Anomaly Detection in Automated Workflow Event Decisions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current digital fraud and abuse detection technologies lack accuracy and real-time capabilities to effectively detect new threats and evolve to neutralize digital threats, failing to provide timely responses to malicious activities over the Internet.
Innovation Solution
A machine learning-based system for automated anomaly detection in online fraud and abuse mitigation platforms that collects real-time data, employs various anomaly detection algorithms, including statistical and machine learning models like LSTM and CNN, to identify anomalies and generate alerts, and automatically updates threat mitigation workflows to address new or evolving threats.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If existing digital fraud detection technologies are used, then some detection capability is provided, but accuracy and real-time response capability are insufficient
Solution Approach 1:
The system dynamically adapts its detection models based on incoming data patterns. The machine learning models continuously learn from new fraud patterns, allowing the system to maintain high accuracy while responding in real-time to evolving threats without requiring manual intervention or model retraining.
Solution Approach 2:
The system incorporates feedback loops where detection results and outcomes are fed back into the machine learning models to continuously improve accuracy. This feedback mechanism allows the system to learn from both successful detections and false alarms, enhancing precision while maintaining real-time operational capability.
2Adaptability or versatility
If existing detection technologies are used, then current threats can be detected, but new and evolving threats cannot be detected
Solution Approach 1:
The system performs preliminary learning and adaptation by continuously training machine learning models on incoming data patterns. This preliminary action enables the system to prepare detection capabilities in advance for emerging threats, allowing it to detect new fraud patterns accurately as they arise rather than reacting after detection failures occur.
Solution Approach 2:
The system changes its detection parameters and model structures dynamically based on observed patterns. When new threat patterns emerge, the machine learning models automatically adjust their parameters and detection criteria, enabling the system to adapt to new threats while maintaining high detection accuracy through continuous parameter optimization.
3Speed
If real-time data collection is implemented, then timely detection is achieved, but system complexity increases
Solution Approach 1:
The system segments the detection process into distinct functional modules: data collection, data processing, machine learning analysis, and alert generation. This segmentation allows each component to be optimized independently, achieving real-time detection speed while managing system complexity through modular architecture where failures in one module do not cascade to the entire system.
Solution Approach 2:
The system introduces intermediary processing layers between data collection and final detection decisions. These intermediary components include preprocessing modules, feature extraction layers, and model selection mechanisms that mediate between raw data and detection outputs, enabling real-time processing while simplifying the overall system architecture through standardized intermediate representations.
Data Source
AI summary
A system and method for automated anomaly detection in automated disposal decisions of an automated decisioning workflow includes collecting a time-series of automated disposal decision data for a current period from an automated decisioning workflow, wherein the automated decisioning workflow computes one of a plurality of distinct disposal decisions for each distinct input comprising subject online event data and a machine learning-based threat score computed for the subject online event data; selecting an anomaly detection algorithm from a plurality of distinct anomaly detection algorithms based on a type of online abuse or online fraud that the automated decisioning workflow is configured to evaluate; evaluating, using the selected anomaly detection algorithm, the time-series of automated decision data for the current period; computing whether anomalies exist in the time-series of automated disposal decision data for the current period based on the evaluation; and generating an anomaly alert based on the computation.


