Fraud Detection Based on Generative Adversarial Networks (GANs)

By generating synthetic transaction data through generative adversarial networks (GANs), this approach addresses the shortcomings of existing fraud detection methods that rely on historical transaction data. It enables effective identification and real-time prevention of new fraudulent transactions, protecting privacy and reducing data requirements.

CN122180980APending Publication Date: 2026-06-09VISA INTERNATIONAL SERVICE ASSOCIATION
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
VISA INTERNATIONAL SERVICE ASSOCIATION
Filing Date
2023-11-06
Publication Date
2026-06-09

AI Technical Summary

Technical Problem

Existing fraud detection methods rely on historical transaction data, which makes it difficult to effectively identify new types of fraudulent transactions. They also require a large amount of historical data and human resources, which may violate data protection regulations and lead to outdated or invalid models.

Method used

Generative Adversarial Networks (GANs) are used to generate synthetic transaction data. The creator model receives real transaction data and fraud detection rules to generate synthetic transaction data, and the evaluator model classifies and updates the fraud detection rules to achieve iterative feedback and improve the effectiveness of fraud detection.

Benefits of technology

The generated synthetic transaction data can effectively identify new types of fraudulent transactions, reduce reliance on historical data, protect personal privacy, comply with regulatory requirements, and prevent fraud in real time.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122180980A_ABST
    Figure CN122180980A_ABST
Patent Text Reader

Abstract

The present disclosure provides a variety of solutions that enable a generative adversarial network (GAN) for fraud detection. For example, in one aspect, the present disclosure provides a system that includes a creator model and an evaluator model. The creator model is to receive real transaction data corresponding to real transactions performed across a payment network, receive fraud detection rules to identify fraudulent transactions, and generate synthetic transaction data based on the real transaction data and the fraud detection rules. The synthetic transaction data corresponds to synthetic transactions that are not actually performed across the payment network. The evaluator model is to receive the synthetic transaction data and classify at least some of the synthetic transactions as fraudulent transactions.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] At least some aspects of this disclosure relate to detecting fraud related to payment transactions, and more specifically, to detecting fraud related to real transaction data based on synthetic transaction data generated using generative adversarial networks. Background Technology

[0002] Various methods for detecting fraud in payment transactions typically rely on historical transaction data. For example, historical transaction data, including data corresponding to both non-fraudulent and fraudulent transactions executed across payment networks, can be used to train fraud detection models to identify features in the historical transaction data that indicate fraudulent transactions. For example (Pattern). Furthermore, fraud detection rules can be developed based on these characteristics. When additional payment transactions are executed across payment networks, trained models and / or fraud detection rules can be applied to the additional transactions to identify potentially fraudulent transactions.

[0003] However, relying on historical transaction data for fraud detection can cause various problems. For example, new payment transaction types are frequently developed ( For example (API-based payments, real-time payments). Furthermore, malicious actors may create methods to execute new types of fraudulent transactions. Data associated with new payment transaction types and new fraudulent transaction types may not be captured from historical transaction data. Therefore, fraud detection models and / or rules developed based on historical transaction data may be ineffective in identifying new fraudulent transaction types. Consequently, new fraudulent transaction types may not be detected until historical data associated with these fraudulent transactions is collected and used to update fraud detection models and / or fraud detection rules.

[0004] As another example, only a small fraction of the transactions represented by historical transaction data may be fraudulent. Therefore, a large amount of historical data is typically needed to capture enough fraudulent transactions to train a fraud detection model. Furthermore, significant human intervention is usually required to label and process historical data. Thus, preparing and implementing a fraud detection model can take several months. This preparation can not only require expensive human resources but may also result in the model becoming outdated by the time it is implemented.

[0005] As yet another example, various regulations ( For example The General Data Protection Regulation (GDPR) may prohibit the processing of personal data. Therefore, some transaction data related to fraud detection ( For example Personal data may be excluded from historical transaction data. Therefore, historical transaction data may be incomplete, and fraud detection models and / or rules developed based on historical transaction data may be ineffective in identifying various types of fraudulent transactions.

[0006] Therefore, alternative devices, systems, and methods are needed for fraud detection. This disclosure provides several solutions for implementing generative adversarial networks (GANs) for fraud detection. Summary of the Invention

[0007] According to one aspect, this disclosure provides a computer-implemented method. The method may include receiving real transaction data and fraud detection rules by a creator neural network. The real transaction data corresponds to real transactions executed across a payment network. The fraud detection rules are used to identify fraudulent transactions. The method may also include generating synthetic transaction data by the creator neural network. The synthetic transaction data corresponds to synthetic transactions that were not actually executed across a payment network. The fraud detection rules may be updated based on the synthetic transaction data.

[0008] According to another aspect, this disclosure provides a system. The system may include a creator model and an evaluator model. The creator model is used to receive real transaction data corresponding to real transactions executed across a payment network, receive fraud detection rules for identifying fraudulent transactions, and generate synthetic transaction data based on the real transaction data and the fraud detection rules. The synthetic transaction data corresponds to synthetic transactions that were not actually executed across a payment network. The evaluator model is used to receive the synthetic transaction data and classify at least some of the synthetic transactions as fraudulent transactions.

[0009] According to another aspect, this disclosure provides a computer-implemented method. The computer-implemented method may include receiving real transaction data by a transaction service provider server, and identifying a first fraudulent transaction by applying fraud detection rules to the real transaction data. The method may also include rejecting the first fraudulent transaction by the transaction service provider server. The method may further include generating synthetic transaction data by the transaction service provider server based on the real transaction data, and generating updated fraud detection rules by the transaction service provider server based on the synthetic transaction data. Attached Figure Description

[0010] In this description, specific details, such as particular aspects, procedures, techniques, etc., are set forth for purposes of explanation and not limitation in order to provide a thorough understanding of the invention. However, it will be apparent to those skilled in the art that the invention may be practiced in other aspects besides these specific details.

[0011] The accompanying drawings, together with the detailed description below, are incorporated in and form part of this specification, and serve to further illustrate aspects of the concepts including the claimed disclosure and to explain the various principles and advantages of those aspects.

[0012] The apparatuses and methods disclosed herein have been indicated by conventional symbols in the accompanying drawings where appropriate, showing only those specific details relevant to understanding various aspects of this disclosure, so as not to obscure this disclosure with details that would be obvious to one of ordinary skill in the art who would benefit from the description herein.

[0013] Figure 1 It is a block diagram of a transaction synthesis system according to at least one aspect of this disclosure.

[0014] Figure 2 This is a block diagram of a fraud detection system according to at least one aspect of this disclosure.

[0015] Figure 3 This is a block diagram of a payment network system according to at least one aspect of this disclosure.

[0016] Figure 4A This is a flowchart of a method for generating synthetic transaction data according to at least one aspect of this disclosure.

[0017] Figure 4B This is a flowchart of a method for classifying synthetic transaction data according to at least one aspect of this disclosure.

[0018] Figure 5 This is a block diagram of a computer device having a data processing subsystem or component according to at least one aspect of the present disclosure.

[0019] Figure 6 This is a schematic diagram of an example system including a host according to at least one aspect of this disclosure.

[0020] Throughout the various views, corresponding reference numerals indicate the corresponding parts. The examples listed herein illustrate various aspects of this disclosure in one form, and such examples should not be construed as limiting the scope of this disclosure in any way. Detailed Implementation

[0021] Before explaining the various forms of devices, systems, and methods for fraud detection based on Generative Adversarial Networks (GANs), it should be noted that the illustrative forms disclosed herein are not limited in application or use to the details of the construction and arrangement of the components illustrated in the figures and descriptions. Illustrative forms may be implemented or incorporated into other forms, variations, and modifications, and may be practiced or performed in various ways. Furthermore, unless otherwise indicated, the terminology and expressions used herein are chosen for the convenience of the reader in describing the illustrative forms, and not for the purpose of limiting them. Similarly, in the following description, it should be understood that terms such as “forward,” “backward,” “left,” “right,” “above,” “below,” “upward,” and “downward” are convenient words and should not be construed as limiting terms.

[0022] As described above, various methods for detecting fraud in payment transactions typically rely on historical transaction data. For example, historical transaction data, including data corresponding to both non-fraudulent and fraudulent transactions executed across payment networks, can be used to train fraud detection models to identify features in the historical transaction data that indicate fraudulent transactions. For example (Pattern). Furthermore, fraud detection rules can be developed based on these characteristics.

[0023] However, relying on historical transaction data for fraud detection can present various problems. For example, data related to new payment transaction types and features indicating new fraudulent transaction types may not be captured by historical transaction data. As another example, only a small fraction of the transactions represented by historical transaction data may be fraudulent. Therefore, a large amount of historical data may be required to capture enough fraudulent transactions to train a fraud detection model. As yet another example, various regulations may prohibit the processing of personal data as part of historical data. Therefore, fraud detection models and / or rules developed based on historical transaction data may be ineffective in identifying fraudulent transactions. Thus, alternative devices, systems, and methods are needed for fraud detection.

[0024] This disclosure provides various devices, systems, and methods for implementing generative adversarial networks (GANs) for fraud detection. For example, in one aspect, a transaction synthesis system is disclosed. The transaction synthesis system can employ a creator model (…). For example Creator neural network) and evaluator model ( For example A GAN (Geoprocessor Animation Network) with an evaluator neural network. The creator model can receive real transaction data corresponding to real transactions executed across payment networks. Additionally or alternatively, the creator model can receive fraud detection rules for identifying fraudulent transactions. The creator model can generate synthetic transaction data based on real transaction data and / or fraud detection rules. The synthetic transaction data can correspond to synthetic transactions that were not actually executed across payment networks. The evaluator model can receive the synthetic transaction data and classify at least some of the synthetic transactions as fraudulent transactions.

[0025] In some respects, synthetic transaction data, including data corresponding to synthetic transactions classified as fraudulent, can be used to update fraud detection rules. Furthermore, some synthetic transactions generated by the creator model can predict future types of fraudulent transactions that have not yet been committed by malicious actors. Therefore, updated fraud detection rules may be more effective in identifying new types of fraudulent transactions compared to those generated solely based on historical transaction data.

[0026] In some respects, the creator model can receive updated fraud detection rules and / or additional real transaction data, and generate additional synthetic transaction data. Therefore, the transaction synthesis system can employ an iterative feedback loop, whereby rules updated based on the synthetic transaction data generated by the creator model are subsequently used by the creator model to generate additional synthetic transaction data, thus enabling further rule updates based on the additional synthetic transaction data. Consequently, robust training and validation data can be generated and used to train both the creator and evaluator models. Therefore, the evaluator model may be more effective in identifying various types of fraudulent transactions compared to fraud detection models generated solely based on historical transaction data. Furthermore, synthetic data can be generated to include a larger proportion of fraudulent transactions compared to the relatively small percentage typically included in historical data. Therefore, the evaluator model can be trained to identify fraudulent transactions using a smaller overall dataset compared to the large amounts of historical data typically required to train traditional fraud detection models.

[0027] In some respects, the creator model includes a large language model. The large language model can format fraud detection rules so that these rules can be processed by the creator model to generate synthetic transaction data. Therefore, various types of rules (including, for example, operational procedures, proxy processing rules, and / or risk rules) can be used to generate synthetic transaction data with minimal and / or no human intervention.

[0028] In some respects, online implementations of the evaluator model can be used to detect fraudulent transactions in real time. As noted above, the feedback loop implemented by the transaction synthesis system allows both the creator and evaluator models to generate and use robust training and validation datasets. Furthermore, this training enables the evaluator model to ( For example (Through synthetic transaction data) to identify potentially new types of fraudulent transactions that have not yet been created and implemented by malicious actors. Therefore, the evaluator model may be effective in identifying fraudulent transactions included in real transaction data. Thus, real transaction data can be (… For example The online implementation of the evaluator model (transmitted by the transaction processing service provider and the issuer) is used to identify fraudulent transactions. Furthermore, transactions identified as fraudulent by the online implementation of the evaluator model can be (…). For example This can be done by the transaction processing service provider or the issuer in real time to prevent fraud.

[0029] The devices, systems, and methods presented in this paper can offer numerous benefits. For example, by generating synthetic transaction data that includes data corresponding to fraudulent synthetic transactions, compared with data based on historical transaction data (… For exampleCompared to fraud detection models trained on a large amount of historical transaction data (including only a small fraction of the data corresponding to fraudulent transactions), evaluator models can be trained to identify fraudulent transactions more effectively.

[0030] As another example, due to the GAN-based methods used to generate synthetic transaction data using real transaction data and iteratively updated fraud detection rules, at least some of the synthetic transaction data may possess characteristics similar to future fraudulent transaction types that have not yet been identified. Therefore, evaluator models that can be trained on synthetic transaction data and / or fraud detection rules that can be updated based on synthetic transaction data may be effective in identifying new fraudulent transaction types that are not present in historical transaction data.

[0031] As yet another example, synthetic transaction data may not include consumers' personal information. Therefore, the devices, systems, and methods presented herein can avoid processing personal data when training evaluator models and updating fraud detection rules, thereby protecting consumer safety and privacy while complying with various regulatory requirements related to the processing of personal data.

[0032] As yet another example, devices, systems, and methods can be improved by using updated fraud detection rules. For example, real Time and place This involves identifying and rejecting fraudulent transactions to implement the generation of synthetic transaction data and updated fraud detection rules in practical applications, thereby preventing fraud.

[0033] Figure 1 This is a block diagram of a transaction synthesis system 100 according to at least one aspect of the present disclosure. The transaction synthesis system 100 may include a creator model 102 and an evaluator model 108. In some aspects, the transaction synthesis system 100 is a generative adversarial network (GAN).

[0034] Creator model 102 may include a neural network. Creator model 102 ( For example The neural network can be trained to generate synthetic transaction data 128 from inputs including real transaction data 110, fraud detection rules 114, and / or fraud report data 124. The synthetic transaction data 128 generated by the creator model 102 may include data corresponding to transactions that were not actually executed across the payment network.

[0035] Real transaction data 110 may include data corresponding to transactions executed across payment networks. For example, see brief reference. Figure 3 And also refer to Figure 1The real transaction data 110 may include data corresponding to a transaction initiated by payment device 2006 and access device 2004 and processed by one or more of payment gateway system 2002, issuer system 2008, transaction service provider system 2010 and / or acquirer system 2012. In some aspects, the real transaction data 110 may be stored by payment gateway system 2002, issuer system 2008, transaction service provider system 2010 and / or acquirer system 2012 and transmitted to transaction synthesis system 100. For example The data of the creator model 102). In some respects, when processing transactions across the payment network system 2000, the real transaction data 110 can be transmitted in real time to the transaction synthesis system 100 ( For example Creator model 102).

[0036] Refer again Figure 1 In some respects, the real transaction data 110 may include reference data 112. Reference data 112 may include various identifying information related to the real transaction data 110. For example, reference data 112 may include various fields and / or tags, including issuer identifiers, acquirer identifiers, country codes, currency codes, merchant codes, etc., corresponding to the transaction represented by the real transaction data 110. Reference data 112 may be processed by the creator model 102 to generate synthetic transaction data 128.

[0037] In some respects, the transaction synthesis system 100 and / or the creator model 102 can be configured to preprocess real transaction data 110. For example, the transaction synthesis system 100 can format or otherwise initialize the real transaction data 110 for use by the creator model 102. For example The neural network is simplified.

[0038] Fraud detection rule 114 may include various rules that can be used to identify potentially fraudulent transactions. For example, in some aspects, fraud detection rule 114 may be applied to transaction data to identify a risk score for a transaction. If the risk score meets a predetermined threshold, the transaction may be considered potentially fraudulent. In some aspects, fraud detection rule 114 may be defined by a fraud detection system (…). For example Fraud Detection System 200 ( Figure 2 This is used to identify potentially fraudulent transactions.

[0039] Fraud detection rule 114 may include risk rule 116, operating procedures 118, proxy processing rule 120, and / or various other rules 122. Risk rule 116 may be determined by the transaction service provider's system ( For example Transaction Service Provider System 2010 Figure 3This implements rules to classify transactions as fraudulent or non-fraudulent. Operating procedure 118 can manage the exchange of transactions and transaction data across various entities within the payment network. For example The rules for exchange between the issuer system 2008 and the acquirer system 2012 of the payment network system 2000. Processing rule 120 can be used by an entity ( For example Transaction Service Provider System 2010) represents another entity ( For example The rules for approving or rejecting transactions (issuer system 2008). Other rules 122 may include those issued by the payment network ( For example Entities operating within a payment network system (2000) implement any type of rule to verify, authenticate, confirm, or otherwise approve or reject transactions. Fraud detection rule 114 may be in any format, including, for example, text, forms, spreadsheets, lists, codes, etc.

[0040] In some respects, the creator model 102 may include a large language model. The large language model can be trained to read fraud detection rules 114 and format these fraud detection rules for use by the creator model 102. For example The neural network simplifies the data. For example, as noted above, fraud detection rule 114 can be in any format, including, for example, text, tables, spreadsheets, lists, codes, etc. The large language model can read any of these various data formats and reformat fraud detection rule 114 for use as input for generating synthetic transaction data 128 by creator model 102.

[0041] In some aspects, the creator model 102 may include a randomizer 104 and / or an aggregator 106. The randomizer 104 and / or aggregator 106 may reduce bias associated with the synthetic transaction data 128 generated by the creator model 102. For example, the randomizer 104 may randomly select inputs to be applied to the creator model 102 from real transaction data 110, fraud detection rules 114, and / or fraud report data 124 to ensure that the various data sources within the inputs are not overrepresented when training the creator model 102. As another example, the randomizer 104 may randomize the initial weights of the creator model 102. As another example, the aggregator 106 may selectively combine the accumulated inputs to be applied to the creator model 102 and / or combine the intermediate layer nodes of the creator model 102 to ensure that the various data sources within the inputs are not overrepresented when training the creator model 102.

[0042] Fraud report data 124 may include transaction data used for transactions identified as fraudulent. For example, fraud report data 124 may include data related to transactions made by the issuer ( For exampleThe issuer system 2008) provides services to the transaction service provider ( For example The transaction service provider system (2010) reports data corresponding to fraudulent transactions.

[0043] The evaluator model 108 can receive real transaction data 110 and / or synthetic transaction data 128 generated by the creator model 102. The evaluator model 108 may include a neural network.

[0044] In some respects, the evaluator model 108 can be trained to classify input data as real transaction data 110 or synthetic transaction data 128. Furthermore, the creator model 102 can be trained to generate synthetic transaction data 128, which, when processed by the evaluator model 108, causes the evaluator model 108 to incorrectly classify the synthetic transaction data 128 as real transaction data 110. For example The creator model 102 can be trained to attempt to fool the evaluator model 108 into thinking that it has received real transaction data 110. Thus, through adversarial training, the creator model 102 becomes better at generating real synthetic transaction data 128, and the evaluator model becomes better at distinguishing synthetic transaction data 128 from real transaction data 110.

[0045] In some respects, the evaluator model 108 can be trained to process transaction data ( For example Real transaction data 110 and synthetic transaction data 128 are classified as corresponding to fraudulent or non-fraudulent transactions. For example, some synthetic transaction data in synthetic transaction data 128 may include data corresponding to synthetic transactions with characteristics indicating fraudulent transactions. Furthermore, synthetic transaction data 128 may include data corresponding to synthetic transactions with characteristics indicating non-fraudulent transactions. Therefore, the evaluator model 108 can be trained to classify each synthetic transaction in the synthetic transaction set as fraudulent or non-fraudulent. In one aspect, the evaluator model 108 classifies transactions as fraudulent or non-fraudulent by generating a risk score for each transaction. If the risk score satisfies ( For example If the risk score exceeds a predetermined threshold, the evaluator model 108 can classify the corresponding transaction as fraudulent. If the risk score does not meet the predetermined threshold, the evaluator model 108 can classify the transaction as fraudulent. For example If the risk score, classification, and / or corresponding transaction data can be processed and / or generated by the evaluator model 108, and do not exceed a predetermined threshold, then the evaluator model 108 can classify the corresponding transaction as non-fraudulent. Figure 1 The output 130 indicates that...

[0046] The output 130 of the evaluator model 108 can be used to update the fraud detection rule 114. In some respects, the fraud detection system ( For exampleFraud Detection System 200 ( Figure 2 The system can receive the output 130 of the evaluator model 108 and generate updated fraud detection rules 114 based on the output 130. For example, as noted above, the output 130 may include synthetic transaction data 128 and a classification indicating the synthetic transaction data corresponding to fraudulent synthetic transactions. The fraud detection rules 114 can be updated to identify fraudulent transactions with characteristics similar to those of fraudulent synthetic transactions.

[0047] As noted above, creator model 102 can generate synthetic transaction data 128 based on fraud detection rule 114. Furthermore, as noted above, updated fraud detection rule 114 can be generated based on the output of evaluator model 108. Therefore, creator model 102 can generate additional synthetic transaction data 128 based on the updated fraud detection rule 114. Thus, transaction synthesis system 100 can employ the following iterative process: generating synthetic transaction data 128, updating fraud detection rule 114 based on synthetic transaction data 128, and applying the updated fraud detection rule 114 to creator model 102 to generate additional synthetic transaction data 128. This iterative process can be implemented to improve fraud detection rule 114, creator model 102 (… example like The quality of the synthetic transaction data 128 generated by the creator model 102 and the evaluator model 108 For example The quality of the output of evaluator model 108 is 130.

[0048] As noted above, the evaluator model 108 can be trained to process transaction data ( For example Real transaction data (110) and synthetic transaction data (128) are categorized as corresponding to fraudulent or non-fraudulent transactions. In some respects, evaluator model 108 ( For example Evaluator Model 208 ( Figure 2 The online implementation of )) can be deployed across payment networks ( For example (In real time) Analyzing transaction data used for these transactions during processing. Furthermore, based on the analyzed transaction data, the online implementation of evaluator model 108 can identify fraudulent transactions as they are processed, thereby enabling various entities within the payment network ( example like The issuer system 2008, transaction service provider system 2010, payment gateway system 2002, and acquirer system 2012 can refuse a transaction and / or take another action. For example Verification is required to prevent potential fraud.

[0049] Figure 2This is a block diagram of a fraud detection system 200 according to at least one aspect of this disclosure. The fraud detection system 200 can receive genuine transaction data 210 and generate output 230 based on the genuine transaction data 210. For example, the genuine transaction data 210 can be compared with data across payment networks (…). For example The transaction corresponds to that executed by the payment network system 2000. The fraud detection system 200 can receive genuine transaction data 210, and while the payment network is processing the corresponding transaction ( For example (Generates output 230 in real time)

[0050] Output 230 may include a fraud classification and / or risk score for each transaction represented by the real transaction data 210. For example, a fraud classification could identify a transaction as fraudulent or non-fraudulent. As another example, a risk score could indicate whether a transaction is fraudulent (…). For example (A numerical probability between 0.0 and 1.0). As yet another example, fraud classification can be based on a risk score, where a risk score exceeding a predetermined threshold corresponds to a fraudulent classification of a transaction.

[0051] Various entities in the payment network ( For example The issuer system 2008, transaction service provider system 2010, payment gateway system 2002, and acquirer system 2012 can take action based on the output 230 of the fraud detection system 200. For example, based on the output 230 that identifies a transaction as fraudulent and / or includes a risk score exceeding a predetermined threshold, one or more entities in the payment network can reject the transaction and / or take another action. For example Verification is required to prevent potential fraud.

[0052] Fraud detection system 200 may include fraud detection rule 214. Fraud detection rule 214 can be applied to genuine transaction data 210 to generate output 230. Fraud detection rule 214 can be combined with fraud detection rule 114 ( Figure 1 Similarly, any aspect of fraud detection rule 114 described herein can be similarly applied to fraud detection rule 214. For example, fraud detection rule 214 can be updated based on the output 130 of evaluator model 108. As another example, fraud detection rule 214 can be received by creator model 102 and processed by creator model 102 to generate synthetic transaction data 128.

[0053] Fraud detection system 200 may include evaluator model 208. Evaluator model 208 may be evaluator model 108 ( Figure 1The online implementation of ) is described. Real transaction data 210 can be applied to evaluator model 208 to generate output 230. Any aspect described herein with respect to evaluator model 108 can be similarly applied to evaluator model 208.

[0054] In some aspects, fraud detection system 200 uses both fraud detection rule 214 and evaluator model 208 to generate output 230. In some aspects, fraud detection system 200 may include fraud detection rule 214 without evaluator model 208. In some aspects, fraud detection system 200 may include evaluator model 208 without fraud detection rule 214.

[0055] Figure 3 This is a diagram of a payment network system 2000 capable of executing transactions across it, according to at least one aspect of this disclosure. (See diagram for example.) Figure 3 As shown, the payment network system 2000 may include a payment gateway system 2002, an access device 2004, a payment device 2006, an issuer system 2008, a transaction service provider system 2010, an acquirer system 2012, a network 2014, a fraud detection system 2200, and a transaction synthesis system 2100. The payment gateway system 2002, access device 2004, payment device 2006, issuer system 2008, transaction service provider system 2010, acquirer system 2012, fraud detection system 2200, and / or transaction synthesis system 2100 may be interconnected via wired connections, wireless connections, or a combination of wired and wireless connections. For example Establish a connection for communication.

[0056] A "payment network" can refer to an electronic payment system used to accept, transmit, or process transactions made by payment devices for funds, goods, or services. Payment networks can transfer information and funds between issuers, acquirers, merchants, and users of payment devices. An illustrative, non-limiting example of a payment network is VisaNet, operated by Visa, Inc.

[0057] "System" can refer to one or more computing devices or a combination of computing devices. For example Processors, servers, client devices, software applications, and components of such computing devices.

[0058] Refer again Figure 3Access device 2004 may include one or more devices capable of receiving information from and / or sending information to the following via network 214: payment gateway system 2002, payment device 2006, issuer system 2008, transaction service provider system 2010, acquirer system 2012, fraud detection system 2200, and / or transaction synthesis system 2100. Access device 2004 may be any suitable device providing access to a remote system. Access device 2004 may also be used to communicate with a merchant's computer, transaction processing computer, authentication computer, or any other suitable system. Access device 2004 may typically be located in any suitable location, such as at the merchant's location. Access device 2004 may take any suitable form. Some examples of access device 2004 may include a POS or point-of-sale device (POS). For example POS terminals, cellular phones, personal digital assistants (PDAs), personal computers (PCs), tablet PCs, handheld dedicated readers, set-top boxes, electronic cash registers (ECRs), automated teller machines (ATMs), virtual cash registers (VCRs), kiosks, security systems, access systems, etc. Access device 2004 can use any suitable contact or contactless operating mode to send or receive data from or associated with payment device 2006. For example, access device 2004 may include a reader, a processor, and a computer-readable medium. The reader may include a radio frequency (RF) antenna, an optical scanner, a barcode reader, and / or a magnetic stripe reader to interact with payment device 2006.

[0059] As noted above, in some aspects, access device 2004 may include a point-of-sale (POS) device. A POS device may include one or more devices, such as a computer, computer system, portable electronic device, and / or peripheral devices that a merchant may use, for example, to conduct payment transactions with a user using payment device 2006. In some aspects, the POS device may be a component of a merchant system associated with the merchant. In some aspects, the POS device may be configured to communicate via a communication connection ( For example The device receives information from the payment device 2006 via a Near Field Communication (NFC) connection, Radio Frequency Identification (RFID) connection, Bluetooth® connection, etc., and / or sends information to the payment device 2006 via the communication connection.

[0060] "Business" can refer to one or more individuals or entities. For example Based on transactions ( For example Payment transactions) to users ( For exampleRetail operators who provide and / or obtain goods and / or services (customers, consumers, customers of merchants, etc.). As used herein, "merchant system" may also refer to one or more computer systems operated by or on behalf of a merchant, such as a server computer running one or more software applications.

[0061] "User" can include an individual. In some implementations or aspects, a user can be associated with one or more personal accounts, payment cards, and / or portable electronic devices. A user can also be referred to as a cardholder, account holder, or consumer.

[0062] Refer again Figure 3 Payment device 2006 may include any device that can be used to conduct transactions (such as financial transactions). For example, payment device 2006 may be used to provide payment information to merchants. In some aspects, payment device 2006 may be a portable computing device. In some aspects, payment device 2006 may be a payment card and may include a substrate such as a paper, metal, or plastic card, and information printed, embossed, encoded, and / or otherwise included on or near the surface of the payment card. Payment device 2006 may be handheld and compact, allowing it to fit comfortably into a consumer's wallet and / or pocket. For example Pocket-sized). Payment device 2006 can be a smart card or debit card device ( For example Debit cards), credit card devices ( For example Credit cards), stored value devices ( For example The payment device 2006 can operate in contact and / or contactless modes. For example, the payment device 2006 can be an electronic payment device, such as a smart card, chip card, integrated circuit card, and / or near field communication (NFC) card. The payment device 2006 may include an embedded integrated circuit. The embedded integrated circuit may include a data storage medium (…). For example The payment device 2006 may include volatile and / or non-volatile memory to store information associated with it, such as account identifiers and / or the name of the account holder. The payment device 2006 may interface with the access device 2004 to initiate transactions.

[0063] Still referencing Figure 3 The payment gateway system 2002 may include one or more devices capable of receiving information from and / or sending information to the following via network 214: access device 2004, issuer system 2008, transaction service provider system 2010, acquirer system 2012, fraud detection system 2200, and / or transaction synthesis system 2100. For example, the payment gateway system 2002 may include computing devices, such as servers (…). For exampleTransaction processing server), server clusters, and / or other similar devices. Payment gateway system 2002 may refer to an entity and / or a payment processing system operated by or on behalf of such an entity, the entity (… For example Merchant service providers, payment service providers (PSPs), payment service providers, payment service providers with contracts with acquirers, payment aggregators, and / or their analogues will provide payment services ( For example The transaction service provider (payment service, payment processing service and / or its analogues) provides payment services to one or more merchants.

[0064] Still referencing Figure 3 The acquiring system 2012 may include one or more devices capable of receiving and / or sending information via network 2014 to: payment gateway system 2002, access device 2004, issuer system 2008, transaction service provider system 2010, fraud detection system 2200, and / or transaction synthesis system 2100. For example, the acquiring system 2012 may include computing devices such as servers, server clusters, and / or other similar devices. In some aspects, the acquiring system 2012 may be associated with an acquiring party. In some aspects, the acquiring system 2012 may be associated with a merchant account of a merchant associated with access device 2004.

[0065] "Acquiring party" can refer to a transaction initiated by a transaction service provider with the permission and / or approval of the transaction service provider to use a portable financial device associated with the transaction service provider. For example The entity that handles payment transactions. "Acquiring party" or "acquiring party system" can also refer to one or more computer systems operated by or on behalf of the acquiring party, such as a server computer executing one or more software applications. For example (This refers to the "acquiring server"). The "acquiring party" can be a merchant bank, or in some cases, a merchant system. The transactions can include Original Credit Transactions (OCT) and Account Funds Transactions (AFT). The transaction service provider can authorize the acquiring party to sign off on merchants of the service provider to initiate transactions using the transaction service provider's portable financial devices. The acquiring party can sign off on payment service providers to enable the service providers to sponsor merchants. The acquiring party can monitor the compliance of payment service providers in accordance with the regulations of the transaction service provider.

[0066] Refer again Figure 3The transaction service provider system 2010 may include one or more devices capable of receiving information from and / or sending information to the following via network 2014: payment gateway system 2002, access device 2004, issuer system 2008, acquirer system 2012, fraud detection system 2200, and / or transaction synthesis system 2100. For example, the transaction service provider system 2010 may include computing devices, such as servers (…). For example The transaction service provider system 2010 may be associated with a transaction service provider. In some aspects, the transaction service provider system 2010 may communicate with a data storage device, which may be local or remote to the transaction service provider system 2010. In some aspects, the transaction service provider system 2010 may be able to receive information from the data storage device, store information in the data storage device, send information to the data storage device, or search for information stored in the data storage device. For example (Transaction data).

[0067] "Transaction service provider" can refer to an entity that receives transaction authorization requests from merchants or other entities and, in some cases, provides payment guarantees through an agreement between the transaction service provider and the issuer. For example, a transaction service provider may include payment networks such as Visa®, MasterCard®, American Express®, or any other entity that processes transactions. As used herein, "transaction service provider system" can refer to one or more systems operated by or on behalf of the transaction service provider, such as a transaction service provider system that executes one or more software applications associated with the transaction service provider. In some non-limiting aspects, a transaction service provider system may include one or more server computers having one or more processors, and in some non-limiting aspects, may be operated by or on behalf of the transaction service provider.

[0068] Refer again Figure 3The issuer system 2008 may include one or more devices capable of receiving and / or sending information via network 2014 to: payment gateway system 2002, access device 2004, transaction service provider system 2010, acquiring system 2012, fraud detection system 2200, and / or transaction synthesis system 2100. For example, the issuer system 2008 may include computing devices such as servers, server clusters, and / or other similar devices. In various aspects, the issuer system 2008 may be associated with an issuing institution. For example, the issuer system 2008 may be associated with an issuing institution that issues credit accounts, debit accounts, credit card accounts, debit card accounts, etc., to users associated with payment device 2006.

[0069] The terms “issuer institution,” “portable financial device issuer,” “issuer,” or “issuer bank” can refer to one or more entities that provide services to users ( For example Customers, consumers, etc.) provide one or more accounts ( For example Credit accounts, debit accounts, credit card accounts, debit card accounts, etc., are used for transactions. For example Payment transactions can be initiated, such as credit payments and / or debit payments. For example, an issuer may provide a user with an account identifier, such as a Personal Account (PAN), which uniquely identifies one or more accounts associated with the user. The account identifier can be used by the user to conduct payment transactions. The account identifier can be embodied in, for example, physical financial instruments (…). For example The payment card is a portable financial device, and / or may be electronic and used for electronic payments. As used herein, "issuer system" or "issuer institution system" may refer to one or more systems operated by or on behalf of the issuer. For example, an issuer system may refer to a server executing one or more software applications associated with the issuer. In some non-limiting aspects of this disclosure, an issuer system may include one or more servers for authorizing payment transactions. For example (One or more authorized servers). "Issuer" may include the payment account issuer. A payment account (which may be associated with one or more payment devices) may refer to any suitable payment account. For example Credit card accounts, checking accounts, savings accounts, merchant accounts or prepaid accounts allocated to consumers), employment accounts, identification accounts, registered accounts ( For example (e.g., student accounts).

[0070] Refer again Figure 3The transaction synthesis system 2100 may include one or more devices capable of receiving information from and / or sending information to the following via network 2014: payment gateway system 2002, access device 2004, transaction service provider system 2010, acquiring system 2012, and / or fraud detection system 2200. In some aspects, the transaction synthesis system 2100 may be included in any one or more of the fraud detection system 2200, issuer system 2008, transaction service provider system 2010, and / or acquiring system 2012. The transaction synthesis system 2100 may ( For example The fraud detection system 2100 receives data corresponding to transactions and / or fraud detection rules executed by the cross-payment network system 2000, generates synthetic transaction data, and / or classifies real transaction data and / or synthetic transaction data as fraudulent or non-fraudulent. The fraud detection rules and / or fraud detection model implemented by the fraud detection system 2200 can be updated based on the synthetic transaction data generated by the transaction synthesis system 2100. Figure 1 Similarly, any aspect described herein with respect to transaction synthesis system 100 can be similarly applied to transaction synthesis system 2100, and vice versa.

[0071] Still referencing Figure 3 Fraud detection system 2200 may include one or more devices capable of receiving and / or sending information to: payment gateway system 2002, access device 2004, transaction service provider system 2010, acquiring system 2012, and / or transaction synthesis system 2100 via network 2104. In some aspects, fraud detection system 2200 may be included in any or more of transaction synthesis system 2100, issuer system 2008, transaction service provider system 2010, and / or acquiring system 2012. Fraud detection system 2200 may receive and analyze data corresponding to transactions executed across payment network system 2000 to identify potentially fraudulent transactions. Issuer system 2008, transaction service provider system 2010, and / or acquiring system 2012 may implement actions for transactions identified as potentially fraudulent by fraud detection system 2200. For example (Refusal, request for further verification). In some respects, fraud detection system 2200 differs from fraud detection system 200 ( Figure 2 Similarly, any aspect described herein with respect to fraud detection system 200 can be similarly applied to fraud detection system 2200, and vice versa.

[0072] Still referencing Figure 3Network 2014 may include one or more wired networks and / or wireless networks. For example, network 2014 may include a cellular network ( For example Long Term Evolution (LTE) networks, fourth-generation (4G) networks, fifth-generation (5G) networks, Code Division Multiple Access (CDMA) networks, etc.), Public Land Mobile Network (PLMN), Local Area Network (LAN), Wide Area Network (WAN), Metropolitan Area Network (MAN), Telephone Network ( For example Public switched telephone network (PSTN), private network, ad hoc network, intranet, Internet, fiber-optic network, cloud computing network, and / or combinations of these or other types of networks.

[0073] Figure 3 The number and arrangement of devices, systems, and networks shown in the payment network system 2000 are provided as an example. Figure 3 Compared to those shown, there may be additional equipment, systems, and / or networks; fewer equipment, systems, and / or networks; different equipment, systems, and / or networks; or equipment, systems, and / or networks arranged in a different manner. Furthermore, Figure 3 The two or more systems shown can be implemented within a single system and / or device, or Figure 3 The single system shown can be implemented as multiple distributed devices and / or systems. Additionally or alternatively, the payment network system 2000 comprises a group of devices ( For example One or more devices can perform one or more functions described as being performed by another set of devices in the payment network system 2000.

[0074] Figure 4A This is a flowchart of a method 400a for generating synthetic transaction data according to at least one aspect of this disclosure. In some aspects, method 400a can be executed by a creator model, such as transaction synthesis system 100 (…). Figure 1 Creator model 102 and / or transaction synthesis system 2100 ( Figure 3 The creator model of ).

[0075] Main Reference Figure 4A as well as Figure 1 and Figure 3 According to method 400a, the creator model 102 receives 402 real transaction data 110 and fraud detection rules 114. Real transaction data 110 can correspond to real transactions executed across the payment network system 2000. Fraud detection rules 114 can be used to identify fraudulent transactions.

[0076] Still mainly refer to Figure 4A as well as Figure 1 and Figure 3According to method 400a, creator model 102 generates synthetic transaction data 128. Synthetic transaction data 128 can correspond to synthetic transactions that were not actually executed across payment network system 2000. Fraud detection rules 114 can be updated based on synthetic transaction data 128.

[0077] Figure 4B This is a flowchart of a method 400b for classifying synthetic transaction data according to at least one aspect of this disclosure. In some aspects, method 400b can be performed by an evaluator model, such as transaction synthesis system 100 (…). Figure 1 The evaluator model 108 and / or transaction synthesis system 2100 ( Figure 3 The evaluator model of ) . In some respects, method 400b can be combined with method 400a ( Figure 4A To achieve this.

[0078] Main Reference Figure 4B as well as Figure 1 , Figure 3 and Figure 4A According to method 400b, evaluator model 108 receives 406 synthetic transaction data 128. Synthetic transaction data 128 may correspond to a synthetic transaction that was not actually executed across payment network system 2000. Synthetic transaction data 128 may be generated 404 by creator model 102.

[0079] Main Reference Figure 4B as well as Figure 1 , Figure 3 and Figure 4A According to method 400b, evaluator model 108 generates risk scores 408 for synthetic transactions. Furthermore, evaluator model 108 classifies at least some synthetic transactions 410 as fraudulent transactions based on the corresponding risk scores meeting predetermined thresholds.

[0080] As noted above, methods 400a and 400b can be implemented in combination. (Reference) Figure 1 , Figure 3 , Figure 4A and Figure 4B According to some aspects of methods 400a and 400b, the evaluator model 108 receives real transaction data 110 and synthetic transaction data 128. Furthermore, the evaluator model 108 classifies each transaction represented by the real transaction data and synthetic transaction data as either a real transaction or a synthetic transaction.

[0081] According to some aspects, method 400a and / or method 400b also includes training the creator model 102 to cause the evaluator neural model 108 to incorrectly classify synthetic transactions as real transactions.

[0082] Various aspects of method 400a and / or method 400b can be performed by a fraud detection system, such as fraud detection system 200 ( Figure 2 ) and / or fraud detection system 2200 ( Figure 3 ). refer to Figure 2 , Figure 3 , Figure 4A and Figure 4B According to aspects of methods 400a and 400b, the fraud detection system 200 receives additional genuine transaction data 210 in real time. The fraud detection system 200 can identify a first genuine transaction represented by the additional genuine transaction data 210 as a fraudulent transaction based on updated fraud detection rules 114, 214. Furthermore, the fraud detection system 200 (and / or another entity of the payment network system 2000) can reject a first genuine transaction based on identifying it as fraudulent.

[0083] According to some aspects of methods 400a and 400b, fraud detection system 200 receives additional genuine transaction data 210 in real time. Fraud detection system 200 may include an online implementation of evaluator model 208. The online implementation of evaluator model 208 can classify a first genuine transaction represented by the additional genuine transaction data 210 as a fraudulent transaction based on updated fraud detection rules 114, 214. Furthermore, fraud detection system 200 (and / or another entity of payment network system 2000) can reject a first genuine transaction based on identifying it as fraudulent.

[0084] According to some aspects of methods 400a and 400b, the real transaction data 110 includes data corresponding to transactions identified as fraudulent. For example Fraud report data 124).

[0085] Figure 5 This is a block diagram of a computer device 3000 including a data processing subsystem or component according to at least one aspect of this disclosure. Figure 5The subsystems shown are interconnected via system bus 3010. Additional subsystems are shown, such as printer 3018, keyboard 3026, fixed disk 3028 (or other memory including computer-readable media), and monitor 3022 coupled to display adapter 3020. Peripheral devices and input / output (I / O) devices coupled to I / O controller 3012 (which may be a processor or other suitable controller) can be connected to the computer system via any number of means known in the art (e.g., serial port 3024). For example, serial port 3024 or external interface 3030 can be used to connect the computer device to a wide area network (e.g., the Internet), a mouse input device, or a scanner. The interconnection via system bus 3010 allows central processing unit 3016 to communicate with each subsystem and control the execution of instructions from system memory 3014 or fixed disk 3028, as well as the exchange of information between subsystems. System memory 3014 and / or fixed disk 3028 may be embodied in computer-readable media.

[0086] Figure 6 This is a schematic diagram of an example computing system 4000 including a host 4002 according to at least one aspect of this disclosure, within which one or more methods for performing the methods discussed herein (such as, for example...) can be executed. Figure 4A Method 400a and / or Figure 4B The instruction set of method 400b). In each aspect, host 4002 operates as a standalone device or can be connected to ( For example (Network connection) to other machines. In a network deployment, host 4002 can operate as a server or client machine in a server-client network environment, or as a peer machine in a peer-to-peer (or distributed) network environment. Host 4002 can be a computer or computing device, personal computer (PC), tablet PC, set-top box (STB), personal digital assistant (PDA), cellular phone, portable music player (… For example Portable hard disk audio devices, such as Moving Picture Experts Group Audio Layer 3 (MP3) players, network appliances, network routers, switches, or bridges, or any machine capable of executing a set of instructions (in sequence or other order) specifying the actions to be taken by the machine. Furthermore, although only a single machine is shown, the term "machine" should also be understood to include any collection of machines that individually or collectively execute a set (or more) of instructions to perform any or more of the methods discussed herein.

[0087] Example computing system 4000 includes a host 4002, thereby enabling one or more processors / processor cores 4006 ( example like A host operating system (OS) 4004 runs on a central processing unit (CPU), graphics processing unit (GPU), or both, and various memory nodes 4008. The host OS 4004 may include a super manager 4010 capable of controlling the functionality of a virtual machine (“VM”) 4012 running on machine-readable media and / or communicating with that VM. The VM 4012 may also include a virtual CPU or vCPU 4014. Memory nodes 4008 may be linked or pinned to virtual memory nodes or vNodes 4016. When a memory node 4008 is linked or pinned to a corresponding vNode 4016, data can then be directly mapped from the memory node 4008 to the corresponding vNode 4016.

[0088] All the individual components shown in host 4002 can be connected to and linked to each other, or communicate with each other via a bus (not shown) or through other coupling or communication channels or mechanisms. Host 4002 may also include a video display, audio devices, or other peripheral devices 4018. For example Liquid crystal displays (LCDs), alphanumeric input devices (including...) For example Keyboard), cursor control device ( For example Mouse), voice recognition or biometric verification unit, external driver, signal generation device ( For example The host 4002 may include a speaker, a persistent storage device 4020 (also referred to as a disk drive unit), and a network interface device 4022. The host 4002 may also include a data encryption module (not shown) for encrypting data. The components disposed in the host 4002 are those commonly found in computer systems suitable for use with aspects of this disclosure, and are intended to represent a broad category of such computer components known in the art. Therefore, the example computing system 4000 may be a server, a minicomputer, a mainframe computer, or any other computer system. The computer may also include different bus configurations, network platforms, multiprocessor platforms, etc. Various operating systems may be used, including UNIX, LINUX, WINDOWS, QNX ANDROID, IOS, CHROME, TIZEN, and other suitable operating systems.

[0089] The disk drive unit 4024 may also be a solid-state drive (SSD), a hard disk drive (HDD), or other drive including a computer or machine-readable medium on which one or more sets of instructions and data structures embodying or utilizing any one or more of the methods or functions described herein are stored. For exampleData / instructions 4026). Data / instructions 4026 may also reside wholly or at least partially within main memory node 4008 and / or processor 4006 during execution by host 4002. This can be achieved via several well-known transport protocols ( For example Network interface device 4022 of any of the Hypertext Transfer Protocol (HTTP) further sends or receives data / instructions 4026 through network 4028.

[0090] Processor 4006 and memory node 4008 may also include machine-readable media. The terms "computer-readable media" or "machine-readable media" should be considered as including a single medium or multiple media storing one or more sets of instructions. For example (Centralized or distributed databases and / or associated caches and servers). The term "computer-readable medium" should also be considered as including any medium capable of storing, encoding, or carrying a set of instructions for execution by host 4002 and causing host 4002 to perform any one or more methods of this application, or any medium capable of storing, encoding, or carrying data structures utilized by or associated with such set of instructions. Therefore, the term "computer-readable medium" should be considered as including, but not limited to, solid-state storage, optical and magnetic media, and carrier signals. Such media may also include, but are not limited to, hard disks, floppy disks, flash memory cards, digital video optical discs, random access memory (RAM), read-only memory (ROM), etc. The exemplary aspects described herein may be implemented in an operating environment including software installed on a computer, in hardware, or in a combination of software and hardware.

[0091] Those skilled in the art will recognize that an Internet service can be configured to provide Internet access to one or more computing devices coupled to the Internet service, and that computing devices may include one or more processors, buses, memory devices, display devices, input / output devices, etc. Furthermore, those skilled in the art will understand that an Internet service can be coupled to one or more databases, repositories, servers, etc., which can be used to implement any aspect of the various aspects of this disclosure as described herein.

[0092] Computer program instructions may also be loaded onto a computer, server, other programmable data processing apparatus or other device to cause a series of operational steps to be performed on the computer, other programmable apparatus or other device to produce a computer-implemented process, such that the instructions, which execute on the computer or other programmable apparatus, provide for implementing the functions / actions specified in one or more boxes of a flowchart and / or block diagram.

[0093] For example, a suitable network may include any one or more of the following, or connected to any one or more of them: local intranet, PAN (Personal Area Network), LAN (Local Area Network), WAN (Wide Area Network), MAN (Metropolitan Area Network), Virtual Private Network (VPN), Storage Area Network (SAN), Frame Relay connection, Advanced Intelligent Network (AIN) connection, Synchronous Fiber Network (SONET) connection, digital T1, T3, E1 or E3 line, Digital Data Service (DDS) connection, DSL (Digital Subscriber Line) connection, Ethernet connection, ISDN (Integrated Services Digital Network) line, dial-up port (e.g., V.90, V.34 or V.34bis), dual analog modem connection, cable modem, ATM (Asynchronous Transfer Mode) connection, or FDDI (Fiber Distributed Data Interface) or CDDI (Copper Distributed Data Interface) connection. In addition, communications may include links to any of a variety of wireless networks, including WAP (Wireless Application Protocol), GPRS (General Packet Radio Service), GSM (Global System for Mobile Communications), CDMA (Code Division Multiple Access) or TDMA (Time Division Multiple Access), cellular telephone networks, GPS (Global Positioning System), CDPD (Cellular Digital Packet Data), RIM (Room Photograph) full-duplex paging networks, Bluetooth radio, or IEEE 802.11-based radio frequency networks. Network 4028 may also include or interface with any one or more of the following: RS-232 serial connection, IEEE-1394 (FireWire) connection, Fibre Channel connection, IrDA (Infrared) port, SCSI (Small Computer System Interface) connection, USB (Universal Serial Bus) connection or other wired or wireless, digital or analog interfaces or connections, mesh or Digi® network connections.

[0094] Broadly speaking, a cloud-based computing environment is a resource that typically combines large groups of processors (e.g., within a web server) with computing power and / or large groups of computer memory or storage devices. Systems providing cloud-based resources may be available only to their owners, or such systems may be accessible to external users who deploy applications within the computing infrastructure to benefit from large computing or storage resources.

[0095] For example, a cloud is formed by a network of web servers comprising multiple computing devices (e.g., host 4002), where each server 4030 (or at least several) provides processor and / or storage resources. These servers are managed by multiple users ( example like The workload provided by cloud resource customers or other users. Typically, each user's workload requirements for the cloud change in real time, sometimes drastically. The nature and extent of these changes usually depend on the type of business associated with the user.

[0096] It is worth noting that any hardware platform suitable for performing the processes described herein is suitable for use with the technology. As used herein, the terms "computer-readable storage medium" and "computer-readable storage media" refer to any one or more media that participate in providing instructions to the CPU for execution. Such media can take many forms, including but not limited to non-volatile media, volatile media, and transmission media. Non-volatile media include, for example, optical discs or magnetic disks, such as fixed disks. Volatile media include dynamic memory, such as system RAM. Transmission media include coaxial cables, copper wires, and optical fibers, which include conductors comprising one side of a bus. Transmission media can also take the form of acoustic or optical waves, such as those generated during radio frequency (RF) and infrared (IR) data communications. Common forms of computer-readable media include, for example, floppy disks, hard disks, magnetic tapes, any other magnetic media, CD-ROMs, digital video discs (DVDs), any other optical media, any other physical media with markings or perforations, RAM, PROMs, EPROMs, EEPROMs, FLASH EPROMs, any other memory chips or data exchange adapters, carrier waves, or any other media from which a computer can read.

[0097] Various forms of computer-readable media can participate in loading one or more sequences of one or more instructions to the CPU for execution. A bus carries data to system RAM, from which the CPU fetches and executes instructions. Instructions received from system RAM may optionally be stored on a disk before or after execution by the CPU.

[0098] Computer program code used to perform operations on aspects of the present invention can be written in any combination of one or more programming languages, including object-oriented programming languages ​​(e.g., Java, Smalltalk, C++, etc.) and conventional procedural programming languages ​​(e.g., the "C" programming language, Go, Python, or other programming languages ​​including assembly language). The program code can execute entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the latter scenario, the remote computer can be connected to the user's computer via any type of network, including a local area network (LAN) or a wide area network (WAN), or can connect to an external computer (e.g., via the Internet using an Internet service provider).

[0099] Examples of the devices, systems, and methods described in accordance with various aspects of this disclosure are provided below in the numbered clauses. Any aspect of the devices, methods, and / or systems described may include any one or more of the numbered clauses below and any combination thereof.

[0100] Clause 1: A computer-implemented method comprising: receiving real transaction data and fraud detection rules by a creator neural network, wherein the real transaction data corresponds to real transactions executed across a payment network, and wherein the fraud detection rules are used to identify fraudulent transactions; and generating synthetic transaction data by the creator neural network, wherein the synthetic transaction data corresponds to synthetic transactions that were not actually executed across the payment network, and wherein the fraud detection rules are updated based on the synthetic transaction data.

[0101] Clause 2: The computer-implemented method as described in Clause 1 further includes: receiving synthetic transaction data by an evaluator neural network; generating a risk score for the synthetic transaction by the evaluator neural network; and classifying at least some of the synthetic transactions as fraudulent transactions by the evaluator neural network based on the corresponding risk scores meeting a predetermined threshold, wherein the fraud detection rule is updated based on the synthetic transaction data and the risk score.

[0102] Clause 3: The computer-implemented method as described in Clause 2 further includes: receiving the real transaction data by the evaluator neural network; and classifying each transaction represented by the real transaction data and the synthetic transaction data as a real transaction or a synthetic transaction by the evaluator neural network.

[0103] Clause 4: The computer-implemented method as described in Clause 3 further includes: training the creator neural network to cause the evaluator neural network to incorrectly classify synthetic transactions as real transactions.

[0104] Clause 5: The computer-implemented method as described in any one of Clauses 2 to 4 further comprises: receiving additional genuine transaction data in real time by a fraud detection system; identifying a first genuine transaction represented by the additional genuine transaction data as a fraudulent transaction by the fraud detection system based on updated fraud detection rules; and rejecting the first genuine transaction by the fraud detection system.

[0105] Clause 6: The computer-implemented method as described in any one of Clauses 2 to 4 further comprises: receiving additional real transaction data in real time by a fraud detection system, wherein the fraud detection system includes an online implementation of the evaluator neural network; classifying a first real transaction represented by the real transaction data as a fraudulent transaction by the online implementation of the evaluator neural network; and rejecting the first real transaction by the fraud detection system.

[0106] Clause 7: A computer-implemented method as described in any one of Clauses 2 to 6, wherein the real transaction data includes data corresponding to transactions identified as fraudulent.

[0107] Clause 8: A system comprising: a creator model configured to: receive real transaction data corresponding to real transactions executed across a payment network; receive fraud detection rules for identifying fraudulent transactions; and generate synthetic transaction data based on the real transaction data and the fraud detection rules, wherein the synthetic transaction data corresponds to synthetic transactions that were not actually executed across the payment network; and an evaluator model configured to: receive the synthetic transaction data; and classify at least some of the synthetic transactions as fraudulent transactions.

[0108] Clause 9: The system as described in Clause 8, wherein the creator model comprises: a large language model for generating formatted fraud detection rules based on the fraud detection rules, wherein the creator model generates the synthetic transaction data based on the real transaction data and the formatted fraud detection rules.

[0109] Clause 10: The system as described in any one of Clauses 8 to 9, wherein the fraud detection rules include operating procedures, proxy processing rules, or risk rules, or a combination thereof.

[0110] Clause 11: The system of any one of Clauses 8 to 10, wherein the creator model further comprises: a randomizer for reducing the bias associated with the synthetic transaction data generated by the creator model; and an aggregator for reducing the bias associated with the synthetic transaction data generated by the creator model.

[0111] Clause 12: The system of any one of Clauses 8 to 11 further includes a fraud detection system, the fraud detection system including the fraud detection rules, wherein the fraud detection system is configured to: update the fraud detection rules based on the synthetic transaction data; and transmit the updated fraud detection rules to the creator model; and wherein the creator model is configured to: generate additional synthetic transaction data based on the updated fraud detection rules.

[0112] Clause 13: The system as described in Clause 12, wherein the fraud detection system is configured to: receive additional real transaction data corresponding to additional real transactions; apply the fraud detection rules to the additional real transaction data; identify a first real transaction in the additional real transactions as fraudulent; and reject the first real transaction.

[0113] Clause 14: The system of any one of Clauses 8 to 11 further includes a fraud detection system, wherein the fraud detection system includes an online implementation of the evaluator model.

[0114] Clause 15: The system as described in Clause 14, wherein the fraud detection system is configured to: receive additional real transaction data corresponding to additional real transactions; apply the additional real transaction data to the online implementation of the evaluator model to identify a first real transaction among the additional real transactions as fraudulent; and reject the first real transaction.

[0115] Clause 16: The system of any one of Clauses 8 to 15, wherein the evaluator model is used to: generate a risk score for the synthetic transaction; and classify at least some of the synthetic transactions as fraudulent transactions based on the corresponding risk scores meeting a predetermined threshold.

[0116] Clause 17: A computer-implemented method comprising: receiving real transaction data by a transaction service provider server; identifying a first fraudulent transaction by the transaction service provider server applying fraud detection rules to the real transaction data; rejecting the first fraudulent transaction by the transaction service provider server; generating synthetic transaction data by the transaction service provider server based on the real transaction data; and generating updated fraud detection rules by the transaction service provider server based on the synthetic transaction data.

[0117] Clause 18: The computer-implemented method as described in Clause 17, wherein generating the synthetic transaction data based on the real transaction data includes the transaction service provider server applying the real transaction data to a generative adversarial network.

[0118] Clause 19: The computer-implemented method as described in any one of Clauses 17 to 18 further comprises: receiving additional genuine transaction data by a transaction service provider server; identifying a second fraudulent transaction by the transaction service provider server by applying the updated fraud detection rule to the additional genuine transaction data; and rejecting the second fraudulent transaction by the transaction service provider server.

[0119] Clause 20: The computer-implemented method as described in Clause 19, the method further comprising: generating additional synthetic transaction data by the transaction service provider server based on the additional real transaction data; and generating further updated fraud detection rules by the transaction service provider server based on the additional synthetic transaction data.

[0120] Furthermore, it should be understood that any one or more of the forms, expressions, and examples described below may be combined with any one or more of the other forms, expressions, and examples described below.

[0121] While several forms have been shown and described, the applicant does not intend to limit or restrict the scope of the appended claims to such details. Many modifications, variations, alterations, substitutions, combinations, and equivalents of those forms can be implemented without departing from the scope of this disclosure, and such modifications, variations, alterations, substitutions, combinations, and equivalents will be apparent to those skilled in the art. Furthermore, the structure of each element associated with a said form can alternatively be described as a device for providing the function performed by said element. Additionally, where materials are disclosed for certain components, other materials may be used. Therefore, it should be understood that the foregoing description and the appended claims are intended to cover all such modifications, combinations, and variations falling within the scope of the disclosed forms. The appended claims are intended to cover all such modifications, variations, alterations, substitutions, modifications, and equivalents.

[0122] As used herein, a “server” can include one or more computing devices, which may be individual, independent machines located in the same or different locations, owned or operated by the same or different entities, and may further be one or more clusters of distributed computers or “virtual” machines housed within a data center. Those skilled in the art will understand and appreciate that the functionality performed by a single “server” may be distributed across multiple different computing devices for various reasons. As used herein, “server” is intended to refer to all such scenarios and should not be construed as or limited to a particular configuration. Furthermore, a server as described herein may, but does not necessarily, reside in (or be operated by) an agent of a merchant, payment network, financial institution, healthcare provider, social media provider, government agency, or any of the aforementioned entities. The term “server” may also refer to or include one or more processors or computers, storage devices, or similar computer arrangements that facilitate multi-party communication and processing through a network environment such as the Internet, but it should be understood that communication may be facilitated through one or more public or private network environments, and various other arrangements are possible. Additionally, multiple computers communicating directly or indirectly in a network environment ( For example Servers or other computerized devices For examplePoint-of-sale equipment can constitute a "system" (e.g., a merchant's point-of-sale system). As used herein, references to "server" or "processor" can refer to a previously stated server and / or processor, different servers and / or processors, and / or combinations of servers and / or processors, as described herein. For example, as used in the specification and claims, a first server and / or first processor stated to perform a first step or function can refer to the same or different servers and / or processors stated to perform a second step or function.

[0123] As used herein, "server computer" can describe a powerful computer or cluster of computers. For example, a server computer can be a mainframe, a small computer cluster, or a group of servers functioning as a single unit. A server computer can be associated with entities such as payment processing networks, wallet providers, merchants, authentication clouds, acquirers, or issuers. In one example, a server computer can be a database server coupled to a web server. The server computer can be coupled to a database and can include any hardware, software, other logic, or combination of the foregoing for serving requests from one or more client computers. A server computer can include one or more computing devices and can use any of a variety of computing architectures, arrangements, and compilations for serving requests from one or more client computers. In some implementations or aspects, a server computer can provide and / or support payment network cloud services.

[0124] As used herein, references to “device,” “server,” “processor,” etc., may refer to a previously stated device, server, or processor, different servers or processors, and / or combinations of servers and / or processors that are said to perform a prior step or function. For example, as used in the specification and claims, a first server or first processor that is said to perform a first step or a first function may refer to the same or different server or the same or different processor that is said to perform a second step or a second function.

[0125] One or more components may be referred to herein as “configured to,” “configurable to,” “operable as,” “suitable for,” “capable of,” “compliant to,” etc. Those skilled in the art will recognize that, unless the context otherwise requires, “configured to” can generally encompass active state components and / or inactive state components and / or standby state components.

[0126] Those skilled in the art will recognize that, generally speaking, and especially in the appended claims ( For example The terminology used in the appended claims is generally intended as an "openness" term. For exampleThe term "including" should be interpreted as "including but not limited to," the term "having at least," and the term "includes" should be interpreted as "including but not limited to," etc. Those skilled in the art will further understand that if a particular number of the introduced claim statements are intended, then such intent will be expressly stated in the claims, and where no such statements are present, such intent does not exist. For example, to aid understanding, the appended claims may include the use of the introductory phrases "at least one" and "one or more" to introduce the claim statement. However, the use of such phrases should not be construed as meaning that introducing the claim statement with the indefinite article "a(a)" or "an" limits any particular claim containing this introduced claim statement to containing only one such statement, even when the same claim includes the introductory phrase "one or more" or "at least one" and the indefinite article such as "a(a)" or "an." example like "A (a)" and / or "an (an)" should generally be interpreted as meaning "at least one" or "one or more"; the same applies to the use of definite articles used to introduce the statement of a claim.

[0127] Unless otherwise stated, the terms “substantially,” “about,” or “approximately” as used in this disclosure mean an acceptable error in a particular value as determined by one of ordinary skill in the art, depending in part on how the value is measured or determined. In some aspects, the terms “substantially,” “about,” or “approximately” mean within 1, 2, 3, or 4 standard deviations. In some aspects, the terms “substantially,” “about,” or “approximately” mean within 50%, 20%, 15%, 10%, 9%, 8%, 7%, 6%, 5%, 4%, 3%, 2%, 1%, 0.5%, or 0.05% of a given value or range.

[0128] Furthermore, even in claims that explicitly state a specific number, those skilled in the art will recognize that such statements should generally be interpreted as meaning at least the stated number ( For example In the absence of other modifiers, simply stating "two statements" generally means at least two statements, or two or more statements. Furthermore, in these cases where conventions such as "at least one of A, B, and C" are used, such a construction is generally expected by a person skilled in the art to reflect the meaning of the convention. For example"A system having at least one of A, B, and C" includes, but is not limited to, systems having only A, only B, only C, A and B together, A and C together, B and C together, and / or A, B, and C together, etc. In these cases where the convention of "at least one of A, B, or C, etc." is used, generally, such constructions are intended to be understood by those skilled in the art in the meaning of the convention. For example "A system having at least one of A, B, or C" will include, but is not limited to, systems having only A, only B, only C, A and B together, A and C together, B and C together, and / or A, B, and C together, etc. Those skilled in the art will further understand that, generally, unless the context otherwise indicates, separate words and / or phrases presenting two or more alternative terms, whether in the specification, claims, or drawings, should be understood to include the possibility of including one term, any one of the terms, or both terms. For example, the phrase "A or B" will generally be understood to include the possibility of including "A" or "B" or "A and B".

[0129] Regarding the appended claims, those skilled in the art will understand that the operations described herein can generally be performed in any order. Furthermore, although the various operation flowcharts are presented sequentially, it should be understood that the various operations can be performed in any order other than those shown, or can be performed simultaneously. Examples of such alternative orderings may include overlapping, interleaving, interrupted, reordered, ascending, preparatory, supplementary, simultaneous, inverted, or other varied orderings, unless the context otherwise specifies. Unless the context otherwise specifies, terms such as “in response to,” “related to,” or other past tense adjectives are generally not intended to exclude such variations.

[0130] It is worth noting that any reference to "an aspect," "one aspect," "an example," "an example," etc., means that a particular feature, structure, or characteristic described in connection with said aspect is included in at least one aspect. Therefore, the phrases "in an aspect," "in one aspect," "in an example," and "in an example" appearing throughout the specification do not necessarily all refer to the same aspect. Furthermore, a particular feature, structure, or characteristic may be combined in one or more aspects in any suitable manner.

[0131] As used herein, unless the context clearly indicates otherwise, the singular forms “a”, “an”, and “the” include plural referents.

[0132] Any patent application, patent, non-patent publication, or other disclosure cited in this specification and / or listed in any application data sheet is incorporated herein by reference so that the incorporated material is not inconsistent with it. Consequently, and to the extent necessary, any conflicting material incorporated by reference as expressly set forth herein supersedes any conflicting material. It is claimed that any material or portion thereof incorporated herein by reference that conflicts with existing definitions, statements, or other disclosures set forth herein will be incorporated only to the extent that the incorporated material does not conflict with existing disclosures.

[0133] In summary, the numerous benefits arising from adopting the concepts described herein have been described. One or more forms of the foregoing description have been presented for illustrative and descriptive purposes. They are not intended to be exhaustive or limited to the precise forms disclosed. Modifications or variations are possible in light of the foregoing teachings. The aforementioned forms have been chosen and described to illustrate principles and practical applications, thereby enabling those skilled in the art to utilize the various forms and make various modifications suitable for the particular application considered. The claims filed herein are intended to define the overall scope.

Claims

1. A computer-implemented method, comprising: The creator neural network receives real transaction data and fraud detection rules, wherein the real transaction data corresponds to real transactions executed across the payment network, and wherein the fraud detection rules are used to identify fraudulent transactions; as well as Synthetic transaction data is generated by the creator neural network, wherein the synthetic transaction data corresponds to synthetic transactions that are not actually executed across the payment network, and wherein the fraud detection rules are updated based on the synthetic transaction data.

2. The computer-implemented method as described in claim 1, further comprising: The synthesized transaction data is received by the evaluator neural network; The evaluator neural network generates a risk score for the synthetic transaction; as well as The evaluator neural network classifies at least some of the synthetic transactions as fraudulent transactions based on the corresponding risk scores meeting a predetermined threshold, wherein the fraud detection rules are updated based on the synthetic transaction data and the risk scores.

3. The computer-implemented method as described in claim 2, further comprising: The real transaction data is received by the evaluator neural network; as well as The evaluator neural network classifies each transaction represented by the real transaction data and the synthetic transaction data into a real transaction or a synthetic transaction.

4. The computer-implemented method as described in claim 3, further comprising: The creator neural network is trained so that the evaluator neural network incorrectly classifies synthetic transactions as real transactions.

5. The computer-implemented method as described in claim 2, further comprising: The fraud detection system receives additional real transaction data in real time. The fraud detection system identifies the first real transaction represented by the additional real transaction data as a fraudulent transaction based on updated fraud detection rules; as well as The fraud detection system rejects the first genuine transaction.

6. The computer-implemented method as described in claim 2, further comprising: Additional real transaction data is received in real time by a fraud detection system, wherein the fraud detection system includes an online implementation of the evaluator neural network; The online implementation of the evaluator neural network classifies the first real transaction, represented by the real transaction data, as a fraudulent transaction; as well as The fraud detection system rejects the first genuine transaction.

7. The computer-implemented method of claim 1, wherein the real transaction data includes data corresponding to transactions identified as fraudulent.

8. A system comprising: Creator model, the creator model is used for: Receive real transaction data corresponding to real transactions executed across payment networks; Receive fraud detection rules used to identify fraudulent transactions; and Synthetic transaction data is generated based on the real transaction data and the fraud detection rules, wherein the synthetic transaction data corresponds to synthetic transactions that are not actually executed across the payment network; as well as Evaluator model, the evaluator model being used for: Receive the synthesized transaction data; and At least some of the synthetic transactions will be classified as fraudulent transactions.

9. The system of claim 8, wherein the creator model comprises: A large language model is used to generate formatted fraud detection rules based on the fraud detection rules, wherein the creator model generates the synthetic transaction data based on the real transaction data and the formatted fraud detection rules.

10. The system of claim 9, wherein the fraud detection rules include operating procedures, proxy processing rules, or risk rules, or combinations thereof.

11. The system of claim 9, wherein the creator model further comprises: A randomizer, the randomizer being used to reduce the bias associated with the synthetic transaction data generated by the creator model; and An aggregator is used to reduce the bias associated with the synthetic transaction data generated by the creator model.

12. The system of claim 11, further comprising a fraud detection system, the fraud detection system including the fraud detection rules, wherein the fraud detection system is used for: The fraud detection rules are updated based on the synthetic transaction data; and The updated fraud detection rules are sent to the creator model; and The creator model mentioned above is used for: Additional synthetic transaction data is generated based on the updated fraud detection rules.

13. The system of claim 12, wherein the fraud detection system is used for: Receive additional real transaction data corresponding to the additional real transaction; Apply the fraud detection rules to the additional real transaction data; The first genuine transaction in the additional genuine transactions is identified as fraudulent; and Reject the first genuine transaction.

14. The system of claim 11, further comprising a fraud detection system, wherein the fraud detection system includes an online implementation of the evaluator model.

15. The system of claim 14, wherein the fraud detection system is used for: Receive additional real transaction data corresponding to the additional real transaction; The additional real transaction data is applied to the online implementation of the evaluator model to identify the first real transaction among the additional real transactions as fraudulent; and Reject the first genuine transaction.

16. The system of claim 8, wherein the evaluator model is used for: Generate a risk score for the synthetic transaction; and At least some of the synthetic transactions are classified as fraudulent transactions based on the corresponding risk scores meeting a predetermined threshold.

17. A computer-implemented method, comprising: The actual transaction data is received by the transaction service provider's server; The transaction service provider's server identifies the first fraudulent transaction by applying fraud detection rules to the real transaction data; The transaction service provider's server rejects the first fraudulent transaction; The transaction service provider's server generates synthetic transaction data based on the real transaction data; as well as The transaction service provider's server generates updated fraud detection rules based on the synthesized transaction data.

18. The computer-implemented method of claim 17, wherein generating the synthetic transaction data based on the real transaction data includes the transaction service provider server applying the real transaction data to a generative adversarial network.

19. The computer-implemented method of claim 18, further comprising: The transaction service provider's server receives additional real transaction data; The transaction service provider's server identifies the second fraudulent transaction by applying the updated fraud detection rules to the additional genuine transaction data; as well as The transaction service provider's server rejects the second fraudulent transaction.

20. The computer-implemented method of claim 19, further comprising: The transaction service provider's server generates additional synthetic transaction data based on the additional real transaction data; as well as The transaction service provider's server generates further updated fraud detection rules based on the additional synthetic transaction data.