth, emergency contact, blood type or other healthcare information, next of kin contact, the permission to retrieve data and information from the requester device 102 and / or the provider device 104 to reduce the likelihood of fraudulent transactions, such as the permission to receive data related to the user's transactions and information related to the user (e.g., user profile, transaction history, risk profile, and user financial profile) from the requester device 102 and / or the provider device 104. Alternatively, another mobile device can be selected to retrieve data instead of the requester device 102 and / or the provider device 104. Once on-boarded, the user will have a transaction account that stores all the detailed information.
[0059] The requester device 102 is associated with a customer (or requester) who is a party to a transaction that occurs between the requester device 102 and the provider device 104 or between the requester device 102 and the action server 140. The requester device 102 can be a computing device, such as a desktop computer, an interactive voice response (IVR) system, a smart phone, a laptop computer, a personal digital assistant computer (PDA), a mobile computer, a tablet computer, etc. The requester device 102 can be associated with a user who initiates a transaction.
[0060] The requesting device 102 includes a transaction credential (e.g., a payment account) of the requester that enables the requesting device 102 to be a party to a payment transaction. If the requester has a transaction account, the transaction account may also be included (i.e., stored) in the requesting device 102. For example, a mobile device (as the requesting device 102) may store the customer's transaction account in the mobile device.
[0061] In one exemplary arrangement, the requesting device 102 is a computing device in a watch or similar wearable and is equipped with a wireless communication interface (e.g., an NFC interface). The requesting device 102 can then communicate electronically with the providing device 104 regarding a transaction request. The customer uses the watch or similar wearable to make a transaction request by pressing a button on the watch or wearable.
[0062] The providing device 104 is associated with a provider who is also a party to the transaction request that takes place between the requesting device 102 and the providing device 104. The providing device 104 can be a computing device such as a desktop computer, an interactive voice response (IVR) system, a smart phone, a laptop computer, a personal digital assistant computer (PDA), a mobile computer, a tablet computer, etc. The providing device 104 may be associated with the initiator or provider of the transaction (e.g., a driver or delivery person responding to a ride or delivery request).
[0063] Hereinafter, the term "provider" refers to the service provider and any third party associated with providing a product or service for purchase or a ride or delivery service via the providing device 104. Thus, the provider's transaction account refers to both the provider's transaction account and the transaction accounts of third parties associated with the provider (e.g., a ride coordination party or a merchant). It should be understood that the providing device 104 may also be used by a user to conduct a transaction.
[0064] If the provider has a transaction account, the transaction account may also be included (i.e., stored) in the providing device 104. For example, a mobile device (as the providing device 104) may store the provider's transaction account in the mobile device.
[0065] In one exemplary arrangement, the providing device 104 is a computing device in a watch or similar wearable and is equipped with a wireless communication interface (e.g., an NFC interface). The providing device 104 can then communicate electronically with the requester to make or respond to a transaction request by pressing a button on the watch or wearable.
[0066] The acquirer server 106 is associated with an acquirer, which can be an entity (such as a company or organization) that issues (e.g., establishes, manages, administers) payment accounts (such as financial bank accounts) for merchants. Examples of acquirers include banks and / or other financial institutions. As discussed above, the acquirer server 106 can include one or more computing devices that are configured to establish communication with another server (such as the transaction processing server 108) by exchanging messages and / or relaying information to other servers. The acquirer server 106 forwards payment transactions related to a transaction request to the transaction processing server 108.
[0067] The transaction processing server 108 is configured to process procedures related to a transaction account by, for example, relaying data and information associated with the transaction to other servers in the system 100, such as the action server 140. In an example, the transaction processing server 108 can transmit data related to a user transaction (such as date, time, details of the goods or services to be purchased, and other similar data) to the action server 140 on behalf of the requester device 102 or the provider device 104. The transaction processing server 108 can use various different protocols and procedures to process the transaction. It should be understood that payment for the transaction can be made via various methods, such as credit cards, debit cards, digital wallets, buy-now-pay-later schemes, and other similar payment methods.
[0068] The issuer server 110 is associated with an issuer and can include one or more computing devices for performing payment transactions. The issuer can be an entity (such as a company or organization) that issues (e.g., establishes, manages, administers) transaction vouchers or payment accounts (such as financial bank accounts) associated with the owner of the requester device 102. As discussed above, the issuer server 110 can include one or more computing devices that are configured to establish communication with another server (such as the transaction processing server 108) by exchanging messages and / or relaying information to other servers.
[0069] The reference database 150 is a database or server associated with an entity (e.g., a company or an organization) that manages (e.g., establishes, operates) data related to users, transactions, products, services, and other similar data related to the entity, for example. In one arrangement, the reference database 150 may include data used by the action server 140 to reduce the likelihood of fraudulent transactions. For example, previously obtained information related to the user (e.g., user profile, transaction history, risk profile, financial profile, and other similar information related to the user), previous determinations of whether to allow or block a user transaction, and historical data of the profit obtained from the user within a period of time after the previous determination may be stored in the reference database 150. The reference database 150 may also store information related to the user (e.g., user profile, transaction history, risk profile, and financial profile of the user). In an implementation, the reference database 150 may be combined with the action server 140. In an example, the reference database 150 may be managed by an external entity.
[0070] Advantageously, the system 100 advantageously enables a fraud prevention system that adapts to changes in the environment by exploring actions to be taken and uses quantitatively measurable metrics (e.g., profit within a specific period of time) to strengthen its decision-making.
[0071] Figure 2 A schematic diagram of an exemplary action server 140 according to various embodiments is shown. The action server 140 may include a data module 260 configured to receive data and information from the requester device 102, the provider device 104, the transaction processing server 108, the reference database 150, the cloud, and other information sources to reduce the likelihood of fraudulent transactions by the action server 140. For example, the data module 260 may be configured to receive historical data and information related to the user, as well as the data and information required to process the historical data and information related to the user, estimate the profit that can be obtained within a period of time after the action (e.g., estimate the profit that can be obtained within a period of time after allowing the user's transaction, blocking the transaction, blocking the promotion associated with the transaction, banning the user's account, or other similar actions), determine whether the transaction is a fraudulent transaction based on the estimated profit, and other similar processes from the requester device 102, the provider device 104, the transaction processing server 108, the reference database 150, and / or other information sources. The data module 260 may also be configured to send information related to determining whether the transaction is a fraudulent transaction to the requester device 102, the provider device 104, the transaction processing server 108, or other destinations that need the information.
[0072] The action server 140 may include a status module 262 configured to define a vector representing the user status based on information related to the user, the information including one or more of a user profile, a transaction history, a risk profile, a financial profile of the user, and other similar information related to the user. The vector definition process is further described in Figure 4 below.
[0073] The action server 140 may further include an estimation module 264 configured to estimate the profit that can be obtained from the user within a period of time after each of allowing the user's transaction and blocking the user's transaction, the estimated profit being based on information related to the user. The estimation process is further described in Figure 4 below.
[0074] The action server 140 may further include an action module 266 configured to determine whether a transaction is a fraudulent transaction based on the estimated profit. The action module 266 may also be configured to allow or block the transaction based on the determination. The determination process is further described in Figure 4 below.
[0075] The action server 140 may further include a training module 268 configured to update historical data based on the profit obtained within a period of time after allowing or blocking a transaction. The training module 268 may also be configured to train the action server 140 based on the updated historical data. The training process is further described in Figure 3 below.
[0076] In an implementation, determining whether a transaction is a fraudulent transaction may also be based on historical data (e.g., historical data stored in the reference database 150), the historical data including previously obtained information related to the user, previous determinations of whether to allow or block the user's transaction, and the profit obtained from the user within a period of time after the previous determination. The determination may also be based on the probability of randomly making a determination to allow or block a transaction.
[0077] In an implementation, determining whether a transaction is a fraudulent transaction may also be based on maximizing the estimated profit that can be obtained from the user within a period of time.
[0078] In an implementation, estimating the profit that can be obtained from the user within the period of time may further include: defining a vector representing the user based on information (the information including one or more of a user profile, a transaction history, a risk profile, and a financial profile of the user), and estimating a value based on the defined vector.
[0079] In an implementation, the estimation may further include: estimating the profit that can be obtained from a user within a period of time after blocking a promotion associated with a transaction, wherein determining whether a transaction is a fraudulent transaction is also based on the estimated profit within the period of time after blocking the promotion; and blocking the promotion based on the determination.
[0080] In an implementation, the estimation may further include: estimating the profit that can be obtained from a user within a period of time after blocking the user's account, wherein determining whether a transaction is a fraudulent transaction is also based on the estimated profit within the period of time after blocking the user's account; and blocking the user's account based on the determination.
[0081] Each of the data module 260, the status module 262, the estimation module 264, the action module 266, and the training module 268 may also communicate with a processing module (not shown) of the action server 140, for example, for coordinating functions during corresponding tasks and processes. The data module 260 may also be configured to communicate with each of the processing module, the status module 262, the estimation module 264, the action module 266, and the training module 268 and store their data and information. Alternatively, all tasks and functions required to adaptively reduce the likelihood of fraudulent transactions may be performed by a single processor of the action server 140.
[0082] Figure 3 An overview 300 of reinforcement learning (RL) according to various embodiments is depicted. A typical framework for an RL scenario is as follows: An agent 302 takes an action 304 in an environment 306, which is interpreted as a representation of a reward 308 and a state 310, and then fed back into the agent 302. The environment 306 is where the user reacts to the action 304 taken by the agent 304 in real life. In an example, the user may choose to continue making further transactions on the platform, which may depend on whether the promotion used with the user's transaction before the action 304 generates a positive or negative reward / profit. In another example, the user may choose to stop using the platform, resulting in zero reward / profit. In another example, the user may commit fraud, resulting in a negative profit for the platform. Therefore, the agent 302 learns to decide what action to take for each user state (e.g., user state or user characteristics) according to a goal, so as to maximize the reward / profit observed from the user in the long run.
[0083] Figure 4 An example illustration 400 depicting how to determine an action taken in response to a transaction request according to various embodiments is shown. The illustration 400 may also be referred to as a DRL fraud prevention system 400, where the system 400 determines whether a transaction is a fraudulent transaction.
[0084] The steps to implement the system 400 are as follows. First, define the state 402. The state 402 consists of information related to a user (e.g., a user associated with a transaction), including but not limited to a feature list 404, such as a user profile, transaction history, risk judgment, financial profile, and other similar features related to the user. It is a vector representation of the user at the time of fraud inspection and can be referred to as vector 402. The user profile may refer to detailed information about the user, such as country, city, platform, device information, predicted gender of the user (e.g., obtained from other ML models) if not registered on the platform (e.g., during the onboarding registration of the transaction processing server 108), predicted age of the user (e.g., obtained from other ML models) if not registered on the platform (e.g., during the onboarding registration of the transaction processing server 108), and other similar detailed information. The risk judgment may refer to the level of risk that the user poses to the platform (e.g., determined by the platform based on the user's transaction history and past activities). The financial profile of the user may refer to information related to, for example, one or more credit or debit accounts and the status of each account of the user.
[0085] Second, define the agent 406. In an implementation, the agent 406 is a deep neural network that takes the vector 402 as input and outputs an estimated value (e.g., expected future reward, such as the estimated profit that can be obtained from the user over a period of time, such as the next X days (X is an adjustable parameter)) for each action (from the fraud prevention system 400) of the user state represented by the vector 402. For example, if allowing a transaction results in an estimated negative profit (e.g., indicating that allowing the transaction causes the company to incur a loss), then the transaction can be determined to be a fraudulent transaction.
[0086] Third, the agent 406 can be trained. Retrieve historical data (e.g., historical data related to the existing fraud prevention system rules of the platform, such as including previously obtained information related to the user, previous determinations of whether to allow or block the user's transactions, and the profit obtained from the user during the period after the previous determination) for training, allowing the agent 406 to imitate its decisions to ensure good baseline performance. The data can be formatted as [state, action, reward], where the reward can be the profit obtained from the user over a period of time (such as the next X days (X is an adjustable parameter)) after fraud inspection and the action.
[0087] Fourth, deploy system 400. System 400 can be configured to use epsilon-greedy action selection online, where it randomly selects action 412 from multiple actions 410 (e.g., allowing a transaction request, blocking a transaction request, blocking a promotion associated with the transaction request, banning the user's account, or other similar actions) with an epsilon probability and learns from the observed rewards (e.g., the value 408 obtained as a result of action 412, such as the profit obtained from the user within a period of time after action 412) to explore the unknown in environment 414. This advantageously allows agent 406 to improve its understanding of the environment and adapt to changes, which in the long run leads to better rewards. At other times, it exploits by selecting the action with the maximum estimated reward, which is essentially profit maximization.
[0088] In the first example, during fraud checking, agent 406 can estimate that allowing the transaction results in a negative profit and blocking the transaction results in a positive profit. Based on this estimate, system 400 can be configured to determine that this is a fraudulent transaction. Due to the high likelihood of exploitation (e.g., to maximize profit), agent 406 can take a 'greedy' action (e.g., an action that maximizes profit) by blocking the transaction. In the second example, agent 406 can estimate that allowing the transaction results in a positive profit and blocking the transaction results in a negative profit. Based on this estimate, system 400 can be configured to determine that this is not a fraudulent transaction. Due to the high likelihood of exploitation (e.g., to maximize profit), agent 406 can thus allow the transaction to proceed. In both cases, there may be a small probability of 1 - epsilon to explore (e.g., the probability of randomly making a decision to allow or block the transaction, or the probability of taking an action different from the 'correct action' (e.g., the 'correct action' of blocking the transaction in the first example and allowing the transaction in the second example)), such that system 400 can learn from the results of the actions taken by agent 406.
[0089] Figure 5 An exemplary flowchart of a method 500 for reducing the likelihood of fraudulent transactions according to various embodiments is shown. In step 502, estimate the profit that can be obtained from the user within a period of time after each of allowing the user's transaction and blocking the user's transaction, where the estimated profit is based on information related to the user. In step 504, determine whether the transaction is a fraudulent transaction based on the estimated profit. In step 506, allow or block the transaction based on this determination.
[0090] Figure 6AIllustrates an exemplary computer system 1400, according to which the described action server 140 can be practiced. The computer system 1400 includes a computer module 1401. The external modem - transceiver device 1416 can be used by the computer module 1401 to communicate to and from a communication network 1420 via a connection 1421. The communication network 1420 can be a wide area network (WAN), such as the Internet, a cellular telecommunications network, or a private WAN. In the case where the connection 1421 is a telephone line, the modem 1416 can be a traditional "dial-up" modem. Alternatively, in the case where the connection 1421 is a high-capacity (e.g., cable) connection, the modem 1416 can be a broadband modem. A wireless modem can also be used for a wireless connection to the communication network 1420.
[0091] The computer module 1401 generally includes at least one processor unit 1405 and a memory unit 1406. For example, the memory unit 1406 can have a semiconductor random access memory (RAM) and a semiconductor read-only memory (ROM). The computer module 1401 also includes an interface 1408 for the external modem 1416. In some implementations, the modem 1416 can be incorporated within the computer module 1401, for example, within the interface 1408. The computer module 1401 also has a local network interface 1411, which permits the computer system 1400 to be coupled via a connection 1423 to a local communication network 1422 known as a local area network (LAN). As Figure 6A illustrated, the local communication network 1422 can also be coupled via a connection 1424 to the wide area network 1420, and this connection will typically include a so-called "firewall" device or a device with similar functionality. The local network interface 1411 can include an Ethernet circuit card, a Bluetooth® wireless device, or an IEEE 802.11 wireless device; however, many other types of interfaces can be practiced for the interface 1411.
[0092] The I / O interface 1408 can provide either or both of serial and parallel connections, the former typically implemented according to the Universal Serial Bus (USB) standard and having a corresponding USB connector (not shown). A storage device 1409 is provided and this storage device typically includes a hard disk drive (HDD) 1410. Other storage devices, such as floppy disk drives and tape drives (not shown), can also be used. An optical disc drive 1412 is typically provided to act as a non-volatile data source. For example, portable memory devices (such as optical discs, USB-RAM, portable external hard disk drives, and floppy disks) can be used as suitable data sources for the system 1400.
[0093] The components 1405 to 1412 of the computer module 1401 typically communicate via the interconnect bus 1304 and in a manner enabling the conventional operating modes of the computer system 1400 known to those skilled in the relevant art. For example, the processor 1405 is coupled to the system bus 1404 using the connection 1418. Similarly, the memory 1406 and the optical disk drive 1412 are coupled to the system bus 1404 via the connection 1419. Examples of computers on which the described apparatus can be practiced include IBM-PC and its compatibles, SunSparcstations, Apple, or similar computer systems.
[0094] The method 500 performed by the action server 140 can be implemented using the computer system 1400. These processes can be implemented as one or more software applications 1433 executable within the computer system 1400. Specifically, the method 500 is implemented by instructions in the software 1433 practiced within the computer system 1400. The software instructions can be formed into one or more code modules, each code module for performing one or more specific tasks. The software can also be divided into two separate parts, where the first part and the corresponding code modules execute the method 500, and the second part and the corresponding code modules manage the user interface between the first part and the user.
[0095] The software can be stored in a computer-readable medium, including, for example, the storage devices described below. The software is loaded from the computer-readable medium into the computer system 1400 and then executed by the computer system 1400. A computer-readable medium having such software or computer program recorded thereon is a computer program product. The use of the computer program product in the computer system 1400 preferably implements an advantageous device for the action server 140.
[0096] The software 1433 is typically stored in the HDD 1410 or the memory 1406. The software is loaded from the computer-readable medium into the computer system 1400 and executed by the computer system 1400. Thus, for example, the software 1433 can be stored on an optically readable disk storage medium (e.g., CD-ROM) 1425 read by the optical disk drive 1412. A computer-readable medium having such software or computer program recorded thereon is a computer program product. The use of the computer program product in the computer system 1400 preferably implements a device for the action server 140.
[0097] In some instances, the application 1433 can be encoded on one or more CD-ROMs 1425 for supply to a user and read via a corresponding drive 1412, or alternatively, can be read by the user from a network 1420 or 1422. Further, the software can also be loaded into the computer system 1400 from other computer-readable media. A computer-readable storage medium is any non-transitory tangible storage medium that provides recorded instructions and / or data to the computer system 1400 for execution and / or processing. Examples of such storage media include floppy disks, magnetic tapes, optical disks, hard disk drives, ROMs or integrated circuits, USB memories, magneto-optical disks, or computer-readable cards (such as PCMCIA cards), etc., whether such devices are internal or external to the computer module 1401. Examples of transitory or non-tangible computer-readable transmission media that can also participate in providing software, applications, instructions, and / or data to the computer module 1401 include radio or infrared transmission channels to another computer or networked device and network connections, as well as the Internet or intranet including information recorded on email transmissions and websites, etc.
[0098] The second part of the application 1433 and the corresponding code modules mentioned above can be executed to implement one or more graphical user interfaces (GUIs) to be presented or otherwise represented on a display. By typically manipulating a keyboard and mouse, the user of the computer system 1400 and the application can manipulate the interface in a functionally adaptable manner to provide control commands and / or input to the application associated with the GUI. Other forms of functionally adaptable user interfaces can also be implemented, such as an audio interface that utilizes voice prompts output via a speaker and user voice commands input via a microphone.
[0099] It should be understood that the structural context of the computer system 1400 (i.e., the action server 140) is presented by way of example only. Thus, in some arrangements, one or more features of the computer system 1400 can be omitted. Additionally, in some arrangements, one or more features of the computer system 1400 can be combined together. Further, in some devices, one or more features of the computer system 1400 can be divided into one or more component parts.
[0100] Figure 7Shows an implementation of the transaction processing server 108. In this implementation, the transaction processing server 108 can generally be described as a physical device including at least one processor 802 and at least one memory 804 including computer program code. The at least one memory 804 and the computer program code are configured to, together with the at least one processor 802, cause the transaction processing server 108 to facilitate the operations described in method 500. The transaction processing server 108 may also include a transaction processing module 806. The memory 804 stores the computer program code, and the processor 802 compiles the program code to cause the transaction processing module 806 to perform corresponding functions.
[0101] Reference Figure 1 , the transaction processing module 806 performs functions of communicating with the requester device 102 and the provider device 104; and the acquirer server 106 and the issuer server 110 respectively receive and send transaction, ride, or delivery requests or other similar messages. The transaction processing module 806 may be configured to process processes related to a transaction account by, for example, forwarding data and information associated with a transaction to other servers in the system 100, such as the action server 140. For example, data related to a user's transaction (e.g., date, time, details of the goods or services to be purchased, and other similar data), information related to the user (e.g., user profile, transaction history, risk profile, financial profile, and other similar information related to the user), and other similar data may be provided to the action server 140 and processed to determine actions to be taken with respect to the user. The transaction processing server 806 may use various different protocols and procedures to process payment and / or travel coordination requests.
[0102] Figure 8 Shows an alternative implementation of the action server 140 (i.e., the computer system 1400). In the alternative implementation, the action server 140 can generally be described as a physical device including at least one processor 902 and at least one memory 904 including computer program code. The at least one memory 904 and the computer program code are configured to, together with the at least one processor 902, cause the action server 140 to perform the operations described in method 500. The action server 140 may also include a data module 906, a status module 908, an estimation module 910, an action module 912, and a training module 914. The memory 904 stores the computer program code, and the processor 902 compiles the program code to cause each of modules 906 to 914 to perform their corresponding functions.
[0103] Reference Figures 1 to 5, the status module 908 performs the following functions: defining a vector representing the user's status based on information related to the user, the information including one or more of a user profile, a transaction history, a risk profile, the user's financial profile, and other similar information related to the user.
[0104] Reference Figures 1 to 5 , the estimation module 910 performs the following functions: estimating the profit that can be obtained from the user within a period of time after each of allowing the user's transaction and blocking the user's transaction, the estimated profit being based on information related to the user.
[0105] Reference Figures 1 to 5 , the action module 912 performs the following functions: determining whether a transaction is a fraudulent transaction based on the estimated profit. The action module 912 can also be configured to allow or block the transaction based on the determination.
[0106] Reference Figures 1 to 5 , the training module 914 performs the following functions: updating historical data based on the profit obtained within a period of time after allowing or blocking a transaction. The training module 914 can also be configured to train the action server 140 based on the updated historical data.
[0107] In an implementation, determining whether a transaction is a fraudulent transaction can also be based on historical data (e.g., stored in the reference database 150), the historical data including previously obtained information related to the user, previous determinations of whether to allow or block the user's transaction, and the profit obtained from the user within a period of time after the previous determination. The determination can also be based on the probability of randomly making a determination to allow or block the transaction.
[0108] In an implementation, determining whether a transaction is a fraudulent transaction can also be based on maximizing the estimated profit that can be obtained from the user within a period of time.
[0109] In an implementation, estimating the profit that can be obtained from the user within the period of time can also include: defining a vector representing the user based on information including one or more of a user profile, a transaction history, a risk profile, and the user's financial profile; and estimating a value based on the defined vector.
[0110] In an implementation, the estimation can also include: estimating the profit that can be obtained from the user within a period of time after blocking a promotion associated with the transaction, where determining whether the transaction is a fraudulent transaction is also based on the estimated profit within the period of time after blocking the promotion; and blocking the promotion based on the determination.
[0111] In an implementation, the estimation may further include: estimating the profit that can be obtained from the user within a period of time after the user's account is blocked, wherein determining whether a transaction is a fraudulent transaction is further based on the estimated profit within the period of time after the user's account is blocked; and blocking the user's account based on the determination.
[0112] Reference Figures 1 to 5 , data module 906 performs the function of receiving data and information from the requester device 102, the provider device 104, the transaction processing server 108, the reference database 150, the cloud, and other information sources to facilitate method 500. For example, data module 906 may be configured to receive historical data and information related to the user, as well as the data and information required to process the historical data and information related to the user, estimate the profit that can be obtained within a period of time after an action (e.g., estimate the profit that can be obtained within a period of time after allowing the user's transaction, blocking a transaction, blocking a promotion associated with the transaction, blocking the user's account, or other similar actions), determine whether a transaction is a fraudulent transaction based on the estimated profit, and other similar processes from the requester device 102, the provider device 104, the transaction processing server 108, the reference database 150, and / or other information sources. Data module 906 may also be configured to send information related to determining whether a transaction is a fraudulent transaction to the requester device 102, the provider device 104, the transaction processing server 108, or other destinations that require information.
[0113] Figure 6B Depicts a general-purpose computer system 1500 on which the described combination of the transaction processing server 108 and the action server 140 may be practiced. Computer system 1500 includes computer module 1501. An external modem - transceiver device 1516 may be used by computer module 1501 to communicate with and from communication network 1520 via connection 1521. Communication network 1520 may be a wide area network (WAN), such as the Internet, a cellular telecommunications network, or a private WAN. In the case where connection 1521 is a telephone line, modem 1516 may be a traditional "dial-up" modem. Alternatively, in the case where connection 1521 is a high-capacity (e.g., cable) connection, modem 1516 may be a broadband modem. A wireless modem may also be used for a wireless connection to communication network 1520.
[0114] Computer module 1501 generally includes at least one processor unit 1505 and a memory unit 1506. For example, the memory unit 1506 may have a semiconductor random access memory (RAM) and a semiconductor read-only memory (ROM). Computer module 1501 also includes an interface 1508 for an external modem 1516. In some implementations, the modem 1516 may be incorporated within the computer module 1501, such as within the interface 1508. Computer module 1501 also has a local network interface 1511 that permits the computer system 1500 to be coupled via a connection 1523 to a local communication network 1522 known as a local area network (LAN). As Figure 6B illustrated, the local communication network 1522 may also be coupled via a connection 1524 to a wide area network 1520, and this connection will generally include a device such as a so-called "firewall" device or a device with a similar function. The local network interface 1511 may include an Ethernet circuit card, a Bluetooth® wireless device, or an IEEE 802.11 wireless device; however, a variety of other types of interfaces may be practiced for the interface 1511.
[0115] The I / O interface 1508 may provide either or both of serial and parallel connections, the former typically being implemented according to the Universal Serial Bus (USB) standard and having a corresponding USB connector (not shown). A storage device 1509 is provided and this storage device typically includes a hard disk drive (HDD) 1510. Other storage devices may also be used, such as floppy disk drives and tape drives (not shown). An optical disk drive 1512 is typically provided to act as a non-volatile data source. For example, portable memory devices such as optical disks, USB-RAMs, portable external hard disk drives, and floppy disks may be used as suitable data sources for the system 1500.
[0116] The components 1505 to 1512 of the computer module 1501 generally communicate via an interconnect bus 1504 and in a manner that enables the conventional operating modes of the computer system 1500 known to those skilled in the relevant art. For example, the processor 1505 is coupled to the system bus 1504 using a connection 1518. Similarly, the memory 1506 and the optical disk drive 1512 are coupled to the system bus 1504 via a connection 1519. Examples of computers on which the described devices may be practiced include IBM-PCs and their compatibles, SunSparcstations, Apples, or similar computer systems.
[0117] The steps of method 500, which are executed by action server 140 and facilitated by transaction processing server 108, can be implemented using computer system 1500. For example, the steps of method 500 executed by action server 140 can be implemented as one or more software applications 1533 executable within computer system 1500. Specifically, the steps of method 500 are implemented by instructions in software 1533 executing within computer system 1500. The software instructions can be formed into one or more code modules, each code module for performing one or more specific tasks. The software can also be divided into two separate parts, where the first part and corresponding code modules execute the steps of method 500, and the second part and corresponding code modules manage the user interface between the first part and the user.
[0118] The software can be stored in a computer-readable medium, including, for example, the storage devices described below. The software is loaded from the computer-readable medium into computer system 1500 and then executed by computer system 1500. A computer-readable medium having such software or a computer program recorded thereon is a computer program product. The use of the computer program product in computer system 1500 preferably implements an advantageous apparatus for combined transaction processing and action server.
[0119] Software 1533 is typically stored in HDD 1510 or memory 1506. The software is loaded from the computer-readable medium into computer system 1500 and executed by computer system 1500. Thus, for example, software 1533 can be stored on an optically readable disc storage medium (e.g., CD-ROM) 1525 read by optical disc drive 1512. A computer-readable medium having such software or a computer program recorded thereon is a computer program product. The use of the computer program product in computer system 1500 preferably implements an apparatus for combined transaction processing and action server.
[0120] In some instances, the application 1533 may be encoded on one or more CD-ROMs 1525 for supply to a user and read via a corresponding drive 1512, or alternatively, may be read by the user from a network 1520 or 1522. Further, the software may also be loaded into the computer system 1500 from other computer-readable media. A computer-readable storage medium is any non-transitory tangible storage medium that provides recorded instructions and / or data to the computer system 1500 for execution and / or processing. Examples of such storage media include floppy disks, magnetic tapes, optical disks, hard disk drives, ROMs or integrated circuits, USB memories, magneto-optical disks, or computer-readable cards (such as PCMCIA cards), etc., whether such devices are internal or external to the computer module 1501. Examples of transitory or non-tangible computer-readable transmission media that may also participate in providing software, applications, instructions, and / or data to the computer module 1501 include radio or infrared transmission channels to another computer or networked device and network connections, as well as the Internet or intranet including information recorded on email transmissions and websites, etc.
[0121] The second part of the application 1533 and the corresponding code modules mentioned above may be executed to implement one or more graphical user interfaces (GUIs) to be presented or otherwise represented on a display. By typically manipulating a keyboard and mouse, the user and the application of the computer system 1500 can manipulate the interface in a functionally adaptable manner to provide control commands and / or input to the application associated with the GUI. Other forms of functionally adaptable user interfaces may also be implemented, such as an audio interface that utilizes voice prompts output via a speaker and user voice commands input via a microphone.
[0122] It should be understood that the structural context of the computer system 1500 (i.e., the combined transaction processing and action server 1500) is presented merely as an example. Thus, in some arrangements, one or more features of the server 1500 may be omitted. Additionally, in some arrangements, one or more features of the server 1500 may be combined together. Additionally, in some arrangements, one or more features of the server 1500 may be divided into one or more component parts.
[0123] Figure 9An alternative implementation of the combined transaction processing and action server (i.e., computer system 1500) is shown. In the alternative implementation, the combined transaction processing and action server can generally be described as a physical device including at least one processor 1002 and at least one memory 904 including computer program code. The at least one memory 1004 and the computer program code are configured to, together with the at least one processor 1002, cause the combined transaction processing and action server to perform the operations described in the steps of method 500. The combined transaction processing and action server may also include a transaction processing module 806, a data module 906, a status module 908, an estimation module 910, an action module 912, and a training module 914. The memory 1004 stores the computer program code, and the processor 1002 compiles the program code to cause each of the modules 806 to 912 to perform their respective functions. The transaction processing module 806 performs the same functions as those described for the same transaction processing module in Figure 9 The same functions as those described for the same corresponding modules in Figure 8 are performed by the data module 906, the status module 908, the estimation module 910, the action module 912, and the training module 914.
[0124] Those skilled in the art should understand that various variations and / or modifications can be made to the present disclosure shown in the specific embodiments without departing from the scope of the broadly described specification. Therefore, the embodiments of the present invention are considered to be illustrative rather than restrictive in all respects.
Claims
1. A method for reducing the likelihood of fraudulent transactions, comprising: estimating, by a server, the profit that can be obtained from the user within a period of time after each of allowing the user's transaction and blocking the user's transaction, the estimated profit being based on information related to the user; determining, by the server, whether the transaction is a fraudulent transaction based on the estimated profit, and allowing or blocking the transaction based on the determination.
2. The method according to claim 1, wherein, determining whether the transaction is a fraudulent transaction is further based on historical data, the historical data including previously obtained information related to the user, previous determinations of whether to allow or block the user's transaction, and the profit obtained from the user within the period of time after the previous determination.
3. The method according to claim 2, wherein, determining whether the transaction is a fraudulent transaction is further based on the probability of randomly making a determination to allow or block the transaction.
4. The method according to claim 1, wherein, determining whether the transaction is a fraudulent transaction is further based on maximizing the estimated profit obtained from the user within the period of time.
5. The method according to claim 1, wherein, estimating the profit that can be obtained from the user within the period of time further includes: defining a vector representing the user based on the information, the information including one or more of a user profile, a transaction history, a risk profile, and a financial profile of the user; and estimating a value based on the defined vector.
6. The method according to claim 1, wherein, estimating the profit that can be obtained from the user within the period of time further includes: estimating the profit that can be obtained from the user within the period of time after blocking a promotion associated with the transaction, wherein determining whether the transaction is a fraudulent transaction is further based on the estimated profit within the period of time after blocking the promotion; and blocking the promotion based on the determination.
7. The method according to claim 1, wherein, estimating the profit that can be obtained from the user within the period of time further includes: estimating the profit that can be obtained from the user within the period of time after blocking the user's account, wherein determining whether the transaction is a fraudulent transaction is further based on the estimated profit within the period of time after blocking the user's account; and blocking the user's account based on the determination.
8. The method according to claim 2, further comprising: updating the historical data based on the profit obtained within the period of time after allowing or blocking the transaction; and training the server based on the updated historical data.
9. A system for reducing the likelihood of fraudulent transactions, comprising: at least one processor; and at least one memory including computer program code; the at least one memory and the computer program code are configured to, together with the at least one processor, cause the system to at least: estimate the profit that can be obtained from the user within a period of time after each of allowing the user's transaction and blocking the user's transaction, the estimated profit being based on information related to the user; Determine whether the transaction is a fraudulent transaction based on the estimated profit, and allow or block the transaction based on the determination.
10. The system according to claim 9, wherein, Determining whether the transaction is a fraudulent transaction is further based on historical data, the historical data including previously obtained information related to the user, previous determinations of whether to allow or block the user's transactions, and the profit obtained from the user during the time period after the previous determination.
11. The system according to claim 10, wherein, Determining whether the transaction is a fraudulent transaction is further based on the probability of randomly making a determination to allow or block the transaction.
12. The system according to claim 9, wherein, Determining whether the transaction is a fraudulent transaction is further based on maximizing the estimated profit obtained from the user during the time period.
13. The system according to claim 9, wherein, Estimating the profit that can be obtained from the user during the time period further includes: defining a vector representing the user based on the information, the information including one or more of a user profile, a transaction history, a risk profile, and a financial profile of the user; and estimating a value based on the defined vector.
14. The system according to claim 8, wherein, Estimating the profit that can be obtained from the user during the time period further includes: estimating the profit that can be obtained from the user during the time period after blocking the promotion associated with the transaction, wherein determining whether the transaction is a fraudulent transaction is further based on the estimated profit during the time period after blocking the promotion; and blocking the promotion based on the determination.
15. The system according to claim 9, wherein, Estimating the profit that can be obtained from the user during the time period further includes: estimating the profit that can be obtained from the user during the time period after blocking the user's account, wherein determining whether the transaction is a fraudulent transaction is further based on the estimated profit during the time period after blocking the user's account; and blocking the user's account based on the determination.
16. The system according to claim 10, is further configured to: update the historical data based on the profit obtained during the time period after allowing or blocking the transaction; and train the server based on the updated historical data.