Anomaly Detection in Automated Workflow Event Decisions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current digital fraud and abuse detection technologies lack accuracy and real-time capabilities to effectively detect new threats and evolve to neutralize digital threats, failing to provide timely responses to malicious activities over the Internet.

Innovation Solution

A machine learning-based system for automated anomaly detection in online fraud and abuse mitigation platforms that collects real-time data, employs various anomaly detection algorithms, including statistical and machine learning models like LSTM and CNN, to identify anomalies and generate alerts, and automatically updates threat mitigation workflows to address new or evolving threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If existing digital fraud detection technologies are used, then some detection capability is provided, but accuracy and real-time response capability are insufficient

Engineering Contradiction:
Improvedetection accuracyVSAvoidreal-time response capability
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The system dynamically adapts its detection models based on incoming data patterns. The machine learning models continuously learn from new fraud patterns, allowing the system to maintain high accuracy while responding in real-time to evolving threats without requiring manual intervention or model retraining.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system incorporates feedback loops where detection results and outcomes are fed back into the machine learning models to continuously improve accuracy. This feedback mechanism allows the system to learn from both successful detections and false alarms, enhancing precision while maintaining real-time operational capability.

Inventive Principle:
Principle #23Feedback

2Adaptability or versatility

If existing detection technologies are used, then current threats can be detected, but new and evolving threats cannot be detected

Engineering Contradiction:
Improvedetection of new threatsVSAvoiddetection accuracy
Core Design Contradiction:
Adaptability or versatilityVSMeasurement precision

Solution Approach 1:

The system performs preliminary learning and adaptation by continuously training machine learning models on incoming data patterns. This preliminary action enables the system to prepare detection capabilities in advance for emerging threats, allowing it to detect new fraud patterns accurately as they arise rather than reacting after detection failures occur.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system changes its detection parameters and model structures dynamically based on observed patterns. When new threat patterns emerge, the machine learning models automatically adjust their parameters and detection criteria, enabling the system to adapt to new threats while maintaining high detection accuracy through continuous parameter optimization.

Inventive Principle:
Principle #35Parameter changes

3Speed

If real-time data collection is implemented, then timely detection is achieved, but system complexity increases

Engineering Contradiction:
Improvedetection speedVSAvoidsystem complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The system segments the detection process into distinct functional modules: data collection, data processing, machine learning analysis, and alert generation. This segmentation allows each component to be optimized independently, achieving real-time detection speed while managing system complexity through modular architecture where failures in one module do not cascade to the entire system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces intermediary processing layers between data collection and final detection decisions. These intermediary components include preprocessing modules, feature extraction layers, and model selection mechanisms that mediate between raw data and detection outputs, enabling real-time processing while simplifying the overall system architecture through standardized intermediate representations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11049116B1Systems and methods for anomaly detection in automated workflow event decisions in a machine learning-based digital threat mitigation platform
Publication Date: 2021.06.29 SIFT SCIENCE INC
  • US11049116B1 patent drawing
  • US11049116B1 patent drawing
  • US11049116B1 patent drawing

AI summary

A system and method for automated anomaly detection in automated disposal decisions of an automated decisioning workflow includes collecting a time-series of automated disposal decision data for a current period from an automated decisioning workflow, wherein the automated decisioning workflow computes one of a plurality of distinct disposal decisions for each distinct input comprising subject online event data and a machine learning-based threat score computed for the subject online event data; selecting an anomaly detection algorithm from a plurality of distinct anomaly detection algorithms based on a type of online abuse or online fraud that the automated decisioning workflow is configured to evaluate; evaluating, using the selected anomaly detection algorithm, the time-series of automated decision data for the current period; computing whether anomalies exist in the time-series of automated disposal decision data for the current period based on the evaluation; and generating an anomaly alert based on the computation.