Digital interaction monitoring and control using machine-learning models
Machine-learning models trained on enriched data improve the efficiency and accuracy of digital interaction moderation by predicting dispute outcomes, addressing the inefficiencies of manual chargeback processes.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- EQUIFAX INC
- Filing Date
- 2026-01-13
- Publication Date
- 2026-07-23
AI Technical Summary
Existing systems face challenges in efficiently moderating and controlling digital interactions in secure computing environments, particularly in resolving disputes such as chargebacks, which are often time-consuming and prone to errors, with manual processes and lack scalability.
Implementing machine-learning models trained on enriched data using feature engineering and stratified random sampling to generate dispute scores, predicting the likelihood of successfully disputing interactions and reversing electronic resource transfers.
Enhances the accuracy and scalability of digital interaction moderation, reducing manual review errors and enabling real-time, efficient dispute resolution with improved statistical analysis.
Smart Images

Figure US2026011108_23072026_PF_FP_ABST
Abstract
Description
PATENT Attorney Docket No. 096923-1541325 Client Ref. No. EFX-209WO DIGITAL INTERACTION MONITORING AND CONTROL USING MACHINELEARNING MODELSCross-Reference to Related Applications
[0001] This application claims the benefit of U.S. Provisional Application No. 63 / 745,129, filed January 14, 2025, and PCT Application No. US / 2025 / 058618, filed December 8, 2025, the entire contents of each of which is incorporated herein by reference in its entirety for all purposes.Technical Field
[0002] This application relates to machine-learning models associated with various workstreams, and more specifically, but not by way of limitations, to techniques for improved system performance in digital interaction monitoring and control using machine-learning models.Background
[0003] Moderated online environments may require directing and controlling digital interactions between various users. Examples of digital interactions can include disputes, where the disputes manifest when a user challenges a particular digital interaction. Disputes often involve seeking reversal or remediation through the relevant platform, service provider, or intermediary. Examples of digital interactions and disputes can include disputes related to accessing protected computer environments and resources. For example, a user may wish to dispute a secure computing environment’s decision to exclude the user on an access control list, to dispute content moderation of the user’s messages delivered in the secure computing environment, or to dispute the secure computing environment’s provisioning of network resources to the user. Digital interactions and disputes can further relate to disputes between users and service providers, described in further detail below as chargebacks and chargeback disputes.Summary
[0004] Various embodiments of the present disclosure provide for improving machinelearning model operations for detecting fraud and other cyber-risks. According to one example, a non-transitory computer-readable storage medium having program code executable by a processing device to perform operations is described. The operations can include receiving, from a third-party device, a digital interaction inquiry associated with a digital interaction and retrieving interaction data associated with the digital interaction. The digital interaction canPATENT Attorney Docket No. 096923-1541325 Client Ref. No. EFX-209WO include a transfer of electronic resources from a third-party associated with the third-party device to a separate entity. The operations can include retrieving interaction data associated with the digital interaction and applying the interaction data to a machine-learning model trained on dispute training data to generate a dispute score. The dispute score can represent a likelihood of successfully disputing the digital interaction and reversing the transfer of the electronic resources. The operations can include transmitting the dispute score to the third-party device to cause the third-party to respond to the digital interaction.
[0005] According to another example, a computer-implemented method executed by a processor is described. The computer-implemented method can include receiving, by a processor and from a third-party device, a digital interaction inquiry associated with a digital interaction and retrieving, by the processor, interaction data associated with the digital interaction. The digital interaction can include a transfer of electronic resources from a third-party associated with the third-party device to a separate entity. The computer-implemented method can include retrieving interaction data associated with the digital interaction and applying, by the processor, the interaction data to a machine-learning model trained on dispute training data to generate a dispute score. The dispute score can represent a likelihood of successfully disputing the digital interaction and reversing the transfer of the electronic resources. The computer-implemented method can include transmitting, by the processor and to the third-party device, the dispute score to cause the third-party to respond to the digital interaction.
[0006] According to yet another example, a processing device and a memory device in which instructions executable by the processing device are stored for causing the processing device are described as executing operations. The operations can include receiving, from a third-party device, a digital interaction inquiry associated with a digital interaction and retrieving interaction data associated with the digital interaction. The digital interaction can include a transfer of electronic resources from a third-party associated with the third-party device to a separate entity. The operations can include retrieving interaction data associated with the digital interaction and applying the interaction data to a machine-learning model trained on dispute training data to generate a dispute score. The dispute score can represent a likelihood of successfully disputing the digital interaction and reversing the transfer of thePATENT Attorney Docket No. 096923-1541325 Client Ref. No. EFX-209WO electronic resources. The operations can include transmitting the dispute score to the third-party device to cause the third-party to respond to the digital interaction.
[0007] This summary is not intended to identify key or essential features of the claimed subject matter, nor is it intended to be used in isolation to determine the scope of the claimed subject matter. The subject matter should be understood by reference to appropriate portions of the entire specification, any or all drawings, and each claim.
[0008] The foregoing, together with other features and examples, will become more apparent upon referring to the following specification, claims, and accompanying drawings.Brief Description of the Drawings
[0009] FIG. 1 is a block diagram depicting an example of a computing environment in which a dispute computing system can efficiently determine dispute scores, according to certain aspects of the present disclosure.
[0010] FIG. 2 is a flow diagram of a process for determining dispute scores via a trained machine-learning model according to certain examples.
[0011] FIG. 3 is a flow diagram of a process for training machine-learning models to generate dispute scores, according to certain examples.
[0012] FIG. 4 is a flow diagram of a process for performing fraud detection and prevention based on determined dispute scores according to certain examples.
[0013] FIG. 5 is a flow diagram of a set of operations for enriching data to facilitate machine-learning model training according to certain examples.
[0014] FIG. 6 is a block diagram depicting an example of a computing device, which can be used to implement the dispute server or the model training server according to disclosed embodiments.Detailed Description
[0015] As discussed above, moderated digital interactions between a user and a secure computing environment can include moderating users’ network access to the secure computing environment, or to services associated with the secure computing environment. The services associated with the secure computing environment can include chargeback disputes. The payment card industry is plagued by disputes between cardholders and merchants, resulting in chargebacks. Chargebacks occur when a cardholder disputes a transaction with their issuing bank, which then reverses the transaction and deducts the amount from the merchant’s account. Cardholders may dispute transactions for various reasons, including non-receipt of goods or services, unauthorized transactions, or other legitimate concerns. In other cases, chargebacksPATENT Attorney Docket No. 096923-1541325 Client Ref. No. EFX-209WO may be disputed for illegitimate and fraudulent reasons. Merchants may choose to contest chargebacks, but this process can be time-consuming and costly. The outcome of a chargeback dispute is often uncertain, and merchants may struggle to determine which disputes are worth fighting.
[0016] Certain aspects and features of the present disclosure address issues related to moderating digital interactions in secure computing environments by leveraging various repositories of data, such as interaction data, and machine-learning (“ML”) techniques. Machine learning models trained on data accessed from various repositories can be applied to user submissions to assess the credibility of a given submission. The described techniques can be used to assign flags to given submissions and to associated users, to provide secured access to various systems, in addition to protecting such systems from user manipulation.
[0017] The following non-limiting example is provided to introduce certain embodiments. A dispute prediction model may be applied, which is trained for assessing entity credibility and outputting the likelihood of reversing an interaction (such as a chargeback dispute) through dispute procedures based on provided interaction data. The dispute prediction model can be trained on data from one or more data repositories including dispute data, industry data, and data related to various entities. Examples of data retrieved from the one or more data repositories can include data related to timing and location of the interaction underlying the dispute, payment information such as credit card IDs, amounts in dispute, address verification service (AVS) results and card verification values (CVVs), interaction outcomes, payment processing information, billing and shipping information, and the like.
[0018] Specific approaches for providing representative sampling to mitigate sampling bias and ensuring model generalizability are described. New features are designed and curated using feature engineering and data enrichment strategies to further improve the accuracy of the dispute prediction model.
[0019] Examples of features used to train the model can include: features derived from the dispute management process; temporal features indicating ranges between key dates in the dispute process such as the number of days between an order being placed and an interaction; timestamp features; flag features based on whether specific conditions were met (i.e., a binary flag indicating whether the underlying transaction was in USD); calculated features such as differences between bill amounts, refund amounts, dispute amounts, and the like; category features which group patterns in underlying data based on frequency; and vertical featuresPATENT Attorney Docket No. 096923-1541325 Client Ref. No. EFX-209WO indicating merchant industry type. Such vertical features can be enriched based on LLM data enrichment techniques to provide additional context and fill gaps in underlying data.
[0020] The trained machine-learning model may thus be capable of receiving interaction inquiries from client devices associated with merchants and other organizations interested in determining whether to dispute a given interaction. The inquiry can include data related to the interaction under dispute, in addition to data related to the entity which submitted the interaction. In response, the model can output the dispute score. The dispute score can reflect a probability of overturning the dispute in a range between 0 and 1, with 0 being not probable, and 1 being highly probable. The score can also be transformed into other ranges such as a 0-100 scale, letter grade scale, a binary win / loss score, and the like. Scores can be further tuned and configured for various capabilities, such as including customized cutoffs and thresholds.
[0021] Compared to prior approaches for assessing fraud and user credibility, the techniques described here provide several improvements. For instance, manual and timeconsuming processes of reviewing dispute data, which are prone to error, can be eliminated. Real-time insights and analysis may be further derived absent delays incurred through manual review. The described techniques are highly scalable, allowing for increases in received dispute datasets while meeting growing demands. The techniques described here can provide more complex statistical analysis and rule-based determinations to capture deeper patterns and relationships in underlying data, leading to improved predictions in assessing the likelihood of succeeding in disputes.
[0022] Certain aspects described herein overcome the limitations of previous statisticalbased analyses and techniques for digital interaction moderation, monitoring, and control. Specific machine-learning model architecture associated with digital interaction monitoring and control are described. The machine-learning models described herein can be implemented to analyze user behaviors when users are initiating digital interactions in secure computing environments. The digital interactions can be analyzed based on a variety of features including temporal features, timestamp features, and vertical features to better assess how to moderate and control various digital interactions, such as in requests to dispute various interactions including requests to rescind denied access to secure computing environments, or whether to deny access to such environments. Further digital interaction moderation, as facilitated by the described machine-learning models, can include assisting relevant personnel in determining whether to deny requests to access or exchange resources within secure computing environments. In further examples still, specific entity devices can be monitored based onPATENT Attorney Docket No. 096923-1541325 Client Ref. No. EFX-209WO historic patterns of initiating suspect interactions, indicative that such entities represent threat actors to a secure computing environment. In response, certain examples can include generating and transmitting signals to relevant devices including third-party devices and intermediary service platforms, where the signals control various entities’ access to secure digital platforms and services for exchanging digital resources. The techniques for tracking suspect interactions, leading to the identification and control of threat actor accounts, can then result in access control implementations resulting in improvements in the stability and security of various digital services.
[0023] Certain aspects described herein further provide improved machine-learning model performance in the example operations as described above. Improved machine-learning model performance can be achieved via techniques described herein related to training data generation, where training data may be generated according to particular rules including stratified random sampling, cluster sampling, and stratified-cluster sampling. Such techniques can result in improved efficiency in machine-learning model training by reducing the overall size of the training data, reducing noise within the training data, and by emphasizing the more dispositive features pertinent to machine-learning model assessments related to digital interactions via cluster-based techniques.
[0024] These illustrative examples are given to introduce the reader to the general subject matter discussed here and are not intended to limit the scope of the disclosed concepts. The following sections describe various additional features and examples with reference to the drawings in which like numerals indicate like elements, and directional descriptions are used to describe the illustrative examples but, like the illustrative examples, should not be used to limit the present disclosure.Operating Environment Example for Dispute Determinations
[0025] Referring now to the drawings, FIG. 1 is a block diagram of an operating environment configured to implement a dispute computing system according to disclosed examples. In the operating environment 100, a dispute computing system 130 builds and trains models that can be used to determine credibility scores for subsequent use according to a variety of configurations of AI / ML models. The dispute computing system 130 can further apply one or more algorithms involving several models to determine dispute scores. FIG. 1 depicts examples of hardware components of the dispute computing system 130, according to some aspects. The dispute computing system 130 is a specialized computing system that may be used for processing large amounts of data using a large number of computer processingPATENT Attorney Docket No. 096923-1541325 Client Ref. No. EFX-209WO cycles. The dispute computing system 130 can include a model training server 110 for building and training machine-learning models 120 including classification models in addition to other ML models. The dispute computing system 130 can further include a dispute server 118 for assessing the likelihood of success (i.e., reversing) an interaction through a dispute process, based on various features associated with the corresponding interaction under inquiry.
[0026] The model training server 110 can include one or more processing devices that execute program code, such as a model training application 112. The program code is stored on a non-transitory computer-readable medium. The model training application 112 can execute one or more processes to execute and / or retrain an LLM for predicting dispute winnability based on interaction data 124, enriched features 142, model training samples 126, and other data.
[0027] In some aspects, the model training application 112 can build and train a machinelearning model 120 utilizing model training samples 126 (e.g., including training entity data and training attributes). The model training samples 126 can be stored in one or more network-attached storage units on which various repositories, databases, or other structures are stored. Examples of these data structures are the data repository 122. Additionally, model training samples 126 can be generated and filtered according to various described techniques, such as those discussed with respect to FIG. 3.
[0028] Network-attached storage units may store a variety of different types of data organized in a variety of different ways and from a variety of different sources. For example, the network-attached storage unit may include storage other than primary storage located within the model training server 110 that is directly accessible by processors located therein. In some aspects, the network-attached storage unit may include secondary, tertiary, or auxiliary storage, such as large hard drives, servers, virtual memory, among other types. Storage devices may include portable or non-portable storage devices, optical storage devices, and various other media capable of storing and containing data. A machine-readable storage medium or computer-readable storage medium may include a non-transitory medium in which data can be stored and that does not include carrier waves or transitory electronic signals. Examples of a non-transitory medium may include, for example, a magnetic disk or tape, optical storage media such as a compact disk or digital versatile disk, flash memory, memory, or memory devices.
[0029] The dispute server 118 can include one or more processing devices that execute program code, such as a dispute application 114. The program code is stored on a non-transitoryPATENT Attorney Docket No. 096923-1541325 Client Ref. No. EFX-209WO computer-readable medium. The dispute application 114 can execute one or more processes to utilize the machine-learning model 120 trained by the model training application 112 based on interaction data 124 to assess the likelihood of reversing an interaction through dispute.
[0030] Furthermore, the dispute computing system 130 can communicate with various other computing systems, such as client computing systems 104. For example, client computing systems 104 may send dispute queries to the dispute server 118 to determine a credibility score for a given entity or may send signals to the dispute server 118 that control or influence different aspects of the dispute computing system 130. The client computing systems 104 may also interact with user computing systems 106 via one or more public data networks 108 to facilitate interactions between users of the user computing systems 106 and interactive computing environments provided by the client computing systems 104.
[0031] Each client computing system 104 may include one or more third-party devices, such as individual servers or groups of servers operating in a distributed manner. A client computing system 104 can include any computing device or group of computing devices operated by a seller, lender, or other providers of products or services. The client computing system 104 can include one or more server devices. The one or more server devices can include or can otherwise access one or more non-transitory computer-readable media. The client computing system 104 can also execute instructions that provide an interactive computing environment accessible to user computing systems 106. Examples of the interactive computing environment include a mobile application specific to a particular client computing system 104, a web-based application accessible via a mobile device, etc. The executable instructions are stored in one or more non-transitory computer-readable media.
[0032] The client computing system 104 can include one or more processing devices that are capable of providing the interactive computing environment to perform operations described herein. The interactive computing environment can include executable instructions stored in one or more non-transitory computer-readable media. The instructions providing the interactive computing environment can configure one or more processing devices to perform operations described herein. In some aspects, the executable instructions for the interactive computing environment can include instructions that provide one or more graphical interfaces. The graphical interfaces are used by a user computing system 106 to access various functions of the interactive computing environment. For instance, the interactive computing environment may transmit data to and receive data from a user computing system 106 to shift between different states of the interactive computing environment, where the different states allow onePATENT Attorney Docket No. 096923-1541325 Client Ref. No. EFX-209WO or more electronics interactions between the user computing system 106 and the client computing system 104 to be performed.
[0033] In some examples, a client computing system 104 may have other computing resources associated therewith (not shown in FIG. 1), such as server computers hosting and managing virtual machine instances for providing cloud computing services, server computers hosting and managing online storage resources for users, server computers for providing database services, and others. The interaction between the user computing system 106 and the client computing system 104 may be performed through graphical user interfaces presented by the client computing system 104 to the user computing system 106, or through an application programming interface (“API”) calls or web service calls.
[0034] A user computing system 106 can include any computing device or other communication device operated by a user, such as a consumer or a customer. The user computing system 106 can include one or more computing devices, such as laptops, smartphones, and other personal computing devices. A user computing system 106 can include executable instructions stored in one or more non-transitory computer-readable media. The user computing system 106 can also include one or more processing devices that are capable of executing program code to perform operations described herein. In various examples, the user computing system 106 can allow a user to access certain online services from a client computing system 104 or other computing resources, to engage in mobile commerce with a client computing system 104, to obtain controlled access to electronic content hosted by the client computing system 104, etc.
[0035] In some examples, the dispute computing system 130 can cause the user computing system 106, the client computing system 104, or a combination of the systems to execute one or more actions in accordance with the generated dispute score. For instance, the dispute computing system 130 can generate entity dispute scores associated with each entity based in part on previous dispute scores related to entity interactions for implementation in a subsequent AI / ML model, where the subsequent AI / ML model can communicate with a user computing system to automatically cause one or more components of the user computing system 106 to reject access to various servers or interactions based on the entity dispute score.
[0036] Each communication within the operating environment 100 may occur over one or more data networks, such as a public data network 108, a network 116 such as a private data network, or some combination thereof. A data network may include one or more of a variety of different types of networks, including a wireless network, a wired network, or a combinationPATENT Attorney Docket No. 096923-1541325 Client Ref. No. EFX-209WO of a wired and wireless network. Examples of suitable networks include the Internet, a personal area network, a local area network (“LAN”), a wide area network (“WAN”), or a wireless local area network (“WLAN”). A wireless network may include a wireless interface or a combination of wireless interfaces. A wired network may include a wired interface. The wired or wireless networks may be implemented using routers, access points, bridges, gateways, or the like, to connect devices in the data network.
[0037] The number of devices depicted in FIG. 1 is provided for illustrative purposes. Different numbers of devices may be used. For example, while certain devices or systems are shown as single devices in FIG. 1, multiple devices may instead be used to implement these devices or systems. Similarly, devices or systems that are shown as separate, such as the model training server 110 and the dispute server 118, may be instead implemented in a single device or system.Example Operations Generating Dispute Scores
[0038] FIG. 2 is a flow diagram of a process for implementing determining dispute scores via a trained machine-learning model according to certain examples. For illustrative purposes, the process 200 is described with reference to implementations described above with respect to one or more examples described herein. Other implementations, however, are possible. In some aspects, the operations in FIG. 2 may be implemented in program code that is executed by one or more computing devices such as the dispute server 118 depicted in FIG. 1. In some aspects of the present disclosure, one or more operations shown in FIG. 2 may be omitted or performed in a different order. Similarly, additional operations not shown in FIG. 2 may be performed.
[0039] At block 202, the process 200 involves receiving, from a third-party device, a digital interaction inquiry associated with a digital interaction. The digital interaction can take the form of a variety of requests and transactions within secure computing environments, such as a request to authenticate into a protected system, a request to remove a user from an accesscontrol list, and the like. The digital interaction can also include exchanges and transfers of electronic resources between entities within the digital environment, such as a chargeback dispute between the third-party (such as a merchant) and a separate entity (such as a user initiating the interaction such as a chargeback dispute). In such examples, the merchant can be associated with the third-party device and the interaction can include a chargeback dispute initiated by the separate entity, resulting in a transfer of funds from the third-party merchant account to the separate entity that initiated the chargeback dispute.PATENT Attorney Docket No. 096923-1541325 Client Ref. No. EFX-209WO
[0040] The interaction inquiry can include messages received from a variety of client computing systems 104 including merchant computing systems, referred to generally as the third-party device. For instance, a user with access to a merchant computing system can select a specific interaction they would like to dispute and submit an interaction inquiry associated with that interaction. In the same or other examples, settings can be configured such that each interaction on a given computing system is received by the dispute computing system 130. According to some settings, specific entities (via associated accounts) can be identified and flagged such that each interaction associated with that entity automatically generates an interaction inquiry. According to the above examples, interaction inquiries can be generated in real-time, near real-time, or can be collected and transmitted according to a variety of other schedules.
[0041] At block 204, the process 200 involves retrieving interaction data associated with the interaction. The interaction data can be retrieved within the same message or data structure as the interaction inquiry. Thus, a given client computing system 104 may transmit both the interaction inquiry into an interaction and the associated interaction data. In the same and other examples, interaction data can also be retrieved via a data repository 122 communicatively coupled to the dispute computing system. As an example, the interaction inquiry received at block 202 may also be received with interaction data such as the name and date of the interaction and an identifier of the entity associated with the interaction. The dispute computing system 130 can then perform a search within the data repository 122 based on the interaction data, such as the entity identifier, to retrieve additional interaction data stored internal the data repository 122, such as data associated with the entity.
[0042] At block 206, the process 200 involves applying the interaction data to a machinelearning model trained on dispute training data. The machine-learning model can generally include one or more of decision trees, random forests, logic regression models or other classifier models. The machine-learning model, according to some examples, can be trained according to a variety of libraries such as extreme Gradient Boosting (“XGBoost”), Light Gradient Boosting Machine (“LightGBM”) and the like. The machine-learning model hyperparameters may also be tuned according to a variety of techniques including through application of optimization algorithms such as Tree of Parzen Estimators (“TPE”).
[0043] The dispute training data can be grouped according to feature engineering techniques to improve the accuracy of the model. Thus, the dispute computing system 130 can generate a set of features from the dispute training data, where the set of features is then usedPATENT Attorney Docket No. 096923-1541325 Client Ref. No. EFX-209WO to train the machine-learning model. The sets of features can include timestamp features, temporal features, and vertical features. Timestamp features can include the date and time of the interaction, such including one or more of the date of the transaction and the date of the submitted chargeback. Temporal features can build from timestamp features and relate to a difference in days between key dates in an interaction procedure, such as the number of days between an order or transaction being placed, and the date of the associated chargeback. Vertical features can relate to the industry associated with the interaction.
[0044] In some examples, the various features and associated data can be enriched to reduce the cardinality (i.e., the number of unique values in the dataset) and further improve machine-learning operations. For instance, verticals may be assigned through data enrichment techniques using large language models (“LLMs”). The verticals, or industry, associated with a given interaction can be assigned by training or tuning an LLM through prompt engineering. In such ways, data sparsity issues can be resolved (i.e., where the interaction data associated with the dispute does not provide the associated vertical), while also reducing the cardinality of the data set. Data enrichment techniques are described further according to the example of FIG. 5.
[0045] Additional examples of specific features that may employed to train the model can include refunded amount values representing the amount disputed within the interaction, the provider name, representing the payment provider of the transaction, bank identification number (“BIN”) of the bank who issued the payment card underlying the transaction in dispute, the reason code underlying the reason provided for the dispute, portal name representing the portal the dispute was initiated through and vertical assignment representing the industry in which the dispute occurred. Additional examples of the machine-learning model structure, and techniques for training the machine-learning model are described according to the examples of FIG. 3.
[0046] At block 208, the process 200 involves generating, via the machine-learning model, a dispute score. The dispute score can represent the “winnability” or likelihood of success that a dispute will result in a digital interaction being reversed, and the likelihood of reversing the transfer of the electronic resources. A greater dispute score can represent a greater likelihood that the digital interaction will be reversed. Thus, according to some examples, the generated dispute score can be used and analyzed by users to determine techniques for maximizing the win-rate. Additionally, the dispute score can be used for fraud analysis measures. For instance, if a given entity is determined to have repeatedly submitted interactions, each with a lowPATENT Attorney Docket No. 096923-1541325 Client Ref. No. EFX-209WO credibility and high dispute score, then the entity can be assigned a dispute score, or otherwise flagged as an entity likely to submit reversible interactions with low credibility. Additional examples of fraud detection and system security based on dispute scores are discussed further with respect to FIG. 4.
[0047] At block 210, the process 200 involves transmitting the dispute score. The dispute score can be transmitted back to the same third-party device which submitted the interaction inquiry or can be transmitted to another device. Transmission of the dispute score can be accompanied by various warnings, flags, alerts, and the like. For instance, exceeding a threshold dispute value can trigger the transmission of an alert along with the dispute score. In some examples, each dispute score is transmitted in-real time (i.e., in immediate response to the dispute inquiry). In other examples, only those dispute scores triggering a threshold dispute value will be transmitted. For instance, in cases where user settings are configured to transmit an interaction inquiry with each interaction, the dispute computing system 130 can be configured to generate alerts and report dispute scores only with those dispute scores exceeding the threshold dispute value. Transmitting the dispute score to the third-party device can cause the third-party to respond to the digital interaction. For example, in reviewing the dispute score, the third-party can then determine that the third-party has a high likelihood of reversing or otherwise challenging the interaction initiated by the separate entity. In response, the third-party may then transmit a response to the digital interaction (either via to the dispute computing system 130, or to the intermediary platform hosting the digital interaction platform or dispute service).
[0048] In some examples, transmitting the dispute score to the third-party device can cause further automated operations related to the interaction. For example, if the dispute score exceeds a heightened threshold, the dispute computing system can then generate an automated signal related to the interaction inquiry. The automated signal can include instructions that cause a response to be transmitted from the third-party device to the intermediary server hosting the interaction (e.g., a payment service processor). The automated signal can be transmitted in addition to or in alternative to the dispute score transmitted to the third-party device. The automated signal can also include supporting documentation, or instructions for causing the third-party device to access the supporting documentation, such that the automated response transmitted to the intermediary server includes supporting documentation as part of the automated response to the initial interaction. The heightened threshold that triggers the automated dispute may be preconfigured by the third-party. In such examples, the disputePATENT Attorney Docket No. 096923-1541325 Client Ref. No. EFX-209WO computing system 130 can receive an authenticated message from the third-party device where the authenticated message sets the heightened threshold, The heightened threshold serves to authorize the dispute computing system 130 to execute responses to the interaction on behalf of third party via transmission and forwarding of the automated signal.
[0049] Additional examples of responses triggered by transmitting the dispute score can include a wide array of automated and semi-automated actions, depending on the nature of the digital interaction and the system’s configuration. Additional examples of responses caused by transmitting the dispute score can include attempts to reclaim the electronic resources that were transferred in the digital interaction, messages transmitted to an intermediation service disputing the digital interaction, logging the interaction. Responses can include requests to restrict the separate entity’s ability to initiate the digital interactions, or messages. Responding to the interaction can include proactive responses to future interactions by the separate entity, such as by flagging the separate entity as requiring additional authentication in future interactions. In such examples, the automated signal including the dispute score can be transmitted to the third-party device, which causes the third-party device to require future interactions between the third-party device and the separate entity.Example Operations for Training A Machine Learning Mode to Generate Dispute Scores
[0050] Sampling bias can be a pervasive issue in data collection and modelling, as biases in sampling can lead to a distorted representation of a target population and can compromise the accuracy and generalizability of the results. FIG. 3 provides an example of certain techniques for mitigating sampling bias while training the machine-learning model 120. FIG.3 is a flow diagram of a process for training machine-learning models to generate dispute scores, according to certain examples. For illustrative purposes, the process 300 is described with reference to implementations described above with respect to one or more examples described herein. Other implementations, however, are possible. In some aspects, the operations in FIG. 3 may be implemented in program code that is executed by one or more computing devices such as the dispute server 118 depicted in FIG. 1. In some aspects of the present disclosure, one or more operations shown in FIG. 3 may be omitted or performed in a different order. Similarly, additional operations not shown in FIG. 3 may be performed.
[0051] At block 302, the process 300 involves retrieving an initial set of dispute training data (e.g., chargeback dispute training data). The initial set of dispute training data can be gathered from one or more repositories (e.g., data repository 122). The dispute training dataPATENT Attorney Docket No. 096923-1541325 Client Ref. No. EFX-209WO can include data related to various organizations and industries such as within the banking sector and any industry in which disputes may occur.
[0052] At block 304, the process 300 involves dividing the initial set of dispute training data into divided sets of strata based on timestamp features. The timestamp features can include, for example, month-year categories identifying the month and year of a dispute. Thus, previous disputes can be divided into stratum, or groups, based on the date of the dispute. While month-year provides one means for dividing the initial set of dispute training data into groups or stratum, it is to be appreciated other methods for dividing the initial set of dispute training data into divided sets of strata may be used.
[0053] At block 306, the process 300 involves generating the dispute training data based at least in part on the divided sets of strata. Generating the dispute training data after the initial set of dispute training data has been divided into various strata can include various operations, as illustrated according to the examples of blocks 306 A and 306B.
[0054] In the example of block 306A, generating the dispute training data based at least in part on the divided sets of strata includes performing a random sampling of each strata of the divided sets of strata to generate the dispute training data. While the previous division of the initial training data into stratum per block 304 refers to a process of stratified random sampling, additional random sampling techniques can be applied to generate the dispute training data from within the initial set of dispute training data during and in alternative to the stratified random sampling techniques including cluster-random sampling, weighted random sampling and the like. Thus, process 300 can represent a multi-stage random sampling technique, used to mitigate biases and discrepancies within the dispute training data.
[0055] In the example of block 306B, generating the dispute training data based at least in part on the divided sets of strata includes clustering the dispute training data in the divided sets of strata based on one or more features and generating the dispute training data based at least in part on the clustered dispute training data. Clustering operations can include anomalydetection based approaches including feature selection, where the feature selected can include those features other than the timestamp features used to separate the training data into stratum. The secondary features employed in clustering per block 306B can include temporal features and vertical features (e.g., including enriched vertical features according to the examples of FIG. 5). Other features for clustering can include transaction amount, dispute codes, geographic location, telemetric data, and the like. The clustering operations can be repeated or executed in parallel for each strata of data generated per block 304.PATENT Attorney Docket No. 096923-1541325 Client Ref. No. EFX-209WO
[0056] Once each strata is clustered, operations at block 306B can include various sampling techniques to sample data from each strata-cluster. The training data can be generated by proportional sampling from each cluster to maintain representative balance. Alternatively, specific strata-clusters can be emphasized or deemphasized in sampling. For example, certain clusters (e.g., clusters correlated to more dispositive dispute outcomes) can be oversampled, while those clusters with low correlation to dispute outcomes can be deemphasized as noise or as less predictive data. In this way, the operations at block 306B can serve to refine the training data set, offering a more targeted and effective approach to training machine-learning models used for dispute scoring by restricting and customizing the data used for model training. These methods can lead to measurable improvements in the overall performance of the machinelearning system implemented in dispute scoring tasks.Example Operations for Entity Veri fication using Dispute Scores
[0057] According to some examples, generation of dispute scores can be used to determine the likelihood that the entity which submitted a set of interactions is fraudulent or otherwise abusing the dispute process. FIG. 4 provides an example of certain techniques for assessing and minimizing the risk of threat actors interacting within a dispute system. FIG. 4 is a flow diagram of a process for assessing dispute scores based on dispute scores, according to certain examples. For illustrative purposes, the process 400 is described with reference to implementations described above with respect to one or more examples described herein. Other implementations, however, are possible. In some aspects, the operations in FIG. 4 may be implemented in program code that is executed by one or more computing devices such as the dispute server 118 depicted in FIG. 1. In some aspects of the present disclosure, one or more operations shown in FIG. 4 may be omitted or performed in a different order. Similarly, additional operations not shown in FIG. 4 may be performed.
[0058] At block 402, the process 400 involves generating, via the machine-learning model, a dispute score. Operations at block 402 are substantially similar to those described at block 208 of process 200. The operations at block 208 can include generating the dispute score for a given interaction the entity by applying the entity interaction data to the machine-learning model trained on dispute training data as described at block 206 of process 200.
[0059] At block 404, the process 400 involves assigning an entity anomaly score to the entity based at least in part on the dispute score. The entity anomaly score can refer to a risk level that the entity is a threat actor or is otherwise abusing the platform for initiating the disputes. Those entities that initiate larger numbers of interactions determined to be disputablePATENT Attorney Docket No. 096923-1541325 Client Ref. No. EFX-209WO by the machine-learning model may be assigned higher entity anomaly scores. The entity anomaly score can be assigned to the entity based on all, or certain disputes scores generated by the machine-learning model. In some examples, the entity anomaly score can be assigned, updated, or otherwise modified in response to the dispute score exceeding a threshold dispute value. The threshold dispute value can be a configurable value with a relatively high threshold (i.e., >.9 confidence that disputing an interaction would result in the interaction being reversed). A high threshold dispute value can be indicative of a baseless, or otherwise fraudulent disputes and interactions and attempts to reverse transactions. According to the process 400 at block 404, the entity anomaly scores can be tracked for any number of entities initiating digital interactions across a variety of platforms. The entity anomaly scores can be used to monitor entity behavior, and can be further used to determine whether a given entity’s interactions are likely to be abusing the platform facilitating the digital interactions. Per blocks 406 and 408, responsive to determining that an entity is likely to be abusing the platform (i.e., through a high entity anomaly score), the dispute computing system 130 can communicate with third parties such as the platform hosting the interaction, or the counter-party to the digital interaction (such as the merchant), the challenge the action. Further, according to block 408, access control mechanisms may be put in place to restrict access to the high entity anomaly score entity to thereby improve the security of the secure digital platform, and the improve the integrity of digital interactions.
[0060] The entity anomaly score, assigned per block 404, can be assigned in response to one or multiple digital interactions. For example, a single interaction with an exceedingly high dispute score (i.e., exceeding multiple thresholds), can cause a greater change in the entity anomaly score for the corresponding entity. Additionally or alternatively, repeated patterns of digital interactions exceeding dispute score thresholds can be aggregated to increase the entity anomaly score. Various combinations of scoring techniques may be applied to generate the entity anomaly score in response to one or a combination of dispute-scored digital interactions within the dispute computing system 130.
[0061] At block 406, the process 400 involves responsive to determining the entity anomaly score exceeds a threshold anomaly value, transmitting an alert to the third-party device. The threshold anomaly value can represent a configurable tolerance or confidence value that must be exceeded for the dispute computing system 130 to determine that the entity initiating the digital interaction is a threat-actor. The threshold anomaly can in some instances be set by the third-party, or by an intermediary hosting the dispute platform, where the abilityPATENT Attorney Docket No. 096923-1541325 Client Ref. No. EFX-209WO to set the threshold is protected behind an authenticated system. The alert can include the one or more dispute scores that caused the entity anomaly score to be assigned, an identifier of the entity that submitted the dispute score, and the like. The alert, transmitted to the third-party entity device, can be reviewed by the third-party entity to assess the entity’s account and digital persona, and can enable further monitoring of entity accounts with assigned high-risk entity anomaly scores.
[0062] In some examples, the process 400 can proceed to block 408, where the process 400 involves transmitting, with the alert, a signal that restricts the entity’s ability to initiate subsequent interactions. The signal can be transmitted to the third-party device, such as a counter-party to the digital interaction, where the third-party may include platform controls that enable the third-party device to control access to the digital interaction platform. Additionally or alternatively, the signal can be transmitted to a platform-hosting device associated with an intermediary party responsible for hosting the digital interaction service, particularly in instances where the third-party and the intermediary party are separate entities. The signal for restricting the entity’s ability to initiate subsequent interactions can include various forms of signals, including API restriction commands, session token invalidations, account flags. The signal may include executable logic or programmable instructions that dynamically alter the recipient party’s access control lists or other authentication and authorization mechanisms, thereby programmatically updating permissions, revoking credentials, or adjusting authorization states in real-time in response to risk conditions identified for entities with elevated anomaly scores.
[0063] The signal transmitted per block 408 can accordingly control access to secure computing environments, including platforms hosting the interaction service. The secure computing environment can include an authentication-backed computing environment, such as a password-protected web page, restricted server, mobile-hosted application, or the like. In the same and other examples, the secure computing environment can be a service-hosting system or intermediary for facilitating digital interactions and transactions. Controlling access to user interactions can include denying a request to execute an interaction, rejecting a request to overturn a dispute, adjusting read and write privileges, limiting or blocking access, implementing additional authentication requirements, and similar security measures. Access to specific servers and computing systems can likewise be subject to restriction.
[0064] In a network security example, the signal transmitted per block 408 can include executable instructions for moderating access restricted web pages, servers, or mobilePATENT Attorney Docket No. 096923-1541325 Client Ref. No. EFX-209WO applications. In such cases, access control is enforced by a range of measures, including denying or blocking requests to execute specific interactions within the system. Additionally, the dispute computing system 130 may adjust user permissions by limiting or revoking read and write privileges, thereby ensuring that only authorized interactions proceed. Enhanced security protocols, such as requiring additional authentication steps, can also be implemented to further safeguard system integrity. These actions collectively serve to prevent unauthorized or potentially harmful activities from compromising the secure computing infrastructure.
[0065] In a service-hosting and mediation example, the signal generated per block 408 can relate to moderating chargeback disputes. In such examples, the signal generated per block 408 can include executable instructions that control dispute-related user actions. Digital interaction control can include rejecting user requests to overturn existing dispute outcomes including chargeback disputes, to then maintain the original decision regarding a chargeback. By controlling dispute resolution access, the dispute computing system 130 can prevent abuse of the dispute process, such as repeated or fraudulent attempts to reverse transactions. Such control signals can ensure that only credible and justified requests proceed, helping to protect merchants and other stakeholders from undue chargeback reversals.Example o f Computing System for Machine-Learning Operations
[0066] FIG. 5 is a flow diagram of a set of operations 500 for enriching data to facilitate machine-learning model training according to certain examples. One or more computing devices (e.g., the dispute server 118) implement operations depicted in FIG. 5 by executing suitable program code (e.g., the dispute application 114). For illustrative purposes, the operations 500 are described with reference to certain examples depicted in the figures. Other implementations, however, are possible. While the blocks of the operations 500 are described in the temporal order below for illustrative purposes, it may be appreciated that the blocks can occur in any order, and some blocks may occur simultaneously.
[0067] At block 502 the operations 500 include receiving a query including an entity name where the entity name is representative of an entity. Generally, the process for data enrichment relates to assigning entities previously unassigned to a vertical to a proper vertical. Thus, the entities queried, via entry of the entity name, can correspond to entities without assigned verticals. In some examples, each entity within a repository may be queried, and as a threshold analysis, if the entity is determined to already be assigned a vertical, the operations 500 may terminate. In other examples, the initial repository queried can include only those entities already determined to not have a corresponding vertical. In further examples, entities alreadyPATENT Attorney Docket No. 096923-1541325 Client Ref. No. EFX-209WO having a vertical assigned can be queried and processed per operations 500 to perform further validation.
[0068] At block 504 the operations 500 involve retrieving, from one or more repositories, an entity data set including records associated with the entity. Generally, the records in each repository can include entity-vertical pairing data. One repository of the one or more repositories can be an inquiry log table including transaction inquiry records for respective transactions. The inquiry log table can provide for a large set of industry codes (e.g., 100+ industry codes) to provide an initial reference point for vertical assignment. The inquiry log table may thus provide an initial data set for subsequent evaluation and refinement according to additional repositories providing smaller sets of industry codes for vertical assignment.
[0069] The one or more repositories storing entity data can include a repository storing transaction data. Unlike the inquiry log table, the repository including transaction data can include a reduced set of industry codes (e.g., on the order of thirty industry codes). As greater numbers of industry codes would on its own contribute to high data cardinality, databases storing a truncated set of industry codes (e.g., a database storing thirty industry codes as opposed to hundreds industry codes), such as provided by the repository including transaction data may be preferred over other repositories such as the inquiry log table in generating the final set of enriched data.
[0070] The initial data and records retrieved from the one or more repositories can be filtered to eliminate records with null or missing values to refine the initial data and form a curated dataset. The data retrieved from the one or more repositories can thus represent an initial set of entity data. Records with null values, such as those lacking an entity name entry, a vertical entry, or an entity-record pairing, can then be identified and the identified records removed to generate the entity data set for use in prompt engineering (also referred to as “tuning”) an LLM. In such a way, incomplete data which would not assist in prompt engineering the LLM to assign verticals can be removed from the entity data set to improve prompt engineering efficiency.
[0071] At block 506 the operations 500 include prompt engineering an LLM with the entity data set. The LLM employed can generally include any pre-trained LLM capable of feature inference based on received prompts. Examples can include Google Gemini, Databricks Llama, Amazon Web Services (“AWS”) SageMaker and the like. As the LLM will generally be pretrained, block 506 refers to a process of tuning the LLM through prompt engineering based on the entity data set. Thus, the LLM, as pre-trained, can use a preexisting corpus of trainingPATENT Attorney Docket No. 096923-1541325 Client Ref. No. EFX-209WO data to predict verticals, further augmented by the entity data set. The entity data set may be used to establish a predefined scope of verticals for assignment to a representative sample of entities. The use of the entity data set can serve as a reference point, providing a set of established vertical-industry pairing examples for further tuning and refining the accuracy of a prebuilt LLM at block 506. In some examples, the entity data set may also be used to train a new LLM that may then be further prompt engineered per block 506.
[0072] According to certain examples, prompt engineering the LLM based on the entity data can include prompt structuring and dialog tuning of the LLM based on the entity data. Prompt structuring refers to the process of generating prompts for input into the LLM (e.g., specifying the inclusion of the entity data) to further train the LLM to predict verticals for a given entity. One example format of prompts used to assign verticals can include “[industry options] + [instructions] + [Entity List]” where the entity list represents the entity data set. In some cases, such prompts may be altered to achieve a desired output format or to achieve additional outputs. Dialog tuning refers to the process of refining the prompts to ensure extraction of the relevant data and ensure that the LLM is outputting accurate vertical predictions. For instance, if the entity data is too large, the LLM may only output, per block 508, a partial set of results due to token limits and other limitations of the LLM. Additional examples of dialog tuning can include refining instructions for output formatting or adding language muting additional commentary beyond entity: industry pairs to conserve tokens or additional prompting to have the LLM continue assigning for long lists of entities should a first prompt not return the complete list.
[0073] At block 508 the operations 500 include generating, using the prompt engineered LLM, a vertical prediction based on the entity name. The vertical prediction represents a confidence of the LLM, based on the entity data used to further tune the LLM and the entity name input into the LLM, that the entity is to be assigned to a given vertical. As an example, an entity name entered into the LLM such as “Jane’ s Provisions” may lead to the LLM to output a confidence score of 0.99 that the entity is to be assigned to the vertical representing grocers. In another example, the entity name “John’ s” may, depending on the entity data used to prompt engineer the LLM, output a corresponding vertical prediction that John’s is to be assigned to vertical defining restaurants with a .6 confidence score. As more entity data is provided to prompt engineer the LLM per blocks 504-506, the confidence scores and accuracies of the LLM may be improved.PATENT Attorney Docket No. 096923-1541325 Client Ref. No. EFX-209WO
[0074] At block 510 the operations 500 include assigning the vertical prediction to the entity. In some examples, the entity refers to a two-dimensional record including entity name and the assigned vertical prediction. Additional dimensions for each record can be included representing other dimensions of the entity. In some examples, the confidence score associated with the vertical prediction may also be stored as a dimension of data with the entity name and assigned vertical. In some examples, the vertical prediction may be assigned to the entity only if a threshold confidence is exceeded. For instance, returning to the examples discussed at block 508, the “Jane’s Provisions” entity may be assigned the grocer vertical prediction for exceeding the confidence threshold (e.g., >=.8 confidence), while “John’s” remains unassigned a vertical prediction for no corresponding vertical prediction exceeding the threshold confidence.
[0075] At block 512 the operations 500 include storing the entity in as enriched features. The enriched features, with the assigned vertical per block 510, may be stored in an enriched data set, where the enriched feature set can be implemented for subsequent use according to a variety of AI / ML model configurations. The enriched data set, storing enriched features and entity data with assigned verticals, can store the entity data with reduced cardinality due to the vertical assignments. As used herein, cardinality can refer to the number of unique values in a data set, particularly related to classifications. The reduced cardinality leads to an improved implementation of the subsequent AI / ML models, contributing to increased efficiencies in larger computing infrastructures.
[0076] In some examples, the operations 500 can be supplemented with techniques for validating the accuracy of the vertical assignments, and for ensuring the accuracy of the enriched features. For instance, techniques including exact matching (e.g., VLOOKUP) and fuzzy matching can be applied to compare entity data as stored across the various databases to ensure proper processing by the LLM.
[0077] For instance, a validation score can be generated representing the degree in confidence that the enriched features accurately reflect the entity data used to generate the entity data set. In other words, such matching techniques may be applied to identify the overlap between entities in the enriched features and those present in the training data. The validation score can be generated by performing, for each record in the entity data set, an exact matching search within the enriched entity data set to determine whether the entity record matches with an enriched entity record within the enriched entity data set. The validation score may then be based on the number of determined matches, such as a percentage of records that were determined to match. Similar techniques may be applied per a fuzzy matching search procedurePATENT Attorney Docket No. 096923-1541325 Client Ref. No. EFX-209WO where tolerances may be applied to allow for minor variations between the query entity record and a candidate matching enriched entity record.Example of Computing System for Machine-Learning Operations
[0078] Any suitable computing system or group of computing systems can be used to perform the operations for the machine-learning operations described herein. For example, FIG. 6 is a block diagram depicting an example of a computing device, which can be used to implement the dispute server or the model training server according to disclosed embodiments. The computing device 600 can include various devices for communicating with other devices in the operating environment, as described with respect to FIG. 1. The computing device 600 can include various devices for performing one or more transformation operations described above with respect to FIGS. 1-5.
[0079] The computing device 600 can include a processor 602 that is communicatively coupled to a memory 604. The processor 602 executes computer-executable program code stored in the memory 604, accesses information stored in the memory 604, or both. Program code 616 may include machine-executable instructions that may represent a procedure, a function, a subprogram, a program, a routine, a subroutine, a module, a software package, a class, or any combination of instructions, data structures, or program statements. A code segment may be coupled to another code segment or a hardware circuit by passing or receiving information, data, arguments, parameters, or memory contents. Information, arguments, parameters, data, etc. may be passed, forwarded, or transmitted via any suitable means including memory sharing, message passing, token passing, network transmission, among others.
[0080] Examples of a processor 602 include a microprocessor, an application-specific integrated circuit, a field-programmable gate array, or any other suitable processing device. The processor 602 can include any number of processing devices, including one. The processor 602 can include or communicate with a memory 604. The memory 604 stores program code 616 that, when executed by the processor 602, causes the processor to perform the operations described in this disclosure.
[0081] The memory 604 can include any suitable non-transitory computer-readable medium. The computer-readable medium can include any electronic, optical, magnetic, or other storage device capable of providing a processor with computer-readable program code or other program code. Non-limiting examples of a computer-readable medium include a magnetic disk, memory chip, optical storage, flash memory, storage-class memory, ROM,PATENT Attorney Docket No. 096923-1541325 Client Ref. No. EFX-209WO RAM, an ASIC, magnetic storage, or any other medium from which a computer processor can read and execute program code. The program code 616 may include processor-specific program code generated by a compiler or an interpreter from code written in any suitable computer-programming language. Examples of suitable programming language include Hadoop, C, C++, C#, Visual Basic, Java, Python, Perl, JavaScript, ActionScript, etc.
[0082] The computing device 600 may also include a number of external or internal devices such as input or output devices. For example, the computing device 600 is shown with an input / output interface 608 that can receive input from input devices or provide output to output devices. A bus 606 can also be included in the computing device 600. The bus 606 can communicatively couple one or more components of the computing device 600.
[0083] The computing device 600 can execute program code 615 that includes the dispute application 114 and / or the model training application 112. The program code 615 for the dispute application 114 and / or the model training application 112 may be resident in any suitable computer-readable medium and may be executed on any suitable processing device. For example, as depicted in FIG. 6, the program code 615 for the dispute application 114 and / or the model training application 112 can reside in the memory 604 at the computing device 600 along with the program data 616 associated with the program code 615, such the dispute application 114 and the machine-learning model(s) 120. Executing the dispute application 114 or the model training application 112 can configure the processor 602 to perform the operations described herein.
[0084] In some aspects, the computing device 600 can include one or more output devices. One example of an output device is the network interface device 610 depicted in FIG. 6. A network interface device 610 can include any device or group of devices suitable for establishing a wired or wireless data connection to one or more data networks described herein. Non-limiting examples of the network interface device 610 include an Ethernet network adapter, a modem, etc.
[0085] Another example of an output device is the presentation device 612 depicted in FIG.6. A presentation device 612 can include any device or group of devices suitable for providing visual, auditory, or other suitable sensory output. Non-limiting examples of the presentation device 612 include a touchscreen, a monitor, a speaker, a separate mobile computing device, etc. In some aspects, the presentation device 612 can include a remote client-computing device that communicates with the computing device 600 using one or more data networks described herein. In other aspects, the presentation device 612 can be omitted.PATENT Attorney Docket No. 096923-1541325 Client Ref. No. EFX-209WO General Considerations
[0086] Numerous specific details are set forth herein to provide a thorough understanding of the claimed subject matter. However, those skilled in the art will understand that the claimed subject matter may be practiced without these specific details. In other instances, methods, apparatuses, or systems that would be known by one of ordinary skill have not been described in detail so as not to obscure claimed subject matter.
[0087] Unless specifically stated otherwise, it is appreciated that throughout this specification that terms such as “processing,” “computing,” “determining,” and “identifying” or the like refer to actions or processes of a computing device, such as one or more computers or a similar electronic computing device or devices, that manipulate or transform data represented as physical electronic or magnetic quantities within memories, registers, or other information storage devices, transmission devices, or display devices of the computing platform.
[0088] The system or systems discussed herein are not limited to any particular hardware architecture or configuration. A computing device can include any suitable arrangement of components that provides a result conditioned on one or more inputs. Suitable computing devices include multipurpose microprocessor-based computing systems accessing stored software that programs or configures the computing system from a general-purpose computing apparatus to a specialized computing apparatus implementing one or more aspects of the present subject matter. Any suitable programming, scripting, or other type of language or combinations of languages may be used to implement the teachings contained herein in software to be used in programming or configuring a computing device.
[0089] Aspects of the methods disclosed herein may be performed in the operation of such computing devices. The order of the blocks presented in the examples above can be varied — for example, blocks can be re-ordered, combined, or broken into sub-blocks. Certain blocks or processes can be performed in parallel.
[0090] The use of “adapted to” or “configured to” herein is meant as open and inclusive language that does not foreclose devices adapted to or configured to perform additional tasks or steps. Additionally, the use of “based on” is meant to be open and inclusive, in that a process, step, calculation, or other action “based on” one or more recited conditions or values may, in practice, be based on additional conditions or values beyond those recited. Headings, lists, and numbering included herein are for ease of explanation only and are not meant to be limiting.PATENT Attorney Docket No. 096923-1541325 Client Ref. No. EFX-209WO
[0091] While the present subject matter has been described in detail with respect to specific aspects thereof, it will be appreciated that those skilled in the art, upon attaining an understanding of the foregoing, may readily produce alterations to, variations of, and equivalents to such aspects. Any aspects or examples may be combined with any other aspects or examples. Accordingly, it should be understood that the present disclosure has been presented for purposes of example rather than limitation, and does not preclude inclusion of such modifications, variations, or additions to the present subject matter as would be readily apparent to one of ordinary skill in the art.
Claims
PATENT Attorney Docket No. 096923-1541325 Client Ref. No. EFX-209WO Claims1. A non-transitory computer-readable storage medium having program code executable by a processing device to perform operations comprising:receiving, from a third-party device, a digital interaction inquiry associated with a digital interaction, the digital interaction comprising a transfer of electronic resources from a third-party associated with the third-party device to a separate entity;retrieving interaction data associated with the digital interaction;applying the interaction data to a machine-learning model trained on dispute training data to generate a dispute score, the dispute score representing a likelihood of successfully disputing the digital interaction and reversing the transfer of the electronic resources; and transmitting the dispute score to the third-party device to cause the third-party to respond to the digital interaction.
2. The non-transitory computer-readable storage medium of claim 1, wherein the operations further comprise:assigning an entity anomaly score to the entity based at least in part on the dispute score; andresponsive to determining the entity anomaly score exceeds a threshold anomaly value, transmitting an alert to the third-party device.
3. The non-transitory computer-readable storage medium of claim 2, wherein the operations further comprise:transmitting, with the alert, a signal that restricts an ability of the entity to initiate subsequent interactions.
4. The non-transitory computer-readable storage medium of claim 1, wherein the operations further comprise training a machine-learning model by:generating a set of features from the dispute training data, the set of features including temporal features, timestamp features, and vertical features; andtraining the machine-learning model on the set of features.PATENT Attorney Docket No. 096923-1541325 Client Ref. No. EFX-209WO 5. The non-transitory computer-readable storage medium of claim 4, wherein the operations further comprise generating the dispute training data by:retrieving an initial set of dispute training data;dividing the initial set of dispute training data into divided sets of strata based on timestamp features; andgenerating the dispute training data based at least in part on the divided sets of strata.
6. The non-transitory computer-readable storage medium of claim 5, wherein generating the dispute training data based at least in part on the divided sets of strata comprises performing a random sampling of each strata of the divided sets of strata to generate the dispute training data.
7. The non-transitory computer-readable storage medium of claim 5, wherein generating the dispute training data based at least in part on the divided sets of strata comprises:clustering the dispute training data in the divided sets of strata based on one or more features; andgenerating the dispute training data based at least in part on the clustered dispute training data.
8. The non-transitory computer-readable storage medium of claim 4, wherein the set of features comprise enriched features, the enriched features generated via operations comprising:receiving a query comprising an entity name, the entity name representative of an entity;retrieving, from one or more repositories, an entity data set comprising records associated with the entity;prompt engineering a large language model (LLM) with the entity data set; generating, using the prompt engineered LLM, a vertical prediction based on the entity name;assigning the vertical prediction to an entity record corresponding to the entity; and storing the entity record in an enriched entity data set.
9. A computer-implemented method comprising:PATENT Attorney Docket No. 096923-1541325 Client Ref. No. EFX-209WO receiving, by a processor and from a third-party device, a digital interaction inquiry associated with a digital interaction, the digital interaction comprising a transfer of electronic resources from a third-party associated with the third-party device to a separate entity;retrieving, by the processor, interaction data associated with the digital interaction; applying, by the processor, the interaction data to a machine-learning model trained on dispute training data to generate a dispute score, the dispute score representing a likelihood of successfully disputing the digital interaction and reversing the transfer of the electronic resources; andtransmitting, by the processor and to the third-party device, the dispute score to cause the third-party to respond to the digital interaction.
10. The computer-implemented method of claim 9, wherein the operations further comprise:assigning an entity anomaly score to the entity based at least in part on the dispute score; andresponsive to determining the entity anomaly score exceeds a threshold anomaly value, transmitting an alert to the third-party device.
11. The computer-implemented method of claim 10, wherein the operations further comprise, transmitting, with the alert, a signal that restricts an ability of the entity to initiate subsequent interactions.
12. The computer-implemented method of claim 9, wherein the operations further comprise training a machine-learning model by:generating a set of features from the dispute training data, the set of features including temporal features, timestamp features, and vertical features; andtraining the machine-learning model on the set of features.
13. The computer-implemented method of claim 12, wherein the operations further comprise generating the dispute training data by:retrieving an initial set of dispute training data;dividing the initial set of dispute training data into divided sets of strata based on timestamp features; andPATENT Attorney Docket No. 096923-1541325 Client Ref. No. EFX-209WO generating the dispute training data based at least in part on the divided sets of strata.
14. The computer-implemented method of claim 13, wherein generating the dispute training data based at least in part on the divided sets of strata comprises performing a random sampling of each strata of the divided sets of strata to generate the dispute training data.
15. The computer-implemented method of claim 13, wherein generating the dispute training data based at least in part on the divided sets of strata comprises clustering the dispute training data in the divided sets of strata based on one or more features; andgenerating the dispute training data based at least in part on the clustered dispute training data.
16. A system comprising:a processing device; anda memory device in which instructions executable by the processing device are stored for causing the processing device to perform operations comprising:receiving, from a third-party device, a digital interaction inquiry associated with a digital interaction, the digital interaction comprising a transfer of electronic resources from a third-party associated with the third-party device to a separate entity;retrieving interaction data associated with the digital interaction; applying the interaction data to a machine-learning model trained on dispute training data to generate a dispute score, the dispute score representing a likelihood of successfully disputing the digital interaction and reversing the transfer of the electronic resources; andtransmitting the dispute score to the third-party device to cause the third-party to respond to the digital interaction.
17. The system of claim 16, wherein the operations further comprise:assigning an entity anomaly score to the entity based at least in part on the dispute score; andresponsive to determining the entity anomaly score exceeds a threshold anomaly value, transmitting an alert to the third-party device.PATENT Attorney Docket No. 096923-1541325 Client Ref. No. EFX-209WO 18. The system of claim 17, wherein the operations further comprise, transmitting, with the alert, a signal that restricts an ability of the entity to initiate subsequent interactions.
19. The system of claim 16, wherein the operations further comprise training a machinelearning model by:generating a set of features from the dispute training data, the set of features including temporal features, timestamp features, and vertical features; andtraining the machine-learning model on the set of features.
20. The system of claim 19, wherein the operations further comprise generating the dispute training data by:retrieving an initial set of dispute training data;dividing the initial set of dispute training data into divided sets of strata based on timestamp features; andgenerating the dispute training data based at least in part on the divided sets of strata.